Skip to content

SecureIbex can be configured without ICache ECC #2508

Description

@KnightGOKU

Observed Behavior

With ICache=1, SecureIbex=1, ICacheECC=0, and ICacheScramble=1, the official ibex_top lint/elaboration accepts the parameter combination and passes ICacheECC=0 through independently of SecureIbex (rtl/ibex_top.sv:34-43, 383-396). Inside the actual ICache, ICacheECC=0 selects gen_noecc_wdata (rtl/ibex_icache.sv:286-315) and omits the ECC-checking generate block (:537). The secure reference configuration (ICacheECC=1) elaborates the encoder/checker branches instead.

Root Cause Analysis

SecureIbex and ICacheECC are independently passed from ibex_top into the core and ICache. The ICache generate condition is controlled by ICacheECC alone, so the secure configuration can select gen_noecc_wdata without an elaboration error. The security documentation and the parameter contract are therefore weaker or less explicit than the secure profile wording suggests.

Expected Behavior

If SecureIbex promises ICache ECC for all secure builds, then SecureIbex=1, ICache=1, ICacheECC=0 should either enable ECC automatically or fail elaboration with a clear diagnostic. If this combination is intentionally supported without ECC, the security documentation should clarify that ECC is an integration responsibility and the configuration should not imply the stronger protection.

Steps to reproduce the issue

  1. Use Ibex commit 8b8ee086aef72e0833b7f0493d9d33f1e4d3c8e2.
  2. From this issue directory, run bash test/run_lint.sh and then bash test/source_contract_oracle.sh.

The trigger output is:

=== ibex_top secure-ecc-disabled-trigger: ICache=1 SecureIbex=1 ICacheECC=0 ICacheScramble=1 ===
result: Verilator lint exit 0
IBEX_TRIGGER_BRANCH=gen_noecc_wdata

The ECC-on reference also exits successfully, but selects the ECC generate/checking path.

The actual ibex_top A/B lint passed for both variants. The runner uses an isolated temporary FuseSoC overlay to expose the existing vlog parameters, without modifying the Ibex RTL checkout.

test.zip

Reproduction Test Case

The complete local test case is stored below this issue directory:

  • test/run_lint.sh runs the real ibex_top lint for the ECC-on reference and ECC-off trigger.
  • test/source_contract_oracle.sh checks the production parameter wiring, security documentation, and gen_ecc_wdata/gen_noecc_wdata branches.

The trigger must show SecureIbex=1 and ICacheECC=0 in the command and must select gen_noecc_wdata; the reference uses the documented secure profile with ICacheECC=1.

Possible Fixes

If ECC is mandatory for secure ICache configurations, enforce !SecureIbex || !ICache || ICacheECC at elaboration and/or force ICacheECC=1 whenever SecureIbex=1. Update the security documentation and ibex_configs.yaml together. If disabling ECC is an intentional integration option, state explicitly that SecureIbex alone does not provide ICache ECC and distinguish the weaker profile.

My Environment

EDA tool and version: FuseSoC 2.4.7 and Verilator 5.020. The actual-top lint replay passed for both the ECC-on reference and ECC-off trigger.

Operating system: Linux x86_64.

Version of the Ibex source code: 8b8ee086aef72e0833b7f0493d9d33f1e4d3c8e2.

Relevant RTL: rtl/ibex_top.sv:34-43, 383-396, rtl/ibex_icache.sv:286-315, 537; documented security contract: doc/03_reference/security.rst:105-107.

If this is confirmed as a real bug, I am glad to work on this issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions