Compare commits

...

922 commits

Author SHA1 Message Date
Richard Henderson
324bb5ef83 IDE patches
- fix the logical CHS translation a guest selects with INITIALIZE
   DEVICE PARAMETERS: reject a translation the device may not accept
   instead of dying on a division by zero, report the default
   translation in IDENTIFY DEVICE words 1, 3 and 6 and the one in
   effect in words 54 to 58, keep those words in sync when the
   translation changes, migrate both the translation and the SET
   FEATURES 0xCC revert flag, and return the power-on defaults on a
   hardware reset rather than on every reset
 - harden the IDE and AHCI state a guest or an incoming migration
   stream can reach: reject an out-of-range PIO transfer window on
   load, refuse a PIO transfer with no command header, clear cur_cmd
   when the command list is unmapped, treat a failed PRDT walk as a
   transfer failure, reject a command header with an invalid FIS
   length, and drain the ports on teardown so that a request cannot
   outlive an unplug
 - report ATAPI UDMA5 with a matching standard and cable
 - extend the IDE/AHCI qtest coverage for all of the above
 
 Signed-off-by: Denis V. Lunev <den@openvz.org>
 CC: Stefan Hajnoczi <stefanha@redhat.com>
 CC: John Snow <jsnow@redhat.com>
 CC: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
 -----BEGIN PGP SIGNATURE-----
 
 iQJDBAABCgAtFiEEC66qh9MCCtwRUOUfXgdxtstmbKsFAmqOyM4PHGRlbkBvcGVu
 dnoub3JnAAoJEF4HcbbLZmyrGSUP+wR5KLZXUCKwEXDM95UnUiDFQQUNO0Ko7XGv
 v8hHnTWRb3pvkIh/lJ9ECWPw0NPRKjugkSm9IGDUCndgw6+AbPOTP+tfJXFNK965
 NFisLDoJCcPrrFNCL+T6EQyPBI2GG1vl9t4bg75GeT55WTUiK4Cv0710COZMV3kc
 RlN3LzxCKLqc1wSGcqOLyObKTw97vL5pmB/xcOn/ciN1vOm4d5jgzvs1NqFcO1CF
 btlqGisG9aRlqecKRgKGeLCGXtUoYq0MBuddsMeDSLD/H4FeZ1W0qYb/e2Zv97Bn
 pdAyKb7Fs6OXV77qSUU5N1tSzALG+mn92BegHoyvuK/YRc8eDdwsiB8+OE7XHRbZ
 Atewt2CVfej+lyZH5LHe72esWrNqpcHSwvTpvP26oxJq3qwUXynKh8VqUnnIwEIa
 i1Y7ATnIGXNd1+w68Gk0TDu2zByUPVi4dw91hQR80YY2L9ZWwN5N2u3WCo81ZpAs
 8hFk44vCAtGtfRZdLPbIboMfVLExRiBIwfNxJNy7btYQLWkvI05s8K5OmyBXeCwh
 rtMQi9745BGcMVCtTIAiUjO/EHEkGtFaAs3JUdN/bdx2lzr6l8jpoofqr6rlZT2k
 R3VNa+r5iw0B/otn/2AEAN6alZpQt6RInenY6LXQlfwCKREWAbD41o3VgfWZVn3P
 VNrAjpDO
 =8aHT
 -----END PGP SIGNATURE-----

Merge tag 'pull-ide-2026-08-26' of https://gitlab.com/dlunev/qemu into staging

IDE patches

- fix the logical CHS translation a guest selects with INITIALIZE
  DEVICE PARAMETERS: reject a translation the device may not accept
  instead of dying on a division by zero, report the default
  translation in IDENTIFY DEVICE words 1, 3 and 6 and the one in
  effect in words 54 to 58, keep those words in sync when the
  translation changes, migrate both the translation and the SET
  FEATURES 0xCC revert flag, and return the power-on defaults on a
  hardware reset rather than on every reset
- harden the IDE and AHCI state a guest or an incoming migration
  stream can reach: reject an out-of-range PIO transfer window on
  load, refuse a PIO transfer with no command header, clear cur_cmd
  when the command list is unmapped, treat a failed PRDT walk as a
  transfer failure, reject a command header with an invalid FIS
  length, and drain the ports on teardown so that a request cannot
  outlive an unplug
- report ATAPI UDMA5 with a matching standard and cable
- extend the IDE/AHCI qtest coverage for all of the above

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Stefan Hajnoczi <stefanha@redhat.com>
CC: John Snow <jsnow@redhat.com>
CC: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>

# -----BEGIN PGP SIGNATURE-----
#
# iQJDBAABCgAtFiEEC66qh9MCCtwRUOUfXgdxtstmbKsFAmqOyM4PHGRlbkBvcGVu
# dnoub3JnAAoJEF4HcbbLZmyrGSUP+wR5KLZXUCKwEXDM95UnUiDFQQUNO0Ko7XGv
# v8hHnTWRb3pvkIh/lJ9ECWPw0NPRKjugkSm9IGDUCndgw6+AbPOTP+tfJXFNK965
# NFisLDoJCcPrrFNCL+T6EQyPBI2GG1vl9t4bg75GeT55WTUiK4Cv0710COZMV3kc
# RlN3LzxCKLqc1wSGcqOLyObKTw97vL5pmB/xcOn/ciN1vOm4d5jgzvs1NqFcO1CF
# btlqGisG9aRlqecKRgKGeLCGXtUoYq0MBuddsMeDSLD/H4FeZ1W0qYb/e2Zv97Bn
# pdAyKb7Fs6OXV77qSUU5N1tSzALG+mn92BegHoyvuK/YRc8eDdwsiB8+OE7XHRbZ
# Atewt2CVfej+lyZH5LHe72esWrNqpcHSwvTpvP26oxJq3qwUXynKh8VqUnnIwEIa
# i1Y7ATnIGXNd1+w68Gk0TDu2zByUPVi4dw91hQR80YY2L9ZWwN5N2u3WCo81ZpAs
# 8hFk44vCAtGtfRZdLPbIboMfVLExRiBIwfNxJNy7btYQLWkvI05s8K5OmyBXeCwh
# rtMQi9745BGcMVCtTIAiUjO/EHEkGtFaAs3JUdN/bdx2lzr6l8jpoofqr6rlZT2k
# R3VNa+r5iw0B/otn/2AEAN6alZpQt6RInenY6LXQlfwCKREWAbD41o3VgfWZVn3P
# VNrAjpDO
# =8aHT
# -----END PGP SIGNATURE-----
# gpg: Signature made Wed 26 Aug 2026 04:06:54 AM PDT
# gpg:                using RSA key 0BAEAA87D3020ADC1150E51F5E0771B6CB666CAB
# gpg:                issuer "den@openvz.org"
# gpg: Good signature from "Denis V. Lunev <den@openvz.org>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 0BAE AA87 D302 0ADC 1150  E51F 5E07 71B6 CB66 6CAB

* tag 'pull-ide-2026-08-26' of https://gitlab.com/dlunev/qemu: (28 commits)
  tests/qtest/ide-test: cover the UDMA5 identify words
  hw/ide: report ATAPI UDMA5 with a matching standard and cable
  tests/qtest/ahci: regression test for a request outliving an unplug
  hw/ide/ahci: drain the ports on teardown
  hw/ide/ahci: reject a command header with an invalid FIS length
  hw/ide/ahci: treat a failed PRDT walk as a PIO transfer failure
  tests/qtest/ahci: regression test for a PIO write vs. engine stop
  hw/ide/ahci: clear cur_cmd when the command list is unmapped
  hw/ide/ahci: refuse a PIO transfer with no command header
  tests/qtest/ide-test: cover the migrated PIO transfer window
  hw/ide: reject an out-of-range PIO transfer window on load
  hw/ide: drop a redundant interrupt from INITIALIZE DEVICE PARAMETERS
  tests/qtest/ide-test: cover the CHS translation across resets
  hw/ide: revert the CHS translation on a hardware reset
  tests/qtest/ide-test: cover the IDENTIFY DEVICE geometry words
  tests/qtest/ide-test: cover a rejected CHS translation in the stream
  tests/qtest/ide-test: cover the CHS translation across migration
  hw/ide: migrate the power-on defaults revert flag
  hw/ide: migrate the logical CHS translation
  hw/ide: restore the power-on device state before loading
  ...

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-26 11:26:47 -07:00
Denis V. Lunev
dd90d3cd73 tests/qtest/ide-test: cover the UDMA5 identify words
/ide/identify/udma and /ide/identify/udma_atapi check that a device
advertising UDMA mode 5 claims a standard that defines it and reports the
hardware reset result, on the disk and on the CD-ROM. The ATAPI case also
checks that the words obsolete in IDENTIFY PACKET DEVICE data stay
clear, and that the reset result reports a passed diagnostic, which
only the packet path does so far.

Cc: John Snow <jsnow@redhat.com>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
60faaa8c3b hw/ide: report ATAPI UDMA5 with a matching standard and cable
IDENTIFY PACKET DEVICE claims UDMA mode 5 in word 88 while word 80
reports support only up to ATA/ATAPI-4. UDMA5 first appears in
ATA/ATAPI-6; ATA/ATAPI-5 stops at mode 4. Bits 3:1 of word 80 are
obsolete in IDENTIFY PACKET DEVICE data as well, so the old 001eh
claimed three standards that mean nothing for a packet device. Report
0070h, ATA/ATAPI-4 through ATA/ATAPI-6.

Word 93 was left unset, so nothing reported the 80-conductor cable that
UDMA5 needs. Fill it in, but only for a parallel attachment: ACS-3
7.13.6.41 gives word 93 of IDENTIFY PACKET DEVICE data the meaning of
word 93 of IDENTIFY DEVICE data, where "For SATA devices, word 93 shall
be set to the value 0000h". A cleared ncq_queues is how both identify
paths already tell a parallel attachment from an AHCI one.

The device 0 reset result is 0fh rather than the 01h ide_identify()
reports: bit 3 says diagnostics passed, which they did, and bits 2:1
say the device number came from some other method, the only one of the
four encodings that is not a jumper, CSEL or reserved.

Raising word 80 has a second effect. Linux decides a device is SATA in
ata_id_is_sata(), which wants word 93 clear and word 80 at ATA/ATAPI-5
or later. An AHCI CD-ROM satisfied neither condition before and was
taken for a parallel device; now it satisfies both.

Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4038
Cc: John Snow <jsnow@redhat.com>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
0b7cc42531 tests/qtest/ahci: regression test for a request outliving an unplug
Add /ahci/io/{ncq,dma,pio}/unplug: arm a read against a null-co backend
whose latency keeps it in flight, then eject the controller through the
ACPI ejection register. Each of the three reaches the freed AHCIDevice
array by a different route, so covering one command class would leave
the other two untested.

That register is what a guest writes to finish a PCI unplug, and unlike
the pciehp attention button it reaches ahci_uninit() with no secondary
bus reset, so nothing cancels the request on the way. It also dictates
the machine: q35 has no ACPI hotplug on pcie.0, so the eject has no
effect there.

The latency is what holds the request; a blkdebug breakpoint cannot
stand in for it, because cancelling a suspended request waits for it and
the unplug would never return.

Unfixed, all three fail reliably under AddressSanitizer. On a plain build
the use-after-free only faults when the freed page has been returned, so
expect the odd pass there.

Cc: John Snow <jsnow@redhat.com>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
5bdc12fed5 hw/ide/ahci: drain the ports on teardown
ahci_uninit() frees s->dev without touching the requests still in flight.
The only blk_aio_cancel() for them lives in ahci_reset_port(), which the
unplug path does not run, and the ide-hd child's own drain is deferred
through call_rcu so it happens after the free. A guest that powers the
root port slot off through SLTCTL, or writes the ACPI ejection register,
while a read is outstanding therefore leaves the completion to run
against freed memory.

A plain device_del is not affected: the pciehp attention-button flow
resets the secondary bus first, which cancels through the reset path.
Surprise removal is what skips it.

Cancelling the NCQ requests alone is not enough. IDEDMA and IDEBus are
embedded in AHCIDevice, so a plain DMA read reaches the freed array
through dma_blk_cb() and a PIO read through ide_buffered_readv_cb(),
neither of which the NCQ bookkeeping covers. ide_exit() drains nothing
and frees io_buffer, which an outstanding request may still target.

Move the NCQ cancel loop into a helper, run it from ahci_uninit() too,
and drain each port before ide_exit() so no class of request can outlive
the allocation. Delete check_bh there as well; qemu_bh_new_guarded() in
check_cmd() has no counterpart on this path either.

Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4069
Cc: John Snow <jsnow@redhat.com>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
795af987ce hw/ide/ahci: reject a command header with an invalid FIS length
AHCI 1.3.1 defines CFL in the command header as the "Length of the
Command FIS", where "A length of '0' or '1' is illegal" and "The
maximum value allowed is 10h, or 16 DW". handle_cmd() never looks at
it, so an all-zero command header is executable: its zero tbl_addr maps
a command table at guest physical address 0, and a guest that has put a
valid Register H2D FIS there gets it run.

That is the reachability a guest gains by pointing PxCLB at an MMIO
region, where the CLB is a zero-filled bounce buffer rather than
anything the guest wrote.

Reject a header whose CFL falls outside the legal range. Nothing else
consults it; the command FIS is always mapped at its full 128 bytes.

The slot is dropped without reporting anything, as the unmappable
command table beside it already is. No PxIS bit describes a malformed
command header: HBFS is for a host bus error, "such as a bad software
pointer", which is why the short mapping below raises it and this does
not.

Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4043
Cc: John Snow <jsnow@redhat.com>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
2713717148 hw/ide/ahci: treat a failed PRDT walk as a PIO transfer failure
ahci_dma_prepare_buf() returns -1 when it cannot build a scatter-gather
list, the PRDTL of zero case among them. ahci_pio_transfer() tests the
result for truth, so a failure sets has_sglist and the transfer goes
ahead against whatever s->sg holds. AHCI 1.3.1 is explicit about the
zero case: "If this field is '0', then no data transfer shall occur
with the command."

Test for a positive byte count instead. A successful walk that yields
nothing to transfer is already handled by the size check below.

Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4043
Cc: John Snow <jsnow@redhat.com>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
d05ae87e7a tests/qtest/ahci: regression test for a PIO write vs. engine stop
Add /ahci/io/pio/engine_stop: hold the backend write of a two-sector
PIO write with a blkdebug breakpoint, clear PxCMD.ST so the command
list is unmapped underneath it, then let the write complete. The
second DRQ phase runs from that completion and reaches
ahci_pio_transfer() with no command header.

Cc: John Snow <jsnow@redhat.com>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
a2fbf1785b hw/ide/ahci: clear cur_cmd when the command list is unmapped
ahci_unmap_clb_address() drops the CLB mapping but leaves cur_cmd
pointing into it. The cancel added by commit d9f78431d8 covers the
buffered reads, and ide_cancel_dma_sync() drains bus->dma->aiocb, but
neither reaches IDEState::pio_aiocb: a PIO write started before the
guest cleared PxCMD.ST completes afterwards and runs its second DRQ
phase against the stale header.

That is harmless while the CLB is direct RAM, because unmapping it
changes nothing. It is a use-after-free once PxCLB points at an MMIO
region, where address_space_map() hands out a bounce buffer that
dma_memory_unmap() then frees.

Clear cur_cmd after the cancel, so nothing reachable from a later
completion still refers to the freed mapping.

Reported-by: Katherine Leaver <katherine.j.leaver@gmail.com>
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3719
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4043
Cc: John Snow <jsnow@redhat.com>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
d7f16bad8f hw/ide/ahci: refuse a PIO transfer with no command header
ahci_map_clb_address() already clears cur_cmd, so every consumer of it
has to cope with there being no current command. ahci_pio_transfer(),
ahci_commit_buf() and ahci_populate_sglist() all dereference it
unconditionally instead.

Give the three of them a NULL check. Declaring the data transferred
anyway is not enough: ide_transfer_start() goes on to call the end
transfer function, and for a multi-sector write that is
ide_sector_write(), which commits an io_buffer the guest never
refilled. Clearing PxCMD.ST during a WRITE SECTOR(S) of two sectors
therefore writes the first sector's contents over the second, at a
sector the guest chose.

Let pio_transfer report that nothing was transferred and halt there, so
no callback acts on a buffer that was never filled. Only the AHCI HBA
implements the callback, so the signature change is local to it.

Cc: John Snow <jsnow@redhat.com>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
e46245cd3b tests/qtest/ide-test: cover the migrated PIO transfer window
/ide/migration/pio_state_rejected leaves a drive in DRQ so the source
streams ide_drive/pio_state, rewrites cur_io_buffer_offset to the end of
the io_buffer, and expects the destination to refuse the load.

It asserts the window the source wrote before overwriting it, so a wrong
guess at the stream layout fails the test rather than passing it for the
wrong reason.

Cc: John Snow <jsnow@redhat.com>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
1332990194 hw/ide: reject an out-of-range PIO transfer window on load
ide_drive_pio_post_load() validates end_transfer_fn_idx but takes
cur_io_buffer_offset and cur_io_buffer_len straight from the migration
stream, so data_ptr and data_end can be placed anywhere within +-2GB of
the 131076-byte io_buffer allocation. Both fields are signed 32-bit.

The subsection loader consumes every subsection present in the stream
without consulting needed(), so a crafted stream can inject
ide_drive/pio_state for a drive that was never in a DRQ state. Once
data_end is out of bounds, ide_data_writew() only compares the guest's
pointer against that same bogus data_end, and the resumed guest turns a
repeated outw to the data port into a controlled 16-bit heap write.
end_transfer_fn_idx picks the direction, so the read side of the same
code path leaks host heap instead.

Validate the window against io_buffer_total_len and fail the load. The
subtraction form avoids overflowing the addition.

Reported-by: XlabAI Team of Tencent Xuanwu Lab <xlabai@tencent.com>
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4179
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3738
Cc: John Snow <jsnow@redhat.com>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
e8a3b42ae5 hw/ide: drop a redundant interrupt from INITIALIZE DEVICE PARAMETERS
ide_bus_exec_cmd() raises the interrupt for every command handler that
reports the command complete, which cmd_specify() does, so the request it
raised itself was the first of two. The one from ide_bus_exec_cmd() is the
one that belongs there, being raised after BSY is cleared and after
ide_cmd_done() has let the bus master post its own completion.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
d1634ae78d tests/qtest/ide-test: cover the CHS translation across resets
A translation the guest selected has to survive a software reset and not a
hardware one, and the two arrive at the same ide_reset(), so a fix for
either direction can break the other. Select a translation, put the drive
through a software reset and then through a machine reset, and name the
sector each translation picks along the way.

The marker read says which translation the device is addressing the disk
with, while IDENTIFY DEVICE words 55 and 56 say which one it reports. The
machine reset leaves the PCI command register cleared, so the device has
to be enabled again before the ports answer.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
cafb3d9625 hw/ide: revert the CHS translation on a hardware reset
A power on or hardware reset returns the device parameters to their
power-on defaults (ATA-5 9.1). A software reset keeps them unless the
guest asked with SET FEATURES 0xCC for the next reset to revert (ATA-5 9.2
and 8.16.6). ide_reset() applied the second rule to every reset, so a
translation a guest selected outlived the reset of the machine it selected
it on, and the guest that came up next addressed the disk through a
geometry it never asked for.

Neither ide_reset() nor, for AHCI, ide_bus_reset() could tell the two
apart: a guest clearing SRST in the second host to device FIS of the
software reset protocol lands in the same ahci_reset_port() as a COMRESET
or a reset of the host adapter. Pass the kind down from the callers, which
do know.

ide_drive_pre_load() stays necessary: it restores the same fields, but a
vmstate cannot depend on its device having been reset first.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Fixes: 176e4961bb ("hw/ide/core.c: Implement ATA INITIALIZE_DEVICE_PARAMETERS command")
Signed-off-by: Denis V. Lunev <den@openvz.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
0720913323 tests/qtest/ide-test: cover the IDENTIFY DEVICE geometry words
INITIALIZE DEVICE PARAMETERS has to leave the geometry the drive came with
in words 3 and 6 and describe the translation it selected in words 54 to
58, and the data is cached, so which of the two a guest is told depends on
when it first asked. Cover both orders, as each alone leaves half of it
untested: one test has the data built while the default is in effect and
then replaces the translation, which the cached copy has to follow, the
other replaces it before the first IDENTIFY DEVICE, where the words
describing the default have to keep doing so.

Factor the reading of the data out of test_specify_zero_sectors() for the
three of them to share.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
5be90dfbc0 tests/qtest/ide-test: cover a rejected CHS translation in the stream
ide_drive_post_load() refuses a logical CHS translation that no command
could have selected, as the fields are a divisor in ide_set_sector() and a
factor in ide_get_sector(). Nothing exercised that, a fixed QEMU having no
way to produce such a stream.

Migrate a guest that selected a translation to a file, replace the number
of sectors per logical track in the subsection with a zero, and let a
destination read the result back. The load has to fail rather than take
the value, so the destination is asked not to exit on a failed incoming
migration and its migration status is what the test looks at.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
ef64d2758e tests/qtest/ide-test: cover the CHS translation across migration
Both defects here are silent: the guest addresses the disk in the
translation it selected while the device translates with another, so reads
and writes land on a sector nobody asked for. Put a marker in each of the
two candidate sectors and name the one the translation picked. CHS 0/1/1
is LBA 32 under 8 heads and 32 sectors per track and LBA 63 under the
16/63 the test drive is configured with; both markers are written by LBA,
which no translation can influence.

A translation the guest selected has to survive migration, and one it
selected after a snapshot was taken must not outlive loading that snapshot
back. The second needs a qcow2 image, so it is skipped without qemu-img.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
67a6d29c28 hw/ide: migrate the power-on defaults revert flag
SET FEATURES 0xCC asks for the next reset to revert to the power-on
defaults, and 0x66 cancels that; ide_reset() restores the default CHS
translation only when the flag is set. It was in no VMStateDescription, so
it always arrived cleared.

That was invisible while the destination had the default translation
anyway. Now that the translation is migrated, the flag decides how long it
stays in effect: without it, a reset after the migration reverts the
geometry on the source and keeps it on the destination.

Send it only alongside a translation the guest replaced. On the default
geometry it reverts to what is already in effect, so such a guest need not
lose its migration to an older QEMU over a subsection that changes
nothing.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Fixes: 176e4961bb ("hw/ide/core.c: Implement ATA INITIALIZE_DEVICE_PARAMETERS command")
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
ba4a996631 hw/ide: migrate the logical CHS translation
INITIALIZE DEVICE PARAMETERS lets a guest replace the logical CHS
translation used to turn the CHS registers into an LBA, but s->heads and
s->sectors were in no VMStateDescription. The destination rebuilt them
from the drive configuration, so a guest that had selected one of its own
kept addressing the disk in it while the device translated with the
default, landing on sectors nobody asked for.

Add a subsection for it, sent only when the guest replaced the default, so
that migration to an older QEMU keeps working for every other guest.
s->cylinders is left out, as no command changes it.

Validate what is loaded in the existing post_load: ide_get_sector()
multiplies by these fields and ide_set_sector() divides by them.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Fixes: 176e4961bb ("hw/ide/core.c: Implement ATA INITIALIZE_DEVICE_PARAMETERS command")
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
33db64cf28 hw/ide: restore the power-on device state before loading
Loading a snapshot reuses the IDEState of the machine it is loaded into:
load_snapshot() resets the machine and then feeds the stream into the
existing devices. The reset does not help, as ide_reset() restores the
logical CHS translation only when the guest asked for power-on defaults to
be reverted with SET FEATURES 0xCC.

A guest that replaced the translation with INITIALIZE DEVICE PARAMETERS
therefore keeps it across the load of a snapshot taken before it did,
while the restored guest expects the geometry of that moment. Every CHS
access then lands on a sector other than the one asked for, with no error
reported. s->reset_reverts survives a load the same way.

Add a pre_load restoring the defaults, which
docs/devel/migration/main.rst recommends for state a stream need not
carry, and which the following subsections rely on. The
RESET_TYPE_SNAPSHOT_LOAD marking that reset would be another way to
recognise the case, but no IDE controller can see it while they all use
device_class_set_legacy_reset().

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Fixes: 176e4961bb ("hw/ide/core.c: Implement ATA INITIALIZE_DEVICE_PARAMETERS command")
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
b5542796b3 hw/ide: keep the IDENTIFY DEVICE current geometry in sync
Bit 0 of IDENTIFY DEVICE word 53 says that words 54 to 58 describe the CHS
translation in effect, and ATA-5 8.16.8 has INITIALIZE DEVICE PARAMETERS
set words 55 and 56 to the heads and sectors per track it was given. The
data is built once and then cached, so those words kept describing
whatever was in effect when a guest first asked for IDENTIFY DEVICE: the
device reported one geometry while addressing the medium with another, and
nothing reported an error. The revert SET FEATURES 0xCC asks for on the
next reset left the same disagreement.

Do not drop the cached data on a change, as parts of it are guest state
rather than a description of the drive: SET FEATURES records the write
cache setting in word 85, which ide_drive_post_load() reads back after
migration. Refresh the affected words in place instead, the way
ide_identify_size() does for the capacity words.

An ATAPI device has no translation but does take SET FEATURES 0xCC, so
leave its IDENTIFY PACKET DEVICE data alone, where those words differ.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Fixes: 176e4961bb ("hw/ide/core.c: Implement ATA INITIALIZE_DEVICE_PARAMETERS command")
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
747679ca59 hw/ide: factor out the IDENTIFY DEVICE current geometry words
Words 54 to 58 of IDENTIFY DEVICE describe the CHS translation in effect
and the capacity it addresses. Both ide_identify() and
ide_cfata_identify() fill them the same way while building their cached
data.

Move them into ide_identify_chs(), so that the next change can refresh
them in place once the translation changes, the way ide_identify_size()
does for the capacity words.

No functional change.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
adf1152b34 hw/ide: name the retired IDENTIFY DEVICE words the device fills in
Words 4, 5 and 20 have carried an "XXX: retired, remove ?" since the
device was written, and word 21 is labelled a cache size when it is a
buffer size. ATA-4 8.12.13 retired words 4 and 5, 8.12.17 retired words
20 and 21, and ATA-5 keeps all four that way.

Retired is not a reason to drop them. ATA-5 3.2.3.6 says a retired word
that is still used shall have "the meaning or functionality as described
in previous standards", and that is what these carry: ATA-1 9.9.3, 9.9.4
and 9.9.7 define the unformatted bytes per track and per sector and the
buffer type, and the ATA-1 IDENTIFY table gives word 21 as the buffer
size in 512 byte increments. Software old enough to read them gets what
it expects, so answer the question rather than leave it open.

Word 22 is obsolete rather than retired (ATA-4 8.12.18) and already
carries its ATA-1 9.9.8 name, so leave it alone.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:19 +02:00
Denis V. Lunev
0df27c66dc hw/ide: report the default CHS translation in IDENTIFY DEVICE
IDENTIFY DEVICE words 1, 3 and 6 describe the default CHS translation,
and ATA-5 8.16.8 requires INITIALIZE DEVICE PARAMETERS to leave them
alone; the translation in effect is described by words 54 to 56 instead.
Words 3 and 6 were filled from s->heads and s->sectors, which the command
replaces, so a guest that selected a translation of its own was told that
its choice was what the drive came with, and could no longer find out the
default. Word 1 is already right, as no command changes s->cylinders.

Report s->drive_heads and s->drive_sectors, which ide_init_drive() keeps
for exactly this, along with the retired word 4 derived from them. The
CompactFlash data labels those words as the default geometry too, and
INITIALIZE DEVICE PARAMETERS is accepted for CFA drives, so fix both.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Cc: qemu-stable@nongnu.org
Fixes: 176e4961bb ("hw/ide/core.c: Implement ATA INITIALIZE_DEVICE_PARAMETERS command")
Signed-off-by: Denis V. Lunev <den@openvz.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-26 12:59:18 +02:00
Denis V. Lunev
d6960ecdde tests/qtest/ahci: cover the sector count of INITIALIZE DEVICE PARAMETERS
The sector count register of a legacy port is eight bits wide, so
ide-test can only reach the lower end of the range the command has to
refuse. A register FIS carries a 16 bit count, which leaves AHCI as the
only way to ask for a translation of 256 sectors per logical track or
more.

Ask for 0, 256 and 65535 sectors and expect each to be aborted, then ask
for 32 and expect it to be accepted, so that the check cannot pass by
refusing everything.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:18 +02:00
Denis V. Lunev
5e16adf555 tests/qtest/libqos/ahci: allow a count and an expected error
A command that transfers no data can still take an argument in the count
register of the register FIS, and a test may well expect such a command
to be aborted. AHCICommand is private to the library, so add two
setters: ahci_command_set_count() writes the count of a non-data
command, and ahci_command_expect_error() records the error register bits
the command is expected to complete with, which is what
ahci_atapi_test_ready() does inline for a sense key today.

INITIALIZE DEVICE PARAMETERS is the first user of both, so describe it
in the command properties table as well.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:18 +02:00
Denis V. Lunev
0905ef5b6d tests/qtest/ide-test: cover a CHS translation with zero sectors
Ask for zero sectors per logical track via INITIALIZE DEVICE PARAMETERS
and check that the command is aborted, that IDENTIFY DEVICE still reports
the translation that was in effect before, and that a CHS read then
completes normally rather than killing QEMU with SIGFPE.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-26 12:59:18 +02:00
Denis V. Lunev
6c712a86f6 hw/ide: reject an unsupported CHS translation
ide_set_sector() divides by (s->heads * s->sectors) when the drive is
addressed in CHS mode. Both come from the guest via INITIALIZE DEVICE
PARAMETERS, and cmd_specify() stored them without any check, so a guest
asking for zero sectors per logical track killed QEMU with SIGFPE on the
completion of the first CHS read or write. s->heads is safe, as the
command passes a heads-1 value.

The count has an upper bound as well. The legacy sector count register is
eight bits wide, but handle_cmd() takes the count from a 16 bit field of
the register FIS, so an AHCI guest can ask for up to 65535 sectors per
track, and the CHS branch of ide_get_sector() then overflows the int it
multiplies cylinder, heads and sectors in.

ATA-5 6.2 numbers CHS sectors from one and ATA-2 D.2.8 limits IDENTIFY
DEVICE word 56 to 1 through 255, so neither end is a translation a device
may accept. ATA-5 8.16.6 requires an unsupported one to be reported as an
aborted command: do that, leave the translation in effect alone, and
refuse the value rather than checking it at every use.

Cc: John Snow <jsnow@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Cc: qemu-stable@nongnu.org
Fixes: 176e4961bb ("hw/ide/core.c: Implement ATA INITIALIZE_DEVICE_PARAMETERS command")
Reported-by: Zheyu Ma <zheyuma97@gmail.com>
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/2399
Signed-off-by: Denis V. Lunev <den@openvz.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-26 12:59:18 +02:00
Richard Henderson
fe11f459f6 Various fixes
Collect various graphics & chardev fixes, and some others.
 
 Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmqNeowACgkQ2ujhCXWW
 nOWcsg//VwpHLApYC+ovKfZJm+4m0NUydmsxsYnQXSNhkPEueXMFPu91qu6sLW+c
 T8eRDwCZaItM4te6nKQ46RiD7GOw5M7AB+D7F6H7za5L8+I7j2QGzTz4N1FQnFLL
 0t3FTjzgNri99/UFd1Tpvkh3r4tmLRN1gvGIslvfVtpXLPq0GlVmseDY+Tih4Vz9
 TZn0jAg1WoR4v4YrtkfWvk/Dl5nzM3CRTiqLYz1/jfUB4kUpo/VxU1pk1Ky3LglK
 osrn6pcWxsFD2VLNZwoIMVzrdLjA9w7cIPwLI3JkNop3MD0GtSkAIoT4nSGji8uI
 Ck3CeuQKwZzHeBb4RJBAjEnVXJSpIhgLD5uQ3B4oIGMvfH0FxUphXZ6I77kehs8V
 awJwlE5c1tsuHcdcj67rrrcW3rzMVdDVCyin+xLJw7TkfofV9P/WH88pGO19EdOY
 eyNuwZLHDmrw08KzGEHlzoPRwh01+ihnTB+/eTPJjDDsOgIIQLjjeD06a878XUkm
 bLFnQktMr0DKFwx1wqkKXAqKLAvoWDTcDhlN9a67Y2G1MsGvROmLOsl4EPFqyfK5
 +phEDzZvRD4dWm1vZhI1ZUfORfTXd67naBLAyvSvFZHEbiDtji6RplmSaP8MgA21
 dRWRkUxlfQp0cIgzq/5DgnA3I0buVwfGxz8oeoQDwe2yXPdJBEs=
 =2qCQ
 -----END PGP SIGNATURE-----

Merge tag 'fixes-pr-v1' of https://gitlab.com/marcandre.lureau/qemu into staging

Various fixes

Collect various graphics & chardev fixes, and some others.

Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmqNeowACgkQ2ujhCXWW
# nOWcsg//VwpHLApYC+ovKfZJm+4m0NUydmsxsYnQXSNhkPEueXMFPu91qu6sLW+c
# T8eRDwCZaItM4te6nKQ46RiD7GOw5M7AB+D7F6H7za5L8+I7j2QGzTz4N1FQnFLL
# 0t3FTjzgNri99/UFd1Tpvkh3r4tmLRN1gvGIslvfVtpXLPq0GlVmseDY+Tih4Vz9
# TZn0jAg1WoR4v4YrtkfWvk/Dl5nzM3CRTiqLYz1/jfUB4kUpo/VxU1pk1Ky3LglK
# osrn6pcWxsFD2VLNZwoIMVzrdLjA9w7cIPwLI3JkNop3MD0GtSkAIoT4nSGji8uI
# Ck3CeuQKwZzHeBb4RJBAjEnVXJSpIhgLD5uQ3B4oIGMvfH0FxUphXZ6I77kehs8V
# awJwlE5c1tsuHcdcj67rrrcW3rzMVdDVCyin+xLJw7TkfofV9P/WH88pGO19EdOY
# eyNuwZLHDmrw08KzGEHlzoPRwh01+ihnTB+/eTPJjDDsOgIIQLjjeD06a878XUkm
# bLFnQktMr0DKFwx1wqkKXAqKLAvoWDTcDhlN9a67Y2G1MsGvROmLOsl4EPFqyfK5
# +phEDzZvRD4dWm1vZhI1ZUfORfTXd67naBLAyvSvFZHEbiDtji6RplmSaP8MgA21
# dRWRkUxlfQp0cIgzq/5DgnA3I0buVwfGxz8oeoQDwe2yXPdJBEs=
# =2qCQ
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 25 Aug 2026 04:20:44 AM PDT
# gpg:                using RSA key 87A9BD933F87C606D276F62DDAE8E10975969CE5
# gpg: Good signature from "Marc-André Lureau <marcandre.lureau@redhat.com>" [unknown]
# gpg:                 aka "Marc-André Lureau <marcandre.lureau@gmail.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 87A9 BD93 3F87 C606 D276  F62D DAE8 E109 7596 9CE5

* tag 'fixes-pr-v1' of https://gitlab.com/marcandre.lureau/qemu:
  hw/input/ps2: say why unknown keyboard commands draw a resend
  hw/input/ps2: answer unknown mouse commands with a resend
  hw/display/virtio-gpu: Validate resource per command
  hw/display/virtio-gpu: Check cursor data presence
  hw/display/virtio-gpu: Propagate udmabuf errors
  hw/display/virtio-gpu: Avoid mmap() for empty blob
  hw/display/virtio-gpu: Avoid creating empty udmabuf
  hw/display/vga: fix text-mode OOB write after a graphics surface switch
  chardev: Don't unregister yank upon async path connection failure
  tests/functional: fix pylint false positives for cv2 module
  ui/egl: fix qemu_egl_display type
  ui/egl: fix render node cleanup order
  tests: tag slow tests with 'slow' suite for easy filtering
  crypto: fix build against nettle >= 4
  virtio-gpu: use g_try_malloc to avoid guest-triggered abort
  hw/display/qxl: validate primary surface stride against width
  hw/core/machine: fix fdt memory leak
  migration/multifd: fix Error leak in multifd_recv_terminate_threads()
  hw/misc: fix trace-events

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-25 06:48:55 -07:00
Christian Quante
a88191a0ca hw/input/ps2: say why unknown keyboard commands draw a resend
The keyboard path has answered unknown commands with KBD_REPLY_RESEND
since commit 06b3611fc2 ("ps2: reject unknown commands, instead of
blindly accepting them"), but never said why. Give it the comment the
mouse path just gained, so the reasoning is written down in both
places.

Suggested-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Christian Quante <christian@quante.one>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Message-ID: <20260825075127.34876-3-christian@quante.one>
2026-08-25 15:20:44 +04:00
Christian Quante
0846740652 hw/input/ps2: answer unknown mouse commands with a resend
ps2_write_mouse() ends its command switch with a bare "default: break;",
so an unknown command draws no reply at all. A real PS/2 device answers
every byte it is given -- ACK (0xFA) when it understood one, resend
(0xFE) when it did not -- and a guest that gets nothing back is left
waiting out its reply timeout. The keyboard path in the same file has
answered unknown commands with KBD_REPLY_RESEND since commit
06b3611fc2 ("ps2: reject unknown commands, instead of blindly
accepting them").

Two guests were measured on this.

OS/2 probes the mouse with the vendor command 0xBB, which QEMU does not
implement, and then polls the status port until its own timeout runs
out. On a Warp 3 guest that wait costs about 25 ms of every boot under
TCG, and 2.1 s under KVM, where each of those polls leaves the guest.
With this patch the wait ends on the first read: the guest takes the
same error path an unexpected reply would, and does not retry.

Linux runs into two of them while probing the mouse: the ALPS probe
sends 0xEC (reset wrap mode), which ps2_write_mouse() only answers
while the mouse is in wrap mode, and the TrackPoint probe sends 0xE1.
Each costs libps2 a 200 ms reply timeout. Timing the psmouse detection
from a mark written to /dev/kmsg to the kernel's "input:" line, three
boots each of a 6.18.35 kernel under TCG: 426.7/428.8/441.6 ms without
this patch, 21.4/21.6/21.2 ms with it. The mouse is detected
identically either way; only the error the probe ends in changes, from
-EIO (nothing came back at all) to -EPROTO (libps2 gives up after its
second attempt).

The specification's second stage -- 0xFC (Error) when the byte after a
rejected one is invalid as well -- is deliberately left out. It would
need state that has to survive migration, no guest is known to test for
it, and the keyboard path does without it as well.

Cc: qemu-stable@nongnu.org
Signed-off-by: Christian Quante <christian@quante.one>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Message-ID: <20260825075127.34876-2-christian@quante.one>
2026-08-25 15:20:44 +04:00
Akihiko Odaki
884363589b hw/display/virtio-gpu: Validate resource per command
virtio_gpu_find_check_resource() checks if the resource has backing
storage if require_backing is true, but the condition conflates backing
storage attachment with host representation; it checks
!res->iov || (!res->image && !res->blob), but !res->iov is sufficient.

Furthermore, its callers passing true as require_backing have different
requirements:

- virtio_gpu_transfer_to_host_2d() requires a non-blob with
  backing storage.
- virtio_gpu_set_scanout() requires a non-blob but does not require
  backing storage.
- virtio_gpu_set_scanout_blob() requires a blob with backing storage.
- virtio_gpu_resource_detach_backing() accepts any resource.

Remove the require_backing parameter and open-code checks appropriate
for each function instead.

Fixes: 25c001a403 ("virtio-gpu: Add virtio_gpu_find_check_resource")
Fixes: e0933d91b1 ("virtio-gpu: Add virtio_gpu_resource_create_blob")
Fixes: 32db3c63ae ("virtio-gpu: Add virtio_gpu_set_scanout_blob")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260825-dmabuf-v2-5-b3d64d3b9a0e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-25 15:20:44 +04:00
Akihiko Odaki
d3c2da174c hw/display/virtio-gpu: Check cursor data presence
Reject a blob that lacks the backing storage for
VIRTIO_GPU_CMD_UPDATE_CURSOR.

Fixes: bdd53f7392 ("virtio-gpu: Update cursor data using blob")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260825-dmabuf-v2-4-b3d64d3b9a0e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-25 15:20:43 +04:00
Akihiko Odaki
cd71534b22 hw/display/virtio-gpu: Propagate udmabuf errors
Propagate udmabuf errors so that the requested operation will be
canceled instead of producing an incomplete result and the user can
notice the failure.

Fixes: e0933d91b1 ("virtio-gpu: Add virtio_gpu_resource_create_blob")
Fixes: f66767f75c ("virtio-gpu: add virtio-gpu/blob vmstate subsection")
Fixes: 4ae1c5c7d6 ("hw/display/virtio-gpu: Initialize blob mapping for ATTACH_BACKING")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260825-dmabuf-v2-3-b3d64d3b9a0e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-25 15:20:43 +04:00
Akihiko Odaki
3f163489c6 hw/display/virtio-gpu: Avoid mmap() for empty blob
Calling mmap() for an empty blob fails with EINVAL, causing QEMU to
emit a spurious warning.

Fixes: e0933d91b1 ("virtio-gpu: Add virtio_gpu_resource_create_blob")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260825-dmabuf-v2-2-b3d64d3b9a0e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-25 15:20:43 +04:00
Akihiko Odaki
14f2511f59 hw/display/virtio-gpu: Avoid creating empty udmabuf
The virtio specification allows creating a blob without backing storage
attached. However, virtio-gpu attempts to create an empty udmabuf for
such a blob. The ioctl fails with EINVAL and emits a spurious warning.
Avoid the invalid ioctl.

Fixes: e0933d91b1 ("virtio-gpu: Add virtio_gpu_resource_create_blob")
Fixes: f66767f75c ("virtio-gpu: add virtio-gpu/blob vmstate subsection")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260825-dmabuf-v2-1-b3d64d3b9a0e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-25 15:20:43 +04:00
Warisjeet Singh
418396be80 hw/display/vga: fix text-mode OOB write after a graphics surface switch
vga_draw_text() decides whether the console surface needs a resize from
its geometry cache, but none of the cache terms observe the graphics
renderer having replaced the console surface in between:

- last_width/last_height are shared with vga_draw_graphic(), which
  stores them in pixels while the text path stores characters;
- last_depth stays 0 for legacy (non-VBE) graphics modes, because
  vga_get_bpp() only reports a depth when VBE is enabled, so the
  "s->last_depth" term that normally forces a resize after a graphics
  frame does not fire.

So a graphics frame that shrinks the console surface (e.g. 80x25
pixels) followed by a text frame with matching character geometry
(80x25 chars) skips the resize, and the glyph loop then paints
width*cw x height*cheight pixels into the smaller surface, out of
bounds, with guest-controlled (DAC palette) values, on every display
refresh.

Separate the geometry cache per renderer: text paths (vga_draw_text,
vga_update_text, and the text handling in vga_invalidate_display /
vga_common_reset) now only manipulate last_text_{width,height}, in
characters; last_{width,height} become graphics-only, in pixels.
Additionally, make the text path compare the pixel size it is about
to paint against the console surface's actual dimensions.  The
surface check is the load-bearing term: caches in either unit cannot
see the other renderer swapping the surface, the surface can.

Fixes: CVE-2026-77913
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4215
Cc: qemu-stable@nongnu.org
Signed-off-by: Warisjeet Singh (sin99xx) <sinxx198@gmail.com>
Message-ID: <vga-v3-20260824.sinxx198@gmail.com>
2026-08-25 15:20:43 +04:00
Fabiano Rosas
ddf5738503 chardev: Don't unregister yank upon async path connection failure
Commit 5c102ac9 ("chardev: Consolidate yank registration") has moved
yank registration in the tcp_chr_connect_client_async() path to after
the connection is successful. If qio_channel_socket_connect_sync()
fails early, there will be no yank registered to be unregistered in
the error path, leading to assert.

Remove the now-extraneous unregister.

Cc: qemu-stable@nongnu.org
Fixes: 5c102ac9 ("chardev: Consolidate yank registration")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3528
Signed-off-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260603141137.1108963-1-farosas@suse.de>
2026-08-25 15:20:43 +04:00
Marc-André Lureau
4fd6561228 tests/functional: fix pylint false positives for cv2 module
Add generated-members=cv2.* to pylintrc so pylint skips member
checking on the cv2 C extension module, whose members are not
visible to static analysis.

Silence:
2026-08-15 10:42:08,710 - INFO: qemu-test.test_pylint Checking files in /home/elmarco/src/qemu.qom-qapi/tests/functional/arm with pylint
2026-08-15 10:42:10,941 - ERROR: qemu-test.test_pylint "/home/elmarco/src/qemu.qom-qapi/tests/functional/arm/test_integratorcp.py:83: E1101: Module 'cv2' has no 'imread' member (no-member)"

Note: I also tried with extension-pkg-allow-list, but that didn't work
for some reason.

Reviewed-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260815072421.4117291-1-marcandre.lureau@redhat.com>
2026-08-25 15:20:43 +04:00
Marc-André Lureau
86fc385ca0 ui/egl: fix qemu_egl_display type
EGLDisplay is already a pointer type (void *), so declaring
qemu_egl_display as EGLDisplay * makes it void **, which
doesn't match any of its usages.

Fixes: 7ced9e9f6d ("ui: add egl-helpers")
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260820131933.2729240-1-marcandre.lureau@redhat.com>
2026-08-25 15:20:43 +04:00
Marc-André Lureau
baca25172d ui/egl: fix render node cleanup order
ASAN detected some memory leaks when terminating. Release thread-bound
EGL state first, destroy the context and terminate the display while the
GBM device is still alive, then destroy GBM and close the render-node
fd.

Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Fixes: a3cf9b55bb ("ui/egl: implement display and EGL cleanup")
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260820132014.2729748-1-marcandre.lureau@redhat.com>
2026-08-25 15:20:43 +04:00
Marc-André Lureau
f4b2607228 tests: tag slow tests with 'slow' suite for easy filtering
Add several RCU and thread-pool unit tests to the slow_tests dict,
and tag all slow tests (both qtest and unit) with a 'slow' suite so
they can be excluded or selected via meson test --suite/--no-suite.

Acked-by: Fabiano Rosas <farosas@suse.de>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260512065633.3542562-1-marcandre.lureau@redhat.com>
2026-08-25 15:20:43 +04:00
Marc-André Lureau
0e62034ca1 crypto: fix build against nettle >= 4
sha.h has been deprecated. It seems we can rely on sha1.h/sha2.h
since we depend on >= 3.7.3.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4184
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-08-25 15:20:43 +04:00
Marc-André Lureau
eb2b3a1fa8 virtio-gpu: use g_try_malloc to avoid guest-triggered abort
Use g_try_malloc/g_try_new0 for guest-controlled allocation, so failure
returns an error to the guest rather than crashing the host (glib
behaviour).

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3898
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260805130141.211398-1-marcandre.lureau@redhat.com>
2026-08-25 15:20:43 +04:00
Marc-André Lureau
ab7183ed4e hw/display/qxl: validate primary surface stride against width
The existing validation in qxl_create_guest_primary() checks that
abs(stride) * height fits in vgamem_size and that stride is 4-byte
aligned, but never checks that abs(stride) is large enough to hold one
row of pixels for the declared width and format.

A malicious guest can create a primary surface with a stride much
smaller than width * bytes_per_pixel (e.g. stride=4 for a 64-wide 32bpp
surface). The spice server rejects this via red_validate_surface(), but
the return is void and QEMU unconditionally proceeds to set up the local
rendering state. On the next display refresh, VNC or SDL reads width *
bytes_pp per scanline from a region backed by only stride bytes per
row, causing a host-side out-of-bounds read.

Add three checks in qxl_create_guest_primary() before creating the
surface:
 - reject unknown surface formats
 - reject zero width or height
 - reject surfaces where abs(stride) < width * bytes_per_pixel

Also fix three related issues in qxl-render.c:
 - qxl_blit() used abs_stride to advance the dst pointer into the
   DisplaySurface, but when stride is negative the DisplaySurface is a
   packed buffer whose stride may be smaller. Use surface_stride()
   instead.
 - qxl_render_update_area_unlocked() uses guest_head0_width (set via
   QXL_IO_MONITORS_CONFIG_ASYNC) without validating it against
   abs_stride, bypassing the new validation. Clamp the effective width
   to abs_stride / bytes_pp to prevent out-of-bounds access while
   tolerating the normal transient where the monitor config arrives
   before the primary surface is resized to match.
 - Similarly, guest_head0_height bypasses qxl_create_guest_primary()
   validation. Without clamping, abs_stride * height can overrun
   vgamem_size, and the product can also overflow 32 bits (e.g.
   abs_stride=16 MiB, height=256 wraps to zero), defeating the
   qxl_phys2virt() bounds check. Clamp height to
   vgamem_size / abs_stride to prevent both.

While touch it, fix some endianness issues.

Fixes: CVE-2026-16271
Fixes: a19cbfb346 ("spice: add qxl device")
Fixes: 979f7ef896 ("qxl: use guest_monitor_config for local renderer.")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3637
Reported-by: huntr bubble
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Message-ID: <20260806094028.640676-1-marcandre.lureau@redhat.com>
2026-08-25 15:20:43 +04:00
Marc-André Lureau
df42a1589f hw/core/machine: fix fdt memory leak
The MachineState fdt field is allocated by various machine types via
create_device_tree(), load_device_tree(), or similar, but was never
freed in machine_finalize(). Add the missing g_free() call.

Reviewed-by: Zhao Liu <zhao1.liu@intel.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260709111249.1107640-1-marcandre.lureau@redhat.com>
2026-08-25 15:20:43 +04:00
Marc-André Lureau
b5102872b8 migration/multifd: fix Error leak in multifd_recv_terminate_threads()
If err != NULL, free it.

Fixes: 11dd7be575 ("migration/multifd: Remove p->quit from recv side")
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Peter Xu <peterx@redhat.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260727-fix2-v2-11-d0c4831ed7ea@redhat.com>
2026-08-25 15:20:43 +04:00
Marc-André Lureau
8fda982a7c hw/misc: fix trace-events
The commit 8041d17308 accidentally removed the vmlaunchupdate.c
trace events.

Fixes: 8041d17308 ("tests/qtest: add test for K230 gsdma")
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Luigi Leonardi <leonardi@redhat.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260825074114.853069-1-marcandre.lureau@redhat.com>
2026-08-25 15:20:43 +04:00
Richard Henderson
fd7ab698c9 ufs queue
- Separate the UFS controller core from the PCI frontend
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEUBfYMVl8eKPZB+73EuIgTA5dtgIFAmqL1G8ACgkQEuIgTA5d
 tgIWthAAvynqQHh4tnILvApKh/E5ePRV/J9KtTYCJIIU1M1V/Xgr8s8R0UwfxzPM
 dl0mibLBozZuyo5tQGLXtEjXCNUEuKFO3YW+UrNk+iIrNjKBiiqHTrh48g2J9wwd
 OeZawTg2EEIde395pBsidCyKp8M7DGOies/MuI3m2yRifyR7dlq1zUsR4JUUDiXu
 +8LvBng8yZHxPK3j3vxT+3VsxcK3qUord0u3kvFK+m+010l3B2WerxG/ZR110LG7
 mL/0fijD3P25lU0x9fryA6BYIE4LppOdJwZJi5rLl6CXiEKcqRlLEBAfUQAh04a5
 AtfXV5Q7iXjJSC9cZB+NXP6qn+yP6Dq6ioHtlAA4koF08DGzd+xMBsCI4k7Bib28
 r1e4tjIcBa8Xn7e/Lwj1/Co2dmM6DlaRsbi4n0oPp3yp+aavIfaLeIfjPwlRVqLF
 mB/I9rR1d09VVlmNBI40cnVdQzWgNU/wcot+hwZ3gyBx7ow4mOG4XmrEKHj8JaTH
 iAEXZq5LEBbP5T6f+1iPqsB16NkdTc4Sl45SG+rDnOiQz4x6B76PmUU/SyDRFmzy
 RVAKPdPp/xigg1clVEoDxZxVueioX5kpxHxAlmwoFjse5CBZmkLlhRtv4o1R72UP
 MGKbVw8i0tW00bHNjW4IBWy8i5jlIE2gu84AnyZTsqp33Srg+Po=
 =7KSJ
 -----END PGP SIGNATURE-----

Merge tag 'pull-ufs-20260824' of https://gitlab.com/jeuk20.kim/qemu into staging

ufs queue

- Separate the UFS controller core from the PCI frontend

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEUBfYMVl8eKPZB+73EuIgTA5dtgIFAmqL1G8ACgkQEuIgTA5d
# tgIWthAAvynqQHh4tnILvApKh/E5ePRV/J9KtTYCJIIU1M1V/Xgr8s8R0UwfxzPM
# dl0mibLBozZuyo5tQGLXtEjXCNUEuKFO3YW+UrNk+iIrNjKBiiqHTrh48g2J9wwd
# OeZawTg2EEIde395pBsidCyKp8M7DGOies/MuI3m2yRifyR7dlq1zUsR4JUUDiXu
# +8LvBng8yZHxPK3j3vxT+3VsxcK3qUord0u3kvFK+m+010l3B2WerxG/ZR110LG7
# mL/0fijD3P25lU0x9fryA6BYIE4LppOdJwZJi5rLl6CXiEKcqRlLEBAfUQAh04a5
# AtfXV5Q7iXjJSC9cZB+NXP6qn+yP6Dq6ioHtlAA4koF08DGzd+xMBsCI4k7Bib28
# r1e4tjIcBa8Xn7e/Lwj1/Co2dmM6DlaRsbi4n0oPp3yp+aavIfaLeIfjPwlRVqLF
# mB/I9rR1d09VVlmNBI40cnVdQzWgNU/wcot+hwZ3gyBx7ow4mOG4XmrEKHj8JaTH
# iAEXZq5LEBbP5T6f+1iPqsB16NkdTc4Sl45SG+rDnOiQz4x6B76PmUU/SyDRFmzy
# RVAKPdPp/xigg1clVEoDxZxVueioX5kpxHxAlmwoFjse5CBZmkLlhRtv4o1R72UP
# MGKbVw8i0tW00bHNjW4IBWy8i5jlIE2gu84AnyZTsqp33Srg+Po=
# =7KSJ
# -----END PGP SIGNATURE-----
# gpg: Signature made Sun 23 Aug 2026 10:19:43 PM PDT
# gpg:                using RSA key 5017D831597C78A3D907EEF712E2204C0E5DB602
# gpg: Good signature from "Jeuk Kim <jeuk20.kim@samsung.com>" [unknown]
# gpg:                 aka "Jeuk Kim <jeuk20.kim@gmail.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 5017 D831 597C 78A3 D907  EEF7 12E2 204C 0E5D B602

* tag 'pull-ufs-20260824' of https://gitlab.com/jeuk20.kim/qemu:
  hw/ufs: Add a generic SysBus frontend
  hw/ufs: Separate the controller core from the PCI frontend

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-24 10:53:36 -07:00
Richard Henderson
2be159078e RISC-V PR for 11.1
* Fix IMSIC CSR write and add tests
 * Parametrise debug trigger number
 * Add 'svbare' satp-mode
 * Fix RINTC PLIC context ID for KVM
 * Avoid abort when reading vtype before env->xl is set
 * Skip reset for KVM irqchip
 * Skip FP/Vector sync on KVM_PUT_RUNTIME_STATE
 * More FDT cleanups (PLIC)
 * Make FCTL.BE in IOMMU read only 0
 * Check DC.TC reserved bits in IOMMU
 * Apply UXL WARL handling to vsstatus
 * Set cmd_ill IOFENCE.C if rsvp bits are set in IOMMU
 * Set RISCV_IOMMU_FQ_HDR_PV appropriately
 * Report QEMU CPU archid as 42
 * Check PMP before updating PTE
 * Add the Tenstorrent Atlantis machine
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEaukCtqfKh31tZZKWr3yVEwxTgBMFAmqL2o0ACgkQr3yVEwxT
 gBOC9g//Ux5snjOzJmmIgJdOFPcBlt1sRxq23Oc5uKoGp54yuDQFvhfg4t8G6w4L
 pgJGdZ6MoA3D+QXsQuXS6WuVDKGuAwTcP4p4rioy+31WjFUL/2bTIOBFGkeER02x
 uF2Z9fq8hF6bLjoOgyv2zyIL9hRY6Vh3cBCHaKXoLJdKmAdByhhHOOcvCpAfi17x
 FmZ4pBZY7yApHIWNb3jBCR2siz8UZ2j0AvHbT2qMENHZBXW8GBrHDdMMOU5mexoB
 nd+sKfiVyYpDJh0N99KzIJaxecK8rF/mt7FMghgKrf9sYMaHwundFl8O44skJ8+b
 HDqAn8Cytfk659S1hiUJZF9Slt+zAAx1bKb7WWORP2hdfXkw5C5skyK0EGIEvb1R
 9FK+2Y0XI8dCoPXFOKaDOWOmTEW4ihAS1QZ/xZuhqOJK1jjQs7qik+8CNbhNVyqd
 GHRZlenlGGtAE1CYELs3kOWVdxPyGQG4VVr9AXk/MmCQqcNtpG7E3gMcrg9a3LVg
 vmIpAyc57MzvzEqGENIVoiSQRBtuF2T8EFnaLZv3PhXsHVGM+xz/BRGWTDza4TgC
 hXS3xxk+UnSwRgjcx9kcMA+S74EjMML/1NmVHviD9dlC2yBGfYk0e90wDB+fJbn5
 XePzJX4moXSaLihTI+srqVmT5uvAoj6fGnmkS1XRwy1JdhWW7Tc=
 =9pMS
 -----END PGP SIGNATURE-----

Merge tag 'pull-riscv-to-apply-20260824-1' of https://github.com/alistair23/qemu into staging

RISC-V PR for 11.1

* Fix IMSIC CSR write and add tests
* Parametrise debug trigger number
* Add 'svbare' satp-mode
* Fix RINTC PLIC context ID for KVM
* Avoid abort when reading vtype before env->xl is set
* Skip reset for KVM irqchip
* Skip FP/Vector sync on KVM_PUT_RUNTIME_STATE
* More FDT cleanups (PLIC)
* Make FCTL.BE in IOMMU read only 0
* Check DC.TC reserved bits in IOMMU
* Apply UXL WARL handling to vsstatus
* Set cmd_ill IOFENCE.C if rsvp bits are set in IOMMU
* Set RISCV_IOMMU_FQ_HDR_PV appropriately
* Report QEMU CPU archid as 42
* Check PMP before updating PTE
* Add the Tenstorrent Atlantis machine

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEaukCtqfKh31tZZKWr3yVEwxTgBMFAmqL2o0ACgkQr3yVEwxT
# gBOC9g//Ux5snjOzJmmIgJdOFPcBlt1sRxq23Oc5uKoGp54yuDQFvhfg4t8G6w4L
# pgJGdZ6MoA3D+QXsQuXS6WuVDKGuAwTcP4p4rioy+31WjFUL/2bTIOBFGkeER02x
# uF2Z9fq8hF6bLjoOgyv2zyIL9hRY6Vh3cBCHaKXoLJdKmAdByhhHOOcvCpAfi17x
# FmZ4pBZY7yApHIWNb3jBCR2siz8UZ2j0AvHbT2qMENHZBXW8GBrHDdMMOU5mexoB
# nd+sKfiVyYpDJh0N99KzIJaxecK8rF/mt7FMghgKrf9sYMaHwundFl8O44skJ8+b
# HDqAn8Cytfk659S1hiUJZF9Slt+zAAx1bKb7WWORP2hdfXkw5C5skyK0EGIEvb1R
# 9FK+2Y0XI8dCoPXFOKaDOWOmTEW4ihAS1QZ/xZuhqOJK1jjQs7qik+8CNbhNVyqd
# GHRZlenlGGtAE1CYELs3kOWVdxPyGQG4VVr9AXk/MmCQqcNtpG7E3gMcrg9a3LVg
# vmIpAyc57MzvzEqGENIVoiSQRBtuF2T8EFnaLZv3PhXsHVGM+xz/BRGWTDza4TgC
# hXS3xxk+UnSwRgjcx9kcMA+S74EjMML/1NmVHviD9dlC2yBGfYk0e90wDB+fJbn5
# XePzJX4moXSaLihTI+srqVmT5uvAoj6fGnmkS1XRwy1JdhWW7Tc=
# =9pMS
# -----END PGP SIGNATURE-----
# gpg: Signature made Sun 23 Aug 2026 10:45:49 PM PDT
# gpg:                using RSA key 6AE902B6A7CA877D6D659296AF7C95130C538013
# gpg: Good signature from "Alistair Francis <alistair@alistair23.me>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 6AE9 02B6 A7CA 877D 6D65  9296 AF7C 9513 0C53 8013

* tag 'pull-riscv-to-apply-20260824-1' of https://github.com/alistair23/qemu: (96 commits)
  target/riscv/tcg: sret in virtual user mode raises virtual instruction exception
  target/riscv: Make Zcmt JVT loads endian-aware
  tests/tcg/riscv64: add misa write test
  riscv: csr: do not drop C bit on misa write
  target/riscv: Allow UXL to be 3 in mstatus on rv128
  target/riscv: Fix sstatus update in rv128
  target/riscv: Restore register dump zero padding
  tests/qtest: remove trace output from k230 watchdog test
  target/riscv: enforce even register constraints for Zdinx fcvt pairs
  target/riscv: reject FMV.X.W/FMV.W.X under Zfinx
  target/riscv: honor zicbo* envcfg gating in linux-user mode
  disas/riscv: Sort riscv-op.c.inc
  disas/riscv: Split rvi_opcode_data
  disas/riscv: Tidy decode of mop.r.n and mop.rr.n
  disas/riscv: Tidy decode of c.mop.n
  disas/riscv: Merge all c.mop.n to one pattern
  disas/riscv: Merge all mop.rr.n to one pattern
  disas/riscv: Merge all mop.r.n to one pattern
  disas/riscv: Split out riscv-op.c.inc
  disas/riscv: Move rv_op_illegal to riscv.c
  ...

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-23 23:04:09 -07:00
Jeuk Kim
6ed05d5e65 hw/ufs: Add a generic SysBus frontend
Add TYPE_SYSBUS_UFS as a reusable frontend for the
transport-independent UFS controller core.

Use the system memory address space for DMA, expose the controller MMIO
region and IRQ through SysBus, and provide the same properties and
migration policy as the PCI frontend. Platform-specific controllers can
derive from this type and keep only their hardware-specific behavior.

Signed-off-by: Jeuk Kim <jeuk20.kim@samsung.com>
2026-08-24 14:17:29 +09:00
Jeuk Kim
42feb94b79 hw/ufs: Separate the controller core from the PCI frontend
UfsHc is currently also the PCI device instance, tying common code to
PCI-specific DMA and IRQ interfaces and preventing reuse by non-PCI
frontends.

Make UfsHc transport-independent and embed it in UfsPciState. Move the
PCI-specific handling to ufs-pci.c, pass the owning DeviceState and DMA
AddressSpace to the core, and record the core explicitly in UfsBus.

Split the common implementation into CONFIG_UFS, selected by
CONFIG_UFS_PCI. The user-visible "ufs" device and its properties remain
unchanged. No functional change is intended.

Signed-off-by: Jeuk Kim <jeuk20.kim@samsung.com>
2026-08-24 14:17:29 +09:00
Christian S. Lima
85d38315fd target/riscv/tcg: sret in virtual user mode raises virtual instruction exception
Currently, when a `sret` is executed in virtual user mode, qemu
raise an `illegal instruction exception`, but in this case the correct
behavior is to raise a `virtual instruction exception` and the code
already contains a check to it, but it's not enough to catch. This
patch is useful to improve the correctness of the virtualization of
the risc v architecture.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3622

Signed-off-by: Christian S. Lima <christianslima@proton.me>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260808031849.59726-1-christianslima@proton.me>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 13:01:48 +10:00
Xu Liu
598ef9c81a target/riscv: Make Zcmt JVT loads endian-aware
The Zcmt specification says JVT table entries follow the current data
endianness. Support that behavior as described by the specification so
big-endian guests can use JVT tables stored in big-endian form.

Signed-off-by: Xu Liu <liuxu@nucleisys.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <02050B1BBB8815BE+20260817083005.2392-1-liuxu@nucleisys.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:33:40 +10:00
Vladimir Isaev
ce781055ff tests/tcg/riscv64: add misa write test
Link: https://lore.kernel.org/r/20260321144554.606417-2-npiggin@gmail.com
Suggested-by: Nicholas Piggin <npiggin@gmail.com>
Signed-off-by: Vladimir Isaev <vvisaev@gmail.com>
Message-ID: <20260817150653.40357-3-vvisaev@gmail.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:31:53 +10:00
Vladimir Isaev
af37cd2821 riscv: csr: do not drop C bit on misa write
According to spec:
> Writing misa may increase IALIGN, e.g., by disabling the "C" extension.
> If an instruction that would write misa increases IALIGN, and the
> subsequent instruction’s address is not IALIGN-bit aligned, the
> write to misa is suppressed, leaving misa unchanged.

So attempt to disable C extension if next instruction is not aligned should not
change the misa.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Vladimir Isaev <vvisaev@gmail.com>
Reviewed-by: Chao Liu <chao.liu@processmission.com>
Message-ID: <20260817150653.40357-2-vvisaev@gmail.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:30:05 +10:00
Frédéric Pétrot
a9779d24be target/riscv: Allow UXL to be 3 in mstatus on rv128
Valid UXL field values for mstatus were restricted to fix a
reported issue, but this inadvertently broke the experimental
rv128 support where a value of 3 validly represents 128-bit
execution.

Update the mstatus write logic to permit UXL=3 when running on
an rv128 CPU.

Fixes: dcd0285177 ("target/riscv: Apply UXL WARL handling to vsstatus")
Signed-off-by: Frédéric Pétrot <frederic.petrot@univ-grenoble-alpes.fr>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Reviewed-by: Chao Liu <chao.liu@processmission.com>
Message-ID: <20260819105655.33391-3-frederic.petrot@univ-grenoble-alpes.fr>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:28:18 +10:00
Frédéric Pétrot
ea8e5d3c50 target/riscv: Fix sstatus update in rv128
The sstatus register assignment was performed before the write
mask was fully constructed, leading to an incomplete update of
sstatus fields on the experimental rv128 target.

Move the sstatus write after the mask completion so the full
write mask is applied correctly.

Signed-off-by: Frédéric Pétrot <frederic.petrot@univ-grenoble-alpes.fr>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Reviewed-by: Chao Liu <chao.liu@processmission.com>
Message-ID: <20260819105655.33391-2-frederic.petrot@univ-grenoble-alpes.fr>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:26:30 +10:00
Joel Stanley
409c7d8682 target/riscv: Restore register dump zero padding
The register values lost their leading zeroes when the underlying type
was changed, resulting in mismatched padding and harder to read output.

Print with a runtime field width based on MXL, so values are 16 hex
digits on rv64 and 8 on rv32, matching the csr and fp dump. This avoids
adding target_ulong back into the dump.

Fixes: c4e6bc6385 ("target/riscv: Fix size of gpr and gprh")
Signed-off-by: Joel Stanley <joel@jms.id.au>
Reviewed-by: Anton Johansson <anjo@rev.ng>
Reviewed-by: Max Chou <max.chou@sifive.com>
Message-ID: <20260813032421.54438-1-joel@jms.id.au>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:24:43 +10:00
Chao Liu
e4ae434836 tests/qtest: remove trace output from k230 watchdog test
The interrupt mode test does not depend on trace output, but passes a
trace file to QEMU. This makes startup fail when QEMU is built without
the log or simple trace backend, so qtest cannot connect.

Drop the unnecessary trace option.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4126

Signed-off-by: Chao Liu <chao.liu@processmission.com>
Reviewed-by: Bin Meng <bin.meng@processmission.com>
Message-ID: <20260813054329.35425-1-chao.liu@processmission.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:22:56 +10:00
wangyang
e68cc2e5cd target/riscv: enforce even register constraints for Zdinx fcvt pairs
fcvt.d.h and fcvt.h.d access a 64-bit double held in a register
pair, so under Zdinx/Zhinxmin the odd-rd (fcvt.d.h) and odd-rs1
(fcvt.h.d) encodings are reserved.  Add the missing REQUIRE_EVEN
checks so those encodings raise an illegal-instruction exception
instead of retiring.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4109
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>
Message-ID: <ea287909fd6043e0bbcdbfdcb0cc8063@wangyang25.otcaix.iscas.ac.cn>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:21:08 +10:00
wangyang
af1e669cef target/riscv: reject FMV.X.W/FMV.W.X under Zfinx
Zfinx explicitly excludes the FMV transfer instructions, but
trans_fmv_x_w/trans_fmv_w_x used REQUIRE_ZFINX_OR_F so a Zfinx-only
CPU accepted them.  Require RVF instead so the transfers trap with
an illegal instruction when only Zfinx is present.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4108
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>
Message-ID: <36c7cfebd27b4b6e8bcdd00e09e9dda0@wangyang25.otcaix.iscas.ac.cn>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
wangyang
12289f2f9a target/riscv: honor zicbo* envcfg gating in linux-user mode
In user-only builds check_zicbo_envcfg() skipped the envcfg check
entirely (#if !defined(CONFIG_USER_ONLY)), so cbo.inval/cbo.flush/
cbo.zero retired unconditionally in linux-user even though the
machine-level envcfg fields are never initialized.  Give the
user-mode build a senvcfg-based gate, and initialize SENVCFG_CBZE at
reset when ext_zicboz is enabled so cbo.zero stays usable while
cbo.inval/cbo.flush remain illegal, matching the user-mode view of a
typical firmware/kernel setup.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4107
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: wangyang <wangyang25@otcaix.iscas.ac.cn>
Message-ID: <9b2f22fc402b48b8ba81f72be8ed04bc@wangyang25.otcaix.iscas.ac.cn>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
7fe2a88a40 disas/riscv: Sort riscv-op.c.inc
To date, opcodes had to be added to the end of the list,
resulting in quite the disorder.  Sort via 'LANG=C sort'.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-53-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
4fec981f18 disas/riscv: Split rvi_opcode_data
Generate separate objects for OP() instead of collecting in a table.
Return pointers to objects directly.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-52-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
ef25a26b7d disas/riscv: Tidy decode of mop.r.n and mop.rr.n
Merge nested if's.
Reuse operand_mop_{r,rr}_imm for zicfiss decode.
Return pointers directly.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-51-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
bf9281b1b0 disas/riscv: Tidy decode of c.mop.n
Merge nested if's.
Reuse operand_cmop_imm for zicfiss decode.
Return pointers directly.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-50-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
59acf4d4e1 disas/riscv: Merge all c.mop.n to one pattern
Avoid performing arithmetic on rv_op_c_mop_1.
Treat the 'n' as an immediate.
Create a codec and format to match.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-49-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
e2851825f4 disas/riscv: Merge all mop.rr.n to one pattern
Avoid performing arithmetic on rv_op_mop_rr_0.
Treat the 'n' as an immediate.
Create a codec and format to match.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-48-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
1a13fad072 disas/riscv: Merge all mop.r.n to one pattern
Avoid performing arithmetic on rv_op_mop_r_0.
Treat the 'n' as an immediate.
Create a codec and format to match.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-47-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
a722ea32fa disas/riscv: Split out riscv-op.c.inc
Move rvi_opcode_data to riscv-op.c.inc and massage the lines into
OP() form.  Unlike other files, keep the enumeration and the table
intact for now, but build them both from the same source.

Adjust the names of rv_*mop to include _op_ to match the general pattern.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-46-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
30bb96e570 disas/riscv: Move rv_op_illegal to riscv.c
illegal is no longer used in other files.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-45-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
282d8cca8b disas/riscv: Split xthead_opcode_data
Move the table to riscv-xthead-op.c.inc and massage
the lines into OP() form.  Drop th.illegal as unused.
Return pointers to objects directly.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-44-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
5fa5e2df67 disas/riscv: Split xlrbr_opcode_data
Move the table to riscv-xlrbr-op.c.inc and massage
the lines into OP() form.  Drop illegal as unused.
Return pointers to objects directly.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-43-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
7a1cca6360 disas/riscv: Split ventana_opcode_data
Move the table to riscv-xventana-op.c.inc and massage
the lines into OP() form.  Drop vt.illegal as unused.
Return pointers to objects directly.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-42-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
ecbd3a031f disas/riscv: Fix typo in th.lbib format
th.lbib should format the same as th.lbia, and the other
increment insns, with the address register in parenthesis.

Cc: qemu-stable@nongnu.org
Fixes: 318df7238b ("disas/riscv: Add support for XThead* instructions")
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-41-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
d610e55c83 disas/riscv: Fix isa decoding of rev8
The encoding of rev8 is different for rv32 and rv64.

Cc: qemu-stable@nongnu.org
Fixes: 02c1b569a1 ("disas/riscv: Add Zb[abcs] instructions")
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-40-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
d4151cf267 disas/riscv: Fix rv32 encoding of zext.h
For rv64, pack with rs2 = 0 does not encode zext.h.

Cc: qemu-stable@nongnu.org
Fixes: 02c1b569a1 ("disas/riscv: Add Zb[abcs] instructions")
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-39-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
78f51b0ea5 disas/riscv: Reject all of OP-32 and OP-IMM-32 for RV32
These entire base opcodes are RV64.  Reject them all at once
rather than one at a time.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-38-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
0da84325e4 disas/riscv: Skip post-processing of illegal insns
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260812223142.349142-37-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
850708045a disas/riscv: Return rv_opcode_data pointer from decoders
Rather than putting array + index into rv_decode,
return the pointer to the object directly.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-36-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
6a238ffe35 disas/riscv: Store op pointer in rv_comp_data
Store a pointer instead of an array index.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-35-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
8594445d44 disas/riscv: Simplify some insn decompressions
Route "c.j" to "j" instead of "jal", etc.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-34-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
73a0f25feb disas/riscv: Use rv_codec_illegal for pseudos
The codec is never used, since we arrive into pseudos
from a decoding of another opcode.
Assert that rv_codec_illegal is never decoded.
Use rv_codec_none for rv_op_illegal.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-33-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:07 +10:00
Richard Henderson
78b2b441a6 disas/riscv: Chain "nop" pseudo off "mv" pseudo
"mv" has already checked a condition that applies to "nop".

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-32-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
583b84e18f disas/riscv: Chain "ret" pseudo off "jr" pseudo
"jr" has already checked two conditions that apply to "ret".

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-31-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
0a2382f086 disas/riscv: Tidy rv_comp_data terminators
Use { } instead of two zeros.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-30-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
ed3a538849 disas/riscv: Drop format from DECOMP insns
The format for these will never be used -- we will use
the format from the decompressed insn.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-29-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
34adc6c2dc disas/riscv: Handle decompression via decode_inst_lift_pseudo
Introduce a DECOMP macro that expands an rv_comp_data
that always succeeds.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-28-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
6b1230862c disas/riscv: Allow decode_inst_lift_pseudo to loop
Allow pseudo expansion to proceed in multiple steps.
Assert that we don't have simple loops.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-27-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
4abc45a78f disas/riscv: Break pseudo loop for jal and jalr
These were clearly intending to simplify
	jal	ra, foo
to
	jal	foo
and similarly for jalr, but the pseudo expansion looped
back to the original jal/jalr with the full format.

Add new opcode expansions dropping the implied ra.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-26-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
9803e82773 disas/riscv: Handle aliases of csrrwi during decode
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-25-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
6bfb641056 disas/riscv: Handle aliases of csrrs during decode
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-24-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
b1d5cbf56a disas/riscv: Handle aliases of csrrw during decode
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-23-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
7376e4d7d2 disas/riscv: Drop always true branch pseudos
The real insns are blt, bge, bltu, bgeu.  Do not include
pseudos that unconditionally swap operands.  That's fine
for an assembler but not a disassembler.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-22-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
ebb571dc80 disas/riscv: Unify decomp_rv{32,64,128}
We now distinguish compressed opcodes by isa during decode.
Therefore we don't need 3 copies of decomp_*.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-21-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
af216549cb disas/riscv: Remove rvcd_imm_nz
Remove rvcd_imm_nz and rv_opcode_data.decomp_data as unused.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-20-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
70c0e44343 disas/riscv: Do not recognize c.{addw, subw} with rv32
These code points are reserved with RV32.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-19-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
4de89e9a82 disas/riscv: Handle c.slli imm != 0 during decode
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-18-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
dc2fe85523 disas/riscv: Handle c.{srli,srai} imm during decode
Zero shift immediate to c.srli and c.srai are not illegal,
but are reserved as HINTs.  Go ahead and disassemble as
shifts rather than falling back to invalid.

On the other hand, shift immediate >= 32 with RV32 is
reserved for custom extensions, and we need to reject those
early so that the extension disassemblers get a look in.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-17-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
3421486be8 disas/riscv: Handle c.lui imm != 0 during decode
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-16-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
87f162e424 disas/riscv: Simplify c.addi
While c.addi with imm == 0 and rd == 0 is c.nop,
other c.addi with imm == 0 and rd != 0 are not illegal,
but are reserved as HINTs.  Go ahead and disassemble as
c.addi rather than falling back to invalid.

Further, there's no reason to differentiate c.nop, since we have
  c.addi -> addi -> nop
vs
  c.nop -> addi -> nop
via decompress and pseudo translation steps.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-15-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
ae8f42f440 disas/riscv: Handle c.addi4spn imm != 0 during decode
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-14-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
4a5a8434bb disas/riscv: Drop codec from rv_decode
This is mostly write-only, only used in one place;
other updates are ignored.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-13-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
81305446b4 disas/riscv: Drop useless const in structures
Individual fields should not be const, only full structures.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-12-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
7de6afd531 disas/riscv: Drop explicit zero of rv_opcode_data fields
Mechanical

s/, NULL, 0, 0, 0 }/ }/
s/, 0, 0, 0 }/ }/
s/, NULL, 0, 0 }/ }/
s/, NULL, 0 }/ }/

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-11-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
42031f21f9 disas/riscv: Set dec->opcode_data in decode function
This allows each opcode table to be private to the decode file.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-10-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
aae0ef66d4 disas/riscv: Tidy disasm_inst main loop
Unroll first iteration, so that always_true_p is not used,
Drop some local variables and use 'decoders' directly.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-9-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
7276d0fbe6 disas/riscv: Pass rv_opcode_data pointer to format_inst
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-8-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
f8bc5f5635 disas/riscv: Pass rv_opcode_data pointer to/from decode_inst_lift_pseudo
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-7-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
3d3abbb146 disas/riscv: Pass rv_opcode_data pointer to/from decode_inst_decompress
Unify 4 functions, sharing code.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-6-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
2d64d3a6a1 disas/riscv: Pass rv_opcode_data pointer to decode_inst_operands
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-5-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
fcb7ec69d8 disas/riscv: Tidy dec initialization in disasm_inst
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-4-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
21aa81318d disas/riscv: Reduce rv_insn to uint32_t
Since 758dce9c98, the only possible values for
instruction length are 2 and 4.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-3-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Richard Henderson
df975586d8 disas/riscv: Move operand extractors earlier in file
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260812223142.349142-2-richard.henderson@linaro.org>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
A-Shehab
bd1ee9ab3c target/riscv: allow menvcfg/henvcfg LPE and SSE bits on RV32
The Zicfilp landing-pad enable (LPE, bit 2) and Zicfiss shadow-stack
enable (SSE, bit 3) controls live in the low 32 bits of menvcfg and
henvcfg, and the CFI specification defines them for both RV32 and RV64.

QEMU only adds MENVCFG_LPE/MENVCFG_SSE (and the henvcfg equivalents) to
the writable mask inside the "riscv_cpu_mxl(env) == MXL_RV64" block, so
on RV32 these bits are silently dropped and the features cannot be
enabled. This is inconsistent with write_senvcfg(), which already
handles SENVCFG_LPE/SENVCFG_SSE regardless of MXLEN.

Hoist the LPE/SSE mask handling out of the RV64-only block in
write_menvcfg() and write_henvcfg() so the bits become writable on RV32
as well. The upper-half writers (write_menvcfgh/write_henvcfgh) are
unaffected because these bits reside in the low 32 bits.

Reproducible on qemu-system-riscv32 -cpu rv32,zicfilp=true,zicfiss=true:
an M-mode write of menvcfg.{LPE,SSE} reads back as zero, while the same
program on rv64 keeps the bits set.

Fixes: 4923f672e3 ("target/riscv: Introduce elp state and enabling controls for zicfilp")
Fixes: 8205bc127a ("target/riscv: introduce ssp and enabling controls for zicfiss")
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4045
Signed-off-by: A-Shehab <ahshehab24@gmail.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260726080537.13913-1-ahshehab24@gmail.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Andrew Jones
aa51eec004 hw/riscv/riscv-iommu: preserve requested perm in spa_fetch()
b18e3f0e2d fixed spa_fetch() faults whose TTYP used the leaf PTE
permission instead of the original request permission.  However, it kept
that request-narrowed value in iotlb->perm after a successful walk, and
riscv_iommu_translate() caches iotlb->perm for later accesses to the same
IOVA.

That means a write to an RW mapping can cache the entry as write-only.
A later read then hits the cache and faults even though the mapping allows
it, which showed up in NVMe testing as bogus completions and controller
timeouts.

Keep the requested permission in a separate req_perm and use it for all
permission checks and fault-type decisions.  Accumulate the leaf
permissions separately and copy them to iotlb->perm only after the full
walk succeeds, so cached entries describe the mapping rather than the
current request.  Since faults leave iotlb->perm as the original request,
the S-stage and G-stage TTYP fixes remain intact.

Fixes: b18e3f0e2d ("hw/riscv/riscv-iommu.c: fix fault type for spa_fetch() faults")
Signed-off-by: Andrew Jones <andrew.jones@oss.qualcomm.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260717144525.1154204-1-andrew.jones@oss.qualcomm.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Andrew Jones
f16fd27b3f hw/riscv/riscv-iommu: fix U-bit check to apply only to leaf S/VS-stage PTEs
Commit b795ea0ba4 ("hw/riscv/riscv-iommu.c: fault when !PTE_U and
no priv access") placed its check ahead of the leaf-vs-non-leaf
branch in riscv_iommu_spa_fetch(), so it fires on every PTE walked,
including non-leaf/table entries. Per the RISC-V privileged spec's
address translation algorithm (Sv39/Sv48/etc., the "leaf PTE has
been reached" step, followed separately by the U-bit permission
check), the U bit is only defined and checked for the leaf PTE
reached at the end of the walk -- non-leaf PTEs don't carry a
meaningful U bit at all.

Move the check after the leaf/non-leaf branch, alongside the other
leaf-only checks, mirroring how the G_STAGE U-bit check (added in
9158c900ab) is already correctly placed.

Fixes: b795ea0ba4 ("hw/riscv/riscv-iommu.c: fault when !PTE_U and no priv access")
Signed-off-by: Andrew Jones <andrew.jones@oss.qualcomm.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Reviewed-by: Nutty Liu <nutty.liu@hotmail.com>
Message-ID: <20260717112340.1071148-1-andrew.jones@oss.qualcomm.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
TANG Tiancheng
dacaa5412b disas/riscv: Use extract helpers for operand fields
Replace shift-based operand extraction with extract32() and sextract32().
For signed immediates, use sextract32() on the field that carries the sign
bit and combine it with the remaining extract32() fields.

The RISC-V disassembler currently follows target/riscv/internals.h:
insn_len() and decodes only 16-bit or 32-bit instruction lengths, so the
converted fields are all in the low 32 bits of rv_inst.

Suggested-by: Richard Henderson <richard.henderson@linaro.org>
Signed-off-by: TANG Tiancheng <lyndra@linux.alibaba.com>
Reviewed-by: LIU Zhiwei <zhiwei_liu@linux.alibaba.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260703-b4-disas-xthead-fix-riscv-next-v4-5-84c566330bc7@linux.alibaba.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
TANG Tiancheng
00cec77a7f disas/riscv: Decode unsigned vector immediates as unsigned
rv_codec_v_i decodes all .vi operands with operand_vimm(), which
sign-extends bits 19:15. That matches spec operands named imm, but not the
.vi forms whose operand is uimm; uimm=31 is decoded as -1 and printed by
the shared 6-bit 'u' formatter as 63.

Add rv_codec_v_i_u/operand_vuimm() for the 5-bit uimm forms: vsll.vi,
vsrl.vi, vsra.vi, vnsrl.wi, vnsra.wi, vssrl.vi, vssra.vi, vnclipu.wi,
vnclip.wi, vslideup.vi, vslidedown.vi, vrgather.vi, vaeskf1.vi,
vaeskf2.vi, vsm3c.vi, vsm4k.vi and vwsll.vi. The remaining rv_codec_v_i
entries are the signed imm forms.

Fixes: 07f4964d17 ("disas/riscv.c: rvv: Add disas support for vector instructions")
Fixes: 9d92f56d4a ("disas/riscv: Add support for vector crypto extensions")
Signed-off-by: TANG Tiancheng <lyndra@linux.alibaba.com>
Reviewed-by: LIU Zhiwei <zhiwei_liu@linux.alibaba.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260703-b4-disas-xthead-fix-riscv-next-v4-4-84c566330bc7@linux.alibaba.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
TANG Tiancheng
7899d3c6bd disas/riscv: Use signed type for vector immediates
operand_vimm() sign-extends the 5-bit vector immediate field in bits
19:15, but returns uint32_t. This sends negative immediates through an
unsigned type before they are assigned to rv_decode.imm.

Return int32_t to match the signed value extracted by the helper.

Signed-off-by: TANG Tiancheng <lyndra@linux.alibaba.com>
Reviewed-by: LIU Zhiwei <zhiwei_liu@linux.alibaba.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260703-b4-disas-xthead-fix-riscv-next-v4-3-84c566330bc7@linux.alibaba.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
TANG Tiancheng
7a8454ef29 disas/riscv: Fix 6-bit immediate extraction
rv_codec_r2_imm6 is used for XThead instructions whose 6-bit
immediate field is encoded in bits 25:20. The old expression
left-shifted by 38 and then right-shifted by 60, so it kept only
bits 25:22.

Use extract32() to decode bits 25:20 directly. This fixes the
immediate printed for th.srri and th.tst.

Fixes: 318df7238b ("disas/riscv: Add support for XThead* instructions")
Suggested-by: Alex Bennée <alex.bennee@linaro.org>
Signed-off-by: TANG Tiancheng <lyndra@linux.alibaba.com>
Reviewed-by: LIU Zhiwei <zhiwei_liu@linux.alibaba.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260703-b4-disas-xthead-fix-riscv-next-v4-2-84c566330bc7@linux.alibaba.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
TANG Tiancheng
6985cfc875 disas/riscv: Fix th.srri decoding
target/riscv/xthead.decode defines th.srri as funct6=000100 in
bits 31:26, with the 6-bit immediate in bits 25:20.

decode_xtheadbb() switches on bits 31:25, i.e. funct6 plus imm[5].
Therefore valid th.srri encodings are 0001000 and 0001001. The
current 0000100 and 0000101 cases use the wrong funct6 value and
decode valid th.srri instructions as illegal.

Fix the cases to match funct6=000100 with both imm[5] values.

Fixes: 318df7238b ("disas/riscv: Add support for XThead* instructions")
Signed-off-by: TANG Tiancheng <lyndra@linux.alibaba.com>
Reviewed-by: LIU Zhiwei <zhiwei_liu@linux.alibaba.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260703-b4-disas-xthead-fix-riscv-next-v4-1-84c566330bc7@linux.alibaba.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Ivan Efremov
e80cf29479 tests/qtest: Add seed CSR zero extension test
Add a qtest that reads the seed CSR on RV64 machine with Zkr support
and verifies that the upper 32 bits are clear.

Signed-off-by: Ivan Efremov <nendensu@ispras.ru>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260802113130.7818-3-nendensu@ispras.ru>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Ivan Efremov
51362da8f7 target/riscv: Fix seed CSR sign extension
The SEED_OPST_* macros expanded to int expressions. When
bit 31 was present, converting a CSR seed value to target_ulong
on RV64 sign extended the value and incorrectly set the upper 32 bits.

Make the SEED_OPST_* constants unsigned so that CSR values are
zero extended on RV64.

Fixes: 77442380ec ("target/riscv: rvk: add CSR support for Zkr")
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4121
Signed-off-by: Ivan Efremov <nendensu@ispras.ru>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260802113130.7818-2-nendensu@ispras.ru>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Zephyr Li
5a9fa8b582 target/riscv: do not count ECALL in minstret
With icount enabled, helper_raise_exception() leaves ECALL in
icount_get_raw() because it exits without restoring the current TB
state. This makes minstret count an instruction that does not retire.

Adjust only the fixed minstret baseline so that mcycle accounting
remains unchanged.

Add an RV64 softmmu regression test for the issue.

Fixes: 4fe8ae0906 ("target/riscv: Combine mhpmcounter and mhpmcounterh")
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4087
Signed-off-by: Zephyr Li <fritchleybohrer@gmail.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260730032122.2564190-1-fritchleybohrer@gmail.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Frank Chang
efb3db2688 tests/tcg/riscv64: Add test for Zicclsm
Cover scalar, floating-point, vector, and segmented misaligned accesses
with Zicclsm enabled and disabled. Clean up both generated test
binaries.

To build and run the tests:

    make -C build/tests/tcg/riscv64-softmmu \
        CC=riscv64-unknown-elf-gcc LD=riscv64-unknown-elf-ld \
        test-zicclsm test-zicclsm-off

    make -C build/tests/tcg/riscv64-softmmu \
        run-test-zicclsm run-test-zicclsm-off

To clean the generated binaries and objects:

    make -C build/tests/tcg/riscv64-softmmu clean

Signed-off-by: Frank Chang <frank.chang@sifive.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260810055618.1175500-8-frank.chang@sifive.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Frank Chang
836ffe9cfa target/riscv: Expose Zicclsm as a CPU property and update RVA22U64 profile
Update Zicclsm ISA string and expose it as a CPU property to allow user
to turn on/off Zicclsm extension.

In addition, Zicclsm extension is mandatory for the RVA22U64 profile.
Previously, Zicclsm was enabled automatically when has_priv_1_11 was true.
Now that Zicclsm has been converted to an explicit CPU option, it must be
explicitly added to the RVA22U64 profile's extension list to ensure the
profile remains compliant with the specification.

Signed-off-by: Frank Chang <frank.chang@sifive.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260810055618.1175500-7-frank.chang@sifive.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Frank Chang
460549ba10 target/riscv: Support raising misaligned exceptions for vector loads/stores
When the Zicclsm extension is not enabled, raise misaligned load/store
exceptions for misaligned accesses from vector load/store instructions.

We will skip the host fast-path and fall back to the slow TLB-path to
raise misaligned load/store exceptions for the misaligned accesses when
Zicclsm extension is disabled.

Signed-off-by: Frank Chang <frank.chang@sifive.com>
Reviewed-by: Max Chou <max.chou@sifive.com>
Acked-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260810055618.1175500-6-frank.chang@sifive.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Frank Chang
e1322e1558 target/riscv: Support raising misaligned exceptions for floating-point loads/stores
When the Zicclsm extension is not enabled, raise misaligned load/store
exceptions for misaligned accesses from floating-point load/store
instructions (RVF, RVD, Zfh).

Signed-off-by: Frank Chang <frank.chang@sifive.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260810055618.1175500-5-frank.chang@sifive.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Frank Chang
7ff17f127b target/riscv: Support raising misaligned exceptions for scalar loads/stores
When the Zicclsm extension is not enabled, raise misaligned load/store
exceptions for misaligned accesses from scalar load/store instructions.

Signed-off-by: Frank Chang <frank.chang@sifive.com>
Reviewed-by: Max Chou <max.chou@sifive.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260810055618.1175500-4-frank.chang@sifive.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Frank Chang
340a8c111d hw/riscv: sifive_u: Align ROM reset vector data
The SiFive U ROM reset vector data needs proper 8-byte alignment for
RV64 ld instructions. The misaligned load will cause exception when
Zicclsm is supported as SiFive U CPU doesn't support hardware misaligned
loads and stores.

Add padding to ensure start_addr and fdt_load_addr are placed at 8-byte
aligned offsets and adjust the load instruction offsets to match the new
data layout.

Signed-off-by: Frank Chang <frank.chang@sifive.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260810055618.1175500-3-frank.chang@sifive.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:06 +10:00
Frank Chang
fbc151a66f target/riscv: Add Zicclsm CPU option and enable it for the eligible CPUs
Add Zicclsm CPU option and enable it for the following eligible CPUs:

- Base 32 CPU (to be backward compatible)
- Base 64 CPU (to be backward compatible)
- XuanTie (T-Head) C908
- Tenstorrent Ascalon
- Ventana Veyron V1
- XiangShan Kunminghu
- MIPS P8700 (ISA doesn't include Zicclsm, but their datasheet claims that
  it has unaligned load/store support in hardware)

Signed-off-by: Frank Chang <frank.chang@sifive.com>
Reviewed-by: Max Chou <max.chou@sifive.com>
Acked-by: Alistair Francis <alistair.francis@wdc.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260810055618.1175500-2-frank.chang@sifive.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:05 +10:00
Zeng Chi
d5ab0bdefe target/riscv: Fix memory leak in riscv_trigger_unrealize()
In riscv_trigger_unrealize(), the per-trigger QEMUTimer objects are
created in riscv_trigger_realize() using timer_new_ns().  However,
unrealize only calls timer_del() to cancel them, but never frees the
timer objects themselves. This results in a memory leak every time a
CPU instance is unrealized (e.g., during hot-unplug or machine teardown).

Fix it by replacing timer_del() with timer_free(), which internally
cancels the timer and frees its memory.  The separate timer_del() call
is no longer needed.

Fixes: 820552a92e ("target/riscv: dynamic alloc of debug trigger arrays")
Signed-off-by: Zeng Chi <zengchi@kylinos.cn>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260724063927.3360599-1-zeng_chi911@163.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:05 +10:00
Abhigyan Kumar
ebef6685a1 target/riscv: use SXL instead of MXL for read_sstatus
According to the RISC-V spec, a 64-bit system can have M-mode in 64-bit
with S-mode being 32-bit (SXL bits or mstatus[35:34] being 1). In this
case, read_sstatus should use SXL.

QEMU doesn't allow changing the SXL bits in mstatus in M-mode. This was
because of the missing MSTATUS64_SXL mask in write_mstatus. Now, both
the SXL field in mstatus can be safely modified in M-mode and
read_sstatus correctly uses SXL not MXL.

Fixes: b550f89457 ("target/riscv: Compute mstatus.sd on demand")
Signed-off-by: Abhigyan Kumar <314abh@gmail.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260723142254.1683113-1-314abh@gmail.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:05 +10:00
Max Chou
4a884ba94b target/riscv: Fix PC sync in trans_sspopchk for CFI exception handling
Move gen_update_pc call before conditional logic to ensure consistent
PC state regardless of execution path.

Previously, the host instructions generated to update the cpu_pc were
only executed in the failure path when shadow stack validation failed.
This created inconsistent PC synchronization.

This inconsistency caused issues in CF_PCREL mode where subsequent
instructions calculated wrong relative offsets from stale pc_save
values, and could lead to incorrect exception return addresses.

This fix ensures PC is always synchronized before any helper that
might raise an exception, maintaining consistent translator state
across all execution paths.

Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4118
Signed-off-by: Max Chou <max.chou@sifive.com>
[ahshehab: rebased on current master; file moved to
 target/riscv/tcg/insn_trans/ and the ssp load is now 64-bit wide]
Tested-by: A-Shehab <ahshehab24@gmail.com>
Signed-off-by: A-Shehab <ahshehab24@gmail.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260730181852.1622-1-ahshehab24@gmail.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:05 +10:00
Xie Bo
ddac7cfb00 target/riscv/kvm: Preserve MP state across migration
RISC-V KVM initializes secondary vCPUs in KVM_MP_STATE_STOPPED, but QEMU
does not save their runtime MP state. A destination therefore retains reset
MP state after migration and cannot reliably resume all vCPUs.

Save KVM_GET_MP_STATE in a capability-gated KVM VMState subsection and
restore it on KVM_PUT_FULL_STATE. Keep the existing reset initialization
path unchanged. Track whether the subsection was loaded so streams where
the subsection is absent retain the destination reset behavior.

Bump the RISC-V CPU VMState version and minimum version to 12 for the new
pre_load hook and KVM MP-state subsection. Keep the subsection out of KVM
migration streams when the host does not support the MP-state capability.

Signed-off-by: Xie Bo <xb@ultrarisc.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260808125157.1220511-3-xb@ultrarisc.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:05 +10:00
Xie Bo
7df9aa5f6d target/riscv/kvm: Synchronize privilege mode
The KVM core register synchronization currently omits the vCPU privilege
mode. As a result, env.priv can be stale when the migration stream is saved
and the destination can restore the vCPU in the wrong mode.

Read and write the KVM core mode register together with the other core
registers. The generic RISC-V CPU VMState already carries env.priv, so no
migration format change is required.

Signed-off-by: Xie Bo <xb@ultrarisc.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260808125157.1220511-2-xb@ultrarisc.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:05 +10:00
Tao Ding
b92d8c60a4 hw/riscv: k230: add a noc stub region in K230 board
The NOC address was accessed in the k230_unzip driver, but it is currently not in k230.
This commit uses create_unimplemented_device to preset the region.

Signed-off-by: Tao Ding <dingtao0430@163.com>
Reviewed-by: Junze Cao <caojunze424@gmail.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260808062227.66961-8-dingtao0430@163.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:19:05 +10:00
Tao Ding
269f5458e0 tests/qtest: add test for K230 decomp gzip
This commit adds test cases for Decomp_gzip.
A compressed data segment has been pre-set, configure GSDMA and decomp_gzip.
Compare the decompressed data with the original data

Update MAINTAINERS for this test.

Run this qtest:
    $ mkdir build && cd build && ../configure --target-list="riscv64-softmmu"
    $ QTEST_QEMU_BINARY=./qemu-system-riscv64   tests/qtest/k230-decomp-gzip-test

Signed-off-by: Tao Ding <dingtao0430@163.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Reviewed-by: Junze Cao <caojunze424@gmail.com>
Message-ID: <20260808062227.66961-7-dingtao0430@163.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:17:18 +10:00
Tao Ding
096ead3195 hw/riscv: k230: add decomp gzip in K230 board
This commit replaces the unimplemented part of Decomp_gzip in K230.
Connect to the handshake interface of GSDMA.

Signed-off-by: Tao Ding <dingtao0430@163.com>
Reviewed-by: Junze Cao <caojunze424@gmail.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260808062227.66961-6-dingtao0430@163.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:15:16 +10:00
Tao Ding
8041d17308 tests/qtest: add test for K230 gsdma
This commit adds test cases for GSDMA.
Imitate the behavior of the driver, set LLT and sdma registers.
After the data transmission is completed, check the destination address data.

Update MAINTAINERS for this test.

Run this qtest:
    $ mkdir build && cd build && ../configure --target-list="riscv64-softmmu"
    $ QTEST_QEMU_BINARY=./qemu-system-riscv64   tests/qtest/k230-gsdma-test

Signed-off-by: Tao Ding <dingtao0430@163.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Reviewed-by: Junze Cao <caojunze424@gmail.com>
Message-ID: <20260808062227.66961-4-dingtao0430@163.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:12:52 +10:00
Tao Ding
dde8fbba19 hw/riscv: k230: add gsdma in K230 board
This commit replaces the unimplemented part of GSDMA in K230. And connect the interrupt to plic.

Update K230.rst.

Signed-off-by: Tao Ding <dingtao0430@163.com>
Reviewed-by: Junze Cao <caojunze424@gmail.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260808062227.66961-3-dingtao0430@163.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:10:49 +10:00
Tao Ding
54bc6c4f15 hw/dma: add K230 gsdma
K230 GSDMA includes SDMA (System Direct Memory Access) and GDMA (Graphic Direct Memory Access).
In this patch, add SDMA for k230 board. The following features have not been implemented:
1. axi protocol related
2. channel arbitration
3. lower power mode

SDMA supports transfer data between memory, in which case SDMA is the controller.
It also supports transfer data to decomp_gzip and caching it through SRAM.
In this case, decomp_gzip is the controller, which controls SDMA through handshake signals.

According to "K230 Technical Reference Manual v0.3.1" section 2.5.2.
https://download.kendryte.com/developer/k230/HDK/K230%E7%A1%AC%E4%BB%B6%E6%96%87%E6%A1%A3/K230_Technical_Reference_Manual_V0.3.1_20241118.pdf

This commit includes:
- K230 SDMA (System Direct Memory Access) model (k230_gsdma.c, k230_gsdma.h)
- GSDMA trace log (trace-events)
- Kconfig and meson.build
- update MAINTAINERS

Signed-off-by: Tao Ding <dingtao0430@163.com>
Reviewed-by: Chao Liu <chao.liu@processmission.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Reviewed-by: Junze Cao <caojunze424@gmail.com>
Message-ID: <20260808062227.66961-2-dingtao0430@163.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:08:25 +10:00
Yanfeng Liu
2a99140258 riscv/virt: Add optional UART1
This adds optional UART1 to RiscV virt board if required at
runtime to simplify multicore development.

Note that UART0 remains default serial_hd(0) and it is:

- the lowest address UART
- first serial in DTB
- behind /aliases/serial0 in DTB
- the /chosen/stdout-path in DTB

Note that UART1 is placed at different page from UART0 to
support page level isolation.

Signed-off-by: Yanfeng Liu <yfliu2008@qq.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <tencent_4EEBFC805F3E59863BEDC38094EF5A109206@qq.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:06:23 +10:00
Junze Cao
98911b604b tests/qtest: Add K230 DDR controller tests
Add qtests for DDRC and PHY reset values, register access policy, the
software-update handshake, and PHY register ownership.

Exercise PHY training and mailbox acknowledgement through the DFI
initialization sequence. Include negative coverage to ensure DFI cannot
complete before PHY training or enter Normal mode before completion is
enabled.

Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Suggested-by: Chao Liu <chao.liu@processmission.com>
Signed-off-by: Junze Cao <caojunze424@gmail.com>
Message-ID: <20260807-k230-ddr-v2-v2-3-c531308ae819@gmail.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 11:04:36 +10:00
Junze Cao
4309ee8e91 hw/riscv: Connect K230 DDR controller and PHY models
Replace the unimplemented K230 DDR configuration region with the DDRC
model and map the PHY model at 0x9a000000.

Connect the controller to the PHY so DFI status reflects PHY training and
initialization state.

Suggested-by: Chao Liu <chao.liu@processmission.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Signed-off-by: Junze Cao <caojunze424@gmail.com>
Message-ID: <20260807-k230-ddr-v2-v2-2-c531308ae819@gmail.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 10:47:13 +10:00
Junze Cao
798eddba10 hw/misc: Add K230 DDR controller and PHY models
The K230 SDK U-Boot SPL programs K230 DDRC CFG and K230 DDR PHY
registers before DRAM can be used.

Add separate SysBus devices for both register ranges. Model controller
reset values, DFI and software-update handshakes. For the PHY, model
register ownership, the training mailbox, and DFI completion.

Include migration state for both devices.

Signed-off-by: Junze Cao <caojunze424@gmail.com>
Suggested-by: Chao Liu <chao.liu@processmission.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Message-ID: <20260807-k230-ddr-v2-v2-1-c531308ae819@gmail.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-08-24 10:47:13 +10:00
Richard Henderson
bde2492aac ppc-for-11.2-20260823
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEa4EM1tK+EPOIPSFCRUTplPnWj7sFAmqKlQcACgkQRUTplPnW
 j7tgEw//anSKG8cNMcauqfv9kB4buOdtGPLZS7QjO35JPYD6bI8Z+DvPMSJKi+xP
 3GcjT3rZbzCI0OsbAzw5OmSCZzsY/Cgr+1FrlJcC49jOEHC4VklD7tVV6dH5MS1j
 CUZlxd5TQrf49URitZcaOcQWHNxrr1WjDhGxmdz0VnV4nJF4QQMyACRM6e+KpgXN
 0qLGfuHF77N79g+ttf1psI+VYESk8kMg48rQDDBqlF1y27D1GEMdsNqq8lhvzvZc
 tLUiui3xvhXPRqUTE6AcvGrpCfdkoiAsR/R6i0kdu+HrQ10CcRHTXCyYpPjBj2wg
 bo7erO4jQBHroIXXkAJ8EJzOTNMmaBtHuXjMZYgCHO9pYMGgHzp3yXvqyC9k3F/c
 dlOgrdw6mC7K+3b4REHeG8kaYRtIFi8vbENGQNSMyEDZswvU+obwKZWz24nmOvvl
 A6QP2C6/gAraodcoDMaJ9pYhU6/5ynGhbcrfjzqiGN1z/pmXIiXffW342oLciWa/
 /yAMCiHhH9k7aBULm27JqcCWOiotk/Xv9J1/TlLfcs6h3YuMlVGl6V4zMvctufYO
 XqqP/iJqbj3djdYQLGUEdEG1Yh2LItO9KYu5F00jET1fE8DW6NS9ceUe4A6oma8f
 nMv3ErfxAbVkr5rN/vibo35yG2O26ApwW8oQDM0NzlesklsMHd0=
 =vkyg
 -----END PGP SIGNATURE-----

Merge tag 'pull-ppc-for-11.2-20260823' of https://gitlab.com/harshpb/qemu into staging

ppc-for-11.2-20260823

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEEa4EM1tK+EPOIPSFCRUTplPnWj7sFAmqKlQcACgkQRUTplPnW
# j7tgEw//anSKG8cNMcauqfv9kB4buOdtGPLZS7QjO35JPYD6bI8Z+DvPMSJKi+xP
# 3GcjT3rZbzCI0OsbAzw5OmSCZzsY/Cgr+1FrlJcC49jOEHC4VklD7tVV6dH5MS1j
# CUZlxd5TQrf49URitZcaOcQWHNxrr1WjDhGxmdz0VnV4nJF4QQMyACRM6e+KpgXN
# 0qLGfuHF77N79g+ttf1psI+VYESk8kMg48rQDDBqlF1y27D1GEMdsNqq8lhvzvZc
# tLUiui3xvhXPRqUTE6AcvGrpCfdkoiAsR/R6i0kdu+HrQ10CcRHTXCyYpPjBj2wg
# bo7erO4jQBHroIXXkAJ8EJzOTNMmaBtHuXjMZYgCHO9pYMGgHzp3yXvqyC9k3F/c
# dlOgrdw6mC7K+3b4REHeG8kaYRtIFi8vbENGQNSMyEDZswvU+obwKZWz24nmOvvl
# A6QP2C6/gAraodcoDMaJ9pYhU6/5ynGhbcrfjzqiGN1z/pmXIiXffW342oLciWa/
# /yAMCiHhH9k7aBULm27JqcCWOiotk/Xv9J1/TlLfcs6h3YuMlVGl6V4zMvctufYO
# XqqP/iJqbj3djdYQLGUEdEG1Yh2LItO9KYu5F00jET1fE8DW6NS9ceUe4A6oma8f
# nMv3ErfxAbVkr5rN/vibo35yG2O26ApwW8oQDM0NzlesklsMHd0=
# =vkyg
# -----END PGP SIGNATURE-----
# gpg: Signature made Sat 22 Aug 2026 11:36:55 PM PDT
# gpg:                using RSA key 6B810CD6D2BE10F3883D21424544E994F9D68FBB
# gpg: Good signature from "Harsh Prateek Bora <harsh.prateek.bora@gmail.com>" [undefined]
# gpg:                 aka "Harsh Prateek Bora <harshpb@linux.ibm.com>" [undefined]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 6B81 0CD6 D2BE 10F3 883D  2142 4544 E994 F9D6 8FBB

* tag 'pull-ppc-for-11.2-20260823' of https://gitlab.com/harshpb/qemu:
  MAINTAINERS: add self as reviewer for PowerPC RAS
  MAINTAINERS: add dedicated PowerPC RAS section
  powernv: boot OpenBSD on POWER9
  hw/watchdog: Add lower bound check for watchdogNumber
  MAINTAINERS: Add myself as a reviewer for PPC KVM and sPAPR
  target/ppc: Validate HTABMASK and reserved bits in SDR1 for 32-bit mode
  target/ppc/cpu_init: make cpu listing deterministic

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-23 08:33:31 -07:00
Shivang Upadhyay
45caf67b9a
MAINTAINERS: add self as reviewer for PowerPC RAS
I have been contributing to Fadump, MPIPL as well as PowerNV for quite
some time, and my daily work responsibilities includes taking care of
PowerPC RAS features. I, therefore would like to step up as a reviewer
to get notified of incoming changes in this area and help reviewing
them.

Acked-by: Aditya Gupta <adityag@linux.ibm.com>
Signed-off-by: Shivang Upadhyay <shivangu@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260819193757.1072909-3-shivangu@linux.ibm.com
Signed-off-by: Harsh Prateek Bora <harshpb@linux.ibm.com>
2026-08-23 11:42:57 +05:30
Shivang Upadhyay
3e182317a6
MAINTAINERS: add dedicated PowerPC RAS section
Introduce a new "PowerPC RAS (Reliability, Availability and
Serviceability)" entry in the PowerPC Machines block, replacing the
existing Fadump/MPIPL sections. Retaining the maintainer and
reviewer entries from Fadump/MPIPL sections for this broader umbrella.

Currently most of RAS related code sits in spapr_rtas.c, So Adding
it to PowerPC RAS section. Additionally adding spapr_events.c, as it
implements RTAS error logging infrastructure and spapr_pci_vfio.c, since
its all EEH related code.

Acked-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Acked-by: Aditya Gupta <adityag@linux.ibm.com>
Signed-off-by: Shivang Upadhyay <shivangu@linux.ibm.com>
Acked-by: Hari Bathini <hbathini@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260819193757.1072909-2-shivangu@linux.ibm.com
Signed-off-by: Harsh Prateek Bora <harshpb@linux.ibm.com>
2026-08-23 11:42:57 +05:30
Kirill A. Korinsky
504810bbdf
powernv: boot OpenBSD on POWER9
The POWER9 Processor User's Manual, section 4.9.4, specifies that POWER9
ignores PTCR[PATS] and only supports a 64 KiB partition table. Use an
effective PATS value of 4 on POWER9; other processors keep the existing
ISA v3.0 interpretation.

The PSI model now exposes POWER9 IRQ level and pending status registers,
and keeps both updated while delivering through the existing XIVE LSI
source. This lets guests that select the POWER9 PSI LSI IRQ method
continue to receive LPC interrupts.

The blast radius is probably minimal: the PTCR change is limited to
POWER9, while the PSI change only touches POWER9 PSI state and reuses
the existing delivery path.

Acked-by: Chinmay Rath <rathc@linux.ibm.com>
Signed-off-by: Kirill A. Korinsky <kirill@korins.ky>
Reviewed-by: Aditya Gupta <adityag@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260719145559.94342-1-kirill@korins.ky
Signed-off-by: Harsh Prateek Bora <harshpb@linux.ibm.com>
2026-08-23 11:40:48 +05:30
Chinmay Rath
eea4de1bd8
hw/watchdog: Add lower bound check for watchdogNumber
Add missing lower bound check for H_WATCHDOG H_CALL's watchdogNumber parameter
as per PAPR documentation ver 12.10.00 section 14.15.5 'H_WATCHDOG'.

Closes : https://gitlab.com/qemu-project/qemu/-/work_items/3600

Reviewed-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Reported-by: huntr bubble <bubblehuntr@gmail.com>
Signed-off-by: Chinmay Rath <rathc@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260818104551.76023-1-rathc@linux.ibm.com
[harshpb: corrected title prefix to hw/watchdog]
Signed-off-by: Harsh Prateek Bora <harshpb@linux.ibm.com>
2026-08-23 11:37:05 +05:30
Amit Machhiwal
ac6a32a106
MAINTAINERS: Add myself as a reviewer for PPC KVM and sPAPR
I have been contributing to PPC KVM and sPAPR (pseries) for some time now and
would like to get notified of incoming changes to help with code reviews.

Signed-off-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Acked-by: Gautam Menghani <gautam@linux.ibm.com>
Acked-by: Chinmay Rath <rathc@linux.ibm.com>
Reviewed-by: Cédric Le Goater <clg@kaod.org>
Link: https://lore.kernel.org/qemu-devel/20260819050545.21232-1-amachhiw@linux.ibm.com
Signed-off-by: Harsh Prateek Bora <harshpb@linux.ibm.com>
2026-08-23 11:30:51 +05:30
Minhang Zhang
e2bbc72a66
target/ppc: Validate HTABMASK and reserved bits in SDR1 for 32-bit mode
ppc_store_sdr1() had validation for 64-bit SDR1 values but lacked
corresponding checks for the 32-bit case.  According to the Power ISA,
in 32-bit mode SDR1 bits 16-22 are reserved (must be zero) and
HTABMASK (bits 23-31) must consist of a consecutive string of
1-bits starting from the LSB, i.e., be of the form 2^n-1.

Add checks to reject invalid HTABMASK values and log a guest error
for non-zero reserved bits, following the same pattern used by the
existing 64-bit validation.

Reviewed-by: Chinmay Rath <rathc@linux.ibm.com>
Signed-off-by: Minhang Zhang <zhangminhang@kylinos.cn>
Link: https://lore.kernel.org/qemu-devel/tencent_8388D4B38DC5172F5EEE70436D3AD6D02006@qq.com
Signed-off-by: Harsh Prateek Bora <harshpb@linux.ibm.com>
2026-08-23 11:26:31 +05:30
Pierrick Bouvier
fa6a91fd8c
target/ppc/cpu_init: make cpu listing deterministic
The existing compare function only make sure that we list cpus with PVR
order. However, we never compare cpu names.
As a result, while cpus are grouped per PVR, the order within a group is
non deterministic. Depending on QOM type initialization order, we get
different results for -cpu help.

For instance, previous output could be:
Available CPUs:
  755_v1.0         PVR 00083100
  745_v1.0         PVR 00083100
  755_v1.1         PVR 00083101
  745_v1.1         PVR 00083101

While a sorted output should be:
Available CPUs:
  745_v1.0         PVR 00083100
  755_v1.0         PVR 00083100
  745_v1.1         PVR 00083101
  755_v1.1         PVR 00083101

Fix it by comparing cpu names to have a stable result.
This allows us to record and compare various command line results across
versions to make sure we didn't break anything while working on
single-binary.

Signed-off-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Tested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Tested-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260720192403.66694-1-pierrick.bouvier@oss.qualcomm.com
Signed-off-by: Harsh Prateek Bora <harshpb@linux.ibm.com>
2026-08-23 11:19:55 +05:30
Richard Henderson
eea8fe61b8 igvm + vmlaunchupdate: allow guests supply their own igvm firmware images.
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEoDKM/7k6F6eZAf59TLbY7tPocTgFAmqIeGcACgkQTLbY7tPo
 cTi6eA/+LTgcwLrRIRlZBJ1ExwYBAVeeI2AwfoVvL7LrNrVTeW5O3HBkkd5iW3u1
 O5GGabV/8dQsrt3cTbQ6Tj1FuTaAFluNgykok4uCb9kavji/WQofkBgoek6PmDBi
 4CPwseO12eh9i/OV1yyCRdKqBuUjwnk1LbJIaBRDhz+AOhvTrPZYtxZMC1XZUY/4
 QPTHzo4lDyRphdq/puXe+Z4WPRMpt0tEUzSq1ev57W2Pwu3Rrf6BNM5X+uH8vTXQ
 3OwzmpNDsJusMKpo0/+gc1pGuLrNSSVWfbrEzsKot6jUg3hfkqmonTEFT+ArZNSn
 cqBCulWVlopJttRcnbUUSdjTaoBHIfS2yX2w10K2eVX7s2DbXy49GERhlfC23BHi
 zMrBQ0JGU4njdZXobFnR8HtCqwAlaTgFHiTHIjk4+IZHRPHUCAOVAIb0rkCeFSX3
 qgE1vHJhEBHLIsCv5F6Kb3aUbTiqWSzfFR67FRZctTzJp0nvJ06EiTlKURDk9CyG
 krInt79qeTHgNu8zNTDwoy8WbHlbDepv0aL/S+liHcE8Drvr5X0pWA0vMWE6mgvj
 Ibd8BEpw6VbLrGe/cz0eLRdu2/6tIDEKYmlAReuRX9ifP3kT41fT9aF/h9BOuJae
 zKWRSDgNfPB6MNf2r/6jvOHNCVaaG69jd0HJH/9cbzxHqinMe54=
 =9hRx
 -----END PGP SIGNATURE-----

Merge tag 'igvm-20260821-pull-request' of https://gitlab.com/kraxel/qemu into staging

igvm + vmlaunchupdate: allow guests supply their own igvm firmware images.

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEoDKM/7k6F6eZAf59TLbY7tPocTgFAmqIeGcACgkQTLbY7tPo
# cTi6eA/+LTgcwLrRIRlZBJ1ExwYBAVeeI2AwfoVvL7LrNrVTeW5O3HBkkd5iW3u1
# O5GGabV/8dQsrt3cTbQ6Tj1FuTaAFluNgykok4uCb9kavji/WQofkBgoek6PmDBi
# 4CPwseO12eh9i/OV1yyCRdKqBuUjwnk1LbJIaBRDhz+AOhvTrPZYtxZMC1XZUY/4
# QPTHzo4lDyRphdq/puXe+Z4WPRMpt0tEUzSq1ev57W2Pwu3Rrf6BNM5X+uH8vTXQ
# 3OwzmpNDsJusMKpo0/+gc1pGuLrNSSVWfbrEzsKot6jUg3hfkqmonTEFT+ArZNSn
# cqBCulWVlopJttRcnbUUSdjTaoBHIfS2yX2w10K2eVX7s2DbXy49GERhlfC23BHi
# zMrBQ0JGU4njdZXobFnR8HtCqwAlaTgFHiTHIjk4+IZHRPHUCAOVAIb0rkCeFSX3
# qgE1vHJhEBHLIsCv5F6Kb3aUbTiqWSzfFR67FRZctTzJp0nvJ06EiTlKURDk9CyG
# krInt79qeTHgNu8zNTDwoy8WbHlbDepv0aL/S+liHcE8Drvr5X0pWA0vMWE6mgvj
# Ibd8BEpw6VbLrGe/cz0eLRdu2/6tIDEKYmlAReuRX9ifP3kT41fT9aF/h9BOuJae
# zKWRSDgNfPB6MNf2r/6jvOHNCVaaG69jd0HJH/9cbzxHqinMe54=
# =9hRx
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri 21 Aug 2026 09:10:15 AM PDT
# gpg:                using RSA key A0328CFFB93A17A79901FE7D4CB6D8EED3E87138
# gpg: Good signature from "Gerd Hoffmann (work) <kraxel@redhat.com>" [unknown]
# gpg:                 aka "Gerd Hoffmann <gerd@kraxel.org>" [unknown]
# gpg:                 aka "Gerd Hoffmann (private) <kraxel@gmail.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: A032 8CFF B93A 17A7 9901  FE7D 4CB6 D8EE D3E8 7138

* tag 'igvm-20260821-pull-request' of https://gitlab.com/kraxel/qemu:
  Update MAINTAINERS
  Add functional and unit tests for the vm-launch-update device
  tests/qtest: Add small igvm files for testing purpose
  docs/spec: Add a specification document for vm-launch-update device
  hw/misc/vmlaunchupdate: Introduce hypervisor fw-cfg interface support
  hw/misc/vmlaunchupdate: add api header
  backends/igvm: add a tracepoint for qigvm_cleanup_memory
  system/memory: add a tracepoint for memory_region_finalize
  igvm: cleanup memory regions
  igvm: track memory regions
  igvm: store IgvmCfg pointer in QIgvm
  MAINTAINERS: elevating myself to be a maintainer for igvm

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-21 10:39:31 -07:00
Richard Henderson
3375621e78 target-arm queue:
* target/arm: Restrict arm_do_plugin_vcpu_discon_cb() to TCG
  * hw/intc: Fix kconfig handling for gicv3 when TCG disabled
  * target/arm: CPU refactoring to prepare for max-v8 and max-v9
  * hw/misc/iotkit-secctl.c: fix AHB secure read
  * target/arm: Fix SVE2 WHILEWR/WHILERW zero diff boundary case
  * hw/arm/ax3000-soc: fix heap overflow from missing class_size
  * target/arm: Implement AArch32 "disable Neon" and "disable
    VFP D16-D31 insns" CPACR/HCPTR/NSACR trap bits
  * hw/arm: put arm_boot_info structs into machine state struct
 -----BEGIN PGP SIGNATURE-----
 
 iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmqIL7YZHHBldGVyLm1h
 eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3pyGD/0fIH5Hq23FdWzGBws4cJOr
 q175XCXQlaxgMG+OuJBWf5aKwLeqNFmcCspjv7p07Ezjrwixb/Qsbth5WFbZ/zCi
 hr8kemvaq9jUzU8GmQsGmv7SgY8yXROaQGLIb8eycOBlG6ih7u3EI5TR37nFcez5
 jxg/WkBbCprHG03Bsi7ZCDpglucNHlgxerOl7O1x2O3yfT0HC9hmVsn8N986S+/y
 nPmzNg1/xEuGGIgOXVijCr/t/T5PgnwNdkZ5HlnLGkYHBIxq9BlINKlMPu3TK4D2
 548ujAJF+ZwNTJh6D84qS0a0Yiq2g+rLvTTZePv/0V7wIy5HOvL9m6zcj+1xAojZ
 86UFY33/AaHowWCNAHEtEISFrKRjfwkiAamLPkkG6wae+8RCpA3/5arY2hNNNbfy
 N1JEvQMeil/roXfei1QTKP5pCqUhUNfMm4pR8xXPb8Ke6uEKwXjjqAw/Gg6jaccn
 ZRCbG/BIs5LlWzUyyYuqsiIzAY9xuuU/UeHj2N+fr+vtqgiltTpgkJ1W2V90WCuu
 1NF1eiUKukyVXn9IW3IxAqcXYCHqMY9lt2D0BcijYyjsaFRfQMLYw220/PACcnsl
 69tqEV92OdwRXZ8MSBwj4Xv4y1U4me9uL490+1oKgQIm+J5dj653ViEmHJ6Of4wb
 fSgKhs91YewlAsZDluKi6w==
 =p8ub
 -----END PGP SIGNATURE-----

Merge tag 'pull-target-arm-20260821' of https://gitlab.com/pm215/qemu into staging

target-arm queue:
 * target/arm: Restrict arm_do_plugin_vcpu_discon_cb() to TCG
 * hw/intc: Fix kconfig handling for gicv3 when TCG disabled
 * target/arm: CPU refactoring to prepare for max-v8 and max-v9
 * hw/misc/iotkit-secctl.c: fix AHB secure read
 * target/arm: Fix SVE2 WHILEWR/WHILERW zero diff boundary case
 * hw/arm/ax3000-soc: fix heap overflow from missing class_size
 * target/arm: Implement AArch32 "disable Neon" and "disable
   VFP D16-D31 insns" CPACR/HCPTR/NSACR trap bits
 * hw/arm: put arm_boot_info structs into machine state struct

# -----BEGIN PGP SIGNATURE-----
#
# iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmqIL7YZHHBldGVyLm1h
# eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3pyGD/0fIH5Hq23FdWzGBws4cJOr
# q175XCXQlaxgMG+OuJBWf5aKwLeqNFmcCspjv7p07Ezjrwixb/Qsbth5WFbZ/zCi
# hr8kemvaq9jUzU8GmQsGmv7SgY8yXROaQGLIb8eycOBlG6ih7u3EI5TR37nFcez5
# jxg/WkBbCprHG03Bsi7ZCDpglucNHlgxerOl7O1x2O3yfT0HC9hmVsn8N986S+/y
# nPmzNg1/xEuGGIgOXVijCr/t/T5PgnwNdkZ5HlnLGkYHBIxq9BlINKlMPu3TK4D2
# 548ujAJF+ZwNTJh6D84qS0a0Yiq2g+rLvTTZePv/0V7wIy5HOvL9m6zcj+1xAojZ
# 86UFY33/AaHowWCNAHEtEISFrKRjfwkiAamLPkkG6wae+8RCpA3/5arY2hNNNbfy
# N1JEvQMeil/roXfei1QTKP5pCqUhUNfMm4pR8xXPb8Ke6uEKwXjjqAw/Gg6jaccn
# ZRCbG/BIs5LlWzUyyYuqsiIzAY9xuuU/UeHj2N+fr+vtqgiltTpgkJ1W2V90WCuu
# 1NF1eiUKukyVXn9IW3IxAqcXYCHqMY9lt2D0BcijYyjsaFRfQMLYw220/PACcnsl
# 69tqEV92OdwRXZ8MSBwj4Xv4y1U4me9uL490+1oKgQIm+J5dj653ViEmHJ6Of4wb
# fSgKhs91YewlAsZDluKi6w==
# =p8ub
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri 21 Aug 2026 04:00:06 AM PDT
# gpg:                using RSA key E1A5C593CD419DE28E8315CF3C2525ED14360CDE
# gpg:                issuer "peter.maydell@linaro.org"
# gpg: Good signature from "Peter Maydell <peter.maydell@linaro.org>" [unknown]
# gpg:                 aka "Peter Maydell <pmaydell@gmail.com>" [unknown]
# gpg:                 aka "Peter Maydell <pmaydell@chiark.greenend.org.uk>" [unknown]
# gpg:                 aka "Peter Maydell <peter@archaic.org.uk>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: E1A5 C593 CD41 9DE2 8E83  15CF 3C25 25ED 1436 0CDE

* tag 'pull-target-arm-20260821' of https://gitlab.com/pm215/qemu: (43 commits)
  hw/arm: xilinx_zynq: Store boot info in the machine state
  hw/arm: versatilepb: Store boot info in the machine state
  hw/arm: sabrelite: Store boot info in the machine state
  hw/arm: realview: Store boot info in the machine state
  hw/arm: orangepi: Store boot info in the machine state
  hw/arm: omap_sx1: Store boot info in the machine state
  hw/arm: npcm8xx: Store boot info in the machine state
  hw/arm: npcm7xx: Store boot info in the machine state
  hw/arm: musicpal: Store boot info in the machine state
  hw/arm: mcimx7d-sabre: Store boot info in the machine state
  hw/arm: kzm: Store boot info in the board state
  hw/arm: integratorcp: Store boot info in the machine state
  hw/arm: imx8mm-evk: Store boot info in the machine state
  hw/arm: imx25_pdk: Store boot info in the board state
  hw/arm: exynos4_boards: Store boot info in the board state
  hw/arm: cubieboard: Store boot info in the machine state
  hw/arm: collie: Store boot info in the machine state
  hw/arm: bananapi_m2u: Store boot info in the machine state
  hw/arm: aspeed_ast27x0-fc: Store boot info in the machine state
  hw/arm: aspeed: Store boot info in the machine state
  ...

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-21 06:58:21 -07:00
Bin Meng
37c0a0059d hw/arm: xilinx_zynq: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Move the boot info into the existing ZynqMachineState.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-id: 20260816131300.51799-21-bin.meng@processmission.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:28:10 +01:00
Bin Meng
4477c14482 hw/arm: versatilepb: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Give both machine types the same VersatileMachineState instance struct
and store the boot info there.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-20-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:28:02 +01:00
Bin Meng
4a421f0a7b hw/arm: sabrelite: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Move the boot info into the existing SabreliteMachineState.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260816131300.51799-19-bin.meng@processmission.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:27:44 +01:00
Bin Meng
42a64af521 hw/arm: realview: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Give all four realview machine types the same RealViewMachineState
instance struct and store the boot info there.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-18-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:27:19 +01:00
Bin Meng
ab7794550f hw/arm: orangepi: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Move it into a new OrangePiMachineState and register the machine type
explicitly instead of through the DEFINE_MACHINE_ARM macro.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Reviewed-by: Niek Linnenbank <nieklinnenbank@gmail.com>
Message-id: 20260816131300.51799-17-bin.meng@processmission.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:27:13 +01:00
Bin Meng
53fad63eeb hw/arm: omap_sx1: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Give both the sx1 and sx1-v1 machine types the same Sx1MachineState
instance struct and store the boot info there.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260816131300.51799-16-bin.meng@processmission.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:27:06 +01:00
Bin Meng
244b542695 hw/arm: npcm8xx: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object inside
npcm8xx_load_kernel().

Let the caller own the boot info: the board stores it in its
NPCM8xxMachine and passes it to npcm8xx_load_kernel(), which only
fills in the SoC specific values.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-15-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:26:59 +01:00
Bin Meng
92fbe79cb0 hw/arm: npcm7xx: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object inside
npcm7xx_load_kernel().

Let the caller own the boot info: the boards store it in their
NPCM7xxMachine and pass it to npcm7xx_load_kernel(), which only fills
in the SoC specific values.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-14-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:26:19 +01:00
Bin Meng
b8e984eb90 hw/arm: musicpal: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Move it into a new MusicPalMachineState and register the machine type
explicitly instead of through the DEFINE_MACHINE_ARM macro.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-13-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:26:06 +01:00
Bin Meng
b8939158c3 hw/arm: mcimx7d-sabre: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a function scoped static object.

Move it into a new Mcimx7dSabreMachineState and register the machine
type explicitly instead of through the DEFINE_MACHINE_ARM macro.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-12-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:25:50 +01:00
Bin Meng
f139ad829a hw/arm: kzm: Store boot info in the board state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

The IMX31KZM struct is already allocated per machine instance, so
move the boot info there.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-11-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:25:44 +01:00
Bin Meng
27d4e71757 hw/arm: integratorcp: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Move it into a new IntegratorcpMachineState and register the machine
type explicitly instead of through the DEFINE_MACHINE_ARM macro.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-10-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:25:31 +01:00
Bin Meng
3b9cb3dd04 hw/arm: imx8mm-evk: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a function scoped static object.

Move it into a new Imx8mmEvkMachineState and register the machine type
explicitly instead of through the DEFINE_MACHINE_AARCH64 macro.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-9-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:25:24 +01:00
Bin Meng
bcdc392396 hw/arm: imx25_pdk: Store boot info in the board state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

The IMX25PDK struct is already allocated per machine instance, so
move the boot info there.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-8-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:25:10 +01:00
Bin Meng
be525becaa hw/arm: exynos4_boards: Store boot info in the board state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

The Exynos4BoardState struct is already allocated per machine
instance, so move the boot info there.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260816131300.51799-7-bin.meng@processmission.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:25:03 +01:00
Bin Meng
edb0b93a70 hw/arm: cubieboard: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Move it into a new CubieboardMachineState and register the machine
type explicitly instead of through the DEFINE_MACHINE_ARM macro.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-6-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:24:33 +01:00
Bin Meng
9130e284e4 hw/arm: collie: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Move the boot info into the existing CollieMachineState.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-5-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:24:21 +01:00
Bin Meng
1fa13d2eef hw/arm: bananapi_m2u: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Move it into a new Bpim2uMachineState and register the machine type
explicitly instead of through the DEFINE_MACHINE_ARM macro.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260816131300.51799-4-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:24:02 +01:00
Bin Meng
98caf59187 hw/arm: aspeed_ast27x0-fc: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Move the boot info into the existing Ast2700FCState.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260816131300.51799-3-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:23:49 +01:00
Bin Meng
7a0c61ad4e hw/arm: aspeed: Store boot info in the machine state
arm_load_kernel() keeps a pointer to the boot info struct for the
lifetime of the VM, so the struct logically belongs to the machine
rather than to a file scoped static object.

Move the boot info into the existing AspeedMachineState.

As in the xlnx-zcu102 and raspi machines, the boot info belongs to
the machine rather than to a static object:

4d1ac883a7 ("hw/arm: xlnx-zcu102: Move arm_boot_info into XlnxZCU102")
0f15c6e338 ("hw/arm/raspi: Move arm_boot_info structure to RaspiMachineState")

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260816131300.51799-2-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 10:19:55 +01:00
Peter Maydell
44d5b628fb target/arm: Pull Neon dregs checks out into a function
Abstract out the register check for Neon insns into a new function,
similarly to what we have for VFP.  We don't have any extra checks
that we need to add here, but having a neon_dregs_ok() is cleaner and
means the Neon decode isn't oddly different to the VFP decode.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260817123838.1578060-9-peter.maydell@linaro.org
2026-08-21 09:50:40 +01:00
Peter Maydell
282ff9baeb target/arm: Implement CPACR.D32DIS
On some v7A CPUs, CPACR.D32DIS is a bit allowing the guest to make
VFP instructions that touch registers D16..D31 UNDEF.  Whether the
CPU implements this or not is IMPDEF, and the only two CPUs we
implement which have this are the Cortex-A7 and Cortex-A9.  In v8A
the bit is no longer defined at all.

Since the only kind of trapping that needs to be done is a simple
UNDEF, this is straightforward enough to implement.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/1499
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260817123838.1578060-8-peter.maydell@linaro.org
2026-08-21 09:50:40 +01:00
Peter Maydell
975a1bd439 target/arm: Pull VFP dregs checks out into a function
Currently we directly call dc_isar_feature(aa32_simd_r32, s) for VFP
insns that use D16-D31 to see if they should UNDEF.  For some v7A
CPUs (Cortex-A7, Cortex-A9) there is also a CPACR.D32DIS trap bit
that will make VFP (and only VFP, not Neon) insns using D16-D31
UNDEF.

Abstract out the register check for VFP insns into a new function
which will provide us a place where we can make this check.

Since D32DIS takes precedence over traps to EL2 and EL3 and simply
makes the insns UNDEF, we are OK to check it at the same point when
we do the CPU feature check, rather than having to wait until
vfp_access_check().

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260817123838.1578060-7-peter.maydell@linaro.org
2026-08-21 09:50:40 +01:00
Peter Maydell
284a3c2924 target/arm: Implement CPACR.ASEDIS and HCPTR.TASE
When executing at AArch32, there are optional trap bits for Neon
instructions in CPACR and HCPTR. We don't currently implement these.

Now we have a separate code path for access checks for Neon insns, we
can straightforwardly add the check there.  We need to track the
target EL for Neon-specific trapping in a new TB flag.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/1499
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260817123838.1578060-6-peter.maydell@linaro.org
2026-08-21 09:50:40 +01:00
Peter Maydell
fdf3c577a9 target/arm: Add new feature ARM_FEATURE_NEON_TRAPS
The traps configurable via CPACR.ASEDIS and HCPTR.TASE that trap only
Neon instructions are unfortunately IMPDEF about whether they are
implemented or not, and there is no ID register field that identifies
whether they are present.  In practice, they are present on every
implementation I have checked except for the Cortex-A8 (which was the
first CPU with Neon).

Add a new feature ARM_FEATURE_NEON_TRAPS which we set on every
ARM_FEATURE_NEON CPU except the Cortex-A8, and make the CPACR.ASEDIS
and HCPTR.TASE bits RAZ/WI unless the CPU has ARM_FEATURE_NEON and
ARM_FEATURE_NEON_TRAPS.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260817123838.1578060-5-peter.maydell@linaro.org
2026-08-21 09:50:40 +01:00
Peter Maydell
11dacc5b83 target/arm: Update confusing comment in cpacr_write()
In cpacr_write() a comment says "In ARMv8 most bits of CPACR_EL1 are
RES0", and the mask value is left at 0, implying that we enforce
those RES0 bits.  In fact we only enforce RES0 when ARM_FEATURE_V8 is
not implemented, and for v8 and up we allow the guest to write any
bits.  The addition of architectural features in v8 and v9 has also
resulted in the addition of new bits to CPACR_EL1, so "most bits are
RES0" isn't really true any more.

Update the comment to be a bit clearer.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260817123838.1578060-4-peter.maydell@linaro.org
2026-08-21 09:50:40 +01:00
Peter Maydell
653311eecd target/arm: Handle NSACR.NSASEDIS in HCPTR accesses
In cptr_el2_read() and cptr_el2_write()  we have code that implements the
"HCPTR.{TCP10,TCP11} behave as RAO/WI from NonSecure when NSACR.cp10 is
0" behaviour.  There is a similar requirement for HCPTR.TASE: if
NSACR.NSASEDIS is 1 then CPACR.ASEDIS behaves as RAO/WI in NS.

This doesn't matter to us yet because we don't currently implement
ASEDIS or NSASEDIS. But we're about to do that, so add the handling
to cptr_el2_read() and cptr_el2_write().

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260817123838.1578060-3-peter.maydell@linaro.org
2026-08-21 09:50:40 +01:00
Peter Maydell
b3f00f492f target/arm: Handle NSACR.NSASEDIS in CPACR accesses
In cpacr_read() and cpacr_write() we have code that implements the
"CPACR.{cp10,cp11} behave as RAZ/WI from NonSecure when NSACR.cp10 is
0" behaviour.  There is a similar requirement for CPACR.ASEDIS: if
NSACR.NSASEDIS is 1 then CPACR.ASEDIS behaves as RAO/WI in NS.

This doesn't matter to us yet because we don't currently implement
ASEDIS or NSASEDIS. But we're about to do that, so add the handling
to cpacr_read() and cpacr_write().

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260817123838.1578060-2-peter.maydell@linaro.org
2026-08-21 09:50:40 +01:00
Doug Cook
4f50d637e2 hw/arm/ax3000-soc: fix heap overflow from missing class_size
TYPE_AX3000_SOC declares an Ax3000SoCClass via OBJECT_DECLARE_TYPE() and
ax3000_class_init() writes to it:

    Ax3000SoCClass *sc = AX3000_SOC_CLASS(oc);
    sc->num_cpus = AX3000_NUM_CPUS;

but its TypeInfo omits .class_size, so type_initialize() only allocates
class_size inherited from the parent, i.e. sizeof(SysBusDeviceClass).
The store to sc->num_cpus therefore writes 4 bytes of the value 4 just
past the end of the class allocation, corrupting whatever heap block
follows it.

Fix by setting class_size.

Fixes: 33a71a68c6 ("hw/arm: Add Axiado SoC AX3000")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4197
Signed-off-by: Doug Cook <dcook@microsoft.com>
Message-id: LVXPR21MB70090B04FF7397B0F2A201C8ADA72@LVXPR21MB7009.namprd21.prod.outlook.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Richard Henderson
3295370010 tests/tcg/aarch64: Add regression test for whilewr/whilerw
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260811191540.79882-4-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Richard Henderson
bab972a2b0 target/arm: Fix SVE2 WHILEWR/WHILERW zero diff boundary case
The trans_WHILE_ptr function incorrectly handles the case where the
address difference divided by ESIZE results in zero. This happens when
the address difference is less than ESIZE but greater than zero.

Fix by dropping direct comparisons of op0 vs op1, and instead
testing the scaled diff vs 0.  Merge with the bounding to the
maximum vector length via wrapping arithmetic.

Cc: qemu-stable@nongnu.org
Fixes: 14f6dad168 ("target/arm: Implement SVE2 WHILERW, WHILEWR")
Reported-by: YanjunYang <yang.yanjun1@sanechips.com.cn>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260811191540.79882-3-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Richard Henderson
b4f6f672a3 tcg: Export tcg_gen_ussub_i{32,64,tl}
Move from tcg-op-gvec.c to tcg-op.c.
Use a temporary, to cover the possibility of operand overlap.

(Cc for stable as this is a prerequisite for the bug fix
in the next commit.)

Cc: qemu-stable@nongnu.org
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260811191540.79882-2-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Simon Xu
4b263689ba hw/misc/iotkit-secctl.c: fix AHB secure read
Fix AHB secure privilege to read AHB instead of APB.

Fixes: b3717c23e1 ("hw/misc/iotkit-secctl: Add handling for PPCs")
Reviewed-by: Owen Giles <owen.giles@hpe.com>
Reviewed-by: Robert Elliott <elliott@hpe.com>
Signed-off-by: Simon Xu <simonxhy0404@gmail.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Richard Henderson
8d346a7109 target/arm: Annotate arch revisions in aarch64_max_tcg_initfn
Annotate the minimum revion from which each feature is OPTIONAL.
Modulo some sorting of properties at the end, comment changes
only.

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260812204435.295067-10-richard.henderson@linaro.org
[PMM: fixed two minor comment issues]

Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Richard Henderson
a2c25ce413 target/arm: Move aa32_max_features to tcg/cpu32.c
The function is unused without TCG, so move.

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260812204435.295067-7-richard.henderson@linaro.org
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Richard Henderson
aa517d9774 target/arm: Split out aarch32_max_tcg_init
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260812204435.295067-6-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Richard Henderson
b5af4f6024 target/arm: Sink aarch64_aa32_a57_init into aarch64_max_tcg_initfn
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260812204435.295067-5-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Richard Henderson
e5b092fa92 target/arm: Pass aarch64_enabled to aarch64_aa32_a57_init
Invert aa32_only argument to what is actually used.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260812204435.295067-4-richard.henderson@linaro.org
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Richard Henderson
9caff83f5b target/arm: Pass ARMCPU to aarch64_aa32_a57_init
There's no reason to pass Object when ARMCPU is more appropriate.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260812204435.295067-3-richard.henderson@linaro.org
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Richard Henderson
66d0446738 target/arm: Tidy cpu_max_initfn
Once we have eliminated hwaccel_enabled, only tcg and qtest remain.
Separate tcg from qtest initialization.  Remove an assert on
aarch64_enabled that is directly protected by a preceding if.

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260812204435.295067-2-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Philippe Mathieu-Daudé
a0c093900d hw/intc/arm_gicv3: Have GIC kconfig select GICv3 for HVF and WHPX
While trying to fix the GICv3 dependency on KVM and WHPX in
commit 39a8c3941e, we missed the Kconfig ARM_GIC symbol only
selects GICv3 for TCG, not HVF and WHPX. Fix that.

Cc: qemu-stable@nongnu.org
Fixes: 39a8c3941e ("hw/intc/arm_gicv3: Fix ARM_GICV3 dependency for KVM / WHPX")
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260812220816.94034-1-philmd@oss.qualcomm.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Richard Henderson
d05febdd32 hw/intc: Fix arm kvm gicv3 selection
While 39a8c3941e may have fixed WHPX, it certainly didn't help KVM:

  $ QTEST_QEMU_BINARY=./qemu-system-aarch64 ./tests/qtest/arm-cpu-features
  ...
  qemu-system-aarch64: unknown type 'kvm-arm-gicv3'

That patch did remove a test for TARGET_AARCH64, which is fine because
it has been a long time since we supported KVM for AArch32.

Cc: qemu-stable@nongnu.org
Fixes: 39a8c3941e ("hw/intc/arm_gicv3: Fix ARM_GICV3 dependency for KVM / WHPX")
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260812200308.289238-1-richard.henderson@linaro.org
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:35 +01:00
Philippe Mathieu-Daudé
1bfce83996 target/arm: Restrict arm_do_plugin_vcpu_discon_cb() to TCG
So far TCG plugins can only be used when TCG is available.
Move the arm_do_plugin_vcpu_discon_cb() call within the
'if tcg_enabled' block and wrap the definition with #ifdef'ry.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Message-id: 20260814080507.23196-1-philmd@oss.qualcomm.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-21 09:14:34 +01:00
Richard Henderson
f57fc2f7ce * dockerfiles: cleanup, update CentOS 9 container to Python 3.11
* rust: fix issues in bits crate
 * rust: replace bilge dependency with bitfield-struct
 * rust: update build system for Meson 1.12.0
 * serial: fix hot-unplug issue
 * target/i386: emulate: simplify flags conversion and storage
 * target/i386: tcg: small fixes
 * target/i386: mshv: complete migration support
 * target/i386: sev: add support for SEV features
 * target/i386: whpx: bugfixes
 -----BEGIN PGP SIGNATURE-----
 
 iQFIBAABCgAyFiEE8TM4V0tmI4mGbHaCv/vSX3jHroMFAmqGq8wUHHBib256aW5p
 QHJlZGhhdC5jb20ACgkQv/vSX3jHroPWBwf6A4w91Tr+mxm3fjcbr/KjVqFnX45k
 qG8l8+60WlA+YY4lUUCJHc4CtPPH9hinOKgm8yGjPdbFrpdcJgQPor4IUgIHnTGu
 Bjceu5k6wlqR7DRetF0TD+NWC2BCkTtbmFcivLd5Ua/vqZVP5j+CITP3t7v5AiuG
 +jEHPTqdk/RMhPdsXcFBl+WditIGNz1/R+pxMKGYfOxF9rQ86sSLd/y2cWrAYNnc
 bO5s8vBxxoNNSxt8qt48aU4gGKvBajpvVQy4/6bPoSs1Z9fwCyCWkQleYSBcBAyn
 3VTRAoift8j/xEgyOtXVdsviIeaUCE4S0aUGso+TMlA+SwEwSi20P917pg==
 =OXwa
 -----END PGP SIGNATURE-----

Merge tag 'for-upstream' of https://gitlab.com/bonzini/qemu into staging

* dockerfiles: cleanup, update CentOS 9 container to Python 3.11
* rust: fix issues in bits crate
* rust: replace bilge dependency with bitfield-struct
* rust: update build system for Meson 1.12.0
* serial: fix hot-unplug issue
* target/i386: emulate: simplify flags conversion and storage
* target/i386: tcg: small fixes
* target/i386: mshv: complete migration support
* target/i386: sev: add support for SEV features
* target/i386: whpx: bugfixes

# -----BEGIN PGP SIGNATURE-----
#
# iQFIBAABCgAyFiEE8TM4V0tmI4mGbHaCv/vSX3jHroMFAmqGq8wUHHBib256aW5p
# QHJlZGhhdC5jb20ACgkQv/vSX3jHroPWBwf6A4w91Tr+mxm3fjcbr/KjVqFnX45k
# qG8l8+60WlA+YY4lUUCJHc4CtPPH9hinOKgm8yGjPdbFrpdcJgQPor4IUgIHnTGu
# Bjceu5k6wlqR7DRetF0TD+NWC2BCkTtbmFcivLd5Ua/vqZVP5j+CITP3t7v5AiuG
# +jEHPTqdk/RMhPdsXcFBl+WditIGNz1/R+pxMKGYfOxF9rQ86sSLd/y2cWrAYNnc
# bO5s8vBxxoNNSxt8qt48aU4gGKvBajpvVQy4/6bPoSs1Z9fwCyCWkQleYSBcBAyn
# 3VTRAoift8j/xEgyOtXVdsviIeaUCE4S0aUGso+TMlA+SwEwSi20P917pg==
# =OXwa
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 20 Aug 2026 12:25:00 AM PDT
# gpg:                using RSA key F13338574B662389866C7682BFFBD25F78C7AE83
# gpg:                issuer "pbonzini@redhat.com"
# gpg: Good signature from "Paolo Bonzini <bonzini@gnu.org>" [unknown]
# gpg:                 aka "Paolo Bonzini <pbonzini@redhat.com>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 46F5 9FBD 57D6 12E7 BFD4  E2F7 7E15 100C CD36 69B1
#      Subkey fingerprint: F133 3857 4B66 2389 866C  7682 BFFB D25F 78C7 AE83

* tag 'for-upstream' of https://gitlab.com/bonzini/qemu: (53 commits)
  rust: remove bilge crate
  rust: pl011: switch from bilge to bitfield-struct
  rust: update Cargo dependencies
  scripts: remove now dead parts of rustc_args.py
  docs: rust: update for new-style build rules
  rust: use meson automatic parsing of Cargo.toml
  meson: use compiler_target() to get rustc target
  rust: switch to autogenerated meson rules
  rust: switch to cargo subprojects
  rust: update Cargo.lock
  rust/bits: Use checked_ilog2() in Binary::format to avoid panic
  rust/bits: Align SubAssign behavior with Sub
  python, meson: update meson required for Rust to 1.12.0
  dockerfiles: update CentOS Stream 9 to Python 3.11, Meson to 1.12
  dockerfiles: remove packages required by Avocado
  meson: make linker warnings non-fatal on Linux
  serial: clear transmit retry callback on unrealize
  whpx: i386: inject back db
  whpx: i386: work around Hyper-V FP state oddities
  whpx: i386: synchronise PAT too
  ...

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-20 16:01:59 -07:00
Ani Sinha
e27a2b5f36 Update MAINTAINERS
Add maintainers for vm-launch-update device and associated documentation and
test code.

Reviewed-by: Alexander Graf <graf@amazon.com>
Signed-off-by: Ani Sinha <anisinha@redhat.com>
Message-ID: <20260817142010.80693-12-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Ani Sinha
0b70c6ce7b Add functional and unit tests for the vm-launch-update device
This patchset adds functional and unit tests that exercize various functions
and behaviors of vm-launch-update device. It uses the IGVM files that were
introduced in the previous patch for exercizing the hypervisor interface.

CC: Alex Graf <graf@amazon.com>
CC: Gerd Hoffman <kraxel@redhat.com>
Reviewed-by: Alexander Graf <graf@amazon.com>
Signed-off-by: Ani Sinha <anisinha@redhat.com>
Message-ID: <20260817142010.80693-11-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Ani Sinha
f0e7be2e8b tests/qtest: Add small igvm files for testing purpose
Needed by launchupdate-test.c. README file is added with explanation on how
to build these IGVM files.

CC: Alex Graf <graf@amazon.com>
CC: Gerd Hoffman <kraxel@redhat.com>

Reviewed-by: Alexander Graf <graf@amazon.com>
Signed-off-by: Ani Sinha <anisinha@redhat.com>
Message-ID: <20260817142010.80693-10-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Ani Sinha
76c16b3c37 docs/spec: Add a specification document for vm-launch-update device
This change adds a specification document and expanation for the
vm-launch-update device.

CC: Alex Graf <graf@amazon.com>
CC: Gerd Hoffman <kraxel@redhat.com>

Reviewed-by: Alexander Graf <graf@amazon.com>
Signed-off-by: Ani Sinha <anisinha@redhat.com>
Message-ID: <20260817142010.80693-9-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Ani Sinha
30688c02a7 hw/misc/vmlaunchupdate: Introduce hypervisor fw-cfg interface support
VM launch update is a mechanism where the virtual machines can use IGVM
file bundle to boot into a trusted execution environment without
having to depend on a untrusted party to provide the IGVM bundle or firmware
image. This is particularly useful for confidential virtual machines that
are deployed in the cloud where the tenant and the cloud provider are two
different entities. In this scenario, virtual machines can bring their own
trusted IGVM file containing a trusted firmware image
bundled as a part of their filesystem and then use this hypervisor interface
to update to a trusted and deterministic boot state.
This also allows the guests to have a consistent measurements on the firmware
image.

Currently, this mechanism only works if the VM was started with IGVM in the
first place.

This change introduces support for the fw-cfg based hypervisor interface
and the corresponding device. The interface is made generic
enough so that guests are free to use their own ABI to pass required
information between initial and trusted execution contexts (where they are
running their own trusted boot state) without the hypervisor getting
involved in between.

Currently, this device is only supported for x86_64 machines. Presence of
IGVM host libraries is also required for parsing IGVM files. Hence, the device
cannot be initialized for other machine types or hosts where IGVM support
is not present. Trying to initialize it for arm for example will lead to failure:

$ ./qemu-system-arm -device vm-launch-update -machine virt
qemu-system-arm: -device vm-launch-update: This machine does not support vm-launch-update device

A document detailing the specification is added in a subsequent patch. Please
see docs/specs/vmlaunchupdate.rst.
Functional and qtests are added in a subsequent patch.

CC: Alex Graf <graf@amazon.com>
CC: Gerd Hoffman <kraxel@redhat.com>

Reviewed-by: Gerd Hoffmann <kraxel@redhat.com>
Reviewed-by: Alexander Graf <graf@amazon.com>
Signed-off-by: Ani Sinha <anisinha@redhat.com>
Message-ID: <20260817142010.80693-8-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Ani Sinha
b23f6d5294 hw/misc/vmlaunchupdate: add api header
Add a separate header file for guest usable api definitions.

CC: Alex Graf <graf@amazon.com>
CC: Gerd Hoffman <kraxel@redhat.com>
Reviewed-by: Alexander Graf <graf@amazon.com>
Signed-off-by: Ani Sinha <anisinha@redhat.com>
Message-ID: <20260819041105.110625-1-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Ani Sinha
68e54556e7 backends/igvm: add a tracepoint for qigvm_cleanup_memory
Useful for debugging memory region cleanups.

Signed-off-by: Ani Sinha <anisinha@redhat.com>
Message-ID: <20260817142010.80693-6-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Ani Sinha
0102503dc5 system/memory: add a tracepoint for memory_region_finalize
cosmetic: add a tracepoint to track when memory regions are getting freed.
Useful for debugging and tracking all freed memory regions.

Reviewed-by: Peter Xu <peterx@redhat.com>
Signed-off-by: Ani Sinha <anisinha@redhat.com>
Message-ID: <20260817142010.80693-5-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Gerd Hoffmann
94cfb5afe7 igvm: cleanup memory regions
This change cleans up existing memory regions that were created by the current
IGVM. The cleanup would be necessary when a new IGVM is loaded. This cleanup
function is called in a subsequent patch.

Reviewed-by: Alexander Graf <graf@amazon.com>
Tested-by: Ani Sinha <anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Message-ID: <20260817142010.80693-4-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Gerd Hoffmann
14eb43761d igvm: track memory regions
Memory regions added by the current IGVM needs to be tracked so that they can be
freed when a new IGVM is loaded.

Reviewed-by: Ani Sinha <anisinha@redhat.com>
Reviewed-by: Alexander Graf <graf@amazon.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Message-ID: <20260817142010.80693-3-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Gerd Hoffmann
acce06adc0 igvm: store IgvmCfg pointer in QIgvm
Store a pointer to IgvmCfg instead of only IgvmFile in QIgvm.  Allows to
store additional state in the (persistent) IgvmCfg struct.

Reviewed-by: Ani Sinha <anisinha@redhat.com>
Reviewed-by: Alexander Graf <graf@amazon.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Message-ID: <20260817142010.80693-2-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Ani Sinha
184417d4ad MAINTAINERS: elevating myself to be a maintainer for igvm
I have worked enough on the igvm to be confident to elevate myself to a
maintainer role.

Signed-off-by: Ani Sinha <anisinha@redhat.com>
Message-ID: <20260818090905.87090-1-anisinha@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-20 16:40:33 +02:00
Richard Henderson
acc271509a pull-loongarch-20260820
-----BEGIN PGP SIGNATURE-----
 
 iLMEAAEKAB0WIQS4/x2g0v3LLaCcbCxAov/yOSY+3wUCaobkOQAKCRBAov/yOSY+
 39I1A/0RIRLfq4CPqkCxPA3/nXctSVB8PlGtmgQuogXsM1+t2+g1VCiPYJ/siU17
 BT59kvocdLGc62MpRIRbR949cwcM/MRJS8AghQ+J4jlo4EwgC2z4QHXrUDEOcrPP
 DiPBaGviLStvGZPZnS0+2ZXmWKgQKD/InB22S/J4b4vOxO9Qwg==
 =qbpH
 -----END PGP SIGNATURE-----

Merge tag 'pull-loongarch-20260820' of https://github.com/gaosong715/qemu into staging

pull-loongarch-20260820

# -----BEGIN PGP SIGNATURE-----
#
# iLMEAAEKAB0WIQS4/x2g0v3LLaCcbCxAov/yOSY+3wUCaobkOQAKCRBAov/yOSY+
# 39I1A/0RIRLfq4CPqkCxPA3/nXctSVB8PlGtmgQuogXsM1+t2+g1VCiPYJ/siU17
# BT59kvocdLGc62MpRIRbR949cwcM/MRJS8AghQ+J4jlo4EwgC2z4QHXrUDEOcrPP
# DiPBaGviLStvGZPZnS0+2ZXmWKgQKD/InB22S/J4b4vOxO9Qwg==
# =qbpH
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 20 Aug 2026 04:25:45 AM PDT
# gpg:                using RSA key B8FF1DA0D2FDCB2DA09C6C2C40A2FFF239263EDF
# gpg: Good signature from "Song Gao <m17746591750@163.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: B8FF 1DA0 D2FD CB2D A09C  6C2C 40A2 FFF2 3926 3EDF

* tag 'pull-loongarch-20260820' of https://github.com/gaosong715/qemu:
  target/loongarch: check FPE before reading fcc in bceqz/bcnez
  target/loongarch: KVM disable msgint
  Add dintc kvm_irqchip_in_kernel support
  target/loongarch: Add kvm support dintc

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-20 07:33:52 -07:00
Jan Mercl
215a4fc08f
target/loongarch: check FPE before reading fcc in bceqz/bcnez
gen_cz_bc() loads env->cf[cj] without CHECK_FPE, unlike every other
translator that touches an fcc register (trans_fcmp.c.inc and
trans_fmov.c.inc, for movcf2gr/movgr2cf/movcf2fr/movfr2cf/fsel).

A guest that manages the FPU lazily -- Linux clears CSR.EUEN.FPE in
lose_fpu() on every context switch -- relies on the next fcc access
raising a Floating-Point-Disabled exception so the kernel can restore
that task's fcc.  Because bceqz and bcnez never raise it, they branch on
the condition flag left behind by whichever task last owned the FPU.

Real Loongson hardware does raise the exception, so this is TCG-only.
It surfaces as Go binaries dying at startup in runtime.check() with
"fatal error: float64nan1" -- roughly one process start in a thousand
once the guest has more runnable tasks than vCPUs -- and in general as a
conditional branch silently taking the wrong path.

With four tasks each executing 5M bcnez on a 2-vCPU guest, master
mispredicts 89 of 20000000.  With this patch, 0 of 100000000 over five
runs; a Loongson-3C5000 is likewise 0 of 600000000.

CHECK_FPE is defined in trans_farith.c.inc, which translate.c includes
before trans_branch.c.inc, so it is already in scope.

Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4209
Cc: qemu-stable@nongnu.org
Signed-off-by: Jan Mercl <0xjnml@gmail.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260819132422.5164-1-0xjnml@gmail.com>
Signed-off-by: Song Gao <gaosong@loongson.cn>
2026-08-20 07:24:34 -04:00
gaosong
11563efaba
target/loongarch: KVM disable msgint
In KVM mode, msgint is disabled by default; please enable it manually.

e.g
   ... -cpu max,msgint=on ...

Signed-off-by: gaosong <gaosong@loongson.cn>
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
Message-ID: <20260813111000.446232-4-gaosong@loongson.cn>
Signed-off-by: Song Gao <gaosong@loongson.cn>
2026-08-20 07:24:08 -04:00
Song Gao
06e75b3923
Add dintc kvm_irqchip_in_kernel support
Function kvm_dintc_realize() is added if kvm_irqchip_in_kernel is
set. It is to create and initialize DINTC device in kernel mode.
and use kvm_irqchip_send_msi() to send  msi to kernel.

Signed-off-by: Song Gao <gaosong@loongson.cn>
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
Message-ID: <20260813111000.446232-3-gaosong@loongson.cn>
2026-08-20 05:40:19 -04:00
Song Gao
dd45df326e
target/loongarch: Add kvm support dintc
This patch adds Kvm put/get msgint CSRs and check msgint feature.

Signed-off-by: Song Gao <gaosong@loongson.cn>
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
Message-ID: <20260813111000.446232-2-gaosong@loongson.cn>
2026-08-20 05:40:08 -04:00
Paolo Bonzini
3ac34c6d25 rust: remove bilge crate
It has just been replaced with bitfield-struct.

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Paolo Bonzini
64574f1c51 rust: pl011: switch from bilge to bitfield-struct
The bilge crate is heavily reliant on traits and, because trait functions
are never const, bilge and const mix about as well as water and oil.
In addition, it has support for the zerocopy crate that only works for an
older version, and is hard to update because the implementation doesn't
like that zerocopy::FromBits and bilge::FromBits are the same name.
zerocopy is definitely something that QEMU could use in the future.

The bitfield-struct crate, instead, is built from the ground up to
support const.  Its use is pretty much the same (device code does not
change at all, only register declarations do), with some things being
more verbose and others being simpler.  The code for the crate itself
is much smaller, too.

It does have two disadvantages: it does not let you annotate enums
as bitfields, and it does not integrate with arbitrary-int.  Thus, it
requires manual size annotations for anything that is not a bool, iNN
or uNN.  Lack of support for arbitrary-int is a very small deal, while
enums are a bit more annoying because they require some repetition
and an implementation of two functions from_bits() and into_bits().
However, the latter is already provided by the "bits!"  and
"#[derive(common::TryInto)]" utilities, and thus is not manual
in QEMU's case.

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Paolo Bonzini
7d33e694af rust: update Cargo dependencies
Update dependencies that are not used by meson, only by Cargo.
Several packages have now reached v1 and therefore updates may
be less intrusive in the future.

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Paolo Bonzini
0836a79ada scripts: remove now dead parts of rustc_args.py
The logic to parse the [lints] section has been integrated
into Meson and can be removed.

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Paolo Bonzini
aac1b59b85 docs: rust: update for new-style build rules
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Paolo Bonzini
4c5c26548b rust: use meson automatic parsing of Cargo.toml
Finally, automatic parsing of Cargo.toml is also possible for QEMU's own
crates, not just for subprojects.  This removes the need to list the
dependencies and language editions in both Cargo.toml and meson.build
files.

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Paolo Bonzini
aaac1f8229 meson: use compiler_target() to get rustc target
The new method in Meson 1.11.x removes the need to pass the triple
via config-host.mak.

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Paolo Bonzini
530a9eb2c6 rust: switch to autogenerated meson rules
Meson can automatically generate most of the build rules for
subprojects, based on the contents of their Cargo.toml.  Handwritten
snippets can be placed in meson/meson.build to replace build.rs.

Disable Meson's use of the nightly-only option "--env-set".  It is
buggy and anyway it should not be there in future version.

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Paolo Bonzini
6d28fc6089 rust: switch to cargo subprojects
Let Meson parse Cargo.lock and Cargo.toml and figure out the set
of Rust build dependencies.  For now, the only change is that
subprojects are retrieved with "cargo_ws.subproject('NAME')"
instead of "subproject('NAME-API-rs')".  However, just calling
"import('rust').workspace()" enables extra functionality that
operates by parsing Cargo.toml; it will be introduced a step
at a time in subsequent commits.

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Paolo Bonzini
015306dec4 rust: update Cargo.lock
Apply change corresponding to bff6413888 ("rust: fix incorrect dependency
in Cargo.toml", 2026-06-17).

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Nguyen Dinh Phi
e27a401d2e rust/bits: Use checked_ilog2() in Binary::format to avoid panic
ilog2() panics when VALID__ is 0 on empty bits. Switch to checked_ilog2()
to handle zero safely.

Signed-off-by: Nguyen Dinh Phi <phind.uet@gmail.com>
Link: https://lore.kernel.org/r/20260802170346.3493821-3-phind.uet@gmail.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Nguyen Dinh Phi
c5974346d7 rust/bits: Align SubAssign behavior with Sub
Update SubAssign to perform a bit-clear operation instead of arithmetic
subtraction, matching the behavior of Sub.

Signed-off-by: Nguyen Dinh Phi <phind.uet@gmail.com>
Link: https://lore.kernel.org/r/20260802170346.3493821-2-phind.uet@gmail.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:24:57 +02:00
Paolo Bonzini
4c8c132036 python, meson: update meson required for Rust to 1.12.0
Meson 1.11.0 brings support for parsing Cargo.toml inside QEMU's source
tree, and Meson 1.12.0 brings support for cross-compilation of Cargo
subprojects.

Together, these two features allow QEMU to remove hundreds of lines of
manual compilation scripts.

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:43 +02:00
Paolo Bonzini
51ea699eb8 dockerfiles: update CentOS Stream 9 to Python 3.11, Meson to 1.12
Python 3.10, which is a requirement for Meson 1.12.0, was never packaged
for CentOS Stream 9 so update directly to 3.11.

CentOS 9 does not install meson from PyPI because configure will install
it from the bundled wheel; this way CI covers that path as well.  This is
guaranteed because, when using a non-default Python, basically nothing
is installed.

The opensuse-leap-15.yml file was not in use anymore, so delete it
while touching tests/lcitool/targets/.

Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:43 +02:00
Paolo Bonzini
2a428c8541 dockerfiles: remove packages required by Avocado
Make our CI containers smaller, by removing a handful of packages that
were only included as dependencies of Avocado.

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:43 +02:00
Paolo Bonzini
501187d0bc meson: make linker warnings non-fatal on Linux
These cause a werror=true build to fail with Meson 1.12.0, as it now
makes linker warnings fatal as well.

Cc: qemu-stable@nongnu.org
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:43 +02:00
Paolo Bonzini
eb3f7fe382 serial: clear transmit retry callback on unrealize
The GSource is removed when resetting but remains active (and can
cause use-after-free) on hot-unplug.  Remove it before the character
device is disconnected.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4125

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:43 +02:00
Mohamed Mediouni
93f38b6e88 whpx: i386: inject back db
When we get a debug exception other than int1,
inject it back to the guest.

Signed-off-by: Mohamed Mediouni <mohamed@unpredictable.fr>
Link: https://lore.kernel.org/r/20260812082814.27217-7-mohamed@unpredictable.fr
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:42 +02:00
Mohamed Mediouni
37ce6d8da7 whpx: i386: work around Hyper-V FP state oddities
On Hyper-V looks like we need to fetch both the legacy
and new state instead of being able to rely on xsave.

Signed-off-by: Mohamed Mediouni <mohamed@unpredictable.fr>
Link: https://lore.kernel.org/r/20260812082814.27217-6-mohamed@unpredictable.fr
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:42 +02:00
Mohamed Mediouni
7b0516912e whpx: i386: synchronise PAT too
https://github.com/cmspam/winq-emu hints that this might be wanted for
some use-cases and it's a step towards full state sync:

> Linux uses PAT to mark virtio-gpu / Venus shared memory as
> Write-Combining. Previously the partition's PAT was not
> synchronised with the guest, so the guest's MTRR/PAT cache-type
> computation could fall back to UC for memory that should be WC.

Signed-off-by: Mohamed Mediouni <mohamed@unpredictable.fr>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260812082814.27217-5-mohamed@unpredictable.fr
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:42 +02:00
Mohamed Mediouni
3bfcd8ef6b whpx: i386: enable fast hypercall output
Already enabled on Arm so extending it to x86.

Signed-off-by: Mohamed Mediouni <mohamed@unpredictable.fr>
Link: https://lore.kernel.org/r/20260812082814.27217-4-mohamed@unpredictable.fr
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:42 +02:00
Mohamed Mediouni
32452bac6d hw/i386: fw_cfg: do not set VMX feature control on WHPX
Hyper-V doesn't allow setting this bit on build 26100.

Signed-off-by: Mohamed Mediouni <mohamed@unpredictable.fr>
Link: https://lore.kernel.org/r/20260812082814.27217-3-mohamed@unpredictable.fr
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:42 +02:00
Mohamed Mediouni
7c84752396 whpx: i386: fix xsaves enablement in legacy probing path
Without this, Linux will crash in a configuration where
xsaves is expected.

Signed-off-by: Mohamed Mediouni <mohamed@unpredictable.fr>
Link: https://lore.kernel.org/r/20260812082814.27217-2-mohamed@unpredictable.fr
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:42 +02:00
Paolo Bonzini
03ce28d453 target/i386: emulate: stop torturing cc_src into carrying SF/PF
x86_flags.c encodes the flags into cc_dst and cc_src with algorithms
essentially derived from Bochs; the exact details have changed but cc_dst
is Bochs result and cc_src is very close to Bochs auxbits.  However,
using only two words is unnecessarily limiting because it splits SF/PF
between the two words even though *ZF* is the real nuisance (ZF=1 implies
SF=PF=0) and the one that commands usage of PD/SD delta bits.

Within TCG, the CCMP instruction would have a similar need of efficiently
encoding an arithmetic result or an EFLAGS value; it is not implemented,
but there are plans (see commit message for 5dcdbd0712, "target/i386:
tcg: use cout to commonize add/adc/sub/sbb cases", 2025-04-17) to use
an algorithm very similar to target/i386/emulate's, but with *three* words.
Then SF and PF live together in harmony, because SF can be encoded with
either parity and PF does not use the high bit where SF is stored; by
placing them in a third word their computation is isolated from ZF's
and everything becomes simpler.

In fact I'm not even sure why Bochs did it like that, and did not just
give SF/PF their own home in a third word as well; the developers believe
that the extra store is too expensive.  I am not really sure about that,
but as far as QEMU is concerned, emulation proceeds one instruction at a
time so using SRC2 should actually be faster, not just easier.  To convert
from the output of arithmetic operations, PD and SD disappear and DST
simply has to be stored in two places; to convert to RFLAGS, SF/PF are
easily computed from SRC2 as if PD=SD=0; conversion to LFLAGS encodes
parity in bit 0 and mixes in SF as an even-parity value with the right
sign bit.

Unlike TCG, there is a single meaning for all operand lengths, which
corresponds to either CCMPL or CCMPQ depending on sizeof(target_ulong).
So the carry-out value still needs to be split---with AF in bit 3
and CF/PO in the higher bits of the target_ulong-sized env->cc_src.
This is an acceptable tradeoff for the interpreter, in order to optimize
lflags_to_rflags.

Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-20 09:06:42 +02:00
Richard Henderson
ae4f344320 QTest pull request
- Use GLib wrappers during QTEST_LOG parsing
 - Skip tests when 'pc' machine is not built in
 -----BEGIN PGP SIGNATURE-----
 
 iQJEBAABCAAuFiEEqhtIsKIjJqWkw2TPx5jcdBvsMZ0FAmqFvgkQHGZhcm9zYXNA
 c3VzZS5kZQAKCRDHmNx0G+wxnaQuD/9itCBxx1EfDgMoyf2nhcWPIiFUnNFoU2g6
 G+V3GcNXsTe3MbA/IImj01bUjjsvnyuTQqgzg1VQg1U2zCth5uLYwr82GxWkLB2W
 M0l66zfwYdlu8R3q24JLd1vWweWK9GH71Wv7oRx5skR1nTqFQeitotcd7Qb6Ut8m
 BHRYqrjAdaOVlx0jvaV9lksoDJkVmDlK09HoSS4+TUmht0lPZv4u3y+t4bUqi7fa
 5zMjdaxgq4jltA4UkBOMy+EqvYijZbEmLHOgtx21c0obmiVWHf+NrE8jMF4rmNNS
 SOk5JFIq1kyF6kLDn/BzxsFUdsX1W3ZYxjnFOuFf3CNHJB+0v9n4S96DLkHpZ4cM
 +1sV98MmaoAAXN5d3Uc1ZwDAlhunkUmoic0r6q4YmNgQCRqVRjMgE9aSr7JevN2U
 nRYfPuLkKj7aoE7sCK88Ft0X6wH7vFxz+lqCx7Crg1Z0t4kCAo8FemNLO8kSSUZ/
 IgDzBx5eoqyL9IJRsmtwFH2O5XFSKuhs8dTZqNLV4X0saIuXxR2iofuTonxtvvHh
 Q30etPmgqnll/LxhtVNrzXP4+gWXKIgpBhAOPGgIpr0xNeNv9G8qGXorMC7m117T
 8iJjaExJGT1u9hyH3TCzjVapgZFylMMT2dFGLOLrSpqfebtAZDz7KoUJZDO343l/
 v17mT8jcCQ==
 =un2j
 -----END PGP SIGNATURE-----

Merge tag 'qtest-20260819-pull-request' of https://gitlab.com/farosas/qemu into staging

QTest pull request

- Use GLib wrappers during QTEST_LOG parsing
- Skip tests when 'pc' machine is not built in

# -----BEGIN PGP SIGNATURE-----
#
# iQJEBAABCAAuFiEEqhtIsKIjJqWkw2TPx5jcdBvsMZ0FAmqFvgkQHGZhcm9zYXNA
# c3VzZS5kZQAKCRDHmNx0G+wxnaQuD/9itCBxx1EfDgMoyf2nhcWPIiFUnNFoU2g6
# G+V3GcNXsTe3MbA/IImj01bUjjsvnyuTQqgzg1VQg1U2zCth5uLYwr82GxWkLB2W
# M0l66zfwYdlu8R3q24JLd1vWweWK9GH71Wv7oRx5skR1nTqFQeitotcd7Qb6Ut8m
# BHRYqrjAdaOVlx0jvaV9lksoDJkVmDlK09HoSS4+TUmht0lPZv4u3y+t4bUqi7fa
# 5zMjdaxgq4jltA4UkBOMy+EqvYijZbEmLHOgtx21c0obmiVWHf+NrE8jMF4rmNNS
# SOk5JFIq1kyF6kLDn/BzxsFUdsX1W3ZYxjnFOuFf3CNHJB+0v9n4S96DLkHpZ4cM
# +1sV98MmaoAAXN5d3Uc1ZwDAlhunkUmoic0r6q4YmNgQCRqVRjMgE9aSr7JevN2U
# nRYfPuLkKj7aoE7sCK88Ft0X6wH7vFxz+lqCx7Crg1Z0t4kCAo8FemNLO8kSSUZ/
# IgDzBx5eoqyL9IJRsmtwFH2O5XFSKuhs8dTZqNLV4X0saIuXxR2iofuTonxtvvHh
# Q30etPmgqnll/LxhtVNrzXP4+gWXKIgpBhAOPGgIpr0xNeNv9G8qGXorMC7m117T
# 8iJjaExJGT1u9hyH3TCzjVapgZFylMMT2dFGLOLrSpqfebtAZDz7KoUJZDO343l/
# v17mT8jcCQ==
# =un2j
# -----END PGP SIGNATURE-----
# gpg: Signature made Wed 19 Aug 2026 07:30:33 AM PDT
# gpg:                using RSA key AA1B48B0A22326A5A4C364CFC798DC741BEC319D
# gpg:                issuer "farosas@suse.de"
# gpg: Good signature from "Fabiano Rosas <farosas@suse.de>" [unknown]
# gpg:                 aka "Fabiano Almeida Rosas <fabiano.rosas@suse.com>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: AA1B 48B0 A223 26A5 A4C3  64CF C798 DC74 1BEC 319D

* tag 'qtest-20260819-pull-request' of https://gitlab.com/farosas/qemu:
  tests/qtest/pxe-test: skip per-row cases whose machine is unavailable
  tests/qtest/drive_del-test: skip pc tests when 'pc' machine is unavailable
  tests/qtest/device-plug-test: skip pc tests when 'pc' machine is unavailable
  tests/qtest/libqtest: Use GLib functions for proper const correctness

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-19 08:21:57 -07:00
Rohitashv Kumar
bb98963d6d tests/qtest/pxe-test: skip per-row cases whose machine is unavailable
The x86 test table mixes 'pc' and 'q35' rows. When QEMU is built without
the i440fx/pc machine, the 'pc' rows fail with "unsupported machine type".

Add a per-row qtest_has_machine() check in test_batch(), mirroring the
existing per-row qtest_has_device() guard, so rows for an unavailable
machine are skipped while the others (e.g. q35) still run.

Signed-off-by: Rohitashv Kumar <roohiit@amazon.de>
Signed-off-by: Fabiano Rosas <farosas@suse.de>
2026-08-19 11:27:58 -03:00
Rohitashv Kumar
4e37f749dd tests/qtest/drive_del-test: skip pc tests when 'pc' machine is unavailable
test_cli_device_del(), test_device_add_and_del(),
test_drive_add_device_add_and_del() and
test_blockdev_add_device_add_and_del() use "-machine pc" on i386/x86_64.
When QEMU is built without the i440fx/pc machine, these fail with
"unsupported machine type 'pc'".

Skip the x86 case when 'pc' is not available. Non-x86 architectures use
the default machine and are unaffected, and the corresponding _q35
variants already cover x86 under qtest_has_machine("q35").

Signed-off-by: Rohitashv Kumar <roohiit@amazon.de>
Signed-off-by: Fabiano Rosas <farosas@suse.de>
2026-08-19 11:27:53 -03:00
Rohitashv Kumar
6500a6abe6 tests/qtest/device-plug-test: skip pc tests when 'pc' machine is unavailable
test_pci_unplug_request() and test_pci_unplug_json_request() use
"-machine pc" on i386/x86_64. When QEMU is built without the i440fx/pc
machine, these fail with "unsupported machine type 'pc'".

Skip the x86 case when 'pc' is not available. Non-x86 architectures use
the default machine and are unaffected, and x86 unplug coverage is still
provided by the q35 variant (test_q35_pci_unplug_request), which already
guards on qtest_has_machine("q35").

Signed-off-by: Rohitashv Kumar <roohiit@amazon.de>
Signed-off-by: Fabiano Rosas <farosas@suse.de>
2026-08-19 11:27:47 -03:00
Amit Machhiwal
c54c041ae0 tests/qtest/libqtest: Use GLib functions for proper const correctness
While commit e68da5b7a2 ("tests/qtest: fix discarded const qualifier
warning") addressed the immediate strstr() warning by making 'found'
const, there's still a room for improvement: getenv() returns char *, but
environment strings are semantically read-only and should be treated as const
throughout their lifetime.

Replace getenv() with g_getenv() and strstr() with g_strstr_len() to
maintain const correctness from source to use. This approach:

- Uses g_getenv() which returns const gchar *, matching the read-only
  semantics of environment variables
- Employs g_strstr_len() for consistent use of GLib string functions,
  aligning with QEMU conventions
- Eliminates all const-correctness warnings with strict compilers

Tested-by: Anushree Mathur <anushree.mathur@linux.ibm.com>
Reviewed-by: Aditya Gupta <adityag@linux.ibm.com>
Signed-off-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Signed-off-by: Fabiano Rosas <farosas@suse.de>
2026-08-19 11:27:41 -03:00
Richard Henderson
dfc917a1d7 accel/tcg: Allow overlapping reads in record_save
tcg/optimize: INDEX_op_mul is commutative
 tcg/optimize: Fix s_mask computation for shifts
 tcg: Defer tb_flush when initial thread region alloc fails
 tcg: Add revbit{8,32,64} opcodes
 tcg: Add integer min/max opcodes
 disas: Updates for capstone v6
 -----BEGIN PGP SIGNATURE-----
 
 iQFRBAABCgA7FiEEekgeeIaLTbaoWgXAZN846K9+IV8FAmqE+7kdHHJpY2hhcmQu
 aGVuZGVyc29uQGxpbmFyby5vcmcACgkQZN846K9+IV+TOAgAj8fl2tgEOHau61Zf
 yM7AS6DatmoJNQeqXa2HTXisA8MLM9319D2MBj5BqzADC+nmlaeMrII4YsJTifWr
 3e3E4Lw/w4MQZrxDciFUAJmkApecImnVSdEdxD6eR9nRo99NpNbUXTjV5Tj0ikEA
 +Ku53VPVKL+f4eD734IyXveBBRwj2hRUHnwTN+SiJywtw5bzu4/dDmhL7RNoWuAw
 eV5qxNmD3h/2gqMcoWMLcSasLBkkFVfSuV0nUUp0hwcrntLSez2yXCb5AY2vSawj
 0nGoQimV0jUhhy4Xq/GuZJR7GrFBcY21h/WYoY8yA5UKvl0NcV4tLrCSGBuQsPS3
 FP9kow==
 =K1aR
 -----END PGP SIGNATURE-----

Merge tag 'pull-tcg-20260818-3' of https://gitlab.com/rth7680/qemu into staging

accel/tcg: Allow overlapping reads in record_save
tcg/optimize: INDEX_op_mul is commutative
tcg/optimize: Fix s_mask computation for shifts
tcg: Defer tb_flush when initial thread region alloc fails
tcg: Add revbit{8,32,64} opcodes
tcg: Add integer min/max opcodes
disas: Updates for capstone v6

# -----BEGIN PGP SIGNATURE-----
#
# iQFRBAABCgA7FiEEekgeeIaLTbaoWgXAZN846K9+IV8FAmqE+7kdHHJpY2hhcmQu
# aGVuZGVyc29uQGxpbmFyby5vcmcACgkQZN846K9+IV+TOAgAj8fl2tgEOHau61Zf
# yM7AS6DatmoJNQeqXa2HTXisA8MLM9319D2MBj5BqzADC+nmlaeMrII4YsJTifWr
# 3e3E4Lw/w4MQZrxDciFUAJmkApecImnVSdEdxD6eR9nRo99NpNbUXTjV5Tj0ikEA
# +Ku53VPVKL+f4eD734IyXveBBRwj2hRUHnwTN+SiJywtw5bzu4/dDmhL7RNoWuAw
# eV5qxNmD3h/2gqMcoWMLcSasLBkkFVfSuV0nUUp0hwcrntLSez2yXCb5AY2vSawj
# 0nGoQimV0jUhhy4Xq/GuZJR7GrFBcY21h/WYoY8yA5UKvl0NcV4tLrCSGBuQsPS3
# FP9kow==
# =K1aR
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 18 Aug 2026 05:41:29 PM PDT
# gpg:                using RSA key 7A481E78868B4DB6A85A05C064DF38E8AF7E215F
# gpg:                issuer "richard.henderson@linaro.org"
# gpg: Good signature from "Richard Henderson <richard.henderson@linaro.org>" [ultimate]

* tag 'pull-tcg-20260818-3' of https://gitlab.com/rth7680/qemu: (38 commits)
  target/mips: Enable disassembly via capstone
  target/m68k: Enable disassembly via capstone
  target/s390x: Update capstone disassembly to v6
  target/loongarch: Enable disassembly via capstone
  target/tricore: Enable disassembly via capstone
  target/sh4: Enable disassembly via capstone
  target/riscv: Enable disassembly via capstone
  disas/capstone: Allow for cap_insn_unit > length
  target/riscv: Improve riscv_has_ext
  tcg/aarch64: Use CTZ from FEAT_CSSC
  tcg/aarch64: Implement ctpop with FEAT_CSSC
  target/riscv64: Implement min/max with Zbb
  tcg/aarch64: Implement min/max with FEAT_CSSC
  util/cpuinfo-aarch64: Detect FEAT_CSSC
  tcg/optimize: Handle min/max opcodes
  tcg: Add integer min/max opcodes
  tests/tcg/loongarch64: Add bitrev smoke tests
  tests/tcg/loongarch64: Tidy test_bit.c
  tcg/riscv64: Implement revbit8
  util/cpuinfo-riscv: Detect Zbkb
  ...

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:41:54 -07:00
Richard Henderson
84dd090703 target/mips: Enable disassembly via capstone
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:35:33 -07:00
Richard Henderson
89faaa5181 target/m68k: Enable disassembly via capstone
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:35:33 -07:00
Richard Henderson
c8220a096f target/s390x: Update capstone disassembly to v6
In particular, this enables many more vector insns.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:35:33 -07:00
Richard Henderson
724452279f target/loongarch: Enable disassembly via capstone
Reviewed-by: Song Gao <17746591750@163.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:35:33 -07:00
Richard Henderson
3a002bbcdd target/tricore: Enable disassembly via capstone
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:35:33 -07:00
Richard Henderson
2b38607286 target/sh4: Enable disassembly via capstone
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:35:33 -07:00
Richard Henderson
09d7b5d49a target/riscv: Enable disassembly via capstone
In capstone v5, riscv support is spare, but v6 is pretty good.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:35:33 -07:00
Richard Henderson
a854350af1 disas/capstone: Allow for cap_insn_unit > length
cap_insn_unit is designed for targets like arm thumb2
and s390x where 4 and 6-byte insns are displayed in
2-byte chunks.

For riscv, we prefer 4-byte insns to display as one
4-byte unit, rather than 2x 2-byte units.  So we will
want to set cap_insn_unit to 4, but allow for insns
that are smaller than 4.  Emit padding to match.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:35:32 -07:00
Richard Henderson
a5572e5214 target/riscv: Improve riscv_has_ext
Constify the env pointer and return bool.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:35:32 -07:00
Richard Henderson
8ad4e32be0 tcg/aarch64: Use CTZ from FEAT_CSSC
We already have an expansion of CTZ using RBIT+CLZ,
but use the new insn with FEAT_CSSC is present.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:35:28 -07:00
Richard Henderson
1643cf8962 tcg/aarch64: Implement ctpop with FEAT_CSSC
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
20eaf9a54a target/riscv64: Implement min/max with Zbb
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
100ec60528 tcg/aarch64: Implement min/max with FEAT_CSSC
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
761bfe07b2 util/cpuinfo-aarch64: Detect FEAT_CSSC
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
db9be9b136 tcg/optimize: Handle min/max opcodes
Reviewed-by: Alex Bennée <alex.bennee@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
90aa356edc tcg: Add integer min/max opcodes
We already have these for vectors; replicate for integers.

Reviewed-by: Alex Bennée <alex.bennee@linaro.org>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
ffc27ce9be tests/tcg/loongarch64: Add bitrev smoke tests
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
2458f0cab5 tests/tcg/loongarch64: Tidy test_bit.c
Use one macro for all test templates.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
9d2e171fd6 tcg/riscv64: Implement revbit8
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
48c18cdc9c util/cpuinfo-riscv: Detect Zbkb
RISCV_HWPROBE_EXT_ZBKB was introduced in linux 6.10
with the rest of the hwprobe api.

Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
fa70120a71 tcg/loongarch64: Implement revbit{8,32,64}
Reviewed-by: Anton Johansson <anjo@rev.ng>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
3e73eda078 tcg/loongarch64: Import REVBIT insns
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:49 -07:00
Richard Henderson
a8687b8632 tcg/aarch64: Implement revbit{32,64}
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:48 -07:00
Richard Henderson
d53c3e911c tcg/optimize: Handle revbit{8,32,64}
These are nearly identical to bswap, so reuse fold_bswap.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:48 -07:00
Richard Henderson
db1c58d777 tcg: Add revbit{8,32,64} opcodes
Add the plumbing, but not yet implemented for any host.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:48 -07:00
Richard Henderson
0a897b9c0c target/riscv: Use generic tcg_gen_revbit8
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:48 -07:00
Richard Henderson
8b416699c8 target/mips: Expand octeon reflections inline
Use tcg_gen_revbit64_i64 instead of out-of-line helpers.

Reviewed-by: Anton Johansson <anjo@rev.ng>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:48 -07:00
Richard Henderson
8c7ba1cedf target/loongarch: Use generic tcg_gen_revbit*
Reviewed-by: Song Gao <17746591750@163.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:48 -07:00
Richard Henderson
ab86f82ba9 target/arm: Use generic tcg_gen_revbit*
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:48 -07:00
Richard Henderson
288d39e26d tcg: Simplify bswap/hswap expansion using bitswap
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:48 -07:00
Richard Henderson
c2ca373740 tcg: Add tcg_gen_revbit{8,32,64}
Add generic expanders for reversing bits within a word.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:48 -07:00
Richard Henderson
3f3a1ea472 tcg: Fix opcode dump for bswap
We use an array of char for bswap_flag_name, so some
entries in the array are non-null but empty.  Check that.

Fixes: 587195bd59 ("tcg: Add flags argument to bswap opcodes")
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:48 -07:00
Richard Henderson
f5d2d8532f tcg: Defer tb_flush when initial thread region alloc fails
A vCPU hotplug may happen at any time.  When the new thread is
started, the region pool may be exhausted.  Do not abort.

Rename tcg_region_thread_initial_alloc to differentiate it
from tcg_region_initial_alloc__locked.  The renamed function
now uses tcg_region_alloc__locked and is prepared for failure.

In tcg_tb_alloc, allow code_gen_ptr to be NULL.  Treat that as
any other region exhaustion.  Reorg with while instead of goto.

Tested-by: Yogesh Vyas <yvyas1991@gmail.com>
Reviewed-by: Yogesh Vyas <yvyas1991@gmail.com>
Reported-by: Anushree Mathur <anushree.mathur@linux.ibm.com>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/2984
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:41 -07:00
Richard Henderson
fcdbc78ad4 tcg: Return success from tcg_region_alloc
Invert the sense of the boolean result from 'error' to 'success'.

Tested-by: Yogesh Vyas <yvyas1991@gmail.com>
Reviewed-by: Yogesh Vyas <yvyas1991@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:31:31 -07:00
Richard Henderson
e131c28b6e tcg: Return success from tcg_region_alloc__locked
Invert the sense of the boolean result from 'error' to 'success'.

Tested-by: Yogesh Vyas <yvyas1991@gmail.com>
Reviewed-by: Yogesh Vyas <yvyas1991@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 17:30:48 -07:00
Ilya Chichkov
784b7f28e2 accel/tcg: Allow overlapping reads in record_save
record_save() assumed that a target reads the bytes of an insn as a
strictly ascending sequence of adjacent chunks, and asserted that each
read begins exactly where the previous one ended.

That assumption no longer holds for riscv.  Since f9eaa1542b
("target/riscv: support atomic instruction fetch (Ziccif)"),
decode_opc() loads a full aligned word whenever pc is 4-byte aligned,
even when the insn turns out to be a 2-byte compressed one, so the
record may already hold bytes past the end of the insn being
translated.  When such a compressed insn sits at page offset 0xffc,
pc_next becomes 0xffe, which is within MAX_INSN_LEN of the end of the
page, and riscv_tr_translate_insn() probes the next insn to decide
whether it would cross the page boundary.  That probe reads at offset
2 while the record already covers [0,4), and the assert fires:

  qemu-system-riscv32: accel/tcg/translator.c:395: record_save:
  Assertion `offset == db->record_start + db->record_len' failed.

record_save() is only reached when the insn is fetched from MMIO, so
this is visible on boards that execute code from a region created with
memory_region_init_io(), such as an XIP flash window mapped over a
serial flash controller.

Both sides of the collision are correct: the wide fetch is required for
Ziccif atomicity, and the probe is required for correct fault reporting
at a page boundary, per 00c07344fa ("target/riscv: Make translator stop
before the end of a page").  Unlike a86d3352ab ("target/riscv: do not
use translator_ldl in opcode_at"), where a non-translation caller had
no business using translator_ld*, the probe here is a genuine
translation read whose bytes must be recorded.

Relax the invariant instead.  Keep requiring that a read neither moves
backwards nor leaves a gap, but let a read overlapping the recorded
range extend it only by the bytes past its end.

Cc: qemu-stable@nongnu.org
Fixes: f9eaa1542b ("target/riscv: support atomic instruction fetch (Ziccif)")
Signed-off-by: Ilya Chichkov <ilya.chichkov.dev@gmail.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260814142159.3800744-1-ilya.chichkov.dev@gmail.com>
2026-08-18 09:05:23 -07:00
Richard Henderson
5fe5160614 tcg/optimize: Fix s_mask computation for shifts
Skip s_mask computation for logical right shift.

Cc: qemu-stable@nongnu.org
Fixes: 93a967fbb5 ("tcg/optimize: Propagate sign info for shifting")
Reported-by: Jacob Young <jacobly@ziglang.org>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 09:03:19 -07:00
Richard Henderson
3181e53c13 tcg/optimize: INDEX_op_mul is commutative
Cc: qemu-stable@nongnu.org
Fixes: 7a2f708452 ("tcg/optimize: Sink commutative operand swapping into fold functions")
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-18 07:18:42 -07:00
Richard Henderson
fa19879df1 block-jobs and dirty-bitmaps patches
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEi5wmzbL9FHyIDoahVh8kwfGfefsFAmqDKl4ACgkQVh8kwfGf
 efsQ6A//SbHOBtTGr5h541r/ag55slCpSSbIZ92HxNkXAtFOiiPwMj2p+gkKH96m
 9AMZslC8WFlrY4oAE9jWe3gnfrV43b+DlpvgeTocJjPMscLvt0BeHWgWrFlu6HkR
 RrXpHM7h75zHD16qON0ZxLWMR/VtN4JJNo0Q8VkVt7GvxrW0QNMfH9LlGHsGwnOS
 3o5BW0BhtIFb4o+rMa5RY43FdghumXVjHZR84iJUvyhSrGiGjq+lZn5a+PhggO1b
 G3IR+/ZcpZv+FKNN0vRbmmgSOFmz0QR5LxQxERyyFajpfhNbUzXae2IbjM+VThSU
 G8JRGC8iL3js3qQdw8JsDEbegsfJniNoKoxolmQx8wAfmfEcHhAnSWwLsKjJttj4
 FVwrF7Sa33xdkztlDdAjAfUANm4u6q3zhy4Ap3mm4t45c9u0tNYtKz/jySgmgoW+
 YGSSWrP0eyXahe7J+BP+TkKooG2sb3mxczOUDhpQoySwgOw/jR4s4CvIn7Cs10WI
 hqHbzZJ5wCfIQK/7E+MfBi0W47amlMdwZ5B42pvAoiBnWsXA2vjl8JTtmI2H25Ax
 bPM0iNOkx1aJK+RMhWW++M1z+jXR246iQHipbpcQsyfFgB8mqKAytbvZ+uXp55jQ
 e8/D8FLVx8zwAVMl7rLFYxo4ntNyTeAfq2akJM5DZd0g7BWvfIM=
 =iQVf
 -----END PGP SIGNATURE-----

Merge tag 'pull-block-jobs-2026-08-17' of https://gitlab.com/vsementsov/qemu into staging

block-jobs and dirty-bitmaps patches

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEi5wmzbL9FHyIDoahVh8kwfGfefsFAmqDKl4ACgkQVh8kwfGf
# efsQ6A//SbHOBtTGr5h541r/ag55slCpSSbIZ92HxNkXAtFOiiPwMj2p+gkKH96m
# 9AMZslC8WFlrY4oAE9jWe3gnfrV43b+DlpvgeTocJjPMscLvt0BeHWgWrFlu6HkR
# RrXpHM7h75zHD16qON0ZxLWMR/VtN4JJNo0Q8VkVt7GvxrW0QNMfH9LlGHsGwnOS
# 3o5BW0BhtIFb4o+rMa5RY43FdghumXVjHZR84iJUvyhSrGiGjq+lZn5a+PhggO1b
# G3IR+/ZcpZv+FKNN0vRbmmgSOFmz0QR5LxQxERyyFajpfhNbUzXae2IbjM+VThSU
# G8JRGC8iL3js3qQdw8JsDEbegsfJniNoKoxolmQx8wAfmfEcHhAnSWwLsKjJttj4
# FVwrF7Sa33xdkztlDdAjAfUANm4u6q3zhy4Ap3mm4t45c9u0tNYtKz/jySgmgoW+
# YGSSWrP0eyXahe7J+BP+TkKooG2sb3mxczOUDhpQoySwgOw/jR4s4CvIn7Cs10WI
# hqHbzZJ5wCfIQK/7E+MfBi0W47amlMdwZ5B42pvAoiBnWsXA2vjl8JTtmI2H25Ax
# bPM0iNOkx1aJK+RMhWW++M1z+jXR246iQHipbpcQsyfFgB8mqKAytbvZ+uXp55jQ
# e8/D8FLVx8zwAVMl7rLFYxo4ntNyTeAfq2akJM5DZd0g7BWvfIM=
# =iQVf
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 17 Aug 2026 08:35:58 AM PDT
# gpg:                using RSA key 8B9C26CDB2FD147C880E86A1561F24C1F19F79FB
# gpg: Good signature from "Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>" [unknown]
# gpg:                 aka "Vladimir Sementsov-Ogievskiy <vsementsov@virtuozzo.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 8B9C 26CD B2FD 147C 880E  86A1 561F 24C1 F19F 79FB

* tag 'pull-block-jobs-2026-08-17' of https://gitlab.com/vsementsov/qemu:
  dirty-bitmap: fix integer overflow in serialization coverage
  block/monitor: allow dropping a bitmap never stored on disk
  migration/block-dirty-bitmap: reject bitmap load onto ro node
  block/monitor: reject persistent bitmap add on a read-only node
  tests/unit/test-blockjob: cover keeping a job paused while a pause is pending
  job: keep job paused across overlapping pause requests

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-17 15:37:53 -07:00
Denis V. Lunev
dc04053687 dirty-bitmap: fix integer overflow in serialization coverage
The chunk size is an int and is shifted left by 3 before the result is
widened, so a chunk size of 1 << 28 or above overflows.

parallels passes s->cluster_size, which parallels_open() lets reach
2 GiB. With a bitmap needing two L1 entries the bogus limit makes the
"bm_size - offset" in parallels_load_bitmap_data() underflow; both
wrong values slip past the assertions in serialization_chunk() and the
resulting index lands outside the hbitmap, so a 128 KiB image memsets
unrelated memory through hbitmap_deserialize_ones().

Widen the shift. qcow2, the only other caller, never exceeds a 2 MiB
cluster.

Fixes: 35f428ba39 ("qcow2-bitmap: make bytes_covered_by_bitmap_cluster() public")
Cc: Eric Blake <eblake@redhat.com>
Cc: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Cc: Stefan Hajnoczi <stefanha@redhat.com>
Cc: Thomas Huth <thuth@redhat.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
Message-ID: <20260811173857.396571-4-den@openvz.org>
Reviewed-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
2026-08-17 18:32:44 +03:00
Denis V. Lunev
9a77ef813f block/monitor: allow dropping a bitmap never stored on disk
block-dirty-bitmap-remove refuses any readonly bitmap outright, via
the generic BDRV_BITMAP_RO check in bdrv_dirty_bitmap_check(). That
check cannot tell whether the bitmap is actually on disk, so it also
blocks dropping one that only ever existed in memory, which needs no
write at all.

Drop the blanket check and let qcow2 decide: bdrv_remove_persistent_
dirty_bitmap() already treats an absent on-disk entry as a no-op, so
such a bitmap is now released with no write attempted. For one that
is genuinely stored, qcow2_co_remove_persistent_dirty_bitmap_locked()
now checks can_write() before it would update the on-disk directory,
so removal still fails there, with a message naming the actual
reason instead of just the bitmap's readonly flag.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Eric Blake <eblake@redhat.com>
CC: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
CC: John Snow <jsnow@redhat.com>
CC: Andrey Drobyshev <andrey.drobyshev@virtuozzo.com>
Message-ID: <20260716112242.3000035-4-den@openvz.org>
Reviewed-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
2026-08-17 18:32:44 +03:00
Denis V. Lunev
3f3f5cdb92 migration/block-dirty-bitmap: reject bitmap load onto ro node
dirty_bitmap_load_start() creates an incoming migrated bitmap with
bdrv_create_dirty_bitmap() and, if the source marked it persistent,
calls bdrv_dirty_bitmap_set_persistence() without checking whether
the destination node can be written to. Same gap as
qmp_block_dirty_bitmap_add(), reached via incoming migration: a
persistent bitmap for a read-only destination (e.g. a migrated
CD-ROM-class attachment with dirty-bitmaps migration enabled) ends
up writable in memory on a node that can never store it.

Reject it the same way, with one difference from the QMP path:
every destination node is BDRV_O_INACTIVE until migration completes,
so bdrv_is_writable() would reject every incoming persistent
bitmap, not just read-only ones. Check bdrv_is_read_only() alone.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Eric Blake <eblake@redhat.com>
CC: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
CC: John Snow <jsnow@redhat.com>
CC: Andrey Drobyshev <andrey.drobyshev@virtuozzo.com>
Message-ID: <20260716112242.3000035-3-den@openvz.org>
Reviewed-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
2026-08-17 18:32:44 +03:00
Denis V. Lunev
59ecd8a1ac block/monitor: reject persistent bitmap add on a read-only node
qmp_block_dirty_bitmap_add() marks a new bitmap persistent without
checking write access to its node. bdrv_create_dirty_bitmap() always
creates bitmaps writable, so a persistent bitmap added to an
already read-only node stays writable in memory on a node that can
never store it, and the next global inactivation fails:

  Lost persistent bitmaps during inactivation of node '<node>': No write access
  migration_block_inactivate: bdrv_inactivate_all() failed: -22

Forcing it read-only instead does not help: it was never stored,
so it stays unpromotable on the next reopen to read-write and can
trip bdrv_set_dirty()'s readonly assert on the first write. Reject
the add instead, for both read-only and inactive nodes -- an
already-inactive node skips qcow2_inactivate() on close, so a
bitmap added during that window would never get stored either.
Wrapped in a transaction, this denies the whole transaction, since
qmp_transaction() is already all-or-none.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Eric Blake <eblake@redhat.com>
CC: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
CC: John Snow <jsnow@redhat.com>
CC: Andrey Drobyshev <andrey.drobyshev@virtuozzo.com>
Message-ID: <20260716112242.3000035-2-den@openvz.org>
Reviewed-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
2026-08-17 18:32:44 +03:00
Denis V. Lunev
438ee08bc9 tests/unit/test-blockjob: cover keeping a job paused while a pause is pending
Add a regression test for the previous commit. A job that has reached
its pause point is spuriously re-entered (job_enter()) while a pause is
still pending (pause_count > 0), reproducing what an overlapping drain
does: one drain's job_resume() wakes the job while the next drain's
job_pause() is already counted. The job must stay parked - it must not
run job code or clear job->paused, or job_set_aio_context() could
observe paused == false and abort.

The test counts the job's run-loop iterations: without the fix the
re-entered job clears job->paused, runs one iteration and re-pauses, so
the counter advances; with the fix it stays parked and the counter is
unchanged. It runs in the main AioContext, so job_enter() is synchronous
and the check is deterministic.

Signed-off-by: Denis V. Lunev <den@openvz.org>
Message-ID: <20260623152406.1180235-3-den@openvz.org>
Reviewed-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Tested-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
2026-08-17 18:32:44 +03:00
Denis V. Lunev
2667133c27 job: keep job paused across overlapping pause requests
job_pause_point_locked() sets job->paused before yielding and clears it
unconditionally on wake, before re-checking whether a pause is still
pending. job_pause() re-enters a parked job only while it is not yet
paused, so the wake that resumes one comes from a drain *ending*
(job_resume() -> job_enter_cond()). If the next drain begins before that
wake runs, the woken coroutine clears job->paused while pause_count is
already > 0 again:

  AioContext change (BQL thread)     job coroutine (iothread)
  -----------------------------      ------------------------
                                     parked in job_pause_point():
                                       paused=1, pause_count=1, yielded
  drain ends -> job_resume():
    pause_count = 0
    job_enter_cond(): queue wake ..>   (wake pending)
  bdrv_try_change_aio_context():
    bdrv_drain_all_begin():
      job_pause() per node
      pause_count = N (> 0)
                                     wake runs, leaves job_do_yield():
                                       paused = 0  (pause_count == N)
    tran_commit -> job_set_aio_context():
      assert(paused || completed) --> abort: paused == 0

bdrv_try_change_aio_context() drains precisely to quiesce the job before
changing its AioContext, but that brief paused==0 window trips the
assertion. It is guest-triggerable: a virtio-blk reset
(virtio_blk_stop_ioeventfd() -> blk_set_aio_context()) racing a running
mirror/blockCopy job hits it, as do x-blockdev-set-iothread, blockdev
hot-plug/unplug and job completion.

Keep job->paused set while a pause is still pending: loop the yield
until job_should_pause_locked() is false (or the job is cancelled), and
only then clear job->paused. Drained-state consumers then never observe
a pending-pause job as unpaused.

Signed-off-by: Denis V. Lunev <den@openvz.org>
Message-ID: <20260623152406.1180235-2-den@openvz.org>
Reviewed-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
2026-08-17 18:32:44 +03:00
Naveen N Rao (AMD)
5be66f90bd target/i386: SEV: Remove use of __func__
Remove all usages of __func__ in target/i386/sev.c to align with the
general QEMU preference, and replace those with "SEV:" prefix.

Suggested-by: Daniel P. Berrangé <berrange@redhat.com>
Signed-off-by: Naveen N Rao (AMD) <naveen@kernel.org>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Link: https://lore.kernel.org/r/20260626070010.1955433-1-naveen@kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:54 +02:00
Naveen N Rao (AMD)
feed8bdfdc target/i386: SEV: Refactor check_sev_features()
Refactor check_sev_features() to consolidate SEV-SNP checks to a single
if block. This is also helpful when adding checks for future SEV
features.  While at it, move the comment about the checks being done
outside of the function body and expand it to describe what this
function does. Update error_setg() invocations to use a consistent
format.

No functional change intended.

Suggested-by: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Naveen N Rao (AMD) <naveen@kernel.org>
Link: https://lore.kernel.org/r/cae04d88adfbcdc2997e518475f3b89091adf8a9.1779281646.git.naveen@kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:54 +02:00
Naveen N Rao (AMD)
f79c89c296 target/i386: SEV: Add support for setting TSC frequency for Secure TSC
Add support for configuring the TSC frequency when Secure TSC is enabled
in SEV-SNP guests through a new "tsc-frequency" property on SEV-SNP
guest objects, similar to the vCPU-specific property used by regular
guests and TDX. A new property is needed since SEV-SNP guests require
the TSC frequency to be specified during early SNP_LAUNCH_START command
before any vCPUs are created.

The user-provided TSC frequency is set through KVM_SET_TSC_KHZ before
issuing KVM_SEV_SNP_LAUNCH_START.

Attempts to set TSC frequency on both the SEV_SNP object and the cpu
object result in an error from KVM (on the vCPU ioctl), so do not add
separate checks for the same.

Sample command-line:
  -machine q35,confidential-guest-support=sev0 \
  -object sev-snp-guest,id=sev0,cbitpos=51,reduced-phys-bits=1,secure-tsc=on,tsc-frequency=2500000000

Co-developed-by: Ketan Chaturvedi <Ketan.Chaturvedi@amd.com>
Signed-off-by: Ketan Chaturvedi <Ketan.Chaturvedi@amd.com>
Co-developed-by: Nikunj A Dadhania <nikunj@amd.com>
Signed-off-by: Nikunj A Dadhania <nikunj@amd.com>
Signed-off-by: Naveen N Rao (AMD) <naveen@kernel.org>
Link: https://lore.kernel.org/r/af688610978f213a456a7753e1d9fe7d3a51e80a.1779281646.git.naveen@kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:54 +02:00
Naveen N Rao (AMD)
a26f9b975d target/i386: SEV: Add support for enabling Secure TSC SEV feature
Add support for enabling Secure TSC VMSA SEV feature in SEV-SNP guests
through a new "secure-tsc" boolean property on SEV-SNP guest objects. By
default, KVM uses the host TSC frequency for Secure TSC.

Sample command-line:
  -machine q35,confidential-guest-support=sev0 \
  -object sev-snp-guest,id=sev0,cbitpos=51,reduced-phys-bits=1,secure-tsc=on

Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
Co-developed-by: Ketan Chaturvedi <Ketan.Chaturvedi@amd.com>
Signed-off-by: Ketan Chaturvedi <Ketan.Chaturvedi@amd.com>
Co-developed-by: Nikunj A Dadhania <nikunj@amd.com>
Signed-off-by: Nikunj A Dadhania <nikunj@amd.com>
Signed-off-by: Naveen N Rao (AMD) <naveen@kernel.org>
Link: https://lore.kernel.org/r/9f58b92a173f319b3ef725f5ed8a2a173eed55b1.1779281646.git.naveen@kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:54 +02:00
Naveen N Rao (AMD)
51ac358fde target/i386: SEV: Add support for enabling debug-swap SEV feature
Add support for enabling debug-swap VMSA SEV feature in SEV-ES and
SEV-SNP guests through a new "debug-swap" boolean property on SEV guest
objects. Though the boolean property is available for plain SEV guests,
check_sev_features() has a check that rejects attempts to enable any SEV
feature for a plain SEV guest.

Though this SEV feature is called "Debug virtualization" in the APM, KVM
calls this "debug swap" so use the same name for consistency.

Sample command-line:
  -machine q35,confidential-guest-support=sev0 \
  -object sev-snp-guest,id=sev0,cbitpos=51,reduced-phys-bits=1,debug-swap=on

Restrict debug-swap to SEV-SNP guests at this time due to a
compatibility issue with SEV-ES pflash devices.

Signed-off-by: Naveen N Rao (AMD) <naveen@kernel.org>
Link: https://lore.kernel.org/r/416e7b156e49f95958f8c5c8549b48a88c1995fc.1779281646.git.naveen@kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:54 +02:00
Naveen N Rao (AMD)
891d419f97 target/i386: SEV: Enable use of KVM_SEV_INIT2 for SEV-ES guests
In preparation for allowing SEV-ES guests to enable VMSA SEV features,
update sev_init2_required() to return true if any SEV features are
requested. This enables qemu to use KVM_SEV_INIT2 for SEV-ES guests when
necessary.

Reviewed-by: Nikunj A Dadhania <nikunj@amd.com>
Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Naveen N Rao (AMD) <naveen@kernel.org>
Link: https://lore.kernel.org/r/f2a7778ab26b11a8de90e170ff984ccd29dc05a0.1779281646.git.naveen@kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Naveen N Rao (AMD)
c93800f544 target/i386: SEV: Validate that SEV-ES is enabled when VMSA features are used
SEV features in the VMSA are only meaningful for SEV-ES and SEV-SNP
guests, as they control aspects of the encrypted guest state that are
not relevant for basic SEV guests.

Add a check in check_sev_features() to ensure that SEV-ES or SEV-SNP is
enabled when any SEV features are specified.

Reviewed-by: Nikunj A Dadhania <nikunj@amd.com>
Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Naveen N Rao (AMD) <naveen@kernel.org>
Link: https://lore.kernel.org/r/11e34ae3db91643e45e097404d1aa949a820aa0d.1779281646.git.naveen@kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Naveen N Rao (AMD)
9743cd30f3 target/i386: SEV: Consolidate SEV feature validation to common init path
Currently, check_sev_features() is called in multiple places when
processing IGVM files: both when processing the initial VMSA SEV
features from IGVM, as well as when validating the full contents of the
VMSA. Move this to a single point in sev_common_kvm_init() to simplify
the flow, as well as to re-use this function when VMSA SEV features are
being set without using IGVM files.

Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Naveen N Rao (AMD) <naveen@kernel.org>
Link: https://lore.kernel.org/r/35449df94eb20c29923a7cd0e2742ddba605928c.1779281646.git.naveen@kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Naveen N Rao (AMD)
a593e468da target/i386: SEV: Ensure SEV features are only set through qemu cli or IGVM
In preparation for qemu being able to set SEV features through the cli,
add a check to ensure that SEV features are not also set if using IGVM
files.

Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Naveen N Rao (AMD) <naveen@kernel.org>
Link: https://lore.kernel.org/r/6939de99f13d7170af68b74e711eb9f03f32f682.1779281646.git.naveen@kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Naveen N Rao (AMD)
4196b5f0a0 target/i386: SEV: Generalize handling of SVM_SEV_FEAT_SNP_ACTIVE
Align with IGVM files providing SEV features with
SVM_SEV_FEAT_SNP_ACTIVE set by setting the same when creating a
sev-snp-guest object.

Since KVM sets this feature itself, SVM_SEV_FEAT_SNP_ACTIVE is unset
before KVM_SEV_INIT2 ioctl is invoked. Move that out of IGVM-specific
section to common code.

While at it, convert the existing SVM_SEV_FEAT_SNP_ACTIVE definition to
use the BIT() macro for consistency with upcoming feature flags.

Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Naveen N Rao (AMD) <naveen@kernel.org>
Link: https://lore.kernel.org/r/031de849edf2ae4eaa6e00df83b053605a3ecfea.1779281646.git.naveen@kernel.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
24bf07b6e2 hw/i386/mshv: drop initial msi vector 0
This has been a warning before that was always raised if the machine has
a hpet. hpet_reset() will eventually result in mshv_send_msi called w/
vector 0, which we can safely drop.

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-13-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
ec38b3d54c target/i386/mshv: migrate MP_STATE
MSHV's "internal activity state" roughly maps to QEMU's env->mp_state
and cpu->halted states that describe state of APs in a guest.

We don't invoke set_mp_state as part of store_vcpu_state() b/c we would
put all BSP + APs in a RUNNABLE (0) state immediately, breaking SMP boot

Instead we store the mp state as part of the load_cleanup() routine
after a migration.

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-11-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
49cd174b56 accel/mshv: write synthetic MSRs after migration
Write partition-wide synthetic MSRs. This ensures the hypercall page and
SynIC facilities are set up before vCPUs attempt to use it.

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-10-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
f2c8f7bcd4 target/i386/mshv: migrate STIMER state
This part of Synic state is retrieved via a mem-aligned page. We declare
the required space (size reference: rust-vmm/mshv) as a buffer on the VM
state struct for inclusion in a migration.

Other than other SynIC features, STIMER doesn't depend on SCONTROL being
set.

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-9-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
e514ff235b target/i386/mshv: migrate SIMP and SIEFP state
This part SynIC state is retrieved from the hypervisor via aligned state
pages:

- Add new synic source file
- Centralize the synic_enabled() check
- r/w pages from the hyper via aligned pages
- only handle pages when synic is enabled
- add buffers for migration to VM state

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Reviewed-by: Doru Blânzeanu <dblanzeanu@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-8-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
65867d2ede target/i386/mshv: migrate Synic SINT MSRs
Migrate HyperV SynIC SINT MSRs. We can only read/write those if SCONTROL
is enabled in the guest, hence we have to split the SINT MSR out and
make reading/writing them dependent on that MSR.

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Reviewed-by: Doru Blânzeanu <dblanzeanu@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-7-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
662b6c053e target/i386/mshv: migrate LAPIC state
This change implements loading and storing the hyperv lapic state as
part of the load/store routines for a vcpu.

The HyperV LAPIC is similar to the the split-irqchip in KVM. MSHV
currently keeps PIC/IOAPIC emulation in userspace, while LAPIC
interrupt injection is handled through hypercalls.

We introduced dedicated apic infra in hw/i386/mshv to handle the
migration and move lapic related functions from target/i386/mshv
there. References have been the WHPX's whpx-apic implemenation and
the mshv-ioctls crate's get_/set_lapic() impl for the mapping
between MSHV/QEMU lapic state.

We are mapping the lapic state that we receive from the hypervisor to
fields in APICCommonState. Common fields are used where feasible, with
an mshv-specific MshvAPICState object that carries mshv-specific
fields.

We have introduced a guard in pic_irq_request() that will early exit
for the mshv accelerator, because mshv cannot take part in the userland
path for legacy PIC interrupt injection.

The TSC_DEADLINE MSR is also migrated as part of LAPIC migration.

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Reviewed-by: Doru Blânzeanu <dblanzeanu@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-6-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
2f6c2ede46 accel/mshv: install dummy handler for SIG_IPI
This is similar to HVF's implementation. We want to interrupt the blocking
vcpu run. The self-kick was effectively a no-op for mshv.

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Reviewed-by: Doru Blânzeanu <dblanzeanu@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-5-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
922c1a4aac hw/i386/mshv: migrate REFERENCE_TIME
This is a partition-wide state for which we use a dedicated hw clock
facility, similar to KVM. We have to freeze the time for a partition
before we are allowed to set it. We register a state change handler for
the clock device and a post-load handler for migration state. In the
post-load handler we toggle a flag that will set the reference time
state on next state to "running" on the partition.

We can move the time freeze and reference-time ioctls/hvcalls to the
clock module.

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Reviewed-by: Doru Blânzeanu <dblanzeanu@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-4-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
f27b4fcfd8 accel/mshv: introduce SaveVMHandler
This mechanism is used to handle more imperative partition-wide steps
that have to be taken as part of a migration routine. Currently it's
just a skeleton.

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Reviewed-by: Doru Blânzeanu <dblanzeanu@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-3-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
3b599ae592 target/i386/mshv: toggle fpu/xsave migration
MSHV exposes overlapping legacy FP/SSE state through two paths:
explicit Hyper-V FPU/XMM + registers and VP XSAVE state. There can
be subtle inconsistencies across migrations when XSAVE is written after
FPU state.

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-12-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Magnus Kulke
f3a89cded2 target/i386/mshv: disable AMX TILE features
For the time being we disable AMX TILE in partition processor features
and CPUID b/c AMX TILE XSAVE state (XTILE_DATA) is 8KB, which exceeds
the current fixed 4KB XSAVE buffer size.

For now we filter it until buffer sizing is computed dynamically from CPUID.

Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Reviewed-by: Doru Blânzeanu <dblanzeanu@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260710101534.664604-2-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Andrey Polivoda
380b959618 target/i386: decode opcode extensions group 3 /1 as TEST
According to Table A-6 in Volume 3 of AMD64 Architecture Programmer's Manual,
opcodes F6 and F7 (opcode extensions group 3) with ModRM's reg field values
of 0 and 1 can be used to encode a TEST instruction.

Although Intel 64 and IA-32 Architectures Software Developer's Manual leaves
the cell 1 of opcode extensions group 3 blank in the opcode table
(Table A-6, Volume 2D), the instruction in a group 3 with reg field of ModRM
byte set to 1 actually behaves like TEST instruction on Intel CPUs.

Currently, QEMU decodes group 3 instruction as TEST only if reg field of ModRM
byte is 0. When the reg field is 1, QEMU raises a #UD exception.
This behavior does not match real Intel and AMD hardware.

This patch fixes this issue by duplicating the existing [0x00] and [0x08]
X86_OP_ENTRYrr(AND, ...) entries into slots [0x01] and [0x09] in the
opcodes_grp3 table.

Fixes: d7c41a60d0 ("target/i386: move C0-FF opcodes to new decoder (except for x87)")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3580
Signed-off-by: Andrey Polivoda <apolivodaa433@gmail.com>
Cc: qemu-devel@nongnu.org
Cc: Paolo Bonzini <pbonzini@redhat.com>
Cc: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Link: https://lore.kernel.org/r/20260621032524.1138213-1-apolivodaa433@gmail.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Andrey Polivoda
36f634fe4a target/i386: allow transition to virtual-8086 mode only if CPL == 0 and CPU is not in long mode
According to the pseudocode for the IRET instruction in both the Intel 64
and IA-32 Architectures Software Developer's Manual and the AMD64 Architecture
Programmer's Manual, a transition to virtual-8086 mode is allowed only if all
of the following conditions are met:

1. The new EFLAGS.VM bit is set to 1.
2. The Current Privilege Level (CPL) is 0.
3. The CPU is in protected mode (and not in long mode).

Currently, QEMU performs only the first check. This omission allows a
transition to virtual-8086 mode from long mode, and also enables the guest's
userspace to trigger this switch.

During a legitimate transition, the EFLAGS register is updated in a way that
allows modification of sensitive fields, such as IOPL and IF (which is expected,
as only privileged code should be able to initiate this transition).

However, due to the lack of appropriate checks, an unprivileged guest userspace
process can now force this transition and freely modify these fields.
This allows the userspace to:

1. Disable interrupts, preventing other processes from running on the CPU.
2. Gain direct hardware I/O access by elevating EFLAGS.IOPL to 3.
3. Crash the guest kernel by setting CS and SS to resemble segments with RPL = 0
   and triggering an exception. Since the kernel is unaware that the process
   entered virtual-8086 mode, it will misinterpret the exception as originating
   from kernel space.

This patch fixes this bug by adding the missing CPL and long mode checks before
jumping to the `return_to_vm86` label.

Fixes: 90a9fdae1f ("more ring 0 operations")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3583
Signed-off-by: Andrey Polivoda <apolivodaa433@gmail.com>
Cc: qemu-devel@nongnu.org
Cc: Paolo Bonzini <pbonzini@redhat.com>
Cc: Richard Henderson <richard.henderson@linaro.org>
Link: https://lore.kernel.org/r/20260622082119.11903-1-apolivodaa433@gmail.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Craaijo, Jos
3589cd995b target/i386: fix long mode segment override prefix decoding
On x86, the ES/CS/SS/DS segment override prefixes are null prefixes in
long mode, and should be ignored. (AMD APM Volume 3, Section 1.2.4)

This patch fixes the prefix decoding to correctly ignore the prefixes in
64-bit mode.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3391
Signed-off-by: Jos Craaijo <jos.craaijo@ou.nl>
Tested-by: Yudistira Putra <pyudistira519@gmail.com>
Link: https://lore.kernel.org/r/20260623-fix-x86-long-mode-segment-override-decoding-v1-1-26d9d4b5804e@ou.nl
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:53 +02:00
Simon Scherer
ce0ee66044 target/i386: fix incorrect decoding of EXTRQ_i
The decoding of the extrq instruction with an immediate operand (EXTRQ_i) is
incorrect. Per the AMD manual the instruction encoding looks as follows:

EXTRQ xmm1, imm8, imm8   66 0F 78 /0 ib ib

The /0 indicates that the "Reg" field of the ModR/M byte must be equal
to 0 and the XMM register operand is specified by the "R/M" field.
However, qemu incorrectly uses the "Reg" field to extract the register operand.

This patch instead extracts the XMM register operand from the "R/M"
field.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3611
Signed-off-by: Simon Scherer <scherer.simon89@gmail.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Link: https://lore.kernel.org/r/20260625155613.192643-1-scherer.simon89@gmail.com
[Check for the reg field to be 0.  Make decoding of REPZ+66 consistent
 between 0F 78 and 0F 79. - Paolo]
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:51:27 +02:00
Paolo Bonzini
5cc3e4ea53 target/i386: use ESA_FEATURE_ALIGN64_MASK
Do not hardcode bit 1.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:16:35 +02:00
Magnus Kulke
654d4cd059 target/i386: Skip supervisor in xsave decompaction
Supervisor state should be skipped b/c there is no slot in standard
format XSAVE buffer for it. CET State is being migrated via MSRs and
other supervisor state isn't currently migrated.

Fixes: 8612deb3f4
Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Reviewed-by: Doru Blânzeanu <dblanzeanu@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260702124746.450228-1-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:16:35 +02:00
Simon Scherer
0924d9d3db target/i386: Clear OF, SF, and AF for fcomi/fucomi
helper_fcomi_ST0_FT0() and helper_fucomi_ST0_FT0() only cleared
CC_Z, CC_P, and CC_C before merging in the comparison result,
leaving CC_O, CC_S, and CC_A untouched from whatever they were
set to beforehand.

The Intel SDM documents FCOMI/FCOMIP/FUCOMI/FUCOMIP as setting OF,
SF, and AF to 0 unconditionally. The AMD manual doesn't mention them
at all. However, testing on multiple real Intel and AMD systems confirms
all three are unconditionally cleared regardless of the comparison
result or their prior value.

Since fcomi_ccval[] only ever contains CC_C, CC_Z, 0, or CC_Z|CC_P|CC_C,
and CC_O|CC_S|CC_Z|CC_A|CC_P|CC_C already covers every flag bit, CC_SRC
can be assigned from fcomi_ccval[ret + 1] directly instead of ORing it
into a masked cpu_cc_compute_all() result.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4133
Signed-off-by: Simon Scherer <scherer.simon89@gmail.com>
Link: https://lore.kernel.org/r/20260807062831.19618-1-scherer.simon89@gmail.com
Cc: qemu-stable@nongnu.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-17 16:16:35 +02:00
Richard Henderson
9696bf5dc5 Misc HW and Monitor patch queue
- Bug fixes
 
  . Reinstate x86/pc 'xenfv' machine alias
  . Defend against malformed ELF headers to prevent underflows
  . Restore ROMD mode after migration for Intel PFlash (CFI01)
  . Fix VLAN tag handling on incoming packets on RTL8139 model
 
 - Refactoring (Monitor, common CPU, NMI)
 
  . Add missing inclusions and remove unnecessary ones
  . Use qdev_is_realized() consistently (no direct field access)
  . Remove deprecated DEFINE_PROP_DMAADDR() macro
  . Renaming churn around cpu_{exec,common}* helpers
  . Simplify NMI API hanlding
  . Move QMP handlers (physmem, nmi) to appropriate subsystems
  . Replace container_of() casts with HMP typed accessors
  . Rename @mon to @hmp in MonitorHMP for clarity
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEE+qvnXhKRciHc/Wuy4+MsLN6twN4FAmqBzKAACgkQ4+MsLN6t
 wN79Og//Qt6s9wU8KyegqCi55+tMSxQfTE96O5qRjV9FcrTeYMrlDWTm5jXcdSXr
 DVjAfM/SDI98TDWkG0Uxk5r0Kr1C1V9u8CAClED1Us81mwloGBX6qar9AdcnNzXL
 Pi0C4jWk2NVZyXq+0cvPQZg8SW2xSsgbEWrkuGRxlDqrwHcljMhEivE6NvHZjrOr
 2QvgB/31JcsqrtdosBnAw4xDsZ7Gf3Gqpoz4IdoVdxn2o9TaTm8+DlZgmHz2klmq
 3diW9BItqQEYzURl/psfjl6WaQ2sls18sEIZs62M+2cTkDBBTFo8ErnFyEUqCRlD
 tPCt+b+DljifV9vKAt/+rMO2WdQxN3eTild+xmQ0DbZH6BCktkS0tR6nEVosC8qB
 3fmqmibyn9T+qaGfAAKrBEbsPhS0yiZaw3/pSY/BBuDMTX9G4URfxsWY6Ka++ZqL
 KRPeypnMeGBYsfEOVmWAbVeMVO9O8aXoIcaXprRc2jvtRj47exHvVKYSCwFPNeTi
 hioNFbI6/EjzcIooWZd0yq3DLrJ5KaW9S/BoZH1B5A8uun9pdmybCbROgOFryr/q
 aZNuk6otVynNwd2sTHzgw34ru76pJv2NqyP1PV3MxmfsLrCpjr3xH0lXaqRiiaKk
 Z+uglV8hrkKsGY5krzbHLWtjRc/XthroFkW4g8VLQw4XLsIeR+s=
 =Dx4p
 -----END PGP SIGNATURE-----

Merge tag 'hw-misc-20260816' of https://github.com/philmd/qemu into staging

Misc HW and Monitor patch queue

- Bug fixes

 . Reinstate x86/pc 'xenfv' machine alias
 . Defend against malformed ELF headers to prevent underflows
 . Restore ROMD mode after migration for Intel PFlash (CFI01)
 . Fix VLAN tag handling on incoming packets on RTL8139 model

- Refactoring (Monitor, common CPU, NMI)

 . Add missing inclusions and remove unnecessary ones
 . Use qdev_is_realized() consistently (no direct field access)
 . Remove deprecated DEFINE_PROP_DMAADDR() macro
 . Renaming churn around cpu_{exec,common}* helpers
 . Simplify NMI API hanlding
 . Move QMP handlers (physmem, nmi) to appropriate subsystems
 . Replace container_of() casts with HMP typed accessors
 . Rename @mon to @hmp in MonitorHMP for clarity

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEE+qvnXhKRciHc/Wuy4+MsLN6twN4FAmqBzKAACgkQ4+MsLN6t
# wN79Og//Qt6s9wU8KyegqCi55+tMSxQfTE96O5qRjV9FcrTeYMrlDWTm5jXcdSXr
# DVjAfM/SDI98TDWkG0Uxk5r0Kr1C1V9u8CAClED1Us81mwloGBX6qar9AdcnNzXL
# Pi0C4jWk2NVZyXq+0cvPQZg8SW2xSsgbEWrkuGRxlDqrwHcljMhEivE6NvHZjrOr
# 2QvgB/31JcsqrtdosBnAw4xDsZ7Gf3Gqpoz4IdoVdxn2o9TaTm8+DlZgmHz2klmq
# 3diW9BItqQEYzURl/psfjl6WaQ2sls18sEIZs62M+2cTkDBBTFo8ErnFyEUqCRlD
# tPCt+b+DljifV9vKAt/+rMO2WdQxN3eTild+xmQ0DbZH6BCktkS0tR6nEVosC8qB
# 3fmqmibyn9T+qaGfAAKrBEbsPhS0yiZaw3/pSY/BBuDMTX9G4URfxsWY6Ka++ZqL
# KRPeypnMeGBYsfEOVmWAbVeMVO9O8aXoIcaXprRc2jvtRj47exHvVKYSCwFPNeTi
# hioNFbI6/EjzcIooWZd0yq3DLrJ5KaW9S/BoZH1B5A8uun9pdmybCbROgOFryr/q
# aZNuk6otVynNwd2sTHzgw34ru76pJv2NqyP1PV3MxmfsLrCpjr3xH0lXaqRiiaKk
# Z+uglV8hrkKsGY5krzbHLWtjRc/XthroFkW4g8VLQw4XLsIeR+s=
# =Dx4p
# -----END PGP SIGNATURE-----
# gpg: Signature made Sun 16 Aug 2026 07:43:44 AM PDT
# gpg:                using RSA key FAABE75E12917221DCFD6BB2E3E32C2CDEADC0DE
# gpg: Good signature from "Philippe Mathieu-Daudé (F4BUG) <f4bug@amsat.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: FAAB E75E 1291 7221 DCFD  6BB2 E3E3 2C2C DEAD C0DE

* tag 'hw-misc-20260816' of https://github.com/philmd/qemu: (56 commits)
  hw/core/machine: Move EHCI migration compat properties to 11.1
  hw/elf_ops: defend against weird elf headers
  monitor: Replace container_of(MonitorHMP, parent_obj) -> MONITOR_HMP()
  monitor: Better express monitor_read()'s opaque arg is of Monitor type
  monitor: Rename MonitorHMP @mon -> @hmp
  system: Move runstate-related code from cpus.c to runstate.c
  system: Extract QMP memsave/pmemsave commands to physmem-qmp-cmds.c
  system: Move qmp_inject_nmi() to hw/core/machine-qmp-cmds.c
  system/dirtylimit: Extract HMP code to dirtylimit-hmp-cmds.c
  system: Remove unnecessary 'monitor/monitor.h' header
  monitor: Remove unnecessary 'block/block.h' header
  monitor: Reduce inclusion of 'qapi/qapi-emit-events.h' header
  monitor: Include missing 'qemu/coroutine-core.h' header
  monitor: Include missing 'qemu/lockable.h' header
  monitor: Include missing 'qemu/aio-wait.h' header
  migration/hmp-cmds: Include 'block/block-global-state.h' header
  qapi/qmp-registry: Remove unnecessary 'monitor/monitor.h' header
  qapi/qmp-dispatch: Include 'qemu/aio-wait.h' and 'monitor/monitor.h'
  tests/unit: Include 'qemu/main-loop.h' header in test-util-sockets.c
  net/vhost-vdpa: Include missing 'qemu/iov.h' header
  ...

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-16 08:17:47 -07:00
Jamin Lin
b409523587 hw/core/machine: Move EHCI migration compat properties to 11.1
The x-migrate-fetch-addr-64bit compatibility properties for
sysbus-ehci-usb and pci-ehci-usb were reviewed before the QEMU 11.1
release and were therefore initially added to hw_compat_11_0.

However, the EHCI migration change was merged after the QEMU 11.1
release. As a result, these compatibility properties belong in
hw_compat_11_1 rather than hw_compat_11_0.

Move both properties to hw_compat_11_1 so that migration compatibility
is associated with the correct machine version.

Fixes: 38ed803aeb ("usb/hcd-ehci: Change descriptor addresses to 64-bit")
Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260814032559.3381363-1-jamin_lin@aspeedtech.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:35:27 +02:00
Alex Bennée
260d49d8e2 hw/elf_ops: defend against weird elf headers
According to the ELF spec:

  PT_LOAD

  The array element specifies a loadable segment, described by
  p_filesz and p_memsz. The bytes from the file are mapped to the
  beginning of the memory segment. If the segment's memory
  size (p_memsz) is larger than the file size (p_filesz), the
  ``extra'' bytes are defined to hold the value 0 and to follow the
  segment's initialized area. The file size may not be larger than the
  memory size. Loadable segment entries in the program header table
  appear in ascending order, sorted on the p_vaddr member.

which implies while both p_filesz and p_memsz can be zero we should
never see a case where p_filesz is greater than the in memory size.
Indeed it has been reported such a hand crafted ELF can blow up, for
example during rom_reset():

  address_space_set(rom->as, rom->addr + rom->datasize, 0,
                    rom->romsize - rom->datasize,
                    MEMTXATTRS_UNSPECIFIED);

which could trigger and underflow leaving QEMU slowly filling a very
large buffer.

Cc: qemu-stable@nongnu.org
Fixes: https://gitlab.com/qemu-project/qemu/-/work_items/4056
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260812081405.3811787-1-alex.bennee@linaro.org>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:35:27 +02:00
Philippe Mathieu-Daudé
f32f9ffcfe monitor: Replace container_of(MonitorHMP, parent_obj) -> MONITOR_HMP()
By replacing the container_of(MonitorHMP) use in ui/ui-hmp-cmds.c
we can remove its incorrect inclusion of "monitor/monitor-internal.h"
header, using the public "monitor/monitor.h" instead.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-23-philmd@oss.qualcomm.com>
2026-08-16 16:35:27 +02:00
Philippe Mathieu-Daudé
e33c5ac0d8 monitor: Better express monitor_read()'s opaque arg is of Monitor type
monitor_read() is a IOReadHandler handler, called by
qemu_chr_fe_set_handlers() with a Monitor* opaque argument.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-20-philmd@oss.qualcomm.com>
2026-08-16 16:35:27 +02:00
Philippe Mathieu-Daudé
e1212b5181 monitor: Rename MonitorHMP @mon -> @hmp
Mechanical change to sanitize using the following patterns:

  MonitorQMP *qmp
  MonitorHMP *hmp
  Monitor *mon

Rename @mon (and @hmp_mon) as @hmp when the type is MonitorHMP.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-Id: <20260812211708.92824-19-philmd@oss.qualcomm.com>
Acked-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-08-16 16:34:03 +02:00
Philippe Mathieu-Daudé
f036b28896 system: Move runstate-related code from cpus.c to runstate.c
Keep cpus.c focused on vCPUs handling, move code related to
VM state to runstate.c where similar code lives.

Fix few checkpatch.pl warnings:

  WARNING: Block comments use a leading /* on a separate line
  WARNING: Block comments use * on subsequent lines
  #327: FILE: system/runstate.c:541:
  +/* does a state transition even if the VM is already stopped,
  +   current state is forgotten forever */

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-17-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
259c2aae8d system: Extract QMP memsave/pmemsave commands to physmem-qmp-cmds.c
Keep cpus.c related to vCPU scheduling, move the QMP handlers
related to dumping physical memory to file to their own unit.
Fix a pair of checkpatch.pl errors doing so:

  ERROR: braces {} are necessary for all arms of this statement
  #185: FILE: system/physmem-qmp-cmds.c:51:
  +        if (l > size)
  [...]

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-16-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
5bd649ccf9 system: Move qmp_inject_nmi() to hw/core/machine-qmp-cmds.c
We figured NMI relates to machines (for their machine-specific
handling), so move the 'inject-nmi' QMP handler with the rest
of machine ones, in hw/core/machine-qmp-cmds.c.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-15-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
c339d8459e system/dirtylimit: Extract HMP code to dirtylimit-hmp-cmds.c
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Hyman Huang <yong.huang@bitdeer.com>
Message-Id: <20260812211708.92824-14-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
bd2871ac50 system: Remove unnecessary 'monitor/monitor.h' header
No code in device_tree.c or physmem.c require declarations
from "monitor/monitor.h".

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-13-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
2697e7199a monitor: Remove unnecessary 'block/block.h' header
Nothing here requires declarations from "block/block.h" anymore.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-12-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
8805844280 monitor: Reduce inclusion of 'qapi/qapi-emit-events.h' header
"monitor/monitor.h" don't use anything declared in the generated
"qapi/qapi-emit-events.h" header.
However the "monitor/monitor-internal.h" do:

  107 struct MonitorClass {
  ...
  116     /*
  117      * If non-NULL, the monitor is able to send event
  118      * notifications back to the client
  119      */
  120     void (*emit_event)(Monitor *mon, QAPIEvent event, QDict *qdict);
                                           ^^^^^^^^^

Move the header inclusion to "monitor/monitor-internal.h" to
avoid including / re-exposing unnecessary declarations in the
global "monitor/monitor.h" header.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-11-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
25780a68e3 monitor: Include missing 'qemu/coroutine-core.h' header
"monitor/monitor.h" declares monitor_set_cur() which use the
'Coroutine' type, itself declared in "qemu/coroutine-core.h".
Include the latter to avoid when refactoring unrelated headers:

  In file included from ../../target/sh4/monitor.c:26:
  qemu/include/monitor/monitor.h:32:26: error: unknown type name 'Coroutine'
     32 | Monitor *monitor_set_cur(Coroutine *co, Monitor *mon);
        |                          ^

Fixes: e69ee454b5 ("monitor: Make current monitor a per-coroutine property")
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-10-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
e883c338dd monitor: Include missing 'qemu/lockable.h' header
Files in monitor/ use the QEMU_LOCK_GUARD() macros, which
are declared in "qemu/lockable.h". Include the latter to
avoid when refactoring unrelated headers:

  ../monitor/fds.c:146:5: error: call to undeclared function 'QEMU_LOCK_GUARD'
    146 |     QEMU_LOCK_GUARD(&mon->mon_lock);
        |     ^
  ../monitor/monitor.c:176:5: error: call to undeclared function 'QEMU_LOCK_GUARD'
    176 |     QEMU_LOCK_GUARD(&mon->mon_lock);
        |     ^
  ../monitor/qmp.c:164:5: error: call to undeclared function 'WITH_QEMU_LOCK_GUARD'
    164 |     WITH_QEMU_LOCK_GUARD(&mon->mon_lock) {
        |     ^

Fixes: 0210c3b39b ("monitor: Use LOCK_GUARD macros")
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-9-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
79a71f3a49 monitor: Include missing 'qemu/aio-wait.h' header
Both monitor.c and qmp.c use types / methods declared in
"qemu/aio-wait.h". Include the latter to avoid the following
errors when refactoring unrelated headers:

  ../monitor/monitor.c:648:5: error: call to undeclared function 'AIO_WAIT_WHILE_UNLOCKED'
    648 |     AIO_WAIT_WHILE_UNLOCKED(NULL,
        |     ^
  ../monitor/qmp.c:792:9: error: call to undeclared function 'aio_wait_bh_oneshot'
    792 |         aio_wait_bh_oneshot(iothread_get_aio_context(mon_iothread),
        |         ^

Fixes: 9ce44e2ce2 ("qmp: Move dispatcher to a coroutine")
Fixes: a5df506e12 ("monitor: implement support for deleting QMP objects")
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-8-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
cca454be70 migration/hmp-cmds: Include 'block/block-global-state.h' header
migration-hmp-cmds.c uses types / methods declared in
"block/block-global-state.h".  Include the latter otherwise
we get when refactoring unrelated headers:

  ../migration/migration-hmp-cmds.c:911:5: error: use of undeclared identifier 'BdrvNextIterator'
    911 |     BdrvNextIterator it;
        |     ^
  ../migration/migration-hmp-cmds.c:918:15: error: call to undeclared function 'bdrv_first'
    918 |     for (bs = bdrv_first(&it); bs; bs = bdrv_next(&it)) {
        |               ^

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Dr. David Alan Gilbert <dave@treblig.org>
Message-Id: <20260812211708.92824-7-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
9829b98dd1 qapi/qmp-registry: Remove unnecessary 'monitor/monitor.h' header
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-6-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
977d5b5018 qapi/qmp-dispatch: Include 'qemu/aio-wait.h' and 'monitor/monitor.h'
qmp-dispatch.c calls aio_wait_kick() and monitor_cur(). Include the
header declaring them in order to avoid the following build failure
when refactoring unrelated headers:

  ../qapi/qmp-dispatch.c:126:12: error: call to undeclared function 'monitor_cur'
    126 |     assert(monitor_cur() == NULL);
        |            ^
  ../qapi/qmp-dispatch.c:141:5: error: call to undeclared function 'aio_wait_kick'
    141 |     aio_wait_kick();
        |     ^

Fixes: 41725fa7ed ("qmp: Call monitor_set_cur() only in qmp_dispatch()")
Fixes: fc1a2ec7da ("monitor: Fix deadlock in monitor_cleanup")
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-5-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
69cf1ebaf5 tests/unit: Include 'qemu/main-loop.h' header in test-util-sockets.c
test-util-sockets.c calls qemu_init_main_loop(), itself declared in
the "qemu/main-loop.h" header. Include the latter to avoid when
refactoring unrelated headers:

  ../tests/unit/test-util-sockets.c:553:5: error: call to undeclared function 'qemu_init_main_loop'
  553 |     qemu_init_main_loop(&error_abort);
      |     ^

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-4-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
c5162b8423 net/vhost-vdpa: Include missing 'qemu/iov.h' header
vhost-vdpa.c uses methods declared in the "qemu/iov." header.
Include it otherwise we get when refactoring unrelated headers:

  ../net/vhost-vdpa.c: In function ‘vhost_vdpa_net_load_cmd’:
  ../net/vhost-vdpa.c:714:24: error: implicit declaration of function ‘iov_size’
    714 |     size_t data_size = iov_size(data_sg, data_num), cmd_size;
        |                        ^~~~~~~~
  ../net/vhost-vdpa.c:714:24: error: nested extern declaration of ‘iov_size’
  ../net/vhost-vdpa.c:742:5: error: implicit declaration of function ‘iov_from_buf’
    742 |     iov_from_buf(out_cursor, 1, 0, &ctrl, sizeof(ctrl));
        |     ^~~~~~~~~~~~
  ../net/vhost-vdpa.c:742:5: error: nested extern declaration of ‘iov_from_buf’
  ../net/vhost-vdpa.c:744:5: error: implicit declaration of function ‘iov_to_buf’
    744 |     iov_to_buf(data_sg, data_num, 0,
        |     ^~~~~~~~~~
  ../net/vhost-vdpa.c:744:5: error: nested extern declaration of ‘iov_to_buf’
  ../net/vhost-vdpa.c:748:5: error: implicit declaration of function ‘iov_copy’
    748 |     iov_copy(&out, 1, out_cursor, 1, 0, cmd_size);
        |     ^~~~~~~~

Fixes: bd907ae4b0 ("vdpa: manual forward CVQ buffers")
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Acked-by: Michael S. Tsirkin <mst@redhat.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-3-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
561710e5d2 hexagon: Remove unnecessary 'monitor/monitor.h' header
The Monitor type is used in these 2 files, as a pointer.
Since the type is forward-declared in "qemu/typedefs.h",
which all source files include via "qemu/osdep.h", we do
not need to include it.

Do however include "exec/hwaddr.h" and "exec/mmu-access-type.h"
which declare the types used by hex_tlb_find_match prototype:

  extern bool hex_tlb_find_match(CPUHexagonState *env, uint32_t VA,
                                 MMUAccessType access_type, hwaddr *PA, int *prot,
                                 ^^^^^^^^^^^^^              ^^^^^^
                                 uint64_t *size, int32_t *excp, int mmu_idx);

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812211708.92824-2-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
c6f9b1dc95 hw/nmi: Raise NMI line only once
We only expect one device in the system to implement the
TYPE_NMI interface (typically the machine, but in a few cases
for e.g. m68k and ppc this is an interrupt controller or
similar device); so we don't need to keep walking the whole
QOM tree once we've found it. As no machine type creates more
than one object implementing TYPE_NMI, this is not a behaviour
change.

Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812121232.71958-8-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
acfbe07619 hw/nmi: Remove unused @errp argument from raise_nmi()
Not a single handler update @errp. The single user is
nmi_inject() filling with "machine does not provide NMIs".
Remove the unused argument from the raise_nmi() callback,
simplifying the methods in hw/core/nmi.c.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812121232.71958-7-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
caabebf76b hw/nmi: Rename nmi_monitor_handler() -> raise_nmi()
nmi_monitor_handler() is not related to the monitor,
rename it as raise_nmi().

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812121232.71958-6-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
64011ef0d9 hw/nmi: Remove @cpu_index argument from nmi_inject()
nmi_monitor_handle() is not related to the monitor, rename
it as nmi_inject().

Return a boolean value indicating success / failure as
recommended by the Error API since commit e3fe3988d7
("error: Document Error API usage rules").

The 'cpu_index' argument is not used, remove it.
This officially drops the current CPU for HMP command.

Document nmi_inject() as suggested by Peter Maydell in
https://lore.kernel.org/qemu-devel/CAFEAcA-yALySmCJLbitCmYpiZKUXJNOavGJG9RYeo8fKqz7gcw@mail.gmail.com/.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-Id: <20260812121232.71958-5-philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
9dad341a52 hw/nmi: Remove @cpu_index argument from NMIClass::nmi_monitor_handler()
Only s390x was using the 'cpu_index' argument, but since the
previous commit it isn't anymore (it use the first cpu).
Since this argument is now completely unused, remove it.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812121232.71958-4-philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
c489b04fbc hw/s390x/virtio-ccw: Always inject NMI to first CPU
We can trigger NMI from HMP or QMP.

QEMU maps the NMI to the s390x per-CPU 'RESTART' interrupt.
Linux guests usually setup this interrupt to trigger kdump
or crash. Such crashdump can be triggered in QEMU by HMP
"nmi" or QMP "inject-nmi" commands.

Using QMP, since we can not select a particular CPU, the first
CPU is used (CPU#0). See the documentation from commit 795dc6e4
("watchdog: Add new Virtual Watchdog action INJECT-NMI"):

  @inject-nmi: a non-maskable interrupt is injected into the
               first VCPU (all VCPUS on x86) (since 2.4)

While we can select a particular CPU on HMP, the guest behavior
is expected to be the same if using CPU #N or CPU #0. Since
always using CPU#0 simplifies API maintenance , update s390_nmi()
to inject NMI to the first CPU.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: David Hildenbrand <david@redhat.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812121232.71958-3-philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:32:42 +02:00
Philippe Mathieu-Daudé
f37b245e56 hw/nmi: Use object_child_foreach_recursive() in nmi_children()
Replace object_child_foreach() and recursion by a single
object_child_foreach_recursive() call.
Propagate the returned value so callers can check it.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-Id: <20260812121232.71958-2-philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Philippe Mathieu-Daudé
398913c47b hw/cpu: Move system-specific cpu_exec_realize() to cpu-system.c
Current cpu_exec_realize() body only contains system-mode
related code. Move that method out of cpu-common.c to
cpu-system.c, removing the system / machine mentions in
this common file. Add an empty stub for user-mode.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-Id: <20260811183410.22428-9-philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Philippe Mathieu-Daudé
721c189cb6 hw/cpu: Extract cpu_exec_realize() out of cpu_common_realizefn()
cpu_common_realizefn() contains code only used by system mode
emulation. Extract it to a new cpu_exec_realize() helper. In
the next commit this helper will be moved to cpu-system.c where
it belongs.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-Id: <20260811183410.22428-8-philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Philippe Mathieu-Daudé
5293cecb89 hw/cpu: Rename cpu_exec_unrealizefn() -> cpu_common_unrealize()
Keep cpu_common_*() pattern for publicly exposed common methods
used by target code. Use cpu_exec_*() pattern for internal ones,
mostly to distinct between system / user mode.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-Id: <20260811183410.22428-7-philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Philippe Mathieu-Daudé
abf1023d63 hw/cpu: Rename cpu_exec_realizefn() -> cpu_common_realize()
Keep cpu_common_*() pattern for publicly exposed common methods
used by target code. Use cpu_exec_*() pattern for internal ones,
mostly to distinct between system / user mode.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-Id: <20260811183410.22428-6-philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Philippe Mathieu-Daudé
dc6c2e6672 hw/cpu: Rename cpu_common_realizefn() -> cpu_exec_realize()
Keep cpu_common_*() pattern for publicly exposed common methods
used by target code. Use cpu_exec_*() pattern for internal ones,
mostly to distinct between system / user mode.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-Id: <20260811183410.22428-5-philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Philippe Mathieu-Daudé
a2d626371d hw/cpu: Move internal declarations to new 'cpu-internal.h' header
Some declarations are only used within hw/core/, in particular
by the 3 cpu-{common,user,system}.c. Restrict the declarations
scope by moving them to a new "cpu-internal.h" local header.

Rename cpu_exec_initfn() -> cpu_exec_init() because we usually
have the 'fn' suffix for handler, not API entry point methods.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-Id: <20260811183410.22428-4-philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Philippe Mathieu-Daudé
fec261633c hw/cpu: Include missing 'qemu/accel.h' header
cpu_common_realize() calls accel_cpu_common_realize(),
itself declared in "qemu/accel.h". Include the latter,
otherwise we get when refactoring unrelated headers:

  hw/core/cpu-common.c:233:10: error: implicit declaration of function ‘accel_cpu_common_realize’
    233 |     if (!accel_cpu_common_realize(cpu, errp)) {
        |          ^~~~~~~~~~~~~~~~~~~~~~~~

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-Id: <20260811183410.22428-3-philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Philippe Mathieu-Daudé
5147e585e7 hw/cpu: Correct CPU_GET_CLASS() comment
commit 0e86d7a71e ("cpus: Cache CPUClass early in instance_init()
handler") renamed cpu_exec_realizefn() -> cpu_common_initfn();
update the comment.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-Id: <20260811183410.22428-2-philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Stefan Hajnoczi
6dab35f549 hw/nvme: add SPDM_SOCKET Kconfig dependency
The NVMe emulation code unconditionally calls spdm_socket_*() APIs. Add
a Kconfig dependency to avoid build errors when NVME_PCI is enabled
without SPDM_SOCKET.

Fixes: 4f947b10d5 ("hw/nvme: Add SPDM over DOE support")
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
Reviewed-by: Klaus Jensen <k.jensen@samsung.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260810214846.76805-1-stefanha@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Bin Guo
60d010f66f hw/block/pflash_cfi01: Restore ROMD mode after migration
pflash_post_load() did not restore the ROMD mode of the memory region.
Although cmd and wcycle are migrated, the destination retains the
default ROMD = true from realize.  When the source was in a non-array
mode (e.g. ID read, cmd = 0x90), reads on the destination bypass
pflash_read() via the ROM fast path and return raw storage bytes
instead of the command-specific response.

Derive ROMD from the migrated cmd/wcycle in pflash_post_load.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4042
Cc: qemu-stable@nongnu.org
Signed-off-by: Bin Guo <guobin@linux.alibaba.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
[PMD: Including review comments from
 https://lore.kernel.org/qemu-devel/CAFEAcA-P6RH7nJK0KQ1H8576ULFA7nocB0EkhhZf6Rw3g0WCag@mail.gmail.com/

 Confirming that this is correct is a bit tricky. It relies on:
  * when we set romd mode to true we also set wcycle = 0, cmd = 0
    (which we do, in reset and in the mode_read_array code)
  * when we set romd mode to false at the top of pflash_write(),
    all paths out of that function either go through the
    mode_read_array path, or else update pfl->cmd to something
    non-zero
  * nowhere outside pflash_write() udpates cmd or wcycle except
    for the "clear them to 0 and set romd mode" places

 This is almost but not quite true. In pflash_read(), the default
 case for the pfl->cmd switch sets wcycle = 0 cmd = 0 but doesn't
 change the romd state. Luckily the "this should never happen"
 comment is true -- there's no way to get a pfl->cmd that falls
 into the default (except for being deliberately fed a bogus value
 via inbound migration).
]
Message-ID: <20260803041808.58174-1-guobin@linux.alibaba.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Peter Maydell
f3a10c1c45 hw/net/rtl8139: Send whole of vlan-tagged packet when doing loopback
In rtl8139_transfer_frame(), if we are transmitting a frame over
loopback then we do this by calling qemu_receive_packet().  If we
have an iovec rather than a simple buffer (which happens only when
we're sending a packet where we are inserting a vlan tag), we have to
convert this into a simple buffer first using iov_to_buf().  However,
when we do this we forget to also update the 'size' local variable to
the size of the new simple buffer, so we will truncate the packet by
4 bytes (the size of the vlan tag).

Correct the logic so we don't truncate vlan-tagged packets when
sending them over loopback.

Cc: qemu-stable@nongnu.org
Reported-by: Bin Meng <bmeng.cn@gmail.com>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Bin Meng <bin.meng@processmission.com>
Message-ID: <20260731093618.2961031-3-peter.maydell@linaro.org>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Peter Maydell
59fc7b747d hw/net/rtl8139: Fix handling of VLAN tags on incoming short packets
The rtl8139 receive code handles VLAN tags in incoming packets by
copying the VLAN tag to a special field in the receive descriptor,
and copying only the actual payload data to the receive buffer.  This
code tries to ensure that it pads out the payload to at least
MIN_BUF_SIZE bytes.

In commit 63b901bfd3 we removed the main "pad short frames" code
from this device because we switched to requiring net backends to do
the padding.  However we didn't notice that this broke the VLAN tag
handling, which relied on the old code making the buffer at least
MIN_BUF_SIZE + VLAN_HLEN bytes so that it could copy MIN_BUF_SIZE
bytes into the receive buffer even after removing the VLAN tag.  The
result is that the guest can make us read 4 bytes off the end of a
buffer by feeding itself a suitable short packet in loopback mode.

The old behaviour is actually not correct, because the IEEE802.1Q
standard says that the minimum ethernet frame size remains 64 bytes
including the 4 checksum bytes, and so when a tag is present the
payload data only needs to be 56 bytes.  (A bridge implementation can
choose to pad tagged frames out to 68 bytes, but it doesn't have to,
and so all devices have to correctly handle incoming tagged frames
that are 64 bytes long.)

The RTL8139 datasheet isn't very communicative on this topic, but
there's nothing that suggests it adds extra padding on receive that
didn't exist in the incoming packet.

Drop the last remnants of the padding handling from this device;
this avoids overcopying into the guest when we receive a short
VLAN tagged packet.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3518
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Bin Meng <bin.meng@processmission.com>
Message-ID: <20260731093618.2961031-2-peter.maydell@linaro.org>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Dario Faggioli
6ccf1e73fc hw/i386/pc: xen: reinstate the "xenfv" machine alias
Commit 7d2778dea3 ("hw/i386/pc:
Remove deprecated pc-q35/pc-i440fx/xenfv 3.1 machines") removed
the Xen machine type that was providing the "xenfv" alias. As a
consequence, since the tools are apparently relying on such alias,
we're getting this, as soon as one tries to start a Xen (HVM) VM:

  qemu-system-i386: unsupported machine type: "xenfv"
  Use -machine help to list supported machines

Reinstate the alias and let it point to the only Xen machine we
still have.

Cc: qemu-stable@nongnu.org
Fixes: 7d2778dea3 Remove deprecated pc-q35/pc-i440fx/xenfv 3.1 machines
Signed-off-by: Dario Faggioli <dfaggioli@suse.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Acked-by: Stefano Stabellini <sstabellini@kernel.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260730162238.3308286-1-dfaggioli@suse.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
c38575a126 hw/qdev: Parent device before setting parent bus
Commit 9940b2cfbc ("qdev: New qdev_new(), qdev_realize(), etc.") says
"device state 'no QOM parent, but plugged into bus' is dangerous". In
such a case, unrealizing the bus will hang in bus_unparent():

    while ((kid = QTAILQ_FIRST(&bus->children)) != NULL) {
        DeviceState *dev = kid->child;
        object_unparent(OBJECT(dev));
    }

object_unparent() does nothing when its argument has no QOM parent,
and the loop spins forever.

However, that commit did not completely eliminate such a situation.
When the device is not parented, device_set_realized() lets
/machine/unattached parent it, but it happens after setting parent bus.
Therefore, any failure between the two operations can leave the device
in a dangerous state.

qdev_realize() at least asserts that the device is not already realized
and prevents one realization failure pattern, but it is not
comprehensive. Besides, it will trip with a command line like the
following:

    qemu-system-x86_64 -M none -nodefaults -nographic \
        -device ipmi-bmc-sim,realized=on

Eliminate the dangerous state by ensuring that the device is parented
before calling qdev_set_parent_bus(). Also, stop asserting that the
device is not already realized in qdev_realize(); it is broken and
no longer serves any purpose.

Fixes: 9940b2cfbc ("qdev: New qdev_new(), qdev_realize(), etc.")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-14-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
72422beb01 target/s390x: Use qdev_is_realized()
DeviceState fields should be accessed through qdev helpers rather than
directly. Use qdev_is_realized() instead of reading
DeviceState::realized directly.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-13-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
58c4aeacfa target/i386/cpu: Use qdev_is_realized()
DeviceState fields should be accessed through qdev helpers rather than
directly. Use qdev_is_realized() instead of reading
DeviceState::realized directly.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-12-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
2c69525a8d hw/virtio/virtio-qmp: Use qdev_is_realized()
DeviceState fields should be accessed through qdev helpers rather than
directly. Use qdev_is_realized() instead of reading
DeviceState::realized directly.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-11-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
a3413cc176 hw/virtio/virtio-mem: Use qdev_is_realized()
DeviceState fields should be accessed through qdev helpers rather than
directly. Use qdev_is_realized() instead of reading
DeviceState::realized directly.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-10-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
30068ef746 hw/vfio: Use qdev_is_realized()
DeviceState fields should be accessed through qdev helpers rather than
directly. Use qdev_is_realized() instead of reading
DeviceState::realized directly.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-9-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
f80ce4a654 hw/ppc/pnv_xscom: Use qdev_is_realized()
DeviceState fields should be accessed through qdev helpers rather than
directly. Use qdev_is_realized() instead of reading
DeviceState::realized directly.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-8-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
56258e616f hw/nvram: Use qdev_is_realized()
DeviceState fields should be accessed through qdev helpers rather than
directly. Use qdev_is_realized() instead of reading
DeviceState::realized directly.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-7-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
4ef1d02325 hw/mem/pc-dimm: Use qdev_is_realized()
DeviceState fields should be accessed through qdev helpers rather than
directly. Use qdev_is_realized() instead of reading
DeviceState::realized directly.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-6-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
9cc59476bb hw/mem/memory-device: Use qdev_is_realized()
DeviceState fields should be accessed through qdev helpers rather than
directly. Use qdev_is_realized() instead of reading
DeviceState::realized directly.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-5-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
b341bc3be8 hw/intc/apic: Use qdev_is_realized()
DeviceState fields should be accessed through qdev helpers rather than
directly. Use qdev_is_realized() instead of reading
DeviceState::realized directly.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-4-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
1fbfec36db hw/hyperv/balloon: Use qdev_is_realized()
DeviceState fields should be accessed through qdev helpers rather than
directly. Use qdev_is_realized() instead of reading
DeviceState::realized directly.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-3-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Akihiko Odaki
f9aea61a19 qdev: Make qdev_is_realized() take a const DeviceState *
qdev_is_realized() only reads DeviceState. Make its parameter const so a
later caller with a const DeviceState * can use it.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721-qdev-v3-2-d2e226fa002e@rsg.ci.i.u-tokyo.ac.jp>
2026-08-16 16:32:41 +02:00
Marc-André Lureau
d6c6d5500c hw/mem/nvdimm: fix "size" property typename
The getter/setter use visit_type_size().

Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260616-qom-qapi-v2-30-cc9396b9c18c@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-16 10:55:27 +02:00
Philippe Mathieu-Daudé
a2deb54e7e hw/qdev: Remove DEFINE_PROP_DMAADDR() and 'hw/qdev-dma.h'
DEFINE_PROP_DMAADDR() is only used once. Since it doesn't
add much value, simply remove it, along with the header
defining it.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Markus Armbruster <armbru@redhat.com>
Message-Id: <20230203145536.17585-14-philmd@linaro.org>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-08-15 14:06:46 +02:00
Richard Henderson
af06b5df26 qom-qdev queue
-----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQT1gm3ws3USUB3fevcsojbiRimx9AUCan7u7AAKCRAsojbiRimx
 9HMOAP9kaRP4mAWHB7nqezcrJ7r32xcsYblIMUqZttkMs4WKaQD8DnLZfKsJ2rbU
 FAhxwHNeoiltolQj/LK4DhDELVSoYwc=
 =zSFV
 -----END PGP SIGNATURE-----

Merge tag 'qom-qdev-20260814' of https://gitlab.com/mcayland-ntx/qemu into staging

qom-qdev queue

# -----BEGIN PGP SIGNATURE-----
#
# iHUEABYKAB0WIQT1gm3ws3USUB3fevcsojbiRimx9AUCan7u7AAKCRAsojbiRimx
# 9HMOAP9kaRP4mAWHB7nqezcrJ7r32xcsYblIMUqZttkMs4WKaQD8DnLZfKsJ2rbU
# FAhxwHNeoiltolQj/LK4DhDELVSoYwc=
# =zSFV
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri 14 Aug 2026 03:33:16 AM PDT
# gpg:                using EDDSA key F5826DF0B37512501DDF7AF72CA236E24629B1F4
# gpg: Good signature from "Mark Cave-Ayland (Nutanix) <mark.caveayland@nutanix.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: F582 6DF0 B375 1250 1DDF  7AF7 2CA2 36E2 4629 B1F4

* tag 'qom-qdev-20260814' of https://gitlab.com/mcayland-ntx/qemu:
  qom/object.c: rename object_class_property_uint*_ptr() to object_class_static_property_uint*_ptr()
  qom/object.h: add missing documentation for object_class_* property functions
  qom/object.h: rename @child to @targetp in object_property_add_link() documentation
  qom/object.c: introduce DEFINE_OBJECT_PROPERTY_SCALAR_METHODS() macro
  qom/object.c: introduce OBJECT_PROPERTY_SCALAR_SETTER(type) macro
  qom/object.c: introduce OBJECT_PROPERTY_SCALAR_GETTER(type) macro

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-14 08:44:51 -07:00
Richard Henderson
cd43599705 * Some minor updates to the functional testing framework
* Fix a guest-triggerable abort() in the usb uas code
 * Fix a guest-triggerable abort() in the vmxnet3 code
 * Fix a undefined behavior problem in the amd_iommu code
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEJ7iIR+7gJQEY8+q5LtnXdP5wLbUFAmp+6F8ACgkQLtnXdP5w
 LbUUCQ//dxC+zK3zIgi7/X0kEGrfosCrCQBbpEGLQi+o9NRoG5H8hWt7ucjiS2Z0
 qGqqNvoEVMKxT1cCLmELOuVtxm2hG0GQP+w7MUGZaFnmm/Jl0w8AGSd8DEWSiujt
 0hLgLyHBzDMnZOJMSCosyPq+QIg8yukeGBsuRksJZtgNy/VWTUG59qcT781TC8bg
 il8yyPWl+U4YjwsAWwLdPJtS1Dbk9gNTpJbDwJ19S3ZKZ/6jca06ycTwHMEb+3Zf
 Ht/+18XkFxn2O661ijF5RO0toFYrkUW0SHWssya3KFguwXCWTe2aMkXVkwqJRXcQ
 EJIhQxIh+YtbZ4OI+SG9caYG1MXi3If6bX7NFTdD18PhvGkDTT49GkwCkM2EphYg
 yRZ7l+zpe+VBYIY1e2nzVDe1pmVek4cKv4Zwd0eO8ONHQKqd7Sz2F0G/1ixgMbCS
 lM9KeZ5+aoIexPorxwjC+SHXb0jQnlWuuKZEmSrbyjBP3EdgYNXBn1g/tJ8sEAxQ
 KihKyKqlggm0Jg3TY8e6+0YTjQu2yVrPqkNeirxhaTIwYMsihesDs+xwZiJ4TVOf
 2udZDD7clJ+JK7UFPUIYOJ1YWcg1IH4bEYOEWYD4DuVnRmXEQdyDebtSkKUVwO7O
 w3hS7+KHE7INcmPgTwtE4uwqXZfAeraXptAJyhxPDGuHNZfmJyc=
 =ozrV
 -----END PGP SIGNATURE-----

Merge tag 'pull-request-2026-08-14' of https://gitlab.com/thuth/qemu into staging

* Some minor updates to the functional testing framework
* Fix a guest-triggerable abort() in the usb uas code
* Fix a guest-triggerable abort() in the vmxnet3 code
* Fix a undefined behavior problem in the amd_iommu code

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEJ7iIR+7gJQEY8+q5LtnXdP5wLbUFAmp+6F8ACgkQLtnXdP5w
# LbUUCQ//dxC+zK3zIgi7/X0kEGrfosCrCQBbpEGLQi+o9NRoG5H8hWt7ucjiS2Z0
# qGqqNvoEVMKxT1cCLmELOuVtxm2hG0GQP+w7MUGZaFnmm/Jl0w8AGSd8DEWSiujt
# 0hLgLyHBzDMnZOJMSCosyPq+QIg8yukeGBsuRksJZtgNy/VWTUG59qcT781TC8bg
# il8yyPWl+U4YjwsAWwLdPJtS1Dbk9gNTpJbDwJ19S3ZKZ/6jca06ycTwHMEb+3Zf
# Ht/+18XkFxn2O661ijF5RO0toFYrkUW0SHWssya3KFguwXCWTe2aMkXVkwqJRXcQ
# EJIhQxIh+YtbZ4OI+SG9caYG1MXi3If6bX7NFTdD18PhvGkDTT49GkwCkM2EphYg
# yRZ7l+zpe+VBYIY1e2nzVDe1pmVek4cKv4Zwd0eO8ONHQKqd7Sz2F0G/1ixgMbCS
# lM9KeZ5+aoIexPorxwjC+SHXb0jQnlWuuKZEmSrbyjBP3EdgYNXBn1g/tJ8sEAxQ
# KihKyKqlggm0Jg3TY8e6+0YTjQu2yVrPqkNeirxhaTIwYMsihesDs+xwZiJ4TVOf
# 2udZDD7clJ+JK7UFPUIYOJ1YWcg1IH4bEYOEWYD4DuVnRmXEQdyDebtSkKUVwO7O
# w3hS7+KHE7INcmPgTwtE4uwqXZfAeraXptAJyhxPDGuHNZfmJyc=
# =ozrV
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri 14 Aug 2026 03:05:19 AM PDT
# gpg:                using RSA key 27B88847EEE0250118F3EAB92ED9D774FE702DB5
# gpg: Good signature from "Thomas Huth <th.huth@gmx.de>" [unknown]
# gpg:                 aka "Thomas Huth <thuth@redhat.com>" [unknown]
# gpg:                 aka "Thomas Huth <th.huth@posteo.de>" [unknown]
# gpg:                 aka "Thomas Huth <huth@tuxfamily.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 27B8 8847 EEE0 2501 18F3  EAB9 2ED9 D774 FE70 2DB5

* tag 'pull-request-2026-08-14' of https://gitlab.com/thuth/qemu:
  hw/i386/amd_iommu: Avoid undefined behavior in amdvi_setevent_bits()
  hw/net/vmxnet3: Do not abort if guest provides bad interrupt numbers
  hw/usb/dev-uas: Don't abort if guest provided an undersized buffer for status
  tests/testcase.py: passthrough monitor_address
  tests/functional/qemu_test: drop *args argument from .get_vm()
  tests/functional: add skipWithoutSudo() decorator

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-14 08:43:56 -07:00
Richard Henderson
d1aadaaa55 IDE patches
- fix a main-loop deadlock when an ATAPI PIO read spanning several
   sectors is in flight while a drain starts: the nested sector fetch
   was issued synchronously from inside the completion of the first
   read and queued behind the drain, which then never finished
 - read the whole ATAPI elementary transfer in one asynchronous
   request instead, removing cd_read_sector_sync()
 - extend the IDE/AHCI qtest coverage of ATAPI CD reads: parametrized
   read helper, multi-sector DMA, raw 2352-byte READ CD on both
   delivery paths, and a regression test for the deadlock above
 
 Changes since v2:
 - resend: the v2 tag was never pushed, so the tree advertised in that
   pull request could not be fetched
 - rebased onto current master, no code changes
 
 Changes since v1:
 - MAINTAINERS patch dropped
 - spare blank line no longer added and removed within the series
 
 NOTE: 'hw/ide: Don't divide by zero if guest specifies 0 sectors requires'
 is not ready for me, skipped from this submission.
 
 Signed-off-by: Denis V. Lunev <den@openvz.org>
 CC: Richard Henderson <richard.henderson@linaro.org>
 CC: Stefan Hajnoczi <stefanha@redhat.com>
 CC: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEC66qh9MCCtwRUOUfXgdxtstmbKsFAmp+FQIACgkQXgdxtstm
 bKuM9A/9HcPhTCHlS+kmZO7XofHtTcLDfU4srvMFtGwf0v9uZ5v8hD38vs1RShEv
 NXwY0ENjXxkuNy+lJEwLqBIJga6l4UrmO0aSoGdWN2vbVAKA0KAkdozYQCihstxE
 qlJhXoqwaPTfbT1EMCbYdaNohDatlyZQA8AsXszuU7SX4sYzPBqO3F3nWSzqqYtM
 uP/nlbsEflvjCIO0P/orcwnNchEGqaIGyeeIfiR4JgqYLkz3qQ/m9ay11M8TBl4i
 97Oh8Xn/0Bs+qWNoU5JugzF0YgMl+M4aDvq15hRvcn8yYtWp2xIpIAyCE69VCoLM
 U6CvBh5DzaJ+zkiPvUrVms6qfSWfjJ3C9PDKf8jEVy6iEmmHNyVpGg/VM09WApnX
 jxxZuT/O0WsHGCITxtpaxoNHXYBcxj6L3gbs0jyTuWBenCLSxT9jyeDgbcG8sK6x
 scIKAkVb9W+0pSsJcMiHVMN3gS1Jak1wf9nU2v2Ij0E6coD0cN84miD1iGybnVDa
 uT4B5bZ6VxR42B64qwSiOcp/2wkxXE5RTxpMK+/M4G7S70uUaXr3rMkONJ8JVfbq
 3mAxxwwLUM0UmYmKtymzyM1yD9c2G0qMvTQ4OWM1wssRHWY1Pdb9hM/Nhu7+NiXt
 JUQGPp2/RC7BP6X7/LmEyYWaLo1frFAcRKaVgDXzCyoO4vTh+Xc=
 =emKZ
 -----END PGP SIGNATURE-----

Merge tag 'pull-ide-2026-08-13' of https://gitlab.com/dlunev/qemu into staging

IDE patches

- fix a main-loop deadlock when an ATAPI PIO read spanning several
  sectors is in flight while a drain starts: the nested sector fetch
  was issued synchronously from inside the completion of the first
  read and queued behind the drain, which then never finished
- read the whole ATAPI elementary transfer in one asynchronous
  request instead, removing cd_read_sector_sync()
- extend the IDE/AHCI qtest coverage of ATAPI CD reads: parametrized
  read helper, multi-sector DMA, raw 2352-byte READ CD on both
  delivery paths, and a regression test for the deadlock above

Changes since v2:
- resend: the v2 tag was never pushed, so the tree advertised in that
  pull request could not be fetched
- rebased onto current master, no code changes

Changes since v1:
- MAINTAINERS patch dropped
- spare blank line no longer added and removed within the series

NOTE: 'hw/ide: Don't divide by zero if guest specifies 0 sectors requires'
is not ready for me, skipped from this submission.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Richard Henderson <richard.henderson@linaro.org>
CC: Stefan Hajnoczi <stefanha@redhat.com>
CC: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEC66qh9MCCtwRUOUfXgdxtstmbKsFAmp+FQIACgkQXgdxtstm
# bKuM9A/9HcPhTCHlS+kmZO7XofHtTcLDfU4srvMFtGwf0v9uZ5v8hD38vs1RShEv
# NXwY0ENjXxkuNy+lJEwLqBIJga6l4UrmO0aSoGdWN2vbVAKA0KAkdozYQCihstxE
# qlJhXoqwaPTfbT1EMCbYdaNohDatlyZQA8AsXszuU7SX4sYzPBqO3F3nWSzqqYtM
# uP/nlbsEflvjCIO0P/orcwnNchEGqaIGyeeIfiR4JgqYLkz3qQ/m9ay11M8TBl4i
# 97Oh8Xn/0Bs+qWNoU5JugzF0YgMl+M4aDvq15hRvcn8yYtWp2xIpIAyCE69VCoLM
# U6CvBh5DzaJ+zkiPvUrVms6qfSWfjJ3C9PDKf8jEVy6iEmmHNyVpGg/VM09WApnX
# jxxZuT/O0WsHGCITxtpaxoNHXYBcxj6L3gbs0jyTuWBenCLSxT9jyeDgbcG8sK6x
# scIKAkVb9W+0pSsJcMiHVMN3gS1Jak1wf9nU2v2Ij0E6coD0cN84miD1iGybnVDa
# uT4B5bZ6VxR42B64qwSiOcp/2wkxXE5RTxpMK+/M4G7S70uUaXr3rMkONJ8JVfbq
# 3mAxxwwLUM0UmYmKtymzyM1yD9c2G0qMvTQ4OWM1wssRHWY1Pdb9hM/Nhu7+NiXt
# JUQGPp2/RC7BP6X7/LmEyYWaLo1frFAcRKaVgDXzCyoO4vTh+Xc=
# =emKZ
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 13 Aug 2026 12:03:30 PM PDT
# gpg:                using RSA key 0BAEAA87D3020ADC1150E51F5E0771B6CB666CAB
# gpg: Good signature from "Denis V. Lunev <den@openvz.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 0BAE AA87 D302 0ADC 1150  E51F 5E07 71B6 CB66 6CAB

* tag 'pull-ide-2026-08-13' of https://gitlab.com/dlunev/qemu:
  tests/qtest/ahci: regression test for ATAPI read vs. drain
  hw/ide/atapi: read the whole elementary transfer asynchronously
  tests/qtest/ahci: cover raw (2352-byte) ATAPI CD reads
  tests/qtest/libqos/ahci: support raw (2352-byte) READ CD
  tests/qtest/ide-test: cover raw (2352-byte) ATAPI CD reads
  tests/qtest/ide-test: add a multi-sector ATAPI DMA read test
  tests/qtest/ide-test: parametrize the ATAPI CD-ROM read test

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-14 08:43:15 -07:00
Mark Cave-Ayland
6b97f3d4d6 qom/object.c: rename object_class_property_uint*_ptr() to object_class_static_property_uint*_ptr()
This more accurately reflects that these properties are held within the class and
not the object. Update the documentation to describe the few cases where static
properties should be used.

Signed-off-by: Mark Cave-Ayland <mark.caveayland@nutanix.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Message-Id: <20260717135254.508701-7-mark.caveayland@nutanix.com>
2026-08-14 11:31:18 +01:00
Mark Cave-Ayland
478542dd83 qom/object.h: add missing documentation for object_class_* property functions
This is so that the object_class_* property functions appear in the generated
QOM documentation at devel/qom-api.html.

Signed-off-by: Mark Cave-Ayland <mark.caveayland@nutanix.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Message-Id: <20260717135254.508701-6-mark.caveayland@nutanix.com>
2026-08-14 11:31:18 +01:00
Mark Cave-Ayland
504be94fe3 qom/object.h: rename @child to @targetp in object_property_add_link() documentation
This was missed when updating the parameter name in commit 36854207f0 ("object:
rename link "child" to "target"").

Signed-off-by: Mark Cave-Ayland <mark.caveayland@nutanix.com>
Fixes: 36854207f0 ("object: rename link "child" to "target"")
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Message-Id: <20260717135254.508701-5-mark.caveayland@nutanix.com>
2026-08-14 11:31:18 +01:00
Mark Cave-Ayland
361a15cff8 qom/object.c: introduce DEFINE_OBJECT_PROPERTY_SCALAR_METHODS() macro
This macro defines both the QOM get and set functions for the given scaler
type. Replace the combined use of OBJECT_PROPERTY_SCALAR_GETTER() and
OBJECT_PROPERTY_SCALAR_SETTER() with the new macro.

Signed-off-by: Mark Cave-Ayland <mark.caveayland@nutanix.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-Id: <20260717135254.508701-4-mark.caveayland@nutanix.com>
2026-08-14 11:31:18 +01:00
Mark Cave-Ayland
5f8edcbc3c qom/object.c: introduce OBJECT_PROPERTY_SCALAR_SETTER(type) macro
This macro can be used to generate the boilerplate property_set_type_ptr()
QOM set function for the specified scalar type. Replace the existing scaler set
functions with the new macro.

Signed-off-by: Mark Cave-Ayland <mark.caveayland@nutanix.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Message-Id: <20260717135254.508701-3-mark.caveayland@nutanix.com>
2026-08-14 11:31:18 +01:00
Mark Cave-Ayland
167882fe86 qom/object.c: introduce OBJECT_PROPERTY_SCALAR_GETTER(type) macro
This macro can be used to generate the boilerplate property_get_type_ptr()
QOM get function for the specified scalar type. Replace the existing scaler get
functions with the new macro.

Signed-off-by: Mark Cave-Ayland <mark.caveayland@nutanix.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Message-Id: <20260717135254.508701-2-mark.caveayland@nutanix.com>
2026-08-14 11:31:18 +01:00
Thomas Huth
4adfb431c0 hw/i386/amd_iommu: Avoid undefined behavior in amdvi_setevent_bits()
The code in amdvi_encode_event() calls amdvi_setevent_bits() with
start = 64:

    amdvi_setevent_bits(evt, addr, 64, 64);

and amdvi_setevent_bits() then calculates:

    uint64_t mask = MAKE_64BIT_MASK(start, length);

but this MAKE_64BIT_MASK() macro shifts a value left by "start" bit
positions. Shifting left by more than 63 is undefined behavior and
could have unexpected results with different compilers / architectures.

Fix it by using "bitpos" instead, which was likely the original
intended behavior anyway. (bitpos is calculated as bitpos = start % 64).

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3633
Fixes: 1d5b128cbe ("hw/iommu: Fix problems reported by Coverity scan")
Reviewed-by: Alejandro Jimenez <alejandro.j.jimenez@oracle.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260731140229.259272-1-thuth@redhat.com>
2026-08-14 09:14:58 +02:00
Thomas Huth
46099d9900 hw/net/vmxnet3: Do not abort if guest provides bad interrupt numbers
vmxnet3_validate_interrupts() currently aborts via hw_error() if
the guest provided bad interrupt numbers. This should not happen,
QEMU should rather refuse to activate the device in this case instead.
Thus propagate the error to the callers to handle it more gracefully
there.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/539
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260731113352.189066-1-thuth@redhat.com>
2026-08-14 09:14:58 +02:00
Thomas Huth
15700a66ec hw/usb/dev-uas: Don't abort if guest provided an undersized buffer for status
QEMU currently aborts if the guest provides an undersized buffer
for the status packet (8 bytes):

 hw/usb/core.c:623: usb_packet_copy:
  Assertion `p->actual_length + bytes <= iov->size' failed.

If we hit this situation, log a guest error and continue by simply
only providing the bytes that the guest asked for.
(Note: This is e.g. similar to the UAS_PIPE_ID_COMMAND case that
also clamps the length with: length = MIN(sizeof(iu), p->iov.size))

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3900
Reported-by: Feifan Qian <bea1e@proton.me>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260730163901.1154791-1-thuth@redhat.com>
2026-08-14 09:14:58 +02:00
Vladimir Sementsov-Ogievskiy
ba6741f63d tests/testcase.py: passthrough monitor_address
We'll need it soon to implement test for cpr-exec mode of
tap-fd-migration.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260729093146.1893719-5-vsementsov@yandex-team.ru>
Signed-off-by: Thomas Huth <thuth@redhat.com>
2026-08-14 09:14:58 +02:00
Vladimir Sementsov-Ogievskiy
c347711ea7 tests/functional/qemu_test: drop *args argument from .get_vm()
It's redundant. Only one caller use it, and it may be simply
substituted by .add_args().

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260729093146.1893719-3-vsementsov@yandex-team.ru>
Signed-off-by: Thomas Huth <thuth@redhat.com>
2026-08-14 09:14:58 +02:00
Vladimir Sementsov-Ogievskiy
ac84b9ec96 tests/functional: add skipWithoutSudo() decorator
To be used in the next commit: that would be a test for TAP
networking, and it will need to setup TAP device.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Thomas Huth <thuth@redhat.com>
Tested-by: Lei Yang <leiyang@redhat.com>
Reviewed-by: Maksim Davydov <davydov-max@yandex-team.ru>
Reviewed-by: Ben Chaney <bchaney@akamai.com>
Message-ID: <20260729091334.1863155-15-vsementsov@yandex-team.ru>
Signed-off-by: Thomas Huth <thuth@redhat.com>
2026-08-14 09:14:58 +02:00
Denis V. Lunev
be1ee6a8f6 tests/qtest/ahci: regression test for ATAPI read vs. drain
Add /ahci/cdrom/drain/{pio,dma}: issue a multi-sector ATAPI read whose
byte-count limit spans two sectors so the device must rebuffer in the
middle of the DRQ burst, hold the backend read in flight with a
blkdebug delay, and fire x-blockdev-set-iothread -- which runs
bdrv_drain_all_begin() exactly like a guest reset does through
virtio_blk_stop_ioeventfd().

On the unfixed PIO path the nested sector fetch is queued behind the
drain and the main loop wedges, so the test hangs. The DMA variant
never rebuffers and serves as a sanity twin.

Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-13 20:59:49 +02:00
Denis V. Lunev
12289dc700 hw/ide/atapi: read the whole elementary transfer asynchronously
An ATAPI PIO read whose byte-count limit spans more than one CD sector
must fetch the later sectors of a DRQ burst from inside the completion
of the first, asynchronous read. cd_read_sector_sync() did this with a
synchronous blk_pread(), which runs blk_wait_while_drained() before
issuing the request.

If a drain is in progress when that completion runs -- as happens when
a guest reset reaches virtio_blk_stop_ioeventfd() ->
bdrv_drain_all_begin() while an ATAPI read is in flight on the same
QEMU -- the nested read is queued until the drained section ends while
the outer completion still holds blk->in_flight. bdrv_drain_all_begin()
then waits forever for that in_flight count to drop: the main loop is
wedged in the drain with the BQL held, and every other QMP/monitor
operation blocks behind it.

Read the whole elementary transfer in a single asynchronous request up
front instead, so no read is ever issued in the middle of a burst.
cd_read_sector() now reads all the sectors a burst spans (the raw
2352-byte case is unpacked in place on completion) and
cd_read_sector_sync() is removed. The DMA path already batched its
reads and is unchanged.

Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-13 20:59:49 +02:00
Denis V. Lunev
31f13e71af tests/qtest/ahci: cover raw (2352-byte) ATAPI CD reads
Add /ahci/cdrom/{pio,dma}/raw: read several sectors with READ CD in
raw mode (atapi_raw), so the ATAPI 2352-byte unpack path is exercised
through the AHCI delivery, which IDE coverage does not reach. Each
sector's 2048-byte payload is verified at its in-sector offset.

The PIO case uses a byte-count limit of one raw sector per DRQ burst:
libqos asserts a one-sector PIO transfer, and the multi-sector unpack
loop is already covered by the IDE raw test.

Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-13 20:59:49 +02:00
Denis V. Lunev
de86ef3dfd tests/qtest/libqos/ahci: support raw (2352-byte) READ CD
ahci_exec() always builds ATAPI commands with a 2048-byte logical
sector size, so it cannot drive a READ CD that returns full 2352-byte
raw sectors. Add an atapi_raw option that sets the READ CD
field-selector to 0xf8 and the command's sector size to 2352 before
the transfer is sized, so the derived block count stays correct while
the buffer and byte counts cover the raw sectors.

Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-13 20:59:49 +02:00
Denis V. Lunev
502dbdfd96 tests/qtest/ide-test: cover raw (2352-byte) ATAPI CD reads
READ CD with the field-selector set to 0xf8 returns full 2352-byte
raw sectors (sync + header + 2048 data + EDC/ECC), driving the ATAPI
raw read path that READ10 never touches. Add a send_scsi_cdb_read_cd()
helper and a CDROM_RAW flag to cdrom_read_impl(), then exercise both
PIO and DMA. The PIO case uses a byte-count limit spanning several
raw sectors so the device must rebuffer mid-burst, and each sector's
2048-byte payload is verified at its in-sector offset.

Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-13 20:59:49 +02:00
Denis V. Lunev
fe543c2d78 tests/qtest/ide-test: add a multi-sector ATAPI DMA read test
test_cdrom_pio_large() already exercises a multi-sector PIO read.
Add the DMA counterpart through the same cdrom_read_impl() helper so
the multi-block ATAPI DMA read path gets equivalent coverage.

Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-13 20:59:49 +02:00
Denis V. Lunev
ebec7c7322 tests/qtest/ide-test: parametrize the ATAPI CD-ROM read test
cdrom_pio_impl() and test_cdrom_dma() duplicate the same image setup
and data-integrity check around two different transfer mechanisms.
Fold them into a single cdrom_read_impl(nblocks, flags) helper, with a
CDROM_PIO/CDROM_DMA flag selecting the transfer, so further read
coverage can be added once for both paths.

No functional change: /ide/cdrom/pio, pio_large and dma run exactly
as before.

Signed-off-by: Denis V. Lunev <den@openvz.org>
2026-08-13 20:59:49 +02:00
Richard Henderson
539bc31553 loongarch queue
-----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQQNhkKjomWfgLCz0aQfewwSUazn0QUCan07bAAKCRAfewwSUazn
 0ZduAP9gFsFWHI9HgdeS+y48rLpqDMTK2y8P+WTGTj61nG5UngEA0HlDV+wQGkcA
 WVqq1qafvTFDi/DSYErFmLlvFhUQCA4=
 =Ai1s
 -----END PGP SIGNATURE-----

Merge tag 'pull-loongarch-20260813' of https://github.com/bibo-mao/qemu into staging

loongarch queue

# -----BEGIN PGP SIGNATURE-----
#
# iHUEABYKAB0WIQQNhkKjomWfgLCz0aQfewwSUazn0QUCan07bAAKCRAfewwSUazn
# 0ZduAP9gFsFWHI9HgdeS+y48rLpqDMTK2y8P+WTGTj61nG5UngEA0HlDV+wQGkcA
# WVqq1qafvTFDi/DSYErFmLlvFhUQCA4=
# =Ai1s
# -----END PGP SIGNATURE-----
# gpg: Signature made Wed 12 Aug 2026 08:35:08 PM PDT
# gpg:                using EDDSA key 0D8642A3A2659F80B0B3D1A41F7B0C1251ACE7D1
# gpg: Good signature from "bibo mao <maobibo@loongson.cn>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 7044 3A00 19C0 E97A 31C7  13C4 8E86 8FB7 A176 9D4C
#      Subkey fingerprint: 0D86 42A3 A265 9F80 B0B3  D1A4 1F7B 0C12 51AC E7D1

* tag 'pull-loongarch-20260813' of https://github.com/bibo-mao/qemu:
  target/loongarch: Set timer tick value even if disabled
  tests/acpi: Update LoongArch virt MADT
  hw/loongarch/virt: Set MADT revision to 6
  tests/acpi: Allow LoongArch virt MADT changes
  hw/intc/loongarch_pch_pic: Validate htmsi_vector before indexing parent_irq

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-13 07:16:25 -07:00
Richard Henderson
42f8118926 migration/mem pull for 11.2
v2: fixes macos build error
 
 - Dongli's patch to add cpr-transfer support for HMP
 - Fabiano's doc update for migration on security issues
 - Gavin's fix for MMIO access support for memory APIs, reverting ram_device ops
 - Sam's migration test build fix for !ASN1
 - Peter's a few migration hardening fixes
 -----BEGIN PGP SIGNATURE-----
 
 iIgEABYKADAWIQS5GE3CDMRX2s990ak7X8zN86vXBgUCan3KARIccGV0ZXJ4QHJl
 ZGhhdC5jb20ACgkQO1/MzfOr1wa76QD/eBLnPtDvmpNHNH3+bm/3XC3zwyy7v69U
 bGK3ocwI3sQA/j9o5FCc7xDCA0QaW6RMeerlLXvXR0uwH46UESKKDloF
 =/Jbs
 -----END PGP SIGNATURE-----

Merge tag 'next-pull-request' of https://gitlab.com/peterx/qemu into staging

migration/mem pull for 11.2

v2: fixes macos build error

- Dongli's patch to add cpr-transfer support for HMP
- Fabiano's doc update for migration on security issues
- Gavin's fix for MMIO access support for memory APIs, reverting ram_device ops
- Sam's migration test build fix for !ASN1
- Peter's a few migration hardening fixes

# -----BEGIN PGP SIGNATURE-----
#
# iIgEABYKADAWIQS5GE3CDMRX2s990ak7X8zN86vXBgUCan3KARIccGV0ZXJ4QHJl
# ZGhhdC5jb20ACgkQO1/MzfOr1wa76QD/eBLnPtDvmpNHNH3+bm/3XC3zwyy7v69U
# bGK3ocwI3sQA/j9o5FCc7xDCA0QaW6RMeerlLXvXR0uwH46UESKKDloF
# =/Jbs
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 13 Aug 2026 06:43:29 AM PDT
# gpg:                using EDDSA key B9184DC20CC457DACF7DD1A93B5FCCCDF3ABD706
# gpg:                issuer "peterx@redhat.com"
# gpg: Good signature from "Peter Xu <xzpeter@gmail.com>" [unknown]
# gpg:                 aka "Peter Xu <peterx@redhat.com>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: B918 4DC2 0CC4 57DA CF7D  D1A9 3B5F CCCD F3AB D706

* tag 'next-pull-request' of https://gitlab.com/peterx/qemu:
  migration: Fix rare hang of migration_channel_read_peek()
  migration/ram: Check for RAMBlock size mismatch when parsing
  migration/multifd: Replace assert() with error_setg() in recv paths
  migration/multifd: Validate next_packet_size in zlib/zstd recv
  tests/qtest/migration: Only build tls_no_hostname test with TASN1
  system/memory: Make ram device region directly accessible
  system/memory: Use qemu_ram_move() for directly accessible regions
  system/memory: Use memmove() for directly accessible regions
  migration/cpr: Add HMP support for cpr-transfer
  docs: Add security considerations for migration

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-13 07:14:33 -07:00
Peter Xu
89f15c1362 migration: Fix rare hang of migration_channel_read_peek()
In an unlikely case, when a migration stream is attached to the destination
QEMU and only send <4 bytes to the channel as magic, it's possible that
migration_channel_read_peek() may spin forever.

Fix it by adding a manual sleep for partial read.

Since the path isn't attached to a coroutine, it means when partial read
happens, there's yet not much we can do but hang the main thread, it will
happen even for len==0 case.  It means monitors can hang due to this,
either partial read or no data arrived (but connection established).

Leave this for later, the hope is this is extremely rare in production.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3889
Reported-by: Feifan Qian <bea1e@proton.me>
Cc: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Link: https://lore.kernel.org/r/20260812124327.2572363-1-peterx@redhat.com
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-08-13 09:41:40 -04:00
Peter Xu
10dd206e92 migration/ram: Check for RAMBlock size mismatch when parsing
Add an underflow check for the subtract of total RAMBlock size to make sure
it won't underflow.  It should not happen in production systems but only if
the migration stream was hijacked, which is not a real concern since
migration channel is trusted.  Still protect against it.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4013
Reported-by: Tristan Madani <tristan@talencesecurity.com>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Link: https://lore.kernel.org/r/20260728210417.1925078-6-peterx@redhat.com
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-08-13 09:41:40 -04:00
Bibo Mao
77b91aca61 target/loongarch: Set timer tick value even if disabled
If constant timer is enabled, its tick value is remained value from
the next expired time. However if timer is not enabled, its value
should be CONSTANT_TIMER_TICK_MASK or zero.

Signed-off-by: Bibo Mao <maobibo@loongson.cn>
Reviewed-by: Xianglai Li <lixianglai@loongson.cn>
2026-08-13 11:34:48 +08:00
Dongyan Qian
c94267793c tests/acpi: Update LoongArch virt MADT
Regenerate the APIC and APIC.topology test data after correcting the
LoongArch virt MADT revision.

The generated tables change only Header.Revision from 1 to 6 and the
corresponding checksum. Their lengths and interrupt controller
subtables remain unchanged.

Signed-off-by: Dongyan Qian <qiandongyan@loongson.cn>
Signed-off-by: Bibo Mao <maobibo@loongson.cn>
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
2026-08-13 11:34:48 +08:00
Dongyan Qian
9583a9c07d hw/loongarch/virt: Set MADT revision to 6
The LoongArch virt machine emits Core PIC, EIO PIC, MSI PIC and BIO PIC
subtables, but advertises MADT revision 1. Revision 1 predates these
LoongArch interrupt controller structures.

ACPI 6.5 introduced the LoongArch interrupt controller structures and
defined MADT revision 6. ACPI 6.6 raises the MADT revision to 7 for the
additional RISC-V interrupt controller structures, while leaving the
LoongArch structures unchanged.

Since the virt machine emits only the LoongArch structures defined by
ACPI 6.5, set the MADT header revision to 6, the minimum revision that
describes the table contents.

Fixes: 735143f10d ("hw/loongarch: Add acpi ged support")
Signed-off-by: Dongyan Qian <qiandongyan@loongson.cn>
Signed-off-by: Bibo Mao <maobibo@loongson.cn>
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
2026-08-13 11:34:48 +08:00
Dongyan Qian
181b584b77 tests/acpi: Allow LoongArch virt MADT changes
The LoongArch virt MADT revision will be corrected to match the
interrupt controller structures it contains.

Allow the APIC and APIC.topology test data to change so that the source
change can be reviewed separately from the regenerated binary tables.

Signed-off-by: Dongyan Qian <qiandongyan@loongson.cn>
Signed-off-by: Bibo Mao <maobibo@loongson.cn>
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
2026-08-13 11:34:47 +08:00
Bin Guo
80776c4df9 hw/intc/loongarch_pch_pic: Validate htmsi_vector before indexing parent_irq
pch_pic_update_irq() used the guest-writable htmsi_vector[irq] value as an
index into parent_irq[] without checking bounds.  A value >= irq_num (64 in
the array, but only 32 are used by the virt machine) causes an out-of-bounds
read and a guest-triggerable QEMU crash.

Validate the vector before calling qemu_set_irq() in both the raise and lower
paths and log a guest error if it is out of range.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4114
Cc: qemu-stable@nongnu.org
Signed-off-by: Bin Guo <guobin@linux.alibaba.com>
Signed-off-by: Bibo Mao <maobibo@loongson.cn>
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
2026-08-13 11:34:47 +08:00
Richard Henderson
8402bdd56e First batch of s390x updates for 11.2:
- compat machines for 11.2
  - allow guest backing with 2G hugepages
  - fixes to TCG (and a couple tests on them)
  - hardening fixes in boot/sclp code
  - regenerate s390-ccw.img
 -----BEGIN PGP SIGNATURE-----
 
 iIsEABYKADMWIQQB3Dhbwk4ZE3uUN6KmTx4R4Fx3tAUCanygMxUcZmFybWFuQGxp
 bnV4LmlibS5jb20ACgkQpk8eEeBcd7RMqwEAzBhcnvUDHowDalVgBJ4QTWcbUx2D
 dZgoMvFpFYB2aEsA/32H81TzvrwX4xAkJlqdGIrQbPGmtdvAOKfjketAjGMC
 =lFhB
 -----END PGP SIGNATURE-----

Merge tag 's390x-20260812' of https://gitlab.com/efarman/qemu into staging

First batch of s390x updates for 11.2:
 - compat machines for 11.2
 - allow guest backing with 2G hugepages
 - fixes to TCG (and a couple tests on them)
 - hardening fixes in boot/sclp code
 - regenerate s390-ccw.img

# -----BEGIN PGP SIGNATURE-----
#
# iIsEABYKADMWIQQB3Dhbwk4ZE3uUN6KmTx4R4Fx3tAUCanygMxUcZmFybWFuQGxp
# bnV4LmlibS5jb20ACgkQpk8eEeBcd7RMqwEAzBhcnvUDHowDalVgBJ4QTWcbUx2D
# dZgoMvFpFYB2aEsA/32H81TzvrwX4xAkJlqdGIrQbPGmtdvAOKfjketAjGMC
# =lFhB
# -----END PGP SIGNATURE-----
# gpg: Signature made Wed 12 Aug 2026 09:32:51 AM PDT
# gpg:                using EDDSA key 01DC385BC24E19137B9437A2A64F1E11E05C77B4
# gpg:                issuer "farman@linux.ibm.com"
# gpg: Good signature from "Eric Farman <farman@linux.ibm.com>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: D2C6 0504 C9E8 F568 CFE5  87B5 3827 B212 71BF 9562
#      Subkey fingerprint: 01DC 385B C24E 1913 7B94  37A2 A64F 1E11 E05C 77B4

* tag 's390x-20260812' of https://gitlab.com/efarman/qemu:
  pc-bios/s390-ccw.img: update s390x bios
  hw: add compat machines for 11.2
  target/s390x: Allow 2G hugepages guest backing
  tests/tcg/s390x: Test STCKF condition code on a faulting store
  target/s390x/tcg: Set STCK/STCKF condition code after the store
  pc-bios/s390-ccw: Fix off-by-one errors with loadparm and boot entries
  pc-bios/s390-ccw: bound zipl menu strlen and replace VLA in zipl_print_entry
  pc-bios/s390-ccw: bounds-check zipl menu entry index before array write
  pc-bios/s390-ccw: fix out-of-bounds read in iso_get_file_size()
  s390x/ipl: validate num_comp against iplb length before iterating
  hw/char/sclpconsole-lm: avoid guest triggerable assert
  tests/tcg/s390x: Test DR overflow (INT64_MIN / -1)
  target/s390x: Fix DR/D INT64_MIN / -1 host crash
  tests/tcg/s390x: Test PRNO TRNG interruptibility
  target/s390x: Make PRNO TRNG interruptible

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-12 18:48:06 -07:00
Richard Henderson
d49f87606a linux-user patches
Patches from Mat Turner to support the mount_setattr() syscall and to add
 floating-point registers to core dumps on alpha, mips, hppa, riscv and sh4.
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCanzZYQAKCRD3ErUQojoP
 X+x4AP9UqX4OuUUZy+HA33eW+54JIT9xfF88VnU6VhZdQpPhlQEA3cYz393TjIpT
 uXlgPvwCVa6C3/qUSq//00v3KQsF+Q0=
 =4lE3
 -----END PGP SIGNATURE-----

Merge tag 'linux-user-pull-request' of https://github.com/hdeller/qemu-hppa into staging

linux-user patches

Patches from Mat Turner to support the mount_setattr() syscall and to add
floating-point registers to core dumps on alpha, mips, hppa, riscv and sh4.

# -----BEGIN PGP SIGNATURE-----
#
# iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCanzZYQAKCRD3ErUQojoP
# X+x4AP9UqX4OuUUZy+HA33eW+54JIT9xfF88VnU6VhZdQpPhlQEA3cYz393TjIpT
# uXlgPvwCVa6C3/qUSq//00v3KQsF+Q0=
# =4lE3
# -----END PGP SIGNATURE-----
# gpg: Signature made Wed 12 Aug 2026 01:36:49 PM PDT
# gpg:                using EDDSA key BCE9123E1AD29F07C049BBDEF712B510A23A0F5F
# gpg: Good signature from "Helge Deller <deller@gmx.de>" [unknown]
# gpg:                 aka "Helge Deller <deller@kernel.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 4544 8228 2CD9 10DB EF3D  25F8 3E5F 3D04 A7A2 4603
#      Subkey fingerprint: BCE9 123E 1AD2 9F07 C049  BBDE F712 B510 A23A 0F5F

* tag 'linux-user-pull-request' of https://github.com/hdeller/qemu-hppa:
  linux-user/sh4: write the floating-point registers to a core dump
  linux-user/riscv: write the floating-point registers to a core dump
  linux-user/hppa: write the floating-point registers to a core dump
  linux-user/mips: write the floating-point registers to a core dump
  linux-user/alpha: write the floating-point registers to a core dump
  linux-user: support writing floating-point registers to a core dump
  linux-user: implement mount_setattr(2)

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-12 15:21:53 -07:00
Richard Henderson
055952c0aa Hexagon queue
Fixes:
 * ssub32_saturate, ssub64_saturate fixes
 
 Features:
 
 * l2vic device
 * qtimer device
 * HVX-IEEE instructions (v68+)
 * HVX GVec overrides for v{avg*,absdiff,sadd,*}
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEPWaq5HRZSCTIjOD4GlSvuOVkbDIFAmp8k4UACgkQGlSvuOVk
 bDJBHg//SKfafuoDX/BLl46aRKD3ESOohRPrMypSdmKxAsPrjKnawVzEtQW7LZha
 U/Ch5wKCpuLZk+ZXXXzVDxaz4rgrbbXtc/jLiJ4EibquFpCRwcIZnQy7+uLXf+DI
 A9tNoCBhWsw8RA/CFPei6tGZjZKLF4eXImf8n9028RwGyX7wGbVP26C1VoVfbegl
 +HOjy2y1Oqmw0DmljFGESSFTyJDEM2Y9SdhyBSrS1fmof24ad0cRiTeoMwNfk1iX
 JoW8+bYteTJ8vLui7RBvDIuk4rHYg5SLk8yqDA3SwzoFuL/jjI612SXM3TIT2ySe
 dgUK4B8XtiqGSYNuQed8TXoTicq3qaKv/zlxDMhpFLl7SV6v+sfhNBxP++gjM8YY
 yuTlNJDppPkorETzvPsVEbS8+Z3xr3EzsqDwYRSMT48XEk26iAyWRLy7EfKsGnUY
 RGe122Hy8oDNXomFTQxWpQ0Nr3fkfh/X+B7ydYGFZbb0Z1shY+7f2Zu9Xefjy7bv
 sdf+bH4bTCSy1/bfG81dPhvYh4JefPEvLOUF6l3ssYeY54asx0yrFy1oipc2Ancw
 sRjD2/10QkDNEnSfwf6v7uUmpvAm4rtY/m8s0fzevst1PxvVOREo2AckK2CYaH6T
 viYpyY881FlyA6zVJTt89ktozzsU9yJmm8zYbE74KPNUs7KV4cU=
 =5k5b
 -----END PGP SIGNATURE-----

Merge tag 'pull-hex-20260812v2-1' of https://github.com/qualcomm/qemu into staging

Hexagon queue

Fixes:
* ssub32_saturate, ssub64_saturate fixes

Features:

* l2vic device
* qtimer device
* HVX-IEEE instructions (v68+)
* HVX GVec overrides for v{avg*,absdiff,sadd,*}

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEPWaq5HRZSCTIjOD4GlSvuOVkbDIFAmp8k4UACgkQGlSvuOVk
# bDJBHg//SKfafuoDX/BLl46aRKD3ESOohRPrMypSdmKxAsPrjKnawVzEtQW7LZha
# U/Ch5wKCpuLZk+ZXXXzVDxaz4rgrbbXtc/jLiJ4EibquFpCRwcIZnQy7+uLXf+DI
# A9tNoCBhWsw8RA/CFPei6tGZjZKLF4eXImf8n9028RwGyX7wGbVP26C1VoVfbegl
# +HOjy2y1Oqmw0DmljFGESSFTyJDEM2Y9SdhyBSrS1fmof24ad0cRiTeoMwNfk1iX
# JoW8+bYteTJ8vLui7RBvDIuk4rHYg5SLk8yqDA3SwzoFuL/jjI612SXM3TIT2ySe
# dgUK4B8XtiqGSYNuQed8TXoTicq3qaKv/zlxDMhpFLl7SV6v+sfhNBxP++gjM8YY
# yuTlNJDppPkorETzvPsVEbS8+Z3xr3EzsqDwYRSMT48XEk26iAyWRLy7EfKsGnUY
# RGe122Hy8oDNXomFTQxWpQ0Nr3fkfh/X+B7ydYGFZbb0Z1shY+7f2Zu9Xefjy7bv
# sdf+bH4bTCSy1/bfG81dPhvYh4JefPEvLOUF6l3ssYeY54asx0yrFy1oipc2Ancw
# sRjD2/10QkDNEnSfwf6v7uUmpvAm4rtY/m8s0fzevst1PxvVOREo2AckK2CYaH6T
# viYpyY881FlyA6zVJTt89ktozzsU9yJmm8zYbE74KPNUs7KV4cU=
# =5k5b
# -----END PGP SIGNATURE-----
# gpg: Signature made Wed 12 Aug 2026 08:38:45 AM PDT
# gpg:                using RSA key 3D66AAE474594824C88CE0F81A54AFB8E5646C32
# gpg: Good signature from "Brian Cain (QUIC) <quic_bcain@quicinc.com>" [unknown]
# gpg:                 aka "Brian Cain <bcain@kernel.org>" [unknown]
# gpg:                 aka "Brian Cain (QuIC) <bcain@quicinc.com>" [unknown]
# gpg:                 aka "Brian Cain (CAF) <bcain@codeaurora.org>" [unknown]
# gpg:                 aka "bcain" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 6350 20F9 67A7 7164 79EF  49E0 175C 464E 541B 6D47
#      Subkey fingerprint: 3D66 AAE4 7459 4824 C88C  E0F8 1A54 AFB8 E564 6C32

* tag 'pull-hex-20260812v2-1' of https://github.com/qualcomm/qemu: (41 commits)
  tests/hexagon: add tests for HVX bfloat
  tests/hexagon: add tests for v68 HVX IEEE float comparisons
  tests/hexagon: add tests for v68 HVX IEEE float conversions
  tests/hexagon: add tests for v68 HVX IEEE float min/max
  tests/hexagon: add tests for v68 HVX IEEE float arithmetics
  target/hexagon: add v73 HVX IEEE bfloat16 insns
  target/hexagon: add v68 HVX IEEE float compare insns
  target/hexagon: add v68 HVX IEEE float conversion insns
  target/hexagon: add v68 HVX IEEE float misc insns
  target/hexagon: add v68 HVX IEEE float min/max insns
  target/hexagon: add v68 HVX IEEE float arithmetic insns
  hexagon: print info on "-d in_asm" for disabled IEEE FP instructions
  hexagon: group cpu configurations in their own struct
  target/hexagon/cpu: add HVX IEEE FP extension
  target/hexagon: fix incorrect/too-permissive HVX encodings
  Hexagon (target/hexagon) Clean up disassembly of control and system regs
  tests/tcg/hexagon: add HVX tests for vabsdiff
  tests/tcg/hexagon: add HVX test for V6_vsubwsat saturation
  target/hexagon: add GVec overrides for HVX vector average
  target/hexagon: add GVec overrides for HVX absolute difference
  ...

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-12 09:20:11 -07:00
Richard Henderson
c0b6d0ca16 target-arm queue:
* Implement emulation of FEAT_SME_TMOP
  * New board model: Axiado EVK SCM3003
  * Fix various minor bugs in mps3-an547 model
  * hw/i2c/bcm2835_i2c: Correct iomem size
  * hw/misc/bcm2835_powermgt: implement a real watchdog timer
  * hw/arm/raspi4b: fix guest never seeing more than ~1 GiB of RAM
 -----BEGIN PGP SIGNATURE-----
 
 iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmp8Y+kZHHBldGVyLm1h
 eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3iwKEACaH/Ztj8k5NiH9AVF7+2ii
 SkM2oJoLLyFw2LXgXMnQgzdmMhwW7odsd8xp76prfDIrOZE5uFXAX+7F8I5Vnmcn
 nyHVhqvJlxx+JEVSGLhjmHhJCaqxisbtaFVEdhvBn2r7b5YCcmB9pOaUnMpZI2Mt
 ahXtqiExHZ04Y57JIoOuMOs+JSLn2QoMlUy3aP0BetyVfDyfxjU/8XnVQnDWec1J
 Df+QWgFdHhOlb8vy6lurrdDC8Q5F0nEKTHfq5aCl4DjpOg4uMzqHQ4GFdxHDlhGi
 2z+Toyq/I2dBKebv0tWdLjcDMkLrmfNZcIs5VPsm+vvQyt2wN5rFnJKAMYcmN4BS
 7Z8C1RBPnsSZaYCeh97oCipce1WeGPpPjKlfBqMwdF95jBnn/zMGULmxB/W2Ays/
 gKD9RpKmvfUZNQ9JRFr/u+vNvvY2xki1u3yB0F0j+f8ggp8PxpHli7gxlA3x9PyZ
 AhmDj6JK0+zciPlC6FnSVTipNE8ZGU8XN8DCp4LNU5zye3aDtoCCmJwVVryYeRBT
 bq7kj2En13pP66OZUAb1MRu2gnwIuq0GZwQ3aYtWqe8DxcVa7r2fGxaRR0GDjY+r
 l1SzSd5CCExpaLi4c3FO6sz12jHfzRLjKtULEyv/37kVNbI+SpOj6UwCQAgAYTz8
 Gq/mTm1heDXTDjcwEp6lQQ==
 =ILzl
 -----END PGP SIGNATURE-----

Merge tag 'pull-target-arm-20260812' of https://gitlab.com/pm215/qemu into staging

target-arm queue:
 * Implement emulation of FEAT_SME_TMOP
 * New board model: Axiado EVK SCM3003
 * Fix various minor bugs in mps3-an547 model
 * hw/i2c/bcm2835_i2c: Correct iomem size
 * hw/misc/bcm2835_powermgt: implement a real watchdog timer
 * hw/arm/raspi4b: fix guest never seeing more than ~1 GiB of RAM

# -----BEGIN PGP SIGNATURE-----
#
# iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmp8Y+kZHHBldGVyLm1h
# eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3iwKEACaH/Ztj8k5NiH9AVF7+2ii
# SkM2oJoLLyFw2LXgXMnQgzdmMhwW7odsd8xp76prfDIrOZE5uFXAX+7F8I5Vnmcn
# nyHVhqvJlxx+JEVSGLhjmHhJCaqxisbtaFVEdhvBn2r7b5YCcmB9pOaUnMpZI2Mt
# ahXtqiExHZ04Y57JIoOuMOs+JSLn2QoMlUy3aP0BetyVfDyfxjU/8XnVQnDWec1J
# Df+QWgFdHhOlb8vy6lurrdDC8Q5F0nEKTHfq5aCl4DjpOg4uMzqHQ4GFdxHDlhGi
# 2z+Toyq/I2dBKebv0tWdLjcDMkLrmfNZcIs5VPsm+vvQyt2wN5rFnJKAMYcmN4BS
# 7Z8C1RBPnsSZaYCeh97oCipce1WeGPpPjKlfBqMwdF95jBnn/zMGULmxB/W2Ays/
# gKD9RpKmvfUZNQ9JRFr/u+vNvvY2xki1u3yB0F0j+f8ggp8PxpHli7gxlA3x9PyZ
# AhmDj6JK0+zciPlC6FnSVTipNE8ZGU8XN8DCp4LNU5zye3aDtoCCmJwVVryYeRBT
# bq7kj2En13pP66OZUAb1MRu2gnwIuq0GZwQ3aYtWqe8DxcVa7r2fGxaRR0GDjY+r
# l1SzSd5CCExpaLi4c3FO6sz12jHfzRLjKtULEyv/37kVNbI+SpOj6UwCQAgAYTz8
# Gq/mTm1heDXTDjcwEp6lQQ==
# =ILzl
# -----END PGP SIGNATURE-----
# gpg: Signature made Wed 12 Aug 2026 05:15:37 AM PDT
# gpg:                using RSA key E1A5C593CD419DE28E8315CF3C2525ED14360CDE
# gpg:                issuer "peter.maydell@linaro.org"
# gpg: Good signature from "Peter Maydell <peter.maydell@linaro.org>" [unknown]
# gpg:                 aka "Peter Maydell <pmaydell@gmail.com>" [unknown]
# gpg:                 aka "Peter Maydell <pmaydell@chiark.greenend.org.uk>" [unknown]
# gpg:                 aka "Peter Maydell <peter@archaic.org.uk>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: E1A5 C593 CD41 9DE2 8E83  15CF 3C25 25ED 1436 0CDE

* tag 'pull-target-arm-20260812' of https://gitlab.com/pm215/qemu: (26 commits)
  tests/functional/aarch64: add raspi4b full-RAM regression test
  hw/arm/raspi4b: fix guest never seeing more than ~1 GiB of RAM
  hw/misc/bcm2835_powermgt: implement a real watchdog timer
  hw/i2c/bcm2835_i2c: Correct iomem size
  hw/arm/mps2-tz.c: add AN547 AHB PPC EXP1 DMA ports
  hw/arm/mps2-tz.c: fix AN547 APB PPC EXP0 MPC ports
  hw/arm/armsse.c: fix SSE-300 PPU addresses
  hw/arm/armsse.c: fix SSE-300 s32kwatchdog address
  hw/arm: ax3000-soc: Enable Cadence GPIO controllers
  hw/gpio: Add Cadence GPIO controller
  hw/arm: Add Axiado EVK SCM3003
  hw/arm: ax3000-soc: Enable Axiado SD host controller
  hw/sd: Add Axiado SD host controller with eMMC PHY
  hw/arm: ax3000-soc: Enable Ax3000 clock control
  hw/misc: Add AX3000 clock control
  hw/arm: Add Axiado SoC AX3000
  target/arm: Enable FEAT_SME_TMOP for -cpu max
  target/arm: Implement {S,SU,US,U}TMOPA (4-way)
  target/arm: Implement [SU]TMOPA (2-way)
  target/arm: Implement FTMOPA (widening, 4-way, FP8 to FP32)
  ...

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-12 09:19:55 -07:00
Eric Farman
9b3d68edb2 pc-bios/s390-ccw.img: update s390x bios
Update the s390 bios with recent fixes for out-of-bounds accesses.

Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-12 11:13:28 -04:00
Cornelia Huck
93676b2472 hw: add compat machines for 11.2
Add 11.2 machine types for arm/i440fx/loongarch/m68k/q35/s390x/spapr.

Signed-off-by: Cornelia Huck <cohuck@redhat.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
Link: https://lore.kernel.org/qemu-devel/20260723163806.368127-1-cohuck@redhat.com
[farman@linux.ibm.com: fixup hw/core/machine.c hunk]
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-12 10:21:15 -04:00
Richard Henderson
d5393e5a03 aspeed queue:
* Fixes missing Kconfig dependencies for Aspeed boards
 * Adds 64-bit addressing support to the EHCI USB controller model.
   Enable it on the AST2700
 * Extends Aspeed SMC qtest coverage with fast-read, DOR and QOR
   read modes
 * Introduces a separate Aspeed2700SCUState type and shares the SCUIO,
   FMC and SCU instances across the AST2700 PSP, SSP and TSP
   coprocessors
 * Adds Data FIFO-based flash access for the AST2700 FMC controller
 * Adds the ADC128D818 12-bit 8-channel ADC sensor device with tests,
   wired up on the Anacapa board
 * Reworks the PCA9552/PCA9555 GPIO/LED driver: polarity inversion,
   datasheet-conformant command handling, GPIO QOM properties, reset
   via the Resettable interface, and extensive qtest coverage
 * Reworks the PCA9554 GPIO driver: output-to-input reflection,
   PCA9536 support, pin direction property, and qtest coverage
 * Adds PCA9555 IO expanders and temperature sensors to the Catalina
   board
 * Adds AST2700 I2C master buffer mode support
 * Updates ASPEED functional tests to SDK v11.03 and Zephyr SDK v03.08
 * Adds AES-GCM support to the QEMU crypto cipher layer (gcrypt,
   nettle, gnutls backends) with unit tests
 * Adds crypto (AES) command emulation to the Aspeed HACE model:
   direct access, scatter-gather, CTR, GCM modes, 64-bit DMA, with
   qtest coverage on AST2500, AST2600, AST1030 and AST2700
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEoPZlSPBIlev+awtgUaNDx8/77KEFAmp7TbQACgkQUaNDx8/7
 7KGqiBAAuiozhStgwzhV1ywfStIVL1wUQsg4UiODmihJEd1eRS7KH6q37enXuydI
 zKycSTjg1gJUglRbq0OUk+WNeMCwusLVZm2u6GCIF4B9m8n7Qn09vpGY9egAfTdv
 XTm1/GStxLLlYp6WaXyXXbm6D5F2KjkaNyqjy2UEQwzsiOfkDcABqnH5CFNT6d3U
 q2rcRZ/8exv1bWDD9PI5ip3Si/Uf1p8X8Kcrij5aQRMaJJMZnQZcccryZFz6waxe
 xTeQEEE6whS0MwTfKqH6uIm1D2NlekYe3FXDjP4agePhTG/RN3leMxCL3QIwJfk4
 sMKf+Mapac1rVE/EY5KHYwKbCGR2t8uRbVTXMhywiZeV8WyBGiq+tabklw8hsFvA
 56Q3ez7oTT6vTaIRMSC7PrXXLEZKywhA4jICd2HWq2Dt+XEiAcT6nvM4pDp2ktXq
 PtpxLKhlelZ2P7GJUAvOa8rtaeif9RiPELN8cliVqT5MrC0iodMmh+eCponYKwZl
 tThzUBatZVn/BP3EFGT7GHicfr3owCblxfuHPVMZiWlX3n4ymixa/3sGk73zb+jo
 foSCpi8YEAYxzhcwBfOrNE1UqQuwhOvQWugmEgFfSbjvqL7sFOeivWraYv46fcwE
 EQ9+Ah35VE2rq6fNvfUHiTZqWFGDYSvMVHKGCGR0CCu8PJOwdFM=
 =SS88
 -----END PGP SIGNATURE-----

Merge tag 'pull-aspeed-20260811' of https://github.com/legoater/qemu into staging

aspeed queue:

* Fixes missing Kconfig dependencies for Aspeed boards
* Adds 64-bit addressing support to the EHCI USB controller model.
  Enable it on the AST2700
* Extends Aspeed SMC qtest coverage with fast-read, DOR and QOR
  read modes
* Introduces a separate Aspeed2700SCUState type and shares the SCUIO,
  FMC and SCU instances across the AST2700 PSP, SSP and TSP
  coprocessors
* Adds Data FIFO-based flash access for the AST2700 FMC controller
* Adds the ADC128D818 12-bit 8-channel ADC sensor device with tests,
  wired up on the Anacapa board
* Reworks the PCA9552/PCA9555 GPIO/LED driver: polarity inversion,
  datasheet-conformant command handling, GPIO QOM properties, reset
  via the Resettable interface, and extensive qtest coverage
* Reworks the PCA9554 GPIO driver: output-to-input reflection,
  PCA9536 support, pin direction property, and qtest coverage
* Adds PCA9555 IO expanders and temperature sensors to the Catalina
  board
* Adds AST2700 I2C master buffer mode support
* Updates ASPEED functional tests to SDK v11.03 and Zephyr SDK v03.08
* Adds AES-GCM support to the QEMU crypto cipher layer (gcrypt,
  nettle, gnutls backends) with unit tests
* Adds crypto (AES) command emulation to the Aspeed HACE model:
  direct access, scatter-gather, CTR, GCM modes, 64-bit DMA, with
  qtest coverage on AST2500, AST2600, AST1030 and AST2700

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEEoPZlSPBIlev+awtgUaNDx8/77KEFAmp7TbQACgkQUaNDx8/7
# 7KGqiBAAuiozhStgwzhV1ywfStIVL1wUQsg4UiODmihJEd1eRS7KH6q37enXuydI
# zKycSTjg1gJUglRbq0OUk+WNeMCwusLVZm2u6GCIF4B9m8n7Qn09vpGY9egAfTdv
# XTm1/GStxLLlYp6WaXyXXbm6D5F2KjkaNyqjy2UEQwzsiOfkDcABqnH5CFNT6d3U
# q2rcRZ/8exv1bWDD9PI5ip3Si/Uf1p8X8Kcrij5aQRMaJJMZnQZcccryZFz6waxe
# xTeQEEE6whS0MwTfKqH6uIm1D2NlekYe3FXDjP4agePhTG/RN3leMxCL3QIwJfk4
# sMKf+Mapac1rVE/EY5KHYwKbCGR2t8uRbVTXMhywiZeV8WyBGiq+tabklw8hsFvA
# 56Q3ez7oTT6vTaIRMSC7PrXXLEZKywhA4jICd2HWq2Dt+XEiAcT6nvM4pDp2ktXq
# PtpxLKhlelZ2P7GJUAvOa8rtaeif9RiPELN8cliVqT5MrC0iodMmh+eCponYKwZl
# tThzUBatZVn/BP3EFGT7GHicfr3owCblxfuHPVMZiWlX3n4ymixa/3sGk73zb+jo
# foSCpi8YEAYxzhcwBfOrNE1UqQuwhOvQWugmEgFfSbjvqL7sFOeivWraYv46fcwE
# EQ9+Ah35VE2rq6fNvfUHiTZqWFGDYSvMVHKGCGR0CCu8PJOwdFM=
# =SS88
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 11 Aug 2026 09:28:36 AM PDT
# gpg:                using RSA key A0F66548F04895EBFE6B0B6051A343C7CFFBECA1
# gpg: Good signature from "Cédric Le Goater <clg@redhat.com>" [full]
# gpg:                 aka "Cédric Le Goater <clg@kaod.org>" [full]

* tag 'pull-aspeed-20260811' of https://github.com/legoater/qemu: (83 commits)
  tests/qtest/aspeed-hace: Test the crypto command on the AST2700
  hw/misc/aspeed_hace: Enable the crypto command on the AST2700
  hw/misc/aspeed_hace: Support the AES-GCM mode for the crypto command
  hw/misc/aspeed_hace: Support 64-bit DMA for the crypto command
  tests/unit/test-crypto-cipher: Test AES-GCM mode
  crypto/cipher-gnutls: Implement AES-GCM
  crypto/cipher-nettle: Implement AES-GCM
  crypto/cipher-gcrypt: Implement AES-GCM
  crypto/cipher: Add setaad/gettag for AEAD modes
  crypto/cipher: Add GCM to QCryptoCipherMode
  tests/qtest/aspeed-hace: Test the crypto command on the AST1030
  tests/qtest/aspeed-hace: Test the crypto command on the AST2600
  hw/misc/aspeed_hace: Support the CTR mode for the crypto command
  hw/misc/aspeed_hace: Support scatter-gather mode for the crypto command
  tests/qtest/aspeed-hace: Test the crypto command on the AST2500
  hw/misc/aspeed_hace: Support the crypto command in direct access mode
  hw/arm/aspeed: avoid sign mismatch on sscanf for uart property
  tests/functional/arm/test_aspeed_ast1060: Update ASPEED ZEPHYR PROJECT v03.07
  tests/functional/arm/test_aspeed_ast1030: Update ASPEED Zephyr SDK v03.08
  tests/functional/arm/test_aspeed_ast2500_sdk: Update ASPEED SDK v11.03
  ...

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-12 07:16:57 -07:00
Peter Xu
cf45083edc migration/multifd: Replace assert() with error_setg() in recv paths
QPL and UADK multifd backends use assert() to validate wire-controlled
fields like per-page compressed lengths and packet size consistency.  These
asserts will stop working with -DNDEBUG builds, so may stop working.

Replace all assert() calls in the receive path with proper error_setg() so
validation failures are reported gracefully rather than crashing or
silently ignored.

While at it, touch up an assert() in qatzip recv path too.

Cc: qemu-stable <qemu-stable@nongnu.org>
Cc: Yuan Liu <yuan1.liu@intel.com>
Cc: Yichen Wang <yichen.wang@bytedance.com>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Link: https://lore.kernel.org/r/20260728210417.1925078-4-peterx@redhat.com
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-08-12 08:39:39 -04:00
Peter Xu
ac7fa2e9d4 migration/multifd: Validate next_packet_size in zlib/zstd recv
The zlib and zstd multifd compression backends read next_packet_size from
the incoming migration stream and use it directly as the read length into a
fixed-size buffer (MULTIFD_PACKET_SIZE * 2 = 1MB).  A malicious migration
source can set next_packet_size bigger than allocated, causing a heap
buffer overflow write on the destination.

Add a check against zbuff_len before reading, matching what the qatzip
backend already does.  Also replace the assert(in_size == 0) for empty
packets with proper error reporting, since the value is wire-controlled,
meanwhile assert() stops working with -DNDEBUG builds.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3737
Reported-by: xlabai <xlabai@tencent.com>
Reported-by: Jules Denardou <jules.denardou@datadoghq.com>
Reported-by: Tristan Madani <tristan@talencesecurity.com>
Reported-by: david korczynski (@david1766)
Reported-by: huntr bubble (@bubblehuntr)
Cc: qemu-stable <qemu-stable@nongnu.org>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Link: https://lore.kernel.org/r/20260728210417.1925078-3-peterx@redhat.com
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-08-12 08:39:39 -04:00
Marcelo Manzo
49aecf3900 tests/functional/aarch64: add raspi4b full-RAM regression test
Guards against the bug fixed in the previous commit: boots raspi4b's
default 2 GiB configuration and checks that the guest actually sees
close to that (>1.9M kB), not the ~921 MiB the bug left it capped at.
Deliberately checks a threshold rather than the exact byte count of
either figure, since the precise number depends on how this specific
pinned kernel accounts for its own early reservations; the threshold
is comfortably between the two (943524 kB broken, 1905824 kB fixed,
confirmed by hand against this exact kernel/initrd).

Folded into the existing test_arm_raspi4_initrd test rather than a
new standalone boot, since it needs no machine state that test isn't
already setting up, and the functional-test suite is already slow
enough from how many separate guest boots it runs.

Signed-off-by: Marcelo Manzo <marcelomanzo@gmail.com>
Message-id: 20260811143539.7835-3-marcelomanzo@gmail.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:56 +01:00
Marcelo Manzo
c59b691626 hw/arm/raspi4b: fix guest never seeing more than ~1 GiB of RAM
raspi4_modify_dtb() decides whether to add a second memory node above
the 1 GiB peripheral hole by checking info->ram_size -- but that field
is the boot loader's RAM budget for loading the kernel/initrd/dtb
image, itself always capped to at most UPPER_RAM_BASE - vcram_size by
raspi_base_machine_init(). Since that capped value can never exceed
UPPER_RAM_BASE by construction, the condition was never true for any
raspi4b configuration, and the second node was never added: the guest
never saw more than ~1 GiB of its nominal RAM, regardless of the
machine's actual size.

board_ram_size(info->board_id), computed one line above in the same
function, is the value that was actually needed -- the board's real
total RAM, not the boot loader's own budget for where it's allowed to
place the kernel image.

Confirmed via direct measurement inside the guest ("free -h" /
/proc/meminfo) on raspi4b's default 2 GiB configuration, before and
after:

    before: MemTotal:  943524 kB (~921 MiB)
    after:  MemTotal: 1905824 kB (~1861 MiB)

Also verified against two real, unmodified Raspberry Pi OS releases
(Debian 11/Bullseye and Debian 13/Trixie): both now report ~1.8 GiB of
usable RAM instead of ~900 MiB, with clean boots, working SSH, and no
kernel errors on either.

Signed-off-by: Marcelo Manzo <marcelomanzo@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260811143539.7835-2-marcelomanzo@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:56 +01:00
Marcelo Manzo
21fcfb6046 hw/misc/bcm2835_powermgt: implement a real watchdog timer
The RSTC register's write-config bits (0x30) being set to the
"full reset" value (0x20) does not mean "reset now" -- it arms the
hardware watchdog so that a reset happens if the WDOG countdown
register is not refreshed before it expires. The previous
implementation treated any such RSTC write as an immediate reset,
regardless of the WDOG value.

This is dormant on older/lighter userspace (nothing in Bullseye's
default boot touches these registers this way), but modern systemd
(observed with Debian 13/Trixie's systemd 257) writes to RSTC as part
of routine early-boot watchdog probing. With the old code, this fires
an immediate reset a few seconds into boot; combined with -no-reboot
this looks exactly like a QEMU crash (clean exit, no panic, no guest
reboot message) with the last log line being the RSTC/WDOG write.

Fix this by actually implementing the watchdog as a QEMUTimer: writes
to RSTC/WDOG (re)compute the timeout from the WDOG register (in units
of 1/65536 s, per the real hardware) and arm a timer for that many
nanoseconds out; only when the timer actually fires do we request a
system reset or shutdown, matching real hardware behavior. Clearing
the write-config bits or the WDOG value disarms the timer, and reset
disarms it too.

Verified against real Raspberry Pi OS images under the patched
raspi4b machine: Bullseye (5.15) and Bookworm (6.12) never exercised
this path either way; Trixie (6.18, systemd 257) no longer crashes at
boot and reaches a working login/SSH state.

This is a migration compatibility break for the raspi boards.

Signed-off-by: Marcelo Manzo <marcelomanzo@gmail.com>
[PMM: bump vmstate version IDs, note migration break in commit msg]
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:56 +01:00
botszhuang
20bf099da7 hw/i2c/bcm2835_i2c: Correct iomem size
The last valid register is the Clock Stretch Timeout (CLKT) at
offset 0x1c. Since it is a 32-bit register, the total memory
region size should be 0x1c + 4 = 0x20.

Update the size parameter in memory_region_init_io() from 0x24
to 0x20 to accurately reflect the hardware specification.


Suggested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: botszhuang <huang.botsz@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260804144611.31735-1-huang.botsz@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:56 +01:00
Simon Xu
f43d950719 hw/arm/mps2-tz.c: add AN547 AHB PPC EXP1 DMA ports
Page 42 of the AN547 TRM defines the AHB PPC EXP1 ports with DMA 1-3

AN547 TRM: https://developer.arm.com/documentation/dai0547/latest/

Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Simon Xu <simonxhy0404@gmail.com>
Message-id: 20260805191257.11303-5-simonxhy0404@gmail.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:56 +01:00
Simon Xu
230edd14d5 hw/arm/mps2-tz.c: fix AN547 APB PPC EXP0 MPC ports
The AN547 TRM defines them to be on ports [15:13], not [2:0].

AN547 TRM: https://developer.arm.com/documentation/dai0547/latest/

Fixes: eb09d533d8 ("hw/arm/mps2-tz: Add new mps3-an547 board")
Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Simon Xu <simonxhy0404@gmail.com>
Message-id: 20260805191257.11303-4-simonxhy0404@gmail.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:56 +01:00
Simon Xu
024c539a62 hw/arm/armsse.c: fix SSE-300 PPU addresses
The SSE-300 CPU0_PPU, MGMT_PPU, DEBUG_PPU had the wrong addresses
that were the same as the SSE-200 addresses.
Page 146 of the SSE-300 TRM defines the addresses of the PPUs.

SSE-300 TRM: https://support.arm.com/documentation/101773/latest/

Fixes: 8901bb414a ("hw/arm/armsse: Add SSE-300 support")
Signed-off-by: Simon Xu <simonxhy0404@gmail.com>
Message-id: 20260805191257.11303-3-simonxhy0404@gmail.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:56 +01:00
Simon Xu
000ef0d13b hw/arm/armsse.c: fix SSE-300 s32kwatchdog address
The SSE-300 SLOWCLK Secure Watchdog Timer is only defined at address
0x5802e000 in the secure region.
Page 45 of the SSE-300 TRM specifies that "the watchdog is Secure
access only".

SSE-300 TRM: https://support.arm.com/documentation/101773/latest/

Fixes: 8901bb414a ("hw/arm/armsse: Add SSE-300 support")
Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Simon Xu <simonxhy0404@gmail.com>
Message-id: 20260805191257.11303-2-simonxhy0404@gmail.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:56 +01:00
Kuan-Jui Chiu
a4256760c0 hw/arm: ax3000-soc: Enable Cadence GPIO controllers
Enable 8 Cadence GPIO controllers into Axiado AX3000 SoC

Signed-off-by: Kuan-Jui Chiu <kchiu@axiado.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260713073033.3883619-9-kchiu@axiado.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:56 +01:00
Kuan-Jui Chiu
cc57a945fe hw/gpio: Add Cadence GPIO controller
This patch add a new model for Cadence GPIO controller which
supports 32 pins and interrupts for level-triggered/edge-triggered type on
input pins.

Also define new trace functions for analysis purpose and new configuration to
enable this model.

Signed-off-by: Kuan-Jui Chiu <kchiu@axiado.com>
Message-id: 20260713073033.3883619-8-kchiu@axiado.com
[PMM: drop unnecessary <private> and <public> marker comments]

Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:56 +01:00
Kuan-Jui Chiu
4e5205339f hw/arm: Add Axiado EVK SCM3003
Add EVK axiado-scm3003 built with AX3000 SoC

Signed-off-by: Kuan-Jui Chiu <kchiu@axiado.com>
Message-id: 20260713073033.3883619-7-kchiu@axiado.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
[PMM: KConfig for the board has to depend on TCG && ARM]
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:40 +01:00
Kuan-Jui Chiu
2019f4e0dd hw/arm: ax3000-soc: Enable Axiado SD host controller
Enable SD host controller into Axiado AX3000 SoC to load kernel and rootfs
from eMMC.

Signed-off-by: Kuan-Jui Chiu <kchiu@axiado.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713073033.3883619-6-kchiu@axiado.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:40 +01:00
Kuan-Jui Chiu
8c55a630c5 hw/sd: Add Axiado SD host controller with eMMC PHY
This patch add a new model for Axiado SD host controller which is compatible
with SDHCI 3.0 spec

This device model also includes a eMMC PHY which helps to control SD/eMMC

Signed-off-by: Kuan-Jui Chiu <kchiu@axiado.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713073033.3883619-5-kchiu@axiado.com
[PMM: Use HWADDR_PRIx]
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:40 +01:00
Kuan-Jui Chiu
406738e508 hw/arm: ax3000-soc: Enable Ax3000 clock control
Signed-off-by: Kuan-Jui Chiu <kchiu@axiado.com>
Message-id: 20260713073033.3883619-4-kchiu@axiado.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:40 +01:00
Kuan-Jui Chiu
38b5256375 hw/misc: Add AX3000 clock control
This patch adds a new model for Axiado AX3000 clock control which supports
to read ID and status

Signed-off-by: Kuan-Jui Chiu <kchiu@axiado.com>
Message-id: 20260713073033.3883619-3-kchiu@axiado.com
[PMM: use HWADDR_PRIx]
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:41:40 +01:00
Kuan-Jui Chiu
33a71a68c6 hw/arm: Add Axiado SoC AX3000
This patch adds new model for Axiado SoC AX3000 which supports
    4 Cortex-A53 ARM64 CPUs
    Arm Generic Interrupt Controller v3
    4 Cadence UARTs

Signed-off-by: Kuan-Jui Chiu <kchiu@axiado.com>
Message-id: 20260713073033.3883619-2-kchiu@axiado.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
[PMM: Kconfig for the SoC shouldn't depend on ARM]
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:20:34 +01:00
Richard Henderson
8ae365bdc8 target/arm: Enable FEAT_SME_TMOP for -cpu max
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713230244.70174-11-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:20:34 +01:00
Richard Henderson
e56b670ea1 target/arm: Implement {S,SU,US,U}TMOPA (4-way)
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713230244.70174-10-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:20:34 +01:00
Richard Henderson
695e4e87a4 target/arm: Implement [SU]TMOPA (2-way)
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713230244.70174-9-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:20:34 +01:00
Richard Henderson
1c7b4f9db3 target/arm: Implement FTMOPA (widening, 4-way, FP8 to FP32)
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713230244.70174-8-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:20:34 +01:00
Richard Henderson
e921da8b98 target/arm: Implement FTMOPA (widening, 2-way, FP8 to FP16)
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713230244.70174-7-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:20:34 +01:00
Richard Henderson
f6a2d780f1 target/arm: Implement FTMOPA (widening, 2-way, FP16 to FP32)
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713230244.70174-6-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:20:34 +01:00
Richard Henderson
cfe1e6503a target/arm: Implement BFTMOPA (widening)
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713230244.70174-5-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:20:34 +01:00
Richard Henderson
aa8965de49 target/arm: Implement BFTMOPA (non-widening)
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713230244.70174-4-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:20:34 +01:00
Richard Henderson
76bc7dc82d target/arm: Implement FTMOPA (non-widening, FP16)
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713230244.70174-3-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:20:34 +01:00
Richard Henderson
21e726d226 target/arm: Implement FTMOPA (non-widening, FP32)
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260713230244.70174-2-richard.henderson@linaro.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-08-12 11:20:34 +01:00
Matheus Tavares Bernardino
2e555f5b44 tests/hexagon: add tests for HVX bfloat
Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/392114c4c16e6f7f2835a6513987aafea82b565c.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:45:45 -07:00
Matheus Tavares Bernardino
6bebed5a47 tests/hexagon: add tests for v68 HVX IEEE float comparisons
Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/53e73707092d31bcde6ed8189c5496b00345f8fa.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:45:44 -07:00
Matheus Tavares Bernardino
57da1eb994 tests/hexagon: add tests for v68 HVX IEEE float conversions
Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/ec6af07a285c47e5f6df343860bfedce5bed9421.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:45:44 -07:00
Matheus Tavares Bernardino
7f3a641101 tests/hexagon: add tests for v68 HVX IEEE float min/max
Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/7fdbc12ed4c62a16068c380a85ee2356051e61ea.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:45:44 -07:00
Matheus Tavares Bernardino
449e485814 tests/hexagon: add tests for v68 HVX IEEE float arithmetics
Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/791f122bfd744a77177608b524d852fe826cd595.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:45:44 -07:00
Matheus Tavares Bernardino
9d70629fa0 target/hexagon: add v73 HVX IEEE bfloat16 insns
Add HVX IEEE bfloat16 (bf16) instructions:

Arithmetic operations:
- V6_vadd_sf_bf, V6_vsub_sf_bf: add/sub bf16 widening to sf output
- V6_vmpy_sf_bf: multiply bf16 widening to sf output
- V6_vmpy_sf_bf_acc: multiply-accumulate bf16 widening to sf output

Min/Max operations:
- V6_vmin_bf, V6_vmax_bf: bf16 min/max

Comparison operations:
- V6_vgtbf: greater-than compare
- V6_vgtbf_and, V6_vgtbf_or, V6_vgtbf_xor: predicate variants

Conversion operations:
- V6_vcvt_bf_sf: convert sf to bf16

Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/1a253373567781e0e141c34b41eaffad4789a493.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:45:44 -07:00
Matheus Tavares Bernardino
7646bc0b72 target/hexagon: add v68 HVX IEEE float compare insns
Add HVX IEEE floating-point compare instructions:
- V6_vgthf, V6_vgtsf: greater-than compare
- V6_vgthf_and, V6_vgtsf_and: greater-than with predicate-and
- V6_vgthf_or, V6_vgtsf_or: greater-than with predicate-or
- V6_vgthf_xor, V6_vgtsf_xor: greater-than with predicate-xor

Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/96e27588ad5a7d47ba9f56f1d547729a19b691c5.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:45:44 -07:00
Matheus Tavares Bernardino
011b2512f9 target/hexagon: add v68 HVX IEEE float conversion insns
Add HVX IEEE floating-point conversion instructions:
- vconv_hf_h, vconv_h_hf, vconv_sf_w, vconv_w_sf: vconv operations
- vcvt_hf_sf, vcvt_sf_hf: float <-> half float conversions
- vcvt_hf_b, vcvt_hf_h, vcvt_hf_ub, vcvt_hf_uh: int to half float
- vcvt_b_hf, vcvt_h_hf, vcvt_ub_hf, vcvt_uh_hf: half float to int

Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/beca620d2e5e0bc15886bf967ab3961a49eca5f7.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Matheus Tavares Bernardino
60f11988eb target/hexagon: add v68 HVX IEEE float misc insns
Add HVX IEEE floating-point miscellaneous instructions:
- vassign_fp (vfmv): vector move
- vfneg_hf, vfneg_sf: vector floating-point negate
- vabs_hf, vabs_sf: vector absolute value

Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/0bd3279ca0bbf7c01548e3b4e7a9c8fdbdbe4ee1.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Matheus Tavares Bernardino
2843fc5feb target/hexagon: add v68 HVX IEEE float min/max insns
Add HVX IEEE floating-point min/max instructions:
- vfmin_hf, vfmin_sf: IEEE floating-point minimum
- vfmax_hf, vfmax_sf: IEEE floating-point maximum
- vmax_hf, vmax_sf: qfloat IEEE maximum
- vmin_hf, vmin_sf: qfloat IEEE minimum

The Hexagon qfloat variants are similar to the IEEE-754 ones, but they
handle NaN slightly differently. See comment on hvx_ieee_fp.h

Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/8e274a7a10a5aae23eb1250db0b4f4250c81f3ef.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Matheus Tavares Bernardino
69e46b2822 target/hexagon: add v68 HVX IEEE float arithmetic insns
Add HVX IEEE floating-point arithmetic instructions:
- vmpy_sf_sf, vmpy_sf_hf, vmpy_hf_hf: multiply operations
- vdmpy_sf_hf: dot-product multiply
- vmpy_sf_hf_acc, vmpy_hf_hf_acc, vdmpy_sf_hf_acc: multiply-accumulate
- vadd_sf_sf, vsub_sf_sf, vadd_sf_hf, vsub_sf_hf: add/sub with sf output
- vadd_hf_hf, vsub_hf_hf: add/sub with hf output

Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/8923b6c6bc4fe750c07a07bcd490761f8bab52fe.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Matheus Tavares Bernardino
97a75a12d6 hexagon: print info on "-d in_asm" for disabled IEEE FP instructions
When cpu->cfg.ieee_fp_extension is off, IEEE FP instructions don't get
executed. Let's print that info on the "-d in_asm" output to help users.
This will generate an output like the following:

0x00020e30:  0x1f82e1c0 {       V0.sf = vadd(V1.sf,V2.sf) (disabled: no ieee_fp) }

Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/1bdc772e4a795ecd9f5bf2b7e7143cc4b297318c.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Matheus Tavares Bernardino
5995de98c4 hexagon: group cpu configurations in their own struct
This will be used in a follow up commit.

Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/8f9a2e2ccfd2eeda73a63d1a6abbfd6e5458b44c.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Matheus Tavares Bernardino
e1245d0ea4 target/hexagon/cpu: add HVX IEEE FP extension
This flag will be used to control the HVX IEEE float instructions, which
are only available at some Hexagon cores. When unavailable, the
instruction effectively only set the destination registers to 0.

Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/10fb5b86db60a465e51db2cf73185307a1ec0895.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Matheus Tavares Bernardino
770e282e50 target/hexagon: fix incorrect/too-permissive HVX encodings
The following encodings have become stricter since v68:

    - V6_vunpackob, V6_vunpackoh: ---00 -> --000
    - V6_vaddbq/hq/wq, V6_vaddbnq/hnq/wnq: ---01 -> --001
    - V6_vsubbq/hq, V6_vsubwq/bnq/hnq/wnq: ---01/---10 -> --001/--010
    - V6_vhist, V6_vwhist128/256, V6_vwhist128/256_sat: ---00 -> --000
    - V6_vhistq, V6_vwhist128/256q, V6_vwhist128/256q_sat: ---10 -> --010

Pre v68 compilers, by default, already use "0" for the non-specified bit
that changed in v68, so unless someone is manually writing the binary
encoding, this should not cause any backwards incompatibility with
pre-v68 binaries.

Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/1fe4b8a0fcae6705a591b1b5131e28f6d8062eed.1776339451.git.matheus.bernardino@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Taylor Simpson
19148de498 Hexagon (target/hexagon) Clean up disassembly of control and system regs
Change disassembly of control regs from C{num}/{name} to {name}
Change disassembly of system regs from S{num}/r{num} to {name}

Signed-off-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260811032206.58501-1-ltaylorsimpson@gmail.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
dde6dc062a tests/tcg/hexagon: add HVX tests for vabsdiff
Cover the four vabsdiff variants.

The expected value is computed in int64_t to avoid overflowing the
source element type.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260807152241.1576334-8-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
ead4d3a8d8 tests/tcg/hexagon: add HVX test for V6_vsubwsat saturation
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260807152241.1576334-7-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
ffbb6bbca5 target/hexagon: add GVec overrides for HVX vector average
Reviewed-by: Marco Liebel <marco.liebel@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260807152241.1576334-6-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
234d8cb6f2 target/hexagon: add GVec overrides for HVX absolute difference
Reviewed-by: Marco Liebel <marco.liebel@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260807152241.1576334-5-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
d47d794ea2 target/hexagon: add GVec override for HVX vmpyih multiply
Reviewed-by: Marco Liebel <marco.liebel@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260807152241.1576334-4-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
8c53023a26 target/hexagon: add GVec overrides for HVX saturating add/sub
Reviewed-by: Marco Liebel <marco.liebel@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260807152241.1576334-3-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
9e96b5953e host-utils: fix ssub32/64_saturate return type and clamp direction
ssub32_saturate() and ssub64_saturate() were declared to return bool
instead of int32_t/int64_t, and clamped to the wrong bound on overflow.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Cc: qemu-stable@nongnu.org
Fixes: 1649553313 ("host-utils: Introduce signed saturation primitives")
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260807152241.1576334-2-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
701eb2ac98 tests/functional/hexagon: enable more arch_tests cases
Add more tests from hexagon-arch-tests, enabled by QTimer device.

These exercise cache maintenance ops, l2vic, thread start/stop, tlb/mmu
operations, and user-mode transitions.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-19-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
71d618d3aa tests/qtest: add qct-qtimer qtest
Add a qtest exercising the QCT QTimer's register access, view-region
frame addressing, and one-shot timer firing behavior.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-18-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
57eaab1e8c hw/hexagon: connect qtimer device
Add the QTimer to the shared hex-subsys so both machine models pick it
up.  Map its view region, wire its interrupt lines into l2vic, and link
it to the globalreg device backing HEX_SREG_TIMERLO/TIMERHI.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-17-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
954f0cec38 hw/timer: Add QCT QTimer device model
Implement the QCT QTimer generic timer device used by Hexagon DSP
systems.

Co-authored-by: Damien Hedde <damien.hedde@greensocs.com>
Co-authored-by: Tobias Röhmel <quic_trohmel@quicinc.com>
Co-authored-by: Sid Manning <sidneym@quicinc.com>
Co-authored-by: Thomas Marceron <tmarcero@qti.qualcomm.com>
Co-authored-by: Mahmoud Kamel <mkamel@qti.qualcomm.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-16-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
240f3620af tests/functional/hexagon: add arch_tests functional test
Add the test_int_steering case from hexagon-arch-tests.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-15-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
8ff5b8d403 tests/qtest: add L2VIC qtest
Add a qtest exercising L2VIC register access and interrupt
enable/disable.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-14-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
5f8e903c02 hw/hexagon/virt: connect pl011 UART interrupt
Wire pl011's sysbus IRQ into l2vic at IRQ 15.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-13-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
abd9e918e7 hw/hexagon/virt: add l2vic interrupt-controller and virtio-mmio FDT nodes
Expose l2vic as a device-tree interrupt-controller node and reference
it via interrupt-parent, so guest kernels can discover the virtio-mmio
transports.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-12-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
76f40eb3f1 hw/hexagon/virt: instantiate virtio-mmio transports
Add a VIRT_MMIO region and virtio-mmio transports, wired into l2vic.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-11-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
03f38eecc9 hw/hexagon: connect l2vic device
Add the l2vic to the shared hex-subsys so both machine models pick it
up.  Map its register banks, wire the interrupt lines to CPU[0]
and link each vCPU, globalregs.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-10-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
df9c6d6396 hw/hexagon: extract get_reg_value/set_reg_value stubs in globalreg
Route the globalreg read/write accessors through new
get_reg_value()/set_reg_value() helpers instead of touching
s->regs[reg] directly.

This will be exploited by a subsequent patch that redirects VID/VID1
accesses to the L2VIC.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-9-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Sid Manning
04f398b2a2 hw/intc: Add l2vic interrupt controller
The Hexagon DSP requires an L2VIC to route up to 1024 external
interrupt sources through 4 VID output groups into the core's 8
interrupt inputs.  Add a device model for it.

Co-authored-by: Matheus Tavares Bernardino <quic_mathbern@quicinc.com>
Co-authored-by: Damien Hedde <damien.hedde@dahe.fr>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-8-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
d922df10b2 bitops.h: Add find_first_bit32()
set_bit32()/test_bit32()/etc already let devices operate on
guest-visible uint32_t register arrays without depending on the host's
'unsigned long' size.  Add find_first_bit32() so callers need not cast
a uint32_t array to 'unsigned long *'.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-7-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
d33ec047c3 hw/hexagon: group the CPUs in a cluster
The CPUs are now grouped in a TYPE_CPU_CLUSTER.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-6-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
d24f9c80f6 hw/hexagon: move the TLB to hex-subsys
The TLB device is sized from the config table, so both machines create
it identically.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-5-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
26088c1e7b hw/hexagon: move global registers to hex-subsys
Both machines create the global register device the same way, so let
hex-subsys own it and link it to each CPU as it is realized.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-4-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
024fff8b81 hw/hexagon: move VTCM to the common machine state
The VTCM is described by the config table, so every machine can set it
up the same way.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-3-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Brian Cain
197870349f hw/hexagon: add hex-subsys
The virt and DSP machine models build the same core subsystem, let's
abstract out that part.  Start with the DDR and config table ROM setup.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260806042723.3785369-2-brian.cain@oss.qualcomm.com
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-11 23:20:45 -07:00
Stefan Hajnoczi
e8d693e12a tests/qtest: Do not use versioned pc-q35-5.2 machine anymore
As of QEMU v11.1.0, the v5.2.0 machines are not usable anymore.

Use the latest x86 q35 machine instead, otherwise we get:

  $ qemu-system-x86_64 -M pc-q35-5.2
  qemu-system-x86_64: unsupported machine type: "pc-q35-5.2"
  Use -machine help to list supported machines

See commit a35f8577a0 ("include/hw: add macros for deprecation
& removal of versioned machines") and f59ee04406 ("include/hw/boards:
cope with dev/rc versions in deprecation checks") for explanation
on automatically removed versioned machines.

This commit message is taken from commit 9eef3854d3 ("tests/qtest: Do
not use versioned pc-q35-5.0 machine anymore") by Philippe Mathieu-Daudé
<philmd@linaro.org>.

Cc: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-ID: <20260811183144.190135-1-stefanha@redhat.com>
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-11 16:12:34 -04:00
Sam Heney
bdfe26faca tests/qtest/migration: Only build tls_no_hostname test with TASN1
The test_precopy_tcp_tls_no_hostname test and its start hook use
TestMigrateTLSX509 and migrate_hook_start_tls_x509_common(), which
are only defined when CONFIG_TASN1 is set. This means building with
gnutls enabled but libtasn1 unavailable fails:

  ../tests/qtest/migration/tls-tests.c: In function 'migrate_hook_start_tls_x509_no_host':
  ../tests/qtest/migration/tls-tests.c:510:5: error: unknown type name 'TestMigrateTLSX509'

Guard the test with CONFIG_TASN1 like the other x509 tests.

Fixes: df9c38b19a ("tests/qtest/migration: Add a NULL parameters test for TLS")
Signed-off-by: Sam Heney <github@me.samiser.xyz>
Link: https://lore.kernel.org/r/5f24de0e-49af-45a7-927f-f79b203bb335@app.fastmail.com
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-08-11 15:34:38 -04:00
Gavin Shan
ff77a51511 system/memory: Make ram device region directly accessible
This basically reverts 4a2e242bbb ("memory: Don't use memcpy for
ram_device regions") to make ram device region directly accessible
again. With this, the bounce buffer is bypassed in address_space_map()
when a ram device region is involved, potentially avoid to overrun
the (small) bounce buffer.

Reported-by: Julia Graham <jugraham@redhat.com>
Suggested-by: Michael S. Tsirkin <mst@redhat.com>
Suggested-by: Peter Xu <peterx@redhat.com>
Suggested-by: Richard Henderson <richard.henderson@linaro.org>
Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Gavin Shan <gshan@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260728031731.286666-4-gshan@redhat.com
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-08-11 15:34:38 -04:00
Gavin Shan
bec5e7c71c system/memory: Use qemu_ram_move() for directly accessible regions
All ram device regions were turned to be indirectly accessible by commit
4a2e242bbb ("memory: Don't use memcpy for ram_device regions"). This leads
to guest hang on attempt to build 'cuda-samples' as reported by Julia. The
guest is started by the following command lines, with GH100 GPU card passed
from the host.

   host$ lspci | grep GH100
   0009:01:00.0 3D controller: NVIDIA Corporation GH100 [GH200 120GB / 480GB] (rev a1)
   host$ /home/sandbox/gavin/qemu.main/build/qemu-system-aarch64            \
         -machine virt,gic-version=host,ras=on,highmem-mmio-size=4T         \
         -accel kvm -cpu host -smp cpus=48 -m size=8G                       \
         -drive file=/home/gavin/sandbox/images/disk.qcow2,if=none,id=d0    \
         -device virtio-blk-pci,id=vb0,bus=pcie.0,drive=d0,num-queues=4     \
         -device vfio-pci-nohotplug,host=0009:01:00.0,bus=pcie.1.0
           :
   guest$ cd cuda-samples/build
   guest$ make -j 20 clean
   guest$ make -j 20
           :
   [ 54%] Linking CUDA executable graphMemoryNodes
   [ 54%] Built target graphMemoryNodes
   <no more output afterwards, guest becomes frozen here>

   guest$ qemu-system-aarch64: virtio: bogus descriptor or out of resources
   [  555.814025] virtio_blk virtio0: [vda] new size: 268435456 512-byte logical blocks (137 GB/128 GiB)

When the GPU's driver (NVidia open driver) is loaded on guest bootup,
the memory blocks residing in the PCI BAR#4 of the GH100 GPU card can
be presented to the guest through memory hot-add. The page cache can
then be allocated from the hot added memory blocks when cuda-samples
is being built. Afterwards, the page cache is sent to QEMU's virtio-blk
device as part of the DMA request, the bounce buffer has to be used to
accomodate the request as the corresponding memory region (MemoryRegion)
is an indirectly accessible ram device region in qemu. However, the max
bounce bufer size is only 4096 bytes by default and that is exhausted
quickly, leading to a reset on the virtio-blk device and frozen guest
eventually.

  QEMU
  ====
  virtio_blk_handle_output
    virtio_blk_handle_vq
      virtio_blk_get_request
        virtqueue_pop
          virtqueue_split_pop
            virtqueue_map_desc
              address_space_map
                memory_access_is_direct         # Return false
                  memory_region_supports_direct_access

  (qemu) info mtree
  memory-region: pci_bridge_pci
    0000000000000000-ffffffffffffffff (prio 0, container): pci_bridge_pci
      0000042000000000-0000043fffffffff (prio 1, i/o): 0009:01:00.0 base BAR 4
        0000042000000000-0000043fffffffff (prio 0, i/o): 0009:01:00.0 BAR 4
          0000042000000000-000004379fffffff (prio 0, ramd): 0009:01:00.0 BAR 4 mmaps[0]

This adds qemu_ram_move() where the aligned and small-sized accesses are
handled by qatomics, and fall back to memmove() otherwise. The memove()
for the directly accessible regions is replaced by qemu_ram_move() so that
the issue covered by commit 4a2e242bbb (MMIO access instructions were
optimized to SSE instructions) is fixed. This makes 'ram_device_mem_ops'
redundant, paving the way to revert that commit to make the ram device
region directly accessible again in the next patch.

Besides, this also fixes the issue of the unexpected frozen reception on
e1000 NIC in the scenario of DPDK due to the wrong Rx queue full indication
caused by the following memcpy(), which is turned to 3 consective 'strb'
instructions to the same location by glibc-2.24+ for aarch64. With this
applied, the syntax of one-byte store is strictly ensured by a one-byte
qatomic set.

  QEMU
  ====
  e1000_receive_iov
    pci_dma_write
      pci_dma_rw
        dma_memory_rw
          dma_memory_rw_relaxed
            address_space_rw
              address_space_write
                flatview_write
                  flatview_write_continue
                    flatview_write_continue_step
                      memcpy    # 3 consective 'strb' instructions

Reported-by: Julia Graham <jugraham@redhat.com>
Reported-by: Liu Gang <liugang24219@sangfor.com.cn>
Reported-by: Ding Hui <dinghui@sangfor.com.cn>
Suggested-by: Michael S. Tsirkin <mst@redhat.com>
Suggested-by: Peter Xu <peterx@redhat.com>
Suggested-by: Richard Henderson <richard.henderson@linaro.org>
Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Gavin Shan <gshan@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260728031731.286666-3-gshan@redhat.com
[peterx: remove src==dst check, fix doc, enhance comments, per PeterM, add R-b]
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-08-11 15:34:38 -04:00
Gavin Shan
d2d7e63da8 system/memory: Use memmove() for directly accessible regions
Similar to what's done in commit 4a73aee881 ("softmmu: Use memmove in
flatview_write_continue"), there are more sites where the overlapping
source and destination buffer are allowed for the directly accessible
regions. Use memmove() in those sites, listed as below.

  hw/remote/vfio-user-obj.c::vfu_object_mr_rw
  include/system/memory.h::address_space_read
  system/physmem.c::flatview_read_continue_step

Signed-off-by: Gavin Shan <gshan@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/r/20260728031731.286666-2-gshan@redhat.com
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-08-11 15:34:38 -04:00
Dongli Zhang
403ccbc55d migration/cpr: Add HMP support for cpr-transfer
Currently the cpr-transfer source QEMU instance cannot be driven entirely
via HMP.  The source must use QMP in order to specify both the
main migration channel and the CPR channel.

Extend the HMP migrate command with an optional CPR channel URI. When the
migration mode is cpr-transfer, HMP uses this URI to build a
CPR MigrationChannel in addition to the main migration channel. The new
option is rejected unless the migration mode is cpr-transfer, so existing
HMP migrate usage is unchanged.

For example, source QEMU HMP commands can be something like below. The
"-c unix:/tmp/cpr.sock" is for CPR URI.

(qemu) migrate_set_parameter mode cpr-transfer
(qemu) migrate -c unix:/tmp/cpr.sock tcp:0:50002

Signed-off-by: Dongli Zhang <dongli.zhang@oracle.com>
Reviewed-by: Dr. David Alan Gilbert <dave@treblig.org>
Acked-by: Maciej S. Szmigiero <maciej.szmigiero@oracle.com>
Link: https://lore.kernel.org/r/20260728085903.173265-1-dongli.zhang@oracle.com
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-08-11 15:34:38 -04:00
Fabiano Rosas
8b6405a493 docs: Add security considerations for migration
Add the security considerations that are unique to migration and that
do not already fall into one of the other categories. Some aspects are
better framed as security architecture considerations, so extend that
section to mention TLS and clarify that disk images and guest network
also need to be isolated from other processes, not just other guests.

Reviewed-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Signed-off-by: Fabiano Rosas <farosas@suse.de>
Link: https://lore.kernel.org/r/20260721131457.3062767-1-farosas@suse.de
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-08-11 15:34:38 -04:00
Jamin Lin
0375f6498e tests/qtest/aspeed-hace: Test the crypto command on the AST2700
Cover the AST2700 crypto engine, which drives 64-bit scatter-gather DMA
and adds AES-GCM on top of the ECB/CBC/CTR modes shared with the AST2600.
Add AES-128 and AES-256 GCM known-answer vectors (GCM specification /
NIST SP 800-38D, no associated data) and a dedicated GCM runner that
programs the tag buffer and reads the tag back, checking it after both
encryption and decryption. Register the AST2700 with all four modes.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-17-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
baf15a2cf2 hw/misc/aspeed_hace: Enable the crypto command on the AST2700
With direct/scatter-gather access, 64-bit DMA and AES-GCM all in place,
the AST2700 crypto engine is now fully modelled. Drop its temporary
interrupt-only workaround so the crypto command runs for real, like the
other HACE variants.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-16-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
7a1a61b7ac hw/misc/aspeed_hace: Support the AES-GCM mode for the crypto command
Implement the AES-GCM mode (HACE10[6:4] = 0b101) used by the AST2700
crypto engine: decode the GCM selection, read the 96-bit IV from the
context buffer, operate on the exact data length (GCM handles a partial
final block itself), and write the 128-bit authentication tag to the tag
buffer (HACE18/HACE8C). The hardware GCM path is only used without
associated data (the driver falls back to software otherwise), so AAD is
not modelled and a non-zero HACE14 is reported as unimplemented.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-15-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
c98058bb3d hw/misc/aspeed_hace: Support 64-bit DMA for the crypto command
The AST2700 crypto engine addresses DRAM with 64 bits, supplying the high
half of the source, destination and context addresses through HACE80,
HACE84 and HACE88. Add those registers and a crypt_get_addr() helper that
combines the low and high halves when the SoC has 64-bit DMA, mirroring
the hash engine. SoCs without 64-bit DMA (AST2500/AST2600/AST1030) ignore
the high registers, so their behaviour is unchanged.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-14-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
69ddeb2fac tests/unit/test-crypto-cipher: Test AES-GCM mode
Exercise the new GCM mode and the setaad/gettag helpers with the
canonical AES-GCM test vectors from the GCM specification (McGrew &
Viega, also NIST SP 800-38D): AES-128 and AES-256, with and without
associated data. Each vector is run through encrypt (checking the
ciphertext and the generated tag) and decrypt (checking the recovered
plaintext and the recomputed tag).

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-13-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
66c320fd5d crypto/cipher-gnutls: Implement AES-GCM
Add the AES-GCM AEAD mode to the gnutls backend so it is available when
QEMU is built with gnutls (neither gcrypt nor nettle). GCM uses the
incremental gnutls_cipher_* API with the GNUTLS_CIPHER_AES_*_GCM
algorithms: gnutls_cipher_set_iv() sets the nonce, gnutls_cipher_add_auth()
feeds the associated data, gnutls_cipher_encrypt2()/decrypt2() process the
message, and gnutls_cipher_tag() reads back the authentication tag.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-12-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
b0f7e8cc97 crypto/cipher-nettle: Implement AES-GCM
Add the AES-GCM AEAD mode to the nettle backend so it is available when
QEMU is built with nettle instead of gcrypt. GCM is driven through
nettle's generic gcm_* interface, using the AES encrypt function for both
directions: gcm_set_iv() sets the (typically 96-bit) nonce, gcm_update()
feeds the associated data, gcm_encrypt()/gcm_decrypt() need not be block
aligned, and gcm_digest() produces the authentication tag.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-11-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
1429ef61c8 crypto/cipher-gcrypt: Implement AES-GCM
Map QCRYPTO_CIPHER_MODE_GCM to GCRY_CIPHER_MODE_GCM and advertise it in
qcrypto_cipher_supports() for 128-bit block ciphers. Add a GCM driver
whose setiv accepts the (typically 96-bit) nonce, whose encrypt/decrypt
do not require block-aligned lengths, and which implements setaad via
gcry_cipher_authenticate() and gettag via gcry_cipher_gettag().

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Acked-by: Daniel P. Berrangé <berrange@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-10-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
a4383c0862 crypto/cipher: Add setaad/gettag for AEAD modes
AEAD modes such as GCM authenticate optional associated data (AAD) and
produce an authentication tag, which the block-cipher encrypt/decrypt
interface cannot express. Add qcrypto_cipher_setaad() and
qcrypto_cipher_gettag() plus the matching backend driver hooks. The
generic front-end reports an error when the selected mode's driver does
not implement them, so calling them on a non-AEAD mode fails cleanly.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-9-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
b781906fcc crypto/cipher: Add GCM to QCryptoCipherMode
Introduce the GCM cipher mode so authenticated encryption can be built
on top of the existing qcrypto_cipher API. GCM is an IV-based mode, so
register it in mode_need_iv. No backend advertises it yet, so it stays
unsupported until a backend and the AAD/tag helpers are added in the
following patches.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Acked-by: Daniel P. Berrangé <berrange@redhat.com>
Acked-by: Markus Armbruster <armbru@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-8-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
d030f3cabe tests/qtest/aspeed-hace: Test the crypto command on the AST1030
The AST1030 reuses the AST2600 crypto engine, so it drives the same
scatter-gather transfers and supports the same ECB/CBC/CTR modes. Reuse
the crypto known-answer tests to cover it, registering the AST1030 with
the same modes and scatter-gather flag as the AST2600.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-7-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
48274cdb83 tests/qtest/aspeed-hace: Test the crypto command on the AST2600
Extend the crypto known-answer tests to cover the AST2600 crypto engine,
which drives the source and destination through scatter-gather lists and
adds CTR mode on top of the ECB/CBC modes shared with the AST2500.

Add a scatter-gather runner that describes each buffer with three
non-adjacent fragments to exercise the gather/scatter path, add
AES/DES/3DES CTR vectors (verifying the counter written back to the
context buffer), and give aspeed_add_crypto_tests() a mode mask and a
scatter-gather flag so each SoC registers exactly the modes and transfer
method it supports. Register the AST2600 with ECB/CBC/CTR in
scatter-gather mode.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-6-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
33399898b8 hw/misc/aspeed_hace: Support the CTR mode for the crypto command
The AST2600, AST1030 and later crypto engines add AES/DES/3DES CTR mode
(HACE10[6:4] = 0b100) on top of the ECB/CBC modes shared with the
AST2500. Decode the CTR selection, round the working buffers up to a
whole block so the stream-like final block is still processed a block at
a time, and write the counter advanced by the number of blocks consumed
back to the context buffer so the driver can continue across requests.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-5-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
604cec223c hw/misc/aspeed_hace: Support scatter-gather mode for the crypto command
The AST2600 and later crypto engines drive the source and destination
through scatter-gather lists (HACE10[18]/[19]) rather than the single
contiguous buffers used by the AST2500 direct access mode. Each SG list
entry is a length word (SG_LIST_LEN_LAST marks the final entry) followed
by a DRAM address, matching the hash engine layout.

Add a crypt_prepare_sg() helper that gathers the source into / scatters
the destination out of the bounce buffer by walking the SG list, and
select it or the existing crypt_prepare_direct() from do_crypt_operation
based on HACE10[18], mirroring the hash engine's direct/scatter-gather
dispatch.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-4-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
d566fb6b1e tests/qtest/aspeed-hace: Test the crypto command on the AST2500
Add a crypto known-answer test harness and exercise the AST2500, which
uses the crypto engine's direct access mode. Each mode (AES/DES/3DES in
ECB and CBC) is a separate test that checks the ciphertext, the
plaintext round-trip and, for CBC, the chaining IV written back to the
context buffer.

The key/IV/plaintext/ciphertext values are taken verbatim from the Linux
kernel crypto self-test templates in crypto/testmgr.h.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-3-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
c264c5175e hw/misc/aspeed_hace: Support the crypto command in direct access mode
The crypt command register was previously stubbed out. Implement it for
the direct access mode, where HACE00/HACE04 point directly at contiguous
source and destination buffers. AES-128/192/256, DES and 3DES are
supported in ECB and CBC modes via the qcrypto cipher API; the IV and
key are read from the context buffer (HACE08) and, for CBC, the
resulting chaining IV is written back to the context.

The completion interrupt is now raised for every HACE variant as the
hardware does, which fixes the crypt command hang on the AST2500, AST2600
and AST1030. The AST2700 crypto engine still needs 64-bit DMA and
AES-GCM, which are added later, so it keeps its temporary interrupt-only
workaround until then.

For debugging, the context, source and destination buffers are dumped
through the existing aspeed_hace_hexdump trace event (disabled by
default). CTR mode, scatter-gather mode and AES-GCM are added separately.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20260811060115.1849266-2-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Carlo Marcelo Arenas Belón
1d06e84aa7 hw/arm/aspeed: avoid sign mismatch on sscanf for uart property
using "%u" with sscanf() was likely meant to indicate that a
negative value was unexpected, but with a signed variable it
could result in undefined behaviour.

use "%d" and check for a negative input explicitly.

Signed-off-by: Carlo Marcelo Arenas Belón <carenas@gmail.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260802162828.16880-1-carenas@gmail.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
007ae802b4 tests/functional/arm/test_aspeed_ast1060: Update ASPEED ZEPHYR PROJECT v03.07
Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260804081955.1563537-9-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
274a9cfdeb tests/functional/arm/test_aspeed_ast1030: Update ASPEED Zephyr SDK v03.08
Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260804081955.1563537-8-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
41bb72aed9 tests/functional/arm/test_aspeed_ast2500_sdk: Update ASPEED SDK v11.03
Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260804081955.1563537-7-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
769661a1ac tests/functional/arm/test_aspeed_ast2600_sdk: Update ASPEED SDK v11.03
Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260804081955.1563537-6-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
ea2387e211 tests/functional/aarch64/test_aspeed_ast2700fc: Update ASPEED SDK v11.03
Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260804081955.1563537-5-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
169d499d65 tests/functional/aarch64/test_aspeed_ast2700a1: Update ASPEED SDK v11.03
Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260804081955.1563537-4-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
809720039f tests/functional/aarch64/test_aspeed_ast2700a2: Update ASPEED SDK v11.03
Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260804081955.1563537-3-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
a5f7d65585 hw/i2c/aspeed_i2c: Support the AST2700 master buffer mode
The AST2700 I2C controller can move master DMA payloads through its
internal SRAM pool rather than DRAM. The Linux driver calls this "buffer
mode" and selects it by default. Buffer mode reuses the master DMA
command bits (TX/RX_DMA_EN) and the DMA length registers, so the only
difference from a DRAM transfer is where the data comes from and goes
to: an offset into the pool programmed in I2CM_DMA_TX/RX_ADDR. The
I2CC_VERSION_CTRL FUNC_CFG_DMA_EN bit selects between the two.

Implement I2CC_VERSION_CTRL and, when FUNC_CFG_DMA_EN is clear, move the
payload through the pool buffer instead of DRAM.

I2CC_VERSION_CTRL resets to all ones, so guests that never program it
keep targeting DRAM and behave as before. The register sits above the
register window of the earlier SoCs, which are therefore unaffected.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260804081955.1563537-2-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
508678167c hw/arm: catalina: add NIC and FIO temperature sensors
Model the temperature sensors described by the Catalina device tree that
have existing QEMU device models but were not yet instantiated: the four
IOB NIC TMP421 sensors behind the i2c0 PCA9546 muxes at 0x71 and 0x75, and
the FIO remote TMP75 sensor at 0x4f on the i2c1 mux.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-25-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
49ec283f15 hw/arm: catalina: model PCA9555 IO expanders with their own type
The Catalina BMC device tree describes several IO expanders as nxp,pca9555.
These were previously instantiated as PCA9552 devices as no PCA9555 model
existed. Now that a dedicated PCA9555 device is available, use it so the
emulated IO expanders match the hardware.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-24-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
b3fa882508 tests/qtest: pca9554: test the PCA9536 4-bit variant
The PCA9536 shares the PCA9554 register map and code path but exposes
only four pins. Add a pca9536 node and check its reset defaults and
output-to-input reflection are masked to the low nibble.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-23-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
f9bf753b58 tests/qtest: pca9554: test absence of command auto-increment
The PCA9554 selects one of its four registers with a single command byte
and does not auto-increment the register pointer, so a multi-byte I2C
transfer keeps addressing the register chosen by the command byte instead
of walking through the register map.

Add a test covering this: a two-byte read returns the addressed register
twice, and a two-byte write updates only that register, leaving its
neighbour untouched.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-22-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
e1338eb6da tests/qtest: pca9554: test polarity inversion
Verify that the polarity register inverts the value read back from the
INPUT register, both on pulled-up inputs and on output-driven pins, while
leaving the OUTPUT register itself unchanged.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-21-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
e5f73c36db tests/qtest: pca9554: test output-to-input reflection and pull-ups
Check that a pin configured as output drives its OUTPUT register level
onto the pin (push-pull) as reflected by the INPUT register, and that a
pin configured as input floats high through its pull-up.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-20-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
ab707882d8 tests/qtest: add PCA9554 register access tests
Add a qtest for the PCA9554 8-bit I/O port expander exercising the basic
register access: power-on reset defaults and read/write of the OUTPUT,
CONFIG and POLARITY registers.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-19-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
a52cf5a182 hw/gpio: pca9554: expose pin%d as a string property
The pinN properties are accessed with visit_type_str() (values "low" and
"high"), but were registered as type "bool", so introspection advertised
a boolean while the accessors require a string. Register them as "str",
matching the PCA9555 GPIO variant.

Fixes: de0c7d543b ("misc: Add a pca9554 GPIO device model")
Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-18-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
ed8e011b92 hw/gpio: pca9554: reflect push-pull outputs in the input register
pca9554_update_pin_input() derived the pin level from CONFIG | OUTPUT,
which treated an output driven high as Hi-Z and let ext_state pull it
low. The PCA9554/PCA9536 output stage is push-pull, so a pin configured
as an output drives the OUTPUT register level regardless of any external
agent. Reflect the output value directly for output pins and keep the
pull-up/ext_state behaviour for input pins, matching the PCA9555 GPIO
variant.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-17-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
0d02f7b877 hw/gpio: pca9554: add hw-dir property honoring the configured pin direction
The pinN QOM accessors are meant to let external agents observe and
stimulate the expander's pins, but their default behaviour does not
match real hardware:

 - to "drive" a pin, set_pin writes the OUTPUT register and then clears
   the pin's Configuration bit to force it into output mode. On a real
   device the pin direction is owned solely by the host (programmed
   through the Configuration register over I2C); an external agent can
   neither flip a pin's direction nor impose a level on a pin the host
   drives as an output -- the latter is a voltage conflict, not a legal
   operation.
 - get_pin returns a CONFIG|OUTPUT composite, i.e. the guest's intent,
   rather than the level actually sampled on the pin.

The PCA9555 GPIO variant (hw/gpio/pca9552.c) already models this
correctly and unconditionally: only input-configured pins can be driven
from outside, and reads return the sampled INPUT register.

Add a "hw-dir" property to bring the pca9554 pin accessors in line with
the hardware (and with the PCA9555 model), without changing the
behaviour seen by existing users:

 - hw-dir=true: set_pin only drives pins the guest has configured as
   inputs; a set on an output pin is refused with a LOG_UNIMP warning.
   get_pin returns the sampled INPUT register.
 - hw-dir=false (default): keeps the legacy, non-conformant behaviour
   for backward compatibility.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-16-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
5eceb48bbe hw/gpio: pca9554: add PCA9536 support
The PCA9536 is a 4-bit I/O expander that's register-compatible with the
PCA9554 but only has 4 pins.  Rather than duplicating the whole driver,
make the existing PCA9554 model parameterizable and register PCA9536 as
a subtype.

Introduce a PCA9554Class with a pin_count property, and replace every
hard-coded PCA9554_PIN_COUNT reference in the driver with the class
value.  The reset function now computes the correct pin mask from
pin_count instead of assuming 0xFF.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-15-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
f41bc13152 tests/qtest: pca9552: test behaviour specific to the LED variant
The PCA9552 shares its device model with the PCA9535/PCA9555 GPIO
expanders but decodes registers differently. Add tests for the behaviour
that is specific to the LED variant and diverges from the PCA9555:

  - the power-on reset defaults of the prescaler, PWM and LED-selector
    registers;
  - the prescaler/PWM registers (2-5), which are OUTPUT/POLARITY on the
    PCA9555, as plain read/write storage;
  - the auto-increment, which only advances when the AI command bit is set
    and wraps modulo the full 10-register map (rather than toggling bit 0
    within a register pair);
  - the 4-bit command decode, where an out-of-range register reads back
    0xFF instead of aliasing into the register window.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-14-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
f43ee33866 tests/qtest: pca9555: test auto-increment and command wrapping
Add tests for the I2C command protocol of the GPIO variant: the
auto-increment that toggles bit 0 within a register pair on reads and
writes, and the 3-bit command wrapping that aliases out-of-range register
addresses back into the register window.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-13-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
f2fa57afff tests/qtest: pca9555: test polarity inversion
Add tests for the polarity inversion register: the inversion is applied
when reading the INPUT register, both for input pins (pull-up) and for
output-driven pins, and it does not affect the OUTPUT register readback.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-12-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
0e96438679 tests/qtest: pca9555: test output-to-input reflection and pull-ups
Add tests covering the pin I/O semantics of the expander: output-driven
pins reflected in the input register, the pull-up seen on input-configured
pins, and the independence of the two 8-bit ports.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-11-82a63fead90c@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
71aa15068c tests/qtest: add PCA9555 register access tests
Introduce a qtest for the PCA9555 16-bit I/O port expander.

This first set covers the power-on reset defaults and the read/write
behaviour of the OUTPUT, CONFIG and POLARITY register pairs.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-10-814575bc076b@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
a11babc632 hw/gpio: pca9552: expose GPIO pins as pin%d QOM properties
The PCA9552 exposes its LED channels as led%d QOM string properties, but
the GPIO variants (PCA9535/PCA9555) inherited the same led%d interface,
which drives the LED selector registers and is meaningless for a plain
I/O expander.

Add pin%d string properties ("low"/"high") for the GPIO variants,
mirroring the standalone pca9555 model:

  - reading returns the raw pin logic level from the INPUT register;
  - writing drives the external input level, but only for pins the guest
    has configured as inputs (writes to output pins are ignored with a
    LOG_UNIMP message).

The LED variant keeps its led%d properties.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-9-814575bc076b@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
f8e1f6488f hw/gpio: pca9552: conform GPIO command handling to the datasheet
The PCA9535/PCA9555 GPIO expanders share the PCA955X command dispatch
path with the PCA9552 LED blinker, but their register access differs from
the LED variant:

  - Auto-increment happens on every access and toggles bit 0 so the
    pointer stays within the addressed register pair (input, output,
    polarity, config); there is no AI enable bit.

  - The command byte only decodes 3 bits, so addresses beyond the last
    register alias back into the 8-register window instead of faulting.

Branch the auto-increment and command-decode logic on has_led_support so
the GPIO variants follow their datasheet while the PCA9552 behaviour is
left untouched.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-8-814575bc076b@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
469daf3eef hw/gpio: pca9552: apply input polarity inversion on read
The PCA9535 polarity inversion register inverts the value read back from
the input port for every pin, regardless of its direction, and does not
affect the output drive or the physical pin level.

Store the raw pin level in the input register and apply the polarity
inversion when the input port is read, instead of XORing it into the
stored value of output-configured pins only. The interrupt output now
reflects the raw pin level, matching the datasheet.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-7-814575bc076b@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
0bfc57212e hw/gpio: pca9552: use the Resettable interface instead of legacy reset
Convert the PCA9552 and PCA9535/PCA9555 reset handlers from the legacy
device reset hook to the Resettable interface: move each reset body into
a ResettableHoldPhase handler and register it through the class's
ResettableClass::phases.hold instead of device_class_set_legacy_reset().

No functional change.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-6-814575bc076b@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
ee7042b317 hw/gpio: pca9552: declare pca9555 device as an alias of pca9535 device
PCA9555 HW is mostly identical to PCA9535.
PCA9555 HW features pull-up resistors that are not available on PCA9535.

Pull-up are not handled by current PCA955x implementation and PCA9535
already initializes input as Hi-Z.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-5-814575bc076b@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
520ea63bd7 hw/gpio: pca9552: default description to the instantiated type name
When no description is supplied, fall back to the actual QOM type name
(pca9552 / pca9535 / pca9555) via object_get_typename() instead of the
opaque "pca-unspecified" placeholder, matching the PCA9554 model and
giving meaningful device labels in traces.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-4-814575bc076b@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
4618d0465a hw/gpio: pca9552: rename I2CSlave member to parent_obj
Use the conventional parent_obj name for the embedded I2CSlave instance.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Signed-off-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-3-814575bc076b@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
9c99502583 hw/gpio: pca9552: move PCA955xState definition out of the header
Nothing outside pca9552.c uses the PCA955xState structure, its instance
checker, or the PCA955X_NR_REGS/PCA955X_PIN_COUNT_MAX defines: the board
files and qtests only rely on the TYPE_* name macros (and the register
macros in pca9552_regs.h).

Move the state structure and the size defines into pca9552.c, leaving
pca9552.h with just the type-name macros. While at it, replace the
separate DECLARE_INSTANCE_CHECKER and DECLARE_CLASS_CHECKERS declarations
with a single OBJECT_DECLARE_TYPE().

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-2-814575bc076b@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
39cb912af9 hw/gpio: pca9552: register types with DEFINE_TYPES()
Replace the separate TypeInfo definitions and pca955x_register_types()
registration function with a single type array registered through the
DEFINE_TYPES() macro, to prepare addition of new PCA955x-derived devices.

No functional change.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Reviewed-by: Glenn Miles <milesg@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260709-catalina-upgrade-v1-1-814575bc076b@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
15d88540b8 hw/arm: anacapa: add ADC128D818 devices
Wire up the two ADC128D818 instances that appear in the Anacapa DTS:
one on i2c8 mux channel 0 and one on i2c13 mux channel 3.

Reviewed-by: Cédric Le Goater <clg@redhat.com>
Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Link: https://lore.kernel.org/qemu-devel/20260707091609.97759-9-emmanuel.blot@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
b3e56ab919 hw/arm/aspeed: anacapa: use ASCII in comments
The anacapa machine source contains a few comments using the U+2014 EM
DASH character. Replace them with plain ASCII hyphens so the file stays
ASCII-only.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Link: https://lore.kernel.org/qemu-devel/20260707091609.97759-8-emmanuel.blot@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
41bea707fe tests/qtest: adc128d818: test operating modes and power control
Cover advanced-configuration mode selection (single-ended,
pseudo-differential pairs, and mixed) and the reset of readings on
reconfiguration, plus channel disable, one-shot conversion, deep
shutdown, BUSY_STATUS lifecycle, and conversion-rate gating.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Link: https://lore.kernel.org/qemu-devel/20260707091609.97759-6-emmanuel.blot@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
af685633f4 tests/qtest: adc128d818: test limit interrupts
Cover per-channel high- and low-limit interrupt status, the
INT_CLEAR bit gating the monitoring loop, and the temperature
high-limit alarm with hysteresis.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Link: https://lore.kernel.org/qemu-devel/20260707091609.97759-5-emmanuel.blot@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
c7300dca45 tests/qtest: adc128d818: test voltage and temperature conversion
Cover single-ended voltage conversion across all channels, voltage
and temperature boundary and clamping cases, and scaling against an
external voltage reference.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Link: https://lore.kernel.org/qemu-devel/20260707091609.97759-4-emmanuel.blot@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
464e655143 tests/qtest: adc128d818: add test harness and register access
Introduce the QOS test node and QMP property helpers for the
ADC128D818, and cover basic register access: manufacturer and
revision IDs, power-on-reset defaults, software reset, and the
ain and temperature property readback.

Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Link: https://lore.kernel.org/qemu-devel/20260707091609.97759-3-emmanuel.blot@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Emmanuel Blot
325d1c9344 hw/sensor: adc128d818: add 12-bit 8-channel ADC device
The ADC128D818 is a TI 12-bit, 8-channel I2C ADC used on several
OpenBMC platforms for voltage and temperature monitoring.

Implement the device with:
 - four operating modes
 - 12-bit voltage conversion from QOM inputs
 - 9-bit temperature conversion from milli-degree Celsius QOM inputs
 - switchable internal or external voltage reference
 - per-channel high/low limit registers
 - interrupt support
 - software reset
 - one-shot conversion support in shutdown mode

Reviewed-by: Alexander Hansen <alexander.hansen@9elements.com>
Tested-by: Alexander Hansen <alexander.hansen@9elements.com>
Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
Link: https://lore.kernel.org/qemu-devel/20260707091609.97759-2-emmanuel.blot@free.fr
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
828872aa98 tests/qtest/ast2700-smc-test: Add Data FIFO mode test
Add two qtest cases exercising the new AST2700 Data FIFO-based flash
access path (R_DATA_FIFO at spi_base + 0x200).

Write_page_datafifo sends the page-program command and data through
the FIFO port, then verifies the result via the regular read path.
Read_page_datafifo writes a page the regular way, then reads it back
through the FIFO port, so both directions are checked independently.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260717084559.3477061-10-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
29139270d8 hw/ssi/aspeed_smc: Add Data FIFO-based flash access support for AST2700
AST2700 supports a Data FIFO mode where flash accesses can be performed
directly through Data FIFO MMIO offsets. The Data FIFO start offset
increments by one for every 16MB of flash address space, allowing the
chip select (CS) to be decoded from the Data FIFO offset.

This change adds Data FIFO support to the Aspeed SMC model and introduces
a class callback to translate Data FIFO offsets into CS indices. For
AST2700, the Data FIFO offset is matched against the segment start address
of each CS to determine the target flash device.

The SMC register region size (nregs) is also extended dynamically
based on the number of supported chip selects to cover all possible
Data FIFO regions.

This breaks migration compatibility with older QEMU builds for the
affected models, even though Aspeed machines are not officially
covered by migration compatibility guarantees.

Bump version_id to 4 and minimum_version_id to 2 to reflect the
incompatible format.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Tested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260717084559.3477061-9-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
ab480be728 hw/arm/ast27x0: Share FMC controller with SSP and TSP
AST2700 provides a single FMC controller shared by the main CA35 processor
(PSP) and the SSP/TSP coprocessors.

>From the PSP perspective, the FMC controller is memory-mapped at
0x14000000–0x140000FF. The SSP and TSP access the same controller through
a different address window at 0x74000000–0x740000FF.

This change allows the SSP and TSP SoC models to reference the existing
PSP FMC instance instead of creating independent controllers. An MMIO
alias is added in the SSP and TSP address spaces to map their FMC access
window to the shared FMC device.

This ensures consistent FMC state across PSP, SSP, and TSP and matches
the AST2700 hardware design.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Tested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260717084559.3477061-8-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
dba6f5c1df hw/arm/ast27x0: Share single SCUIO instance across PSP, SSP, and TSP
AST2700 has a single SCUIO hardware block, memory-mapped at
0x14C02000–0x14C03FFF from the perspective of the main CA35 processor (PSP).
The SSP and TSP coprocessors access this same SCUIO block at different
addresses: 0x74C02000–0x74C03FFF.

Previously, each subsystem (PSP, SSP, and TSP) instantiated its own SCUIO
device, resulting in three independent SCUIO instances in the QEMU model.
In real hardware, however, only a single SCUIO exists and is shared among
all processors.

This commit reworks the SCUIO model to correctly reflect the hardware
behavior by allowing SSP and TSP to reference the PSP’s SCUIO instance.
The following changes are introduced:

- Add a scuio property to Aspeed27x0CoprocessorState for linking the
  coprocessor to the PSP’s SCUIO instance.
- Replace per-coprocessor SCUIO instantiation with a shared SCUIO link.
- Add "MemoryRegion scuio_alias" to model address remapping for SSP and TSP.
- Create SCUIO alias regions in both SSP and TSP coprocessors and map
  them at 0x74C02000 to mirror the PSP’s SCUIO registers.
- Ensure the SCUIO device in PSP is realized before SSP/TSP alias setup.

With this change, PSP, SSP, and TSP now share a consistent SCUIO state,
matching the single-SCUIO hardware design of AST2700.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Tested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260717084559.3477061-7-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:58 +02:00
Jamin Lin
7bb309ed43 hw/arm/aspeed_ast27x0: Pass realized PSP SoC to SSP/TSP initialization
Pass the realized PSP SoC to the SSP/TSP initialization helpers instead
of retrieving it from the MachineState.

This makes the dependency explicit, since the SSP and TSP coprocessors
use resources owned by the PSP SoC, including the UARTs, SRAM, SCU and
SCUIO. The PSP SoC must therefore be realized before the coprocessors
are initialized.

No functional change.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Tested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260717084559.3477061-6-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
2fbefe0eb4 hw/misc/aspeed_scu: Add separate reset handler for AST2700 SCUIO
Introduce a dedicated reset handler for SCUIO.

Previously, SCU and SCUIO shared the same reset handler. This no longer
fits the AST2700 design, where SCU uses the Aspeed2700SCUState subclass
and will handle coprocessor-related control in future changes.

Since these controls are defined in SCU (not SCUIO), SCU and SCUIO
should not share the same reset logic.

This change gives SCUIO its own reset handler and prepares for upcoming
SCU-specific functionality.

No functional change.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Tested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260717084559.3477061-5-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
ee3f2ace6f hw/arm/aspeed_ast27x0: Move SCU link into AST27x0 coprocessors
The SCU link is only needed by the AST27x0 SSP/TSP coprocessors for their
AST2700-specific SCU alias window.

Move the link property from the common AspeedCoprocessorState into
Aspeed27x0CoprocessorState, so the generic coprocessor model no longer
contains an AST2700-specific dependency.

Also validate that the SCU link has been provided during device realize
before accessing it.

No functional change.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Tested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260717084559.3477061-4-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
69ba4d5b96 hw/arm/aspeed: Use Aspeed2700SCUState for AST2700 users
Now that Aspeed2700SCUState has been introduced, update the AST1700 and
AST27x0 SoCs to instantiate the AST2700-specific SCU subclass instead of
the generic AspeedSCUState.

Also update the AST27x0 FC board to link the SSP/TSP coprocessors to the
AST2700 SCU instance.

This prepares the AST2700 platform for subsequent patches that move
AST2700-specific SCU functionality into the subclass.

No functional change.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Tested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260717084559.3477061-3-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
ffcbeb1f5a hw/misc/aspeed_scu: Introduce Aspeed2700SCUState
Introduce Aspeed2700SCUState as an AST2700-specific subclass of
AspeedSCUState.

Currently, AST1700 and AST2700 reuse the generic AspeedSCUState.
However, AST2700 requires SCU functionality that is specific to the
platform, particularly for interactions with its coprocessors.

Introduce a dedicated Aspeed2700SCUState to provide an extension point
for AST2700-specific functionality while keeping the generic
AspeedSCUState unchanged.

Subsequent patches will migrate AST2700 users to the new subclass and
move AST2700-specific code into it.

No functional change.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Tested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260717084559.3477061-2-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Cédric Le Goater
a15167a329 tests/qtest: aspeed_smc: Add Quad Output Read (QOR) test coverage
Add read_page_mem_qor (CTRL_FREADMODE with QOR command and quad data
IO mode) and write_page_qor (user-mode QOR) tests.

Reviewed-by: Bin Meng <bin.meng@processmission.com>
Link: https://lore.kernel.org/qemu-devel/20260714124621.522948-5-clg@redhat.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Cédric Le Goater
da5598227d tests/qtest: aspeed_smc: Add Dual Output Read (DOR) test coverage
Add read_page_mem_dor (CTRL_FREADMODE with DOR command and dual data
IO mode) and write_page_dor (user-mode DOR) tests.

Reviewed-by: Bin Meng <bin.meng@processmission.com>
Link: https://lore.kernel.org/qemu-devel/20260714124621.522948-4-clg@redhat.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Cédric Le Goater
afd36b9c07 tests/qtest: aspeed_smc: Add fast-read test coverage
Introduce a spi_ctrl_set_fast_read() helper and add
read_page_mem_fast_read (CTRL_FREADMODE with dummy byte) and
write_page_fast_read (user-mode FAST_READ) tests.

While at it, replace the license boilerplate with SPDX identifier.

Reviewed-by: Bin Meng <bin.meng@processmission.com>
Link: https://lore.kernel.org/qemu-devel/20260714124621.522948-3-clg@redhat.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Cédric Le Goater
7a79a76286 tests/qtest: aspeed_smc: Introduce read_page_mem_fn for page read helpers
This to prepare for fast-read variants. No functional change.

Reviewed-by: Bin Meng <bin.meng@processmission.com>
Link: https://lore.kernel.org/qemu-devel/20260714124621.522948-2-clg@redhat.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
87c5653340 tests/functional/aarch64/test_aspeed_ast2700: Add USB EHCI test for AST2700 A1/A2
Add a functional test to verify USB EHCI support on the AST2700 A2/A1
by attaching a USB keyboard device and checking its
enumeration via lsusb.

This introduces a helper routine that runs lsusb in the guest
and validates that the emulated "QEMU USB Keyboard" is detected.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260713032704.3583103-11-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
39170be7cf hw/arm/aspeed_ast27x0: Enable 64-bit EHCI DMA addressing
AST2700 supports a 64-bit DRAM address space. Therefore, DMA
transactions must be capable of accessing 64-bit addresses.

Enable the "caps-64bit-addr" property for the EHCI controllers
on AST2700 so that USB DMA operations can correctly handle
64-bit memory addresses.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260713032704.3583103-10-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
8b529eeccb hw/arm/aspeed_ast27x0: Set EHCI ctrldssegment-default
On AST2700 platforms, system DRAM is mapped above 4GB with a base
address at 0x400000000.

The Linux EHCI driver programs the segment register to zero when
64-bit addressing is supported. As a result, descriptor addresses
derived from the EHCI registers do not include the DRAM base
address.

Descriptor memory is allocated through the DMA API with a 64-bit
DMA mask, allowing descriptors to reside in DRAM above 4GB. On
AST2700, EHCI queue heads (QH) and queue element transfer
descriptors (qTD) are therefore placed at addresses starting from
0x400000000.

Set the ctrldssegment-default property to "sc->memmap[ASPEED_DEV_SDRAM] >> 32"
so the upper 32 bits of descriptor addresses are adjusted accordingly. This
allows the emulated EHCI controller to construct correct system
addresses when accessing descriptors in DRAM above 4GB.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260713032704.3583103-9-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
11438bb2b4 hw/usb/hcd-ehci: Add ctrldssegment-default property
When 64-bit addressing is supported, the Linux EHCI driver programs the
segment register to zero. See ehci_run function:
https://github.com/torvalds/linux/blob/master/drivers/usb/host/ehci-hcd.c

The driver comment also notes that descriptor structures allocated from
the DMA pool use segment zero semantics.

Descriptor memory is allocated using the DMA API. The platform driver
configures a 64-bit DMA mask so memory can be allocated above 4GB.
See ehci_platform_probe function:
https://github.com/torvalds/linux/blob/master/drivers/usb/host/ehci-platform.c

On AST2700 platforms, system DRAM is mapped above 4GB at 0x400000000.
As a result, descriptor addresses constructed directly from the guest
EHCI registers do not match the actual system address used by the
controller when fetching queue heads (QH) and queue element transfer
descriptors (qTD).

Add a ctrldssegment-default property so platforms can provide a
descriptor address offset when constructing descriptor addresses.
This allows systems where DRAM resides above 4GB to access EHCI
descriptors correctly.

The default value is zero, so existing machines are not affected.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260713032704.3583103-8-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
11b30c864a hw/usb/hcd-ehci: Implement 64-bit siTD descriptor addressing
EHCI supports 64-bit control data structure addressing when the
64-bit Addressing Capability bit in HCCPARAMS is set. In that mode,
the CTRLDSSEGMENT register provides the upper 32 bits that are
concatenated with 32-bit link pointer values to form full 64-bit
descriptor addresses (EHCI 1.0, section 2.3.5 and Appendix B).

siTD link pointers are stored as 32-bit values and must be expanded
to full 64-bit descriptor addresses when 64-bit mode is enabled.
Update the siTD traversal path to use ehci_get_desc_addr() when
following link pointers.

When 64-bit capability is disabled, descriptor addresses remain
32-bit and existing behaviour is unchanged.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260713032704.3583103-7-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
d027e3c63c hw/usb/hcd-ehci: Implement 64-bit iTD descriptor addressing
EHCI supports 64-bit control data structure addressing when the
64-bit Addressing Capability bit in HCCPARAMS is set. In that mode,
the CTRLDSSEGMENT register provides the upper 32 bits that are
concatenated with 32-bit link pointer values to form full 64-bit
descriptor addresses (EHCI 1.0, section 2.3.5 and Appendix B).

iTD link pointers are stored as 32-bit values and must be expanded
to full 64-bit descriptor addresses when 64-bit mode is enabled.
Update the iTD traversal path to use ehci_get_desc_addr() when
following link pointers.

Appendix B also defines high dword fields for iTD buffer pointers.
Add bufptr_hi[7] to EHCIitd and use ehci_get_buf_addr() to construct
full 64-bit buffer addresses from bufptr[] and bufptr_hi[] fields
when processing isochronous transfers. This allows buffers above
4GB to be handled correctly.

When 64-bit capability is disabled, descriptor and buffer addresses
remain 32-bit and existing behaviour is unchanged.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260713032704.3583103-6-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
dea1ed14c9 hw/usb/hcd-ehci: Implement 64-bit qTD descriptor addressing
EHCI supports 64-bit addressing when the 64-bit Addressing Capability
bit in HCCPARAMS is set. In that mode, the CTRLDSSEGMENT register
provides the upper 32 bits that are concatenated with 32-bit link
pointer values to form 64-bit control data structure addresses
(EHCI 1.0, section 2.3.5 and Appendix B).

qTD link pointers (current_qtd/next_qtd/altnext_qtd and qTD.next)
are stored as 32-bit values in the data structures and must be
expanded to full 64-bit descriptor addresses when 64-bit mode is
enabled. Update the qTD traversal paths to use ehci_get_desc_addr()
when following link pointers.

Appendix B also defines high dword fields for qTD buffer pointers.
Add bufptr_hi[5] to EHCIqtd and extend qTD fetch and QH overlay
handling to load and propagate the high buffer pointer fields.

When 64-bit capability is disabled, descriptor and buffer addresses
remain 32-bit and existing behaviour is unchanged.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260713032704.3583103-5-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
0cb43fdc0b hw/usb/hcd-ehci: Implement 64-bit QH descriptor addressing
EHCI supports 64-bit control data structure addressing when the
64-bit Addressing Capability bit in HCCPARAMS is set. In that mode,
the CTRLDSSEGMENT register supplies the upper 32 bits which are
concatenated with 32-bit link pointer fields to form full 64-bit
descriptor addresses (EHCI 1.0, section 2.3.5 and Appendix B).

The current implementation assumes 32-bit QH descriptor addresses
and directly uses link pointer values without applying the
CTRLDSSEGMENT upper dword.

Introduce a helper, ehci_get_desc_addr(), to construct full 64-bit
descriptor addresses when 64-bit capability is enabled. Update QH
traversal paths (async list walk, horizontal QH link, and periodic
schedule entry handling) to use the translated 64-bit addresses.

EHCI 64-bit buffer pointer fields are defined in Appendix B as
split 32-bit low/high parts located at separate offsets, rather
than a single contiguous 64-bit field. Therefore, the buffer
pointers cannot be represented as uint64_t bufptr[5] without
violating the descriptor layout defined by the specification.

Introduce ehci_get_buf_addr() to construct full 64-bit buffer
addresses from bufptr[] and bufptr_hi[] fields. Use this helper
when calculating transfer buffer addresses so that data buffers
above 4GB are correctly handled.

Also add bufptr_hi[5] to EHCIqh to support 64-bit buffer pointer
fields as defined in Appendix B.

When 64-bit capability is disabled, descriptor addresses remain
32-bit and existing behaviour is unchanged.

Note: Similar split 64-bit buffer pointer handling is required for
qTD, iTD and siTD descriptors, which will be addressed in follow-up
changes.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260713032704.3583103-4-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
7e6c5727e1 hw/usb/hcd-ehci: Add property to advertise 64-bit addressing capability
Introduce a new boolean property, "caps-64bit-addr", to control
HCCPARAMS[0] (64-bit Addressing Capability).

When enabled, the EHCI controller advertises support for 64-bit
address memory pointers as defined in the EHCI specification
(Table 2-7, HCCPARAMS). This allows software to use the 64-bit
data structure formats described in Appendix B.

When disabled (default), the controller reports 32-bit addressing
capability and uses the standard 32-bit data structures.

The EHCI CTRLDSSEGMENT register provides the upper 32 bits [63:32] used to
form 64-bit addresses for EHCI control data structures. Per EHCI 1.0
spec section 2.3.5, when the HCCPARAMS 64-bit Addressing Capability bit
is zero, CTRLDSSEGMENT is not used: software cannot write it and reads
must return zero.

Add a capability check in the operational register write handler and
reject guest writes to CTRLDSSEGMENT when 64-bit addressing is
not enabled.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260713032704.3583103-3-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Jamin Lin
38ed803aeb hw/usb/hcd-ehci: Change descriptor addresses to 64-bit with migration compatibility
Change internal EHCI descriptor addresses from uint32_t to uint64_t.

The following fields are updated:
- EHCIPacket::qtdaddr
- EHCIQueue::{qhaddr, qtdaddr}
- EHCIState::{a_fetch_addr, p_fetch_addr}

Update get_dwords() and put_dwords() to take 64-bit addresses and
propagate the type change through the descriptor traversal paths.

Adjust NLPTR_GET() to operate on 64-bit values:

    #define NLPTR_GET(x) ((x) & ~0x1fULL)

so that link pointer masking works correctly when descriptor
addresses exceed 32-bit space. The previous mask (0xffffffe0)
implicitly truncated addresses to 32 bits.

This patch does not change the on-wire descriptor layout yet.
It only removes the internal 32-bit address limit and prepares
for later patches that will add full 64-bit QH/qTD/iTD/siTD support.

Update the EHCI trace-events prototypes for QH, qTD, iTD, and siTD to
use uint64_t for the address argument and print it with PRIx64. This
ensures full 64-bit addresses are shown in trace output and improves
debugging of queue heads and transfer descriptors.

Migration compatibility:

To preserve backward migration compatibility, keep the legacy 32-bit
fetch address fields (a_fetch_addr_32, p_fetch_addr_32) alongside the
new 64-bit fields.

Migration format is selected using a machine compat property
"x-migrate-fetch-addr-64bit":

- Old machine types migrate 32-bit fetch addresses
- New machine types migrate full 64-bit fetch addresses

This is implemented using VMSTATE_UINT32_TEST() and
VMSTATE_UINT64_TEST() so that only the appropriate format is migrated.

In pre_save, the 32-bit shadow fields are populated when migrating
to old machine types. In post_load, the 32-bit values are restored
into the 64-bit fields when loading old migration streams.

No functional change.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260713032704.3583103-2-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Philippe Mathieu-Daudé
826f9765c0 hw/arm/aspeed: Add missing Kconfig dependencies on optional components
Add missing Kconfig optional dependencies to avoid the
following runtime error:

  qemu-system-aarch64: -device loader,force-raw=on,addr=0x400000000,file=./u-boot.bin: 'loader' is not a valid device model name
  qemu-system-aarch64: -device e1000e,netdev=net1,bus=pcie.2: 'e1000e' is not a valid device model name

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260709164103.37614-4-philmd@oss.qualcomm.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Philippe Mathieu-Daudé
6440880ed3 hw/arm/aspeed: Add missing Kconfig dependencies on required components
Add various missing Kconfig dependencies of the Aspeed SoCs:

- USB EHCI (commit bfdd34f1ca "hw/arm: ast2400/ast2500: Wire up
  EHCI controllers")
- OR-IRQ (commit d831c5fd86 "aspeed/intc: Add AST2700 support")
- SDHCI (commit 2bea128c3d "hw/sd/aspeed_sdhci: New device"
  and f25c0ae107 "aspeed/soc: Add AST2600 support")

This fixes the following runtime issues:

  qemu-system-aarch64: unknown type 'platform-ehci-usb'
  qemu-system-aarch64: unknown type 'or-irq'
  qemu-system-aarch64: unknown type 'generic-sdhci'

Cc: qemu-stable@nongnu.org
Fixes: 2bea128c3d ("hw/sd/aspeed_sdhci: New device")
Fixes: f25c0ae107 ("aspeed/soc: Add AST2600 support")
Fixes: d831c5fd86 ("aspeed/intc: Add AST2700 support")
Fixes: bfdd34f1ca ("hw/arm: ast2400/ast2500: Wire up EHCI controllers")
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260709164103.37614-3-philmd@oss.qualcomm.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Philippe Mathieu-Daudé
2fad751ed6 hw/arm/aspeed: Add missing PCI_EXPRESS -> PCIE_PORT Kconfig dependency
Add the missing Kconfig dependency on PCIE_PORT to avoid the
following runtime error:

  Type 'aspeed.pcie-root-port' is missing its parent 'pcie-root-port-base'

No need to have ASPEED_SOC select PCI_EXPRESS since it is
already selected by PCI_EXPRESS_ASPEED.

Cc: qemu-stable@nongnu.org
Fixes: 2af56518fa ("hw/pci-host/aspeed: Add AST2600 PCIe Root Port and make address configurable")
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260709164103.37614-2-philmd@oss.qualcomm.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-11 18:25:57 +02:00
Denis V. Lunev
0573b1e11a MAINTAINERS: add myself to IDE maintainers
Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Stefan Hajnoczi <stefanha@redhat.com>
CC: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260730081325.1816193-2-den@openvz.org>
[John Snow <jsnow@redhat.com> has acknowledged this:
https://lore.kernel.org/qemu-devel/CAFn=p-abWtYqGtCbH9XTK62oEPK=vLPjy-scwqR+crXvOQ3RrA@mail.gmail.com/
--Stefan]
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-11 11:48:25 -04:00
Stefan Hajnoczi
b2718011fb hexagon: fix cmpy*(), same-slot packets
Fixes for these two bugs:
 * short-circuited packets with `cmpy(Rs,Rt)` would get the wrong result
 when Rs is the same register as Rt.
 * some packets with slot constraints were incorrectly rejected as having
 an invalid encoding/shuffle.
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEPWaq5HRZSCTIjOD4GlSvuOVkbDIFAmp0/fkACgkQGlSvuOVk
 bDLMNBAAyqvEkchJfhrvAgY6kOkf4z9SoC8dQedyw26S3rtmjWFH8rBIQC1WYenc
 O+bOfGW1apv9VpNr+8BsX9WIBfNF6yNVCu6+RxoG0/A2JOD09T7q7+vfJAKJXXk9
 d0c8plnMBa0waqIwl1Pn+JIzcYBwVgqQkBAlY9BVbmtpBuf8GW9IctJcJpst9huP
 9pyY8UNo6THvstPKB1d7dwNu+/35+QDuF2j9OI7ueY0kft7PmRn02sJBmgslhkx2
 KPTjgyNT1jYR2y+jLXJfJUQHuJPn0pwW6QkoPB1P9zghxBjbGlETK8fxFZBuZGL7
 y/c003GHsNBOhDj2fzrPfrh8foIg132ldkbV4+h4Ybpz/TPa/3aKhpfDm7wNTTHA
 mQW17HZ5j9Zp3PzEL1JmZA8Ek5pFBFQSnsxwEo0eMb6ZjNjsZzaqO0rpJ0iZ3kPT
 P889exq0A6qMT8v/o04R9r258VFnuiifBJNkEdQohQfNOKO+N/LcpSlvsaVR9Rid
 i5/ikTlPOlFm8AvgRa37KOF7m+jzp7brvEreKtlhmeaQv5Oox2F4fBsEo6WWVA5R
 xzjpTrdstc8l5NwY1iZEe2LexgcO0kxGvteFciFvwWSZ++91nl6/a99Nts06AfHc
 p8Cor5pzeOfKZBbECbTnp8BGwDY+CCpo0Mg0Bsuupfj/kb/uYxQ=
 =OpJQ
 -----END PGP SIGNATURE-----

Merge tag 'hex-20260806-pull-request' of https://github.com/qualcomm/qemu into staging

hexagon: fix cmpy*(), same-slot packets

Fixes for these two bugs:
* short-circuited packets with `cmpy(Rs,Rt)` would get the wrong result
when Rs is the same register as Rt.
* some packets with slot constraints were incorrectly rejected as having
an invalid encoding/shuffle.

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEPWaq5HRZSCTIjOD4GlSvuOVkbDIFAmp0/fkACgkQGlSvuOVk
# bDLMNBAAyqvEkchJfhrvAgY6kOkf4z9SoC8dQedyw26S3rtmjWFH8rBIQC1WYenc
# O+bOfGW1apv9VpNr+8BsX9WIBfNF6yNVCu6+RxoG0/A2JOD09T7q7+vfJAKJXXk9
# d0c8plnMBa0waqIwl1Pn+JIzcYBwVgqQkBAlY9BVbmtpBuf8GW9IctJcJpst9huP
# 9pyY8UNo6THvstPKB1d7dwNu+/35+QDuF2j9OI7ueY0kft7PmRn02sJBmgslhkx2
# KPTjgyNT1jYR2y+jLXJfJUQHuJPn0pwW6QkoPB1P9zghxBjbGlETK8fxFZBuZGL7
# y/c003GHsNBOhDj2fzrPfrh8foIg132ldkbV4+h4Ybpz/TPa/3aKhpfDm7wNTTHA
# mQW17HZ5j9Zp3PzEL1JmZA8Ek5pFBFQSnsxwEo0eMb6ZjNjsZzaqO0rpJ0iZ3kPT
# P889exq0A6qMT8v/o04R9r258VFnuiifBJNkEdQohQfNOKO+N/LcpSlvsaVR9Rid
# i5/ikTlPOlFm8AvgRa37KOF7m+jzp7brvEreKtlhmeaQv5Oox2F4fBsEo6WWVA5R
# xzjpTrdstc8l5NwY1iZEe2LexgcO0kxGvteFciFvwWSZ++91nl6/a99Nts06AfHc
# p8Cor5pzeOfKZBbECbTnp8BGwDY+CCpo0Mg0Bsuupfj/kb/uYxQ=
# =OpJQ
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 06 Aug 2026 17:34:49 EDT
# gpg:                using RSA key 3D66AAE474594824C88CE0F81A54AFB8E5646C32
# gpg: Good signature from "Brian Cain (OSS Qualcomm) <brian.cain@oss.qualcomm.com>" [unknown]
# gpg:                 aka "Brian Cain <bcain@kernel.org>" [unknown]
# gpg:                 aka "Brian Cain (QuIC) <bcain@quicinc.com>" [unknown]
# gpg:                 aka "Brian Cain (CAF) <bcain@codeaurora.org>" [unknown]
# gpg:                 aka "bcain" [unknown]
# gpg:                 aka "Brian Cain (QUIC) <quic_bcain@quicinc.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 6350 20F9 67A7 7164 79EF  49E0 175C 464E 541B 6D47
#      Subkey fingerprint: 3D66 AAE4 7459 4824 C88C  E0F8 1A54 AFB8 E564 6C32

* tag 'hex-20260806-pull-request' of https://github.com/qualcomm/qemu:
  target/hexagon: don't let an idef-parser dest clobber its own source
  tests/tcg/hexagon: add slot-assignment tests
  target/hexagon: accept valid packets rejected by check

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-11 11:45:06 -04:00
Stefan Hajnoczi
98d0250e7c linux-user sh4 signal patches
Three important small signal handling fixes for the sh4 architecture from
 Mikulas Patocka.
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCanXdBQAKCRD3ErUQojoP
 X09PAP4winoHrCRXxCb9+P377se13P1W3b/bYmf5ju/Ptb5QTwD8C4/No2NGQBjY
 6y7skdLtRn5Ztc7BOla2cTMpBUuy9wI=
 =qH5w
 -----END PGP SIGNATURE-----

Merge tag 'linux-user-pull-request' of https://github.com/hdeller/qemu-hppa into staging

linux-user sh4 signal patches

Three important small signal handling fixes for the sh4 architecture from
Mikulas Patocka.

# -----BEGIN PGP SIGNATURE-----
#
# iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCanXdBQAKCRD3ErUQojoP
# X09PAP4winoHrCRXxCb9+P377se13P1W3b/bYmf5ju/Ptb5QTwD8C4/No2NGQBjY
# 6y7skdLtRn5Ztc7BOla2cTMpBUuy9wI=
# =qH5w
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri 07 Aug 2026 09:26:29 EDT
# gpg:                using EDDSA key BCE9123E1AD29F07C049BBDEF712B510A23A0F5F
# gpg: Good signature from "Helge Deller <deller@gmx.de>" [unknown]
# gpg:                 aka "Helge Deller <deller@kernel.org>" [unknown]
# gpg:                 aka "Helge Deller <deller@debian.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 4544 8228 2CD9 10DB EF3D  25F8 3E5F 3D04 A7A2 4603
#      Subkey fingerprint: BCE9 123E 1AD2 9F07 C049  BBDE F712 B510 A23A 0F5F

* tag 'linux-user-pull-request' of https://github.com/hdeller/qemu-hppa:
  linux-user/sh4: Fix crashes on signal delivery in conditional delay slot
  linux-user/sh4: Initialize the FPSCR register on signal
  linux-user/sh4: Deliver SIGILL on invalid instruction

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-11 11:44:51 -04:00
Stefan Hajnoczi
daee32476d * target/i386: fix typo in CET_SHSTK check
-----BEGIN PGP SIGNATURE-----
 
 iQFIBAABCgAyFiEE8TM4V0tmI4mGbHaCv/vSX3jHroMFAmp17jQUHHBib256aW5p
 QHJlZGhhdC5jb20ACgkQv/vSX3jHroOsSwf/WSeFRmpGDQnPARDmqK2co4HkHEDv
 d0u1dawoT7MB0IxrgDBTIu2stfU61JZtP0sjrrrkbrCQq0gAcG3Zy7/xLLXPHpdF
 O3pTur5wE9lYy9rTs3h2j3k16G/UOlA5iu2idwpGUTgS9V72fYe+AHHkEz55yH+m
 aTTyG3HECLWMBMIInPB4bxLEZvplOJ0Kms5pSVAZNaAwxfJa/xx8q3u+73MqdoHE
 d3LdIeOWpFbiCAPJyIrBKsD2V8BdRl6xQonhH3okQZLBoDL3DExPKZPntJNE8TgP
 0mkSVHS6hGg+dK6+9E4W/nvajSKpbBje3hDs8L5QziNeq6UaXwYaMrT/Zg==
 =9BnL
 -----END PGP SIGNATURE-----

Merge tag 'for-upstream' of https://gitlab.com/bonzini/qemu into staging

* target/i386: fix typo in CET_SHSTK check

# -----BEGIN PGP SIGNATURE-----
#
# iQFIBAABCgAyFiEE8TM4V0tmI4mGbHaCv/vSX3jHroMFAmp17jQUHHBib256aW5p
# QHJlZGhhdC5jb20ACgkQv/vSX3jHroOsSwf/WSeFRmpGDQnPARDmqK2co4HkHEDv
# d0u1dawoT7MB0IxrgDBTIu2stfU61JZtP0sjrrrkbrCQq0gAcG3Zy7/xLLXPHpdF
# O3pTur5wE9lYy9rTs3h2j3k16G/UOlA5iu2idwpGUTgS9V72fYe+AHHkEz55yH+m
# aTTyG3HECLWMBMIInPB4bxLEZvplOJ0Kms5pSVAZNaAwxfJa/xx8q3u+73MqdoHE
# d3LdIeOWpFbiCAPJyIrBKsD2V8BdRl6xQonhH3okQZLBoDL3DExPKZPntJNE8TgP
# 0mkSVHS6hGg+dK6+9E4W/nvajSKpbBje3hDs8L5QziNeq6UaXwYaMrT/Zg==
# =9BnL
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri 07 Aug 2026 10:39:48 EDT
# gpg:                using RSA key F13338574B662389866C7682BFFBD25F78C7AE83
# gpg:                issuer "pbonzini@redhat.com"
# gpg: Good signature from "Paolo Bonzini <bonzini@gnu.org>" [full]
# gpg:                 aka "Paolo Bonzini <pbonzini@redhat.com>" [full]
# Primary key fingerprint: 46F5 9FBD 57D6 12E7 BFD4  E2F7 7E15 100C CD36 69B1
#      Subkey fingerprint: F133 3857 4B66 2389 866C  7682 BFFB D25F 78C7 AE83

* tag 'for-upstream' of https://gitlab.com/bonzini/qemu:
  target/i386/kvm: Fix CET SSP MSR read feature check

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-11 11:44:34 -04:00
Stefan Hajnoczi
343b1d2d88 Open 11.2 development tree
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-11 11:43:44 -04:00
Stefan Hajnoczi
84f07211cc Update version for v11.1.0 release
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-11 10:04:46 -04:00
Claudio Imbrenda
6126cbe2e5 target/s390x: Allow 2G hugepages guest backing
Allow mapping guest with 2G hugepages on hosts that support it.

Rename kvm_s390_get_hpage_1m() to kvm_s390_get_hpage() to reflect that
it is not anymore limited only to 1m hpages.

Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Reviewed-by: Hendrik Brueckner <brueckner@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260805103728.97602-2-imbrenda@linux.ibm.com
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:36:23 -04:00
Ilya Leoshkevich
e79ea44726 tests/tcg/s390x: Test STCKF condition code on a faulting store
Add a small test to prevent regressions.

Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260714203206.363028-3-iii@linux.ibm.com
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Ilya Leoshkevich
2c32c273da target/s390x/tcg: Set STCK/STCKF condition code after the store
STORE CLOCK [FAST] to an inaccessible address aborts QEMU:

  $ qemu-s390x ./stckf
  ERROR:cc_helper.c:128:cc_calc_addu: assertion failed: (carry_out <= 1)

op_stck() sets the condition code with gen_op_movi_cc() before the
output operand store, which is deferred to wout_m1_64(). Assigning a
constant condition code discards the lazy CC values, so the optimizer
drops the writes that produced them. When the store then raises an
exception, the instruction is suppressed and
s390x_restore_state_to_opc() reinstates the cc_op recorded at the start
of STCK[F], but cc_src/cc_dst now hold stale values, so the next
condition code evaluation reads garbage.

Fix by performing the store manually. The alternative of not discarding
in gen_op_movi_cc() keeps the inputs live, but results in less optimal
code.

Reported-by: Ido Plat <Ido.Plat1@ibm.com>
Fixes: 434c91a5f4 ("target-s390: Convert STCK")
Cc: qemu-stable@nongnu.org
Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260714203206.363028-2-iii@linux.ibm.com
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Jared Rossi
c4d9412cdd pc-bios/s390-ccw: Fix off-by-one errors with loadparm and boot entries
The loadparm may optionally be used to select a boot entry, with the
intended range being 0 through 31 inclusive, for a total of 32 entries.
Previously, MAX_BOOT_ENTRIES was defined as 31, indicating that it was
intended to correspond to the index of the boot entry rather than the
count; however, some guards also used MAX_BOOT_ENTRIES as a count of the
maximum allowed entries, which resulted in a mismatch between the intended
and actual range such that index 31 could never be used in practice.

Move the definition of MAX_BOOT_ENTRIES to qipl.h so it is shared and
change the value to 32, representing a count of the maximum number of
allowed boot entries and allowing the loadparm to accept values 0 through
31 as intended.  Update some instances in the netboot code where
MAX_BOOT_ENTRIES was used as the max index so that all guards treat
MAX_BOOT_ENTRIES as a count across all boot methods.

Cc: qemu-stable@nongnu.org
Fixes: 806315279d ("pc-bios/s390-ccw: Remove panics from ECKD IPL path")
Signed-off-by: Jared Rossi <jrossi@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260728223013.4047042-1-jrossi@linux.ibm.com
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Joshua Daley
a3856a7ba4 pc-bios/s390-ccw: bound zipl menu strlen and replace VLA in zipl_print_entry
menu_get_zipl_boot_index() calls strlen() on a pointer into the middle
of _s2 with no upper bound, so a stage-2 image whose blocks contain no
NUL bytes causes strlen() to walk beyond _s2. The resulting length
is then used to size a stack VLA in zipl_print_entry(), risking a stack
overflow.

Fix by:

- Implementing strnlen(), a bounded version of strlen(). s390-ccw uses
  libc from SLOF, which includes strlen() but does not have an
  implementation of strnlen(), so we must implement our own.

- Adding a menu_data_end parameter to menu_get_zipl_boot_index() and
  replacing both strlen() calls with strnlen() bounded by the remaining
  buffer space. The loop guard also checks that the pointer has not
  reached menu_data_end. The function returns 0 (boot default) if
  somehow menu_data reaches menu_data_end before printing any entries.

- Replacing the VLA char buf[len + 2] in zipl_print_entry() with a fixed
  ZIPL_ENTRY_MAX + 2 (82-byte) buffer and truncating len before use.

- Passing s2_end (_s2 + sizeof(_s2)) as menu_data_end at the one call
  site in eckd_get_boot_menu_index(), so the bound is exactly the end of
  the buffer.

Fixes: f717891084 ("s390-ccw: print zipl boot menu")
Cc: qemu-stable@nongnu.org
Signed-off-by: Joshua Daley <jdaley@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260728134704.2924005-2-jdaley@linux.ibm.com
[farman@linux.ibm.com: Per list, add strnlen rationale to commit message
 and added cc stable]
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Joshua Daley
33909d4ebd pc-bios/s390-ccw: bounds-check zipl menu entry index before array write
menu_get_zipl_boot_index() iterates NUL-separated strings from the
zipl stage-2 boot-menu block, passes each to zipl_print_entry() which
converts EBCDIC to ASCII and returns atoi(), then writes true into
valid_entries[entry]. valid_entries is a MAX_BOOT_ENTRIES element
stack array, but entry was never bounds-checked, so a crafted on-disk
value could index arbitrarily beyond the array.

Fix this in two places:

- zipl_print_entry() now validates that the first significant character
  (after an optional leading space) is a digit. Entries that fail this
  check return -1 without printing.

- menu_get_zipl_boot_index() skips any entry whose index is outside
  [0, MAX_BOOT_ENTRIES) before writing to valid_entries[].

Fixes: 7385e947fc ("pc-bios/s390-ccw: fix non-sequential boot entries (eckd)")
Cc: qemu-stable@nongnu.org
Signed-off-by: Joshua Daley <jdaley@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260727115052.24289-5-borntraeger@linux.ibm.com
[farman@linux.ibm.com: Added qemu-stable]
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Joshua Daley
a9f1e84c6b pc-bios/s390-ccw: fix out-of-bounds read in iso_get_file_size()
In the dir_rem[level] == 0 case, level is decremented, then
a virtio_read() is issued on sec_loc[level]. If level is -1, then the
4 bytes before the static sec_loc array are read, and the virtio_read()
is issued on that garbage block number.

Guard the call to virtio_read() against the value of level to prevent
this.

Fixes: 869648e87e ("pc-bios/s390-ccw: El Torito 16-bit boot image size field workaround")
Cc: qemu-stable@nongnu.org
Signed-off-by: Joshua Daley <jdaley@linux.ibm.com>
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260727115052.24289-4-borntraeger@linux.ibm.com
[farman@linux.ibm.com: Fixed typo on Christian's tag, added qemu-stable]
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Joshua Daley
df607fd056 s390x/ipl: validate num_comp against iplb length before iterating
In ipl_valid_pv_components(), the upper bound of the for loop,
ipib_pv->num_comp, is read from guest memory. Before iterating, verify
that its value will not cause a read beyond the end of the
IplParameterBlock.

Fixes: c3347ed0d2 ("s390x: protvirt: Support unpack facility")
Cc: qemu-stable@nongnu.org
Signed-off-by: Joshua Daley <jdaley@linux.ibm.com>
Reviewed-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260727115052.24289-3-borntraeger@linux.ibm.com
[farman@linux.ibm.com: Added qemu-stable]
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Christian Borntraeger
4e994ebb01 hw/char/sclpconsole-lm: avoid guest triggerable assert
If a guest uses incorrect message length it can trigger an assert in
process_mdb which kills the guest instead of reporting an error.  Fix
this by adding the correct length check.

Fixes: 6a444f8507 ("s390/sclplmconsole: Add support for SCLP line-mode console")
Cc: qemu-stable@nongnu.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260727115052.24289-2-borntraeger@linux.ibm.com
[farman@linux.ibm.com: Fixed typo in commit message, added qemu-stable]
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Ilya Leoshkevich
aa5d03bc93 tests/tcg/s390x: Test DR overflow (INT64_MIN / -1)
Check that DR with a non-representable quotient raises SIGFPE rather than
crashing the emulator.

Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260714190351.337923-3-iii@linux.ibm.com
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Ilya Leoshkevich
0103cb1cd1 target/s390x: Fix DR/D INT64_MIN / -1 host crash
helper_divs32() divides the 64-bit dividend by the 32-bit divisor as a 64-bit
host operation, guarding only against a zero divisor. INT64_MIN / -1 therefore
overflows the host division before the representability check runs; on hosts
that trap this, QEMU is killed with SIGFPE instead of raising the
fixed-point-divide exception the guest expects:

    qemu-s390x: QEMU internal SIGFPE {code=INTDIV, addr=...}

helper_divs64() already guards the same case; add the missing check to
helper_divs32().

Reported-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Fixes: b4e2bd3563 ("target-s390: Send signals for divide")
Cc: qemu-stable@nongnu.org
Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260714190351.337923-2-iii@linux.ibm.com
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Ilya Leoshkevich
abe1d893f4 tests/tcg/s390x: Test PRNO TRNG interruptibility
Add a small test that issues a large PRNO TRNG request while a timer is
running, and checks that the timer interrupts it several times.

Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
Reviewed-by: Harald Freudenberger <freude@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260714191948.342204-3-iii@linux.ibm.com
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Ilya Leoshkevich
aae77f5ddd target/s390x: Make PRNO TRNG interruptible
fill_buf_random() writes the entire guest-requested amount of random
bytes in one go. Since the length is a full 64-bit value, a guest can
request several gigabytes and keep the vCPU spinning inside the helper,
without a chance to react to interrupts.

Do the same thing as HELPER(mvcl): check cpu_loop_exit_requested() at the
bottom of the loop, and when a return to the main loop is pending, stop
and report partial completion with condition code 3.

Reported-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Fixes: 3dbc5fdacb ("target/s390x: support PRNO_TRNG instruction")
Cc: qemu-stable@nongnu.org
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
Reviewed-by: Harald Freudenberger <freude@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260714191948.342204-2-iii@linux.ibm.com
Signed-off-by: Eric Farman <farman@linux.ibm.com>
2026-08-10 14:06:58 -04:00
Matt Turner
ce276ab1a9 linux-user/sh4: write the floating-point registers to a core dump
Write an NT_FPREGSET note for SH4, matching struct user_fpu_struct
from arch/sh/include/asm/user.h: fr0-fr15, xf0-xf15, fpscr, fpul.

