[colophon] // Had to make the above a level 1 heading (two equals signs) to avoid error when building // the ISA manual as a book with other "parts". This is opposite to what the adoc says to do // but otherwise asciidoctor creates the error message: // // asciidoctor: ERROR: ext/riscv-isa-manual/src/priv-preface.adoc: line 2: invalid part, must have at least one section (e.g., chapter, appendix, etc.) // // See asciidoctor doc which seems wrong: https://docs.asciidoctor.org/asciidoc/latest/sections/colophon/ == Preface This document describes the RISC-V privileged architecture. It contains the following versions of the RISC-V ISA modules, all of which have been ratified: [%autowidth,float="center",align="center",cols="^,<",options="header",] |=== |Privilege Level |Version |Machine |1.13 |Supervisor |1.13 h|Extension h|Version |ext:smstateen[] |1.0 |ext:smcsrind[] |1.0 |ext:smepmp[] |1.0 |ext:smcntrpmf[] |1.0 |ext:smrnmi[] |1.0 |ext:smcdeleg[] |1.0 |ext:smdbltrp[] |1.0 |ext:smctr[] |1.0 |Control-flow Integrity |1.0 |Pointer Masking |1.0 |ext:svade[] |1.0 |ext:svnapot[] |1.0 |ext:svpbmt[] |1.0 |ext:svadu[] |1.0 |ext:svinval[] |1.0 |ext:svvptc[] |1.0 |ext:svrsw60t59b[] |1.0 |ext:ssstateen[] |1.0 |ext:sscsrind[] |1.0 |ext:ssccfg[] |1.0 |ext:ssqosid[] |1.0 |ext:ssu64xl[] |1.0 |ext:ssccptr[] |1.0 |ext:sstvecd[] |1.0 |ext:sstvala[] |1.0 |ext:sscounterenw[] |1.0 |ext:ssstrict[] |1.0 |ext:sstc[] |1.0 |ext:sscofpmf[] |1.0 |ext:ssdbltrp[] |1.0 |ext:h[] |1.0 |ext:shlcofideleg[] |1.0 |ext:shvstvecd[] |1.0 |ext:shcounterenw[] |1.0 |ext:shvstvala[] |1.0 |ext:shtvala[] |1.0 |ext:shvsatpa[] |1.0 |ext:shgatpa[] |1.0 |ext:sha[] |1.0 |=== The following changes have been made since version 20260120: * Addition of extensions that have already been ratified as part of the profile specifications. [.big]*_Preface to Version 20260120_* This document describes the RISC-V privileged architecture. It contains the following versions of the RISC-V ISA modules, all of which have been ratified: [%autowidth,float="center",align="center",cols="^,<",options="header",] |=== |Module |Version |*Machine ISA* |*1.13* |*Smstateen Extension* |*1.0* |*Smcsrind/Sscsrind Extension* |*1.0* |*Smepmp Extension* |*1.0* |*Smcntrpmf Extension* |*1.0* |*Smrnmi Extension* |*1.0* |*Smcdeleg Extension* |*1.0* |*Smdbltrp Extension* |*1.0* |*Smctr Extension* |*1.0* |*Supervisor ISA* |*1.13* |*Svade Extension* |*1.0* |*Svnapot Extension* |*1.0* |*Svpbmt Extension* |*1.0* |*Svinval Extension* |*1.0* |*Svadu Extension* |*1.0* |*Svvptc Extension* |*1.0* |*Ssqosid Extension* |*1.0* |*Sstc Extension* |*1.0* |*Sscofpmf Extension* |*1.0* |*Ssdbltrp Extension* |*1.0* |*Hypervisor ISA* |*1.0* |*Shlcofideleg Extension* |*1.0* |*Svvptc Extension* |*1.0* |*Pointer-Masking Extensions* |*1.0* |*Svrsw60t59b Extension* |*1.0* |=== The following changes have been made since version 20250508: * Addition of the ext:svrsw60t59b[] extension for additional PTE reserved-for-software bits. [.big]*_Preface to Version 20250508_* This document describes the RISC-V privileged architecture. The ISA modules marked *Ratified* have been ratified at this time. The modules marked _Frozen_ are not expected to change significantly before being put up for ratification. The modules marked _Draft_ are expected to change before ratification. The document contains the following versions of the RISC-V ISA modules: [%autowidth,float="center",align="center",cols="^,<,^",options="header",] |=== |Module |Version |Status |*Machine ISA* |*1.13* |*Ratified* |*Smstateen Extension* |*1.0* |*Ratified* |*Smcsrind/Sscsrind Extension* |*1.0* |*Ratified* |*Smepmp Extension* |*1.0* |*Ratified* |*Smcntrpmf Extension* |*1.0* |*Ratified* |*Smrnmi Extension* |*1.0* |*Ratified* |*Smcdeleg Extension* |*1.0* |*Ratified* |*Smdbltrp Extension* |*1.0* |*Ratified* |*Smctr Extension* |*1.0* |*Ratified* |*Supervisor ISA* |*1.13* |*Ratified* |*Svade Extension* |*1.0* |*Ratified* |*Svnapot Extension* |*1.0* |*Ratified* |*Svpbmt Extension* |*1.0* |*Ratified* |*Svinval Extension* |*1.0* |*Ratified* |*Svadu Extension* |*1.0* |*Ratified* |*Svvptc Extension* |*1.0* |*Ratified* |*Ssqosid Extension* |*1.0* |*Ratified* |*Sstc Extension* |*1.0* |*Ratified* |*Sscofpmf Extension* |*1.0* |*Ratified* |*Ssdbltrp Extension* |*1.0* |*Ratified* |*Hypervisor ISA* |*1.0* |*Ratified* |*Shlcofideleg Extension* |*1.0* |*Ratified* |*Svvptc Extension* |*1.0* |*Ratified* |*Pointer-Masking Extensions* |*1.0* |*Ratified* |=== The following changes have been made since version 20241101: * Addition of the Smctr Control Transfer Records extension. * Addition of the Svvptc Extension for Obviating Memory-Management Instructions after Marking PTEs Valid. * Addition of the Ssqosid Extension for Quality-of-Service Identifiers. * Addition of the Pointer-Masking Extensions. [.big]*_Preface to Version 20241101_* This document describes the RISC-V privileged architecture. The ISA modules marked *Ratified* have been ratified at this time. The modules marked _Frozen_ are not expected to change significantly before being put up for ratification. The modules marked _Draft_ are expected to change before ratification. The document contains the following versions of the RISC-V ISA modules: [%autowidth,float="center",align="center",cols="^,<,^",options="header",] |=== |Module |Version |Status |*Machine ISA* |*1.13* |*Ratified* |*Smstateen Extension* |*1.0* |*Ratified* |*Smcsrind/Sscsrind Extension* |*1.0* |*Ratified* |*Smepmp Extension* |*1.0* |*Ratified* |*Smcntrpmf Extension* |*1.0* |*Ratified* |*Smrnmi Extension* |*1.0* |*Ratified* |*Smcdeleg Extension* |*1.0* |*Ratified* |*Smdbltrp Extension* |*1.0* |*Ratified* |*Supervisor ISA* |*1.13* |*Ratified* |*Svade Extension* |*1.0* |*Ratified* |*Svnapot Extension* |*1.0* |*Ratified* |*Svpbmt Extension* |*1.0* |*Ratified* |*Svinval Extension* |*1.0* |*Ratified* |*Svadu Extension* |*1.0* |*Ratified* |*Sstc Extension* |*1.0* |*Ratified* |*Sscofpmf Extension* |*1.0* |*Ratified* |*Ssdbltrp Extension* |*1.0* |*Ratified* |*Ssqosid Extension* |*1.0* |*Ratified* |*Hypervisor ISA* |*1.0* |*Ratified* |*Shlcofideleg Extension* |*1.0* |*Ratified* |*Svvptc Extension* |*1.0* |*Ratified* |=== [.big]*_Preface to Version 20241017_* This document describes the RISC-V privileged architecture. This release, version 20241017, contains the following versions of the RISC-V ISA modules: [%autowidth,float="center",align="center",cols="^,<,^",options="header",] |=== |Module |Version |Status |*Machine ISA* |*1.13* |*Ratified* |*Smstateen Extension* |*1.0* |*Ratified* |*Smcsrind/Sscsrind Extension* |*1.0* |*Ratified* |*Smepmp* |*1.0* |*Ratified* |*Smcntrpmf* |*1.0* |*Ratified* |*Smrnmi Extension* |*1.0* |*Ratified* |*Smcdeleg* |*1.0* |*Ratified* |*Smdbltrp* |*1.0* |*Ratified* |*Supervisor ISA* |*1.13* |*Ratified* |*Svade Extension* |*1.0* |*Ratified* |*Svnapot Extension* |*1.0* |*Ratified* |*Svpbmt Extension* |*1.0* |*Ratified* |*Svinval Extension* |*1.0* |*Ratified* |*Svadu Extension* |*1.0* |*Ratified* |*Sstc* |*1.0* |*Ratified* |*Sscofpmf* |*1.0* |*Ratified* |*Ssdbltrp* |*1.0* |*Ratified* |*Hypervisor ISA* |*1.0* |*Ratified* |*Shlcofideleg* |*1.0* |*Ratified* |*Svvptc* |*1.0* |*Ratified* |=== The following changes have been made since version 1.12 of the Machine and Supervisor ISAs, which, while not strictly backwards compatible, are not anticipated to cause software portability problems in practice: * Redefined csr:misa.