Skip to content

[BUG] cva6_mmu: RV64-only fetch check creates a reversed part-select in cv32a6_imac_sv32 #3594

Description

@xtofalex

Code of Conduct

  • I have searched the existing bug issues.
  • I am a human engaging in an interpersonal interaction. During this interaction, my words are my own and are not generated. If relevant, I provide links to my sources.

CVA6 commit affected

81245a47fad8fe1a5d562d953ef2662e099def76 — upstream openhwfoundation/cva6 master checked on 2026-09-25, in a fresh checkout with its pinned submodules.

Bug Description

The shipped cv32a6_imac_sv32 configuration fails elaboration with latest Slang because an RV64-only instruction-fetch address check contains a reversed part-select when instantiated for Sv32.

At core/cva6_mmu/cva6_mmu.sv:405:

enable_g_translation_i && !enable_translation_i && CVA6Cfg.IS_XLEN64 &&
  (|icache_areq_i.fetch_vaddr[CVA6Cfg.VLEN-1:CVA6Cfg.GPLEN] != 1'b0)

The configuration sets XLEN=32 and VLEN=32. build_config_pkg.sv sets GPLEN=34 for RV32 and IS_XLEN64=0. Consequently, the expression selects [31:34] from logic[31:0]. Although the check is functionally disabled for RV32, its slice remains ill-formed for this configuration.

Steps to reproduce

Use Slang built from MikePopoloski/slang commit 1c475726ff072666dcee5281368c526030f68d63 (latest master checked on 2026-09-25). Tested on macOS / Apple Silicon.

git clone https://github.com/openhwfoundation/cva6.git
cd cva6
git checkout 81245a47fad8fe1a5d562d953ef2662e099def76
git submodule update --init --recursive core/cvfpu core/cache_subsystem/hpdcache

export CVA6_REPO_DIR="$PWD"
export TARGET_CFG=cv32a6_imac_sv32
export HPDCACHE_DIR="$CVA6_REPO_DIR/core/cache_subsystem/hpdcache"

slang --top cva6 -Wno-error=index-oob -f core/Flist.cva6

-Wno-error=index-oob only downgrades a separate existing diagnostic at core/cva6_mmu/cva6_tlb.sv:321 (tags_q[i].vpn[2] on a two-element array). It leaves the reversed-range diagnostic at its default error severity. Without this option, both sites produce errors.

Expected behavior

The fetch-address check should have legal elaborated bounds for the shipped Sv32 configuration, while retaining the intended upper-address check for RV64.

Observed behavior

Exit status is 1:

core/cva6_mmu/cva6_mmu.sv:405:115: error: range of selection [31:34] from 'logic[31:0]' is reversed [-Wrange-select-reversed]
...
Build failed: 1 error, 1 warning

A standalone reduction of this configuration-dependent expression also fails:

module repro(input logic en, input logic [31:0] addr, output logic fault);
  localparam bit RV64 = 0;
  always_comb begin
    fault = 0;
    if (en && RV64 && (|addr[31:34] != 1'b0)) fault = 1;
  end
endmodule

Suggested fix direction and validation

Make the unused Sv32 slice legal, or move the RV64-specific expression into a suitable generate branch. One candidate is to bound the slice's low index:

icache_areq_i.fetch_vaddr[
  CVA6Cfg.VLEN-1:
  ((CVA6Cfg.GPLEN < CVA6Cfg.VLEN) ? CVA6Cfg.GPLEN : CVA6Cfg.VLEN-1)
]

Keep the existing IS_XLEN64 guard. For Sv32 this selects one legal, unused bit; when GPLEN < VLEN it preserves the original range.

Tested by replacing only this source expression in a temporary copy of the latest upstream MMU source, with the same full CVA6 file list and configuration:

  • Original: 1 error, 1 warning, exit 1.
  • Candidate range correction: 0 errors, 1 warning, exit 0.
  • The remaining warning is the separate TLB array-index diagnostic described above.

This validates elaboration of the candidate correction, not architectural simulation or complete RV64 regression coverage.

Related reports and prior discussion

  • PR #3221 introduced this address check. In this discussion, the author already identified the mismatch between the 32-bit fetch address and the 34-bit GPA in Sv32x4, and described updating the condition for RV32/RV64. This report identifies a remaining elaboration problem: the IS_XLEN64 guard disables the check for RV32, but its part-select still becomes [31:34]. The reproducing configuration is cv32a6_imac_sv32, with the H extension disabled; reproducing this failure does not require working RV32 hypervisor support.
  • Open issue #3428 concerns the exception cause produced by the same instruction-fetch check during RV64 G-stage translation. This report concerns legal slice bounds during Sv32 elaboration. A change addressing [BUG] cva6_mmu: a pure G-stage (vsatp=Bare, Sv39x4) instruction-fetch address with bits [63:41] set raises INSTR_PAGE_FAULT instead of INSTR_GUEST_PAGE_FAULT #3428 should also keep the RV32 slice elaboration-safe; changing the exception cause alone would not address the failure demonstrated here.

A search of open and closed issues and pull requests on 2026-09-26 did not find a separate report of this exact reversed-range elaboration failure.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Component:RTLFor issues in the RTL (e.g. for files in the rtl directory)Status:NewNewly created issue, nobody has looked at it yet.Type:BugFor bugs in the RTL, Documentation, Verification environment or Tool and Build system

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions