From nobody Mon Sep 28 01:15:14 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1786006206; cv=none; d=zohomail.com; s=zohoarc; b=fE6bZdK7iD6n14rVmFctB/npg7hjjVwPBCdkfMv6ssciQdaXrRvA+CNamJUta4IeEMvZLaPaocawP/bi5aR1TLCT67TCOidgAdMRoi5ZbG5wKltxeywt/M/iDeEXtTsEg4Q7iMfzPLgQGIJsn30ZrWJOXQARAnMolSQ5AwB6IAU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786006206; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=aVrtlsA7Jg/Ha9/qbJG0kFJ5A7fFXUivVpxYdndNPFs=; b=BourzIgtWidGvxHDPodSw8jofQNlB9JVsoqhcsd2nveoPlVau7XcRh5GXiKBQc4IXsG73Sd+tMdMyCRTNUW8c32/5Z95A8uLzyjhzaNQ/7LPs/veGPylumAlnyAjIc/vZ5fvbqwy3DQ7O2StTVjnbXONWuFNzE4XYGa3O36YH+s= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786006206360547.2085561114234; Thu, 6 Aug 2026 01:50:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wrtmw-0004G9-V9; Thu, 06 Aug 2026 04:49:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrtmt-0004FB-W0 for qemu-devel@nongnu.org; Thu, 06 Aug 2026 04:49:16 -0400 Received: from [115.124.30.111] (helo=out30-111.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrtmm-0001NM-Rq for qemu-devel@nongnu.org; Thu, 06 Aug 2026 04:49:15 -0400 Received: from U-92DF4J33-2338.local(mailfrom:zhengrong_li@linux.alibaba.com fp:SMTPD_---0X8TQ57R_1786006123 cluster:ay36) by smtp.aliyun-inc.com; Thu, 06 Aug 2026 16:48:49 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1786006129; h=From:To:Subject:Date:Message-ID:Content-Type:MIME-Version; bh=aVrtlsA7Jg/Ha9/qbJG0kFJ5A7fFXUivVpxYdndNPFs=; b=I5nrtSqamcyFMjRkAoasv6/J2xXOUir3Ohhe27zMpfTkwZvQLW1FI8zuKm2hhd+uDonGutQ10rkSfUbAgBj/yvRt3v7UrlJC2i2Ped7sr+5Cr60JSkoTl8QxssRM/INS5XlDEOyi7+uhEqCVsP+GZPL7udG9QQD+qlRttPW8gzg= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R831e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045133197; MF=zhengrong_li@linux.alibaba.com; NM=1; PH=DS; RN=6; SR=0; TI=SMTPD_---0X8TQ57R_1786006123; From: Zhengrong Li To: qemu-devel@nongnu.org Cc: akihiko.odaki@gmail.com, philmd@qualcomm.com, pbonzini@redhat.com, viktor.prutyanov@phystech.edu, zhengrong_li@linux.alibaba.com Subject: [PATCH v3 1/3] runstate: set crash_occurred on guest crashloaded Date: Thu, 06 Aug 2026 16:47:41 +0800 Message-ID: <178600606177.41696.1952897016467970943@linux.alibaba.com> In-Reply-To: <178600606177.41696.3160576684819885412@linux.alibaba.com> References: <178600606177.41696.3160576684819885412@linux.alibaba.com> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.111 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.111; envelope-from=zhengrong_li@linux.alibaba.com; helo=out30-111.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1786006207461158500 Windows pvpanic driver writes PVPANIC_CRASH_LOADED (bit 1) on bugcheck, not PVPANIC_PANICKED (bit 0). As a result, qemu_system_guest_panicked() is never called and crash_occurred stays false for Windows guests. Set crash_occurred in qemu_system_guest_crashloaded() as well, so the faulting CPU can be identified in the guest dump. Signed-off-by: Zhengrong Li --- system/runstate.