From nobody Sat Sep 26 20:00:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=sifive.com ARC-Seal: i=1; a=rsa-sha256; t=1788943416; cv=none; d=zohomail.com; s=zohoarc; b=ERCM9K8q8t7NSTEYmIEShUDa3klrjf1hW/BGi70OVtqUdAEzvLKVDczvEpjNLorUH0sjcLBr3+WBh33yPz50NRWZo/MxxLNSLq8mvjv4R8uQ+/IlhkB3dPQOx63DH40lbPZm4swHZqpg6ZGTELP/KbtJ4YVNhc3hI+j8rxDpCcQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788943416; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YonI5g7MMuvuxfLeG4auDPo0EnkSd0OHxLNejjnXnho=; b=CW2OwBxFCYb4O4y+DFnXLi1kyzmVfYUpyHHvAzZNUwEMaRj30+8H7OEuelx+dkhJR91+1h297IpIiyQ0HrNmuwDDnMEP5nZKN8GzmHHZ7DAVX1NyJ6EMcWhNtaU8fD9f1k2rO8ycjpvTAcAlDBbN/1nn4k9O2Jf7paEX1+3eO0U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788943416487155.8656603801286; Wed, 9 Sep 2026 01:43:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4DtE-0008Ed-8Q; Wed, 09 Sep 2026 04:42:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4DtC-0008EN-RF for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:42 -0400 Received: from mail-pl1-x62f.google.com ([2607:f8b0:4864:20::62f]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x4DtB-0003IN-Bu for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:42 -0400 Received: by mail-pl1-x62f.google.com with SMTP id d9443c01a7336-2d944747d41so61004405ad.0 for ; Wed, 09 Sep 2026 01:42:40 -0700 (PDT) Received: from duncan.localdomain (114-35-142-126.hinet-ip.hinet.net. [114.35.142.126]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2db56c2a1f1sm38328225ad.78.2026.09.09.01.42.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 01:42:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1788943360; x=1789548160; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=YonI5g7MMuvuxfLeG4auDPo0EnkSd0OHxLNejjnXnho=; b=fYr+1foXHyR1S5aVBqcpdxIsWJjyy/uLQEnacmjUXNZ8+SuD9utAifLmD6Fq+wtEpG OSHA8s+1dvAi5/QgiCLsuJwZmNDMJ8dOTzpoRRewSTcR9DtfJwgca1HZwtK3m9+1hGv2 kSNnudwfGhJY+vR9L25v9lbPyhC3wzce4BKzjtMx4lvDCjOipgiZPSrm4klrbhqy7mIk 8jaIHrHmHEMTblC7TZVNQe3DW7RkLns81WfmHj2qF7GKQt7TNB2eaRJrZ1jGyGLFqm+E rPGJA2GtCwZ9fCHD/GAxEOmSUuum96/hfeho4SSE+pnNfkDqdtE17GufV210ynG3nCME V7FQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788943360; x=1789548160; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=YonI5g7MMuvuxfLeG4auDPo0EnkSd0OHxLNejjnXnho=; b=Mg8CcinoDbWH63bp3/RN6b8RLRogshWhK+E+0CayFjw1qUyyFlQR7sWFlAVaYy3mjl ZaOEI86oajung6dcDwb0dPzCFylHxpH0gYQw2gKfdaSouXiZnc4V7LCY/0zMc5Wr0HQW 0Z2CzdmGxmn7CzMHjWTxrqLhcyRJi5DrKsV77CxRd12AqZR3n+aEHmWknvM+kW5QOx5E B8i1HkcFjppUbC00fkqHW0C/teg2m6Qa42fDXGnnsCXfNxKM30qOcw1rLbdHEHy93AF2 xPojKqg94qxTXgNY+TURj+E92IrnRYMiaLmAehiI2hlPNdbxGAIenRHj1HDN8neOiQsR pwJQ== X-Gm-Message-State: AFuF++l9N29fZNPgERYShoPqb4tsPrP2mLcfAZVOfcroTuMkGSA92w61 ritmNovfK+qkn1Py/8FOJ8Bmch/gzyggX6PiTrazJn9QPtmReI0y4Ln2YV/qLex3+qJuJ1Vs3hP UYFLNzh0PQ9Gt8YayWdEoccr7+T3iDLQzsgOEyZ1EiGzIRHPI08PeSNjxKFBS4jTVS8rQzmhLQb On+WokgNV8U0ee9/+/h9aRprVprHX0O3dLTnTfZNqijw== X-Gm-Gg: AYBFou2bNhoXPMOkmeEKw9qq7vq2eUlkex5k6oF6O/u42RSi1kCZqR3tZXlIVEVF+yJ BvC6y/5Ma3NjgtTnvQDEg0oE3fq/Nc1T2iWeWOeDuK0f1oU64zYPxlA2EemYAJ7alURpPYyab+2 B4Lwfrf7iJHsL6HUr0wA/0BSUn0oWx9LdB7Ipqh1Sk1hnEEroNAUPJcRHMo5XgxF2qkni///cg3 x/mpLL/phmH+6h6/icLmmr72qyIK0ecjzF8hA53JEX+ai3WYcwHy7HTBDvp1KljBnFjIG41apek p4e5NCRVsAzEbKMnEYowh3kGpNBVRuf1UsqmO+RDJfxQkjTufM/DR3tciOu0awp0+UahO34T4jD TY3WsrG3l8IIlvzje4KiQ3/k9DDbjNG6+dBQdwIjwdKRveiteGCFW+vRXp40HvWn263VmkTZc1P xL0e+5QsCsosUzb5s+IthGANk5C7wcSa5dhz2nBqek/Fh/8j8g04e6rYVqsUrl4wQlILRARQHUq LxjE8X0kzD15dn/oDz4p28CYPvZ1DtA29mB5PNK7CP9XHYxJkdgDRHE2T6PsuHHisIPQS03FA== X-Received: by 2002:a17:903:2a8c:b0:2d6:f988:398f with SMTP id d9443c01a7336-2db1259d1edmr482824065ad.12.1788943359705; Wed, 09 Sep 2026 01:42:39 -0700 (PDT) From: Max Chou To: qemu-devel@nongnu.org, qemu-riscv@nongnu.org, richard.henderson@linaro.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , Max Chou Subject: [PATCH 1/6] target/riscv: Match PMP entries lying inside the checked range Date: Wed, 9 Sep 2026 16:41:48 +0800 Message-ID: <20260909084154.223529-2-max.chou@sifive.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260909084154.223529-1-max.chou@sifive.com> References: <20260909084154.223529-1-max.chou@sifive.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::62f; envelope-from=max.chou@sifive.com; helo=mail-pl1-x62f.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @sifive.com) X-ZM-MESSAGEID: 1788943419611158500 Content-Type: text/plain; charset="utf-8" pmp_hart_has_privs decides the permissions of a byte range by testing only the two endpoint bytes against each PMP entry. An active entry lying strictly between the endpoints matches neither byte and is skipped, so a lower-priority entry silently grants an access that the higher-priority entry must deny. Replace the endpoint sampling with interval tests, mirroring the predicate pmp_get_tlb_size already uses. Signed-off-by: Max Chou --- target/riscv/tcg/pmp.c | 31 ++++++++++--------------------- 1 file changed, 10 insertions(+), 21 deletions(-) diff --git a/target/riscv/tcg/pmp.c b/target/riscv/tcg/pmp.c index 41b55519a8e..94224920d8d 100644 --- a/target/riscv/tcg/pmp.c +++ b/target/riscv/tcg/pmp.c @@ -299,20 +299,6 @@ void pmp_update_rule_nums(CPURISCVState *env) } } =20 -static int pmp_is_in_range(CPURISCVState *env, int pmp_index, hwaddr addr) -{ - int result =3D 0; - - if ((addr >=3D env->pmp_state.addr[pmp_index].sa) && - (addr <=3D env->pmp_state.addr[pmp_index].ea)) { - result =3D 1; - } else { - result =3D 0; - } - - return result; -} - /* * Check if the address has required RWX privs when no PMP entry is matche= d. */ @@ -387,8 +373,8 @@ bool pmp_hart_has_privs(CPURISCVState *env, hwaddr addr, { int i =3D 0; int pmp_size =3D 0; - hwaddr s =3D 0; - hwaddr e =3D 0; + hwaddr last =3D 0; + bool size_known =3D size !=3D 0; uint8_t pmp_regions =3D riscv_cpu_cfg(env)->pmp_regions; =20 /* Short cut if no rules */ @@ -414,12 +400,15 @@ bool pmp_hart_has_privs(CPURISCVState *env, hwaddr ad= dr, * 1.10 draft priv spec states there is an implicit order * from low to high */ + last =3D addr + pmp_size - 1; + for (i =3D 0; i < pmp_regions; i++) { - s =3D pmp_is_in_range(env, i, addr); - e =3D pmp_is_in_range(env, i, addr + pmp_size - 1); + hwaddr sa =3D env->pmp_state.addr[i].sa; + hwaddr ea =3D env->pmp_state.addr[i].ea; + bool contains =3D (sa <=3D addr) && (last <=3D ea); + bool overlaps =3D (addr <=3D ea) && (sa <=3D last); =20 - /* partially inside */ - if ((s + e) =3D=3D 1) { + if (size_known && overlaps && !contains) { qemu_log_mask(LOG_GUEST_ERROR, "pmp violation - access is partially inside\n"); *allowed_privs =3D 0; @@ -430,7 +419,7 @@ bool pmp_hart_has_privs(CPURISCVState *env, hwaddr addr, const uint8_t a_field =3D pmp_get_a_field(env->pmp_state.pmp[i].cfg_reg); =20 - if (((s + e) =3D=3D 2) && (PMP_AMATCH_OFF !=3D a_field)) { + if (contains && (PMP_AMATCH_OFF !=3D a_field)) { /* * If the PMP entry is not off and the address is in range, * do the priv check --=20 2.43.0 From nobody Sat Sep 26 20:00:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=sifive.com ARC-Seal: i=1; a=rsa-sha256; t=1788943446; cv=none; d=zohomail.com; s=zohoarc; b=Is1TFVqZOJ2SHivm6hICEaIHQ6Uu7YDAMN39GgFsekGoUMAp1Q0PtKpYY9PcuVISBsKjEsubqOkSf9vayIyF5T7xnXNN2HKeiVOtbyiZ0f6A8joy9t/JyzLU/eBxMasDoBhSedGR86c5q4VZ3W5ef0H1ie4c0HS9xA2fhFyHD8w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788943446; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=JmH3bJrn2KxIguqbsDJoQtnz4vzZycqSDA0K9jBnEPs=; b=Tua92vTqkLA+VyyL7nXKdZ0kWJaUj3PNrJpqsv2e7gWAgSKb0S4yzhtKonWsuPbEyp4HUANx1J0x/lr4UPrUp6gGuODXP0qaEHOzohArGqIFLVs8xHAbD9RG9riDipg6xUpYB/+xU0f0Wu38+kMDP4grIyS3j551q1/n5CB0J+s= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788943446483697.5307962959105; Wed, 9 Sep 2026 01:44:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4DtG-0008FV-Ki; Wed, 09 Sep 2026 04:42:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4DtF-0008FJ-PT for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:45 -0400 Received: from mail-pl1-x62a.google.com ([2607:f8b0:4864:20::62a]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x4DtE-0003Ik-6e for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:45 -0400 Received: by mail-pl1-x62a.google.com with SMTP id d9443c01a7336-2d91ff7d9acso48058765ad.3 for ; Wed, 09 Sep 2026 01:42:43 -0700 (PDT) Received: from duncan.localdomain (114-35-142-126.hinet-ip.hinet.net. [114.35.142.126]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2db56c2a1f1sm38328225ad.78.2026.09.09.01.42.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 01:42:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1788943363; x=1789548163; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JmH3bJrn2KxIguqbsDJoQtnz4vzZycqSDA0K9jBnEPs=; b=E/3Izq2Jk1JReOQ6Yp/wvKzoQWfH0JDCj1DjQzAqlACBB7MKhj0p10CfiUdvse+q3k ZNouQK1I7xvggx3BGf9h7QgnBt73cBrfR6ozeluTDQ5BGfc35CHJfjQx09uNB1NT4im1 fXT/LnWP4CCVzR3p+ElDYdLFjry1q34nyW6vnNshnr3a0xmrfAnP8XcdM8E2qwsfMi8I w874SQ8gfOMvmqGlFf5ZdK9uT7TbiSYhJc9TFcrCeaYoEtczbWdQJuoqQobWCEpCEyaK CguU1gu9mVUSan7taqLNnEfBxoDL6ImwChPBnFyQkRuUI4DMT06L7Y30X+YtH9Q60m1Y a7XQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788943363; x=1789548163; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=JmH3bJrn2KxIguqbsDJoQtnz4vzZycqSDA0K9jBnEPs=; b=o+sP43CuXMkFzj6ezLcGw6eY5zpPo2qCJNdS7V4O+9u7/gYbRdhRGjnNCZYNVKmpSR mRNf4LgQQan05tMb0yHymmjpxUnHvuv3+v1odrrbdA8ooeWvFf1CAS9IdIf02IQ4+qUX pvucjuE/bP8+SrwJftRtMCFE9Vl+e4mhiRG4IRn8ecofM40rJFOTOkg6lvhsIKl2Nmg/ 1nkkpox++Hk3mzjyQx4s9dJp7geYBLfIRFqgf3EyUpUrqjVyqDXbAcB238wQ3Fjvqm5r 74tqOIGCR+1nQZlJrAlRorkNDrhctJudMB+6pIdWgNbiISQgkzB8egKdM0Kbe0zZPLrN tGtQ== X-Gm-Message-State: AFuF++mupK1E9SyhaJKu9RYmJLTGlM+y0xS3T4tdPHiP7gd4lR1edqSH cKiHH+ydRetcHHXN5ZRfSgPs9pA3SMnSNnN1TTfB1O7+dpheMJqoi3c/sIJUKr0Oi1rmTLgISES 7U7sHiFuepv7BoY72ICWmDrZhYzUmiJRqWIGMvDth5VyqgU7FufFkPxweyNUF/pQpeWrV74Trqd 8E4vzq+dY2/a616zRR+xI738KvpuYsem74pL/apf2mtA== X-Gm-Gg: AYBFou0Nltw2ID+/fXQanL1pXmM5UteADIkUx0lCIXRVAloZ3rXmObUrFnIR68ANqVy 63x25HRyevphAynvBZxV0AY/adLpALy1RIf+aZJQzV3bWd1Z+Mh/BY7nDCcyMldlzn3FVI1zDiR DAdMiaOk/9Z85JUCs5NKG5YMAT0s6thhgPx2TE7h2QLe7D88CmpFuchF8PF8LxvVX7bDEt9+025 bqfGhLKn8eqqLgOhS9k7bk63a/dsMB0+EPUzadKkUt0Cr3DHJx3kuiv2qbrSBxn98nyK9wA7/Yr YD8wbxmgLhRyLtcDBUgkelQPFpzSCoBcudx1noviocxBacmTLyKwNvtgWpmfT5xCcfwxkx2uG2g v7uSufqzElyOIkKLCRebIQpKG1Ty7guV66Co2dXm6rIrYCBq2RmT/mjqqmoc6/TdXIy+Jr7uZJu IYL79JPQaysEKL9GctvGQwtJmZKJUMdb94/IKjE1a7/ZnagTTAABLCQZqVyCpsKPaki2wwqMiQS HI+qYqmSbqc5C9vRiMr95lkYdE+oFqa3oOg640P8JJCoeUKjW1sZJ9Z0eUwbs5Bx+OhEsFkXg== X-Received: by 2002:a17:903:40c9:b0:2d6:f6ba:263d with SMTP id d9443c01a7336-2db124b451cmr471899745ad.7.1788943362496; Wed, 09 Sep 2026 01:42:42 -0700 (PDT) From: Max Chou To: qemu-devel@nongnu.org, qemu-riscv@nongnu.org, richard.henderson@linaro.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , Max Chou Subject: [PATCH 2/6] target/riscv: rvv: Probe unit-stride accesses by the first element Date: Wed, 9 Sep 2026 16:41:49 +0800 Message-ID: <20260909084154.223529-3-max.chou@sifive.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260909084154.223529-1-max.chou@sifive.com> References: <20260909084154.223529-1-max.chou@sifive.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::62a; envelope-from=max.chou@sifive.com; helo=mail-pl1-x62a.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @sifive.com) X-ZM-MESSAGEID: 1788943449139158500 Content-Type: text/plain; charset="utf-8" Probe only the first access of the range with probe_access_full and inspect the resulting lg_page_size: when the page is subdivided, fall back to the per-element TLB path. Pages with uniform permissions keep the direct host fast path. Signed-off-by: Max Chou --- target/riscv/tcg/vector_helper.c | 45 ++++++++++++++++++++++++++++---- 1 file changed, 40 insertions(+), 5 deletions(-) diff --git a/target/riscv/tcg/vector_helper.c b/target/riscv/tcg/vector_hel= per.c index efe10156daa..569da995482 100644 --- a/target/riscv/tcg/vector_helper.c +++ b/target/riscv/tcg/vector_helper.c @@ -406,6 +406,41 @@ static void vext_test_alignment(CPURISCVState *env, va= ddr addr, uint32_t esz, } } =20 +static void *vext_probe_host_page(CPURISCVState *env, target_ulong addr, + target_ulong probe_bytes, uint32_t msize, + MMUAccessType access_type, int mmu_index, + uintptr_t ra) +{ +#ifdef CONFIG_USER_ONLY + return probe_access(env, addr, probe_bytes, access_type, mmu_index, ra= ); +#else + CPUTLBEntryFull *full; + void *host; + int flags; + + flags =3D probe_access_full(env, addr, MIN(msize, probe_bytes), + access_type, mmu_index, false, &host, &full,= ra); + if (flags || full->lg_page_size < TARGET_PAGE_BITS) { + return NULL; + } + + if (access_type =3D=3D MMU_DATA_STORE) { + /* + * The permissions are uniform across the page, so probing the + * first access has validated the whole range. It has only + * marked MIN(msize, probe_bytes) bytes as dirty, though, while + * the caller writes probe_bytes through the returned host + * pointer. Probe the whole range as well, so that + * notdirty_write invalidates every translation block that it + * overlaps and the migration dirty bitmap covers all of it. + */ + return probe_access(env, addr, probe_bytes, access_type, + mmu_index, ra); + } + return host; +#endif +} + static void vext_ldst_us_notail(void *vd, target_ulong base, CPURISCVState *env, uint32_t log2_esz, uint32_t nf, uint32_t evl, @@ -448,9 +483,9 @@ vext_ldst_us_notail(void *vd, target_ulong base, CPURIS= CVState *env, page_split =3D -(addr | TARGET_PAGE_MASK); =20 /* Validate the first page is accessible. */ - host =3D probe_access(env, adjust_addr(env, addr), - MIN(last, last_in_page) - addr + 1, - access_type, mmu_index, ra); + host =3D vext_probe_host_page(env, adjust_addr(env, addr), + MIN(last, last_in_page) - addr + 1, + msize, access_type, mmu_index, ra); =20 /* Get number of complete elements in the first page. */ elems =3D MIN(page_split / msize, evl - i); @@ -490,8 +525,8 @@ vext_ldst_us_notail(void *vd, target_ulong base, CPURIS= CVState *env, /* Validate the second page is accessible. */ assert(i < evl); elems =3D evl - i; - host =3D probe_access(env, adjust_addr(env, addr), elems * msize, - access_type, mmu_index, ra); + host =3D vext_probe_host_page(env, adjust_addr(env, addr), elems * msi= ze, + msize, access_type, mmu_index, ra); =20 if (host) { vext_page_ldst_us_host(vd, host, i, evl, nf, log2_esz, --=20 2.43.0 From nobody Sat Sep 26 20:00:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=sifive.com ARC-Seal: i=1; a=rsa-sha256; t=1788943444; cv=none; d=zohomail.com; s=zohoarc; b=MExSLX66berz2dhnYeF+riYWxUsDxycrg6t403FLDl+CJQItKKFJE2DnTqohEh+4DaIA2Ams5iLDHEG2ywn853l/088+veMsme2lbD5aVz9FifmA5pZBSzb5/N18mbjGHcd9cfZ5Z6/Ln3QNLQcU/oAF22A5v6ejPMHhEbRWmXk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788943444; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wN+jBrsk9ZXuLNa7PYx1X0UEa+sJ9PCm+XtlYprhtYg=; b=n/Fbz0L29A9hs8iI4dEurU4R+o4b3n6FNkLPUiWTCHD0Fs1r1y2RPRcDGdRY04SNokD+Q/p+JUO/QdxcRhsdQtJ1wSVlnuE1MVc2fjpyClixQgfivEJK8pMWmRDffDPrI1IZLWVuRByi+tiqL8AoIDP1Udg/3T+E181ES2YVVzc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788943443987662.9059250228881; Wed, 9 Sep 2026 01:44:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4DtL-0008Gf-7V; Wed, 09 Sep 2026 04:42:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4DtJ-0008G9-RX for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:49 -0400 Received: from mail-pl1-x632.google.com ([2607:f8b0:4864:20::632]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x4DtG-0003J8-QN for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:49 -0400 Received: by mail-pl1-x632.google.com with SMTP id d9443c01a7336-2d8fd3b729dso47233105ad.1 for ; Wed, 09 Sep 2026 01:42:46 -0700 (PDT) Received: from duncan.localdomain (114-35-142-126.hinet-ip.hinet.net. [114.35.142.126]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2db56c2a1f1sm38328225ad.78.2026.09.09.01.42.