target/riscv/cpu_bits.h | 10 +++++----- tests/qtest/riscv-csr-test.c | 26 ++++++++++++++++++++++++++ 2 files changed, 31 insertions(+), 5 deletions(-)
The seed CSR value on RV64 was sign extended while converting to target_ulong. The first patch makes SEED_OPST_* unsigned. The second patch adds qtest to check that upper 32 bits are zero. Tests ran: - riscv-csr-test - make check: 324 passed, 11 skipped - RISC-V Zkr-00 architectural test Ivan Efremov (2): target/riscv: Fix seed CSR sign extension tests/qtest: Add seed CSR zero extension test target/riscv/cpu_bits.h | 10 +++++----- tests/qtest/riscv-csr-test.c | 26 ++++++++++++++++++++++++++ 2 files changed, 31 insertions(+), 5 deletions(-) -- 2.43.0
On 8/2/26 14:31, Ivan Efremov wrote: > The seed CSR value on RV64 was sign extended while converting to target_ulong. > > The first patch makes SEED_OPST_* unsigned. > The second patch adds qtest to check that upper 32 bits are zero. > > Tests ran: > - riscv-csr-test > - make check: 324 passed, 11 skipped > - RISC-V Zkr-00 architectural test > > Ivan Efremov (2): > target/riscv: Fix seed CSR sign extension > tests/qtest: Add seed CSR zero extension test I'm picking this patch set for the currently active qemu stable series (10.0 LTS, 11.0, 11.1). However, it does not work on 11.0.x already (it works ok on 11.1.x), the test fails: TAP version 14 # random seed: R02Sac6635c76a7dc335fadd70845da72f99 1..2 # Start of riscv64 tests # Start of cpu tests # starting QEMU: exec ./qemu-system-riscv64 -qtest unix:/tmp/qtest-182934.sock -qtest-log /dev/null -chardev socket,path=/tmp/qtest-182934.qmp,id=char0 -mon chardev=char0,mode=control -display none -audio none -run-with exit-with-parent=on -machine virt -cpu veyron-v1 -accel qtest ok 1 /riscv64/cpu/csr # Start of csr tests # starting QEMU: exec ./qemu-system-riscv64 -qtest unix:/tmp/qtest-182934.sock -qtest-log /dev/null -chardev socket,path=/tmp/qtest-182934.qmp,id=char0 -mon chardev=char0,mode=control -display none -audio none -run-with exit-with-parent=on -machine virt -cpu tt-ascalon -accel qtest ** ERROR:../../build/qemu/11.0/hw/riscv/riscv_hart.c:78:csr_call: assertion failed: (ret == RISCV_EXCP_NONE) Bail out! ERROR:../../build/qemu/11.0/hw/riscv/riscv_hart.c:78:csr_call: assertion failed: (ret == RISCV_EXCP_NONE) Broken pipe ../../build/qemu/11.0/tests/qtest/libqtest.c:210: kill_qemu() detected QEMU death from signal 6 (Aborted) Aborted Should I pick something else for 11.0 and 10.0 (on 10.0 it fails the same way), so the test succeeds, or should I drop this patch set from 11.1.x? Thanks, /mjt
On 2026-08-25 10:11 AM, Michael Tokarev wrote: > On 8/2/26 14:31, Ivan Efremov wrote: >> The seed CSR value on RV64 was sign extended while converting to >> target_ulong. >> >> The first patch makes SEED_OPST_* unsigned. >> The second patch adds qtest to check that upper 32 bits are zero. >> >> Tests ran: >> - riscv-csr-test >> - make check: 324 passed, 11 skipped >> - RISC-V Zkr-00 architectural test >> >> Ivan Efremov (2): >> target/riscv: Fix seed CSR sign extension >> tests/qtest: Add seed CSR zero extension test > > I'm picking this patch set for the currently active qemu stable > series (10.0 LTS, 11.0, 11.1). However, it does not work on > 11.0.x already (it works ok on 11.1.x), the test fails: > > TAP version 14 > # random seed: R02Sac6635c76a7dc335fadd70845da72f99 > 1..2 > # Start of riscv64 tests > # Start of cpu tests > # starting QEMU: exec ./qemu-system-riscv64 -qtest > unix:/tmp/qtest-182934.sock -qtest-log /dev/null -chardev > socket,path=/tmp/qtest-182934.qmp,id=char0 -mon > chardev=char0,mode=control -display none -audio none -run-with > exit-with-parent=on -machine virt -cpu veyron-v1 -accel qtest > ok 1 /riscv64/cpu/csr > # Start of csr tests > # starting QEMU: exec ./qemu-system-riscv64 -qtest > unix:/tmp/qtest-182934.sock -qtest-log /dev/null -chardev > socket,path=/tmp/qtest-182934.qmp,id=char0 -mon > chardev=char0,mode=control -display none -audio none -run-with > exit-with-parent=on -machine virt -cpu tt-ascalon -accel qtest > ** > ERROR:../../build/qemu/11.0/hw/riscv/riscv_hart.c:78:csr_call: > assertion failed: (ret == RISCV_EXCP_NONE) > Bail out! > ERROR:../../build/qemu/11.0/hw/riscv/riscv_hart.c:78:csr_call: > assertion failed: (ret == RISCV_EXCP_NONE) > Broken pipe > ../../build/qemu/11.0/tests/qtest/libqtest.c:210: kill_qemu() detected > QEMU death from signal 6 (Aborted) > Aborted > > Should I pick something else for 11.0 and 10.0 (on 10.0 it fails the > same way), > so the test succeeds, or should I drop this patch set from 11.1.x? > > Thanks, > > /mjt Thank you for testing. From my runs it seems that 10.0, 11.0 lack commit 569aa628 (target/riscv: tt-ascalon: Enable Zkr extension), which enables Zkr for tt-ascalon, so reading the seed triggers an assertion in csr_call. Apologies if I`m missing something here. I`m not sure which is better for stable: backporting 569aa628, or skipping the test patch. Best regards, Ivan Efremov
On Thu, 27 Aug 2026 at 07:57, <nendensu@ispras.ru> wrote: > > I'm picking this patch set for the currently active qemu stable > > series (10.0 LTS, 11.0, 11.1). However, it does not work on > > 11.0.x already (it works ok on 11.1.x), the test fails: > > Should I pick something else for 11.0 and 10.0 (on 10.0 it fails the > > same way), > > so the test succeeds, or should I drop this patch set from 11.1.x? > > > > Thanks, > > > > /mjt > Thank you for testing. From my runs it seems that 10.0, 11.0 lack commit > 569aa628 (target/riscv: tt-ascalon: Enable Zkr extension), which enables > Zkr for tt-ascalon, so reading the seed triggers an assertion in > csr_call. Apologies if I`m missing something here. I`m not sure which is > better for stable: backporting 569aa628, or skipping the test patch. Backporting 569aa628 seems reasonable to me. Cheers, Joel
On 8/27/26 08:18, Joel Stanley wrote:
> On Thu, 27 Aug 2026 at 07:57, <nendensu@ispras.ru> wrote:
>>> I'm picking this patch set for the currently active qemu stable
>>> series (10.0 LTS, 11.0, 11.1). However, it does not work on
>>> 11.0.x already (it works ok on 11.1.x), the test fails:
>
>>> Should I pick something else for 11.0 and 10.0 (on 10.0 it fails the
>>> same way),
>>> so the test succeeds, or should I drop this patch set from 11.1.x?
>> Thank you for testing. From my runs it seems that 10.0, 11.0 lack commit
>> 569aa628 (target/riscv: tt-ascalon: Enable Zkr extension), which enables
>> Zkr for tt-ascalon, so reading the seed triggers an assertion in
>> csr_call. Apologies if I`m missing something here. I`m not sure which is
>> better for stable: backporting 569aa628, or skipping the test patch.
Aha. This is why I'm asking - I don't know much about riscv internals :)
Ivan, there's nothing to apologize about, you did nothing wrong in this
context, - it is just me who does not have knowledge about all these riscv
details, what does it all mean, and which parts are important or not.
> Backporting 569aa628 seems reasonable to me.
I agree it's best to pick up 569aa628 too, this is my initial thought when
I was reading reply from Ivan.
However it has another issue: this commit works fine on 11.0.x, but 10.0.x
pre-dates RISCVCPUDef conversion.
As far as I can see, 569aa628 is about TYPE_RISCV_CPU_TT_ASCALON, and hence
it is 09ef7d97454 "target/riscv: convert TT Ascalon to RISCVCPUDef", so in
10.0.x it becomes:
diff --git a/target/riscv/cpu.c b/target/riscv/cpu.c
index bf4855ec02d..5e37cc3645d 100644
--- a/target/riscv/cpu.c
+++ b/target/riscv/cpu.c
@@ -646,6 +646,7 @@ static void rv64_tt_ascalon_cpu_init(Object *obj)
cpu->cfg.ext_zba = true;
cpu->cfg.ext_zbb = true;
cpu->cfg.ext_zbs = true;
+ cpu->cfg.ext_zkr = true;
cpu->cfg.ext_zkt = true;
cpu->cfg.ext_zvbb = true;
cpu->cfg.ext_zvbc = true;
(the RISCVCPUDef conversion made this stuff a bit more difficult
to see in a diff, since now the diff does not show which cpu type
the change belongs to).
With that, it all should work, and I'm picking it up for the
next stable series.
But overall, it looks like it all is a rather niche thing, and
might not really belong to stable series at all (*). Since we
already spent quite some time on this and resolved all issues,
let's pick it up anyway :)
(*) I mean, all these small fixes together, which should be
either picked up or not, but all together, - 569aa628, this
patch I'm replying to, and the test for it.
