All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 5/5] target/riscv: enforce SSE precedence for ssp CSR access
  2026-08-23 13:14 [PATCH 0/5] target/riscv: fix CFI and envcfg CSR handling wangyang25
                   ` (3 preceding siblings ...)
  2026-08-23 13:14 ` [PATCH 1/5] target/riscv: make mnstatus.MNPELP writable with Zicfilp wangyang25
@ 2026-08-23 13:14 ` wangyang25
  4 siblings, 0 replies; 10+ messages in thread
From: wangyang25 @ 2026-08-23 13:14 UTC (permalink / raw)
  To: qemu-devel
  Cc: qemu-riscv, palmer, alistair.francis, liwei1518, daniel.barboza,
	zhiwei_liu, chao.liu

When menvcfg.SSE is clear, ssp access below M mode raises an
illegal-instruction exception before virtual-instruction classification.
Apply the henvcfg/senvcfg checks for VS/VU and preserve the user-only
path.
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4226

Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>
---
 target/riscv/tcg/csr.c | 29 ++++++++++++++++++++++++-----
 1 file changed, 24 insertions(+), 5 deletions(-)

diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c
index fd00538..17a6fc1 100644
--- a/target/riscv/tcg/csr.c
+++ b/target/riscv/tcg/csr.c
@@ -201,15 +201,34 @@ static RISCVException cfi_ss(CPURISCVState *env, int csrno)
         return RISCV_EXCP_NONE;
     }
 
-    /* if bcfi not active for current env, access to csr is illegal */
-    if (!cpu_get_bcfien(env)) {
 #if !defined(CONFIG_USER_ONLY)
-        if (env->debugger) {
-            return RISCV_EXCP_NONE;
-        } else if (env->virt_enabled) {
+    if (env->debugger) {
+        return RISCV_EXCP_NONE;
+    }
+
+    /* priv < M and menvcfg.SSE = 0 must raise illegal-instruction */
+    if (!(env->menvcfg & MENVCFG_SSE)) {
+        return RISCV_EXCP_ILLEGAL_INST;
+    }
+
+    if (env->virt_enabled) {
+        if (env->priv == PRV_S) {
+            if (env->henvcfg & HENVCFG_SSE) {
+                return RISCV_EXCP_NONE;
+            }
+            return RISCV_EXCP_VIRT_INSTRUCTION_FAULT;
+        }
+        if (env->priv == PRV_U) {
+            if ((env->henvcfg & HENVCFG_SSE) &&
+                (env->senvcfg & SENVCFG_SSE)) {
+                return RISCV_EXCP_NONE;
+            }
             return RISCV_EXCP_VIRT_INSTRUCTION_FAULT;
         }
+    }
 #endif
+
+    if (!cpu_get_bcfien(env)) {
         return RISCV_EXCP_ILLEGAL_INST;
     }
 
-- 
2.55.0.windows.2


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [PATCH 3/5] target/riscv: mask inactive senvcfg.SSE on read
  2026-08-23 13:14 [PATCH 0/5] target/riscv: fix CFI and envcfg CSR handling wangyang25
  2026-08-23 13:14 ` [PATCH 4/5] target/riscv: gate envcfg CBO fields on extensions wangyang25
  2026-08-23 13:14 ` [PATCH 2/5] target/riscv: save ELP in MPELP for RNMI exceptions wangyang25
@ 2026-08-23 13:14 ` wangyang25
  2026-08-23 13:14 ` [PATCH 1/5] target/riscv: make mnstatus.MNPELP writable with Zicfilp wangyang25
  2026-08-23 13:14 ` [PATCH 5/5] target/riscv: enforce SSE precedence for ssp CSR access wangyang25
  4 siblings, 0 replies; 10+ messages in thread
From: wangyang25 @ 2026-08-23 13:14 UTC (permalink / raw)
  To: qemu-devel
  Cc: qemu-riscv, palmer, alistair.francis, liwei1518, daniel.barboza,
	zhiwei_liu, chao.liu