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/system/runstate.c b/system/runstate.c index 08acf801b0..c7961cc1df 100644 --- a/system/runstate.c +++ b/system/runstate.c @@ -724,6 +724,11 @@ void qemu_system_guest_panicked(GuestPanicInformation = *info) void qemu_system_guest_crashloaded(GuestPanicInformation *info) { qemu_log_mask(LOG_GUEST_ERROR, "Guest crash loaded"); + + if (current_cpu) { + current_cpu->crash_occurred =3D true; + } + qapi_event_send_guest_crashloaded(GUEST_PANIC_ACTION_RUN, info); qapi_free_GuestPanicInformation(info); } --=20 2.43.0 From nobody Mon Sep 28 01:15:14 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1786006206; cv=none; d=zohomail.com; s=zohoarc; b=WfeV7CftjRcG6eu33Idpswc9Hj004fhEtGYi3HnR74hm65VlyqMxKCbTV6kDRIr2a3+nPGvvglEIktgOH6733BH+lTRJTqgq94kG2E9hnPx0/fBWV0W7YOul9INtVg1aesF0axm6p+MUU1wLX9ajQl3asNcrom63fV0mQPSx/6Y= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786006206; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=NT6gSRJ0N5NlgtHEp7zRxfcB9RS16InktidXXB3lk+o=; b=nkdr8c56yxn+/240hnqWu2Z1i+CNPVKsy2hvS8rmmw8bOXC0CE9WcTBnP/CK9tzEXxFCrx0vMfKk6QUiT8oVrd8C9vHlGeAY6yOvhayFlz95/s1yqlG4s8f64EkRmFiJMrNbLIhcs2ajbVGnV+U8juNgDesgs3YRCE8y0s1W69A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786006206131792.44230618929; Thu, 6 Aug 2026 01:50:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wrtmw-0004FC-GH; Thu, 06 Aug 2026 04:49:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrtms-0004Ev-Li for qemu-devel@nongnu.org; Thu, 06 Aug 2026 04:49:14 -0400 Received: from [115.124.30.110] (helo=out30-110.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrtmn-0001Ne-S6 for qemu-devel@nongnu.org; Thu, 06 Aug 2026 04:49:14 -0400 Received: from U-92DF4J33-2338.local(mailfrom:zhengrong_li@linux.alibaba.com fp:SMTPD_---0X8TNAfU_1786006129 cluster:ay36) by smtp.aliyun-inc.com; Thu, 06 Aug 2026 16:48:55 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1786006135; h=From:To:Subject:Date:Message-ID:Content-Type:MIME-Version; bh=NT6gSRJ0N5NlgtHEp7zRxfcB9RS16InktidXXB3lk+o=; b=f48JOnwOCbP8FDjJ5TmTmjMnp2OQv/Dmx/pgBaI3Txz3cgF5tKraquBEVZ2cPTXF3LL8c+6+BVAtH3+UYuqfSj0ShJQRetWhtFYR15t0l7F0RaEGJmWCNdA/5wZoiR6t2ykIEn3cfmCrpMpOLpQzfVHQv1On/C+dnJ+M57uMcWA= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R791e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037009110; MF=zhengrong_li@linux.alibaba.com; NM=1; PH=DS; RN=6; SR=0; TI=SMTPD_---0X8TNAfU_1786006129; From: Zhengrong Li To: qemu-devel@nongnu.org Cc: akihiko.odaki@gmail.com, philmd@qualcomm.com, pbonzini@redhat.com, viktor.prutyanov@phystech.edu, zhengrong_li@linux.alibaba.com Subject: [PATCH v3 2/3] dump: add crash_occurred flag to QEMUCPUState Date: Thu, 06 Aug 2026 16:47:41 +0800 Message-ID: <178600606177.41696.17514250023045302941@linux.alibaba.com> In-Reply-To: <178600606177.41696.3160576684819885412@linux.alibaba.com> References: <178600606177.41696.3160576684819885412@linux.alibaba.com> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.110 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.110; envelope-from=zhengrong_li@linux.alibaba.com; helo=out30-110.