From nobody Sat Sep 26 20:01:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788833846664281.37763797077537; Mon, 7 Sep 2026 19:17:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x3lNZ-0008Mm-Dj; Mon, 07 Sep 2026 22:16:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3lNU-0008Ka-S4; Mon, 07 Sep 2026 22:16:04 -0400 Received: from smtp21.cstnet.cn ([159.226.251.21] helo=cstnet.cn) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1x3lNQ-00034W-NV; Mon, 07 Sep 2026 22:16:04 -0400 Received: from [192.168.144.1] (unknown [124.16.137.194]) by APP-01 (Coremail) with SMTP id qwCowACneu7Vb59qVCxsBw--.59943S3; Tue, 08 Sep 2026 10:15:50 +0800 (CST) From: wangyang To: qemu-devel@nongnu.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , qemu-riscv@nongnu.org Subject: [PATCH v2 1/5] target/riscv: enforce XTheadCmo U-mode privilege checks Date: Tue, 08 Sep 2026 10:15:50 +0800 Message-ID: <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-2> In-Reply-To: <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-1> References: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-1> X-Mailer: git-send-email 2.55.0.windows.2 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-CM-TRANSID: qwCowACneu7Vb59qVCxsBw--.59943S3 X-Coremail-Antispam: 1UD129KBjvJXoWxJr47XFyUurWftFyfGrW3Jrb_yoW8Cw18pF WDKayYkrZ5JF15A3Zxur47Za97JFZ8Jw47X3W3Z398Aa15CrW7W3Z7K39Fgw48Cr40gr1q kF1qyr15Zr1jyaUanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUmIb7Iv0xC_Kw4lb4IE77IF4wAFF20E14v26ryj6rWUM7CY07I2 0VC2zVCF04k26cxKx2IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28IrcIa0xkI8VA2jI 8067AKxVWUGwA2048vs2IY020Ec7CjxVAFwI0_JFI_Gr1l8cAvFVAK0II2c7xJM28CjxkF 64kEwVA0rcxSw2x7M28EF7xvwVC0I7IYx2IY67AKxVWUJVWUCwA2z4x0Y4vE2Ix0cI8IcV CY1x0267AKxVW8JVWxJwA2z4x0Y4vEx4A2jsIE14v26r1j6r4UM28EF7xvwVC2z280aVCY 1x0267AKxVW8JVW8Jr1lnxkEFVAIw20F6cxK64vIFxWle2I262IYc4CY6c8Ij28IcVAaY2 xG8wAqx4xG64xvF2IEw4CE5I8CrVC2j2WlYx0E2Ix0cI8IcVAFwI0_Jr0_Jr4lYx0Ex4A2 jsIE14v26r1j6r4UMcvjeVCFs4IE7xkEbVWUJVW8JwACjcxG0xvY0x0EwIxGrwCY1x0262 kKe7AKxVWUAVWUtwCY02Avz4vE14v_Gr1l42xK82IYc2Ij64vIr41l4I8I3I0E4IkC6x0Y z7v_Jr0_Gr1lx2IqxVAqx4xG67AKxVWUJVWUGwC20s026x8GjcxK67AKxVWUGVWUWwC2zV AF1VAY17CE14v26r1q6r43MIIYrxkI7VAKI48JMIIF0xvE2Ix0cI8IcVAFwI0_Jr0_JF4l IxAIcVC0I7IYx2IY6xkF7I0E14v26r4j6F4UMIIF0xvE42xK8VAvwI8IcIk0rVWUJVWUCw CI42IY6I8E87Iv67AKxVWUJVW8JwCI42IY6I8E87Iv6xkF7I0E14v26r4j6r4UJbIYCTnI WIevJa73UjIFyTuYvjxUy5ktUUUUU X-Originating-IP: [124.16.137.194] X-CM-SenderInfo: 5zdqw5xdqjjk46rwut1l0ox2xfdvhtffof0/ Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=159.226.251.21; envelope-from=wangyang25@otcaix.iscas.ac.cn; helo=cstnet.cn X-Spam_score_int: -41 X-Spam_score: -4.2 X-Spam_bar: ---- X-Spam_report: (-4.2 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1788833848579154100 The XTheadCmo specification restricts th.dcache.cva and th.dcache.iva to privilege modes above U, while th.dcache.civa remains available in U-mode. Both restricted instructions currently use the empty REQUIRE_PRIV_MSU macro, so they retire in U-mode. Use REQUIRE_PRIV_MS for the two restricted instructions. Tested: RV32/RV64 Linux-user witness matrix with xtheadcmo enabled and disabled. