From: Daniel Henrique Barboza Date: Thu, 14 May 2026 19:45:36 +0000 (-0300) Subject: target/riscv/csr.c: do not allow mstatus MPV/GVA writes X-Git-Tag: v11.1.0-rc0~61^2~79 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=18645f19578955ec5ff2c40cd2c8753d6bc460c2;p=thirdparty%2Fqemu.git target/riscv/csr.c: do not allow mstatus MPV/GVA writes The priv spec states the following about mstatus.MPV: "The MPV bit (Machine Previous Virtualization Mode) is written by the implementation whenever a trap is taken into M-mode." And, about mstatus.GVA: "Field GVA (Guest Virtual Address) is written by the implementation whenever a trap is taken into M-mode." Both are written during riscv_cpu_do_interrupt(). They're not supposed to be written by userspace. As far as write_mstatus goes these fields are read only. The same applies for mstatush.MPV/mstatush.GVA. Fixes: 03dd405dd5 ("target/riscv: Support MSTATUS.MPV/GVA only when RVH is enabled") Signed-off-by: Daniel Henrique Barboza Acked-by: Alistair Francis Message-ID: <20260514194537.2416243-2-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis --- diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 5514e0f455..83ca354bf0 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -2044,9 +2044,6 @@ static RISCVException write_mstatus(CPURISCVState *env, int csrno, } if (xl != MXL_RV32 || env->debugger) { - if (riscv_has_ext(env, RVH)) { - mask |= MSTATUS_MPV | MSTATUS_GVA; - } if ((val & MSTATUS64_UXL) != 0) { mask |= MSTATUS64_UXL; } @@ -2083,7 +2080,7 @@ static RISCVException write_mstatush(CPURISCVState *env, int csrno, target_ulong val, uintptr_t ra) { uint64_t valh = (uint64_t)val << 32; - uint64_t mask = riscv_has_ext(env, RVH) ? MSTATUS_MPV | MSTATUS_GVA : 0; + uint64_t mask = 0; if (riscv_cpu_cfg(env)->ext_smdbltrp) { mask |= MSTATUS_MDT;