From nobody Sat Sep 26 20:02:28 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788601169859439.7263869130078; Sat, 5 Sep 2026 02:39:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2mqd-0004mz-MQ; Sat, 05 Sep 2026 05:38:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2mqb-0004mY-Aa; Sat, 05 Sep 2026 05:38:05 -0400 Received: from smtp81.cstnet.cn ([159.226.251.81] helo=cstnet.cn) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1x2mqY-0002d3-EO; Sat, 05 Sep 2026 05:38:04 -0400 Received: from DESKTOP-7FLBREN (unknown [124.16.137.194]) by APP-03 (Coremail) with SMTP id rQCowABHUT_u4ptqIsvvBg--.16071S3; Sat, 05 Sep 2026 17:37:52 +0800 (CST) From: wangyang To: qemu-devel@nongnu.org Cc: wangyang , Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , qemu-riscv@nongnu.org Subject: [PATCH 1/5] target/riscv: enforce XTheadCmo U-mode privilege checks Date: Sat, 5 Sep 2026 17:37:45 +0800 Message-ID: <20260905093749.491-2-wangyang25@otcaix.iscas.ac.cn> X-Mailer: git-send-email 2.55.0.windows.2 In-Reply-To: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> References: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: rQCowABHUT_u4ptqIsvvBg--.16071S3 X-Coremail-Antispam: 1UD129KBjvJXoWxJr47XFyUurWftFyfGrW3Jrb_yoW8Cw18pF WDKayYkrZ5JF15A3Zxur47Za97JFZ8Jw47X3W3Z398Aa15CrW7W3Z7K39Fgw48Cr40gr1q kF1qyr15Zr1jyaUanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUmm14x267AKxVW5JVWrJwAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2048vs2IY020E87I2jVAFwI0_Jr4l82xGYIkIc2 x26xkF7I0E14v26r1I6r4UM28lY4IEw2IIxxk0rwA2F7IY1VAKz4vEj48ve4kI8wA2z4x0 Y4vE2Ix0cI8IcVAFwI0_Jr0_JF4l84ACjcxK6xIIjxv20xvEc7CjxVAFwI0_Gr0_Cr1l84 ACjcxK6I8E87Iv67AKxVWUJVW8JwA2z4x0Y4vEx4A2jsIEc7CjxVAFwI0_Gr0_Gr1UM2vY z4IE04k24VAvwVAKI4IrM2AIxVAIcxkEcVAq07x20xvEncxIr21l5I8CrVACY4xI64kE6c 02F40Ex7xfMcIj6xIIjxv20xvE14v26r126r1DMcIj6I8E87Iv67AKxVWUJVW8JwAm72CE 4IkC6x0Yz7v_Jr0_Gr1lF7xvr2IYc2Ij64vIr41lF7I21c0EjII2zVCS5cI20VAGYxC7Mx kF7I0En4kS14v26r1q6r43MxkIecxEwVAFwVW8uwCF04k20xvY0x0EwIxGrwCFx2IqxVCF s4IE7xkEbVWUJVW8JwC20s026c02F40E14v26r1j6r18MI8I3I0E7480Y4vE14v26r106r 1rMI8E67AF67kF1VAFwI0_Jw0_GFylIxkGc2Ij64vIr41lIxAIcVC0I7IYx2IY67AKxVWU JVWUCwCI42IY6xIIjxv20xvEc7CjxVAFwI0_Gr0_Cr1lIxAIcVCF04k26cxKx2IYs7xG6r 1j6r1xMIIF0xvEx4A2jsIE14v26r1j6r4UMIIF0xvEx4A2jsIEc7CjxVAFwI0_Gr0_Gr1U YxBIdaVFxhVjvjDU0xZFpf9x0JU4mhwUUUUU= X-Originating-IP: [124.16.137.194] X-CM-SenderInfo: 5zdqw5xdqjjk46rwut1l0ox2xfdvhtffof0/ Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=159.226.251.81; envelope-from=wangyang25@otcaix.iscas.ac.cn; helo=cstnet.cn X-Spam_score_int: -41 X-Spam_score: -4.2 X-Spam_bar: ---- X-Spam_report: (-4.2 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1788601176111154100 Content-Type: text/plain; charset="utf-8" The XTheadCmo specification restricts th.dcache.cva and th.dcache.iva to privilege modes above U, while th.dcache.civa remains available in U-mode. Both restricted instructions currently use the empty REQUIRE_PRIV_MSU macro, so they retire in U-mode. Use REQUIRE_PRIV_MS for the two restricted instructions. Tested: RV32/RV64 Linux-user witness matrix with xtheadcmo enabled and disabled. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4412 Signed-off-by: wangyang Reviewed-by: Daniel Henrique Barboza --- target/riscv/tcg/insn_trans/trans_xthead.c.inc | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/target/riscv/tcg/insn_trans/trans_xthead.c.inc b/target/riscv/= tcg/insn_trans/trans_xthead.c.inc index f4e3051000..681f70e5bc 100644 --- a/target/riscv/tcg/insn_trans/trans_xthead.c.inc +++ b/target/riscv/tcg/insn_trans/trans_xthead.c.inc @@ -289,9 +289,9 @@ NOP_PRIVCHECK(th_dcache_iall, REQUIRE_XTHEADCMO, REQUIR= E_PRIV_MS) NOP_PRIVCHECK(th_dcache_cpa, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_cipa, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_ipa, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) -NOP_PRIVCHECK(th_dcache_cva, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MSU) +NOP_PRIVCHECK(th_dcache_cva, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_civa, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MSU) -NOP_PRIVCHECK(th_dcache_iva, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MSU) +NOP_PRIVCHECK(th_dcache_iva, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_csw, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_cisw, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_isw, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) --=20 2.55.0.windows.2 From nobody Sat Sep 26 20:02:28 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788601184172549.2390731492832; Sat, 5 Sep 2026 02:39:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2mqg-0004qn-KK; Sat, 05 Sep 2026 05:38:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2mqc-0004my-Iq; Sat, 05 Sep 2026 05:38:06 -0400 Received: from smtp81.cstnet.cn ([159.226.251.81] helo=cstnet.cn) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1x2mqY-0002d4-MO; Sat, 05 Sep 2026 05:38:06 -0400 Received: from DESKTOP-7FLBREN (unknown [124.16.137.194]) by APP-03 (Coremail) with SMTP id rQCowABHUT_u4ptqIsvvBg--.16071S4; Sat, 05 Sep 2026 17:37:52 +0800 (CST) From: wangyang To: qemu-devel@nongnu.org Cc: wangyang , Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , qemu-riscv@nongnu.org Subject: [PATCH 2/5] target/riscv: mask RV32 XTheadBb th.srri shift amount Date: Sat, 5 Sep 2026 17:37:46 +0800 Message-ID: <20260905093749.491-3-wangyang25@otcaix.iscas.ac.cn> X-Mailer: git-send-email 2.55.0.windows.2 In-Reply-To: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> References: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: rQCowABHUT_u4ptqIsvvBg--.16071S4 X-Coremail-Antispam: 1UD129KBjvdXoW7Xw4fGrW8Xr4kur4Uur15Jwb_yoWkCrX_KF 18GFn7u395Xr47Ka9Fkr18CF1UCry5KFn0y39xtay3u3sxWF15uFn7WFn5A3WUCwn5Grs3 AwsrXa429r1Y9jkaLaAFLSUrUUUUjb8apTn2vfkv8UJUUUU8Yxn0WfASr-VFAUDa7-sFnT 9fnUUIcSsGvfJTRUUUb9kFF20E14v26rWj6s0DM7CY07I20VC2zVCF04k26cxKx2IYs7xG 6rWj6s0DM7CIcVAFz4kK6r1j6r18M28IrcIa0xkI8VA2jI8067AKxVWUXwA2048vs2IY02 0Ec7CjxVAFwI0_Gr0_Xr1l8cAvFVAK0II2c7xJM28CjxkF64kEwVA0rcxSw2x7M28EF7xv wVC0I7IYx2IY67AKxVWUJVWUCwA2z4x0Y4vE2Ix0cI8IcVCY1x0267AKxVW8JVWxJwA2z4 x0Y4vEx4A2jsIE14v26r1j6r4UM28EF7xvwVC2z280aVCY1x0267AKxVW8JVW8Jr1lnxkE FVAIw20F6cxK64vIFxWle2I262IYc4CY6c8Ij28IcVAaY2xG8wAqx4xG64xvF2IEw4CE5I 8CrVC2j2WlYx0E2Ix0cI8IcVAFwI0_JF0_Jw1lYx0Ex4A2jsIE14v26r1j6r4UMcvjeVCF