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 01:42:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1788943365; x=1789548165; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=wN+jBrsk9ZXuLNa7PYx1X0UEa+sJ9PCm+XtlYprhtYg=; b=Rla+VW0Qm4zObi+7P9QDTBWEAD/ONjFXS0Vx3hxTMPZdWzWQUxHfwkMKdw+7FY7Yym OR6+Mi/ndAcj+vIOOohmLtx1QmIiLZTE2nhdvOx21w0HiicAL6ltsPxrli7Zl/afcWu6 OucGmNC5kaFETP2Joiz4kdU1WyWZidUFnCba5gBqUD5GZg2vxbChZrNQgnQU6ybvbjDV WVKYrGztOP0bbVqAetDB6lNBM8wjjuJzvXzD/0ThlOgwb/RhNhax2Ymyc/I4DX6Ep4jP ICNGXAN/g5Tr3up1vXW30U2+PGab8liOpH5hzKTyUmQjseumhueyWIYZ0iRQCa9sKisi VdgQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788943365; x=1789548165; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=wN+jBrsk9ZXuLNa7PYx1X0UEa+sJ9PCm+XtlYprhtYg=; b=JVh+xBhKHCkkvoJtEmzUiOVGs3d4BK6lqMXqTi/Eo+Juwj9Wm0Z0wBgoEgU+G+c/2y GHEdCHnVzaxdUYMXP8AAQXUgtzPxzobNofx0/f4K7shewinHbExY9KQHO32UOJiCSI25 RKRRvK2Yt99N5Ci3FFERd65CE0lfV/2hs+kVW3TC/AAYh28ck/SZ63BIl/RgijHXS8PV YpXRQ6JI9YkSGTE4a1SRfm1VzobCQps84pRjUxqoVac1dfjKps37mWXsND/+0czAjzJs skQAyvC6NZeO1fR1MfYjNqCLQeiM9ZCl+v8Go1ZaZAVntGaXQrewnoD2b2Ug6koJaeFc x9mA== X-Gm-Message-State: AFuF++lFEs3moISqdwWjR39KovA+CcFg2KlNCae2Rry1nE/QUNFwFcVg i0TI/QVvnK8eQQTAyVtP0qyK+wmIoG0crd01g6Qiq8RBKKtJ5gwbcqTSiC3uzaEsPKc39K6K6gZ EVXFjSdbR3UYHhsXB3v/2inGN0jLCDH3V2HkiYNtZexbmwvwnd0VVUf9P0E2F/+F8gXpofbVz2I MGYOwk3pLkVGK8Es3Kv6yuSMeJaLYnQIIk45KcL0gPFA== X-Gm-Gg: AYBFou0QD15ubVRSF/kH6UYyslqcHClIN/XuidWHoQ1QVEEDmka8p+xrAe4cqiojU61 0gbGBHgU4Dh5W15FY8by5gxmW0sJi+v1sSRZL0hexFRvciNFFXpleThUokefbMiGAFN1k7iBmAV t5u3DcFDQo9a/NG9TGZ6a0spVQ0l9QtQJ/eGa+ogOE0Q1EBy2td0Q2Au6dPlVH8ZxiE1PknCEYP eCLGM0ET7OlSePHPgJVIqzDtm2mcS+0Fn/GQgvn7HzQ0JYmTVr/UHFVeqo0Q+ZSZjZxtGcsxg1w raImyIqv6hpTowurUcXFf8h4/d3qJ+cHHSNqzDTRS3UGA3DFUg3+A6EHxLR4TBh7tFMcUTNIYfS 69iXsnG10owP44yy+ysXHo+vn289CbbtRds60F6HCqsX2Ahi6YWRTbeFN/7MIdW13v4Tqvw3REL JqZQMWwyBH1brXynrpFNR3IH22KjpsJH0dVNluTtuCZQVpBLlURqaajYLl0HxwMXfOnOEY2viIO nWPNYt9tI9Qui0YKybUFBm/RPzecmduu3vGjFX0ywN/TFdEfUaAm7nI+B27D/PLGcVcDb9WEZFh 9SoKIOUU X-Received: by 2002:a17:902:c94f:b0:2d6:df31:5bd0 with SMTP id d9443c01a7336-2db125c3322mr492527375ad.10.1788943365199; Wed, 09 Sep 2026 01:42:45 -0700 (PDT) From: Max Chou To: qemu-devel@nongnu.org, qemu-riscv@nongnu.org, richard.henderson@linaro.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , Max Chou Subject: [PATCH 3/6] tests/tcg/riscv64: Add vector masked fault-only-first PMP test Date: Wed, 9 Sep 2026 16:41:50 +0800 Message-ID: <20260909084154.223529-4-max.chou@sifive.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260909084154.223529-1-max.chou@sifive.com> References: <20260909084154.223529-1-max.chou@sifive.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::632; envelope-from=max.chou@sifive.com; helo=mail-pl1-x632.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @sifive.com) X-ZM-MESSAGEID: 1788943445699158500 Content-Type: text/plain; charset="utf-8" Add a bare-metal test for masked vector fault-only-first loads across locked NA4 PMP regions inside one page. The test covers masked-off elements, a faulting active element 0, and later active faults that shorten vl. Signed-off-by: Max Chou --- tests/tcg/riscv64/Makefile.softmmu-target | 13 ++ tests/tcg/riscv64/rvv-ldst.inc | 91 ++++++++ tests/tcg/riscv64/test-rvv-ldst-ff-pmp.S | 259 ++++++++++++++++++++++ 3 files changed, 363 insertions(+) create mode 100644 tests/tcg/riscv64/rvv-ldst.inc create mode 100644 tests/tcg/riscv64/test-rvv-ldst-ff-pmp.S diff --git a/tests/tcg/riscv64/Makefile.softmmu-target b/tests/tcg/riscv64/= Makefile.softmmu-target index f2c75abd57a..0fdf242f735 100644 --- a/tests/tcg/riscv64/Makefile.softmmu-target +++ b/tests/tcg/riscv64/Makefile.softmmu-target @@ -85,5 +85,18 @@ run-test-vle32ff: test-vle32ff $(call run-test, $<, $(QEMU) -cpu rv64$(comma)v=3Dtrue $(QEMU_OPTS)$<) test-vle32ff: CFLAGS +=3D -march=3Drv64gcv =20 +RVV_LDST_MARCH =3D -march=3Drv64gcv +RVV_LDST_TESTS =3D test-rvv-ldst-ff-pmp +CLEANFILES +=3D $(RVV_LDST_TESTS) + +$(RVV_LDST_TESTS): %: %.S rvv-ldst.inc $(LINK_SCRIPT) + $(CC) $(CFLAGS) $(RVV_LDST_MARCH) $< -Wa,--noexecstack -c -o $@.o + $(LD) $(LDFLAGS) $@.o -o $@ + +EXTRA_RUNS +=3D run-test-rvv-ldst-ff-pmp + +run-test-rvv-ldst-ff-pmp: test-rvv-ldst-ff-pmp + $(call run-test, $<, $(QEMU) -cpu rv64$(comma)v=3Dtrue$(comma)vlen=3D128$= (comma)elen=3D64$(comma)vext_spec=3Dv1.0$(comma)rvv_ta_all_1s=3Dtrue$(comma= )rvv_ma_all_1s=3Dtrue $(QEMU_OPTS)$<) + # We don't currently support the multiarch system tests undefine MULTIARCH_TESTS diff --git a/tests/tcg/riscv64/rvv-ldst.inc b/tests/tcg/riscv64/rvv-ldst.inc new file mode 100644 index 00000000000..061f330abef --- /dev/null +++ b/tests/tcg/riscv64/rvv-ldst.inc @@ -0,0 +1,91 @@ +/* + * Common support for bare-metal RVV load/store regressions + * + * Register contract: these macros use t0, t1, t5 and t6 as scratch and + * keep the current case number in s11. ASSERT_EQ and CHECK_VELEM hold + * their expected value in t6 across a branch, so a trap handler that can + * run in between must leave t6 alone; use t5 and s5 for that instead. + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + + .option norelax + .option norvc + + .macro RVV_ENABLE + li t0, 0x6600 + csrs mstatus, t0 + csrw vcsr, zero + .endm + + .macro ASSERT_EQ actual, expected + li t6, \expected + bne \actual, t6, fail + .endm + + .macro CASE number + li s11, \number + .endm + + .macro SEMI_EXIT + lla a1, semiargs + li t0, 0x20026 + sd t0, 0(a1) + sd a0, 8(a1) + li a0, 0x20 + .balign 16 + slli zero, zero, 0x1f + ebreak + srai zero, zero, 0x7 + j . + .endm + + .macro FAIL +fail: + mv a0, s11 + bnez a0, 1f + li a0, 1 +1: + j exit + .endm + + /* Pre-fill selected registers with a sentinel neither data nor 1s. */ + .macro PREFILL vd=3D, vl=3D4, sew=3De32, value=3D0x05050505 + vsetivli zero, \vl, \sew, m1, ta, ma + li t0, \value + .ifb \vd + vmv.v.x v2, t0 + vmv.v.x v3, t0 + .else + vmv.v.x \vd, t0 + .endif + .endm + + /* Set the low mask bits of v0 to \val. */ + .macro SET_MASK val + vsetivli zero, 1, e8, m1, ta, ma + li t0, \val + vmv.s.x v0, t0 + .endm + + /* Assert element \idx of \vsrc (e32) equals \expected. */ + .macro CHECK_VELEM vsrc, idx, expected + vsetivli zero, 4, e32, m1, ta, ma + vslidedown.vi v8, \vsrc, \idx + vmv.x.s t0, v8 + li t6, \expected + bne t0, t6, fail + .endm + + /* Assert that no trap has been taken since the last check. */ + .macro CHECK_NO_TRAP + bne s2, s4, fail + .endm + + /* Assert that exactly one expected trap has been taken. */ + .macro CHECK_TRAP + addi s4, s4, 1 + bne s2, s4, fail + li s0, 0 + li s1, 0 + .endm diff --git a/tests/tcg/riscv64/test-rvv-ldst-ff-pmp.S b/tests/tcg/riscv64/t= est-rvv-ldst-ff-pmp.S new file mode 100644 index 00000000000..80b48965625 --- /dev/null +++ b/tests/tcg/riscv64/test-rvv-ldst-ff-pmp.S @@ -0,0 +1,259 @@ +/* + * RISC-V vector masked fault-only-first with PMP tests + * + * PMP permissions may change at NA4 (4-byte) granularity inside one + * target page, matching one e32 element exactly. A masked-off body + * element performs no memory access, so a read-denied PMP region under + * a masked-off