From nobody Thu Jan 8 13:17:12 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=unpredictable.fr ARC-Seal: i=1; a=rsa-sha256; t=1767021624; cv=none; d=zohomail.com; s=zohoarc; b=ms8WOJLqtNRG2bdbcha1S19NiDnpExs/AoCkft83s/Tv3ZTMAyuAkS2JD9bqORyFzA8bDGYMtzg6kMZTYr2uczMmuIbqhShKfHv/M2C7/OXgZxfrt4bCT7fwgMkG6V7AUv8MIbhuvEpqwHLx0ewQowu3WRtu1R+QiMEMD3EVcPU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1767021624; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lgwCp5DfxciUDn8r7r6up05OxWfXTLGq2WF/7T24a1c=; b=fkXWbq77fongrbCaOVWhlAgCz/wRDXcZiWckZQB9tVW/ufnYAsOZfJnbx7eTvnMGTecOsnhc5BFXH4cHPRdiB1uekhTZ9Et05sc7VIyB10wjgiBgr5xcuzDE01hGcza0v5Nsz0UC5kLreUGEvcKPg1AXkcc3HaqUrf1iw0bhBys= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 176702162390976.94848151050292; Mon, 29 Dec 2025 07:20:23 -0800 (PST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1vaF1q-0001Zi-TG; Mon, 29 Dec 2025 10:19:26 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vaF1j-0001WB-9I for qemu-devel@nongnu.org; Mon, 29 Dec 2025 10:19:20 -0500 Received: from p-west1-cluster3-host6-snip4-5.eps.apple.com ([57.103.66.18] helo=outbound.pv.icloud.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vaF1h-0004dZ-3o for qemu-devel@nongnu.org; Mon, 29 Dec 2025 10:19:18 -0500 Received: from outbound.pv.icloud.com (unknown [127.0.0.2]) by p00-icloudmta-asmtp-us-west-1a-10-percent-1 (Postfix) with ESMTPS id D755E1800293; Mon, 29 Dec 2025 15:19:12 +0000 (UTC) Received: from localhost.localdomain (unknown [17.56.9.36]) by p00-icloudmta-asmtp-us-west-1a-10-percent-1 (Postfix) with ESMTPSA id 000DC18005BC; Mon, 29 Dec 2025 15:19:08 +0000 (UTC) Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=unpredictable.fr; s=sig1; bh=lgwCp5DfxciUDn8r7r6up05OxWfXTLGq2WF/7T24a1c=; h=From:To:Subject:Date:Message-ID:MIME-Version:x-icloud-hme; b=UGc8MIpoYBZBd4ub7fNh0nRxV50+2j8/kmK+Wc1g0OSdnAFmVjGilIjOLhVyAXlMFApDlUFk/fmW3OoLeKAxRKrCPve8kS8GKngzJe6qbnZxDw5ClEafzY0VQwWWdAaqFiYJ3PartGWoHajRfwIdUlW8K8CiDROyzUyF6BeEABvI8PdT4h3cDVFhhbgfcmOVxs0pZmJY0ZC67aULQc/wyNcBL/ubK3jxK+IuOuHCtHkhCjDwNJnfBRdjV8E5GE4PFX6MmRGpHwjjtCI4vljrFbZO+eSX+whke0j/bdXQKwd/TuJxjUZF9HTDiHbOlsed9wYwmGayQGVVKAlyxh6jdw== mail-alias-created-date: 1752046281608 From: Mohamed Mediouni To: qemu-devel@nongnu.org Cc: Roman Bolshakov , Mads Ynddal , Phil Dennis-Jordan , Alexander Graf , Peter Maydell , Cameron Esfahani , qemu-arm@nongnu.org, Mohamed Mediouni Subject: [RFC v3 2/4] vmapple: apple-gfx: make it work on the latest macOS release Date: Mon, 29 Dec 2025 16:18:48 +0100 Message-ID: <20251229151850.96852-3-mohamed@unpredictable.fr> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20251229151850.96852-1-mohamed@unpredictable.fr> References: <20251229151850.96852-1-mohamed@unpredictable.fr> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Proofpoint-Spam-Details-Enc: AW1haW4tMjUxMjI5MDE0MCBTYWx0ZWRfXyMGK16BH7AJH QFR/P2A4xCGjYRgCmSmFIpi6X9URvYfqrPyHIcyM/1KZxECNzWxzj9Fm0E5g6igGXfNVefxwguy 4AXw29GARW0KGHYrPAVw1HszrPshUZUzYSxT8rIVVHtUdOW6t6XVkqYGDKkmMA3+juS3wDqmNFF aryRjyvKUEaebh2OW4Bm0bp5VQ/JjM1rWicvz+k/MDw/5SpD33TOA84S7px9zDkaE+6D/w/Xl8Z BV8kCEG8FqzZy1zWX9YvaXZgsrSM16Sl6zHajc/970AZZiAswntTl3FvfqDrjQnTaBZrzyCd+P6 GZwKUrowtWxui+RBmh+ X-Proofpoint-GUID: jTB4IL4EJfCznX7_eMSjKVNkxBWFjiEO X-Authority-Info: v=2.4 cv=d+b4CBjE c=1 sm=1 tr=0 ts=69529bf1 cx=c_apl:c_pps a=azHRBMxVc17uSn+fyuI/eg==:117 a=azHRBMxVc17uSn+fyuI/eg==:17 a=XaNHVGzJZ3ayr3Wv:21 