From nobody Mon Sep 28 01:12:07 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1786017174; cv=none; d=zohomail.com; s=zohoarc; b=LvGvPFq0NF9XB0ZECBbhEtsl19KPAw/wOg2AxQtB7C3Rv+aoXmhbsnr134NOpjEmQGQT/JNLunFf93jZEoHOitpa9Hz6OmU2TA3o1ETsJlSwNMw2X59iw6mG3snrfa+zpAJfcrEYkn8zfqyXWlHM41Of/NgOHrZjev5NRIWTZxs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786017174; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=cO3UybPtoarePKl6I9T+LZhn3yIOK96B54b90jfJvg8=; b=VGUI1w6j/jGWiULEggLxet98PFW+Iw2/bbbl53s9nRXiX7kvW102+Z025o8F9+L2zlyJoWbIyBE3qvMpvQ8hagdzSi6qXzJz4FBUuNeYmwGsIy0+K0PUpTovYVaMBdUJ5pYpqTau79ImFgqQUJxjrxHF8r1h+FLN/YqfZA6yhh8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786017174440514.004646268911; Thu, 6 Aug 2026 04:52:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wrweH-0000dY-CX; Thu, 06 Aug 2026 07:52:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrweE-0000cb-76 for qemu-devel@nongnu.org; Thu, 06 Aug 2026 07:52:30 -0400 Received: from [115.124.30.99] (helo=out30-99.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrwe5-00083g-Kb for qemu-devel@nongnu.org; Thu, 06 Aug 2026 07:52:29 -0400 Received: from U-92DF4J33-2338.local(mailfrom:zhengrong_li@linux.alibaba.com fp:SMTPD_---0X8TobeA_1786017116 cluster:ay36) by smtp.aliyun-inc.com; Thu, 06 Aug 2026 19:52:02 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1786017123; h=From:To:Subject:Date:Message-ID:Content-Type:MIME-Version; bh=cO3UybPtoarePKl6I9T+LZhn3yIOK96B54b90jfJvg8=; b=CveXWj7QbnPQz8P47hU5egm4lOqCwfHHVuknQ6CQjubiyow7ckeuVk68TxZCDNl8WQlvgJ0yfqFboEbCLu7nBoKa+lLEc5UcfiBHVZujvhKes7d8hJlBewKtVFSZ1J+csx4jr3hMgGLbVUi7yfnrWLpc407nmdYBNOz1s0JO39w= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R151e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045098064; MF=zhengrong_li@linux.alibaba.com; NM=1; PH=DS; RN=6; SR=0; TI=SMTPD_---0X8TobeA_1786017116; From: Zhengrong Li To: qemu-devel@nongnu.org Cc: odaki@rsg.ci.i.u-tokyo.ac.jp, philmd@qualcomm.com, pbonzini@redhat.com, viktor.prutyanov@phystech.edu, zhengrong_li@linux.alibaba.com Subject: [PATCH v3 1/3] runstate: set crash_occurred on guest crashloaded Date: Thu, 06 Aug 2026 19:51:34 +0800 Message-ID: <178601709477.48495.14496636525040049395@linux.alibaba.com> In-Reply-To: <178601709477.48495.9850518471453430873@linux.alibaba.com> References: <178601709477.48495.9850518471453430873@linux.alibaba.com> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.99 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.99; envelope-from=zhengrong_li@linux.alibaba.com; helo=out30-99.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_PASS=-0.001, T_SPF_HELO_TEMPERROR=0.01, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1786017177392158500 Windows pvpanic driver writes PVPANIC_CRASH_LOADED (bit 1) when crash dumping is enabled, so qemu_system_guest_panicked() is not always called and crash_occurred remains false. Set crash_occurred in qemu_system_guest_crashloaded() as well, so the faulting CPU can be identified in the guest dump. Signed-off-by: Zhengrong Li Reviewed-by: Akihiko Odaki --- system/runstate.