On Thu, Aug 27, 2026 at 05:33 Richard Henderson <
[email protected]> wrote:

> On 8/26/26 11:40, Max Chou wrote:
> > Sorry, my previous example was unclear. It does not need a 1-byte PMP
> > region: RISC-V PMP definition allows the minimum 4-byte PMP region,
> > which exactly matches one e32 element.
> >
> > For example, with vl=3, vstart=0, e32, and v0.mask = [1, 0, 1],
> > configure locked PMP entries as follows:
> >
> >    PMP0: NA4   [base + 4, base + 7], L, ---    # element 1, no read
> >    PMP1: NAPOT target page,          L, R      # lower-priority page
> allow
> >
> >    bytes:       base       base + 4     base + 8
> >                 +-----+    +-----+      +-----+
> >    element:       0          1            2
> >    mask:          1          0            1
> >    access:     active      inactive      active
> >    PMP:        PMP1 R      PMP0 ---      PMP1 R
> >
> > The RISC-V spec defines that masked vector loads access memory and raise
> > exceptions only for active elements.
> > Therefore this situation has reads only for elements 0 and 2; PMP0 must
> > not create an access-fault condition for this instruction.
> >
> > My concern is that the page probe may be unsafe in some situations
> > because PMP permissions can change at 4-byte granularity inside a
> > target page, while the probe includes bytes which are not part of
> > active vector memory operations.
> >
> > Maybe we could use the page probe only when it returns flags == 0,
> > and otherwise fall back to checking only active elements or active
> > runs?
>
> Ok, thanks for the clear example.  flags == 0 does not help with this case.
>
> What we want is to probe the first active element, with
> probe_access_full.  For this particular case, where a PMP rule matches
> something smaller than the page, we will have set lg_page_size <
> TARGET_PAGE_BITS.  So we get the fault (or not) for the first element
> exactly, and can then tell via flags and lg_page_size whether the rest
> of the page can use the fast or slow paths.
>
> > I'm trying to create masked fauly-only-first + PMP test for this.
>
> Thanks, that would be helpful.  Similarly for masked not-first-fault,
> please?
>

I am glad to help with this. I will send the test cases for both the fault
at the first element and the no-fault at the first element scenarios for
masked vector fault-only-first instructions to this list.

rnax



>
> r~
>
>

Reply via email to