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1786006207682158500 Add is_crash_occurred_cpu field to the local QEMUCPUState in arch_dump.c so that dump-guest-memory can record which CPU triggered the guest panic. The new field is appended after kernel_gs_base, so existing tools that check the 'size' field can safely ignore it when reading older dumps. Signed-off-by: Zhengrong Li --- target/i386/arch_dump.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/target/i386/arch_dump.c b/target/i386/arch_dump.c index 16e47c4747..8ce2c7e9bb 100644 --- a/target/i386/arch_dump.c +++ b/target/i386/arch_dump.c @@ -264,6 +264,8 @@ struct QEMUCPUState { * by checking 'size' field. */ uint64_t kernel_gs_base; + uint8_t is_crash_occurred_cpu; + uint8_t pad[7]; }; =20 typedef struct QEMUCPUState QEMUCPUState; @@ -279,6 +281,7 @@ static void copy_segment(QEMUCPUSegment *d, SegmentCach= e *s) =20 static void qemu_get_cpustate(QEMUCPUState *s, CPUX86State *env) { + CPUState *cs =3D env_cpu(env); memset(s, 0, sizeof(QEMUCPUState)); =20 s->version =3D QEMUCPUSTATE_VERSION; @@ -325,6 +328,9 @@ static void qemu_get_cpustate(QEMUCPUState *s, CPUX86St= ate *env) #ifdef TARGET_X86_64 s->kernel_gs_base =3D env->kernelgsbase; #endif + if (cs->crash_occurred) { + s->is_crash_occurred_cpu =3D 1; + } } =20 static inline int cpu_write_qemu_note(WriteCoreDumpFunction f, --=20 2.43.0 From nobody Mon Sep 28 01:15:14 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1786006206; cv=none; d=zohomail.com; s=zohoarc; b=lbqlbRnPCqZaVolQIgZyYOgmQrKT5wSmbUKqwlt/B9eBdDbGx26JuqK/1vhDMnq03OCAhdPNNsRXwgU72287yHmAU5hDiFP9dRQAosZXTEflmqwK9238LOLn3h7mCq0N9ISTHhEy6b/SILuAz4v8vD/J3EOIWr6x460Q5Mf8Gsw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786006206; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lHcxbi6g7OAtyRpi0UMSwNd6umxV1oga6e6WoWCPtNY=; b=OlGWLv54egGO7kCFRNteGkyQqkYwPle079TNrcCp1tPOiF/jnd0feRlEvH98Xe5xpsj9wITxSM4L3PB7fun4cRfhOP4Ui7FMHvkz/tjduenUhwQP9qYiAext5qqr6pZVFDhWOe48eNaY0MqVN5ab+PQQ4sXrqnULAUZrCjJ5jhs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786006206370784.5016249627336; Thu, 6 Aug 2026 01:50:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wrtn0-0004GP-PO; Thu, 06 Aug 2026 04:49:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrtn0-0004GH-3S for qemu-devel@nongnu.org; Thu, 06 Aug 2026 04:49:22 -0400 Received: from [115.124.30.118] (helo=out30-118.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrtmw-0001Nw-Pl for qemu-devel@nongnu.org; Thu, 06 Aug 2026 04:49:21 -0400 Received: from U-92DF4J33-2338.local(mailfrom:zhengrong_li@linux.alibaba.com fp:SMTPD_---0X8TZ0Gl_1786006135 cluster:ay36) by smtp.aliyun-inc.com; Thu, 06 Aug 2026 16:49:01 