Signed-off-by: Matt Turner <mattst88@gmail.com>
Reviewed-by: Helge Deller <deller@gmx.de>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-08-07 18:14:13 +02:00
Matt Turner
0f183237d2 linux-user/riscv: write the floating-point registers to a core dump
Write an NT_FPREGSET note for RISC-V, matching struct __riscv_d_ext_state
from uapi/asm/ptrace.h: f0-f31 as 64-bit values followed by fcsr.

Signed-off-by: Matt Turner <mattst88@gmail.com>
Reviewed-by: Helge Deller <deller@gmx.de>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-08-07 18:14:13 +02:00
Matt Turner
474ad68669 linux-user/hppa: write the floating-point registers to a core dump
Write an NT_FPREGSET note for HPPA, matching the kernel's
elf_fpregset_t layout (ELF_NFPREG = 32): fr0-fr31 as 64-bit values.

Signed-off-by: Matt Turner <mattst88@gmail.com>
Reviewed-by: Helge Deller <deller@gmx.de>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-08-07 18:14:13 +02:00
Matt Turner
bc22871fc0 linux-user/mips: write the floating-point registers to a core dump
Write an NT_FPREGSET note for MIPS and MIPS64, matching the kernel's
elf_fpregset_t layout (ELF_NFPREG = 33): fpr[0..31] hold f0-f31, and
fcsr occupies the low 32 bits of slot 32.  The pad field rounds the
struct to 33 × 8 bytes = 264 bytes.

Signed-off-by: Matt Turner <mattst88@gmail.com>
Reviewed-by: Helge Deller <deller@gmx.de>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-08-07 18:14:13 +02:00
Matt Turner
2304a65529 linux-user/alpha: write the floating-point registers to a core dump
A guest core carried only the general-purpose registers, so a debugger
opening one reported every floating-point register as unavailable --
including the arguments of the function that crashed.

Implement HAVE_ELF_CORE_FPREGS for Alpha: define target_elf_fpregset_t
to match the kernel's layout ($f0-$f30 plus the control register in the
slot $f31 would occupy) and fill it from elf_core_copy_fpregs().

Checked with lldb on a core from a program that faults with live values
in $f16 and $f17: both read back correctly, as does the control register.

Signed-off-by: Matt Turner <mattst88@gmail.com>
Reviewed-by: Helge Deller <deller@gmx.de>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-08-07 18:14:13 +02:00
Matt Turner
88dfd97b8a linux-user: support writing floating-point registers to a core dump
Write an NT_FPREGSET note for targets that opt in: a target_elf.h that
defines HAVE_ELF_CORE_FPREGS and target_elf_fpregset_t, and supplies an
elf_core_copy_fpregs() beside the existing elf_core_copy_regs().

Signed-off-by: Matt Turner <mattst88@gmail.com>
Reviewed-by: Helge Deller <deller@gmx.de>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-08-07 18:14:13 +02:00
Saul Freedman
01b4e06b52 target/i386/kvm: Fix CET SSP MSR read feature check
kvm_get_msrs() adds U_CET and S_CET when CET shadow stacks or IBT are
enabled, but it checks FEAT_7_0_EDX with the ECX-defined
CPUID_7_0_ECX_CET_SHSTK bit before adding the PL0-PL3 SSP MSRs.

CPUID_7_0_ECX_CET_SHSTK belongs to FEAT_7_0_ECX. The current check
therefore skips MSR_IA32_PL0_SSP through MSR_IA32_PL3_SSP even when
guest shadow stacks are enabled.

kvm_put_msrs() already uses FEAT_7_0_ECX for the same shadow-stack
condition. Use the same feature word in kvm_get_msrs() so QEMU does
not restore CET enablement with stale or zero SSP values.

Fixes: b6f85c5e45 ("i386/kvm: Add save/restore support for CET MSRs")
Cc: qemu-stable@nongnu.org
Signed-off-by: Saul Freedman <fre3dm4n@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260615033338.1563854-1-fre3dm4n@gmail.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-08-07 16:39:22 +02:00
Matt Turner
4713988da1 linux-user: implement mount_setattr(2)
mount_setattr() was in the syscall tables but had no implementation, so
guests always got -ENOSYS. systemd uses it when setting up per-unit
credential mounts, which fails the affected units with EXIT_CREDENTIALS.

struct mount_attr is an extensible struct like open_how, so handle it the
same way openat2() does: reject sizes smaller than the ver0 struct and
require any unknown trailing bytes to be zero. All of its fields are
64-bit, and the MOUNT_ATTR_* and MS_* propagation values are identical on
every target, so only the byte order needs fixing up.

Signed-off-by: Matt Turner <mattst88@gmail.com>
Reviewed-by: Helge Deller <deller@gmx.de>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-08-07 15:56:21 +02:00
Mikulas Patocka
f7ad7b1f8c linux-user/sh4: Fix crashes on signal delivery in conditional delay slot
If we get a signal in the delay slot, we must roll-back the PC to the
jump instruction. This was already fixed by the commit 3b894b699c
("linux-user/sh4: Fix crashes on signal delivery"), however this fix
omits a test for TB_FLAG_DELAY_SLOT_COND. TB_FLAG_DELAY_SLOT_COND is set
by the conditional delayed branches bf/s and bt/s. Qemu did not roll-back
the PC in this case, resulting in incorrect program execution.

This patch fixes it.

Cc: qemu-stable@nongnu.org
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Reviewed-by: Yoshinori Sato <yoshinori.sato@nifty.com>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-08-07 15:13:36 +02:00
Mikulas Patocka
668d571bf0 linux-user/sh4: Initialize the FPSCR register on signal
On the SH4 architecture, the instructions that perform single precision
and double precision floating point operations are encoded in the same
way. The bit PR in the FPSCR register determines if the CPU performs
single or double operation.

According to the ABI, the PR bit must be set at function entry and
function exit.

GCC generates code that flips this bit as needed during function
execution. If we get a signal, we must set the PR bit, so that the signal
handler finds the bit in the expected state. Qemu lacked this logic, so
that if the signal interrupts single-precision floating point
calculation, the PR bit would be incorrectly clear at signal handler
entry. If the signal handler performed some floating-point calculation,
it would get incorrect result.

This patch fixes the bug, by initializing the FPSCR register at signal
entry. Note that we initialize the whole register, because the Linux
kernel initializes the whole register too.

Cc: qemu-stable@nongnu.org
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Reviewed-by: Yoshinori Sato <yoshinori.sato@nifty.com>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-08-07 15:12:36 +02:00
Mikulas Patocka
bc4681990b linux-user/sh4: Deliver SIGILL on invalid instruction
On invalid instruction, deliver SIGILL rather than crashing the whole
process unconditionally.

Cc: qemu-stable@nongnu.org
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Reviewed-by: Yoshinori Sato <yoshinori.sato@nifty.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-08-07 15:10:51 +02:00
Brian Cain
8f5bf4fa0a target/hexagon: don't let an idef-parser dest clobber its own source
The idef-parser emitters write the destination in place, so when a packet
is short-circuited and get_result_gpr() returns hex_gpr[] itself, an
instruction naming one register as both source and destination reads back
a value it already overwrote.

`Rd32=cmpy(Rs32,Rt32):<<1:rnd:sat` with Rs == Rd is an example.

Give a source reg that aliases a destination its own copy of the
register value.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-06 08:18:51 -07:00
Brian Cain
d2504d4cea tests/tcg/hexagon: add slot-assignment tests
valid-slots: packets that legally share a slot and were wrongly
rejected before the fix (load and transfer, load encoded first;
dczeroa packed last with three transfers).

invalid-slots: unassignable packets that must still be rejected:
store + duplex, load + indirect jump, three logical ops competing for
slots 2 and 3, and five ops for four slots.

Reviewed-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-06 08:18:16 -07:00
Brian Cain
0177efb9b7 target/hexagon: accept valid packets rejected by check
has_valid_slot_assignment() rejected any packet with two instructions
assigned to the same slot.  That is too strict.  When a memory
instruction is encoded before a slot-flexible instruction in a packet,
the descending slot assignment places the memory op in slot 1 and the
other in slot 0, then the "mem insns to slot 0" fixup moves the memory
op to slot 0 as well, leaving both in slot 0.  Such a packet is valid
and executes correctly, but the uniqueness test flagged it as
HEX_CAUSE_INVALID_PACKET, raising SIGILL in linux-user and a precise
exception in system mode.

For example this packet, with the load encoded first, was wrongly
rejected:

    { r6 = memw(r3+#-4)
      r7 = #0x4ae6 }

Replace the uniqueness test with a slot-exhaustion check: walk the
instructions in encoding order handing out slots in strictly decreasing
order and fail only if an instruction has no valid slot at or below the
running slot.  This accepts packets that legally share a slot while
still rejecting genuinely unassignable packets, such as a memory
instruction grouped with a duplex, or a load followed by an instruction
that requires a high slot.

Reviewed-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-08-06 08:18:16 -07:00
Stefan Hajnoczi
3e3ccab106 Update version for v11.1.0-rc3 release
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-04 15:36:08 -04:00
Stefan Hajnoczi
86acc650be Block layer patches
- Fix missing locking in latency histogram setters
 - coroutine: fix lost wakeup in qemu_co_sleep_wake()
 - floppy: Fix READ/WRITE/FORMAT/READ ID behaviour with missing medium
 - qcow2: Fix crash on closing a read-only image with dirty bit set
 - cloop: fix integer overflow in total_sectors calculation
 - dmg: Fix out of bounds accesses (CVE-2026-65929, CVE-2026-65928)
 - FUSE export: fix regression with O_TRUNC when export is not growable
 - iotests: Various small fixes
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEE3D3rFZqa+V09dFb+fwmycsiPL9YFAmpx+c4RHGt3b2xmQHJl
 ZGhhdC5jb20ACgkQfwmycsiPL9YB1A/7BBA88fhvpA1E/X+1DGpjFyAJbssRVWxq
 OuKgpvVgm1EZHIl/ST5scOm971h3e4zXQLVERY0nY30wMl5mZVXrFMHOLdqP+1rv
 dPjqHwgiBp+YOP3Ol2EHaObDta+bf5GM3DZ6naAHdK0Zdxqywo0qsrKwHpSG2NhG
 uEWanrZC0SsaZ5sUmVdwYp8SA6iW1RtvS23kgP4szSIy6jYoFYcZYKv5AcitohCq
 HejMiLcoDcqPKy1l4CnqypsNEW+SyabG2Zr0IkRattM7It2Vq+bswRuo4tKRjn2I
 TBldmMiBIhW8txV3u6DglR02pXThSVhxFZV3O9DSntCii4rubz7smvqR1X3pmknW
 ERE4b4fvLAlzIrugMfvVNRVZpWLVdHqx+iu0wh3QvvCxZGMuCksQ+1Kr0ayi3IH/
 cBcudetL9WnYVchMJRgwYDSahDvqgm7xiMGU1X1dAjfb4LKlmVAccuuUy0iHsg/p
 mSBrnxWpABIQgwN+rhUeWMLo6faVUpf5GUmfT/EwyMNrOhCo4K+qfR17S+McJeYC
 a1nxUbLUKdkAFX31bTmEIQlp+395RGh1o0UGOrrQUW8pRZgAQqBCitRRmEXZiOmD
 PNNeCZS1wyWMbSz0R19/vpp/uwPmMBakN/QxWmY+H3nHUrKEnZGmtPZlJGFoam+m
 9qHJno8c2Ak=
 =2bLV
 -----END PGP SIGNATURE-----

Merge tag 'for-upstream' of https://gitlab.com/kmwolf/qemu into staging

Block layer patches

- Fix missing locking in latency histogram setters
- coroutine: fix lost wakeup in qemu_co_sleep_wake()
- floppy: Fix READ/WRITE/FORMAT/READ ID behaviour with missing medium
- qcow2: Fix crash on closing a read-only image with dirty bit set
- cloop: fix integer overflow in total_sectors calculation
- dmg: Fix out of bounds accesses (CVE-2026-65929, CVE-2026-65928)
- FUSE export: fix regression with O_TRUNC when export is not growable
- iotests: Various small fixes

# -----BEGIN PGP SIGNATURE-----
#
# iQJFBAABCgAvFiEE3D3rFZqa+V09dFb+fwmycsiPL9YFAmpx+c4RHGt3b2xmQHJl
# ZGhhdC5jb20ACgkQfwmycsiPL9YB1A/7BBA88fhvpA1E/X+1DGpjFyAJbssRVWxq
# OuKgpvVgm1EZHIl/ST5scOm971h3e4zXQLVERY0nY30wMl5mZVXrFMHOLdqP+1rv
# dPjqHwgiBp+YOP3Ol2EHaObDta+bf5GM3DZ6naAHdK0Zdxqywo0qsrKwHpSG2NhG
# uEWanrZC0SsaZ5sUmVdwYp8SA6iW1RtvS23kgP4szSIy6jYoFYcZYKv5AcitohCq
# HejMiLcoDcqPKy1l4CnqypsNEW+SyabG2Zr0IkRattM7It2Vq+bswRuo4tKRjn2I
# TBldmMiBIhW8txV3u6DglR02pXThSVhxFZV3O9DSntCii4rubz7smvqR1X3pmknW
# ERE4b4fvLAlzIrugMfvVNRVZpWLVdHqx+iu0wh3QvvCxZGMuCksQ+1Kr0ayi3IH/
# cBcudetL9WnYVchMJRgwYDSahDvqgm7xiMGU1X1dAjfb4LKlmVAccuuUy0iHsg/p
# mSBrnxWpABIQgwN+rhUeWMLo6faVUpf5GUmfT/EwyMNrOhCo4K+qfR17S+McJeYC
# a1nxUbLUKdkAFX31bTmEIQlp+395RGh1o0UGOrrQUW8pRZgAQqBCitRRmEXZiOmD
# PNNeCZS1wyWMbSz0R19/vpp/uwPmMBakN/QxWmY+H3nHUrKEnZGmtPZlJGFoam+m
# 9qHJno8c2Ak=
# =2bLV
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 04 Aug 2026 10:40:14 EDT
# gpg:                using RSA key DC3DEB159A9AF95D3D7456FE7F09B272C88F2FD6
# gpg:                issuer "kwolf@redhat.com"
# gpg: Good signature from "Kevin Wolf <kwolf@redhat.com>" [full]
# Primary key fingerprint: DC3D EB15 9A9A F95D 3D74  56FE 7F09 B272 C88F 2FD6

* tag 'for-upstream' of https://gitlab.com/kmwolf/qemu:
  iotests: increase timeouts for tests to 5 minutes
  hw/block/fdc: report a missing address mark on an empty drive
  hw/block/fdc: select the drive named by the READ ID command
  iotests: test O_TRUNC behavior for fuse exports
  block/export/fuse: fix regression with O_TRUNC when export is not growable
  coroutine: fix lost wakeup in qemu_co_sleep_wake()
  iotests/migrate-bitmaps-postcopy-test: replace the timing assertion with a content check
  iotests: skip FUSE tests when FUSE is not usable
  iotests: run the test pool with the 'fork' start method
  qcow2: do not try to clear the dirty bit on a read-only node
  dmg: reject inconsistent UDRW chunk sector count and length (CVE-2026-65928)
  dmg: refuse to open files with no chunks
  dmg: fix out-of-bounds load in search_chunk() (CVE-2026-65929)
  tests/unit: add reproducer for BlockAcctStats histogram locking race
  block/qapi: take stats->lock when reading BlockAcctStats for query-blockstats
  block/accounting: take stats->lock in latency histogram setters
  block/cloop: fix integer overflow in total_sectors calculation

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-04 15:35:59 -04:00
Stefan Hajnoczi
8dfde8fb21 Fixes for 11.1-rc
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
 
 ---
 v2:
  - fix CVE# in "virtio-gpu: reject requests with short/truncated control
  headers"
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmpyO8QACgkQ2ujhCXWW
 nOVnCQ/9H1HlmL0SwDyNnFdG/xk8gby7F6H45HTX+gDx/i6VNDU1V60MbDcE2g1D
 dgTeNCgA81M9Lxa3FwWcVyRoRkp2ZygQmEb+XU9fRqAasL/YxvR/c+/Drk0gcsXX
 Qd1UQba6oelqK1SngEVEfhJauHSaVJq4YJWWak2u65FALGpj0CCgBT+42Syaj6+i
 f23crPOO01Ooggyk6TqtuH3Z7hal5mo2amOX5GBJ/YHJ94FRgoW/AcNe7k1xQ7/M
 hXuPG7ix3I18d6T0OUHTF2w+Fj/iplUR6F12ocrRBtc30IUw6/rG0MHFyuljT8Tg
 gyvn38b7JJLQL7dYFD7tYyFZJrum7c5BXQUkqg7hEYtwo7IR2f2V3FHEGcmg1inf
 wooVmrlfA3DA302QBBwCKzVgqD2x6DVPtlDALC1mKouCKz45OEBxQ6iMx5x9jaAo
 BcL415RnVRukK6aHvOvhj93eJqWyc/O6nrALDzy5B+4Zt0X15ytSL4t1ZmRumhxY
 O2d5kFEJC4rvjeQg9EfqSmjs8CWT87jHxLx54LEJIuQeknO4b9SXzQNHZstshY76
 cXPWTOqiKQeswKxK91W4svtBtQmrTp6pYMATmkOexUDAeo4+/d8GCBPYuaABJrJe
 llDdzfwFjsiFAHJ8DcROiOvU9lwy39J29pmp+yQcKKw2k5YZmww=
 =m5jV
 -----END PGP SIGNATURE-----

Merge tag 'fix-pr-v2' of https://gitlab.com/marcandre.lureau/qemu into staging

Fixes for 11.1-rc

Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>

---
v2:
 - fix CVE# in "virtio-gpu: reject requests with short/truncated control
 headers"

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmpyO8QACgkQ2ujhCXWW
# nOVnCQ/9H1HlmL0SwDyNnFdG/xk8gby7F6H45HTX+gDx/i6VNDU1V60MbDcE2g1D
# dgTeNCgA81M9Lxa3FwWcVyRoRkp2ZygQmEb+XU9fRqAasL/YxvR/c+/Drk0gcsXX
# Qd1UQba6oelqK1SngEVEfhJauHSaVJq4YJWWak2u65FALGpj0CCgBT+42Syaj6+i
# f23crPOO01Ooggyk6TqtuH3Z7hal5mo2amOX5GBJ/YHJ94FRgoW/AcNe7k1xQ7/M
# hXuPG7ix3I18d6T0OUHTF2w+Fj/iplUR6F12ocrRBtc30IUw6/rG0MHFyuljT8Tg
# gyvn38b7JJLQL7dYFD7tYyFZJrum7c5BXQUkqg7hEYtwo7IR2f2V3FHEGcmg1inf
# wooVmrlfA3DA302QBBwCKzVgqD2x6DVPtlDALC1mKouCKz45OEBxQ6iMx5x9jaAo
# BcL415RnVRukK6aHvOvhj93eJqWyc/O6nrALDzy5B+4Zt0X15ytSL4t1ZmRumhxY
# O2d5kFEJC4rvjeQg9EfqSmjs8CWT87jHxLx54LEJIuQeknO4b9SXzQNHZstshY76
# cXPWTOqiKQeswKxK91W4svtBtQmrTp6pYMATmkOexUDAeo4+/d8GCBPYuaABJrJe
# llDdzfwFjsiFAHJ8DcROiOvU9lwy39J29pmp+yQcKKw2k5YZmww=
# =m5jV
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 04 Aug 2026 15:21:40 EDT
# gpg:                using RSA key 87A9BD933F87C606D276F62DDAE8E10975969CE5
# gpg: Good signature from "Marc-André Lureau <marcandre.lureau@redhat.com>" [full]
# gpg:                 aka "Marc-André Lureau <marcandre.lureau@gmail.com>" [full]
# Primary key fingerprint: 87A9 BD93 3F87 C606 D276  F62D DAE8 E109 7596 9CE5

* tag 'fix-pr-v2' of https://gitlab.com/marcandre.lureau/qemu:
  qapi/dump: add allowed-by-guest feature to win-dmp
  hw/display/virtio-gpu: Unmap DMA regions on reset
  hw/display/virtio-gpu: Always reject invalid scanout bounds
  virtio-gpu: reject requests with short/truncated control headers
  hw/display/virtio-gpu: drop redundant node->value NULL checks
  hw/display/virtio-gpu: fix offset wraparound in scanout_blob_to_fb
  vhost-user-gpu: fix integer overflow in buffer allocation
  hw/display/vga: fix panning_buf OOB after text/graphics switch
  hw/display/virtio-gpu: validate blob iov size

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-04 15:29:15 -04:00
Stefan Hajnoczi
c4deaead6a nvme queue
-----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEUigzqnXi3OaiR2bATeGvMW1PDekFAmpxGacACgkQTeGvMW1P
 DekckggApSTjUU3IWkllM1WDy7leeobceXeBKv9Aihlccz3RAjd5pXJTHAMEnpQ4
 /97pUJMzoZN9KB/qMLiYsmS24UngFZo7u7jTY4auPddIBBtLH7W6ojx2fNHnlwul
 7/84/8M3hQbIy7nIkrMHM7he2hlysRBDvtClTk1kfz5IaXWKfMi50gGbGSFXhAQT
 2fQz/hQvEnSMHdILfSL4NLAYGu5FDnEM38yX84z/M26ISKYPd12omA9g4Xv+YZL3
 b3ptE+833yAnoUs6ymSxandoL+Fj1GmCC9UZqjmDS7+7txvjQOBl68SgQhidI6F+
 yb4PjPCEv8xE+i/jNoVfAVFhOs64Sg==
 =nPqu
 -----END PGP SIGNATURE-----

Merge tag 'pull-nvme-20260803' of https://gitlab.com/birkelund/qemu into staging

nvme queue

# -----BEGIN PGP SIGNATURE-----
#
# iQEzBAABCgAdFiEEUigzqnXi3OaiR2bATeGvMW1PDekFAmpxGacACgkQTeGvMW1P
# DekckggApSTjUU3IWkllM1WDy7leeobceXeBKv9Aihlccz3RAjd5pXJTHAMEnpQ4
# /97pUJMzoZN9KB/qMLiYsmS24UngFZo7u7jTY4auPddIBBtLH7W6ojx2fNHnlwul
# 7/84/8M3hQbIy7nIkrMHM7he2hlysRBDvtClTk1kfz5IaXWKfMi50gGbGSFXhAQT
# 2fQz/hQvEnSMHdILfSL4NLAYGu5FDnEM38yX84z/M26ISKYPd12omA9g4Xv+YZL3
# b3ptE+833yAnoUs6ymSxandoL+Fj1GmCC9UZqjmDS7+7txvjQOBl68SgQhidI6F+
# yb4PjPCEv8xE+i/jNoVfAVFhOs64Sg==
# =nPqu
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 03 Aug 2026 18:43:51 EDT
# gpg:                using RSA key 522833AA75E2DCE6A24766C04DE1AF316D4F0DE9
# gpg: Good signature from "Klaus Jensen <its@irrelevant.dk>" [unknown]
# gpg:                 aka "Klaus Jensen <k.jensen@samsung.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: DDCA 4D9C 9EF9 31CC 3468  4272 63D5 6FC5 E55D A838
#      Subkey fingerprint: 5228 33AA 75E2 DCE6 A247  66C0 4DE1 AF31 6D4F 0DE9

* tag 'pull-nvme-20260803' of https://gitlab.com/birkelund/qemu:
  hw/nvme: fix leak on copy ranges
  hw/nvme: cancel inflight requests on controller reset
  hw/nvme: factor out nvme_sq_cancel_inflight()
  hw/nvme: drop AER requests without aiocb in nvme_del_sq()

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-04 15:29:04 -04:00
Stefan Hajnoczi
78141c5084 vfio queue:
* Fix accel_irqchip_begin_route_changes() abort under TCG
 * Fix SIGSEGV in vfio_connect_kvm_msi_virq() during loadvm
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEoPZlSPBIlev+awtgUaNDx8/77KEFAmpvTOgACgkQUaNDx8/7
 7KG+sRAAjhjXZA20OE3g/kHka6ThsffYowc9Hln3lHCZNsYP+ZBY8dbavjj+/vO2
 aL1F2d6HyI7t4zrswRZwIEpCaW6N6j4Oh8PLA9GsJw991+b692SjuSxujrijubwv
 A7gVPJTTc70HS7YwS4p1MhUzTZcZcDY/hAlBK4rAfym9wO0sIu4PGMVgnRCIQGQU
 dvZPUw22nDDwxaVAxmxMg11CBMX7vm3653d9/Q9IhiYHwq+WqKDOr8swNppeSV88
 ephrbAsh3OmQUhAss/7rZS18IF6P2xZ688PCCzo3GvgiKMSqSebzwVsCSA2mghNh
 QxacbPbIRnXIWp8zYlsujevjfinQWrA1CpyNeNTgcGZqFmAW/p5gfDMY0A9p7bjE
 NaUhxlmwLhO583tBi9wmLLTf0Xdr0b/tKFpxGj/bJAkXWiguTXZZJDzgbWlFldIa
 OvavqWFDguE2VBh10lfv+elSu1eBPy1I4W1FyLiUpWoCdmijSukUrlwaLNaAFiv0
 9idUG6bAUnMklaIWtQGDZaRyK76x83lKB8rKs2wFN7up4LvAcELFH41Y0Nd25tTR
 rzCPjHZEu7QAe52aus1aDnwuKLtwclreS6kAD5zB4HqQPoUjXO82o6oHQBnXHCJl
 LjRoCKghiR5E2DkP2E3Z2zT/rM5Jy6g6XwBuORXvObso5V/HQEg=
 =B++f
 -----END PGP SIGNATURE-----

Merge tag 'pull-vfio-20260802' of https://github.com/legoater/qemu into staging

vfio queue:

* Fix accel_irqchip_begin_route_changes() abort under TCG
* Fix SIGSEGV in vfio_connect_kvm_msi_virq() during loadvm

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEEoPZlSPBIlev+awtgUaNDx8/77KEFAmpvTOgACgkQUaNDx8/7
# 7KG+sRAAjhjXZA20OE3g/kHka6ThsffYowc9Hln3lHCZNsYP+ZBY8dbavjj+/vO2
# aL1F2d6HyI7t4zrswRZwIEpCaW6N6j4Oh8PLA9GsJw991+b692SjuSxujrijubwv
# A7gVPJTTc70HS7YwS4p1MhUzTZcZcDY/hAlBK4rAfym9wO0sIu4PGMVgnRCIQGQU
# dvZPUw22nDDwxaVAxmxMg11CBMX7vm3653d9/Q9IhiYHwq+WqKDOr8swNppeSV88
# ephrbAsh3OmQUhAss/7rZS18IF6P2xZ688PCCzo3GvgiKMSqSebzwVsCSA2mghNh
# QxacbPbIRnXIWp8zYlsujevjfinQWrA1CpyNeNTgcGZqFmAW/p5gfDMY0A9p7bjE
# NaUhxlmwLhO583tBi9wmLLTf0Xdr0b/tKFpxGj/bJAkXWiguTXZZJDzgbWlFldIa
# OvavqWFDguE2VBh10lfv+elSu1eBPy1I4W1FyLiUpWoCdmijSukUrlwaLNaAFiv0
# 9idUG6bAUnMklaIWtQGDZaRyK76x83lKB8rKs2wFN7up4LvAcELFH41Y0Nd25tTR
# rzCPjHZEu7QAe52aus1aDnwuKLtwclreS6kAD5zB4HqQPoUjXO82o6oHQBnXHCJl
# LjRoCKghiR5E2DkP2E3Z2zT/rM5Jy6g6XwBuORXvObso5V/HQEg=
# =B++f
# -----END PGP SIGNATURE-----
# gpg: Signature made Sun 02 Aug 2026 09:58:00 EDT
# gpg:                using RSA key A0F66548F04895EBFE6B0B6051A343C7CFFBECA1
# gpg: Good signature from "Cédric Le Goater <clg@redhat.com>" [full]
# gpg:                 aka "Cédric Le Goater <clg@kaod.org>" [full]
# Primary key fingerprint: A0F6 6548 F048 95EB FE6B  0B60 51A3 43C7 CFFB ECA1

* tag 'pull-vfio-20260802' of https://github.com/legoater/qemu:
  vfio/pci: Guard accel_irqchip_begin_route_changes() calls
  hw/vfio: Fix liveness check in vfio_connect_kvm_msi_virq()

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-04 15:28:54 -04:00
Stefan Hajnoczi
2ef60c8e6f target/i386: Update cc_op for SAHF
-----BEGIN PGP SIGNATURE-----
 
 iQFRBAABCgA7FiEEekgeeIaLTbaoWgXAZN846K9+IV8FAmpuICcdHHJpY2hhcmQu
 aGVuZGVyc29uQGxpbmFyby5vcmcACgkQZN846K9+IV8lhQf/d427AaCDKBRIkHxo
 cqQYlN6D5CoM9f5WYZlXxm7IB+jORTnhYpjjQGapMYH3Al07N2y19NrGFokf1p3+
 j8fFGvJv5/UPIH4zovud4l2R6l9/sGVsm7NT6NV27ipydzoKVeWEacNnYukJx9yc
 p3fy/rw/8PSUn3sigOmRJpyO5vCJmUigp0SrZI5v3oGRNtvgRBcQMu8iPWb6mHVj
 esL1qruWBrbJUIZAeHCTCtoJHzOrpfq4XmUMGD0Ct+XVVZ3gLOlUJjOt2d5nL2DT
 JOtsNmn396lXxGlrFI4CRG9jG3bl1sIQOI1kvUblwdlrWow64LvqO2l7ImSMKdXq
 UeRZBg==
 =IvU9
 -----END PGP SIGNATURE-----

Merge tag 'pull-i386-20260801' of https://gitlab.com/rth7680/qemu into staging

target/i386: Update cc_op for SAHF

# -----BEGIN PGP SIGNATURE-----
#
# iQFRBAABCgA7FiEEekgeeIaLTbaoWgXAZN846K9+IV8FAmpuICcdHHJpY2hhcmQu
# aGVuZGVyc29uQGxpbmFyby5vcmcACgkQZN846K9+IV8lhQf/d427AaCDKBRIkHxo
# cqQYlN6D5CoM9f5WYZlXxm7IB+jORTnhYpjjQGapMYH3Al07N2y19NrGFokf1p3+
# j8fFGvJv5/UPIH4zovud4l2R6l9/sGVsm7NT6NV27ipydzoKVeWEacNnYukJx9yc
# p3fy/rw/8PSUn3sigOmRJpyO5vCJmUigp0SrZI5v3oGRNtvgRBcQMu8iPWb6mHVj
# esL1qruWBrbJUIZAeHCTCtoJHzOrpfq4XmUMGD0Ct+XVVZ3gLOlUJjOt2d5nL2DT
# JOtsNmn396lXxGlrFI4CRG9jG3bl1sIQOI1kvUblwdlrWow64LvqO2l7ImSMKdXq
# UeRZBg==
# =IvU9
# -----END PGP SIGNATURE-----
# gpg: Signature made Sat 01 Aug 2026 12:34:47 EDT
# gpg:                using RSA key 7A481E78868B4DB6A85A05C064DF38E8AF7E215F
# gpg:                issuer "richard.henderson@linaro.org"
# gpg: Good signature from "Richard Henderson <richard.henderson@linaro.org>" [full]
# Primary key fingerprint: 7A48 1E78 868B 4DB6 A85A  05C0 64DF 38E8 AF7E 215F

* tag 'pull-i386-20260801' of https://gitlab.com/rth7680/qemu:
  target/i386: Update cc_op for SAHF

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-04 15:28:45 -04:00
Stefan Hajnoczi
9232220004 gitlab: disable provenance attestations to work around CI bug
QEMU's CI pipeline involves building container images that will be used
to run builds and tests. A recent Docker change triggered the following
error:

  $ docker push "$TAG"
  ...
  error from registry: blob unknown to registry - sha256:4401f6f779caf8841cafd5f483e642fcac56a23a4e4a59523231e101c890dad9

https://gitlab.com/qemu-project/qemu/-/jobs/15701875927#L2372

This happens because Docker now pushes out-of-order and the GitLab
Container Registry rejects due to an unknown reference:
https://forum.gitlab.com/t/started-yesterday-docker-push-error-from-registry-blob-unknown-to-registry/134733/5

It is unclear at this point whether GitLab will modify the behavior of
Container Registry or whether Docker will ship a fix.

The current workaround is to disable the provenance attestation that is
involved in this issue. QEMU's CI pipeline container images are used
internally for testing and are not widely distributed. Provenance
attestation can be disabled as there are no external consumers of these
images. Expect to revert this commit in the future when GitLab or Docker
have released their own fixes.

Cc: Alex Bennée <alex.bennee@linaro.org>
Cc: Daniel P. Berrangé <berrange@redhat.com>
Cc: Thomas Huth <thuth@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Message-ID: <20260804165414.480435-1-stefanha@redhat.com>
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-08-04 15:28:33 -04:00
Denis V. Lunev
dd272c8c87 qapi/dump: add allowed-by-guest feature to win-dmp
Commit 1c0e259c5a ("dump: make win_dump_available() check vmcoreinfo
for a Windows dump header") changed two things in a way that is visible
to QMP clients but not to introspection:
query-dump-guest-memory-capability now lists win-dmp only for a guest
that has published a Windows dump header through the vmcoreinfo device,
and dump-guest-memory, which shares win_dump_available(), rejects the
format otherwise. Before that, both accepted win-dmp on any x86
machine.

A client that wants to select win-dmp automatically therefore cannot
trust the capability query on its own: on an older QEMU it reports
win-dmp for every x86 guest, Linux ones included, where the resulting
dump is useless. libvirt ran into exactly this while picking a format
for on_crash and watchdog triggered dumps, and has no way to tell the
two behaviours apart.

Add an 'allowed-by-guest' feature to the win-dmp member of
DumpGuestMemoryFormat so the fixed behaviour becomes discoverable.
DumpGuestMemoryFormat is reachable from both
query-dump-guest-memory-capability's return type and
dump-guest-memory's arguments, so a single flag covers both halves of
the change. Where the feature is absent, a reported win-dmp says
nothing about the guest, and a client that needs the dump to be
loadable afterwards should fall back to elf.

CC: Eric Blake <eblake@redhat.com>
CC: Markus Armbruster <armbru@redhat.com>
CC: "Marc-André Lureau" <marcandre.lureau@redhat.com>
Suggested-by: Daniel P. Berrangé <berrange@redhat.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260731155001.1204103-1-den@openvz.org>
2026-08-04 23:21:40 +04:00
Bin Guo
5ce01c9238 hw/display/virtio-gpu: Unmap DMA regions on reset
virtio_gpu_reset() freed in-flight commands without unmapping the
DMA regions acquired by virtqueue_pop().  Call virtqueue_detach_element()
before g_free() in both drain loops.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3467
Cc: qemu-stable@nongnu.org
Signed-off-by: Bin Guo <guobin@linux.alibaba.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260803082158.62998-1-guobin@linux.alibaba.com>
2026-08-04 23:21:40 +04:00
Akihiko Odaki
d513c644b8 hw/display/virtio-gpu: Always reject invalid scanout bounds
virtio-gpu does not consistently check scanout bounds with wraparound
handling. In the unchecked virgl SET_SCANOUT path, guest dimensions
reach qemu_console_resize(), qemu_create_displaysurface(), and
ultimately qemu_pixman_image_new_shareable(..., &error_abort), so an
invalid rectangle can terminate QEMU. Implement a check with proper
wraparound handling and apply it consistently.

Fixes: 9d9e152136 ("virtio-gpu: add 3d mode and virgl rendering support.")
Fixes: 32db3c63ae ("virtio-gpu: Add virtio_gpu_set_scanout_blob")
Fixes: 7c092f17cc ("virtio-gpu: Handle resource blob commands")
Fixes: 1dcc6adbc1 ("gfxstream + rutabaga: add initial support for gfxstream")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260803-scanout-v1-1-c9831dafdab2@rsg.ci.i.u-tokyo.ac.jp>
2026-08-04 23:21:40 +04:00
Ankur Saini
1f24066fc8 virtio-gpu: reject requests with short/truncated control headers
A short control request can leave command data partially initialized.
For the common header, guest-controlled flags can then cause stale fence
metadata to be returned to the guest.

The command fill helpers detect a short copy but only log and return.
For the common header this leaves the request without any completion;
for type-specific commands the caller still completes the request but
reports VIRTIO_GPU_RESP_OK_NODATA, masking the error. Make
VIRTIO_GPU_FILL_CMD() clear the partially copied object and complete the
request with ERR_INVALID_PARAMETER. Make VUGPU_FILL_CMD() report the same
error through the existing vhost-user-gpu dispatcher. This also rejects
truncated type-specific commands.

The vhost-user-gpu common header is copied outside VUGPU_FILL_CMD(), so
clear it and complete the request directly when that copy is short.

Fixes: CVE-2026-18054
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4094
Reported-by: Ankur Saini <ankur98saini@gmail.com>
Suggested-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Ankur Saini <ankur98saini@gmail.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260803-virtio-gpu-short-header-v3-1-936c1daa8e61@gmail.com>
2026-08-04 23:21:40 +04:00
Marc-André Lureau
555d0a1eba hw/display/virtio-gpu: drop redundant node->value NULL checks
QAPI-generated list visitors guarantee that node->value is never NULL:
the input visitor allocates it via g_malloc0() in visit_start_struct(),
and on failure the entire list parse is aborted and freed.

Remove the unnecessary NULL checks from both callsites iterating
g->conf.outputs.

Resolves: Coverity CID 1664272
Fixes: 8dc8449a67 ("hw/display/virtio-gpu: Avoid leaking migration blocker")
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260730114751.3515083-1-marcandre.lureau@redhat.com>
2026-08-04 23:21:40 +04:00
Marc-André Lureau
b8ef970532 hw/display/virtio-gpu: fix offset wraparound in scanout_blob_to_fb
virtio_gpu_scanout_blob_to_fb() computes the framebuffer offset from
guest-controlled offsets[0], r.x, r.y and stride using uint32_t
arithmetic. When the sum exceeds UINT32_MAX, silent wraparound lets
the guest steer the scanout to an arbitrary in-bounds region of the
blob instead of the intended rectangle.

Compute the offset in uint64_t, reject values exceeding UINT32_MAX
(the width of fb->offset), and only store into fb->offset once both
range checks pass.

("[PATCH] hw/display/virtio-gpu: Remove the bytes_pp field")

Fixes: 32db3c63ae ("virtio-gpu: Add virtio_gpu_set_scanout_blob")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3871
Based-on: <20260719-bpp-v1-1-9b91946d6cf3@rsg.ci.i.u-tokyo.ac.jp>
Reported-by: Cyber_black <Cyberblackk@proton.me>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260725122734.1775774-1-marcandre.lureau@redhat.com>
2026-08-04 23:21:40 +04:00
Marc-André Lureau
a113e0c53f vhost-user-gpu: fix integer overflow in buffer allocation
A malicious guest can trigger a heap buffer overflow in the
vhost-user-gpu backend by sending a VIRTIO_GPU_CMD_RESOURCE_CREATE_2D
with large width and height values (e.g. 65537x65537). The allocation
size width * height * 4 silently wraps in uint32_t arithmetic,
resulting in a much smaller allocation than expected. Subsequent
VIRTIO_GPU_CMD_TRANSFER_TO_HOST_2D writes past the heap buffer.

The in-tree virtio-gpu device (hw/display/virtio-gpu.c) already handles
this via calc_image_hostmem() with uint64_t arithmetic and an overflow
check. Apply the same approach to the vhost-user-gpu contrib backend:

- Add an overflow check in vugbm_buffer_create() rejecting dimensions
  where width * height * 4 exceeds UINT32_MAX
- Promote the size arithmetic to uint64_t in mem_alloc_bo() and
  udmabuf_get_size()
- Check the return value of vugbm_buffer_create() in
  vg_resource_create_2d(), which was previously ignored

Fixes: CVE-2026-15264
Reported-by: "Vulnerability Report" <vr@darknavy.com>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3940
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
Acked-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260710134720.2317856-1-marcandre.lureau@redhat.com>
2026-08-04 23:21:40 +04:00
Marc-André Lureau
95687639e6 hw/display/vga: fix panning_buf OOB after text/graphics switch
The fields last_width and last_height serve two purposes: the text
renderer counts in characters, the graphics renderer in pixels.
panning_buf reallocation is guarded by geometry-change check, so the
unit mismatch can trick it into thinking nothing changed when the
resolution actually grew.

A guest can trigger this by switching graphics -> text -> graphics:

  1. Enter graphics mode with a small width (CR01=0x00, 8 pixels).
     The predicate fires and panning_buf is allocated for that width.

  2. Switch to text mode with a large width (CR01=0xFF, 256 chars).
     The text renderer stores 256 into last_width. The text path
     never touches panning_buf.

  3. Switch back to graphics with a width that happens to equal 256
     in pixels (CR01=0x1F, 32*8 = 256). The predicate sees
     256 == 256 and skips the realloc. With horizontal pel panning
     enabled, vga_draw_line4() then writes a full 256-pixel scanline
     into the buffer still sized for 8 pixels -- a 960-byte heap
     overflow on every scanline, every refresh.

Fix it by reallocating unconditionally panning_buf on
vga_draw_graphic().

Fixes: CVE-2026-17516
Fixes: 973a724eb0 ("vga: implement horizontal pel panning in graphics modes")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4085
Cc: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Warisjeet Singh <sinxx198@gmail.com>
[ Marc- André - drop realloc() resize condition & commit message ]
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260728151456.3704099-1-marcandre.lureau@redhat.com>
2026-08-04 23:21:40 +04:00
Marc-André Lureau
241095547a hw/display/virtio-gpu: validate blob iov size
virtio_gpu_resource_create_blob() stores the guest-controlled blob_size
without checking it against the total size of the iov backing entries.
Since both values are independently guest-controlled, a malicious guest
can set blob_size much larger than the actual iov backing. Subsequent
SET_SCANOUT_BLOB checks bounds against the inflated blob_size, allowing
a pixman surface to be created over the undersized buffer. Any display
refresh then reads past the actual allocation, potentially crashing
QEMU or leaking host memory contents depending on the backing type.

Validate that the iov backing is at least as large as the declared
blob_size in create_blob (when nr_entries > 0, since the spec permits
deferred backing), attach_backing (when attaching to a blob resource),
and the blob migration load path.

Fixes: CVE-2026-66021
Fixes: e0933d91b1 ("virtio-gpu: Add virtio_gpu_resource_create_blob")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3945
Reported-by: "sundayjiang(蒋浩天)" <sundayjiang@tencent.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260729161431.1180691-1-marcandre.lureau@redhat.com>
2026-08-04 23:21:40 +04:00
Daniel P. Berrangé
29922afeae iotests: increase timeouts for tests to 5 minutes
Currently we have tests timeout set to 3 minutes, on the basis
that they're generally done in less than a minute. I've hit a
couple of random failures suggesting that's not sufficiently
pessimistic. Increase the timeout to 5 minutes to have a greater
safety net in high load scenarios.

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
Message-ID: <20260623160326.2346255-1-berrange@redhat.com>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-04 16:30:45 +02:00
Christian Quante
431f59a34d hw/block/fdc: report a missing address mark on an empty drive
READ ID on a drive with no medium terminates normally and returns the
made-up sector ID left over from the "Pretend we are spinning" emulation.
The only error path is a data rate mismatch, and media_rate is assigned
solely by pick_geometry(); it is never reset when the medium is removed.
A guest that has just ejected a diskette is therefore told that one is
still present.

READ, WRITE and FORMAT have a related problem: fd_seek() answers 2 both
for "track/head out of range" and for "no medium", so the callers report
ST0 = ABNTERM with ST1 = 0x00 either way.  Without ST1.MA the guest cannot
tell an absent diskette from a transient error.  Give fd_seek() a return
code of its own for an absent medium, and let both switch statements
report the missing address mark for it.

The comments on the two switches were swapped: fd_seek() answers 2 for a
bad track or head and 3 for a sector past last_sect, but case 2 read
"sect too big" and case 3 "track too big".  Both now say what they mean.

This is a behaviour change for FORMAT TRACK on an empty drive as well,
which now answers ST1.MA rather than ST1 = 0x00.  None of the guests
tested reaches that path -- DOS gives up during media sensing and never
issues the command -- but it seemed wrong to leave fdctrl_format_sector()
falling through to "default" for a case fd_seek() now reports explicitly.

Failing READ ID does not make guests detect the removal: real hardware
never completes the command on an empty drive, because there are no index
pulses, and OS/2 for one relies on that timeout.  It does stop the
controller from claiming a diskette that is not there.

tests/qtest/fdc-test.c starts QEMU with "-device floppy,id=floppy0" and
no medium, and test_read_id asserts a normal termination with a made-up
cylinder 8 / head 1.  That contradicts its neighbours
test_no_media_on_start and test_media_change, which state that DSKCHG
signals an absent medium.  Insert a medium before READ ID and eject it
afterwards -- the rewritten test passes before and after this change --
and add test_read_id_no_media for the empty drive.

Guests checked, reading and writing, with and without a medium: Linux
2.0.34 and 7.0, PC-DOS 7, IBM DOS 5.02, Windows for Workgroups 3.11 and
OS/2 2.11.  None changes behaviour.  No version of the Linux floppy driver
from 1.2.13 to master issues READ ID at all -- FD_READID is defined in the
uapi header for FDRAWCMD users and the driver never sends it -- so Linux
detects an empty drive by stepping the head and reading DSKCHG instead.

Buglink: https://gitlab.com/qemu-project/qemu/-/issues/3971
Signed-off-by: Christian Quante <christian@quante.one>
Message-ID: <20260714164031.60551-3-christian@quante.one>
[kwolf: Added fd_seek() comment for new return value 5]
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-04 16:30:45 +02:00
Christian Quante
d00567f7fb hw/block/fdc: select the drive named by the READ ID command
Every other command handler begins by latching the drive from the command
byte:

    SET_CUR_DRV(fdctrl, fdctrl->fifo[1] & FD_DOR_SELMASK);

fdctrl_handle_readid() does not, so it works on whichever drive happened to
be selected last.  A guest that issues READ ID for a drive other than the
one currently selected gets an answer about the wrong one.

It has gone unnoticed because a driver normally writes the DOR to spin up
the motor first, and that write selects the drive as a side effect.  The
controller does not require it, though, and the command carries the drive
number for a reason.

Reported-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Christian Quante <christian@quante.one>
Message-ID: <20260714164031.60551-2-christian@quante.one>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-04 16:30:45 +02:00
Fiona Ebner
7d06bbb2d9 iotests: test O_TRUNC behavior for fuse exports
The test cases for the blockdev-based export and for the file-based
export with growable=on work before commit a94a1d7699 ("fuse: Manually
process requests (without libfuse)"), then are broken until commit
"block/export/fuse: fix regression with O_TRUNC when export is
growable".

The test case for the blockdev-based export requires passwordless sudo
for losetup and chmod similar to test 108.

Signed-off-by: Fiona Ebner <f.ebner@proxmox.com>
Message-ID: <20260702132256.661429-3-f.ebner@proxmox.com>
[kwolf: Catch OSError when probing sudo support]
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-04 16:30:41 +02:00
Klaus Jensen
7a34f7b879 hw/nvme: fix leak on copy ranges
The buffer holding the ranges for the copy command is not correctly
deallocated.

Fix this.

Cc: qemu-stable@nongnu.org
Link: https://gitlab.com/qemu-project/qemu/-/work_items/4072
Fixes: 796d20681d ("hw/nvme: reimplement the copy command to allow aio cancellation")
Reviewed-by: Jesper Wendel Devantier <foss@defmacro.it>
Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
2026-08-03 15:35:20 -07:00
Minwoo Im
86f938333e hw/nvme: cancel inflight requests on controller reset
nvme_ctrl_reset() freed every SQ/CQ right after nvme_ns_drain(), which
only waits out requests on a per-namespace BlockBackend. That is safe
as long as the guest first tore down I/O queues gracefully (Delete
I/O SQ/CQ), since nvme_del_sq() already cancels and waits for
anything left on a queue before freeing it.

A reset that happens without that graceful sequence first (e.g. an
abrupt/asynchronous controller reset) can still have commands
inflight on blk_aio_*. Freeing sq/cq before those complete leaves
their completion callbacks (nvme_rw_cb() and friends) to run against
already-freed NvmeRequest/NvmeSQueue/NvmeCQueue memory via
nvme_enqueue_req_completion(), causing a use-after-free/segfault.

Run nvme_sq_cancel_inflight() over every queue in nvme_ctrl_reset()
before the free loops, so no in-flight blk_aio_* callback can fire
after sq/cq memory is freed.

Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3398
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3883
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4068
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4072
Signed-off-by: Minwoo Im <minwoo.im@samsung.com>
Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
2026-08-03 06:43:03 -07:00
Minwoo Im
849ea354dd hw/nvme: factor out nvme_sq_cancel_inflight()
Factor the cancel-and-wait loop used by nvme_del_sq() into
nvme_sq_cancel_inflight(), so it can be reused to drain queues on
controller reset.

Cc: qemu-stable@nongnu.org
Signed-off-by: Minwoo Im <minwoo.im@samsung.com>
Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
2026-08-03 06:43:03 -07:00
Minwoo Im
1d5e53df16 hw/nvme: drop AER requests without aiocb in nvme_del_sq()
nvme_del_sq() asserted r->aiocb was always set when canceling a
queue's inflight requests. A pending Async Event Request has no
aiocb (nvme_aer() parks it without issuing any block I/O), so
deleting a queue with an outstanding AER trips the assert instead of
just dropping the request.

Cc: qemu-stable@nongnu.org
Signed-off-by: Minwoo Im <minwoo.im@samsung.com>
Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
2026-08-03 06:43:03 -07:00
Fiona Ebner
b9ad1c4396 block/export/fuse: fix regression with O_TRUNC when export is not growable
Before commit a94a1d7699 ("fuse: Manually process requests (without
libfuse)"), the O_TRUNC flag when open()-ing an export would be
ignored. This is because libfuse sets FUSE_CAP_ATOMIC_O_TRUNC, so the
kernel lets user space handle the O_TRUNC flag, which is ignored by
the fuse code for export. After the commit, FUSE_CAP_ATOMIC_O_TRUNC is
not set anymore, so the O_TRUNC flag is handled by the kernel, which
executes a truncate.

For blockdev-based exports, this causes a regression, because opening
with O_TRUNC would previously work, but results in an ENOTSUP after
commit a94a1d7699. For file-based exports, the fact that truncate is
executed can be considered an improvement in general. However, in
combination with growable=off, this still results in a practical
regression in combination with virt-fw-vars, which opens its output
file with O_TRUNC and previously worked with a file-based export with
growable=off. After commit a94a1d7699, the file is truncated upon open
and then cannot grow, meaning virt-fw-vars won't be able to write the
output.

To fix these regressions, while keeping the improved behavior for
file-based exports with growable=on, set the FUSE_CAP_ATOMIC_O_TRUNC
flag again if growable=off.

Cc: qemu-stable@nongnu.org
Fixes: a94a1d7699 ("fuse: Manually process requests (without libfuse)")
Signed-off-by: Fiona Ebner <f.ebner@proxmox.com>
Message-ID: <20260702132256.661429-2-f.ebner@proxmox.com>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Denis V. Lunev
e554413bd2 coroutine: fix lost wakeup in qemu_co_sleep_wake()
cache_clean_timer_del_and_wait() cancels the cache-cleaner coroutine
by setting s->cache_clean_interval = 0 and calling qemu_co_sleep_wake()
to cut short its qemu_co_sleep_ns_wakeable(). qemu_co_sleep_wake() is
fire-and-forget: it reads w->to_wake and silently returns when it is
NULL. A sleeper that is between two iterations -- has just released
s->lock but has not yet set w->to_wake inside qemu_co_sleep() -- loses
the wake:

  iothread0 timer coroutine           main thread (qcow2 close)
  -------------------------           -------------------------
  while-body (holding s->lock):
    read interval = 600
    wait_ns = 600 * NS
    release s->lock
                                      take s->lock
                                      interval = 0
                                      qemu_co_sleep_wake(w):
                                        w->to_wake == NULL -> skip
                                        return
                                      qemu_co_queue_wait(exit, s->lock):
                                        release s->lock
                                        yield
  qemu_co_sleep_ns_wakeable:
    aio_timer_init(+600 s)
    qemu_co_sleep:
      cas scheduled NULL -> "qsns"
      w->to_wake = co
      yield  [sleeps 600 s]

cache_clean_timer_del_and_wait() then blocks on cache_clean_timer_exit
until the original 600 s expiry fires, and qcow2_close() holds BQL the
whole time so the VM stalls behind it.

block_copy_kick() has the same shape. Fix the primitive once instead
of working around it in each caller.

Use a tri-state for QemuCoSleep::to_wake:

  NULL     - idle
  co       - sleeper parked
  PENDING  - wake delivered, no sleeper yet (sticky)

qemu_co_sleep_wake() xchgs PENDING into to_wake: a real sleeper is
woken, NULL/PENDING is left untouched so the wake stays sticky.
qemu_co_sleep() cmpxchg-publishes itself as the sleeper; if a wake
was delivered before it got there or races the publish, the cmpxchg
observes PENDING and returns without yielding. On normal resume
qemu_co_sleep() clears the PENDING the waker left behind so the next
sleep starts clean.

A double-fire (real wake plus timer callback) is harmless: the first
xchg returns the coroutine and wakes it; the second returns PENDING
and is a no-op. Cancellation latency through qemu_co_sleep_wake() is
now bounded by aio_co_wake() rather than by the sleep duration.

Fixes: f86dde9a15 ("qcow2: Fix cache_clean_timer")
Signed-off-by: Denis V. Lunev <den@openvz.org>
Cc: Hanna Czenczek <hreitz@redhat.com>
Cc: Kevin Wolf <kwolf@redhat.com>
Message-ID: <20260610115850.2410566-2-den@openvz.org>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Denis V. Lunev
5add514ba3 iotests/migrate-bitmaps-postcopy-test: replace the timing assertion with a content check
`downtime * 10 < postcopy_time` was an unnormalized wall-clock
heuristic (commit e80a4150a5) that fails on fast hosts, where the
bitmap payload now transfers in under a second.

Check the actual invariant instead: right after RESUME, bitmap0's
content hash on the destination must not yet match the fully
migrated value. Throttle max-bandwidth first, since all-zero chunks
skip the payload write and would otherwise let a fast host finish
the transfer before the check runs.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Kevin Wolf <kwolf@redhat.com>
CC: Hanna Reitz <hreitz@redhat.com>
CC: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Message-ID: <20260715103451.1930909-4-den@openvz.org>
Reviewed-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Denis V. Lunev
951227d375 iotests: skip FUSE tests when FUSE is not usable
file-io-error, fuse-allow-other and fuse-mmap-shared skip only when
FUSE is not compiled in. When FUSE is built in but unusable at run
time (no /dev/fuse access, fusermount lacking permissions), the
export fails to mount with "Failed to mount FUSE session to export"
and the tests report a spurious failure instead of skipping, like
NBD tests already do for missing NBD support.

Add _notrun_on_fuse_error() to common.rc and use it in the shell
tests. fuse-mmap-shared is Python, so it gets an equivalent inline
check.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Kevin Wolf <kwolf@redhat.com>
CC: Hanna Reitz <hreitz@redhat.com>
Message-ID: <20260715103451.1930909-3-den@openvz.org>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Denis V. Lunev
43e4791d99 iotests: run the test pool with the 'fork' start method
run_tests_pool() shares the runner via the class attribute
TestRunner.shared_self, relying on worker processes to inherit it.
That only works with the 'fork' start method. Python 3.14 switched
the Linux default to 'forkserver', so workers see shared_self as
None and parallel runs abort with:

  assert runner is not None
  AssertionError

Only reproduces with Python 3.14+ and 'check -jN' (N > 1); meson
runs one test per process and never calls run_tests_pool(), so CI
is unaffected.

Request get_context('fork') explicitly; it is available on all
supported Python versions and a no-op before 3.14.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Kevin Wolf <kwolf@redhat.com>
CC: Hanna Reitz <hreitz@redhat.com>
Message-ID: <20260715103451.1930909-2-den@openvz.org>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Denis V. Lunev
fe0f9e3ab2 qcow2: do not try to clear the dirty bit on a read-only node
qcow2_do_close() -> qcow2_inactivate() clears the dirty bit with a
plain write to bs->file, unconditionally. A read-only node can still
be dirty, inherited from an earlier writable session, and that write
then hits a missing BLK_PERM_WRITE and asserts in
bdrv_co_write_req_prepare() (block/io.c) on an entirely ordinary
close -- closing is expected, the dirty bit on a read-only node
is not.

Skip the clear for read-only nodes, same as read access already does.
Any other still-dirty node keeps the unguarded write: it is expected
to hold write permission, and a missing one there is a bug worth
seeing.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Kevin Wolf <kwolf@redhat.com>
CC: Hanna Reitz <hreitz@redhat.com>
Message-ID: <20260716153552.3376009-1-den@openvz.org>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Stefan Hajnoczi
370882d086 dmg: reject inconsistent UDRW chunk sector count and length (CVE-2026-65928)
The chunk metadata contains both:
- Sector count: number of 512-byte sectors in the virtual disk
- Length: number of bytes in the image file

The UDRW chunk type indicates uncompressed data that can be accessed
directly. The code is missing input validation to verify that sector
count is consistent with length.

If sector count is larger than length, then read requests can access
beyond the end of the s->uncompressed_chunk buffer. This is an
out-of-bounds heap access that could lead to a crash or an information
leak.

While we're at it, also zero the end of the last sector when length is
unaligned. This prevents information leaks from the
s->uncompressed_chunk buffer.

Fixes: CVE-2026-65928
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3846
Reported-by: boy juju <agx1657748706@gmail.com>
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
Message-ID: <20260723144519.364701-4-stefanha@redhat.com>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Stefan Hajnoczi
ab7b872f0c dmg: refuse to open files with no chunks
The dmg block driver expects the disk image file to contain at least one
chunk. Refuse to open such files. This ensures that dmg block driver
state always has non-NULL s->sectors[] and related fields.

Note that the previous commit fixed the only known way to trigger a
crash. This patch is just for defense - let's avoid opening the file and
having NULL pointers in dmg block driver state.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4021
Reported-by: Tristan Madani <tristan@talencesecurity.com>
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
Message-ID: <20260723144519.364701-3-stefanha@redhat.com>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Stefan Hajnoczi
0c43f801c0 dmg: fix out-of-bounds load in search_chunk() (CVE-2026-65929)
The binary search in search_chunk() uses s->n_chunks as the (inclusive)
upper bound. Chunk indices are in the right-open interval [0,
s->n_chunks) so it is wrong to search all the way up to s->n_chunks
rather than s->n_chunks - 1.

The worst case security scenario I can see is convincing a victim to
hotplug a malicious DMG file to a running guest, potentially causing
QEMU to crash when loading from memory beyond the end of s->sectors[] or
s->sectorscounts[]. This could be a denial of service.

Fixes: CVE-2026-65929
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3844
Reported-by: boy juju <agx1657748706@gmail.com>
Reported-by: Tristan Madani <tristan@talencesecurity.com>
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
Message-ID: <20260723144519.364701-2-stefanha@redhat.com>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Denis V. Lunev
842c89281a tests/unit: add reproducer for BlockAcctStats histogram locking race
block_latency_histogram_set() and block_latency_histograms_clear()
replace BlockLatencyHistogram's nbins/boundaries/bins without taking
stats->lock, while block_account_one_io() reads those same fields
under that lock from whatever iothread completes the I/O.

Add a test that races two real threads against
block_latency_histogram_set() and
block_acct_start()/block_acct_done() on the same BlockAcctStats.
Applied here it passes, since the previous two commits already take
the lock; reverting them locally reproduces the abort this series
fixes, in about a second.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Kevin Wolf <kwolf@redhat.com>
CC: Hanna Reitz <hreitz@redhat.com>
CC: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
CC: Andrey Drobyshev <andrey.drobyshev@virtuozzo.com>
Message-ID: <20260724111311.4086859-4-den@openvz.org>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Denis V. Lunev
16f94ef4c6 block/qapi: take stats->lock when reading BlockAcctStats for query-blockstats
bdrv_query_blk_stats() reads BlockAcctStats's counters, latency
histogram, and per-interval TimedAverage stats without stats->lock,
while block_account_one_io() updates the same fields under that lock
from an iothread. timed_average_min()/max()/avg() make this worse
than a stale read: they call check_expirations(), which can reset a
window's sum/count/min/max -- a write, not just a read -- so this is
a genuine race with a concurrent writer, not merely a slower reader
like the scalar counters.

Take stats->lock for the whole call, both to close the race and to
make the returned snapshot internally consistent (previously each
field could reflect a different instant relative to concurrent
updates).

block_acct_queue_depth() used to take the lock itself on every call;
since bdrv_query_blk_stats() is its only caller and now already holds
the lock, that would self-deadlock. Make it require the caller to
hold stats->lock instead (documented and asserted).

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Kevin Wolf <kwolf@redhat.com>
CC: Hanna Reitz <hreitz@redhat.com>
CC: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
CC: Andrey Drobyshev <andrey.drobyshev@virtuozzo.com>
Message-ID: <20260724111311.4086859-3-den@openvz.org>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Denis V. Lunev
5b0ba385a0 block/accounting: take stats->lock in latency histogram setters
block_latency_histogram_set() and block_latency_histograms_clear()
replace BlockLatencyHistogram's nbins/boundaries/bins without taking
stats->lock, while block_account_one_io() reads those same fields
under that lock from whatever iothread completes the I/O. The result
is usual use-after-free and qemu crash.

Take stats->lock in both setters, matching the lock already held by
the reader.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Kevin Wolf <kwolf@redhat.com>
CC: Hanna Reitz <hreitz@redhat.com>
CC: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
CC: Andrey Drobyshev <andrey.drobyshev@virtuozzo.com>
Message-ID: <20260724111311.4086859-2-den@openvz.org>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
malike
0d3db94a88 block/cloop: fix integer overflow in total_sectors calculation
The total_sectors is computed as n_blocks * sectors_per_block where
both operands are uint32_t. The multiplication is performed in 32-bit
arithmetic and can overflow when the product exceeds UINT32_MAX,
producing a value much smaller than the true image size. The result
is assigned to int64_t total_sectors but the 32-bit multiplication
has already wrapped around, and the zero-extension to 64-bit does
not recover the correct value.

This causes the block layer to reject valid I/O requests (DoS) when
the reported total_sectors is smaller than the actual image.

Use 64-bit arithmetic by casting one operand to uint64_t so the
multiplication is performed in 64-bit precision.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3972
Signed-off-by: Ma Like <malike@kylinos.cn>
Message-ID: <20260713031750.58448-1-malike@kylinos.cn>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
2026-08-03 10:42:29 +02:00
Cédric Le Goater
338d81b22b vfio/pci: Guard accel_irqchip_begin_route_changes() calls
Since commit 49b2dcbd24 ("accel/accel-irq: add generic
begin_route_changes"), accel_irqchip_begin_route_changes() aborts when
no accelerator irqchip is available. This causes a fatal error when
running VFIO passthrough devices under TCG emulation:

  qemu-system-aarch64: can't initiate route change, no accel irqchip available

The previous kvm_irqchip_begin_route_changes() was a simple inline
that did not have a fatal path. The VFIO code already handles the
absence of KVM MSI routing gracefully by falling back to userspace
handling, but the new generic function aborts before that fallback
can take effect.

Guard the call sites in hw/vfio/pci.c with
accel_msi_via_irqfd_enabled() so that route changes are only
initiated when an accelerator irqchip is actually present.

Fixes: 49b2dcbd24 ("accel/accel-irq: add generic begin_route_changes")
Cc: Magnus Kulke <magnuskulke@linux.microsoft.com>
Link: https://lore.kernel.org/qemu-devel/20260721105026.3932297-1-clg@redhat.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-02 15:53:05 +02:00
Tycho Andersen (AMD)
f498c21b35 hw/vfio: Fix liveness check in vfio_connect_kvm_msi_virq()
While working on savevm/loadvm for a new vfio device, I encountered the
crash below. Since vfio_connect_kvm_msi_virq() didn't check the ->use flag
for the vector, it would pass an unused vector down to
vfio_cpr_load_vector_fd() which would crash.

Fix this by checking the ->use flag along with the virq number to detect
whether a vector is valid or not.

Thread 1 "qemu-system-x86" received signal SIGSEGV, Segmentation fault.
0x0000555555a891ef in vfio_cpr_load_vector_fd (vdev=vdev@entry=0x0,
    name=name@entry=0x555555eeb27e "kvm_interrupt", nr=nr@entry=1) at ../hw/vfio/cpr.c:44
44	    g_autofree char *fdname = STRDUP_VECTOR_FD_NAME(vdev, name);
(gdb) bt
#0  0x0000555555a891ef in vfio_cpr_load_vector_fd
    (vdev=vdev@entry=0x0, name=name@entry=0x555555eeb27e "kvm_interrupt", nr=nr@entry=1)
    at ../hw/vfio/cpr.c:44
#1  0x0000555555ce64a1 in vfio_notifier_init
    (vdev=0x0, e=e@entry=0x5555586971b4, name=name@entry=0x555555eeb27e "kvm_interrupt", nr=nr@entry=1, errp=errp@entry=0x0) at ../hw/vfio/pci.c:79
#2  0x0000555555ce721e in vfio_connect_kvm_msi_virq (vector=0x5555586971a8, nr=nr@entry=1)
    at ../hw/vfio/pci.c:601
#3  0x0000555555cea5a5 in vfio_connect_kvm_msi_virq (nr=1, vector=<optimized out>)
    at ../hw/vfio/pci.c:597
#4  vfio_pci_commit_kvm_msi_virq_batch (vdev=0x55555906de40) at ../hw/vfio/pci.c:822
#5  0x0000555555cea9f2 in vfio_msix_enable (vdev=vdev@entry=0x55555906de40) at ../hw/vfio/pci.c:850
#6  0x0000555555ceb152 in vfio_pci_load_config (vbasedev=0x55555906e900, f=<optimized out>)
    at ../hw/vfio/pci.c:3088
#7  0x0000555555a8c765 in vfio_load_device_config_state (f=0x5555574a43d0, opaque=0x55555906e900)
    at ../hw/vfio/migration.c:278
#8  0x0000555555b3a522 in vmstate_load
    (f=f@entry=0x5555574a43d0, se=se@entry=0x5555591edd40, errp=errp@entry=0x7fffffffe130)
    at ../migration/savevm.c:971
#9  0x0000555555b3ab1a in qemu_loadvm_section_start_full
    (f=f@entry=0x5555574a43d0, type=type@entry=4 '\004', errp=errp@entry=0x7fffffffe130)
    at ../migration/savevm.c:2654
#10 0x0000555555b3e1ee in qemu_loadvm_state_main
    (f=f@entry=0x5555574a43d0, mis=mis@entry=0x5555571de5a0, errp=0x7fffffffe130,
    errp@entry=0x555557157c10 <error_fatal>) at ../migration/savevm.c:2973
#11 0x0000555555b3f7b7 in qemu_loadvm_state
    (f=f@entry=0x5555574a43d0, errp=errp@entry=0x555557157c10 <error_fatal>)
    at ../migration/savevm.c:3058
#12 0x0000555555b40863 in load_snapshot
    (name=0x7fffffffecc9 "foo", vmstate=vmstate@entry=0x0, has_devices=has_devices@entry=false, devices=devices@entry=0x0, errp=errp@entry=0x555557157c10 <error_fatal>) at ../migration/savevm.c:3452
#13 0x0000555555adc211 in qmp_x_exit_preconfig (errp=0x555557157c10 <error_fatal>) at ../system/vl.c:2817
#14 qmp_x_exit_preconfig (errp=0x555557157c10 <error_fatal>) at ../system/vl.c:2802
#15 0x0000555555adf8ed in qemu_init (argc=<optimized out>, argv=<optimized out>) at ../system/vl.c:3849
#16 0x00005555558903fd in main (argc=<optimized out>, argv=<optimized out>) at ../system/main.c:71

Fixes: 30edcb4d4e ("vfio-pci: preserve MSI")
Signed-off-by: Tycho Andersen (AMD) <tycho@kernel.org>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260727150038.2684512-1-tycho@kernel.org
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-08-02 15:53:05 +02:00
Richard Henderson
c25f69595a target/i386: Update cc_op for SAHF
Removing the call to gen_compute_eflags meant we no longer
updated cc_op after computing EFLAGS.

Cc: qemu-stable@nongnu.org
Fixes: da7649c6ae ("target/i386/tcg: do not compute all flags for SAHF")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3537
Tested-by: Christian Quante <christian@quante.one>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-08-01 09:33:18 -07:00
Stefan Hajnoczi
b428fe0362 target-arm queue:
* target/arm: Fix b16b16 feature test for SME2 BFCLAMP, BFMAX, BFMIN
  * target/arm: Fix feature tests for AArch32 SEV, WFI, WFE, YIELD
 -----BEGIN PGP SIGNATURE-----
 
 iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmpsyvcZHHBldGVyLm1h
 eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3srrEACDq61BLXaeUwtXRcDTT6Dn
 SwQo24KzVPzyiSZkamXJHxQ+H35uHXhcM2MmbH9IVRLkj3ryp+XlkdYbocO5gveD
 KjXKryjhVf2zbiO0O3OQm2pzeZEQyZrqsj1byc1VqQ5sgd3PUb/xJCI/BFjedpWu
 0l2XdbdtZ3G90DuLHpjdtxP1MLgNHsly4D16BuCT6B5QGSgJhs7o9sKuijlneu82
 wEIHz5wWqZUPVWAZfigRaR9ZnVHD9Ko4CvEmvowdjvKGlZuff6c28mzHJHHIe2IL
 soJRYTPeQTp3t5E0G69plgSfR1SU2PE8F5qL5AN4uS21QspqZH+byNmfoVwXe834
 WN3OR3OaevkPc5Z6dJEvgQpBGMzRgPD1o5UDel4AMyDck8kHnksM5ycNev4uhgLH
 irgiGq28w0laab00dkQKdIVhqYBie9vZqH+3MoOaf3DL8qZu9xTk3w4PUgDRijsg
 FsPYuxTegJ9TWxtDnVTCucE+Fyai5H3p9jLKHBj3exh7hKTi52JG9cmIMoXNv7jn
 hikRtNkj6ZkPB2hxI8BcKV6wO6sWEWx53djVhEKQ7KdKlSD0uRv6rWqSkMO89rfx
 m79soqA6Bbj8B6pYE8Y2rC7mWtkoZu+2mgjCLEGghVnIJ40yN3d9+9IKvT4Gq9RJ
 LrYWr1rtVCahlKByyAipQg==
 =+8IO
 -----END PGP SIGNATURE-----

Merge tag 'pull-target-arm-20260731' of https://gitlab.com/pm215/qemu into staging

target-arm queue:
 * target/arm: Fix b16b16 feature test for SME2 BFCLAMP, BFMAX, BFMIN
 * target/arm: Fix feature tests for AArch32 SEV, WFI, WFE, YIELD

# -----BEGIN PGP SIGNATURE-----
#
# iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmpsyvcZHHBldGVyLm1h
# eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3srrEACDq61BLXaeUwtXRcDTT6Dn
# SwQo24KzVPzyiSZkamXJHxQ+H35uHXhcM2MmbH9IVRLkj3ryp+XlkdYbocO5gveD
# KjXKryjhVf2zbiO0O3OQm2pzeZEQyZrqsj1byc1VqQ5sgd3PUb/xJCI/BFjedpWu
# 0l2XdbdtZ3G90DuLHpjdtxP1MLgNHsly4D16BuCT6B5QGSgJhs7o9sKuijlneu82
# wEIHz5wWqZUPVWAZfigRaR9ZnVHD9Ko4CvEmvowdjvKGlZuff6c28mzHJHHIe2IL
# soJRYTPeQTp3t5E0G69plgSfR1SU2PE8F5qL5AN4uS21QspqZH+byNmfoVwXe834
# WN3OR3OaevkPc5Z6dJEvgQpBGMzRgPD1o5UDel4AMyDck8kHnksM5ycNev4uhgLH
# irgiGq28w0laab00dkQKdIVhqYBie9vZqH+3MoOaf3DL8qZu9xTk3w4PUgDRijsg
# FsPYuxTegJ9TWxtDnVTCucE+Fyai5H3p9jLKHBj3exh7hKTi52JG9cmIMoXNv7jn
# hikRtNkj6ZkPB2hxI8BcKV6wO6sWEWx53djVhEKQ7KdKlSD0uRv6rWqSkMO89rfx
# m79soqA6Bbj8B6pYE8Y2rC7mWtkoZu+2mgjCLEGghVnIJ40yN3d9+9IKvT4Gq9RJ
# LrYWr1rtVCahlKByyAipQg==
# =+8IO
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri 31 Jul 2026 12:19:03 EDT
# gpg:                using RSA key E1A5C593CD419DE28E8315CF3C2525ED14360CDE
# gpg:                issuer "peter.maydell@linaro.org"
# gpg: Good signature from "Peter Maydell <peter.maydell@linaro.org>" [full]
# gpg:                 aka "Peter Maydell <pmaydell@gmail.com>" [full]
# gpg:                 aka "Peter Maydell <pmaydell@chiark.greenend.org.uk>" [full]
# gpg:                 aka "Peter Maydell <peter@archaic.org.uk>" [unknown]
# Primary key fingerprint: E1A5 C593 CD41 9DE2 8E83  15CF 3C25 25ED 1436 0CDE

* tag 'pull-target-arm-20260731' of https://gitlab.com/pm215/qemu:
  target/arm: Remove stale comment about WFE/SEV implementation
  target/arm: Make YIELD, WFI and WFE be NOPs on pre-v6K
  target/arm: Don't NOP the SEV insn on v6K CPUs
  target/arm: Fix b16b16 feature test for SME2 BFCLAMP, BFMAX, BFMIN

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-31 16:19:04 -04:00
Peter Maydell
c490037c13 target/arm: Remove stale comment about WFE/SEV implementation
We forgot to remove a comment about WFE/SEV only being implemented
for M-profile when we added the A-profile support for this; delete
the stale text.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260728111629.1705308-4-peter.maydell@linaro.org
2026-07-31 11:24:27 +01:00
Peter Maydell
d88781a4e8 target/arm: Make YIELD, WFI and WFE be NOPs on pre-v6K
The YIELD, WFI and WFE instructions are in the NOP hint space, and
were only defined to actual non-NOP instructions starting in the v6K
architecture; they are also present for all M-profile architecture
versions.

We never did check the architecture version before making these
instructions have their special behaviour.  Mostly this has not been
a problem because a guest won't execute one of these insns unless it
is prepared for it to have its usual effect, and because we
implemented SEV and WFE as NOPs anyway.

Now we have implemented SEV and WFE to be more than just NOPs, it's
important that we have the same condition on the SEV as the WFE, so
that we either NOP both or else implement both.  A guest probably
won't try to use SEV/WFE on CPUs that don't implement them, but it is
valid for it to do that and rely on them both being NOPs (and so a
WFE-loop falls back to a pure busy-wait loop).

Add the "only if M profile or v6K or better" check to YIELD, WFE and
WFI.  This means that all the insns in the NOP-hint space for A32,
T32 and T16 have a correct feature check.

Fixes: 60e7ee5bb7 ("target/arm: implements SEV/SEVL for all modes")
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260728111629.1705308-3-peter.maydell@linaro.org
2026-07-31 11:24:27 +01:00
Peter Maydell
dd0d695306 target/arm: Don't NOP the SEV insn on v6K CPUs
When we implememented SEV to do something on A-profile rather than
being a nop, we got the condition slightly wrong, and made it only
effective from v7.  In fact the instruction's Arm encoding has
non-NOP behaviour from ARMv6K.

The effect is that a kernel boot may hang on a v6K CPU like the
ARM11MPCore.

(This wouldn't have been so noticeable if we feature checked the WFE
instruction, and had made the same mistake for the condition on both
instructions.  But we never have done the feature checks that we
ought on WFE, so the mistake on SEV meant that we showed the 11mpcore
guest a WFE that did something and a SEV that was a NOP.)

The v7A Arm ARM is not entirely clear about whether v6K has the Thumb
SEV encoding or not: it says "ARMv7 (executes as NOP in ARMv6T2)",
leaving v6K not stated.  The 11MPCore TRM says it has at least WFI in
both Arm and Thumb, and the v7A Arm ARM uses the same condition text
for WFI, so I make the assumption that WFI, WFE, and SEV all get
their functionality for both Thumb and Arm in v6K.  It's possible
that this differed between v6K CPUs -- the 1176 TRM says it has the
v6K STREXD/STREXH/STREXB etc, but the WFI is the old-style cp15 one.

Keeping the condition check the same for both Thumb and Arm encodings
is the conservative choice: if guests try to execute the Thumb SEV
insn it will be because they want SEV, not because they want a NOP.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4044
Fixes: 60e7ee5bb7 ("target/arm: implements SEV/SEVL for all modes")
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260728111629.1705308-2-peter.maydell@linaro.org
2026-07-31 11:24:27 +01:00
Richard Henderson
702252a0db target/arm: Fix b16b16 feature test for SME2 BFCLAMP, BFMAX, BFMIN
These are controlled by FEAT_SVE_B16B16 not FEAT_SME_B16B16.

Cc: qemu-stable@nongnu.org
Fixes: bc65d2bd1c ("target/arm: Implement SME2 Multiple and Single SVE Destructive")
Fixes: 930760eb75 ("target/arm: Implement SME2 Multiple Vectors SVE Destructive")
Fixes: 8b61eff8e7 ("target/arm: Implement SME2 FCLAMP, SCLAMP, UCLAMP")
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-31 11:24:27 +01:00
Stefan Hajnoczi
0345ef676b linux-user patches
Three linux-user patches, one aarch64 shadow stack fix
 and two fixes for members of the target_msqid_ds struct.
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCampphwAKCRD3ErUQojoP
 X7D4AQDACw5DckBlNDY+3pDWE6/vYLFx+GJXgZKpF7nVf+/VugEA7QggRBMc82ch
 5g4vDD+y8o6EBPHT+/vD8Ip2uYcDqgQ=
 =azKH
 -----END PGP SIGNATURE-----

Merge tag 'linux-user-pull-request' of https://github.com/hdeller/qemu-hppa into staging

linux-user patches

Three linux-user patches, one aarch64 shadow stack fix
and two fixes for members of the target_msqid_ds struct.

# -----BEGIN PGP SIGNATURE-----
#
# iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCampphwAKCRD3ErUQojoP
# X7D4AQDACw5DckBlNDY+3pDWE6/vYLFx+GJXgZKpF7nVf+/VugEA7QggRBMc82ch
# 5g4vDD+y8o6EBPHT+/vD8Ip2uYcDqgQ=
# =azKH
# -----END PGP SIGNATURE-----
# gpg: Signature made Wed 29 Jul 2026 16:58:47 EDT
# gpg:                using EDDSA key BCE9123E1AD29F07C049BBDEF712B510A23A0F5F
# gpg: Good signature from "Helge Deller <deller@gmx.de>" [unknown]
# gpg:                 aka "Helge Deller <deller@kernel.org>" [unknown]
# gpg:                 aka "Helge Deller <deller@debian.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 4544 8228 2CD9 10DB EF3D  25F8 3E5F 3D04 A7A2 4603
#      Subkey fingerprint: BCE9 123E 1AD2 9F07 C049  BBDE F712 B510 A23A 0F5F

* tag 'linux-user-pull-request' of https://github.com/hdeller/qemu-hppa:
  linux-user/aarch64: Fix SHADOW_STACK_SET_TOKEN
  linux-user: fix incorrect msg_l[sr]pid members of target_msqid_ds
  linux-user: Fix msqid_ds struct wrt 32-bit big endian architectures

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-30 10:52:26 -04:00
Richard Henderson
8d0ac5933a linux-user/aarch64: Fix SHADOW_STACK_SET_TOKEN
The token is not computed via TARGET_PAGE_SIZE, but via a fixed 12-bit field.

Cc: qemu-stable@nongnu.org
Fixes: ad1afe433f ("linux-user/aarch64: Implement map_shadow_stack syscall")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4106
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-07-29 22:56:12 +02:00
no92
518a4aa01b linux-user: fix incorrect msg_l[sr]pid members of target_msqid_ds
The members are declared as __kernel_pid_t in Linux UAPI headers.
Analogous members in struct target_shmid_ds (shm_[cl]pid) are also
declared as abi_int.

Cc: qemu-stable@nongnu.org
Fixes: 1c54ff97bb ("linux-user: fix and cleanup IPCOP_msg* ipc calls handling")
Signed-off-by: no92 <leo@managarm.org>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-07-29 22:56:12 +02:00
Helge Deller
9e3df3019d linux-user: Fix msqid_ds struct wrt 32-bit big endian architectures
Make sure that the time entries (msg_stime, msg_rtime and msg_ctime)
are defined as 64-bit time_t values, since the userspace may access
the whole 64-bit value. By this change we fix the word ordering for
32-bit big endian architectures as well.

This fixes the msgctl01 LTP testcase on hppa32.

Cc: qemu-stable@nongnu.org
Signed-off-by: Helge Deller <deller@gmx.de>
2026-07-29 22:56:12 +02:00
Stefan Hajnoczi
e1705a25af Update version for v11.1.0-rc2 release
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-29 06:16:08 -04:00
Stefan Hajnoczi
6d9b2e4a2c Parallels block driver patches
- fix a reachable assert()/process abort on a crafted image with an
   inconsistent BAT vs. advertised disk size (GitLab #3804)
 - fix related integer overflows capping the format's usable catalog
   size below its documented maximum
 - reject BAT entries pointing outside the data area in either
   direction
 - harden the dirty-bitmap extension loader against a reachable
   abort and an unsafe allocator
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEC66qh9MCCtwRUOUfXgdxtstmbKsFAmpoy6UACgkQXgdxtstm
 bKvDcA/7Bis1fqsgvsLDiLfxPmNXmaA6JwsHLCgcqnBtrlfucLpDghsE6Nr6Lthb
 zgkYuWrNRtnIwbGEe4oW4jEukLb8k6hyUlwfQvIQik3rV0nnv1G4ewQMH7TmLKX+
 xqFSK+TUpW5bQMphH3yOM2IShgytCXirPSZLfz1GY76eOSWcab/SgzPhANTf6bG3
 o3eVZML9GrPDeDx3MuNdqfup+pX081xOM9l3Ub1hn8YRVvvZiaEmaw4HvT66Qnul
 XL9/biNii0r7b4uITOj6Pvvft7W5yW5d+VL9P5hiidDvhwpC6CAjpu7/qScA3ZH2
 v3MWnXwOEPLnmUE43ZR/8Vb07bHdSHuVLGgD7RPdmWGMMM2pzaCpbMRkdr9ABY5k
 IdPISsijSeGt4Vi9hhXsBiL2tzBJ0w8w+x6o7YNM8RkHzKm7APWwKssJ6kIyQC7g
 ImNgSVRbXBf+4bAD2MUiy3MOfkJ8li9oCXuFaC9fUx5Y4Y4DZdAmARjccUNwttMa
 oixwlypndqJsXspikAsqQqMqA/cVAUd+rec2jDVx3W2nhZsV3KsMu8hD4jYeQkTx
 CRi7owYuA0Z+eNLVvdsji292GcQKP7jcriM1gsSbhyyYDJUT3FHtpNKUxWOr1nFz
 YWj8xSPy5rCpO9CheSXWtk7v/GKpq3riQ48KBbnfArBNxPBPNDY=
 =aCB6
 -----END PGP SIGNATURE-----

Merge tag 'pull-parallels-2026-07-28' of https://gitlab.com/dlunev/qemu into staging

Parallels block driver patches

- fix a reachable assert()/process abort on a crafted image with an
  inconsistent BAT vs. advertised disk size (GitLab #3804)
- fix related integer overflows capping the format's usable catalog
  size below its documented maximum
- reject BAT entries pointing outside the data area in either
  direction
- harden the dirty-bitmap extension loader against a reachable
  abort and an unsafe allocator

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEC66qh9MCCtwRUOUfXgdxtstmbKsFAmpoy6UACgkQXgdxtstm
# bKvDcA/7Bis1fqsgvsLDiLfxPmNXmaA6JwsHLCgcqnBtrlfucLpDghsE6Nr6Lthb
# zgkYuWrNRtnIwbGEe4oW4jEukLb8k6hyUlwfQvIQik3rV0nnv1G4ewQMH7TmLKX+
# xqFSK+TUpW5bQMphH3yOM2IShgytCXirPSZLfz1GY76eOSWcab/SgzPhANTf6bG3
# o3eVZML9GrPDeDx3MuNdqfup+pX081xOM9l3Ub1hn8YRVvvZiaEmaw4HvT66Qnul
# XL9/biNii0r7b4uITOj6Pvvft7W5yW5d+VL9P5hiidDvhwpC6CAjpu7/qScA3ZH2
# v3MWnXwOEPLnmUE43ZR/8Vb07bHdSHuVLGgD7RPdmWGMMM2pzaCpbMRkdr9ABY5k
# IdPISsijSeGt4Vi9hhXsBiL2tzBJ0w8w+x6o7YNM8RkHzKm7APWwKssJ6kIyQC7g
# ImNgSVRbXBf+4bAD2MUiy3MOfkJ8li9oCXuFaC9fUx5Y4Y4DZdAmARjccUNwttMa
# oixwlypndqJsXspikAsqQqMqA/cVAUd+rec2jDVx3W2nhZsV3KsMu8hD4jYeQkTx
# CRi7owYuA0Z+eNLVvdsji292GcQKP7jcriM1gsSbhyyYDJUT3FHtpNKUxWOr1nFz
# YWj8xSPy5rCpO9CheSXWtk7v/GKpq3riQ48KBbnfArBNxPBPNDY=
# =aCB6
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 28 Jul 2026 11:32:53 EDT
# gpg:                using RSA key 0BAEAA87D3020ADC1150E51F5E0771B6CB666CAB
# gpg: Good signature from "Denis V. Lunev <den@openvz.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 0BAE AA87 D302 0ADC 1150  E51F 5E07 71B6 CB66 6CAB

* tag 'pull-parallels-2026-07-28' of https://gitlab.com/dlunev/qemu:
  MAINTAINERS: update parallels tree location
  parallels: validate BAT capacity against advertised disk size
  parallels: avoid fatal abort on large bitmap L1 table
  parallels: skip loading a genuinely empty bitmap L1 table
  parallels: validate bitmap L1 table size before allocating it
  parallels: reject BAT entries pointing outside backed storage
  parallels: fix bat_entries overflow in image creation
  parallels: read header/BAT table in bounded chunks
  parallels: fix integer overflow in header size calculation

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 17:00:42 -04:00
Stefan Hajnoczi
0b6369d225 nvme queue
-----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEUigzqnXi3OaiR2bATeGvMW1PDekFAmpo7fsACgkQTeGvMW1P
 DenNsQf8DKGh04GdsYWRBg6HTaLtLLO4Bb077QWBXEPjg0ZK08mR9QCWRvgC8neo
 CeriJ7NtALaN1om0A+z2duNH75HtG2w+GZoIfBP154uGPNsPKYMx0abT/q69+z9s
 aW+qwvlonj445N3zWAMH5ye5IOVc89tLf8MwUnooDfV5jfNg3JJBH5fFDIq91IkA
 22mSS5d00yB03cu+b43wrGVyBymlT2fo/oESrKDBoF5/Bf5Sx7OPzbNwRtuDekga
 xmmsMp9Zh7otvghBk8jL/fh1DFUt1ZB2jWF2QDjQhe94A6OaU0L7CBZ8U42x3lXe
 M5v1bwWmcru0otLCNsA1C5VLOksfzw==
 =4WPu
 -----END PGP SIGNATURE-----

Merge tag 'pull-nvme-20260728' of https://gitlab.com/birkelund/qemu into staging

nvme queue

# -----BEGIN PGP SIGNATURE-----
#
# iQEzBAABCgAdFiEEUigzqnXi3OaiR2bATeGvMW1PDekFAmpo7fsACgkQTeGvMW1P
# DenNsQf8DKGh04GdsYWRBg6HTaLtLLO4Bb077QWBXEPjg0ZK08mR9QCWRvgC8neo
# CeriJ7NtALaN1om0A+z2duNH75HtG2w+GZoIfBP154uGPNsPKYMx0abT/q69+z9s
# aW+qwvlonj445N3zWAMH5ye5IOVc89tLf8MwUnooDfV5jfNg3JJBH5fFDIq91IkA
# 22mSS5d00yB03cu+b43wrGVyBymlT2fo/oESrKDBoF5/Bf5Sx7OPzbNwRtuDekga
# xmmsMp9Zh7otvghBk8jL/fh1DFUt1ZB2jWF2QDjQhe94A6OaU0L7CBZ8U42x3lXe
# M5v1bwWmcru0otLCNsA1C5VLOksfzw==
# =4WPu
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 28 Jul 2026 13:59:23 EDT
# gpg:                using RSA key 522833AA75E2DCE6A24766C04DE1AF316D4F0DE9
# gpg: Good signature from "Klaus Jensen <its@irrelevant.dk>" [unknown]
# gpg:                 aka "Klaus Jensen <k.jensen@samsung.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: DDCA 4D9C 9EF9 31CC 3468  4272 63D5 6FC5 E55D A838
#      Subkey fingerprint: 5228 33AA 75E2 DCE6 A247  66C0 4DE1 AF31 6D4F 0DE9

* tag 'pull-nvme-20260728' of https://gitlab.com/birkelund/qemu:
  hw/nvme: fix unintentional integer overflow in shift
  hw/nvme: fix cross-namespace copy dif buffer overflow
  hw/nvme: fix assertion failure on subregion removal
  hw/nvme: use GPtrArray for blocker_features

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 17:00:07 -04:00
Klaus Jensen
c39e05af43 hw/nvme: fix unintentional integer overflow in shift
Fix potentially overflowing shift operation.

Cc: qemu-stable@nongnu.org
Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Suggested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Resolves: Coverity CID 1663674
Fixes: ec917cd499 ("hw/nvme: fix FDP set FDP events")
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
2026-07-28 19:59:01 +02:00
Klaus Jensen
df67805ee9 hw/nvme: fix cross-namespace copy dif buffer overflow
The NVMe specification allows a controller with multiple namespaces to
use different LBA formats per namespace. One implication of this is that
the destination namespace may have a metadata area for PI, but the
source does not. In that case, the controller shall generate the
protection information, but the bounce buffer is erroneously allocated
without space for that, causing a buffer overflow.

Fix the allocation.

Cc: qemu-stable@nongnu.org
Fixes: d522aef88d ("hw/nvme: add cross namespace copy support")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3387
Reported-by: Jihe Wang <wangjihe.mail@gmail.com>
Reported-by: boy juju <agx1657748706@gmail.com>
Reported-by: contact <contact@xchglabs.com>
Reported-by: david korczynski <david@adalogics.com>
Reported-by: Brian Chastain (off_by_one / Curious-Keeper) <brian@scalingsuccess.io>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
2026-07-28 19:59:01 +02:00
Daniel Paziyski
6e5ca34f38 hw/nvme: fix assertion failure on subregion removal
When a controller is created with a MSI-X exclusive BAR, the bar0 memory region
is not used at all, and so, the iomem region is not added as a subregion of it.
However, when removing a NVMe controller, the iomem region is unconditionally
removed as a subregion of bar0, causing an assertion failure. Remove the iomem
memory region as a subregion of bar0 only if not using a MSI-X exclusive BAR.

QEMU options (requires a hotunplug-aware OS):

        -M q35 -device pcie-root-port,id=rp0 \
        -device nvme,serial=ctrl0,id=ctrl0,bus=rp0,msix-exclusive-bar=on

In the QEMU monitor, or by causing an ejection from the OS:

        device_del ctrl0

Message in stderr:

qemu-system-x86_64: ../system/memory.c:2617: memory_region_del_subregion: Assertion `subregion->container == mr' failed.

Fixes: fa905f65c5 ("hw/nvme: add machine compatibility parameter to enable msix exclusive bar")
Fixes: 9162f10125 ("hw/nvme: fix msix_uninit with exclusive bar")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4090
Signed-off-by: Daniel Paziyski <danielpaziyski@gmail.com>
Reviewed-by: Klaus Jensen <k.jensen@samsung.com>
Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
2026-07-28 19:58:52 +02:00
Alexander Mikhalitsyn
30724cfee6 hw/nvme: use GPtrArray for blocker_features
Let's use GPtrArray to build a list of blocker features and then
g_strjoinv() to build a final comma-delimited string.

While previous approach was technically correct, it is fragile
(because we need to take care of static buffer size choice) and
Coverity dislikes it too.

Note, that we use g_ptr_array_new() to allocate array which means
that GDestroyNotify callback is not set, so we can pass pointers to
a static memory like g_ptr_array_add(..., (gpointer) "SR-IOV") without
any problems as there won't be any attempt to free that memory.

Resolves: Coverity CID 1663673
Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Klaus Jensen <k.jensen@samsung.com>
[k.jensen: change cast from gpointer to void ptr]
Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
2026-07-28 19:58:10 +02:00
Stefan Hajnoczi
9f4d05a21f target-arm queue:
* target/arm: Fix various compilation issues in --disable-tcg configs
  * hw/net/flexcan: Fix issues spotted by Coverity
  * docs/system/arm: Update Nuvoton OpenBMC image guidance
  * hw/misc/mps2-scc.c: Ffix cfg7 write
  * hw/misc/mps2-scc.c: fix scc_partno field width
  * hw/i2c/bcm2835_i2c: Correct CLKT register offset
  * hw/display/exynos4210_fimd: fix coordinates bounds handling to avoid
    guest being able to access outside the framebuffer backing memory
 -----BEGIN PGP SIGNATURE-----
 
 iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmpooNkZHHBldGVyLm1h
 eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3r3DD/9zWC6QBBqqP70C8uAgZgHe
 AUI84BFa3OU5ttIBdG1Ze/qfv6ZKb6G16egjwIyikAIdrylSdhFyQIhUPad7INFN
 Yb6wIuGFTr4UTRr3tbnMAELyxamIwsp2vuNeWCjG6XxwJo6FECnV2ruAjALr1fjn
 vitKESyBdp0aCnjtsbRNvIWxFBGUnn6o1UwNX5epHQJQySEFTyUaadA7xeXxnhc4
 wNLzxccj1epzWuvEYfXPmxTa8QcEIR7cgs1U3hdI3tYVaCMdE0KTyFdf5CpDDek6
 p/dwMjsm4Bq00/2P8PGosDQjI20ySAzG2aB9KFiBr50HhDiAgm5iVS5Qf7QekLmm
 Si4rUIGBh3l+SVBUwbH9y3qUTrCtkBY2hU03pV1cU4FDH5wGsSc/lEh34jnS3ilw
 s79GonlH2GlUAaspyb9DuYFqu6qYoXC5gSLVHDBp+t2dEdV1vPAYARhimvLXK+qM
 v5fWyQW8Nn0u8sztNRw2gh4LVs7zMzYXwLqemeZdpkFBHVQ3os5bCkfsFHVU/uqN
 uZdz/6HLC+jmvN5Y9Y6fuHFcbIYOvpKrPjMR78Q/68F0ZtKFqhvtu2gN2XgFkKeO
 8GlpO8WOMfEpwTQxPnUIrErCZsCDMhg80oRgDFyEPFHvwfm5uGdLQmhedD8jlKcY
 y0PRWdahSreEI0F9ari9JQ==
 =8hdb
 -----END PGP SIGNATURE-----

Merge tag 'pull-target-arm-20260728' of https://gitlab.com/pm215/qemu into staging

target-arm queue:
 * target/arm: Fix various compilation issues in --disable-tcg configs
 * hw/net/flexcan: Fix issues spotted by Coverity
 * docs/system/arm: Update Nuvoton OpenBMC image guidance
 * hw/misc/mps2-scc.c: Ffix cfg7 write
 * hw/misc/mps2-scc.c: fix scc_partno field width
 * hw/i2c/bcm2835_i2c: Correct CLKT register offset
 * hw/display/exynos4210_fimd: fix coordinates bounds handling to avoid
   guest being able to access outside the framebuffer backing memory

# -----BEGIN PGP SIGNATURE-----
#
# iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmpooNkZHHBldGVyLm1h
# eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3r3DD/9zWC6QBBqqP70C8uAgZgHe
# AUI84BFa3OU5ttIBdG1Ze/qfv6ZKb6G16egjwIyikAIdrylSdhFyQIhUPad7INFN
# Yb6wIuGFTr4UTRr3tbnMAELyxamIwsp2vuNeWCjG6XxwJo6FECnV2ruAjALr1fjn
# vitKESyBdp0aCnjtsbRNvIWxFBGUnn6o1UwNX5epHQJQySEFTyUaadA7xeXxnhc4
# wNLzxccj1epzWuvEYfXPmxTa8QcEIR7cgs1U3hdI3tYVaCMdE0KTyFdf5CpDDek6
# p/dwMjsm4Bq00/2P8PGosDQjI20ySAzG2aB9KFiBr50HhDiAgm5iVS5Qf7QekLmm
# Si4rUIGBh3l+SVBUwbH9y3qUTrCtkBY2hU03pV1cU4FDH5wGsSc/lEh34jnS3ilw
# s79GonlH2GlUAaspyb9DuYFqu6qYoXC5gSLVHDBp+t2dEdV1vPAYARhimvLXK+qM
# v5fWyQW8Nn0u8sztNRw2gh4LVs7zMzYXwLqemeZdpkFBHVQ3os5bCkfsFHVU/uqN
# uZdz/6HLC+jmvN5Y9Y6fuHFcbIYOvpKrPjMR78Q/68F0ZtKFqhvtu2gN2XgFkKeO
# 8GlpO8WOMfEpwTQxPnUIrErCZsCDMhg80oRgDFyEPFHvwfm5uGdLQmhedD8jlKcY
# y0PRWdahSreEI0F9ari9JQ==
# =8hdb
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 28 Jul 2026 08:30:17 EDT
# gpg:                using RSA key E1A5C593CD419DE28E8315CF3C2525ED14360CDE
# gpg:                issuer "peter.maydell@linaro.org"
# gpg: Good signature from "Peter Maydell <peter.maydell@linaro.org>" [full]
# gpg:                 aka "Peter Maydell <pmaydell@gmail.com>" [full]
# gpg:                 aka "Peter Maydell <pmaydell@chiark.greenend.org.uk>" [full]
# gpg:                 aka "Peter Maydell <peter@archaic.org.uk>" [unknown]
# Primary key fingerprint: E1A5 C593 CD41 9DE2 8E83  15CF 3C25 25ED 1436 0CDE

* tag 'pull-target-arm-20260728' of https://gitlab.com/pm215/qemu:
  hw/display/exynos4210_fimd: Clamp windows to screen size
  hw/display/exynos4210_fimd: Pass width to draw_line functions
  hw/display/exynos4210_fimd: Factor out finding screen width/height
  hw/i2c/bcm2835_i2c: Correct CLKT register offset
  hw/misc/mps2-scc.c: fix scc_partno field width
  hw/misc/mps2-scc.c: fix cfg7 write
  docs/system/arm: Update Nuvoton OpenBMC image guidance
  hw/net/can/flexcan: Remove RX SMB raw view
  hw/net/can/flexcan: Fix RXIMR reset mask
  hw/net/flexcan: Drop oversized 'mb[]' mailbox view
  hw/net/can/flexcan: Fix mailbox reset mask initialization
  hw/net/can/flexcan: Fix mailbox index calculation in flexcan_mem_read()
  hw/net/can/flexcan: Fix mailbox index calculation in flexcan_mem_write()
  hw/net/can/flexcan: Fix out-of-bounds access in flexcan_mx_rx()
  hw/net/flexcan: Drop unused RX FIFO register overlay
  hw/net/can/flexcan: Use mbs[] array for FIFO pop
  target/arm: Build TCG stubs as stub library
  target/arm: Only compile gicv5-cpuif.c when GICv5 is selected
  target/arm: Add stub for define_gicv5_cpuif_regs()
  hw/intc/arm_gicv3: Fix ARM_GICV3 dependency for KVM / WHPX

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 11:33:19 -04:00
Denis V. Lunev
352587cbe2 MAINTAINERS: update parallels tree location
src.openvz.org is become unmaintained, point to the GitLab tree
instead.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 16:55:00 +02:00
Denis V. Lunev
e8a28c2e0e parallels: validate BAT capacity against advertised disk size
parallels_open() copied nb_sectors, tracks, and bat_entries from the
image header without checking that the BAT actually covers the
advertised virtual disk size. An image whose header claims more
sectors than its BAT covers passes the generic block-layer bounds
check on open. A write into the gap between BAT coverage and the
advertised size then reaches allocate_clusters(), whose internal
assert(idx < s->bat_size && idx + to_allocate <= s->bat_size) aborts
the process instead of returning a normal I/O error.

Reject such images at open time by requiring
bat_size * tracks >= total_sectors, matching the invariant that
allocate_clusters() already assumes.

Reported-by: Feifan Qian <bea1e@proton.me>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3804
Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Thomas Huth <thuth@redhat.com>
CC: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 16:55:00 +02:00
Denis V. Lunev
4b620302ea parallels: avoid fatal abort on large bitmap L1 table
parallels_load_bitmap() allocated the L1 table with g_new(), which
aborts the whole process on allocation failure instead of returning
an error.

Use g_try_new() and fail the open normally.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Thomas Huth <thuth@redhat.com>
CC: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 16:42:45 +02:00
Denis V. Lunev
d5250d7ed7 parallels: skip loading a genuinely empty bitmap L1 table
parallels_load_bitmap_data() unconditionally calls
bdrv_dirty_bitmap_deserialize_finish() even when there is nothing to
deserialize, which hits an assertion in hbitmap
(hbitmap_iter_init: 'pos < hb->size') when the bitmap itself has
zero size, i.e. the disk is a zero-sector image.

Skip allocating, populating and loading the L1 table entirely when
l1_size == 0. This is safe only because the previous commit already
guarantees l1_size == 0 exclusively means the disk has 0 size.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Thomas Huth <thuth@redhat.com>
CC: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 16:42:45 +02:00
Denis V. Lunev
ac52279673 parallels: validate bitmap L1 table size before allocating it
parallels_load_bitmap() allocated the L1 table sized directly from
the untrusted l1_size field, only cross-checking it against the
bitmap's actual size after the allocation and the L1 table copy had
already happened.

Compute the expected size and reject a mismatch before touching the
allocator, instead of after.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Thomas Huth <thuth@redhat.com>
CC: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 16:42:45 +02:00
Denis V. Lunev
26c871c768 parallels: reject BAT entries pointing outside backed storage
parallels_open()'s BAT scan and parallels_check_outside_image() only
checked entries against the file's upper end, matching just half of
what docs/interop/parallels.rst requires: an entry's offset must be
both >= data_start and < the file size. An entry below data_start
resolves into the header/BAT region itself, corrupting metadata on
write or losing the write silently on a partial overlap, and neither
qemu-img check nor the open-time scan ever caught it.

Check both bounds everywhere a BAT entry is resolved to a host
offset: seek_to_sector(), the open-time scan (without letting a bad
entry inflate data_end), and parallels_check_outside_image().

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Thomas Huth <thuth@redhat.com>
CC: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 16:42:45 +02:00
Denis V. Lunev
3a1e0618ae parallels: fix bat_entries overflow in image creation
parallels_co_create() computed the BAT entry count directly into a
uint32_t, wrapping silently to zero at exactly 2^32 entries and
writing out a header whose BAT no longer matches its advertised
size. Compute it in an int64_t first and reject it once it no longer
fits, matching the cap parallels_open() already enforces. Also
reject cluster-size 0, and clamp header.cylinders instead of letting
it truncate the same way.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Thomas Huth <thuth@redhat.com>
CC: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 16:42:45 +02:00
Denis V. Lunev
af777e817a parallels: read header/BAT table in bounded chunks
parallels_open() read the whole header+BAT table with a single
bdrv_pread() call sized s->header_size. For an image whose catalog
approaches the "Catalog too large" bound (INT_MAX / sizeof(uint32_t)
entries), that size approaches BDRV_REQUEST_MAX_BYTES, and the block
layer legitimately refuses a single request that large, so the image
failed to open with a generic I/O error even though the catalog size
itself is within the format's documented limit.

Read the header and BAT table in fixed-size chunks instead, so the
maximum catalog size parallels_open() can actually address matches
the bound it already enforces, independent of the file's block-layer
alignment requirements.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Thomas Huth <thuth@redhat.com>
CC: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 16:42:45 +02:00
Stefan Hajnoczi
de5eb7c4dd Misc HW patches
- HW model fixes (network, SDHCI)
 - SPARC64 vCPU migration fix
 - PPC64 functional test fix
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEE+qvnXhKRciHc/Wuy4+MsLN6twN4FAmpoePcACgkQ4+MsLN6t
 wN4Lqw/+J1ShimJaaGRNP4CSzTIoHjO4fCdTuEtUd+x3sVjhWONmyDBMnNAoama+
 Q5o8fb6sM4LtueoFPEjlk0oAqLrGR0d9gUEqop4AWanQReXOl2C4iIiyvH9mPttm
 NvDHIpLV/c7pcxaMOrvKp8HXEy46y1K/45SatbaDAPRGt3Rw8RvyuAP8x8RjmiNN
 4+3wxHMzdMEMg+yIL0qDLeDqgqPtmVsr8dco7S8wHSvJOfrgFtML+zA9iwZ65MGr
 g8q5zgI5N+eAWSZxvRSLuhujWg8eEbj8hlkcpiLV7seSNkGYmo/kp2AyEHsuspaa
 ngZjzcygMfeg6JY276q+8Q8Oy2T3ZJdsx53irig6LlE4pWTFcpE6sCvus3w28ofU
 9DRUJjSExV77F68GULVJilTl3y3kuS/CmAymtXrrjfSOvRE+mnM8/IRkNQpXVko7
 +b2oNfTwnWyeDrd2tv686g5ggVMIig3B0GZZjELzR7CsqeiRDw0btXhKWNKtBKDQ
 Tif17dHq7iHHxFEwLOYJ2SidD274EAnW6YVsem7cPhHAYOMvYEPYQ2Smj2RNFwEL
 xA08vusJTYqexnz1d2i6kmVth6HIH0H2bqO9UnyV/dt09U+sizILqLeRYVvcyuzd
 VZEDDmlW7tRkY4Im+Txs+omdC45d1U85+KgludyKze1BaxrGA2w=
 =wLOi
 -----END PGP SIGNATURE-----

Merge tag 'hw-misc-20260728' of https://github.com/philmd/qemu into staging

Misc HW patches

- HW model fixes (network, SDHCI)
- SPARC64 vCPU migration fix
- PPC64 functional test fix

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEE+qvnXhKRciHc/Wuy4+MsLN6twN4FAmpoePcACgkQ4+MsLN6t
# wN4Lqw/+J1ShimJaaGRNP4CSzTIoHjO4fCdTuEtUd+x3sVjhWONmyDBMnNAoama+
# Q5o8fb6sM4LtueoFPEjlk0oAqLrGR0d9gUEqop4AWanQReXOl2C4iIiyvH9mPttm
# NvDHIpLV/c7pcxaMOrvKp8HXEy46y1K/45SatbaDAPRGt3Rw8RvyuAP8x8RjmiNN
# 4+3wxHMzdMEMg+yIL0qDLeDqgqPtmVsr8dco7S8wHSvJOfrgFtML+zA9iwZ65MGr
# g8q5zgI5N+eAWSZxvRSLuhujWg8eEbj8hlkcpiLV7seSNkGYmo/kp2AyEHsuspaa
# ngZjzcygMfeg6JY276q+8Q8Oy2T3ZJdsx53irig6LlE4pWTFcpE6sCvus3w28ofU
# 9DRUJjSExV77F68GULVJilTl3y3kuS/CmAymtXrrjfSOvRE+mnM8/IRkNQpXVko7
# +b2oNfTwnWyeDrd2tv686g5ggVMIig3B0GZZjELzR7CsqeiRDw0btXhKWNKtBKDQ
# Tif17dHq7iHHxFEwLOYJ2SidD274EAnW6YVsem7cPhHAYOMvYEPYQ2Smj2RNFwEL
# xA08vusJTYqexnz1d2i6kmVth6HIH0H2bqO9UnyV/dt09U+sizILqLeRYVvcyuzd
# VZEDDmlW7tRkY4Im+Txs+omdC45d1U85+KgludyKze1BaxrGA2w=
# =wLOi
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 28 Jul 2026 05:40:07 EDT
# gpg:                using RSA key FAABE75E12917221DCFD6BB2E3E32C2CDEADC0DE
# gpg: Good signature from "Philippe Mathieu-Daudé (F4BUG) <f4bug@amsat.org>" [full]
# Primary key fingerprint: FAAB E75E 1291 7221 DCFD  6BB2 E3E3 2C2C DEAD C0DE

* tag 'hw-misc-20260728' of https://github.com/philmd/qemu:
  tests/functional/ppc: skip remote interrupts test if -net user not built
  target/sparc: set reg window data structures currently after vmstate load
  hw/net/igb: recalculate rx_desc_len on migration load
  hw/net/e1000e: recalculate rx_desc_len on migration load
  hw/sd/sdhci: Extract uSDHC-specific quirk
  hw/net/xilinx_axienet: Don't write checksums off end of packet

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 10:04:08 -04:00
Stefan Hajnoczi
e3a6296ec7 linux-user patches
Enable fsmount() syscalls, fix build with Linux 7.2 kernel headers and
 allow full 32-bit address space on sh4.
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCamhzJgAKCRD3ErUQojoP
 X2WUAP9UOBDozOx0rqpDRDM1ktMQdp3zaUT+wJIyLojcNZcj8QD/aaImcmjuU4h9
 Slgtdh5qtIUJynvOemumwW442Ftd3AQ=
 =RFH+
 -----END PGP SIGNATURE-----

Merge tag 'linux-user-pull-request' of https://github.com/hdeller/qemu-hppa into staging

linux-user patches

Enable fsmount() syscalls, fix build with Linux 7.2 kernel headers and
allow full 32-bit address space on sh4.

# -----BEGIN PGP SIGNATURE-----
#
# iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCamhzJgAKCRD3ErUQojoP
# X2WUAP9UOBDozOx0rqpDRDM1ktMQdp3zaUT+wJIyLojcNZcj8QD/aaImcmjuU4h9
# Slgtdh5qtIUJynvOemumwW442Ftd3AQ=
# =RFH+
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 28 Jul 2026 05:15:18 EDT
# gpg:                using EDDSA key BCE9123E1AD29F07C049BBDEF712B510A23A0F5F
# gpg: Good signature from "Helge Deller <deller@gmx.de>" [unknown]
# gpg:                 aka "Helge Deller <deller@kernel.org>" [unknown]
# gpg:                 aka "Helge Deller <deller@debian.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 4544 8228 2CD9 10DB EF3D  25F8 3E5F 3D04 A7A2 4603
#      Subkey fingerprint: BCE9 123E 1AD2 9F07 C049  BBDE F712 B510 A23A 0F5F

* tag 'linux-user-pull-request' of https://github.com/hdeller/qemu-hppa:
  linux-user/sh4: allow full 32-bit address space
  linux-user: fix guards for the fsmount(2) syscall series
  linux-user: Guard local FUTEX_CMD_MASK definition

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-28 10:03:54 -04:00
Peter Maydell
a5f8d33682 hw/display/exynos4210_fimd: Clamp windows to screen size
In exynos4210_fimd_update(), we iterate through the enabled windows,
blitting them to the screen. We assume here that the guest has not
programmed the window's coordinates to be outside the overall LCD
screen resulation, but we never check this. This can result in the
guest being able to cause us to access outside our allocated
framebuffer backing memory.

Since all the coordinates here are unsigned, they can't be off
the left/top side of the screen, only the bottom/right. If
the top left corner of the window is out of bounds, the whole
window is invisible and we can skip it. If the bottom right
corner is out of bounds, we clamp it to the screen size so that
we only draw the visible part.

Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3795
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-id: 20260706173324.804340-4-peter.maydell@linaro.org
2026-07-28 11:38:51 +01:00
Peter Maydell
7dd1e22188 hw/display/exynos4210_fimd: Pass width to draw_line functions
The draw_line functions currently assume the width of the line they
need to draw is w->rightbot_x - w->lefttop_x + 1, i.e.  the full
width of the guest-programmed window.  We want to be able to clamp
this to the overall screen size, which we can calculate in the
calling function.

Refactor to do this calculation in the caller and pass the
width as an argument to the draw_line functions.

Stable CC because this is a prerequisite for an upcoming bugfix
commit.

Cc: qemu-stable@nongnu.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-id: 20260706173324.804340-3-peter.maydell@linaro.org
2026-07-28 11:38:51 +01:00
Peter Maydell
4f635bddf5 hw/display/exynos4210_fimd: Factor out finding screen width/height
Currently we hard-code the expressions for getting the global screen
width and height out of the VIDTCON2 register where we need them.
Use functions instead.  Make the global_width variable in
exynos4210_fimd_update() uint32_t for consistency.  (The values are
clamped to well below INT_MAX, so there is no overflow risk here.)

Stable CC because this is a prerequisite for an upcoming bugfix
commit.

Cc: qemu-stable@nongnu.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-id: 20260706173324.804340-2-peter.maydell@linaro.org
2026-07-28 11:38:51 +01:00
botszhuang
c4580a3a6d hw/i2c/bcm2835_i2c: Correct CLKT register offset
The Clock Stretch Timeout (CLKT) register for the BCM2835 I2C
controller is actually located at offset 0x1c, not 0x20.

Update the BCM2835_I2C_CLKT macro to match the hardware
specification.

Since QEMU's implementation ignores whatever value the guest
writes to this register, and Linux only writes to CLKT and
doesn't read it back, the main effect of this fix is to
avoid an incorrect GUEST_ERROR log.

Cc: qemu-stable@nongnu.org
Fixes: 9cf3bc65af ("hw/i2c: Implement Broadcom Serial Controller (BSC)")
Signed-off-by: botszhuang <botszhuang@gmail.com>
Tested-by: Nick Huang <sef1548@gmail.com>
Message-id: 20260724124220.24152-1-22925483+botszhuang@users.noreply.github.com
[PMM: removed commit message paragraph about effects which I think
 is incorrect, substituted a different one]
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Simon Xu
ccde37589f hw/misc/mps2-scc.c: fix scc_partno field width
Increase the extract32 length from 8 to 12. The Primary part number is
defined as bits[15:4] by the "SSE-310 with M85 and U55 FPGA"
documentation. For example for the mps3-an547, 0x547 is 12 bits but we
only return 8 bits right now.

Signed-off-by: Simon Xu <simonxhy0404@gmail.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260724160943.52509-3-simonxhy0404@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Simon Xu
1892a0cd43 hw/misc/mps2-scc.c: fix cfg7 write
Change the CFG7 write function to modify the correct variable. This only
affects the an536 machine currently as only it uses cfg7 to store the
core 1 vector table base address.

Signed-off-by: Simon Xu <simonxhy0404@gmail.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260724160943.52509-2-simonxhy0404@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Bin Meng
24506d7709 docs/system/arm: Update Nuvoton OpenBMC image guidance
Describe the current OpenBMC target naming and release status for
Nuvoton machines. The latest 2.18.0 release no longer includes GSJ,
so point users at older 2.14.0 sources and explain how to find
Jenkins MTD artifacts.

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Message-id: 20260627063208.33642-1-bin.meng@processmission.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Bernhard Beschow
62007626ac hw/net/can/flexcan: Remove RX SMB raw view
Use the existing `rx_smb0` message buffer view for register masks instead
of the raw register array. Since all accesses now use the structured view,
remove the redundant `rx_smb0_raw` union member.

Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Tested-by: Pavel Pisa <pisa@fel.cvut.cz>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260723070059.6332-10-shentey@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Bernhard Beschow
cf942d0268 hw/net/can/flexcan: Fix RXIMR reset mask
The RXIMR registers are not affected by soft reset, so their reset mask
must preserve all entries. Set the mask for the entire array instead of
only the first register.

Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Tested-by: Pavel Pisa <pisa@fel.cvut.cz>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260723070059.6332-9-shentey@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Bernhard Beschow
21d3af36b0 hw/net/flexcan: Drop oversized 'mb[]' mailbox view
As indicated in the comments, the `mb[]` a.k.a. `mbs []` views should
cover 0x400 (1024) bytes. However, the `mb[]` array covers four times
the size since `sizeof(FlexcanRegsMessageBuffer)` returns the size in
bytes instead of counting the number of uint32_t fields. This shifts the
subsequent register offsets by 0xc00 which is not intended. Fix the size
and thus the offsets by dropping the now unused `mb[]` view.

Note that the different size changes the migration layout. Since the device
model is new, no change in the version fields is needed.

Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Tested-by: Pavel Pisa <pisa@fel.cvut.cz>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260723070059.6332-8-shentey@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Bernhard Beschow
7f780d9d2a hw/net/can/flexcan: Fix mailbox reset mask initialization
The mailbox reset mask initialized only the first word of the raw `mb[]`
array. Fix the initialization to cover the whole mailbox, as indicated
in the field description in the header. While at it, use the `mbs[]`
view instead in order to drop the redundant and oversized `mb[]` view in
the next commit.

Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Tested-by: Pavel Pisa <pisa@fel.cvut.cz>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260723070059.6332-7-shentey@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Bernhard Beschow
8f8f86306f hw/net/can/flexcan: Fix mailbox index calculation in flexcan_mem_read()
Calculate mailbox indices from the `mbs[]` array layout instead of the
oversized raw `mb[]` view. This prevents accessing mailbox entries beyond
the valid array range and fixes Coverity CID 1662974.

Reported-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Tested-by: Pavel Pisa <pisa@fel.cvut.cz>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260723070059.6332-6-shentey@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Bernhard Beschow
9981b70ce7 hw/net/can/flexcan: Fix mailbox index calculation in flexcan_mem_write()
Calculate mailbox indices from the `mbs[]` array layout instead of the
oversized raw `mb[]` view. This prevents accessing mailbox entries beyond
the valid array range and fixes Coverity CID 1662974.

Reported-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Tested-by: Pavel Pisa <pisa@fel.cvut.cz>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260723070059.6332-5-shentey@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Bernhard Beschow
4ac969571b hw/net/can/flexcan: Fix out-of-bounds access in flexcan_mx_rx()
Require `last_not_free_to_receive_mbid >= 0` before indexing `mbs[]`.
This prevents a possible `-1` array index and fixes Coverity CID
1662790.

Reported-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Tested-by: Pavel Pisa <pisa@fel.cvut.cz>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260723070059.6332-4-shentey@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Bernhard Beschow
8af2ced638 hw/net/flexcan: Drop unused RX FIFO register overlay
Remove the unused `FlexcanRegsRXFifo` union view now that FIFO accesses
use the underlying `mbs[]` array directly.

Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Tested-by: Pavel Pisa <pisa@fel.cvut.cz>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260723070059.6332-3-shentey@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Bernhard Beschow
c4e2347693 hw/net/can/flexcan: Use mbs[] array for FIFO pop
Implement FIFO entry shifting using the underlying `mbs[]` array instead
of the overlapping `fifo` union view. This makes it explicit that the
operation copies within a contiguous mailbox array and avoids Coverity
CID 1662971.

Reported-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Tested-by: Pavel Pisa <pisa@fel.cvut.cz>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260723070059.6332-2-shentey@gmail.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:49 +01:00
Philippe Mathieu-Daudé
e5ab18130a target/arm: Build TCG stubs as stub library
Use the stub library introduced in commit 0da978cdbc ("target/arm:
define stub library") to prevent symbol conflicts.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260721122135.6288-5-philmd@oss.qualcomm.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:40 +01:00
Philippe Mathieu-Daudé
b3a977da8f target/arm: Only compile gicv5-cpuif.c when GICv5 is selected
Only compile gicv5-cpuif.c when ARM_GICV5 is Kconfig-selected,
otherwise we get when building with --without-default-devices:

  Undefined symbols for architecture arm64:
    "_gicv5_activate", referenced from:
        _gicr_cdia_read in target_arm_tcg_gicv5-cpuif.c.o
    "_gicv5_deactivate", referenced from:
        _gic_cddi_write in target_arm_tcg_gicv5-cpuif.c.o
    "_gicv5_get_hppi", referenced from:
        _gic_hppi in target_arm_tcg_gicv5-cpuif.c.o
    "_gicv5_request_config", referenced from:
        _gic_cdrcfg_write in target_arm_tcg_gicv5-cpuif.c.o
    "_gicv5_set_enabled", referenced from:
        _gic_cddis_write in target_arm_tcg_gicv5-cpuif.c.o
        _gic_cden_write in target_arm_tcg_gicv5-cpuif.c.o
    "_gicv5_set_handling", referenced from:
        _gic_cdhm_write in target_arm_tcg_gicv5-cpuif.c.o
    "_gicv5_set_pending", referenced from:
        _gic_cdpend_write in target_arm_tcg_gicv5-cpuif.c.o
    "_gicv5_set_priority", referenced from:
        _gic_cdpri_write in target_arm_tcg_gicv5-cpuif.c.o
    "_gicv5_set_target", referenced from:
        _gic_cdaff_write in target_arm_tcg_gicv5-cpuif.c.o

Fixes: ee0f1ce00d ("target/arm: GICv5 cpuif: Initial skeleton and GSB barrier insns")
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260721122135.6288-4-philmd@oss.qualcomm.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:40 +01:00
Philippe Mathieu-Daudé
48201bb01f target/arm: Add stub for define_gicv5_cpuif_regs()
The common helper.c file calls define_gicv5_cpuif_regs() which
is only defined when TCG is built:

  $ git grep -w define_gicv5_cpuif_regs
  target/arm/internals.h:1885:void define_gicv5_cpuif_regs(ARMCPU *cpu);
  target/arm/helper.c:6334:        define_gicv5_cpuif_regs(cpu);
  target/arm/tcg/gicv5-cpuif.c:923:void define_gicv5_cpuif_regs(ARMCPU *cpu)

This fixes when building on macOS with --disable-tcg:

  Undefined symbols for architecture arm64:
    "_define_gicv5_cpuif_regs", referenced from:
        _register_cp_regs_for_features in target_arm_helper.c.o

Define the GICv5 stubs in their own compilation unit, otherwise
we get the following error:

  duplicate symbol '_raise_exception_ra' in:
    libsystem_arm.a.p/target_arm_tcg_op_helper.c.o
    libstubs_arm.a[4](target_arm_tcg-stubs.c.o)

Fixes: ee0f1ce00d ("target/arm: GICv5 cpuif: Initial skeleton and GSB barrier insns")
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260721122135.6288-3-philmd@oss.qualcomm.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:40 +01:00
Philippe Mathieu-Daudé
39a8c3941e hw/intc/arm_gicv3: Fix ARM_GICV3 dependency for KVM / WHPX
KVM and WHPX GICv3 implementations call gicv3_init_irqs_and_mmio()
which is defined in arm_gicv3_common.c, itself build when ARM_GIC
is selected. Both KVM and WHPX are conditional on ARM_GICV3,
itself selecting ARM_GIC. Only build the ARM_GICV3 accelerator
variants when ARM_GICV3 is selected.

 $ git grep -w gicv3_init_irqs_and_mmio
 hw/intc/arm_gicv3_common.c:314:void gicv3_init_irqs_and_mmio(GICv3State *s,
 hw/intc/arm_gicv3.c:450:    gicv3_init_irqs_and_mmio(s, gicv3_set_irq, gic_ops);
 hw/intc/arm_gicv3_hvf.c:710:    gicv3_init_irqs_and_mmio(s, hvf_gicv3_set_irq, NULL);
 hw/intc/arm_gicv3_kvm.c:822:    gicv3_init_irqs_and_mmio(s, kvm_arm_gicv3_set_irq, NULL);
 hw/intc/arm_gicv3_whpx.c:186:    gicv3_init_irqs_and_mmio(s, whpx_gicv3_set_irq, NULL);

Fixes: a7bf30342e ("hw/intc: Initial implementation of vGICv3")
Fixes: e4c95f78a4 ("hw, target, accel: whpx: change apic_in_platform to kernel_irqchip")
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260721122135.6288-2-philmd@oss.qualcomm.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-28 11:36:40 +01:00
Laurent Vivier
db3abd36e4 linux-user/sh4: allow full 32-bit address space
On real SH4 hardware, the address space is split between user mode
(U0, 0x00000000-0x7fffffff) and kernel mode (P1-P4, 0x80000000-0xffffffff),
so TARGET_VIRT_ADDR_SPACE_BITS was set to 31 for CONFIG_USER_ONLY.

However, qemu-user does not emulate the MMU, so this limit is not needed.
The only effect is to restrict reserved_va to 2 GB, causing OOM failures
for memory-intensive builds (e.g. webkit2gtk on Debian sh4 buildds).

Set TARGET_VIRT_ADDR_SPACE_BITS to 32 unconditionally, like most other
32-bit targets. Also fix the TASK_UNMAPPED_BASE macro to use 1ull instead
of 1u to avoid undefined behavior when shifting by 32.

Reported-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Signed-off-by: Laurent Vivier <laurent@vivier.eu>
Reviewed-by: Helge Deller <deller@gmx.de>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-07-28 11:12:37 +02:00
Shivang Upadhyay
c607cca75c tests/functional/ppc: skip remote interrupts test if -net user not built
While running remote interrupts test, without libslirp-devel installed,
facing the following panic logs.

  File
    ...
    raise VMLaunchFailure(
    ...<3 lines>...
    ) from exc
    ...
        Output: qemu-system-ppc64: -netdev user,id=net0: network backend
'user' is not compiled into this binary

Adding netdev user requirement for this test.

Suggested-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Reviewed-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Suggested-by: Thomas Huth <thuth@redhat.com>
Reviewed-by: Thomas Huth <thuth@redhat.com>
Fixes: 63f5ba8092 ("tests/functional: Add remote interrupts test for PowerNV")
Signed-off-by: Shivang Upadhyay <shivangu@linux.ibm.com>
Tested-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Message-ID: <20260728074612.42397-1-shivangu@linux.ibm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-28 11:09:08 +02:00
Mark Cave-Ayland
d8813fdc4b target/sparc: set reg window data structures currently after vmstate load
In the SPARC CPU state, env->regwptr points into the env->regbase
array at wherever the architectural CWP (current window pointer) says
we are in the register windows.  We don't migrate this directly,
since it's a host pointer, so we must ensure it is set up again
after migration load.

We also have to deal with a special case when CWP is (nwindows - 1).
In this case, while running we keep the "in" register data for this
window in a temporary location at the end of the regbase[] array, so
that generated code doesn't have to special case this "wrap around"
case.  In cpu_pre_save() we call cpu_set_cwp() to force a copy of the
wrapped data from its temporary location into the architectural
location in window 0's "out" registers.  We then migrate only
(nwindows * 16) entries in the regbase[] array.  So on the
destination we need to copy the "in" register data back to its
temporary location again.

For 32-bit SPARC we get this right, because the CWP is in the PSR.
The get_psr() function does:
     env->cwp = 0;
     cpu_put_psr_raw(env, val);
which causes cpu_put_psr_raw() to call cpu_set_cwp() in a way that
sets up both regwptr and the wrapped-register data.

However, for 64-bit SPARC the CWP is not in the PSR, and
cpu_put_psr_raw() will not call cpu_set_cwp().  This leaves the guest
register state in a corrupted state, and the guest will likely crash
on the destination if it didn't happen to be executing with CWP == 0.

Fix this by adding a custom vmstate_cwp VMStateInfo with corresponding
get_cwp() and put_cwp() helpers which does the same for the 64-bit
case.

Cc: qemu-stable@nongnu.org
Signed-off-by: Mark Cave-Ayland <mark.cave-ayland@ilande.co.uk>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260725123411.993099-1-mark.cave-ayland@ilande.co.uk>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-28 11:09:08 +02:00
Laurent Vivier
1e5efe6d93 hw/net/igb: recalculate rx_desc_len on migration load
rx_desc_len is migrated as a raw uint8_t from the stream but is a
derived value. Currently igb_rx_use_legacy_descriptor() is a stub
that always returns false, so rx_desc_len is always set to
sizeof(union e1000_adv_rx_desc). Recalculate it in post_load to
prevent a crafted migration stream from setting an invalid value.

Cc: qemu-stable@nongnu.org
Signed-off-by: Laurent Vivier <lvivier@redhat.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Message-ID: <20260722112449.1386162-3-lvivier@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-28 11:09:03 +02:00
Laurent Vivier
b395a655ae hw/net/e1000e: recalculate rx_desc_len on migration load
rx_desc_len is migrated as a raw uint8_t from the stream, but it
is a derived value that can be computed from the register state
in core.mac[RFCTL] and core.mac[RCTL]. A crafted migration stream
can set rx_desc_len to an invalid value (e.g. 64), causing a stack
buffer overflow in e1000e_write_packet_to_guest() which copies
rx_desc_len bytes into a 32-byte stack union.

Recalculate rx_desc_len and other derived values from the register
state in post_load, ignoring the untrusted values from the stream.

Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3869
Signed-off-by: Laurent Vivier <lvivier@redhat.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Message-ID: <20260722112449.1386162-2-lvivier@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-28 11:09:03 +02:00
Bernhard Beschow
11ed6b9213 hw/sd/sdhci: Extract uSDHC-specific quirk
In Linux, the ESDHC_MIX_CTRL quirk is guarded by esdhc_is_usdhc() while
the eSDHC code path uses the standard SDHC interface. Extract the quirk
into a new `usdhc_write()` function.

Fixes file system corruption on emulated i.MX53 where Linux'
esdhc_is_usdhc() returns false. The same likely happens on e500 and
imx25-pdk machines.

Cc: qemu-stable@nongnu.org
Fixes: 75e98bc4f8 ("hw/sd/sdhci: Add TYPE_FSL_ESDHC_BE")
Reviewed-by: Bin Meng <bin.meng@processmission.com>
Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Message-ID: <20260720201133.24796-3-shentey@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-28 11:08:52 +02:00
Matt Turner
aba80ad9d8 linux-user: fix guards for the fsmount(2) syscall series
The fsopen(), fsconfig(), fsmount() and fspick() implementations are
guarded by defined(NR_fsopen) rather than defined(__NR_fsopen). No such
macro exists, so the guard is never true and the entire series compiles
out. Guests calling any of the four get -ENOSYS, which for example makes
systemd's credential setup fail with EXIT_CREDENTIALS for most units.

The strace bits for fsconfig() have the same typo.

Check if FSCONFIG_SET_FLAG is defined to avoid build errors in the strace
code on some older distributions (Helge).

Fixes: 767c32fe69 ("linux-user: implement fsmount(2) series of syscalls")
Fixes: 6e0aa9f6c7 ("linux-user/strace: add fsmount series of syscalls")
Signed-off-by: Matt Turner <mattst88@gmail.com>
Reviewed-by: Helge Deller <deller@gmx.de>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-07-28 11:06:15 +02:00
Peter Maydell
8cbcf75793 hw/net/xilinx_axienet: Don't write checksums off end of packet
The xilinx_axienet device has ethernet checksum offloading, with a
mode where the guest provides the offsets within the packet where
the data to be checksummed starts, and where the final checksum
should be written into the packet.

We don't sanity check the TX_CSINSERT offset before writing the
checksum data into it, which means the guest can pass us a value that
is larger than the packet itself and cause us to write the checksum
off the end of the buffer.  We also don't explicitly check the
TX_CSBEGIN offset; this doesn't currently cause any problems because
we will pass a negative length to net_checksum_add() which does
nothing, but it's a potential trap for the future if the type
used for the length gets changed to be unsigned.

Explicitly check the offsets.  The datasheet doesn't say what happens
if the guest misprograms this, so we choose to log an error and send
the packet as-is.

Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3599
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260706162704.787495-1-peter.maydell@linaro.org>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-28 10:27:28 +02:00
Stefan Hajnoczi
299e7557ed pci, vhost, virtio, iommu: bugfixes
Fixes all over the place, including a bunch of CVE fixes.
 
 Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
 -----BEGIN PGP SIGNATURE-----
 
 iQFDBAABCgAtFiEEXQn9CHHI+FuUyooNKB8NuNKNVGkFAmpnrsMPHG1zdEByZWRo
 YXQuY29tAAoJECgfDbjSjVRpRkkIAMbp882suVq4uqhYOJFCvu0pNzKyjqQRyPHk
 L+YFuKhVYoEF0Ssw9pcmq1AFT/1LzCz7DlrG1h8glxaBQ3UUyLylZWlPyDNZWUzs
 YrclY51iB4aHJm3uMmNlF82DR22BsS8DZmft65a7Xt76Z7LzhNboxW6jz2eeqWka
 /rc/0p9rymk0WOlXMwQANk3JQ9WizrYS+DBeYdbtTpHxPahZ+6napbrDQ3FS7lp8
 Ne06JjapYKZVE0XSkP4JMFRN5261NGrcS8PfCzrzdDnD7xfdnUMrYB3eqm3ZfO4D
 ZGpDloCSqblsiSXV9w9r84iStMY7EX3gnBMeUoZMTgs0erIZYdI=
 =tYYk
 -----END PGP SIGNATURE-----

Merge tag 'for_upstream' of https://git.kernel.org/pub/scm/virt/kvm/mst/qemu into staging

pci, vhost, virtio, iommu: bugfixes

Fixes all over the place, including a bunch of CVE fixes.

Signed-off-by: Michael S. Tsirkin <mst@redhat.com>

# -----BEGIN PGP SIGNATURE-----
#
# iQFDBAABCgAtFiEEXQn9CHHI+FuUyooNKB8NuNKNVGkFAmpnrsMPHG1zdEByZWRo
# YXQuY29tAAoJECgfDbjSjVRpRkkIAMbp882suVq4uqhYOJFCvu0pNzKyjqQRyPHk
# L+YFuKhVYoEF0Ssw9pcmq1AFT/1LzCz7DlrG1h8glxaBQ3UUyLylZWlPyDNZWUzs
# YrclY51iB4aHJm3uMmNlF82DR22BsS8DZmft65a7Xt76Z7LzhNboxW6jz2eeqWka
# /rc/0p9rymk0WOlXMwQANk3JQ9WizrYS+DBeYdbtTpHxPahZ+6napbrDQ3FS7lp8
# Ne06JjapYKZVE0XSkP4JMFRN5261NGrcS8PfCzrzdDnD7xfdnUMrYB3eqm3ZfO4D
# ZGpDloCSqblsiSXV9w9r84iStMY7EX3gnBMeUoZMTgs0erIZYdI=
# =tYYk
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 27 Jul 2026 15:17:23 EDT
# gpg:                using RSA key 5D09FD0871C8F85B94CA8A0D281F0DB8D28D5469
# gpg:                issuer "mst@redhat.com"
# gpg: Good signature from "Michael S. Tsirkin <mst@kernel.org>" [full]
# gpg:                 aka "Michael S. Tsirkin <mst@redhat.com>" [full]
# Primary key fingerprint: 0270 606B 6F3C DF3D 0B17  0970 C350 3912 AFBE 8E67
#      Subkey fingerprint: 5D09 FD08 71C8 F85B 94CA  8A0D 281F 0DB8 D28D 5469

* tag 'for_upstream' of https://git.kernel.org/pub/scm/virt/kvm/mst/qemu: (30 commits)
  virtio: avoid packed vring virtio_queue_empty() infinite loops (CVE-2026-16457)
  backends/rng: cap request size to avoid oversized allocation
  hw/virtio-rng: Fix host use-after-free (CVE-2026-50624)
  hw/net/virtio-net: Protect from DMA re-entrancy bugs
  intel_iommu: Check address mask before using it in pasid-based iotlb invalidation
  hw/cxl: fix OOB access in cxl_doe_cdat_rsp via entry_handle
  hw/virtio/vdpa-dev: pass set_config buffer to vhost backend
  hw/pci-host/q35.c: Avoid early return in mch_write_config()
  hw/pci-host/q35.c: Factor out creation of SMRAM MRs
  hw/pci-host/q35.c: Always initialize smram-region even if SMM disabled
  virtio-snd: check for overflow before g_malloc0
  virtio-snd: check rx buffer descriptor size
  virtio-iommu: fix OOM due to unbounded call_rcu
  libvduse: validate vq size
  libvhost-user: fix heap overflow in vu_check_queue_inflights
  libvhost-user: validate last_batch_head in vu_check_queue_inflights
  virtio-pmem: wait for flush requests on unrealize
  vhost-user: assert nregions within limit
  virtio: fail early on bad config_len in migration
  virtio: stop migrating num_default, validate vring.num on load
  ...

