Skip to content

fix(riscv): reject illegal compressed encodings at the native boundary - #239

Closed
carlosqwqqwq wants to merge 2 commits into
HexRaysSA:masterfrom
carlosqwqqwq:fix-riscv-jit-illegal-admission
Closed

fix(riscv): reject illegal compressed encodings at the native boundary#239
carlosqwqqwq wants to merge 2 commits into
HexRaysSA:masterfrom
carlosqwqqwq:fix-riscv-jit-illegal-admission

Conversation

@carlosqwqqwq

Copy link
Copy Markdown
Contributor

fix(riscv): reject illegal compressed encodings at the native boundary

Closes #238

Summary

Under RV64GC, the reserved compressed encoding C.LUI rd=x0 (raw 0x6005) is admitted and retired by the translated/JIT path instead of raising an illegal-instruction trap (cause 2). The hand-written compressed lifter dispatches by quadrant/funct3 and lift_c_lui_addi16sp() produces empty ops for rd=x0; the empty block is accepted by the native path and retired. The same admission gap covers C.ADDIW rd=x0, reserved RV32C shift encodings, and Zcb aliases when M/Zbb/Zba are missing.

The fix rejects Insn::Illegal first at the decoded native boundary so the encoding falls back to the interpreter, which delivers the precise trap and mtval.

Validation

  • Targeted test jit_does_not_admit_illegal_compressed_encoding fails on the base checkout and passes with the fix.
  • The interpreter fallback delivers the precise trap (cause 2) with mtval for the same encodings.
  • cargo test --lib: full library test suite passes with no regressions.

No new upstream test files are added; this is a source-only change.

cpu.rs exceeded the AGENTS.md hard split triggers (2000 lines / 150 kB). Move the vector (RVV) element access and data-path execution group, including set_vtype, into cpu/vector.rs with no behavior change.

19h commented Aug 11, 2026

Copy link
Copy Markdown
Member

Thank you for reporting and proposing this fix. I independently reimplemented and validated fail-closed native admission for predecoded illegal compressed instructions across O0 and O2 in the consolidation PR #231; no commits or code from this branch were taken. The rollup carries @carlosqwqqwq as co-author on its commits and includes direct and native regression coverage. I’m closing this PR as superseded by #231—please review the consolidated implementation there.

@19h 19h closed this Aug 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reserved compressed encodings are admitted and retired by the JIT path

2 participants