HARTBREAKER: Deterministic Fuzzing of Multi-Hart RISC-V CPUs with Non-Deterministic Programs
Quentin Bordier, Tobias Kovats, Flavien Solt, Kaveh Razavi
Abstract
Hardware bugs threaten the correctness and security of modern CPUs. Relying on a deterministic correct baseline, pre-silicon fuzzing has proven to be an effective strategy for discovering deviations from correct behavior (i.e., bugs) in single-core CPUs. Modern CPUs, however, often feature multiple cores with complex interconnects that implement communication channels such as inter-processor interrupts or shared memory. Is it possible to effectively fuzz multicore CPUs despite their inherent non-deterministic operations? We make a key observation that multi-hart interactions may result in non-deterministic data flows, control flows, or combinations thereof. An efficient fuzzing campaign needs to manage this non-determinism without limiting the exploration of the possible state space that may lead to bugs. Our new multi-hart RISC-V fuzzer, called HartBreaker, achieves this with a judicious use of three determinism anchors: control- and data-flow anchors enable non-deterministic control- and dataflow interactions between harts while ensuring a correct execution of multi-hart test programs, achieving high testing throughput and simplified bug detection. Synchronization anchors bound the non-deterministic window across harts, enabling HartBreaker to detect bugs that do not contaminate the control flow. We test HartBreaker on five multi-hart designs, namely Rocket, BOOM, Toooba, NaxRiscv and XiangShan. HartBreaker discovers five new concurrency bugs in these designs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a98ff123-f403-4036-a847-df58f640828aRelated papers
- MorFuzz: Fuzzing Processor via Runtime Instruction Morphing enhanced Synchronizable Co-simulationJinyan Xu, Yiyuan Liu, Sirui He, Haoran Lin et al.USENIX Security 2023
- GoldenFuzz: Generative Golden Reference Hardware FuzzingLichao Wu, Mohamadreza Rostami, Huimin Li, Nikhilesh Singh et al.NDSS 2026 · 3 citations
- PortRush: Detect Write Port Contention Side-Channel Vulnerabilities via Hardware FuzzingPeihong Lin, Pengfei Wang, Lei Zhou, Gen Zhang et al.NDSS 2026
- BPUFuzzer: Effective Fuzz Testing for Branching Transient Execution Vulnerabilities of RISC-V CPURihui Sun, Jin Wu, Hanyin Liu, Zikang Tao et al.DAC 2025
- INSIGHT: Automatic Generation of Explanations for Efficient Identification of Hardware Bugs and UnderspecificationsVincent Quentin Ulitzsch, Alessandro Bertani, Peter W. Deutsch, David Langus Rodriguez et al.S&P 2026