The CFI rules make senvcfg.SSE read as zero when menvcfg.SSE is clear.
In VU mode it also reads as zero when henvcfg.SSE is clear. Mask the
readback to match those rules.
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4224

Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>
---
 target/riscv/tcg/csr.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c
index 5ffd858..7078736 100644
--- a/target/riscv/tcg/csr.c
+++ b/target/riscv/tcg/csr.c
@@ -3305,6 +3305,14 @@ static RISCVException read_senvcfg(CPURISCVState *env, int csrno,
     }
 
     *val = env->senvcfg;
+
+    if (env_archcpu(env)->cfg.ext_zicfiss) {
+        if (!(env->menvcfg & MENVCFG_SSE) ||
+            (env->virt_enabled && !(env->henvcfg & HENVCFG_SSE))) {
+            *val &= ~SENVCFG_SSE;
+        }
+    }
+
     return RISCV_EXCP_NONE;
 }
 
-- 
2.55.0.windows.2


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [PATCH 0/5] target/riscv: fix CFI and envcfg CSR handling
@ 2026-08-23 13:14 wangyang25
  2026-08-23 13:14 ` [PATCH 4/5] target/riscv: gate envcfg CBO fields on extensions wangyang25
                   ` (4 more replies)
  0 siblings, 5 replies; 10+ messages in thread
From: wangyang25 @ 2026-08-23 13:14 UTC (permalink / raw)
  To: qemu-devel
  Cc: qemu-riscv, palmer, alistair.francis, liwei1518, daniel.barboza,
	zhiwei_liu, chao.liu

This series fixes five independent RISC-V CSR and trap-handling defects.

The patches cover:

 - making mnstatus.MNPELP writable when Zicfilp is implemented;
 - saving ELP in mstatus.MPELP for M-mode RNMI exceptions;
 - masking inactive senvcfg.SSE on readback;
 - gating envcfg CBO fields on Zicbom and Zicboz;
 - enforcing menvcfg.SSE precedence for ssp CSR access.

Each patch includes a corresponding GitLab Work Item and a Signed-off-by
line. The reports were found with an automated differential/emulation tool
and manually triaged against QEMU master eea8fe61b8be.

The witness families were rerun on the Linux x86_64 execution plane. The
patches apply cleanly and pass git diff --check and checkpatch.pl with zero
errors and zero warnings.

wangyang (5):
  target/riscv: make mnstatus.MNPELP writable with Zicfilp
  target/riscv: save ELP in MPELP for RNMI exceptions
  target/riscv: mask inactive senvcfg.SSE on read
  target/riscv: gate envcfg CBO fields on extensions
  target/riscv: enforce SSE precedence for ssp CSR access

 target/riscv/tcg/cpu_helper.c |  7 +---
 target/riscv/tcg/csr.c        | 79 +++++++++++++++++++++++++++++++----
 2 files changed, 71 insertions(+), 15 deletions(-)

-- 
2.55.0.windows.2

^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH 1/5] target/riscv: make mnstatus.MNPELP writable with Zicfilp
  2026-08-23 13:14 [PATCH 0/5] target/riscv: fix CFI and envcfg CSR handling wangyang25
                   ` (2 preceding siblings ...)
  2026-08-23 13:14 ` [PATCH 3/5] target/riscv: mask inactive senvcfg.SSE on read wangyang25
@ 2026-08-23 13:14 ` wangyang25
  2026-09-03  5:40   ` Alistair Francis
  2026-08-23 13:14 ` [PATCH 5/5] target/riscv: enforce SSE precedence for ssp CSR access wangyang25
  4 siblings, 1 reply; 10+ messages in thread
From: wangyang25 @ 2026-08-23 13:14 UTC (permalink / raw)
  To: qemu-devel
  Cc: qemu-riscv, palmer, alistair.francis, liwei1518, daniel.barboza,
	zhiwei_liu, chao.liu

Zicfilp adds MNPELP to mnstatus, and MNRET consumes it when restoring ELP.
Include the field in write_mnstatus() when Zicfilp is implemented.
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4222

Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>
---
 target/riscv/tcg/csr.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c
index 36f2004..5ffd858 100644
--- a/target/riscv/tcg/csr.c
+++ b/target/riscv/tcg/csr.c
@@ -5563,6 +5563,10 @@ static RISCVException write_mnstatus(CPURISCVState *env, int csrno,
         mask |= MNSTATUS_MNPV;
     }
 
+    if (env_archcpu(env)->cfg.ext_zicfilp) {
+        mask |= MNSTATUS_MNPELP;
+    }
+
     /* mnstatus.mnie can only be cleared by hardware. */
     env->mnstatus = (env->mnstatus & MNSTATUS_NMIE) | (val & mask);
     return RISCV_EXCP_NONE;
-- 
2.55.0.windows.2


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [PATCH 2/5] target/riscv: save ELP in MPELP for RNMI exceptions
  2026-08-23 13:14 [PATCH 0/5] target/riscv: fix CFI and envcfg CSR handling wangyang25
  2026-08-23 13:14 ` [PATCH 4/5] target/riscv: gate envcfg CBO fields on extensions wangyang25
@ 2026-08-23 13:14 ` wangyang25
  2026-09-03  5:46   ` Alistair Francis
  2026-08-23 13:14 ` [PATCH 3/5] target/riscv: mask inactive senvcfg.SSE on read wangyang25
                   ` (2 subsequent siblings)
  4 siblings, 1 reply; 10+ messages in thread
From: wangyang25 @ 2026-08-23 13:14 UTC (permalink / raw)
  To: qemu-devel
  Cc: qemu-riscv, palmer, alistair.francis, liwei1518, daniel.barboza,
	zhiwei_liu, chao.liu

An M-mode exception with mnstatus.NMIE clear uses the RNMI vector, but
Smrnmi otherwise specifies the normal M-mode state updates. MRET restores
ELP from mstatus.MPELP, so save it there rather than in MNPELP.
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4223

Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>
---
 target/riscv/tcg/cpu_helper.c | 7 +------
 1 file changed, 1 insertion(+), 6 deletions(-)

diff --git a/target/riscv/tcg/cpu_helper.c b/target/riscv/tcg/cpu_helper.c
index 07d9222..6337e91 100644
--- a/target/riscv/tcg/cpu_helper.c
+++ b/target/riscv/tcg/cpu_helper.c
@@ -2275,12 +2275,7 @@ void riscv_cpu_do_interrupt(CPUState *cs)
         /* handle the trap in M-mode */
         /* save elp status */
         if (cpu_get_fcfien(env)) {
-            if (nnmi_excep) {
-                env->mnstatus = set_field(env->mnstatus, MNSTATUS_MNPELP,
-                                          env->elp);
-            } else {
-                env->mstatus = set_field(env->mstatus, MSTATUS_MPELP, env->elp);
-            }
+            env->mstatus = set_field(env->mstatus, MSTATUS_MPELP, env->elp);
         }
 
         if (riscv_has_ext(env, RVH)) {
-- 
2.55.0.windows.2


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [PATCH 4/5] target/riscv: gate envcfg CBO fields on extensions
  2026-08-23 13:14 [PATCH 0/5] target/riscv: fix CFI and envcfg CSR handling wangyang25
@ 2026-08-23 13:14 ` wangyang25
  2026-09-03  5:23   ` Alistair Francis
  2026-08-23 13:14 ` [PATCH 2/5] target/riscv: save ELP in MPELP for RNMI exceptions wangyang25
                   ` (3 subsequent siblings)
  4 siblings, 1 reply; 10+ messages in thread
From: wangyang25 @ 2026-08-23 13:14 UTC (permalink / raw)
  To: qemu-devel
  Cc: qemu-riscv, palmer, alistair.francis, liwei1518, daniel.barboza,
	zhiwei_liu, chao.liu

The envcfg CBO fields are provided by Zicbom and Zicboz. Keep them
read-only zero when the corresponding extension is absent in all three
envcfg CSRs.
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4225

Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>
---
 target/riscv/tcg/csr.c | 38 ++++++++++++++++++++++++++++++++++----
 1 file changed, 34 insertions(+), 4 deletions(-)

diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c
index 7078736..fd00538 100644
--- a/target/riscv/tcg/csr.c
+++ b/target/riscv/tcg/csr.c
@@ -3212,10 +3212,19 @@ static RISCVException write_menvcfg(CPURISCVState *env, int csrno,
                                     target_ulong val, uintptr_t ra)
 {
     const RISCVCPUConfig *cfg = riscv_cpu_cfg(env);
-    uint64_t mask = MENVCFG_FIOM | MENVCFG_CBIE | MENVCFG_CBCFE |
-                    MENVCFG_CBZE;
+    uint64_t mask = MENVCFG_FIOM;
     bool stce_changed = false;
 
+    /* CBIE/CBCFE are read-only zero when Zicbom is not implemented. */
+    if (cfg->ext_zicbom) {
+        mask |= MENVCFG_CBIE | MENVCFG_CBCFE;
+    }
+
+    /* CBZE is read-only zero when Zicboz is not implemented. */
+    if (cfg->ext_zicboz) {
+        mask |= MENVCFG_CBZE;
+    }
+
     if (riscv_cpu_mxl(env) == MXL_RV64) {
         mask |= (cfg->ext_svpbmt ? MENVCFG_PBMTE : 0) |
                 (cfg->ext_sstc ? MENVCFG_STCE : 0) |
@@ -3319,8 +3328,19 @@ static RISCVException read_senvcfg(CPURISCVState *env, int csrno,
 static RISCVException write_senvcfg(CPURISCVState *env, int csrno,
                                     target_ulong val, uintptr_t ra)
 {
-    uint64_t mask = SENVCFG_FIOM | SENVCFG_CBIE | SENVCFG_CBCFE | SENVCFG_CBZE;
+    uint64_t mask = SENVCFG_FIOM;
     RISCVException ret;
+
+    /* CBIE/CBCFE are read-only zero when Zicbom is not implemented. */
+    if (env_archcpu(env)->cfg.ext_zicbom) {
+        mask |= SENVCFG_CBIE | SENVCFG_CBCFE;
+    }
+
+    /* CBZE is read-only zero when Zicboz is not implemented. */
+    if (env_archcpu(env)->cfg.ext_zicboz) {
+        mask |= SENVCFG_CBZE;
+    }
+
     /* Update PMM field only if the value is valid according to Zjpm v1.0 */
     if (env_archcpu(env)->cfg.ext_ssnpm &&
         riscv_cpu_mxl(env) == MXL_RV64 &&
@@ -3377,7 +3397,7 @@ static RISCVException write_henvcfg(CPURISCVState *env, int csrno,
                                     target_ulong val, uintptr_t ra)
 {
     const RISCVCPUConfig *cfg = riscv_cpu_cfg(env);
-    uint64_t mask = HENVCFG_FIOM | HENVCFG_CBIE | HENVCFG_CBCFE | HENVCFG_CBZE;
+    uint64_t mask = HENVCFG_FIOM;
     RISCVException ret;
     bool stce_changed = false;
 
@@ -3386,6 +3406,16 @@ static RISCVException write_henvcfg(CPURISCVState *env, int csrno,
         return ret;
     }
 
+    /* CBIE/CBCFE are read-only zero when Zicbom is not implemented. */
+    if (cfg->ext_zicbom) {
+        mask |= HENVCFG_CBIE | HENVCFG_CBCFE;
+    }
+
+    /* CBZE is read-only zero when Zicboz is not implemented. */
+    if (cfg->ext_zicboz) {
+        mask |= HENVCFG_CBZE;
+    }
+
     if (riscv_cpu_mxl(env) == MXL_RV64) {
         mask |= env->menvcfg & (HENVCFG_PBMTE | HENVCFG_STCE | HENVCFG_ADUE |
                                 HENVCFG_DTE);
-- 
2.55.0.windows.2


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* Re: [PATCH 4/5] target/riscv: gate envcfg CBO fields on extensions
  2026-08-23 13:14 ` [PATCH 4/5] target/riscv: gate envcfg CBO fields on extensions wangyang25
@ 2026-09-03  5:23   ` Alistair Francis
  0 siblings, 0 replies; 10+ messages in thread
From: Alistair Francis @ 2026-09-03  5:23 UTC (permalink / raw)
  To: qemu-devel@nongnu.org, wangyang25@otcaix.iscas.ac.cn
  Cc: qemu-riscv@nongnu.org, palmer@dabbelt.com,
	daniel.barboza@oss.qualcomm.com, chao.liu@processmission.com,
	liwei1518@gmail.com, zhiwei_liu@linux.alibaba.com

On Sun, 2026-08-23 at 21:14 +0800, wangyang25@otcaix.iscas.ac.cn wrote:
> The envcfg CBO fields are provided by Zicbom and Zicboz. Keep them
> read-only zero when the corresponding extension is absent in all
> three
> envcfg CSRs.
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4225
> 
> Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>

Alistair

> ---
>  target/riscv/tcg/csr.c | 38 ++++++++++++++++++++++++++++++++++----
>  1 file changed, 34 insertions(+), 4 deletions(-)
> 
> diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c
> index 7078736..fd00538 100644
> --- a/target/riscv/tcg/csr.c
> +++ b/target/riscv/tcg/csr.c
> @@ -3212,10 +3212,19 @@ static RISCVException
> write_menvcfg(CPURISCVState *env, int csrno,
>                                      target_ulong val, uintptr_t ra)
>  {
>      const RISCVCPUConfig *cfg = riscv_cpu_cfg(env);
> -    uint64_t mask = MENVCFG_FIOM | MENVCFG_CBIE | MENVCFG_CBCFE |
> -                    MENVCFG_CBZE;
> +    uint64_t mask = MENVCFG_FIOM;
>      bool stce_changed = false;
>  
> +    /* CBIE/CBCFE are read-only zero when Zicbom is not implemented.
> */
> +    if (cfg->ext_zicbom) {
> +        mask |= MENVCFG_CBIE | MENVCFG_CBCFE;
> +    }
> +
> +    /* CBZE is read-only zero when Zicboz is not implemented. */
> +    if (cfg->ext_zicboz) {
> +        mask |= MENVCFG_CBZE;
> +    }
> +
>      if (riscv_cpu_mxl(env) == MXL_RV64) {
>          mask |= (cfg->ext_svpbmt ? MENVCFG_PBMTE : 0) |
>                  (cfg->ext_sstc ? MENVCFG_STCE : 0) |
> @@ -3319,8 +3328,19 @@ static RISCVException
> read_senvcfg(CPURISCVState *env, int csrno,
>  static RISCVException write_senvcfg(CPURISCVState *env, int csrno,
>                                      target_ulong val, uintptr_t ra)
>  {
> -    uint64_t mask = SENVCFG_FIOM | SENVCFG_CBIE | SENVCFG_CBCFE |
> SENVCFG_CBZE;
> +    uint64_t mask = SENVCFG_FIOM;
>      RISCVException ret;
> +
> +    /* CBIE/CBCFE are read-only zero when Zicbom is not implemented.
> */
> +    if (env_archcpu(env)->cfg.ext_zicbom) {
> +        mask |= SENVCFG_CBIE | SENVCFG_CBCFE;
> +    }
> +
> +    /* CBZE is read-only zero when Zicboz is not implemented. */
> +    if (env_archcpu(env)->cfg.ext_zicboz) {
> +        mask |= SENVCFG_CBZE;
> +    }
> +
>      /* Update PMM field only if the value is valid according to Zjpm
> v1.0 */
>      if (env_archcpu(env)->cfg.ext_ssnpm &&
>          riscv_cpu_mxl(env) == MXL_RV64 &&
> @@ -3377,7 +3397,7 @@ static RISCVException
> write_henvcfg(CPURISCVState *env, int csrno,
>                                      target_ulong val, uintptr_t ra)
>  {
>      const RISCVCPUConfig *cfg = riscv_cpu_cfg(env);
> -    uint64_t mask = HENVCFG_FIOM | HENVCFG_CBIE | HENVCFG_CBCFE |
> HENVCFG_CBZE;
> +    uint64_t mask = HENVCFG_FIOM;
>      RISCVException ret;
>      bool stce_changed = false;
>  
> @@ -3386,6 +3406,16 @@ static RISCVException
> write_henvcfg(CPURISCVState *env, int csrno,
>          return ret;
>      }
>  
> +    /* CBIE/CBCFE are read-only zero when Zicbom is not implemented.
> */
> +    if (cfg->ext_zicbom) {
> +        mask |= HENVCFG_CBIE | HENVCFG_CBCFE;
> +    }
> +
> +    /* CBZE is read-only zero when Zicboz is not implemented. */
> +    if (cfg->ext_zicboz) {
> +        mask |= HENVCFG_CBZE;
> +    }
> +
>      if (riscv_cpu_mxl(env) == MXL_RV64) {
>          mask |= env->menvcfg & (HENVCFG_PBMTE | HENVCFG_STCE |
> HENVCFG_ADUE |
>                                  HENVCFG_DTE);

