You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I am a human engaging in an interpersonal interaction. During this interaction, my words are my own and are not generated. If relevant, I provide links to my sources.
CVA6 commit affected
81245a47fad8fe1a5d562d953ef2662e099def76 — upstream openhwfoundation/cva6 master checked on 2026-09-25, in a fresh checkout with its pinned submodules.
Bug Description
The shipped cv32a6_imac_sv32 configuration fails elaboration with latest Slang because an RV64-only instruction-fetch address check contains a reversed part-select when instantiated for Sv32.
The configuration sets XLEN=32 and VLEN=32. build_config_pkg.sv sets GPLEN=34 for RV32 and IS_XLEN64=0. Consequently, the expression selects [31:34] from logic[31:0]. Although the check is functionally disabled for RV32, its slice remains ill-formed for this configuration.
Steps to reproduce
Use Slang built from MikePopoloski/slang commit 1c475726ff072666dcee5281368c526030f68d63 (latest master checked on 2026-09-25). Tested on macOS / Apple Silicon.
-Wno-error=index-oob only downgrades a separate existing diagnostic at core/cva6_mmu/cva6_tlb.sv:321 (tags_q[i].vpn[2] on a two-element array). It leaves the reversed-range diagnostic at its default error severity. Without this option, both sites produce errors.
Expected behavior
The fetch-address check should have legal elaborated bounds for the shipped Sv32 configuration, while retaining the intended upper-address check for RV64.
Observed behavior
Exit status is 1:
core/cva6_mmu/cva6_mmu.sv:405:115: error: range of selection [31:34] from 'logic[31:0]' is reversed [-Wrange-select-reversed]
...
Build failed: 1 error, 1 warning
A standalone reduction of this configuration-dependent expression also fails:
modulerepro(inputlogic en, inputlogic [31:0] addr, outputlogic fault);
localparam bitRV64=0;
always_combbegin
fault =0;
if (en &&RV64&& (|addr[31:34] !=1'b0)) fault =1;
endendmodule
Suggested fix direction and validation
Make the unused Sv32 slice legal, or move the RV64-specific expression into a suitable generate branch. One candidate is to bound the slice's low index:
Keep the existing IS_XLEN64 guard. For Sv32 this selects one legal, unused bit; when GPLEN < VLEN it preserves the original range.
Tested by replacing only this source expression in a temporary copy of the latest upstream MMU source, with the same full CVA6 file list and configuration:
Original: 1 error, 1 warning, exit 1.
Candidate range correction: 0 errors, 1 warning, exit 0.
The remaining warning is the separate TLB array-index diagnostic described above.
This validates elaboration of the candidate correction, not architectural simulation or complete RV64 regression coverage.
Related reports and prior discussion
PR #3221 introduced this address check. In this discussion, the author already identified the mismatch between the 32-bit fetch address and the 34-bit GPA in Sv32x4, and described updating the condition for RV32/RV64. This report identifies a remaining elaboration problem: the IS_XLEN64 guard disables the check for RV32, but its part-select still becomes [31:34]. The reproducing configuration is cv32a6_imac_sv32, with the H extension disabled; reproducing this failure does not require working RV32 hypervisor support.
Code of Conduct
CVA6 commit affected
81245a47fad8fe1a5d562d953ef2662e099def76— upstreamopenhwfoundation/cva6master checked on 2026-09-25, in a fresh checkout with its pinned submodules.Bug Description
The shipped
cv32a6_imac_sv32configuration fails elaboration with latest Slang because an RV64-only instruction-fetch address check contains a reversed part-select when instantiated for Sv32.At core/cva6_mmu/cva6_mmu.sv:405:
The configuration sets XLEN=32 and VLEN=32. build_config_pkg.sv sets GPLEN=34 for RV32 and IS_XLEN64=0. Consequently, the expression selects
[31:34]fromlogic[31:0]. Although the check is functionally disabled for RV32, its slice remains ill-formed for this configuration.Steps to reproduce
Use Slang built from
MikePopoloski/slangcommit1c475726ff072666dcee5281368c526030f68d63(latest master checked on 2026-09-25). Tested on macOS / Apple Silicon.-Wno-error=index-oobonly downgrades a separate existing diagnostic atcore/cva6_mmu/cva6_tlb.sv:321(tags_q[i].vpn[2]on a two-element array). It leaves the reversed-range diagnostic at its default error severity. Without this option, both sites produce errors.Expected behavior
The fetch-address check should have legal elaborated bounds for the shipped Sv32 configuration, while retaining the intended upper-address check for RV64.
Observed behavior
Exit status is 1:
A standalone reduction of this configuration-dependent expression also fails:
Suggested fix direction and validation
Make the unused Sv32 slice legal, or move the RV64-specific expression into a suitable generate branch. One candidate is to bound the slice's low index:
Keep the existing IS_XLEN64 guard. For Sv32 this selects one legal, unused bit; when GPLEN < VLEN it preserves the original range.
Tested by replacing only this source expression in a temporary copy of the latest upstream MMU source, with the same full CVA6 file list and configuration:
This validates elaboration of the candidate correction, not architectural simulation or complete RV64 regression coverage.
Related reports and prior discussion
[31:34]. The reproducing configuration iscv32a6_imac_sv32, with the H extension disabled; reproducing this failure does not require working RV32 hypervisor support.A search of open and closed issues and pull requests on 2026-09-26 did not find a separate report of this exact reversed-range elaboration failure.