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-27 16:51:28 -04:00
Stefan Hajnoczi
0046be6e04 * Validate bounds in CXL "Set Feature" payloads
* Fix guest-triggerable heap OOB access in "usb-uas" device
 * Fix possible crash via NULL pointer in ide_cancel_dma_sync()
 * Avoid possible assert() usb_packet_copy()
 * Check return value of xhci_xfer_create_sgl() for errors
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEJ7iIR+7gJQEY8+q5LtnXdP5wLbUFAmpnVAMACgkQLtnXdP5w
 LbXM1Q/+J7zxVdGniadV0FpTn4ZalaIFmJCenoC1fqbwy2ygf3lupuOKPlkEUl+/
 NHc6LnXMZ3+/+L1FQENVgConAZnb0CLJ/l/3zhlvIShPvWkPpgWFzUFO3fGkwc1G
 RppCNRO280tLbNTFqSc57YXyqbmzG/A4N6+bGMb6sbZYrWAwuiIXDgt9TA1XM7S+
 9Yqh+qcJ6/aFm1HUY82+cF6Kf+NFpMDI/Q7R23WpgrjAAuw/0R07PQSfyVHKe0HK
 NP7lw/xuQWvhcOHLMF3RZaQTZGekTEXK56CGvcrh0RcyPXVOYSBBtHVY7VRvEM0K
 Vjnp6vuFWKz/Mk1z2HFu+VL91PhN7FmT/vJHylkBt1UItz2M+XwfPlzAGUUobyr+
 sCrm0Cf1lIkMUOBzT1zJcvhZ1bFtk0e4YszkWVlk5ymvbov3+laiveNBJbMHz1qt
 3QAqaiSfLnVjunQh4XRta6QVeZBO3DD1QYpT+LcsQX4GJMKqfBilyJiz1tAJsQ3i
 sZtbSMUR5HY8geGHz2VGi5Sa3ZW9dyHbFY2p99DL7l1WobJr8CIMGzxUqrsly55C
 lXeYZPjAfSnShv6SYq1kUeJ2c3otL+ti9Wq22lZzJ00Jv0LeXzgx5SMH6Dz6+KMq
 QGnFo9wEMihMWcgXwJu3sEyqiguNPHTYgZKWOHMHnfdHL19TnqU=
 =wtEN
 -----END PGP SIGNATURE-----

Merge tag 'pull-request-2026-07-27' of https://gitlab.com/thuth/qemu into staging

* Validate bounds in CXL "Set Feature" payloads
* Fix guest-triggerable heap OOB access in "usb-uas" device
* Fix possible crash via NULL pointer in ide_cancel_dma_sync()
* Avoid possible assert() usb_packet_copy()
* Check return value of xhci_xfer_create_sgl() for errors

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEJ7iIR+7gJQEY8+q5LtnXdP5wLbUFAmpnVAMACgkQLtnXdP5w
# LbXM1Q/+J7zxVdGniadV0FpTn4ZalaIFmJCenoC1fqbwy2ygf3lupuOKPlkEUl+/
# NHc6LnXMZ3+/+L1FQENVgConAZnb0CLJ/l/3zhlvIShPvWkPpgWFzUFO3fGkwc1G
# RppCNRO280tLbNTFqSc57YXyqbmzG/A4N6+bGMb6sbZYrWAwuiIXDgt9TA1XM7S+
# 9Yqh+qcJ6/aFm1HUY82+cF6Kf+NFpMDI/Q7R23WpgrjAAuw/0R07PQSfyVHKe0HK
# NP7lw/xuQWvhcOHLMF3RZaQTZGekTEXK56CGvcrh0RcyPXVOYSBBtHVY7VRvEM0K
# Vjnp6vuFWKz/Mk1z2HFu+VL91PhN7FmT/vJHylkBt1UItz2M+XwfPlzAGUUobyr+
# sCrm0Cf1lIkMUOBzT1zJcvhZ1bFtk0e4YszkWVlk5ymvbov3+laiveNBJbMHz1qt
# 3QAqaiSfLnVjunQh4XRta6QVeZBO3DD1QYpT+LcsQX4GJMKqfBilyJiz1tAJsQ3i
# sZtbSMUR5HY8geGHz2VGi5Sa3ZW9dyHbFY2p99DL7l1WobJr8CIMGzxUqrsly55C
# lXeYZPjAfSnShv6SYq1kUeJ2c3otL+ti9Wq22lZzJ00Jv0LeXzgx5SMH6Dz6+KMq
# QGnFo9wEMihMWcgXwJu3sEyqiguNPHTYgZKWOHMHnfdHL19TnqU=
# =wtEN
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 27 Jul 2026 08:50:11 EDT
# gpg:                using RSA key 27B88847EEE0250118F3EAB92ED9D774FE702DB5
# gpg: Good signature from "Thomas Huth <th.huth@gmx.de>" [full]
# gpg:                 aka "Thomas Huth <thuth@redhat.com>" [full]
# gpg:                 aka "Thomas Huth <huth@tuxfamily.org>" [full]
# gpg:                 aka "Thomas Huth <th.huth@posteo.de>" [full]
# gpg:                 aka "Thomas Huth <th.huth@posteo.eu>" [full]
# Primary key fingerprint: 27B8 8847 EEE0 2501 18F3  EAB9 2ED9 D774 FE70 2DB5

* tag 'pull-request-2026-07-27' of https://gitlab.com/thuth/qemu:
  hw/usb/hcd-xhci: Check return value of xhci_xfer_create_sgl() for errors
  hw/usb/core: Avoid possible assert() in do_parameter() --> usb_packet_copy()
  hw/ide/core: Fix possible crash via NULL pointer in ide_cancel_dma_sync()
  hw/usb/dev-uas: Fix guest-triggerable heap OOB access
  hw/cxl: Validate Set Feature payload bounds

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-27 16:51:16 -04:00
Stefan Hajnoczi
0ae6e3a207 Fixes for 11.1-rc2
To: qemu-devel@nongnu.org
 Cc: Stefan Hajnoczi <stefanha@redhat.com>
 Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmpnRicACgkQ2ujhCXWW
 nOXZBQ//QU9T9pFCTYthaXOWgdijcwnq1RZGJ2C+u/jf6w1raKWdWnSdyYmJvAwT
 bbraLOE34dLatvmcNWdUBDpTlVm2KOTUrCnDfh2c3XM4P25owTA8edmfy7LFaVew
 EYQJCW41+3ew3eYKvjKnoNXgbcCo2LCfPfU6+cd5im6jMWidC468dgTXBjgWHcOq
 sKnnSS6ML8OhwY7T0sPcqjGdgWUdNezx719zh1tG8g0Lr4ZqXxavIsBazfCOIsD9
 n6kit18MHZRkwE5A7pH45NLg0DKG2+tZu4OxHTAO/Z/FEswI4ALnrK1vJteG7emu
 uq7nLXzFQuBEjqsJnXJ5jwJGXW7ZfAO6IBvBYqvsgCln9EdxdzNcYMsK3lgV1Bi0
 qodVwK4oadrh7V0GGxTO0xkiLQkOzrCAPsNicDaFpAOPYMhahQyp6F60V5ua6bPS
 XovncfnzhXzjD7BED4Bu3yCi+8rbSiEa4YYJPrRNNh2tK9460VIB0xwBrEQtuJFF
 rrAe39WKlzYtXzbEG2+mwvgKebqYF6heluT5eJ6FiGNEXrrKvK6KD9OX/0J3EMLp
 Ni5xO4wWSQ63IpDVLvUNxoGBvNh0UtDZOXBAzm1S+LsoPBHu35i0uYJtS4d22EVI
 SEqARDKBn6hRq2NUxW8ZMMuDCkH2uQyUHnIGgKLSW5N9+nNj97s=
 =YIXw
 -----END PGP SIGNATURE-----

Merge tag 'fix-pr-v1' of https://gitlab.com/marcandre.lureau/qemu into staging

Fixes for 11.1-rc2

To: qemu-devel@nongnu.org
Cc: Stefan Hajnoczi <stefanha@redhat.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmpnRicACgkQ2ujhCXWW
# nOXZBQ//QU9T9pFCTYthaXOWgdijcwnq1RZGJ2C+u/jf6w1raKWdWnSdyYmJvAwT
# bbraLOE34dLatvmcNWdUBDpTlVm2KOTUrCnDfh2c3XM4P25owTA8edmfy7LFaVew
# EYQJCW41+3ew3eYKvjKnoNXgbcCo2LCfPfU6+cd5im6jMWidC468dgTXBjgWHcOq
# sKnnSS6ML8OhwY7T0sPcqjGdgWUdNezx719zh1tG8g0Lr4ZqXxavIsBazfCOIsD9
# n6kit18MHZRkwE5A7pH45NLg0DKG2+tZu4OxHTAO/Z/FEswI4ALnrK1vJteG7emu
# uq7nLXzFQuBEjqsJnXJ5jwJGXW7ZfAO6IBvBYqvsgCln9EdxdzNcYMsK3lgV1Bi0
# qodVwK4oadrh7V0GGxTO0xkiLQkOzrCAPsNicDaFpAOPYMhahQyp6F60V5ua6bPS
# XovncfnzhXzjD7BED4Bu3yCi+8rbSiEa4YYJPrRNNh2tK9460VIB0xwBrEQtuJFF
# rrAe39WKlzYtXzbEG2+mwvgKebqYF6heluT5eJ6FiGNEXrrKvK6KD9OX/0J3EMLp
# Ni5xO4wWSQ63IpDVLvUNxoGBvNh0UtDZOXBAzm1S+LsoPBHu35i0uYJtS4d22EVI
# SEqARDKBn6hRq2NUxW8ZMMuDCkH2uQyUHnIGgKLSW5N9+nNj97s=
# =YIXw
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 27 Jul 2026 07:51:03 EDT
# gpg:                using RSA key 87A9BD933F87C606D276F62DDAE8E10975969CE5
# gpg: Good signature from "Marc-André Lureau <marcandre.lureau@redhat.com>" [full]
# gpg:                 aka "Marc-André Lureau <marcandre.lureau@gmail.com>" [full]
# Primary key fingerprint: 87A9 BD93 3F87 C606 D276  F62D DAE8 E109 7596 9CE5

* tag 'fix-pr-v1' of https://gitlab.com/marcandre.lureau/qemu: (23 commits)
  migration/rdma: annotate and simplify wait_comp_channel()
  hw/9pfs: annotate V9fsTransport callbacks as coroutine_fn
  qcow2: remove invalid qcow2_check_refcounts calls
  block: add missing coroutine annotation
  io: add missing coroutine annotation
  migration: fix qemu_get_counted_string annotation
  monitor: annotate monitor_qmp_dispatcher_pop_any() as coroutine
  block/blkio: fix compiler false-positive warning
  hw/hexagon: fix machine->fdt leak in qom-test
  hw/cxl: fix invalid free on early return
  hw/display/virtio-gpu-rutabaga: zero-init capset info response
  hw/display/virtio-gpu: Block Rutabaga migration
  hw/display/virtio-gpu: Avoid leaking migration blocker
  hw/display/virtio-gpu: Initialize blob mapping for ATTACH_BACKING
  hw/display/virtio-gpu: Fix empty blob discrimination
  docs/hyperv: fix misleading hv-crash shutdown description
  virtio-gpu: fix NULL deref in rutabaga set_scanout
  target/i386/sev: fix MemoryRegion reference leaks in gpa2hva callers
  net/colo: fix g_hash_table_destroy assertion on uninitialized filter
  hw/display/qxl: unregister vm_change_state handler and BHs
  ...

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-27 16:51:04 -04:00
Stefan Hajnoczi
2901cf47f2 aspeed queue:
* Fix remaining hostname-specific login prompts in functional tests
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEoPZlSPBIlev+awtgUaNDx8/77KEFAmpm7h8ACgkQUaNDx8/7
 7KFgTQ/+NpDx4+MCDx76b6LSiQjX/lIOjpKsMd7+ZdGV9qJmF4AoLTcXp3P1seWj
 VzVzUi79acG3Xi7ozrtf+dIIYDh/uLtFpRewDiigvL0R2XkLSD4vIMxw3xkm74hi
 25P0jNL3kOqz5fdFepRE6spDQtrP3sBPEFK6RYO+AT/L0wBuEnWDhUqoHpwXMZya
 OeBIm3EW2X400SWiTkW1KJPlvJJXiIrYkIjz40RRninocHEy8zWqlYwOSKnUAsNB
 gsdljUQnxH1wbl0pG7LHshz/RvTPVX0UC9ZR3zO3UOfdtA5yRfBZVVzon0QpzlWS
 4Bjf6fV1KS5fOh38Zd5hcYNIVNbbemnuF8fLj4BYYmATtKhPvSZxqI5IL8RdVjBJ
 bAOI6cmZ0l0bWDWoBuzHa8zvyevvnEzz/R6ndHnG/AsmWCVUiWlE4BZmJ09YYoOU
 9lOo1yjNvKf4L1I567FavKMjXuckkVoBA2mOfr7Sl6ccJ3DmxYpRx19/ur+n+Lwk
 0d5UCjoLXXgTz//XtvB7CkpmR6Z7WiIs+L7XzwAT0lVMmnkSMdBA2jAPdIdvNu6/
 XuAepDpFq24U9kezWFnYKjXDSEPel8+skWLtvOFKH1tAOz3RQfNOIsi21IwJcn09
 C3Fq5HkKRZHm2zF+5IV7pV8s7LkE+o3lB2w1+iY0BPIFesagCY0=
 =xH2q
 -----END PGP SIGNATURE-----

Merge tag 'pull-aspeed-20260727' of https://github.com/legoater/qemu into staging

aspeed queue:

* Fix remaining hostname-specific login prompts in functional tests

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEEoPZlSPBIlev+awtgUaNDx8/77KEFAmpm7h8ACgkQUaNDx8/7
# 7KFgTQ/+NpDx4+MCDx76b6LSiQjX/lIOjpKsMd7+ZdGV9qJmF4AoLTcXp3P1seWj
# VzVzUi79acG3Xi7ozrtf+dIIYDh/uLtFpRewDiigvL0R2XkLSD4vIMxw3xkm74hi
# 25P0jNL3kOqz5fdFepRE6spDQtrP3sBPEFK6RYO+AT/L0wBuEnWDhUqoHpwXMZya
# OeBIm3EW2X400SWiTkW1KJPlvJJXiIrYkIjz40RRninocHEy8zWqlYwOSKnUAsNB
# gsdljUQnxH1wbl0pG7LHshz/RvTPVX0UC9ZR3zO3UOfdtA5yRfBZVVzon0QpzlWS
# 4Bjf6fV1KS5fOh38Zd5hcYNIVNbbemnuF8fLj4BYYmATtKhPvSZxqI5IL8RdVjBJ
# bAOI6cmZ0l0bWDWoBuzHa8zvyevvnEzz/R6ndHnG/AsmWCVUiWlE4BZmJ09YYoOU
# 9lOo1yjNvKf4L1I567FavKMjXuckkVoBA2mOfr7Sl6ccJ3DmxYpRx19/ur+n+Lwk
# 0d5UCjoLXXgTz//XtvB7CkpmR6Z7WiIs+L7XzwAT0lVMmnkSMdBA2jAPdIdvNu6/
# XuAepDpFq24U9kezWFnYKjXDSEPel8+skWLtvOFKH1tAOz3RQfNOIsi21IwJcn09
# C3Fq5HkKRZHm2zF+5IV7pV8s7LkE+o3lB2w1+iY0BPIFesagCY0=
# =xH2q
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 27 Jul 2026 01:35:27 EDT
# gpg:                using RSA key A0F66548F04895EBFE6B0B6051A343C7CFFBECA1
# gpg: Good signature from "Cédric Le Goater <clg@redhat.com>" [full]
# gpg:                 aka "Cédric Le Goater <clg@kaod.org>" [full]
# Primary key fingerprint: A0F6 6548 F048 95EB FE6B  0B60 51A3 43C7 CFFB ECA1

* tag 'pull-aspeed-20260727' of https://github.com/legoater/qemu:
  tests/functional/aspeed: Fix remaining hostname-specific login prompts

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-27 16:50:52 -04:00
Stefan Hajnoczi
6682ea3391 virtio: avoid packed vring virtio_queue_empty() infinite loops (CVE-2026-16457)
Virtqueue handler functions in device emulation code often look
something like this:

  while (!virtio_queue_empty(vq)) {
      ...pop and process virtqueue element...
  }

virtio-blk, virtio-scsi, virtio-crypto, and vhost-shadow-virtqueue use
this pattern.

The device may break (i.e. hit an error that requires device reset)
during the loop. virtio_queue_empty() returns 1 for broken split vrings
but not for broken packed vrings, leading to an infinite loop.

Adjust the packed vring behavior to match split vrings and avoid
infinite loops.

Fixes: CVE-2026-16457
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3968
Reported-by: Anatol Belski <anbelski@linux.microsoft.com>
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260721134424.196337-1-stefanha@redhat.com>
2026-07-27 15:14:16 -04:00
Laurent Vivier
70074cc48f backends/rng: cap request size to avoid oversized allocation
rng_backend_request_entropy() uses the requested size to allocate
a buffer with g_malloc(). With virtio-rng, this size comes from
guest-supplied descriptor lengths. A malicious guest can set a very
large descriptor length, causing QEMU to attempt a multi-gigabyte
allocation and abort.

Cap the allocation to 64 KiB. The virtio-rng queue size is
hardcoded to 8 entries, the EGD backend protocol limits requests
to 255 bytes, the Linux kernel hwrng framework requests at most
SMP_CACHE_BYTES per call (64 bytes on x86_64), and the Windows
viorng driver uses a 4 KiB buffer. The worst legitimate case is
8 x 4 KiB = 32 KiB, so 64 KiB is well above any legitimate use.

Fixes: 1441703965 ("virtio-rng: use virtqueue_get_avail_bytes, fix migration")
Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3983
Reported-by: dong ling <dongling226655@outlook.com>
Signed-off-by: Laurent Vivier <lvivier@redhat.com>
Reviewed-by: Thomas Huth <thuth@redhat.com>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260715141300.2295392-1-lvivier@redhat.com>
2026-07-27 15:14:13 -04:00
Laurent Vivier
0be94d8d9c hw/virtio-rng: Fix host use-after-free (CVE-2026-50624)
Fix a heap-use-after-free in the virtio-rng frontend when a delayed
rng-random backend completion arrives after the virtio-rng device has been
hot-unplugged.

Fixes: CVE-2026-50624
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3917
Reported-by: Jia Jia <physicalmtea@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Laurent Vivier <lvivier@redhat.com>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260724094931.3005968-1-lvivier@redhat.com>
2026-07-27 15:14:13 -04:00
Laurent Vivier
df12999cc8 hw/net/virtio-net: Protect from DMA re-entrancy bugs
Replace qemu_bh_new_guarded() by virtio_bh_new_guarded()
so the bus and device use the same guard. Otherwise the
DMA-reentrancy protection can be bypassed.

This update was missing in CVE-2024-3446 fix.

Fixes: CVE-2026-66022
Cc: qemu-stable@nongnu.org
Cc: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Cc: alxndr@bu.edu
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4073
Reported-by: Giovanni Vignone <gio@octane.security>
Signed-off-by: Laurent Vivier <lvivier@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260723233555.2970619-1-lvivier@redhat.com>
2026-07-27 15:14:10 -04:00
Clément MATHIEU--DRIF
0691bb257a intel_iommu: Check address mask before using it in pasid-based iotlb invalidation
Prevent a buggy driver to execute malformed invalidation operations.

Add the same assert as in vtd_iotlb_page_invalidate.

Link: https://gitlab.com/qemu-project/qemu/-/work_items/3619
Fixes: 6ebe6cf2a0 ("intel_iommu: Process PASID-based iotlb invalidation")
Reported-by: huntr bubble <bubblehuntr@gmail.com>
Signed-off-by: Clement Mathieu--Drif <clement.mathieu--drif@bull.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260724111424.376680-1-clement.mathieu--drif@bull.com>
2026-07-27 15:13:53 -04:00
Haotian Jiang
292902ae4e hw/cxl: fix OOB access in cxl_doe_cdat_rsp via entry_handle
cxl_doe_cdat_rsp() takes ent = req->entry_handle (uint16_t, fully
guest-controlled, 0..0xFFFF) and directly indexes cdat->entry[ent]
without checking ent < cdat->entry_len. For a default cxl-type3 with
one volatile memory region, entry_len = 1 + CT3_CDAT_NUM_ENTRIES = 7,
so any entry_handle >= 7 reads past the CDATEntry array into host heap.

The OOB-read base/length are then used in
memcpy(read_mbox + offset, base, len) at cxl_type3.c:298-299, leaking
host heap memory to the guest via PCI_EXP_DOE_RD_DATA_MBOX, and
potentially overflowing the 1 MiB read_mbox heap buffer when the OOB
length field is large.

The same bug exists in the cxl-upstream implementation.

Existing checks do not bound ent: assert(cdat->entry_len) only ensures
the table is loaded; the minimum-length check only guards against a
truncated CDATReq; the entry_handle ternary at line 293 only decides
the next-handle echo, not the current access; pcie_doe_get_obj_len
reads header.length, not entry_handle.

Reproduce: build QEMU with CONFIG_CXL, boot
  -M q35,cxl=on -device pxb-cxl,bus_nr=52 ... -device cxl-type3,...
then send a CDATReq with entry_handle=0xFFFF via the DOE mailbox at
config offset 0x190. Under ASAN this reports SEGV in cxl_doe_cdat_rsp
at cxl_type3.c:281.

Fixes: f5ee7413d5 ("hw/mem/cxl-type3: Add CXL CDAT Data Object Exchange")
Fixes: 882877fc35 ("hw/pci-bridge/cxl-upstream: Add a CDAT table access DOE")
Signed-off-by: Haotian Jiang <jianghaotian.sunday@gmail.com>
Cc: qemu-stable@nongnu.org
Reviewed-by: Jonathan Cameron <jic23@kernel.org>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260713072336.623604-2-jianghaotian.sunday@gmail.com>
2026-07-27 15:13:53 -04:00
GuoHan Zhao
421f45d03f hw/virtio/vdpa-dev: pass set_config buffer to vhost backend
vhost_vdpa_device_set_config() receives the updated config buffer, but
forwards s->config to the vhost backend. Since s->config is refreshed by
get_config(), it may contain stale backend state.

Pass the supplied config buffer to vhost_dev_set_config() instead.

Fixes: b430a2bd23 ("vdpa: add vdpa-dev support")
Signed-off-by: GuoHan Zhao <zhaoguohan@kylinos.cn>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260709073225.2341642-1-zhaoguohan@kylinos.cn>
2026-07-27 15:13:53 -04:00
Peter Maydell
e07c67584c hw/pci-host/q35.c: Avoid early return in mch_write_config()
In mch_write_config() we return early if has_smm_ranges is false.
This is slightly bug-prone because it leaves the door open to somebody
later adding non-SMM-specific code at the bottom of the function.

This case isn't as bad as the one in realize, because the function is
a lot shorter.  But putting the handling of the three SMM specific
ranges into an if() rather than having an early return seems better.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Michael Tokarev <mjt@tls.msk.ru>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260708121011.1653365-4-peter.maydell@linaro.org>
2026-07-27 15:13:53 -04:00
Peter Maydell
a90fcf0080 hw/pci-host/q35.c: Factor out creation of SMRAM MRs
mch_realize has a large section that deals with initializing the
SMRAM-specific MemoryRegions.  Currently we do an early return from
the realize function if mch->has_smm_ranges is false, but this has
the potential for bugs if somebody adds new code at the end of the
function that isn't SMM-specific.  Pull the MR init code out into its
own function, so we can do the smm-ranges specific handling in the
realize function in a more obvious way.

This commit shouldn't change behaviour at all.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Michael Tokarev <mjt@tls.msk.ru>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260708121011.1653365-3-peter.maydell@linaro.org>
2026-07-27 15:13:53 -04:00
Peter Maydell
7ea56dcc94 hw/pci-host/q35.c: Always initialize smram-region even if SMM disabled
The MCHPCIState::smram_region looks like it ought to be SMM-specific,
but it isn't, because its behaviour is "alias the PCI address space
into system memory at the SMRAM_C_BASE offset", and it must be
enabled for "hide SMRAM", and disabled for "show SMRAM".  If the
SMRAM regions are disabled, we want "hide SMRAM", so we need to
initialize and place this MR.  Do this in the minimal way, by moving
the "bail out of realize if has_smm_ranges is false" check down below
the initialization code.

This fixes a bug where disabling SMM causes the VGA screen to be
blank during seabios output, until the OS graphics driver is
initialized.  This is most obvious for accelerators which have no SMM
support (e.g.  NVMM, HVF, WHPX) as there smm=off is the default, but
you can also see it on KVM and TCG if you explicitly pass smm=off:
 qemu-system-x86_64 -machine q35,accel=kvm,smm=off

The early return is bug-prone, so we can refactor the code to clean
it up, but this is the minimal bug fix for backports, and is what
Debian used to work around this:
 6e0766f0f8

Another proposed fix for this:
 https://patchew.org/QEMU/20260413170407.57574-1-mohamed@unpredictable.fr/
also moves an early return in mch_update-smram() and tweaks
mch_update_smram() accordingly.  This shouldn't be necessary, because
in the no-SMM case smram_region should always be enabled and we don't
want to allow the guest to make it disabled.

NetBSD bug: https://gnats.NetBSD.org/59721

Cc: qemu-stable@nongnu.org
Fixes: b07bf7b7 ("q35: Introduce smm_ranges property for q35-pci-host")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/2608
Reported-by: Kroese (gitlab @kroese)
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260708121011.1653365-2-peter.maydell@linaro.org>
2026-07-27 15:13:38 -04:00
Manos Pitsidianakis
fa9c0c9f71 virtio-snd: check for overflow before g_malloc0
Coverity points out one g_malloc0 overflow, but it seems to be a false
positive. Add a check to it regardless to fortify the code, and also add
checks for every other g_malloc0 use.

Resolves: Coverity CID 1547527
Signed-off-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260420-virtio-fixups-v3-2-07aef1eff9d2@linaro.org>
2026-07-27 15:13:38 -04:00
Manos Pitsidianakis
bdac94e9cf virtio-snd: check rx buffer descriptor size
It must be at least sizeof(virtio_snd_pcm_status).

I haven't verified if it's possible to get an underflow, but coverity
points it out in CID 1547527 so add a check.

Reviewed-by: Alex Bennée <alex.bennee@linaro.org>
Signed-off-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260420-virtio-fixups-v3-1-07aef1eff9d2@linaro.org>
2026-07-27 15:13:38 -04:00
Michael S. Tsirkin
67550d65b4 virtio-iommu: fix OOM due to unbounded call_rcu
Currently, within virtio-iommu, handle_command processes the command vq
without any limits on the number of entries processed.
This can easily and repeatedly enable/disable multiple memory regions.
Within the memory code, this causes an accumulation of an
unbounded number of RCU-deferred FlatViews - each of these
is supposed to be freed with call_rcu, but that never happens
because the main thread never returns to the main loop.

Given FlatView is big, it's easy to have this balloon out to multiple
Gigabytes of memory.

Limit the loop defer any remaining work to a timer.

Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3930
Cc: Eric Auger <eric.auger@redhat.com>
Cc: Jean-Philippe Brucker <jean-philippe@linaro.org>
Reviewed-by: Eric Auger <eric.auger@redhat.com>
Tested-by: Eric Auger <eric.auger@redhat.com>
Reported-by: Jia Jia <physicalmtea@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <eb46ab360dbe28c29cfa78812a7440dcb7444d59.1784807826.git.mst@redhat.com>
2026-07-27 15:13:20 -04:00
Michael S. Tsirkin
733a98a552 libvduse: validate vq size
libvduse assumes that vq size (aka vq num) is below VIRTQUEUE_MAX_SIZE
and maps logs large enough based on this assumption.

However, vduse_queue_enable() accepts the vq size returned through
VDUSE_VQ_GET_INFO without validation, so a value above
VIRTQUEUE_MAX_SIZE (1024) overruns the inflight log and causes
out-of-bounds writes in vduse_queue_inflight_get().

According to the virtio spec, vq size can only be reduced, not
increased, so vq size must not exceed the previously configured
max_size, but the kernel vduse module does not validate this for us, and
we should not trust another process to follow the spec.

Validate and reject vq size values above VIRTQUEUE_MAX_SIZE.

Fixes: CVE-2026-61402
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3652
Reported-by: Jia Jia <physicalmtea@gmail.com>
Message-ID: <bf7e71b3139875e5e00fd53970c772d6c90dc2a1.1784888961.git.mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
2026-07-27 15:13:20 -04:00
Michael S. Tsirkin
b9d248dfac libvhost-user: fix heap overflow in vu_check_queue_inflights
vu_check_queue_inflights counts inflight descriptors using inflight == 1
but copies entries using inflight != 0. If the inflight field contains
an unexpected non-0/1 value, the function copies more entries than it
allocates and overflows the heap buffer.

Stop the copy pass once resubmit_num reaches the counted inuse value.
Note: the value is not guest-accessible so not a security vulnerability.

Fixes: CVE-2026-63110
Fixes: 5f9ff1eff3 ("libvhost-user: Support tracking inflight I/O in shared memory")
Cc: Xie Yongji <xieyongji@bytedance.com>
Cc: Stefano Garzarella <sgarzare@redhat.com>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3974
Reported-by: BB CC <wywwzjj@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-Id: <e2315efc526c0ee918485df4be69e2b26e8b7a73.1784892981.git.mst@redhat.com>
2026-07-27 15:13:18 -04:00
Michael S. Tsirkin
bf21298c08 libvhost-user: validate last_batch_head in vu_check_queue_inflights
vu_check_queue_inflights uses last_batch_head from the frontend-controlled
inflight shared memory as an index into desc[] without bounds checking.
A malicious or buggy frontend can set last_batch_head >= desc_num,
causing an out-of-bounds write.

Validate last_batch_head before using it.
Note: the value is not guest-accessible so not a security vulnerability.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3974
Fixes: 5f9ff1eff3 ("libvhost-user: Support tracking inflight I/O in shared memory")
Cc: Xie Yongji <xieyongji@bytedance.com>
Cc: Stefano Garzarella <sgarzare@redhat.com>
Reported-by: BB CC <wywwzjj@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-Id: <8133770c75c9907578dd551f4d468140a0a75cd2.1784892981.git.mst@redhat.com>
2026-07-27 15:13:15 -04:00
Michael S. Tsirkin
5cc182ba39 virtio-pmem: wait for flush requests on unrealize
virtio_pmem_flush submits fsync requests to the thread pool and stores a
VirtIOPMEM pointer in each request. If device is deleted e.g. by
hot-unplug, once these complete, done_cb can run after
virtio_pmem_unrealize frees the device, causing a use-after-free.

Track in-flight requests and wait in virtio_pmem_unrealize until
their completions finish before tearing the device down.

Fixes: CVE-2026-63323
Fixes: 5f503cd9f3 ("virtio-pmem: add virtio device")
Cc: David Hildenbrand <david@kernel.org>
Cc: Pankaj Gupta <pagupta@redhat.com>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3938
Reported-by: Jia Jia <physicalmtea@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <417b6685f37ce818c660ca3c84945992f5c30dcf.1784894206.git.mst@redhat.com>
2026-07-27 15:13:12 -04:00
Michael S. Tsirkin
cf89b769cd vhost-user: assert nregions within limit
scrub_shadow_regions() and vhost_user_add_remove_regions() use
fixed-size stack arrays sized to VHOST_USER_MAX_RAM_SLOTS and index them
with dev->mem->nregions.

nregions is calculated to never overrun these, but let's add an assert
to make sure we don't get a stack overflow if there's a bug.

Fixes: f1aeb14b08 ("Transmit vhost-user memory regions individually")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3910
Cc: Stefano Garzarella <sgarzare@redhat.com>
Cc: Raphael Norwitz <raphael.norwitz@nutanix.com>
Reported-by: Feifan Qian <bea1e@proton.me>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <48fb8411f67e525872fb19618a886e52b670ab7f.1784896199.git.mst@redhat.com>
2026-07-27 15:13:09 -04:00
Michael S. Tsirkin
665c854390 virtio: fail early on bad config_len in migration
virtio_load() attempts to load config_len bytes from the migration
stream. If that's huge (e.g. 4g) this will uselessly spin
beyond the end of the stream for seconds. Not nice.
Check qemu_file_get_error() and bail out early, instead.

Also note that config_len is int32_t but is coerced to unsigned when
used. Switch it to uint32_t to make this clearer.

Fixes: 2f5732e964 ("Allow mismatched virtio config-len")
Cc: Dr. David Alan Gilbert <dave@treblig.org>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3891
Reported-by: Feifan Qian <bea1e@proton.me>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <cfbefa358af5885eb386637216552bfeba5e7bbc.1784898922.git.mst@redhat.com>
Reviewed-by: Dr. David Alan Gilbert <dave@treblig.org>
2026-07-27 15:12:34 -04:00
Michael S. Tsirkin
d6384ad1c1 virtio: stop migrating num_default, validate vring.num on load
num_default tracks the allocation size of used_elems, set by
virtio_add_queue(). Migrating it via the ringsize subsection is
wrong: a migration stream (malicious or simply from a different
configuration) can inflate num_default so that
virtio_queue_set_num() accepts oversized values, leading to OOB
access on the used_elems array.

It is not even migrated consistently: a configuration with a
smaller num_default could thinkably migrate and work but in the
common case of num == num_default the value is not actually sent.

Stop migrating num_default: make virtio_ringsize_needed() return
false so the subsection is never sent, and use VMSTATE_UNUSED to
consume the field from old streams without applying it. The
destination keeps its local num_default from virtio_add_queue(),
which matches the actual allocation.

Also validate vring.num against num_default when loading the core
virtio state, rejecting streams that supply a queue size larger
than the locally allocated maximum.

Fixes: 46c5d0823d ("virtio: ring sizes vs. reset")
Fixes: 50e5ae4dc3 ("migration/virtio: Remove simple .get/.put use")
Cc: Cornelia Huck <cohuck@redhat.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <3e6a7c403f93acc37af6a6332fdc65049ae218fb.1784894327.git.mst@redhat.com>
2026-07-27 15:12:34 -04:00
Michael S. Tsirkin
d530f2dfbd virtio: fix queue size validation against allocated maximum
virtio_add_queue() allocates used_elems for num_default entries, but
virtio_queue_set_num() accepts larger guest-supplied queue sizes up to
VIRTQUEUE_MAX_SIZE. With VIRTIO_F_IN_ORDER, this lets the guest drive
used_elems accesses past the allocation and cause out-of-bounds reads
and writes.

Reject queue sizes larger than num_default in virtio_queue_set_num()
and mark the device broken.

Fixes: e63c0ba1bc ("virtio: Add support for guest setting of queue size")
Fixes: CVE-2026-50626
Cc: Peter Maydell <peter.maydell@linaro.org>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3882
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3921
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3923
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3613
Reported-by: huntr bubble <bubblehuntr@gmail.com>
Reported-by: Jia Jia <physicalmtea@gmail.com>
Reported-by: Miku Hatsune <anznu1l@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <eb7cc3672a20db392f577edbece2300aa6754dd3.1784898967.git.mst@redhat.com>
2026-07-27 15:12:00 -04:00
Michael S. Tsirkin
a5cff318f0 virtio-mmio: fix QUEUE_NUM_MAX
virtio-mmio reports VIRTQUEUE_MAX_SIZE (1024) as QUEUE_NUM_MAX for every
queue, regardless of the size the device passes to virtio_add_queue().

This works by accident because QEMU mostly does not care about the ring
size - the guest is the one allocating memory here.  But this changes
with in-order vqs where qemu is the one allocating resources.
Now, specifying a larger vq than allocated causes an OOB memory access.

To fix:
- for new machine types, report the actual max queue size to guest
- for old machine types, use a compat property to allocate 1k sized
  queues

Fixes: 525d82e323 ("virtio: fix queue size validation against allocated maximum")
Fixes: CVE-2026-50626
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3882
Cc: Peter Maydell <peter.maydell@linaro.org>
Message-ID: <8715acbb9516e67e2a776cda6f9edf105343f788.1784930765.git.mst@redhat.com>
Acked-by: Yonggang Luo <luoyonggang@gmail.com>
Reported-by: Miku Hatsune <anznu1l@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
2026-07-27 15:11:43 -04:00
Michael S. Tsirkin
f404bf0e65 virtio-scsi: fix SCSIRequest leak on a bad request
When virtio_scsi_handle_cmd_vq() cleans up prepared requests after a
malformed element in the same batch, it drops only one reference even
though virtio_scsi_handle_cmd_req_prepare() leaves each unsubmitted
SCSIRequest with two references. This leaks the request and allows
repeated bad batches to cause unbounded host memory growth.

Add a second scsi_req_unref() and clear hba_private first.

Fixes: CVE-2026-61476
Fixes: 661e32fb3c ("virtio-scsi: convert virtio_scsi_bad_req() to use virtio_error()")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3875
Cc: Paolo Bonzini <pbonzini@redhat.com>
Cc: Fam Zheng <fam@euphon.net>
Cc: Greg Kurz <groug@kaod.org>
Reported-by: Feifan Qian <bea1e@proton.me>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <5092cd4716e08d29731bfe85eea82a732b837ff4.1784895264.git.mst@redhat.com>
2026-07-27 15:11:31 -04:00
Michael S. Tsirkin
27806d2ddb vhost: do not crash on ring map failure
When vhost_commit() rebuilds the memory region table after a flatview
change, it revalidates cached host virtual addresses for active vring
parts. If a mapping is stale, QEMU abort().

This is not a security problem - only the priviledged guest
can control make it invalid - but not nice e.g. for driver debugging.

Let's call virtio_error() instead, marking the device as broken.

Fixes: 0ca1fd2d68 ("vhost: Simplify ring verification checks")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3783
Cc: Stefano Garzarella <sgarzare@redhat.com>
Cc: Dr. David Alan Gilbert <dave@treblig.org>
Reported-by: Feifan Qian <bea1e@proton.me>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <71961a7dc157f552303aeea8c99a75c5e1ce904e.1784898432.git.mst@redhat.com>
Reviewed-by: Dr. David Alan Gilbert <dave@treblig.org>
2026-07-27 15:10:51 -04:00
Laurent Vivier
6dbdc271f5 hw/virtio: reject zero-length packed indirect descriptor table
The split-ring path already rejects a zero-length indirect descriptor
table since commit 7423192912 ("virtio: add checks for the size of
the indirect table"). The packed-ring path is missing the same check,
allowing a guest to trigger an assertion in address_space_cache_init()
with a packed indirect descriptor that has len=0.

Add the same !desc.len check to the packed-ring indirect validation
in both virtqueue_packed_get_avail_bytes() and virtqueue_packed_pop().

Fixes: 86044b24e8 ("virtio: basic packed virtqueue support")
Cc: jasowangio@gmail.com
Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3984
Reported-by: dong ling <dongling226655@outlook.com>
Signed-off-by: Laurent Vivier <lvivier@redhat.com>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260715115040.2186274-1-lvivier@redhat.com>
2026-07-27 15:10:38 -04:00
Michael S. Tsirkin
758ef96a2d libvhost-user: protect against OOB vring queue access
SET_VRING_NUM, SET_VRING_ADDR, SET_VRING_BASE, and GET_VRING_BASE
handlers all use the queue index from the message to access dev->vq[]
without checking that it is below dev->max_queues, so a malformed
message causes an out-of-bounds heap access.

Frontend is trusted so not a security problem, but
an OOB access is not a nice way to handle errors.
Check, and panic.

Fixes: 7b2e5c65f4 ("contrib: add libvhost-user")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3741
Cc: Stefano Garzarella <sgarzare@redhat.com>
Reported-by: xlabai <xlabai@tencent.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <dbba777b25f86587c8d131891a2b4b2be97e5c5b.1784899069.git.mst@redhat.com>
2026-07-27 15:10:23 -04:00
Michael S. Tsirkin
fbdfdbb992 libvhost-user: protect against OOB writes in vu_set_inflight_fd
vu_set_inflight_fd() trusts the num_queues value from the
VHOST_USER_SET_INFLIGHT_FD message without checking it against
dev->max_queues, so an oversized value causes out-of-bounds writes to
dev->vq.

Front end is generally trusted so not a security problem, but OOB isn't
a nice way to handle frontend bugs.  Let's harden this a bit:
check num_queues and panic if it's invalid.

Fixes: 5f9ff1eff3 ("libvhost-user: Support tracking inflight I/O in shared memory")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3740
Cc: Stefano Garzarella <sgarzare@redhat.com>
Reported-by: xlabai <xlabai@tencent.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <23b3f12388c1035f208550df9de9944c22d8d534.1784899127.git.mst@redhat.com>
2026-07-27 15:09:52 -04:00
Michael S. Tsirkin
7724885620 virtio-net: fix short frame OOB read in receive_filter()
Within virtio-net, receive_filter() reads Ethernet header fields without
any length checks.

But virtio-net sets do_not_pad in NetClientState, so backends such as
socket forward frames at the size supplied by the peer without padding
to the Ethernet minimum. A short frame thus causes an out-of-bounds
read.

Add size checks in receive_filter() and drop the truncated frames.

Fixes: CVE-2026-63320
Fixes: 3831ab2094 ("qemu:virtio-net: Enable filtering based on MAC, promisc, broadcast and allmulti (Alex Williamson)")
Cc: Jason Wang <jasowangio@gmail.com>
Cc: Alex Williamson <alex@shazbot.org>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3626
Reported-by: huntr bubble <bubblehuntr@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <ee5c77b96ab66b2dd518f146def8727216a5c495.1784895727.git.mst@redhat.com>
2026-07-27 15:09:40 -04:00
Michael S. Tsirkin
52c7bb369b virtio-net: fix OOB read in RSC receive path
The RSC receive path parses incoming frames at guest_hdr_len byte
offsets, but the backend buffer contains only host_hdr_len bytes of vnet
header. If the lengths differ, RSC would read at the wrong offset and
cause an OOB read.

This is no longer possible after the previous patch, but the assumption
seem fragile. Along the defense in depth lines, let's validate.  To
ensure we are not breaking any valid setups by mistake, warn and fall
back to the normal receive path when host_hdr_len != guest_hdr_len.

Fixes: CVE-2026-63321
Fixes: 2974e916df ("virtio-net: support RSC v4/v6 tcp traffic for Windows HCK")
Cc: Jason Wang <jasowangio@gmail.com>
Cc: Yuri Benditovich <ybendito@redhat.com>
Cc: Wei Xu <wexu@redhat.com>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3623
Reported-by: huntr bubble <bubblehuntr@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <f261dcd535edc890f8636d8ae5ac1007bc32b8b4.1784891251.git.mst@redhat.com>
2026-07-27 15:09:29 -04:00
Michael S. Tsirkin
a6e0519ea8 virtio: use masked features with set_features_ex
virtio_set_features_nocheck() calls set_features_ex
with guest-supplied feature bits, without masking the value
with host features (unlike set_features which gets the
correct val & host_features).

This does not matter if the driver matches spec, but drivers
can be malicious or buggy and set bit outside the host mask.

Devices don't expect this, so unsupported guest feature bits getting set
can break the host. In virtio-net, this can enable RSC without vnet
header support and cause out-of-bounds reads from short packets.

Pass the masked features to set_features_ex, consistent with set_features.

Fixes: CVE-2026-63321
Fixes: 64a6a336f4 ("virtio: add support for negotiating extended features")
Cc: Jason Wang <jasowangio@gmail.com>
Cc: Yuri Benditovich <ybendito@redhat.com>
Cc: Paolo Abeni <pabeni@redhat.com>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3623
Reported-by: huntr bubble <bubblehuntr@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <dfd27c9b26e442a2076f6ddc9bb3d38363d9b2da.1784891251.git.mst@redhat.com>
2026-07-27 15:08:59 -04:00
Denis V. Lunev
21a77a2158 parallels: fix integer overflow in header size calculation
parallels_open() caches bat_entry_off(s->bat_size) - a uint32_t -
in a plain int before it feeds into s->header_size. Near the
"Catalog too large" bound the value exceeds INT_MAX and overflows
on assignment.

Match the cached value's type to bat_entry_off()'s return type.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Thomas Huth <thuth@redhat.com>
CC: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-27 14:42:24 +02:00
Marc-André Lureau
0e83d68945 migration/rdma: annotate and simplify wait_comp_channel()
The function calls yield_until_fd_readable() (coroutine_fn) when in
coroutine context, and polls with qemu_poll_ns() otherwise.

Replace the migration-state proxy check with qemu_in_coroutine(),
which directly tests what matters.

Fixes: 2da776db48 ("rdma: core logic")
Reviewed-by: Peter Xu <peterx@redhat.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
12d3fd9a0a hw/9pfs: annotate V9fsTransport callbacks as coroutine_fn
All V9fsTransport callbacks are invoked exclusively from coroutine
context (the v9fs_* PDU handlers). Annotate the function pointer
types in V9fsTransport and all implementations (virtio and xen
backends), as well as intermediate callers in 9p.c (pdu_marshal,
pdu_unmarshal, v9fs_init_qiov_from_pdu, etc.).

Acked-by: Christian Schoenebeck <qemu_oss@crudebyte.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
c15ca7cf98 qcow2: remove invalid qcow2_check_refcounts calls
Those DEBUG_ALLOC-guarded are dead code incorrectly calling coroutine fn
from non-coroutine. Remove it.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Fixes: 70bacc4453 ("qcow2: mark more functions as coroutine_fns and  GRAPH_RDLOCK")
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
a6c131217d block: add missing coroutine annotation
The function was extracted without carrying the annotation.

Fixes: 23743ab282 ("block: move commit_run loop to separate function")
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
1fe1ec6773 io: add missing coroutine annotation
Fixes: 1edf0df284 ("io: Add qio_channel_wait_cond() helper")
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
aea4af8c51 migration: fix qemu_get_counted_string annotation
Fixes: 394b9407e4 ("migration: mark mixed functions that can suspend")
Reviewed-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
8c57370d18 monitor: annotate monitor_qmp_dispatcher_pop_any() as coroutine
The function calls qemu_coroutine_yield(), and is called from
monitor_qmp_dispatcher_co().

Fixes: 60f4f62efe ("monitor: extract request dequeuing to a new function")
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Markus Armbruster <armbru@redhat.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
6b47b70185 block/blkio: fix compiler false-positive warning
Under some optimization, gcc produces a false-positive:
    ../block/blkio.c: In function ‘blkio_co_getlength’:
    ../block/blkio.c:943:8: error: ‘ret’ may be used uninitialized [-Werror=maybe-uninitialized]
      943 |     if (ret < 0) {
          |        ^

Replace WITH_QEMU_LOCK_GUARD with the simpler QEMU_LOCK_GUARD.

Suggested-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
5e8d44971e hw/hexagon: fix machine->fdt leak in qom-test
virt_instance_init() built the FDT unconditionally at QOM
instance-init time, so simply instantiating the object (e.g. via
qom-test's introspection, without ever realizing the machine) leaked
the 1MB FDT blob: machine_finalize() does not free machine->fdt.

Other boards (arm/virt, riscv/virt, ...) build the FDT lazily from
their MachineClass::init callback, which only runs when the machine
is actually selected to boot. Do the same here by moving create_fdt()
into virt_init().

Fixes: 88a8bc7f43 ("hw/hexagon: Define hexagon "virt" machine")
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
fdad10190a hw/cxl: fix invalid free on early return
docs/devel/style.rst:

 * Variables declared with g_auto* MUST always be initialized,
   otherwise the cleanup function will use uninitialized stack memory

Fixes: 680935c9a6 ("hw/cxl: Add a performant (and correct) path for the non interleaved cases")
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
d541d7dc2f hw/display/virtio-gpu-rutabaga: zero-init capset info response
rutabaga_cmd_get_capset_info() only fills in capset_id,
capset_max_version and capset_max_size before sending the response to
the guest. The remaining fields of struct virtio_gpu_resp_capset_info,
including hdr.fence_id, hdr.ctx_id and hdr.ring_idx, are left with
stack garbage and leaked to the guest, including host pointers useful
for an ASLR bypass.

Zero the response first, matching virgl_cmd_get_capset_info().

Not a real risk thanks to -ftrivial-auto-var-init=zero, but only with
gcc >= 12 or clang >= 16.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3609
Fixes: 1dcc6adbc1 ("gfxstream + rutabaga: add initial support for gfxstream")
Reported-by: Haotian Jiang <jianghaotian.sunday@gmail.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Akihiko Odaki
5c9ef661a6 hw/display/virtio-gpu: Block Rutabaga migration
The migration stream encoding is not defined for Rutabaga yet.

Fixes: 1dcc6adbc1 ("gfxstream + rutabaga: add initial support for gfxstream")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260725-rutabaga-v1-1-4832b56e679d@rsg.ci.i.u-tokyo.ac.jp>
2026-07-27 15:51:03 +04:00
Akihiko Odaki
8dc8449a67 hw/display/virtio-gpu: Avoid leaking migration blocker
virtio_gpu_base_device_realize() leaks a migration blocker if a
check of the output list fails after adding one. Perform the check
before adding a migration blocker to avoid the leak. This also
simplifies the code by merging two loops.

Fixes: d3a4969dc5 ("Support per-head resolutions with virtio-gpu")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260725-virgl-v1-1-58bb51e60da5@rsg.ci.i.u-tokyo.ac.jp>
2026-07-27 15:51:03 +04:00
Akihiko Odaki
4ae1c5c7d6 hw/display/virtio-gpu: Initialize blob mapping for ATTACH_BACKING
It is necessary for blob cursor and scanout.

Fixes: e0933d91b1 ("virtio-gpu: Add virtio_gpu_resource_create_blob")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260725-backing-v1-1-5b584bf7df5a@rsg.ci.i.u-tokyo.ac.jp>
2026-07-27 15:51:03 +04:00
Akihiko Odaki
0fa3e1823b hw/display/virtio-gpu: Fix empty blob discrimination
Discriminating blobs by checking whether blob_size is nonzero fails for
empty blobs. Identify 2D resources by their non-NULL image instead.

Fixes: bdd53f7392 ("virtio-gpu: Update cursor data using blob")
Fixes: f66767f75c ("virtio-gpu: add virtio-gpu/blob vmstate subsection")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260725-image-v1-1-4698a805afde@rsg.ci.i.u-tokyo.ac.jp>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
521500bd80 docs/hyperv: fix misleading hv-crash shutdown description
The documentation stated that writing to HV_X64_MSR_CRASH_CTL
unconditionally causes the guest to shutdown. In reality, it triggers
qemu_system_guest_panicked() via KVM_SYSTEM_EVENT_CRASH and the
resulting action depends on the generic panic action policy
(-action panic=...), which defaults to shutdown.

Reviewed-by: Vitaly Kuznetsov <vkuznets@redhat.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260701122135.3168729-1-marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Haotian Jiang
8ac0a1c7b9 virtio-gpu: fix NULL deref in rutabaga set_scanout
rutabaga_cmd_set_scanout() checks scanout_id < VIRTIO_GPU_MAX_SCANOUTS
(16), but does not check scanout_id < conf.max_outputs like the base
class (virtio-gpu.c) and virgl backend (virtio-gpu-virgl.c) do.

With the default max_outputs=1, virtio_gpu_base_device_realize only
initializes scanout[0].con. A guest submitting SET_SCANOUT with
scanout_id >= 1 takes the con=NULL path, and
qemu_console_set_surface(NULL, NULL) dereferences con->ds, crashing
QEMU.

Replace VIRTIO_GPU_MAX_SCANOUTS with vb->conf.max_outputs in the
CHECK, since realization already ensures max_outputs <=
VIRTIO_GPU_MAX_SCANOUTS.

Fixes: 1dcc6adbc1 ("gfxstream + rutabaga: add initial support for gfxstream")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3897
Cc: qemu-stable@nongnu.org
Message-ID: <20260720071556.106003-1-jianghaotian.sunday@gmail.com>
Reviewed-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Haotian Jiang <jianghaotian.sunday@gmail.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
415f2759d7 target/i386/sev: fix MemoryRegion reference leaks in gpa2hva callers
gpa2hva() returns a referenced MemoryRegion via its p_mr out-parameter
(inherited from memory_region_find()), but both SEV callers were failing
to release it.

Fixes: c7f7e6970d ("sev: add sev-inject-launch-secret")
Reviewed-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Zhao Liu <zhao1.liu@intel.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260521145451.1831984-1-marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
b28778131f net/colo: fix g_hash_table_destroy assertion on uninitialized filter
colo_rewriter_cleanup() unconditionally destroys connection_track_table,
but the table is only allocated in colo_rewriter_setup(). When the
filter-rewriter object is finalized without having been set up (e.g.
during qom-test property enumeration), the pointer is NULL and
g_hash_table_destroy() fires an assertion.

Use g_clear_pointer() to skip the destroy when the table was never
initialized.

Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Zhang Chen <zhangckid@gmail.com>
Message-ID: <20260709111315.1108185-1-marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Haotian Jiang
4727cc883b hw/display/qxl: unregister vm_change_state handler and BHs
qxl_realize_common() registers a vm_change_state handler via
qemu_add_vm_change_state_handler() and creates three bottom halves
(update_irq, update_area_bh, cursor_bh), but none are ever cleaned up.
The return value of qemu_add_vm_change_state_handler() is discarded, so
the handler is never removed from the global list, and there is no
PCIDeviceClass.exit callback to delete the BHs.

When a secondary QXL device (hotpluggable by default) is hot-unplugged
via device_del, the PCIQXLDevice memory is freed but the vm_state
handler and BH entries remain with dangling opaque pointers. On the
next VM state change (stop/cont/migrate) or BH dispatch, the callback
dereferences freed memory, causing a use-after-free.

Fix this by storing the VMChangeStateEntry returned by
qemu_add_vm_change_state_handler() and adding a qxl_exit() callback
that deletes the vm_state handler, all three BHs, and the
guest_surfaces.cmds allocation before the device memory is freed.

Fixes: a19cbfb346 ("spice: add qxl device")
Fixes: CVE-2026-63322
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3607
Signed-off-by: Haotian Jiang <jianghaotian.sunday@gmail.com>
Cc: qemu-stable@nongnu.org
[ Marc-André - tweak commit message, add TODO ]
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260720024855.3757499-1-jianghaotian.sunday@gmail.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
efa7244b2a ui/vnc: remove redundant rows computation
"rows" was already computed in an earlier commit 3543c2b855 ("ui/vnc:
fix OOB write in vnc_refresh_lossy_rect").

Fixes: e650e4fe0f ("ui/vnc: fix out-of-bounds write in lossy refresh dirty marking")
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Marc-André Lureau
1c1232c2ee hw/display/vhost-user-gpu: validate message payload sizes
A malicious or buggy vhost-user-gpu backend can send messages with
undersized payloads, leading to out-of-bounds reads when the handler
accesses struct fields beyond the allocated buffer. However,
vhost-user-gpu is considered trusted by QEMU by design (it has access to
shared memory etc).

Add a centralized minimum payload size check in vhost_user_gpu_chr_read()
that rejects messages before dispatch, and a per-pixel bounds check in
the VHOST_USER_GPU_UPDATE handler to ensure the variable-length data
covers the declared width x height.

Fixes: 267f66465 ("hw/display: add vhost-user-vga & gpu-pci")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3866
Reported-by: Feifan Qian <bea1e@proton.me>
Reviewed-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-27 15:51:03 +04:00
Akihiko Odaki
76dcc0832c hw/display/virtio-gpu: Remove the bytes_pp field
virtio_gpu_do_set_scanout() validates the stride field of struct
virtio_gpu_framebuffer against the bytes_pp field, but bytes_pp in the
migration stream may be inconsistent with the format field, which
pixman_image_create_bits() uses when it accesses the framebuffer.
That validation is therefore incomplete.

To avoid the trouble of synchronizing the two fields, remove bytes_pp,
and always derive its value from format. Removing bytes_pp is safe
because no released version of QEMU uses its migrated value.

Fixes: 7b55742254 ("hw/display: check frame buffer can hold blob")
Cc: qemu-stable@nongnu.org
Reviewed-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
[ Marc-André - fix rebase conflict ]
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Message-ID: <20260719-bpp-v1-1-9b91946d6cf3@rsg.ci.i.u-tokyo.ac.jp>
2026-07-27 15:51:03 +04:00
Thomas Huth
92abc3c51e hw/usb/hcd-xhci: Check return value of xhci_xfer_create_sgl() for errors
xhci_xfer_create_sgl() can fail if a guest programmed the XHCI in
a weird way. The current code ignores this error, and this triggers
an assert() shortly afterwards:

 hw/usb/core.c:612: usb_packet_copy:
  Assertion `p->actual_length + bytes <= iov->size' failed.

Fix it by handling the error correctly (i.e. return with an error to
the caller).

While we're at it, change the DPRINTF statements in xhci_xfer_create_sgl()
into proper qemu_log_mask() statements, so we have a better way to detect
this situation.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3786
Reported-by: Feifan Qian <bea1e@proton.me>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260724110933.629791-1-thuth@redhat.com>
2026-07-27 13:00:45 +02:00
Thomas Huth
68809288c7 hw/usb/core: Avoid possible assert() in do_parameter() --> usb_packet_copy()
usb_packet_copy() uses assert(p->actual_length + bytes <= iov->size)
to make sure that there is enough space in the the iov. This assert()
can be triggered from do_parameter() if the guest programs the XHCI
in a weird way. Avoid the hard error by checking for the condition
in do_parameter() first and signalling a USB_RET_STALL to the guest,
just like it is done for another error condition here already some
lines earlier.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3746
Reported-by: Yunhe Wang <yunhewwww@163.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260721185140.247775-1-thuth@redhat.com>
2026-07-27 13:00:45 +02:00
Thomas Huth
9b899ddb27 hw/ide/core: Fix possible crash via NULL pointer in ide_cancel_dma_sync()
ide_cancel_dma_sync() is called with a "IDEState *s" for one of the
two IDE drives on a bus (primary or secondary drive) to cancel all
pending DMA transfers on the drive. The code then checks
s->bus->dma->aiocb to see whether there is any IO in flight on the
*bus* and then calls blk_drain(s->blk) to wait for its completion.
However, s->bus->dma->aiocb might belong to the other drive on the
bus, and if there is no disk attached to the current drive, s->blk
is NULL. Since blk_drain() does not check its parameter for a NULL
pointer, QEMU can crash in such a case.

To fix the problem, we have to check that "blk" is not NULL before
calling blk_drain(). And we have to call blk_drain() for both drives,
otherwise the assert(s->bus->dma->aiocb == NULL) statement after
the blk_drain() might trigger if the IO in flight belongs to the
the other drive.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/905
Reported-by: Alexander Bulekov <alxndr@bu.edu>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4052
Reported-by: dong ling
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260721070216.82984-1-thuth@redhat.com>
2026-07-27 13:00:45 +02:00
Thomas Huth
b7520c9a59 hw/usb/dev-uas: Fix guest-triggerable heap OOB access
The stream ID is under control of the guest, and some spots in the
code currently use it for indexing into the status3[] array without
checking it for being in range first, so the code accesses the heap
beyond the limit of the status3 array.

Since our status delivery code depends on having a valid stream ID,
we must not try to generate a fake sense code in this situation.
Simply log a guest error and return early in usb_uas_command().

And to make sure that we really cannot access the status3[] array
beyond its limit anymore, add some assert() statements in the
affected functions, too.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3612
Reported-by: Reported-by: huntr bubble
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3986
Reported-by: Tristan Madani <tristan@talencesecurity.com>
Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260720134809.573757-1-thuth@redhat.com>
2026-07-27 13:00:45 +02:00
Feifan Qian
b71a179148 hw/cxl: Validate Set Feature payload bounds
cmd_features_set_feature() derives bytes_to_copy from the mailbox input
length and uses hdr->offset as the destination offset into per-feature
write attribute buffers.

The patrol scrub and ECS paths already reject writes where hdr->offset
plus bytes_to_copy exceeds the destination structure. Add the same check
to the soft PPR, hard PPR and memory sparing feature paths before
copying into their write attribute buffers.

Without the check, a malformed Set Feature request can write past the
selected write attribute object and corrupt adjacent CXL type 3 device
state.

Fixes: 5e5a86bab8 ("hw/cxl: Add support for Maintenance command and Post Package Repair (PPR)")
Fixes: da5cafdc4d ("hw/cxl: Add emulation for memory sparing control feature")
Signed-off-by: Feifan Qian <bea1e@proton.me>
Reviewed-by: Thomas Huth <thuth@redhat.com>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3458
Reported-by: Jia Jia <physicalmtea@gmail.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
2026-07-27 13:00:45 +02:00
Cédric Le Goater
d71fa99ca8 tests/functional/aspeed: Fix remaining hostname-specific login prompts
Commit b04746bd0d unified boot completion detection on the generic
'login:' prompt but missed several SDK test files that still matched
on hostname-prefixed patterns. Apply the same fix.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4059
Fixes: b04746bd0d ("tests/functional/aspeed: unify boot completion detection on 'login:' prompt")
Reported-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260720162321.3497633-1-clg@redhat.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-27 07:32:56 +02:00
Cédric Le Goater
8268d216a0 linux-user: Guard local FUTEX_CMD_MASK definition
Building linux-user on a host with Linux 7.2 kernel headers fails with
a macro redefinition error for FUTEX_CMD_MASK. The kernel commit
3ca9595d9fb6 ("futex: Add support for unlocking robust futexes")
expanded the mask to include the new FUTEX_ROBUST_UNLOCK and
FUTEX_ROBUST_LIST32 flags, which conflicts with QEMU's local
definition.

Add a #ifndef guard so the host definition takes precedence when
available. The local fallback is kept for older kernel headers
(pre-2.6.29) that lack FUTEX_CMD_MASK or define a mask without
FUTEX_CLOCK_REALTIME.

Signed-off-by: Cédric Le Goater <clg@redhat.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-07-26 15:10:59 +02:00
Stefan Hajnoczi
6333226c2a 9pfs changes:
- Fix O_TRUNC bypass on read-only export (CVE-2026-63318).
 
 - Fix guest-triggered Treaddir/ACPI eject UAF (#3937).
 
 - Tests: fix "slow" type test errors on certain host systems.
 
 - Tests: fix CID 1660926.
 -----BEGIN PGP SIGNATURE-----
 
 iQJLBAABCgA1FiEEltjREM96+AhPiFkBNMK1h2Wkc5UFAmpkmGMXHHFlbXVfb3Nz
 QGNydWRlYnl0ZS5jb20ACgkQNMK1h2Wkc5U2txAAkY7pxVx4NoZYM/JGFuuAbHAY
 GQUYAqK4IxA0QpYdr047x53WISzRx5hq/xzJuh+OxKDLJ7nWm/lO08N05hpwtaER
 kBY95LT4dE3fbWVrUo9sC/GitUbvRqU8xiHFpnU9+c3ZSx2pZR3AzNLTFmPQveZ4
 68M7XN3EiCo8rmr9WDt4Rby+KDrfaJb1pUqpur0RxnS3qUukxgIbqXlFT5IY22sm
 eXNGs8FIhKNggfLosM4rdrGujs/NIqBVIWKR3c3Lm4OZhA72ZJjpqc61p1vhx8Gk
 bNtIGDD/LkmKrFBcTYWNuBmVh5MxPsG0ytH3L727P6wka/RKVHYHBBBsxsFaHePP
 8rU6Zh3d6VlY+8sbUY/tx261hFBX3o4IBxPlzRNnwWSHfBkjDFc/Lvl08LKOBjM9
 84HvcuhsdAY9OTUARdKKKAGKEjX3C4mfY6eWiG2AwjIg0DvbwHGlpu8AaUiCdDBk
 BU7SSIRrP7bHhVf1bhfu/GKHt8n7ETYTpMX/9xzEW/AXLjTtVg0w7fid9vtUZwhJ
 6JoWheQQZJD9NVUf8xu+mmeo3YZMZiWyv3B3WN42CYYzIDUTvHFY1ZvM936rxZ+Z
 o8u55CfiE7ddeYDKEsmDIi2pSFSvvtT0zZA1+hYYjjcmu3OzfANJn4r8sjEUepjf
 wLy/aY44R1EG5TXCCT4=
 =Fm7q
 -----END PGP SIGNATURE-----

Merge tag 'pull-9p-20260725' of https://github.com/cschoenebeck/qemu into staging

9pfs changes:

- Fix O_TRUNC bypass on read-only export (CVE-2026-63318).

- Fix guest-triggered Treaddir/ACPI eject UAF (#3937).

- Tests: fix "slow" type test errors on certain host systems.

- Tests: fix CID 1660926.

# -----BEGIN PGP SIGNATURE-----
#
# iQJLBAABCgA1FiEEltjREM96+AhPiFkBNMK1h2Wkc5UFAmpkmGMXHHFlbXVfb3Nz
# QGNydWRlYnl0ZS5jb20ACgkQNMK1h2Wkc5U2txAAkY7pxVx4NoZYM/JGFuuAbHAY
# GQUYAqK4IxA0QpYdr047x53WISzRx5hq/xzJuh+OxKDLJ7nWm/lO08N05hpwtaER
# kBY95LT4dE3fbWVrUo9sC/GitUbvRqU8xiHFpnU9+c3ZSx2pZR3AzNLTFmPQveZ4
# 68M7XN3EiCo8rmr9WDt4Rby+KDrfaJb1pUqpur0RxnS3qUukxgIbqXlFT5IY22sm
# eXNGs8FIhKNggfLosM4rdrGujs/NIqBVIWKR3c3Lm4OZhA72ZJjpqc61p1vhx8Gk
# bNtIGDD/LkmKrFBcTYWNuBmVh5MxPsG0ytH3L727P6wka/RKVHYHBBBsxsFaHePP
# 8rU6Zh3d6VlY+8sbUY/tx261hFBX3o4IBxPlzRNnwWSHfBkjDFc/Lvl08LKOBjM9
# 84HvcuhsdAY9OTUARdKKKAGKEjX3C4mfY6eWiG2AwjIg0DvbwHGlpu8AaUiCdDBk
# BU7SSIRrP7bHhVf1bhfu/GKHt8n7ETYTpMX/9xzEW/AXLjTtVg0w7fid9vtUZwhJ
# 6JoWheQQZJD9NVUf8xu+mmeo3YZMZiWyv3B3WN42CYYzIDUTvHFY1ZvM936rxZ+Z
# o8u55CfiE7ddeYDKEsmDIi2pSFSvvtT0zZA1+hYYjjcmu3OzfANJn4r8sjEUepjf
# wLy/aY44R1EG5TXCCT4=
# =Fm7q
# -----END PGP SIGNATURE-----
# gpg: Signature made Sat 25 Jul 2026 07:05:07 EDT
# gpg:                using RSA key 96D8D110CF7AF8084F88590134C2B58765A47395
# gpg:                issuer "qemu_oss@crudebyte.com"
# gpg: Good signature from "Christian Schoenebeck <qemu_oss@crudebyte.com>" [unknown]
# gpg: Note: This key has expired!
# Primary key fingerprint: ECAB 1A45 4014 1413 BA38  4926 30DB 47C3 A012 D5F4
#      Subkey fingerprint: 96D8 D110 CF7A F808 4F88  5901 34C2 B587 65A4 7395

* tag 'pull-9p-20260725' of https://github.com/cschoenebeck/qemu:
  hw/9pfs/xen: drain in-flight PDUs before xen-9p disconnect
  hw/9pfs/virtio: drain in-flight PDUs before virtio-9p unrealize
  hw/9pfs: fix O_TRUNC bypass on read-only export
  tests/9p: reduce xattr size to 1k
  tests/9p: prevent potential error in do_local_xattr_limit()

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-26 08:30:07 -04:00
Christian Schoenebeck
1de8aea061 hw/9pfs/xen: drain in-flight PDUs before xen-9p disconnect
The xen-9p disconnect path has two issues:

1. It frees the Xen9pfsRing structures while in-flight PDUs may still
   reference them via pdu->tag to index rings[]. This causes a UAF
   in xen_9pfs_push_and_notify() when worker threads resume after
   completing filesystem operations.

2. It never calls v9fs_device_unrealize_common(), which means server
   state (struct LocalData, mountfd, FIDs) is never cleaned up on
   disconnect, causing a resource leak on every guest-initiated
   disconnect.

Fix both by draining in-flight PDUs via v9fs_reset() before tearing
down rings, and calling v9fs_device_unrealize_common() to clean up
server state.

Additionally, explicit calls of xen_9pfs_disconnect() in the error
paths of xen_9pfs_pdu_vmarshal() and xen_9pfs_pdu_vunmarshal() must
be deferred (via aio_bh_schedule_oneshot()), because
xen_9pfs_pdu_v(un)marshal() are running within a coroutine context
which makes them unsafe [1] for calling v9fs_reset() directly, as
the latter e.g. has a loop like:

    while (!QLIST_EMPTY(&s->active_list)) {
        aio_poll(qemu_get_aio_context(), true);
    }

which would a) never terminate (as the coroutine is on the
active_list) and b) aio_poll() is marked as no_coroutine_fn.

[1] https://lore.kernel.org/qemu-devel/3351181.5fSG56mABF@weasel/

And finally, add an idempotent guard to xen_9pfs_disconnect()
for the v9fs_reset(s) and v9fs_device_unrealize_common(s) calls
specifically [2], just to be sure.

[2] https://lore.kernel.org/qemu-devel/alpine.DEB.2.22.394.2607221815520.5295@ubuntu-linux-20-04-desktop/

Fixes: b37eeb0201 ("xen/9pfs: introduce Xen 9pfs backend")
Reviewed-by: Stefano Stabellini <sstabellini@kernel.org>
Link: https://lore.kernel.org/qemu-devel/82bc736158e827e05d4b55da27c39d42e2062e96.1784809978.git.qemu_oss@crudebyte.com
Signed-off-by: Christian Schoenebeck <qemu_oss@crudebyte.com>
2026-07-25 12:35:25 +02:00
Jia Jia
210701c82e hw/9pfs/virtio: drain in-flight PDUs before virtio-9p unrealize
A guest can trigger a heap-use-after-free in the virtio transport
unrealize path by submitting a Treaddir request and immediately
ejecting the device via ACPI PCI hotplug. The unrealize path frees
struct LocalData while a worker thread still holds a reference
on it, causing a UAF in local_open_nofollow().

Fix this by draining all in-flight 9p PDUs by calling v9fs_reset()
before final server cleanup. This ensures all coroutines completed,
all FIDs are closed, and no worker thread still holds references
on 9p server state when it is freed.

Fixes: 6cecf09373 ("virtio-9p-device: add minimal unrealize handler")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3937
Signed-off-by: Jia Jia <physicalmtea@gmail.com>
[ Christian Schoenebeck: add commit log message. ]
Link: https://lore.kernel.org/qemu-devel/bc503aefffd20b1806941b3ef708afbd92f0aef2.1784809978.git.qemu_oss@crudebyte.com
Signed-off-by: Christian Schoenebeck <qemu_oss@crudebyte.com>
2026-07-25 12:35:25 +02:00
Christian Schoenebeck
a0414545a2 hw/9pfs: fix O_TRUNC bypass on read-only export
Guest 9p client opening a file with O_TRUNC on a read-only 9p file
system using 9p2000.u protocol version, allowed to bypass 9p
server's read-only check, eventually causing file(s) being
truncated to empty file(s) on host's read-only export.

Root cause is that 9p server's read-only check is using Linux open
flags like O_WRONLY, O_RDWR, O_TRUNC, but checking them against
the 9p Topen request's "mode" parameter, which has a different
encoding (Otrunc = 0x10 vs. O_TRUNC = 0x200).

Fix this by checking against the "flags" variable instead of the
protocol's "mode" option. Because the "flags" variable is already
converted to Linux encoding by omode_to_uflags() for 9p2000.u and
by get_dotl_openflags() for 9p2000.L protocol version.

Only 9p2000.u was affected by this bypass, 9p2000.L uses the Linux
format on protocol level already.

Fixes: 2c74c2cb4b ("hw/9pfs: Read-only support for 9p export")
Fixes: CVE-2026-63318
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4000
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Link: https://lore.kernel.org/qemu-devel/E1wk2Dq-0019kY-JK@kylie.crudebyte.com
Signed-off-by: Christian Schoenebeck <qemu_oss@crudebyte.com>
2026-07-25 12:35:24 +02:00
Christian Schoenebeck
d55b123473 tests/9p: reduce xattr size to 1k
On host systems with ext4 and ea_inode capability not enabled, the max. size
for xattr values is slightly below 4k, which caused the new xattr tests to
fail on such host systems.

Reduce the xattr size for our tests to 1k to prevent them to fail on such
host systems.

Reported-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Fixes: 04a62cdfe8 ("tests/9p: add 3 xattr FID limit test cases (local fs driver)")
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Tested-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/E1wffqw-001Sc8-I9@kylie.crudebyte.com
Signed-off-by: Christian Schoenebeck <qemu_oss@crudebyte.com>
2026-07-25 12:35:24 +02:00
Christian Schoenebeck
7858dbb367 tests/9p: prevent potential error in do_local_xattr_limit()
The local fs backend driver tests require that a dummy file is
created on the host side before running the xattr limit tests,
otherwise the test will fail because the file is expected to exist.

The original call of g_file_set_contents() didn't check its
return value, which might cause subsequent test checks to fail,
making it harder to identify the root cause.

Fix this by simply wrapping the call into a g_assert().

Fixes: 04a62cdfe8 ("tests/9p: add 3 xattr FID limit test cases (local fs driver)")
CID: 1660926
Tested-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/E1wfg2F-001Sfn-Rr@kylie.crudebyte.com
Signed-off-by: Christian Schoenebeck <qemu_oss@crudebyte.com>
2026-07-25 12:35:24 +02:00
Stefan Hajnoczi
300438ffbb trivial patches for 2026-07-24
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmpjNGwACgkQgqpKJDse
 lHgNTQ/9HIA3y8yT624Jk6G89QS++yk4J+uIILBWnPOSL1DxHT3sIpkgZ7eoTDmx
 6ivno8dIssTvBZ9VJBlt6gy1c70KJH2sk4csZ9LA89FoGcm+VpV+hLWoqihiYvkr
 59JGdMqrAqiYT0DXIYFQGUVtwquFPKSifrQv+zR4PwXhm8yMwSMPI4OPWUEm3Nm9
 PTwZrPY07khCdtF4/x5zn4NZoOcolPVP1/cMjY1VaHY350/4HQr2Xh4tL7X/tqfJ
 TBoEzRDIP+ts/xa9KWd2lxi9v7bjZbT9FbqfmmY1iqkd6nOH7hY65UIjxEA0kAP6
 gW74czuBHYLpPnS9z4kC0Zh4oZohaz5e46IcPps5nr8z2DqEJ2HPnV9MCGHKEa8Q
 40P7zlDU17RcvMN9Ymv9TzlPyg/y3MlhwWMDcW+D3l7SX5bCBQXjAdF+fa1njFBk
 A91jr92Z68uYgqEIvlFZJzhdF2X0NWd9SaLnXx9IlIYNOU2dcqoo2yOGlROAwc4s
 goJbLQLWT9+2eyl/l7xrJR0DPDA5QZAQNCnJ6qbCga6jKpJxzIgcfMu+V7sKZJU4
 zfzEzu17uocszZd4apeK24TvJlY6rZfV878oJ31qmikxx9wkWSuThNS1luuu+Esl
 jkDvAGyhmNVHoie5ds1C+AHBTxZyiWk4ipSINS4WB+muC8UWuJA=
 =vHq8
 -----END PGP SIGNATURE-----

Merge tag 'pull-trivial-patches' of https://gitlab.com/mjt0k/qemu into staging

trivial patches for 2026-07-24

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmpjNGwACgkQgqpKJDse
# lHgNTQ/9HIA3y8yT624Jk6G89QS++yk4J+uIILBWnPOSL1DxHT3sIpkgZ7eoTDmx
# 6ivno8dIssTvBZ9VJBlt6gy1c70KJH2sk4csZ9LA89FoGcm+VpV+hLWoqihiYvkr
# 59JGdMqrAqiYT0DXIYFQGUVtwquFPKSifrQv+zR4PwXhm8yMwSMPI4OPWUEm3Nm9
# PTwZrPY07khCdtF4/x5zn4NZoOcolPVP1/cMjY1VaHY350/4HQr2Xh4tL7X/tqfJ
# TBoEzRDIP+ts/xa9KWd2lxi9v7bjZbT9FbqfmmY1iqkd6nOH7hY65UIjxEA0kAP6
# gW74czuBHYLpPnS9z4kC0Zh4oZohaz5e46IcPps5nr8z2DqEJ2HPnV9MCGHKEa8Q
# 40P7zlDU17RcvMN9Ymv9TzlPyg/y3MlhwWMDcW+D3l7SX5bCBQXjAdF+fa1njFBk
# A91jr92Z68uYgqEIvlFZJzhdF2X0NWd9SaLnXx9IlIYNOU2dcqoo2yOGlROAwc4s
# goJbLQLWT9+2eyl/l7xrJR0DPDA5QZAQNCnJ6qbCga6jKpJxzIgcfMu+V7sKZJU4
# zfzEzu17uocszZd4apeK24TvJlY6rZfV878oJ31qmikxx9wkWSuThNS1luuu+Esl
# jkDvAGyhmNVHoie5ds1C+AHBTxZyiWk4ipSINS4WB+muC8UWuJA=
# =vHq8
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri 24 Jul 2026 05:46:20 EDT
# gpg:                using RSA key 64AA2AB531D56903366BFEF982AA4A243B1E9478
# gpg: Good signature from "Michael Tokarev <mjt@debian.org>" [unknown]
# gpg:                 aka "Michael Tokarev <mjt@corpit.ru>" [unknown]
# gpg:                 aka "Michael Tokarev <mjt@tls.msk.ru>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 9D8B E14E 3F2A 9DD7 9199  28F1 61AD 3D98 ECDF 2C8E
#      Subkey fingerprint: 64AA 2AB5 31D5 6903 366B  FEF9 82AA 4A24 3B1E 9478

* tag 'pull-trivial-patches' of https://gitlab.com/mjt0k/qemu:
  hw/ide: replace assert with proper error handling
  hw/usb: record async control completion for parameter transfers
  hw/hyperv/vmbus: Use QEMU_LOCK_GUARD()
  hw/display/vmware_vga: Don't allow guest to trigger long running loop in host
  block/curl: set User-Agent header
  char-win-stdio: fix typo in spelling of 'stdio'
  spelling: happend

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-24 09:13:49 -04:00
Artem Nasonov
443e024106 hw/ide: replace assert with proper error handling
In ide_dma_cb(), the call to prepare_buf() might return a negative
result and cause an assertion failure. This was found during fuzzing
and can be triggered with some qtest commands. Replace the assert with
proper error handling in case the result is negative, but keep the
assert for failing to respect the limit upon success. If that happens,
it is an implementation error.

Found by Linux Verification Center (linuxtesting.org) with libFuzzer.

Cc: qemu-stable@nongnu.org
Fixes: ed78352a59 ("ide: Fix incorrect handling of some PRDTs in ide_dma_cb()")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/2777
Signed-off-by: Artem Nasonov <anasonov@astralinux.ru>
Link: https://lore.kernel.org/qemu-devel/20250116111600.2570490-1-anasonov@astralinux.ru
[FE: improve commit message
     keep assert for failing to respect the limit]
Signed-off-by: Fiona Ebner <f.ebner@proxmox.com>
Reviewed-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
2026-07-24 12:42:11 +03:00
Ziyi Fu
a525551d86 hw/usb: record async control completion for parameter transfers
Record the completion side of parameter-based control transfers when they
complete asynchronously. This lets pcap captures include descriptor
response data for requests such as GET_DESCRIPTOR from usb-host devices.

The synchronous path already recorded the completion, but the async
SETUP_STATE_PARAM path was missing it.

Signed-off-by: Ziyi Fu <ziyi.fu@cyberus-technology.de>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Fixes: 0f6dba145a ("usb: add pcap support.")
Reviewed-by: Michael Tokarev <mjt@tls.msk.ru>
Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
2026-07-24 12:41:56 +03:00
Evgeny Kolmakov
d915f9d607 hw/hyperv/vmbus: Use QEMU_LOCK_GUARD()
Replace manual qemu_mutex_(un)lock() calls with
QEMU_LOCK_GUARD() to remove 'goto out' code

Signed-off-by: Evgeny Kolmakov <randomjack94dev@gmail.com>
Reviewed-by: Maciej S. Szmigiero <maciej.szmigiero@oracle.com>
Reviewed-by: Michael Tokarev <mjt@tls.msk.ru>
Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
2026-07-24 12:28:28 +03:00
Thomas Huth
f604b807a5 hw/display/vmware_vga: Don't allow guest to trigger long running loop in host
The code in the SVGA_CMD_DEFINE_ALPHA_CURSOR handler in vmsvga_fifo_run()
basically does:

            x = vmsvga_fifo_read(s);
            y = vmsvga_fifo_read(s);
            args = x * y;
            goto badcmd;
            ...
badcmd:
            len -= args;
            if (len < 0) {
                goto rewind;
            }
            while (args--) {
                vmsvga_fifo_read(s);
            }

Thus by supplying huge values for x and y that overflow the result of
the multiplication, the guest can trigger a long-running loop here
that burns the host's CPU cycles.

Add some sanity checks so that this cannot happen anymore.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3782
Reported-by: Feifan Qian <bea1e@proton.me>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4026
Reported-by: Tristan Madani <tristan@talencesecurity.com>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4076
Reported-by: Sunday Jiang
Signed-off-by: Thomas Huth <thuth@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Michael Tokarev <mjt@tls.msk.ru>
Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
2026-07-24 12:24:54 +03:00
Vladimir Lobanov
68dd6989ab block/curl: set User-Agent header
Some HTTP servers and WAFs (e.g. Amazon CloudFront) reject
requests without a User-Agent header with 403 Forbidden. This
makes qemu-img info and other curl-based operations fail on
such URLs without any obvious indication of the root cause.

Set a "QEMU/<version>" User-Agent string on all curl handles
to ensure compatibility with these endpoints.

Signed-off-by: Vladimir Lobanov <lobanov-vla@yandex.ru>
Reviewed-by: Michael Tokarev <mjt@tls.msk.ru>
Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
2026-07-23 18:03:24 +03:00
Filip Hejsek
dacbde0ad7 char-win-stdio: fix typo in spelling of 'stdio'
Signed-off-by: Filip Hejsek <filip.hejsek@gmail.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Stefan Weil <sw@weilnetz.de>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Michael Tokarev <mjt@tls.msk.ru>
Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
2026-07-23 18:03:24 +03:00
Michael Tokarev
1667cf6b7d spelling: happend
Fixes: 44adb5fcc2 "target/riscv: Remove spike as default machine"
Fixes: 4881411136 "migration: Always set DEVICE state"
Fixes: 3345fb3b6d "migration/postcopy: Add latency distribution report for blocktime"
Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
2026-07-23 17:57:09 +03:00
Stefan Hajnoczi
006a22cb26 hw/uefi: security fix collection
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEoDKM/7k6F6eZAf59TLbY7tPocTgFAmpgzEYACgkQTLbY7tPo
 cThnDQ/+LLrl0XZ2/xV37yzNNQVrkVdLpRpmDMrzl60mT/mTaG9QKJkVoXRQs2lb
 RvKlVJ0H2F21aicgECLLMVK2jLFaguYuqY3LWbApLm59ddz8VKcQ6/Hzi4mKv2gJ
 oe7RuYQxeMX85o+026htsROnF+/QYGdGeen+jvyX5uvWDjAKNacK9qAkCwviUkvo
 8Xn4773dPiLiuLm17TLZtnrpFNFvMuDkA6nOyUcFcb0ko80pOWZLTkHCDYgQg70H
 xrxuzl872mmChh6Bw65BTpWNYtJP2uCn7QdeW1SaFeRdeEgDN1jJ6Ghg6hZAijiT
 3i61VgXEcHDvUnTAPunGJSAG7AiFM5/biJ40tmbkST0LzvhyGJGLciQnzKwxmfa9
 I45YQ2l63p4TZIOsKBg51hphGJvoKZMI7u0FhTd507fx4thZw8tOdd0eUA5wU61A
 bvUciEGvcm+kwYcd2aaUOwISgPjluB70KfoQw4U8yLZeOn5Yal++6hRGcGrk4Tg6
 gqjASeX8/C3Fd10KppOrpGkG2504EjvbeXVCtUNlhHp4tys5e/Q0GBn3BIW8T7QR
 E3UQIvIlnrAnN/ciDcBJqjx0VLel/UxMufV9EGcu5UWvsU4AK0kjIq/zTUq0KOVl
 /Bcyjt6gqGU2Ozhj/aXSBdK2vhtzXlUPvmTNbRUwg18jbQErVg8=
 =mm3O
 -----END PGP SIGNATURE-----

Merge tag 'firmware-20260722-pull-request' of https://gitlab.com/kraxel/qemu into staging

hw/uefi: security fix collection

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEoDKM/7k6F6eZAf59TLbY7tPocTgFAmpgzEYACgkQTLbY7tPo
# cThnDQ/+LLrl0XZ2/xV37yzNNQVrkVdLpRpmDMrzl60mT/mTaG9QKJkVoXRQs2lb
# RvKlVJ0H2F21aicgECLLMVK2jLFaguYuqY3LWbApLm59ddz8VKcQ6/Hzi4mKv2gJ
# oe7RuYQxeMX85o+026htsROnF+/QYGdGeen+jvyX5uvWDjAKNacK9qAkCwviUkvo
# 8Xn4773dPiLiuLm17TLZtnrpFNFvMuDkA6nOyUcFcb0ko80pOWZLTkHCDYgQg70H
# xrxuzl872mmChh6Bw65BTpWNYtJP2uCn7QdeW1SaFeRdeEgDN1jJ6Ghg6hZAijiT
# 3i61VgXEcHDvUnTAPunGJSAG7AiFM5/biJ40tmbkST0LzvhyGJGLciQnzKwxmfa9
# I45YQ2l63p4TZIOsKBg51hphGJvoKZMI7u0FhTd507fx4thZw8tOdd0eUA5wU61A
# bvUciEGvcm+kwYcd2aaUOwISgPjluB70KfoQw4U8yLZeOn5Yal++6hRGcGrk4Tg6
# gqjASeX8/C3Fd10KppOrpGkG2504EjvbeXVCtUNlhHp4tys5e/Q0GBn3BIW8T7QR
# E3UQIvIlnrAnN/ciDcBJqjx0VLel/UxMufV9EGcu5UWvsU4AK0kjIq/zTUq0KOVl
# /Bcyjt6gqGU2Ozhj/aXSBdK2vhtzXlUPvmTNbRUwg18jbQErVg8=
# =mm3O
# -----END PGP SIGNATURE-----
# gpg: Signature made Wed 22 Jul 2026 09:57:26 EDT
# gpg:                using RSA key A0328CFFB93A17A79901FE7D4CB6D8EED3E87138
# gpg: Good signature from "Gerd Hoffmann (work) <kraxel@redhat.com>" [full]
# gpg:                 aka "Gerd Hoffmann <gerd@kraxel.org>" [full]
# gpg:                 aka "Gerd Hoffmann (private) <kraxel@gmail.com>" [full]
# Primary key fingerprint: A032 8CFF B93A 17A7 9901  FE7D 4CB6 D8EE D3E8 7138

* tag 'firmware-20260722-pull-request' of https://gitlab.com/kraxel/qemu:
  hw/uefi: make SetupMode read-only
  hw/uefi: add post_load checks
  hw/uefi: account variable policy entries against storage size
  hw/uefi: check lower limit for signature list size
  hw/uefi: remove debug function
  hw/uefi: add sanity check

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-22 11:17:49 -04:00
Stefan Hajnoczi
c6bac4e201 * meson: propagate qemu_ldflags to Rust link step
* target/i386: helper_sysret(): Check that RCX contains a canonical address when emulating an Intel CPU
 * target/i386: tcg: remove FIXME
 * scsi-disk: protect against guest sending truncated data for MODE SELECT commands
 * scsi-disk: fix off by one in assertion
 -----BEGIN PGP SIGNATURE-----
 
 iQFIBAABCgAyFiEE8TM4V0tmI4mGbHaCv/vSX3jHroMFAmpgcwoUHHBib256aW5p
 QHJlZGhhdC5jb20ACgkQv/vSX3jHroPfhwf+PLJ73Xf71TyKsRp0q+aEBHuT0v+h
 KYSAzjqhKF3MvzTJXm/NBpnCQjxQ1FCypwcUvbDF/amOBjP/FQnFUORZMrFNkRIr
 LQqnuI4SSLkYBsx+/uCnZ2WsoELh0te/I/WqhjuimUhjQau93qLPByBaE0p3ifl6
 kWqeq7lgiLFSgJxOZPXfyFZPmYvfLQatO0LVArydkcNjIMhPi1sZ2ZEBrqbV/QnA
 pEpKkbeiS2t7x/kYCQ+X2scLiReWfVz1VHnufSI6L8+8/S4UE1Y3FaQcyfuPFFBC
 urgInhQqjrs+2e9BQa14yD5A4G9gYOn1+vL6yB/aJ2bYlvPxhw/u7XojNQ==
 =mZw/
 -----END PGP SIGNATURE-----

Merge tag 'for-upstream' of https://gitlab.com/bonzini/qemu into staging

* meson: propagate qemu_ldflags to Rust link step
* target/i386: helper_sysret(): Check that RCX contains a canonical address when emulating an Intel CPU
* target/i386: tcg: remove FIXME
* scsi-disk: protect against guest sending truncated data for MODE SELECT commands
* scsi-disk: fix off by one in assertion

# -----BEGIN PGP SIGNATURE-----
#
# iQFIBAABCgAyFiEE8TM4V0tmI4mGbHaCv/vSX3jHroMFAmpgcwoUHHBib256aW5p
# QHJlZGhhdC5jb20ACgkQv/vSX3jHroPfhwf+PLJ73Xf71TyKsRp0q+aEBHuT0v+h
# KYSAzjqhKF3MvzTJXm/NBpnCQjxQ1FCypwcUvbDF/amOBjP/FQnFUORZMrFNkRIr
# LQqnuI4SSLkYBsx+/uCnZ2WsoELh0te/I/WqhjuimUhjQau93qLPByBaE0p3ifl6
# kWqeq7lgiLFSgJxOZPXfyFZPmYvfLQatO0LVArydkcNjIMhPi1sZ2ZEBrqbV/QnA
# pEpKkbeiS2t7x/kYCQ+X2scLiReWfVz1VHnufSI6L8+8/S4UE1Y3FaQcyfuPFFBC
# urgInhQqjrs+2e9BQa14yD5A4G9gYOn1+vL6yB/aJ2bYlvPxhw/u7XojNQ==
# =mZw/
# -----END PGP SIGNATURE-----
# gpg: Signature made Wed 22 Jul 2026 03:36:42 EDT
# gpg:                using RSA key F13338574B662389866C7682BFFBD25F78C7AE83
# gpg:                issuer "pbonzini@redhat.com"
# gpg: Good signature from "Paolo Bonzini <bonzini@gnu.org>" [full]
# gpg:                 aka "Paolo Bonzini <pbonzini@redhat.com>" [full]
# Primary key fingerprint: 46F5 9FBD 57D6 12E7 BFD4  E2F7 7E15 100C CD36 69B1
#      Subkey fingerprint: F133 3857 4B66 2389 866C  7682 BFFB D25F 78C7 AE83

* tag 'for-upstream' of https://gitlab.com/bonzini/qemu:
  scsi-disk: fix off by one in assertion
  scsi-disk: protect against guest sending truncated data for MODE SELECT commands
  target/i386: helper_sysret(): Check that RCX contains a canonical address when emulating an Intel CPU
  meson: propagate qemu_ldflags to Rust link step
  target/i386: tcg: remove FIXME

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-22 11:17:29 -04:00
Stefan Hajnoczi
b2e5620b4f vfio queue:
* Fix IGD legacy VBIOS ROM to clear saved BDSM at load time, avoiding
   garbled BIOS POST output
 * Clarify dma-buf failure messages for P2P DMA
 * Fix config read error handling and reject invalid PCI_INTERRUPT_PIN
   values in vfio/pci
 * Harden vfio-user: prevent buffer overflows, excessive mallocs, and
   fix region info capability check
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEoPZlSPBIlev+awtgUaNDx8/77KEFAmpfppcACgkQUaNDx8/7
 7KHf7g/+LY4BptviNUX5XKYdCZKPiLSTDL5mejuU5ynu5b2WeHNqu9Iuml9B5k7a
 6ZWDcdp2OqaZehIgJcpn9XHA4sXT9EXan0z4+W5K2ZauMKLinxCq2oXYmz38YJCh
 IPn8i7LpBJ94U02Vcqd/EDoRHeV9/4RcapqukuU67TYL5d31NP2IpXQqqOFhawWQ
 kVqCvT1hl9IntRAgZdhERrz3BF7v4cgFhRPWMBhlUTbXvpWJBOAmZuPao9QyAXCE
 VA1cjGtE/dM1g/z/8N+Ok5vOWeh/7ajPCzmZAC1JCsdCIyVe+N7nxfg5P2SvvmDj
 j0cbj6KXLA8JXt/f3oDO813Ji+TNYY5FYSPcMlHTBO2uXAOCIuZb+RpIWV4xPsrv
 HqinRGG/BSbusU69v/W6bPJAK4DfJnNrnXckCj7qcGpmVJ/gqfen1qCmnacvql87
 tlNJQEyqTZEPcb2BEqEvCWOX7xKoq9+rRsnn0vOAoYIQiJHBoEDxkhbbmHcW++t9
 Tl+HAAqK3oaynMIi6zBcgL75G+CgUo/DAWpms4w0vl0hmP5R1I+lDobd3GFNcBO2
 rPsj4CZxxX6fvP4XZ/c81TWPgY4z0SkBDPNktjPM4fW2dhyHSEwn2Wz32iD8HSwv
 XtPdm7f8CTbAXRhKQU6XjnGizhn8XeICwqXfRTZCPqtKNCIklH0=
 =/TnF
 -----END PGP SIGNATURE-----

Merge tag 'pull-vfio-20260721' of https://github.com/legoater/qemu into staging

vfio queue:

* Fix IGD legacy VBIOS ROM to clear saved BDSM at load time, avoiding
  garbled BIOS POST output
* Clarify dma-buf failure messages for P2P DMA
* Fix config read error handling and reject invalid PCI_INTERRUPT_PIN
  values in vfio/pci
* Harden vfio-user: prevent buffer overflows, excessive mallocs, and
  fix region info capability check

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEEoPZlSPBIlev+awtgUaNDx8/77KEFAmpfppcACgkQUaNDx8/7
# 7KHf7g/+LY4BptviNUX5XKYdCZKPiLSTDL5mejuU5ynu5b2WeHNqu9Iuml9B5k7a
# 6ZWDcdp2OqaZehIgJcpn9XHA4sXT9EXan0z4+W5K2ZauMKLinxCq2oXYmz38YJCh
# IPn8i7LpBJ94U02Vcqd/EDoRHeV9/4RcapqukuU67TYL5d31NP2IpXQqqOFhawWQ
# kVqCvT1hl9IntRAgZdhERrz3BF7v4cgFhRPWMBhlUTbXvpWJBOAmZuPao9QyAXCE
# VA1cjGtE/dM1g/z/8N+Ok5vOWeh/7ajPCzmZAC1JCsdCIyVe+N7nxfg5P2SvvmDj
# j0cbj6KXLA8JXt/f3oDO813Ji+TNYY5FYSPcMlHTBO2uXAOCIuZb+RpIWV4xPsrv
# HqinRGG/BSbusU69v/W6bPJAK4DfJnNrnXckCj7qcGpmVJ/gqfen1qCmnacvql87
# tlNJQEyqTZEPcb2BEqEvCWOX7xKoq9+rRsnn0vOAoYIQiJHBoEDxkhbbmHcW++t9
# Tl+HAAqK3oaynMIi6zBcgL75G+CgUo/DAWpms4w0vl0hmP5R1I+lDobd3GFNcBO2
# rPsj4CZxxX6fvP4XZ/c81TWPgY4z0SkBDPNktjPM4fW2dhyHSEwn2Wz32iD8HSwv
# XtPdm7f8CTbAXRhKQU6XjnGizhn8XeICwqXfRTZCPqtKNCIklH0=
# =/TnF
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 21 Jul 2026 13:04:23 EDT
# gpg:                using RSA key A0F66548F04895EBFE6B0B6051A343C7CFFBECA1
# gpg: Good signature from "Cédric Le Goater <clg@redhat.com>" [full]
# gpg:                 aka "Cédric Le Goater <clg@kaod.org>" [full]
# Primary key fingerprint: A0F6 6548 F048 95EB FE6B  0B60 51A3 43C7 CFFB ECA1

* tag 'pull-vfio-20260721' of https://github.com/legoater/qemu:
  vfio-user: vfio_user_device_io_set_irqs: prevent excessive malloc
  vfio-user: vfio_user_device_io_set_irqs: prevent buffer overflow
  vfio-user: vfio_user_device_io_device_feature: prevent excessive malloc
  vfio-user: vfio_user_device_io_device_feature: prevent buffer overflow
  vfio-user: vfio_user_device_io_get_region_info: fix capability check
  vfio-user: vfio_user_get_region_info: prevent excessive malloc
  vfio-user: vfio_user_get_region_info: reject unreasonably short struct
  vfio-user: vfio_user_get_region_info: respect max_xfer_size
  vfio-user: vfio_user_get_region_info: prevent buffer overflow
  vfio/pci: reject invalid PCI_INTERRUPT_PIN values
  vfio/pci: don't narrow a failed config read to a plausible value
  vfio/region: Clarify dma-buf failure messages
  vfio/igd: Clear saved BDSM in legacy VBIOS ROM at load time

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-22 11:17:02 -04:00
Stefan Hajnoczi
6eb5f75e6f * Update FreeBSD image to 14.4
* Fix inotify test for FreeBSD 15
 * Fix crypt/nettle build option argument handling
 * Add tracking & reporting of GitLab account handles for maintainers
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEEOSEivHoFu8YQee2OpU5XPKwd8GwFAmpflkgACgkQpU5XPKwd
 8GxlYhAAk0BsuWP3BW5MXcpNJ4qP3jVq4jIdNGKYove+9WgAUbItk50RSZ8duDgG
 dccreY7VC9VDvdTc2FrIFZmmZSMsPKqWaUDx6BIqWXZAAd0qy+Ez2CtFBu4V1q++
 6uu4YkBI3z1zwNszSxP9E80b2gufDTgfZhxAlCQT/Oj1OTPY/3YsxNOVBs6sETTY
 FTMzBM7K5zjoPO0oC0Qj18Vd81/ifs2SKzRWFDqo/kZic3wJLI0fAWd2WMyzihwk
 svIbbLBEvUhVlJyDcKyzOfTBzcUZYjbbXsOBmSkoqRCRvJUtAvRzW5Gb9amv25nq
 A80rgTgA/ebUUwJQ/2cXJuuX/E3pUZL4+LfMBAFCANhM8DklWhVAy5bNz3smnWIq
 WF4Pd75bcW/J0vzPbIH7rxkwAJKIO3UonZcvJM3IcjDX/VP9HkY491sn9aXyeJES
 UaC/NA9FK/w1VMFefjXbInD7/Idza8uQWDtL/EQzkG28mc4SqZwrbKcQYL3kazlW
 SRz+UxMvNh79D1MI2+0yCuFPDwkY8LVpIqlS0tutSCk6xc9MAukTLnCum+4m//5k
 ZiP0HmIVUqaLnlzSVERrzD9mZEl92sLWwEvwrLxa7np/3A6ZJxSE+zarpJFbgEsB
 9JgNQZWa+4kWeoeJE93vgsvximsIyx3UMWuNQdi4Xy1lkSi8qcI=
 =Jp4q
 -----END PGP SIGNATURE-----

Merge tag 'misc-next-pull-request' of https://gitlab.com/berrange/qemu into staging

* Update FreeBSD image to 14.4
* Fix inotify test for FreeBSD 15
* Fix crypt/nettle build option argument handling
* Add tracking & reporting of GitLab account handles for maintainers

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEEOSEivHoFu8YQee2OpU5XPKwd8GwFAmpflkgACgkQpU5XPKwd
# 8GxlYhAAk0BsuWP3BW5MXcpNJ4qP3jVq4jIdNGKYove+9WgAUbItk50RSZ8duDgG
# dccreY7VC9VDvdTc2FrIFZmmZSMsPKqWaUDx6BIqWXZAAd0qy+Ez2CtFBu4V1q++
# 6uu4YkBI3z1zwNszSxP9E80b2gufDTgfZhxAlCQT/Oj1OTPY/3YsxNOVBs6sETTY
# FTMzBM7K5zjoPO0oC0Qj18Vd81/ifs2SKzRWFDqo/kZic3wJLI0fAWd2WMyzihwk
# svIbbLBEvUhVlJyDcKyzOfTBzcUZYjbbXsOBmSkoqRCRvJUtAvRzW5Gb9amv25nq
# A80rgTgA/ebUUwJQ/2cXJuuX/E3pUZL4+LfMBAFCANhM8DklWhVAy5bNz3smnWIq
# WF4Pd75bcW/J0vzPbIH7rxkwAJKIO3UonZcvJM3IcjDX/VP9HkY491sn9aXyeJES
# UaC/NA9FK/w1VMFefjXbInD7/Idza8uQWDtL/EQzkG28mc4SqZwrbKcQYL3kazlW
# SRz+UxMvNh79D1MI2+0yCuFPDwkY8LVpIqlS0tutSCk6xc9MAukTLnCum+4m//5k
# ZiP0HmIVUqaLnlzSVERrzD9mZEl92sLWwEvwrLxa7np/3A6ZJxSE+zarpJFbgEsB
# 9JgNQZWa+4kWeoeJE93vgsvximsIyx3UMWuNQdi4Xy1lkSi8qcI=
# =Jp4q
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 21 Jul 2026 11:54:48 EDT
# gpg:                using RSA key 392122BC7A05BBC61079ED8EA54E573CAC1DF06C
# gpg: Good signature from "Daniel P. Berrange <dan@berrange.com>" [full]
# gpg:                 aka "Daniel P. Berrange <berrange@redhat.com>" [full]
# Primary key fingerprint: DAF3 A6FD B26B 6291 2D0E  8E3F BE86 EBB4 1510 4FDF
#      Subkey fingerprint: 3921 22BC 7A05 BBC6 1079  ED8E A54E 573C AC1D F06C

* tag 'misc-next-pull-request' of https://gitlab.com/berrange/qemu:
  get_maintainer: add ability to report Git Lab handle
  gitlab: introduce files mapping GitLab accounts to real names
  meson.build: re-add explicit gcrypt/nettle request check
  tests/vm: update to FreeBSD 14.4 image
  test-util-filemonitor: Adapt to FreeBSD 15's native inotify semantics

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-22 11:16:31 -04:00
Gerd Hoffmann
bd9b3c50f4 hw/uefi: make SetupMode read-only
This is read-only variable which informs the OS about the
secure boot state.  Reject any attempts to write to it.

Fixes: CVE-2026-16288
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4039
Acked-by: Luigi Leonardi <leonardi@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Message-ID: <20260720143244.821889-7-kraxel@redhat.com>
2026-07-22 15:22:40 +02:00
Gerd Hoffmann
acba2d7817 hw/uefi: add post_load checks
Add sanity checks to uefi-vars state loaded from live migration data
stream.  Fail migration if invalid data or inconsistencies are found.

Fixes: CVE-2026-61404
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3837
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3838
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3839
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3885
Acked-by: Luigi Leonardi <leonardi@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Message-ID: <20260720143244.821889-6-kraxel@redhat.com>
2026-07-22 15:22:40 +02:00
Gerd Hoffmann
8e0ddb4a6e hw/uefi: account variable policy entries against storage size
uefi-vars already tracks (and limits) the memory footprint of UEFI
variables.  Do that for variable policies too.

Fixes: CVE-2026-61405
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3890
Acked-by: Luigi Leonardi <leonardi@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Message-ID: <20260720143244.821889-5-kraxel@redhat.com>
2026-07-22 12:28:46 +02:00
Gerd Hoffmann
647ba95eda hw/uefi: check lower limit for signature list size
Specifically disallow zero which can lead to an endless loop.

Fixes: CVE-2026-61406
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3899
Acked-by: Luigi Leonardi <leonardi@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Message-ID: <20260720143244.821889-4-kraxel@redhat.com>
2026-07-22 12:28:46 +02:00
Gerd Hoffmann
ff5a9eb13c hw/uefi: remove debug function
This was never meant to be present in production builds.  It's a code
path not hit on a normal boot (OVMF wouldn't try variable updates which
are not allowed), so this went unnoticed.

Remove the function.  If needed for debugging the git log is your
friend.

Fixes: CVE-2026-58582
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3615
Acked-by: Luigi Leonardi <leonardi@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Message-ID: <20260720143244.821889-3-kraxel@redhat.com>
2026-07-22 12:28:46 +02:00
Gerd Hoffmann
702216619e hw/uefi: add sanity check
Verify the passed buffer has the minimal required length before
reading the size field + verifying the total length.

Fixes: CVE-2026-58581
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3614
Acked-by: Luigi Leonardi <leonardi@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Message-ID: <20260720143244.821889-2-kraxel@redhat.com>
2026-07-22 12:28:46 +02:00
Paolo Bonzini
e2da3d9274 scsi-disk: fix off by one in assertion
When documenting the invariant that mode pages need to fit the smallest
output buffer of all callers (which is SCSI_MAX_MODE_LEN), the expression
used by the assertion was incorrect.

Even though SCSI_MAX_MODE_LEN is indeed 256, using "length < 256" had
two issues: 1) it used the wrong operator, since "length < ..." is more
related to having room for extra data; 2) it missed the extra two bytes
for page number and length.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-07-22 09:36:02 +02:00
Paolo Bonzini
d149a11c6c scsi-disk: protect against guest sending truncated data for MODE SELECT commands
scsi-disk has a MODE SELECT path where a truncated mode page can be
allowed by a compatibility quirk, but the parser continues to use the
page's declared length rather than the number of bytes actually remaining
in the request buffer.  This means that scsi_disk_check_mode_select() and
scsi_disk_apply_mode_select() can read beyond the valid part of inbuf[],
potentially up to the emulated age's length.

Clamping page_len (the size of the page) to len (whatever the
guest provided) ensures that scsi_disk_check_mode_select() and
scsi_disk_apply_mode_select() do not access anything beyond bounds;
however, this requires care to accept and handle truncated input in
those two functions.

In particular, until scsi_disk_check_mode_select()'s first call to
mode_sense_page() the number of bytes to be cleared in mode_current[] is
unknown, so zero it completely.  And for everything else, be conservative
and use len when providing inputs to other functions; but at the same time,
ensure all accesses to inbuf[] are bound by expected_len.

Note that pages longer than the emulated one are still rejected.

Fixes: 389e18eb9a ("scsi-disk: add SCSI_DISK_QUIRK_MODE_PAGE_TRUNCATED quirk for Macintosh")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4051
Tested-by: Mark Cave-Ayland <mark.cave-ayland@ilande.co.uk>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-07-22 09:35:44 +02:00
Stefan Hajnoczi
cbd42e2b75 Update version for v11.1.0-rc1 release
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-21 13:18:25 -04:00
Stefan Hajnoczi
0a71e84dd0 Changes:
- [PATCH] docs: fix sphinx build failure (Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>)
   Link: https://lore.kernel.org/qemu-devel/20260720222717.33078-1-pierrick.bouvier@oss.qualcomm.com
 -----BEGIN PGP SIGNATURE-----
 
 iQGzBAABCgAdFiEEN8FWlNi6l2Sxlz/btEQ30ZwoYt8FAmpfo7UACgkQtEQ30Zwo
 Yt8lZAwAiHwARWTSDMDi2VIfEqbFC7O3wvPuuN6hNURPrFHNaAuJVgo40ADuxAWk
 4fNtUiORC62/9XBDFKoD5DlqHwPjzB7eU+2vNP+BudtP/bRJjPolf+EjHx0ltwD7
 OYWw1qf2YTagOvqweyYUnBTKTF3BZaYGnBAlH8IXPL7HXYBZMSuzxDwK0vAAB4+q
 rZQWYUaEBOadLB+1FntcBYmGALFYmIqS+Un80fkTLgW+QjNOgG3bUGeqGfTL/qs7
 arlSEzFLCJYXuBBM//FxE9XWI4gTo5W/RbcszksNnxiP9WbdMOoevdjFepHS2+JQ
 0tNMe2jxpakTriC7rO1JqRyuppCeS9f2HMjW2+22BPAnYF9eNRmXzQ6deKvnQoyH
 Im+DKcKhYWLDjFPAhF/KX4N+97U80MjnpIQuMT+YboGCOxPbptwwvo7zQZt88xN7
 mSyAE4BMbYLLyZZMouH8h+0J/buJUH3168GGgUaYdIyXn0i1zp+UKJCJFdzmHe5A
 ogg078TG
 =vXrS
 -----END PGP SIGNATURE-----

Merge tag 'pbouvier/pr/docs-20260721' of https://gitlab.com/p-b-o/qemu into staging

Changes:
- [PATCH] docs: fix sphinx build failure (Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>)
  Link: https://lore.kernel.org/qemu-devel/20260720222717.33078-1-pierrick.bouvier@oss.qualcomm.com

# -----BEGIN PGP SIGNATURE-----
#
# iQGzBAABCgAdFiEEN8FWlNi6l2Sxlz/btEQ30ZwoYt8FAmpfo7UACgkQtEQ30Zwo
# Yt8lZAwAiHwARWTSDMDi2VIfEqbFC7O3wvPuuN6hNURPrFHNaAuJVgo40ADuxAWk
# 4fNtUiORC62/9XBDFKoD5DlqHwPjzB7eU+2vNP+BudtP/bRJjPolf+EjHx0ltwD7
# OYWw1qf2YTagOvqweyYUnBTKTF3BZaYGnBAlH8IXPL7HXYBZMSuzxDwK0vAAB4+q
# rZQWYUaEBOadLB+1FntcBYmGALFYmIqS+Un80fkTLgW+QjNOgG3bUGeqGfTL/qs7
# arlSEzFLCJYXuBBM//FxE9XWI4gTo5W/RbcszksNnxiP9WbdMOoevdjFepHS2+JQ
# 0tNMe2jxpakTriC7rO1JqRyuppCeS9f2HMjW2+22BPAnYF9eNRmXzQ6deKvnQoyH
# Im+DKcKhYWLDjFPAhF/KX4N+97U80MjnpIQuMT+YboGCOxPbptwwvo7zQZt88xN7
# mSyAE4BMbYLLyZZMouH8h+0J/buJUH3168GGgUaYdIyXn0i1zp+UKJCJFdzmHe5A
# ogg078TG
# =vXrS
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 21 Jul 2026 12:52:05 EDT
# gpg:                using RSA key 37C15694D8BA9764B1973FDBB44437D19C2862DF
# gpg: Good signature from "Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 37C1 5694 D8BA 9764 B197  3FDB B444 37D1 9C28 62DF

* tag 'pbouvier/pr/docs-20260721' of https://gitlab.com/p-b-o/qemu:
  docs: fix sphinx build failure

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-21 13:17:59 -04:00
Pierrick Bouvier
c3662589c4 docs: fix sphinx build failure
We recently started to have those failures appearing when building
documentation. It's hard to identify if it comes from a python, sphinx
or sphinx extension, but it blocks us.

Exception occurred:
  File "/usr/lib/python3.13/multiprocessing/connection.py", line 399, in _recv
    raise EOFError
EOFError
The full traceback has been saved in /tmp/sphinx-*.log, if you want to report the issue to the developers.

This seems to be the generic error message for "something went wrong in
sphinx multiprocess":
- https://github.com/sphinx-doc/sphinx/issues/11449
- https://github.com/sphinx-doc/sphinx/issues/14458
- https://github.com/sphinx-doc/sphinx/issues/8973

Solve the issue by simply going back to sequential builds. We didn't
notice a huge speedup anyway.

Reviewed-by: Stefan Hajnoczi <stefanha@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260720222717.33078-1-pierrick.bouvier@oss.qualcomm.com
Signed-off-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
2026-07-21 16:50:55 +00:00
Andrey Polivoda
51aa3f3e05 target/i386: helper_sysret(): Check that RCX contains a canonical address when emulating an Intel CPU
Intel and AMD CPUs implement SYSRETQ instruction differently.
One of these differences is whether a canonicality check of the address that
will be loaded to RIP is performed: Intel CPUs do this check, AMD CPUs don't.

Currently, QEMU does not perform this check when emulating Intel CPUs.
This patch corrects this by implementing the canonlicality check on a new RIP
value from RCX and performing it only when emulating Intel CPUs.

Flags and segment registers' caches are updated only after checking the new RIP
value to ensure that CPU state is not modified in case the #GP(0) exception
is raised due to the check failure.

Cc: qemu-devel@nongnu.org
Cc: Paolo Bonzini <pbonzini@redhat.com>
Cc: Richard Henderson <richard.henderson@linaro.org>
Fixes: 14ce26e755 ("x86_64 target support")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3223
Signed-off-by: Andrey Polivoda <apolivodaa433@gmail.com>
Link: https://lore.kernel.org/r/20260608091815.31303-1-apolivodaa433@gmail.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-07-21 18:04:36 +02:00
Brian Cain
0e48aaae73 meson: propagate qemu_ldflags to Rust link step
Sanitizer flags are added to qemu_ldflags and applied globally for
all_languages, but all_languages never includes 'rust'.

Fixes link errors like the ones below:

    -Wl,-rpath,$ORIGIN/../qemu-macros:<sysroot>/lib/rustlib/x86_64-unknown-linux-gnu/lib"
      = note: some arguments are omitted. use `--verbose` to show all linker arguments
      = note: rust-lld: error: undefined symbol: __ubsan_handle_type_mismatch_v1
              >>> referenced by event-loop-base.c:104 (../qemu_before_fix/event-loop-base.c:104)
              >>>               libevent-loop-base.a.p/event-loop-base.c.o:(event_loop_base_class_init)
              >>> referenced by event-loop-base.c:105 (../qemu_before_fix/event-loop-base.c:105)
              >>>               libevent-loop-base.a.p/event-loop-base.c.o:(event_loop_base_class_init)
              >>> referenced by event-loop-base.c:58 (../qemu_before_fix/event-loop-base.c:58)
              >>>               libevent-loop-base.a.p/event-loop-base.c.o:(event_loop_base_set_param)
              >>> referenced 11240 more times

Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260714021236.2361604-1-brian.cain@oss.qualcomm.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-07-21 18:04:36 +02:00
Paolo Bonzini
21069e6b35 target/i386: tcg: remove FIXME
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-07-21 18:04:36 +02:00
Thanos Makatos
aef1e7c5ec vfio-user: vfio_user_device_io_set_irqs: prevent excessive malloc
This isn't in practise a problem since irq->argsz is not externally
provided, it's a good hardening step nonetheless.

Fixes: ca1add1696 ("vfio-user: implement VFIO_USER_DEVICE_GET/SET_IRQ*")
Signed-off-by: Thanos Makatos <thanos.makatos@nutanix.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-10-thanos.makatos@nutanix.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Thanos Makatos
bf10c11af5 vfio-user: vfio_user_device_io_set_irqs: prevent buffer overflow
This isn't in practise a problem since irq->argsz is not
externally provided, it's a good hardening step nonetheless.

Fixes: ca1add1696 ("vfio-user: implement VFIO_USER_DEVICE_GET/SET_IRQ*")
Signed-off-by: Thanos Makatos <thanos.makatos@nutanix.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-9-thanos.makatos@nutanix.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Thanos Makatos
761ac964a8 vfio-user: vfio_user_device_io_device_feature: prevent excessive malloc
This isn't in practise a problem since feature->argsz is not externally
provided, it's a good hardening step nonetheless.

Fixes: e2358af583 ("vfio-user: support VFIO_USER_DEVICE_FEATURE")
Signed-off-by: Thanos Makatos <thanos.makatos@nutanix.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-8-thanos.makatos@nutanix.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Thanos Makatos
5f0cbed64c vfio-user: vfio_user_device_io_device_feature: prevent buffer overflow
This isn't in practise a problem since feature->argsz is not
externally provided, it's a good hardening step nonetheless.

Fixes: e2358af583 ("vfio-user: support VFIO_USER_DEVICE_FEATURE")
Signed-off-by: Thanos Makatos <thanos.makatos@nutanix.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-7-thanos.makatos@nutanix.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Thanos Makatos
20b3a363fa vfio-user: vfio_user_device_io_get_region_info: fix capability check
The existing check for PCI capabilities misses the case where
info->cap_offset == info->argsz, which results in accessing unallocated
memory. Fix the comparison.

Fixes: 667866d666 ("vfio-user: implement VFIO_USER_DEVICE_GET_REGION_INFO")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3865
Signed-off-by: Thanos Makatos <thanos.makatos@nutanix.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-6-thanos.makatos@nutanix.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Thanos Makatos
6a51aab908 vfio-user: vfio_user_get_region_info: prevent excessive malloc
If the vfio-user server responds with a value larger than max_xfer_size
vfio_device_get_region_info() blindly uses it in the next loop in
g_realloc. An value larger than max_xfer_size is anyway rejected by the
check at the beginning of vfio_user_get_region_info(), however that only
happens _after_ the g_realloc, and if that value is excessively large it
can cause g_realloc to fail, so check it here.

Signed-off-by: Thanos Makatos <thanos.makatos@nutanix.com>
Fixes: 667866d666 ("vfio-user: implement VFIO_USER_DEVICE_GET_REGION_INFO")
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-5-thanos.makatos@nutanix.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Thanos Makatos
3966a4258b vfio-user: vfio_user_get_region_info: reject unreasonably short struct
While this isn't technically a bug, it's highly unlikely that the
server wouldn't be writing an entire struct.

Signed-off-by: Thanos Makatos <thanos.makatos@nutanix.com>
Fixes: 667866d666 ("vfio-user: implement VFIO_USER_DEVICE_GET_REGION_INFO")
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-4-thanos.makatos@nutanix.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Thanos Makatos
152f7dd3b0 vfio-user: vfio_user_get_region_info: respect max_xfer_size
Signed-off-by: Thanos Makatos <thanos.makatos@nutanix.com>
Fixes: 667866d666 ("vfio-user: implement VFIO_USER_DEVICE_GET_REGION_INFO")
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-3-thanos.makatos@nutanix.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Thanos Makatos
f6a321c94b vfio-user: vfio_user_get_region_info: prevent buffer overflow
If the vfio-user responds with a value large enough such that adding
the header size to it overflows, a smaller buffer would be
inadvertently allocated, leading to buffer overflow.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3867
Signed-off-by: Thanos Makatos <thanos.makatos@nutanix.com>
Fixes: 667866d666 ("vfio-user: implement VFIO_USER_DEVICE_GET_REGION_INFO")
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-2-thanos.makatos@nutanix.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Denis V. Lunev
86abb10256 vfio/pci: reject invalid PCI_INTERRUPT_PIN values
qemu-kvm aborts a few seconds after starting a VM with a
passed-through GPU whose PCI_INTERRUPT_PIN comes back as an
out-of-range value: vfio_intx_enable() only guards against pin == 0
and stores vdev->intx.pin = pin - 1 with no upper-bound check. That
value later reaches pci_irq_handler()'s
assert(0 <= irq_num && irq_num < PCI_NUM_PINS) via
pci_irq_deassert() -> pci_set_irq(), aborting the process.

Legal PCI_INTERRUPT_PIN values are 0 (no legacy interrupt) or
1-PCI_NUM_PINS (INTA-INTD); reject anything else before it reaches
vdev->intx.pin, whether the out-of-range value came from a read
failure (now caught by the previous commit) or was handed back as
data by the device itself.

Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Alex Williamson <alex@shazbot.org>
CC: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260717122232.468955-3-den@openvz.org
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Denis V. Lunev
dff528657f vfio/pci: don't narrow a failed config read to a plausible value
vfio_pci_read_config() signals a failed host-side read by returning
(uint32_t)-1, regardless of the requested length. vfio_intx_enable()
and vfio_pci_pre_reset() both narrowed that return value straight
into a uint8_t/uint16_t local before checking anything, which
truncates -1 into 0xff or 0xffff - values a real 1- or 2-byte
register read can legitimately produce. From that point on, a
failed read and real all-ones content are indistinguishable.

Keep the full uint32_t result and check it against (uint32_t)-1
before narrowing. In vfio_pci_pre_reset(), skip the corresponding
write-back on a failed read instead of writing back constructed
garbage to the device.

Resolves: Coverity CID 1663684
Resolves: Coverity CID 1663688
Signed-off-by: Denis V. Lunev <den@openvz.org>
CC: Alex Williamson <alex@shazbot.org>
CC: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260717122232.468955-2-den@openvz.org
[ clg: Added Coverity IDs ]
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Cédric Le Goater
4b2e6505d5 vfio/region: Clarify dma-buf failure messages
The dma-buf failure messages in vfio_region_create_dma_buf() say "PCI
BAR IOMMU mappings may fail", which suggests the BAR is broken. In
practice, only P2P DMA is affected -- normal passthrough uses the mmap
fallback.

Reword both messages to mention P2P DMA explicitly and clarify that
the mmap fallback is in use. Use warn_report_err_once() at the call
site so per-BAR repetition on mdev devices is suppressed.

Fixes: dcf1b77e834d ("hw/vfio/region: Create dmabuf for PCI BAR per region")
Cc: Nicolin Chen <nicolinc@nvidia.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Tomita Moeko
256229e8f9 vfio/igd: Clear saved BDSM in legacy VBIOS ROM at load time
IGD does not come with a ROM BAR [1], the ROM BAR read by default from
kernel is actually the host VBIOS shadow RAM region that contains host
modifications on boot. With AI-assisted reverse engineering on VBIOS
binaries, it is observed that VBIOS saves BDSM register value on first
access and uses saved value if present.

When the image is executed in guest, since there is already a saved HPA
in VBIOS, it keeps using that value instead of the GPA programmed by
SeaBIOS in BDSM register in PCI config space, causing VBIOS to program
GTT entries with wrong address, resulting in garbled output in BIOS
POST and the error below detected by i915 driver.

i915 0000:00:02.0: [drm] *ERROR* Initial plane programming using invalid range, dma_addr=0x00000000db200000 ((null) [0x00000000baf00000-0x00000000beefffff])

The previous solution, c4c45e943e ("vfio/pci: Intel graphics legacy
mode assignment"), adjusts GTT entry addresses to (addr - host BDSM +
guest BDSM) to workaround that. But it is removed in 5aed8b0f0b
("vfio/igd: Remove GTT write quirk in IO BAR 4") due to inconsistent
values in MMIO BAR0 and IO BAR4.

Since it was a value latched into the VBIOS that breaks virtualization
(QEMU does not map the GTT at the same address in the VM), a ROM quirk
clearing the saved value in VBIOS image is introduced. It searches the
BDSM accessor routine by matching a 19-byte signature anchored on the
unique `mov $0x105e,%ax` instruction, then locates the offset of saved
BDSM and clears it. This makes the routine fall through to the PCI
config read on the first call inside the guest.

[1] 3.5.15, 4th Generation Intel Core Processor Family Datasheet Vol. 2
    https://www.intel.com/content/dam/www/public/us/en/documents/datasheets/4th-gen-core-family-desktop-vol-2-datasheet.pdf

Fixes: 5aed8b0f0b ("vfio/igd: Remove GTT write quirk in IO BAR 4")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3093
Reported-by: K S Maan <kirandeepmaan45@gmail.com>
Cc: qemu-stable@nongnu.org
Signed-off-by: Tomita Moeko <tomitamoeko@gmail.com>
Reviewed-by: Alex Williamson <alex@shazbot.org>
Link: https://lore.kernel.org/qemu-devel/20260708103100.23127-1-tomitamoeko@gmail.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-07-21 18:02:47 +02:00
Daniel P. Berrangé
84a6c5f94b get_maintainer: add ability to report Git Lab handle
With the GitLab mapping files from the previous commit, the
get_manitainer.pl script is now able to report the gitlab
handle for each maintainer/reviewer when displaying output.

For example:

  $ ./scripts/get_maintainer.pl -f hw/scsi/lsi53c895a.c
  Paolo Bonzini <pbonzini@redhat.com> (supporter:SCSI, gitlab:@bonzini)
  Fam Zheng <fam@euphon.net> (reviewer:SCSI, gitlab:@famzheng)
  qemu-devel@nongnu.org (open list:All patches CC here)

Reviewed-by: Fabiano Rosas <farosas@suse.de>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2026-07-21 16:53:12 +01:00
Daniel P. Berrangé
4f7615789b gitlab: introduce files mapping GitLab accounts to real names
It is desirable to be able to discover the GitLab account handle
assocaited with a real name in the MAINTAINERS file.

Rather that duplicating the same account handle multiple times,
inline with the MAINTAINERS file entries, this introduces mapping
files:

  * .gitlab-map-auto - data automatically queried from GitLab
    using the 'glab' tool and REST API
  * .gitlab-map-manual - manual overrides/augmentation for
    cases where the MAINTAINERS real name does not match the
    GitLab account real name

The former would need refreshing when we add new MAINTAINERS
entries, if the person had to be added as a GitLab account
member. For this purpose scripts/gitlab-map-update can be
used, assuming the user has the 'glab' client tool present
and configured with an access token.

To audit how many maintainers have GitLab handles present/missing
scripts/gitlab-map-check can run a report.

  $ ./scripts/gitlab-map-check
  Missing GitLab handle for maintainer 'Akihiko Odaki'
  Missing GitLab handle for maintainer 'Albert Esteve'
  ....
  Missing GitLab handle for maintainer 'Zhenzhong Duan'
  Missing GitLab handle for maintainer 'Zhuoying Cai'
  GitLab handles missing: 158 / present: 68

Reviewed-by: Fabiano Rosas <farosas@suse.de>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2026-07-21 16:52:25 +01:00
Luc Michel
15ebb1ec8c meson.build: re-add explicit gcrypt/nettle request check
c4b3d0074 removed the check that nettle or gcrypt were explicitly
requested as the crypto library to use, breaking the --enable-nettle and
--enable-gcrypt options. Re-add the logic to force usage of nettle or
gcrypt for crypto operations, while still keeping gnutls for TLS.

Fixes: c4b3d0074 (crypto: bump min gnutls to 3.7.5)
Tested-by: Daniel P. Berrangé <berrange@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Signed-off-by: Luc Michel <luc.michel@amd.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2026-07-21 16:52:18 +01:00
Daniel P. Berrangé
1b03da3bf8 tests/vm: update to FreeBSD 14.4 image
This avoids an interactive prompt that halts execution when
attempting to run the FreeBSD tests due to outdated 14.3
base image:

  `Bootstrapping pkg from pkg+https://pkg.FreeBSD.org/FreeBSD:14:amd64/quarterly, please wait...
  Verifying signature with trusted certificate pkg.freebsd.org.2013102301... done
  Installing pkg-2.6.2_1...
  Newer FreeBSD version for package pkg:
  To ignore this error set IGNORE_OSVERSION=yes
  - package: 1404000
  - running userland: 1403000
  Ignore the mismatch and continue? [y/N]:

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2026-07-21 16:52:14 +01:00
Jessica Clarke
7430c34b25 test-util-filemonitor: Adapt to FreeBSD 15's native inotify semantics
FreeBSD 15 introduces a native inotify implementation rather than
requiring use of the kqueue-based libinotify package. This native
implementation does not generate the extra deleted events, so don't
expect them. However, the original implementation did have a bug that
caused IN_IGNORED to never be generated if you did not also watch for
IN_DELETE_SELF, which affects 15.0 and 15.1, but has been fixed and will
no longer apply in 15.2 / 16.0.

Note that the deleted event check is for the userspace version, since
that governs whether libinotify is being used or not, whereas the
ignored event check is both for the userspace version (to check if we're
using the native syscall) and the kernel version (to check if the kernel
has the bug or not).

All __FreeBSD_version values used here correspond to the value in-tree
at the time of the relevant commits. Since neither commit bumped the
value there will be a window of development snapshots between each
commit and the previous bump that will be incorrectly identified here,
but this is the best we can do, and something users of snapshots should
be prepared to deal with.

Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Signed-off-by: Jessica Clarke <jrtc27@jrtc27.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2026-07-21 16:52:03 +01:00
Alex Bennée
ad14439be5 gitlab: remove gdb from MacOS jobs
The gdb jobs fail on CI and although I can't replicate locally on the
machine I have access to it definitely fixes it for the gitlab CI
machines.

Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Message-ID: <20260720180459.2542918-1-alex.bennee@linaro.org>
[This fixes the following CI jobs: aarch64-macos-15-build and
aarch64-macos-26-build.

Removing gdb from macOS jobs skips the softmmu gdbstub tests which
currently hang on GitLab's macOS runners:

qemu-system-aarch64: -gdb unix:path=/var/folders/fc/8_hzw5tx3n7c9c04tzd6tv_40000gn/T/tmpes3paikrqemu-gdbstub/gdbstub.socket,server=on: info: QEMU waiting for connection on: disconnected:unix:/var/folders/fc/8_hzw5tx3n7c9c04tzd6tv_40000gn/T/tmpes3paikrqemu-gdbstub/gdbstub.socket,server=on
gmake[1]: *** [/Users/gitlab/builds/qemu-project/qemu/tests/tcg/multiarch/system/Makefile.softmmu-target:35: run-gdbstub-interrupt] Error 137
gmake: *** [/Users/gitlab/builds/qemu-project/qemu/tests/Makefile.include:75: run-tcg-tests-aarch64-softmmu] Error 2

The following GitLab work item tracks solving the underlying issue that
is hanging softmmu gdbstub tests:
https://gitlab.com/qemu-project/qemu/-/work_items/4063
--Stefan]
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-21 10:09:47 -04:00
Stefan Hajnoczi
b376a19e5f Misc HW patches
Various fixes mostly related to misc hardware devices.
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEE+qvnXhKRciHc/Wuy4+MsLN6twN4FAmpfTF0ACgkQ4+MsLN6t
 wN6AihAAxGV6G2cmqwqB8KhfWxc+Y9CJDqlmE2DtLrImdJE63I8wj/DLKh5JzzGv
 62Fo6WCihhqV6tP4LRONHTih/yYgrtuX/U4C+blvw6PH/vTE9p6Q26QRzO2kebeh
 bupFxbou9l0uKvOccG/pbizbGT++XwP8qaLVQUjIxGE5np8VnueyVYS7TH7Dnr4j
 Ca7E4eotyPIXFAw/YORshwnfd9yFKF9gRyeAzUygyhaROGHnlVj0cRd14AR6W81J
 LsbfjrAu4j7lUaIDOlT97u/dDCA1bgcxdLbhkpQMYtL5acayyDS0qmU99WIuVLA/
 qt6f5jLeUvmy6/qgl9UXlQlbLzmAzC9eBBUcxJNE77xPGZ6Jww0ezZSTc0vhVItk
 bMStkac/HmnzqaHAV7qHgAyY7tYSEL3ElXGSia1Pm2YSzjnlAo0G3PEYPyZSyYIC
 RJb958ycKDfwMwDymDYsPRQo04JwkQb0tuQUhJ2BUNBDMFNJLhRC9Gs+CTnTSNaC
 TuuEGMUnSXRRYenqLVAxal0aWOTXU3dRmYjjfJ/7G+2I5JP2KhUAgQhADvNlOrTF
 MTSFUhiiDrn32WQZyLOJOyOhvCoT5usPWOxV/T63sesgV6OZ55EFdpndA0+R2Oda
 xkqkezub+GJJ1HwZhiAUa55ZQgwXGvvddMsxD/wcBAW/poaw8lI=
 =W2Lt
 -----END PGP SIGNATURE-----

Merge tag 'hw-misc-20260714' of https://github.com/philmd/qemu into staging

Misc HW patches

Various fixes mostly related to misc hardware devices.

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEE+qvnXhKRciHc/Wuy4+MsLN6twN4FAmpfTF0ACgkQ4+MsLN6t
# wN6AihAAxGV6G2cmqwqB8KhfWxc+Y9CJDqlmE2DtLrImdJE63I8wj/DLKh5JzzGv
# 62Fo6WCihhqV6tP4LRONHTih/yYgrtuX/U4C+blvw6PH/vTE9p6Q26QRzO2kebeh
# bupFxbou9l0uKvOccG/pbizbGT++XwP8qaLVQUjIxGE5np8VnueyVYS7TH7Dnr4j
# Ca7E4eotyPIXFAw/YORshwnfd9yFKF9gRyeAzUygyhaROGHnlVj0cRd14AR6W81J
# LsbfjrAu4j7lUaIDOlT97u/dDCA1bgcxdLbhkpQMYtL5acayyDS0qmU99WIuVLA/
# qt6f5jLeUvmy6/qgl9UXlQlbLzmAzC9eBBUcxJNE77xPGZ6Jww0ezZSTc0vhVItk
# bMStkac/HmnzqaHAV7qHgAyY7tYSEL3ElXGSia1Pm2YSzjnlAo0G3PEYPyZSyYIC
# RJb958ycKDfwMwDymDYsPRQo04JwkQb0tuQUhJ2BUNBDMFNJLhRC9Gs+CTnTSNaC
# TuuEGMUnSXRRYenqLVAxal0aWOTXU3dRmYjjfJ/7G+2I5JP2KhUAgQhADvNlOrTF
# MTSFUhiiDrn32WQZyLOJOyOhvCoT5usPWOxV/T63sesgV6OZ55EFdpndA0+R2Oda
# xkqkezub+GJJ1HwZhiAUa55ZQgwXGvvddMsxD/wcBAW/poaw8lI=
# =W2Lt
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 21 Jul 2026 06:39:25 EDT
# gpg:                using RSA key FAABE75E12917221DCFD6BB2E3E32C2CDEADC0DE
# gpg: Good signature from "Philippe Mathieu-Daudé (F4BUG) <f4bug@amsat.org>" [full]
# Primary key fingerprint: FAAB E75E 1291 7221 DCFD  6BB2 E3E3 2C2C DEAD C0DE

* tag 'hw-misc-20260714' of https://github.com/philmd/qemu:
  vfio/listener: Remove unnecessary 'linux/kvm.h' include
  hw/audio/intel-hda: restrict all DMA engine paths to memories
  hw/sd/sdcard: Fix error case for CMD18
  hw/net/cadence: Return current Cadence GEM queue pointers
  hw/misc/applesmc: Fix a typo setting MSSD key
  replay: fix use of uninitialized pointer on error
  user/guest-host: Include exec/abi_ptr.h
  hw/display/qxl: validate monitors_config heads[] in phys2virt
  net: Correct padding check in qemu_receive_packet()

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-21 10:06:51 -04:00
Stefan Hajnoczi
67078714a3 target-arm queue:
* hw/char: imx_serial: add missing migration state
  * hw/net/xilinx_axienet: Fix PHY register 17 link status reporting
  * target/arm: GICv5 cpuif: gicr_cdia_read() ppibit should be 64 bits
  * target/arm: GICv5 cpuif: Writes to ICC_APR_EL1 can change IRQ/FIQ
  * target/ppc: Remove unused helper_lscbx()
  * target/arm: Fix testing of raw mtx value
  * hw/dma/omap_dma: don't allow guest to memcopy arbitrary memory
  * target/arm: restore missing A-profile CPU types to qemu-arm
 -----BEGIN PGP SIGNATURE-----
 
 iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmpfMq8ZHHBldGVyLm1h
 eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3r2rD/9gHdiiSGLdUhYJBGZ10DOH
 wF4NopP/4YfVemZcf//aelUi+UNMQHmtRZf38BjXoNBNP6u3ovKp97wD+OvnujKP
 3Sbi1XJ+t3MSCdd+30WPrKzfzg9N3cR9BrXDGQV2R0zZREmoT1ue61KI/HVq7Xe+
 0uB1EcG7ovYthompNhUAeUx8xlNiPLNm60utXb5G8rJSyHT9pUjECo85/FuVRucu
 O1SZybZWccTzAyn5uw9CAb9VlNLy6xbaot43Dy7U7mHCTo6ycyteTTpSGtHGQ6tf
 Dhw9Pg8p/TQU77KNKKVI8PhJF7/42xdVubzV8jssOxFDAMyIIMyZSJYn7CTJcXj9
 fwa0BL/16JZZQK0PcUiWeQmkHG3MZLgdtuSbk8Yzf36oa64zQvEfYttLSQP3cW29
 iL3oGacugpjSI2AH1Eizt5d5fFkndvZHV4rCsGEq29TVnSXHqwoTKF72L/xCcxbY
 PeIIVJAdwsS/e2KenV2zvbUxej02JBtn9JtIeTlE9VmwsOf1Dtvb3yIZvfEUvwu7
 SyNPBfHaXf9ZXc5ookauGF0NLvos8pXli/LmyN7rxygkbf2dabZK5hV6fRSgjY1i
 O6N51lFSm9zFDBCLUNi8Giwxk4ojcv1bokFRpCvb5SfuFomdIGSNJmyU2e5yDn3/
 hUhfkBWv8b5JE4d3JjwGWg==
 =2Y3e
 -----END PGP SIGNATURE-----

Merge tag 'pull-target-arm-20260721' of https://gitlab.com/pm215/qemu into staging

target-arm queue:
 * hw/char: imx_serial: add missing migration state
 * hw/net/xilinx_axienet: Fix PHY register 17 link status reporting
 * target/arm: GICv5 cpuif: gicr_cdia_read() ppibit should be 64 bits
 * target/arm: GICv5 cpuif: Writes to ICC_APR_EL1 can change IRQ/FIQ
 * target/ppc: Remove unused helper_lscbx()
 * target/arm: Fix testing of raw mtx value
 * hw/dma/omap_dma: don't allow guest to memcopy arbitrary memory
 * target/arm: restore missing A-profile CPU types to qemu-arm

# -----BEGIN PGP SIGNATURE-----
#
# iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmpfMq8ZHHBldGVyLm1h
# eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3r2rD/9gHdiiSGLdUhYJBGZ10DOH
# wF4NopP/4YfVemZcf//aelUi+UNMQHmtRZf38BjXoNBNP6u3ovKp97wD+OvnujKP
# 3Sbi1XJ+t3MSCdd+30WPrKzfzg9N3cR9BrXDGQV2R0zZREmoT1ue61KI/HVq7Xe+
# 0uB1EcG7ovYthompNhUAeUx8xlNiPLNm60utXb5G8rJSyHT9pUjECo85/FuVRucu
# O1SZybZWccTzAyn5uw9CAb9VlNLy6xbaot43Dy7U7mHCTo6ycyteTTpSGtHGQ6tf
# Dhw9Pg8p/TQU77KNKKVI8PhJF7/42xdVubzV8jssOxFDAMyIIMyZSJYn7CTJcXj9
# fwa0BL/16JZZQK0PcUiWeQmkHG3MZLgdtuSbk8Yzf36oa64zQvEfYttLSQP3cW29
# iL3oGacugpjSI2AH1Eizt5d5fFkndvZHV4rCsGEq29TVnSXHqwoTKF72L/xCcxbY
# PeIIVJAdwsS/e2KenV2zvbUxej02JBtn9JtIeTlE9VmwsOf1Dtvb3yIZvfEUvwu7
# SyNPBfHaXf9ZXc5ookauGF0NLvos8pXli/LmyN7rxygkbf2dabZK5hV6fRSgjY1i
# O6N51lFSm9zFDBCLUNi8Giwxk4ojcv1bokFRpCvb5SfuFomdIGSNJmyU2e5yDn3/
# hUhfkBWv8b5JE4d3JjwGWg==
# =2Y3e
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 21 Jul 2026 04:49:51 EDT
# gpg:                using RSA key E1A5C593CD419DE28E8315CF3C2525ED14360CDE
# gpg:                issuer "peter.maydell@linaro.org"
# gpg: Good signature from "Peter Maydell <peter.maydell@linaro.org>" [full]
# gpg:                 aka "Peter Maydell <pmaydell@gmail.com>" [full]
# gpg:                 aka "Peter Maydell <pmaydell@chiark.greenend.org.uk>" [full]
# gpg:                 aka "Peter Maydell <peter@archaic.org.uk>" [unknown]
# Primary key fingerprint: E1A5 C593 CD41 9DE2 8E83  15CF 3C25 25ED 1436 0CDE

* tag 'pull-target-arm-20260721' of https://gitlab.com/pm215/qemu:
  Revert "target/arm: Build cpu32-system.o as common object"
  MAINTAINERS: Add soc_dma to OMAP section
  include/hw/arm/omap_dma.h: Move to include/hw/dma
  hw/dma/soc_dma: Remove unused mem.base, paddr fields
  hw/dma/soc_dma: Use physical_memory_map() for mem2mem transfers
  hw/dma/soc_dma: dma bytes is uint64_t
  hw/dma/omap_dma: Be more careful about overflow in transfer setup
  hw/dma/soc_dma: Remove union from memmap_entry_s struct
  hw/dma/soc_dma: Simplify soc_dma_ch_update()
  hw/dma/soc_dma: Remove soc_dma_port_fifo support
  target/arm: Fix testing of raw mtx value
  target/ppc: Remove unused helper_lscbx()
  target/arm: GICv5 cpuif: Writes to ICC_APR_EL1 can change IRQ/FIQ
  target/arm: GICv5 cpuif: gicr_cdia_read() ppibit should be 64 bits
  hw/net/xilinx_axienet: Fix PHY register 17 link status reporting
  hw/char: imx_serial: add missing migration state

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-21 10:06:04 -04:00
Stefan Hajnoczi
83e8f88135 Changes:
- [PATCH 0/3] dlcall: correct the syscall number claim and the guest (Ziyang Zhang <functioner@sjtu.edu.cn>)
   Link: https://lore.kernel.org/qemu-devel/20260719074730.1520517-1-functioner@sjtu.edu.cn
 -----BEGIN PGP SIGNATURE-----
 
 iQGzBAABCgAdFiEEN8FWlNi6l2Sxlz/btEQ30ZwoYt8FAmpef1oACgkQtEQ30Zwo
 Yt9/RQv8CqO4yZnBiNnuSlxgz740t7N+5HZDIqP9LR4htpLbdw9FG7NLs179ZME2
 aZ2gQGGMutlh8CuZHGs9A587mQT0sBd6KLmSfMcwyM9FnXw5ewzJqQsZ8YmbKwyM
 nT4BB9OyYJ0RSndov7iAj1EHn7YyDXr4NoVMdRVv8QCXMin9ztgxcHph4D+AsAHe
 0D+iO1aT88pSuYOWMya1XQln/NkL7cQq3NY8w7IdlMA+edDUcmv0LazQRljywxS+
 IIcGvVcreUlu/v1w9bbqYrI3BualHVdqkbNAQyNuSNSqAQnHkFb9EKcpY4gpe+ZS
 oeoIrHFYu0VM50C/mAE8m+I+iRgJGAlyCaNohpYVj5MQdVZ+hlZx2vpvWGV+4zHG
 GrtRvjVhND88GEsYj5pigQS9HMOZ4FnrSjyQ0t6uI6lcKDeCtfTbz8Q49VUD7okA
 eO3/JLYJPcrdipFjwfM/ahTXpkgejgCJypD90vCIZpO6UF8A1dp7Fl/07XFXDouz
 5b6YkWGE
 =i09L
 -----END PGP SIGNATURE-----

Merge tag 'pbouvier/pr/plugins-20260720' of https://gitlab.com/p-b-o/qemu into staging

Changes:
- [PATCH 0/3] dlcall: correct the syscall number claim and the guest (Ziyang Zhang <functioner@sjtu.edu.cn>)
  Link: https://lore.kernel.org/qemu-devel/20260719074730.1520517-1-functioner@sjtu.edu.cn

# -----BEGIN PGP SIGNATURE-----
#
# iQGzBAABCgAdFiEEN8FWlNi6l2Sxlz/btEQ30ZwoYt8FAmpef1oACgkQtEQ30Zwo
# Yt9/RQv8CqO4yZnBiNnuSlxgz740t7N+5HZDIqP9LR4htpLbdw9FG7NLs179ZME2
# aZ2gQGGMutlh8CuZHGs9A587mQT0sBd6KLmSfMcwyM9FnXw5ewzJqQsZ8YmbKwyM
# nT4BB9OyYJ0RSndov7iAj1EHn7YyDXr4NoVMdRVv8QCXMin9ztgxcHph4D+AsAHe
# 0D+iO1aT88pSuYOWMya1XQln/NkL7cQq3NY8w7IdlMA+edDUcmv0LazQRljywxS+
# IIcGvVcreUlu/v1w9bbqYrI3BualHVdqkbNAQyNuSNSqAQnHkFb9EKcpY4gpe+ZS
# oeoIrHFYu0VM50C/mAE8m+I+iRgJGAlyCaNohpYVj5MQdVZ+hlZx2vpvWGV+4zHG
# GrtRvjVhND88GEsYj5pigQS9HMOZ4FnrSjyQ0t6uI6lcKDeCtfTbz8Q49VUD7okA
# eO3/JLYJPcrdipFjwfM/ahTXpkgejgCJypD90vCIZpO6UF8A1dp7Fl/07XFXDouz
# 5b6YkWGE
# =i09L
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 20 Jul 2026 16:04:42 EDT
# gpg:                using RSA key 37C15694D8BA9764B1973FDBB44437D19C2862DF
# gpg: Good signature from "Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 37C1 5694 D8BA 9764 B197  3FDB B444 37D1 9C28 62DF

* tag 'pbouvier/pr/plugins-20260720' of https://gitlab.com/p-b-o/qemu:
  docs/about/emulation: sharpen the dlcall boundary and its guest requirements
  tests/tcg: correct why the magic syscall number is safe here
  contrib/plugins/dlcall: correct the syscall number claim, note the data model

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-21 10:05:29 -04:00
Stefan Hajnoczi
dbe4ebedda Pull request
A fix for qemu-iotests 108 failures that have been seen in CI.
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCgAdFiEEhpWov9P5fNqsNXdanKSrs4Grc8gFAmpeaRcACgkQnKSrs4Gr
 c8jqAAf/aXSpWGPaBXBOkpEE7O7E5q8WLwf2P7E4V9NNi6jMlukBadiqxUsog9Hy
 M4bt6u39vx0MfnPxnElOYmy92heohT3EbPEEuDCG+fDW8eC2k1wU9IOiI/7Rmt+G
 xXNz8jtbW6llRyPEVMd6k4YuK9xNxRmHT0H94sfOOIOk1VMotAPuNdVt95iRSKGI
 xmaIb3NAiVDfUiD6KiW8VstlUdN9LrcDK/keFlHabNETbkbDPJnKAEuy63Xt90Oy
 BQAN1nGlsXI1NT47iIANpTmO6ROQGjRrStZxqszClRbBFscLI1zG2W7bQaqvhXPo
 BR8Clcjpt1snSeiihJ5IPmZ1/DCwEQ==
 =mJv6
 -----END PGP SIGNATURE-----

Merge tag 'block-pull-request' of https://gitlab.com/stefanha/qemu into staging

Pull request

A fix for qemu-iotests 108 failures that have been seen in CI.