element must not fault. + * + * Runs with rvv_ta_all_1s=3Dtrue and rvv_ma_all_1s=3Dtrue so that with a + * "ta, ma" vtype every masked-off and tail element must read back as + * all-1s, distinct from the 0x05050505 sentinel and the loaded data. + * + * PMP layout (locked entries, lowest number wins; everything outside + * the test page is unmatched and so fully accessible from M-mode): + * pmp0: NA4 buf_a+4, L, --- deny element 1 of buf_a + * pmp1: NA4 buf_b+0, L, --- deny element 0 of buf_b + * pmp2: NA4 buf_c+8, L, --- deny element 2 of buf_c + * pmp3: NAPOT test page, L, R lower-priority page allow + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + #include "rvv-ldst.inc" + + .text + .global _start +_start: + RVV_ENABLE + lla t0, trap_handler + csrw mtvec, t0 + + /* + * Trap handler protocol: + * s0: expected mcause (0: no trap expected) + * s1: expected mtval (-1 accepts any value) + * s2: traps taken + * s3: vstart seen at last trap + * s4: traps expected + * s5: mtval seen at last trap + */ + li s0, 0 + li s1, 0 + li s2, 0 + li s3, -1 + li s4, 0 + + /* Program the locked PMP entries; single locking cfg write last. */ + lla t0, buf_a + 4 + srli t0, t0, 2 + csrw pmpaddr0, t0 + lla t0, buf_b + srli t0, t0, 2 + csrw pmpaddr1, t0 + lla t0, buf_c + 8 + srli t0, t0, 2 + csrw pmpaddr2, t0 + lla t0, pmp_page + srli t0, t0, 2 + ori t0, t0, 0x1ff + csrw pmpaddr3, t0 + li t0, 0x99909090 + csrw pmpcfg0, t0 + + /* + * Case 1: sanity: the NA4 deny is in effect for a scalar load. + */ + CASE 1 + li s0, 5 + li s1, -1 + lla t1, buf_a + lw t0, 4(t1) + CHECK_TRAP + + /* + * Case 2: denied bytes lie only under masked-off element 1: no trap. + * QEMU retains vl at 3 for this successful access. + */ + CASE 2 + PREFILL + SET_MASK 0b101 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_a + vle32ff.v v2, (a0), v0.t + CHECK_NO_TRAP + csrr t0, vl + ASSERT_EQ t0, 3 + csrr t0, vstart + bnez t0, fail + CHECK_VELEM v2, 0, 0x00aa0000 + CHECK_VELEM v2, 1, -1 + CHECK_VELEM v2, 2, 0x00aa0002 + CHECK_VELEM v2, 3, -1 + + /* + * Case 3: active element 0 denied: trap, vstart 0. + */ + CASE 3 + PREFILL + li s0, 5 + li s1, -1 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_b + vle32ff.v v2, (a0) + CHECK_TRAP + bnez s3, fail + + /* + * Case 4: masked-off element 0 over denied bytes: no trap. + * retains vl at 3 and loads elements 1 and 2. + */ + CASE 4 + PREFILL + SET_MASK 0b110 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_b + vle32ff.v v2, (a0), v0.t + CHECK_NO_TRAP + csrr t0, vl + ASSERT_EQ t0, 3 + CHECK_VELEM v2, 0, -1 + CHECK_VELEM v2, 1, 0x00bb0001 + CHECK_VELEM v2, 2, 0x00bb0002 + CHECK_VELEM v2, 3, -1 + + /* + * Case 5: active element 2 denied, unmasked: no trap, vl 2. + */ + CASE 5 + PREFILL + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_c + vle32ff.v v2, (a0) + CHECK_NO_TRAP + csrr t0, vl + ASSERT_EQ t0, 2 + CHECK_VELEM v2, 0, 0x00cc0000 + CHECK_VELEM v2, 1, 0x00cc0001 + CHECK_VELEM v2, 2, -1 + CHECK_VELEM v2, 3, -1 + + /* + * Case 6: masked-off element 0, active element 2 denied: vl 2. + */ + CASE 6 + PREFILL + SET_MASK 0b110 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_c + vle32ff.v v2, (a0), v0.t + CHECK_NO_TRAP + csrr t0, vl + ASSERT_EQ t0, 2 + CHECK_VELEM v2, 0, -1 + CHECK_VELEM v2, 1, 0x00cc0001 + CHECK_VELEM v2, 2, -1 + CHECK_VELEM v2, 3, -1 + + /* + * Case 7: nf=3D2 segments, masked-off segment 0 covers the denied byt= es at + * buf_b: no trap. retains vl at 3 and loads segments 1 and 2. + */ + CASE 7 + PREFILL + SET_MASK 0b110 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_b + vlseg2e32ff.v v2, (a0), v0.t + CHECK_NO_TRAP + csrr t0, vl + ASSERT_EQ t0, 3 + CHECK_VELEM v2, 0, -1 + CHECK_VELEM v3, 0, -1 + CHECK_VELEM v2, 1, 0x00bb0002 + CHECK_VELEM v3, 1, 0x00bb0003 + CHECK_VELEM v2, 2, 0x00bb0004 + CHECK_VELEM v3, 2, 0x00bb0005 + CHECK_VELEM v2, 3, -1 + CHECK_VELEM v3, 3, -1 + + /* + * Case 8: nf=3D2 segments, unmasked, field 0 of segment 1 denied + * at buf_c+8: no trap, vl truncates to 1, segment 0 loaded. + */ + CASE 8 + PREFILL + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_c + vlseg2e32ff.v v2, (a0) + CHECK_NO_TRAP + csrr t0, vl + ASSERT_EQ t0, 1 + CHECK_VELEM v2, 0, 0x00cc0000 + CHECK_VELEM v3, 0, 0x00cc0001 + CHECK_VELEM v2, 1, -1 + CHECK_VELEM v3, 1, -1 + CHECK_VELEM v2, 2, -1 + CHECK_VELEM v3, 2, -1 + CHECK_VELEM v2, 3, -1 + CHECK_VELEM v3, 3, -1 + + /* + * Case 9: the denied masked-off element is the last element of the + * accessed range, so a range probe cannot miss it as an interior + * region: no trap. retains vl at 2. + */ + CASE 9 + PREFILL + SET_MASK 0b01 + vsetivli zero, 2, e32, m1, ta, ma + lla a0, buf_a + vle32ff.v v2, (a0), v0.t + CHECK_NO_TRAP + csrr t0, vl + ASSERT_EQ t0, 2 + CHECK_VELEM v2, 0, 0x00aa0000 + CHECK_VELEM v2, 1, -1 + CHECK_VELEM v2, 2, -1 + CHECK_VELEM v2, 3, -1 + + li a0, 0 +exit: + SEMI_EXIT + FAIL + + .balign 4 +trap_handler: + csrr t5, mcause + bne t5, s0, fail + csrr s5, mtval + li t5, -1 + beq s1, t5, 1f + bne s5, s1, fail +1: + csrr s3, vstart + addi s2, s2, 1 + csrw vstart, zero + csrr t5, mepc + addi t5, t5, 4 + csrw mepc, t5 + mret + + .data + .balign 16 +semiargs: .space 16 + + /* One dedicated page; the locked NAPOT entry grants R only. */ + .balign 4096 +pmp_page: +buf_a: + .word 0x00aa0000, 0x00aa0001, 0x00aa0002, 0x00aa0003 + .word 0x00aa0004, 0x00aa0005 + .skip 40 +buf_b: + .word 0x00bb0000, 0x00bb0001, 0x00bb0002, 0x00bb0003 + .word 0x00bb0004, 0x00bb0005 + .skip 40 +buf_c: + .word 0x00cc0000, 0x00cc0001, 0x00cc0002, 0x00cc0003 + .word 0x00cc0004, 0x00cc0005 + .skip 3944 --=20 2.43.0 From nobody Sat Sep 26 20:00:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=sifive.com ARC-Seal: i=1; a=rsa-sha256; t=1788943459; cv=none; d=zohomail.com; s=zohoarc; b=MsrTQB22vrN8vdOfKvqnvP8p1+rWlTh/SoEjJXI3DGzIiDEXg+Q/PHbgGeqOi12hmdhgmT1wHaXmyA4gJcdWan2gbV+hTfIo5DmaKN/7WPtsAjIsHUcJYHSO8Pomnkw5uY3QyUbnuP8VWB+wodnpsErDB61ruwpVIiCUM6gEkdE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788943459; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=vImdkmvMo/lSnFvS/i/NnfNPKJd5mdI+EH5Dgwt+YC8=; b=UjTZU+8PO3h+83rmGWK0yHmoVXVXxyODhQkNiIgMjnOoKS6DcgixnV5Fm7drmrzVd0yiQDat1wLU5Y3C1etCDlYj2QIZ0H9j5owl1zg+qdpTVxM+GwcHVPA1/wv993SJiFGPtXnUnMsbUzfMVi91lH6bGm3t/lBHgQVoRk5WT5I= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788943458984186.36037386900443; Wed, 9 Sep 2026 01:44:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4DtM-0008H9-OX; Wed, 09 Sep 2026 04:42:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4DtL-0008Gt-KU for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:51 -0400 Received: from mail-pj2-x10.google.com ([2607:f8b0:4864:39::10]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x4DtJ-0003JO-E8 for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:51 -0400 Received: by mail-pj2-x10.google.com with SMTP id d9443c01a7336-2d8fb334e72so7666885ad.1 for ; Wed, 09 Sep 2026 01:42:49 -0700 (PDT) Received: from duncan.localdomain (114-35-142-126.hinet-ip.hinet.net. [114.35.142.126]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2db56c2a1f1sm38328225ad.78.2026.09.09.01.42.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 01:42:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1788943368; x=1789548168; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=vImdkmvMo/lSnFvS/i/NnfNPKJd5mdI+EH5Dgwt+YC8=; b=kozbK1NmsgMXNpEtC+BcQBTnK4sNv2Ku4dZ+5YvJJtBCfdn3bPuFeJ93P3j5RCJn9p r0UAqYQTBwtqMXOK8FH6m/5AMQFlc9dsw4TSxH9YeDxXO4ySkvkmhcyfVUca/pz1xcNq V0asP57L1m8nmOauv73fecZNRwQWjqW8n4lEUfEEsqeCgZBBp9tOs0BxyT65U0r//lUd zorN/UgWN8UOibTwEed85Tkfp7xAvNRfD2iFWN0DDFBpR1R4a7suee7KEZP1GvxnTECl HXfC1MUEneKE324QdDhAFqPU7Yqir1a3Jv5GB8Hv5w462gs+b5Zc9NksvcMtJmDMxPYL XJ4A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788943368; x=1789548168; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=vImdkmvMo/lSnFvS/i/NnfNPKJd5mdI+EH5Dgwt+YC8=; b=dx13K2bamSmPCTaBqzbpwOv3QLdOs50tAs6gJs9q200Kg5kBjnL2TpLBn3KzfDSjoj 34dsWbzX8pbIyISpmT6Zksyu/OTwsyIaToEUPJMpW23qZG8a5h8xEw8Q8pGGtfvSSpif v+HFg19/hA0ZJYTWQvRmrqVhT/RjVeRvmTM/3oPHb51cJ5d62gdgFJUOjHHbwn/iBC2d mLNseat7B98a+Fb60UTgqrHEOh2EbxLbW7dCwQ7ifJW8H5BlMldzUJ+uNfRDifBH9m2i G86mkX/DxfgYY5+w+amHfBpkdM0lk2+bOy72IHTX57POi1K8OXiMzvhs6iTEuF8HEeQ1 8Bqg== X-Gm-Message-State: AFuF++muPprDMn0PUQwa94vYGzVPIGftrAlyxLPCD/GdRBE3fHRVfuvS PRrQx0IeH6df77a+Xo6N8ae1L7nj8HFnuBctFxEts3Udhu0dqzSBzm71JGSFlXS0nA6Lsqgvng0 Fb3/UhTII5qv1iSaGk3uOlZnqLCbh1CMVIORlPiwKqF2Ba4IsWIELbGpBhxBK4YF8BDctKyvcdI qoaLkhMb8J/g+tVeAI48T74lGi6rfDR5URPDwVtmAC7Q== X-Gm-Gg: AYBFou1RtQ/0dwf4cZqK2buybkmUK3QNeLR0wR/kmboCmQsKFQfy7J7CG5bngTUijFE aqD+lz3nYMC4bqEaQEfHvyE5nn/VpLi+qAyav1skAyZUwX/ezgua24PWoQx8dG4gKld5bdmA6ct wsZCWm3Kg/RvSLGF/FQlmYRSaI7PbdzYx+8pqi7VVOfl187GrD4H/7MDL/TbXxzI2jdi8LR68ya TjCpgIwDCB4H5ndCgeBPdAs2saX7cgtvCT7E8xnlh8FaJlQYbnRJiSNi08UsCawqFtPOtF23D4x Dv4046+kg9ZM/KB1HdHpOPe09Hre9f4gz5VCtftENxYK5i4lrmXTGsOptLzWNQBW9INKONQuZhj robqspzY65phi2B+PP8dUMu8MX3WsOsgaj2dO/fKZVnM9qxrXnX+AlxplDpM9VlnUBEm+xjTCUk 7BWMEe1hzBQLVR8lkedUC/5UKgR5/AkWk9wKzjOfsMp4trtV2IJa91mNCGrwGb6HaVpJVCcR5mM OuQupSmh0IBiDtt7J9XIYI1E4dZiQr1dzGpbfL9iRyavYAWHCCS384dvE8wx0nwk/xtnUsaY2eK C9WXG4UJ X-Received: by 2002:a17:902:fc4e:b0:2d7:3f6e:5cb9 with SMTP id d9443c01a7336-2db8da30a48mr62754735ad.8.1788943367894; Wed, 09 Sep 2026 01:42:47 -0700 (PDT) From: Max Chou To: qemu-devel@nongnu.org, qemu-riscv@nongnu.org, richard.henderson@linaro.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , Max Chou Subject: [PATCH 4/6] tests/tcg/riscv64: Add vector unit-stride PMP test Date: Wed, 9 Sep 2026 16:41:51 +0800 Message-ID: <20260909084154.223529-5-max.chou@sifive.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260909084154.223529-1-max.chou@sifive.com> References: <20260909084154.223529-1-max.chou@sifive.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:39::10; envelope-from=max.chou@sifive.com; helo=mail-pj2-x10.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @sifive.com) X-ZM-MESSAGEID: 1788943461173158500 Content-Type: text/plain; charset="utf-8" Add a bare-metal test for locked NA4 PMP permissions lying inside unit-stride access ranges. The test covers unmasked and masked reads and writes, and checks that an interior deny is reported with the exact faulting mtval and vstart rather than merely trapping somewhere in the range. Signed-off-by: Max Chou --- tests/tcg/riscv64/Makefile.softmmu-target | 7 +- tests/tcg/riscv64/test-rvv-ldst-us-pmp.S | 281 ++++++++++++++++++++++ 2 files changed, 286 insertions(+), 2 deletions(-) create mode 100644 tests/tcg/riscv64/test-rvv-ldst-us-pmp.S diff --git a/tests/tcg/riscv64/Makefile.softmmu-target b/tests/tcg/riscv64/= Makefile.softmmu-target index 0fdf242f735..9e0e0490753 100644 --- a/tests/tcg/riscv64/Makefile.softmmu-target +++ b/tests/tcg/riscv64/Makefile.softmmu-target @@ -86,17 +86,20 @@ run-test-vle32ff: test-vle32ff test-vle32ff: CFLAGS +=3D -march=3Drv64gcv =20 RVV_LDST_MARCH =3D -march=3Drv64gcv -RVV_LDST_TESTS =3D test-rvv-ldst-ff-pmp +RVV_LDST_TESTS =3D test-rvv-ldst-ff-pmp test-rvv-ldst-us-pmp CLEANFILES +=3D $(RVV_LDST_TESTS) =20 $(RVV_LDST_TESTS): %: %.S rvv-ldst.inc $(LINK_SCRIPT) $(CC) $(CFLAGS) $(RVV_LDST_MARCH) $< -Wa,--noexecstack -c -o $@.o $(LD) $(LDFLAGS) $@.o -o $@ =20 -EXTRA_RUNS +=3D run-test-rvv-ldst-ff-pmp +EXTRA_RUNS +=3D run-test-rvv-ldst-ff-pmp run-test-rvv-ldst-us-pmp =20 run-test-rvv-ldst-ff-pmp: test-rvv-ldst-ff-pmp $(call run-test, $<, $(QEMU) -cpu rv64$(comma)v=3Dtrue$(comma)vlen=3D128$= (comma)elen=3D64$(comma)vext_spec=3Dv1.0$(comma)rvv_ta_all_1s=3Dtrue$(comma= )rvv_ma_all_1s=3Dtrue $(QEMU_OPTS)$<) =20 +run-test-rvv-ldst-us-pmp: test-rvv-ldst-us-pmp + $(call run-test, $<, $(QEMU) -cpu rv64$(comma)v=3Dtrue$(comma)vlen=3D128$= (comma)elen=3D64$(comma)vext_spec=3Dv1.0$(comma)rvv_ta_all_1s=3Dtrue$(comma= )rvv_ma_all_1s=3Dtrue $(QEMU_OPTS)$<) + # We don't currently support the multiarch system tests undefine MULTIARCH_TESTS diff --git a/tests/tcg/riscv64/test-rvv-ldst-us-pmp.S b/tests/tcg/riscv64/t= est-rvv-ldst-us-pmp.S new file mode 100644 index 00000000000..521667628da --- /dev/null +++ b/tests/tcg/riscv64/test-rvv-ldst-us-pmp.S @@ -0,0 +1,281 @@ +/* + * RISC-V vector unit-stride with PMP tests + * + * Runs with rvv_ta_all_1s=3Dtrue and rvv_ma_all_1s=3Dtrue so that with a + * "ta, ma" vtype QEMU fills every masked-off and tail element with + * all-1s, distinct from the 0x05050505 sentinel and the loaded data. + * + * PMP layout (locked entries, lowest number wins; everything outside + * the test page is unmatched and so fully accessible from M-mode): + * pmp0: NA4 buf_a+4, L, --- deny word 1 of buf_a + * pmp1: NA4 buf_b+8, L, --- deny word 2 of buf_b + * pmp2: NA4 buf_c+4, L, R-- word 1 of buf_c readable, no write + * pmp3: NAPOT test page, L, RW lower-priority page allow + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + #include "rvv-ldst.inc" + + /* Assert the word at \sym+\off (readable) still equals \expected. */ + .macro CHECK_WORD sym, off, expected + lla t1, \sym + lw t0, \off(t1) + li t6, \expected + bne t0, t6, fail + .endm + + .text + .global _start +_start: + RVV_ENABLE + lla t0, trap_handler + csrw mtvec, t0 + + /* + * Trap handler protocol: + * s0: expected mcause (0: no trap expected) + * s1: expected mtval (-1: any mtval accepted) + * s2: traps taken s3: vstart seen at last trap + * s4: traps expected s5: mtval seen at last trap + */ + li s0, 0 + li s1, 0 + li s2, 0 + li s3, -1 + li s4, 0 + li s5, -1 + + /* Program the locked PMP entries; single locking cfg write last. */ + lla t0, buf_a + 4 + srli t0, t0, 2 + csrw pmpaddr0, t0 + lla t0, buf_b + 8 + srli t0, t0, 2 + csrw pmpaddr1, t0 + lla t0, buf_c + 4 + srli t0, t0, 2 + csrw pmpaddr2, t0 + lla t0, pmp_page + srli t0, t0, 2 + ori t0, t0, 0x1ff + csrw pmpaddr3, t0 + li t0, 0x000000009b919090 + csrw pmpcfg0, t0 + + /* + * Case 1: sanity: the NA4 read deny traps a scalar load. + */ + CASE 1 + li s0, 5 + li s1, -1 + lla t1, buf_a + lw t0, 4(t1) + CHECK_TRAP + + /* + * Case 2: sanity: the read-only NA4 word traps a scalar store and + * still reads back, proving stores can be verified via loads. + */ + CASE 2 + li s0, 7 + li s1, -1 + lla t1, buf_c + sw t1, 4(t1) + CHECK_TRAP + CHECK_WORD buf_c, 4, 0x00cc0001 + + /* + * Case 3: unmasked vle32.v, vl 3, read deny strictly inside the + * range at buf_a+4 (element 1): element 1 is active, so the access + * must raise a load access fault. A probe that samples only the range + * endpoints sees just the page allow and loads the denied word silent= ly. + */ + CASE 3 + PREFILL + li s0, 5 + li s1, -1 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_a + vle32.v v2, (a0) + CHECK_TRAP + + /* + * Case 4: unmasked vle32.v with the denied word first in the + * range: element 0 faults and vstart is zero. + */ + CASE 4 + PREFILL + li s0, 5 + li s1, -1 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_a + 4 + vle32.v v2, (a0) + CHECK_TRAP + bnez s3, fail + + /* + * Case 5: unmasked vle32.v with the denied word last in the range + * at buf_b+8 (element 2): must trap. + */ + CASE 5 + PREFILL + li s0, 5 + li s1, -1 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_b + vle32.v v2, (a0) + CHECK_TRAP + + /* + * Case 6: unmasked vse32.v, vl 3, write deny strictly inside the + * range at buf_c+4 (element 1): the protected word must remain + * unmodified. Element 0 must have been