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1786006141; h=From:To:Subject:Date:Message-ID:Content-Type:MIME-Version; bh=lHcxbi6g7OAtyRpi0UMSwNd6umxV1oga6e6WoWCPtNY=; b=xdCjnmI7K7QbrxIU1EJYwMEkP3GeOEqfmgPAGN1A4K/WackLWFCtCQqvmTxeEL80NXD+ehMLtabRC4SeFJuRkMiLK4ejlg3ZYG5FUuGGojOreuG7xp/ETXZXeYTyMInMbu7vlWa+19TQlfwN/DHOSgrcvBNjKClzeJbVEI0NgK0= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R111e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037026112; MF=zhengrong_li@linux.alibaba.com; NM=1; PH=DS; RN=6; SR=0; TI=SMTPD_---0X8TZ0Gl_1786006135; From: Zhengrong Li To: qemu-devel@nongnu.org Cc: akihiko.odaki@gmail.com, philmd@qualcomm.com, pbonzini@redhat.com, viktor.prutyanov@phystech.edu, zhengrong_li@linux.alibaba.com Subject: [PATCH v3 3/3] elf2dmp: fill ContextBuffer with faulting CPU context Date: Thu, 06 Aug 2026 16:47:41 +0800 Message-ID: <178600606177.41696.17020382803154474312@linux.alibaba.com> In-Reply-To: <178600606177.41696.3160576684819885412@linux.alibaba.com> References: <178600606177.41696.3160576684819885412@linux.alibaba.com> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.118 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.118; envelope-from=zhengrong_li@linux.alibaba.com; helo=out30-118.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1786006207517158500 When is_crash_occurred_cpu is set in QEMUCPUState, copy that CPU's context into WinDumpHeader64 ContextBuffer so WinDbg opens on the faulting CPU instead of CPU 0. A per-CPU size check ensures the field is present before reading, supporting heterogeneous dumps. Also extract KiBugCheckData from the guest kernel to populate BugcheckCode and BugcheckParameters in the dump header. The embedded state->size is clamped to MIN(state->size, n_descsz) in init_states() to prevent reading beyond the note descriptor. Signed-off-by: Zhengrong Li --- contrib/elf2dmp/kdbg.h | 9 +++++++ contrib/elf2dmp/main.c | 50 ++++++++++++++++++++++++++++++++++++-- contrib/elf2dmp/qemu_elf.c | 7 ++++++ contrib/elf2dmp/qemu_elf.h | 2 ++ 4 files changed, 66 insertions(+), 2 deletions(-) diff --git a/contrib/elf2dmp/kdbg.h b/contrib/elf2dmp/kdbg.h index 002e3d0cd5..15e4fb1140 100644 --- a/contrib/elf2dmp/kdbg.h +++ b/contrib/elf2dmp/kdbg.h @@ -195,4 +195,13 @@ typedef struct KDDEBUGGER_DATA64 { uint16_t OffsetPrcbContext; } KDDEBUGGER_DATA64; =20 +typedef struct KIBUGCHECK_INFO { + uint32_t BugcheckCode; + uint32_t unused0; + uint64_t BugcheckParameter1; + uint64_t BugcheckParameter2; + uint64_t BugcheckParameter3; + uint64_t BugcheckParameter4; +} KIBUGCHECK_INFO; + #endif /* KDBG_H */ diff --git a/contrib/elf2dmp/main.c b/contrib/elf2dmp/main.c index a62abadcc0..e25709b45d 100644 --- a/contrib/elf2dmp/main.c +++ b/contrib/elf2dmp/main.c @@ -338,11 +338,26 @@ static bool fill_header(WinDumpHeader64 *hdr, struct = pa_space *ps, * A dump may still contain valuable information even if it lacks contexts= of * some CPUs due to dump corruption or a failure before starting CPUs. */ -static void fill_context(KDDEBUGGER_DATA64 *kdbg, +static void fill_context(WinDumpHeader64 *hdr, KDDEBUGGER_DATA64 *kdbg, struct va_space *vs, QEMU_Elf *qe) { int i; =20 + /* First pass: identify faulting CPU and set header context early */ + for (i =3D 0; i < qe->state_nr; i++) { + QEMUCPUState *s =3D