target/arm/hvf: seed NO_RAW ID registers from isar.idregs[] on vCPU init
Commit 887eaa8a29 ("target/arm: implement FEAT_RNG_TRAP for RNDR/RNDRRS") gave ID_AA64ISAR0_EL1 a readfn so the RNDR field can reflect SCR_EL3.TRNDR at read time, and marked the cpreg ARM_CP_NO_RAW in the system-emulation path. HVF then trips its hvf_arch_init_vcpu() assertion that no ID register in hvf_sreg_list[] is NO_RAW, aborting on boot on Apple Silicon: Assertion failed: (!(ri->type & ARM_CP_NO_RAW)), function hvf_arch_init_vcpu, file hvf.c, line 1441. Reproduce with: qemu-system-aarch64 -M virt,accel=hvf -cpu host \ -nographic -display none -bios /dev/null Fix it the same way ID_AA64PFR0_EL1 already is: list HV_SYS_REG_ID_AA64ISAR0_EL1 in the SYNC_NO_RAW_REGS block in sysreg.c.inc so the assert loop skips it, and seed the vCPU's copy at init time. While here, unify how the three isar.idregs[]-backed ID registers are seeded. isar.idregs[] already holds QEMU's intended value for each (the host caps, probed once at realize via hv_vcpu_config_get_feature_reg(), plus any QEMU adjustment), so there is no need to read each register back from the vCPU first. Seed PFR0, ISAR0 and MMFR0 directly from isar.idregs[], dropping the two per-vCPU hv_vcpu_get_sys_reg() reads: - PFR0: take the GIC sysreg-interface bit from env->gicv3state, as the id_aa64pfr0_read() readfn does. Identical to the previous code whenever a GICv3 sysreg interface is present (the configuration HVF runs in practice); it differs only in that a vCPU with no GICv3 now reports ID_AA64PFR0_EL1.GIC == 0 instead of inheriting the host's value, which matches the field's meaning. - ISAR0: no overlay is needed; HVF does not expose EL3, so SCR_EL3.TRNDR is never set and the readfn is constant. - MMFR0: still clamp PARANGE to the chosen IPA size, updating isar.idregs[] in place because the page-table walker and the ID_AA64MMFR0_EL1 cpreg resetvalue read PARANGE back from there. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3533 Reported-by: Zenghui Yu <zenghui.yu@linux.dev> Suggested-by: Peter Maydell <peter.maydell@linaro.org> Fixes: 887eaa8a29 ("target/arm: implement FEAT_RNG_TRAP for RNDR/RNDRRS") Signed-off-by: Jason Wright <wrigjl@proton.me> Reviewed-by: Richard Henderson <richard.henderson@linaro.org> Tested-by: Zenghui Yu <zenghui.yu@linux.dev> Signed-off-by: Peter Maydell <peter.maydell@linaro.org>