s4IE7xkEbVWUJVW8JwACjcxG0xvY0x0EwIxGrwACjI8F5VA0II8E6IAqYI8I648v4I1lc7 CjxVAaw2AFwI0_Jw0_GFylc2xSY4AK67AK6r4fMxAIw28IcxkI7VAKI48JMxC20s026xCa FVCjc4AY6r1j6r4UMI8I3I0E5I8CrVAFwI0_Jr0_Jr4lx2IqxVCjr7xvwVAFwI0_JrI_Jr Wlx4CE17CEb7AF67AKxVWUtVW8ZwCIc40Y0x0EwIxGrwCI42IY6xIIjxv20xvE14v26r1j 6r1xMIIF0xvE2Ix0cI8IcVCY1x0267AKxVW8JVWxJwCI42IY6xAIw20EY4v20xvaj40_Jr 0_JF4lIxAIcVC2z280aVAFwI0_Jr0_Gr1lIxAIcVC2z280aVCY1x0267AKxVW8JVW8JrUv cSsGvfC2KfnxnUUI43ZEXa7VUU22NtUUUUU== X-Originating-IP: [124.16.137.194] X-CM-SenderInfo: 5zdqw5xdqjjk46rwut1l0ox2xfdvhtffof0/ Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=159.226.251.81; envelope-from=wangyang25@otcaix.iscas.ac.cn; helo=cstnet.cn X-Spam_score_int: -41 X-Spam_score: -4.2 X-Spam_bar: ---- X-Spam_report: (-4.2 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1788601188208154100 Content-Type: text/plain; charset="utf-8" The XTheadBb th.srri instruction uses the low log2(XLEN) bits of imm6. The generic shift helper rejects values greater than or equal to XLEN, which incorrectly rejects imm6 values 32 through 63 on RV32. Normalize the operand before calling the helper. Tested: RV32 imm6 0, 31, 32, and 63 witnesses with XTheadBb enabled and disabled. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4413 Signed-off-by: wangyang Reviewed-by: Daniel Henrique Barboza --- target/riscv/tcg/insn_trans/trans_xthead.c.inc | 1 + 1 file changed, 1 insertion(+) diff --git a/target/riscv/tcg/insn_trans/trans_xthead.c.inc b/target/riscv/= tcg/insn_trans/trans_xthead.c.inc index 681f70e5bc..34226b1be5 100644 --- a/target/riscv/tcg/insn_trans/trans_xthead.c.inc +++ b/target/riscv/tcg/insn_trans/trans_xthead.c.inc @@ -141,6 +141,7 @@ GEN_TRANS_TH_ADDSL(3) static bool trans_th_srri(DisasContext *ctx, arg_th_srri * a) { REQUIRE_XTHEADBB(ctx); + a->shamt &=3D get_olen(ctx) - 1; return gen_shift_imm_fn_per_ol(ctx, a, EXT_NONE, tcg_gen_rotri_tl, gen_roriw, NULL); } --=20 2.55.0.windows.2 From nobody Sat Sep 26 20:02:28 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788601172641622.1152178373386; Sat, 5 Sep 2026 02:39:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2mqd-0004mx-AW; Sat, 05 Sep 2026 05:38:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2mqb-0004mZ-Eo; Sat, 05 Sep 2026 05:38:05 -0400 Received: from smtp81.cstnet.cn ([159.226.251.81] helo=cstnet.cn) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1x2mqY-0002d5-FL; Sat, 05 Sep 2026 05:38:05 -0400 Received: from DESKTOP-7FLBREN (unknown [124.16.137.194]) by APP-03 (Coremail) with SMTP id rQCowABHUT_u4ptqIsvvBg--.16071S5; Sat, 05 Sep 2026 17:37:53 +0800 (CST) From: wangyang To: qemu-devel@nongnu.org Cc: wangyang , Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , qemu-riscv@nongnu.org Subject: [PATCH 3/5] target/riscv: require read permission for HLVX accesses Date: Sat, 5 Sep 2026 17:37:47 +0800 Message-ID: <20260905093749.491-4-wangyang25@otcaix.iscas.ac.cn> X-Mailer: git-send-email 2.55.0.windows.2 In-Reply-To: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> References: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: rQCowABHUT_u4ptqIsvvBg--.16071S5 X-Coremail-Antispam: 