qe->state[i]; + if (s->size >=3D offsetof(QEMUCPUState, is_crash_occurred_cpu) + + sizeof(s->is_crash_occurred_cpu) && + s->is_crash_occurred_cpu) { + WinContext64 ctx; + win_context_init_from_qemu_cpu_state(&ctx, s); + memcpy(hdr->ContextBuffer, &ctx, sizeof(ctx)); + printf("Faulting CPU identified: #%d\n", i); + break; + } + } + + /* Second pass: fill context for all CPUs (best-effort) */ for (i =3D 0; i < qe->state_nr; i++) { uint64_t Prcb; uint64_t Context; @@ -512,6 +527,7 @@ int main(int argc, char *argv[]) uint64_t KdVersionBlock; bool kernel_found =3D false; OMFSignatureRSDS rsds; + uint64_t KiBugCheckData; =20 if (argc !=3D 3) { eprintf("usage:\n\t%s elf_file dmp_file\n", argv[0]); @@ -611,7 +627,37 @@ int main(int argc, char *argv[]) goto out_kdbg; } =20 - fill_context(kdbg, &vs, &qemu_elf); + if (!SYM_RESOLVE(KernBase, &pdb, KiBugCheckData)) { + eprintf("Failed to get KiBugCheckData.\n"); + } else { + KIBUGCHECK_INFO data =3D { 0 }; + if (va_space_rw(&vs, KiBugCheckData, &data, sizeof(data), 0)) { + header.BugcheckCode =3D data.BugcheckCode; + header.BugcheckParameter1 =3D data.BugcheckParameter1; + header.BugcheckParameter2 =3D data.BugcheckParameter2; + header.BugcheckParameter3 =3D data.BugcheckParameter3; + header.BugcheckParameter4 =3D data.BugcheckParameter4; + + /* + * If BugcheckCode wasn't saved, we consider guest OS as alive. + */ + if (!header.BugcheckCode) { + header.BugcheckCode =3D LIVE_SYSTEM_DUMP; + } + + printf("KiBugCheckData: 0x%016" PRIx64 + ", BugcheckCode: 0x%08" PRIx32 ", Args:" + " 0x%016" PRIx64 " 0x%016" PRIx64 + " 0x%016" PRIx64 " 0x%016" PRIx64 "\n", + KiBugCheckData, header.BugcheckCode, + data.BugcheckParameter1, data.BugcheckParameter2, + data.BugcheckParameter3, data.BugcheckParameter4); + } else { + eprintf("Failed to va_space_rw KiBugCheckData.\n"); + } + } + + fill_context(&header, kdbg, &vs, &qemu_elf); =20 if (!write_dump(&ps, &header, argv[2])) { eprintf("Failed to save dump\n"); diff --git a/contrib/elf2dmp/qemu_elf.c b/contrib/elf2dmp/qemu_elf.c index c9bad6e82c..b181d418bd 100644 --- a/contrib/elf2dmp/qemu_elf.c +++ b/contrib/elf2dmp/qemu_elf.c @@ -103,6 +103,13 @@ static bool init_states(QEMU_Elf *qe) nhdr->n_descsz >=3D offsetof(QEMUCPUState, kernel_gs_base)) { state_size =3D MIN(state->size, nhdr->n_descsz); =20 + /* + * Clamp the embedded size to the actual note descriptor size + * so that downstream size checks (e.g. fill_context) never + * read beyond the descriptor boundary. + */ + state->size =3D state_size; + if (state_size < sizeof(*state)) { eprintf("CPU #%u: QEMU CPU state size %u doesn't match\n", states->len, state_size); diff --git a/contrib/elf2dmp/qemu_elf.h b/contrib/elf2dmp/qemu_elf.h index adc50238b4..3b28332e67 100644 --- a/contrib/elf2dmp/qemu_elf.h +++ b/contrib/elf2dmp/qemu_elf.h @@ -27,6 +27,8 @@ typedef struct QEMUCPUState { QEMUCPUSegment ldt, tr, gdt, idt; uint64_t cr[5]; uint64_t kernel_gs_base; + uint8_t is_crash_occurred_cpu; + uint8_t pad[7]; } QEMUCPUState; =20 int is_system(QEMUCPUState *s); --=20 2.43.0