Commit ebfde6daff for qemu.org

commit ebfde6dafff2ebfb653d8b9a620ea52a4f714f5b
Author: wangyang <wangyang25@otcaix.iscas.ac.cn>
Date:   Fri Sep 11 09:54:57 2026 +0800

    linux-user/riscv: honor zicntr=false for base counterCSRs

    In user-only builds, the base cycle and instret CSRs bypass the zicntr
    feature gate because the check is inside the system-mode block. Move the
    check before the conditional block so an explicitly disabled zicntr
    extension makes the CSRs illegal in linux-user mode.

    Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4148

    Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
    Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>
    Signed-off-by: Helge Deller <deller@gmx.de>

diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c
index bd4b6dc114..061bc9db77 100644
--- a/target/riscv/tcg/csr.c
+++ b/target/riscv/tcg/csr.c
@@ -111,6 +111,13 @@ static RISCVException vs(CPURISCVState *env, int csrno)

 static RISCVException ctr(CPURISCVState *env, int csrno)
 {
+    if ((csrno >= CSR_CYCLE && csrno <= CSR_INSTRET) ||
+        (csrno >= CSR_CYCLEH && csrno <= CSR_INSTRETH)) {
+        if (!riscv_cpu_cfg(env)->ext_zicntr) {
+            return RISCV_EXCP_ILLEGAL_INST;
+        }
+    }
+
 #if !defined(CONFIG_USER_ONLY)
     RISCVCPU *cpu = env_archcpu(env);
     int ctr_index;
@@ -127,10 +134,6 @@ static RISCVException ctr(CPURISCVState *env, int csrno)

     if ((csrno >= CSR_CYCLE && csrno <= CSR_INSTRET) ||
         (csrno >= CSR_CYCLEH && csrno <= CSR_INSTRETH)) {
-        if (!riscv_cpu_cfg(env)->ext_zicntr) {
-            return RISCV_EXCP_ILLEGAL_INST;
-        }
-
         goto skip_ext_pmu_check;
     }