From ebfde6dafff2ebfb653d8b9a620ea52a4f714f5b Mon Sep 17 00:00:00 2001 From: wangyang Date: Fri, 11 Sep 2026 09:54:57 +0800 Subject: [PATCH] linux-user/riscv: honor zicntr=false for base counterCSRs In user-only builds, the base cycle and instret CSRs bypass the zicntr feature gate because the check is inside the system-mode block. Move the check before the conditional block so an explicitly disabled zicntr extension makes the CSRs illegal in linux-user mode. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4148 Reviewed-by: Alistair Francis Signed-off-by: wangyang Signed-off-by: Helge Deller --- target/riscv/tcg/csr.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c index bd4b6dc114..061bc9db77 100644 --- a/target/riscv/tcg/csr.c +++ b/target/riscv/tcg/csr.c @@ -111,6 +111,13 @@ static RISCVException vs(CPURISCVState *env, int csrno) static RISCVException ctr(CPURISCVState *env, int csrno) { + if ((csrno >= CSR_CYCLE && csrno <= CSR_INSTRET) || + (csrno >= CSR_CYCLEH && csrno <= CSR_INSTRETH)) { + if (!riscv_cpu_cfg(env)->ext_zicntr) { + return RISCV_EXCP_ILLEGAL_INST; + } + } + #if !defined(CONFIG_USER_ONLY) RISCVCPU *cpu = env_archcpu(env); int ctr_index; @@ -127,10 +134,6 @@ static RISCVException ctr(CPURISCVState *env, int csrno) if ((csrno >= CSR_CYCLE && csrno <= CSR_INSTRET) || (csrno >= CSR_CYCLEH && csrno <= CSR_INSTRETH)) { - if (!riscv_cpu_cfg(env)->ext_zicntr) { - return RISCV_EXCP_ILLEGAL_INST; - } - goto skip_ext_pmu_check; }