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH 1/5] target/riscv: make mnstatus.MNPELP writable with Zicfilp
  2026-08-23 13:14 ` [PATCH 1/5] target/riscv: make mnstatus.MNPELP writable with Zicfilp wangyang25
@ 2026-09-03  5:40   ` Alistair Francis
  0 siblings, 0 replies; 10+ messages in thread
From: Alistair Francis @ 2026-09-03  5:40 UTC (permalink / raw)
  To: qemu-devel@nongnu.org, wangyang25@otcaix.iscas.ac.cn
  Cc: qemu-riscv@nongnu.org, palmer@dabbelt.com,
	daniel.barboza@oss.qualcomm.com, chao.liu@processmission.com,
	liwei1518@gmail.com, zhiwei_liu@linux.alibaba.com

On Sun, 2026-08-23 at 21:14 +0800, wangyang25@otcaix.iscas.ac.cn wrote:
> Zicfilp adds MNPELP to mnstatus, and MNRET consumes it when restoring
> ELP.
> Include the field in write_mnstatus() when Zicfilp is implemented.
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4222
> 
> Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>

Alistair

> ---
>  target/riscv/tcg/csr.c | 4 ++++
>  1 file changed, 4 insertions(+)
> 
> diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c
> index 36f2004..5ffd858 100644
> --- a/target/riscv/tcg/csr.c
> +++ b/target/riscv/tcg/csr.c
> @@ -5563,6 +5563,10 @@ static RISCVException
> write_mnstatus(CPURISCVState *env, int csrno,
>          mask |= MNSTATUS_MNPV;
>      }
>  
> +    if (env_archcpu(env)->cfg.ext_zicfilp) {
> +        mask |= MNSTATUS_MNPELP;
> +    }
> +
>      /* mnstatus.mnie can only be cleared by hardware. */
>      env->mnstatus = (env->mnstatus & MNSTATUS_NMIE) | (val & mask);
>      return RISCV_EXCP_NONE;

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH 2/5] target/riscv: save ELP in MPELP for RNMI exceptions
  2026-08-23 13:14 ` [PATCH 2/5] target/riscv: save ELP in MPELP for RNMI exceptions wangyang25
@ 2026-09-03  5:46   ` Alistair Francis
  2026-09-03  7:54     ` Wang Yang
  0 siblings, 1 reply; 10+ messages in thread
From: Alistair Francis @ 2026-09-03  5:46 UTC (permalink / raw)
  To: qemu-devel@nongnu.org, wangyang25@otcaix.iscas.ac.cn
  Cc: qemu-riscv@nongnu.org, palmer@dabbelt.com,
	daniel.barboza@oss.qualcomm.com, chao.liu@processmission.com,
	liwei1518@gmail.com, zhiwei_liu@linux.alibaba.com

On Sun, 2026-08-23 at 21:14 +0800, wangyang25@otcaix.iscas.ac.cn wrote:
> An M-mode exception with mnstatus.NMIE clear uses the RNMI vector,
> but
> Smrnmi otherwise specifies the normal M-mode state updates. MRET
> restores
> ELP from mstatus.MPELP, so save it there rather than in MNPELP.