stored and element 2 must + * not, so that a "store every element whose own probe succeeds" + * implementation is rejected rather than passing on the protected + * word alone. + */ + CASE 6 + vsetivli zero, 4, e32, m1, ta, ma + lla a0, st_data_a + vle32.v v4, (a0) + li s0, 7 + li s1, -1 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_c + vse32.v v4, (a0) + CHECK_TRAP + CHECK_WORD buf_c, 0, 0x11111111 + CHECK_WORD buf_c, 4, 0x00cc0001 + CHECK_WORD buf_c, 8, 0x00cc0002 + + /* + * Case 7: masked vle32.v with the read deny only under masked-off + * element 1: no access is performed there, so no trap and the + * mask-agnostic all-1s fill applies. + */ + CASE 7 + PREFILL + SET_MASK 0b101 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_a + vle32.v v2, (a0), v0.t + CHECK_NO_TRAP + CHECK_VELEM v2, 0, 0x00aa0000 + CHECK_VELEM v2, 1, -1 + CHECK_VELEM v2, 2, 0x00aa0002 + CHECK_VELEM v2, 3, -1 + + /* + * Case 8: masked vse32.v with the write deny only under masked-off + * element 1: no trap, elements 0 and 2 stored, the protected word + * untouched. + */ + CASE 8 + vsetivli zero, 4, e32, m1, ta, ma + lla a0, st_data_b + vle32.v v4, (a0) + SET_MASK 0b101 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_c + vse32.v v4, (a0), v0.t + CHECK_NO_TRAP + CHECK_WORD buf_c, 0, 0x44444444 + CHECK_WORD buf_c, 4, 0x00cc0001 + CHECK_WORD buf_c, 8, 0x66666666 + + /* + * Case 9: like case 3 (read deny at element 1 of 3), the mtval should= be + * the denied word's own address and vstart should be 1, not the range + * base and 0. + */ + CASE 9 + PREFILL + li s0, 5 + lla s1, buf_a + 4 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_a + vle32.v v2, (a0) + CHECK_TRAP + ASSERT_EQ s3, 1 + + /* + * Case 10: like case 5 (read deny at element 2, the last of 3), + * confirming precise reporting also holds when the denied element + * is not the first one probed. + */ + CASE 10 + PREFILL + li s0, 5 + lla s1, buf_b + 8 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_b + vle32.v v2, (a0) + CHECK_TRAP + ASSERT_EQ s3, 2 + + /* + * Case 11: like case 6 (write deny at element 1 of 3), on the + * store side. buf_c+8 still holds the 0x66666666 that case 8 + * stored, so checking it here proves element 2 was not written + * after the trap. + */ + CASE 11 + vsetivli zero, 4, e32, m1, ta, ma + lla a0, st_data_a + vle32.v v4, (a0) + li s0, 7 + lla s1, buf_c + 4 + vsetivli zero, 3, e32, m1, ta, ma + lla a0, buf_c + vse32.v v4, (a0) + CHECK_TRAP + ASSERT_EQ s3, 1 + CHECK_WORD buf_c, 0, 0x11111111 + CHECK_WORD buf_c, 4, 0x00cc0001 + CHECK_WORD buf_c, 8, 0x66666666 + + li a0, 0 +exit: + SEMI_EXIT + FAIL + + .balign 4 +trap_handler: + csrr t5, mcause + bne t5, s0, fail + csrr s5, mtval + li t5, -1 + beq s1, t5, 1f + bne s5, s1, fail +1: + csrr s3, vstart + addi s2, s2, 1 + csrw vstart, zero + csrr t5, mepc + addi t5, t5, 4 + csrw mepc, t5 + mret + + .data + .balign 16 +semiargs: .space 16 + + /* Store source data; outside every PMP region. */ +st_data_a: .word 0x11111111, 0x22222222, 0x33333333, 0x77777777 +st_data_b: .word 0x44444444, 0x55555555, 0x66666666, 0x88888888 + + /* One dedicated page governed by the locked NAPOT RW entry. */ + .balign 4096 +pmp_page: +buf_a: + .word 0x00aa0000, 0x00aa0001, 0x00aa0002, 0x00aa0003 + .word 0x00aa0004, 0x00aa0005 + .skip 40 +buf_b: + .word 0x00bb0000, 0x00bb0001, 0x00bb0002, 0x00bb0003 + .word 0x00bb0004, 0x00bb0005 + .skip 40 +buf_c: + .word 0x00cc0000, 0x00cc0001, 0x00cc0002, 0x00cc0003 + .word 0x00cc0004, 0x00cc0005 + .skip 3944 --=20 2.43.0 From nobody Sat Sep 26 20:00:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=sifive.com ARC-Seal: i=1; a=rsa-sha256; t=1788943445; cv=none; d=zohomail.com; s=zohoarc; b=Ex3D6FilOH3Kkuk0LyUKrbMZHiwzi31V/1RFFShQXx7OphrYgFv9nk/57B1n4s5PgSY+qLt1QBaYFQZsObxOQwZ1OlBhE84D5axfPbXDerYVZB4JnXConRzQ8PlQdWSgJ951bIUaZnf+mSM3DbVz9kqSCO40CuBRYtnT5DIUIA8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788943445; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3/JSEN4yZJQug9AgbAgWw+4fekDHImfUc2lZDl80p84=; b=HFoxqZg5h7DUFIrVWpY5skdnX3DTrZ/FpF1c49RdXnaleFqkcDqS/bYdxLnjLd7LU8vzytFk2lNvdHL5cxw6iOY5cFudrb+1yxyEwPny0Kmw+M4fLQluT5s+o3NTt/8295ceBRBEg2E9eR+XQrJnC8xRrKmx0yW2I7L5PwcPVHw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788943445391281.89829048601996; Wed, 9 Sep 2026 01:44:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4DtP-0008IJ-VW; Wed, 09 Sep 2026 04:42:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4DtO-0008Hq-JH for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:54 -0400 Received: from mail-pl1-x629.google.com ([2607:f8b0:4864:20::629]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x4DtM-0003K3-QX for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:54 -0400 Received: by mail-pl1-x629.google.com with SMTP id d9443c01a7336-2d944747d41so61006025ad.0 for ; Wed, 09 Sep 2026 01:42:52 -0700 (PDT) Received: from duncan.localdomain (114-35-142-126.hinet-ip.hinet.net. [114.35.142.126]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2db56c2a1f1sm38328225ad.78.2026.09.09.01.42.48 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 01:42:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1788943371; x=1789548171; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3/JSEN4yZJQug9AgbAgWw+4fekDHImfUc2lZDl80p84=; b=DQ9dL677NoWmHBzHOeiHaD0vc2xMax+B0qvdsoPJGTlZNKGAQUrigGhB7TpverFhl8 5ykiqrpHrfyT0X/b3CyYL/D6DxeWkfKtfINEeVBTG7y+zs2lrlQKiR5pwJIo1PnRGkY2 xdrCWJdDxd09vwEBjcpoLSFvNF4J2Iogu4S4l+p0wDobKySY4cfnTQWtUNYT3TToa0UJ 35TM0AOfCHFTHE4Mbx5uoDC97ewwXxEquU8bKAIszgpmzUBH21OuQMKAN0Y2QV/Ehy/I y4HJiR+unPNghYajoIpib4RMWAM2HM3e/agIkiGF8mvX4H8lmw0nGkvWsLKemDtaGBeY ltXg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788943371; x=1789548171; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=3/JSEN4yZJQug9AgbAgWw+4fekDHImfUc2lZDl80p84=; b=I9yIZJF3obYcAT02ERvQQADq4dKle4wfxuBmV0C7Tt8cAnCFUlU5M6GDefKfxgU+q5 Lvu4zEVPoB/4Zzqa5v/SpcUJcW6KxYnn8QqW70ghyuKrxvT2X399UXGJ4NlgnzidNT+u VryWV8rklmp/sYIgcQvf5WfzqeP9uBzozWWygA0SWK2bq3HgeeEttuqIbYV4ta/hXdSn HLq5AulX/Ncr54qzkr10Fif8oJP5cDrJWn5i3TzL9YwnbC5O9YofGc5zaj7vHaexb0PW 27ToAOea86zJuq6dqhkCHy1hMZfGJaqgHYsRfLVUFidAOZW+qmTlb8WvmvoDePHnP7uu 2Fmw== X-Gm-Message-State: AFuF++k0dHTynhcAFrG3+Jj9xWyiG15FBbhfVAAzbH2a8TvSbpDBXsNG Jk4jHepmf9sADx7x5w5IBQp4CvuJzRfKz/52cam/zVVqNTe7pbBeRnGxSK9mE0E9GwgVD4GsPWw dccFFYZn8NYgS3Ro10ADrv2wSbMSkvWu0nxrK6pVoKR1wW5I45Iy/grsa2xNEF6i8WOgm4+pidz Hv6brsFFM3CTDltwNJeG1BNUMXOgNQUcn1zi4276PpFA== X-Gm-Gg: AYBFou2+TciKwCA3ixMcSS0cfaj0TRvbqoJJaGIYuLO7TffMG1AItfoflLcn8YdqFRt iNy6s0fEztuR6GTM9ezG1CA1hkm6INgjnZM5zp7amcneuX8uVOk1osb+6S6G5hvcQWyKiay17S9 lriXFKzrl8N53sa3VGjbkmd7H8pK00S0xOUa37sQRgtOl9veDGajUiVO4NweaV8iV9r0GvgD8eH iap48YRdedoI+J7aID2IrY/GOPaNOtA3YEJJA99HS/VauJEHghsmSl1Wx34Gba5Ea+/snJl5oYv dimcxPXmRkrX2VF/SEfG4YAx+GkwzIVV4f88n6GTiqjVf1VzHqcNm2fQVM5BdDs7LbIW2CeoBP5 zCW00GRFcl4dqADioW0EqtbDnENIlkUF0wpr+jCZP7FUegDsFcrlln1U5KGcI8Up5EZBxvRawWG fTGmm1V+COUiJ8egnpGAAzDFGoHo8rBRpJGbmXwC0A+HH2d2Z3WXvcCpqg3nPrPjQ4EBXiVkNcI shtJx2l6oOLIz+IY8AiwaTdKm7bNKYFlpiynxCI3i2xdKKdDfTNNxgFkcrINSESiafvb3ZVMex8 CBR/i4Wk X-Received: by 2002:a17:902:930a:b0:2d6:e074:9cad with SMTP id d9443c01a7336-2db1236f4femr349937195ad.6.1788943371077; Wed, 09 Sep 2026 01:42:51 -0700 (PDT) From: Max Chou To: qemu-devel@nongnu.org, qemu-riscv@nongnu.org, richard.henderson@linaro.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , Max Chou Subject: [PATCH 5/6] tests/tcg/riscv64: Add vector fault-only-first page probe test Date: Wed, 9 Sep 2026 16:41:52 +0800 Message-ID: <20260909084154.223529-6-max.chou@sifive.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260909084154.223529-1-max.chou@sifive.com> References: <20260909084154.223529-1-max.chou@sifive.