1UD129KBjvJXoW3Jw4fCrWxZr13uw47Aw1xuFg_yoW7Cw43pr WrCrZIkw4kKFZrGayxtFyjyF15CF43GFWjg3Z7WwsY93Waq3yru3WkGa42gFs8GFWkWw1j ga1qyF1jk3WjqFDanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUmm14x267AKxVWrJVCq3wAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2048vs2IY020E87I2jVAFwI0_JrWl82xGYIkIc2 x26xkF7I0E14v26ryj6s0DM28lY4IEw2IIxxk0rwA2F7IY1VAKz4vEj48ve4kI8wA2z4x0 Y4vE2Ix0cI8IcVAFwI0_Jr0_JF4l84ACjcxK6xIIjxv20xvEc7CjxVAFwI0_Gr0_Cr1l84 ACjcxK6I8E87Iv67AKxVWUJVW8JwA2z4x0Y4vEx4A2jsIEc7CjxVAFwI0_Gr0_Gr1UM2vY z4IE04k24VAvwVAKI4IrM2AIxVAIcxkEcVAq07x20xvEncxIr21l5I8CrVACY4xI64kE6c 02F40Ex7xfMcIj6xIIjxv20xvE14v26r126r1DMcIj6I8E87Iv67AKxVWUJVW8JwAm72CE 4IkC6x0Yz7v_Jr0_Gr1lF7xvr2IYc2Ij64vIr41lF7I21c0EjII2zVCS5cI20VAGYxC7Mx kF7I0En4kS14v26r1q6r43MxkIecxEwVAFwVW8uwCF04k20xvY0x0EwIxGrwCFx2IqxVCF s4IE7xkEbVWUJVW8JwC20s026c02F40E14v26r1j6r18MI8I3I0E7480Y4vE14v26r106r 1rMI8E67AF67kF1VAFwI0_Jw0_GFylIxkGc2Ij64vIr41lIxAIcVC0I7IYx2IY67AKxVWU JVWUCwCI42IY6xIIjxv20xvEc7CjxVAFwI0_Gr0_Cr1lIxAIcVCF04k26cxKx2IYs7xG6r 1j6r1xMIIF0xvEx4A2jsIE14v26r1j6r4UMIIF0xvEx4A2jsIEc7CjxVAFwI0_Gr0_Gr1U YxBIdaVFxhVjvjDU0xZFpf9x0JUStCwUUUUU= X-Originating-IP: [124.16.137.194] X-CM-SenderInfo: 5zdqw5xdqjjk46rwut1l0ox2xfdvhtffof0/ Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=159.226.251.81; envelope-from=wangyang25@otcaix.iscas.ac.cn; helo=cstnet.cn X-Spam_score_int: -41 X-Spam_score: -4.2 X-Spam_bar: ---- X-Spam_report: (-4.2 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1788601177030158500 Content-Type: text/plain; charset="utf-8" HLVX address translation uses execute permission, but the final PMP check on the supervisor physical address must also require read permission. Carry the HLVX operation through the MMU index and include PMP_READ in the final check so execute-only pages fault. Tested: RV32 system-mode RWX, HLV, and HLVX.WU PMP witness matrix. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4414 Signed-off-by: wangyang --- target/riscv/internals.h | 6 ++++++ target/riscv/tcg/cpu_helper.c | 24 ++++++++++++++++-------- target/riscv/tcg/op_helper.c | 11 +++++------ 3 files changed, 27 insertions(+), 14 deletions(-) diff --git a/target/riscv/internals.h b/target/riscv/internals.h index 5d84e4de96..832c6406bc 100644 --- a/target/riscv/internals.h +++ b/target/riscv/internals.h @@ -42,6 +42,7 @@ #define MMUIdx_M 3 #define MMU_2STAGE_BIT (1 << 2) #define MMU_IDX_SS_WRITE (1 << 3) +#define MMU_IDX_HLVX (1 << 4) =20 static inline privilege_mode_t mmuidx_priv(int mmu_idx) { @@ -62,6 +63,11 @@ static inline bool mmuidx_2stage(int mmu_idx) return mmu_idx & MMU_2STAGE_BIT; } =20 +static inline bool mmuidx_hlvx(int mmu_idx) +{ + return mmu_idx & MMU_IDX_HLVX; +} + /* * Return the endianness for the current privilege * level, based on the MSTATUS MBE/SBE/UBE bits. diff --git a/target/riscv/tcg/cpu_helper.c b/target/riscv/tcg/cpu_helper.c index 07d9222652..ad41de9d06 100644 --- a/target/riscv/tcg/cpu_helper.c +++ b/target/riscv/tcg/cpu_helper.c @@ -905,6 +905,7 @@ void riscv_cpu_set_mode(CPURISCVState *env, privilege_m= ode_t newpriv, */ static int get_physical_address_pmp(CPURISCVState *env, int *prot, hwaddr = addr, int size, MMUAccessType access_type, + pmp_priv_t extra_privs, privilege_mode_t mode) { pmp_priv_t pmp_priv; @@ -915,7 +916,8 @@ static int get_physical_address_pmp(CPURISCVState *env,= int *prot, hwaddr addr, return TRANSLATE_SUCCESS; } =20 - pmp_has_privs =3D pmp_hart_has_privs(env, addr, size, 1 << access_type, + pmp_has_privs =3D pmp_hart_has_privs(env, addr, size, + (1 << access_type) | extra_privs, &pmp_priv, mode); if (!pmp_has_privs) { *prot =3D 0; @@ -1177,7 +1179,7 @@ static int get_physical_address(CPURISCVState *env, h= waddr *physical, int pmp_prot; int pmp_ret =3D get_physical_address_pmp(env, &pmp_prot, pte_addr, sxlen_bytes, - MMU_DATA_LOAD, PRV_S); + MMU_DATA_LOAD, 0, PRV_S); if (pmp_ret !=3D TRANSLATE_SUCCESS) { return TRANSLATE_PMP_FAIL; } @@ -1425,7 +1427,8 @@ static int get_physical_address(CPURISCVState *env, h= waddr *physical, } =20 pmp_ret =3D get_physical_address_pmp(env, &pmp_prot, pte_addr, - sxlen_bytes, MMU_DATA_STORE, PR= V_S); + sxlen_bytes, MMU_DATA_STORE, 0, + PRV_S); if (pmp_ret !=3D TRANSLATE_SUCCESS) { return TRANSLATE_PMP_FAIL; } @@ -1711,7 +1714,9 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address, = int size, =20 if (ret =3D=3D TRANSLATE_SUCCESS) { ret =3D get_physical_address_pmp(env, &prot_pmp, pa, - size, access_type, mode); + size, access_type, + mmuidx_hlvx(mmu_idx) ? + PMP_READ : 0, mode); tlb_size =3D pmp_get_tlb_size(env, pa); =20 qemu_log_mask(CPU_LOG_MMU, @@ -1746,7 +1751,9 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address, = int size, =20 if (ret =3D=3D TRANSLATE_SUCCESS) { ret =3D get_physical_address_pmp(env, &prot_pmp, pa, - size, access_type, mode); + size, access_type, + mmuidx_hlvx(mmu_idx) ? + PMP_READ : 0, mode); tlb_size =3D pmp_get_tlb_size(env, pa); =20 qemu_log_mask(CPU_LOG_MMU, @@ -1786,9 +1793,10 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address,= int size, cpu_check_watchpoint(cs, address, size, MEMTXATTRS_UNSPECIFIED, wp_access, retaddr); =20 - raise_mmu_exception(env, address, access_type, pmp_pma_violation, - first_stage_error, two_stage_lookup, - two_stage_indirect_error); + raise_mmu_exception(env, address, + mmuidx_hlvx(mmu_idx) ? MMU_DATA_LOAD : access_= type, + pmp_pma_violation, first_stage_error, + two_stage_lookup, two_stage_indirect_error); cpu_loop_exit_restore(cs, retaddr); } =20 diff --git a/target/riscv/tcg/op_helper.c b/target/riscv/tcg/op_helper.c index 3e94005d2b..060d97ee9c 100644 --- a/target/riscv/tcg/op_helper.c +++ b/target/riscv/tcg/op_helper.c @@ -650,7 +650,7 @@ static int check_access_hlsv(CPURISCVState *env, bool x= , uintptr_t ra) if (!x && mode =3D=3D PRV_S && get_field(env->vsstatus, MSTATUS_SUM)) { mode =3D MMUIdx_S_SUM; } - return mode | MMU_2STAGE_BIT; + return mode | MMU_2STAGE_BIT | (x ? MMU_IDX_HLVX : 0); } =20 target_ulong helper_hyp_hlv_bu(CPURISCVState *env, target_ulong addr) @@ -726,11 +726,10 @@ void helper_hyp_hsv_d(CPURISCVState *env, target_ulon= g addr, target_ulong val) } =20 /* - * TODO: These implementations are not quite correct. They perform the - * access using execute permission just fine, but the final PMP check - * is supposed to have read permission as well. Without replicating - * a fair fraction of cputlb.c, fixing this requires adding new mmu_idx - * which would imply that exact check in tlb_fill. + * HLVX accesses are translated with execute permission (first stage), + * but the final PMP check on the supervisor physical address must + * require read permission as well. The MMU_IDX_HLVX mmu_idx bit set + * by check_access_hlsv() makes riscv_cpu_tlb_fill() enforce this. */ target_ulong helper_hyp_hlvx_hu(CPURISCVState *env, target_ulong addr) { --=20 2.55.0.windows.2 From nobody Sat Sep 26 20:02:28 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788601172179319.6259818841902; Sat, 5 Sep 2026 02:39:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2mqe-0004pL-C3; Sat, 05 Sep 2026 05:38:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2mqc-0004n2-Lb; Sat, 05 Sep 2026 05:38:06 -0400 Received: from smtp81.cstnet.cn ([159.226.251.81] helo=cstnet.cn) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1x2mqY-0002d6-QQ; Sat, 05 Sep 2026 05:38:06 -0400 Received: from DESKTOP-7FLBREN (unknown [124.16.137.194]) by APP-03 (Coremail) with SMTP id rQCowABHUT_u4ptqIsvvBg--.16071S6; Sat, 05 Sep 2026 17:37:53 +0800 (CST) From: wangyang To: qemu-devel@nongnu.org Cc: wangyang , Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , qemu-riscv@nongnu.org Subject: [PATCH 4/5] target/riscv: prioritize Zicfilp checks for misaligned JALR Date: Sat, 5 Sep 2026 17:37:48 +0800 Message-ID: <20260905093749.491-5-wangyang25@otcaix.iscas.ac.cn> X-Mailer: git-send-email 2.55.0.windows.2 In-Reply-To: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> References: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: rQCowABHUT_u4ptqIsvvBg--.16071S6 X-Coremail-Antispam: 1UD129KBjvJXoW7tF4UWF17Zr1fWF4DJryDtrb_yoW8XF4fpF 40krWUKrW5tFZ5ZF4IqF4UtF43Xa1fWa10qws2q3Z5tF4Yyry3tF1qkryagF1UCF4kWr12 9FWqy3W5WFWUJ3JanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUmC14x267AKxVWrJVCq3wAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2048vs2IY020E87I2jVAFwI0_JF0E3s1l82xGYI kIc2x26xkF7I0E14v26ryj6s0DM28lY4IEw2IIxxk0rwA2F7IY1VAKz4vEj48ve4kI8wA2 z4x0Y4vE2Ix0cI8IcVAFwI0_Jr0_JF4l84ACjcxK6xIIjxv20xvEc7CjxVAFwI0_Gr0_Cr 1l84ACjcxK6I8E87Iv67AKxVWUJVW8JwA2z4x0Y4vEx4A2jsIEc7CjxVAFwI0_Gr0_Gr1U M2vYz4IE04k24VAvwVAKI4IrM2AIxVAIcxkEcVAq07x20xvEncxIr21l5I8CrVACY4xI64 kE6c02F40Ex7xfMcIj6xIIjxv20xvE14v26r126r1DMcIj6I8E87Iv67AKxVWUJVW8JwAm 72CE4IkC6x0Yz7v_Jr0_Gr1lF7xvr2IYc2Ij64vIr41lF7I21c0EjII2zVCS5cI20VAGYx C7MxkF7I0En4kS14v26r1q6r43MxkIecxEwVAFwVW8uwCF04k20xvY0x0EwIxGrwCFx2Iq xVCFs4IE7xkEbVWUJVW8JwC20s026c02F40E14v26r1j6r18MI8I3I0E7480Y4vE14v26r 106r1rMI8E67AF67kF1VAFwI0_Jw0_GFylIxkGc2Ij64vIr41lIxAIcVC0I7IYx2IY67AK xVWUJVWUCwCI42IY6xIIjxv20xvEc7CjxVAFwI0_Gr0_Cr1lIxAIcVCF04k26cxKx2IYs7 xG6r1j6r1xMIIF0xvEx4A2jsIE14v26r1j6r4UMIIF0xvEx4A2jsIEc7CjxVAFwI0_Gr0_ Gr1UYxBIdaVFxhVjvjDU0xZFpf9x0JUfcTQUUUUU= X-Originating-IP: [124.16.137.194] X-CM-SenderInfo: 5zdqw5xdqjjk46rwut1l0ox2xfdvhtffof0/ Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=159.226.251.81; envelope-from=wangyang25@otcaix.iscas.ac.cn; helo=cstnet.cn X-Spam_score_int: -41 X-Spam_score: -4.2 X-Spam_bar: ---- X-Spam_report: (-4.2 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1788601175946158500 Content-Type: text/plain; charset="utf-8" When Zicfilp tracking is active, a misaligned indirect JALR target also violates the landing-pad requirement. Generate the landing-pad software-check before the generic instruction-address-misaligned exception for tracked targets, while retaining the existing exception for untracked targets. Tested: RV64 M-mode and S-mode Zicfilp controls and misaligned targets with c=3Dtrue and c=3Dfalse. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4415 Signed-off-by: wangyang Reviewed-by: Daniel Henrique Barboza --- target/riscv/tcg/insn_trans/trans_rvi.c.inc | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/target/riscv/tcg/insn_trans/trans_rvi.c.inc b/target/riscv/tcg= /insn_trans/trans_rvi.c.inc index cc1b5dbbad..aa79a5ef3c 100644 --- a/target/riscv/tcg/insn_trans/trans_rvi.c.inc +++ b/target/riscv/tcg/insn_trans/trans_rvi.c.inc @@ -187,7 +187,14 @@ static bool trans_jalr(DisasContext *ctx, arg_jalr *a) =20 if (misaligned) { gen_set_label(misaligned); - gen_exception_inst_addr_mis(ctx, target_pc); + if (ctx->fcfi_enabled && + a->rs1 !=3D xRA && a->rs1 !=3D xT0 && a->rs1 !=3D xT2) { + tcg_gen_st8_i32(tcg_constant_i32(RISCV_EXCP_SW_CHECK_FCFI_TVAL= ), + tcg_env, offsetof(CPURISCVState, sw_check_code= )); + generate_exception(ctx, RISCV_EXCP_SW_CHECK); + } else { + gen_exception_inst_addr_mis(ctx, target_pc); + } } ctx->base.is_jmp =3D DISAS_NORETURN; =20 --=20 2.55.0.windows.2 From nobody Sat Sep 26 20:02:28 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788601168861638.216112659486; Sat, 5 Sep 2026 02:39:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2mqe-0004pK-3B; Sat, 05 Sep 2026 05:38:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2mqc-0004n0-Ky; Sat, 05 Sep 2026 05:38:06 -0400 Received: from smtp81.cstnet.cn ([159.226.251.81] helo=cstnet.cn) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1x2mqY-0002d8-Ni; Sat, 05 Sep 2026 05:38:06 -0400 Received: from DESKTOP-7FLBREN (unknown [124.16.137.194]) by APP-03 (Coremail) with SMTP id rQCowABHUT_u4ptqIsvvBg--.16071S7; Sat, 05 Sep 2026 17:37:53 +0800 (CST) From: wangyang To: qemu-devel@nongnu.org Cc: wangyang , Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , qemu-riscv@nongnu.org Subject: [PATCH 5/5] target/riscv: canonicalize reserved CBIE encoding Date: Sat, 5 Sep 2026 17:37:49 +0800 Message-ID: <20260905093749.491-6-wangyang25@otcaix.iscas.ac.cn> X-Mailer: git-send-email 2.55.0.windows.2 In-Reply-To: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> References: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: rQCowABHUT_u4ptqIsvvBg--.16071S7 X-Coremail-Antispam: 1UD129KBjvJXoW7CFy3Wr48uF1kXr15urW7Jwb_yoW8tF48pF 4UWF45KrWv934I9a93Jr1UWF1akrWrGay5Wwnruw4kXa13GFyftFnrG345Kr4UWFWxK3sF 9wsxGry5Cws5JFDanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUmE14x267AKxVWrJVCq3wAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2048vs2IY020E87I2jVAFwI0_JF0E3s1l82xGYI kIc2x26xkF7I0E14v26ryj6s0DM28lY4IEw2IIxxk0rwA2F7IY1VAKz4vEj48ve4kI8wA2 z4x0Y4vE2Ix0cI8IcVAFwI0_JFI_Gr1l84ACjcxK6xIIjxv20xvEc7CjxVAFwI0_Cr0_Gr 1UM28EF7xvwVC2z280aVAFwI0_Jr0_Gr1l84ACjcxK6I8E87Iv6xkF7I0E14v26r4j6r4U