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4412 Signed-off-by: wangyang --- target/riscv/tcg/insn_trans/trans_xthead.c.inc | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/target/riscv/tcg/insn_trans/trans_xthead.c.inc b/target/riscv/= tcg/insn_trans/trans_xthead.c.inc index f4e3051000..681f70e5bc 100644 --- a/target/riscv/tcg/insn_trans/trans_xthead.c.inc +++ b/target/riscv/tcg/insn_trans/trans_xthead.c.inc @@ -289,9 +289,9 @@ NOP_PRIVCHECK(th_dcache_iall, REQUIRE_XTHEADCMO, REQUIR= E_PRIV_MS) NOP_PRIVCHECK(th_dcache_cpa, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_cipa, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_ipa, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) -NOP_PRIVCHECK(th_dcache_cva, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MSU) +NOP_PRIVCHECK(th_dcache_cva, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_civa, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MSU) -NOP_PRIVCHECK(th_dcache_iva, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MSU) +NOP_PRIVCHECK(th_dcache_iva, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_csw, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_cisw, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) NOP_PRIVCHECK(th_dcache_isw, REQUIRE_XTHEADCMO, REQUIRE_PRIV_MS) --=20 2.55.0.windows.2 From nobody Sat Sep 26 20:01:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788833808621604.2299923441343; Mon, 7 Sep 2026 19:16:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x3lNb-0008NX-Av; Mon, 07 Sep 2026 22:16:11 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3lNV-0008Kh-1v; Mon, 07 Sep 2026 22:16:05 -0400 Received: from smtp21.cstnet.cn ([159.226.251.21] helo=cstnet.cn) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1x3lNQ-00034R-Op; Mon, 07 Sep 2026 22:16:04 -0400 Received: from [192.168.144.1] (unknown [124.16.137.194]) by APP-01 (Coremail) with SMTP id qwCowACneu7Vb59qVCxsBw--.59943S4; Tue, 08 Sep 2026 10:15:50 +0800 (CST) From: wangyang To: qemu-devel@nongnu.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , qemu-riscv@nongnu.org Subject: [PATCH v2 2/5] target/riscv: mask RV32 XTheadBb th.srri shift amount Date: Tue, 08 Sep 2026 10:15:50 +0800 Message-ID: <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-3> In-Reply-To: <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-1> References: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-1> X-Mailer: git-send-email 2.55.0.windows.2 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-CM-TRANSID: qwCowACneu7Vb59qVCxsBw--.59943S4 X-Coremail-Antispam: 1UD129KBjvdXoW7Xw4fGrW8Xr4kur4Uur15Jwb_yoWkCrX_KF 18GFn7u395Xr47Ka9Fkr18CF1UCry5KFn0y39xtay3u3sxWF15uFn7WFn5A3WUCwn5Grs3 AwsrXa429r1Y9jkaLaAFLSUrUUUUjb8apTn2vfkv8UJUUUU8Yxn0WfASr-VFAUDa7-sFnT 9fnUUIcSsGvfJTRUUUbvxYjsxI4VWkKwAYFVCjjxCrM7AC8VAFwI0_Wr0E3s1l1xkIjI8I 6I8E6xAIw20EY4v20xvaj40_Wr0E3s1l1IIY67AEw4v_Jr0_Jr4l82xGYIkIc2x26280x7 IE14v26r15M28IrcIa0xkI8VCY1x0267AKxVW8JVW5JwA2ocxC64kIII0Yj41l84x0c7CE w4AK67xGY2AK021l84ACjcxK6xIIjxv20xvE14v26r1j6r1xM28EF7xvwVC0I7IYx2IY6x kF7I0E14v26r4j6F4UM28EF7xvwVC2z280aVAFwI0_Jr0_Gr1l84ACjcxK6I8E87Iv6xkF 7I0E14v26r4j6r4UJwAac4AC62xK8xCEY4vEwIxC4wAS0I0E0xvYzxvE52x082IY62kv04 87Mc02F40EFcxC0VAKzVAqx4xG6I80ewAv7VC0I7IYx2IY67AKxVWUJVWUGwAv7VC2z280 aVAFwI0_Jr0_Gr1lOx8S6xCaFVCjc4AY6r1j6r4UM4x0Y48IcxkI7VAKI48JMxkF7I0En4 kS14v26r126r1DMxkIecxEwVAFwVW8JwCF04k20xvY0x0EwIxGrwCFx2IqxVCFs4IE7xkE bVWUJVW8JwC20s026c02F40E14v26r1j6r18MI8I3I0E7480Y4vE14v26r106r1rMI8E67 AF67kF1VAFwI0_Jw0_GFylIxkGc2Ij64vIr41lIxAIcVC0I7IYx2IY67AKxVWUJVWUCwCI 42IY6xIIjxv20xvEc7CjxVAFwI0_Gr0_Cr1lIxAIcVCF04k26cxKx2IYs7xG6r1j6r1xMI IF0xvEx4A2jsIE14v26r1j6r4UMIIF0xvEx4A2jsIEc7CjxVAFwI0_Gr0_Gr1UYxBIdaVF xhVjvjDU0xZFpf9x07b7Vy3UUUUU= X-Originating-IP: [124.16.137.194] X-CM-SenderInfo: 5zdqw5xdqjjk46rwut1l0ox2xfdvhtffof0/ Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=159.226.251.21; envelope-from=wangyang25@otcaix.iscas.ac.cn; helo=cstnet.cn X-Spam_score_int: -41 X-Spam_score: -4.2 X-Spam_bar: ---- X-Spam_report: (-4.2 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1788833813215158500 The XTheadBb th.srri instruction uses the low log2(XLEN) bits of imm6. The generic shift helper rejects values greater than or equal to XLEN, which incorrectly rejects imm6 values 32 through 63 on RV32. Normalize the operand before calling the helper. Tested: RV32 imm6 0, 31, 32, and 63 witnesses with XTheadBb enabled and disabled. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4413 Signed-off-by: wangyang --- target/riscv/tcg/insn_trans/trans_xthead.c.inc | 1 + 1 file changed, 1 insertion(+) diff --git a/target/riscv/tcg/insn_trans/trans_xthead.c.inc b/target/riscv/= tcg/insn_trans/trans_xthead.c.inc index 681f70e5bc..34226b1be5 100644 --- a/target/riscv/tcg/insn_trans/trans_xthead.c.inc +++ b/target/riscv/tcg/insn_trans/trans_xthead.c.inc @@ -141,6 +141,7 @@ GEN_TRANS_TH_ADDSL(3) static bool trans_th_srri(DisasContext *ctx, arg_th_srri * a) { REQUIRE_XTHEADBB(ctx); + a->shamt &=3D get_olen(ctx) - 1; return gen_shift_imm_fn_per_ol(ctx, a, EXT_NONE, tcg_gen_rotri_tl, gen_roriw, NULL); } --=20 2.55.0.windows.2 From nobody Sat Sep 26 20:01:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178883382869447.70288867633019; Mon, 7 Sep 2026 19:17:08 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x3lNY-0008Kv-Ls; Mon, 07 Sep 2026 22:16:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3lNT-0008KI-Mt; Mon, 07 Sep 2026 22:16:03 -0400 Received: from smtp21.cstnet.cn ([159.226.251.21] helo=cstnet.cn) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1x3lNQ-00034Q-Gm; Mon, 07 Sep 2026 22:16:03 -0400 Received: from [192.168.144.1] (unknown [124.16.137.194]) by APP-01 (Coremail) with SMTP id qwCowACneu7Vb59qVCxsBw--.59943S5; Tue, 08 Sep 2026 10:15:50 +0800 (CST) From: wangyang To: qemu-devel@nongnu.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , qemu-riscv@nongnu.org Subject: [PATCH v2 3/5] target/riscv: require read permission for HLVX accesses Date: Tue, 08 Sep 2026 10:15:50 +0800 Message-ID: <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-4> In-Reply-To: <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-1> References: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-1> X-Mailer: git-send-email 2.55.0.windows.2 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-CM-TRANSID: qwCowACneu7Vb59qVCxsBw--.59943S5 