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::629; envelope-from=max.chou@sifive.com; helo=mail-pl1-x629.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @sifive.com) X-ZM-MESSAGEID: 1788943447137158500 Content-Type: text/plain; charset="utf-8" Add a bare-metal test for vector fault-only-first loads whose first-element probe crosses a page boundary. The test covers a body access that crosses the boundary after the first element, and a first element that itself straddles the boundary, checking that both cases report a full vl and vstart of 0 rather than faulting on a mapped page. Signed-off-by: Max Chou --- tests/tcg/riscv64/Makefile.softmmu-target | 9 ++- tests/tcg/riscv64/test-rvv-ldst-ff-page.S | 83 +++++++++++++++++++++++ 2 files changed, 90 insertions(+), 2 deletions(-) create mode 100644 tests/tcg/riscv64/test-rvv-ldst-ff-page.S diff --git a/tests/tcg/riscv64/Makefile.softmmu-target b/tests/tcg/riscv64/= Makefile.softmmu-target index 9e0e0490753..93c4e58e0c2 100644 --- a/tests/tcg/riscv64/Makefile.softmmu-target +++ b/tests/tcg/riscv64/Makefile.softmmu-target @@ -86,14 +86,16 @@ run-test-vle32ff: test-vle32ff test-vle32ff: CFLAGS +=3D -march=3Drv64gcv =20 RVV_LDST_MARCH =3D -march=3Drv64gcv -RVV_LDST_TESTS =3D test-rvv-ldst-ff-pmp test-rvv-ldst-us-pmp +RVV_LDST_TESTS =3D test-rvv-ldst-ff-pmp test-rvv-ldst-us-pmp \ + test-rvv-ldst-ff-page CLEANFILES +=3D $(RVV_LDST_TESTS) =20 $(RVV_LDST_TESTS): %: %.S rvv-ldst.inc $(LINK_SCRIPT) $(CC) $(CFLAGS) $(RVV_LDST_MARCH) $< -Wa,--noexecstack -c -o $@.o $(LD) $(LDFLAGS) $@.o -o $@ =20 -EXTRA_RUNS +=3D run-test-rvv-ldst-ff-pmp run-test-rvv-ldst-us-pmp +EXTRA_RUNS +=3D run-test-rvv-ldst-ff-pmp run-test-rvv-ldst-us-pmp \ + run-test-rvv-ldst-ff-page =20 run-test-rvv-ldst-ff-pmp: test-rvv-ldst-ff-pmp $(call run-test, $<, $(QEMU) -cpu rv64$(comma)v=3Dtrue$(comma)vlen=3D128$= (comma)elen=3D64$(comma)vext_spec=3Dv1.0$(comma)rvv_ta_all_1s=3Dtrue$(comma= )rvv_ma_all_1s=3Dtrue $(QEMU_OPTS)$<) @@ -101,5 +103,8 @@ run-test-rvv-ldst-ff-pmp: test-rvv-ldst-ff-pmp run-test-rvv-ldst-us-pmp: test-rvv-ldst-us-pmp $(call run-test, $<, $(QEMU) -cpu rv64$(comma)v=3Dtrue$(comma)vlen=3D128$= (comma)elen=3D64$(comma)vext_spec=3Dv1.0$(comma)rvv_ta_all_1s=3Dtrue$(comma= )rvv_ma_all_1s=3Dtrue $(QEMU_OPTS)$<) =20 +run-test-rvv-ldst-ff-page: test-rvv-ldst-ff-page + $(call run-test, $<, $(QEMU) -cpu rv64$(comma)v=3Dtrue$(comma)vlen=3D128$= (comma)elen=3D64$(comma)vext_spec=3Dv1.0 $(QEMU_OPTS)$<) + # We don't currently support the multiarch system tests undefine MULTIARCH_TESTS diff --git a/tests/tcg/riscv64/test-rvv-ldst-ff-page.S b/tests/tcg/riscv64/= test-rvv-ldst-ff-page.S new file mode 100644 index 00000000000..63b1e0ac8a8 --- /dev/null +++ b/tests/tcg/riscv64/test-rvv-ldst-ff-page.S @@ -0,0 +1,83 @@ +/* + * RISC-V vector fault-only-first probe page-crossing tests + * + * A first-element probe validates the mapping only for the bytes that + * the first (fault-only) element itself touches, then lets the + * remaining elements of the vector body fault normally. An + * implementation that instead probes the whole multi-element access + * range as one host operation aborts as soon as that range crosses a + * page boundary, even though every page involved is in fact mapped. + * + * Case 1 crosses the page boundary only in the vector body, after the + * first element. Case 2 crosses it inside the first element itself, + * so the first-element probe must span both pages it touches. + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + #include "rvv-ldst.inc" + + .text + .global _start +_start: + RVV_ENABLE + lla t0, trap_handler + csrw mtvec, t0 + + /* + * Case 1: the body crosses the page boundary; the first element does = not. + */ + CASE 1 + li t0, 3 + vsetvli t1, t0, e8, m1, tu, mu + lla a0, cross_segment + vlseg2e8ff.v v2, (a0) + csrr t0, vl + ASSERT_EQ t0, 3 + csrr t0, vstart + ASSERT_EQ t0, 0 + lla a0, output + vsseg2e8.v v2, (a0) + lbu t0, 5(a0) + ASSERT_EQ t0, 0x66 + + /* + * Case 2: the first segment element itself straddles the page boundar= y. + */ + CASE 2 + li t0, 3 + vsetvli t1, t0, e8, m1, tu, mu + lla a0, straddle_segment + vlseg2e8ff.v v2, (a0) + csrr t0, vl + ASSERT_EQ t0, 3 + csrr t0, vstart + ASSERT_EQ t0, 0 + lla a0, output + vsseg2e8.v v2, (a0) + lbu t0, 5(a0) + ASSERT_EQ t0, 0xf6 + li a0, 0 +exit: + SEMI_EXIT + FAIL + + /* + * No trap is expected: a spurious fault from the page-crossing probe + * is the very thing under test. Report the case number rather than + * vectoring to the reset value of mtvec and hanging until the + * harness timeout. + */ + .balign 4 +trap_handler: + j fail + + .data + .balign 16 +semiargs: .space 16 + .balign 4096 + .space 4094 +cross_segment: .byte 0x11, 0x22, 0x33, 0x44, 0x55, 0x66 +output: .space 6 + .balign 4096 + .space 4095 +straddle_segment: .byte 0xa1, 0xb2, 0xc3, 0xd4, 0xe5, 0xf6 --=20 2.43.0 From nobody Sat Sep 26 20:00:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=sifive.com ARC-Seal: i=1; a=rsa-sha256; t=1788943441; cv=none; d=zohomail.com; s=zohoarc; b=Xr6ztFna0OxTmid4SQ7yuoXD900G4GPRQ1gPA49s+SNRzRw5uvAGGR7k5eZGCpVAU3ykwRUY72Qv2PQwlHNYFrKmSmKvgZ+RS8YZFj2Udbo/guiJc0Isi3sA/1yCladsTSmkblRKaxsCkHCIHwwgF9dLWyVKwLlBWuIVBiuDg4k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788943441; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YGg/RvrSoKzoUlW9nA/79/jfYq8eoWdPwOwzok+Tzg4=; b=MAJ82/nMzI5XlxaHXNf6AZfNJGkaQMUDJenP5VcjwA1aPLbVFiAFquyLToa0eqAjcytevf0BqrR/Ifp0nsZ2xbjfnNInfZ7kUOA1pERMYzGnowg+NFhTBHrHLKqU7QcU6eDEb6JSQrLunXhxMq00wKccoFDLGJ6iLM96mCzxFZs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788943441195302.3247180331564; Wed, 9 Sep 2026 01:44:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4DtT-0008JI-Ln; Wed, 09 Sep 2026 04:42:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4DtR-0008Iy-Qo for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:57 -0400 Received: from mail-pl1-x62b.google.com ([2607:f8b0:4864:20::62b]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x4DtQ-0003KO-2b for qemu-devel@nongnu.org; Wed, 09 Sep 2026 04:42:57 -0400 Received: by mail-pl1-x62b.google.com with SMTP id d9443c01a7336-2d71d1cc8b2so42022575ad.1 for ; Wed, 09 Sep 2026 01:42:55 -0700 (PDT) Received: from duncan.localdomain (114-35-142-126.hinet-ip.hinet.net. [114.35.142.126]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2db56c2a1f1sm38328225ad.78.2026.09.09.01.42.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 01:42:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sifive.com; s=google; t=1788943374; x=1789548174; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=YGg/RvrSoKzoUlW9nA/79/jfYq8eoWdPwOwzok+Tzg4=; b=MOeuW42xf3w0f02RtiD5F2KkrjDHKbniAHcUSCT+Y8GcQAfpyvAeVHMVQ1RjX1xPti uRhBxEbbn1Mxkq/YAtgJjK8JUtDZYbMV4ZOmFpDAFSNy4j8yU2Y7V3a64RwmNjA1hcFl 1BVYFtF6PuFDVT3skukS4j+dUNUeh5FpLUpq5JYYqrd5bQ8Xcux7yLwPIZO8oaxdr9MS ksaTewBdYzg8aoIOSmtuKedPd4M3NQuqBquMVBkFQx7UraJroba6PM/vIqGnH3RSag4w IZZ/ia4JNkDmwtey/QnR4SilnoQCwUIkBUqNeCs/FGAZV17U2SzB6CFJIkpta6GXcRa7 cFBw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788943374; x=1789548174; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=YGg/RvrSoKzoUlW9nA/79/jfYq8eoWdPwOwzok+Tzg4=; b=tHeXWpOwg7OKsThBXoCG2nrRqrEiE0JMFkLWf7Jm5i1133MJuO7LekQK6haH6oee2m vM1Zok2Kg/F9UvdfHek6Eg/PYYcdRQi127U/Wbwf/0SAG5tVl6z3UYMPSGdf3L3cir5n HrywxFncsGS1U5YnSTXNWjdFWxA1QRDzWsideeKzbC8sT0EpwsB28WfI/tM5bu4lfDaZ xpAhKbEoWMQYc+ppI04DgX2z16yeVLZbeL/BrLHBzZEbRn0yADNBJv/KaGG6N6oFx1Iz MhNlq6uFWt9caLeqnthXYl6Ozuln26yG9T0J+rcE3g8eaYFr3NjKO0jO9kx3KtbxYOJD EbJA== X-Gm-Message-State: AFuF++mY5GVGqtqtSKDYEAB7vlOWr6DGERnBjBI1FFR5ULotZ40byimz 7Bt8sjNmj18112RZD9ejmndSKsMcfy+/MgmtzL4Qm8xPg3g4n+v/JZXCRaUHKAd/ePN7J4bjpv5 XHqodqBwxaylaFOrfQ+EDO/xO1f4QsQvtu8nwksSIf3mRsC7mRxE6R2OFPpHOJGT4sBUsKLsvsm pn5q7YIwEVQDuBZ5GFr+wy7jJE1yg914YgiBIZuIuNLA== X-Gm-Gg: AYBFou2FTkfKuqpUR+pf9fFHhdcQmR82KsbDIKAmtf+S8IBAe1MK21SWAeMqRdHxp4l Mm8aRokTlXoUbpVBttFz0novEHwSPh7Upl8noAghlf6AvPfHenxX/z+qmSP/DyCQSCaKTZz1k2G vhJmLVX3wRvZAIPsfsb/OT/s6TxBTgr8rm8gy3LCRirVVwCHmzHDqtkDNBXvBsTma5Nsxdg4+2a 0FOlyRUshB41jdHMxprPDynb+jIaBNJmN1hPRbFweqy6tY0/pr7NhluzTqhwFcR0V0H3Ph8RzHs 46pmR3s6TTATCwICMgQpiRuxWkqn872f0VT3l0+G+MuWxqNIwvbTeI2DH2RhIB5BeeD7A/NflP2 IqMerYYfE03uWHfZJvcevcstF6tLWma2SXZl/bBr53Za1+ptHZxjRRT/YARRLWZvd33dWcF7rVb AIvbEnnR8qYrMrFpG9RvmqX7x4Lo/omfU85RkQkaxbUVJOHhIN6Pd0DO3zDl4ghXD6UCYyHjJqU d27k0RXBwKhDP2jD8UghxqkxRgCzDPmVETmFahw4JhY0muCSfG4Y/i9WsdlZ2mkJCg1UgN97ko= X-Received: by 2002:a17:903:1ae3:b0:2d9:54:fc69 with SMTP id d9443c01a7336-2db1247f4d0mr487022885ad.7.1788943374212; Wed, 09 Sep 2026 01:42:54 -0700 (PDT) From: Max Chou To: qemu-devel@nongnu.org, qemu-riscv@nongnu.org, richard.henderson@linaro.