# -----BEGIN PGP SIGNATURE-----
#
# iQEzBAABCgAdFiEEhpWov9P5fNqsNXdanKSrs4Grc8gFAmpeaRcACgkQnKSrs4Gr
# c8jqAAf/aXSpWGPaBXBOkpEE7O7E5q8WLwf2P7E4V9NNi6jMlukBadiqxUsog9Hy
# M4bt6u39vx0MfnPxnElOYmy92heohT3EbPEEuDCG+fDW8eC2k1wU9IOiI/7Rmt+G
# xXNz8jtbW6llRyPEVMd6k4YuK9xNxRmHT0H94sfOOIOk1VMotAPuNdVt95iRSKGI
# xmaIb3NAiVDfUiD6KiW8VstlUdN9LrcDK/keFlHabNETbkbDPJnKAEuy63Xt90Oy
# BQAN1nGlsXI1NT47iIANpTmO6ROQGjRrStZxqszClRbBFscLI1zG2W7bQaqvhXPo
# BR8Clcjpt1snSeiihJ5IPmZ1/DCwEQ==
# =mJv6
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 20 Jul 2026 14:29:43 EDT
# gpg:                using RSA key 8695A8BFD3F97CDAAC35775A9CA4ABB381AB73C8
# gpg: Good signature from "Stefan Hajnoczi <stefanha@redhat.com>" [ultimate]
# gpg:                 aka "Stefan Hajnoczi <stefanha@gmail.com>" [ultimate]
# Primary key fingerprint: 8695 A8BF D3F9 7CDA AC35  775A 9CA4 ABB3 81AB 73C8

* tag 'block-pull-request' of https://gitlab.com/stefanha/qemu:
  iotests/108: avoid leaking FUSE mount

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-21 10:05:03 -04:00
Cédric Le Goater
d06edc83b5 vfio/listener: Remove unnecessary 'linux/kvm.h' include
Since commit d0e8bccafc ("hw/vfio/listener.c: remove CONFIG_KVM"),
the linux/kvm.h include is unconditional. This breaks the build on
targets that lack asm/kvm.h such as sparc and sparc64:

  In file included from ../hw/vfio/listener.c:23:
  linux-headers/linux/kvm.h:16:10: fatal error: asm/kvm.h: No such file or directory

This include is not needed in listener.c which only uses kvm_enabled()
and kvm_get_max_memslots(), both are declared in "system/kvm.h".
Remove it.

Fixes: d0e8bccafc ("hw/vfio/listener.c: remove CONFIG_KVM")
Cc: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>"
Suggested-by: Alex Williamson <alex@shazbot.org>
Signed-off-by: Cédric Le Goater <clg@redhat.com>
Tested-by: Michael Tokarev <mjt@tls.msk.ru>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721062745.3793066-1-clg@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-21 12:38:48 +02:00
Haotian Jiang
c257745248 hw/audio/intel-hda: restrict all DMA engine paths to memories
CVE-2021-3611 (commit 79fa99831d) restricted the DMA engine to memories
by setting attrs.memory=true, but only applied this to intel_hda_response.
Three other DMA engine access points still use MEMTXATTRS_UNSPECIFIED,
allowing a malicious guest to trigger DMA-to-self-MMIO reentry:

  - intel_hda_xfer (line 398): called from the audio timer callback
    (hda_codec_xfer -> bus->xfer), so the MemReentrancyGuard does not
    fire (engaged_in_io is false outside MMIO dispatch). A guest that
    points a BDL entry at the HDA controller's own MMIO BAR can write
    audio samples to device registers, triggering whandler side effects
    such as starting/stopping streams or injecting codec commands via
    CORBWP.
  - intel_hda_parse_bdl (line 478): uses pci_dma_read which hardcodes
    MEMTXATTRS_UNSPECIFIED. A guest-controlled BDL base address can
    point at controller MMIO, allowing the DMA engine to read device
    registers as BDL descriptors.
  - intel_hda_corb_run (line 333): ldl_le_pci_dma reads the CORB ring
    with MEMTXATTRS_UNSPECIFIED, allowing the DMA engine to read
    controller MMIO as CORB entries.

Fix all three by passing {.memory = true} explicitly, matching the
fix already applied to intel_hda_response. For intel_hda_parse_bdl,
replace pci_dma_read with pci_dma_rw to pass the controlled attrs.

Fixes: 79fa99831d ("hw/audio/intel-hda: Restrict DMA engine to memories (not MMIO devices)")
Reported-by: Haotian Jiang of Tencent Security (Yunding Lab) <jianghaotian.sunday@gmail.com>
Signed-off-by: Haotian Jiang <jianghaotian.sunday@gmail.com>
Cc: qemu-stable@nongnu.org
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260721060941.2989396-1-jianghaotian.sunday@gmail.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-21 12:38:48 +02:00
Bernhard Beschow
c477e32b64 hw/sd/sdcard: Fix error case for CMD18
In commit 468fa450a7 ("hw/sd: Switch read/write primitive to
buf+len"), `sd_read_byte()` changed its contract to return the read size
rather than the read value (and was renamed to `sd_read_data()`
accordingly). In an error case, however, `sd_read_data()` returns 0 by
means of `dummy_byte` which is the code for the old contract. Moreover,
`sdbus_read_data()` asserts the virtual method `read_data()` (and thus
`sd_read_data()`) to return a non-zero size, i.e. to make progress and
not loop forever. Fix the code to behave like the "DAT read illegal for
command" case.

Fixes: 468fa450a7 ("hw/sd: Switch read/write primitive to buf+len")
Reviewed-by: Bin Meng <bin.meng@processmission.com>
Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260720201133.24796-2-shentey@gmail.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-21 12:38:44 +02:00
Bin Meng
94c510a5dc hw/net/cadence: Return current Cadence GEM queue pointers
Cadence GEM queue pointer registers are programmed with the descriptor
ring base, but reads return the descriptor currently being accessed.
The model tracked the current positions separately while continuing to
return the configured base.

The Linux macb driver uses the transmit queue pointer when recovering
from a used-buffer interrupt. A stale priority-queue pointer can make
the driver restart DMA before that queue handles its completion
interrupt, causing queue 0 to repeatedly raise TX_USED.

The primary queue has had this mismatch since the initial model.
Priority queue support later copied the same register-read behavior.

A single-queue machine usually handles TX_COMPLETE before TX_USED and
empties the software queue before the restart check, which kept the
issue hidden there.

Return the current RX and TX descriptor positions on queue-pointer reads
and clear those positions on reset.

Fixes: e9f186e514 ("cadence_gem: initial version of device model")
Fixes: 6710172501 ("cadence_gem: Add queue support")
Cc: qemu-stable@nongnu.org
Signed-off-by: Bin Meng <bin.meng@processmission.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260720120731.2022475-1-bin.meng@processmission.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-21 12:18:53 +02:00
Philippe Mathieu-Daudé
2142689d92 hw/misc/applesmc: Fix a typo setting MSSD key
In commit 1ddda5cd36 we meant to set MSSD=3, but due
to a typo we ended setting MSSD=0. Convert the two other
NATJ and MSSP keys to use hexadecimal notation to avoid
similar copy/paste typos.

Cc: qemu-stable@nongnu.org
Fixes: 1ddda5cd36 ("AppleSMC device emulation")
Reported-by: Matthew Jackson <matthew@pq.io>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Alexander Graf <agraf@csgraf.de>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Message-Id: <20260720115336.75063-1-philmd@oss.qualcomm.com>
2026-07-21 12:18:53 +02:00
Marc-André Lureau
fe68e4b47b replay: fix use of uninitialized pointer on error
When bdrv_snapshot_list() returns a negative error code, sn_tab is
uninitialized. The loop does not execute (since i=0 < negative is
false), but the code falls through to g_free(sn_tab) which frees
an uninitialized pointer.

Fixes: f6baed3d14 ("replay: implement replay-seek command")
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260719113216.1177594-1-marcandre.lureau@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-21 12:18:36 +02:00
Richard Henderson
701e8d1ee9 user/guest-host: Include exec/abi_ptr.h
The COMPILING_PER_TARGET block uses the abi_ptr type
without including the proper header.

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260717232306.378988-2-richard.henderson@linaro.org>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-21 12:18:36 +02:00
Marc-André Lureau
9f436938c5 hw/display/qxl: validate monitors_config heads[] in phys2virt
The qxl_phys2virt() call for guest_monitors_config only validates
sizeof(QXLMonitorsConfig), which covers the fixed header (count and
max_allowed) since commit 8efec0ef8b ("hw/display/qxl: Pass requested
buffer size to qxl_phys2virt()"), but not the flexible array member
heads[]. When count == 1, heads[0] is accessed without its memory being
validated, allowing a guest to cause an out-of-bounds read.

Include sizeof(QXLHead) in the size passed to qxl_phys2virt() so that
the first head entry is validated within the guest memory slot, preventing
guest-visible memory reading.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4027
Reported-by: Tristan @TristanInSec
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260715072722.1643289-1-marcandre.lureau@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-21 12:18:36 +02:00
Peter Maydell
b1e73b2ddb net: Correct padding check in qemu_receive_packet()
In qemu_receive_packet() we check to see if we should pad a short
packet.  This is doing the wrong test: because this function is used
when the device adds a packet to its own incoming queue (i.e.  for
loopback), we should be checking the NetClientState's own do_not_pad
flag, not that for its peer.

We didn't notice this earlier, because at the moment all the real
peers of a network device (i.e.  the network backends) do not set
do_not_pad, so net_peer_needs_padding() always returns true except in
the corner case where the network device has no peer at all.

The effect of this is that if a network device has no peer (e.g.
because QEMU was started with -net none or with -nodefaults) then we
can still let through the kind of "guest misprograms the network
device to loopback-transmit a short packet and then we mishandle it
in the receive path" bug like #3043 which commit a01344d9d7 was
trying to fix.

Since the distinction between "we should check nc->do_not_pad"
and "we should check nc->peer->do_not_pad" is a bit subtle, add
enough documentation commentary to make it more obvious.

Cc: qemu-stable@nongnu.org
Fixes: a01344d9d7 ("net: pad packets to minimum length in qemu_receive_packet()")
Suggested-by: Bin Meng <bmeng.cn@gmail.com>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Bin Meng <bin.meng@processmission.com>
Message-ID: <20260629164246.2028947-1-peter.maydell@linaro.org>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-21 12:18:36 +02:00
Ziyang Zhang
533c98e769 docs/about/emulation: sharpen the dlcall boundary and its guest requirements
Record the same data model requirement as the plugin: guest_base == 0 is
necessary but not sufficient.

Describe the magic syscall number the way the plugin now does. It has to be a
number the guest ABI does not use and does not reject before the plugin sees
it, rather than merely a high one, so show syscall_num= being used as well.

A library is not turned into thunks, it is left alone and the thunks are
produced for it, so say that instead. Argument marshalling, callbacks and
variadic functions are also what the plugin does not do, and listing them in
its description blurs the boundary it draws. Move them to Lorelei, where they
are pointed at as a reference.

Co-authored-by: Kailiang Xu <xukl2019@sjtu.edu.cn>
Co-authored-by: Mingyuan Xia <xiamy@ultrarisc.com>
Signed-off-by: Ziyang Zhang <functioner@sjtu.edu.cn>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260719074730.1520517-4-functioner@sjtu.edu.cn
Signed-off-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
2026-07-20 13:03:14 -07:00
Ziyang Zhang
99916cdb4d tests/tcg: correct why the magic syscall number is safe here
The comment said 4096 was picked because no ISA in Linux uses it. The same
comment already notes that mips 32 bits numbers from 4000, which makes 4096 its
getpriority.

What actually keeps this test safe is the filter, which matches on the first
argument as well, so a real syscall carrying this number is left alone. Say
that instead.

Co-authored-by: Kailiang Xu <xukl2019@sjtu.edu.cn>
Co-authored-by: Mingyuan Xia <xiamy@ultrarisc.com>
Signed-off-by: Ziyang Zhang <functioner@sjtu.edu.cn>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260719074730.1520517-3-functioner@sjtu.edu.cn
Signed-off-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
2026-07-20 13:03:14 -07:00
Ziyang Zhang
bc5b22b4d4 contrib/plugins/dlcall: correct the syscall number claim, note the data model
The comment claimed every Linux ABI keeps its syscall numbers well below the
minimum, and that the minimum is all N has to satisfy. Neither holds.

MIPS O32 bases its numbering at 4000, so the default 4096 is its getpriority.
Raising N does not rescue it either, because O32 answers numbers its table does
not define with ENOSYS before the filter runs, which leaves no number that is
both free and reachable on that ABI. arm32 bounds N from above too, with ENOSYS
or SIGILL past ARM_NR_BASE. Say all of this, so the number can be chosen with
the target in mind.

guest_base == 0 is not the only requirement either. Host pointers are written
back through the caller's out pointers, so the guest must match the host's
pointer width and endianness. Fold that into the existing warning.

Also assert the two out pointers that lacked it, and point at Lorelei for
argument marshalling, callbacks and variadic functions.

Co-authored-by: Kailiang Xu <xukl2019@sjtu.edu.cn>
Co-authored-by: Mingyuan Xia <xiamy@ultrarisc.com>
Signed-off-by: Ziyang Zhang <functioner@sjtu.edu.cn>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260719074730.1520517-2-functioner@sjtu.edu.cn
Signed-off-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
2026-07-20 13:03:14 -07:00
Peter Maydell
b693da615a Revert "target/arm: Build cpu32-system.o as common object"
In c8bea1276c we moved cpu32.c and built it as a common object.  The
commit message says "cpu32.c only contains CPU types used in 32-bit
system emulation".  However, this is incorrect -- it contains 32-bit
CPU types used in both system and usermode emulation.  (The case
where we don't need these CPUs and which we were using ifdefs to
avoid is specifically the AArch64 usermode qemu-aarch64 binary.)

The effect is that qemu-arm lost all the named CPU types except
the M-profile ones (which are in cpu-v7m.c).

This reverts commit c8bea1276c.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3962
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Message-id: 20260720100312.119894-1-peter.maydell@linaro.org
2026-07-20 19:05:30 +01:00
Peter Maydell
fcebaea2e3 MAINTAINERS: Add soc_dma to OMAP section
The hw/dma/soc_dma.c code appears to have been written with the idea
that it abstracts out DMA transfer operations from the details of a
particular DMA controller device.  In practice, it's used only by the
omap_dma code and I would not today recommend trying to use it in any
new DMA device.  Add the files to the OMAP section of MAINTAINERS so
that patches can be cc'd to the appropriate places.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260710105907.2570621-10-peter.maydell@linaro.org
2026-07-20 19:05:30 +01:00
Peter Maydell
a5223ea536 include/hw/arm/omap_dma.h: Move to include/hw/dma
omap_dma.h is the header file for hw/dma/omap_dma.c; it fits better
to put it in include/hw/dma/ to match where we have the .c file.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260710105907.2570621-9-peter.maydell@linaro.org
2026-07-20 19:05:30 +01:00
Peter Maydell
f5541f51cf hw/dma/soc_dma: Remove unused mem.base, paddr fields
Now that transfer_mem2mem() uses physical_memory_map(), the
soc_dma_ch_s::paddr field is unused; remove it, and the code that set
it, and the memmap_entry_s::mem.base and the soc_dma_port_add_mem()
phys_base argument that were passing around host pointers to use for
setting paddr.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260710105907.2570621-8-peter.maydell@linaro.org
2026-07-20 19:05:30 +01:00
Peter Maydell
3162318194 hw/dma/soc_dma: Use physical_memory_map() for mem2mem transfers
The soc_dma code has a fastpath for when DMA transfers are from RAM
to RAM.  The current implementation of this has the caller of
soc_dma_port_add_mem() pass the underlying host address of the RAM
block that the DMA port is connected to (obtained via
memory_region_get_ram_ptr()).  Then the actual transfer function does
a simple memcpy(). This has several problems.

Most importantly, no bounds checking is done on the address and size
passed by the guest, so the memcpy source and destination might be
outside the backing host RAM entirely.  Secondly, because the DMA
access is done via this back door, there is no updating of the dirty
region when memory is written this way (there is a TODO comment
in omap_dma.c noting this).

Fix both of these by making the memory to memory transfer function
use physical_memory_map() to get the host addresses for the memory
copy.  That function will automatically give us the bounds check that
we want and return a short length if the transfer would run off the
end of the RAM MemoryRegion it starts in.  Since the OMAP DMA
documentation states that it's a guest error to misprogram the
addresses so that they fall outside the range that is valid for the
particular DMA port being addressed and that this can result in guest
memory corruption , we don't need to loop for short transfers, but
can simply log them and continue.

Note that we don't need to update addresses or bytecount here in the
transfer function, because when soc_dma_ch_update() selects
transfer_mem2mem it also sets ch->update to 1, which tells the
omap_dma_transfer_setup() code that it is responsible for updating
all the guest visible fields to match "transfer completed".

(We use physical_memory_map() here to match the use of
physical_memory_read() and physical_memory_write() in omap_dma.c;
making the DMA controller use an explicit AddressSpace would be
a separate cleanup task.)

Together with the preceding commits that fixed some integer overflow
problems, this fixes the "guest can provoke a bad memcpy() operation"
reported in issue #3204.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3204
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260710105907.2570621-7-peter.maydell@linaro.org
2026-07-20 19:05:30 +01:00
Peter Maydell
22afad9489 hw/dma/soc_dma: dma bytes is uint64_t
The worst case number of DMA bytes that omap_dma will ask us to
transfer is 0xffff * 0xffff * 4 == 0x3fff80004, which is slightly
larger than fits into a uint32_t.  Move the byte count to uint64_t,
and adjust code that passes it around to also use uint64_t.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Jim MacArthur <jim.macarthur@linaro.org>
Message-id: 20260710105907.2570621-6-peter.maydell@linaro.org
2026-07-20 19:05:30 +01:00
Peter Maydell
efbf01e03f hw/dma/omap_dma: Be more careful about overflow in transfer setup
In omap_dma_transfer_setup(), the maximum number of elements we can
transfer is 0xffff * 0xffff == 0xfffe0001 (because the max frame
count and max elements per frame are both 65535).  However, we store
total element counts in 'int' variables, and use INT_MAX as a "bigger
than any valid value" sentinel, and when performing arithmetic with
the total count of transferred elements we are not careful about
avoiding overflows. Fix these:

 - use uint32_t rather than int for the local variables tracking
   various element and frame counts
 - use UINT_MAX as our sentinel
 - calculate new packet, element and frame counter values using
   arithmetic on a local uint32_t, rather than doing it in-place
   on local variables that are only 'int' because the actual
   counter registers are 16 bits
 - use 64-bit arithmetic when calculating how much to advance the
   source and dest pointers and the total dma->bytes transferred

Note that since soc_dma_ch_s::bytes is only 'int' this can still
overflow; we'll fix that in a subsequent patch.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Jim MacArthur <jim.macarthur@linaro.org>
Message-id: 20260710105907.2570621-5-peter.maydell@linaro.org
2026-07-20 19:05:30 +01:00
Peter Maydell
68f788e705 hw/dma/soc_dma: Remove union from memmap_entry_s struct
There's only one field in the union inside memmap_entry_s now that
we've removed the soc_dma_port_fifo handling.  Simplify by removing
the union.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260710105907.2570621-4-peter.maydell@linaro.org
2026-07-20 19:05:30 +01:00
Peter Maydell
f00bef33fe hw/dma/soc_dma: Simplify soc_dma_ch_update()
Now we only have "mem" and "other" as soc_dma_port_type values, we
can simplify soc_dma_ch_update(): either both src and dst are mem, in
which case we use transfer_mem2mem and set update to 1 to tell
omap_dma_transfer_setup() to update all the guest-visible
src/dest/count information to indicate a completed transfer; or else
we use the omap_dma_transfer_generic() function, and we set update to
0 to tell omap_dma_transfer_setup() that the transfer function will
be updating the src/dest/count.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260710105907.2570621-3-peter.maydell@linaro.org
Reviewed-by: Alex Bennée <alex.bennee@linaro.org>
2026-07-20 19:05:30 +01:00
Peter Maydell
02cfe21f6a hw/dma/soc_dma: Remove soc_dma_port_fifo support
Our current single OMAP SoC doesn't call the soc_dma_port_add_fifo(),
soc_dma_port_add_fifo_in() or soc_dma_port_add_fifo_out() functions.
Remove them, plus the soc_dma_port_fifo handling that only those
functions needed.

The motivation for this is that it removes a lot of code that is
careless about the fact that the largest possible DMA transfer is
more bits than will fit into an "int" variable, and which does direct
accesses to host memory pointers into guest backing RAM without doing
bounds checks.  Deleting this code means we don't have to audit and
update it.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260710105907.2570621-2-peter.maydell@linaro.org
2026-07-20 19:05:30 +01:00
Richard Henderson
1f8aa4b6af target/arm: Fix testing of raw mtx value
MTX is always a pair of bits, one for each half of the address space.
Testing it like a boolean is incorrect.

Introduce raw_mte_check, a mirror of the similar mte_check function
that applies when MTX is passed in MTEDESC.

Fixes: 8912ceced8 ("target/arm: load on canonical tag loads ext bits")
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260717161430.37264-1-richard.henderson@linaro.org
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-20 19:05:30 +01:00
Peter Maydell
a148ca7627 target/ppc: Remove unused helper_lscbx()
The helper_lscbx() function isn't called anywhere.  It used to be
used by the PPC 601 CPU support; we removed that in commit 005b69fdcc
in 2022 but missed this helper function.

Fixes: 005b69fdcc ("target/ppc: Remove PowerPC 601 CPUs")
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Message-id: 20260709095056.1803725-1-peter.maydell@linaro.org
2026-07-20 19:05:30 +01:00
Peter Maydell
2a9847868f target/arm: GICv5 cpuif: Writes to ICC_APR_EL1 can change IRQ/FIQ
The ICC_APR_EL1 register values change the current running priority,
which we use in our calculations in gic_hppi().  Changing them can
affect whether we have a HPPI, and so the value of the IRQ/FIQ
outputs.  We need to trigger an update in the register writefn.

Fixes: 9bd90bddb7 ("target/arm: GICv5 cpuif: Signal IRQ or FIQ")
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260714091806.3568281-3-peter.maydell@linaro.org
2026-07-20 19:05:29 +01:00
Peter Maydell
4ef00a9fc4 target/arm: GICv5 cpuif: gicr_cdia_read() ppibit should be 64 bits
In gicr_cdia_read() we turn a PPI interrupt ID into a register
index and a bit mask with a 1 for the bit we want to change:

        ppireg = id / 64;
        ppibit = 1ULL << (id % 64);

However, we used the wrong type for ppibit, making it a uint32_t.  If
'id' is too large we'll shift off the end, so we won't ever update
the state of PPIs with indexes above 31.

This didn't have any visible effects because the currently allocated
architected PPIs are indexes 0..31, so you'd only see this if for
some reason a guest was manually marking as pending a PPI in 32..63.

Fix the type of ppibit to the intended 64 bit width.

Fixes: 3f79212aba ("target/arm: GICv5 cpuif: Implement GICR CDIA command")
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20260714091806.3568281-2-peter.maydell@linaro.org
2026-07-20 19:05:29 +01:00
Jay Chang
8392734722 hw/net/xilinx_axienet: Fix PHY register 17 link status reporting
The Marvell 88E1111 PHY register 17 (PHY Specific Status Register)
bit 10 reports real-time link status. Previously, this register
returned a fixed value of 0x8800 with bit 10 always cleared,
causing U-Boot to always detect "No link" even when the link
was up.

Signed-off-by: Jay Chang <jay.chang@sifive.com>
Reviewed-by: Frank Chang <frank.chang@sifive.com>
Message-id: 20260713064617.85374-1-jay.chang@sifive.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-20 19:05:29 +01:00
Tao Ding
8833ff95ea hw/char: imx_serial: add missing migration state
The imx_serial vmstate is missing the ucr2 field.  This register
includes important state like the transmit enable and receive enable
bits, so it's likely that after a migration the UART will be in a
completely broken state. This bug has been present ever since
the UART code was first added to QEMU.

Add ucr2 from imx_serial to vmstate, and increment the version_id.
This is a migration compatibility break, but this UART is only used
in the various imx-based boards, where we are OK with compat breaks.

Migrating on sabrelite can reproduce this issue:
1. Prepare the U-Boot required for sabrelite. (according to sabrelite.rst)
2. Compile qemu
    $ mkdir build && cd build && ../configure --target-list="arm-softmmu" && make -j4
3. Start sabrelite and prepare for migration
    $ ./build/qemu-system-arm -M sabrelite \
    -smp 1 -m 1G -display none -serial null -serial mon:stdio \
    -kernel ~/u-boot
4. Enter qemu monitor after uboot. (ctrl + a + c)
    (qemu) stop
    (qemu) xp /4wx 0x021e8084
    021e8084: 0x00004027 0x00000784 0x00008000 0x00000a01
    (qemu) migrate -d file:vmstate
    (qemu) q

Load the migrated vmstate, before repairing:

$ ./build/qemu-system-arm -M sabrelite \
    -smp 1 -m 1G -display none -serial null -serial mon:stdio \
    -kernel ~/u-boot -incoming file:vmstate

(ctrl + a + c)
    QEMU 11.0.50 monitor - type 'help' for more information
    (qemu) xp /4wx 0x021e8084
    021e8084: 0x00000004 0x00000784 0x00008000 0x00000a01
    (qemu) q

It can be found that the data for address 0x021e8084 (register of usr2 in imx_serial of sabrelite)
is not the data before the migration.

After being repaired:
$ ./build/qemu-system-arm -M sabrelite \
    -smp 1 -m 1G -display none -serial null -serial mon:stdio \
    -kernel ~/u-boot -incoming file:vmstate
(ctrl + a + c)
    QEMU 11.0.50 monitor - type 'help' for more information
    (qemu) xp /4wx 0x021e8084
    021e8084: 0x00004027 0x00000784 0x00008000 0x00000a01

Cc: qemu-stable@nongnu.org
Fixes: 40b6f91151 ("i.MX: UART support")
Signed-off-by: Tao Ding <dingtao0430@163.com>
Message-id: 20260715131819.14827-2-dingtao0430@163.com
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-20 19:05:29 +01:00
Stefan Hajnoczi
94bd02908a iotests/108: avoid leaking FUSE mount
The QEMU s390x CI gitlab-runner recently broke because qemu-iotests 108
FUSE mount leaked and prevented the setup of the gitlab-runner
environment:

  chmod: cannot access '/home/gitlab-runner/builds/P3MFS4LUf/0/qemu-project/qemu/build/scratch/qcow2-file-108/fuse-export': Transport endpoint is not connected

https://gitlab.com/qemu-project/qemu/-/jobs/14796143507#L11

Always umount the FUSE export when cleaning up to prevent the leak.

Closes: https://gitlab.com/qemu-project/qemu/-/work_items/3541
Cc: Hanna Czenczek <hreitz@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Message-ID: <20260611125438.194479-1-stefanha@redhat.com>
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-20 13:52:40 -04:00
Stefan Hajnoczi
bd6079a7a1 Migration pull for rc1
- Bin's cleanup on migration blocktime (partly)
 - Yujun's fix on print format
 -----BEGIN PGP SIGNATURE-----
 
 iIgEABYKADAWIQS5GE3CDMRX2s990ak7X8zN86vXBgUCal43iBIccGV0ZXJ4QHJl
 ZGhhdC5jb20ACgkQO1/MzfOr1wYzkwD9H0wbDbw9KNk4Wz5bwqa3SblpniWRByEg
 OeCWcZ68th8BAOS+jwufS002GImaUCYZLlsg0oRAYnTOp45vU65z5y0B
 =VOpz
 -----END PGP SIGNATURE-----

Merge tag 'next-pull-request' of https://gitlab.com/peterx/qemu into staging

Migration pull for rc1

- Bin's cleanup on migration blocktime (partly)
- Yujun's fix on print format

# -----BEGIN PGP SIGNATURE-----
#
# iIgEABYKADAWIQS5GE3CDMRX2s990ak7X8zN86vXBgUCal43iBIccGV0ZXJ4QHJl
# ZGhhdC5jb20ACgkQO1/MzfOr1wYzkwD9H0wbDbw9KNk4Wz5bwqa3SblpniWRByEg
# OeCWcZ68th8BAOS+jwufS002GImaUCYZLlsg0oRAYnTOp45vU65z5y0B
# =VOpz
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 20 Jul 2026 10:58:16 EDT
# gpg:                using EDDSA key B9184DC20CC457DACF7DD1A93B5FCCCDF3ABD706
# gpg:                issuer "peterx@redhat.com"
# gpg: Good signature from "Peter Xu <xzpeter@gmail.com>" [full]
# gpg:                 aka "Peter Xu <peterx@redhat.com>" [full]
# Primary key fingerprint: B918 4DC2 0CC4 57DA CF7D  D1A9 3B5F CCCD F3AB D706

* tag 'next-pull-request' of https://gitlab.com/peterx/qemu:
  migration: clean up postcopy blocktime presentation
  migration: fix ineffective overflow assert in postcopy blocktime
  migration: Fix invalid %ud format and trace arg typo

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-20 11:12:38 -04:00
Stefan Hajnoczi
90229f6aba * Fixes for various USB-related bugs
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEJ7iIR+7gJQEY8+q5LtnXdP5wLbUFAmpd+gkACgkQLtnXdP5w
 LbWVJQ//fnxnOSQLc977PcdQCy1jP7sQ7dO6Wb6WKddQuaGQh49wFeMdHp3ktfH/
 o3IslKo951H2urrz5KhStE08DumCgUxir+Yl6ImDqcOPA0Qzc6i9grxPhhpyUdtZ
 +o50nn73hBalKYf+s8qo81Ba39QdhsJwd5LoEPbmd21ZQiWsTOeQ7c0l8PkP7ZCt
 dnSf4ox7Vn8en897btcxhuY12u29NKPmWEWSLzgXJXmp1CHFTexml8Cp/qYaavg/
 jjE30rM0r/W2nkB3E1HMdMM8fvLeeKKwdarfdJ56Ysx/D4LOBR/aAGjWs8iYx/qM
 jjgzNt4Rps6eKfz+uMXOOvpLhYmue+D4OVZl0kxvoRKckVp6idMXBCWCTnXlthbl
 gxub+sbajrEi7HnT8CthTj8Ct6MTO04V2hpX5JmCrL+X+JLXxC6ZIbJKU7/WuwnT
 MpvkzkmwLPqlf2VKtEMgkRGsvEQz4rxOjpNjy7+TTFoKUd/qoCYyPiW1WL5/Bo6q
 M8z31tGcfmsV5P2A+8HTBwGUfHGByIONVq5J8T9E4dUo4wH5ar9avMKSrxVsFnTo
 a7D+reNJrLb3Y+qSq1U8TH2pf3xcNYz3JAsncBZOb688JbtKjpH5wDwHkH1Myjw7
 j5zEW/Put7xafKrD86I4N32X7V/SOrnnjZMFSYlqiM2wU1aCwcA=
 =cXwW
 -----END PGP SIGNATURE-----

Merge tag 'pull-request-2026-07-20' of https://gitlab.com/thuth/qemu into staging

* Fixes for various USB-related bugs

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEJ7iIR+7gJQEY8+q5LtnXdP5wLbUFAmpd+gkACgkQLtnXdP5w
# LbWVJQ//fnxnOSQLc977PcdQCy1jP7sQ7dO6Wb6WKddQuaGQh49wFeMdHp3ktfH/
# o3IslKo951H2urrz5KhStE08DumCgUxir+Yl6ImDqcOPA0Qzc6i9grxPhhpyUdtZ
# +o50nn73hBalKYf+s8qo81Ba39QdhsJwd5LoEPbmd21ZQiWsTOeQ7c0l8PkP7ZCt
# dnSf4ox7Vn8en897btcxhuY12u29NKPmWEWSLzgXJXmp1CHFTexml8Cp/qYaavg/
# jjE30rM0r/W2nkB3E1HMdMM8fvLeeKKwdarfdJ56Ysx/D4LOBR/aAGjWs8iYx/qM
# jjgzNt4Rps6eKfz+uMXOOvpLhYmue+D4OVZl0kxvoRKckVp6idMXBCWCTnXlthbl
# gxub+sbajrEi7HnT8CthTj8Ct6MTO04V2hpX5JmCrL+X+JLXxC6ZIbJKU7/WuwnT
# MpvkzkmwLPqlf2VKtEMgkRGsvEQz4rxOjpNjy7+TTFoKUd/qoCYyPiW1WL5/Bo6q
# M8z31tGcfmsV5P2A+8HTBwGUfHGByIONVq5J8T9E4dUo4wH5ar9avMKSrxVsFnTo
# a7D+reNJrLb3Y+qSq1U8TH2pf3xcNYz3JAsncBZOb688JbtKjpH5wDwHkH1Myjw7
# j5zEW/Put7xafKrD86I4N32X7V/SOrnnjZMFSYlqiM2wU1aCwcA=
# =cXwW
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 20 Jul 2026 06:35:53 EDT
# gpg:                using RSA key 27B88847EEE0250118F3EAB92ED9D774FE702DB5
# gpg: Good signature from "Thomas Huth <th.huth@gmx.de>" [full]
# gpg:                 aka "Thomas Huth <thuth@redhat.com>" [full]
# gpg:                 aka "Thomas Huth <huth@tuxfamily.org>" [full]
# gpg:                 aka "Thomas Huth <th.huth@posteo.de>" [full]
# gpg:                 aka "Thomas Huth <th.huth@posteo.eu>" [full]
# Primary key fingerprint: 27B8 8847 EEE0 2501 18F3  EAB9 2ED9 D774 FE70 2DB5

* tag 'pull-request-2026-07-20' of https://gitlab.com/thuth/qemu:
  hw/usb/hcd-xhci-sysbus: Fix OOB heap access in xhci_sysbus_intr_raise()
  hw/usb/hcd-xhci: Fix guest-triggerable assert() in xhci_find_stream()
  usbredir: fix infinite loop and SIGFPE with zero max_packet_size
  usbredir: fix use-after-free on buffered bulk packet overflow
  tests/qtest: add xhci-pci unplug finalize regression test
  hw/usb/hcd-xhci-pci: break host link cycle so device_finalize() runs on unplug
  hw/usb/xhci: clamp interval exponent to avoid UB shift in xhci_init_epctx()

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-20 11:12:31 -04:00
Stefan Hajnoczi
1a269766d4 linux-user for v11.1 pull request
One patch for the linux-user to fix the sparc target regarding signal handling.
 -----BEGIN PGP SIGNATURE-----
 
 iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCal0ZRgAKCRD3ErUQojoP
 X1K5AP0XoVwQ54p3sZgkQ81yHjH4Y4IUL/UKrAzDwLXQn05qbQEA3BpI+4JK03/N
 bxXzomlXJbSXlggNTf2pKCwRwGu6/QA=
 =odCr
 -----END PGP SIGNATURE-----

Merge tag 'linux-user-for-v11.1-pull-request' of https://github.com/hdeller/qemu-hppa into staging

linux-user for v11.1 pull request

One patch for the linux-user to fix the sparc target regarding signal handling.

# -----BEGIN PGP SIGNATURE-----
#
# iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCal0ZRgAKCRD3ErUQojoP
# X1K5AP0XoVwQ54p3sZgkQ81yHjH4Y4IUL/UKrAzDwLXQn05qbQEA3BpI+4JK03/N
# bxXzomlXJbSXlggNTf2pKCwRwGu6/QA=
# =odCr
# -----END PGP SIGNATURE-----
# gpg: Signature made Sun 19 Jul 2026 14:36:54 EDT
# gpg:                using EDDSA key BCE9123E1AD29F07C049BBDEF712B510A23A0F5F
# gpg: Good signature from "Helge Deller <deller@gmx.de>" [unknown]
# gpg:                 aka "Helge Deller <deller@kernel.org>" [unknown]
# gpg:                 aka "Helge Deller <deller@debian.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 4544 8228 2CD9 10DB EF3D  25F8 3E5F 3D04 A7A2 4603
#      Subkey fingerprint: BCE9 123E 1AD2 9F07 C049  BBDE F712 B510 A23A 0F5F

* tag 'linux-user-for-v11.1-pull-request' of https://github.com/hdeller/qemu-hppa:
  linux-user/sparc: Take pending signals in sparc64_set_context()

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-20 11:12:20 -04:00
Thomas Huth
cc479aa897 hw/usb/hcd-xhci-sysbus: Fix OOB heap access in xhci_sysbus_intr_raise()
Some machines like the microvm machine instantiate a "sysbus-xhci"
device with just 1 interrupt (by setting the "intrs" property to 1).
xhci_sysbus_realize() then only allocates the s->irq array with one
entry.

When the guest writes to the ERDP register of a corresponding XHCI
"interrupter", the generic XHCI code calls the xhci_sysbus_intr_raise()
function with n > 1, and this function then calls qemu_set_irq() with
s->irq[n] pointing to a bad heap address. The qemu_set_irq() then tries
to call an IRQ handler via a function pointer in that heap space. This
either causes QEMU to die with a segmentation fault (if it's a bad
address), or even worse runs some unexpected code if the destination
of the pointer is executable code.

Looking at the xHCI spec, it is up to the implementation of the host
controller how many interrupters are available. So if we only support
one or some few interrupters, the registers of the other interrupters
should not do anything, i.e. reads should result in zeros and writes
should be completely ignored. (big thanks to Peter Maydell for helping
with the analyzation of the correct way to fix this here)

This way, the xhci_sysbus_intr_raise() function cannot be called with
an invalid interrupt number anymore. But for good measure, also add an
assert() statement to the xhci_sysbus_intr_raise() function to prevent
that similar problems with calling arbitrary function pointers on the
heap could occur again.

Fixes: CVE-2026-16043
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4001
Reported-by: Tristan Madani <tristan@talencesecurity.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260719061528.15587-1-thuth@redhat.com>
2026-07-20 11:27:52 +02:00
Thomas Huth
4daeaa2fe0 hw/usb/hcd-xhci: Fix guest-triggerable assert() in xhci_find_stream()
The assert() statement in xhci_find_stream() can be triggered by
the guest (see bug tickets #273, #3895 and #3988 on gitlab.com).
Turn it into a qemu_log_mask() instead to fix this problem.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/273
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260715203357.424556-1-thuth@redhat.com>
2026-07-20 11:27:52 +02:00
Marc-André Lureau
a002485bfe usbredir: fix infinite loop and SIGFPE with zero max_packet_size
A malicious usbredir peer can send an ep_info message resetting
max_packet_size to 0 after bulk receiving has started. This causes:
- infinite loop in usbredir_buffered_bulk_packet() where the splitting
  loop increments by max_packet_size (0)
- SIGFPE in usbredir_buffered_bulk_in_complete_ftdi() from modulo by 0
- SIGFPE in usbredir_handle_buffered_bulk_in_data() from division by 0
  when computing bytes_per_transfer

Fix by stopping and disabling bulk receiving in usbredir_ep_info() when
max_packet_size is set to 0.

Add post-load check, and assert() for the invariant.

Fixes: CVE-2026-63319
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3995
Reported-by: Tristan @TristanInSec
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260716141107.3597076-1-marcandre.lureau@redhat.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
2026-07-20 11:27:52 +02:00
Marc-André Lureau
9bf52d056a usbredir: fix use-after-free on buffered bulk packet overflow
When usbredir_buffered_bulk_packet() splits a multi-fragment buffered
bulk packet into max-packet-size chunks, only the final fragment owns
the shared parser allocation (via free_on_destroy). If bufp_alloc()
drops the final fragment due to queue overflow, it frees the backing
buffer while earlier fragments already queued still hold interior
pointers into it. Subsequent guest bulk-IN transfers then read from
freed heap memory.

Fix this by tracking how many fragments were queued during the current
packet. When bufp_alloc() fails, remove all already-queued fragments
from the tail of the endpoint queue before breaking out of the loop.
If the dropped fragment was non-final, free the data buffer explicitly
since no fragment took ownership.

Fixes: CVE-2026-15705
Fixes: b2d1fe67d0 ("usbredir: Add support for buffered bulk input (v2)")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3808
Reported-by: Feifan Qian <bea1e@proton.me>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260714185717.1156157-1-marcandre.lureau@redhat.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
2026-07-20 11:27:52 +02:00
Xiangfeng Cai
ba54d7e66e tests/qtest: add xhci-pci unplug finalize regression test
Add a qtest that hot-adds an nec-usb-xhci controller, requests unplug,
resets the system to process the request, and waits for DEVICE_DELETED.
This covers the xHCI PCI host-link refcount cycle by verifying that
device_finalize() runs after unplug.

Signed-off-by: Xiangfeng Cai <caixiangfeng@bytedance.com>
Message-ID: <20260618110119.3084296-3-caixiangfeng@bytedance.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
2026-07-20 11:27:52 +02:00
Xiangfeng Cai
054ef33f67 hw/usb/hcd-xhci-pci: break host link cycle so device_finalize() runs on unplug
The xHCI PCI wrapper embeds an xhci-core child via object_initialize_child()
and, in usb_xhci_pci_realize(), points the child's "host" link back at the PCI
device:

    object_property_set_link(OBJECT(&s->xhci), "host", OBJECT(s), NULL);

"host" is a DEFINE_PROP_LINK property, which qdev registers as an
OBJ_PROP_LINK_STRONG link. A strong link takes a reference on its target, so
this creates a refcount cycle: the PCI device owns the child, and the child's
strong link pins the PCI device.

On unplug (guest ACPI eject or QMP device_del), pci_qdev_unrealize() calls
pc->exit() but never unrealizes the no-bus child. object_unparent() then drops
only the parent/bus references, leaving the link reference in place. The PCI
device stays at refcount 1 forever, so object_finalize()/device_finalize() is
never reached. Symptom observed under gdb after eject:

    p *((Object *)dev)  =>  ref = 1, parent = 0x0, realized = false
    p ((XHCIPciState *)dev)->xhci.hostOpaque  =>  points back at dev

Fix usb_xhci_pci_exit() to tear down the embedded child explicitly: unrealize
it first (so the set-link-before-realize check passes), then clear the "host"
link. This releases the strong reference, lets the PCI device refcount reach 0,
and allows device_finalize() to run.

Fixes: 8ddab8dd3d ("usb/hcd-xhci: Split pci wrapper for xhci base model")
Signed-off-by: Xiangfeng Cai <caixiangfeng@bytedance.com>
Acked-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260618110119.3084296-2-caixiangfeng@bytedance.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
2026-07-20 11:27:52 +02:00
Feifan Qian
12d8ee9d53 hw/usb/xhci: clamp interval exponent to avoid UB shift in xhci_init_epctx()
The xHCI endpoint context dword 0 bits 23:16 ("Interval") are written
by the guest and passed directly as the shift amount in:

    epctx->interval = 1 << ((ctx[0] >> 16) & 0xff);

The shift amount can be 0-255.  Shifting a 32-bit `int` left by >= 32
is undefined behaviour under C11 §6.5.7p4.  With UBSan
(halt_on_error=1) this causes QEMU to abort; with aggressive compiler
optimisations that assume UB is unreachable the result is
unpredictable.

Clamp the exponent to [0, 18] with MIN() before the shift, and use
`1u` (unsigned) to avoid shifting a signed integer.  The xHCI
specification defines a maximum meaningful Interval value of 18 for
most endpoint types; thus clamping to 18 is a safe fix that
preserves the full unsigned 32-bit range for any compliant value.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3703
Reported-by: Feifan Qian <bea1e@proton.me>
Signed-off-by: Feifan Qian <bea1e@proton.me>
[thuth: Clamp to 18 instead of 31]
Signed-off-by: Thomas Huth <thuth@redhat.com>
2026-07-20 11:05:50 +02:00
Stefan Hajnoczi
b9e9a55f99 Hexagon fix queue
Fixes for these issues:
 
 * fix unaligned scalar accesses (now correctly faults/raises exception)
 * fix build error with --disable-hexagon-idef-parser and gcc 14
 * fix system emulation bugs: packet sreg writes, PC stuck on non-COF TB-end
 * fix debug accesses w/MMU
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEPWaq5HRZSCTIjOD4GlSvuOVkbDIFAmpafbcACgkQGlSvuOVk
 bDIdcRAAn5KmbHrrVpx7IArEybXMOnnARkacIUOmMWIY9zcU7e3jcq3BvdYysG3r
 VmcsUa/r0jxV8ix0TZui6qTtikNOmS2GPf4q4TxopwCv+YCteKPK5cLXmZ3cmMPM
 nv3Maoe3WnIVY9ZMTSIA3B+BY2QlfCSKb71Q4Ll8KkI19sX0t4lkQbjeMLkAkOML
 Kg5u7+A4uGVD9WFWxjn0G3Uuji5+xOqvPPTiM1oi8IIT/jUDREx1M4yQU0s/o3y1
 0wVhCAwkbqCrSi1Kkwk23WSFDtA5l9ggFN52lNoJkwgDbVXZ6MZnTanbgR58mlGB
 09CzAA4QbNMpL9chbQiY4T9utni3td7RC+edCAd+r5+pBIzQn25dLVUAutqqVOiH
 g90x/HBx9sv8MiFcYRCsSZ4bhcnfW2Wip58Ub/7lkMb90/2OOhcORpeufMHqkNfj
 IsMLRoMPXdT/YLyCsALK7WW8zYpFyFlFPcX475T9Z/D1Pr/UN2SGoNe4L9hltCdI
 0E/5NcDHBuKYxua+v4wKzPxAYsBBcS0ldfCjwiuef3CR6V7xQVYRvjvOHtckl5+B
 k3fXyORqtkF00B4cuGNIXPFV5z+ei4WTPKBZlxn4/rmDf4sdZcoHowEFMp1hbI2L
 8yPTswzKHByIibFg8wF6xzE/duoS2Lo+eg9WBfvr3UY8WQtz44w=
 =Q8R/
 -----END PGP SIGNATURE-----

Merge tag 'hex-next-express-pull-request' of https://github.com/qualcomm/qemu into staging

Hexagon fix queue

Fixes for these issues:

* fix unaligned scalar accesses (now correctly faults/raises exception)
* fix build error with --disable-hexagon-idef-parser and gcc 14
* fix system emulation bugs: packet sreg writes, PC stuck on non-COF TB-end
* fix debug accesses w/MMU

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEPWaq5HRZSCTIjOD4GlSvuOVkbDIFAmpafbcACgkQGlSvuOVk
# bDIdcRAAn5KmbHrrVpx7IArEybXMOnnARkacIUOmMWIY9zcU7e3jcq3BvdYysG3r
# VmcsUa/r0jxV8ix0TZui6qTtikNOmS2GPf4q4TxopwCv+YCteKPK5cLXmZ3cmMPM
# nv3Maoe3WnIVY9ZMTSIA3B+BY2QlfCSKb71Q4Ll8KkI19sX0t4lkQbjeMLkAkOML
# Kg5u7+A4uGVD9WFWxjn0G3Uuji5+xOqvPPTiM1oi8IIT/jUDREx1M4yQU0s/o3y1
# 0wVhCAwkbqCrSi1Kkwk23WSFDtA5l9ggFN52lNoJkwgDbVXZ6MZnTanbgR58mlGB
# 09CzAA4QbNMpL9chbQiY4T9utni3td7RC+edCAd+r5+pBIzQn25dLVUAutqqVOiH
# g90x/HBx9sv8MiFcYRCsSZ4bhcnfW2Wip58Ub/7lkMb90/2OOhcORpeufMHqkNfj
# IsMLRoMPXdT/YLyCsALK7WW8zYpFyFlFPcX475T9Z/D1Pr/UN2SGoNe4L9hltCdI
# 0E/5NcDHBuKYxua+v4wKzPxAYsBBcS0ldfCjwiuef3CR6V7xQVYRvjvOHtckl5+B
# k3fXyORqtkF00B4cuGNIXPFV5z+ei4WTPKBZlxn4/rmDf4sdZcoHowEFMp1hbI2L
# 8yPTswzKHByIibFg8wF6xzE/duoS2Lo+eg9WBfvr3UY8WQtz44w=
# =Q8R/
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri 17 Jul 2026 15:08:39 EDT
# gpg:                using RSA key 3D66AAE474594824C88CE0F81A54AFB8E5646C32
# gpg: Good signature from "Brian Cain (OSS Qualcomm) <brian.cain@oss.qualcomm.com>" [unknown]
# gpg:                 aka "Brian Cain <bcain@kernel.org>" [unknown]
# gpg:                 aka "Brian Cain (QuIC) <bcain@quicinc.com>" [unknown]
# gpg:                 aka "Brian Cain (CAF) <bcain@codeaurora.org>" [unknown]
# gpg:                 aka "bcain" [unknown]
# gpg:                 aka "Brian Cain (QUIC) <quic_bcain@quicinc.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 6350 20F9 67A7 7164 79EF  49E0 175C 464E 541B 6D47
#      Subkey fingerprint: 3D66 AAE4 7459 4824 C88C  E0F8 1A54 AFB8 E564 6C32

* tag 'hex-next-express-pull-request' of https://github.com/qualcomm/qemu:
  tests/functional/hexagon: add arch_tests functional test
  target/hexagon: fix PC not advancing for non-COF TB-ending packets
  target/hexagon: initialize deferred sreg-write temps to current value
  target/hexagon: fix get_phys_addr_debug with in-page offset
  tests/tcg/hexagon: add unaligned scalar test
  target/hexagon: raise SIGBUS on unaligned data access in sysemu
  target/hexagon: raise SIGBUS on unaligned scalar stores
  target/hexagon: raise SIGBUS on unaligned scalar loads
  target/hexagon: handle misaligned load/store cause codes in cpu_loop
  target/hexagon: fix -Wshadow=local build error on GCC 14
  gitlab-ci: build hexagon-softmmu to enable functional test
  tests/docker: hexagon fix podman untar, 22.1.8

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-18 19:17:14 -04:00
Stefan Hajnoczi
bd9a2e5974 Various UI/security-related fixes for 11.1
To: qemu-devel@nongnu.org
 Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmpaF38ACgkQ2ujhCXWW
 nOWJLQ//Qo05CJVgpZyhYb2xCgWGBXZ5DmNIB6FidL3ZF7OHavpuGfT0c35TA6Iy
 wh8U7x44FFsvc0N1T52es13sEX6ff8KSGRL356fVq1O5KdbLUg9NxQ7DFHBAQFkA
 rk/A/tj1+4F/T2snukpSr/M8XDL9nLtCC4vVasFysce6TdGFiRrYYoYSMoV7sPMD
 meBTLqHUXMoqCW84K0bX5CZWii3j//ZkoRDoSn3n61QrUAw3hQEc4jB8heHY2MW4
 i1sIYHbfoO5l75mZPfm34aSs889ooEfw0MVMYb4BqMXdFxwm8UuvyMrCv5sT/SKJ
 XsfSgtdCYODrlkDscGW9X774QtejuIsEsKp73ZANBj7U4W/JysAc55Ej9doaY8SO
 teLiR0/0tJD0+z7K4z5Euqzv0DXUPM/LTWAkoa77JyUPWIuzRUftbEAtvLQEYhCf
 S08SILBUcMytD6tBGOXw5tO+MLL313hGjfWB/KxKQM9GtxzK22+wMHOiry91WcD2
 duPuExN21irqsNtBoJ5EHE5EluUIFZjqEILNqtwPoiUU4sn1tPDUeXXzv1AXtln/
 y0JGp7zg1y+wMswkBEES8nrSQhWHNkY9nWOseY/N2LzPs7CyZmgI1ZIU8aW3U20g
 jg77LHTXTfwJyHChGo3SiYpm++x4GDrt+WOi8o4SpcTzLW0+KIA=
 =uFU3
 -----END PGP SIGNATURE-----

Merge tag 'fix-pr-v1' of https://gitlab.com/marcandre.lureau/qemu into staging

Various UI/security-related fixes for 11.1

To: qemu-devel@nongnu.org
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmpaF38ACgkQ2ujhCXWW
# nOWJLQ//Qo05CJVgpZyhYb2xCgWGBXZ5DmNIB6FidL3ZF7OHavpuGfT0c35TA6Iy
# wh8U7x44FFsvc0N1T52es13sEX6ff8KSGRL356fVq1O5KdbLUg9NxQ7DFHBAQFkA
# rk/A/tj1+4F/T2snukpSr/M8XDL9nLtCC4vVasFysce6TdGFiRrYYoYSMoV7sPMD
# meBTLqHUXMoqCW84K0bX5CZWii3j//ZkoRDoSn3n61QrUAw3hQEc4jB8heHY2MW4
# i1sIYHbfoO5l75mZPfm34aSs889ooEfw0MVMYb4BqMXdFxwm8UuvyMrCv5sT/SKJ
# XsfSgtdCYODrlkDscGW9X774QtejuIsEsKp73ZANBj7U4W/JysAc55Ej9doaY8SO
# teLiR0/0tJD0+z7K4z5Euqzv0DXUPM/LTWAkoa77JyUPWIuzRUftbEAtvLQEYhCf
# S08SILBUcMytD6tBGOXw5tO+MLL313hGjfWB/KxKQM9GtxzK22+wMHOiry91WcD2
# duPuExN21irqsNtBoJ5EHE5EluUIFZjqEILNqtwPoiUU4sn1tPDUeXXzv1AXtln/
# y0JGp7zg1y+wMswkBEES8nrSQhWHNkY9nWOseY/N2LzPs7CyZmgI1ZIU8aW3U20g
# jg77LHTXTfwJyHChGo3SiYpm++x4GDrt+WOi8o4SpcTzLW0+KIA=
# =uFU3
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri 17 Jul 2026 07:52:31 EDT
# gpg:                using RSA key 87A9BD933F87C606D276F62DDAE8E10975969CE5
# gpg: Good signature from "Marc-André Lureau <marcandre.lureau@redhat.com>" [full]
# gpg:                 aka "Marc-André Lureau <marcandre.lureau@gmail.com>" [full]
# Primary key fingerprint: 87A9 BD93 3F87 C606 D276  F62D DAE8 E109 7596 9CE5

* tag 'fix-pr-v1' of https://gitlab.com/marcandre.lureau/qemu:
  hw/display/virtio-gpu: Check pixman_image_create_bits() results
  hw/display/virtio-gpu: reject strides exceeding INT_MAX
  hw/display/virtio-gpu: handle migration iov allocation failure
  hw/display/virtio-gpu: cap submit_3d command buffer allocation
  hw/display/virtio-gpu: validate stride against width on scanout
  hw/display/qxl: fix TOCTOU in cursor chunk data_size handling
  hw/display/virtio-gpu: fix dmabuf_fd leak on remap failure
  ui/vnc: validate SetPixelFormat field ranges
  ui/vnc: fix out-of-bounds write in lossy refresh dirty marking
  ui/gtk: Narrow DMA-BUF critical section
  ui/input-barrier: fix off-by-one in keycode bounds check
  ui/vnc: use RFB wire types for client message handlers
  ui/vnc: validate color shifts in SetPixelFormat
  ui/vnc: fix OOB write in vnc_refresh_lossy_rect
  i386/tdx: fix uninitialized variable warning in tdx_check_features

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-18 19:16:51 -04:00
Peter Maydell
c0e370474b linux-user/sparc: Take pending signals in sparc64_set_context()
Every callsite of block_signals() checks its return value, except
the one in sparc64_set_context(). Generally you need to check,
because the standard pattern is:

    if (block_signals()) {
        return -QEMU_ERESTARTSYS;
    }
    /* do some blocking syscall */

and we need to take any pending signal before we do the blocking
operation, not afterwards.

The use in sparc64_set_context() doesn't do this.  It doesn't have to
because the operations it is doing aren't blocking, so it won't get
into "we didn't take the signal that we should have" races that
blocking syscalls do.  But it does make this way of updating the
signal mask inconsistent with how we do it in do_sigprocmask().
do_sigprocmask() does the usual "return -QEMU_ERESTARTSYS", so a
pending signal that was not blocked by the old signal mask and which
will be blocked by the new mask we're about to install will be taken
before we change the mask.  sparc64_set_context() doesn't check the
return value, so we won't take that pending signal.  That's not
wrong, because it just means the signal lost the race with the
executing code.  But it seems clearer to behave the same way as
do_sigprocmask(), not differently.

Make sparc64_set_context() check the return value of block_signals()
and return early if there's a pending signal to take.  We don't need
to return a separate return code to indicate this because the main
loop handles it the same either way.

Coverity CID: 1660058

Fixes: e0f0ce88eb ("linux-user/sparc: call block_signals() before set_sigmask() in setcontext")
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Matt Turner <mattst88@gmail.com>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-07-18 23:47:33 +02:00
Stefan Hajnoczi
43bf3a0ce9 Changes:
- [PATCH v3] tests/docker: ensure container command is probed at most (=?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= <berrange@redhat.com>)
   Link: https://lore.kernel.org/qemu-devel/20260716102515.1503404-1-berrange@redhat.com
 -----BEGIN PGP SIGNATURE-----
 
 iQGzBAABCgAdFiEEN8FWlNi6l2Sxlz/btEQ30ZwoYt8FAmpZN8kACgkQtEQ30Zwo
 Yt8XSgwApNAUMhYPKaV69+X0BkeQfJZrjHWP6+19RTSr05ze/x6Ugz84Xc9m0M0O
 Onf6Aa+KryULysNiR8bnHmvBtOfHYkjgqKc9GjAUeBkPSuwW2PgD94N5VSd7RWzI
 38mkTVzqw2l07HwnSHl82L5VDUB74GVsgoOevIKqbhlmxG+NdvYwCIDy9F4VzG3O
 R0uWoHfY7uTMho21ae1FB5OyFAfMlIpTEHQzKSNNzLYhDMeThMPNZg1AE+ZCoFff
 py91b1ECgofpIxt7CFNp9dy1FDW8NzIAHA+HvEWYvvuB0uVjPg1UjJfi29XST1wu
 kq8E7d2o2Dc5mUbx8rzSqBAt6b6pYMxNAy3m6VwP4KXOJdGnoCUy4AcEiPd4/xXp
 fKGTxA9HsoXacticUGhqqb1e8XCTusEj5ICUsjbl8dSo1oXAdDWOZe9IcfQLhBOx
 A5dYetdbzdH7iaEDGiQvlfuxYLR1mZQAxikjEZF4xkCmcNH/yskONceENwLZuuaP
 alqDEN9G
 =OcuQ
 -----END PGP SIGNATURE-----

Merge tag 'pbouvier/pr/docker-20260716' of https://gitlab.com/p-b-o/qemu into staging

Changes:
- [PATCH v3] tests/docker: ensure container command is probed at most (=?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= <berrange@redhat.com>)
  Link: https://lore.kernel.org/qemu-devel/20260716102515.1503404-1-berrange@redhat.com

# -----BEGIN PGP SIGNATURE-----
#
# iQGzBAABCgAdFiEEN8FWlNi6l2Sxlz/btEQ30ZwoYt8FAmpZN8kACgkQtEQ30Zwo
# Yt8XSgwApNAUMhYPKaV69+X0BkeQfJZrjHWP6+19RTSr05ze/x6Ugz84Xc9m0M0O
# Onf6Aa+KryULysNiR8bnHmvBtOfHYkjgqKc9GjAUeBkPSuwW2PgD94N5VSd7RWzI
# 38mkTVzqw2l07HwnSHl82L5VDUB74GVsgoOevIKqbhlmxG+NdvYwCIDy9F4VzG3O
# R0uWoHfY7uTMho21ae1FB5OyFAfMlIpTEHQzKSNNzLYhDMeThMPNZg1AE+ZCoFff
# py91b1ECgofpIxt7CFNp9dy1FDW8NzIAHA+HvEWYvvuB0uVjPg1UjJfi29XST1wu
# kq8E7d2o2Dc5mUbx8rzSqBAt6b6pYMxNAy3m6VwP4KXOJdGnoCUy4AcEiPd4/xXp
# fKGTxA9HsoXacticUGhqqb1e8XCTusEj5ICUsjbl8dSo1oXAdDWOZe9IcfQLhBOx
# A5dYetdbzdH7iaEDGiQvlfuxYLR1mZQAxikjEZF4xkCmcNH/yskONceENwLZuuaP
# alqDEN9G
# =OcuQ
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 16 Jul 2026 15:58:01 EDT
# gpg:                using RSA key 37C15694D8BA9764B1973FDBB44437D19C2862DF
# gpg: Good signature from "Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 37C1 5694 D8BA 9764 B197  3FDB B444 37D1 9C28 62DF

* tag 'pbouvier/pr/docker-20260716' of https://gitlab.com/p-b-o/qemu:
  tests/docker: ensure container command is probed at most once

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-18 17:32:38 -04:00
Stefan Hajnoczi
3b49fccda4 Changes:
- [PATCH v2 0/2] plugins/execlog: fix segfault and flush output on vcpu (Harry van Haaren <harry.vanhaaren@openchip.com>)
   Link: https://lore.kernel.org/qemu-devel/20260716094126.787556-1-harry.vanhaaren@openchip.com
 -----BEGIN PGP SIGNATURE-----
 
 iQGzBAABCgAdFiEEN8FWlNi6l2Sxlz/btEQ30ZwoYt8FAmpZN5UACgkQtEQ30Zwo
 Yt/eGQv+OFExxMNfE2ZNGCEmXu9JQkZu7m+aXVVz0Vfq2PjV2Gyz5xuvllFeXpoq
 vgdJl/pUzqY457p8dqnKgOa/wB++J6u4692O5jYsUCYWIAweLZxFyRu5fl+r7yz4
 Yo0rkWvBFUZKVl5LpKKbaQnLqkmP17xTCeLk7PLu5Gh5hWfVK+ReBKogDOSp232K
 8tvyB7JL9H5RoL9BurYXmyplFqjAOjRelYKFJ5bF4O7Ayo8vtCRVyIyk7ydKT43q
 1w4BIRBFVaKwQ9VZVk01eXU11EP98hmwi9/umPpDdGkqZGL9qfqBTsdeQ3Ej/ifw
 ruwY3G2LDPQJCXlHOUE4RUoxw+naThyN/Y4dSyhtjSdimrpjAyB1sKCUxoVBKh84
 wBCzx99sh1g2RmtXzYa9c6cavGNnkuorSgmhL+0aKWL8T8oBbDW0m2vZCZJ/Vy41
 XkeR/HRq6ag29YB7pKLUpurou9a7vx4U4EgPf0/R9XqUkPqRws6Ma7jpxl/71GAt
 akiO6qgr
 =yj8L
 -----END PGP SIGNATURE-----

Merge tag 'pbouvier/pr/plugins-20260716' of https://gitlab.com/p-b-o/qemu into staging

Changes:
- [PATCH v2 0/2] plugins/execlog: fix segfault and flush output on vcpu (Harry van Haaren <harry.vanhaaren@openchip.com>)
  Link: https://lore.kernel.org/qemu-devel/20260716094126.787556-1-harry.vanhaaren@openchip.com

# -----BEGIN PGP SIGNATURE-----
#
# iQGzBAABCgAdFiEEN8FWlNi6l2Sxlz/btEQ30ZwoYt8FAmpZN5UACgkQtEQ30Zwo
# Yt/eGQv+OFExxMNfE2ZNGCEmXu9JQkZu7m+aXVVz0Vfq2PjV2Gyz5xuvllFeXpoq
# vgdJl/pUzqY457p8dqnKgOa/wB++J6u4692O5jYsUCYWIAweLZxFyRu5fl+r7yz4
# Yo0rkWvBFUZKVl5LpKKbaQnLqkmP17xTCeLk7PLu5Gh5hWfVK+ReBKogDOSp232K
# 8tvyB7JL9H5RoL9BurYXmyplFqjAOjRelYKFJ5bF4O7Ayo8vtCRVyIyk7ydKT43q
# 1w4BIRBFVaKwQ9VZVk01eXU11EP98hmwi9/umPpDdGkqZGL9qfqBTsdeQ3Ej/ifw
# ruwY3G2LDPQJCXlHOUE4RUoxw+naThyN/Y4dSyhtjSdimrpjAyB1sKCUxoVBKh84
# wBCzx99sh1g2RmtXzYa9c6cavGNnkuorSgmhL+0aKWL8T8oBbDW0m2vZCZJ/Vy41
# XkeR/HRq6ag29YB7pKLUpurou9a7vx4U4EgPf0/R9XqUkPqRws6Ma7jpxl/71GAt
# akiO6qgr
# =yj8L
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 16 Jul 2026 15:57:09 EDT
# gpg:                using RSA key 37C15694D8BA9764B1973FDBB44437D19C2862DF
# gpg: Good signature from "Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 37C1 5694 D8BA 9764 B197  3FDB B444 37D1 9C28 62DF

* tag 'pbouvier/pr/plugins-20260716' of https://gitlab.com/p-b-o/qemu:
  plugins/execlog: fix execlog vcpu_exit execution print loss
  plugins/execlog: fix segfault/race-cond on per-vCPU structures

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-18 17:32:11 -04:00
Brian Cain
260d15c45b tests/functional/hexagon: add arch_tests functional test
Add new test cases from hexagon-arch-tests to exercise exceptions,
guest mode.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:04:45 -07:00
Brian Cain
94a5b3ff4e target/hexagon: fix PC not advancing for non-COF TB-ending packets
Add hex_next_PC, a global mirroring CPUHexagonState::next_PC,
and ctx->need_next_pc, so that gen_write_new_pc_addr() can write the
branch target through hex_next_PC instead of hex_gpr[HEX_REG_PC]
when a later unconditional write of PC is expected. gen_end_tb()
then commits hex_next_PC into hex_gpr[HEX_REG_PC] at the end of the
packet.

Previously, non-COF instructions that still end a TB did not advance the
PC, since next_PC's value was never written back into the PC register.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:04:45 -07:00
Brian Cain
c4066c84cd target/hexagon: initialize deferred sreg-write temps to current value
Unconditionally allocate and initialize the temp to the sreg's current
value for every logged sreg write, rather than only allocating
when need_commit is set or the register is SSR.

Without this, reading a deferred sreg write within the same packet
before it is committed can observe an uninitialized temp instead
of the register's pre-packet value.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:04:45 -07:00
Matheus Tavares Bernardino
44d1829c6c target/hexagon: fix get_phys_addr_debug with in-page offset
As documented:

     * @get_phys_addr_debug: Callback for obtaining a physical address.
     * This must be able to handle a non-page-aligned address, and will
     * return the physical address corresponding to that address.

When MMU is enabled, hexagon_cpu_get_phys_addr_debug() returns the
physical address page-aligned, not corrected to reflect the exact byte
the virtual addr maps to within the page. Let's fix that. The
MMU-disabled case is already correct.

This would break semihosting argument reads when it is added for Hexagon.

Signed-off-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:04:45 -07:00
Brian Cain
430261acac tests/tcg/hexagon: add unaligned scalar test
Add unaligned_data.c to exercise unaligned memh/memw/memd accesses and
verify SIGBUS is raised and caught.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:04:45 -07:00
Brian Cain
13eb268182 target/hexagon: raise SIGBUS on unaligned data access in sysemu
hexagon-softmmu had no enforcement of alignment for scalar loads and
stores: the MO_ALIGN flag added by the previous two commits triggers
TLB_INVALID_MASK/alignment faults in cputlb.c, but Hexagon's
TCGCPUOps did not implement do_unaligned_access, so the fault was
never delivered to the guest.

Add hexagon_cpu_do_unaligned_access(), which raises
HEX_CAUSE_MISALIGNED_LOAD/_STORE via the existing HEX_EVENT_PRECISE
path, mirroring raise_tlbmiss_exception()/raise_perm_exception().

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Reviewed-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:04:45 -07:00
Brian Cain
84b9a537d6 target/hexagon: raise SIGBUS on unaligned scalar stores
hexagon-linux-user had no enforcement of alignment for scalar store
exceptions, and unaligned stores silently succeeded instead of raising
SIGBUS.

Stores are logged rather than committed immediately, so both commit
paths need the fix.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Reviewed-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:04:45 -07:00
Brian Cain
93cf730514 target/hexagon: raise SIGBUS on unaligned scalar loads
hexagon-linux-user had no enforcement of alignment for scalar load
exceptions, and unaligned loads silently succeeded instead of raising
SIGBUS.

Add MO_ALIGN to the MEM_LOAD* macros, the locked-load and
load-frame helpers in genptr.c, and the idef-parser's fLOAD.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Reviewed-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:04:45 -07:00
Brian Cain
d7a6df755b target/hexagon: handle misaligned load/store cause codes in cpu_loop
Add a linux-user cpu_loop handler for HEX_CAUSE_MISALIGNED_LOAD and
HEX_CAUSE_MISALIGNED_STORE, raising SIGBUS for consistency with
hexswi.c's sysemu handling, even though linux-user's own alignment
check in accel/tcg/user-exec.c currently raises SIGBUS before
Hexagon's cause-code machinery is reached.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Reviewed-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:04:45 -07:00
Brian Cain
8aea63e965 target/hexagon: fix -Wshadow=local build error on GCC 14
With --disable-hexagon-idef-parser, tcg_funcs_generated.c.inc fails
to build under GCC 14 with:

  error: declaration of 'HALF' shadows a previous local
  [-Werror=shadow=local]

This became a hard error with GCC ced651b7757e `c23: tag compatibility
rules for enums`.

After that GCC change, DECL_FILE_SCOPE_P is false for all
enumerators, so shadowing now falls under -Wshadow=local.

Rename the local variable to tmp_half to avoid the collision.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:04:45 -07:00
Brian Cain
e872e09add gitlab-ci: build hexagon-softmmu to enable functional test
Add hexagon-softmmu to build-system-debian's target list so that the
existing functional-system-debian job picks up hexagon functional
test.

Reviewed-by: Thomas Huth <thuth@redhat.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:04:45 -07:00
Brian Cain
390bf4fbc3 tests/docker: hexagon fix podman untar, 22.1.8
The debian-hexagon-cross image previously unpacked the codelinaro
clang+llvm hexagon toolchain by piping a .tar.zst archive straight
into "tar --zstd -xC". GNU tar restores the archive's stored file
modes on extraction, including lchmod() on symlinks. Under rootless
podman, where the build runs in a user namespace on overlay storage,
those chmod()/lchmod() calls are rejected with EPERM:

  tar: .../libclang_rt.builtins.a: Cannot change mode to rwxrwxrwx: \
       Operation not permitted
  tar: .../x86_64-linux-gnu: Cannot change mode to rwxr-xr-x: \
       Operation not permitted
  tar: Exiting with failure status due to previous errors

tar then exits non-zero and aborts the build, so debian-hexagon-cross
only builds reliably under docker, not rootless podman.

So instead we can switch to a different packaging.  clang, lld
come from LLVM Debian builds from apt.llvm.org, instead of custom ones for
hexagon.  And only the hexagon linux sysroot is required, avoiding the
tar issues.

Reviewed-by: Matheus Tavares Bernardino <quic_mathbern@quicinc.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
2026-07-17 10:03:51 -07:00
Bin Guo
60f2281450 migration: clean up postcopy blocktime presentation
Small cleanups for the postcopy blocktime fine-grained tracking
feature:

* Remove a redundant memset() on latency_buckets after g_new0().
* Use singular "Latency" in the HMP label for postcopy non-vCPU
  latency, consistent with other single-value labels.

Signed-off-by: Bin Guo <guobin@linux.alibaba.com>
Link: https://lore.kernel.org/r/20260716101952.65329-4-guobin@linux.alibaba.com
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-07-17 12:33:42 -04:00
Bin Guo
c923ae77e7 migration: fix ineffective overflow assert in postcopy blocktime
vcpu_faults_current[] is uint8_t.  The overflow assert was checked
after the post-increment, so 255 would wrap to 0 and the assert
would pass silently.  Move the check before the increment and use
< 255.

Signed-off-by: Bin Guo <guobin@linux.alibaba.com>
Link: https://lore.kernel.org/r/20260716101952.65329-2-guobin@linux.alibaba.com
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-07-17 12:33:34 -04:00
Akihiko Odaki
f1af81ba2a hw/display/virtio-gpu: Check pixman_image_create_bits() results
pixman_image_create_bits() returns NULL for allocation failures and
unaligned strides, which may be supplied by the guest with
VIRTIO_GPU_CMD_SET_SCANOUT_BLOB, and virtio_gpu_do_set_scanout()
subsequently dereferences it.

Fixes: fa06e5cb7b ("virtio-gpu: fix scanout rectangles")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260717-pixman-v1-1-89ea33b50b75@rsg.ci.i.u-tokyo.ac.jp>
2026-07-17 15:52:31 +04:00
Akihiko Odaki
9c724426f5 hw/display/virtio-gpu: reject strides exceeding INT_MAX
VIRTIO_GPU_CMD_SET_SCANOUT_BLOB supplies a guest-controlled uint32_t
stride, but some downstream consumers take it as int. They may interpret
a value greater than INT_MAX as negative and cause issues:

- pixman_image_create_bits() takes the stride as int, and Pixman may
  later access memory before the blob buffer.

- eglCreateImageKHR() also takes the stride as EGLint when importing the
  DMA-BUF, and Mesa rejects it.

Reject such strides before scanout.

The check in virtio_gpu_scanout_blob_to_fb() rejects unsupported blob
configurations early. The check added in virtio_gpu_do_set_scanout()
covers migration post_load.

Fixes: 32db3c63ae ("virtio-gpu: Add virtio_gpu_set_scanout_blob")
Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260717-int-v1-1-8aa05e1791a0@rsg.ci.i.u-tokyo.ac.jp>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
e99488c5d4 hw/display/virtio-gpu: handle migration iov allocation failure
An unbounded iov_cnt from the migration stream drives two g_new()
allocations whose combined size can exceed available memory, causing
GLib to abort the process.

Switch to g_try_new() and propagate the failure as a migration error.

Fixes: 0c244e50ee ("virtio-gpu: add live migration support")
Fixes: f66767f75c ("virtio-gpu: add virtio-gpu/blob vmstate subsection")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3753
Reported-by: Feifan Qian <bea1e@proton.me>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
8720061c6d hw/display/virtio-gpu: cap submit_3d command buffer allocation
Both virgl_cmd_submit_3d() and rutabaga_cmd_submit_3d() pass the
guest-controlled cs.size directly to malloc() without bounds checking. A
malicious guest can set cs.size to an arbitrarily large value, causing
an OOM abort that crashes the QEMU process.

Checking cs.size against the descriptor payload length (iov_size) is not
sufficient: indirect descriptor tables can repeat entries aliasing the
same guest-physical range, inflating iov_size() to nearly 4 GiB while
referring to only a small amount of unique memory.

Instead, cap cs.size at 4 MiB. With 4 KiB pages and QEMU's
VIRTQUEUE_MAX_SIZE (1024) mapped-iov limit, the Linux virtio driver
cannot carry more than ~4 MiB of inline command data, so legitimate
submissions are unaffected.

Fixes: 9d9e152136 ("virtio-gpu: add 3d mode and virgl rendering support.")
Fixes: 1dcc6adbc1 ("gfxstream + rutabaga: add initial support for gfxstream")
Fixes: d52c454aad ("contrib: add vhost-user-gpu")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3776
Reported-by: admin@fluentlogic.org
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
861372428b hw/display/virtio-gpu: validate stride against width on scanout
Validate that the framebuffer stride is at least width * bytes_per_pixel
in both virtio_gpu_scanout_blob_to_fb() and virtio_gpu_do_set_scanout().

A guest can set a very small stride while using a large width. The total
size check (offset + stride * height <= blob_size) passes because
stride * height is small, but pixman reads width * bytes_per_pixel per
row, causing heap OOB reads. The leaked data is rendered to the host
display.

The check is added in virtio_gpu_do_set_scanout() to cover all paths:
blob scanout, non-blob scanout and migration post_load. The additional
early check in virtio_gpu_scanout_blob_to_fb() rejects invalid blob
configurations early.

Fixes: CVE-2026-63109
Fixes: 7b55742254 ("hw/display: check frame buffer can hold blob")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3989
Reported-by: Tristan @TristanInSec
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
6d2cf4466f hw/display/qxl: fix TOCTOU in cursor chunk data_size handling
Snapshot chunk.data_size into a host-local variable before passing it to
qxl_phys2virt() for validation, and pass it through qxl_cursor() and
qxl_unpack_chunks() so that no subsequent code re-reads the field.

Without this, a racing vCPU can inflate data_size between the
qxl_phys2virt() validation and the memcpy in qxl_unpack_chunks(),
causing a source read past the validated region. In practice the read
stays within the guest's own VRAM mmap, so the impact is limited.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3757
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reported-by: Feifan Qian <bea1e@proton.me>
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
db2716bce2 hw/display/virtio-gpu: fix dmabuf_fd leak on remap failure
When virtio_gpu_create_udmabuf() succeeds but virtio_gpu_remap_udmabuf()
fails (mmap returns MAP_FAILED), virtio_gpu_init_udmabuf() returns early
without closing the dmabuf fd. Since res->blob is never set in this
path, later cleanup via virtio_gpu_cleanup_mapping() skips
virtio_gpu_fini_udmabuf() entirely, leaking the file descriptor.

Call virtio_gpu_destroy_udmabuf() before the early return to close
the fd. This function already handles partial state correctly: it
skips the munmap when res->remapped is NULL and closes the fd when
res->dmabuf_fd >= 0.

Fixes: 9b60cdf987 ("virtio-gpu: Add udmabuf helpers")
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
6075444c5a ui/vnc: validate SetPixelFormat field ranges
The VNC SetPixelFormat message carries red/green/blue_max as 16-bit
values, but PixelFormat stores them as uint8_t. A client sending a
max value above 255 (e.g. 0x0100) passes the existing non-zero check
but silently truncates to 0 on assignment, leading to a division by
zero in the Tight PNG palette path.

Add explicit range checks if any channel max exceeds UINT8_MAX.

Fixes: CVE-2026-15578
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3976
Reported-by: dong ling
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
e650e4fe0f ui/vnc: fix out-of-bounds write in lossy refresh dirty marking
vnc_refresh_lossy_rect() marks a full VNC_STAT_RECT (64) rows of the
dirty bitmap when refreshing a lossy tile. When the display height is
not a multiple of VNC_STAT_RECT, the last tile row is a partial tile and
the loop writes past the end of vs->dirty[VNC_MAX_HEIGHT].

For example, with a 2160-pixel-high display (VNC_MAX_HEIGHT), the last
stat tile starts at y=2112. The unconditional 64-row loop writes rows
2112..2175, overflowing 16 rows (640 bytes) past the dirty bitmap into
subsequent VncState fields.

Fix by passing the effective display height into
vnc_refresh_lossy_rect() and clamping the inner loop.

Fixes: CVE-2026-61475
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3935
Reported-by: "Vulnerability Report" <vr@darknavy.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Akihiko Odaki
53f0d87db7 ui/gtk: Narrow DMA-BUF critical section
Scanout operations need to be properly ordered to avoid tearing. The
virtio specification allows the guest to use pageflip. With pageflip,
the guest only modifies the invisible framebuffer while the host scans
out the visible framebuffer. The guest may choose not to use pageflip to
avoid its overhead, accepting the risk of tearing.

ui/gtk performs the following procedure to flush a scanout:
1) Queue a draw event.
2) The draw event gets triggered.
3) Blit the guest framebuffer to the host framebuffer.

When flushing a DMA-BUF scanout, ui/gtk blocks the device before 2) if
possible and unblocks it after 3) to enforce proper ordering. However,
blocking the device before 2) has two problems.

First, it can leave the device blocked indefinitely because GTK
sometimes decides to cancel 2) when the window is not visible for
example. ui/gtk regularly repeats 1) as a workaround, but it is not
applicable to GtkGLArea because it causes display corruption.

Second, the behavior is inconsistent with the other types of scanout
that leave the device unblocked between 1) and 2).

To fix these problems, let ui/gtk block the device only when the
queued draw event runs, immediately before 3). Blocking before that is
unnecessary since ui/gtk does not access the framebuffer yet. If the
guest does not use pageflip but instead updates the visible framebuffer
directly, ui/gtk should not add the overhead of a pre-draw block.

ui/gtk still blocks the device during 3) for DMA-BUF. Unlike the other
scanout types, 3) can happen asynchronously with the device for a
DMA-BUF, so ui/gtk needs to keep the visible guest framebuffer stable
for the blit.

With the problems fixed, the workaround to repeat 1) is no longer
necessary and is removed.

Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Acked-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Message-ID: <20260628-gtk-v2-1-1e4839012f09@rsg.ci.i.u-tokyo.ac.jp>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
82b4d693d5 ui/input-barrier: fix off-by-one in keycode bounds check
Use strict "<" to fix the off-by-one.

Fixes: 6105683da3 ("ui: add an embedded Barrier client")
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3951
Reported-by: huntr bubble
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Laurent Vivier <lvivier@redhat.com>
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
3162692a3b ui/vnc: use RFB wire types for client message handlers
Use exact-width unsigned types for the static functions that process
RFB client messages, matching the types returned by read_u8(),
read_u16(), and read_u32():

 - set_pixel_format: uint8_t/uint16_t for pixel format fields
 - pointer_event: uint8_t button_mask, uint16_t x/y
 - key_event/ext_key_event: bool down, uint32_t sym/keycode
 - do_key_event: uint32_t sym
 - framebuffer_update_request: uint8_t incremental, uint16_t x/y/w/h

Drop needless declarations.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
fb71c895d7 ui/vnc: validate color shifts in SetPixelFormat
A malicious VNC client can send a SetPixelFormat message with shift
values >= 32, causing UB mask computation
(e.g. red_max << red_shift where red_shift is 255). Apparently, this is
not covered by -fwrapv.

Reject color shifts >= bits_per_pixel || 32 before computing masks.

Fixes: 9f64916da2 ("pixman/vnc: use pixman images in vnc.")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3948
Reported-by: huntr bubble
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
3543c2b855 ui/vnc: fix OOB write in vnc_refresh_lossy_rect
vnc_refresh_lossy_rect() always marks a full VNC_STAT_RECT (64) rows
as dirty when refreshing a lossy tile. When the display height is not
a multiple of VNC_STAT_RECT (e.g. VNC_MAX_HEIGHT = 2160), the bottom
tile is partial -- the last tile at y=2112 has only 48 valid rows.
The unclamped loop writes to vs->dirty[2160..2175], past the end of
the VNC_MAX_HEIGHT-sized array.

Clamp the row count to the actual surface height so partial bottom
tiles only mark valid dirty bitmap entries.

Fixes: CVE-2026-48002
Fixes: 7d964c9d2f ("vnc: refresh lossy rect after a given timeout")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3950
Reported-by: huntr bubble
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Marc-André Lureau
40cdadfefd i386/tdx: fix uninitialized variable warning in tdx_check_features
tdx_fetch_cpuid() only sets the output ret parameter on the error
path. GCC cannot prove that r is always initialized before use in
the caller, triggering -Werror=maybe-uninitialized.

Initialize r to -1 to silence the warning.

Fixes: 228e40f33048 ("i386/tdx: Fetch and validate CPUID of TD guest")
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
2026-07-17 15:52:31 +04:00
Stefan Hajnoczi
5ef0ecc594 Misc HW patches
Various fixes mostly related to misc hardware devices.
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCAAdFiEE+qvnXhKRciHc/Wuy4+MsLN6twN4FAmpYiKcACgkQ4+MsLN6t
 wN75XhAAhaSICy5imrRLP39yCKHuw+YKblyzGOBE5v17io7BntQoBOrYERTETwcm
 R7SFUMFrvEJC21anOJ7kyc62jhrsnjWofmBp3sBV6eENboZXxuHxsIIr8mxJ+dgv
 5u9UTfYQ6CMDWbM7keRpRFIKU2sogk1RUyH7Z3kedh3G6MEA4CrSkSf6B777G1lQ
 rm0rcJd5m6lDQ5rmrAd0jsJaI0UaOKLamcb43pm9w3KBDTHhOdJQNwqUX517R69p
 kjhZPAdIGRfyXsOd9S74jr+ZI+kzCi0fCcQGUwD5yges2oxAS+1N5TjYPzMz0E2v
 LDmuTrzRAqfl015QHbj5ayQHk/pAS/Mogoho29G4F6+nTKoo9HeIPX3bEEezJ1Nv
 TpQaD3fp3YBa7BubCSzij0zVZ3PFK1wTY1CrkFC8Je3gejZAafoWKWtZKGBD0nNz
 2Qzwbef1g45v/GfQzdg3Fp3pgMeU7cHR60pAJsSI8ATbtXEZnWi/wc5VbhiJXXBB
 b8C2wefcbYP1wMKOL+cVZSG9wrwyj5/Yc9wW9nlFykOsBHVPYwvFhwA4dZlxCUXV
 MFWJHUdLdSOomhJqr/syH4V2EGuP9dXsz1zw9E0F06dwayjVOhX6Sd3rW6qj8+H7
 a8Nt7ZthWYpF/6e47HXOzS7VaXy4mvXz8kg4QGVlTBLbS3hGXpg=
 =Wjnj
 -----END PGP SIGNATURE-----

Merge tag 'hw-misc-20260714' of https://github.com/philmd/qemu into staging

Misc HW patches

Various fixes mostly related to misc hardware devices.

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEE+qvnXhKRciHc/Wuy4+MsLN6twN4FAmpYiKcACgkQ4+MsLN6t
# wN75XhAAhaSICy5imrRLP39yCKHuw+YKblyzGOBE5v17io7BntQoBOrYERTETwcm
# R7SFUMFrvEJC21anOJ7kyc62jhrsnjWofmBp3sBV6eENboZXxuHxsIIr8mxJ+dgv
# 5u9UTfYQ6CMDWbM7keRpRFIKU2sogk1RUyH7Z3kedh3G6MEA4CrSkSf6B777G1lQ
# rm0rcJd5m6lDQ5rmrAd0jsJaI0UaOKLamcb43pm9w3KBDTHhOdJQNwqUX517R69p
# kjhZPAdIGRfyXsOd9S74jr+ZI+kzCi0fCcQGUwD5yges2oxAS+1N5TjYPzMz0E2v
# LDmuTrzRAqfl015QHbj5ayQHk/pAS/Mogoho29G4F6+nTKoo9HeIPX3bEEezJ1Nv
# TpQaD3fp3YBa7BubCSzij0zVZ3PFK1wTY1CrkFC8Je3gejZAafoWKWtZKGBD0nNz
# 2Qzwbef1g45v/GfQzdg3Fp3pgMeU7cHR60pAJsSI8ATbtXEZnWi/wc5VbhiJXXBB
# b8C2wefcbYP1wMKOL+cVZSG9wrwyj5/Yc9wW9nlFykOsBHVPYwvFhwA4dZlxCUXV
# MFWJHUdLdSOomhJqr/syH4V2EGuP9dXsz1zw9E0F06dwayjVOhX6Sd3rW6qj8+H7
# a8Nt7ZthWYpF/6e47HXOzS7VaXy4mvXz8kg4QGVlTBLbS3hGXpg=
# =Wjnj
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 16 Jul 2026 08:30:47 BST
# gpg:                using RSA key FAABE75E12917221DCFD6BB2E3E32C2CDEADC0DE
# gpg: Good signature from "Philippe Mathieu-Daudé (F4BUG) <f4bug@amsat.org>" [full]
# Primary key fingerprint: FAAB E75E 1291 7221 DCFD  6BB2 E3E3 2C2C DEAD C0DE

* tag 'hw-misc-20260714' of https://github.com/philmd/qemu:
  net: only advertise passt in netdev help when CONFIG_PASST
  hw/usb/hcd-xhci: Use qemu_log_mask() instead of fprintf() statement
  hw/usb/hcd-xhci: Remove the FIXME macro
  hw/usb/hcd-xhci: Turn guest-triggerable abort() into qemu_log_mask()
  hw/usb/hcd-ohci: Make sure that ohci_service_ed_list() cannot loop forever
  hw/display/virtio-gpu: fix dmabuf_fd leak on remap failure
  hw/sparc64/niagara: use int64_t for vdisk size to avoid truncation
  hw/display/qxl: fix TOCTOU in cursor chunk data_size handling
  hw/scsi/vmw_pvscsi: add a comment to explain the endianness
  hw/scsi/vmw_pvscsi: translate data endianness
  docs/devel: Document SSI dummy-cycle ownership
  hw/misc/ivshmem: clear chardev handlers before freeing peers
  hw/sparc64/sun4u: Mark unusable PCI busses as full to ease device plugging

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-17 10:01:52 +01:00
Stefan Hajnoczi
17ea1bfb9b Miscellaneous patches for 2026-07-14
-----BEGIN PGP SIGNATURE-----
 
 iQJGBAABCgAwFiEENUvIs9frKmtoZ05fOHC0AOuRhlMFAmpV/gsSHGFybWJydUBy
 ZWRoYXQuY29tAAoJEDhwtADrkYZTi/oP/1B9i3crkWVFgzZ3YyvDFG5aAPtMZ4MU
 TFEh3xKtzOMIu/jvFvapSNAHG/4kPuiHTJXsi8VYtvzoKhhJggczSJI1K3JSxEtg
 8j7RVKevIwEk3kBR4+L3yegGerNJd2cFfyJLK6DzljxqwRd1bo6/iigxwrg5WzG6
 YDyPqeOtrOBVDjjRXH5T1k+rL5HgmUp5JQWsc+gZSqdVSLWPnTEOtg1Xs1ipEIRm
 JRiKG/5ADwao8Ml6iGmmQQsFvNe6EYWbm6NGdavzuD7mp6Roxuq4CtxD+6jT3roK
 GxQKsig2Un2vBWgvI9ZokwULcpB4esiUAvz9pPYg9WZB/PXi24Fjivhjm2w69E8N
 QIU1TimQFkR0nIFkChYPAfQvBbzdTGv71dZ4/vxVI5ha7kAYw3xWMAGuMhX4FivW
 mEGu7j999IlRSWZYBLUsbsBCM4gXuxzPjs9Cp8xghLi9mnF+MITz0zCHKx2FQwE7
 06yTeEvjPe8LWqx6mfeFq/k4c+Hpiib+D4cOyIBLqldGjFowbaaTmLP8W6VUGM07
 QsuPIE0Py9EOBwOXqYTYrv/SsBLPp03j3Om/P4Bo6E3Zhms0gF8+WXACyJX1t1H0
 V+GtgloccjgfP9hynHa5RaoFeDxOZwksV6cxbuWm38yhhcyaq0iZMXqGWjfO4h5f
 HgNAI8X660MA
 =fEwp
 -----END PGP SIGNATURE-----

Merge tag 'pull-misc-2026-07-14' of https://repo.or.cz/qemu/armbru into staging

Miscellaneous patches for 2026-07-14

# -----BEGIN PGP SIGNATURE-----
#
# iQJGBAABCgAwFiEENUvIs9frKmtoZ05fOHC0AOuRhlMFAmpV/gsSHGFybWJydUBy
# ZWRoYXQuY29tAAoJEDhwtADrkYZTi/oP/1B9i3crkWVFgzZ3YyvDFG5aAPtMZ4MU
# TFEh3xKtzOMIu/jvFvapSNAHG/4kPuiHTJXsi8VYtvzoKhhJggczSJI1K3JSxEtg
# 8j7RVKevIwEk3kBR4+L3yegGerNJd2cFfyJLK6DzljxqwRd1bo6/iigxwrg5WzG6
# YDyPqeOtrOBVDjjRXH5T1k+rL5HgmUp5JQWsc+gZSqdVSLWPnTEOtg1Xs1ipEIRm
# JRiKG/5ADwao8Ml6iGmmQQsFvNe6EYWbm6NGdavzuD7mp6Roxuq4CtxD+6jT3roK
# GxQKsig2Un2vBWgvI9ZokwULcpB4esiUAvz9pPYg9WZB/PXi24Fjivhjm2w69E8N
# QIU1TimQFkR0nIFkChYPAfQvBbzdTGv71dZ4/vxVI5ha7kAYw3xWMAGuMhX4FivW
# mEGu7j999IlRSWZYBLUsbsBCM4gXuxzPjs9Cp8xghLi9mnF+MITz0zCHKx2FQwE7
# 06yTeEvjPe8LWqx6mfeFq/k4c+Hpiib+D4cOyIBLqldGjFowbaaTmLP8W6VUGM07
# QsuPIE0Py9EOBwOXqYTYrv/SsBLPp03j3Om/P4Bo6E3Zhms0gF8+WXACyJX1t1H0
# V+GtgloccjgfP9hynHa5RaoFeDxOZwksV6cxbuWm38yhhcyaq0iZMXqGWjfO4h5f
# HgNAI8X660MA
# =fEwp
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 14 Jul 2026 10:14:51 BST
# gpg:                using RSA key 354BC8B3D7EB2A6B68674E5F3870B400EB918653
# gpg:                issuer "armbru@redhat.com"
# gpg: Good signature from "Markus Armbruster <armbru@redhat.com>" [full]
# gpg:                 aka "Markus Armbruster <armbru@pond.sub.org>" [full]
# Primary key fingerprint: 354B C8B3 D7EB 2A6B 6867  4E5F 3870 B400 EB91 8653

* tag 'pull-misc-2026-07-14' of https://repo.or.cz/qemu/armbru:
  json-parser: fix formatting of comment
  MAINTAINERS: Regularise the status fields (again)
  qom: Fix device-list-properties & friends to show legacy-FOO props
  qapi: Fix misspelled section tags in doc comments

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-17 10:00:20 +01:00
Daniel P. Berrangé
c4ce04cfb7 tests/docker: ensure container command is probed at most once
The '--engine' arg accepts either 'podman' or 'docker', which is
not sufficiently granular to map directly to a command. This
means that  docker.py still has to then probe the exact command
to use.

Meanwhile the 'probe' command prints out the full command to use
but this cannot be passed back to docker.py to avoid probing
again, so the caching is only useful in the few case where we
run a container directly bypassing docker.py.

Address this by replacing --engine with --command for docker.py.

This in turn requires the --container-engine configure arg to be
replaced with --container-command.

With these changes the container command is probed at most once
during configure and never again, while running in an unconfigured
tree will still probe on demand.

Tested-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260716102515.1503404-1-berrange@redhat.com
Signed-off-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
2026-07-16 10:49:11 -07:00
Harry van Haaren
fdff1c864a plugins/execlog: fix execlog vcpu_exit execution print loss
Executed instructions are cached in string format inside the
execlog plugin. These strings are flushed on exit of a TB, improving
performance. This causes executed instructions to be lost when an
'ecall' (riscv system call) occurs that causes the thread to terminate.

The fix in this patch registers a 'vcpu_exit' callback, and flushes
any content in the c->last_exec buffer, to ensure all instructions are
present in the final instruction log.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Tested-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Harry van Haaren <harry.vanhaaren@openchip.com>
Link: https://lore.kernel.org/qemu-devel/20260716094126.787556-3-harry.vanhaaren@openchip.com
Signed-off-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
2026-07-16 10:33:59 -07:00
Harry van Haaren
c0c8990a2b plugins/execlog: fix segfault/race-cond on per-vCPU structures
The existing code in execlog was never upgraded to the Scoreboard
API, resulting in a bespoke implementation of per-vCPU datastructure
handling. This had some race-conditions, and causes segfaults with
a simple multi-threaded program and two instances of execlog running.

The patch here refactors the custom GArray and GRWLock code away, and
uses the scoreboard APIs like the other plugins. This solves the
"printing while expanding" race-condition of two plugins with multiple
threads in the guest, and hence fixes a segfault.

Output remains atomic per instruction by building the full line
(including the trailing newline) in the per-vCPU GString before making
a single qemu_plugin_outs() call, relying on QEMU's own log locking
rather than an additional mutex.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Tested-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Harry van Haaren <harry.vanhaaren@openchip.com>
Link: https://lore.kernel.org/qemu-devel/20260716094126.787556-2-harry.vanhaaren@openchip.com
Signed-off-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
2026-07-16 10:33:59 -07:00
Rohitashv Kumar
504f2bad93 net: only advertise passt in netdev help when CONFIG_PASST
show_netdevs() lists each conditionally-compiled netdev backend behind
its CONFIG_* guard (CONFIG_SLIRP for "user", CONFIG_L2TPV3 for
"l2tpv3", CONFIG_NET_BRIDGE for "bridge", ...). The "passt" entry was
added unconditionally, so "-netdev help" advertises passt even in
builds configured with --disable-passt. Trying to use it then fails
with "Parameter 'type' does not accept value 'passt'", since the QAPI
NetClientDriver enum member "passt" is gated by 'if': 'CONFIG_PASST'.

Guard the help entry with CONFIG_PASST so the advertised backends match
those actually compiled into the binary.

Signed-off-by: Rohitashv Kumar <roohiit@amazon.de>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Puranjay Mohan <puranjay@kernel.org>
Message-ID: <20260713194511.1058450-1-rohit.kuma1313@gmail.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:29:09 +02:00
Thomas Huth
ebe66684a5 hw/usb/hcd-xhci: Use qemu_log_mask() instead of fprintf() statement
We've got a proper way for logging unimplemented hardware features,
so use qemu_log_mask() instead of the fprintf() here now.

Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260713161406.361197-4-thuth@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:29:09 +02:00
Thomas Huth
96c9f9709d hw/usb/hcd-xhci: Remove the FIXME macro
The FIXME macro is only used in one case, which should hopefully
never trigger: The containing function handles all the USB_RET_*
values except for USB_RET_ADD_TO_QUEUE and USB_RET_REMOVE_FROM_QUEUE,
which are both internal return values for when an async packet needs
to be queued or dequeued, and which shouldn't still be the status by
the time we get to this function. Thus let's simplify this spot
and use a g_assert_not_reached() instead (and remove the DPRINT()
in front of it to avoid that code analyzers trip over unreachable
code here).

Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260713161406.361197-3-thuth@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:29:09 +02:00
Thomas Huth
5257259428 hw/usb/hcd-xhci: Turn guest-triggerable abort() into qemu_log_mask()
The FIXME macros in xhci_alloc_device_streams() can be triggered
by a (malicious) guest. Since the macro also contains an abort()
statement, this terminates QEMU. Turn the FIXME statements into
a qemu_log_mask() instead to avoid that a guest can shoot itself
this way.

Reported-by: Feifan Qian <bea1e@proton.me>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3784
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260713161406.361197-2-thuth@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:29:09 +02:00
Thomas Huth
98e5a8eb4f hw/usb/hcd-ohci: Make sure that ohci_service_ed_list() cannot loop forever
The inner while loop in ohci_service_ed_list() could theoretically
loop forever if a malicious guest prepares a set of bad descriptors.
Add a check to the loop to avoid this situation.

Reported-by: Feifan Qian <bea1e@proton.me>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3781
Signed-off-by: Thomas Huth <thuth@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Message-ID: <20260713160458.343323-1-thuth@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:29:09 +02:00
Marc-André Lureau
564c4d7e99 hw/display/virtio-gpu: fix dmabuf_fd leak on remap failure
When virtio_gpu_create_udmabuf() succeeds but virtio_gpu_remap_udmabuf()
fails (mmap returns MAP_FAILED), virtio_gpu_init_udmabuf() returns early
without closing the dmabuf fd. Since res->blob is never set in this
path, later cleanup via virtio_gpu_cleanup_mapping() skips
virtio_gpu_fini_udmabuf() entirely, leaking the file descriptor.

Call virtio_gpu_destroy_udmabuf() before the early return to close
the fd. This function already handles partial state correctly: it
skips the munmap when res->remapped is NULL and closes the fd when
res->dmabuf_fd >= 0.

Fixes: 9b60cdf987 ("virtio-gpu: Add udmabuf helpers")
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Message-ID: <20260713125622.111513-1-marcandre.lureau@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:28:54 +02:00
Dmitry Pimenov
76dbe26fd6 hw/sparc64/niagara: use int64_t for vdisk size to avoid truncation
blk_getlength() returns int64_t, but niagara_init() stored it in an int,
truncating the if=pflash virtual-ramdisk size for images >= 2 GiB. A ~4 GiB
image truncated to 0/negative, failed the `size > 0` check, and exit(1)'d
before the CPU ran, ending with:

  qemu-system-sparc64: could not load ram disk

Signed-off-by: Dmitry Pimenov <sun4qemu@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260710222350.9185-1-sun4qemu@gmail.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Marc-André Lureau
a3cc0069e1 hw/display/qxl: fix TOCTOU in cursor chunk data_size handling
Snapshot chunk.data_size into a host-local variable before passing it to
qxl_phys2virt() for validation, and pass it through qxl_cursor() and
qxl_unpack_chunks() so that no subsequent code re-reads the field.

Without this, a racing vCPU can inflate data_size between the
qxl_phys2virt() validation and the memcpy in qxl_unpack_chunks(),
causing a source read past the validated region. In practice the read
stays within the guest's own VRAM mmap, so the impact is limited.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3757
Reported-by: Feifan Qian <bea1e@proton.me>
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260710134352.2313675-1-marcandre.lureau@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Miao Wang
ecc569639a hw/scsi/vmw_pvscsi: add a comment to explain the endianness
Add a comment to explain the endianness of the pvscsi device. We have
no information about the endianness should be little-endian or CPU
native endian because the current driver code is designed to work only
on x86 and is not endianness aware. We assume that the pvscsi device is
implicitly little-endian.

Signed-off-by: Miao Wang <shankerwangmiao@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260710-pvscsi-endianness-v3-2-27fe1c4d1f6e@gmail.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Miao Wang
5a811329bd hw/scsi/vmw_pvscsi: translate data endianness
This patch improves the implementation of the pvscsi device by
translating the endianness of the data sent or received from the guest.
This ensures pvscsi can work on big-endian hosts with little-endian
guests.

This patch assumes, although not having found any specifications, that
the pvscsi device is little-endian, since pvscsi seems to be used only
on x86 platforms, which are little-endian.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Miao Wang <shankerwangmiao@gmail.com>
Message-ID: <20260710-pvscsi-endianness-v3-1-27fe1c4d1f6e@gmail.com>
[PMD: Rebased on top of commit cb30b8758d physmem API conversion]
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Bin Meng
6387fbad45 docs/devel: Document SSI dummy-cycle ownership
Document the boundary between SPI/SSI controller models and SPI flash
models when representing fast-read dummy cycles. It explains that
flash models own command semantics, while controllers own
hardware-generated dummy transfers and cycle-to-byte conversion.

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260707083431.219671-11-bin.meng@processmission.com>
[PMD: Update MAINTAINERS]
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Haotian Jiang
5157ceb10c hw/misc/ivshmem: clear chardev handlers before freeing peers
ivshmem_exit() frees s->peers and s->msi_vectors but does not clear
the chardev handlers registered in ivshmem_common_realize(). Those
handlers are only removed later in object_finalize() via release_chr,
which runs after ivshmem_exit().

Between exit and finalize, ivshmem_read() can fire on pending chardev
data and process_msg_connect() dereferences the freed s->peers.
Additionally, s->peers, s->nb_peers, and s->msi_vectors are not
zeroed after free, leaving dangling pointers that make the UAF code
paths reachable.

Fix by clearing chardev handlers at the beginning of ivshmem_exit(),
before any resources they access are freed, and nullifying freed
pointers.

Cc: qemu-stable@nongnu.org
Fixes: f64a078d45 ("ivshmem: fix pci_ivshmem_exit()")
Link: https://gitlab.com/qemu-project/qemu/-/work_items/3594
Reported-by: Haotian Jiang <sundayjiang@tencent.com>
Signed-off-by: Haotian Jiang <sundayjiang@tencent.com>
Message-ID: <tencent_3105EC28797360A155078F53@qq.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Thomas Huth
506fa577db hw/sparc64/sun4u: Mark unusable PCI busses as full to ease device plugging
When trying to plug a PCI device to a Sparc64 machine, you currently
have to specify the right bus ("bus=pciB"), otherwise you get this error:

 $ qemu-system-sparc64 -device virtio-scsi-pci
 qemu-system-sparc64: -device virtio-scsi-pci: PCI: no slot/function
 available for virtio-scsi-pci, all in use or reserved

This is quite annoying for the unexperienced users, and it also breaks
e.g. the iotests ("make check-block") when running with qemu-system-sparc64.

Mark the non-usable PCI busses as full now, so that QEMU can automatically
plug new PCI devices to the right "pciB" bus.

Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260309181452.83702-1-thuth@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Paolo Bonzini
87f608e3c2 json-parser: fix formatting of comment
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Message-ID: <20260713114622.1950506-1-pbonzini@redhat.com>
Reviewed-by: Markus Armbruster <armbru@redhat.com>
[Mea culpa]
Signed-off-by: Markus Armbruster <armbru@redhat.com>
2026-07-14 10:59:58 +02:00
Markus Armbruster
f87693a841 MAINTAINERS: Regularise the status fields (again)
Orphaned isn't a state, Orphan is.

Fixes: fb7001e458 (MAINTAINERS: Remove PhilMD from firmware sections, 2026-04-17)
Signed-off-by: Markus Armbruster <armbru@redhat.com>
Message-ID: <20260710111403.2953873-1-armbru@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-14 10:58:17 +02:00
Markus Armbruster
9dbce799e7 qom: Fix device-list-properties & friends to show legacy-FOO props
qmp_device_list_properties() skips properties whose name starts with
"legacy-".  This is a flawed test for "is a legacy property".

The test is flawed because non-legacy properties can and do start with
"legacy-".  Back when it was added, no such properties existed.  Right
now, three such properties do: property "legacy-cmb" of device "nvme",
and properties "legacy-cache" and "legacy-multi-node" of devices
"x86_64-cpu", "i386-cpu", and its children.

This affects QMP command "device-list-properties", HMP command
"device_add T,help", and command line option "-device T,help".

Legacy properties are gone since commit a61383f7ab (qdev: Legacy
properties are now unused internally, drop, 2025-10-22).  This makes
the fix easy: delete the code that skips them.

Reproducer: -device nvme,help doesn't show legacy-cmb before the
patch, and does after.

Fixes: f4eb32b590 (qmp: show QOM properties in device-list-properties, 2014-05-20)
Signed-off-by: Markus Armbruster <armbru@redhat.com>
Message-ID: <20260708140948.2622814-1-armbru@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
2026-07-14 10:58:15 +02:00
Markus Armbruster
8b61adae4e qapi: Fix misspelled section tags in doc comments
Section tags are case sensitive and end with a colon.  Screwing up
either gets them interpreted as ordinary paragraph.  Fix a few.

Fixes: 4e88e7e340 (qapi/qom: Define cache enumeration and properties for machine, 2024-11-01)
Fixes: 8eb6d39e22 (qom: qom-list-get, 2025-07-11)
Signed-off-by: Markus Armbruster <armbru@redhat.com>
Message-ID: <20260701061136.798815-1-armbru@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-14 10:53:03 +02:00
yujun
8ba384cc32 migration: Fix invalid %ud format and trace arg typo
Standard printf has no %ud conversion; glibc treats it as %u followed
by a literal 'd', so postcopy userfaultfd error messages printed event
values like "5d" instead of "5".  The same typo existed in two postcopy
discard trace format strings.

Also rename the misspelled ram_save_iterate_big_wait() trace argument
milliconds to milliseconds.

Fixes: 00fa4fc85b ("postcopy: Allow registering of fd handler")
Signed-off-by: yujun <yujun@kylinos.cn>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Link: https://lore.kernel.org/r/20260630031324.43453-1-yujun@kylinos.cn
Signed-off-by: Peter Xu <peterx@redhat.com>
2026-06-30 10:57:49 -04:00
891 changed files with 32992 additions and 10676 deletions

View file

@ -70,8 +70,8 @@ build-system-debian:
variables:
IMAGE: debian
CONFIGURE_ARGS: --with-coroutine=sigaltstack --enable-rust
TARGETS: arm-softmmu i386-softmmu riscv64-softmmu sh4eb-softmmu
sparc-softmmu xtensa-softmmu
TARGETS: arm-softmmu hexagon-softmmu i386-softmmu riscv64-softmmu
sh4eb-softmmu sparc-softmmu xtensa-softmmu
MAKE_CHECK_ARGS: check-build
check-system-debian:

View file

@ -14,7 +14,7 @@
- echo "TAG:$TAG"
- echo "COMMON_TAG:$COMMON_TAG"
- docker build --tag "$TAG" --cache-from "$TAG" --cache-from "$COMMON_TAG"
--build-arg BUILDKIT_INLINE_CACHE=1
--build-arg BUILDKIT_INLINE_CACHE=1 --provenance=false
-f "tests/docker/dockerfiles/$NAME.docker" "."
- docker push "$TAG"
after_script:

View file

@ -12,5 +12,5 @@ NINJA='/opt/homebrew/bin/ninja'
PACKAGING_COMMAND='brew'
PIP3='/opt/homebrew/bin/pip3'
PKGS='bash bc bindgen bison bzip2 capstone ccache cmocka coreutils ctags curl dbus diffutils dtc flex gcovr gettext git glib gnu-sed gnutls gtk+3 gtk-vnc jemalloc jpeg-turbo json-c libcbor libepoxy libffi libgcrypt libiscsi libnfs libpng libslirp libssh libtasn1 libusb llvm lzo make meson mtools ncurses nettle ninja pixman pkg-config python-setuptools python3 rpm2cpio rust sdl2 sdl2_image snappy socat sparse spice-protocol swtpm tesseract usbredir vde vte3 vulkan-tools xorriso zlib zstd'
PYPI_PKGS='PyYAML numpy pillow sphinx sphinx-rtd-theme tomli'
PYPI_PKGS='sphinx sphinx-rtd-theme tomli'
PYTHON='/opt/homebrew/bin/python3'

View file

@ -22,7 +22,7 @@
- export PKG_CONFIG_PATH="$PKG_CONFIG_PATH"
- brew update
- brew install $PKGS
- brew install gdb aarch64-elf-gcc i686-elf-gcc x86_64-elf-gcc
- brew install aarch64-elf-gcc i686-elf-gcc x86_64-elf-gcc
- if test -n "$PYPI_PKGS" ; then PYLIB=$($PYTHON -c 'import sysconfig; print(sysconfig.get_path("stdlib"))'); rm -f $PYLIB/EXTERNALLY-MANAGED; $PIP3 install --break-system-packages $PYPI_PKGS ; fi
script:
- mkdir build

View file

@ -55,7 +55,7 @@ check-rust-tools-nightly:
- source scripts/ci/gitlab-ci-section
- section_start test "Running Rust code checks"
- cd build
- pyvenv/bin/meson devenv -w ../rust ${CARGO-cargo} fmt --check
- pyvenv/bin/meson devenv -w ../ ${CARGO-cargo} fmt --check
- make clippy
- make rustdoc
- section_end test
@ -69,7 +69,7 @@ check-rust-tools-nightly:
when: on_success
expire_in: 2 days
paths:
- rust/target/doc
- target/doc
check-build-units:
extends: .base_job_template

93
.gitlab-map-auto Normal file
View file

@ -0,0 +1,93 @@
# This file is auto-generated by scripts/gitlab-map-update
#
# This GitLab map associates GitLab account handles
# with real names, in order to allow mapping from
# MAINTAINERS entries. The format of entries is
#
# {gitlab-handle}<tab>{real name}
#
# Manual overrides must be placed in .gitlab-map-manual
TaoTang Tao Tang
a1xndr Alexander Bulekov
adi-g15-ibm Aditya Gupta
agraf Alexander Graf
alex.williamson Alex Williamson
aliang1 Aihua Liang
alistair23 Alistair Francis
anisinha Ani Sinha
anthony-linaro Anthony Roberts
anthonyper Anthony PERARD
berrange Daniel P. Berrangé
birkelund Klaus Jensen
bonzini Paolo Bonzini
brian-cain Brian Cain
bsdimp Warner Losh
cborntra Christian Borntraeger
chao23.liu Chao Liu (Zevorn)
cleber.gnu Cleber Rosa
clegoate Cédric Le Goater
cohuck Cornelia Huck
cota_ Emilio Cota
dagrh Dr. David Alan Gilbert
danielhb Daniel Henrique Barboza
davidhildenbrand David Hildenbrand
dgibson dgibson
dwmw2 David Woodhouse
eauger1 Eric Auger
ebblake Eric Blake
edgar.iglesias Edgar E. Iglesias
ehabkost Eduardo Habkost
eldondev Eldon
epilys Manos Pitsidianakis
famzheng Fam Zheng
farosas Fabiano Rosas
gautammenghani Gautam Menghani
gkurz Greg Kurz
gusbromero Gustavo Romero
harshpb Harsh Prateek Bora
hdeller Helge Deller
hreitz Hanna Czenczek
imammedo Igor Mammedov
jasowang Jason Wang
jmacarthur Jim MacArthur
jsnow John Snow
juan.quintela Juan Quintela
kbastian-qemu Bastian Koppelmann
kmwolf Kevin Wolf
kostyanf14 Kostiantyn Kostiuk
kraxel Gerd Hoffmann
lbmeng Bin Meng
legoater Cédric Le Goater
lvivier Laurent Vivier
lygstate Yonggang Luo
maciejsszmigiero Maciej S. Szmigiero
marcandre.lureau Marc-André Lureau
marcandre.lureau-rh Marc-André Lureau
mauromatteo.cascella Mauro Matteo Cascella
mcayland Mark Cave-Ayland
mdroth Michael Roth
mediouni-m M. Mediouni
mjt0k Michael Tokarev
mstredhat MST
npiggin npiggin
p-b-o Pierrick Bouvier
pauldzim Paul Zimmerman
peterx Peter Xu
philmd Philippe Mathieu-Daudé
pierrick.bouvier Pierrick Bouvier
pipo.sk Peter Krempa
pkrempa Peter Krempa (work)
pm215 Peter Maydell
qemu-janitor Qemu Janitor
rathc Chinmay Rath
rth7680 Richard Henderson
schoenebeck Christian Schoenebeck
sgarzarella Stefano Garzarella
sstabellini Stefano Stabellini
stefanberger Stefan Berger
stefanha Stefan Hajnoczi
stsquad Alex Bennée
stweil Stefan Weil
thuth Thomas Huth
vsementsov Vladimir Sementsov-Ogievskiy
xcancerberox Joaquin de Andres

18
.gitlab-map-manual Normal file
View file

@ -0,0 +1,18 @@
# This GitLab map associates GitLab account handles
# with real names, in order to allow mapping from
# MAINTAINERS entries. The format of entries is
#
# {gitlab-handle}<tab>{real name}
#
# This file is manually written, to augment the
# auto-generated data in .gitlab-map-auto. This
# is needed where a GitLab account real name does
# not exactly match the MAINTAINERS file real
# name.
#
berrange Daniel P. Berrange
dgibson David Gibson
hreitz Hanna Reitz
mstredhat Michael S. Tsirkin
npiggin Nicholas Piggin
mediouni-m Mohamed Mediouni

View file

@ -8,12 +8,6 @@ version = "1.0.98"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "e16d2d3311acee920a9eb8d33b8cbc1787ce4a264e85f964c2404b969bdcd487"
[[package]]
name = "arbitrary-int"
version = "1.2.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c84fc003e338a6f69fbd4f7fe9f92b535ff13e9af8997f3b14b6ddff8b1df46d"
[[package]]
name = "attrs"
version = "0.2.9"
@ -25,23 +19,11 @@ dependencies = [
]
[[package]]
name = "bilge"
version = "0.2.0"
name = "bitfield-struct"
version = "0.13.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "dc707ed8ebf81de5cd6c7f48f54b4c8621760926cdf35a57000747c512e67b57"
checksum = "3ca6739863c590881f038d033a146c51ddae239186a4327014839fd864f44ed5"
dependencies = [
"arbitrary-int",
"bilge-impl",
]
[[package]]
name = "bilge-impl"
version = "0.2.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "feb11e002038ad243af39c2068c8a72bcf147acf05025dcdb916fcc000adb2d8"
dependencies = [
"itertools",
"proc-macro-error",
"proc-macro2",
"quote",
"syn",
@ -103,12 +85,6 @@ dependencies = [
"qemu_macros",
]
[[package]]
name = "either"
version = "1.12.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "3dca9240753cf90908d7e4aac30f630662b02aebaa1b58a3cadabdb23385b58b"
[[package]]
name = "equivalent"
version = "1.0.2"
@ -136,9 +112,9 @@ dependencies = [
[[package]]
name = "hashbrown"
version = "0.16.0"
version = "0.17.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "5419bdc4f6a9207fbeba6d11b604d481addf78ecd10c11ad51e76c2f6482748d"
checksum = "ed5909b6e89a2db4456e54cd5f673791d7eca6732202bbf2a9cc504fe2f9b84a"
[[package]]
name = "heck"
@ -184,41 +160,25 @@ dependencies = [
"glib-sys",
"migration-sys",
"qom-sys",
"system-sys",
"util-sys",
]
[[package]]
name = "indexmap"
version = "2.11.4"
version = "2.14.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "4b0f83760fb341a774ed326568e19f5a863af4a952def8c39f9ab92fd95b88e5"
checksum = "d466e9454f08e4a911e14806c24e16fba1b4c121d1ea474396f396069cf949d9"
dependencies = [
"equivalent",
"hashbrown",
]
[[package]]
name = "itertools"
version = "0.11.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b1c173a5686ce8bfa551b3563d0c2170bf24ca44da99c7ca4bfdab5418c3fe57"
dependencies = [
"either",
]
[[package]]
name = "libc"
version = "0.2.162"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "18d287de67fe55fd7e1581fe933d965a5a9477b38e949cfa9f8574ef01506398"
[[package]]
name = "memchr"
version = "2.7.6"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "f52b00d39961fc5b2736ea853c9cc86238e165017a493d1d5c8eac6bdc4cc273"
[[package]]
name = "migration"
version = "0.1.0"
@ -250,8 +210,7 @@ checksum = "7edddbd0b52d732b21ad9a5fab5c704c14cd949e5e9a1ec5929a24fded1b904c"
name = "pl011"
version = "0.1.0"
dependencies = [
"bilge",
"bilge-impl",
"bitfield-struct",
"bits",
"bql",
"chardev",
@ -271,29 +230,6 @@ version = "0.5.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "136558b6e1ebaecc92755d0ffaf9421f519531bed30cc2ad23b22cb00965cc5e"
[[package]]
name = "proc-macro-error"
version = "1.0.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "da25490ff9892aab3fcf7c36f08cfb902dd3e71ca0f9f9517bea02a73a5ce38c"
dependencies = [
"proc-macro-error-attr",
"proc-macro2",
"quote",
"version_check",
]
[[package]]
name = "proc-macro-error-attr"
version = "1.0.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "a1be40180e52ecc98ad80b184934baf3d0d29f979574e439af5a55274b35f869"
dependencies = [
"proc-macro2",
"quote",
"version_check",
]
[[package]]
name = "proc-macro2"
version = "1.0.95"
@ -343,29 +279,20 @@ dependencies = [
"proc-macro2",
]
[[package]]
name = "serde"
version = "1.0.226"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0dca6411025b24b60bfa7ec1fe1f8e710ac09782dca409ee8237ba74b51295fd"
dependencies = [
"serde_core",
]
[[package]]
name = "serde_core"
version = "1.0.226"
version = "1.0.228"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "ba2ba63999edb9dac981fb34b3e5c0d111a69b0924e253ed29d83f7c99e966a4"
checksum = "41d385c7d4ca58e59fc732af25c3983b67ac852c1a25000afe1175de458b67ad"
dependencies = [
"serde_derive",
]
[[package]]
name = "serde_derive"
version = "1.0.226"
version = "1.0.228"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "8db53ae22f34573731bafa1db20f04027b2d25e02d8205921b569171699cdb33"
checksum = "d540f220d3187173da220f885ab66608367b6574e925011a9353e4badda91d79"
dependencies = [
"proc-macro2",
"quote",
@ -374,18 +301,18 @@ dependencies = [
[[package]]
name = "serde_spanned"
version = "0.6.9"
version = "1.1.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "bf41e0cfaf7226dca15e8197172c295a782857fcb97fad1808a166870dee75a3"
checksum = "6662b5879511e06e8999a8a235d848113e942c9124f211511b16466ee2995f26"
dependencies = [
"serde",
"serde_core",
]
[[package]]
name = "smallvec"
version = "1.15.1"
version = "1.15.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "67b1b7a3b5fe4f1376887184045fcf45c69e92af734b7aaddc05fb777b6fbd03"
checksum = "8ed6a63f02c8539c91a8685a86f4099661ba3da017932f6ebbea6de3f0fa7c90"
[[package]]
name = "syn"
@ -414,9 +341,9 @@ dependencies = [
[[package]]
name = "system-deps"
version = "7.0.5"
version = "7.0.8"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "e4be53aa0cba896d2dc615bd42bbc130acdcffa239e0a2d965ea5b3b2a86ffdb"
checksum = "396a35feb67335377e0251fcbc1092fc85c484bd4e3a7a54319399da127796e7"
dependencies = [
"cfg-expr",
"heck",
@ -431,6 +358,7 @@ version = "0.1.0"
dependencies = [
"common",
"glib-sys",
"hwcore-sys",
"migration-sys",
"qom-sys",
"util-sys",
@ -458,38 +386,43 @@ dependencies = [
[[package]]
name = "toml"
version = "0.8.23"
version = "1.1.3+spec-1.1.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "dc1beb996b9d83529a9e75c17a1686767d148d70663143c7854d8b4a09ced362"
checksum = "53c96ecdfa941c8fc4fcaed14f99ada8ebed502eef533015095a07e3301d4c3c"
dependencies = [
"serde",
"indexmap",
"serde_core",
"serde_spanned",
"toml_datetime",
"toml_edit",
"toml_parser",
"toml_writer",
"winnow",
]
[[package]]
name = "toml_datetime"
version = "0.6.11"
version = "1.1.1+spec-1.1.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "22cddaf88f4fbc13c51aebbf5f8eceb5c7c5a9da2ac40a13519eb5b0a0e8f11c"
checksum = "3165f65f62e28e0115a00b2ebdd37eb6f3b641855f9d636d3cd4103767159ad7"
dependencies = [
"serde",
"serde_core",
]
[[package]]
name = "toml_edit"
version = "0.22.27"
name = "toml_parser"
version = "1.1.2+spec-1.1.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "41fe8c660ae4257887cf66394862d21dbca4a6ddd26f04a3560410406a2f819a"
checksum = "a2abe9b86193656635d2411dc43050282ca48aa31c2451210f4202550afb7526"
dependencies = [
"indexmap",
"serde",
"serde_spanned",
"toml_datetime",
"winnow",
]
[[package]]
name = "toml_writer"
version = "1.1.2+spec-1.1.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7d56353a2a665ad0f41a421187180aab746c8c325620617ad883a99a1cbe66d2"
[[package]]
name = "trace"
version = "0.1.0"
@ -529,17 +462,8 @@ version = "0.2.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "852e951cb7832cb45cb1169900d19760cfa39b82bc0ea9c0e5a14ae88411c98b"
[[package]]
name = "version_check"
version = "0.9.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "49874b5167b65d7193b8aba1567f5c7d93d001cafc34600cee003eda787e483f"
[[package]]
name = "winnow"
version = "0.7.13"
version = "1.0.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "21a0236b59786fed61e2a80582dd500fe61f18b5dca67a4a067d0bc9039339cf"
dependencies = [
"memchr",
]
checksum = "23b97319f7b8343df12cc98938e5c3eb436064524c8d2b4e30a1d3a36eecdf81"

View file

@ -1,9 +1,9 @@
[workspace]
resolver = "2"
members = [
"hw/char/pl011",
"hw/timer/hpet",
"tests",
"rust/hw/char/pl011",
"rust/hw/timer/hpet",
"rust/tests",
]
[workspace.package]
@ -101,5 +101,6 @@ used_underscore_binding = "deny"
#wildcard_imports = "deny" # still have many bindings::* imports
# these may have false positives
enum_variant_names = "allow"
#option_if_let_else = "deny"
cognitive_complexity = "deny"

View file

@ -250,6 +250,12 @@ M: Brian Cain <brian.cain@oss.qualcomm.com>
R: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
S: Supported
F: target/hexagon/
F: hw/intc/hex-l2vic.c
F: include/hw/intc/hex-l2vic.h
F: tests/qtest/l2vic-test.c
F: hw/timer/qct-qtimer.c
F: include/hw/timer/qct-qtimer.h
F: tests/qtest/qct-qtimer-test.c
X: target/hexagon/idef-parser/
X: target/hexagon/gen_idef_parser_funcs.py
F: linux-user/hexagon/
@ -262,6 +268,7 @@ F: gdbstub/gdb-xml/hexagon*.xml
F: docs/system/target-hexagon.rst
F: docs/system/hexagon/
F: docs/devel/hexagon-sys.rst
F: docs/devel/hexagon-l2vic.rst
T: git https://github.com/qualcomm/qemu.git hex-next
Hexagon idef-parser
@ -490,6 +497,7 @@ F: tests/functional/aarch64/test_kvm.py
PPC KVM CPUs
M: Nicholas Piggin <npiggin@gmail.com>
R: Harsh Prateek Bora <harshpb@linux.ibm.com>
R: Amit Machhiwal <amachhiw@linux.ibm.com>
S: Odd Fixes
F: target/ppc/kvm.c
@ -613,6 +621,7 @@ R: Wei Liu <wei.liu@kernel.org>
R: Doru Blânzeanu <dblanzeanu@linux.microsoft.com>
S: Supported
F: target/i386/mshv/
F: hw/i386/mshv/
X86 Instruction Emulator
M: Roman Bolshakov <rbolshakov@ddn.com>
@ -1300,6 +1309,15 @@ M: Manos Pitsidianakis <manos.pitsidianakis@linaro.org>
S: Maintained
F: rust/hw/char/pl011/
Axiado SoCs and EVKs
M: Kuan-Jui Chiu <kchiu@axiado.com>
L: qemu-arm@nongnu.org
S: Maintained
F: hw/arm/ax3000*.c
F: hw/*/axiado*.c
F: include/hw/arm/ax3000*.h
F: include/hw/*/axiado*.h
AVR Machines
-------------
@ -1357,6 +1375,7 @@ F: hw/hexagon/
F: include/hw/hexagon/
F: configs/devices/hexagon-softmmu/default.mak
F: docs/system/hexagon/
F: tests/functional/hexagon/
F: docs/devel/hexagon-sys.rst
LoongArch Machines
@ -1644,6 +1663,7 @@ F: tests/functional/ppc/test_40p.py
sPAPR (pseries)
M: Nicholas Piggin <npiggin@gmail.com>
M: Harsh Prateek Bora <harshpb@linux.ibm.com>
R: Amit Machhiwal <amachhiw@linux.ibm.com>
L: qemu-ppc@nongnu.org
S: Odd Fixes
F: hw/*/spapr*
@ -1745,6 +1765,22 @@ F: include/hw/ppc/vof*
F: pc-bios/vof/*
F: pc-bios/vof*
PowerPC RAS (Reliability, Availability and Serviceability)
M: Aditya Gupta <adityag@linux.ibm.com>
R: Sourabh Jain <sourabhjain@linux.ibm.com>
R: Hari Bathini <hbathini@linux.ibm.com>
R: Shivang Upadhyay <shivangu@linux.ibm.com>
L: qemu-ppc@nongnu.org
S: Maintained
F: hw/ppc/spapr_events.c
F: hw/ppc/spapr_fadump.c
F: hw/ppc/spapr_pci_vfio.c
F: hw/ppc/spapr_rtas.c
F: hw/ppc/pnv_mpipl.c
F: include/hw/ppc/spapr_fadump.h
F: include/hw/ppc/pnv_mpipl.h
F: tests/functional/ppc64/test_fadump.py
RISC-V Machines
---------------
OpenTitan
@ -1826,12 +1862,21 @@ M: Chao Liu <chao.liu@processmission.com>
L: qemu-riscv@nongnu.org
S: Maintained
F: docs/system/riscv/k230.rst
F: hw/misc/k230_ddr.c
F: hw/riscv/k230.c
F: hw/watchdog/k230_wdt.c
F: hw/dma/k230_gsdma.c
F: hw/misc/k230_decomp_gzip.c
F: include/hw/misc/k230_ddr.h
F: include/hw/riscv/k230.h
F: include/hw/watchdog/k230_wdt.h
F: include/hw/dma/k230_gsdma.h
F: include/hw/misc/k230_decomp_gzip.h
F: tests/functional/riscv64/test_k230.py
F: tests/qtest/k230-ddr-test.c
F: tests/qtest/k230-wdt-test.c
F: tests/qtest/k230-gsdma-test.c
F: tests/qtest/k230-decomp-gzip-test.c
RX Machines
-----------
@ -2076,6 +2121,7 @@ Machine core
M: Philippe Mathieu-Daudé <philmd@mailo.com>
R: Zhao Liu <zhao1.liu@intel.com>
S: Maintained
F: hw/core/cpu-internal.h
F: hw/core/cpu-common.c
F: hw/core/cpu-system.c
F: hw/core/machine-qmp-cmds.c
@ -2159,6 +2205,7 @@ F: docs/specs/edu.rst
IDE
M: John Snow <jsnow@redhat.com>
M: Denis V. Lunev <den@openvz.org>
L: qemu-block@nongnu.org
S: Odd Fixes
F: include/hw/ide/
@ -2204,7 +2251,9 @@ M: Peter Maydell <peter.maydell@linaro.org>
L: qemu-arm@nongnu.org
S: Odd Fixes
F: hw/*/omap*
F: hw/dma/soc_dma.c
F: include/hw/arm/omap.h
F: include/hw/dma/soc_dma.h
F: docs/system/arm/sx1.rst
F: tests/functional/arm/test_sx1.py
@ -2350,6 +2399,7 @@ T: git https://github.com/bonzini/qemu.git scsi-next
SSI
M: Alistair Francis <alistair@alistair23.me>
S: Maintained
F: docs/devel/ssi.rst
F: hw/ssi/*
F: hw/block/m25p80*
F: include/hw/ssi/ssi.h
@ -2829,6 +2879,19 @@ F: include/hw/acpi/vmgenid.h
F: docs/specs/vmgenid.rst
F: tests/qtest/vmgenid-test.c
VM Launch Update
M: Ani Sinha <anisinha@redhat.com>
M: Gerd Hoffman <kraxel@redhat.com>
S: Maintained
F: hw/misc/vmlaunchupdate.c
F: include/hw/misc/vmlaunchupdate.h
F: include/standard-headers/misc/vmlaunchupdate.h
F: docs/specs/vmlaunchupdate.rst
F: tests/functional/aarch64/test_vm_launch_update_aarch.py
F: tests/functional/x86_64/test_vm_launch_update.py
F: tests/qtest/launchupdate-test.c
F: tests/data/igvm/*
LED
M: Philippe Mathieu-Daudé <philmd@mailo.com>
S: Maintained
@ -2940,7 +3003,7 @@ F: include/hw/isa/vt82c686.h
Firmware configuration (fw_cfg)
R: Gerd Hoffmann <kraxel@redhat.com>
S: Orphaned
S: Orphan
F: docs/specs/fw_cfg.rst
F: hw/nvram/fw_cfg*.c
F: stubs/fw_cfg.c
@ -3364,23 +3427,6 @@ F: scripts/coccinelle/remove_local_err.cocci
F: scripts/coccinelle/use-error_fatal.cocci
F: scripts/coccinelle/errp-guard.cocci
Firmware Assisted Dump (fadump) for sPAPR (pseries)
M: Aditya Gupta <adityag@linux.ibm.com>
R: Sourabh Jain <sourabhjain@linux.ibm.com>
S: Maintained
F: include/hw/ppc/spapr_fadump.h
F: hw/ppc/spapr_fadump.c
F: tests/functional/ppc64/test_fadump.py
Memory-Preserving Initial Program Load (MPIPL) for PowerNV
M: Aditya Gupta <adityag@linux.ibm.com>
R: Hari Bathini <hbathini@linux.ibm.com>
R: Sourabh <sourabhjain@linux.ibm.com>
S: Maintained
F: include/hw/ppc/pnv_mpipl.h
F: hw/ppc/pnv_mpipl.c
F: tests/functional/ppc64/test_fadump.py
GDB stub
M: Alex Bennée <alex.bennee@linaro.org>
R: Philippe Mathieu-Daudé <philmd@mailo.com>
@ -3414,6 +3460,7 @@ F: system/ioport.c
F: system/memory.c
F: system/memory_mapping.c
F: system/physmem.c
F: system/physmem-qmp-cmds.c
F: system/memory_ldst*
F: system/memory-internal.h
F: system/ram-block-attributes.c
@ -3853,6 +3900,7 @@ Migration dirty limit and dirty page rate
M: Hyman Huang <infra.ai.cloud@bitdeer.com>
S: Maintained
F: system/dirtylimit.c
F: system/dirtylimit-hmp-cmds.c
F: include/system/dirtylimit.h
F: migration/dirtyrate.c
F: migration/dirtyrate.h
@ -4094,7 +4142,7 @@ F: tests/uefi-test-tools/
IGVM Firmware
M: Gerd Hoffmann <kraxel@redhat.com>
M: Stefano Garzarella <sgarzare@redhat.com>
R: Ani Sinha <anisinha@redhat.com>
M: Ani Sinha <anisinha@redhat.com>
S: Maintained
F: backends/igvm*.c
F: docs/system/igvm.rst
@ -4389,7 +4437,7 @@ F: block/parallels.c
F: block/parallels-ext.c
F: docs/interop/parallels.rst
F: docs/interop/prl-xml.rst
T: git https://src.openvz.org/scm/~den/qemu.git parallels
T: git https://gitlab.com/dlunev/qemu.git parallels
qed
M: Stefan Hajnoczi <stefanha@redhat.com>

View file

@ -1 +1 @@
11.0.90
11.1.50

View file

@ -39,6 +39,8 @@
#include "system/mshv.h"
#include "system/mshv_int.h"
#include "system/reset.h"
#include "migration/qemu-file-types.h"
#include "migration/register.h"
#include "trace.h"
#include <err.h>
#include <sys/ioctl.h>
@ -58,53 +60,29 @@ static int init_mshv(int *mshv_fd)
return 0;
}
/* freeze 1 to pause, 0 to resume */
static int set_time_freeze(int vm_fd, int freeze)
static int mshv_load_cleanup(void *opaque)
{
CPUState *cpu;
int ret;
struct hv_input_set_partition_property in = {0};
in.property_code = HV_PARTITION_PROPERTY_TIME_FREEZE;
in.property_value = freeze;
struct mshv_root_hvcall args = {0};
args.code = HVCALL_SET_PARTITION_PROPERTY;
args.in_sz = sizeof(in);
args.in_ptr = (uint64_t)&in;
ret = mshv_hvcall(vm_fd, &args);
ret = mshv_arch_set_partition_msrs(first_cpu);
if (ret < 0) {
error_report("Failed to set time freeze");
error_report("Failed to set partition MSRs: %s", strerror(-ret));
return -1;
}
CPU_FOREACH(cpu) {
ret = mshv_arch_set_mp_state(cpu);
if (ret < 0) {
error_report("Failed to set mp state for vCPU %d: %s",
cpu->cpu_index, strerror(-ret));
return -1;
}
}
return 0;
}
static int pause_vm(int vm_fd)
{
int ret;
ret = set_time_freeze(vm_fd, 1);
if (ret < 0) {
error_report("Failed to pause partition: %s", strerror(errno));
return -1;
}
return 0;
}
static int resume_vm(int vm_fd)
{
int ret;
ret = set_time_freeze(vm_fd, 0);
if (ret < 0) {
error_report("Failed to resume partition: %s", strerror(errno));
return -1;
}
return 0;
}
static int get_host_partition_property(int mshv_fd, uint32_t property_code,
uint64_t *value)
@ -203,6 +181,14 @@ static int create_partition(int mshv_fd, int *vm_fd)
/* enable all */
disabled_xsave_features.as_uint64 = 0;
/*
* AMX TILE XSAVE state (XTILE_DATA) is 8KB, which exceeds the
* current fixed 4KB XSAVE buffer size.
*/
disabled_xsave_features.amx_tile_support = 1;
disabled_xsave_features.amx_bf16_support = 1;
disabled_xsave_features.amx_int8_support = 1;
disabled_xsave_features.amx_fp16_support = 1;
/*
* query host for supported processor features and disable unsupported
@ -320,9 +306,6 @@ static int create_vm(int mshv_fd, int *vm_fd)
return -1;
}
/* Always create a frozen partition */
pause_vm(*vm_fd);
return 0;
}
@ -536,6 +519,10 @@ static int mshv_init_vcpu(CPUState *cpu)
return 0;
}
static SaveVMHandlers savevm_mshv = {
.load_cleanup = mshv_load_cleanup,
};
static int mshv_init(AccelState *as, MachineState *ms)
{
MshvState *s;
@ -565,13 +552,6 @@ static int mshv_init(AccelState *as, MachineState *ms)
return -1;
}
ret = resume_vm(vm_fd);
if (ret < 0) {
close(mshv_fd);
close(vm_fd);
return -1;
}
s->vm = vm_fd;
s->fd = mshv_fd;
@ -591,6 +571,10 @@ static int mshv_init(AccelState *as, MachineState *ms)
0, "mshv-memory");
memory_listener_register(&mshv_io_listener, &address_space_io);
register_savevm_live("mshv", 0, 1, &savevm_mshv, s);
mshv_clock_init();
return 0;
}
@ -628,6 +612,13 @@ static int mshv_cpu_exec(CPUState *cpu)
cpu->vcpu_dirty = false;
}
/* Corresponding store-release is in cpu_exit. */
if (qatomic_load_acquire(&cpu->exit_request)) {
trace_mshv_interrupt_exit_request(cpu->cpu_index);
ret = EXCP_INTERRUPT;
break;
}
ret = mshv_run_vcpu(mshv_state->vm, cpu, &mshv_msg, &exit_reason);
if (ret < 0) {
error_report("Failed to run on vcpu %d", cpu->cpu_index);
@ -655,17 +646,13 @@ static int mshv_cpu_exec(CPUState *cpu)
}
/*
* The signal handler is triggered when QEMU's main thread receives a SIG_IPI
* (SIGUSR1). This signal causes the current CPU thread to be kicked, forcing a
* VM exit on the CPU. The VM exit generates an exit reason that breaks the loop
* (see mshv_cpu_exec). If the exit is due to a Ctrl+A+x command, the system
* will shut down. For other cases, the system will continue running.
* We need a dummy handler to make SIG_IPI a deliverable signal. The kernel
* handler will be woken up by the caught signal and instruct the hypervisor
* to suspend execution (the concrete mechanism differs between schedulers)
* and return to userspace.
*/
static void sa_ipi_handler(int sig)
static void dummy_handler(int sig)
{
/* TODO: call IOCTL to set_immediate_exit, once implemented. */
qemu_cpu_kick_self();
}
static void init_signal(CPUState *cpu)
@ -675,7 +662,7 @@ static void init_signal(CPUState *cpu)
sigset_t set;
memset(&sigact, 0, sizeof(sigact));
sigact.sa_handler = sa_ipi_handler;
sigact.sa_handler = dummy_handler;
sigaction(SIG_IPI, &sigact, NULL);
pthread_sigmask(SIG_BLOCK, NULL, &set);
@ -851,6 +838,7 @@ static void mshv_accel_ops_class_init(ObjectClass *oc, const void *data)
ops->synchronize_state = mshv_cpu_synchronize;
ops->synchronize_pre_loadvm = mshv_cpu_synchronize_pre_loadvm;
ops->cpus_are_resettable = mshv_cpus_are_resettable;
ops->cpu_thread_is_idle = mshv_vcpu_thread_is_idle;
ops->handle_interrupt = generic_handle_interrupt;
}

View file

@ -4,6 +4,7 @@
# SPDX-License-Identifier: GPL-2.0-or-later
mshv_start_vcpu_thread(const char* thread, uint32_t cpu) "thread=%s cpu_index=%d"
mshv_interrupt_exit_request(uint32_t cpu) "cpu_index=%d"
mshv_set_memory(bool add, uint64_t gpa, uint64_t size, uint64_t user_addr, bool readonly, int ret) "add=%d gpa=0x%" PRIx64 " size=0x%" PRIx64 " user=0x%" PRIx64 " readonly=%d result=%d"
mshv_mem_ioeventfd_add(uint64_t addr, uint32_t size, uint32_t data) "addr=0x%" PRIx64 " size=%d data=0x%x"

