Observed Behavior
With ICache=1, SecureIbex=1, ICacheECC=0, and ICacheScramble=1, the official ibex_top lint/elaboration accepts the parameter combination and passes ICacheECC=0 through independently of SecureIbex (rtl/ibex_top.sv:34-43, 383-396). Inside the actual ICache, ICacheECC=0 selects gen_noecc_wdata (rtl/ibex_icache.sv:286-315) and omits the ECC-checking generate block (:537). The secure reference configuration (ICacheECC=1) elaborates the encoder/checker branches instead.
Root Cause Analysis
SecureIbex and ICacheECC are independently passed from ibex_top into the core and ICache. The ICache generate condition is controlled by ICacheECC alone, so the secure configuration can select gen_noecc_wdata without an elaboration error. The security documentation and the parameter contract are therefore weaker or less explicit than the secure profile wording suggests.
Expected Behavior
If SecureIbex promises ICache ECC for all secure builds, then SecureIbex=1, ICache=1, ICacheECC=0 should either enable ECC automatically or fail elaboration with a clear diagnostic. If this combination is intentionally supported without ECC, the security documentation should clarify that ECC is an integration responsibility and the configuration should not imply the stronger protection.
Steps to reproduce the issue
- Use Ibex commit
8b8ee086aef72e0833b7f0493d9d33f1e4d3c8e2.
- From this issue directory, run
bash test/run_lint.sh and then bash test/source_contract_oracle.sh.
The trigger output is:
=== ibex_top secure-ecc-disabled-trigger: ICache=1 SecureIbex=1 ICacheECC=0 ICacheScramble=1 ===
result: Verilator lint exit 0
IBEX_TRIGGER_BRANCH=gen_noecc_wdata
The ECC-on reference also exits successfully, but selects the ECC generate/checking path.
The actual ibex_top A/B lint passed for both variants. The runner uses an isolated temporary FuseSoC overlay to expose the existing vlog parameters, without modifying the Ibex RTL checkout.
test.zip
Reproduction Test Case
The complete local test case is stored below this issue directory:
test/run_lint.sh runs the real ibex_top lint for the ECC-on reference and ECC-off trigger.
test/source_contract_oracle.sh checks the production parameter wiring, security documentation, and gen_ecc_wdata/gen_noecc_wdata branches.
The trigger must show SecureIbex=1 and ICacheECC=0 in the command and must select gen_noecc_wdata; the reference uses the documented secure profile with ICacheECC=1.
Possible Fixes
If ECC is mandatory for secure ICache configurations, enforce !SecureIbex || !ICache || ICacheECC at elaboration and/or force ICacheECC=1 whenever SecureIbex=1. Update the security documentation and ibex_configs.yaml together. If disabling ECC is an intentional integration option, state explicitly that SecureIbex alone does not provide ICache ECC and distinguish the weaker profile.
My Environment
EDA tool and version: FuseSoC 2.4.7 and Verilator 5.020. The actual-top lint replay passed for both the ECC-on reference and ECC-off trigger.
Operating system: Linux x86_64.
Version of the Ibex source code: 8b8ee086aef72e0833b7f0493d9d33f1e4d3c8e2.
Relevant RTL: rtl/ibex_top.sv:34-43, 383-396, rtl/ibex_icache.sv:286-315, 537; documented security contract: doc/03_reference/security.rst:105-107.
If this is confirmed as a real bug, I am glad to work on this issue.
Observed Behavior
With
ICache=1,SecureIbex=1,ICacheECC=0, andICacheScramble=1, the officialibex_toplint/elaboration accepts the parameter combination and passesICacheECC=0through independently ofSecureIbex(rtl/ibex_top.sv:34-43, 383-396). Inside the actual ICache,ICacheECC=0selectsgen_noecc_wdata(rtl/ibex_icache.sv:286-315) and omits the ECC-checking generate block (:537). The secure reference configuration (ICacheECC=1) elaborates the encoder/checker branches instead.Root Cause Analysis
SecureIbexandICacheECCare independently passed fromibex_topinto the core and ICache. The ICache generate condition is controlled byICacheECCalone, so the secure configuration can selectgen_noecc_wdatawithout an elaboration error. The security documentation and the parameter contract are therefore weaker or less explicit than the secure profile wording suggests.Expected Behavior
If SecureIbex promises ICache ECC for all secure builds, then
SecureIbex=1, ICache=1, ICacheECC=0should either enable ECC automatically or fail elaboration with a clear diagnostic. If this combination is intentionally supported without ECC, the security documentation should clarify that ECC is an integration responsibility and the configuration should not imply the stronger protection.Steps to reproduce the issue
8b8ee086aef72e0833b7f0493d9d33f1e4d3c8e2.bash test/run_lint.shand thenbash test/source_contract_oracle.sh.The trigger output is:
The ECC-on reference also exits successfully, but selects the ECC generate/checking path.
The actual
ibex_topA/B lint passed for both variants. The runner uses an isolated temporary FuseSoC overlay to expose the existing vlog parameters, without modifying the Ibex RTL checkout.test.zip
Reproduction Test Case
The complete local test case is stored below this issue directory:
test/run_lint.shruns the realibex_toplint for the ECC-on reference and ECC-off trigger.test/source_contract_oracle.shchecks the production parameter wiring, security documentation, andgen_ecc_wdata/gen_noecc_wdatabranches.The trigger must show
SecureIbex=1andICacheECC=0in the command and must selectgen_noecc_wdata; the reference uses the documented secure profile withICacheECC=1.Possible Fixes
If ECC is mandatory for secure ICache configurations, enforce
!SecureIbex || !ICache || ICacheECCat elaboration and/or forceICacheECC=1wheneverSecureIbex=1. Update the security documentation andibex_configs.yamltogether. If disabling ECC is an intentional integration option, state explicitly that SecureIbex alone does not provide ICache ECC and distinguish the weaker profile.My Environment
EDA tool and version: FuseSoC 2.4.7 and Verilator 5.020. The actual-top lint replay passed for both the ECC-on reference and ECC-off trigger.
Operating system: Linux x86_64.
Version of the Ibex source code:
8b8ee086aef72e0833b7f0493d9d33f1e4d3c8e2.Relevant RTL:
rtl/ibex_top.sv:34-43, 383-396,rtl/ibex_icache.sv:286-315, 537; documented security contract:doc/03_reference/security.rst:105-107.If this is confirmed as a real bug, I am glad to work on this issue.