Repository navigation
Conversation
When a load or store fails its integrity check, Ibex takes the internal NMI and writes the failing address to mtval. The cosim only tells Spike that the NMI happened, so Spike sets mtval to zero. The cosim then reports a mismatch when a handler reads mtval. Add an RVFI output that carries the address, and have Spike write it to mtval when it takes the internal NMI. The output only exists in RVFI builds. Signed-off-by: Kulan Palanichamy <kulan.palanichamy@opentitan.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
riscv_mem_intg_error_testfails on master on a few seeds with a cosim mismatch:The failing instruction reads
mtvalin a trap handler. When a load or store fails its integrity check, Ibextakes the internal NMI and writes the failing address to
mtval. Spike takes the NMI at the same point, butthe cosim only tells it that the NMI happened, so Spike sets
mtvalto zero. In the failing seeds the accessalso raises an access fault, and the NMI arrives on entry to the fault handler.
mretfrom the NMI does notrestore
mtval, so the fault handler reads the address on Ibex and zero in Spike.This PR adds an RVFI output,
rvfi_ext_nmi_int_mtval, that carries this address. It travels through theRVFI pipeline with the existing
rvfi_ext_nmi_intbit. Spike writes it tomtvalwhen it takes the internalNMI. When Spike does not take it, for example because an external NMI wins, the existing checks in
set_nmi_int()skip the write. The new output only exists in RVFI builds, so the design itself does notchange.
I tested on VCS with the
opentitanconfig. On 50 seeds of the test, 7 fail on master with this mismatch andnone fail on this branch. Both trees run the same programs. The nested interrupt, memory error and arithmetic
tests also pass. Simple System cosim passes CI's tests on
opentitanandsmall. I did not hit an externaland an internal NMI at the same time.
This PR does not depend on other PRs. It touches the same cosim files as #2324 and adds one line to two
blocks that #2324 realigns, so whichever lands second needs a small rebase.
AI disclosure (CLA §9): written with help from Claude Code and reviewed with OpenAI Codex; I have reviewed and understood every change and take full responsibility for it.