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/system/runstate.c b/system/runstate.c index 08acf801b0..c7961cc1df 100644 --- a/system/runstate.c +++ b/system/runstate.c @@ -724,6 +724,11 @@ void qemu_system_guest_panicked(GuestPanicInformation = *info) void qemu_system_guest_crashloaded(GuestPanicInformation *info) { qemu_log_mask(LOG_GUEST_ERROR, "Guest crash loaded"); + + if (current_cpu) { + current_cpu->crash_occurred =3D true; + } + qapi_event_send_guest_crashloaded(GUEST_PANIC_ACTION_RUN, info); qapi_free_GuestPanicInformation(info); } --=20 2.43.0 From nobody Mon Sep 28 01:12:07 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1786017162; cv=none; d=zohomail.com; s=zohoarc; b=eIO9nx+Vr8qnmhnnT9MBkrgg87YEbL4CHXqBdbYfzWSlz/hlErUYs5xG4zT0294wrqCGlbPr49myfZMvGaYl80FklgijULEVt3aAVq5Zzc4LGIo6vMHC2q1KHedavc8qdDeC57mOhyT2ZGAEMASYbP2NTKw5NHlfHb8LQLFKCyk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786017162; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=UqgHlXWWzFX4kz1w5/WkDBFGvm9Y+RSWkY9vjwcblnw=; b=Y/D8dJ0fCEmqvyeJJFD/m7t5rxFEIDDn3b1cIYb//mBL3W4ia8QmfShpcMWeyZNEoiCgOu5ZJPkiBPILhWkb1xGU3zir9TmxiRXMzeyyPc+zYt0ATK/wuGIAgj92FVHBPigiB2TeoWzkz+tdhgD6sgEM9N71p2V78ExGUJzZBlk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786017162700615.6656091317449; Thu, 6 Aug 2026 04:52:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wrweF-0000dH-Tk; Thu, 06 Aug 2026 07:52:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrweD-0000cc-PC for qemu-devel@nongnu.org; Thu, 06 Aug 2026 07:52:29 -0400 Received: from [115.124.30.101] (helo=out30-101.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrwe7-00083m-4P for qemu-devel@nongnu.org; Thu, 06 Aug 2026 07:52:29 -0400 Received: from U-92DF4J33-2338.local(mailfrom:zhengrong_li@linux.alibaba.com fp:SMTPD_---0X8TvDSq_1786017123 cluster:ay36) by smtp.aliyun-inc.com; Thu, 06 Aug 2026 19:52:08 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1786017129; h=From:To:Subject:Date:Message-ID:Content-Type:MIME-Version; bh=UqgHlXWWzFX4kz1w5/WkDBFGvm9Y+RSWkY9vjwcblnw=; b=axWXrUc34lWw4mNjsg9wp+7yJxAKvJ1r9ZnGK9NgUcJLteaHtANRL5v4562HzFqJSuwh7Tv9z/ew40FNSDYML2WYnyV+VwjxVtadQbPKgRqOewO1CoUXnlHQnbgS7GHt8/KVsYE/qweIQ62t3ZeBP+UHv/7B7S/mZ6NMDYp0Z+Q= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R471e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037009110; MF=zhengrong_li@linux.alibaba.com; NM=1; PH=DS; RN=6; SR=0; TI=SMTPD_---0X8TvDSq_1786017123; From: Zhengrong Li To: qemu-devel@nongnu.org Cc: odaki@rsg.ci.i.u-tokyo.ac.jp, philmd@qualcomm.com, pbonzini@redhat.com, viktor.prutyanov@phystech.edu, zhengrong_li@linux.alibaba.com Subject: [PATCH v3 2/3] dump: add crash_occurred flag to QEMUCPUState Date: Thu, 06 Aug 2026 19:51:34 +0800 Message-ID: <178601709478.48495.1330561530288193332@linux.alibaba.com> In-Reply-To: <178601709477.48495.9850518471453430873@linux.alibaba.com> References: <178601709477.48495.9850518471453430873@linux.alibaba.com> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.101 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.101; envelope-from=zhengrong_li@linux.alibaba.com; helo=out30-101.