From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id D6628CA1009 for ; Wed, 3 Sep 2025 20:14:19 +0000 (UTC) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1uttrj-0000Vd-RX; Wed, 03 Sep 2025 16:13:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uttrc-0000U4-6I for qemu-riscv@nongnu.org; Wed, 03 Sep 2025 16:13:56 -0400 Received: from mail-pj1-x102d.google.com ([2607:f8b0:4864:20::102d]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1uttrT-0002ix-SJ for qemu-riscv@nongnu.org; Wed, 03 Sep 2025 16:13:49 -0400 Received: by mail-pj1-x102d.google.com with SMTP id 98e67ed59e1d1-32326793a85so167059a91.1 for ; Wed, 03 Sep 2025 13:13:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ventanamicro.com; s=google; t=1756930421; x=1757535221; darn=nongnu.org; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=Z8oR7Ug/NBOYS0ZxmroGQfUtno2HikxnOcrwBNJDARM=; b=FWW4FJn8KXBKM+GrSYZ9no6yiNtK8bxahMoFypUUN6RF2RecqA09vxgdQBiKjrHVFg sY7FDfEyqGxv0dLDivRr4TQT4x9M9624/MYc2OjZYUihvBB1tRSXUtDONHtY9u84tvHM 42sXCtCHD0Qg8hy2jcxjhb945T2cI0O6BugF8AX6tKvj7V1vKSCLvky85Oc6DvTKoI3b san7pPy9xZwXEGdexq19/iyIJNHbbyc3FL0K1uD9VFvbv573J+7hK/jhXEXlvHA0cOxC sZM5IMmlSQc/i98vfcwcKzttUOpYw26J51fKF2IjVlfB9hjqx6ASLqOlt4xKvGbsKn8V ZcSg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1756930421; x=1757535221; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=Z8oR7Ug/NBOYS0ZxmroGQfUtno2HikxnOcrwBNJDARM=; b=BvPkHV1iSnJnINTwCg9eidr8pY9cN4ZyG2kScT7FYcfjRBstruqhIQA0PXJmOEpwxN Bv821Wc+3ZrANGeiDRwlQY6CjMZ0ApUv9flugutQJUTFXJm2PuDjcQ8NhHk/GAB53CuP jLEPTAWtuvL8yyH0Rpn41Ea1vnP5GfeAMzeKWNk7MFC/Sf6SbRSg5kQbBjz+I2A9zVFf ofJK+HP7euxqelj3tC0HjWr7HwKhJjRggg4IGd4n8RchgVt/r5m8hK2CinFnabCTEpDs kiUvtLDdlDr42jgGQzfu7SgfR6ZC58vR/YlOgXptegXsnsBjAVbnOlo5JzO0AXaXTRoV XqSw== X-Forwarded-Encrypted: i=1; AJvYcCXv8xYRdUL5sdx50xsT3y6q+5FGls7ykStGSzJ8iMYMRd/3yyYQMMTXOxWFs0LXO/LfGl9if3PMT8O2@nongnu.org X-Gm-Message-State: AOJu0Yyd+nRk9dHvxoOF6RzMvCodcWynyJQ9jeQTzCjOU5UtDXFU+qYB ddZzW/wTvPKW6BFXrSiieKVT5H/fUvQ5F+Aap1mNCTs32mvX/6gGAjPlrGMK7MFsK/I= X-Gm-Gg: ASbGncvlJvxfYB6/TFt9q8vaBI3DcPQCuIwerZHSIbKSz5OdI2ZUtjTH0rGZXwz4RWB RkV1LqadOQSZA5q3Y6oia/PvxI0wF1yza91EweKLSpmUmZPK/E8vWg8Bqv9amcMLjvP6BNxgXCE 9JrCF2BVr2L6EQ8o6h9+ZvuI9rWv4gCZgw6xEYQybFfB4sexZ43bLE8afWpVFQOYDjIsZs7tC3i DQLNsa8ppDS59YkYbADYI/emsYRhp5ojmTvQGtK7MVhOmGskgTmlcder9vPjigG4CaEOVamA2l/ cr7nUYDq6VVGFH1axlq9Sl7FIefqRJfTUgW3jS3/m1bwlWyYt/RToODjgIdYrgqu/2nIP1b6XAB 9lmGkE4Ia5I5kqxxfSIls5BCYBPVhlcXpJvsxPs9m97J7YfU= X-Google-Smtp-Source: AGHT+IH6lyJIqKNClqanASQizB/0VF5Kcvuuvw8f/faiT7LrhBlLXCWtptmMbwZJ3BXuvduUv3DIOg== X-Received: by 2002:a17:90b:1642:b0:32b:6132:5f94 with SMTP id 98e67ed59e1d1-32b61326258mr4103392a91.21.1756930421459; Wed, 03 Sep 2025 13:13:41 -0700 (PDT) Received: from [192.168.68.110] ([187.10.187.251]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-b4cd28adc00sm15228576a12.32.2025.09.03.13.13.38 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 03 Sep 2025 