FA-89783 / Instruction set emulation / Member archive
MPP not cleared by mret · case 03
A second mret without an intervening trap returns to the old privilege instead of user mode.
Case contract
Input [pc, priv, mie, mtvec, events]; MPIE, MPP, mcause, mepc start 0. step: pc += 4. ecall: exception cause 8 + priv (U 8, S 9, M 11). illegal: cause 2. irq k: interrupt cause 2^31 | k, taken only if priv < 3 or MIE. Trap: mepc = pc, mcause = cause, MPIE = MIE, MIE = 0, MPP = priv, priv = 3, pc = mtvec base (mtvec & ~3), plus 4*k for interrupts when mtvec mode (low 2 bits) is 1. mret: MIE = MPIE, MPIE = 1, priv = MPP, MPP = 0, pc = mepc. Return [pc, priv, MIE, MPIE, MPP, mcause, mepc] after each event.
Why this case matters
Trap and return sequencing defines how emulated operating systems handle syscalls and interrupts; one misordered status update corrupts the interrupt enable state.
One recorded failure
Sample boundary fixtureThis sample comes from the broken implementation of a controlled reproducer.
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| supervisor and machine ecall | [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 3, 11, 4096], [4096, 3, 1, 1, 3, 11, 4096]] | [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]] | Failed |
MEMBER ARCHIVE
The complete case is available to members.
This record includes three runnable implementations, regression fixtures, execution results, and source hashes.
Member access is invitation-based. Sign in with your invited account to inspect the sources.
Sign in to the archive ↗