[mxl] to be read-only, making MXLEN a constant. * Added the constraint that SXLEN{ge}UXLEN. Additionally, the following compatible changes have been made to the Machine and Supervisor ISAs since version 1.12: * Defined the csr:misa[b] field to reflect that the ext:b[] extension has been implemented. * Defined the csr:misa[v] field to reflect that the ext:v[] extension has been implemented. * Defined the RV32-only csr:medelegh[] and csr:hedelegh[] CSRs. * Defined the misaligned atomicity granule PMA, superseding the proposed ext:zam[] extension. * Allocated interrupt 13 for ext:sscofpmf[] csr::[lcofi] interrupt. * Defined hardware-error and software-check exception codes. * Specified synchronization requirements when changing the csr::[pbmte] and csr::[adue] fields in csr:menvcfg[] and csr:henvcfg[]. * Exposed count-overflow interrupts to VS-mode via the ext:shlcofideleg[] extension. * Relaxed behavior of some HINTs when MXLEN > XLEN. * Defined the format of the memory-mapped csr:msip[] registers. Finally, the following clarifications and document improvements have been made since the last document release: * Transliterated the document from LaTeX into AsciiDoc. * Included all ratified extensions through March 2024. * Clarified that "`platform- or custom-use`" interrupts are actually "`platform-use interrupts`", where the platform can choose to make some custom. * Clarified semantics of explicit accesses to CSRs wider than XLEN bits. * Clarified that MXLEN{ge}SXLEN. * Clarified that insn:wfi[] is not a HINT instruction. * Clarified that VS-stage page-table accesses set G-stage A/D bits. * Clarified ordering rules when PBMT=IO is used on main-memory regions. * Clarified ordering rules for hardware A/D bit updates. * Clarified that, for a given exception cause, `__x__tval` might sometimes be set to a nonzero value but sometimes not. * Clarified exception behavior of unimplemented or inaccessible CSRs. * Clarified that Svpbmt allows implementations to override additional PMAs. * Replaced the concept of vacant memory regions with inaccessible memory or I/O regions. * Clarified that timer and count-overflow interrupts' arrival in interrupt-pending registers is not immediate. * Clarified that MXR affects only explicit memory accesses. [.big]*_Preface to Version 20211203_* This document describes the RISC-V privileged architecture. This release, version 20211203, contains the following versions of the RISC-V ISA modules: [%autowidth,float="center",align="center",cols="^,<,^",options="header",] |=== |Module |Version |Status |*Machine ISA* |*1.12* |*Ratified* |*Supervisor ISA* |*1.12* |*Ratified* |*Svnapot Extension* |*1.0* |*Ratified* |*Svpbmt Extension* |*1.0* |*Ratified* |*Svinval Extension* |*1.0* |*Ratified* |*Hypervisor ISA* |*1.0* |*Ratified* |=== The following changes have been made since version 1.11, which, while not strictly backwards compatible, are not anticipated to cause software portability problems in practice: * Changed insn:mret[] and insn:sret[] to clear csr:mstatus[mprv] when leaving M-mode. * Reserved additional csr:satp[] patterns for future use. * Stated that the csr:scause[] Exception Code field must implement bits 4–0 at minimum. * Relaxed I/O regions have been specified to follow RVWMO. The previous specification implied that PPO rules other than fences and acquire/release annotations did not apply. * Constrained the LR/SC reservation set size and shape when using page-based virtual memory. * PMP changes require an insn:sfence.vma[] on any hart that implements page-based virtual memory, even if VM is not currently enabled. * Allowed for speculative updates of page table entry A bits. * Clarify that if the address-translation algorithm non-speculatively reaches a PTE in which a bit reserved for future standard use is set, a page-fault exception must be raised. Additionally, the following compatible changes have been made since version 1.11: * Removed the ext:n[] extension. * Defined the mandatory RV32-only CSR csr:mstatush[], which contains most of the same fields as the upper 32 bits of RV64’s csr:mstatus[]. * Defined the mandatory CSR csr:mconfigptr[], which if nonzero contains the address of a configuration data structure. * Defined csr:mseccfg[] and csr:mseccfgh[] CSRs, which control the machine’s security configuration. * Defined csr:menvcfg[], csr:henvcfg[], and csr:senvcfg[] CSRs (and RV32-only csr:menvcfgh[] and csr:henvcfgh[] CSRs), which control various characteristics of the execution environment. * Designated part of