X-Coremail-Antispam: 1UD129KBjvJXoW3Jw4DCry8Xw1xtFWkKF18Grg_yoW7Cw45pr WrCrZIkw4kKFZrXayxtF1jyF15CF43GFWjg3Z7WwsY93Waq3yru3WkKa42gFs8GFWkWw1j ga1qyF1jk3WjqFDanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUmIb7Iv0xC_Kw4lb4IE77IF4wAFF20E14v26rWj6s0DM7CY07I2 0VC2zVCF04k26cxKx2IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28IrcIa0xkI8VA2jI 8067AKxVWUWwA2048vs2IY020Ec7CjxVAFwI0_Xr0E3s1l8cAvFVAK0II2c7xJM28CjxkF 64kEwVA0rcxSw2x7M28EF7xvwVC0I7IYx2IY67AKxVWUJVWUCwA2z4x0Y4vE2Ix0cI8IcV CY1x0267AKxVW8JVWxJwA2z4x0Y4vEx4A2jsIE14v26r1j6r4UM28EF7xvwVC2z280aVCY 1x0267AKxVW8JVW8Jr1lnxkEFVAIw20F6cxK64vIFxWle2I262IYc4CY6c8Ij28IcVAaY2 xG8wAqx4xG64xvF2IEw4CE5I8CrVC2j2WlYx0E2Ix0cI8IcVAFwI0_Jr0_Jr4lYx0Ex4A2 jsIE14v26r1j6r4UMcvjeVCFs4IE7xkEbVWUJVW8JwACjcxG0xvY0x0EwIxGrwCY1x0262 kKe7AKxVWUAVWUtwCY02Avz4vE14v_Gr1l42xK82IYc2Ij64vIr41l4I8I3I0E4IkC6x0Y z7v_Jr0_Gr1lx2IqxVAqx4xG67AKxVWUJVWUGwC20s026x8GjcxK67AKxVWUGVWUWwC2zV AF1VAY17CE14v26r1q6r43MIIYrxkI7VAKI48JMIIF0xvE2Ix0cI8IcVAFwI0_Jr0_JF4l IxAIcVC0I7IYx2IY6xkF7I0E14v26r4j6F4UMIIF0xvE42xK8VAvwI8IcIk0rVWUJVWUCw CI42IY6I8E87Iv67AKxVWUJVW8JwCI42IY6I8E87Iv6xkF7I0E14v26r4j6r4UJbIYCTnI WIevJa73UjIFyTuYvjxUg6BfUUUUU X-Originating-IP: [124.16.137.194] X-CM-SenderInfo: 5zdqw5xdqjjk46rwut1l0ox2xfdvhtffof0/ Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=159.226.251.21; envelope-from=wangyang25@otcaix.iscas.ac.cn; helo=cstnet.cn X-Spam_score_int: -41 X-Spam_score: -4.2 X-Spam_bar: ---- X-Spam_report: (-4.2 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1788833832439158500 HLVX address translation uses execute permission, but the final PMP check on the supervisor physical address must also require read permission. Carry the HLVX operation through the MMU index and include PMP_READ in the final check so execute-only pages fault. Tested: RV32 system-mode RWX, HLV, and HLVX.WU PMP test cases. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4414 Signed-off-by: wangyang --- target/riscv/internals.h | 6 ++++++ target/riscv/tcg/cpu_helper.c | 24 ++++++++++++++++-------- target/riscv/tcg/op_helper.c | 11 +++++------ 3 files changed, 27 insertions(+), 14 deletions(-) diff --git a/target/riscv/internals.h b/target/riscv/internals.h index 5d84e4de96..832c6406bc 100644 --- a/target/riscv/internals.h +++ b/target/riscv/internals.h @@ -42,6 +42,7 @@ #define MMUIdx_M 3 #define MMU_2STAGE_BIT (1 << 2) #define MMU_IDX_SS_WRITE (1 << 3) +#define MMU_IDX_HLVX (1 << 4) =20 static inline privilege_mode_t mmuidx_priv(int mmu_idx) { @@ -62,6 +63,11 @@ static inline bool mmuidx_2stage(int mmu_idx) return mmu_idx & MMU_2STAGE_BIT; } =20 +static inline bool mmuidx_hlvx(int mmu_idx) +{ + return mmu_idx & MMU_IDX_HLVX; +} + /* * Return the endianness for the current privilege * level, based on the MSTATUS MBE/SBE/UBE bits. diff --git a/target/riscv/tcg/cpu_helper.c b/target/riscv/tcg/cpu_helper.c index 07d9222652..ad41de9d06 100644 --- a/target/riscv/tcg/cpu_helper.c +++ b/target/riscv/tcg/cpu_helper.c @@ -905,6 +905,7 @@ void riscv_cpu_set_mode(CPURISCVState *env, privilege_m= ode_t newpriv, */ static int get_physical_address_pmp(CPURISCVState *env, int *prot, hwaddr = addr, int size, MMUAccessType access_type, + pmp_priv_t