Thanks,
/mjt
On Thu, 2026-08-27 at 08:49 +0300, Michael Tokarev wrote: > On 8/27/26 08:18, Joel Stanley wrote: > > On Thu, 27 Aug 2026 at 07:57, <nendensu@ispras.ru> wrote: > > > > I'm picking this patch set for the currently active qemu stable > > > > series (10.0 LTS, 11.0, 11.1). However, it does not work on > > > > 11.0.x already (it works ok on 11.1.x), the test fails: > > > > > > Should I pick something else for 11.0 and 10.0 (on 10.0 it > > > > fails the > > > > same way), > > > > so the test succeeds, or should I drop this patch set from > > > > 11.1.x? > > > > Thank you for testing. From my runs it seems that 10.0, 11.0 lack > > > commit > > > 569aa628 (target/riscv: tt-ascalon: Enable Zkr extension), which > > > enables > > > Zkr for tt-ascalon, so reading the seed triggers an assertion in > > > csr_call. Apologies if I`m missing something here. I`m not sure > > > which is > > > better for stable: backporting 569aa628, or skipping the test > > > patch. > > Aha. This is why I'm asking - I don't know much about riscv > internals :) > > Ivan, there's nothing to apologize about, you did nothing wrong in > this > context, - it is just me who does not have knowledge about all these > riscv > details, what does it all mean, and which parts are important or not. > > > Backporting 569aa628 seems reasonable to me. > > I agree it's best to pick up 569aa628 too, this is my initial thought > when > I was reading reply from Ivan. > > However it has another issue: this commit works fine on 11.0.x, but > 10.0.x > pre-dates RISCVCPUDef conversion. > > As far as I can see, 569aa628 is about TYPE_RISCV_CPU_TT_ASCALON, and > hence > it is 09ef7d97454 "target/riscv: convert TT Ascalon to RISCVCPUDef", > so in > 10.0.x it becomes: > > diff --git a/target/riscv/cpu.c b/target/riscv/cpu.c > index bf4855ec02d..5e37cc3645d 100644 > --- a/target/riscv/cpu.c > +++ b/target/riscv/cpu.c > @@ -646,6 +646,7 @@ static void rv64_tt_ascalon_cpu_init(Object *obj) > cpu->cfg.ext_zba = true; > cpu->cfg.ext_zbb = true; > cpu->cfg.ext_zbs = true; > + cpu->cfg.ext_zkr = true; > cpu->cfg.ext_zkt = true; > cpu->cfg.ext_zvbb = true; > cpu->cfg.ext_zvbc = true; That looks correct > > (the RISCVCPUDef conversion made this stuff a bit more difficult > to see in a diff, since now the diff does not show which cpu type > the change belongs to). > > With that, it all should work, and I'm picking it up for the > next stable series. Thank you! Alistair > > But overall, it looks like it all is a rather niche thing, and > might not really belong to stable series at all (*). Since we > already spent quite some time on this and resolved all issues, > let's pick it up anyway :) > > (*) I mean, all these small fixes together, which should be > either picked up or not, but all together, - 569aa628, this > patch I'm replying to, and the test for it. > > Thanks, > > /mjt
On Sun, 2026-08-02 at 14:31 +0300, Ivan Efremov wrote: > The seed CSR value on RV64 was sign extended while converting to > target_ulong. > > The first patch makes SEED_OPST_* unsigned. > The second patch adds qtest to check that upper 32 bits are zero. > > Tests ran: > - riscv-csr-test > - make check: 324 passed, 11 skipped > - RISC-V Zkr-00 architectural test Thanks! Applied to riscv-to-apply.next Alistair > > Ivan Efremov (2): > target/riscv: Fix seed CSR sign extension > tests/qtest: Add seed CSR zero extension test > > target/riscv/cpu_bits.h | 10 +++++----- > tests/qtest/riscv-csr-test.c | 26 ++++++++++++++++++++++++++ > 2 files changed, 31 insertions(+), 5 deletions(-)
On Sun, 2026-08-02 at 14:31 +0300, Ivan Efremov wrote: > The seed CSR value on RV64 was sign extended while converting to > target_ulong. > > The first patch makes SEED_OPST_* unsigned. > The second patch adds qtest to check that upper 32 bits are zero. > > Tests ran: > - riscv-csr-test > - make check: 324 passed, 11 skipped > - RISC-V Zkr-00 architectural test Reviewed-by: Alistair Francis <alistair.francis@wdc.com> Alistair > > Ivan Efremov (2): > target/riscv: Fix seed CSR sign extension > tests/qtest: Add seed CSR zero extension test > > target/riscv/cpu_bits.h | 10 +++++----- > tests/qtest/riscv-csr-test.c | 26 ++++++++++++++++++++++++++ > 2 files changed, 31 insertions(+), 5 deletions(-)
© 2016 - 2026 Red Hat, Inc.