SYSTEM major opcode for custom use. * Permitted the unconditional delegation of less-privileged interrupts. * Added optional big-endian and bi-endian support. * Made priority of load/store/AMO address-misaligned exceptions implementation-defined relative to load/store/AMO page-fault and access-fault exceptions. * PMP reset values are now platform-defined. * An additional 48 optional PMP registers have been defined. * Slightly relaxed the atomicity requirement for A and D bit updates performed by the implementation. * Clarify the architectural behavior of address-translation caches * Added ext:sv57[] and ext:sv57x4[] address translation modes. * Software breakpoint exceptions are permitted to write either 0 or the `pc` to `__x__tval`. * Clarified that bare S-mode need not support the insn:sfence.vma[] instruction. * Specified relaxed constraints for implicit reads of non-idempotent regions. * Added the Svnapot Standard Extension, along with the N bit in ext:sv39[], ext:sv48[], and ext:sv57[] PTEs. * Added the ext:svpbmt[] Standard Extension, along with the PBMT bits in ext:sv39[], ext:sv48[], and ext:sv57[] PTEs. * Added the ext:svinval[] Standard Extension and associated instructions. Finally, the hypervisor architecture proposal has been extensively revised. [.big]*_Preface to Version 1.11_* This is version 1.11 of the RISC-V privileged architecture. The document contains the following versions of the RISC-V ISA modules: [%autowidth,float="center",align="center",cols="^,<,^",options="header",] |=== |Module |Version |Status |*Machine ISA* |*1.11* |*Ratified* |*Supervisor ISA* |*1.11* |*Ratified* |_Hypervisor ISA_ |_0.3_ |_Draft_ |=== Changes from version 1.10 include: * Moved Machine and Supervisor spec to *Ratified* status. * Improvements to the description and commentary. * Added a draft proposal for a hypervisor extension. * Specified which interrupt sources are reserved for standard use. * Allocated some synchronous exception causes for custom use. * Specified the priority ordering of synchronous exceptions. * Added specification that __x__RET instructions may, but are not required to, clear LR reservations if ext:a[] extension present. * The virtual-memory system no longer permits supervisor mode to execute instructions from user pages, regardless of the csr::[sum] setting. * Clarified that ASIDs are private to a hart, and added commentary about the possibility of a future global-ASID extension. * insn:sfence.vma[] semantics have been clarified. * Made the csr:mstatus[mpp] field *WARL*, rather than *WLRL*. * Made the unused `__x__ip` fields *WPRI*, rather than *WIRI*. * Made the unused csr:misa[] fields *WARL*, rather than *WIRI*. * Made the unused csr:pmpaddr[] and csr:pmpcfg[] fields *WARL*, rather than *WIRI*. * Required all harts in a system to employ the same PTE-update scheme as each other. * Rectified an editing error that misdescribed the mechanism by which csr:mstatus[].`__x__IE` is written upon an exception. * Described scheme for emulating misaligned AMOs. * Specified the behavior of the csr:misa[] and `__x__epc` registers in systems with variable IALIGN. * Specified the behavior of writing self-contradictory values to the csr:misa[] register. * Defined the csr:mcountinhibit[] CSR, which stops performance counters from incrementing to reduce energy consumption. * Specified semantics for PMP regions coarser than four bytes. * Specified contents of CSRs across XLEN modification. * Moved PLIC chapter into its own document. [.big]*_Preface to Version 1.10_* This is version 1.10 of the RISC-V privileged architecture proposal. Changes from version 1.9.1 include: * The previous version of this document was released under a Creative Commons Attribution 4.0 International License by the original authors, and this and future versions of this document will be released under the same license. * The explicit convention on shadow CSR addresses has been removed to reclaim CSR space. Shadow CSRs can still be