Skip to content

fix(riscv): reject RV32-only counter-high CSRs on RV64 - #235

Closed
carlosqwqqwq wants to merge 2 commits into
HexRaysSA:masterfrom
carlosqwqqwq:fix-riscv-csr-availability
Closed

fix(riscv): reject RV32-only counter-high CSRs on RV64#235
carlosqwqqwq wants to merge 2 commits into
HexRaysSA:masterfrom
carlosqwqqwq:fix-riscv-csr-availability

Conversation

@carlosqwqqwq

Copy link
Copy Markdown
Contributor

fix(riscv): reject RV32-only counter-high CSRs on RV64

Closes #234

Summary

On RV64, the counter-high CSRs cycleh, timeh and instreth (0xC80-0xC82) are RV32-only high shadows and must raise an illegal-instruction exception. The affected RAX interpreter instead reads the internal high-half value and continues. The same missing availability check affects CSR families whose declaring extension is disabled, such as JVT without Zcmt and vector CSRs without V, so guest code can probe or use a CSR that is not present in the selected RISC-V profile.

The fix adds a shared csr_available() check and gates both the CSR read and CSR write paths on XLEN and the configured extension set.

Validation

  • Affected: RAX completes the csrr x1, cycleh witness normally with a trap-frame x1=0.
  • Fixed: RAX raises cause=2 (illegal instruction) at the CSR instruction with no frame.
  • Reference: QEMU raises an illegal-instruction signal; the native RISC-V hardware reference exits 132 (SIGILL) on all direct runs.
  • cargo test --lib: full library test suite passes with no regressions.

No new upstream test files are added; this is a source-only change.

cpu.rs exceeded the AGENTS.md hard split triggers (2000 lines / 150 kB). Move the vector (RVV) element access and data-path execution group, including set_vtype, into cpu/vector.rs with no behavior change.

19h commented Aug 11, 2026

Copy link
Copy Markdown
Member

Thank you for reporting and proposing this fix. I independently reimplemented and validated CSR availability checks for RV32-only counters and extension-owned FP, vector, and JVT CSRs in the consolidation PR #231; no commits or code from this branch were taken. The rollup carries @carlosqwqqwq as co-author on its commits and includes direct and native regression coverage. I’m closing this PR as superseded by #231—please review the consolidated implementation there.

@19h 19h closed this Aug 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

RV64 accepts RV32-only counter-high CSRs and disabled-extension CSRs

2 participants