extra_privs, privilege_mode_t mode) { pmp_priv_t pmp_priv; @@ -915,7 +916,8 @@ static int get_physical_address_pmp(CPURISCVState *env,= int *prot, hwaddr addr, return TRANSLATE_SUCCESS; } =20 - pmp_has_privs =3D pmp_hart_has_privs(env, addr, size, 1 << access_type, + pmp_has_privs =3D pmp_hart_has_privs(env, addr, size, + (1 << access_type) | extra_privs, &pmp_priv, mode); if (!pmp_has_privs) { *prot =3D 0; @@ -1177,7 +1179,7 @@ static int get_physical_address(CPURISCVState *env, h= waddr *physical, int pmp_prot; int pmp_ret =3D get_physical_address_pmp(env, &pmp_prot, pte_addr, sxlen_bytes, - MMU_DATA_LOAD, PRV_S); + MMU_DATA_LOAD, 0, PRV_S); if (pmp_ret !=3D TRANSLATE_SUCCESS) { return TRANSLATE_PMP_FAIL; } @@ -1425,7 +1427,8 @@ static int get_physical_address(CPURISCVState *env, h= waddr *physical, } =20 pmp_ret =3D get_physical_address_pmp(env, &pmp_prot, pte_addr, - sxlen_bytes, MMU_DATA_STORE, PR= V_S); + sxlen_bytes, MMU_DATA_STORE, 0, + PRV_S); if (pmp_ret !=3D TRANSLATE_SUCCESS) { return TRANSLATE_PMP_FAIL; } @@ -1711,7 +1714,9 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address, = int size, =20 if (ret =3D=3D TRANSLATE_SUCCESS) { ret =3D get_physical_address_pmp(env, &prot_pmp, pa, - size, access_type, mode); + size, access_type, + mmuidx_hlvx(mmu_idx) ? + PMP_READ : 0, mode); tlb_size =3D pmp_get_tlb_size(env, pa); =20 qemu_log_mask(CPU_LOG_MMU, @@ -1746,7 +1751,9 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address, = int size, =20 if (ret =3D=3D TRANSLATE_SUCCESS) { ret =3D get_physical_address_pmp(env, &prot_pmp, pa, - size, access_type, mode); + size, access_type, + mmuidx_hlvx(mmu_idx) ? + PMP_READ : 0, mode); tlb_size =3D pmp_get_tlb_size(env, pa); =20 qemu_log_mask(CPU_LOG_MMU, @@ -1786,9 +1793,10 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address,= int size, cpu_check_watchpoint(cs, address, size, MEMTXATTRS_UNSPECIFIED, wp_access, retaddr); =20 - raise_mmu_exception(env, address, access_type, pmp_pma_violation, - first_stage_error, two_stage_lookup, - two_stage_indirect_error); + raise_mmu_exception(env, address, + mmuidx_hlvx(mmu_idx) ? MMU_DATA_LOAD : access_= type, + pmp_pma_violation, first_stage_error, + two_stage_lookup, two_stage_indirect_error); cpu_loop_exit_restore(cs, retaddr); } =20 diff --git a/target/riscv/tcg/op_helper.c b/target/riscv/tcg/op_helper.c index 3e94005d2b..060d97ee9c 100644 --- a/target/riscv/tcg/op_helper.c +++ b/target/riscv/tcg/op_helper.c @@ -650,7 +650,7 @@ static int check_access_hlsv(CPURISCVState *env, bool x= , uintptr_t ra) if (!x && mode =3D=3D PRV_S && get_field(env->vsstatus, MSTATUS_SUM)) { mode =3D MMUIdx_S_SUM; } - return mode | MMU_2STAGE_BIT; + return mode | MMU_2STAGE_BIT | (x ? MMU_IDX_HLVX : 0); } =20 target_ulong helper_hyp_hlv_bu(CPURISCVState *env, target_ulong addr) @@ -726,11 +726,10 @@ void helper_hyp_hsv_d(CPURISCVState *env, target_ulon= g addr, target_ulong val) } =20 /* - * TODO: These implementations are not quite correct. They perform the - * access using execute permission just fine, but the final PMP check - * is supposed to have read permission as well. Without replicating - * a fair fraction of cputlb.c, fixing this