target/riscv/tcg/debug.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-)
tdata_csr_write is approachable by guest programs. In case of unassigned
values written to a tdata CSR in debug mode, the switch-case falls
through straight to default causing an immediate abort. The risc-v spec
says:
All tdata registers follow write-any-read-legal semantics. If a debugger
writes an unsupported configuration, the register will read back a value
that is supported (which may simply be a disabled trigger). This means
that a debugger must always read back values it writes to tdata
registers, unless it already knows what is supported.
This fix correctly ensures that the WARL behaviour of tdata CSRs.
Fixes: a42bd001 ("target/riscv: debug: Determine the trigger type from
tdata1.type")
Signed-off-by: Abhigyan Kumar <314abh@gmail.com>
---
target/riscv/tcg/debug.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/target/riscv/tcg/debug.c b/target/riscv/tcg/debug.c
index 3c0fe7010..ae493235d 100644
--- a/target/riscv/tcg/debug.c
+++ b/target/riscv/tcg/debug.c
@@ -913,7 +913,8 @@ void tdata_csr_write(CPURISCVState *env, int tdata_index, target_ulong val)
trigger_type);
break;
default:
- g_assert_not_reached();
+ qemu_log_mask(LOG_GUEST_ERROR, "trigger type: %d is unassigned\n",
+ trigger_type);
}
}
--
2.55.0
On Thu, 2026-07-30 at 04:30 +0530, Abhigyan Kumar wrote:
> tdata_csr_write is approachable by guest programs. In case of
> unassigned
> values written to a tdata CSR in debug mode, the switch-case falls
> through straight to default causing an immediate abort. The risc-v
> spec
> says:
>
> All tdata registers follow write-any-read-legal semantics. If a
> debugger
> writes an unsupported configuration, the register will read back
> a value
> that is supported (which may simply be a disabled trigger). This
> means
> that a debugger must always read back values it writes to tdata
> registers, unless it already knows what is supported.
>
> This fix correctly ensures that the WARL behaviour of tdata CSRs.
>
> Fixes: a42bd001 ("target/riscv: debug: Determine the trigger type
> from
> tdata1.type")
> Signed-off-by: Abhigyan Kumar <314abh@gmail.com>
Thanks!
Applied to riscv-to-apply.next
Alistair
> ---
> target/riscv/tcg/debug.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/target/riscv/tcg/debug.c b/target/riscv/tcg/debug.c
> index 3c0fe7010..ae493235d 100644
> --- a/target/riscv/tcg/debug.c
> +++ b/target/riscv/tcg/debug.c
> @@ -913,7 +913,8 @@ void tdata_csr_write(CPURISCVState *env, int
> tdata_index, target_ulong val)
> trigger_type);
> break;
> default:
> - g_assert_not_reached();
> + qemu_log_mask(LOG_GUEST_ERROR, "trigger type: %d is
> unassigned\n",
> + trigger_type);
> }
> }
>
On Thu, 2026-07-30 at 04:30 +0530, Abhigyan Kumar wrote:
> tdata_csr_write is approachable by guest programs. In case of
> unassigned
> values written to a tdata CSR in debug mode, the switch-case falls
> through straight to default causing an immediate abort. The risc-v
> spec
> says:
>
> All tdata registers follow write-any-read-legal semantics. If a
> debugger
> writes an unsupported configuration, the register will read back
> a value
> that is supported (which may simply be a disabled trigger). This
> means
> that a debugger must always read back values it writes to tdata
> registers, unless it already knows what is supported.
>
> This fix correctly ensures that the WARL behaviour of tdata CSRs.
>
> Fixes: a42bd001 ("target/riscv: debug: Determine the trigger type
> from
> tdata1.type")
> Signed-off-by: Abhigyan Kumar <314abh@gmail.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Alistair
> ---
> target/riscv/tcg/debug.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/target/riscv/tcg/debug.c b/target/riscv/tcg/debug.c
> index 3c0fe7010..ae493235d 100644
> --- a/target/riscv/tcg/debug.c
> +++ b/target/riscv/tcg/debug.c
> @@ -913,7 +913,8 @@ void tdata_csr_write(CPURISCVState *env, int
> tdata_index, target_ulong val)
> trigger_type);
> break;
> default:
> - g_assert_not_reached();
> + qemu_log_mask(LOG_GUEST_ERROR, "trigger type: %d is
> unassigned\n",
> + trigger_type);
> }
> }
>
On 7/30/26 4:30 AM, Abhigyan Kumar wrote:
> tdata_csr_write is approachable by guest programs. In case of unassigned
> values written to a tdata CSR in debug mode, the switch-case falls
> through straight to default causing an immediate abort. The risc-v spec
> says:
>
> All tdata registers follow write-any-read-legal semantics. If a debugger
> writes an unsupported configuration, the register will read back a value
> that is supported (which may simply be a disabled trigger). This means
> that a debugger must always read back values it writes to tdata
> registers, unless it already knows what is supported.
>
> This fix correctly ensures that the WARL behaviour of tdata CSRs.
>
> Fixes: a42bd001 ("target/riscv: debug: Determine the trigger type from
> tdata1.type")
> Signed-off-by: Abhigyan Kumar <314abh@gmail.com>
> ---
> target/riscv/tcg/debug.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/target/riscv/tcg/debug.c b/target/riscv/tcg/debug.c
> index 3c0fe7010..ae493235d 100644
> --- a/target/riscv/tcg/debug.c
> +++ b/target/riscv/tcg/debug.c
> @@ -913,7 +913,8 @@ void tdata_csr_write(CPURISCVState *env, int tdata_index, target_ulong val)
> trigger_type);
> break;
> default:
> - g_assert_not_reached();
> + qemu_log_mask(LOG_GUEST_ERROR, "trigger type: %d is unassigned\n",
> + trigger_type);
> }
> }
>
Greetings. It has been over two weeks since I submitted this patch. It's
my humble request to know the status of the review/acceptance for my
patch. Please inform me about any required amends.
Thank you for your patience and attention.
© 2016 - 2026 Red Hat, Inc.