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , Max Chou Subject: [PATCH 6/6] tests/tcg/riscv64: Add vector segment PMP region spanning test Date: Wed, 9 Sep 2026 16:41:53 +0800 Message-ID: <20260909084154.223529-7-max.chou@sifive.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260909084154.223529-1-max.chou@sifive.com> References: <20260909084154.223529-1-max.chou@sifive.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::62b; envelope-from=max.chou@sifive.com; helo=mail-pl1-x62b.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @sifive.com) X-ZM-MESSAGEID: 1788943443123158500 Content-Type: text/plain; charset="utf-8" A segment load performs nf independent eew-sized accesses, so PMP checks each field on its own. Probing the whole nf * eew segment as one range instead reports a fault whenever a PMP boundary falls inside a segment. Signed-off-by: Max Chou --- tests/tcg/riscv64/Makefile.softmmu-target | 21 +++- tests/tcg/riscv64/test-rvv-ldst-seg-pmp.S | 141 ++++++++++++++++++++++ 2 files changed, 160 insertions(+), 2 deletions(-) create mode 100644 tests/tcg/riscv64/test-rvv-ldst-seg-pmp.S diff --git a/tests/tcg/riscv64/Makefile.softmmu-target b/tests/tcg/riscv64/= Makefile.softmmu-target index 93c4e58e0c2..aea1e7fcb15 100644 --- a/tests/tcg/riscv64/Makefile.softmmu-target +++ b/tests/tcg/riscv64/Makefile.softmmu-target @@ -87,7 +87,8 @@ test-vle32ff: CFLAGS +=3D -march=3Drv64gcv =20 RVV_LDST_MARCH =3D -march=3Drv64gcv RVV_LDST_TESTS =3D test-rvv-ldst-ff-pmp test-rvv-ldst-us-pmp \ - test-rvv-ldst-ff-page + test-rvv-ldst-ff-page \ + test-rvv-ldst-seg-pmp CLEANFILES +=3D $(RVV_LDST_TESTS) =20 $(RVV_LDST_TESTS): %: %.S rvv-ldst.inc $(LINK_SCRIPT) @@ -95,7 +96,8 @@ $(RVV_LDST_TESTS): %: %.S rvv-ldst.inc $(LINK_SCRIPT) $(LD) $(LDFLAGS) $@.o -o $@ =20 EXTRA_RUNS +=3D run-test-rvv-ldst-ff-pmp run-test-rvv-ldst-us-pmp \ - run-test-rvv-ldst-ff-page + run-test-rvv-ldst-ff-page \ + run-test-rvv-ldst-seg-pmp =20 run-test-rvv-ldst-ff-pmp: test-rvv-ldst-ff-pmp $(call run-test, $<, $(QEMU) -cpu rv64$(comma)v=3Dtrue$(comma)vlen=3D128$= (comma)elen=3D64$(comma)vext_spec=3Dv1.0$(comma)rvv_ta_all_1s=3Dtrue$(comma= )rvv_ma_all_1s=3Dtrue $(QEMU_OPTS)$<) @@ -106,5 +108,20 @@ run-test-rvv-ldst-us-pmp: test-rvv-ldst-us-pmp run-test-rvv-ldst-ff-page: test-rvv-ldst-ff-page $(call run-test, $<, $(QEMU) -cpu rv64$(comma)v=3Dtrue$(comma)vlen=3D128$= (comma)elen=3D64$(comma)vext_spec=3Dv1.0 $(QEMU_OPTS)$<) =20 +run-test-rvv-ldst-seg-pmp: test-rvv-ldst-seg-pmp + $(call run-test, $<, $(QEMU) -cpu rv64$(comma)v=3Dtrue$(comma)vlen=3D128$= (comma)elen=3D64$(comma)vext_spec=3Dv1.0 $(QEMU_OPTS)$<) + +PMP_TESTS =3D test-pmp-interior-entry +CLEANFILES +=3D $(PMP_TESTS) + +$(PMP_TESTS): %: %.S rvv-ldst.inc $(LINK_SCRIPT) + $(CC) $(CFLAGS) -march=3Drv64gc_zicboz $< -Wa,--noexecstack -c -o $@.o + $(LD) $(LDFLAGS) $@.o -o $@ + +EXTRA_RUNS +=3D run-test-pmp-interior-entry + +run-test-pmp-interior-entry: test-pmp-interior-entry + $(call run-test, $<, $(QEMU) -cpu rv64$(comma)zicboz=3Dtrue$(comma)cboz_b= locksize=3D64 $(QEMU_OPTS)$<) + # We don't currently support the multiarch system tests undefine MULTIARCH_TESTS diff --git a/tests/tcg/riscv64/test-rvv-ldst-seg-pmp.S b/tests/tcg/riscv64/= test-rvv-ldst-seg-pmp.S new file mode 100644 index 00000000000..9b3703ba338 --- /dev/null +++ b/tests/tcg/riscv64/test-rvv-ldst-seg-pmp.S @@ -0,0 +1,141 @@ +/* + * RISC-V vector segment load spanning two PMP regions + * + * A segment load performs nf independent eew-sized accesses, so each + * field is checked against PMP on its own. A probe that presents the + * whole nf * eew segment as one range instead reports a fault whenever + * a PMP boundary falls inside the segment, even though every access the + * instruction actually performs is permitted. + * + * PMP layout (locked entries, lowest number wins; everything outside + * the test page is unmatched and so fully accessible from M-mode): + * pmp0: NA4 buf+0, L, R-- field 0 readable + * pmp1: NA4 buf+4, L, R-- field 1 readable, adjacent to pmp0 + * pmp2: NAPOT test page, L, RW- lower-priority page allow + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + #include "rvv-ldst.inc" + + .text + .global _start +_start: + RVV_ENABLE + lla t0, trap_handler + csrw mtvec, t0 + + /* + * Trap handler protocol: + * s0: expected mcause (0: no trap expected) + * s1: expected mtval (-1: any mtval accepted) + * s2: traps taken s3: vstart seen at last trap + * s4: traps expected s5: mtval seen at last trap + */ + li s0, 0 + li s1, 0 + li s2, 0 + li s3, -1 + li s4, 0 + + /* Program the locked PMP entries; single locking cfg write last. */ + lla t0, buf + srli t0, t0, 2 + csrw pmpaddr0, t0 + lla t0, buf + 4 + srli t0, t0, 2 + csrw pmpaddr1, t0 + lla t0, pmp_page + srli t0, t0, 2 + ori t0, t0, 0x1ff + csrw pmpaddr2, t0 + li t0, 0x9b9191 + csrw pmpcfg0, t0 + + /* Case 1: a 4-byte load fully inside pmp0 is granted. */ + CASE 1 + lla t1, buf + lw t0, 0(t1) + CHECK_NO_TRAP + ASSERT_EQ t0, 0x00dd0000 + + /* Case 2: a 4-byte load fully inside pmp1 is granted. */ + CASE 2 + lla t1, buf + lw t0, 4(t1) + CHECK_NO_TRAP + ASSERT_EQ t0, 0x00dd0001 + + /* + * Case 3: control. One 8-byte access covers both entries and is + * contained by neither, so it must fault however permissive the + * two entries are on their own. + */ + CASE 3 + li s0, 5 + lla s1, buf + lla t1, buf + ld t0, 0(t1) + CHECK_TRAP + + /* + * Case 4: vlseg2e32.v performs one 4-byte access per field, each + * contained by its own entry, so the segment must load. A probe + * covering the whole 8-byte segment reports a load access fault + * here instead. + */ + CASE 4 + PREFILL + vsetivli zero, 1, e32, m1, ta, ma + lla a0, buf + vlseg2e32.v v2, (a0) + CHECK_NO_TRAP + CHECK_VELEM v2, 0, 0x00dd0000 + CHECK_VELEM v3, 0, 0x00dd0001 + + /* + * Case 5: the same on the fault-only-first path, which must not + * truncate vl either. + */ + CASE 5 + PREFILL + vsetivli zero, 1, e32, m1, ta, ma + lla a0, buf + vlseg2e32ff.v v2, (a0) + csrr t2, vl + CHECK_NO_TRAP + ASSERT_EQ t2, 1 + CHECK_VELEM v2, 0, 0x00dd0000 + CHECK_VELEM v3, 0, 0x00dd0001 + + li a0, 0 +exit: + SEMI_EXIT + FAIL + + .balign 4 +trap_handler: + csrr t5, mcause + bne t5, s0, fail + csrr s5, mtval + li t5, -1 + beq s1, t5, 1f + bne s5, s1, fail +1: + csrr s3, vstart + addi s2, s2, 1 + csrw vstart, zero + csrr t5, mepc + addi t5, t5, 4 + csrw mepc, t5 + mret + + .data + .balign 16 +semiargs: .space 16 + + /* One dedicated page governed by the locked NAPOT RW entry. */ + .balign 4096 +pmp_page: +buf: + .word 0x00dd0000, 0x00dd0001, 0x00dd0002, 0x00dd0003 + .skip 4080 --=20 2.43.0