[PATCH] target/riscv: prevent abrupt abortion on unassigned value write to tdata

Abhigyan Kumar posted 1 patch 2 months ago
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20260729230028.1797355-1-314abh@gmail.com
Maintainers: Palmer Dabbelt <palmer@dabbelt.com>, Alistair Francis <alistair.francis@wdc.com>, Weiwei Li <liwei1518@gmail.com>, Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>, Liu Zhiwei <zhiwei_liu@linux.alibaba.com>, Chao Liu <chao.liu@processmission.com>
target/riscv/tcg/debug.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
[PATCH] target/riscv: prevent abrupt abortion on unassigned value write to tdata
Posted by Abhigyan Kumar 2 months ago
tdata_csr_write is approachable by guest programs. In case of unassigned
values written to a tdata CSR in debug mode, the switch-case falls
through straight to default causing an immediate abort. The risc-v spec
says:

    All tdata registers follow write-any-read-legal semantics. If a debugger
    writes an unsupported configuration, the register will read back a value
    that is supported (which may simply be a disabled trigger). This means
    that a debugger must always read back values it writes to tdata
    registers, unless it already knows what is supported.

This fix correctly ensures that the WARL behaviour of tdata CSRs.

Fixes: a42bd001 ("target/riscv: debug: Determine the trigger type from
tdata1.type")
Signed-off-by: Abhigyan Kumar <314abh@gmail.com>
---
 target/riscv/tcg/debug.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/target/riscv/tcg/debug.c b/target/riscv/tcg/debug.c
index 3c0fe7010..ae493235d 100644
--- a/target/riscv/tcg/debug.c
+++ b/target/riscv/tcg/debug.c
@@ -913,7 +913,8 @@ void tdata_csr_write(CPURISCVState *env, int tdata_index, target_ulong val)
                       trigger_type);
         break;
     default:
-        g_assert_not_reached();
+        qemu_log_mask(LOG_GUEST_ERROR, "trigger type: %d is unassigned\n",
+                trigger_type);
     }
 }
 
-- 
2.55.0
Re: [PATCH] target/riscv: prevent abrupt abortion on unassigned value write to tdata
Posted by Alistair Francis 3 weeks, 3 days ago
On Thu, 2026-07-30 at 04:30 +0530, Abhigyan Kumar wrote:
> tdata_csr_write is approachable by guest programs. In case of
> unassigned
> values written to a tdata CSR in debug mode, the switch-case falls
> through straight to default causing an immediate abort. The risc-v
> spec
> says:
> 
>     All tdata registers follow write-any-read-legal semantics. If a
> debugger
>     writes an unsupported configuration, the register will read back
> a value
>     that is supported (which may simply be a disabled trigger). This
> means
>     that a debugger must always read back values it writes to tdata
>     registers, unless it already knows what is supported.
> 
> This fix correctly ensures that the WARL behaviour of tdata CSRs.
> 
> Fixes: a42bd001 ("target/riscv: debug: Determine the trigger type
> from
> tdata1.type")
> Signed-off-by: Abhigyan Kumar <314abh@gmail.com>

Thanks!

Applied to riscv-to-apply.next

Alistair

> ---
>  target/riscv/tcg/debug.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/target/riscv/tcg/debug.c b/target/riscv/tcg/debug.c
> index 3c0fe7010..ae493235d 100644
> --- a/target/riscv/tcg/debug.c
> +++ b/target/riscv/tcg/debug.c
> @@ -913,7 +913,8 @@ void tdata_csr_write(CPURISCVState *env, int
> tdata_index, target_ulong val)
>                        trigger_type);
>          break;
>      default:
> -        g_assert_not_reached();
> +        qemu_log_mask(LOG_GUEST_ERROR, "trigger type: %d is
> unassigned\n",
> +                trigger_type);
>      }
>  }
>  
Re: [PATCH] target/riscv: prevent abrupt abortion on unassigned value write to tdata
Posted by Alistair Francis 3 weeks, 3 days ago
On Thu, 2026-07-30 at 04:30 +0530, Abhigyan Kumar wrote:
> tdata_csr_write is approachable by guest programs. In case of
> unassigned
> values written to a tdata CSR in debug mode, the switch-case falls
> through straight to default causing an immediate abort. The risc-v
> spec
> says:
> 
>     All tdata registers follow write-any-read-legal semantics. If a
> debugger
>     writes an unsupported configuration, the register will read back
> a value
>     that is supported (which may simply be a disabled trigger). This
> means
>     that a debugger must always read back values it writes to tdata
>     registers, unless it already knows what is supported.
> 
> This fix correctly ensures that the WARL behaviour of tdata CSRs.
> 
> Fixes: a42bd001 ("target/riscv: debug: Determine the trigger type
> from
> tdata1.type")
> Signed-off-by: Abhigyan Kumar <314abh@gmail.com>

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>

Alistair

> ---
>  target/riscv/tcg/debug.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/target/riscv/tcg/debug.c b/target/riscv/tcg/debug.c
> index 3c0fe7010..ae493235d 100644
> --- a/target/riscv/tcg/debug.c
> +++ b/target/riscv/tcg/debug.c
> @@ -913,7 +913,8 @@ void tdata_csr_write(CPURISCVState *env, int
> tdata_index, target_ulong val)
>                        trigger_type);
>          break;
>      default:
> -        g_assert_not_reached();
> +        qemu_log_mask(LOG_GUEST_ERROR, "trigger type: %d is
> unassigned\n",
> +                trigger_type);
>      }
>  }
>  
Re: [PATCH] target/riscv: prevent abrupt abortion on unassigned value write to tdata
Posted by abh 1 month, 2 weeks ago
On 7/30/26 4:30 AM, Abhigyan Kumar wrote:
> tdata_csr_write is approachable by guest programs. In case of unassigned
> values written to a tdata CSR in debug mode, the switch-case falls
> through straight to default causing an immediate abort. The risc-v spec
> says:
> 
>      All tdata registers follow write-any-read-legal semantics. If a debugger
>      writes an unsupported configuration, the register will read back a value
>      that is supported (which may simply be a disabled trigger). This means
>      that a debugger must always read back values it writes to tdata
>      registers, unless it already knows what is supported.
> 
> This fix correctly ensures that the WARL behaviour of tdata CSRs.
> 
> Fixes: a42bd001 ("target/riscv: debug: Determine the trigger type from
> tdata1.type")
> Signed-off-by: Abhigyan Kumar <314abh@gmail.com>
> ---
>   target/riscv/tcg/debug.c | 3 ++-
>   1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/target/riscv/tcg/debug.c b/target/riscv/tcg/debug.c
> index 3c0fe7010..ae493235d 100644
> --- a/target/riscv/tcg/debug.c
> +++ b/target/riscv/tcg/debug.c
> @@ -913,7 +913,8 @@ void tdata_csr_write(CPURISCVState *env, int tdata_index, target_ulong val)
>                         trigger_type);
>           break;
>       default:
> -        g_assert_not_reached();
> +        qemu_log_mask(LOG_GUEST_ERROR, "trigger type: %d is unassigned\n",
> +                trigger_type);
>       }
>   }
>   

Greetings. It has been over two weeks since I submitted this patch. It's 
my humble request to know the status of the review/acceptance for my 
patch. Please inform me about any required amends.

Thank you for your patience and attention.