View file

@ -387,14 +387,22 @@ static void record_save(DisasContextBase *db, vaddr pc,
* Either the first or second page may be I/O. If it is the second,
* then the first byte we need to record will be at a non-zero offset.
* In either case, we should not need to record but a single insn.
*
* A read may re-read bytes that are already recorded: a target may
* fetch a whole aligned word to decode an insn (e.g. riscv Ziccif),
* then probe the following insn, which lies within that same word.
* Such a read extends the record only by the bytes past its end.
*/
if (db->record_len == 0) {
db->record_start = offset;
db->record_len = size;
} else {
assert(offset == db->record_start + db->record_len);
assert(db->record_len + size <= sizeof(db->record));
db->record_len += size;
int end = offset - db->record_start + size;
assert(offset >= db->record_start);
assert(offset <= db->record_start + db->record_len);
assert(end <= sizeof(db->record));
db->record_len = MAX(db->record_len, end);
}
memcpy(db->record + (offset - db->record_start), from, size);

View file

@ -52,6 +52,8 @@ static void igvm_reset_hold(Object *obj, ResetType type)
trace_igvm_reset_hold(type);
/* cleanup existing memory regions first */
qigvm_cleanup_memory(igvm);
qigvm_process_file(igvm, ms, false, &error_fatal);
}
@ -65,6 +67,7 @@ static void igvm_complete(UserCreatable *uc, Error **errp)
IgvmCfg *igvm = IGVM_CFG(uc);
igvm->file = qigvm_file_init(igvm->filename, errp);
QTAILQ_INIT(&igvm->memory_regions);
}
OBJECT_DEFINE_TYPE_WITH_INTERFACES(IgvmCfg, igvm_cfg, IGVM_CFG, OBJECT,

View file

@ -14,6 +14,7 @@
#include "qapi/error.h"
#include "qemu/error-report.h"
#include "qemu/target-info-qapi.h"
#include "migration/vmstate.h"
#include "system/igvm.h"
#include "system/igvm-cfg.h"
#include "system/igvm-internal.h"
@ -178,7 +179,8 @@ static int qigvm_handler(QIgvm *ctx, IgvmVariableHeaderType raw_type,
if (handlers[handler].type != type) {
continue;
}
header_handle = igvm_get_header(ctx->file, handlers[handler].section,
header_handle = igvm_get_header(ctx->cfg->file,
handlers[handler].section,
ctx->current_header_index);
if (header_handle < 0) {
error_setg(
@ -187,7 +189,7 @@ static int qigvm_handler(QIgvm *ctx, IgvmVariableHeaderType raw_type,
(int)header_handle);
return -1;
}
header_data = igvm_get_buffer(ctx->file, header_handle);
header_data = igvm_get_buffer(ctx->cfg->file, header_handle);
if (header_data != NULL) {
header_data += sizeof(IGVM_VHS_VARIABLE_HEADER);
result = handlers[handler].handler(ctx, header_data, errp);
@ -198,7 +200,7 @@ static int qigvm_handler(QIgvm *ctx, IgvmVariableHeaderType raw_type,
header_handle, type);
result = -1;
}
igvm_free_buffer(ctx->file, header_handle);
igvm_free_buffer(ctx->cfg->file, header_handle);
return result;
}
@ -219,7 +221,7 @@ static void *qigvm_prepare_memory(QIgvm *ctx, uint64_t addr, uint64_t size,
int region_identifier, Error **errp)
{
ERRP_GUARD();
MemoryRegion *igvm_pages = NULL;
IgvmMemoryRegion *imr = NULL;
Int128 gpa_region_size;
MemoryRegionSection mrs =
memory_region_find(get_system_memory(), addr, size);
@ -253,23 +255,27 @@ static void *qigvm_prepare_memory(QIgvm *ctx, uint64_t addr, uint64_t size,
*/
g_autofree char *region_name =
g_strdup_printf("igvm.%X", region_identifier);
igvm_pages = g_new0(MemoryRegion, 1);
imr = g_new0(IgvmMemoryRegion, 1);
imr->mr = g_new0(MemoryRegion, 1);
if (ctx->machine_state->cgs &&
ctx->machine_state->cgs->require_guest_memfd) {
if (!memory_region_init_ram_guest_memfd(igvm_pages, NULL,
if (!memory_region_init_ram_guest_memfd(imr->mr, NULL,
region_name, size, errp)) {
g_free(igvm_pages);
g_free(imr->mr);
g_free(imr);
return NULL;
}
} else {
if (!memory_region_init_ram(igvm_pages, NULL, region_name, size,
if (!memory_region_init_ram(imr->mr, NULL, region_name, size,
errp)) {
g_free(igvm_pages);
g_free(imr->mr);
g_free(imr);
return NULL;
}
}
memory_region_add_subregion(get_system_memory(), addr, igvm_pages);
return memory_region_get_ram_ptr(igvm_pages);
memory_region_add_subregion(get_system_memory(), addr, imr->mr);
QTAILQ_INSERT_TAIL(&ctx->cfg->memory_regions, imr, next);
return memory_region_get_ram_ptr(imr->mr);
}
}
@ -344,7 +350,8 @@ static int qigvm_process_mem_region(QIgvm *ctx, unsigned start_index,
for (page_index = 0; page_index < page_count; page_index++) {
data_handle = igvm_get_header_data(
ctx->file, IGVM_HEADER_SECTION_DIRECTIVE, page_index + start_index);
ctx->cfg->file, IGVM_HEADER_SECTION_DIRECTIVE,
page_index + start_index);
if (data_handle == IGVMAPI_NO_DATA) {
/* No data indicates a zero page */
memset(&region[page_index * page_size], 0, page_size);
@ -357,7 +364,7 @@ static int qigvm_process_mem_region(QIgvm *ctx, unsigned start_index,
return -1;
} else {
zero = false;
data_size = igvm_get_buffer_size(ctx->file, data_handle);
data_size = igvm_get_buffer_size(ctx->cfg->file, data_handle);
if (data_size < page_size) {
memset(&region[page_index * page_size], 0, page_size);
} else if (data_size > page_size) {
@ -367,14 +374,14 @@ static int qigvm_process_mem_region(QIgvm *ctx, unsigned start_index,
page_index + start_index);
return -1;
}
data = igvm_get_buffer(ctx->file, data_handle);
data = igvm_get_buffer(ctx->cfg->file, data_handle);
if (data == NULL) {
error_setg(errp, "IGVM: No buffer for handle %d", data_handle);
igvm_free_buffer(ctx->file, data_handle);
igvm_free_buffer(ctx->cfg->file, data_handle);
return -1;
}
memcpy(&region[page_index * page_size], data, data_size);
igvm_free_buffer(ctx->file, data_handle);
igvm_free_buffer(ctx->cfg->file, data_handle);
}
}
@ -411,7 +418,8 @@ static int qigvm_process_mem_page(QIgvm *ctx,
ctx->region_start = page_data->gpa;
ctx->region_start_index = ctx->current_header_index;
} else {
if (!qigvm_page_attrs_equal(ctx->file, ctx->current_header_index,
if (!qigvm_page_attrs_equal(ctx->cfg->file,
ctx->current_header_index,
page_data,
&ctx->region_prev_page_data) ||
((ctx->region_prev_page_data.gpa +
@ -474,7 +482,8 @@ static int qigvm_directive_vp_context(QIgvm *ctx, const uint8_t *header_data,
return 0;
}
data_handle = igvm_get_header_data(ctx->file, IGVM_HEADER_SECTION_DIRECTIVE,
data_handle = igvm_get_header_data(ctx->cfg->file,
IGVM_HEADER_SECTION_DIRECTIVE,
ctx->current_header_index);
if (data_handle < 0) {
error_setg(errp, "Invalid VP context in IGVM file. Error code: %X",
@ -482,7 +491,7 @@ static int qigvm_directive_vp_context(QIgvm *ctx, const uint8_t *header_data,
return -1;
}
data = (uint8_t *)igvm_get_buffer(ctx->file, data_handle);
data = (uint8_t *)igvm_get_buffer(ctx->cfg->file, data_handle);
if (data == NULL) {
error_setg(errp, "IGVM: No buffer for handle %d", data_handle);
result = -1;
@ -491,7 +500,8 @@ static int qigvm_directive_vp_context(QIgvm *ctx, const uint8_t *header_data,
if (ctx->machine_state->cgs) {
result = ctx->cgsc->set_guest_state(
vp_context->gpa, data, igvm_get_buffer_size(ctx->file, data_handle),
vp_context->gpa, data,
igvm_get_buffer_size(ctx->cfg->file, data_handle),
CGS_PAGE_TYPE_VMSA, vp_context->vp_index, errp);
} else if (target_arch() == SYS_EMU_TARGET_X86_64) {
result = qigvm_x86_set_vp_context(data, vp_context->vp_index, errp);
@ -504,7 +514,7 @@ static int qigvm_directive_vp_context(QIgvm *ctx, const uint8_t *header_data,
}
exit:
igvm_free_buffer(ctx->file, data_handle);
igvm_free_buffer(ctx->cfg->file, data_handle);
if (result < 0) {
return result;
}
@ -863,7 +873,8 @@ static int qigvm_supported_platform_compat_mask(QIgvm *ctx, Error **errp)
uint32_t compatibility_mask_sev_snp = 0;
uint32_t compatibility_mask = 0;
header_count = igvm_header_count(ctx->file, IGVM_HEADER_SECTION_PLATFORM);
header_count = igvm_header_count(ctx->cfg->file,
IGVM_HEADER_SECTION_PLATFORM);
if (header_count < 0) {
error_setg(errp,
"Invalid platform header count in IGVM file. Error code: %X",
@ -874,11 +885,11 @@ static int qigvm_supported_platform_compat_mask(QIgvm *ctx, Error **errp)
for (header_index = 0; header_index < (unsigned)header_count;
header_index++) {
IgvmVariableHeaderType typ = igvm_get_header_type(
ctx->file, IGVM_HEADER_SECTION_PLATFORM, header_index);
ctx->cfg->file, IGVM_HEADER_SECTION_PLATFORM, header_index);
typ = igvm_vht_type(typ);
if (typ == IGVM_VHT_SUPPORTED_PLATFORM) {
header_handle = igvm_get_header(
ctx->file, IGVM_HEADER_SECTION_PLATFORM, header_index);
ctx->cfg->file, IGVM_HEADER_SECTION_PLATFORM, header_index);
if (header_handle < 0) {
error_setg(errp,
"Invalid platform header in IGVM file. "
@ -887,11 +898,11 @@ static int qigvm_supported_platform_compat_mask(QIgvm *ctx, Error **errp)
return -1;
}
platform =
(IGVM_VHS_SUPPORTED_PLATFORM *)(igvm_get_buffer(ctx->file,
(IGVM_VHS_SUPPORTED_PLATFORM *)(igvm_get_buffer(ctx->cfg->file,
header_handle));
if (platform == NULL) {
error_setg(errp, "IGVM: No buffer for handle %d", header_handle);
igvm_free_buffer(ctx->file, header_handle);
igvm_free_buffer(ctx->cfg->file, header_handle);
return -1;
}
@ -922,7 +933,7 @@ static int qigvm_supported_platform_compat_mask(QIgvm *ctx, Error **errp)
} else if (platform->platform_type == IGVM_PLATFORM_TYPE_NATIVE) {
compatibility_mask = platform->compatibility_mask;
}
igvm_free_buffer(ctx->file, header_handle);
igvm_free_buffer(ctx->cfg->file, header_handle);
}
}
/* Choose the strongest supported isolation technology */
@ -999,7 +1010,7 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *machine_state,
error_setg(errp, "No IGVM file loaded.");
return -1;
}
ctx.file = cfg->file;
ctx.cfg = cfg;
trace_igvm_process_file(cfg->file, onlyVpContext);
ctx.machine_state = machine_state;
@ -1021,7 +1032,8 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *machine_state,
goto cleanup;
}
header_count = igvm_header_count(ctx.file, IGVM_HEADER_SECTION_DIRECTIVE);
header_count = igvm_header_count(ctx.cfg->file,
IGVM_HEADER_SECTION_DIRECTIVE);
if (header_count <= 0) {
error_setg(
errp, "Invalid directive header count in IGVM file. Error code: %X",
@ -1035,7 +1047,8 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *machine_state,
ctx.current_header_index < (unsigned)header_count;
ctx.current_header_index++) {
IgvmVariableHeaderType raw_type = igvm_get_header_type(
ctx.file, IGVM_HEADER_SECTION_DIRECTIVE, ctx.current_header_index);
ctx.cfg->file, IGVM_HEADER_SECTION_DIRECTIVE,
ctx.current_header_index);
if (!onlyVpContext || igvm_vht_type(raw_type) == IGVM_VHT_VP_CONTEXT) {
if (qigvm_handler(&ctx, raw_type, errp) < 0) {
goto cleanup_parameters;
@ -1053,7 +1066,7 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *machine_state,
}
header_count =
igvm_header_count(ctx.file, IGVM_HEADER_SECTION_INITIALIZATION);
igvm_header_count(ctx.cfg->file, IGVM_HEADER_SECTION_INITIALIZATION);
if (header_count < 0) {
error_setg(
errp,
@ -1066,7 +1079,8 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *machine_state,
ctx.current_header_index < (unsigned)header_count;
ctx.current_header_index++) {
IgvmVariableHeaderType type =
igvm_get_header_type(ctx.file, IGVM_HEADER_SECTION_INITIALIZATION,
igvm_get_header_type(ctx.cfg->file,
IGVM_HEADER_SECTION_INITIALIZATION,
ctx.current_header_index);
if (qigvm_handler(&ctx, type, errp) < 0) {
goto cleanup_parameters;
@ -1096,3 +1110,22 @@ cleanup_parameters:
cleanup:
return retval;
}
/*
* cleanup any memory regions created by qigvm_prepare_memory()
*/
void qigvm_cleanup_memory(IgvmCfg *cfg)
{
IgvmMemoryRegion *imr, *tmp;
QTAILQ_FOREACH_SAFE(imr, &cfg->memory_regions, next, tmp)
{
trace_qigvm_cleanup_memory(imr->mr->name);
memory_region_del_subregion(get_system_memory(), imr->mr);
vmstate_unregister_ram(imr->mr, NULL);
QTAILQ_REMOVE(&cfg->memory_regions, imr, next);
/* this triggers MemoryRegion cleanup */
object_unparent(OBJECT(imr->mr));
g_free(imr);
}
}

View file

@ -11,11 +11,14 @@
*/
#include "qemu/osdep.h"
#include "qemu/units.h"
#include "system/rng.h"
#include "qapi/error.h"
#include "qemu/module.h"
#include "qom/object_interfaces.h"
#define RNG_MAX_REQUEST_SIZE (64 * KiB)
void rng_backend_request_entropy(RngBackend *s, size_t size,
EntropyReceiveFunc *receive_entropy,
void *opaque)
@ -27,7 +30,7 @@ void rng_backend_request_entropy(RngBackend *s, size_t size,
req = g_malloc(sizeof(*req));
req->offset = 0;
req->size = size;
req->size = MIN(size, RNG_MAX_REQUEST_SIZE);
req->receive_entropy = receive_entropy;
req->opaque = opaque;
req->data = g_malloc(req->size);
@ -68,6 +71,22 @@ static void rng_backend_free_request(RngRequest *req)
g_free(req);
}
void rng_backend_cancel_requests(RngBackend *s,
EntropyReceiveFunc *receive_entropy,
const void *opaque)
{
RngRequest *req, *next;
QSIMPLEQ_FOREACH_SAFE(req, &s->requests, next, next) {
if (req->receive_entropy != receive_entropy ||
req->opaque != opaque) {
continue;
}
QSIMPLEQ_REMOVE(&s->requests, req, RngRequest, next);
rng_backend_free_request(req);
}
}
static void rng_backend_free_requests(RngBackend *s)
{
RngRequest *req, *next;

View file

@ -33,3 +33,4 @@ igvm_reset_hold(int type) "type=%u"
igvm_reset_exit(int type) "type=%u"
igvm_file_loaded(const char *fn, int32_t handle) "fn=%s, handle=0x%x"
igvm_process_file(int32_t handle, bool context_only) "handle=0x%x context-only=%d"
qigvm_cleanup_memory(const char* name) "freeing mr %s"

View file

@ -194,6 +194,8 @@ int block_latency_histogram_set(BlockAcctStats *stats, enum BlockAcctType type,
return -EINVAL;
}
qemu_mutex_lock(&stats->lock);
hist->nbins = new_nbins;
g_free(hist->boundaries);
hist->boundaries = g_new(uint64_t, hist->nbins - 1);
@ -206,6 +208,8 @@ int block_latency_histogram_set(BlockAcctStats *stats, enum BlockAcctType type,
g_free(hist->bins);
hist->bins = g_new0(uint64_t, hist->nbins);
qemu_mutex_unlock(&stats->lock);
return 0;
}
@ -213,12 +217,16 @@ void block_latency_histograms_clear(BlockAcctStats *stats)
{
int i;
qemu_mutex_lock(&stats->lock);
for (i = 0; i < BLOCK_MAX_IOTYPE; i++) {
BlockLatencyHistogram *hist = &stats->latency_histogram[i];
g_free(hist->bins);
g_free(hist->boundaries);
memset(hist, 0, sizeof(*hist));
}
qemu_mutex_unlock(&stats->lock);
}
static void block_account_one_io(BlockAcctStats *stats, BlockAcctCookie *cookie,
@ -310,10 +318,9 @@ double block_acct_queue_depth(BlockAcctTimedStats *stats,
uint64_t sum, elapsed;
assert(type < BLOCK_MAX_IOTYPE);
assert(qemu_mutex_trylock(&stats->stats->lock) == -EBUSY);
qemu_mutex_lock(&stats->stats->lock);
sum = timed_average_sum(&stats->latency[type], &elapsed);
qemu_mutex_unlock(&stats->stats->lock);
return (double) sum / elapsed;
}

View file

@ -937,9 +937,8 @@ static int64_t coroutine_fn blkio_co_getlength(BlockDriverState *bs)
uint64_t capacity;
int ret;
WITH_QEMU_LOCK_GUARD(&s->blkio_lock) {
ret = blkio_get_uint64(s->blkio, "capacity", &capacity);
}
QEMU_LOCK_GUARD(&s->blkio_lock);
ret = blkio_get_uint64(s->blkio, "capacity", &capacity);
if (ret < 0) {
return -ret;
}

View file

@ -202,7 +202,8 @@ static int cloop_open(BlockDriverState *bs, QDict *options, int flags,
s->current_block = s->n_blocks;
s->sectors_per_block = s->block_size/512;
bs->total_sectors = s->n_blocks * s->sectors_per_block;
/* Cast to uint64_t to prevent uint32_t overflow */
bs->total_sectors = (uint64_t)s->n_blocks * s->sectors_per_block;
qemu_co_mutex_init(&s->lock);
return 0;

View file

@ -128,8 +128,9 @@ static void commit_clean(Job *job)
blk_unref(s->top);
}
static int commit_iteration(CommitBlockJob *s, int64_t offset,
int64_t *requested_bytes, void *buf)
static int coroutine_fn
commit_iteration(CommitBlockJob *s, int64_t offset,
int64_t *requested_bytes, void *buf)
{
BlockErrorAction action;
int64_t bytes = *requested_bytes;

View file

@ -482,6 +482,8 @@ static int curl_init_state(BDRVCURLState *s, CURLState *state)
}
}
if (curl_easy_setopt(state->curl, CURLOPT_TIMEOUT, (long)s->timeout) ||
curl_easy_setopt(state->curl, CURLOPT_USERAGENT,
"QEMU/" QEMU_VERSION) ||
curl_easy_setopt(state->curl, CURLOPT_WRITEFUNCTION,
(void *)curl_read_cb) ||
curl_easy_setopt(state->curl, CURLOPT_WRITEDATA, (void *)state) ||

View file

@ -612,7 +612,7 @@ uint64_t bdrv_dirty_bitmap_serialization_coverage(int serialized_chunk_size,
const BdrvDirtyBitmap *bitmap)
{
uint64_t granularity = bdrv_dirty_bitmap_granularity(bitmap);
uint64_t limit = granularity * (serialized_chunk_size << 3);
uint64_t limit = granularity * ((uint64_t)serialized_chunk_size << 3);
assert(QEMU_IS_ALIGNED(limit,
bdrv_dirty_bitmap_serialization_align(bitmap)));

View file

@ -312,6 +312,21 @@ static int dmg_read_mish_block(BDRVDMGState *s, DmgHeaderState *ds,
goto fail;
}
/*
* Uncompressed chunk length must match sector count. Compressed chunks
* are validated during dmg_read_chunk() since the uncompressed size is
* not known ahead of time.
*/
if (s->types[i] == UDRW) {
if (s->sectorcounts[i] != DIV_ROUND_UP(s->lengths[i], 512)) {
error_report("length %" PRIu64 " for chunk %" PRIu32
" is inconsistent with sector count %" PRIu64,
s->lengths[i], i, s->sectorcounts[i]);
ret = -EINVAL;
goto fail;
}
}
update_max_chunk_size(s, i, &ds->max_compressed_size,
&ds->max_sectors_per_chunk);
offset += 40;
@ -559,6 +574,12 @@ static int dmg_open(BlockDriverState *bs, QDict *options, int flags,
goto fail;
}
/* There must be at least one chunk */
if (s->n_chunks == 0) {
ret = -EINVAL;
goto fail;
}
/* initialize zlib engine */
s->compressed_chunk = qemu_try_blockalign(bs->file->bs,
ds.max_compressed_size + 1);
@ -609,7 +630,10 @@ static inline int is_sector_in_chunk(BDRVDMGState *s,
static inline uint32_t search_chunk(BDRVDMGState *s, uint64_t sector_num)
{
/* binary search */
uint32_t chunk1 = 0, chunk2 = s->n_chunks, chunk3;
uint32_t chunk1 = 0, chunk2 = s->n_chunks - 1, chunk3;
if (s->n_chunks == 0) {
goto err; /* should never happen */
}
while (chunk1 <= chunk2) {
chunk3 = (chunk1 + chunk2) / 2;
if (s->sectors[chunk3] > sector_num) {
@ -713,6 +737,16 @@ dmg_read_chunk(BlockDriverState *bs, uint64_t sector_num)
if (ret < 0) {
return -1;
}
/*
* Zero the unread part of the last sector when chunk length is
* unaligned to avoid exposing uninitialized memory. Valid image
* files may never hit this case, but cover it to be safe.
*/
if (s->lengths[chunk] & 511) {
size_t trailing_bytes = 512 - (s->lengths[chunk] & 511);
memset(s->uncompressed_chunk + s->lengths[chunk], 0, trailing_bytes);
}
break;
case UDZE: /* zeros */
case UDIG: /* ignore */

View file

@ -859,6 +859,18 @@ fuse_co_init(FuseExport *exp, struct fuse_init_out *out,
uint32_t supported_flags = FUSE_ASYNC_READ | FUSE_ASYNC_DIO;
uint32_t flags2 = 0;
if (!exp->growable) {
/*
* Back when libfuse was used, it would always set this flag and thus
* the kernel did not execute a truncate itself and passed along O_TRUNC
* to user space. Continue setting the flag for backwards compatibility
* when the export is not growable to avoid issues with O_TRUNC, i.e.
* blockdev-based exports running into ENOTSUP and file-based exports
* with growable=off to be truncated and then stuck with size 0.
*/
supported_flags = FUSE_ATOMIC_O_TRUNC;
}
if (in->major != 7) {
error_report("FUSE major version mismatch: We have 7, but kernel has %"
PRIu32, in->major);

View file

@ -125,10 +125,17 @@ void qmp_block_dirty_bitmap_add(const char *node, const char *name,
disabled = false;
}
if (persistent &&
!bdrv_can_store_new_dirty_bitmap(bs, name, granularity, errp))
{
return;
if (persistent) {
if (!bdrv_is_writable(bs)) {
error_setg(errp, "Cannot add a persistent bitmap to "
"read-only or inactive node '%s'",
bdrv_get_node_name(bs));
return;
}
if (!bdrv_can_store_new_dirty_bitmap(bs, name, granularity, errp)) {
return;
}
}
bitmap = bdrv_create_dirty_bitmap(bs, granularity, name, errp);
@ -158,11 +165,11 @@ BdrvDirtyBitmap *block_dirty_bitmap_remove(const char *node, const char *name,
return NULL;
}
if (bdrv_dirty_bitmap_check(bitmap, BDRV_BITMAP_BUSY | BDRV_BITMAP_RO,
errp)) {
if (bdrv_dirty_bitmap_check(bitmap, BDRV_BITMAP_BUSY, errp)) {
return NULL;
}
/* Dropping a bitmap needs no write access unless it is actually stored. */
if (bdrv_dirty_bitmap_get_persistence(bitmap) &&
bdrv_remove_persistent_dirty_bitmap(bs, name, errp) < 0)
{

View file

@ -70,20 +70,11 @@ parallels_load_bitmap_data(BlockDriverState *bs, const uint64_t *l1_table,
uint64_t offset, limit;
uint64_t bm_size = bdrv_dirty_bitmap_size(bitmap);
uint8_t *buf = NULL;
uint64_t i, tab_size =
DIV_ROUND_UP(bdrv_dirty_bitmap_serialization_size(bitmap, 0, bm_size),
s->cluster_size);
if (tab_size != l1_size) {
error_setg(errp, "Bitmap table size %" PRIu32 " does not correspond "
"to bitmap size and cluster size. Expected %" PRIu64,
l1_size, tab_size);
return -EINVAL;
}
uint64_t i;
buf = qemu_blockalign(bs, s->cluster_size);
limit = bdrv_dirty_bitmap_serialization_coverage(s->cluster_size, bitmap);
for (i = 0, offset = 0; i < tab_size; ++i, offset += limit) {
for (i = 0, offset = 0; i < l1_size; ++i, offset += limit) {
uint64_t count = MIN(bm_size - offset, limit);
uint64_t entry = l1_table[i];
@ -124,12 +115,14 @@ static BdrvDirtyBitmap * GRAPH_RDLOCK
parallels_load_bitmap(BlockDriverState *bs, uint8_t *data, size_t data_size,
Error **errp)
{
BDRVParallelsState *s = bs->opaque;
int ret;
ParallelsDirtyBitmapFeature bf;
g_autofree uint64_t *l1_table = NULL;
BdrvDirtyBitmap *bitmap;
QemuUUID uuid;
char uuidstr[UUID_STR_LEN];
uint64_t bm_size, tab_size;
int i;
if (data_size < sizeof(bf)) {
@ -164,15 +157,34 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *data, size_t data_size,
return NULL;
}
l1_table = g_new(uint64_t, bf.l1_size);
for (i = 0; i < bf.l1_size; i++, data += sizeof(uint64_t)) {
l1_table[i] = ldq_le_p(data);
bm_size = bdrv_dirty_bitmap_size(bitmap);
tab_size = DIV_ROUND_UP(
bdrv_dirty_bitmap_serialization_size(bitmap, 0, bm_size),
s->cluster_size);
if (tab_size != bf.l1_size) {
error_setg(errp, "Bitmap table size %" PRIu32 " does not correspond "
"to bitmap size and cluster size. Expected %" PRIu64,
bf.l1_size, tab_size);
goto fail;
}
ret = parallels_load_bitmap_data(bs, l1_table, bf.l1_size, bitmap, errp);
if (ret < 0) {
bdrv_release_dirty_bitmap(bitmap);
return NULL;
if (bf.l1_size != 0) {
l1_table = g_try_new(uint64_t, bf.l1_size);
if (!l1_table) {
error_setg(errp, "Failed to allocate the bitmap L1 table "
"(%" PRIu32 " entries)", bf.l1_size);
goto fail;
}
for (i = 0; i < bf.l1_size; i++, data += sizeof(uint64_t)) {
l1_table[i] = ldq_le_p(data);
}
ret = parallels_load_bitmap_data(bs, l1_table, bf.l1_size, bitmap,
errp);
if (ret < 0) {
goto fail;
}
}
/* We support format extension only for RO parallels images. */
@ -180,6 +192,10 @@ parallels_load_bitmap(BlockDriverState *bs, uint8_t *data, size_t data_size,
bdrv_dirty_bitmap_set_readonly(bitmap, true);
return bitmap;
fail:
bdrv_release_dirty_bitmap(bitmap);
return NULL;
}
static int GRAPH_RDLOCK

View file

@ -52,6 +52,7 @@
#define HEADER_VERSION 2
#define HEADER_INUSE_MAGIC (0x746F6E59)
#define MAX_PARALLELS_IMAGE_FACTOR (1ull << 32)
#define PARALLELS_HEADER_READ_CHUNK (64 * 1024 * 1024)
static QEnumLookup prealloc_mode_lookup = {
.array = (const char *const[]) {
@ -118,6 +119,7 @@ static uint32_t bat_entry_off(uint32_t idx)
static int64_t seek_to_sector(BDRVParallelsState *s, int64_t sector_num)
{
uint32_t index, offset;
int64_t cluster_off;
index = sector_num / s->tracks;
offset = sector_num % s->tracks;
@ -126,7 +128,14 @@ static int64_t seek_to_sector(BDRVParallelsState *s, int64_t sector_num)
if ((index >= s->bat_size) || (s->bat_bitmap[index] == 0)) {
return -1;
}
return bat2sect(s, index) + offset;
cluster_off = bat2sect(s, index);
if (cluster_off < s->data_start || cluster_off + s->tracks > s->data_end) {
/* Cluster is outside of the image file or overlaps the header. */
return -1;
}
return cluster_off + offset;
}
static int cluster_remainder(BDRVParallelsState *s, int64_t sector_num,
@ -702,18 +711,22 @@ parallels_check_outside_image(BlockDriverState *bs, BdrvCheckResult *res,
{
BDRVParallelsState *s = bs->opaque;
uint32_t i;
int64_t off, high_off, size;
int64_t off, high_off, size, data_start_off;
size = bdrv_co_getlength(bs->file->bs);
if (size < 0) {
res->check_errors++;
return size;
}
data_start_off = s->data_start << BDRV_SECTOR_BITS;
high_off = 0;
for (i = 0; i < s->bat_size; i++) {
off = bat2sect(s, i) << BDRV_SECTOR_BITS;
if (off + s->cluster_size > size) {
if (off == 0) {
continue;
}
if (off < data_start_off || off + s->cluster_size > size) {
fprintf(stderr, "%s cluster %u is outside image\n",
fix & BDRV_FIX_ERRORS ? "Repairing" : "ERROR", i);
res->corruptions++;
@ -998,7 +1011,8 @@ parallels_co_create(BlockdevCreateOptions* opts, Error **errp)
BlockdevCreateOptionsParallels *parallels_opts;
BlockDriverState *bs;
BlockBackend *blk;
int64_t total_size, cl_size;
int64_t total_size, cl_size, bat_count;
uint64_t cylinders;
uint32_t bat_entries, bat_sectors;
ParallelsHeader header;
uint8_t tmp[BDRV_SECTOR_SIZE];
@ -1016,16 +1030,22 @@ parallels_co_create(BlockdevCreateOptions* opts, Error **errp)
cl_size = DEFAULT_CLUSTER_SIZE;
}
/* XXX What is the real limit here? This is an insanely large maximum. */
/* Bounds cl_size so the multiplication below can't overflow int64_t. */
if (cl_size >= INT64_MAX / MAX_PARALLELS_IMAGE_FACTOR) {
error_setg(errp, "Cluster size is too large");
return -EINVAL;
}
if (total_size >= MAX_PARALLELS_IMAGE_FACTOR * cl_size) {
if (cl_size <= 0 || total_size >= MAX_PARALLELS_IMAGE_FACTOR * cl_size) {
error_setg(errp, "Image size is too large for this cluster size");
return -E2BIG;
}
bat_count = DIV_ROUND_UP(total_size, cl_size);
if (bat_count > INT_MAX / (int64_t)sizeof(uint32_t)) {
error_setg(errp, "Catalog too large");
return -EFBIG;
}
if (!QEMU_IS_ALIGNED(total_size, BDRV_SECTOR_SIZE)) {
error_setg(errp, "Image size must be a multiple of 512 bytes");
return -EINVAL;
@ -1051,7 +1071,7 @@ parallels_co_create(BlockdevCreateOptions* opts, Error **errp)
blk_set_allow_write_beyond_eof(blk, true);
/* Create image format */
bat_entries = DIV_ROUND_UP(total_size, cl_size);
bat_entries = bat_count;
bat_sectors = DIV_ROUND_UP(bat_entry_off(bat_entries), cl_size);
bat_sectors = (bat_sectors * cl_size) >> BDRV_SECTOR_BITS;
@ -1060,8 +1080,12 @@ parallels_co_create(BlockdevCreateOptions* opts, Error **errp)
header.version = cpu_to_le32(HEADER_VERSION);
/* don't care much about geometry, it is not used on image level */
header.heads = cpu_to_le32(HEADS_NUMBER);
header.cylinders = cpu_to_le32(total_size / BDRV_SECTOR_SIZE
/ HEADS_NUMBER / SEC_IN_CYL);
cylinders = total_size / BDRV_SECTOR_SIZE / HEADS_NUMBER / SEC_IN_CYL;
/* Write only by spec, do not care */
if (cylinders >= UINT32_MAX) {
cylinders = UINT32_MAX;
}
header.cylinders = cpu_to_le32(cylinders);
header.tracks = cpu_to_le32(cl_size >> BDRV_SECTOR_BITS);
header.bat_entries = cpu_to_le32(bat_entries);
header.nb_sectors = cpu_to_le64(DIV_ROUND_UP(total_size, BDRV_SECTOR_SIZE));
@ -1240,7 +1264,8 @@ static int parallels_open(BlockDriverState *bs, QDict *options, int flags,
{
BDRVParallelsState *s = bs->opaque;
ParallelsHeader ph;
int ret, size, i;
int ret, i;
uint32_t size, header_off;
int64_t file_nb_sectors, sector;
uint32_t data_start;
bool need_check = false;
@ -1303,6 +1328,12 @@ static int parallels_open(BlockDriverState *bs, QDict *options, int flags,
return -EFBIG;
}
if ((uint64_t)s->bat_size * s->tracks < bs->total_sectors) {
error_setg(errp, "Invalid image: Catalog size too small for "
"advertised disk size");
return -EINVAL;
}
size = bat_entry_off(s->bat_size);
s->header_size = ROUND_UP(size, bdrv_opt_mem_align(bs->file->bs));
s->header = qemu_try_blockalign(bs->file->bs, s->header_size);
@ -1310,9 +1341,17 @@ static int parallels_open(BlockDriverState *bs, QDict *options, int flags,
return -ENOMEM;
}
ret = bdrv_pread(bs->file, 0, s->header_size, s->header, 0);
if (ret < 0) {
goto fail;
/* A single request s->header_size large exceeds BDRV_REQUEST_MAX_BYTES. */
for (header_off = 0; header_off < s->header_size;
header_off += PARALLELS_HEADER_READ_CHUNK) {
uint32_t chunk = MIN(s->header_size - header_off,
PARALLELS_HEADER_READ_CHUNK);
ret = bdrv_pread(bs->file, header_off, chunk,
(uint8_t *)s->header + header_off, 0);
if (ret < 0) {
goto fail;
}
}
s->bat_bitmap = (uint32_t *)(s->header + 1);
@ -1377,11 +1416,18 @@ static int parallels_open(BlockDriverState *bs, QDict *options, int flags,
for (i = 0; i < s->bat_size; i++) {
sector = bat2sect(s, i);
if (sector == 0) {
continue; /* not allocated */
}
if (sector < data_start || sector + s->tracks > file_nb_sectors) {
/* Cluster is outside of the image file or overlaps the header. */
need_check = true;
continue;
}
if (sector + s->tracks > s->data_end) {
s->data_end = sector + s->tracks;
}
}
need_check = need_check || s->data_end > file_nb_sectors;
if (!need_check) {
ret = parallels_fill_used_bitmap(bs);

View file

@ -535,6 +535,8 @@ static void bdrv_query_blk_stats(BlockDeviceStats *ds, BlockBackend *blk)
BlockAcctTimedStats *ts = NULL;
BlockLatencyHistogram *hgram;
qemu_mutex_lock(&stats->lock);
ds->rd_bytes = stats->nr_bytes[BLOCK_ACCT_READ];
ds->wr_bytes = stats->nr_bytes[BLOCK_ACCT_WRITE];
ds->zone_append_bytes = stats->nr_bytes[BLOCK_ACCT_ZONE_APPEND];
@ -624,6 +626,7 @@ static void bdrv_query_blk_stats(BlockDeviceStats *ds, BlockBackend *blk)
= bdrv_latency_histogram_stats(&hgram[BLOCK_ACCT_ZONE_APPEND]);
ds->flush_latency_histogram
= bdrv_latency_histogram_stats(&hgram[BLOCK_ACCT_FLUSH]);
qemu_mutex_unlock(&stats->lock);
}
static BlockStats * GRAPH_RDLOCK

View file

@ -1487,6 +1487,15 @@ int coroutine_fn qcow2_co_remove_persistent_dirty_bitmap(BlockDriverState *bs,
goto out;
}
if (!can_write(bs)) {
error_setg(errp, "Cannot remove persistent bitmap '%s': "
"no write access to node '%s'", name,
bdrv_get_node_name(bs));
ret = -EACCES;
bm = NULL;
goto out;
}
QSIMPLEQ_REMOVE(bm_list, bm, Qcow2Bitmap, entry);
ret = update_ext_header_and_dir(bs, bm_list);

View file

@ -740,12 +740,6 @@ int qcow2_snapshot_create(BlockDriverState *bs, QEMUSnapshotInfo *sn_info)
ROUND_UP(sn->vm_state_size, s->cluster_size),
QCOW2_DISCARD_NEVER, false);
#ifdef DEBUG_ALLOC
{
BdrvCheckResult result = {0};
qcow2_check_refcounts(bs, &result, 0);
}
#endif
return 0;
fail:
@ -893,12 +887,6 @@ int qcow2_snapshot_goto(BlockDriverState *bs, const char *snapshot_id)
goto fail;
}
#ifdef DEBUG_ALLOC
{
BdrvCheckResult result = {0};
qcow2_check_refcounts(bs, &result, 0);
}
#endif
return 0;
fail:
@ -975,12 +963,6 @@ int qcow2_snapshot_delete(BlockDriverState *bs,
return ret;
}
#ifdef DEBUG_ALLOC
{
BdrvCheckResult result = {0};
qcow2_check_refcounts(bs, &result, 0);
}
#endif
return 0;
}

View file

@ -2870,7 +2870,11 @@ static int GRAPH_RDLOCK qcow2_inactivate(BlockDriverState *bs)
strerror(-ret));
}
if (result == 0) {
/*
* A read-only node cannot resolve an inherited dirty bit here;
* leave it dirty, same as plain read access already does.
*/
if (result == 0 && !bdrv_is_read_only(bs)) {
qcow2_mark_clean(bs);
}

View file

@ -1128,11 +1128,6 @@ static void qemu_chr_socket_connected(QIOTask *task, void *opaque)
if (qio_task_propagate_error(task, &err)) {
tcp_chr_change_state(s, TCP_CHARDEV_STATE_DISCONNECTED);
if (s->registered_yank) {
yank_unregister_function(CHARDEV_YANK_INSTANCE(chr->label),
char_socket_yank_iochannel,
QIO_CHANNEL(sioc));
}
check_report_connect_error(chr, err);
goto cleanup;
}

View file

@ -128,7 +128,7 @@ static void win_stdio_thread_wait_func(void *opaque)
SetEvent(stdio->hInputDoneEvent);
}
static void win_stiod_chr_set_echo(Chardev *chr, bool echo)
static void win_stdio_chr_set_echo(Chardev *chr, bool echo)
{
WinStdioChardev *stdio = WIN_STDIO_CHARDEV(chr);
DWORD dwMode = 0;
@ -205,7 +205,7 @@ static bool win_stdio_chr_open(Chardev *chr,
SetConsoleMode(stdio->hStdIn, dwMode);
win_stiod_chr_set_echo(chr, false);
win_stdio_chr_set_echo(chr, false);
qemu_chr_be_event(chr, CHR_EVENT_OPENED);
return true;
@ -263,7 +263,7 @@ static void char_win_stdio_class_init(ObjectClass *oc, const void *data)
cc->chr_open = win_stdio_chr_open;
cc->chr_write = win_stdio_chr_write;
cc->chr_set_echo = win_stiod_chr_set_echo;
cc->chr_set_echo = win_stdio_chr_set_echo;
}
static const TypeInfo char_win_stdio_type_info = {

32
configure vendored
View file

@ -172,7 +172,7 @@ fi
# some defaults, based on the host environment
# default parameters
container_engine="auto"
container_command=""
cpu=""
cross_compile="no"
cross_prefix=""
@ -734,7 +734,7 @@ for opt do
;;
--disable-containers) use_containers="no"
;;
--container-engine=*) container_engine="$optarg"
--container-command=*) container_command="$optarg"
;;
--rust-target-triple=*) rust_target_triple="$optarg"
;;
@ -869,7 +869,7 @@ Advanced options (experts only):
--enable-debug enable common debug build options
--cpu=CPU Build for host CPU [$cpu]
--disable-containers don't use containers for cross-building
--container-engine=TYPE which container engine to use [$container_engine]
--container-command=CMD which container command to use [autodetect]
--gdb=GDB-path gdb to use for gdbstub tests [$gdb_bin]
--wasm64-32bit-address-limit Restrict wasm64 address space to 32-bit (default
is to use the whole 64-bit range).
@ -1166,12 +1166,12 @@ fi
# detect rust triple
meson_version=$($meson --version)
if test "$rust" != disabled && ! version_ge "$meson_version" 1.10.0; then
if test "$rust" != disabled && ! version_ge "$meson_version" 1.12.0; then
if test "$rust" = enabled; then
$mkvenv ensuregroup --dir "${source_path}/python/wheels" \
${source_path}/pythondeps.toml meson-rust || exit 1
else
echo "Rust needs Meson 1.10.0, disabling" 2>&1
echo "Rust needs Meson 1.12.0, disabling" 2>&1
rust=disabled
fi
fi
@ -1291,12 +1291,12 @@ fi
##########################################
# functions to probe cross compilers
runc="no"
if test $use_containers = "yes" && (has "docker" || has "podman"); then
runc=$($python "$source_path"/tests/docker/docker.py --engine "$container_engine" probe)
if test "$runc" != "no"; then
docker_py="$python $source_path/tests/docker/docker.py --engine $container_engine"
fi
if test "$container_command" = ""; then
container_command=$($python "$source_path"/tests/docker/docker.py probe)
test "$container_command" = "no" && container_command=""
fi
if test $use_containers = "yes" && test "$container_command" != ""; then
docker_py="$python $source_path/tests/docker/docker.py --command $container_command"
fi
# cross compilers defaults, can be overridden with --cross-cc-ARCH
@ -1415,7 +1415,7 @@ probe_target_compiler() {
esac
for host in $container_hosts; do
test "$runc" != no || continue
test "$container_command" != "" || continue
test "$host" = "$cpu" || continue
case $target_arch in
# debian-all-test-cross architectures
@ -1736,14 +1736,10 @@ echo all: >> $config_host_mak
echo "SRC_PATH=$source_path" >> $config_host_mak
echo "TARGET_DIRS=$target_list" >> $config_host_mak
echo "GDB=$gdb_bin" >> $config_host_mak
if test "$runc" != no; then
echo "RUNC=$runc" >> $config_host_mak
echo "CONTAINER_ENGINE=$container_engine" >> $config_host_mak
if test "$container_command" != ""; then
echo "CONTAINER_COMMAND=$container_command" >> $config_host_mak
fi
echo "SUBDIRS=$subdirs" >> $config_host_mak
if test "$rust" != disabled; then
echo "RUST_TARGET_TRIPLE=$rust_target_triple" >> $config_host_mak
fi
echo "PYTHON=$python" >> $config_host_mak
echo "MKVENV_ENSUREGROUP=$mkvenv ensuregroup $mkvenv_online_flag" >> $config_host_mak
echo "GENISOIMAGE=$genisoimage" >> $config_host_mak

View file

@ -10,7 +10,8 @@
* nothing about how a library is thunked. Any toolchain can implement the
* userspace side. Lorelei is one end-to-end implementation (guest/host
* runtimes plus a thunk compiler that generates thunks from a library's
* headers):
* headers), and how it handles argument marshalling, callbacks and variadic
* functions can serve as a reference:
* https://github.com/rover2024/lorelei
*
* See docs/about/emulation.rst|Dynamic Linking Call for details and examples.
@ -20,12 +21,13 @@
* execution in the QEMU host process. It is NOT a sandbox and provides no
* isolation; only load it for guests you fully trust.
*
* WARNING: requires guest_base == 0, which is qemu-user's default. Pointer
* operands are dereferenced as host addresses directly, and the invoked host
* functions dereference guest pointers with no address translation, so guest
* and host must share a single address space. A non-zero guest_base (e.g. set
* via -B/-R) would make every pointer off by guest_base and hit unrelated
* host memory.
* WARNING: requires guest_base == 0, which is qemu-user's default, and a
* guest whose pointer width and endianness match the host's. Pointer operands
* are dereferenced as host addresses directly, and the invoked host functions
* dereference guest pointers with no address translation, so guest and host
* must share a single address space and agree on how a pointer is stored. A
* non-zero guest_base (e.g. set via -B/-R) would make every pointer off by
* guest_base and hit unrelated host memory.
*
* SPDX-License-Identifier: GPL-2.0-or-later
*/
@ -46,8 +48,18 @@ QEMU_PLUGIN_EXPORT int qemu_plugin_version = QEMU_PLUGIN_VERSION;
*
* It defaults to DLCALL_SYSCALL_DEFAULT and can be overridden at load time
* with the "syscall_num=N" argument. To avoid hijacking a real syscall the
* guest might issue, N must be at least DLCALL_SYSCALL_MIN: every Linux ABI
* keeps its syscall numbers well below this; numbers from here up are free.
* guest might issue, N must be at least DLCALL_SYSCALL_MIN, which most Linux
* ABIs keep their syscall numbers well below.
*
* N also has to reach the filter at all, which bounds it from above in a
* target specific way: arm32 answers anything past ARM_NR_BASE (0xf0000) with
* ENOSYS or SIGILL before do_syscall() runs, while aarch64 has no such bound.
*
* MIPS O32 bases its numbering at 4000, so the default is a real syscall there
* (getpriority). Raising N does not help either, because O32 rejects numbers
* its table does not define, again before the filter runs, which leaves no
* number that is both free and reachable on that ABI. Its N32 and N64 ABIs
* base at 6000 and 5000 and have no such gate, so they are unaffected.
*/
enum {
DLCALL_SYSCALL_DEFAULT = 4096,
@ -168,6 +180,7 @@ static bool vcpu_syscall_filter(unsigned int vcpu_index,
case DLCALL_ID_FREE_LIBRARY: {
void *handle = (void *) a2;
int *ret_ptr = (int *) a3;
assert(ret_ptr);
*ret_ptr = dlclose(handle);
*sysret = 0;
break;
@ -176,6 +189,7 @@ static bool vcpu_syscall_filter(unsigned int vcpu_index,
/* Get the last error message for a library event. */
case DLCALL_ID_GET_LIBRARY_ERROR: {
const char **error_ptr = (const char **) a2;
assert(error_ptr);
*error_ptr = dlerror();
*sysret = 0;
break;

View file

@ -31,8 +31,12 @@ typedef struct CPU {
QEMU_PLUGIN_EXPORT int qemu_plugin_version = QEMU_PLUGIN_VERSION;
static GArray *cpus;
static GRWLock expand_array_lock;
/*
* Per-vCPU state stored in a qemu_plugin_scoreboard. The scoreboard manages
* per-vCPU storage automatically, eliminating the need for manual array
* growth, locks, or pointer-stability workarounds.
*/
static struct qemu_plugin_scoreboard *cpus;
static GPtrArray *imatches;
static GArray *amatches;
@ -41,23 +45,13 @@ static bool disas_assist;
static GMutex add_reg_name_lock;
static GPtrArray *all_reg_names;
static CPU *get_cpu(int vcpu_index)
{
CPU *c;
g_rw_lock_reader_lock(&expand_array_lock);
c = &g_array_index(cpus, CPU, vcpu_index);
g_rw_lock_reader_unlock(&expand_array_lock);
return c;
}
/**
* Add memory read or write information to current instruction log
*/
static void vcpu_mem(unsigned int cpu_index, qemu_plugin_meminfo_t info,
uint64_t vaddr, void *udata)
{
CPU *c = get_cpu(cpu_index);
CPU *c = qemu_plugin_scoreboard_find(cpus, cpu_index);
GString *s = c->last_exec;
/* Find vCPU in array */
@ -117,7 +111,7 @@ static void insn_check_regs(CPU *cpu)
/* Log last instruction while checking registers */
static void vcpu_insn_exec_with_regs(unsigned int cpu_index, void *udata)
{
CPU *cpu = get_cpu(cpu_index);
CPU *cpu = qemu_plugin_scoreboard_find(cpus, cpu_index);
/* Print previous instruction in cache */
if (cpu->last_exec->len) {
@ -125,8 +119,8 @@ static void vcpu_insn_exec_with_regs(unsigned int cpu_index, void *udata)
insn_check_regs(cpu);
}
g_string_append_c(cpu->last_exec, '\n');
qemu_plugin_outs(cpu->last_exec->str);
qemu_plugin_outs("\n");
}
/* Store new instruction in cache */
@ -138,7 +132,7 @@ static void vcpu_insn_exec_with_regs(unsigned int cpu_index, void *udata)
/* Log last instruction while checking registers, ignore next */
static void vcpu_insn_exec_only_regs(unsigned int cpu_index, void *udata)
{
CPU *cpu = get_cpu(cpu_index);
CPU *cpu = qemu_plugin_scoreboard_find(cpus, cpu_index);
/* Print previous instruction in cache */
if (cpu->last_exec->len) {
@ -146,8 +140,8 @@ static void vcpu_insn_exec_only_regs(unsigned int cpu_index, void *udata)
insn_check_regs(cpu);
}
g_string_append_c(cpu->last_exec, '\n');
qemu_plugin_outs(cpu->last_exec->str);
qemu_plugin_outs("\n");
}
/* reset */
@ -157,12 +151,12 @@ static void vcpu_insn_exec_only_regs(unsigned int cpu_index, void *udata)
/* Log last instruction without checking regs, setup next */
static void vcpu_insn_exec(unsigned int cpu_index, void *udata)
{
CPU *cpu = get_cpu(cpu_index);
CPU *cpu = qemu_plugin_scoreboard_find(cpus, cpu_index);
/* Print previous instruction in cache */
if (cpu->last_exec->len) {
g_string_append_c(cpu->last_exec, '\n');
qemu_plugin_outs(cpu->last_exec->str);
qemu_plugin_outs("\n");
}
/* Store new instruction in cache */
@ -378,40 +372,47 @@ static GPtrArray *registers_init(int vcpu_index)
* - last_exec tracking data
* - list of tracked registers
* - initial value of registers
*
* As we could have multiple threads trying to do this we need to
* serialise the expansion under a lock.
*/
static void vcpu_init(unsigned int vcpu_index, void *userdata)
{
CPU *c;
g_rw_lock_writer_lock(&expand_array_lock);
if (vcpu_index >= cpus->len) {
g_array_set_size(cpus, vcpu_index + 1);
}
g_rw_lock_writer_unlock(&expand_array_lock);
c = get_cpu(vcpu_index);
CPU *c = qemu_plugin_scoreboard_find(cpus, vcpu_index);
c->last_exec = g_string_new(NULL);
c->registers = registers_init(vcpu_index);
}
/**
* On plugin exit, print last instruction in cache
* On vCPU exit, flush the last cached instruction for this vCPU.
*
* The one-instruction-delay pattern stores each instruction in last_exec and
* only prints it when the *next* callback fires. When a thread exits via
* syscall (e.g. ecall/exit), no subsequent callback fires for that vCPU and
* the final instruction is silently dropped. Flushing here guarantees it is
* written before the vCPU is torn down.
*/
static void vcpu_exit(unsigned int vcpu_index, void *udata)
{
CPU *c = qemu_plugin_scoreboard_find(cpus, vcpu_index);
if (c->last_exec && c->last_exec->len) {
g_string_append_c(c->last_exec, '\n');
qemu_plugin_outs(c->last_exec->str);
g_string_truncate(c->last_exec, 0);
}
}
/**
* On plugin exit, flush any remaining cached instructions and free state.
*/
static void plugin_exit(void *p)
{
guint i;
g_rw_lock_reader_lock(&expand_array_lock);
for (i = 0; i < cpus->len; i++) {
CPU *c = get_cpu(i);
if (c->last_exec && c->last_exec->str) {
int n = qemu_plugin_num_vcpus();
for (int i = 0; i < n; i++) {
CPU *c = qemu_plugin_scoreboard_find(cpus, i);
if (c->last_exec && c->last_exec->len) {
g_string_append_c(c->last_exec, '\n');
qemu_plugin_outs(c->last_exec->str);
qemu_plugin_outs("\n");
}
}
g_rw_lock_reader_unlock(&expand_array_lock);
qemu_plugin_scoreboard_free(cpus);
}
/* Add a match to the array of matches */
@ -452,12 +453,8 @@ QEMU_PLUGIN_EXPORT int qemu_plugin_install(qemu_plugin_id_t id,
const qemu_info_t *info, int argc,
char **argv)
{
/*
* Initialize dynamic array to cache vCPU instruction. In user mode
* we don't know the size before emulation.
*/
cpus = g_array_sized_new(true, true, sizeof(CPU),
info->system_emulation ? info->system.max_vcpus : 1);
/* Initialize scoreboard to cache per-vCPU instruction state. */
cpus = qemu_plugin_scoreboard_new(sizeof(CPU));
for (int i = 0; i < argc; i++) {
char *opt = argv[i];
@ -483,6 +480,7 @@ QEMU_PLUGIN_EXPORT int qemu_plugin_install(qemu_plugin_id_t id,
/* Register init, translation block and exit callbacks */
qemu_plugin_register_vcpu_init_cb(id, vcpu_init, NULL);
qemu_plugin_register_vcpu_tb_trans_cb(id, vcpu_tb_trans, NULL);
qemu_plugin_register_vcpu_exit_cb(id, vcpu_exit, NULL);
qemu_plugin_register_atexit_cb(id, plugin_exit, NULL);
return 0;

View file

@ -388,7 +388,13 @@ vg_resource_create_2d(VuGpu *g,
cmd->error = VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER;
return;
}
vugbm_buffer_create(&res->buffer, &g->gdev, c2d.width, c2d.height);
if (!vugbm_buffer_create(&res->buffer, &g->gdev, c2d.width, c2d.height)) {
g_critical("%s: buffer creation failed %d %d %d",
__func__, c2d.resource_id, c2d.width, c2d.height);
g_free(res);
cmd->error = VIRTIO_GPU_RESP_ERR_OUT_OF_MEMORY;
return;
}
res->image = pixman_image_create_bits(pformat,
c2d.width,
c2d.height,
@ -481,7 +487,7 @@ vg_create_mapping_iov(VuGpu *g,
struct virtio_gpu_ctrl_command *cmd,
struct iovec **iov)
{
struct virtio_gpu_mem_entry *ents;
g_autofree struct virtio_gpu_mem_entry *ents = NULL;
size_t esize, s;
int i;
@ -492,17 +498,22 @@ vg_create_mapping_iov(VuGpu *g,
}
esize = sizeof(*ents) * ab->nr_entries;
ents = g_malloc(esize);
ents = g_try_malloc(esize);
if (!ents && esize) {
return -1;
}
s = iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num,
sizeof(*ab), ents, esize);
if (s != esize) {
g_critical("%s: command data size incorrect %zu vs %zu",
__func__, s, esize);
g_free(ents);
return -1;
}
*iov = g_new0(struct iovec, ab->nr_entries);
*iov = g_try_new0(struct iovec, ab->nr_entries);
if (!*iov && ab->nr_entries) {
return -1;
}
for (i = 0; i < ab->nr_entries; i++) {
uint64_t len = ents[i].length;
(*iov)[i].iov_len = ents[i].length;
@ -511,12 +522,10 @@ vg_create_mapping_iov(VuGpu *g,
g_critical("%s: resource %d element %d",
__func__, ab->resource_id, i);
g_free(*iov);
g_free(ents);
*iov = NULL;
return -1;
}
}
g_free(ents);
return 0;
}
@ -822,8 +831,14 @@ vg_resource_flush(VuGpu *g,
PIXMAN_FORMAT_BPP(pixman_image_get_format(res->image)) / 8;
size_t size = width * height * bpp;
void *p = g_malloc(VHOST_USER_GPU_HDR_SIZE +
sizeof(VhostUserGpuUpdate) + size);
void *p = g_try_malloc(VHOST_USER_GPU_HDR_SIZE +
sizeof(VhostUserGpuUpdate) + size);
if (!p) {
pixman_region_fini(&region);
pixman_region_fini(&finalregion);
cmd->error = VIRTIO_GPU_RESP_ERR_OUT_OF_MEMORY;
break;
}
VhostUserGpuMsg *msg = p;
msg->request = VHOST_USER_GPU_UPDATE;
msg->size = sizeof(VhostUserGpuUpdate) + size;
@ -924,16 +939,19 @@ vg_handle_ctrl(VuDev *dev, int qidx)
if (len != sizeof(cmd->cmd_hdr)) {
g_warning("%s: command size incorrect %zu vs %zu\n",
__func__, len, sizeof(cmd->cmd_hdr));
}
virtio_gpu_ctrl_hdr_bswap(&cmd->cmd_hdr);
g_debug("%d %s\n", cmd->cmd_hdr.type,
vg_cmd_to_string(cmd->cmd_hdr.type));
if (vg->virgl) {
vg_virgl_process_cmd(vg, cmd);
memset(&cmd->cmd_hdr, 0, sizeof(cmd->cmd_hdr));
vg_ctrl_response_nodata(
vg, cmd, VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER);
} else {
vg_process_cmd(vg, cmd);
virtio_gpu_ctrl_hdr_bswap(&cmd->cmd_hdr);
g_debug("%d %s\n", cmd->cmd_hdr.type,
vg_cmd_to_string(cmd->cmd_hdr.type));
if (vg->virgl) {
vg_virgl_process_cmd(vg, cmd);
} else {
vg_process_cmd(vg, cmd);
}
}
if (cmd->state != VG_CMD_STATE_FINISHED) {

View file

@ -202,7 +202,18 @@ virgl_cmd_submit_3d(VuGpu *g,
VUGPU_FILL_CMD(cs);
buf = g_malloc(cs.size);
if (cs.size > VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE) {
g_critical("%s: command buffer too large (%u)",
__func__, cs.size);
cmd->error = VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER;
return;
}
buf = g_try_malloc(cs.size);
if (!buf && cs.size) {
cmd->error = VIRTIO_GPU_RESP_ERR_OUT_OF_MEMORY;
return;
}
s = iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num,
sizeof(cs), buf, cs.size);
if (s != cs.size) {

View file

@ -13,7 +13,10 @@
static bool
mem_alloc_bo(struct vugbm_buffer *buf)
{
buf->mmap = g_malloc(buf->width * buf->height * 4);
buf->mmap = g_try_malloc((uint64_t)buf->width * buf->height * 4);
if (!buf->mmap && buf->width && buf->height) {
return false;
}
buf->stride = buf->width * 4;
return true;
}
@ -53,7 +56,8 @@ struct udmabuf_create {
static size_t
udmabuf_get_size(struct vugbm_buffer *buf)
{
return ROUND_UP(buf->width * buf->height * 4, qemu_real_host_page_size());
return ROUND_UP((uint64_t)buf->width * buf->height * 4,
qemu_real_host_page_size());
}
static bool
@ -293,6 +297,12 @@ bool
vugbm_buffer_create(struct vugbm_buffer *buffer, struct vugbm_device *dev,
uint32_t width, uint32_t height)
{
uint64_t size = (uint64_t)width * height * 4;
if (size > UINT32_MAX) {
g_warning("buffer dimensions too large: %ux%u", width, height);
return false;
}
buffer->dev = dev;
buffer->width = width;
buffer->height = height;

View file

@ -22,6 +22,7 @@
#include "qemu/queue.h"
#include "qemu/iov.h"
#include "qemu/bswap.h"
#include "qemu/units.h"
#include "vugbm.h"
typedef enum VhostUserGpuRequest {
@ -163,6 +164,14 @@ struct virtio_gpu_ctrl_command {
QTAILQ_ENTRY(virtio_gpu_ctrl_command) next;
};
/*
* With 4 KiB pages and QEMU's VIRTQUEUE_MAX_SIZE (1024) mapped-iov
* limit, the largest inline command is ~4 MiB. Cap submit_3d
* allocations to this value to prevent a malicious guest from
* triggering an OOM abort via an inflated cs.size field.
*/
#define VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE (4 * MiB)
#define VUGPU_FILL_CMD(out) do { \
size_t vugpufillcmd_s_ = \
iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num, 0, \
@ -170,6 +179,7 @@ struct virtio_gpu_ctrl_command {
if (vugpufillcmd_s_ != sizeof(out)) { \
g_critical("%s: command size incorrect %zu vs %zu", \
__func__, vugpufillcmd_s_, sizeof(out)); \
cmd->error = VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; \
return; \
} \
} while (0)

View file

@ -65,6 +65,8 @@ static int qcrypto_cipher_mode_to_gcry_mode(QCryptoCipherMode mode)
return GCRY_CIPHER_MODE_CBC;
case QCRYPTO_CIPHER_MODE_CTR:
return GCRY_CIPHER_MODE_CTR;
case QCRYPTO_CIPHER_MODE_GCM:
return GCRY_CIPHER_MODE_GCM;
default:
return GCRY_CIPHER_MODE_NONE;
}
@ -104,6 +106,10 @@ bool qcrypto_cipher_supports(QCryptoCipherAlgo alg,
case QCRYPTO_CIPHER_MODE_XTS:
case QCRYPTO_CIPHER_MODE_CTR:
return true;
case QCRYPTO_CIPHER_MODE_GCM:
/* GCM requires a 128-bit block cipher. */
return gcry_cipher_get_algo_blklen(
qcrypto_cipher_alg_to_gcry_alg(alg)) == 16;
default:
return false;
}
@ -228,6 +234,99 @@ static const struct QCryptoCipherDriver qcrypto_gcrypt_ctr_driver = {
.cipher_free = qcrypto_gcrypt_ctx_free,
};
/*
* GCM is an AEAD stream mode: the IV/nonce need not match the block size,
* the message length need not be a multiple of the block size, associated
* data is fed with gcry_cipher_authenticate() and the authentication tag is
* read back with gcry_cipher_gettag().
*/
static int qcrypto_gcrypt_gcm_setiv(QCryptoCipher *cipher,
const uint8_t *iv, size_t niv,
Error **errp)
{
QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
gcry_error_t err;
gcry_cipher_reset(ctx->handle);
err = gcry_cipher_setiv(ctx->handle, iv, niv);
if (err != 0) {
error_setg(errp, "Cannot set IV: %s", gcry_strerror(err));
return -1;
}
return 0;
}
static int qcrypto_gcrypt_gcm_setaad(QCryptoCipher *cipher,
const uint8_t *aad, size_t len,
Error **errp)
{
QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
gcry_error_t err;
err = gcry_cipher_authenticate(ctx->handle, aad, len);
if (err != 0) {
error_setg(errp, "Cannot set AAD: %s", gcry_strerror(err));
return -1;
}
return 0;
}
static int qcrypto_gcrypt_gcm_encrypt(QCryptoCipher *cipher, const void *in,
void *out, size_t len, Error **errp)
{
QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
gcry_error_t err;
err = gcry_cipher_encrypt(ctx->handle, out, len, in, len);
if (err != 0) {
error_setg(errp, "Cannot encrypt data: %s", gcry_strerror(err));
return -1;
}
return 0;
}
static int qcrypto_gcrypt_gcm_decrypt(QCryptoCipher *cipher, const void *in,
void *out, size_t len, Error **errp)
{
QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
gcry_error_t err;
err = gcry_cipher_decrypt(ctx->handle, out, len, in, len);
if (err != 0) {
error_setg(errp, "Cannot decrypt data: %s", gcry_strerror(err));
return -1;
}
return 0;
}
static int qcrypto_gcrypt_gcm_gettag(QCryptoCipher *cipher,
uint8_t *tag, size_t len, Error **errp)
{
QCryptoCipherGcrypt *ctx = container_of(cipher, QCryptoCipherGcrypt, base);
gcry_error_t err;
err = gcry_cipher_gettag(ctx->handle, tag, len);
if (err != 0) {
error_setg(errp, "Cannot get tag: %s", gcry_strerror(err));
return -1;
}
return 0;
}
static const struct QCryptoCipherDriver qcrypto_gcrypt_gcm_driver = {
.cipher_encrypt = qcrypto_gcrypt_gcm_encrypt,
.cipher_decrypt = qcrypto_gcrypt_gcm_decrypt,
.cipher_setiv = qcrypto_gcrypt_gcm_setiv,
.cipher_setaad = qcrypto_gcrypt_gcm_setaad,
.cipher_gettag = qcrypto_gcrypt_gcm_gettag,
.cipher_free = qcrypto_gcrypt_ctx_free,
};
static QCryptoCipher *qcrypto_cipher_ctx_new(QCryptoCipherAlgo alg,
QCryptoCipherMode mode,
const uint8_t *key,
@ -259,6 +358,8 @@ static QCryptoCipher *qcrypto_cipher_ctx_new(QCryptoCipherAlgo alg,
if (mode == QCRYPTO_CIPHER_MODE_CTR) {
drv = &qcrypto_gcrypt_ctr_driver;
} else if (mode == QCRYPTO_CIPHER_MODE_GCM) {
drv = &qcrypto_gcrypt_gcm_driver;
} else {
drv = &qcrypto_gcrypt_driver;
}

View file

@ -48,6 +48,15 @@ bool qcrypto_cipher_supports(QCryptoCipherAlgo alg,
default:
return false;
}
case QCRYPTO_CIPHER_MODE_GCM:
switch (alg) {
case QCRYPTO_CIPHER_ALGO_AES_128:
case QCRYPTO_CIPHER_ALGO_AES_192:
case QCRYPTO_CIPHER_ALGO_AES_256:
return true;
default:
return false;
}
default:
return false;
}
@ -223,6 +232,147 @@ static struct QCryptoCipherDriver gnutls_driver = {
.cipher_free = qcrypto_gnutls_cipher_free,
};
/*
* GCM is an AEAD stream mode: the nonce need not match the block size, the
* message length need not be a multiple of the block size, associated data is
* fed with gnutls_cipher_add_auth() and the authentication tag is read back
* with gnutls_cipher_tag().
*/
static int
qcrypto_gnutls_cipher_encrypt_gcm(QCryptoCipher *cipher,
const void *in, void *out,
size_t len, Error **errp)
{
QCryptoCipherGnutls *ctx = container_of(cipher, QCryptoCipherGnutls, base);
int err;
err = gnutls_cipher_encrypt2(ctx->handle, in, len, out, len);
if (err != 0) {
error_setg(errp, "Cannot encrypt data: %s", gnutls_strerror(err));
return -1;
}
return 0;
}
static int
qcrypto_gnutls_cipher_decrypt_gcm(QCryptoCipher *cipher,
const void *in, void *out,
size_t len, Error **errp)
{
QCryptoCipherGnutls *ctx = container_of(cipher, QCryptoCipherGnutls, base);
int err;
err = gnutls_cipher_decrypt2(ctx->handle, in, len, out, len);
if (err != 0) {
error_setg(errp, "Cannot decrypt data: %s", gnutls_strerror(err));
return -1;
}
return 0;
}
static int
qcrypto_gnutls_cipher_setiv_gcm(QCryptoCipher *cipher,
const uint8_t *iv, size_t niv,
Error **errp)
{
QCryptoCipherGnutls *ctx = container_of(cipher, QCryptoCipherGnutls, base);
gnutls_cipher_set_iv(ctx->handle, (void *)iv, niv);
return 0;
}
static int
qcrypto_gnutls_cipher_setaad_gcm(QCryptoCipher *cipher,
const uint8_t *aad, size_t len,
Error **errp)
{
QCryptoCipherGnutls *ctx = container_of(cipher, QCryptoCipherGnutls, base);
int err;
err = gnutls_cipher_add_auth(ctx->handle, aad, len);
if (err != 0) {
error_setg(errp, "Cannot add associated data: %s",
gnutls_strerror(err));
return -1;
}
return 0;
}
static int
qcrypto_gnutls_cipher_gettag_gcm(QCryptoCipher *cipher,
uint8_t *tag, size_t len,
Error **errp)
{
QCryptoCipherGnutls *ctx = container_of(cipher, QCryptoCipherGnutls, base);
int err;
err = gnutls_cipher_tag(ctx->handle, tag, len);
if (err != 0) {
error_setg(errp, "Cannot get authentication tag: %s",
gnutls_strerror(err));
return -1;
}
return 0;
}
static struct QCryptoCipherDriver gnutls_gcm_driver = {
.cipher_encrypt = qcrypto_gnutls_cipher_encrypt_gcm,
.cipher_decrypt = qcrypto_gnutls_cipher_decrypt_gcm,
.cipher_setiv = qcrypto_gnutls_cipher_setiv_gcm,
.cipher_setaad = qcrypto_gnutls_cipher_setaad_gcm,
.cipher_gettag = qcrypto_gnutls_cipher_gettag_gcm,
.cipher_free = qcrypto_gnutls_cipher_free,
};
static QCryptoCipher *
qcrypto_gnutls_aes_gcm_ctx_new(QCryptoCipherAlgo alg, const uint8_t *key,
size_t nkey, Error **errp)
{
gnutls_datum_t gkey = { (unsigned char *)key, nkey };
gnutls_cipher_algorithm_t galg = GNUTLS_CIPHER_UNKNOWN;
QCryptoCipherGnutls *ctx;
int err;
switch (alg) {
case QCRYPTO_CIPHER_ALGO_AES_128:
galg = GNUTLS_CIPHER_AES_128_GCM;
break;
case QCRYPTO_CIPHER_ALGO_AES_192:
galg = GNUTLS_CIPHER_AES_192_GCM;
break;
case QCRYPTO_CIPHER_ALGO_AES_256:
galg = GNUTLS_CIPHER_AES_256_GCM;
break;
default:
error_setg(errp, "Unsupported cipher algorithm %s with GCM mode",
QCryptoCipherAlgo_str(alg));
return NULL;
}
if (!qcrypto_cipher_validate_key_length(alg, QCRYPTO_CIPHER_MODE_GCM,
nkey, errp)) {
return NULL;
}
ctx = g_new0(QCryptoCipherGnutls, 1);
ctx->base.driver = &gnutls_gcm_driver;
ctx->blocksize = 16;
err = gnutls_cipher_init(&ctx->handle, galg, &gkey, NULL);
if (err != 0) {
error_setg(errp, "Cannot initialize cipher: %s", gnutls_strerror(err));
g_free(ctx);
return NULL;
}
return &ctx->base;
}
static QCryptoCipher *qcrypto_cipher_ctx_new(QCryptoCipherAlgo alg,
QCryptoCipherMode mode,
const uint8_t *key,
@ -234,6 +384,10 @@ static QCryptoCipher *qcrypto_cipher_ctx_new(QCryptoCipherAlgo alg,
gnutls_cipher_algorithm_t galg = GNUTLS_CIPHER_UNKNOWN;
int err;
if (mode == QCRYPTO_CIPHER_MODE_GCM) {
return qcrypto_gnutls_aes_gcm_ctx_new(alg, key, nkey, errp);
}
switch (mode) {
case QCRYPTO_CIPHER_MODE_XTS:
switch (alg) {

View file

@ -27,6 +27,7 @@
#include <nettle/twofish.h>
#include <nettle/ctr.h>
#include <nettle/xts.h>
#include <nettle/gcm.h>
#ifdef CONFIG_CRYPTO_SM4
#include <nettle/sm4.h>
#endif
@ -410,6 +411,125 @@ DEFINE_ECB(qcrypto_nettle_sm4,
sm4_encrypt_native, sm4_decrypt_native)
#endif
/*
* GCM is an AEAD mode built on AES (128-bit block only). Drive it through the
* generic gcm_* interface, using the block cipher's encrypt function for both
* directions; associated data is fed with gcm_update() and the authentication
* tag is produced by gcm_digest().
*/
typedef struct QCryptoNettleAESGCM {
QCryptoCipher base;
struct gcm_key gcm_key;
struct gcm_ctx gcm_ctx;
union {
struct aes128_ctx aes128;
struct aes192_ctx aes192;
struct aes256_ctx aes256;
} cipher;
nettle_cipher_func *encrypt;
} QCryptoNettleAESGCM;
static int qcrypto_nettle_aes_gcm_setiv(QCryptoCipher *cipher,
const uint8_t *iv, size_t niv,
Error **errp)
{
QCryptoNettleAESGCM *ctx = container_of(cipher, QCryptoNettleAESGCM, base);
gcm_set_iv(&ctx->gcm_ctx, &ctx->gcm_key, niv, iv);
return 0;
}
static int qcrypto_nettle_aes_gcm_setaad(QCryptoCipher *cipher,
const uint8_t *aad, size_t len,
Error **errp)
{
QCryptoNettleAESGCM *ctx = container_of(cipher, QCryptoNettleAESGCM, base);
gcm_update(&ctx->gcm_ctx, &ctx->gcm_key, len, aad);
return 0;
}
static int qcrypto_nettle_aes_gcm_encrypt(QCryptoCipher *cipher,
const void *in, void *out,
size_t len, Error **errp)
{
QCryptoNettleAESGCM *ctx = container_of(cipher, QCryptoNettleAESGCM, base);
gcm_encrypt(&ctx->gcm_ctx, &ctx->gcm_key, &ctx->cipher, ctx->encrypt,
len, out, in);
return 0;
}
static int qcrypto_nettle_aes_gcm_decrypt(QCryptoCipher *cipher,
const void *in, void *out,
size_t len, Error **errp)
{
QCryptoNettleAESGCM *ctx = container_of(cipher, QCryptoNettleAESGCM, base);
gcm_decrypt(&ctx->gcm_ctx, &ctx->gcm_key, &ctx->cipher, ctx->encrypt,
len, out, in);
return 0;
}
static int qcrypto_nettle_aes_gcm_gettag(QCryptoCipher *cipher,
uint8_t *tag, size_t len,
Error **errp)
{
QCryptoNettleAESGCM *ctx = container_of(cipher, QCryptoNettleAESGCM, base);
gcm_digest(&ctx->gcm_ctx, &ctx->gcm_key, &ctx->cipher, ctx->encrypt,
len, tag);
return 0;
}
static const struct QCryptoCipherDriver qcrypto_nettle_aes_gcm_driver = {
.cipher_encrypt = qcrypto_nettle_aes_gcm_encrypt,
.cipher_decrypt = qcrypto_nettle_aes_gcm_decrypt,
.cipher_setiv = qcrypto_nettle_aes_gcm_setiv,
.cipher_setaad = qcrypto_nettle_aes_gcm_setaad,
.cipher_gettag = qcrypto_nettle_aes_gcm_gettag,
.cipher_free = qcrypto_cipher_ctx_free,
};
static QCryptoCipher *qcrypto_nettle_aes_gcm_ctx_new(QCryptoCipherAlgo alg,
const uint8_t *key,
size_t nkey,
Error **errp)
{
QCryptoNettleAESGCM *ctx;
if (!qcrypto_cipher_validate_key_length(alg, QCRYPTO_CIPHER_MODE_GCM,
nkey, errp)) {
return NULL;
}
ctx = g_new0(QCryptoNettleAESGCM, 1);
ctx->base.driver = &qcrypto_nettle_aes_gcm_driver;
switch (alg) {
case QCRYPTO_CIPHER_ALGO_AES_128:
aes128_set_encrypt_key(&ctx->cipher.aes128, key);
ctx->encrypt = aes128_encrypt_native;
break;
case QCRYPTO_CIPHER_ALGO_AES_192:
aes192_set_encrypt_key(&ctx->cipher.aes192, key);
ctx->encrypt = aes192_encrypt_native;
break;
case QCRYPTO_CIPHER_ALGO_AES_256:
aes256_set_encrypt_key(&ctx->cipher.aes256, key);
ctx->encrypt = aes256_encrypt_native;
break;
default:
error_setg(errp, "Unsupported cipher algorithm %s with GCM mode",
QCryptoCipherAlgo_str(alg));
g_free(ctx);
return NULL;
}
gcm_set_key(&ctx->gcm_key, &ctx->cipher, ctx->encrypt);
return &ctx->base;
}
bool qcrypto_cipher_supports(QCryptoCipherAlgo alg,
QCryptoCipherMode mode)
{
@ -440,6 +560,10 @@ bool qcrypto_cipher_supports(QCryptoCipherAlgo alg,
case QCRYPTO_CIPHER_MODE_XTS:
case QCRYPTO_CIPHER_MODE_CTR:
return true;
case QCRYPTO_CIPHER_MODE_GCM:
return alg == QCRYPTO_CIPHER_ALGO_AES_128 ||
alg == QCRYPTO_CIPHER_ALGO_AES_192 ||
alg == QCRYPTO_CIPHER_ALGO_AES_256;
default:
return false;
}
@ -451,6 +575,10 @@ static QCryptoCipher *qcrypto_cipher_ctx_new(QCryptoCipherAlgo alg,
size_t nkey,
Error **errp)
{
if (mode == QCRYPTO_CIPHER_MODE_GCM) {
return qcrypto_nettle_aes_gcm_ctx_new(alg, key, nkey, errp);
}
switch (mode) {
case QCRYPTO_CIPHER_MODE_ECB:
case QCRYPTO_CIPHER_MODE_CBC:

View file

@ -66,6 +66,7 @@ static const bool mode_need_iv[QCRYPTO_CIPHER_MODE__MAX] = {
[QCRYPTO_CIPHER_MODE_CBC] = true,
[QCRYPTO_CIPHER_MODE_XTS] = true,
[QCRYPTO_CIPHER_MODE_CTR] = true,
[QCRYPTO_CIPHER_MODE_GCM] = true,
};
@ -142,7 +143,7 @@ qcrypto_cipher_validate_key_length(QCryptoCipherAlgo alg,
#include "cipher-gcrypt.c.inc"
#elif defined CONFIG_NETTLE
#include "cipher-nettle.c.inc"
#elif defined CONFIG_GNUTLS
#elif defined CONFIG_GNUTLS_CRYPTO
#include "cipher-gnutls.c.inc"
#else
#include "cipher-stub.c.inc"
@ -204,6 +205,37 @@ int qcrypto_cipher_setiv(QCryptoCipher *cipher,
}
int qcrypto_cipher_setaad(QCryptoCipher *cipher,
const uint8_t *aad, size_t len,
Error **errp)
{
const QCryptoCipherDriver *drv = cipher->driver;
if (!drv->cipher_setaad) {
error_setg(errp, "The cipher mode does not support associated data");
return -1;
}
return drv->cipher_setaad(cipher, aad, len, errp);
}
int qcrypto_cipher_gettag(QCryptoCipher *cipher,
uint8_t *tag, size_t len,
Error **errp)
{
const QCryptoCipherDriver *drv = cipher->driver;
if (!drv->cipher_gettag) {
error_setg(errp,
"The cipher mode does not produce an authentication tag");
return -1;
}
return drv->cipher_gettag(cipher, tag, len, errp);
}
void qcrypto_cipher_free(QCryptoCipher *cipher)
{
if (cipher) {

View file

@ -34,6 +34,14 @@ struct QCryptoCipherDriver {
const uint8_t *iv, size_t niv,
Error **errp);
int (*cipher_setaad)(QCryptoCipher *cipher,
const uint8_t *aad, size_t len,
Error **errp);
int (*cipher_gettag)(QCryptoCipher *cipher,
uint8_t *tag, size_t len,
Error **errp);
void (*cipher_free)(QCryptoCipher *cipher);
};

View file

@ -24,7 +24,8 @@
#include "crypto/hash.h"
#include "hashpriv.h"
#include <nettle/md5.h>
#include <nettle/sha.h>
#include <nettle/sha1.h>
#include <nettle/sha2.h>
#include <nettle/ripemd160.h>
#ifdef CONFIG_CRYPTO_SM3
#include <nettle/sm3.h>

View file

@ -38,7 +38,7 @@ if nettle.found()
endif
elif gcrypt.found()
crypto_ss.add(gcrypt, files('hash-gcrypt.c', 'hmac-gcrypt.c', 'pbkdf-gcrypt.c'))
elif gnutls.found()
elif gnutls_crypto.found()
crypto_ss.add(gnutls, files('hash-gnutls.c', 'hmac-gnutls.c', 'pbkdf-gnutls.c'))
else
crypto_ss.add(files('hash-glib.c', 'hmac-glib.c', 'pbkdf-stub.c'))

View file

@ -49,6 +49,20 @@ static const cs_opt_skipdata cap_skipdata_s390x = {
.callback = cap_skipdata_s390x_cb
};
/* Similarly for RISCV */
static size_t CAPSTONE_API
cap_skipdata_riscv_cb(const uint8_t *code, size_t code_size,
size_t offset, void *user_data)
{
/* See insn_len() from target/riscv/internals.h */
return (code[offset] & 3) == 3 ? 4 : 2;
}
static const cs_opt_skipdata cap_skipdata_riscv = {
.mnemonic = ".byte",
.callback = cap_skipdata_riscv_cb
};
/*
* Initialize the Capstone library.
*
@ -76,7 +90,12 @@ static cs_err cap_disas_start(disassemble_info *info, csh *handle)
cs_option(*handle, CS_OPT_SKIPDATA, CS_OPT_ON);
switch (info->cap_arch) {
case CS_ARCH_SYSZ:
case CS_ARCH_RISCV:
cs_option(*handle, CS_OPT_SKIPDATA_SETUP,
(uintptr_t)&cap_skipdata_riscv);
break;
case CS_ARCH_SYSTEMZ:
cs_option(*handle, CS_OPT_SKIPDATA_SETUP,
(uintptr_t)&cap_skipdata_s390x);
break;
@ -107,8 +126,9 @@ static void cap_dump_insn_units(disassemble_info *info, cs_insn *insn,
{
fprintf_function print = info->fprintf_func;
FILE *stream = info->stream;
int unit = MIN(info->cap_insn_unit, n - i);
switch (info->cap_insn_unit) {
switch (unit) {
case 4:
if (info->endian == BFD_ENDIAN_BIG) {
for (; i < n; i += 4) {
@ -140,6 +160,11 @@ static void cap_dump_insn_units(disassemble_info *info, cs_insn *insn,
}
break;
}
if (unit < info->cap_insn_unit) {
int width = (info->cap_insn_unit - unit) * 2;
print(stream, "%*s", width, "");
}
}
static void cap_dump_insn(disassemble_info *info, cs_insn *insn)

View file

@ -31,7 +31,6 @@
int print_insn_hexagon(bfd_vma memaddr, struct disassemble_info *info)
{
const HexagonCPUDef *hex_def = (const HexagonCPUDef *)info->target_info;
uint32_t words[PACKET_WORDS_MAX];
bool found_end = false;
GString *buf;
@ -58,8 +57,9 @@ int print_insn_hexagon(bfd_vma memaddr, struct disassemble_info *info)
return PACKET_WORDS_MAX * sizeof(uint32_t);
}
const HexagonCPUConfig *cfg = info->target_info;
buf = g_string_sized_new(PACKET_BUFFER_LEN);
len = disassemble_hexagon(words, i, memaddr, buf, hex_def);
len = disassemble_hexagon(words, i, memaddr, buf, cfg);
(*info->fprintf_func)(info->stream, "%s", buf->str);
g_string_free(buf, true);

913
disas/riscv-op.c.inc Normal file
View file

@ -0,0 +1,913 @@
OP(add, "add", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(add_uw, "add.uw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(addd, "addd", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(addi, "addi", rv_codec_i, rv_fmt_rd_rs1_imm, rvcp_addi)
OP(addid, "addid", rv_codec_i, rv_fmt_rd_rs1_imm)
OP(addiw, "addiw", rv_codec_i, rv_fmt_rd_rs1_imm, rvcp_addiw)
OP(addw, "addw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(aes32dsi, "aes32dsi", rv_codec_k_bs, rv_fmt_rs1_rs2_bs)
OP(aes32dsmi, "aes32dsmi", rv_codec_k_bs, rv_fmt_rs1_rs2_bs)
OP(aes32esi, "aes32esi", rv_codec_k_bs, rv_fmt_rs1_rs2_bs)
OP(aes32esmi, "aes32esmi", rv_codec_k_bs, rv_fmt_rs1_rs2_bs)
OP(aes64ds, "aes64ds", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(aes64dsm, "aes64dsm", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(aes64es, "aes64es", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(aes64esm, "aes64esm", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(aes64im, "aes64im", rv_codec_r, rv_fmt_rd_rs1)
OP(aes64ks1i, "aes64ks1i", rv_codec_k_rnum, rv_fmt_rd_rs1_rnum)
OP(aes64ks2, "aes64ks2", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(amoadd_b, "amoadd.b", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoadd_d, "amoadd.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoadd_h, "amoadd.h", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoadd_q, "amoadd.q", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoadd_w, "amoadd.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoand_b, "amoand.b", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoand_d, "amoand.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoand_h, "amoand.h", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoand_q, "amoand.q", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoand_w, "amoand.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amocas_b, "amocas.b", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amocas_d, "amocas.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amocas_h, "amocas.h", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amocas_q, "amocas.q", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amocas_w, "amocas.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomax_b, "amomax.b", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomax_d, "amomax.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomax_h, "amomax.h", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomax_q, "amomax.q", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomax_w, "amomax.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomaxu_b, "amomaxu.b", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomaxu_d, "amomaxu.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomaxu_h, "amomaxu.h", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomaxu_q, "amomaxu.q", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomaxu_w, "amomaxu.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomin_b, "amomin.b", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomin_d, "amomin.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomin_h, "amomin.h", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomin_q, "amomin.q", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amomin_w, "amomin.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amominu_b, "amominu.b", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amominu_d, "amominu.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amominu_h, "amominu.h", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amominu_q, "amominu.q", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amominu_w, "amominu.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoor_b, "amoor.b", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoor_d, "amoor.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoor_h, "amoor.h", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoor_q, "amoor.q", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoor_w, "amoor.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoswap_b, "amoswap.b", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoswap_d, "amoswap.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoswap_h, "amoswap.h", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoswap_q, "amoswap.q", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoswap_w, "amoswap.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoxor_b, "amoxor.b", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoxor_d, "amoxor.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoxor_h, "amoxor.h", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoxor_q, "amoxor.q", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(amoxor_w, "amoxor.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(and, "and", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(andi, "andi", rv_codec_i, rv_fmt_rd_rs1_imm)
OP(andn, "andn", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(auipc, "auipc", rv_codec_u, rv_fmt_rd_uoffset)
OP(bclr, "bclr", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(bclri, "bclri", rv_codec_i_sh7, rv_fmt_rd_rs1_imm)
OP(beq, "beq", rv_codec_sb, rv_fmt_rs1_rs2_offset, rvcp_beq)
OP(beqz, "beqz", rv_codec_illegal, rv_fmt_rs1_offset)
OP(bext, "bext", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(bexti, "bexti", rv_codec_i_sh7, rv_fmt_rd_rs1_imm)
OP(bge, "bge", rv_codec_sb, rv_fmt_rs1_rs2_offset, rvcp_bge)
OP(bgeu, "bgeu", rv_codec_sb, rv_fmt_rs1_rs2_offset)
OP(bgez, "bgez", rv_codec_illegal, rv_fmt_rs1_offset)
OP(bgtz, "bgtz", rv_codec_illegal, rv_fmt_rs2_offset)
OP(binv, "binv", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(binvi, "binvi", rv_codec_i_sh7, rv_fmt_rd_rs1_imm)
OP(blez, "blez", rv_codec_illegal, rv_fmt_rs2_offset)
OP(blt, "blt", rv_codec_sb, rv_fmt_rs1_rs2_offset, rvcp_blt)
OP(bltu, "bltu", rv_codec_sb, rv_fmt_rs1_rs2_offset)
OP(bltz, "bltz", rv_codec_illegal, rv_fmt_rs1_offset)
OP(bne, "bne", rv_codec_sb, rv_fmt_rs1_rs2_offset, rvcp_bne)
OP(bnez, "bnez", rv_codec_illegal, rv_fmt_rs1_offset)
OP(brev8, "brev8", rv_codec_r, rv_fmt_rd_rs1)
OP(bset, "bset", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(bseti, "bseti", rv_codec_i_sh7, rv_fmt_rd_rs1_imm)
OP(c_add, "c.add", rv_codec_cr, NULL, DECOMP(op_add))
OP(c_addi, "c.addi", rv_codec_ci, NULL, DECOMP(op_addi))
OP(c_addi16sp, "c.addi16sp", rv_codec_ci_16sp, NULL, DECOMP(op_addi))
OP(c_addi4spn, "c.addi4spn", rv_codec_ciw_4spn, NULL, DECOMP(op_addi))
OP(c_addiw, "c.addiw", rv_codec_ci, NULL, DECOMP(op_addiw))
OP(c_addw, "c.addw", rv_codec_cs, NULL, DECOMP(op_addw))
OP(c_and, "c.and", rv_codec_cs, NULL, DECOMP(op_and))
OP(c_andi, "c.andi", rv_codec_cb_imm, NULL, DECOMP(op_andi))
OP(c_beqz, "c.beqz", rv_codec_cb, NULL, DECOMP(op_beqz))
OP(c_bnez, "c.bnez", rv_codec_cb, NULL, DECOMP(op_bnez))
OP(c_ebreak, "c.ebreak", rv_codec_ci_none, NULL, DECOMP(op_ebreak))
OP(c_fld, "c.fld", rv_codec_cl_ld, NULL, DECOMP(op_fld))
OP(c_fldsp, "c.fldsp", rv_codec_ci_ldsp, NULL, DECOMP(op_fld))
OP(c_flw, "c.flw", rv_codec_cl_lw, NULL, DECOMP(op_flw))
OP(c_flwsp, "c.flwsp", rv_codec_ci_lwsp, NULL, DECOMP(op_flw))
OP(c_fsd, "c.fsd", rv_codec_cs_sd, NULL, DECOMP(op_fsd))
OP(c_fsdsp, "c.fsdsp", rv_codec_css_sdsp, NULL, DECOMP(op_fsd))
OP(c_fsw, "c.fsw", rv_codec_cs_sw, NULL, DECOMP(op_fsw))
OP(c_fswsp, "c.fswsp", rv_codec_css_swsp, NULL, DECOMP(op_fsw))
OP(c_j, "c.j", rv_codec_cj, NULL, DECOMP(op_j))
OP(c_jal, "c.jal", rv_codec_cj_jal, NULL, DECOMP(op_jal))
OP(c_jalr, "c.jalr", rv_codec_cr_jalr, NULL, DECOMP(op_jalr))
OP(c_jr, "c.jr", rv_codec_cr_jr, NULL, DECOMP(op_jr))
OP(c_lbu, "c.lbu", rv_codec_zcb_lb, rv_fmt_rs1_rs2_zce_ldst)
OP(c_ld, "c.ld", rv_codec_cl_ld, NULL, DECOMP(op_ld))
OP(c_ldsp, "c.ldsp", rv_codec_ci_ldsp, NULL, DECOMP(op_ld))
OP(c_lh, "c.lh", rv_codec_zcb_lh, rv_fmt_rs1_rs2_zce_ldst)
OP(c_lhu, "c.lhu", rv_codec_zcb_lh, rv_fmt_rs1_rs2_zce_ldst)
OP(c_li, "c.li", rv_codec_ci_li, NULL, DECOMP(op_addi))
OP(c_lq, "c.lq", rv_codec_cl_lq, NULL, DECOMP(op_lq))
OP(c_lqsp, "c.lqsp", rv_codec_ci_lqsp, NULL, DECOMP(op_lq))
OP(c_lui, "c.lui", rv_codec_ci_lui, NULL, DECOMP(op_lui))
OP(c_lw, "c.lw", rv_codec_cl_lw, NULL, DECOMP(op_lw))
OP(c_lwsp, "c.lwsp", rv_codec_ci_lwsp, NULL, DECOMP(op_lw))
OP(c_mop, "c.mop", rv_codec_cmop, rv_fmt_cmop)
OP(c_mul, "c.mul", rv_codec_zcb_mul, rv_fmt_rd_rs2)
OP(c_mv, "c.mv", rv_codec_cr_mv, NULL, DECOMP(op_mv))
OP(c_not, "c.not", rv_codec_zcb_ext, rv_fmt_rd)
OP(c_or, "c.or", rv_codec_cs, NULL, DECOMP(op_or))
OP(c_sb, "c.sb", rv_codec_zcb_lb, rv_fmt_rs1_rs2_zce_ldst)
OP(c_sd, "c.sd", rv_codec_cs_sd, NULL, DECOMP(op_sd))
OP(c_sdsp, "c.sdsp", rv_codec_css_sdsp, NULL, DECOMP(op_sd))
OP(c_sext_b, "c.sext.b", rv_codec_zcb_ext, rv_fmt_rd)
OP(c_sext_h, "c.sext.h", rv_codec_zcb_ext, rv_fmt_rd)
OP(c_sh, "c.sh", rv_codec_zcb_lh, rv_fmt_rs1_rs2_zce_ldst)
OP(c_slli, "c.slli", rv_codec_ci_sh6, NULL, DECOMP(op_slli))
OP(c_sq, "c.sq", rv_codec_cs_sq, NULL, DECOMP(op_sq))
OP(c_sqsp, "c.sqsp", rv_codec_css_sqsp, NULL, DECOMP(op_sq))
OP(c_srai, "c.srai", rv_codec_cb_sh6, NULL, DECOMP(op_srai))
OP(c_srli, "c.srli", rv_codec_cb_sh6, NULL, DECOMP(op_srli))
OP(c_sspopchk, "c.sspopchk", rv_codec_cmop_ss, NULL, DECOMP(op_sspopchk))
OP(c_sspush, "c.sspush", rv_codec_cmop_ss, NULL, DECOMP(op_sspush))
OP(c_sub, "c.sub", rv_codec_cs, NULL, DECOMP(op_sub))
OP(c_subw, "c.subw", rv_codec_cs, NULL, DECOMP(op_subw))
OP(c_sw, "c.sw", rv_codec_cs_sw, NULL, DECOMP(op_sw))
OP(c_swsp, "c.swsp", rv_codec_css_swsp, NULL, DECOMP(op_sw))
OP(c_xor, "c.xor", rv_codec_cs, NULL, DECOMP(op_xor))
OP(c_zext_b, "c.zext.b", rv_codec_zcb_ext, rv_fmt_rd)
OP(c_zext_h, "c.zext.h", rv_codec_zcb_ext, rv_fmt_rd)
OP(c_zext_w, "c.zext.w", rv_codec_zcb_ext, rv_fmt_rd)
OP(cbo_clean, "cbo.clean", rv_codec_r, rv_fmt_rs1)
OP(cbo_flush, "cbo.flush", rv_codec_r, rv_fmt_rs1)
OP(cbo_inval, "cbo.inval", rv_codec_r, rv_fmt_rs1)
OP(cbo_zero, "cbo.zero", rv_codec_r, rv_fmt_rs1)
OP(clmul, "clmul", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(clmulh, "clmulh", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(clmulr, "clmulr", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(clz, "clz", rv_codec_r, rv_fmt_rd_rs1)
OP(clzw, "clzw", rv_codec_r, rv_fmt_rd_rs1)
OP(cm_jalt, "cm.jalt", rv_codec_zcmt_jt, rv_fmt_zcmt_index)
OP(cm_jt, "cm.jt", rv_codec_zcmt_jt, rv_fmt_zcmt_index)
OP(cm_mva01s, "cm.mva01s", rv_codec_zcmp_cm_mv, rv_fmt_rd_rs2)
OP(cm_mvsa01, "cm.mvsa01", rv_codec_zcmp_cm_mv, rv_fmt_rd_rs2)
OP(cm_pop, "cm.pop", rv_codec_zcmp_cm_pushpop, rv_fmt_pop_rlist)
OP(cm_popret, "cm.popret", rv_codec_zcmp_cm_pushpop, rv_fmt_pop_rlist)
OP(cm_popretz, "cm.popretz", rv_codec_zcmp_cm_pushpop, rv_fmt_pop_rlist)
OP(cm_push, "cm.push", rv_codec_zcmp_cm_pushpop, rv_fmt_push_rlist)
OP(cpop, "cpop", rv_codec_r, rv_fmt_rd_rs1)
OP(cpopw, "cpopw", rv_codec_r, rv_fmt_rd_rs1)
OP(csrrc, "csrrc", rv_codec_i_csr, rv_fmt_rd_csr_rs1)
OP(csrrci, "csrrci", rv_codec_i_csr, rv_fmt_rd_csr_zimm)
OP(csrrs, "csrrs", rv_codec_i_csr, rv_fmt_rd_csr_rs1)
OP(csrrsi, "csrrsi", rv_codec_i_csr, rv_fmt_rd_csr_zimm)
OP(csrrw, "csrrw", rv_codec_i_csr, rv_fmt_rd_csr_rs1)
OP(csrrwi, "csrrwi", rv_codec_i_csr, rv_fmt_rd_csr_zimm)
OP(ctz, "ctz", rv_codec_r, rv_fmt_rd_rs1)
OP(ctzw, "ctzw", rv_codec_r, rv_fmt_rd_rs1)
OP(czero_eqz, "czero.eqz", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(czero_nez, "czero.nez", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(div, "div", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(divd, "divd", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(divu, "divu", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(divud, "divud", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(divuw, "divuw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(divw, "divw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(dret, "dret", rv_codec_none, rv_fmt_none)
OP(ebreak, "ebreak", rv_codec_none, rv_fmt_none)
OP(ecall, "ecall", rv_codec_none, rv_fmt_none)
OP(fabs_d, "fabs.d", rv_codec_illegal, rv_fmt_frd_frs1)
OP(fabs_q, "fabs.q", rv_codec_illegal, rv_fmt_frd_frs1)
OP(fabs_s, "fabs.s", rv_codec_illegal, rv_fmt_frd_frs1)
OP(fadd_d, "fadd.d", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fadd_q, "fadd.q", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fadd_s, "fadd.s", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fclass_d, "fclass.d", rv_codec_r, rv_fmt_rd_frs1)
OP(fclass_q, "fclass.q", rv_codec_r, rv_fmt_rd_frs1)
OP(fclass_s, "fclass.s", rv_codec_r, rv_fmt_rd_frs1)
OP(fcvt_bf16_s, "fcvt.bf16.s", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fcvt_d_l, "fcvt.d.l", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_d_lu, "fcvt.d.lu", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_d_q, "fcvt.d.q", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fcvt_d_s, "fcvt.d.s", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fcvt_d_w, "fcvt.d.w", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_d_wu, "fcvt.d.wu", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_l_d, "fcvt.l.d", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvt_l_q, "fcvt.l.q", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvt_l_s, "fcvt.l.s", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvt_lu_d, "fcvt.lu.d", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvt_lu_q, "fcvt.lu.q", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvt_lu_s, "fcvt.lu.s", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvt_q_d, "fcvt.q.d", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fcvt_q_l, "fcvt.q.l", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_q_lu, "fcvt.q.lu", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_q_s, "fcvt.q.s", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fcvt_q_w, "fcvt.q.w", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_q_wu, "fcvt.q.wu", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_s_bf16, "fcvt.s.bf16", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fcvt_s_d, "fcvt.s.d", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fcvt_s_l, "fcvt.s.l", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_s_lu, "fcvt.s.lu", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_s_q, "fcvt.s.q", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fcvt_s_w, "fcvt.s.w", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_s_wu, "fcvt.s.wu", rv_codec_r_m, rv_fmt_rm_frd_rs1)
OP(fcvt_w_d, "fcvt.w.d", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvt_w_q, "fcvt.w.q", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvt_w_s, "fcvt.w.s", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvt_wu_d, "fcvt.wu.d", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvt_wu_q, "fcvt.wu.q", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvt_wu_s, "fcvt.wu.s", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fcvtmod_w_d, "fcvtmod.w.d", rv_codec_r_m, rv_fmt_rm_rd_frs1)
OP(fdiv_d, "fdiv.d", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fdiv_q, "fdiv.q", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fdiv_s, "fdiv.s", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fence, "fence", rv_codec_r_f, rv_fmt_pred_succ)
OP(fence_i, "fence.i", rv_codec_none, rv_fmt_none)
OP(feq_d, "feq.d", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(feq_q, "feq.q", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(feq_s, "feq.s", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(fld, "fld", rv_codec_i, rv_fmt_frd_offset_rs1)
OP(fle_d, "fle.d", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(fle_q, "fle.q", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(fle_s, "fle.s", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(fleq_d, "fleq.d", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(fleq_h, "fleq.h", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(fleq_q, "fleq.q", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(fleq_s, "fleq.s", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(flh, "flh", rv_codec_i, rv_fmt_frd_offset_rs1)
OP(fli_d, "fli.d", rv_codec_fli, rv_fmt_fli)
OP(fli_h, "fli.h", rv_codec_fli, rv_fmt_fli)
OP(fli_q, "fli.q", rv_codec_fli, rv_fmt_fli)
OP(fli_s, "fli.s", rv_codec_fli, rv_fmt_fli)
OP(flq, "flq", rv_codec_i, rv_fmt_frd_offset_rs1)
OP(flt_d, "flt.d", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(flt_q, "flt.q", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(flt_s, "flt.s", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(fltq_d, "fltq.d", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(fltq_h, "fltq.h", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(fltq_q, "fltq.q", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(fltq_s, "fltq.s", rv_codec_r, rv_fmt_rd_frs1_frs2)
OP(flw, "flw", rv_codec_i, rv_fmt_frd_offset_rs1)
OP(fmadd_d, "fmadd.d", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(fmadd_q, "fmadd.q", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(fmadd_s, "fmadd.s", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(fmax_d, "fmax.d", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fmax_q, "fmax.q", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fmax_s, "fmax.s", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fmaxm_d, "fmaxm.d", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fmaxm_h, "fmaxm.h", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fmaxm_q, "fmaxm.q", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fmaxm_s, "fmaxm.s", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fmin_d, "fmin.d", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fmin_q, "fmin.q", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fmin_s, "fmin.s", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fminm_d, "fminm.d", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fminm_h, "fminm.h", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fminm_q, "fminm.q", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fminm_s, "fminm.s", rv_codec_r, rv_fmt_frd_frs1_frs2)
OP(fmsub_d, "fmsub.d", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(fmsub_q, "fmsub.q", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(fmsub_s, "fmsub.s", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(fmul_d, "fmul.d", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fmul_q, "fmul.q", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fmul_s, "fmul.s", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fmv_d, "fmv.d", rv_codec_illegal, rv_fmt_frd_frs1)
OP(fmv_d_x, "fmv.d.x", rv_codec_r, rv_fmt_frd_rs1)
OP(fmv_h_x, "fmv.h.x", rv_codec_r, rv_fmt_frd_rs1)
OP(fmv_q, "fmv.q", rv_codec_illegal, rv_fmt_frd_frs1)
OP(fmv_q_x, "fmv.q.x", rv_codec_r, rv_fmt_frd_rs1)
OP(fmv_s, "fmv.s", rv_codec_illegal, rv_fmt_frd_frs1)
OP(fmv_s_x, "fmv.s.x", rv_codec_r, rv_fmt_frd_rs1)
OP(fmv_x_d, "fmv.x.d", rv_codec_r, rv_fmt_rd_frs1)
OP(fmv_x_h, "fmv.x.h", rv_codec_r, rv_fmt_rd_frs1)
OP(fmv_x_q, "fmv.x.q", rv_codec_r, rv_fmt_rd_frs1)
OP(fmv_x_s, "fmv.x.s", rv_codec_r, rv_fmt_rd_frs1)
OP(fmvh_x_d, "fmvh.x.d", rv_codec_r, rv_fmt_rd_frs1)
OP(fmvh_x_q, "fmvh.x.q", rv_codec_r, rv_fmt_rd_frs1)
OP(fmvp_d_x, "fmvp.d.x", rv_codec_r, rv_fmt_frd_rs1_rs2)
OP(fmvp_q_x, "fmvp.q.x", rv_codec_r, rv_fmt_frd_rs1_rs2)
OP(fneg_d, "fneg.d", rv_codec_illegal, rv_fmt_frd_frs1)
OP(fneg_q, "fneg.q", rv_codec_illegal, rv_fmt_frd_frs1)
OP(fneg_s, "fneg.s", rv_codec_illegal, rv_fmt_frd_frs1)
OP(fnmadd_d, "fnmadd.d", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(fnmadd_q, "fnmadd.q", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(fnmadd_s, "fnmadd.s", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(fnmsub_d, "fnmsub.d", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(fnmsub_q, "fnmsub.q", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(fnmsub_s, "fnmsub.s", rv_codec_r4_m, rv_fmt_rm_frd_frs1_frs2_frs3)
OP(frcsr, "frcsr", rv_codec_i_csr, rv_fmt_rd)
OP(frflags, "frflags", rv_codec_i_csr, rv_fmt_rd)
OP(fround_d, "fround.d", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fround_h, "fround.h", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fround_q, "fround.q", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fround_s, "fround.s", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(froundnx_d, "froundnx.d", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(froundnx_h, "froundnx.h", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(froundnx_q, "froundnx.q", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(froundnx_s, "froundnx.s", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(frrm, "frrm", rv_codec_i_csr, rv_fmt_rd)
OP(fscsr, "fscsr", rv_codec_i_csr, rv_fmt_rd_rs1)
OP(fsd, "fsd", rv_codec_s, rv_fmt_frs2_offset_rs1)
OP(fsflags, "fsflags", rv_codec_i_csr, rv_fmt_rd_rs1)
OP(fsflagsi, "fsflagsi", rv_codec_i_csr, rv_fmt_rd_zimm)
OP(fsgnj_d, "fsgnj.d", rv_codec_r, rv_fmt_frd_frs1_frs2, rvcp_fsgnj_d)
OP(fsgnj_q, "fsgnj.q", rv_codec_r, rv_fmt_frd_frs1_frs2, rvcp_fsgnj_q)
OP(fsgnj_s, "fsgnj.s", rv_codec_r, rv_fmt_frd_frs1_frs2, rvcp_fsgnj_s)
OP(fsgnjn_d, "fsgnjn.d", rv_codec_r, rv_fmt_frd_frs1_frs2, rvcp_fsgnjn_d)
OP(fsgnjn_q, "fsgnjn.q", rv_codec_r, rv_fmt_frd_frs1_frs2, rvcp_fsgnjn_q)
OP(fsgnjn_s, "fsgnjn.s", rv_codec_r, rv_fmt_frd_frs1_frs2, rvcp_fsgnjn_s)
OP(fsgnjx_d, "fsgnjx.d", rv_codec_r, rv_fmt_frd_frs1_frs2, rvcp_fsgnjx_d)
OP(fsgnjx_q, "fsgnjx.q", rv_codec_r, rv_fmt_frd_frs1_frs2, rvcp_fsgnjx_q)
OP(fsgnjx_s, "fsgnjx.s", rv_codec_r, rv_fmt_frd_frs1_frs2, rvcp_fsgnjx_s)
OP(fsh, "fsh", rv_codec_s, rv_fmt_frs2_offset_rs1)
OP(fsq, "fsq", rv_codec_s, rv_fmt_frs2_offset_rs1)
OP(fsqrt_d, "fsqrt.d", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fsqrt_q, "fsqrt.q", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fsqrt_s, "fsqrt.s", rv_codec_r_m, rv_fmt_rm_frd_frs1)
OP(fsrm, "fsrm", rv_codec_i_csr, rv_fmt_rd_rs1)
OP(fsrmi, "fsrmi", rv_codec_i_csr, rv_fmt_rd_zimm)
OP(fsub_d, "fsub.d", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fsub_q, "fsub.q", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fsub_s, "fsub.s", rv_codec_r_m, rv_fmt_rm_frd_frs1_frs2)
OP(fsw, "fsw", rv_codec_s, rv_fmt_frs2_offset_rs1)
OP(hret, "hret", rv_codec_none, rv_fmt_none)
OP(illegal, "illegal", rv_codec_none, rv_fmt_none)
OP(j, "j", rv_codec_illegal, rv_fmt_offset)
OP(jal, "jal", rv_codec_uj, rv_fmt_rd_offset, rvcp_jal)
OP(jal_ra, "jal", rv_codec_illegal, rv_fmt_offset)
OP(jalr, "jalr", rv_codec_i, rv_fmt_rd_rs1_offset, rvcp_jalr)
OP(jalr_ra, "jalr", rv_codec_illegal, rv_fmt_rs1)
OP(jr, "jr", rv_codec_illegal, rv_fmt_rs1, rvcp_jr)
OP(lb, "lb", rv_codec_i, rv_fmt_rd_offset_rs1)
OP(lbu, "lbu", rv_codec_i, rv_fmt_rd_offset_rs1)
OP(ld, "ld", rv_codec_i, rv_fmt_rd_offset_rs1)
OP(ldu, "ldu", rv_codec_i, rv_fmt_rd_offset_rs1)
OP(lh, "lh", rv_codec_i, rv_fmt_rd_offset_rs1)
OP(lhu, "lhu", rv_codec_i, rv_fmt_rd_offset_rs1)
OP(lpad, "lpad", rv_codec_lp, rv_fmt_imm)
OP(lq, "lq", rv_codec_i, rv_fmt_rd_offset_rs1)
OP(lr_d, "lr.d", rv_codec_r_l, rv_fmt_aqrl_rd_rs1)
OP(lr_q, "lr.q", rv_codec_r_l, rv_fmt_aqrl_rd_rs1)
OP(lr_w, "lr.w", rv_codec_r_l, rv_fmt_aqrl_rd_rs1)
OP(lui, "lui", rv_codec_u, rv_fmt_rd_uimm)
OP(lw, "lw", rv_codec_i, rv_fmt_rd_offset_rs1)
OP(lwu, "lwu", rv_codec_i, rv_fmt_rd_offset_rs1)
OP(max, "max", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(maxu, "maxu", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(min, "min", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(minu, "minu", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(mnret, "mnret", rv_codec_none, rv_fmt_none)
OP(mop_r, "mop.r", rv_codec_mop_r, rv_fmt_mop_r)
OP(mop_rr, "mop.rr", rv_codec_mop_rr, rv_fmt_mop_rr)
OP(mret, "mret", rv_codec_none, rv_fmt_none)
OP(mul, "mul", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(muld, "muld", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(mulh, "mulh", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(mulhsu, "mulhsu", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(mulhu, "mulhu", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(mulw, "mulw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(mv, "mv", rv_codec_illegal, rv_fmt_rd_rs1, rvcp_mv)
OP(neg, "neg", rv_codec_illegal, rv_fmt_rd_rs2)
OP(negw, "negw", rv_codec_illegal, rv_fmt_rd_rs2)
OP(nop, "nop", rv_codec_illegal, rv_fmt_none)
OP(not, "not", rv_codec_illegal, rv_fmt_rd_rs1)
OP(or, "or", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(orc_b, "orc.b", rv_codec_r, rv_fmt_rd_rs1)
OP(ori, "ori", rv_codec_i, rv_fmt_rd_rs1_imm)
OP(orn, "orn", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(pack, "pack", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(packh, "packh", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(packw, "packw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(rdcycle, "rdcycle", rv_codec_i_csr, rv_fmt_rd)
OP(rdcycleh, "rdcycleh", rv_codec_i_csr, rv_fmt_rd)
OP(rdinstret, "rdinstret", rv_codec_i_csr, rv_fmt_rd)
OP(rdinstreth, "rdinstreth", rv_codec_i_csr, rv_fmt_rd)
OP(rdtime, "rdtime", rv_codec_i_csr, rv_fmt_rd)
OP(rdtimeh, "rdtimeh", rv_codec_i_csr, rv_fmt_rd)
OP(rem, "rem", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(remd, "remd", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(remu, "remu", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(remud, "remud", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(remuw, "remuw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(remw, "remw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(ret, "ret", rv_codec_illegal, rv_fmt_none)
OP(rev8, "rev8", rv_codec_r, rv_fmt_rd_rs1)
OP(rol, "rol", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(rolw, "rolw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(ror, "ror", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(rori, "rori", rv_codec_i_sh7, rv_fmt_rd_rs1_imm)
OP(roriw, "roriw", rv_codec_i_sh5, rv_fmt_rd_rs1_imm)
OP(rorw, "rorw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sb, "sb", rv_codec_s, rv_fmt_rs2_offset_rs1)
OP(sc_d, "sc.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(sc_q, "sc.q", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(sc_w, "sc.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(sd, "sd", rv_codec_s, rv_fmt_rs2_offset_rs1)
OP(seqz, "seqz", rv_codec_illegal, rv_fmt_rd_rs1)
OP(sext_b, "sext.b", rv_codec_r, rv_fmt_rd_rs1)
OP(sext_h, "sext.h", rv_codec_r, rv_fmt_rd_rs1)
OP(sext_w, "sext.w", rv_codec_illegal, rv_fmt_rd_rs1)
OP(sfence_vm, "sfence.vm", rv_codec_r, rv_fmt_rs1)
OP(sfence_vma, "sfence.vma", rv_codec_r, rv_fmt_rs1_rs2)
OP(sgtz, "sgtz", rv_codec_illegal, rv_fmt_rd_rs2)
OP(sh, "sh", rv_codec_s, rv_fmt_rs2_offset_rs1)
OP(sh1add, "sh1add", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sh1add_uw, "sh1add.uw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sh2add, "sh2add", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sh2add_uw, "sh2add.uw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sh3add, "sh3add", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sh3add_uw, "sh3add.uw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sha256sig0, "sha256sig0", rv_codec_r, rv_fmt_rd_rs1)
OP(sha256sig1, "sha256sig1", rv_codec_r, rv_fmt_rd_rs1)
OP(sha256sum0, "sha256sum0", rv_codec_r, rv_fmt_rd_rs1)
OP(sha256sum1, "sha256sum1", rv_codec_r, rv_fmt_rd_rs1)
OP(sha512sig0, "sha512sig0", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sha512sig0h, "sha512sig0h", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sha512sig0l, "sha512sig0l", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sha512sig1, "sha512sig1", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sha512sig1h, "sha512sig1h", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sha512sig1l, "sha512sig1l", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sha512sum0, "sha512sum0", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sha512sum0r, "sha512sum0r", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sha512sum1, "sha512sum1", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sha512sum1r, "sha512sum1r", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sll, "sll", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(slld, "slld", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(slli, "slli", rv_codec_i_sh7, rv_fmt_rd_rs1_imm)
OP(slli_uw, "slli.uw", rv_codec_i_sh6, rv_fmt_rd_rs1_imm)
OP(sllid, "sllid", rv_codec_i_sh6, rv_fmt_rd_rs1_imm)
OP(slliw, "slliw", rv_codec_i_sh5, rv_fmt_rd_rs1_imm)
OP(sllw, "sllw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(slt, "slt", rv_codec_r, rv_fmt_rd_rs1_rs2, rvcp_slt)
OP(slti, "slti", rv_codec_i, rv_fmt_rd_rs1_imm)
OP(sltiu, "sltiu", rv_codec_i, rv_fmt_rd_rs1_imm, rvcp_sltiu)
OP(sltu, "sltu", rv_codec_r, rv_fmt_rd_rs1_rs2, rvcp_sltu)
OP(sltz, "sltz", rv_codec_illegal, rv_fmt_rd_rs1)
OP(sm3p0, "sm3p0", rv_codec_r, rv_fmt_rd_rs1)
OP(sm3p1, "sm3p1", rv_codec_r, rv_fmt_rd_rs1)
OP(sm4ed, "sm4ed", rv_codec_k_bs, rv_fmt_rs1_rs2_bs)
OP(sm4ks, "sm4ks", rv_codec_k_bs, rv_fmt_rs1_rs2_bs)
OP(snez, "snez", rv_codec_illegal, rv_fmt_rd_rs2)
OP(sq, "sq", rv_codec_s, rv_fmt_rs2_offset_rs1)
OP(sra, "sra", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(srad, "srad", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(srai, "srai", rv_codec_i_sh7, rv_fmt_rd_rs1_imm)
OP(sraid, "sraid", rv_codec_i_sh6, rv_fmt_rd_rs1_imm)
OP(sraiw, "sraiw", rv_codec_i_sh5, rv_fmt_rd_rs1_imm)
OP(sraw, "sraw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(sret, "sret", rv_codec_none, rv_fmt_none)
OP(srl, "srl", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(srld, "srld", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(srli, "srli", rv_codec_i_sh7, rv_fmt_rd_rs1_imm)
OP(srlid, "srlid", rv_codec_i_sh6, rv_fmt_rd_rs1_imm)
OP(srliw, "srliw", rv_codec_i_sh5, rv_fmt_rd_rs1_imm)
OP(srlw, "srlw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(ssamoswap_d, "ssamoswap.d", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(ssamoswap_w, "ssamoswap.w", rv_codec_r_a, rv_fmt_aqrl_rd_rs2_rs1)
OP(sspopchk, "sspopchk", rv_codec_r, rv_fmt_rs1)
OP(sspush, "sspush", rv_codec_r, rv_fmt_rs2)
OP(ssrdp, "ssrdp", rv_codec_r, rv_fmt_rd)
OP(sub, "sub", rv_codec_r, rv_fmt_rd_rs1_rs2, rvcp_sub)
OP(subd, "subd", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(subw, "subw", rv_codec_r, rv_fmt_rd_rs1_rs2, rvcp_subw)
OP(sw, "sw", rv_codec_s, rv_fmt_rs2_offset_rs1)
OP(unzip, "unzip", rv_codec_r, rv_fmt_rd_rs1)
OP(uret, "uret", rv_codec_none, rv_fmt_none)
OP(vaadd_vv, "vaadd.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vaadd_vx, "vaadd.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vaaddu_vv, "vaaddu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vaaddu_vx, "vaaddu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vadc_vim, "vadc.vim", rv_codec_v_i, rv_fmt_vd_vs2_imm_vl)
OP(vadc_vvm, "vadc.vvm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vl)
OP(vadc_vxm, "vadc.vxm", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vl)
OP(vadd_vi, "vadd.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vadd_vv, "vadd.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vadd_vx, "vadd.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vaesdf_vs, "vaesdf.vs", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vaesdf_vv, "vaesdf.vv", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vaesdm_vs, "vaesdm.vs", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vaesdm_vv, "vaesdm.vv", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vaesef_vs, "vaesef.vs", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vaesef_vv, "vaesef.vv", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vaesem_vs, "vaesem.vs", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vaesem_vv, "vaesem.vv", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vaeskf1_vi, "vaeskf1.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm)
OP(vaeskf2_vi, "vaeskf2.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm)
OP(vaesz_vs, "vaesz.vs", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vand_vi, "vand.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vand_vv, "vand.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vand_vx, "vand.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vandn_vv, "vandn.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vandn_vx, "vandn.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vasub_vv, "vasub.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vasub_vx, "vasub.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vasubu_vv, "vasubu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vasubu_vx, "vasubu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vbrev8_v, "vbrev8.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vbrev_v, "vbrev.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vclmul_vv, "vclmul.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vclmul_vx, "vclmul.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vclmulh_vv, "vclmulh.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vclmulh_vx, "vclmulh.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vclz_v, "vclz.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vcompress_vm, "vcompress.vm", rv_codec_v_r, rv_fmt_vd_vs2_vs1)
OP(vcpop_m, "vcpop.m", rv_codec_v_r, rv_fmt_rd_vs2_vm)
OP(vcpop_v, "vcpop.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vctz_v, "vctz.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vdiv_vv, "vdiv.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vdiv_vx, "vdiv.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vdivu_vv, "vdivu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vdivu_vx, "vdivu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vfadd_vf, "vfadd.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfadd_vv, "vfadd.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfclass_v, "vfclass.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfcvt_f_x_v, "vfcvt.f.x.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfcvt_f_xu_v, "vfcvt.f.xu.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfcvt_rtz_x_f_v, "vfcvt.rtz.x.f.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfcvt_rtz_xu_f_v, "vfcvt.rtz.xu.f.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfcvt_x_f_v, "vfcvt.x.f.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfcvt_xu_f_v, "vfcvt.xu.f.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfdiv_vf, "vfdiv.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfdiv_vv, "vfdiv.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfirst_m, "vfirst.m", rv_codec_v_r, rv_fmt_rd_vs2_vm)
OP(vfmacc_vf, "vfmacc.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfmacc_vv, "vfmacc.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfmadd_vf, "vfmadd.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfmadd_vv, "vfmadd.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfmax_vf, "vfmax.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfmax_vv, "vfmax.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfmerge_vfm, "vfmerge.vfm", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vl)
OP(vfmin_vf, "vfmin.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfmin_vv, "vfmin.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfmsac_vf, "vfmsac.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfmsac_vv, "vfmsac.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfmsub_vf, "vfmsub.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfmsub_vv, "vfmsub.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfmul_vf, "vfmul.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfmul_vv, "vfmul.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfmv_f_s, "vfmv.f.s", rv_codec_v_r, rv_fmt_fd_vs2)
OP(vfmv_s_f, "vfmv.s.f", rv_codec_v_r, rv_fmt_vd_fs1)
OP(vfmv_v_f, "vfmv.v.f", rv_codec_v_r, rv_fmt_vd_fs1)
OP(vfncvt_f_f_w, "vfncvt.f.f.w", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfncvt_f_x_w, "vfncvt.f.x.w", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfncvt_f_xu_w, "vfncvt.f.xu.w", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfncvt_rod_f_f_w, "vfncvt.rod.f.f.w", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfncvt_rtz_x_f_w, "vfncvt.rtz.x.f.w", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfncvt_rtz_xu_f_w, "vfncvt.rtz.xu.f.w", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfncvt_x_f_w, "vfncvt.x.f.w", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfncvt_xu_f_w, "vfncvt.xu.f.w", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfncvtbf16_f_f_w, "vfncvtbf16.f.f.w", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfnmacc_vf, "vfnmacc.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfnmacc_vv, "vfnmacc.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfnmadd_vf, "vfnmadd.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfnmadd_vv, "vfnmadd.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfnmsac_vf, "vfnmsac.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfnmsac_vv, "vfnmsac.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfnmsub_vf, "vfnmsub.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfnmsub_vv, "vfnmsub.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfrdiv_vf, "vfrdiv.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfrec7_v, "vfrec7.v", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vfredmax_vs, "vfredmax.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfredmin_vs, "vfredmin.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfredosum_vs, "vfredosum.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfredusum_vs, "vfredusum.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfrsqrt7_v, "vfrsqrt7.v", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vfrsub_vf, "vfrsub.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfsgnj_vf, "vfsgnj.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfsgnj_vv, "vfsgnj.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfsgnjn_vf, "vfsgnjn.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfsgnjn_vv, "vfsgnjn.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfsgnjx_vf, "vfsgnjx.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfsgnjx_vv, "vfsgnjx.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfslide1down_vf, "vfslide1down.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfslide1up_vf, "vfslide1up.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfsqrt_v, "vfsqrt.v", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vfsub_vf, "vfsub.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfsub_vv, "vfsub.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfwadd_vf, "vfwadd.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfwadd_vv, "vfwadd.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfwadd_wf, "vfwadd.wf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfwadd_wv, "vfwadd.wv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfwcvt_f_f_v, "vfwcvt.f.f.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfwcvt_f_x_v, "vfwcvt.f.x.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfwcvt_f_xu_v, "vfwcvt.f.xu.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfwcvt_rtz_x_f_v, "vfwcvt.rtz.x.f.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfwcvt_rtz_xu_f_v, "vfwcvt.rtz.xu.f.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfwcvt_x_f_v, "vfwcvt.x.f.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfwcvt_xu_f_v, "vfwcvt.xu.f.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfwcvtbf16_f_f_v, "vfwcvtbf16.f.f.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vfwmacc_vf, "vfwmacc.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfwmacc_vv, "vfwmacc.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfwmaccbf16_vf, "vfwmaccbf16.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfwmaccbf16_vv, "vfwmaccbf16.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfwmsac_vf, "vfwmsac.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfwmsac_vv, "vfwmsac.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfwmul_vf, "vfwmul.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfwmul_vv, "vfwmul.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfwnmacc_vf, "vfwnmacc.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfwnmacc_vv, "vfwnmacc.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfwnmsac_vf, "vfwnmsac.vf", rv_codec_v_r, rv_fmt_vd_fs1_vs2_vm)
OP(vfwnmsac_vv, "vfwnmsac.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vfwredosum_vs, "vfwredosum.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfwredusum_vs, "vfwredusum.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfwsub_vf, "vfwsub.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfwsub_vv, "vfwsub.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vfwsub_wf, "vfwsub.wf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vfwsub_wv, "vfwsub.wv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vghsh_vv, "vghsh.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1)
OP(vgmul_vv, "vgmul.vv", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vid_v, "vid.v", rv_codec_v_r, rv_fmt_vd_vm)
OP(viota_m, "viota.m", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vl1re16_v, "vl1re16.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl1re32_v, "vl1re32.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl1re64_v, "vl1re64.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl1re8_v, "vl1re8.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl2re16_v, "vl2re16.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl2re32_v, "vl2re32.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl2re64_v, "vl2re64.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl2re8_v, "vl2re8.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl4re16_v, "vl4re16.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl4re32_v, "vl4re32.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl4re64_v, "vl4re64.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl4re8_v, "vl4re8.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl8re16_v, "vl8re16.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl8re32_v, "vl8re32.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl8re64_v, "vl8re64.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vl8re8_v, "vl8re8.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vle16_v, "vle16.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vle16ff_v, "vle16ff.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vle32_v, "vle32.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vle32ff_v, "vle32ff.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vle64_v, "vle64.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vle64ff_v, "vle64ff.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vle8_v, "vle8.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vle8ff_v, "vle8ff.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vlm_v, "vlm.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vloxei16_v, "vloxei16.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vloxei32_v, "vloxei32.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vloxei64_v, "vloxei64.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vloxei8_v, "vloxei8.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vlse16_v, "vlse16.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_rs2_vm)
OP(vlse32_v, "vlse32.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_rs2_vm)
OP(vlse64_v, "vlse64.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_rs2_vm)
OP(vlse8_v, "vlse8.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_rs2_vm)
OP(vluxei16_v, "vluxei16.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vluxei32_v, "vluxei32.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vluxei64_v, "vluxei64.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vluxei8_v, "vluxei8.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vmacc_vv, "vmacc.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vmacc_vx, "vmacc.vx", rv_codec_v_r, rv_fmt_vd_rs1_vs2_vm)
OP(vmadc_vim, "vmadc.vim", rv_codec_v_i, rv_fmt_vd_vs2_imm_vl)
OP(vmadc_vvm, "vmadc.vvm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vl)
OP(vmadc_vxm, "vmadc.vxm", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vl)
OP(vmadd_vv, "vmadd.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vmadd_vx, "vmadd.vx", rv_codec_v_r, rv_fmt_vd_rs1_vs2_vm)
OP(vmand_mm, "vmand.mm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmandn_mm, "vmandn.mm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmax_vv, "vmax.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmax_vx, "vmax.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmaxu_vv, "vmaxu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmaxu_vx, "vmaxu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmerge_vim, "vmerge.vim", rv_codec_v_i, rv_fmt_vd_vs2_imm_vl)
OP(vmerge_vvm, "vmerge.vvm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vl)
OP(vmerge_vxm, "vmerge.vxm", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vl)
OP(vmfeq_vf, "vmfeq.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vmfeq_vv, "vmfeq.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmfge_vf, "vmfge.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vmfgt_vf, "vmfgt.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vmfle_vf, "vmfle.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vmfle_vv, "vmfle.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmflt_vf, "vmflt.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vmflt_vv, "vmflt.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmfne_vf, "vmfne.vf", rv_codec_v_r, rv_fmt_vd_vs2_fs1_vm)
OP(vmfne_vv, "vmfne.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmin_vv, "vmin.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmin_vx, "vmin.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vminu_vv, "vminu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vminu_vx, "vminu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmnand_mm, "vmnand.mm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmnor_mm, "vmnor.mm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmor_mm, "vmor.mm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmorn_mm, "vmorn.mm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmsbc_vvm, "vmsbc.vvm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vl)
OP(vmsbc_vxm, "vmsbc.vxm", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vl)
OP(vmsbf_m, "vmsbf.m", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vmseq_vi, "vmseq.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vmseq_vv, "vmseq.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmseq_vx, "vmseq.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmsgt_vi, "vmsgt.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vmsgt_vx, "vmsgt.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmsgtu_vi, "vmsgtu.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vmsgtu_vx, "vmsgtu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmsif_m, "vmsif.m", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vmsle_vi, "vmsle.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vmsle_vv, "vmsle.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmsle_vx, "vmsle.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmsleu_vi, "vmsleu.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vmsleu_vv, "vmsleu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmsleu_vx, "vmsleu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmslt_vv, "vmslt.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmslt_vx, "vmslt.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmsltu_vv, "vmsltu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmsltu_vx, "vmsltu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmsne_vi, "vmsne.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vmsne_vv, "vmsne.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmsne_vx, "vmsne.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmsof_m, "vmsof.m", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vmul_vv, "vmul.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmul_vx, "vmul.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmulh_vv, "vmulh.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmulh_vx, "vmulh.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmulhsu_vv, "vmulhsu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmulhsu_vx, "vmulhsu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmulhu_vv, "vmulhu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmulhu_vx, "vmulhu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vmv1r_v, "vmv1r.v", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vmv2r_v, "vmv2r.v", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vmv4r_v, "vmv4r.v", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vmv8r_v, "vmv8r.v", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vmv_s_x, "vmv.s.x", rv_codec_v_r, rv_fmt_vd_rs1)
OP(vmv_v_i, "vmv.v.i", rv_codec_v_i, rv_fmt_vd_imm)
OP(vmv_v_v, "vmv.v.v", rv_codec_v_r, rv_fmt_vd_vs1)
OP(vmv_v_x, "vmv.v.x", rv_codec_v_r, rv_fmt_vd_rs1)
OP(vmv_x_s, "vmv.x.s", rv_codec_v_r, rv_fmt_rd_vs2)
OP(vmxnor_mm, "vmxnor.mm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vmxor_mm, "vmxor.mm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vnclip_wi, "vnclip.wi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vnclip_wv, "vnclip.wv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vnclip_wx, "vnclip.wx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vnclipu_wi, "vnclipu.wi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vnclipu_wv, "vnclipu.wv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vnclipu_wx, "vnclipu.wx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vnmsac_vv, "vnmsac.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vnmsac_vx, "vnmsac.vx", rv_codec_v_r, rv_fmt_vd_rs1_vs2_vm)
OP(vnmsub_vv, "vnmsub.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vnmsub_vx, "vnmsub.vx", rv_codec_v_r, rv_fmt_vd_rs1_vs2_vm)
OP(vnsra_wi, "vnsra.wi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vnsra_wv, "vnsra.wv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vnsra_wx, "vnsra.wx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vnsrl_wi, "vnsrl.wi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vnsrl_wv, "vnsrl.wv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vnsrl_wx, "vnsrl.wx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vor_vi, "vor.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vor_vv, "vor.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vor_vx, "vor.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vredand_vs, "vredand.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vredmax_vs, "vredmax.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vredmaxu_vs, "vredmaxu.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vredmin_vs, "vredmin.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vredminu_vs, "vredminu.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vredor_vs, "vredor.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vredsum_vs, "vredsum.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vredxor_vs, "vredxor.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vrem_vv, "vrem.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vrem_vx, "vrem.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vremu_vv, "vremu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vremu_vx, "vremu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vrev8_v, "vrev8.v", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vrgather_vi, "vrgather.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vrgather_vv, "vrgather.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vrgather_vx, "vrgather.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vrgatherei16_vv, "vrgatherei16.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vrol_vv, "vrol.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vrol_vx, "vrol.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vror_vi, "vror.vi", rv_codec_vror_vi, rv_fmt_vd_vs2_uimm_vm)
OP(vror_vv, "vror.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vror_vx, "vror.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vrsub_vi, "vrsub.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vrsub_vx, "vrsub.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vs1r_v, "vs1r.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vs2r_v, "vs2r.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vs4r_v, "vs4r.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vs8r_v, "vs8r.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vsadd_vi, "vsadd.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vsadd_vv, "vsadd.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vsadd_vx, "vsadd.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vsaddu_vi, "vsaddu.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vsaddu_vv, "vsaddu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vsaddu_vx, "vsaddu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vsbc_vvm, "vsbc.vvm", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vl)
OP(vsbc_vxm, "vsbc.vxm", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vl)
OP(vse16_v, "vse16.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vse32_v, "vse32.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vse64_v, "vse64.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vse8_v, "vse8.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vsetivli, "vsetivli", rv_codec_vsetivli, rv_fmt_vsetivli)
OP(vsetvl, "vsetvl", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(vsetvli, "vsetvli", rv_codec_vsetvli, rv_fmt_vsetvli)
OP(vsext_vf2, "vsext.vf2", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vsext_vf4, "vsext.vf4", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vsext_vf8, "vsext.vf8", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vsha2ch_vv, "vsha2ch.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1)
OP(vsha2cl_vv, "vsha2cl.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1)
OP(vsha2ms_vv, "vsha2ms.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1)
OP(vslide1down_vx, "vslide1down.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vslide1up_vx, "vslide1up.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vslidedown_vi, "vslidedown.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vslidedown_vx, "vslidedown.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vslideup_vi, "vslideup.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vslideup_vx, "vslideup.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vsll_vi, "vsll.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vsll_vv, "vsll.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vsll_vx, "vsll.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vsm3c_vi, "vsm3c.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm)
OP(vsm3me_vv, "vsm3me.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1)
OP(vsm4k_vi, "vsm4k.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm)
OP(vsm4r_vs, "vsm4r.vs", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vsm4r_vv, "vsm4r.vv", rv_codec_v_r, rv_fmt_vd_vs2)
OP(vsm_v, "vsm.v", rv_codec_v_ldst, rv_fmt_ldst_vd_rs1_vm)
OP(vsmul_vv, "vsmul.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vsmul_vx, "vsmul.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vsoxei16_v, "vsoxei16.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vsoxei32_v, "vsoxei32.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vsoxei64_v, "vsoxei64.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vsoxei8_v, "vsoxei8.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vsra_vi, "vsra.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vsra_vv, "vsra.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vsra_vx, "vsra.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vsrl_vi, "vsrl.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vsrl_vv, "vsrl.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vsrl_vx, "vsrl.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vsse16_v, "vsse16.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_rs2_vm)
OP(vsse32_v, "vsse32.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_rs2_vm)
OP(vsse64_v, "vsse64.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_rs2_vm)
OP(vsse8_v, "vsse8.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_rs2_vm)
OP(vssra_vi, "vssra.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vssra_vv, "vssra.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vssra_vx, "vssra.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vssrl_vi, "vssrl.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vssrl_vv, "vssrl.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vssrl_vx, "vssrl.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vssub_vv, "vssub.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vssub_vx, "vssub.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vssubu_vv, "vssubu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vssubu_vx, "vssubu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vsub_vv, "vsub.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vsub_vx, "vsub.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vsuxei16_v, "vsuxei16.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vsuxei32_v, "vsuxei32.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vsuxei64_v, "vsuxei64.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vsuxei8_v, "vsuxei8.v", rv_codec_v_r, rv_fmt_ldst_vd_rs1_vs2_vm)
OP(vwadd_vv, "vwadd.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwadd_vx, "vwadd.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vwadd_wv, "vwadd.wv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwadd_wx, "vwadd.wx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vwaddu_vv, "vwaddu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwaddu_vx, "vwaddu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vwaddu_wv, "vwaddu.wv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwaddu_wx, "vwaddu.wx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vwmacc_vv, "vwmacc.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vwmacc_vx, "vwmacc.vx", rv_codec_v_r, rv_fmt_vd_rs1_vs2_vm)
OP(vwmaccsu_vv, "vwmaccsu.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vwmaccsu_vx, "vwmaccsu.vx", rv_codec_v_r, rv_fmt_vd_rs1_vs2_vm)
OP(vwmaccu_vv, "vwmaccu.vv", rv_codec_v_r, rv_fmt_vd_vs1_vs2_vm)
OP(vwmaccu_vx, "vwmaccu.vx", rv_codec_v_r, rv_fmt_vd_rs1_vs2_vm)
OP(vwmaccus_vx, "vwmaccus.vx", rv_codec_v_r, rv_fmt_vd_rs1_vs2_vm)
OP(vwmul_vv, "vwmul.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwmul_vx, "vwmul.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vwmulsu_vv, "vwmulsu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwmulsu_vx, "vwmulsu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vwmulu_vv, "vwmulu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwmulu_vx, "vwmulu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vwredsum_vs, "vwredsum.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwredsumu_vs, "vwredsumu.vs", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwsll_vi, "vwsll.vi", rv_codec_v_i_u, rv_fmt_vd_vs2_uimm_vm)
OP(vwsll_vv, "vwsll.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwsll_vx, "vwsll.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vwsub_vv, "vwsub.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwsub_vx, "vwsub.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vwsub_wv, "vwsub.wv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwsub_wx, "vwsub.wx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vwsubu_vv, "vwsubu.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwsubu_vx, "vwsubu.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vwsubu_wv, "vwsubu.wv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vwsubu_wx, "vwsubu.wx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vxor_vi, "vxor.vi", rv_codec_v_i, rv_fmt_vd_vs2_imm_vm)
OP(vxor_vv, "vxor.vv", rv_codec_v_r, rv_fmt_vd_vs2_vs1_vm)
OP(vxor_vx, "vxor.vx", rv_codec_v_r, rv_fmt_vd_vs2_rs1_vm)
OP(vzext_vf2, "vzext.vf2", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vzext_vf4, "vzext.vf4", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(vzext_vf8, "vzext.vf8", rv_codec_v_r, rv_fmt_vd_vs2_vm)
OP(wfi, "wfi", rv_codec_none, rv_fmt_none)
OP(wrs_nto, "wrs.nto", rv_codec_none, rv_fmt_none)
OP(wrs_sto, "wrs.sto", rv_codec_none, rv_fmt_none)
OP(xnor, "xnor", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(xor, "xor", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(xori, "xori", rv_codec_i, rv_fmt_rd_rs1_imm, rvcp_xori)
OP(xperm4, "xperm4", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(xperm8, "xperm8", rv_codec_r, rv_fmt_rd_rs1)
OP(zext_h, "zext.h", rv_codec_r, rv_fmt_rd_rs1)
OP(zip, "zip", rv_codec_r, rv_fmt_rd_rs1)

View file

@ -0,0 +1,8 @@
OP(crc32_b, "crc32.b", rv_codec_r, rv_fmt_rd_rs1)
OP(crc32_h, "crc32.h", rv_codec_r, rv_fmt_rd_rs1)
OP(crc32_w, "crc32.w", rv_codec_r, rv_fmt_rd_rs1)
OP(crc32_d, "crc32.d", rv_codec_r, rv_fmt_rd_rs1)
OP(crc32c_b, "crc32c.b", rv_codec_r, rv_fmt_rd_rs1)
OP(crc32c_h, "crc32c.h", rv_codec_r, rv_fmt_rd_rs1)
OP(crc32c_w, "crc32c.w", rv_codec_r, rv_fmt_rd_rs1)
OP(crc32c_d, "crc32c.d", rv_codec_r, rv_fmt_rd_rs1)

View file

@ -8,38 +8,16 @@
*/
#include "qemu/osdep.h"
#include "disas/riscv.h"
#include "disas/riscv-xlrbr.h"
typedef enum {
/* 0 is reserved for rv_op_illegal. */
rv_op_crc32_b = 1,
rv_op_crc32_h = 2,
rv_op_crc32_w = 3,
rv_op_crc32_d = 4,
rv_op_crc32c_b = 5,
rv_op_crc32c_h = 6,
rv_op_crc32c_w = 7,
rv_op_crc32c_d = 8,
} rv_xlrbr_op;
#define OP(N, ...) static const rv_opcode_data op_##N = { __VA_ARGS__ };
#include "riscv-xlrbr-op.c.inc"
#undef OP
const rv_opcode_data rv_xlrbr_opcode_data[] = {
{ "illegal", rv_codec_illegal, rv_fmt_none, NULL, 0, 0, 0 },
{ "crc32.b", rv_codec_r, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
{ "crc32.h", rv_codec_r, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
{ "crc32.w", rv_codec_r, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
{ "crc32.d", rv_codec_r, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
{ "crc32c.b", rv_codec_r, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
{ "crc32c.h", rv_codec_r, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
{ "crc32c.w", rv_codec_r, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
{ "crc32c.d", rv_codec_r, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
};
void decode_xlrbr(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xlrbr(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch ((inst >> 0) & 0b1111111) {
case 0b0010011:
@ -47,33 +25,26 @@ void decode_xlrbr(rv_decode *dec, rv_isa isa)
case 0b001:
switch ((inst >> 20 & 0b111111111111)) {
case 0b011000010000:
op = rv_op_crc32_b;
break;
return &op_crc32_b;
case 0b011000010001:
op = rv_op_crc32_h;
break;
return &op_crc32_h;
case 0b011000010010:
op = rv_op_crc32_w;
break;
return &op_crc32_w;
case 0b011000010011:
op = rv_op_crc32_d;
break;
return &op_crc32_d;
case 0b011000011000:
op = rv_op_crc32c_b;
break;
return &op_crc32c_b;
case 0b011000011001:
op = rv_op_crc32c_h;
break;
return &op_crc32c_h;
case 0b011000011010:
op = rv_op_crc32c_w;
break;
return &op_crc32c_w;
case 0b011000011011:
op = rv_op_crc32c_d;
break;
return &op_crc32c_d;
}
break;
}
break;
}
dec->op = op;
return NULL;
}