JwAac4AC62xK8xCEY4vEwIxC4wAS0I0E0xvYzxvE52x082IY62kv0487Mc02F40EFcxC0V AKzVAqx4xG6I80ewAv7VC0I7IYx2IY67AKxVWUAVWUtwAv7VC2z280aVAFwI0_Jr0_Gr1l Ox8S6xCaFVCjc4AY6r1j6r4UM4x0Y48IcxkI7VAKI48JM4x0x7Aq67IIx4CEVc8vx2IErc IFxwCY1x0262kKe7AKxVWUtVW8ZwCY02Avz4vE14v_GFWl42xK82IYc2Ij64vIr41l4I8I 3I0E4IkC6x0Yz7v_Jr0_Gr1lx2IqxVAqx4xG67AKxVWUJVWUGwC20s026x8GjcxK67AKxV WUGVWUWwC2zVAF1VAY17CE14v26r1q6r43MIIYrxkI7VAKI48JMIIF0xvE2Ix0cI8IcVAF wI0_JFI_Gr1lIxAIcVC0I7IYx2IY6xkF7I0E14v26F4j6r4UJwCI42IY6xAIw20EY4v20x vaj40_Jr0_JF4lIxAIcVC2z280aVAFwI0_Jr0_Gr1lIxAIcVC2z280aVCY1x0267AKxVW8 JVW8JrUvcSsGvfC2KfnxnUUI43ZEXa7VUjGYLPUUUUU== X-Originating-IP: [124.16.137.194] X-CM-SenderInfo: 5zdqw5xdqjjk46rwut1l0ox2xfdvhtffof0/ Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=159.226.251.81; envelope-from=wangyang25@otcaix.iscas.ac.cn; helo=cstnet.cn X-Spam_score_int: -41 X-Spam_score: -4.2 X-Spam_bar: ---- X-Spam_report: (-4.2 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1788601175985158500 Content-Type: text/plain; charset="utf-8" CBIE encoding 10 is reserved when Zicbom is implemented, while encoding 11 has defined behavior. Canonicalize only encoding 10 in the menvcfg, senvcfg, and henvcfg write paths so the reserved value is not retained and the defined encoding remains unchanged. Tested: RV64 menvcfg, senvcfg, and henvcfg CBIE 10 and CBIE 11 write/readback witnesses. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4416 Signed-off-by: wangyang --- target/riscv/tcg/csr.c | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c index bd4b6dc114..cf59f9ae54 100644 --- a/target/riscv/tcg/csr.c +++ b/target/riscv/tcg/csr.c @@ -3260,6 +3260,16 @@ static RISCVException write_menvcfg(CPURISCVState *e= nv, int csrno, stce_changed =3D true; } } + + /* + * CBIE is a WARL field: encoding 10 is reserved. A software write of + * this encoding must canonicalize to a supported value instead of bei= ng + * retained in the readback. + */ + if (cfg->ext_zicbom && get_field(val, MENVCFG_CBIE) =3D=3D 2) { + val &=3D ~MENVCFG_CBIE; + } + env->menvcfg =3D (env->menvcfg & ~mask) | (val & mask); =20 if (stce_changed) { @@ -3354,6 +3364,16 @@ static RISCVException write_senvcfg(CPURISCVState *e= nv, int csrno, mask |=3D SENVCFG_UKTE; } =20 + /* + * CBIE is a WARL field: encoding 10 is reserved. A software write of + * this encoding must canonicalize to a supported value instead of bei= ng + * retained in the readback. + */ + if (env_archcpu(env)->cfg.ext_zicbom && + get_field(val, SENVCFG_CBIE) =3D=3D 2) { + val &=3D ~SENVCFG_CBIE; + } + env->senvcfg =3D (env->senvcfg & ~mask) | (val & mask); return RISCV_EXCP_NONE; } @@ -3422,6 +3442,15 @@ static RISCVException write_henvcfg(CPURISCVState *e= nv, int csrno, } } =20 + /* + * CBIE is a WARL field: encoding 10 is reserved. A software write of + * this encoding must canonicalize to a supported value instead of bei= ng + * retained in the readback. + */ + if (cfg->ext_zicbom && get_field(val, HENVCFG_CBIE) =3D=3D 2) { + val &=3D ~HENVCFG_CBIE; + } + if (riscv_cpu_mxl(env) =3D=3D MXL_RV32) { /* * RV32 stores STCE/ADUE/PBMTE/DTE in henvcfgh, so a low-half henv= cfg --=20 2.55.0.windows.2