added as needed. * The csr:mvendorid[] register now contains the JEDEC code of the core provider as opposed to a code supplied by the Foundation. This avoids redundancy and offloads work from the Foundation. * The interrupt-enable stack discipline has been simplified. * An optional mechanism to change the base ISA used by supervisor and user modes has been added to the csr:mstatus[] CSR, and the field previously called Base in csr:misa[] has been renamed to csr::[mxl] for consistency. * Clarified expected use of csr::[xs] to summarize additional extension state status fields in csr:mstatus[]. * Optional vectored interrupt support has been added to the csr:mtvec[] and csr:stvec[] CSRs. * The csr::[seip] and csr::[ueip] bits in the csr:mip[] CSR have been redefined to support software injection of external interrupts. * The csr:mbadaddr[] register has been subsumed by a more general csr:mtval[] register that can now capture bad instruction bits on an illegal-instruction fault to speed instruction emulation. * The machine-mode base-and-bounds translation and protection schemes have been removed from the specification as part of moving the virtual memory configuration to csr:sptbr[] (now csr:satp[]). Some of the motivation for the base and bound schemes are now covered by the PMP registers, but space remains available in csr:mstatus[] to add these back at a later date if deemed useful. * In systems with only M-mode, or with both M-mode and U-mode but without U-mode trap support, the csr:medeleg[] and csr:mideleg[] registers now do not exist, whereas previously they returned zero. * Virtual-memory page faults now have csr:mcause[] values distinct from physical-memory access faults. Page-fault exceptions can now be delegated to S-mode without delegating exceptions generated by PMA and PMP checks. * An optional physical-memory protection (PMP) scheme has been proposed. * The supervisor virtual memory configuration has been moved from the csr:mstatus[] register to the csr:sptbr[] register. Accordingly, the csr:sptbr[] register has been renamed to csr:satp[] (Supervisor Address Translation and Protection) to reflect its broadened role. * The insn:sfence.vm[] instruction has been removed in favor of the improved insn:sfence.vma[] instruction. * The csr:mstatus[] bit csr::[mxr] has been exposed to S-mode via csr:sstatus[]. * The polarity of the csr::[pum] bit in csr:sstatus[] has been inverted to shorten code sequences involving csr::[mxr]. The bit has been renamed to csr::[sum]. * Hardware management of page-table entry Accessed and Dirty bits has been made optional; simpler implementations may trap to software to set them. * The counter-enable scheme has changed, so that S-mode can control availability of counters to U-mode. * H-mode has been removed, as we are focusing on recursive virtualization support in S-mode. The encoding space has been reserved and may be repurposed at a later date. * A mechanism to improve virtualization performance by trapping S-mode virtual-memory management operations has been added. * The Supervisor Binary Interface (SBI) chapter has been removed, so that it can be maintained as a separate specification. [.big]*_Preface to Version 1.9.1_* This is version 1.9.1 of the RISC-V privileged architecture proposal. Changes from version 1.9 include: * Numerous additions and improvements to the commentary sections. * Change configuration string proposal to be use a search process that supports various formats including Device Tree String and flattened Device Tree. * Made csr:misa[] optionally writable to support modifying base and supported ISA extensions. CSR address of csr:misa[] changed. * Added description of debug mode and debug CSRs. * Added a hardware performance monitoring scheme. Simplified the handling of existing hardware counters, removing privileged versions of the counters and the corresponding delta registers. * Fixed description of csr::[spie] in presence of user-level interrupts.