13:13:41 -0700 (PDT) Message-ID: <6bff4c9d-1da4-40b3-901a-789923d8ef7e@ventanamicro.com> Date: Wed, 3 Sep 2025 17:13:36 -0300 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH 2/3] target/risvc: Fix vector whole ldst vstart check To: Nicholas Piggin , qemu-riscv@nongnu.org Cc: Palmer Dabbelt , Alistair Francis , Weiwei Li , Liu Zhiwei , qemu-devel@nongnu.org, Chao Liu , Nicholas Joaquin , Ganesh Valliappan References: <20250903030114.274535-1-npiggin@gmail.com> <20250903030114.274535-3-npiggin@gmail.com> From: Daniel Henrique Barboza Content-Language: en-US In-Reply-To: <20250903030114.274535-3-npiggin@gmail.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Received-SPF: pass client-ip=2607:f8b0:4864:20::102d; envelope-from=dbarboza@ventanamicro.com; helo=mail-pj1-x102d.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-riscv@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-riscv-bounces+qemu-riscv=archiver.kernel.org@nongnu.org Sender: qemu-riscv-bounces+qemu-riscv=archiver.kernel.org@nongnu.org Hi Nick, ^ typo in the patch subject: s/risvc/riscv On 9/3/25 12:01 AM, Nicholas Piggin wrote: > The whole vector ldst instructions do not include a vstart check, > so an overflowed vstart can result in an underflowed memory address > offset and crash: > > accel/tcg/cputlb.c:1465:probe_access_flags: > assertion failed: (-(addr | TARGET_PAGE_MASK) >= size) > > Add the VSTART_CHECK_EARLY_EXIT() check for these helpers. > > This was found with a verification test generator based on RiESCUE. > > Reported-by: Nicholas Joaquin > Reported-by: Ganesh Valliappan > Signed-off-by: Nicholas Piggin > --- > target/riscv/vector_helper.c | 2 + > tests/tcg/riscv64/Makefile.target | 5 ++ > tests/tcg/riscv64/test-vstart-overflow.c | 75 ++++++++++++++++++++++++ > 3 files changed, 82 insertions(+) > create mode 100644 tests/tcg/riscv64/test-vstart-overflow.c > > diff --git a/target/riscv/vector_helper.c b/target/riscv/vector_helper.c > index fc85a34a84..e0e8735000 100644 > --- a/target/riscv/vector_helper.c > +++ b/target/riscv/vector_helper.c > @@ -825,6 +825,8 @@ vext_ldst_whole(void *vd, target_ulong base, CPURISCVState *env, uint32_t desc, > uint32_t esz = 1 << log2_esz; > int mmu_index = riscv_env_mmu_index(env, false); > > + VSTART_CHECK_EARLY_EXIT(env, evl); > + > /* Calculate the page range of first page */ > addr = base + (env->vstart << log2_esz); > page_split = -(addr | TARGET_PAGE_MASK); > diff --git a/tests/tcg/riscv64/Makefile.target b/tests/tcg/riscv64/Makefile.target > index 4da5b9a3b3..19a49b6467 100644 > --- a/tests/tcg/riscv64/Makefile.target > +++ b/tests/tcg/riscv64/Makefile.target > @@ -18,3 +18,8 @@ TESTS += test-fcvtmod > test-fcvtmod: CFLAGS += -march=rv64imafdc > test-fcvtmod: LDFLAGS += -static > run-test-fcvtmod: QEMU_OPTS += -cpu rv64,d=true,zfa=true > + > +# Test for vstart >= vl > +TESTS += test-vstart-overflow > +test-vstart-overflow: CFLAGS += -march=rv64gcv > +run-test-vstart-overflow: QEMU_OPTS += -cpu rv64,v=on > diff --git a/tests/tcg/riscv64/test-vstart-overflow.c b/tests/tcg/riscv64/test-vstart-overflow.c > new file mode 100644 > index 0000000000..72999f2c8a > --- /dev/null > +++ b/tests/tcg/riscv64/test-vstart-overflow.c > @@ -0,0 +1,75 @@ > +/* > + * Test for VSTART set to overflow VL > + * > + * TCG vector instructions should call VSTART_CHECK_EARLY_EXIT() to check > + * this case, otherwise memory addresses can underflow and misbehave or > + * crash QEMU. > + * > + * TODO: Add stores and other instructions. > + * > + * SPDX-License-Identifier: GPL-2.0-or-later > + */ > +#include > +#include The fix in vector_helper.c is fine but this patch (and patch 3) won't execute 'make check-tcg'. It complains about this header being missing in the docker env. To eliminate the possibility of my env being the problem I ran this series in Gitlab. Same error: https://gitlab.com/danielhb/qemu/-/jobs/11236091281 /builds/danielhb/qemu/tests/tcg/riscv64/test-vstart-overflow.c:13:10: fatal error: riscv_vector.h: No such file or directory 3899 13 | #include 3900 | ^~~~~~~~~~~~~~~~ 3901 compilation terminated. 3902 make[1]: *** [Makefile:122: test-vstart-overflow] Error 1 I believe you need to add the Docker changes you made in this patch. Same thing for patch 3. And same thing for patch 4 of: [PATCH 0/4] linux-user/riscv: add vector state to signal Given that you're also using riscv_vector.h in there too. Thanks, Daniel > + > +#define VSTART_OVERFLOW_TEST(insn) \ > +({ \ > + uint8_t vmem[64] = { 0 }; \ > + uint64_t vstart; \ > + asm volatile(" \r\n \ > + # Set VL=52 and VSTART=56 \r\n \ > + li t0, 52 \r\n \ > + vsetvli x0, t0, e8, m4, ta, ma \r\n \ > + li t0, 56 \r\n \ > + csrrw x0, vstart, t0 \r\n \ > + li t1, 64 \r\n \ > + " insn " \r\n \ > + csrr %0, vstart \r\n \ > + " : "=r"(vstart), "+A"(vmem) :: "t0", "t1", "v24", "memory"); \ > + vstart; \ > +}) > + > +int run_vstart_overflow_tests() > +{ > + /* > + * An implementation is permitted to raise an illegal instruction > + * exception when executing a vector instruction if vstart is set to a > + * value that could not be produced by the execution of that instruction > + * with the same vtype. If TCG is changed to do this, then this test > + * could be updated to handle the SIGILL. > + */ > + if (VSTART_OVERFLOW_TEST("vl1re16.v v24, %1")) { > + return 1; > + } > + > + if (VSTART_OVERFLOW_TEST("vs1r.v v24, %1")) { > + return 1; > + } > + > + if (VSTART_OVERFLOW_TEST("vle16.v v24, %1")) { > + return 1; > + } > + > + if (VSTART_OVERFLOW_TEST("vse16.v v24, %1")) { > + return 1; > + } > + > + if (VSTART_OVERFLOW_TEST("vluxei8.v v24, %1, v20")) { > + return 1; > + } > + > + if (VSTART_OVERFLOW_TEST("vlse16.v v24, %1, t1")) { > + return 1; > + } > + > + if (VSTART_OVERFLOW_TEST("vlseg2e8.v v24, %1")) { > + return 1; > + } > + > + return 0; > +} > + > +int main() > +{ > + return run_vstart_overflow_tests(); > +}