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_PASS=-0.001, T_SPF_HELO_TEMPERROR=0.01, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1786017165402158500 Add is_crash_occurred_cpu field to the local QEMUCPUState in arch_dump.c so that dump-guest-memory can record which CPU triggered the guest panic. The new field is appended after kernel_gs_base, so older tools safely ignore the extra bytes in newer dumps, and newer tools detect its absence in older dumps by checking the 'size' field. Signed-off-by: Zhengrong Li Reviewed-by: Akihiko Odaki --- target/i386/arch_dump.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/target/i386/arch_dump.c b/target/i386/arch_dump.c index 16e47c4747..8ce2c7e9bb 100644 --- a/target/i386/arch_dump.c +++ b/target/i386/arch_dump.c @@ -264,6 +264,8 @@ struct QEMUCPUState { * by checking 'size' field. */ uint64_t kernel_gs_base; + uint8_t is_crash_occurred_cpu; + uint8_t pad[7]; }; =20 typedef struct QEMUCPUState QEMUCPUState; @@ -279,6 +281,7 @@ static void copy_segment(QEMUCPUSegment *d, SegmentCach= e *s) =20 static void qemu_get_cpustate(QEMUCPUState *s, CPUX86State *env) { + CPUState *cs =3D env_cpu(env); memset(s, 0, sizeof(QEMUCPUState)); =20 s->version =3D QEMUCPUSTATE_VERSION; @@ -325,6 +328,9 @@ static void qemu_get_cpustate(QEMUCPUState *s, CPUX86St= ate *env) #ifdef TARGET_X86_64 s->kernel_gs_base =3D env->kernelgsbase; #endif + if (cs->crash_occurred) { + s->is_crash_occurred_cpu =3D 1; + } } =20 static inline int cpu_write_qemu_note(WriteCoreDumpFunction f, --=20 2.43.0 From nobody Mon Sep 28 01:12:07 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1786017194; cv=none; d=zohomail.com; s=zohoarc; b=hi+p5gFdJ1JU7+hWGOXbYEkm9bNlQ/ub9CkafrpujuyCehF8fP1JEU9ZACpGnsYT+CL1vTJ4fhi0KEe8bPrr+DBtBnzkEnHRPnmohg906Mvlob7zxRQykqd9+O38wCiL0+tNmmlmNUoB9WSOCY+aFEJf2ss2elP2phSkstC+CeE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786017194; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Ticgn9kwPOoMRioR/Pec1N76znx4SZUbf99lKRA91f4=; b=R5fpdKNm+2GtsKea3/CMgbH6zYzErp6bJ/wQ+x862lDvGhYsvt9CorggcH5r/ZOWVMNW6lEm+oA9MHUfxGWWwdvt73SNyHj4pI3Lo1h84f8CdslqJNSm3OD0L7NmMIRPwLd46VtN3ezD+lmzHyzEcSLXhEF62WCF4n03HIHhTPQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786017194583211.81160922676145; Thu, 6 Aug 2026 04:53:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wrweN-0000eT-0k; Thu, 06 Aug 2026 07:52:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrweK-0000e7-UE for qemu-devel@nongnu.org; Thu, 06 Aug 2026 07:52:36 -0400 Received: from [115.124.30.97] (helo=out30-97.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrweF-00084E-3R for qemu-devel@nongnu.org; Thu, 06 Aug 2026 07:52:36 -0400 Received: from U-92DF4J33-2338.local(mailfrom:zhengrong_li@linux.alibaba.com fp:SMTPD_---0X8Tu5Ta_1786017129 cluster:ay36) by smtp.aliyun-inc.com; Thu, 06 Aug 2026 19:52:14 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1786017135; h=From:To:Subject:Date:Message-ID:Content-Type:MIME-Version; bh=Ticgn9kwPOoMRioR/Pec1N76znx4SZUbf99lKRA91f4=; b=iewDIOpXInI0MUuQeF7NZHrSblI0uRYuQ3G/FbLOdASnuJfa530wYgbwxn4RjkNxmiGC7LzSFeVf6em2IAynZyIdovn3zhK0TFvsLirat4p0zo3ptR62MKyzUFOGDmdQl21eq9dipl0oIg3jgvX2WMPfO3YMN67Y67MD+dx9MXg= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R551e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045133197; MF=zhengrong_li@linux.alibaba.com; NM=1; PH=DS; RN=6; SR=0; TI=SMTPD_---0X8Tu5Ta_1786017129; From: Zhengrong Li To: qemu-devel@nongnu.org Cc: odaki@rsg.ci.i.u-tokyo.ac.jp, philmd@qualcomm.com, pbonzini@redhat.com, viktor.prutyanov@phystech.edu, zhengrong_li@linux.alibaba.com Subject: [PATCH v3 3/3] elf2dmp: fill ContextBuffer with faulting CPU context Date: Thu, 06 Aug 2026 19:51:34 +0800 Message-ID: <178601709478.48495.18042917568665873564@linux.alibaba.com> In-Reply-To: <178601709477.48495.9850518471453430873@linux.alibaba.com> References: <178601709477.48495.9850518471453430873@linux.alibaba.com> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.97 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.97; envelope-from=zhengrong_li@linux.alibaba.com; helo=out30-97.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_PASS=-0.001, T_SPF_HELO_TEMPERROR=0.01, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1786017197627158500 When is_crash_occurred_cpu is set in QEMUCPUState, copy that CPU's context into WinDumpHeader64 ContextBuffer so WinDbg opens on the faulting CPU instead of CPU 0. A per-CPU size check ensures the field is present before reading, supporting heterogeneous dumps. Also extract KiBugCheckData from the guest kernel to populate BugcheckCode and BugcheckParameters in the dump header. The embedded state->size is clamped to MIN(state->size, n_descsz) in init_states() to prevent reading beyond the note descriptor. Signed-off-by: Zhengrong Li Reviewed-by: Akihiko Odaki --- contrib/elf2dmp/kdbg.h | 9 +++++++ contrib/elf2dmp/main.c | 50 ++++++++++++++++++++++++++++++++++++-- contrib/elf2dmp/qemu_elf.c | 10 +++++++- contrib/elf2dmp/qemu_elf.h | 2 ++ 4 files changed, 68 insertions(+), 3 deletions(-) diff --git a/contrib/elf2dmp/kdbg.h b/contrib/elf2dmp/kdbg.h index 002e3d0cd5..15e4fb1140 100644 --- a/contrib/elf2dmp/kdbg.h +++ b/contrib/elf2dmp/kdbg.h @@ -195,4 +195,13 @@ typedef struct KDDEBUGGER_DATA64 { uint16_t OffsetPrcbContext; } KDDEBUGGER_DATA64; =20 +typedef struct KIBUGCHECK_INFO { + uint32_t BugcheckCode; + uint32_t unused0; + uint64_t BugcheckParameter1; + uint64_t BugcheckParameter2; + uint64_t BugcheckParameter3; + uint64_t BugcheckParameter4; +} KIBUGCHECK_INFO; + #endif /* KDBG_H */ diff --git a/contrib/elf2dmp/main.c b/contrib/elf2dmp/main.c index a62abadcc0..e25709b45d 100644 --- a/contrib/elf2dmp/main.c +++ b/contrib/elf2dmp/main.c @@ -338,11 +338,26 @@ static bool fill_header(WinDumpHeader64 *hdr, struct = pa_space *ps, * A dump may still contain valuable information even if it lacks contexts= of * some CPUs due to dump corruption or a failure before starting CPUs. */ -static void fill_context(KDDEBUGGER_DATA64 *kdbg, +static void fill_context(WinDumpHeader64 *hdr, KDDEBUGGER_DATA64 *kdbg, struct va_space *vs, QEMU_Elf *qe) { int i; =20 + /* First pass: identify faulting CPU and set header context early */ + for (i =3D 0; i < qe->state_nr; i++) { + QEMUCPUState *s =3D qe->state[i]; + if (s->size >=3D offsetof(QEMUCPUState, is_crash_occurred_cpu) + + sizeof(s->is_crash_occurred_cpu) && + s->is_crash_occurred_cpu) { + WinContext64 ctx; + win_context_init_from_qemu_cpu_state(&ctx, s); + memcpy(hdr->ContextBuffer, &ctx, sizeof(ctx)); + printf("Faulting CPU identified: #%d\n", i); + break; + } + } + + /* Second pass: fill context for all CPUs (best-effort) */ for (i =3D 0; i < qe->state_nr; i++) { uint64_t Prcb; uint64_t Context; @@ -512,6 +527,7 @@ int main(int argc, char *argv[]) uint64_t KdVersionBlock; bool kernel_found =3D false; OMFSignatureRSDS rsds; + uint64_t KiBugCheckData; =20 if (argc !=3D 3) { eprintf("usage:\n\t%s elf_file dmp_file\n", argv[0]); @@ -611,7 +627,37 @@ int main(int argc, char *argv[]) goto out_kdbg; } =20 - fill_context(kdbg, &vs, &qemu_elf); + if (!SYM_RESOLVE(KernBase, &pdb, KiBugCheckData)) { + eprintf("Failed to get KiBugCheckData.\n"); + } else { + KIBUGCHECK_INFO data =3D { 0 }; + if (va_space_rw(&vs, KiBugCheckData, &data, sizeof(data), 0)) { + header.BugcheckCode =3D data.BugcheckCode; + header.BugcheckParameter1 =3D data.BugcheckParameter1; + header.BugcheckParameter2 =3D data.BugcheckParameter2; + header.BugcheckParameter3 =3D data.BugcheckParameter3; + header.BugcheckParameter4 =3D data.BugcheckParameter4; + + /* + * If BugcheckCode wasn't saved, we consider guest OS as alive. + */ + if (!header.BugcheckCode) { + header.BugcheckCode =3D LIVE_SYSTEM_DUMP; + } + + printf("KiBugCheckData: 0x%016" PRIx64 + ", BugcheckCode: 0x%08" PRIx32 ", Args:" + " 0x%016" PRIx64 " 0x%016" PRIx64 + " 0x%016" PRIx64 " 0x%016" PRIx64 "\n", + KiBugCheckData, header.BugcheckCode, + data.BugcheckParameter1, data.BugcheckParameter2, + data.BugcheckParameter3, data.BugcheckParameter4); + } else { + eprintf("Failed to va_space_rw KiBugCheckData.\n"); + } + } + + fill_context(&header, kdbg, &vs, &qemu_elf); =20 if (!write_dump(&ps, &header, argv[2])) { eprintf("Failed to save dump\n"); diff --git a/contrib/elf2dmp/qemu_elf.c b/contrib/elf2dmp/qemu_elf.c index c9bad6e82c..f69023554b 100644 --- a/contrib/elf2dmp/qemu_elf.c +++ b/contrib/elf2dmp/qemu_elf.c @@ -103,7 +103,15 @@ static bool init_states(QEMU_Elf *qe) nhdr->n_descsz >=3D offsetof(QEMUCPUState, kernel_gs_base)) { state_size =3D MIN(state->size, nhdr->n_descsz); =20 - if (state_size < sizeof(*state)) { + /* + * Clamp the embedded size to the actual note descriptor size + * so that downstream size checks (e.g. fill_context) never + * read beyond the descriptor boundary. + */ + state->size =3D state_size; + + if (state_size < offsetof(QEMUCPUState, kernel_gs_base) + + sizeof(state->kernel_gs_base)) { eprintf("CPU #%u: QEMU CPU state size %u doesn't match\n", states->len, state_size); /* diff --git a/contrib/elf2dmp/qemu_elf.h b/contrib/elf2dmp/qemu_elf.h index adc50238b4..3b28332e67 100644 --- a/contrib/elf2dmp/qemu_elf.h +++ b/contrib/elf2dmp/qemu_elf.h @@ -27,6 +27,8 @@ typedef struct QEMUCPUState { QEMUCPUSegment ldt, tr, gdt, idt; uint64_t cr[5]; uint64_t kernel_gs_base; + uint8_t is_crash_occurred_cpu; + uint8_t pad[7]; } QEMUCPUState; =20 int is_system(QEMUCPUState *s); --=20 2.43.0