This commit message isn't really clear. What are you fixing?

Alistair

> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4223
> 
> Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>
> ---
>  target/riscv/tcg/cpu_helper.c | 7 +------
>  1 file changed, 1 insertion(+), 6 deletions(-)
> 
> diff --git a/target/riscv/tcg/cpu_helper.c
> b/target/riscv/tcg/cpu_helper.c
> index 07d9222..6337e91 100644
> --- a/target/riscv/tcg/cpu_helper.c
> +++ b/target/riscv/tcg/cpu_helper.c
> @@ -2275,12 +2275,7 @@ void riscv_cpu_do_interrupt(CPUState *cs)
>          /* handle the trap in M-mode */
>          /* save elp status */
>          if (cpu_get_fcfien(env)) {
> -            if (nnmi_excep) {
> -                env->mnstatus = set_field(env->mnstatus,
> MNSTATUS_MNPELP,
> -                                          env->elp);
> -            } else {
> -                env->mstatus = set_field(env->mstatus,
> MSTATUS_MPELP, env->elp);
> -            }
> +            env->mstatus = set_field(env->mstatus, MSTATUS_MPELP,
> env->elp);
>          }
>  
>          if (riscv_has_ext(env, RVH)) {

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH 2/5] target/riscv: save ELP in MPELP for RNMI exceptions
  2026-09-03  5:46   ` Alistair Francis
@ 2026-09-03  7:54     ` Wang Yang
  0 siblings, 0 replies; 10+ messages in thread
From: Wang Yang @ 2026-09-03  7:54 UTC (permalink / raw)
  To: Alistair.Francis, qemu-devel
  Cc: qemu-riscv, palmer, daniel.barboza, chao.liu, liwei1518,
	zhiwei_liu

Hi Alistair,

Thank you for the feedback, and sorry that the commit message was unclear.

This patch fixes the Smrnmi and Zicfilp case where an M-mode exception occurs with mnstatus.NMIE=0. QEMU currently saves ELP in mnstatus.MNPELP when redirecting to the RNMI exception vector, but this path returns with MRET, which restores ELP from mstatus.MPELP. As a result, ELP is lost and a subsequent indirect branch requiring a landing pad may avoid the expected software-check exception. The patch saves ELP in mstatus.MPELP for this path; the true RNMI interrupt path using MNPELP and MNRET is unchanged.

I also found that Zephyr Li has submitted an equivalent fix, including a TCG regression test: https://www.mail-archive.com/qemu-devel@nongnu.org/msg1222084.html. Since that patch fixes the same issue, I will not submit a duplicate revision. Please let me know if any further clarification is needed.

Best regards,
Wang Yang



^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-09-03  7:54 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-23 13:14 [PATCH 0/5] target/riscv: fix CFI and envcfg CSR handling wangyang25
2026-08-23 13:14 ` [PATCH 4/5] target/riscv: gate envcfg CBO fields on extensions wangyang25
2026-09-03  5:23   ` Alistair Francis
2026-08-23 13:14 ` [PATCH 2/5] target/riscv: save ELP in MPELP for RNMI exceptions wangyang25
2026-09-03  5:46   ` Alistair Francis
2026-09-03  7:54     ` Wang Yang
2026-08-23 13:14 ` [PATCH 3/5] target/riscv: mask inactive senvcfg.SSE on read wangyang25
2026-08-23 13:14 ` [PATCH 1/5] target/riscv: make mnstatus.MNPELP writable with Zicfilp wangyang25
2026-09-03  5:40   ` Alistair Francis
2026-08-23 13:14 ` [PATCH 5/5] target/riscv: enforce SSE precedence for ssp CSR access wangyang25

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.