View file

@ -12,8 +12,6 @@
#include "disas/riscv.h"
extern const rv_opcode_data rv_xlrbr_opcode_data[];
void decode_xlrbr(rv_decode *, rv_isa);
const rv_opcode_data *decode_xlrbr(rv_decode *, rv_isa);
#endif /* DISAS_RISCV_XLRBR_H */

125
disas/riscv-xthead-op.c.inc Normal file
View file

@ -0,0 +1,125 @@
/* XTheadBa */
OP(th_addsl, "th.addsl", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
/* XTheadBb */
OP(th_srri, "th.srri", rv_codec_r2_imm6, rv_fmt_rd_rs1_imm)
OP(th_srriw, "th.srriw", rv_codec_r2_imm5, rv_fmt_rd_rs1_imm)
OP(th_ext, "th.ext", rv_codec_r2_immhl, rv_fmt_rd_rs1_immh_imml)
OP(th_extu, "th.extu", rv_codec_r2_immhl, rv_fmt_rd_rs1_immh_imml)
OP(th_ff0, "th.ff0", rv_codec_r2, rv_fmt_rd_rs1)
OP(th_ff1, "th.ff1", rv_codec_r2, rv_fmt_rd_rs1)
OP(th_rev, "th.rev", rv_codec_r2, rv_fmt_rd_rs1)
OP(th_revw, "th.revw", rv_codec_r2, rv_fmt_rd_rs1)
OP(th_tstnbz, "th.tstnbz", rv_codec_r2, rv_fmt_rd_rs1)
/* XTheadBs */
OP(th_tst, "th.tst", rv_codec_r2_imm6, rv_fmt_rd_rs1_imm)
/* XTheadCmo */
OP(th_dcache_call, "th.dcache.call", rv_codec_none, rv_fmt_none)
OP(th_dcache_ciall, "th.dcache.ciall", rv_codec_none, rv_fmt_none)
OP(th_dcache_iall, "th.dcache.iall", rv_codec_none, rv_fmt_none)
OP(th_dcache_cpa, "th.dcache.cpa", rv_codec_r, rv_fmt_rs1)
OP(th_dcache_cipa, "th.dcache.cipa", rv_codec_r, rv_fmt_rs1)
OP(th_dcache_ipa, "th.dcache.ipa", rv_codec_r, rv_fmt_rs1)
OP(th_dcache_cva, "th.dcache.cva", rv_codec_r, rv_fmt_rs1)
OP(th_dcache_civa, "th.dcache.civa", rv_codec_r, rv_fmt_rs1)
OP(th_dcache_iva, "th.dcache.iva", rv_codec_r, rv_fmt_rs1)
OP(th_dcache_csw, "th.dcache.csw", rv_codec_r, rv_fmt_rs1)
OP(th_dcache_cisw, "th.dcache.cisw", rv_codec_r, rv_fmt_rs1)
OP(th_dcache_isw, "th.dcache.isw", rv_codec_r, rv_fmt_rs1)
OP(th_dcache_cpal1, "th.dcache.cpal1", rv_codec_r, rv_fmt_rs1)
OP(th_dcache_cval1, "th.dcache.cval1", rv_codec_r, rv_fmt_rs1)
OP(th_icache_iall, "th.icache.iall", rv_codec_none, rv_fmt_none)
OP(th_icache_ialls, "th.icache.ialls", rv_codec_none, rv_fmt_none)
OP(th_icache_ipa, "th.icache.ipa", rv_codec_r, rv_fmt_rs1)
OP(th_icache_iva, "th.icache.iva", rv_codec_r, rv_fmt_rs1)
OP(th_l2cache_call, "th.l2cache.call", rv_codec_none, rv_fmt_none)
OP(th_l2cache_ciall, "th.l2cache.ciall", rv_codec_none, rv_fmt_none)
OP(th_l2cache_iall, "th.l2cache.iall", rv_codec_none, rv_fmt_none)
/* XTheadCondMov */
OP(th_mveqz, "th.mveqz", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(th_mvnez, "th.mvnez", rv_codec_r, rv_fmt_rd_rs1_rs2)
/* XTheadFMemIdx */
OP(th_flrd, "th.flrd", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm)
OP(th_flrw, "th.flrw", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm)
OP(th_flurd, "th.flurd", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm)
OP(th_flurw, "th.flurw", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm)
OP(th_fsrd, "th.fsrd", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm)
OP(th_fsrw, "th.fsrw", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm)
OP(th_fsurd, "th.fsurd", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm)
OP(th_fsurw, "th.fsurw", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm)
/* XTheadFmv */
OP(th_fmv_hw_x, "th.fmv.hw.x", rv_codec_r, rv_fmt_rd_frs1)
OP(th_fmv_x_hw, "th.fmv.x.hw", rv_codec_r, rv_fmt_rd_frs1)
/* XTheadMac */
OP(th_mula, "th.mula", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(th_mulaw, "th.mulaw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(th_mulah, "th.mulah", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(th_muls, "th.muls", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(th_mulsw, "th.mulsw", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(th_mulsh, "th.mulsh", rv_codec_r, rv_fmt_rd_rs1_rs2)
/* XTheadMemIdx */
OP(th_lbia, "th.lbia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lbib, "th.lbib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lbuia, "th.lbuia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lbuib, "th.lbuib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lhia, "th.lhia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lhib, "th.lhib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lhuia, "th.lhuia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lhuib, "th.lhuib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lwia, "th.lwia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lwib, "th.lwib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lwuia, "th.lwuia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lwuib, "th.lwuib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_ldia, "th.ldia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_ldib, "th.ldib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_sbia, "th.sbia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_sbib, "th.sbib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_shia, "th.shia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_shib, "th.shib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_swia, "th.swia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_swib, "th.swib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_sdia, "th.sdia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_sdib, "th.sdib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr)
OP(th_lrb, "th.lrb", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lrbu, "th.lrbu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lrh, "th.lrh", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lrhu, "th.lrhu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lrw, "th.lrw", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lrwu, "th.lrwu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lrd, "th.lrd", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_srb, "th.srb", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_srh, "th.srh", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_srw, "th.srw", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_srd, "th.srd", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lurb, "th.lurb", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lurbu, "th.lurbu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lurh, "th.lurh", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lurhu, "th.lurhu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lurw, "th.lurw", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lurwu, "th.lurwu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_lurd, "th.lurd", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_surb, "th.surb", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_surh, "th.surh", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_surw, "th.surw", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
OP(th_surd, "th.surd", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm)
/* XTheadMemPair */
OP(th_ldd, "th.ldd", rv_codec_r_imm2, rv_fmt_rd2_imm)
OP(th_lwd, "th.lwd", rv_codec_r_imm2, rv_fmt_rd2_imm)
OP(th_lwud, "th.lwud", rv_codec_r_imm2, rv_fmt_rd2_imm)
OP(th_sdd, "th.sdd", rv_codec_r_imm2, rv_fmt_rd2_imm)
OP(th_swd, "th.swd", rv_codec_r_imm2, rv_fmt_rd2_imm)
/* XTheadSync */
OP(th_sfence_vmas, "th.sfence.vmas", rv_codec_r, rv_fmt_rs1_rs2)
OP(th_sync, "th.sync", rv_codec_none, rv_fmt_none)
OP(th_sync_i, "th.sync.i", rv_codec_none, rv_fmt_none)
OP(th_sync_is, "th.sync.is", rv_codec_none, rv_fmt_none)
OP(th_sync_s, "th.sync.s", rv_codec_none, rv_fmt_none)

View file

@ -8,248 +8,13 @@
#include "disas/riscv.h"
#include "disas/riscv-xthead.h"
typedef enum {
/* 0 is reserved for rv_op_illegal. */
/* XTheadBa */
rv_op_th_addsl = 1,
/* XTheadBb */
rv_op_th_srri,
rv_op_th_srriw,
rv_op_th_ext,
rv_op_th_extu,
rv_op_th_ff0,
rv_op_th_ff1,
rv_op_th_rev,
rv_op_th_revw,
rv_op_th_tstnbz,
/* XTheadBs */
rv_op_th_tst,
/* XTheadCmo */
rv_op_th_dcache_call,
rv_op_th_dcache_ciall,
rv_op_th_dcache_iall,
rv_op_th_dcache_cpa,
rv_op_th_dcache_cipa,
rv_op_th_dcache_ipa,
rv_op_th_dcache_cva,
rv_op_th_dcache_civa,
rv_op_th_dcache_iva,
rv_op_th_dcache_csw,
rv_op_th_dcache_cisw,
rv_op_th_dcache_isw,
rv_op_th_dcache_cpal1,
rv_op_th_dcache_cval1,
rv_op_th_icache_iall,
rv_op_th_icache_ialls,
rv_op_th_icache_ipa,
rv_op_th_icache_iva,
rv_op_th_l2cache_call,
rv_op_th_l2cache_ciall,
rv_op_th_l2cache_iall,
/* XTheadCondMov */
rv_op_th_mveqz,
rv_op_th_mvnez,
/* XTheadFMemIdx */
rv_op_th_flrd,
rv_op_th_flrw,
rv_op_th_flurd,
rv_op_th_flurw,
rv_op_th_fsrd,
rv_op_th_fsrw,
rv_op_th_fsurd,
rv_op_th_fsurw,
/* XTheadFmv */
rv_op_th_fmv_hw_x,
rv_op_th_fmv_x_hw,
/* XTheadMac */
rv_op_th_mula,
rv_op_th_mulah,
rv_op_th_mulaw,
rv_op_th_muls,
rv_op_th_mulsw,
rv_op_th_mulsh,
/* XTheadMemIdx */
rv_op_th_lbia,
rv_op_th_lbib,
rv_op_th_lbuia,
rv_op_th_lbuib,
rv_op_th_lhia,
rv_op_th_lhib,
rv_op_th_lhuia,
rv_op_th_lhuib,
rv_op_th_lwia,
rv_op_th_lwib,
rv_op_th_lwuia,
rv_op_th_lwuib,
rv_op_th_ldia,
rv_op_th_ldib,
rv_op_th_sbia,
rv_op_th_sbib,
rv_op_th_shia,
rv_op_th_shib,
rv_op_th_swia,
rv_op_th_swib,
rv_op_th_sdia,
rv_op_th_sdib,
rv_op_th_lrb,
rv_op_th_lrbu,
rv_op_th_lrh,
rv_op_th_lrhu,
rv_op_th_lrw,
rv_op_th_lrwu,
rv_op_th_lrd,
rv_op_th_srb,
rv_op_th_srh,
rv_op_th_srw,
rv_op_th_srd,
rv_op_th_lurb,
rv_op_th_lurbu,
rv_op_th_lurh,
rv_op_th_lurhu,
rv_op_th_lurw,
rv_op_th_lurwu,
rv_op_th_lurd,
rv_op_th_surb,
rv_op_th_surh,
rv_op_th_surw,
rv_op_th_surd,
/* XTheadMemPair */
rv_op_th_ldd,
rv_op_th_lwd,
rv_op_th_lwud,
rv_op_th_sdd,
rv_op_th_swd,
/* XTheadSync */
rv_op_th_sfence_vmas,
rv_op_th_sync,
rv_op_th_sync_i,
rv_op_th_sync_is,
rv_op_th_sync_s,
} rv_xthead_op;
#define OP(N, ...) static const rv_opcode_data op_##N = { __VA_ARGS__ };
#include "riscv-xthead-op.c.inc"
#undef OP
const rv_opcode_data xthead_opcode_data[] = {
{ "th.illegal", rv_codec_illegal, rv_fmt_none, NULL, 0, 0, 0 },
/* XTheadBa */
{ "th.addsl", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
/* XTheadBb */
{ "th.srri", rv_codec_r2_imm6, rv_fmt_rd_rs1_imm, NULL, 0, 0, 0 },
{ "th.srriw", rv_codec_r2_imm5, rv_fmt_rd_rs1_imm, NULL, 0, 0, 0 },
{ "th.ext", rv_codec_r2_immhl, rv_fmt_rd_rs1_immh_imml, NULL, 0, 0, 0 },
{ "th.extu", rv_codec_r2_immhl, rv_fmt_rd_rs1_immh_imml, NULL, 0, 0, 0 },
{ "th.ff0", rv_codec_r2, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
{ "th.ff1", rv_codec_r2, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
{ "th.rev", rv_codec_r2, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
{ "th.revw", rv_codec_r2, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
{ "th.tstnbz", rv_codec_r2, rv_fmt_rd_rs1, NULL, 0, 0, 0 },
/* XTheadBs */
{ "th.tst", rv_codec_r2_imm6, rv_fmt_rd_rs1_imm, NULL, 0, 0, 0 },
/* XTheadCmo */
{ "th.dcache.call", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
{ "th.dcache.ciall", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
{ "th.dcache.iall", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
{ "th.dcache.cpa", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.dcache.cipa", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.dcache.ipa", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.dcache.cva", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.dcache.civa", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.dcache.iva", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.dcache.csw", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.dcache.cisw", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.dcache.isw", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.dcache.cpal1", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.dcache.cval1", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.icache.iall", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
{ "th.icache.ialls", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
{ "th.icache.ipa", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.icache.iva", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 },
{ "th.l2cache.call", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
{ "th.l2cache.ciall", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
{ "th.l2cache.iall", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
/* XTheadCondMov */
{ "th.mveqz", rv_codec_r, rv_fmt_rd_rs1_rs2, NULL, 0, 0, 0 },
{ "th.mvnez", rv_codec_r, rv_fmt_rd_rs1_rs2, NULL, 0, 0, 0 },
/* XTheadFMemIdx */
{ "th.flrd", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.flrw", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.flurd", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.flurw", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.fsrd", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.fsrw", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.fsurd", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.fsurw", rv_codec_r_imm2, rv_fmt_frd_rs1_rs2_imm, NULL, 0, 0, 0 },
/* XTheadFmv */
{ "th.fmv.hw.x", rv_codec_r, rv_fmt_rd_frs1, NULL, 0, 0, 0 },
{ "th.fmv.x.hw", rv_codec_r, rv_fmt_rd_frs1, NULL, 0, 0, 0 },
/* XTheadMac */
{ "th.mula", rv_codec_r, rv_fmt_rd_rs1_rs2, NULL, 0, 0, 0 },
{ "th.mulaw", rv_codec_r, rv_fmt_rd_rs1_rs2, NULL, 0, 0, 0 },
{ "th.mulah", rv_codec_r, rv_fmt_rd_rs1_rs2, NULL, 0, 0, 0 },
{ "th.muls", rv_codec_r, rv_fmt_rd_rs1_rs2, NULL, 0, 0, 0 },
{ "th.mulsw", rv_codec_r, rv_fmt_rd_rs1_rs2, NULL, 0, 0, 0 },
{ "th.mulsh", rv_codec_r, rv_fmt_rd_rs1_rs2, NULL, 0, 0, 0 },
/* XTheadMemIdx */
{ "th.lbia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.lbib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml, NULL, 0, 0, 0 },
{ "th.lbuia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.lbuib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.lhia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.lhib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.lhuia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.lhuib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.lwia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.lwib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.lwuia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.lwuib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.ldia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.ldib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.sbia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.sbib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.shia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.shib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.swia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.swib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.sdia", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.sdib", rv_codec_r2_imm2_imm5, rv_fmt_rd_rs1_immh_imml_addr, NULL, 0, 0, 0 },
{ "th.lrb", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lrbu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lrh", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lrhu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lrw", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lrwu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lrd", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.srb", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.srh", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.srw", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.srd", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lurb", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lurbu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lurh", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lurhu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lurw", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lurwu", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.lurd", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.surb", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.surh", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.surw", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
{ "th.surd", rv_codec_r_imm2, rv_fmt_rd_rs1_rs2_imm, NULL, 0, 0, 0 },
/* XTheadMemPair */
{ "th.ldd", rv_codec_r_imm2, rv_fmt_rd2_imm, NULL, 0, 0, 0 },
{ "th.lwd", rv_codec_r_imm2, rv_fmt_rd2_imm, NULL, 0, 0, 0 },
{ "th.lwud", rv_codec_r_imm2, rv_fmt_rd2_imm, NULL, 0, 0, 0 },
{ "th.sdd", rv_codec_r_imm2, rv_fmt_rd2_imm, NULL, 0, 0, 0 },
{ "th.swd", rv_codec_r_imm2, rv_fmt_rd2_imm, NULL, 0, 0, 0 },
/* XTheadSync */
{ "th.sfence.vmas", rv_codec_r, rv_fmt_rs1_rs2, NULL, 0, 0, 0 },
{ "th.sync", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
{ "th.sync.i", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
{ "th.sync.is", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
{ "th.sync.s", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 },
};
void decode_xtheadba(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xtheadba(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
@ -262,7 +27,7 @@ void decode_xtheadba(rv_decode *dec, rv_isa isa)
case 0b0000000:
case 0b0000001:
case 0b0000010:
case 0b0000011: op = rv_op_th_addsl; break;
case 0b0000011: return &op_th_addsl;
}
break;
}
@ -272,13 +37,12 @@ void decode_xtheadba(rv_decode *dec, rv_isa isa)
break;
}
dec->op = op;
return NULL;
}
void decode_xtheadbb(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xtheadbb(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
@ -288,39 +52,41 @@ void decode_xtheadbb(rv_decode *dec, rv_isa isa)
switch ((inst >> 12) & 0b111) {
case 1:
switch ((inst >> 25) & 0b1111111) {
case 0b0001010: op = rv_op_th_srriw; break;
case 0b0001010: return &op_th_srriw;
case 0b1000000:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_tstnbz;
return &op_th_tstnbz;
}
break;
case 0b1000001:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_rev;
return &op_th_rev;
}
break;
case 0b1000010:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_ff0;
return &op_th_ff0;
}
break;
case 0b1000011:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_ff1;
return &op_th_ff1;
}
break;
case 0b1000100:
case 0b1001000:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_revw;
return &op_th_revw;
}
break;
case 0b0000100:
case 0b0000101: op = rv_op_th_srri; break;
case 0b0001000:
case 0b0001001:
return &op_th_srri;
break;
}
break;
case 2: op = rv_op_th_ext; break;
case 3: op = rv_op_th_extu; break;
case 2: return &op_th_ext;
case 3: return &op_th_extu;
}
break;
/* custom-0 */
@ -328,13 +94,12 @@ void decode_xtheadbb(rv_decode *dec, rv_isa isa)
break;
}
dec->op = op;
return NULL;
}
void decode_xtheadbs(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xtheadbs(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
@ -344,7 +109,7 @@ void decode_xtheadbs(rv_decode *dec, rv_isa isa)
switch ((inst >> 12) & 0b111) {
case 1:
switch ((inst >> 26) & 0b111111) {
case 0b100010: op = rv_op_th_tst; break;
case 0b100010: return &op_th_tst;
}
break;
}
@ -354,13 +119,12 @@ void decode_xtheadbs(rv_decode *dec, rv_isa isa)
break;
}
dec->op = op;
return NULL;
}
void decode_xtheadcmo(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xtheadcmo(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
@ -372,55 +136,55 @@ void decode_xtheadcmo(rv_decode *dec, rv_isa isa)
switch ((inst >> 20 & 0b111111111111)) {
case 0b000000000001:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_dcache_call;
return &op_th_dcache_call;
}
break;
case 0b000000000011:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_dcache_ciall;
return &op_th_dcache_ciall;
}
break;
case 0b000000000010:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_dcache_iall;
return &op_th_dcache_iall;
}
break;
case 0b000000101001: op = rv_op_th_dcache_cpa; break;
case 0b000000101011: op = rv_op_th_dcache_cipa; break;
case 0b000000101010: op = rv_op_th_dcache_ipa; break;
case 0b000000100101: op = rv_op_th_dcache_cva; break;
case 0b000000100111: op = rv_op_th_dcache_civa; break;
case 0b000000100110: op = rv_op_th_dcache_iva; break;
case 0b000000100001: op = rv_op_th_dcache_csw; break;
case 0b000000100011: op = rv_op_th_dcache_cisw; break;
case 0b000000100010: op = rv_op_th_dcache_isw; break;
case 0b000000101000: op = rv_op_th_dcache_cpal1; break;
case 0b000000100100: op = rv_op_th_dcache_cval1; break;
case 0b000000101001: return &op_th_dcache_cpa;
case 0b000000101011: return &op_th_dcache_cipa;
case 0b000000101010: return &op_th_dcache_ipa;
case 0b000000100101: return &op_th_dcache_cva;
case 0b000000100111: return &op_th_dcache_civa;
case 0b000000100110: return &op_th_dcache_iva;
case 0b000000100001: return &op_th_dcache_csw;
case 0b000000100011: return &op_th_dcache_cisw;
case 0b000000100010: return &op_th_dcache_isw;
case 0b000000101000: return &op_th_dcache_cpal1;
case 0b000000100100: return &op_th_dcache_cval1;
case 0b000000010000:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_icache_iall;
return &op_th_icache_iall;
}
break;
case 0b000000010001:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_icache_ialls;
return &op_th_icache_ialls;
}
break;
case 0b000000111000: op = rv_op_th_icache_ipa; break;
case 0b000000110000: op = rv_op_th_icache_iva; break;
case 0b000000111000: return &op_th_icache_ipa;
case 0b000000110000: return &op_th_icache_iva;
case 0b000000010101:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_l2cache_call;
return &op_th_l2cache_call;
}
break;
case 0b000000010111:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_l2cache_ciall;
return &op_th_l2cache_ciall;
}
break;
case 0b000000010110:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_l2cache_iall;
return &op_th_l2cache_iall;
}
break;
}
@ -432,13 +196,12 @@ void decode_xtheadcmo(rv_decode *dec, rv_isa isa)
break;
}
dec->op = op;
return NULL;
}
void decode_xtheadcondmov(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xtheadcondmov(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
@ -448,8 +211,8 @@ void decode_xtheadcondmov(rv_decode *dec, rv_isa isa)
switch ((inst >> 12) & 0b111) {
case 1:
switch ((inst >> 25) & 0b1111111) {
case 0b0100000: op = rv_op_th_mveqz; break;
case 0b0100001: op = rv_op_th_mvnez; break;
case 0b0100000: return &op_th_mveqz;
case 0b0100001: return &op_th_mvnez;
}
break;
}
@ -459,13 +222,12 @@ void decode_xtheadcondmov(rv_decode *dec, rv_isa isa)
break;
}
dec->op = op;
return NULL;
}
void decode_xtheadfmemidx(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xtheadfmemidx(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
@ -475,18 +237,18 @@ void decode_xtheadfmemidx(rv_decode *dec, rv_isa isa)
switch ((inst >> 12) & 0b111) {
case 6:
switch ((inst >> 27) & 0b11111) {
case 8: op = rv_op_th_flrw; break;
case 10: op = rv_op_th_flurw; break;
case 12: op = rv_op_th_flrd; break;
case 14: op = rv_op_th_flurd; break;
case 8: return &op_th_flrw;
case 10: return &op_th_flurw;
case 12: return &op_th_flrd;
case 14: return &op_th_flurd;
}
break;
case 7:
switch ((inst >> 27) & 0b11111) {
case 8: op = rv_op_th_fsrw; break;
case 10: op = rv_op_th_fsurw; break;
case 12: op = rv_op_th_fsrd; break;
case 14: op = rv_op_th_fsurd; break;
case 8: return &op_th_fsrw;
case 10: return &op_th_fsurw;
case 12: return &op_th_fsrd;
case 14: return &op_th_fsurd;
}
break;
}
@ -496,13 +258,12 @@ void decode_xtheadfmemidx(rv_decode *dec, rv_isa isa)
break;
}
dec->op = op;
return NULL;
}
void decode_xtheadfmv(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xtheadfmv(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
@ -514,12 +275,12 @@ void decode_xtheadfmv(rv_decode *dec, rv_isa isa)
switch ((inst >> 25) & 0b1111111) {
case 0b1010000:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_fmv_hw_x;
return &op_th_fmv_hw_x;
}
break;
case 0b1100000:
if (((inst >> 20) & 0b11111) == 0) {
op = rv_op_th_fmv_x_hw;
return &op_th_fmv_x_hw;
}
break;
}
@ -531,13 +292,12 @@ void decode_xtheadfmv(rv_decode *dec, rv_isa isa)
break;
}
dec->op = op;
return NULL;
}
void decode_xtheadmac(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xtheadmac(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
@ -547,12 +307,12 @@ void decode_xtheadmac(rv_decode *dec, rv_isa isa)
switch ((inst >> 12) & 0b111) {
case 1:
switch ((inst >> 25) & 0b1111111) {
case 0b0010000: op = rv_op_th_mula; break;
case 0b0010001: op = rv_op_th_muls; break;
case 0b0010010: op = rv_op_th_mulaw; break;
case 0b0010011: op = rv_op_th_mulsw; break;
case 0b0010100: op = rv_op_th_mulah; break;
case 0b0010101: op = rv_op_th_mulsh; break;
case 0b0010000: return &op_th_mula;
case 0b0010001: return &op_th_muls;
case 0b0010010: return &op_th_mulaw;
case 0b0010011: return &op_th_mulsw;
case 0b0010100: return &op_th_mulah;
case 0b0010101: return &op_th_mulsh;
}
break;
}
@ -562,13 +322,12 @@ void decode_xtheadmac(rv_decode *dec, rv_isa isa)
break;
}
dec->op = op;
return NULL;
}
void decode_xtheadmemidx(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xtheadmemidx(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
@ -578,54 +337,54 @@ void decode_xtheadmemidx(rv_decode *dec, rv_isa isa)
switch ((inst >> 12) & 0b111) {
case 4:
switch ((inst >> 27) & 0b11111) {
case 0: op = rv_op_th_lrb; break;
case 1: op = rv_op_th_lbib; break;
case 2: op = rv_op_th_lurb; break;
case 3: op = rv_op_th_lbia; break;
case 4: op = rv_op_th_lrh; break;
case 5: op = rv_op_th_lhib; break;
case 6: op = rv_op_th_lurh; break;
case 7: op = rv_op_th_lhia; break;
case 8: op = rv_op_th_lrw; break;
case 9: op = rv_op_th_lwib; break;
case 10: op = rv_op_th_lurw; break;
case 11: op = rv_op_th_lwia; break;
case 12: op = rv_op_th_lrd; break;
case 13: op = rv_op_th_ldib; break;
case 14: op = rv_op_th_lurd; break;
case 15: op = rv_op_th_ldia; break;
case 16: op = rv_op_th_lrbu; break;
case 17: op = rv_op_th_lbuib; break;
case 18: op = rv_op_th_lurbu; break;
case 19: op = rv_op_th_lbuia; break;
case 20: op = rv_op_th_lrhu; break;
case 21: op = rv_op_th_lhuib; break;
case 22: op = rv_op_th_lurhu; break;
case 23: op = rv_op_th_lhuia; break;
case 24: op = rv_op_th_lrwu; break;
case 25: op = rv_op_th_lwuib; break;
case 26: op = rv_op_th_lurwu; break;
case 27: op = rv_op_th_lwuia; break;
case 0: return &op_th_lrb;
case 1: return &op_th_lbib;
case 2: return &op_th_lurb;
case 3: return &op_th_lbia;
case 4: return &op_th_lrh;
case 5: return &op_th_lhib;
case 6: return &op_th_lurh;
case 7: return &op_th_lhia;
case 8: return &op_th_lrw;
case 9: return &op_th_lwib;
case 10: return &op_th_lurw;
case 11: return &op_th_lwia;
case 12: return &op_th_lrd;
case 13: return &op_th_ldib;
case 14: return &op_th_lurd;
case 15: return &op_th_ldia;
case 16: return &op_th_lrbu;
case 17: return &op_th_lbuib;
case 18: return &op_th_lurbu;
case 19: return &op_th_lbuia;
case 20: return &op_th_lrhu;
case 21: return &op_th_lhuib;
case 22: return &op_th_lurhu;
case 23: return &op_th_lhuia;
case 24: return &op_th_lrwu;
case 25: return &op_th_lwuib;
case 26: return &op_th_lurwu;
case 27: return &op_th_lwuia;
}
break;
case 5:
switch ((inst >> 27) & 0b11111) {
case 0: op = rv_op_th_srb; break;
case 1: op = rv_op_th_sbib; break;
case 2: op = rv_op_th_surb; break;
case 3: op = rv_op_th_sbia; break;
case 4: op = rv_op_th_srh; break;
case 5: op = rv_op_th_shib; break;
case 6: op = rv_op_th_surh; break;
case 7: op = rv_op_th_shia; break;
case 8: op = rv_op_th_srw; break;
case 9: op = rv_op_th_swib; break;
case 10: op = rv_op_th_surw; break;
case 11: op = rv_op_th_swia; break;
case 12: op = rv_op_th_srd; break;
case 13: op = rv_op_th_sdib; break;
case 14: op = rv_op_th_surd; break;
case 15: op = rv_op_th_sdia; break;
case 0: return &op_th_srb;
case 1: return &op_th_sbib;
case 2: return &op_th_surb;
case 3: return &op_th_sbia;
case 4: return &op_th_srh;
case 5: return &op_th_shib;
case 6: return &op_th_surh;
case 7: return &op_th_shia;
case 8: return &op_th_srw;
case 9: return &op_th_swib;
case 10: return &op_th_surw;
case 11: return &op_th_swia;
case 12: return &op_th_srd;
case 13: return &op_th_sdib;
case 14: return &op_th_surd;
case 15: return &op_th_sdia;
}
break;
break;
@ -636,13 +395,12 @@ void decode_xtheadmemidx(rv_decode *dec, rv_isa isa)
break;
}
dec->op = op;
return NULL;
}
void decode_xtheadmempair(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xtheadmempair(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
@ -652,15 +410,15 @@ void decode_xtheadmempair(rv_decode *dec, rv_isa isa)
switch ((inst >> 12) & 0b111) {
case 4:
switch ((inst >> 27) & 0b11111) {
case 28: op = rv_op_th_lwd; break;
case 30: op = rv_op_th_lwud; break;
case 31: op = rv_op_th_ldd; break;
case 28: return &op_th_lwd;
case 30: return &op_th_lwud;
case 31: return &op_th_ldd;
}
break;
case 5:
switch ((inst >> 27) & 0b11111) {
case 28: op = rv_op_th_swd; break;
case 31: op = rv_op_th_sdd; break;
case 28: return &op_th_swd;
case 31: return &op_th_sdd;
}
break;
}
@ -670,13 +428,12 @@ void decode_xtheadmempair(rv_decode *dec, rv_isa isa)
break;
}
dec->op = op;
return NULL;
}
void decode_xtheadsync(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xtheadsync(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
@ -686,13 +443,13 @@ void decode_xtheadsync(rv_decode *dec, rv_isa isa)
switch ((inst >> 12) & 0b111) {
case 0:
switch ((inst >> 25) & 0b1111111) {
case 0b0000010: op = rv_op_th_sfence_vmas; break;
case 0b0000010: return &op_th_sfence_vmas;
case 0b0000000:
switch ((inst >> 20) & 0b11111) {
case 0b11000: op = rv_op_th_sync; break;
case 0b11010: op = rv_op_th_sync_i; break;
case 0b11011: op = rv_op_th_sync_is; break;
case 0b11001: op = rv_op_th_sync_s; break;
case 0b11000: return &op_th_sync;
case 0b11010: return &op_th_sync_i;
case 0b11011: return &op_th_sync_is;
case 0b11001: return &op_th_sync_s;
}
break;
}
@ -704,5 +461,5 @@ void decode_xtheadsync(rv_decode *dec, rv_isa isa)
break;
}
dec->op = op;
return NULL;
}

View file

@ -11,18 +11,16 @@
#include "disas/riscv.h"
extern const rv_opcode_data xthead_opcode_data[];
void decode_xtheadba(rv_decode *, rv_isa);
void decode_xtheadbb(rv_decode *, rv_isa);
void decode_xtheadbs(rv_decode *, rv_isa);
void decode_xtheadcmo(rv_decode *, rv_isa);
void decode_xtheadcondmov(rv_decode *, rv_isa);
void decode_xtheadfmemidx(rv_decode *, rv_isa);
void decode_xtheadfmv(rv_decode *, rv_isa);
void decode_xtheadmac(rv_decode *, rv_isa);
void decode_xtheadmemidx(rv_decode *, rv_isa);
void decode_xtheadmempair(rv_decode *, rv_isa);
void decode_xtheadsync(rv_decode *, rv_isa);
const rv_opcode_data *decode_xtheadba(rv_decode *, rv_isa);
const rv_opcode_data *decode_xtheadbb(rv_decode *, rv_isa);
const rv_opcode_data *decode_xtheadbs(rv_decode *, rv_isa);
const rv_opcode_data *decode_xtheadcmo(rv_decode *, rv_isa);
const rv_opcode_data *decode_xtheadcondmov(rv_decode *, rv_isa);
const rv_opcode_data *decode_xtheadfmemidx(rv_decode *, rv_isa);
const rv_opcode_data *decode_xtheadfmv(rv_decode *, rv_isa);
const rv_opcode_data *decode_xtheadmac(rv_decode *, rv_isa);
const rv_opcode_data *decode_xtheadmemidx(rv_decode *, rv_isa);
const rv_opcode_data *decode_xtheadmempair(rv_decode *, rv_isa);
const rv_opcode_data *decode_xtheadsync(rv_decode *, rv_isa);
#endif /* DISAS_RISCV_XTHEAD_H */

View file

@ -0,0 +1,2 @@
OP(vt_maskc, "vt.maskc", rv_codec_r, rv_fmt_rd_rs1_rs2)
OP(vt_maskcn, "vt.maskcn", rv_codec_r, rv_fmt_rd_rs1_rs2)

View file

@ -8,35 +8,26 @@
#include "disas/riscv.h"
#include "disas/riscv-xventana.h"
typedef enum {
/* 0 is reserved for rv_op_illegal. */
ventana_op_vt_maskc = 1,
ventana_op_vt_maskcn = 2,
} rv_ventana_op;
#define OP(N, ...) static const rv_opcode_data op_##N = { __VA_ARGS__ };
#include "riscv-xventana-op.c.inc"
#undef OP
const rv_opcode_data ventana_opcode_data[] = {
{ "vt.illegal", rv_codec_illegal, rv_fmt_none, NULL, 0, 0, 0 },
{ "vt.maskc", rv_codec_r, rv_fmt_rd_rs1_rs2, NULL, 0, 0, 0 },
{ "vt.maskcn", rv_codec_r, rv_fmt_rd_rs1_rs2, NULL, 0, 0, 0 },
};
void decode_xventanacondops(rv_decode *dec, rv_isa isa)
const rv_opcode_data *decode_xventanacondops(rv_decode *dec, rv_isa isa)
{
rv_inst inst = dec->inst;
rv_opcode op = rv_op_illegal;
switch (((inst >> 0) & 0b11)) {
case 3:
switch (((inst >> 2) & 0b11111)) {
case 30:
switch (((inst >> 22) & 0b1111111000) | ((inst >> 12) & 0b0000000111)) {
case 6: op = ventana_op_vt_maskc; break;
case 7: op = ventana_op_vt_maskcn; break;
case 6: return &op_vt_maskc;
case 7: return &op_vt_maskcn;
}
break;
}
break;
}
dec->op = op;
return NULL;
}

View file

@ -11,8 +11,6 @@
#include "disas/riscv.h"
extern const rv_opcode_data ventana_opcode_data[];
void decode_xventanacondops(rv_decode*, rv_isa);
const rv_opcode_data *decode_xventanacondops(rv_decode*, rv_isa);
#endif /* DISAS_RISCV_XVENTANA_H */

File diff suppressed because it is too large Load diff

View file

@ -11,7 +11,7 @@
/* types */
typedef uint64_t rv_inst;
typedef uint32_t rv_inst;
typedef uint16_t rv_opcode;
/* enums */
@ -84,15 +84,6 @@ typedef enum {
rvc_imm_eq_zero,
rvc_imm_eq_n1,
rvc_imm_eq_p1,
rvc_csr_eq_0x001,
rvc_csr_eq_0x002,
rvc_csr_eq_0x003,
rvc_csr_eq_0xc00,
rvc_csr_eq_0xc01,
rvc_csr_eq_0xc02,
rvc_csr_eq_0xc80,
rvc_csr_eq_0xc81,
rvc_csr_eq_0xc82,
} rvc_constraint;
typedef enum {
@ -149,6 +140,7 @@ typedef enum {
rv_codec_v_r,
rv_codec_v_ldst,
rv_codec_v_i,
rv_codec_v_i_u,
rv_codec_vsetvli,
rv_codec_vsetivli,
rv_codec_vror_vi,
@ -167,36 +159,34 @@ typedef enum {
rv_codec_r2_imm2_imm5,
rv_codec_fli,
rv_codec_lp,
rv_codec_cmop,
rv_codec_cmop_ss,
rv_codec_mop_r,
rv_codec_mop_rr,
} rv_codec;
/* structures */
typedef struct rv_opcode_data rv_opcode_data;
typedef struct {
const int op;
const rv_opcode_data *op;
const rvc_constraint *constraints;
} rv_comp_data;
typedef struct {
const char * const name;
const rv_codec codec;
const char * const format;
struct rv_opcode_data {
const char *name;
rv_codec codec;
const char *format;
const rv_comp_data *pseudo;
const short decomp_rv32;
const short decomp_rv64;
const short decomp_rv128;
const short decomp_data;
} rv_opcode_data;
};
typedef struct {
const RISCVCPUConfig *cfg;
uint64_t pc;
uint64_t inst;
const rv_opcode_data *opcode_data;
int32_t imm;
int32_t imm1;
uint16_t op;
uint8_t codec;
uint8_t rd;
uint8_t rs1;
uint8_t rs2;
@ -213,14 +203,6 @@ typedef struct {
uint8_t rlist;
} rv_decode;
enum {
rv_op_illegal = 0
};
enum {
rvcd_imm_nz = 0x1
};
/* instruction formats */
#define rv_fmt_none "O\t"
@ -305,5 +287,8 @@ enum {
#define rv_fmt_rd_rs1_immh_imml_addr "O\t0,(1),i,j"
#define rv_fmt_rd2_imm "O\t0,2,(1),i"
#define rv_fmt_fli "O\t3,h"
#define rv_fmt_cmop "O.i"
#define rv_fmt_mop_r "O.i\t0,1"
#define rv_fmt_mop_rr "O.i\t0,1,2"
#endif /* DISAS_RISCV_H */

View file

@ -1072,14 +1072,13 @@ syscall, so the real kernel never sees it.
Trusted guests only. The guest can load arbitrary host libraries and run
arbitrary code in the QEMU host process. The plugin is not a sandbox and
provides no isolation. It also requires ``guest_base == 0`` (qemu-user's
default), as guest pointers are dereferenced as host addresses with no
translation.
default) and a guest whose pointer width and endianness match the host's, as
guest pointers are dereferenced as host addresses with no translation.
The plugin intentionally keeps the QEMU side lightweight and knows nothing
about any particular library or its calling convention. Turning a real library
into working thunks, including argument marshalling, callbacks and variadic
functions, is done entirely in userspace, and any toolchain can implement the
interface.
about any particular library or its calling convention. Producing the thunks
for a real library is done entirely in userspace, and any toolchain can
implement the interface.
Loading the plugin is all that is required from QEMU's side:
@ -1087,11 +1086,21 @@ Loading the plugin is all that is required from QEMU's side:
qemu-x86_64 -plugin contrib/plugins/libdlcall.so <guest-program> ...
If the default number does not suit the guest ABI, pick another one, and build
the userspace side to issue the same one:
.. code-block:: shell
qemu-x86_64 -plugin contrib/plugins/libdlcall.so,syscall_num=8192 \
<guest-program> ...
`Lorelei <https://github.com/rover2024/lorelei>`_ is one end-to-end userspace
implementation of this: it provides the guest and host runtimes and an
automated toolchain that generates the thunks from a library's headers, so guest
library calls run on the host's native libraries. It supports an x86_64 guest
running on an x86_64, aarch64 or riscv64 host.
library calls run on the host's native libraries. How it handles the parts the
plugin leaves out, including argument marshalling, callbacks and variadic
functions, can serve as a reference. It supports an x86_64 guest running on an
x86_64, aarch64 or riscv64 host.
A minimal end-to-end example uses a one-function library, ``libhello.so``, built
two ways: the guest build tags its output ``(from the guest)`` and the host
@ -1201,8 +1210,10 @@ which prints::
* - Option
- Description
* - syscall_num=N
- The magic syscall number the guest issues (default 4096). Must be high
enough not to clash with a real syscall.
- The magic syscall number the guest issues (default 4096). It must be a
number the guest ABI does not use for a real syscall, and does not
reject before the plugin sees it, which bounds the choice from both
sides.
Other emulation features
------------------------

View file

@ -1241,7 +1241,7 @@ RISC-V default machine (removed in 11.1)
''''''''''''''''''''''''''''''''''''''''
RISC-V used to define ``spike`` as the default machine if no machine option
was given via the command line. This happend because ``spike`` was the first
was given via the command line. This happened because ``spike`` was the first
RISC-V machine implemented in QEMU and setting it as default was
convenient at that time. Now we have 7 riscv64 and 6 riscv32 machines
and having ``spike`` as a default is no longer justified.

View file

@ -0,0 +1,55 @@
.. SPDX-License-Identifier: GPL-2.0-or-later
Hexagon L2 Vectored Interrupt Controller
========================================
.. code-block:: none
+-------------+ +----------------------+
| l2vic | | hexagon core |
| | | |
IRQ in ---->| | | |
IRQ in ---->| VID0 -|----------------->| irq2 |
... ---->| | | | |
IRQ in ---->| | | v |
| ... | | <int steering> |
| | | / | | \ |
IRQ in ---->| | | t0 t1 t2 t3 ...|
IRQ in ---->| VIDN -| | |
... ---->| | | |
IRQ in ---->| | | Global SREG File |
| | | |
| State | | |
| [ ] <--|==================|==> [ VID ] |
| [ ] <--|==================|==> [ VID1 ] |
| | | |
+-------------+ +----------------------+
L2VIC/Core Integration
----------------------
* hexagon core supports 8 external interrupt sources
* l2vic supports 1024 input interrupts mapped among 4 output interrupts
* l2vic has four output signals: { VID0, VID1, VID2, VID3 }
* l2vic device has a bank of registers per-VID that can be used to query
the status or assert new interrupts.
* Interrupts are 'steered' to threads based on { thread priority, 'EX' state,
thread interrupt mask, thread interrupt enable, global interrupt enable,
etc. }.
* Any hardware thread could conceivably handle any input interrupt, dependent
on state.
* The system register transfer instruction can read the VID0-VID3 values from
the l2vic when reading from hexagon core system registers "VID" and "VID1".
* When l2vic VID0 has multiple active interrupts, it pulses the VID0 output
IRQ and stores the IRQ number for the VID0 register field. Only after this
interrupt is cleared can the l2vic pulse the VID0 output IRQ again and provide
the next interrupt number on the VID0 register.
* The ``ciad`` instruction clears the l2vic input interrupt and un-disables the
core interrupt. If some/an l2vic VID0 interrupt is pending when this occurs,
the next interrupt should fire and any subsequent reads of the VID register
should reflect the newly raised interrupt.
* In QEMU, on an external interrupt or an unmasked-pending interrupt,
all vCPUs are triggered (has_work==true) and each will grab the IO lock
while considering the steering logic to determine whether they're the thread
that must handle the interrupt.

View file

@ -15,11 +15,13 @@ Details about QEMU's various subsystems including how to add features to them.
clocks
ebpf_rss
hexagon-sys
hexagon-l2vic
migration/index
multi-process
reset
s390-cpu-topology
s390-dasd-ipl
ssi
tracing
uefi-vars
vfio-iommufd

View file

@ -21,19 +21,15 @@ invokes rustc directly, building static libraries that are then linked
together with the C code. This is completely automatic when you run
``make`` or ``ninja``.
However, QEMU's build system also tries to be easy to use for people who
are accustomed to the more "normal" Cargo-based development workflow.
In particular:
* the set of warnings and lints that are used to build QEMU always
comes from the ``rust/Cargo.toml`` workspace file
* it is also possible to use ``cargo`` for common Rust-specific coding
tasks, in particular to invoke ``clippy``, ``rustfmt`` and ``rustdoc``.
However, Meson is able to consume ``Cargo.toml`` files and tries
to be easy to use for people who are accustomed to the more "normal"
Cargo-based development workflow. In the case of QEMU, in addition,
it is possible to use ``cargo`` for common Rust-specific coding
tasks, in particular to invoke ``clippy``, ``rustfmt`` and ``rustdoc``.
To this end, QEMU includes a ``build.rs`` build script that picks up
generated sources from QEMU's build directory and puts it in Cargo's
output directory (typically ``rust/target/``). A vanilla invocation
output directory (typically ``target/``). A vanilla invocation
of Cargo will complain that it cannot find the generated sources,
which can be fixed in different ways:
@ -466,63 +462,38 @@ Adding dependencies
Generally, the set of dependent crates is kept small. Think twice before
adding a new external crate, especially if it comes with a large set of
dependencies itself. Sometimes QEMU only needs a small subset of the
functionality; see for example QEMU's ``assertions`` module.
functionality; see for example QEMU's ``assertions`` module. Also,
choose a version of the crate that works with QEMU's minimum supported
Rust version (|msrv|).
On top of this recommendation, adding external crates to QEMU is a
slightly complicated process, mostly due to the need to teach Meson how
to build them. While Meson has initial support for parsing ``Cargo.lock``
files, it is still highly experimental and is therefore not used.
to download them. While QEMU uses Meson's support for parsing ``Cargo.toml``
files, it ships ``.wrap`` files instead of using ``Cargo.lock``; this way,
distros can adjust the set of dependencies to the exact versions they use.
The versions specified in QEMU's ``Cargo.lock`` must be the same as the
one in the wrap file.
Therefore, external crates must be added as subprojects for Meson to
learn how to build them, as well as to the relevant ``Cargo.toml`` files.
The versions specified in ``rust/Cargo.lock`` must be the same as the
subprojects; note that the ``rust/`` directory forms a Cargo `workspace`__,
and therefore there is a single lock file for the whole build.
__ https://doc.rust-lang.org/cargo/reference/workspaces.html#virtual-workspace
Choose a version of the crate that works with QEMU's minimum supported
Rust version (|msrv|).
Second, a new ``wrap`` file must be added to teach Meson how to download the
crate. The wrap file must be named ``NAME-SEMVER-rs.wrap``, where ``NAME``
The wrap file must be named ``NAME-SEMVER-rs.wrap``, where ``NAME``
is the name of the crate and ``SEMVER`` is the version up to and including the
first non-zero number. For example, a crate with version ``0.2.3`` will use
``0.2`` for its ``SEMVER``, while a crate with version ``1.0.84`` will use ``1``.
Third, the Meson rules to build the crate must be added at
``subprojects/NAME-SEMVER-rs/meson.build``. Generally this includes:
Usually, Meson is able to figure out how to build the crate, and also handles
cross compilation correctly. For crates that have a ``build.rs`` file,
equivalent rules must be added to
``subprojects/packagefiles/NAME-SEMVER-rs/meson/meson.build``.
The file can modify the ``extra_args`` and ``extra_deps`` variables,
which contain respectively the compiler arguments and external dependencies
for the crate.
* ``subproject`` and ``dependency`` lines for all dependent crates
After every change to the ``meson/meson.build`` file you have to update the
patched version with ``meson subprojects update --reset ``NAME-SEMVER-rs``.
This might be automated in the future.
* a ``static_library`` or ``rust.proc_macro`` line to perform the actual build
* ``declare_dependency`` and a ``meson.override_dependency`` lines to expose
the result to QEMU and to other subprojects
Remember to add ``native: true`` to ``dependency``, ``static_library`` and
``meson.override_dependency`` for dependencies of procedural macros.
If a crate is needed in both procedural macros and QEMU binaries, everything
apart from ``subproject`` must be duplicated to build both native and
non-native versions of the crate.
It's important to specify the right compiler options. These include:
* the language edition (which can be found in the ``Cargo.toml`` file)
* the ``--cfg`` (which have to be "reverse engineered" from the ``build.rs``
file of the crate).
* usually, a ``--cap-lints allow`` argument to hide warnings from rustc
or clippy.
After every change to the ``meson.build`` file you have to update the patched
version with ``meson subprojects update --reset ``NAME-SEMVER-rs``. This might
be automated in the future.
Also, after every change to the ``meson.build`` file it is strongly suggested to
do a dummy change to the ``.wrap`` file (for example adding a comment like
``# version 2``), which will help Meson notice that the subproject is out of date.
Also, after every change to the file it is strongly suggested to do a dummy
change to the ``.wrap`` file (for example adding a comment like ``# version 2``),
which will help Meson notice that the subproject is out of date.
As a last step, add the new subproject to ``scripts/archive-source.sh``,
``scripts/make-release`` and ``subprojects/.gitignore``.

132
docs/devel/ssi.rst Normal file
View file

@ -0,0 +1,132 @@
================================
SSI devices and SPI flash models
================================
QEMU's Synchronous Serial Interface (SSI) bus models the full-duplex transfer
of words between a controller and one selected peripheral. Most SPI flash
models, including ``m25p80``, are attached to controllers through this bus.
This page documents the expected boundary between a controller model and a
flash model for SPI fast-read dummy cycles. The boundary is important because
many real controllers expose dummy-cycle configuration in registers, while the
flash model observes only the byte stream delivered through ``ssi_transfer()``.
SSI transfer granularity
------------------------
``ssi_transfer()`` transfers one SSI word. Flash models that implement common
SPI NOR command streams usually consume one 8-bit word at a time:
* command opcode;
* address bytes;
* optional mode or continuous-read bytes;
* dummy bytes;
* data bytes.
The SSI core does not model individual clock edges or the number of active SPI
data lines. If a real transaction has a dummy phase expressed in clock cycles,
the device model that generates transfers on the SSI bus must represent that
phase as a number of dummy byte transfers.
Flash model responsibilities
----------------------------
A SPI flash model owns the command semantics for the flash device:
* which opcodes are recognized;
* how many address bytes are required;
* whether a command has mode bytes;
* how many dummy bytes must be consumed before data can be returned;
* manufacturer-specific differences in fast-read command behavior.
For the ``m25p80`` model, ``needed_bytes`` is a byte count. It must not store
raw dummy cycles. When a flash datasheet describes the dummy phase in cycles,
the flash model converts the cycles to bytes using the bus width used for the
dummy phase::
dummy_bytes = DIV_ROUND_UP(dummy_cycles * dummy_bus_width, 8)
For SPI NOR fast-read commands modeled by ``m25p80``, the dummy phase follows
the address phase width. For example, output-only dual and quad read commands
such as DOR and QOR use one line for command, address, and dummy phases, then
use two or four lines only for the data phase. Dual I/O and Quad I/O commands
such as DIOR and QIOR use the wider bus for both address and dummy phases.
If the exact dummy phase cannot be represented as a whole number of SSI byte
transfers, the model should round up and log the limitation instead of silently
treating cycles as bytes.
Controller model responsibilities
---------------------------------
A controller model owns the behavior of the controller hardware:
* how guest-visible registers select command, address width, bus width, and
dummy-cycle count;
* whether the guest supplies dummy bytes in a transmit FIFO;
* whether the controller itself generates the dummy phase for a memory-mapped,
direct-read, or other automatic transfer mode;
* how chip-select state changes around controller-generated transfers.
When guest software writes dummy bytes into a transmit FIFO or manual transfer
path, the controller should pass those bytes to ``ssi_transfer()`` like any
other guest-provided byte. It should not add more dummy transfers on behalf of
the flash.
When hardware registers instruct the controller to generate a dummy phase, the
controller must emit dummy byte transfers before data transfers reach the flash
model. The controller should convert the configured cycle count using the bus
width that the controller uses during the dummy phase. For example:
* 8 dummy cycles on a single data line become 1 dummy byte;
* 8 dummy cycles on two data lines become 2 dummy bytes;
* 8 dummy cycles on four data lines become 4 dummy bytes.
The controller should not duplicate flash-specific opcode tables merely to
guess which commands need dummy cycles. In automatic modes the controller
already has enough hardware configuration to know whether it must generate a
dummy phase. In manual modes the guest-provided byte stream is authoritative.
Avoiding double counting
------------------------
Exactly one side should generate each dummy byte transfer seen by the flash:
* If the guest sends dummy bytes through the controller, the controller forwards
them and the flash consumes them.
* If the guest programs a controller dummy-cycle register, the controller
converts those cycles to dummy byte transfers and the flash consumes them.
* The flash may know that a command requires dummy bytes, but it does not create
transfers on the SSI bus.
Do not implement controller-side snooping that watches manual-mode opcode
streams and injects extra dummy transfers based on flash opcodes. That mixes
flash command semantics into the controller and is fragile when flash models
gain correct dummy-byte accounting.
Examples in the tree
--------------------
The following models illustrate the boundary:
* ``hw/block/m25p80.c`` keeps fast-read dummy requirements as byte counts in
``needed_bytes``. Manufacturer-specific helpers convert datasheet dummy
cycles to the byte stream expected by the model.
* ``hw/ssi/aspeed_smc.c`` generates dummy byte transfers for direct fast-read
mode from controller registers, but manual user-mode writes are forwarded as
guest-provided bytes.
* ``hw/ssi/npcm7xx_fiu.c`` converts the direct-read dummy configuration to the
number of dummy byte transfers sent before reading data.
Review checklist
----------------
When adding or changing a SPI flash controller or flash model, check:
* Are dummy counts stored in byte units when they drive flash state machines?
* If a hardware register stores cycles, is the conversion to bytes based on the
bus width of the dummy phase?
* Are manual guest-provided dummy bytes forwarded without extra injection?
* Are automatic controller-generated dummy phases modeled by the controller?
* Is flash-specific opcode knowledge kept in the flash model rather than copied
into controller snooping paths?

View file

@ -317,6 +317,18 @@ Arithmetic
pass 0 to *nh* to make a simple zero-extension of *nl*,
so overflow should never occur.
* - smax *t0*, *t1*, *t2*
umax *t0*, *t1*, *t2*
- | *t0* = MAX(*t1*, *t2*), for signed and unsigned integers.
* - smin *t0*, *t1*, *t2*
umin *t0*, *t1*, *t2*
- | *t0* = MIN(*t1*, *t2*), for signed and unsigned integers.
Logical
-------
@ -495,6 +507,22 @@ Misc
into 32-bit output *t0*. Depending on the host, this may be a simple shift,
or may require additional canonicalization.
* - revbit8 *dest*, *t1*
- | Reverse the 8 bits within each byte of input *t1* with
| output in *dest*; the byte order is unchanged.
* - revbit32 *dest*, *t1*, *flags*
- | Reverse the 32 bits of the lower 32 bits of input *t1*
| with output in *dest*. On TCG_TYPE_I64, *flags* control
| any required sign or zero extension of the result in
| the same way as for bswap32.
| On TCG_TYPE_I32, *flags* should be zero.
* - revbit64 *dest*, *t1*
- | Reverse the 64 bits of input *t1* with output in *dest*.
Conditional moves
-----------------

View file

@ -4,7 +4,7 @@ sphinx_build = find_program(fs.parent(python.full_path()) / 'sphinx-build',
# Check if tools are available to build documentation.
build_docs = false
if sphinx_build.found()
SPHINX_ARGS = ['env', 'CONFDIR=' + qemu_confdir, sphinx_build, '-q', '-j', 'auto']
SPHINX_ARGS = ['env', 'CONFDIR=' + qemu_confdir, sphinx_build, '-q']
# If we're making warnings fatal, apply this to Sphinx runs as well
if get_option('werror')
SPHINX_ARGS += [ '-W', '-Dkerneldoc_werror=1' ]

View file

@ -34,6 +34,7 @@ guest hardware that is specific to QEMU.
virt-ctlr
vmcoreinfo
vmgenid
vmlaunchupdate
rapl-msr
rocker
riscv-iommu

View file

@ -0,0 +1,198 @@
.. SPDX-License-Identifier: GPL-2.0-or-later
VMLAUNCHUPDATE Interface Specification
######################################
Introduction
************
``VmLaunchUpdate`` is an extension to ``fw-cfg`` that allows guests to replace
boot state in their virtual machine using IGVM file container. Through a combination
of this ``fw-cfg`` hypervisor interface, an IGVM file containing specific directives
and with hypervisor stack knowledge, guests can deterministically replace the launch
state for guests. This is useful for environments like SEV-SNP where the
launch payload becomes the launch digest. Guests can use vm-launch-update device to
provide a measured, full guest payload (BIOS image, kernel, initramfs, kernel
command line) to the virtual machine which enables them to easily reason about
integrity of the resulting system.
It is also to be noted that this mechanism currently works only when the guest was
already started with an IGVM file defining its initial launch state. Subsequent
guest resets will use the launch state as defined in the guest provided IGVM file,
not the file with which the guest was initially started. If the guest was not started
with IGVM, writing a new bundle through the ``fw-cfg`` interface has no effect.
For more information, please see the `KVM Forum 2024 presentation <KVMFORUM_>`__
about this work.
.. _KVMFORUM: https://www.youtube.com/watch?v=VCMBxU6tAto
Base Requirements
*****************
#. **fw-cfg**:
The target system must provide a ``fw-cfg`` interface. For x86 based
environments, this ``fw-cfg`` interface must be accessible through PIO ports
0x510 and 0x511. The ``fw-cfg`` interface does not need to be announced as part
of system device tables such as DSDT. The ``fw-cfg`` interface must support the
DMA interface. It may only support the DMA interface for write operations.
#. **IGVM support**:
The hypervisor must provide support for parsing and executing the IGVM file bundle.
#. **Confidential guests**:
For confidential guests, the hypervisor must support guest reset. Otherwise, the new
boot state provided through IGVM will not be applied.
The Fw-cfg File
***************
Guests drive vmlaunchupdate through special ``fw-cfg`` files that control its flow
followed by a standard system reset operation. When the ``vm-launch-update`` device
is available, it provides the following ``fw-cfg`` file:
* ``etc/vmlaunchupdate`` - It exposes a structure of the following type, all in
little-endian format:
.. code-block:: c
:linenos:
typedef struct {
uint16_t version;
uint16_t status;
uint32_t _padding;
uint64_t capabilities;
uint64_t control;
uint64_t fw_image_addr;
uint64_t fw_image_size;
uint64_t opaque_addr;
uint64_t opaque_size;
} VMLaunchUpdate;
Currently, the ``version`` number (line 2 above) is initialized to the value ``1``.
Only IGVM files are supported at present. The ``capabilities`` (line 7) and ``control`` (line 8) both support
the following single value:
* ``VM_LAUNCHUPDATE_FORMAT_IGVM``
This value is used by the hypervisor to indicate that only IGVM container files are supported.
This is set as a part of ``capabilities`` parameter (line 7) in the above structure. This same value
is passed by the guest to the hypervisor in the ``control`` parameter (line 8) in the above structure
to indicate that the guest passed IGVM file in memory to the hypervisor. The starting guest physical
address of the IGVM file in memory is specified in ``fw_image_addr`` and it's length is specified in
``fw_image_size`` by the guest. If any other value is passed by the guest in the ``control`` parameter,
the write is ignored by the hypervisor.
Following ``control`` parameters are supported:
* ``VM_LAUNCHUPDATE_CTL_DISABLE``
This value is set in the ``control`` parameter by the guest in order to disable this ``fw-cfg``
hypervisor interface from further updating the guest launch state with a new IGVM file.
* ``VM_LAUNCHUPDATE_CTL_HOST_IGVM``
This value is set in the ``control`` parameter by the guest in order to send request to the
hypervisor to initialize the guest using the original host provided IGVM file.
It is useful if the guest wanted to update the UKIs present in the ESP and upon
reset, use one of the updated UKIs present there. If the guest passed addresses in memory
where its own IGVM file is loaded (see below) while also setting this control value, the next
reset will load the guest provided IGVM file and a subsequent second reset will restore the original
host IGVM. If the guest did not provide any addresses of its own IGVM (the address values are
cleared) while setting this control parameter, the immediate next guest reset will load the
original host provided IGVM file.
The combination of the above two ctl interfaces work as
follows:
A) ``CTL_HOST_IGVM`` = off ``CTL_DISABLE`` = off
Supplied IGVM file replaces the firmware permanently. Updating the
firmware again is possible.
B) ``CTL_HOST_IGVM`` = off ``CTL_DISABLE`` = on
Supplied IGVM file replaces the firmware permanently. Updating the
firmware again is not possible.
C) ``CTL_HOST_IGVM`` = on ``CTL_DISABLE`` = off
Supplied IGVM file replaces the firmware for one reset. Resetting
again will switch back to the original firmware. Updating the
firmware again is possible.
D) ``CTL_HOST_IGVM`` = on ``CTL_DISABLE`` = on
Supplied IGVM file replaces the firmware for one reset. Resetting
again will switch back to the original firmware. Updating the
firmware again is NOT possible.
``fw_image_addr`` (line 10) is the base guest physical address of the guest memory where the IGVM file of size
``fw_image_size`` (line 11) is loaded. ``opaque_addr`` (line 13) and ``opaque_size`` (line 14) are used by
the guest for passing data across resets. The contents of this guest memory are preserved across the
reset. For confidential guests, this memory region must come from guest shared unencrypted memory.
``status`` (line 3) is written by the hypervisor and it indicates the result of the IGVM loading operation.
A success indicates status code 0. Otherwise a non-zero status code indicates failure. The nature of the
failure is indicated by the value of the code.
Triggering the Launch State Update using IGVM
*********************************************
To initiate the launch update process, the guest issues a standard system reset
operation through any of the means implemented by the machine model.
On a write to the ``etc/vmlaunchupdate`` interface, the hypervisor evaluates whether this
hypervisor interface is disabled. If it is, it ignores any writes to this ``fw-cfg`` file
by the guest. No updates to initial launch state is performed.
If the hypervisor interface is enabled, upon write to the ``etc/vmlaunchupdate`` interface,
the hypervisor parses the IGVM file bundle passed to it in memory, with starting guest physical
address at ``fw_image_addr`` and length ``fw_image_size``. If parsing is successful, it creates
a context handle to the IGVM file. If parsing and context loading is successful and there are no
errors, ``fw_image_addr`` and ``fw_image_size`` are cleared. The guest can check this in order
to determine if the IGVM was successfully parsed and the new context was loaded. If not, the
guest can throw error and abort rebooting to new IGVM boot state. Alternatively, the guest can
also check the ``status`` code from the ``fw-cfg`` file. A status code of 0 indicates success
of the operation. Non-zero status code indicates failure. Exact nature of the failure is
indicated by the value of the code. Currently, only two error values are supported:
* ``VM_LAUNCHUPDATE_LOAD_FAIL`` - defined as value 1 and is set when loading of the IGVM file failed.
* ``VM_LAUNCHUPDATE_NOT_IGVM_INIT`` - defined as value 2 and is set when the guest was not started with
IGVM file.
Upon guest reset, the hypervisor executes the IGVM bundle using
the context handle, setting the initial launch state of the guest accordingly.
If an invalid IGVM file is passed, parsing the file fails and the hypervisor ignores it
when ``fw-cfg`` files are written. In this case, the initial launch state
is not modified. If invalid addresses are passed, the hypervisor ignores them as well and no
new launch state is set.
The launch state update mechanism works both for confidential and non-confidential
guests. In confidential guests, as a part of the reset operation, all existing
guest shared memory (shared with the hypervisor) as well as the guest memory region
starting with ``opaque_addr`` and length ``opaque_size`` are preserved.
The reset causes recreation of the VM context which triggers a fresh
measurement of the replaced BIOS region and reset CPU state.
For non-confidential guests, there is no concept of guest private memory and all the existing
guest memory is preserved (this is the default behaviour today - QEMU does not reset/clear
guest memory upon reset).
In both confidential and non-confidential cases, CPU and device state are reset to
the reset states specified in IGVM. In confidential environments, the guest
always resumes operation in the highest privileged mode available to it (VMPL0 in SEV-SNP).
Closing Remarks
***************
The exact content of the memory region specified by starting address ``opaque_addr``
and length ``opaque_size`` is guest specific and is hypervisor agnostic. The hypervisor does
not care about the contents of this memory region. Therefore, it is not included in this
specification. As of writing this document, TDX guests on QEMU does not support IGVM.
Therefore, this mechanism cannot be used to change launch state of TDX guests.

View file

@ -188,6 +188,7 @@ the following architecture extensions:
- FEAT_SME_I16I64 (16-bit to 64-bit integer widening outer product instructions)
- FEAT_SME_LUTv2 (Lookup table instructions with 4-bit indices and 8-bit elements)
- FEAT_SME_MOP4 (Quarter-tile outer product instructions)
- FEAT_SME_TMOP (Structured sparsity outer product instructions)
- FEAT_SSVE_AES (Streaming SVE Mode Advanced Encryption Standard and 128-bit polynomial multiply long instructions)
- FEAT_SSVE_FEXPA (Streaming FEXPA instruction)
- FEAT_SSVE_FP8DOT2 (SVE2 FP8 2-way dot product to half-precision instructions in Streaming SVE mode)

View file

@ -94,16 +94,60 @@ Boot options
------------
The Nuvoton machines can boot from an OpenBMC firmware image, or directly into
a kernel using the ``-kernel`` option. OpenBMC images for ``quanta-gsj`` and
possibly others can be downloaded from the OpenBMC jenkins :
a kernel using the ``-kernel`` option. OpenBMC machine names do not always
match QEMU machine names. Check the OpenBMC supported-machine list and Jenkins
for currently available source and pre-built images.
Known OpenBMC (v2.18.0) target names for QEMU Nuvoton machines per:
https://github.com/openbmc/openbmc/blob/2.18.0/meta-phosphor/docs/supported-machines.md
.. list-table::
:header-rows: 1
* - QEMU machine
- OpenBMC machine
* - ``npcm750-evb``
- ``evb-npcm750``
* - ``npcm845-evb``
- ``evb-npcm845``
* - ``quanta-gbs-bmc``
- ``gbs``
* - ``kudo-bmc``
- ``kudo``
* - ``mori-bmc``
- ``mori``
As of June 2026, the latest OpenBMC release, ``2.18.0``, no longer lists a
``gsj`` machine. To build an image for QEMU's ``quanta-gsj`` machine, use an
older OpenBMC release that still contains ``meta-quanta/meta-gsj``. The
``2.14.0`` release contains the ``gsj`` machine:
https://github.com/openbmc/openbmc/tree/2.14.0/meta-quanta/meta-gsj
Some pre-built OpenBMC images for QEMU Nuvoton machines may be available on
Jenkins:
https://jenkins.openbmc.org/
The firmware image should be attached as an MTD drive. Example :
To find a pre-built MTD image on Jenkins, start from the Jenkins home page and
open the ``latest-master`` job. Select the matrix configuration whose
``target`` matches the OpenBMC machine name, for example
``label=docker-builder,target=gbs``, then open its latest successful build's
artifacts. The MTD image is usually published under
``openbmc/build/tmp/deploy/images/<machine>/`` as
``obmc-phosphor-image-<machine>-<timestamp>.static.mtd``. If Jenkins does not
list a matching target, or the build artifacts do not include an MTD image,
there is no current pre-built MTD image for that machine.
The firmware image should be attached as an MTD drive. Example:
.. code-block:: bash
$ qemu-system-arm -machine quanta-gsj -nographic \
-drive file=image-bmc,if=mtd,bus=0,unit=0,format=raw
$ qemu-system-arm -machine quanta-gbs-bmc -nographic \
-drive file=obmc-phosphor-image-gbs-xxxxxx.static.mtd,if=mtd,bus=0,unit=0,format=raw
The default root password for test images is usually ``0penBmc``.
For other machines that don't have pre-built images on Jenkins, build an image
from source by following the OpenBMC build documentation.

View file

@ -71,8 +71,11 @@ Existing enlightenments
by the guest when it crashes, HV_X64_MSR_CRASH_P0..HV_X64_MSR_CRASH_P5 MSRs
contain additional crash information. This information is outputted in QEMU log
and through QAPI.
Note: unlike under genuine Hyper-V, write to HV_X64_MSR_CRASH_CTL causes guest
to shutdown. This effectively blocks crash dump generation by Windows.
Note: unlike under genuine Hyper-V, write to HV_X64_MSR_CRASH_CTL triggers
``qemu_system_guest_panicked()`` via ``KVM_SYSTEM_EVENT_CRASH`` and the
resulting action depends on the ``-action panic=...`` policy (default:
``shutdown``). With the default action, this effectively blocks crash dump
generation by Windows.
``hv-time``
Enables two Hyper-V-specific clocksources available to the guest: MSR-based
@ -304,8 +307,9 @@ currently implemented Hyper-V enlightenments with the following exceptions:
``hv-version-id-snumber`` can be left unchanged, guests are not supposed to
behave differently when different Hyper-V version is presented to them.
- ``hv-crash`` must only be enabled if the crash information is consumed via
QAPI by higher levels of the virtualization stack. Enabling this feature
effectively prevents Windows from creating dumps upon crashes.
QAPI by higher levels of the virtualization stack. With the default
``-action panic=shutdown`` policy, enabling this feature effectively
prevents Windows from creating dumps upon crashes.
- ``hv-reenlightenment`` can only be used on hardware which supports TSC
scaling or when guest migration is not needed.
- ``hv-spinlocks`` should be set to e.g. 0xfff when host CPUs are overcommited

View file

@ -20,12 +20,18 @@ The ``k230`` machine supports the following devices:
* Platform-Level Interrupt Controller (PLIC)
* 2 K230 Watchdog Timer
* 5 UART
* K230 DDRC CFG and DDR PHY
* System Direct Memory Access (SDMA)
* GZIP Decompress Engine (Decomp_gzip)
Boot options
------------
The ``k230`` machine supports K230 SDK boot through M-mode U-Boot, which then
starts OpenSBI/Linux with ``bootm``. It also supports direct Linux boot.
The DDRC CFG and DDR PHY models allow the K230 SDK U-Boot SPL to complete DDR
initialization before loading the next boot stage.
K230 SDK Linux kernels use T-HEAD C9xx private MAEE page table attributes. QEMU
does not implement MAEE in the generic RISC-V MMU, so such kernels need to be
built with standard RISC-V PTE bits before they can boot under QEMU.

View file

@ -16,7 +16,7 @@ The ``virt`` machine supports the following devices:
* Core Local Interruptor (CLINT)
* Platform-Level Interrupt Controller (PLIC)
* CFI parallel NOR flash memory
* 1 NS16550 compatible UART
* Either 1 or 2 NS16550 compatible UARTs
* 1 Google Goldfish RTC
* 1 SiFive Test device
* 8 virtio-mmio transport devices
@ -27,6 +27,9 @@ The hypervisor extension has been enabled for the default CPU, so virtual
machines with hypervisor extension can simply be used without explicitly
declaring.
The second UART only exists if a backend is configured explicitly (e.g.
with a second ``-serial`` command line option).
Hardware configuration information
----------------------------------

View file

@ -133,6 +133,16 @@ an issue as a normal bug.
that affect the level 0 QEMU process. While these bugs should be
fixed, they will not be triaged as security flaws at this time.
* **migration/snapshots**. Migration failures and snapshot load
failures are considered part of normal operation as long as the
source virtual machine and savevm file, respectively, are still
functional. Aborting the QEMU process at the migration/snapshot
destination is similarly not considered a security issue. The
migration stream is assumed to be secure as long as the design
principles described in the Architecture section are held, in
which case plain manipulation of the stream is not considered as
an attack vector.
* **low severity impact**. As a catch all rule, issues which
are judged to have a "low" severity impact on the system will
usually not justify handling as security bugs, nor assignment
@ -159,10 +169,11 @@ could allow malicious guests to gain code execution in QEMU. At this point the
guest has escaped the virtual machine and is able to act in the context of the
QEMU process on the host.
Guests often interact with other guests and share resources with them. A
malicious guest must not gain control of other guests or access their data.
Disk image files and network traffic must be protected from other guests unless
explicitly shared between them by the user.
Guests often interact with other guests and share resources with them.
A malicious guest must not gain control of other guests or access
their data. Disk image files and network traffic must be protected
from other guests, users and processes unless explicitly shared with
them by the user.
Principle of Least Privilege
''''''''''''''''''''''''''''
@ -223,6 +234,9 @@ Some Linux distros already ship with UNIX groups for these devices by default.
system calls that are not needed by QEMU, thereby reducing the host kernel
attack surface.
- Transport Layer Security (TLS) protocol can be used to ensure authenticity and
encryption of the live migration connection where the network is untrusted.
Sensitive configurations
------------------------

View file

@ -865,12 +865,13 @@ ERST
.name = "nmi",
.args_type = "",
.params = "",
.help = "inject an NMI",
.help = "Inject an NMI, in a machine-specific way",
.cmd = hmp_nmi,
},
SRST
``nmi`` *cpu*
Inject an NMI on the default CPU (x86/s390) or all CPUs (ppc64).
``nmi``
Inject an NMI, in a machine-specific way.
Not all machines implement NMI handling.
ERST
{
@ -928,16 +929,17 @@ ERST
{
.name = "migrate",
.args_type = "detach:-d,resume:-r,uri:s",
.params = "[-d] [-r] uri",
.args_type = "detach:-d,resume:-r,uri-cpr:-cs,uri:s",
.params = "[-d] [-r] [-c uri-cpr] uri",
.help = "migrate to URI (using -d to not wait for completion)"
"\n\t\t\t -r to resume a paused postcopy migration",
"\n\t\t\t -r to resume a paused postcopy migration"
"\n\t\t\t -c to specify a CPR URI for cpr-transfer mode",
.cmd = hmp_migrate,
},
SRST
``migrate [-d] [-r]`` *uri*
``migrate [-d] [-r] [-c uri-cpr]`` *uri*
Migrate the VM to *uri*.
``-d``
@ -945,6 +947,9 @@ SRST
query an ongoing migration process, use "info migrate".
``-r``
Resume a paused postcopy migration.
``-c`` *uri-cpr*
Specify the CPR URI for cpr-transfer mode. It must be a UNIX domain
socket.
ERST
{

View file

@ -12,6 +12,7 @@
#define CPUINFO_AES (1u << 3)
#define CPUINFO_PMULL (1u << 4)
#define CPUINFO_BTI (1u << 5)
#define CPUINFO_CSSC (1u << 6)
/* Initialized with a constructor. */
extern unsigned cpuinfo;

View file

@ -12,6 +12,7 @@
#define CPUINFO_ZBS (1u << 3)
#define CPUINFO_ZICOND (1u << 4)
#define CPUINFO_ZVE64X (1u << 5)
#define CPUINFO_ZBKB (1u << 6)
/* Initialized with a constructor. */
extern unsigned cpuinfo;

View file

@ -55,7 +55,8 @@ enum {
P9ARRAY_DEFINE_TYPE(V9fsPath, v9fs_path_free);
static ssize_t pdu_marshal(V9fsPDU *pdu, size_t offset, const char *fmt, ...)
static ssize_t coroutine_fn
pdu_marshal(V9fsPDU *pdu, size_t offset, const char *fmt, ...)
{
ssize_t ret;
va_list ap;
@ -67,7 +68,8 @@ static ssize_t pdu_marshal(V9fsPDU *pdu, size_t offset, const char *fmt, ...)
return ret;
}
static ssize_t pdu_unmarshal(V9fsPDU *pdu, size_t offset, const char *fmt, ...)
static ssize_t coroutine_fn
pdu_unmarshal(V9fsPDU *pdu, size_t offset, const char *fmt, ...)
{
ssize_t ret;
va_list ap;
@ -1841,7 +1843,8 @@ out_nofid:
pdu_complete(pdu, err);
}
static int v9fs_walk_marshal(V9fsPDU *pdu, uint16_t nwnames, V9fsQID *qids)
static int coroutine_fn
v9fs_walk_marshal(V9fsPDU *pdu, uint16_t nwnames, V9fsQID *qids)
{
int i;
ssize_t err;
@ -2181,8 +2184,8 @@ static void coroutine_fn v9fs_open(void *opaque)
flags = omode_to_uflags(mode);
}
if (is_ro_export(&s->ctx)) {
if (mode & O_WRONLY || mode & O_RDWR ||
mode & O_APPEND || mode & O_TRUNC) {
if (flags & O_WRONLY || flags & O_RDWR ||
flags & O_APPEND || flags & O_TRUNC) {
err = -EROFS;
goto out;
}
@ -2363,9 +2366,10 @@ out_nofid:
* The resulting QEMUIOVector has heap-allocated iovecs and must be cleaned up
* with qemu_iovec_destroy().
*/
static void v9fs_init_qiov_from_pdu(QEMUIOVector *qiov, V9fsPDU *pdu,
size_t skip, size_t size,
bool is_write)
static void coroutine_fn
v9fs_init_qiov_from_pdu(QEMUIOVector *qiov, V9fsPDU *pdu,
size_t skip, size_t size,
bool is_write)
{
QEMUIOVector elem;
struct iovec *iov;
@ -2382,8 +2386,9 @@ static void v9fs_init_qiov_from_pdu(QEMUIOVector *qiov, V9fsPDU *pdu,
qemu_iovec_concat(qiov, &elem, skip, size);
}
static int v9fs_xattr_read(V9fsState *s, V9fsPDU *pdu, V9fsFidState *fidp,
uint64_t off, uint32_t max_count)
static int coroutine_fn
v9fs_xattr_read(V9fsState *s, V9fsPDU *pdu, V9fsFidState *fidp,
uint64_t off, uint32_t max_count)
{
ssize_t err;
size_t offset = 7;
@ -2793,9 +2798,10 @@ out_nofid:
pdu_complete(pdu, retval);
}
static int v9fs_xattr_write(V9fsState *s, V9fsPDU *pdu, V9fsFidState *fidp,
uint64_t off, uint32_t count,
struct iovec *sg, int cnt)
static int coroutine_fn
v9fs_xattr_write(V9fsState *s, V9fsPDU *pdu, V9fsFidState *fidp,
uint64_t off, uint32_t count,
struct iovec *sg, int cnt)
{
int i, to_copy;
ssize_t err = 0;
@ -3729,7 +3735,8 @@ out_nofid:
pdu_complete(pdu, err);
}
static int v9fs_fill_statfs(V9fsState *s, V9fsPDU *pdu, struct statfs *stbuf)
static int coroutine_fn
v9fs_fill_statfs(V9fsState *s, V9fsPDU *pdu, struct statfs *stbuf)
{
uint32_t f_type;
uint32_t f_bsize;
@ -4530,6 +4537,7 @@ void v9fs_device_unrealize_common(V9fsState *s)
qp_table_destroy(&s->qpp_table);
qp_table_destroy(&s->qpf_table);
g_free(s->ctx.fs_root);
s->transport = NULL;
}
typedef struct VirtfsCoResetData {

View file

@ -472,17 +472,21 @@ void pdu_submit(V9fsPDU *pdu, P9MsgHeader *hdr);
void v9fs_reset(V9fsState *s);
struct V9fsTransport {
ssize_t (*pdu_vmarshal)(V9fsPDU *pdu, size_t offset, const char *fmt,
va_list ap);
ssize_t (*pdu_vunmarshal)(V9fsPDU *pdu, size_t offset, const char *fmt,
va_list ap);
void (*init_in_iov_from_pdu)(V9fsPDU *pdu, struct iovec **piov,
unsigned int *pniov, size_t size);
void (*init_out_iov_from_pdu)(V9fsPDU *pdu, struct iovec **piov,
unsigned int *pniov, size_t size);
void (*push_and_notify)(V9fsPDU *pdu);
size_t (*msize_limit)(V9fsState *s);
size_t (*response_buffer_size)(V9fsPDU *pdu);
ssize_t coroutine_fn (*pdu_vmarshal)(V9fsPDU *pdu, size_t offset,
const char *fmt, va_list ap);
ssize_t coroutine_fn (*pdu_vunmarshal)(V9fsPDU *pdu, size_t offset,
const char *fmt, va_list ap);
void coroutine_fn (*init_in_iov_from_pdu)(V9fsPDU *pdu,
struct iovec **piov,
unsigned int *pniov,
size_t size);
void coroutine_fn (*init_out_iov_from_pdu)(V9fsPDU *pdu,
struct iovec **piov,
unsigned int *pniov,
size_t size);
void coroutine_fn (*push_and_notify)(V9fsPDU *pdu);
size_t coroutine_fn (*msize_limit)(V9fsState *s);
size_t coroutine_fn (*response_buffer_size)(V9fsPDU *pdu);
};
#endif

View file

@ -28,7 +28,7 @@
#include "qemu/module.h"
#include "system/qtest.h"
static void virtio_9p_push_and_notify(V9fsPDU *pdu)
static void coroutine_fn virtio_9p_push_and_notify(V9fsPDU *pdu)
{
V9fsState *s = pdu->s;
V9fsVirtioState *v = container_of(s, V9fsVirtioState, state);
@ -117,8 +117,8 @@ static void virtio_9p_reset(VirtIODevice *vdev)
v9fs_reset(&v->state);
}
static ssize_t virtio_pdu_vmarshal(V9fsPDU *pdu, size_t offset,
const char *fmt, va_list ap)
static ssize_t coroutine_fn
virtio_pdu_vmarshal(V9fsPDU *pdu, size_t offset, const char *fmt, va_list ap)
{
V9fsState *s = pdu->s;
V9fsVirtioState *v = container_of(s, V9fsVirtioState, state);
@ -135,8 +135,8 @@ static ssize_t virtio_pdu_vmarshal(V9fsPDU *pdu, size_t offset,
return ret;
}
static ssize_t virtio_pdu_vunmarshal(V9fsPDU *pdu, size_t offset,
const char *fmt, va_list ap)
static ssize_t coroutine_fn
virtio_pdu_vunmarshal(V9fsPDU *pdu, size_t offset, const char *fmt, va_list ap)
{
V9fsState *s = pdu->s;
V9fsVirtioState *v = container_of(s, V9fsVirtioState, state);
@ -152,8 +152,9 @@ static ssize_t virtio_pdu_vunmarshal(V9fsPDU *pdu, size_t offset,
return ret;
}
static void virtio_init_in_iov_from_pdu(V9fsPDU *pdu, struct iovec **piov,
unsigned int *pniov, size_t size)
static void coroutine_fn
virtio_init_in_iov_from_pdu(V9fsPDU *pdu, struct iovec **piov,
unsigned int *pniov, size_t size)
{
V9fsState *s = pdu->s;
V9fsVirtioState *v = container_of(s, V9fsVirtioState, state);
@ -172,8 +173,9 @@ static void virtio_init_in_iov_from_pdu(V9fsPDU *pdu, struct iovec **piov,
*pniov = elem->in_num;
}
static void virtio_init_out_iov_from_pdu(V9fsPDU *pdu, struct iovec **piov,
unsigned int *pniov, size_t size)
static void coroutine_fn
virtio_init_out_iov_from_pdu(V9fsPDU *pdu, struct iovec **piov,
unsigned int *pniov, size_t size)
{
V9fsState *s = pdu->s;
V9fsVirtioState *v = container_of(s, V9fsVirtioState, state);
@ -192,13 +194,13 @@ static void virtio_init_out_iov_from_pdu(V9fsPDU *pdu, struct iovec **piov,
*pniov = elem->out_num;
}
static size_t virtio_9p_msize_limit(V9fsState *s)
static size_t coroutine_fn virtio_9p_msize_limit(V9fsState *s)
{
const size_t guestPageSize = 4096;
return (VIRTQUEUE_MAX_SIZE - 2) * guestPageSize;
}
static size_t virtio_9p_response_buffer_size(V9fsPDU *pdu)
static size_t coroutine_fn virtio_9p_response_buffer_size(V9fsPDU *pdu)
{
V9fsState *s = pdu->s;
V9fsVirtioState *v = container_of(s, V9fsVirtioState, state);
@ -243,6 +245,7 @@ static void virtio_9p_device_unrealize(DeviceState *dev)
V9fsVirtioState *v = VIRTIO_9P(dev);
V9fsState *s = &v->state;
v9fs_reset(s); /* cancel all in-flight PDUs to prevent UAF */
virtio_delete_queue(v->vq);
virtio_cleanup(vdev);
v9fs_device_unrealize_common(s);

View file

@ -68,6 +68,11 @@ typedef struct Xen9pfsDev {
static void xen_9pfs_disconnect(struct XenLegacyDevice *xendev);
static void xen_9pfs_disconnect_bh(void *opaque)
{
xen_9pfs_disconnect(opaque);
}
static void xen_9pfs_in_sg(Xen9pfsRing *ring,
struct iovec *in_sg,
int *num,
@ -131,10 +136,10 @@ static void xen_9pfs_out_sg(Xen9pfsRing *ring,
}
}
static ssize_t xen_9pfs_pdu_vmarshal(V9fsPDU *pdu,
size_t offset,
const char *fmt,
va_list ap)
static ssize_t coroutine_fn xen_9pfs_pdu_vmarshal(V9fsPDU *pdu,
size_t offset,
const char *fmt,
va_list ap)
{
Xen9pfsDev *xen_9pfs = container_of(pdu->s, Xen9pfsDev, state);
struct iovec in_sg[2];
@ -150,15 +155,16 @@ static ssize_t xen_9pfs_pdu_vmarshal(V9fsPDU *pdu,
"Failed to encode VirtFS reply type %d\n",
pdu->id + 1);
xen_be_set_state(&xen_9pfs->xendev, XenbusStateClosing);
xen_9pfs_disconnect(&xen_9pfs->xendev);
aio_bh_schedule_oneshot(qemu_get_aio_context(),
xen_9pfs_disconnect_bh, &xen_9pfs->xendev);
}
return ret;
}
static ssize_t xen_9pfs_pdu_vunmarshal(V9fsPDU *pdu,
size_t offset,
const char *fmt,
va_list ap)
static ssize_t coroutine_fn xen_9pfs_pdu_vunmarshal(V9fsPDU *pdu,
size_t offset,
const char *fmt,
va_list ap)
{
Xen9pfsDev *xen_9pfs = container_of(pdu->s, Xen9pfsDev, state);
struct iovec out_sg[2];
@ -173,15 +179,16 @@ static ssize_t xen_9pfs_pdu_vunmarshal(V9fsPDU *pdu,
xen_pv_printf(&xen_9pfs->xendev, 0,
"Failed to decode VirtFS request type %d\n", pdu->id);
xen_be_set_state(&xen_9pfs->xendev, XenbusStateClosing);
xen_9pfs_disconnect(&xen_9pfs->xendev);
aio_bh_schedule_oneshot(qemu_get_aio_context(),
xen_9pfs_disconnect_bh, &xen_9pfs->xendev);
}
return ret;
}
static void xen_9pfs_init_out_iov_from_pdu(V9fsPDU *pdu,
struct iovec **piov,
unsigned int *pniov,
size_t size)
static void coroutine_fn xen_9pfs_init_out_iov_from_pdu(V9fsPDU *pdu,
struct iovec **piov,
unsigned int *pniov,
size_t size)
{
Xen9pfsDev *xen_9pfs = container_of(pdu->s, Xen9pfsDev, state);
Xen9pfsRing *ring = &xen_9pfs->rings[pdu->tag % xen_9pfs->num_rings];
@ -195,10 +202,10 @@ static void xen_9pfs_init_out_iov_from_pdu(V9fsPDU *pdu,
*pniov = num;
}
static void xen_9pfs_init_in_iov_from_pdu(V9fsPDU *pdu,
struct iovec **piov,
unsigned int *pniov,
size_t size)
static void coroutine_fn xen_9pfs_init_in_iov_from_pdu(V9fsPDU *pdu,
struct iovec **piov,
unsigned int *pniov,
size_t size)
{
Xen9pfsDev *xen_9pfs = container_of(pdu->s, Xen9pfsDev, state);
Xen9pfsRing *ring = &xen_9pfs->rings[pdu->tag % xen_9pfs->num_rings];
@ -227,7 +234,7 @@ again:
*pniov = num;
}
static void xen_9pfs_push_and_notify(V9fsPDU *pdu)
static void coroutine_fn xen_9pfs_push_and_notify(V9fsPDU *pdu)
{
RING_IDX prod;
Xen9pfsDev *priv = container_of(pdu->s, Xen9pfsDev, state);
@ -368,10 +375,16 @@ static void xen_9pfs_evtchn_event(void *opaque)
static void xen_9pfs_disconnect(struct XenLegacyDevice *xendev)
{
Xen9pfsDev *xen_9pdev = container_of(xendev, Xen9pfsDev, xendev);
V9fsState *s = &xen_9pdev->state;
int i;
trace_xen_9pfs_disconnect(xendev->name);
if (s->transport) {
v9fs_reset(s); /* cancel all in-flight PDUs to prevent UAF */
v9fs_device_unrealize_common(s);
}
for (i = 0; i < xen_9pdev->num_rings; i++) {
if (xen_9pdev->rings[i].evtchndev != NULL) {
qemu_set_fd_handler(qemu_xen_evtchn_fd(xen_9pdev->rings[i].evtchndev),

View file

@ -533,7 +533,9 @@ config ASPEED_SOC
bool
default y
depends on TCG && ARM
imply GENERIC_LOADER
imply PCI_DEVICES
imply E1000E_PCI_EXPRESS
select DS1338
select FTGMAC100
select I2C
@ -551,14 +553,17 @@ config ASPEED_SOC
select TMP105
select TMP421
select EMC141X
select OR_IRQ
select UNIMP
select LED
select PMBUS
select MAX31785
select ADC128D818
select FSI_APB2OPB_ASPEED
select AT24C
select PCI_EXPRESS
select PCI_EXPRESS_ASPEED
select USB_EHCI_SYSBUS
select SDHCI
config MPS2
bool
@ -725,3 +730,18 @@ config ARMSSE
select UNIMP
select SSE_COUNTER
select SSE_TIMER
config AXIADO_SOC
bool
select ARM_GIC
select CADENCE # UART
select AXIADO_CLK
select CADENCE_GPIO
select AXIADO_SDHCI
select UNIMP
config AXIADO_EVK
bool
default y
depends on TCG && ARM
select AXIADO_SOC

View file

@ -409,7 +409,7 @@ static const ARMSSEDeviceInfo sse300_devices[] = {
.name = "s32kwatchdog",
.type = TYPE_CMSDK_APB_WATCHDOG,
.index = 0,
.addr = 0x4802e000,
.addr = 0x5802e000,
.ppc = NO_PPC,
.irq = NMI_0,
.slowclk = true,
@ -452,7 +452,7 @@ static const ARMSSEDeviceInfo sse300_devices[] = {
.name = "CPU0CORE_PPU",
.type = TYPE_UNIMPLEMENTED_DEVICE,
.index = 2,
.addr = 0x50023000,
.addr = 0x58023000,
.size = 0x1000,
.ppc = NO_PPC,
.irq = NO_IRQ,
@ -461,7 +461,7 @@ static const ARMSSEDeviceInfo sse300_devices[] = {
.name = "MGMT_PPU",
.type = TYPE_UNIMPLEMENTED_DEVICE,
.index = 3,
.addr = 0x50028000,
.addr = 0x58028000,
.size = 0x1000,
.ppc = NO_PPC,
.irq = NO_IRQ,
@ -470,7 +470,7 @@ static const ARMSSEDeviceInfo sse300_devices[] = {
.name = "DEBUG_PPU",
.type = TYPE_UNIMPLEMENTED_DEVICE,
.index = 4,
.addr = 0x50029000,
.addr = 0x58029000,
.size = 0x1000,
.ppc = NO_PPC,
.irq = NO_IRQ,

View file

@ -24,10 +24,6 @@
#include "hw/core/qdev-clock.h"
#include "system/system.h"
static struct arm_boot_info aspeed_board_binfo = {
.board_id = -1, /* device-tree-only board */
};
#define AST_SMP_MAILBOX_BASE 0x1e6e2180
#define AST_SMP_MBOX_FIELD_ENTRY (AST_SMP_MAILBOX_BASE + 0x0)
#define AST_SMP_MBOX_FIELD_GOSIGN (AST_SMP_MAILBOX_BASE + 0x4)
@ -206,13 +202,14 @@ static void aspeed_machine_init(MachineState *machine)
memory_region_add_subregion(get_system_memory(),
AST_SMP_MAILBOX_BASE, smpboot);
aspeed_board_binfo.write_secondary_boot = aspeed_write_smpboot;
aspeed_board_binfo.secondary_cpu_reset_hook = aspeed_reset_secondary;
aspeed_board_binfo.smp_loader_start = AST_SMP_MBOX_CODE;
bmc->bootinfo.write_secondary_boot = aspeed_write_smpboot;
bmc->bootinfo.secondary_cpu_reset_hook = aspeed_reset_secondary;
bmc->bootinfo.smp_loader_start = AST_SMP_MBOX_CODE;
}
aspeed_board_binfo.ram_size = machine->ram_size;
aspeed_board_binfo.loader_start = sc->memmap[ASPEED_DEV_SDRAM];
bmc->bootinfo.board_id = -1; /* device-tree-only board */
bmc->bootinfo.ram_size = machine->ram_size;
bmc->bootinfo.loader_start = sc->memmap[ASPEED_DEV_SDRAM];
if (amc->i2c_init) {
amc->i2c_init(bmc);
@ -248,7 +245,7 @@ static void aspeed_machine_init(MachineState *machine)
aspeed_load_vbootrom(bmc->soc, bios_name, &error_abort);
}
arm_load_kernel(ARM_CPU(first_cpu), machine, &aspeed_board_binfo);
arm_load_kernel(ARM_CPU(first_cpu), machine, &bmc->bootinfo);
}
void aspeed_create_pca9552(AspeedSoCState *soc, int bus_id, int addr)
@ -327,7 +324,7 @@ static void aspeed_set_bmc_console(Object *obj, const char *value, Error **errp)
int uart_first = aspeed_uart_first(sc->uarts_base);
int uart_last = aspeed_uart_last(sc->uarts_base, sc->uarts_num);
if (sscanf(value, "uart%u", &val) != 1) {
if (sscanf(value, "uart%d", &val) != 1 || val < 0) {
error_setg(errp, "Bad value for \"uart\" property");
return;
}

View file

@ -1,13 +1,14 @@
/*
* Facebook Anacapa
*
* Copyright (c) Meta Platforms, Inc. and affiliates.
* Copyright (c) 2026 Meta Platforms, Inc. and affiliates.
*
* SPDX-License-Identifier: GPL-2.0-or-later
*/
#include "qemu/osdep.h"
#include "qapi/error.h"
#include "hw/sensor/adc128d818.h"
#include "hw/arm/machines-qom.h"
#include "hw/arm/aspeed.h"
#include "hw/arm/aspeed_soc.h"
@ -15,7 +16,6 @@
#include "hw/gpio/pca9552.h"
#include "hw/nvram/eeprom_at24c.h"
/* Anacapa hardware value */
#define ANACAPA_BMC_HW_STRAP1 0x00002002
#define ANACAPA_BMC_HW_STRAP2 0x00000000
#define ANACAPA_BMC_RAM_SIZE ASPEED_RAM_SIZE(2 * GiB)
@ -221,6 +221,17 @@ static const uint8_t hpm_brd_id_eeprom[] = {
};
static const size_t hpm_brd_id_eeprom_len = sizeof(hpm_brd_id_eeprom);
static void anacapa_add_adc128d818(I2CBus *bus, uint8_t addr,
const char *description)
{
DeviceState *dev = DEVICE(i2c_slave_new(TYPE_ADC128D818, addr));
g_autofree char *childname = g_strdup_printf("0x%02x", addr);
qdev_prop_set_string(dev, "description", description);
object_property_add_child(OBJECT(bus), childname, OBJECT(dev));
i2c_slave_realize_and_unref(I2C_SLAVE(dev), bus, &error_fatal);
}
static void anacapa_bmc_i2c_init(AspeedMachineState *bmc)
{
/* Reference: aspeed-bmc-facebook-anacapa.dts */
@ -242,7 +253,7 @@ static void anacapa_bmc_i2c_init(AspeedMachineState *bmc)
/* &i2c1 */
/* eeprom@50 */
at24c_eeprom_init(i2c[1], 0x50, 256 * KiB);
/* i2c-mux@70 (PCA9546) 4 channels, empty */
/* i2c-mux@70 (PCA9546) - 4 channels, empty */
i2c_slave_create_simple(i2c[1], TYPE_PCA9546, 0x70);
/* &i2c4 */
@ -259,7 +270,8 @@ static void anacapa_bmc_i2c_init(AspeedMachineState *bmc)
i2c_mux = i2c_slave_create_simple(i2c[8], TYPE_PCA9546, 0x72);
/* i2c8mux ch0 */
/* adc128d818@1f — no model */
/* adc128d818@1f - R-PDB ADC (mode 1: 8 voltage channels) */
anacapa_add_adc128d818(pca954x_i2c_get_bus(i2c_mux, 0), 0x1f, "i2c8:0:1f");
/* pca9555@22 */
i2c_slave_create_simple(pca954x_i2c_get_bus(i2c_mux, 0),
TYPE_PCA9552, 0x22);
@ -305,7 +317,7 @@ static void anacapa_bmc_i2c_init(AspeedMachineState *bmc)
/* i2c-mux@71 (PCA9548) */
i2c_mux = i2c_slave_create_simple(i2c[11], TYPE_PCA9548, 0x71);
/* i2c11mux ch0-ch4 empty */
/* i2c11mux ch0-ch4 - empty */
/* i2c11mux ch5 */
/* pca9555@22 */
@ -320,7 +332,8 @@ static void anacapa_bmc_i2c_init(AspeedMachineState *bmc)
i2c_mux = i2c_slave_create_simple(i2c[13], TYPE_PCA9548, 0x70);
/* i2c13mux ch3 */
/* adc128d818@1f - no model */
/* adc128d818@1f - MB ADC (mode 1: 8 voltage channels) */
anacapa_add_adc128d818(pca954x_i2c_get_bus(i2c_mux, 3), 0x1f, "i2c13:3:1f");
/* i2c13mux ch4 */
/* eeprom@51 */
@ -328,7 +341,7 @@ static void anacapa_bmc_i2c_init(AspeedMachineState *bmc)
hpm_brd_id_eeprom, hpm_brd_id_eeprom_len);
/* i2c13mux ch7 */
/* nfc@28 no model */
/* nfc@28 - no model */
}
static void aspeed_machine_anacapa_class_init(ObjectClass *oc,

View file

@ -472,7 +472,16 @@ static void catalina_bmc_i2c_init(AspeedMachineState *bmc)
/* &i2c0 */
/* i2c-mux@71 (PCA9546) on i2c0 */
i2c_slave_create_simple(i2c[0], TYPE_PCA9546, 0x71);
i2c_mux = i2c_slave_create_simple(i2c[0], TYPE_PCA9546, 0x71);
/* i2c0mux0ch0 */
/* IOB0 NIC0 temperature-sensor@1f - tmp421 */
i2c_slave_create_simple(pca954x_i2c_get_bus(i2c_mux, 0),
TYPE_TMP421, 0x1f);
/* i2c0mux0ch2 */
/* IOB0 NIC1 temperature-sensor@1f - tmp421 */
i2c_slave_create_simple(pca954x_i2c_get_bus(i2c_mux, 2),
TYPE_TMP421, 0x1f);
/* i2c-mux@72 (PCA9546) on i2c0 */
i2c_mux = i2c_slave_create_simple(i2c[0], TYPE_PCA9546, 0x72);
@ -489,7 +498,16 @@ static void catalina_bmc_i2c_init(AspeedMachineState *bmc)
i2c_slave_create_simple(i2c[0], TYPE_PCA9546, 0x73);
/* i2c-mux@75 (PCA9546) on i2c0 */
i2c_slave_create_simple(i2c[0], TYPE_PCA9546, 0x75);
i2c_mux = i2c_slave_create_simple(i2c[0], TYPE_PCA9546, 0x75);
/* i2c0mux3ch0 */
/* IOB1 NIC0 temperature-sensor@1f - tmp421 */
i2c_slave_create_simple(pca954x_i2c_get_bus(i2c_mux, 0),
TYPE_TMP421, 0x1f);
/* i2c0mux3ch2 */
/* IOB1 NIC1 temperature-sensor@1f - tmp421 */
i2c_slave_create_simple(pca954x_i2c_get_bus(i2c_mux, 2),
TYPE_TMP421, 0x1f);
/* i2c-mux@76 (PCA9546) on i2c0 */
i2c_mux = i2c_slave_create_simple(i2c[0], TYPE_PCA9546, 0x76);
@ -533,7 +551,7 @@ static void catalina_bmc_i2c_init(AspeedMachineState *bmc)
TYPE_PCA9554, 0x27);
/* io_expander6 - pca9555@25 */
i2c_slave_create_simple(pca954x_i2c_get_bus(i2c_mux, 6),
TYPE_PCA9552, 0x25);
TYPE_PCA9555, 0x25);
/* eeprom@51 */
at24c_eeprom_init_rom(pca954x_i2c_get_bus(i2c_mux, 6), 0x51, 8 * KiB,
osfp_eeprom, osfp_eeprom_len);
@ -544,14 +562,16 @@ static void catalina_bmc_i2c_init(AspeedMachineState *bmc)
fio_eeprom, fio_eeprom_len);
/* temperature-sensor@4b - tmp75 */
i2c_slave_create_simple(pca954x_i2c_get_bus(i2c_mux, 7), TYPE_TMP75, 0x4b);
/* temperature-sensor@4f - tmp75 (FIO remote) */
i2c_slave_create_simple(pca954x_i2c_get_bus(i2c_mux, 7), TYPE_TMP75, 0x4f);
/* &i2c2 */
/* io_expander0 - pca9555@20 */
i2c_slave_create_simple(i2c[2], TYPE_PCA9552, 0x20);
i2c_slave_create_simple(i2c[2], TYPE_PCA9555, 0x20);
/* io_expander0 - pca9555@21 */
i2c_slave_create_simple(i2c[2], TYPE_PCA9552, 0x21);
i2c_slave_create_simple(i2c[2], TYPE_PCA9555, 0x21);
/* io_expander0 - pca9555@27 */
i2c_slave_create_simple(i2c[2], TYPE_PCA9552, 0x27);
i2c_slave_create_simple(i2c[2], TYPE_PCA9555, 0x27);
/* eeprom@50 */
at24c_eeprom_init(i2c[2], 0x50, 8 * KiB);
/* eeprom@51 */
@ -564,21 +584,17 @@ static void catalina_bmc_i2c_init(AspeedMachineState *bmc)
/* eeprom@52 */
at24c_eeprom_init_rom(pca954x_i2c_get_bus(i2c_mux, 6), 0x52, 8 * KiB,
hdd_eeprom, hdd_eeprom_len);
/* i2c5mux0ch7 */
/* ina230@40 - no model */
/* ina230@41 - no model */
/* ina230@44 - no model */
/* ina230@45 - no model */
/* i2c5mux0ch7 - empty */
/* &i2c6 */
/* io_expander3 - pca9555@21 */
i2c_slave_create_simple(i2c[6], TYPE_PCA9552, 0x21);
i2c_slave_create_simple(i2c[6], TYPE_PCA9555, 0x21);
/* rtc@6f - nct3018y */
i2c_slave_create_simple(i2c[6], TYPE_DS1338, 0x6f);
/* &i2c9 */
/* io_expander4 - pca9555@4f */
i2c_slave_create_simple(i2c[9], TYPE_PCA9552, 0x4f);
i2c_slave_create_simple(i2c[9], TYPE_PCA9555, 0x4f);
/* temperature-sensor@4b - tpm75 */
i2c_slave_create_simple(i2c[9], TYPE_TMP75, 0x4b);
/* eeprom@50 */
@ -615,17 +631,17 @@ static void catalina_bmc_i2c_init(AspeedMachineState *bmc)
/* &i2c14 */
/* io_expander9 - pca9555@10 */
i2c_slave_create_simple(i2c[14], TYPE_PCA9552, 0x10);
i2c_slave_create_simple(i2c[14], TYPE_PCA9555, 0x10);
/* io_expander10 - pca9555@11 */
i2c_slave_create_simple(i2c[14], TYPE_PCA9552, 0x11);
i2c_slave_create_simple(i2c[14], TYPE_PCA9555, 0x11);
/* io_expander11 - pca9555@12 */
i2c_slave_create_simple(i2c[14], TYPE_PCA9552, 0x12);
i2c_slave_create_simple(i2c[14], TYPE_PCA9555, 0x12);
/* io_expander12 - pca9555@13 */
i2c_slave_create_simple(i2c[14], TYPE_PCA9552, 0x13);
i2c_slave_create_simple(i2c[14], TYPE_PCA9555, 0x13);
/* io_expander13 - pca9555@14 */
i2c_slave_create_simple(i2c[14], TYPE_PCA9552, 0x14);
i2c_slave_create_simple(i2c[14], TYPE_PCA9555, 0x14);
/* io_expander14 - pca9555@15 */
i2c_slave_create_simple(i2c[14], TYPE_PCA9552, 0x15);
i2c_slave_create_simple(i2c[14], TYPE_PCA9555, 0x15);
/* &i2c15 */
/* temperature-sensor@1f - tmp421 */

View file

@ -27,10 +27,6 @@
#define TYPE_AST2700FC MACHINE_TYPE_NAME("ast2700fc")
OBJECT_DECLARE_SIMPLE_TYPE(Ast2700FCState, AST2700FC);
static struct arm_boot_info ast2700fc_board_info = {
.board_id = -1, /* device-tree-only board */
};
struct Ast2700FCState {
MachineState parent_obj;
@ -46,6 +42,8 @@ struct Ast2700FCState {
Aspeed27x0SoCState ca35;
Aspeed27x0CoprocessorState ssp;
Aspeed27x0CoprocessorState tsp;
struct arm_boot_info bootinfo;
};
#define AST2700FC_BMC_RAM_SIZE (2 * GiB)
@ -114,8 +112,9 @@ static bool ast2700fc_ca35_init(MachineState *machine, Error **errp)
aspeed_board_init_flashes(&soc->fmc, AST2700FC_FMC_MODEL, 2, 0);
aspeed_board_init_flashes(&soc->spi[0], AST2700FC_SPI_MODEL, 1, 2);
ast2700fc_board_info.ram_size = machine->ram_size;
ast2700fc_board_info.loader_start = sc->memmap[ASPEED_DEV_SDRAM];
s->bootinfo.ram_size = machine->ram_size;
s->bootinfo.loader_start = sc->memmap[ASPEED_DEV_SDRAM];
s->bootinfo.board_id = -1; /* device-tree-only board */
dev = ssi_get_cs(soc->fmc.spi, 0);
fmc0 = dev ? m25p80_get_blk(dev) : NULL;
@ -129,16 +128,14 @@ static bool ast2700fc_ca35_init(MachineState *machine, Error **errp)
bios_name = machine->firmware ?: VBOOTROM_FILE_NAME;
aspeed_load_vbootrom(soc, bios_name, errp);
arm_load_kernel(ARM_CPU(first_cpu), machine, &ast2700fc_board_info);
arm_load_kernel(ARM_CPU(first_cpu), machine, &s->bootinfo);
return true;
}
static bool ast2700fc_ssp_init(MachineState *machine, Error **errp)
static bool ast2700fc_ssp_init(Ast2700FCState *s, AspeedSoCState *psp,
Error **errp)
{
Ast2700FCState *s = AST2700FC(machine);
AspeedSoCState *psp = ASPEED_SOC(&s->ca35);
s->ssp_sysclk = clock_new(OBJECT(s), "SSP_SYSCLK");
clock_set_hz(s->ssp_sysclk, 200000000ULL);
@ -158,7 +155,11 @@ static bool ast2700fc_ssp_init(MachineState *machine, Error **errp)
object_property_set_link(OBJECT(&s->ssp), "sram",
OBJECT(&psp->sram), &error_abort);
object_property_set_link(OBJECT(&s->ssp), "scu",
OBJECT(&psp->scu), &error_abort);
OBJECT(&s->ca35.scu), &error_abort);
object_property_set_link(OBJECT(&s->ssp), "scuio",
OBJECT(&psp->scuio), &error_abort);
object_property_set_link(OBJECT(&s->ssp), "fmc",
OBJECT(&psp->fmc), &error_abort);
if (!qdev_realize(DEVICE(&s->ssp), NULL, errp)) {
return false;
}
@ -166,11 +167,9 @@ static bool ast2700fc_ssp_init(MachineState *machine, Error **errp)
return true;
}
static bool ast2700fc_tsp_init(MachineState *machine, Error **errp)
static bool ast2700fc_tsp_init(Ast2700FCState *s, AspeedSoCState *psp,
Error **errp)
{
Ast2700FCState *s = AST2700FC(machine);
AspeedSoCState *psp = ASPEED_SOC(&s->ca35);
s->tsp_sysclk = clock_new(OBJECT(s), "TSP_SYSCLK");
clock_set_hz(s->tsp_sysclk, 200000000ULL);
@ -190,7 +189,11 @@ static bool ast2700fc_tsp_init(MachineState *machine, Error **errp)
object_property_set_link(OBJECT(&s->tsp), "sram",
OBJECT(&psp->sram), &error_abort);
object_property_set_link(OBJECT(&s->tsp), "scu",
OBJECT(&psp->scu), &error_abort);
OBJECT(&s->ca35.scu), &error_abort);
object_property_set_link(OBJECT(&s->tsp), "scuio",
OBJECT(&psp->scuio), &error_abort);
object_property_set_link(OBJECT(&s->tsp), "fmc",
OBJECT(&psp->fmc), &error_abort);
if (!qdev_realize(DEVICE(&s->tsp), NULL, errp)) {
return false;
}
@ -200,9 +203,19 @@ static bool ast2700fc_tsp_init(MachineState *machine, Error **errp)
static void ast2700fc_init(MachineState *machine)
{
Ast2700FCState *s = AST2700FC(machine);
AspeedSoCState *psp;
ast2700fc_ca35_init(machine, &error_abort);
ast2700fc_ssp_init(machine, &error_abort);
ast2700fc_tsp_init(machine, &error_abort);
/*
* SSP and TSP use resources owned by the PSP SoC, such as UART,
* SRAM, SCU and SCUIO. Therefore the PSP SoC must be realized
* before the coprocessors are initialized.
*/
psp = ASPEED_SOC(&s->ca35);
ast2700fc_ssp_init(s, psp, &error_abort);
ast2700fc_tsp_init(s, psp, &error_abort);
}
static void ast2700fc_class_init(ObjectClass *oc, const void *data)

View file

@ -27,6 +27,7 @@ static const hwaddr aspeed_soc_ast27x0ssp_memmap[] = {
[ASPEED_DEV_TIMER1] = 0x72C10000,
[ASPEED_DEV_UART4] = 0x72C1A000,
[ASPEED_DEV_IPC0] = 0x72C1C000,
[ASPEED_DEV_FMC] = 0x74000000,
[ASPEED_DEV_PRIC1] = 0x74100000,
[ASPEED_DEV_SCUIO] = 0x74C02000,
[ASPEED_DEV_OTP] = 0x74C07000,
@ -142,8 +143,6 @@ static void aspeed_soc_ast27x0ssp_init(Object *obj)
TYPE_UNIMPLEMENTED_DEVICE);
object_initialize_child(obj, "ipc1", &a->ipc[1],
TYPE_UNIMPLEMENTED_DEVICE);
object_initialize_child(obj, "scuio", &a->scuio,
TYPE_UNIMPLEMENTED_DEVICE);
object_initialize_child(obj, "pric0", &a->pric[0],
TYPE_UNIMPLEMENTED_DEVICE);
object_initialize_child(obj, "pric1", &a->pric[1],
@ -167,6 +166,24 @@ static void aspeed_soc_ast27x0ssp_realize(DeviceState *dev_soc, Error **errp)
return;
}
if (!a->scu) {
error_setg(errp, TYPE_ASPEED27X0SSP_COPROCESSOR
": 'scu' link is not set");
return;
}
if (!a->scuio) {
error_setg(errp, TYPE_ASPEED27X0SSP_COPROCESSOR
": 'scuio' link is not set");
return;
}
if (!a->fmc) {
error_setg(errp, TYPE_ASPEED27X0SSP_COPROCESSOR
": 'fmc' link is not set");
return;
}
/* AST27X0 SSP Core */
armv7m = DEVICE(&a->armv7m);
qdev_prop_set_uint32(armv7m, "num-irq", 256);
@ -195,11 +212,18 @@ static void aspeed_soc_ast27x0ssp_realize(DeviceState *dev_soc, Error **errp)
&s->sram_alias);
/* SCU */
memory_region_init_alias(&s->scu_alias, OBJECT(s), "scu.alias",
&s->scu->iomem, 0,
memory_region_size(&s->scu->iomem));
memory_region_init_alias(&a->scu_alias, OBJECT(a), "scu.alias",
&a->scu->parent_obj.iomem, 0,
memory_region_size(&a->scu->parent_obj.iomem));
memory_region_add_subregion(s->memory, sc->memmap[ASPEED_DEV_SCU],
&s->scu_alias);
&a->scu_alias);
/* SCUIO */
memory_region_init_alias(&a->scuio_alias, OBJECT(a), "scuio.alias",
&a->scuio->iomem, 0,
memory_region_size(&a->scuio->iomem));
memory_region_add_subregion(s->memory, sc->memmap[ASPEED_DEV_SCUIO],
&a->scuio_alias);
/* INTC */
if (!sysbus_realize(SYS_BUS_DEVICE(&a->intc[0]), errp)) {
@ -252,6 +276,13 @@ static void aspeed_soc_ast27x0ssp_realize(DeviceState *dev_soc, Error **errp)
sysbus_connect_irq(SYS_BUS_DEVICE(s->uart), 0,
aspeed_soc_ast27x0ssp_get_irq(s, s->uart_dev));
/* FMC */
memory_region_init_alias(&a->fmc_alias, OBJECT(a), "fmc.alias",
&a->fmc->mmio, 0,
memory_region_size(&a->fmc->mmio));
memory_region_add_subregion(s->memory, sc->memmap[ASPEED_DEV_FMC],
&a->fmc_alias);
aspeed_mmio_map_unimplemented(s->memory, SYS_BUS_DEVICE(&s->timerctrl),
"aspeed.timerctrl",
sc->memmap[ASPEED_DEV_TIMER1], 0x200);
@ -261,9 +292,6 @@ static void aspeed_soc_ast27x0ssp_realize(DeviceState *dev_soc, Error **errp)
aspeed_mmio_map_unimplemented(s->memory, SYS_BUS_DEVICE(&a->ipc[1]),
"aspeed.ipc1",
sc->memmap[ASPEED_DEV_IPC1], 0x1000);
aspeed_mmio_map_unimplemented(s->memory, SYS_BUS_DEVICE(&a->scuio),
"aspeed.scuio",
sc->memmap[ASPEED_DEV_SCUIO], 0x1000);
aspeed_mmio_map_unimplemented(s->memory, SYS_BUS_DEVICE(&a->pric[0]),
"aspeed.pric0",
sc->memmap[ASPEED_DEV_PRIC0], 0x1000);
@ -275,6 +303,15 @@ static void aspeed_soc_ast27x0ssp_realize(DeviceState *dev_soc, Error **errp)
sc->memmap[ASPEED_DEV_OTP], 0x800);
}
static const Property aspeed_27x0_coprocessor_properties[] = {
DEFINE_PROP_LINK("scu", Aspeed27x0CoprocessorState, scu,
TYPE_ASPEED_2700_SCU, Aspeed2700SCUState *),
DEFINE_PROP_LINK("scuio", Aspeed27x0CoprocessorState, scuio,
TYPE_ASPEED_SCU, AspeedSCUState *),
DEFINE_PROP_LINK("fmc", Aspeed27x0CoprocessorState, fmc, TYPE_ASPEED_SMC,
AspeedSMCState *),
};
static void aspeed_soc_ast27x0ssp_class_init(ObjectClass *klass,
const void *data)
{
@ -288,6 +325,7 @@ static void aspeed_soc_ast27x0ssp_class_init(ObjectClass *klass,
/* Reason: The Aspeed Coprocessor can only be instantiated from a board */
dc->user_creatable = false;
dc->realize = aspeed_soc_ast27x0ssp_realize;
device_class_set_props(dc, aspeed_27x0_coprocessor_properties);
sc->valid_cpu_types = valid_cpu_types;
sc->irqmap = aspeed_soc_ast27x0ssp_irqmap;

View file

@ -27,6 +27,7 @@ static const hwaddr aspeed_soc_ast27x0tsp_memmap[] = {
[ASPEED_DEV_TIMER1] = 0x72C10000,
[ASPEED_DEV_UART4] = 0x72C1A000,
[ASPEED_DEV_IPC0] = 0x72C1C000,
[ASPEED_DEV_FMC] = 0x74000000,
[ASPEED_DEV_PRIC1] = 0x74100000,
[ASPEED_DEV_SCUIO] = 0x74C02000,
[ASPEED_DEV_OTP] = 0x74C07000,
@ -142,8 +143,6 @@ static void aspeed_soc_ast27x0tsp_init(Object *obj)
TYPE_UNIMPLEMENTED_DEVICE);
object_initialize_child(obj, "ipc1", &a->ipc[1],
TYPE_UNIMPLEMENTED_DEVICE);
object_initialize_child(obj, "scuio", &a->scuio,
TYPE_UNIMPLEMENTED_DEVICE);
object_initialize_child(obj, "pric0", &a->pric[0],
TYPE_UNIMPLEMENTED_DEVICE);
object_initialize_child(obj, "pric1", &a->pric[1],
@ -167,6 +166,24 @@ static void aspeed_soc_ast27x0tsp_realize(DeviceState *dev_soc, Error **errp)
return;
}
if (!a->scu) {
error_setg(errp, TYPE_ASPEED27X0TSP_COPROCESSOR
": 'scu' link is not set");
return;
}
if (!a->scuio) {
error_setg(errp, TYPE_ASPEED27X0TSP_COPROCESSOR
": 'scuio' link is not set");
return;
}
if (!a->fmc) {
error_setg(errp, TYPE_ASPEED27X0TSP_COPROCESSOR
": 'fmc' link is not set");
return;
}
/* AST27X0 TSP Core */
armv7m = DEVICE(&a->armv7m);
qdev_prop_set_uint32(armv7m, "num-irq", 256);
@ -195,11 +212,18 @@ static void aspeed_soc_ast27x0tsp_realize(DeviceState *dev_soc, Error **errp)
&s->sram_alias);
/* SCU */
memory_region_init_alias(&s->scu_alias, OBJECT(s), "scu.alias",
&s->scu->iomem, 0,
memory_region_size(&s->scu->iomem));
memory_region_init_alias(&a->scu_alias, OBJECT(a), "scu.alias",
&a->scu->parent_obj.iomem, 0,
memory_region_size(&a->scu->parent_obj.iomem));
memory_region_add_subregion(s->memory, sc->memmap[ASPEED_DEV_SCU],
&s->scu_alias);
&a->scu_alias);
/* SCUIO */
memory_region_init_alias(&a->scuio_alias, OBJECT(a), "scuio.alias",
&a->scuio->iomem, 0,
memory_region_size(&a->scuio->iomem));
memory_region_add_subregion(s->memory, sc->memmap[ASPEED_DEV_SCUIO],
&a->scuio_alias);
/* INTC */
if (!sysbus_realize(SYS_BUS_DEVICE(&a->intc[0]), errp)) {
@ -252,6 +276,13 @@ static void aspeed_soc_ast27x0tsp_realize(DeviceState *dev_soc, Error **errp)
sysbus_connect_irq(SYS_BUS_DEVICE(s->uart), 0,
aspeed_soc_ast27x0tsp_get_irq(s, s->uart_dev));
/* FMC */
memory_region_init_alias(&a->fmc_alias, OBJECT(a), "fmc.alias",
&a->fmc->mmio, 0,
memory_region_size(&a->fmc->mmio));
memory_region_add_subregion(s->memory, sc->memmap[ASPEED_DEV_FMC],
&a->fmc_alias);
aspeed_mmio_map_unimplemented(s->memory, SYS_BUS_DEVICE(&s->timerctrl),
"aspeed.timerctrl",
sc->memmap[ASPEED_DEV_TIMER1], 0x200);
@ -261,9 +292,6 @@ static void aspeed_soc_ast27x0tsp_realize(DeviceState *dev_soc, Error **errp)
aspeed_mmio_map_unimplemented(s->memory, SYS_BUS_DEVICE(&a->ipc[1]),
"aspeed.ipc1",
sc->memmap[ASPEED_DEV_IPC1], 0x1000);
aspeed_mmio_map_unimplemented(s->memory, SYS_BUS_DEVICE(&a->scuio),
"aspeed.scuio",
sc->memmap[ASPEED_DEV_SCUIO], 0x1000);
aspeed_mmio_map_unimplemented(s->memory, SYS_BUS_DEVICE(&a->pric[0]),
"aspeed.pric0",
sc->memmap[ASPEED_DEV_PRIC0], 0x1000);
@ -275,6 +303,15 @@ static void aspeed_soc_ast27x0tsp_realize(DeviceState *dev_soc, Error **errp)
sc->memmap[ASPEED_DEV_OTP], 0x800);
}
static const Property aspeed_27x0_coprocessor_properties[] = {
DEFINE_PROP_LINK("scu", Aspeed27x0CoprocessorState, scu,
TYPE_ASPEED_2700_SCU, Aspeed2700SCUState *),
DEFINE_PROP_LINK("scuio", Aspeed27x0CoprocessorState, scuio,
TYPE_ASPEED_SCU, AspeedSCUState *),
DEFINE_PROP_LINK("fmc", Aspeed27x0CoprocessorState, fmc, TYPE_ASPEED_SMC,
AspeedSMCState *),
};
static void aspeed_soc_ast27x0tsp_class_init(ObjectClass *klass,
const void *data)
{
@ -288,6 +325,7 @@ static void aspeed_soc_ast27x0tsp_class_init(ObjectClass *klass,
/* Reason: The Aspeed Coprocessor can only be instantiated from a board */
dc->user_creatable = false;
dc->realize = aspeed_soc_ast27x0tsp_realize;
device_class_set_props(dc, aspeed_27x0_coprocessor_properties);
sc->valid_cpu_types = valid_cpu_types;
sc->irqmap = aspeed_soc_ast27x0tsp_irqmap;

View file

@ -435,12 +435,12 @@ static void aspeed_soc_ast2700_init(Object *obj)
object_initialize_child(obj, "gic", &a->gic, gicv3_class_name());
object_initialize_child(obj, "scu", &s->scu, TYPE_ASPEED_2700_SCU);
qdev_prop_set_uint32(DEVICE(&s->scu), "silicon-rev",
object_initialize_child(obj, "scu", &a->scu, TYPE_ASPEED_2700_SCU);
qdev_prop_set_uint32(DEVICE(&a->scu), "silicon-rev",
sc->silicon_rev);
object_property_add_alias(obj, "hw-strap1", OBJECT(&s->scu),
object_property_add_alias(obj, "hw-strap1", OBJECT(&a->scu),
"hw-strap1");
object_property_add_alias(obj, "hw-prot-key", OBJECT(&s->scu),
object_property_add_alias(obj, "hw-prot-key", OBJECT(&a->scu),
"hw-prot-key");
object_initialize_child(obj, "scuio", &s->scuio, TYPE_ASPEED_2700_SCUIO);
@ -808,10 +808,10 @@ static void aspeed_soc_ast2700_realize(DeviceState *dev, Error **errp)
sc->memmap[ASPEED_DEV_VBOOTROM], &s->vbootrom);
/* SCU */
if (!sysbus_realize(SYS_BUS_DEVICE(&s->scu), errp)) {
if (!sysbus_realize(SYS_BUS_DEVICE(&a->scu), errp)) {
return;
}
aspeed_mmio_map(s->memory, SYS_BUS_DEVICE(&s->scu), 0,
aspeed_mmio_map(s->memory, SYS_BUS_DEVICE(&a->scu), 0,
sc->memmap[ASPEED_DEV_SCU]);
/* SCU1 */
@ -870,6 +870,11 @@ static void aspeed_soc_ast2700_realize(DeviceState *dev, Error **errp)
/* EHCI */
for (i = 0; i < sc->ehcis_num; i++) {
object_property_set_int(OBJECT(&s->ehci[i]), "ctrldssegment-default",
sc->memmap[ASPEED_DEV_SDRAM] >> 32,
&error_abort);
object_property_set_bool(OBJECT(&s->ehci[i]), "caps-64bit-addr", true,
&error_abort);
if (!sysbus_realize(SYS_BUS_DEVICE(&s->ehci[i]), errp)) {
return;
}
@ -929,7 +934,7 @@ static void aspeed_soc_ast2700_realize(DeviceState *dev, Error **errp)
AspeedWDTClass *awc = ASPEED_WDT_GET_CLASS(&s->wdt[i]);
hwaddr wdt_offset = sc->memmap[ASPEED_DEV_WDT] + i * awc->iosize;
object_property_set_link(OBJECT(&s->wdt[i]), "scu", OBJECT(&s->scu),
object_property_set_link(OBJECT(&s->wdt[i]), "scu", OBJECT(&a->scu),
&error_abort);
if (!sysbus_realize(SYS_BUS_DEVICE(&s->wdt[i]), errp)) {
return;
@ -1032,7 +1037,7 @@ static void aspeed_soc_ast2700_realize(DeviceState *dev, Error **errp)
aspeed_soc_ast2700_get_irq(s, ASPEED_DEV_EMMC));
/* Timer */
object_property_set_link(OBJECT(&s->timerctrl), "scu", OBJECT(&s->scu),
object_property_set_link(OBJECT(&s->timerctrl), "scu", OBJECT(&a->scu),
&error_abort);
if (!sysbus_realize(SYS_BUS_DEVICE(&s->timerctrl), errp)) {
return;

View file

@ -27,8 +27,6 @@ static const Property aspeed_coprocessor_properties[] = {
TYPE_MEMORY_REGION, MemoryRegion *),
DEFINE_PROP_LINK("sram", AspeedCoprocessorState, sram, TYPE_MEMORY_REGION,
MemoryRegion *),
DEFINE_PROP_LINK("scu", AspeedCoprocessorState, scu, TYPE_ASPEED_SCU,
AspeedSCUState *),
DEFINE_PROP_LINK("uart", AspeedCoprocessorState, uart, TYPE_SERIAL_MM,
SerialMM *),
DEFINE_PROP_INT32("uart-dev", AspeedCoprocessorState, uart_dev, 0),

56
hw/arm/ax3000-boards.c Normal file
View file

@ -0,0 +1,56 @@
/*
* Axiado Boards
*
* Author: Kuan-Jui Chiu <kchiu@axiado.com>
*
* SPDX-License-Identifier: GPL-2.0-or-later
*/
#include "qemu/osdep.h"
#include "hw/arm/ax3000-boards.h"
#include "hw/arm/boot.h"
#include "hw/arm/machines-qom.h"
#include "qemu/error-report.h"
#include "qom/object.h"
static struct arm_boot_info ax3000_binfo = {
.loader_start = AX3000_DRAM0_BASE,
.board_id = -1,
};
static void ax3000_machine_init(MachineState *machine)
{
Ax3000MachineState *ams = AX3000_MACHINE(machine);
ams->soc = AX3000_SOC(object_new(TYPE_AX3000_SOC));
object_property_add_child(OBJECT(machine), "soc", OBJECT(ams->soc));
sysbus_realize_and_unref(SYS_BUS_DEVICE(ams->soc), &error_fatal);
ax3000_binfo.ram_size = machine->ram_size;
arm_load_kernel(&ams->soc->cpu[0], machine, &ax3000_binfo);
}
static void ax3000_machine_class_init(ObjectClass *oc, const void *data)
{
MachineClass *mc = MACHINE_CLASS(oc);
mc->init = ax3000_machine_init;
mc->default_cpus = AX3000_NUM_CPUS;
mc->min_cpus = AX3000_NUM_CPUS;
mc->max_cpus = AX3000_NUM_CPUS;
mc->default_cpu_type = ARM_CPU_TYPE_NAME("cortex-a53");
}
static const TypeInfo ax3000_machine_types[] = {
{
.name = TYPE_AX3000_MACHINE,
.parent = TYPE_MACHINE,
.instance_size = sizeof(Ax3000MachineState),
.class_size = sizeof(Ax3000MachineClass),
.class_init = ax3000_machine_class_init,
.interfaces = aarch64_machine_interfaces,
.abstract = true,
}
};
DEFINE_TYPES(ax3000_machine_types)

27
hw/arm/ax3000-evk.c Normal file
View file

@ -0,0 +1,27 @@
/*
* Axiado Evaluation Kit Emulation
*
* Author: Kuan-Jui Chiu <kchiu@axiado.com>
*
* SPDX-License-Identifier: GPL-2.0-or-later
*/
#include "qemu/osdep.h"
#include "hw/arm/ax3000-boards.h"
static void axiado_scm3003_class_init(ObjectClass *oc, const void *data)
{
MachineClass *mc = MACHINE_CLASS(oc);
mc->desc = "Axiado SCM3003 EVK Board";
}
static const TypeInfo ax3000_evk_types[] = {
{
.name = MACHINE_TYPE_NAME("axiado-scm3003"),
.parent = TYPE_AX3000_MACHINE,
.class_init = axiado_scm3003_class_init,
}
};
DEFINE_TYPES(ax3000_evk_types)

243
hw/arm/ax3000-soc.c Normal file
View file

@ -0,0 +1,243 @@
/*
* Axiado SoC AX3000
*
* Author: Kuan-Jui Chiu <kchiu@axiado.com>
*
* SPDX-License-Identifier: GPL-2.0-or-later
*/
#include "qemu/osdep.h"
#include "system/address-spaces.h"
#include "hw/arm/bsa.h"
#include "hw/arm/ax3000-soc.h"
#include "hw/misc/unimp.h"
#include "system/system.h"
#include "qobject/qlist.h"
#include "qom/object.h"
#include "hw/core/boards.h"
static void ax3000_init(Object *obj)
{
Ax3000SoCState *s = AX3000_SOC(obj);
Ax3000SoCClass *sc = AX3000_SOC_GET_CLASS(s);
for (int i = 0; i < sc->num_cpus; i++) {
g_autofree char *name = g_strdup_printf("cpu%d", i);
object_initialize_child(obj, name, &s->cpu[i],
ARM_CPU_TYPE_NAME("cortex-a53"));
}
object_initialize_child(obj, "gic", &s->gic, gicv3_class_name());
for (int i = 0; i < AX3000_NUM_UARTS; i++) {
g_autofree char *name = g_strdup_printf("uart%d", i);
object_initialize_child(obj, name, &s->uart[i], TYPE_CADENCE_UART);
}
object_initialize_child(obj, "clk", &s->ax3000_clk, TYPE_AX3000_CLK);
object_initialize_child(obj, "sdhci0", &s->sdhci0, TYPE_AXIADO_SDHCI);
for (int i = 0; i < AX3000_NUM_GPIOS; i++) {
g_autofree char *name = g_strdup_printf("gpio%d", i);
object_initialize_child(obj, name, &s->gpio[i], TYPE_CADENCE_GPIO);
}
}
static void ax3000_realize(DeviceState *dev, Error **errp)
{
Ax3000SoCState *s = AX3000_SOC(dev);
Ax3000SoCClass *sc = AX3000_SOC_GET_CLASS(s);
SysBusDevice *gic_sbd = SYS_BUS_DEVICE(&s->gic);
DeviceState *gic_dev = DEVICE(&s->gic);
QList *redist_region_count;
SysBusDevice *sdhci0_sbd;
DeviceState *card;
DriveInfo *dinfo;
/* CPUs */
for (int i = 0; i < sc->num_cpus; i++) {
object_property_set_int(OBJECT(&s->cpu[i]), "cntfrq", 8000000,
&error_abort);
if (object_property_find(OBJECT(&s->cpu[i]), "has_el3")) {
object_property_set_bool(OBJECT(&s->cpu[i]), "has_el3",
false, &error_abort);
}
if (!qdev_realize(DEVICE(&s->cpu[i]), NULL, errp)) {
return;
}
}
/* GIC */
qdev_prop_set_uint32(gic_dev, "num-cpu", sc->num_cpus);
qdev_prop_set_uint32(gic_dev, "num-irq",
AX3000_NUM_IRQS + GIC_INTERNAL);
redist_region_count = qlist_new();
qlist_append_int(redist_region_count, sc->num_cpus);
qdev_prop_set_array(gic_dev, "redist-region-count", redist_region_count);
if (!sysbus_realize(gic_sbd, errp)) {
return;
}
sysbus_mmio_map(gic_sbd, 0, AX3000_GIC_DIST_BASE);
sysbus_mmio_map(gic_sbd, 1, AX3000_GIC_REDIST_BASE);
/*
* Mapping from the output timer irq lines from the CPU to the
* GIC PPI inputs.
*/
const int timer_irqs[] = {
[GTIMER_PHYS] = ARCH_TIMER_NS_EL1_IRQ,
[GTIMER_VIRT] = ARCH_TIMER_VIRT_IRQ,
[GTIMER_HYP] = ARCH_TIMER_NS_EL2_IRQ,
[GTIMER_SEC] = ARCH_TIMER_S_EL1_IRQ
};
/*
* Wire the outputs from each CPU's generic timer and the GICv3
* maintenance interrupt signal to the appropriate GIC PPI inputs, and
* the GIC's IRQ/FIQ interrupt outputs to the CPU's inputs.
*/
for (int i = 0; i < sc->num_cpus; i++) {
DeviceState *cpu_dev = DEVICE(&s->cpu[i]);
int intidbase = AX3000_NUM_IRQS + i * GIC_INTERNAL;
qemu_irq irq;
for (int j = 0; j < ARRAY_SIZE(timer_irqs); j++) {
irq = qdev_get_gpio_in(gic_dev, intidbase + timer_irqs[j]);
qdev_connect_gpio_out(cpu_dev, j, irq);
}
irq = qdev_get_gpio_in(gic_dev, intidbase + ARCH_GIC_MAINT_IRQ);
qdev_connect_gpio_out_named(cpu_dev, "gicv3-maintenance-interrupt",
0, irq);
sysbus_connect_irq(gic_sbd, i,
qdev_get_gpio_in(cpu_dev, ARM_CPU_IRQ));
sysbus_connect_irq(gic_sbd, i + sc->num_cpus,
qdev_get_gpio_in(cpu_dev, ARM_CPU_FIQ));
sysbus_connect_irq(gic_sbd, i + 2 * sc->num_cpus,
qdev_get_gpio_in(cpu_dev, ARM_CPU_VIRQ));
sysbus_connect_irq(gic_sbd, i + 3 * sc->num_cpus,
qdev_get_gpio_in(cpu_dev, ARM_CPU_VFIQ));
}
/* DRAM */
const struct {
hwaddr addr;
size_t size;
const char *name;
} dram_table[] = {
{ AX3000_DRAM0_BASE, AX3000_DRAM0_SIZE, "dram0" },
{ AX3000_DRAM1_BASE, AX3000_DRAM1_SIZE, "dram1" }
};
for (int i = 0; i < AX3000_NUM_BANKS; i++) {
memory_region_init_ram(&s->dram[i], OBJECT(s), dram_table[i].name,
dram_table[i].size, &error_fatal);
memory_region_add_subregion(get_system_memory(), dram_table[i].addr,
&s->dram[i]);
}
/* UARTs */
const struct {
hwaddr addr;
unsigned int irq;
} serial_table[] = {
{ AX3000_UART0_BASE, AX3000_UART0_IRQ },
{ AX3000_UART1_BASE, AX3000_UART1_IRQ },
{ AX3000_UART2_BASE, AX3000_UART2_IRQ },
{ AX3000_UART3_BASE, AX3000_UART3_IRQ }
};
for (int i = 0; i < AX3000_NUM_UARTS; i++) {
qdev_prop_set_chr(DEVICE(&s->uart[i]), "chardev", serial_hd(i));
if (!sysbus_realize(SYS_BUS_DEVICE(&s->uart[i]), errp)) {
return;
}
sysbus_mmio_map(SYS_BUS_DEVICE(&s->uart[i]), 0, serial_table[i].addr);
sysbus_connect_irq(SYS_BUS_DEVICE(&s->uart[i]), 0,
qdev_get_gpio_in(gic_dev, serial_table[i].irq));
}
/* Timer control */
create_unimplemented_device("ax3000.timerctrl", AX3000_TIMER_CTRL, 32);
/* Clock control */
if (!sysbus_realize(SYS_BUS_DEVICE(&s->ax3000_clk), errp)) {
return;
}
sysbus_mmio_map(SYS_BUS_DEVICE(&s->ax3000_clk), 0, AX3000_PLL_BASE);
/* SDHCI */
sdhci0_sbd = SYS_BUS_DEVICE(&s->sdhci0);
if (!sysbus_realize(sdhci0_sbd, errp)) {
return;
}
sysbus_mmio_map(sdhci0_sbd, 0, AX3000_SDHCI0_BASE);
sysbus_mmio_map(sdhci0_sbd, 1, AX3000_EMMC_PHY_BASE);
sysbus_connect_irq(sdhci0_sbd, 0,
qdev_get_gpio_in(gic_dev, AX3000_SDHCI0_IRQ));
dinfo = drive_get(IF_SD, 0, 0);
if (dinfo) {
card = qdev_new(TYPE_SD_CARD);
qdev_prop_set_drive_err(card, "drive",
blk_by_legacy_dinfo(dinfo),
&error_fatal);
qdev_realize_and_unref(card, s->sdhci0.sd_bus, &error_fatal);
}
/* GPIOs */
const struct {
hwaddr addr;
unsigned int irq;
} gpio_table[] = {
{ AX3000_GPIO0_BASE, AX3000_GPIO0_IRQ },
{ AX3000_GPIO1_BASE, AX3000_GPIO1_IRQ },
{ AX3000_GPIO2_BASE, AX3000_GPIO2_IRQ },
{ AX3000_GPIO3_BASE, AX3000_GPIO3_IRQ },
{ AX3000_GPIO4_BASE, AX3000_GPIO4_IRQ },
{ AX3000_GPIO5_BASE, AX3000_GPIO5_IRQ },
{ AX3000_GPIO6_BASE, AX3000_GPIO6_IRQ },
{ AX3000_GPIO7_BASE, AX3000_GPIO7_IRQ }
};
for (int i = 0; i < AX3000_NUM_GPIOS; i++) {
if (!sysbus_realize(SYS_BUS_DEVICE(&s->gpio[i]), errp)) {
return;
}
sysbus_mmio_map(SYS_BUS_DEVICE(&s->gpio[i]), 0, gpio_table[i].addr);
sysbus_connect_irq(SYS_BUS_DEVICE(&s->gpio[i]), 0,
qdev_get_gpio_in(gic_dev, gpio_table[i].irq));
}
}
static void ax3000_class_init(ObjectClass *oc, const void *data)
{
DeviceClass *dc = DEVICE_CLASS(oc);
Ax3000SoCClass *sc = AX3000_SOC_CLASS(oc);
dc->desc = "Axiado SoC AX3000";
dc->realize = ax3000_realize;
sc->num_cpus = AX3000_NUM_CPUS;
}
static const TypeInfo axiado_soc_types[] = {
{
.name = TYPE_AX3000_SOC,
.parent = TYPE_SYS_BUS_DEVICE,
.instance_size = sizeof(Ax3000SoCState),
.instance_init = ax3000_init,
.class_init = ax3000_class_init,
.class_size = sizeof(Ax3000SoCClass),
}
};
DEFINE_TYPES(axiado_soc_types)

View file

@ -29,7 +29,14 @@
#include "hw/arm/boot.h"
#include "hw/arm/machines-qom.h"
static struct arm_boot_info bpim2u_binfo;
#define TYPE_BPIM2U_MACHINE MACHINE_TYPE_NAME("bpim2u")
OBJECT_DECLARE_SIMPLE_TYPE(Bpim2uMachineState, BPIM2U_MACHINE)
struct Bpim2uMachineState {
MachineState parent;
struct arm_boot_info bootinfo;
};
/*
* R40 can boot from mmc0 and mmc2, and bpim2u has two mmc interface, one is
@ -62,6 +69,7 @@ static void mmc_attach_drive(AwR40State *s, AwSdHostState *mmc, int unit,
static void bpim2u_init(MachineState *machine)
{
Bpim2uMachineState *bpms = BPIM2U_MACHINE(machine);
bool bootroom_loaded = false;
AwR40State *r40;
I2CBus *i2c;
@ -120,10 +128,10 @@ static void bpim2u_init(MachineState *machine)
memory_region_add_subregion(get_system_memory(),
r40->memmap[AW_R40_DEV_SDRAM], machine->ram);
bpim2u_binfo.loader_start = r40->memmap[AW_R40_DEV_SDRAM];
bpim2u_binfo.ram_size = machine->ram_size;
bpim2u_binfo.psci_conduit = QEMU_PSCI_CONDUIT_SMC;
arm_load_kernel(&r40->cpus[0], machine, &bpim2u_binfo);
bpms->bootinfo.loader_start = r40->memmap[AW_R40_DEV_SDRAM];
bpms->bootinfo.ram_size = machine->ram_size;
bpms->bootinfo.psci_conduit = QEMU_PSCI_CONDUIT_SMC;
arm_load_kernel(&r40->cpus[0], machine, &bpms->bootinfo);
}
static void bpim2u_machine_init(MachineClass *mc)
@ -145,4 +153,5 @@ static void bpim2u_machine_init(MachineClass *mc)
mc->auto_create_sdcard = true;
}
DEFINE_MACHINE_ARM("bpim2u", bpim2u_machine_init)
DEFINE_MACHINE_EXTENDED("bpim2u", MACHINE, Bpim2uMachineState,
bpim2u_machine_init, false, arm_machine_interfaces)

Some files were not shown because too many files have changed in this diff Show more