requires adding new mmu_idx - * which would imply that exact check in tlb_fill. + * HLVX accesses are translated with execute permission (first stage), + * but the final PMP check on the supervisor physical address must + * require read permission as well. The MMU_IDX_HLVX mmu_idx bit set + * by check_access_hlsv() makes riscv_cpu_tlb_fill() enforce this. */ target_ulong helper_hyp_hlvx_hu(CPURISCVState *env, target_ulong addr) { --=20 2.55.0.windows.2 From nobody Sat Sep 26 20:01:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788833832592321.6152504408243; Mon, 7 Sep 2026 19:17:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x3lNY-0008Ko-MI; Mon, 07 Sep 2026 22:16:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3lNT-0008KC-Fg; Mon, 07 Sep 2026 22:16:03 -0400 Received: from smtp21.cstnet.cn ([159.226.251.21] helo=cstnet.cn) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1x3lNQ-00034O-Fr; Mon, 07 Sep 2026 22:16:03 -0400 Received: from [192.168.144.1] (unknown [124.16.137.194]) by APP-01 (Coremail) with SMTP id qwCowACneu7Vb59qVCxsBw--.59943S6; Tue, 08 Sep 2026 10:15:50 +0800 (CST) From: wangyang To: qemu-devel@nongnu.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , qemu-riscv@nongnu.org Subject: [PATCH v2 4/5] target/riscv: prioritize Zicfilp checks for misaligned JALR Date: Tue, 08 Sep 2026 10:15:50 +0800 Message-ID: <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-5> In-Reply-To: <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-1> References: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-1> X-Mailer: git-send-email 2.55.0.windows.2 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-CM-TRANSID: qwCowACneu7Vb59qVCxsBw--.59943S6 X-Coremail-Antispam: 1UD129KBjvJXoW7tF4UWF17Zr1fWF4DJryDtrb_yoW8XF4fpF 40krWUKrW5tFZ5ZF4IqF4UtF43Xa1fWa10qws2q3Z5tF4Yyry3tF1qkryagF1UCF4kWr12 9FWqy3W5WFWUJ3JanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUmqb7Iv0xC_Kw4lb4IE77IF4wAFF20E14v26rWj6s0DM7CY07I2 0VC2zVCF04k26cxKx2IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28IrcIa0xkI8VA2jI 8067AKxVWUAVCq3wA2048vs2IY020Ec7CjxVAFwI0_Xr0E3s1l8cAvFVAK0II2c7xJM28C jxkF64kEwVA0rcxSw2x7M28EF7xvwVC0I7IYx2IY67AKxVWUCVW8JwA2z4x0Y4vE2Ix0cI 8IcVCY1x0267AKxVW8JVWxJwA2z4x0Y4vEx4A2jsIE14v26r1j6r4UM28EF7xvwVC2z280 aVCY1x0267AKxVW8JVW8Jr1lnxkEFVAIw20F6cxK64vIFxWle2I262IYc4CY6c8Ij28IcV AaY2xG8wAqx4xG64xvF2IEw4CE5I8CrVC2j2WlYx0E2Ix0cI8IcVAFwI0_Jr0_Jr4lYx0E x4A2jsIE14v26r1j6r4UMcvjeVCFs4IE7xkEbVWUJVW8JwACjcxG0xvY0x0EwIxGrwCY1x 0262kKe7AKxVWUAVWUtwCY02Avz4vE14v_Gr1l42xK82IYc2Ij64vIr41l4I8I3I0E4IkC 6x0Yz7v_Jr0_Gr1lx2IqxVAqx4xG67AKxVWUJVWUGwC20s026x8GjcxK67AKxVWUGVWUWw C2zVAF1VAY17CE14v26r1q6r43MIIYrxkI7VAKI48JMIIF0xvE2Ix0cI8IcVAFwI0_Jr0_ JF4lIxAIcVC0I7IYx2IY6xkF7I0E14v26r4j6F4UMIIF0xvE42xK8VAvwI8IcIk0rVWUJV WUCwCI42IY6I8E87Iv67AKxVWUJVW8JwCI42IY6I8E87Iv6xkF7I0E14v26r4j6r4UJbIY CTnIWIevJa73UjIFyTuYvjxUg9jbDUUUU X-Originating-IP: [124.16.137.194] X-CM-SenderInfo: 5zdqw5xdqjjk46rwut1l0ox2xfdvhtffof0/ Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=159.226.251.21; envelope-from=wangyang25@otcaix.iscas.ac.cn; helo=cstnet.cn X-Spam_score_int: -41 X-Spam_score: -4.2 X-Spam_bar: ---- X-Spam_report: (-4.2 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1788833836600154100 When Zicfilp tracking is active, a misaligned indirect JALR target also violates the landing-pad requirement. Generate the landing-pad software-check before the generic instruction-address-misaligned exception for tracked targets, while retaining the existing exception for untracked targets. Tested: RV64 M-mode and S-mode Zicfilp controls and misaligned targets with c=3Dtrue and c=3Dfalse. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4415 Signed-off-by: wangyang --- target/riscv/tcg/insn_trans/trans_rvi.c.inc | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/target/riscv/tcg/insn_trans/trans_rvi.c.inc b/target/riscv/tcg= /insn_trans/trans_rvi.c.inc index cc1b5dbbad..aa79a5ef3c 100644 --- a/target/riscv/tcg/insn_trans/trans_rvi.c.inc +++ b/target/riscv/tcg/insn_trans/trans_rvi.c.inc @@ -187,7 +187,14 @@ static bool trans_jalr(DisasContext *ctx, arg_jalr *a) =20 if (misaligned) { gen_set_label(misaligned); - gen_exception_inst_addr_mis(ctx, target_pc); + if (ctx->fcfi_enabled && + a->rs1 !=3D xRA && a->rs1 !=3D xT0 && a->rs1 !=3D xT2) { + tcg_gen_st8_i32(tcg_constant_i32(RISCV_EXCP_SW_CHECK_FCFI_TVAL= ), + tcg_env, offsetof(CPURISCVState, sw_check_code= )); + generate_exception(ctx, RISCV_EXCP_SW_CHECK); + } else { + gen_exception_inst_addr_mis(ctx, target_pc); + } } ctx->base.is_jmp =3D DISAS_NORETURN; =20 --=20 2.55.0.windows.2 From nobody Sat Sep 26 20:01:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788833803473899.9708365646705; Mon, 7 Sep 2026 19:16:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x3lNc-0008Nw-FR; Mon, 07 Sep 2026 22:16:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x3lNV-0008Kc-0N; Mon, 07 Sep 2026 22:16:05 -0400 Received: from smtp21.cstnet.cn ([159.226.251.21] helo=cstnet.cn) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1x3lNQ-00034P-Pi; Mon, 07 Sep 2026 22:16:04 -0400 Received: from [192.168.144.1] (unknown [124.16.137.194]) by APP-01 (Coremail) with SMTP id qwCowACneu7Vb59qVCxsBw--.59943S7; Tue, 08 Sep 2026 10:15:50 +0800 (CST) From: wangyang To: qemu-devel@nongnu.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , qemu-riscv@nongnu.org Subject: [PATCH v2 5/5] target/riscv: canonicalize reserved CBIE encoding Date: Tue, 08 Sep 2026 10:15:50 +0800 Message-ID: <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-6> In-Reply-To: <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-1> References: <20260905093749.491-1-wangyang25@otcaix.iscas.ac.cn> <20260908101550.v2-wangyang25@otcaix.iscas.ac.cn-1> X-Mailer: git-send-email 2.55.0.windows.2 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-CM-TRANSID: qwCowACneu7Vb59qVCxsBw--.59943S7 X-Coremail-Antispam: 1UD129KBjvJXoW7CFy3Wr48uF1kXr15urW7Jwb_yoW8tF48pF 4UWF45KrWq9ryI9a93Jr1UWF13Kr4rGay5Wwnruw4kXa13CFyftFnrK345Kr4UXFWxK3sF 9wsxGry5Cws5JFDanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUmqb7Iv0xC_Kw4lb4IE77IF4wAFF20E14v26rWj6s0DM7CY07I2 0VC2zVCF04k26cxKx2IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28IrcIa0xkI8VA2jI 8067AKxVWUAVCq3wA2048vs2IY020Ec7CjxVAFwI0_Xr0E3s1l8cAvFVAK0II2c7xJM28C jxkF64kEwVA0rcxSw2x7M28EF7xvwVC0I7IYx2IY67AKxVWUCVW8JwA2z4x0Y4vE2Ix0cI 8IcVCY1x0267AKxVW8JVWxJwA2z4x0Y4vEx4A2jsIE14v26r1j6r4UM28EF7xvwVC2z280 aVCY1x0267AKxVW8JVW8Jr1lnxkEFVAIw20F6cxK64vIFxWle2I262IYc4CY6c8Ij28IcV AaY2xG8wAqx4xG64xvF2IEw4CE5I8CrVC2j2WlYx0E2Ix0cI8IcVAFwI0_Jr0_Jr4lYx0E x4A2jsIE14v26r1j6r4UMcvjeVCFs4IE7xkEbVWUJVW8JwACjcxG0xvY0x0EwIxGrwCY1x 0262kKe7AKxVWUAVWUtwCY02Avz4vE14v_Gr1l42xK82IYc2Ij64vIr41l4I8I3I0E4IkC 6x0Yz7v_Jr0_Gr1lx2IqxVAqx4xG67AKxVWUJVWUGwC20s026x8GjcxK67AKxVWUGVWUWw C2zVAF1VAY17CE14v26r1q6r43MIIYrxkI7VAKI48JMIIF0xvE2Ix0cI8IcVAFwI0_JFI_ Gr1lIxAIcVC0I7IYx2IY6xkF7I0E14v26r4j6F4UMIIF0xvE42xK8VAvwI8IcIk0rVWUJV WUCwCI42IY6I8E87Iv67AKxVWUJVW8JwCI42IY6I8E87Iv6xkF7I0E14v26r4j6r4UJbIY CTnIWIevJa73UjIFyTuYvjxUg9jbDUUUU X-Originating-IP: [124.16.137.194] X-CM-SenderInfo: 5zdqw5xdqjjk46rwut1l0ox2xfdvhtffof0/ Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=159.226.251.21; envelope-from=wangyang25@otcaix.iscas.ac.cn; helo=cstnet.cn X-Spam_score_int: -41 X-Spam_score: -4.2 X-Spam_bar: ---- X-Spam_report: (-4.2 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1788833810276154100 CBIE encoding 10 is reserved when Zicbom is implemented, while encoding 11 has defined behavior. Canonicalize only encoding 10 in the menvcfg, senvcfg, and henvcfg write paths so the reserved value is not retained and the defined encoding remains unchanged. Tested: RV64 menvcfg, senvcfg, and henvcfg CBIE 10 and CBIE 11 write/readback test cases. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4416 Signed-off-by: wangyang --- target/riscv/tcg/csr.c | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c index bd4b6dc114..cf59f9ae54 100644 --- a/target/riscv/tcg/csr.c +++ b/target/riscv/tcg/csr.c @@ -3260,6 +3260,16 @@ static RISCVException write_menvcfg(CPURISCVState *e= nv, int csrno, stce_changed =3D true; } } + + /* + * CBIE is a WARL field: encoding 10 is reserved. A software write of + * this encoding must canonicalize to a supported value instead of bei= ng + * retained in the readback. + */ + if (cfg->ext_zicbom && get_field(val, MENVCFG_CBIE) =3D=3D 2) { + val &=3D ~MENVCFG_CBIE; + } + env->menvcfg =3D (env->menvcfg & ~mask) | (val & mask); =20 if (stce_changed) { @@ -3354,6 +3364,16 @@ static RISCVException write_senvcfg(CPURISCVState *e= nv, int csrno, mask |=3D SENVCFG_UKTE; } =20 + /* + * CBIE is a WARL field: encoding 10 is reserved. A software write of + * this encoding must canonicalize to a supported value instead of bei= ng + * retained in the readback. + */ + if (env_archcpu(env)->cfg.ext_zicbom && + get_field(val, SENVCFG_CBIE) =3D=3D 2) { + val &=3D ~SENVCFG_CBIE; + } + env->senvcfg =3D (env->senvcfg & ~mask) | (val & mask); return RISCV_EXCP_NONE; } @@ -3422,6 +3442,15 @@ static RISCVException write_henvcfg(CPURISCVState *e= nv, int csrno, } } =20 + /* + * CBIE is a WARL field: encoding 10 is reserved. A software write of + * this encoding must canonicalize to a supported value instead of bei= ng + * retained in the readback. + */ + if (cfg->ext_zicbom && get_field(val, HENVCFG_CBIE) =3D=3D 2) { + val &=3D ~HENVCFG_CBIE; + } + if (riscv_cpu_mxl(env) =3D=3D MXL_RV32) { /* * RV32 stores STCE/ADUE/PBMTE/DTE in henvcfgh, so a low-half henv= cfg --=20 2.55.0.windows.2