From: wangyang <[email protected]>

In user-only builds, the base cycle and instret CSRs bypass the zicntr
feature gate because the check is inside the system-mode block. Move the
check before the conditional block so an explicitly disabled zicntr
extension makes the CSRs illegal in linux-user mode.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4148

Reviewed-by: Alistair Francis <[email protected]>
Signed-off-by: wangyang <[email protected]>
Signed-off-by: Helge Deller <[email protected]>
(cherry picked from commit ebfde6dafff2ebfb653d8b9a620ea52a4f714f5b)
Signed-off-by: Michael Tokarev <[email protected]>

diff --git a/target/riscv/csr.c b/target/riscv/csr.c
index 9d43dbfab81..8dbe82c7f6d 100644
--- a/target/riscv/csr.c
+++ b/target/riscv/csr.c
@@ -107,6 +107,13 @@ static RISCVException vs(CPURISCVState *env, int csrno)
 
 static RISCVException ctr(CPURISCVState *env, int csrno)
 {
+    if ((csrno >= CSR_CYCLE && csrno <= CSR_INSTRET) ||
+        (csrno >= CSR_CYCLEH && csrno <= CSR_INSTRETH)) {
+        if (!riscv_cpu_cfg(env)->ext_zicntr) {
+            return RISCV_EXCP_ILLEGAL_INST;
+        }
+    }
+
 #if !defined(CONFIG_USER_ONLY)
     RISCVCPU *cpu = env_archcpu(env);
     int ctr_index;
@@ -123,10 +130,6 @@ static RISCVException ctr(CPURISCVState *env, int csrno)
 
     if ((csrno >= CSR_CYCLE && csrno <= CSR_INSTRET) ||
         (csrno >= CSR_CYCLEH && csrno <= CSR_INSTRETH)) {
-        if (!riscv_cpu_cfg(env)->ext_zicntr) {
-            return RISCV_EXCP_ILLEGAL_INST;
-        }
-
         goto skip_ext_pmu_check;
     }
 
-- 
2.47.3


Reply via email to