a=wP3pNCr1ah4A:10 a=VkNPw1HP01LnGYTKEx00:22 a=qV0ahJ5E5Ghjqxzh6q4A:9 X-Proofpoint-ORIG-GUID: jTB4IL4EJfCznX7_eMSjKVNkxBWFjiEO X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1121,Hydra:6.1.9,FMLib:17.12.100.49 definitions=2025-12-29_04,2025-12-29_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxscore=0 malwarescore=0 suspectscore=0 bulkscore=0 spamscore=0 clxscore=1030 adultscore=0 phishscore=0 mlxlogscore=999 classifier=spam authscore=0 adjust=0 reason=mlx scancount=1 engine=8.22.0-2510240001 definitions=main-2512290140 X-JNJ: AAAAAAAB+FbBXeRK+XBThZrM7nu/u6Xy8c7jSQGFNR5Rd+mrXOnCyLIEbawzsKPjzuJHVRj8LzJRyfp/JpsAl4/sEdtydlVGcjpJPr+IaUQLG5w34AT3WRNbagWGaU1WcTH58GUfTczPWyKiZKNwAXTkDTGMDX4gL/ucUPDG/KNXTK/InxwDwvVv5rGdunQQ1xwU/fHI3ad69STk99u1TFF2itZIaAQFAIajhXn1BUQ8oslhnfstJOqB85LPkPZkFCdfQBPpLxp/SoXuTpfN7BL1wbpDeEoyEzzMnseIDJTZPO3RHTfFIlCKpmphLOsFT/q3ttz6SoiWyIQRyl5Hfpka/xA/7KPokGQ6ZifVRjSxDmvsqtCkR4TXxOD5u88ISLs9r/0rekTmC6AFZ6aKxvP9JLJq75Gkh7ScP9+GT1MTj/qtWm3aiCWPq89cSUXhZjRRyOM99YsGqbAWWq4XnP1Za5lsGoByN/fj84Fp4oJ3UKy9cGtJ4a9tvgvvfFgGzMWnbWmmg/vg5GtJpylCwx42wSitNROT/yH3ZH0RzJeBU/5W2+dYz0qs9WZJ6Y/v4al0JjzBqU6owWNFslEsy7TZkNiJoinQ1P4iaofi6WeKtheviCON/f113SEKh+YicL5RqDYdHG36BSvbLsUUC3/8QDdB8VprT2eRwgRgk2x0QzTp+vjmkcdQ8dQBnT71jQ6ISdqMF9thd2FK Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=57.103.66.18; envelope-from=mohamed@unpredictable.fr; helo=outbound.pv.icloud.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @unpredictable.fr) X-ZM-MESSAGEID: 1767021630142158500 Content-Type: text/plain; charset="utf-8" Follow changes in memory management introduced on macOS 15.4. The legacy memory management API has been removed for the IOSurface mapper = on that macOS version. Also enable process isolation for a sandboxed GPU process when on a new OS. Signed-off-by: Mohamed Mediouni --- hw/display/apple-gfx-mmio.m | 65 ++++++++++++++++++++++++++++--------- hw/display/apple-gfx.h | 13 ++++++++ hw/display/apple-gfx.m | 47 ++++++++++++++++++++++++++- 3 files changed, 109 insertions(+), 16 deletions(-) diff --git a/hw/display/apple-gfx-mmio.m b/hw/display/apple-gfx-mmio.m index 58beaadd1f..2031baceda 100644 --- a/hw/display/apple-gfx-mmio.m +++ b/hw/display/apple-gfx-mmio.m @@ -19,6 +19,7 @@ #include "hw/core/irq.h" #include "apple-gfx.h" #include "trace.h" +#include "system/address-spaces.h" =20 #import =20 @@ -34,14 +35,25 @@ typedef bool(^IOSFCMapMemory)(uint64_t phys, uint64_t len, bool ro, void *= *va, void *, void *); =20 +@interface PGMemoryMapDescriptor : NSObject +-(void)addRange:(struct PGGuestPhysicalRange_s) range; +@end + @interface PGDeviceDescriptor (IOSurfaceMapper) @property (readwrite, nonatomic) bool usingIOSurfaceMapper; +@property (readwrite, nonatomic) bool enableArgumentBuffers; +@property (readwrite, nonatomic) bool enableProcessIsolation; +@property (readwrite, nonatomic) bool enableProtectedContent; + +@property (readwrite, nonatomic, copy, nullable) PGMemoryMapDescriptor* me= moryMapDescriptor; @end =20 @interface PGIOSurfaceHostDeviceDescriptor : NSObject -(PGIOSurfaceHostDeviceDescriptor *)init; @property (readwrite, nonatomic, copy, nullable) IOSFCMapMemory mapMemory; @property (readwrite, nonatomic, copy, nullable) IOSFCUnmapMemory unmapMem= ory; +@property (readwrite, nonatomic, copy, nullable) PGMemoryMapDescriptor* me= moryMapDescriptor; +@property (readwrite, nonatomic) unsigned long long mmioLength; @property (readwrite, nonatomic, copy, nullable) IOSFCRaiseInterrupt raise= Interrupt; @end =20 @@ -182,20 +194,33 @@ static bool apple_gfx_mmio_unmap_surface_memory(void = *ptr) PGIOSurfaceHostDeviceDescriptor *iosfc_desc =3D [PGIOSurfaceHostDeviceDescriptor new]; PGIOSurfaceHostDevice *iosfc_host_dev; - - iosfc_desc.mapMemory =3D - ^bool(uint64_t phys, uint64_t len, bool ro, void **va, void *e, vo= id *f) { - *va =3D apple_gfx_mmio_map_surface_memory(phys, len, ro); - - trace_apple_gfx_iosfc_map_memory(phys, len, ro, va, e, f, *va); - - return *va !=3D NULL; - }; - - iosfc_desc.unmapMemory =3D - ^bool(void *va, void *b, void *c, void *d, void *e, void *f) { - return apple_gfx_mmio_unmap_surface_memory(va); - }; + PGMemoryMapDescriptor* memoryMapDescriptor =3D [PGMemoryMapDescriptor = new]; + + /* + * The legacy memory management API is no longer present + * for the IOSurface mapper as of macOS 15.4. + */ + if (@available(macOS 15.4, *)) { + FlatView* fv =3D address_space_to_flatview(&address_space_memory); + flatview_for_each_range(fv, apple_gfx_register_memory_cb, memoryMa= pDescriptor); + /* Single-page MMIO region: 16KB */ + iosfc_desc.mmioLength =3D 0x10000; + iosfc_desc.memoryMapDescriptor =3D memoryMapDescriptor; + } else { + iosfc_desc.mapMemory =3D + ^bool(uint64_t phys, uint64_t len, bool ro, void **va, void *e= , void *f) { + *va =3D apple_gfx_mmio_map_surface_memory(phys, len, ro); + + trace_apple_gfx_iosfc_map_memory(phys, len, ro, va, e, f, = *va); + + return *va !=3D NULL; + }; + + iosfc_desc.unmapMemory =3D + ^bool(void *va, void *b, void *c, void *d, void *e, void *f) { + return apple_gfx_mmio_unmap_surface_memory(va); + }; + } =20 iosfc_desc.raiseInterrupt =3D ^bool(uint32_t vector) { trace_apple_gfx_iosfc_raise_irq(vector); @@ -223,13 +248,23 @@ static void apple_gfx_mmio_realize(DeviceState *dev, = Error **errp) }; =20 desc.usingIOSurfaceMapper =3D true; - s->pgiosfc =3D apple_gfx_prepare_iosurface_host_device(s); + desc.enableArgumentBuffers =3D true; + /*=20 + * Process isolation needs PGMemoryMapDescriptor instead of + * the legacy memory management interface present in releases + * older than macOS 15.4. + */ + if (@available(macOS 15.4, *)) { + desc.enableProcessIsolation =3D true; + } =20 if (!apple_gfx_common_realize(&s->common, dev, desc, errp)) { [s->pgiosfc release]; s->pgiosfc =3D nil; } =20 + s->pgiosfc =3D apple_gfx_prepare_iosurface_host_device(s); + [desc release]; desc =3D nil; } diff --git a/hw/display/apple-gfx.h b/hw/display/apple-gfx.h index 3197bd853d..1b94a55a7d 100644 --- a/hw/display/apple-gfx.h +++ b/hw/display/apple-gfx.h @@ -23,6 +23,13 @@ @protocol MTLTexture; @protocol MTLCommandQueue; =20 +typedef struct PGGuestPhysicalRange_s +{ + uint64_t physicalAddress; + uint64_t physicalLength; + void *hostAddress; +} PGGuestPhysicalRange_t; + typedef QTAILQ_HEAD(, PGTask_s) PGTaskList; =20 typedef struct AppleGFXDisplayMode { @@ -68,6 +75,12 @@ void *apple_gfx_host_ptr_for_gpa_range(uint64_t guest_ph= ysical, uint64_t length, bool read_only, MemoryRegion **mapping_in_region); =20 +bool apple_gfx_register_memory_cb(Int128 start, + Int128 len, + const MemoryRegion *mr, + hwaddr offset_in_region, + void *opaque); + extern const PropertyInfo qdev_prop_apple_gfx_display_mode; =20 #endif diff --git a/hw/display/apple-gfx.m b/hw/display/apple-gfx.m index e0a765fcb1..68ca8e93b6 100644 --- a/hw/display/apple-gfx.m +++ b/hw/display/apple-gfx.m @@ -21,6 +21,7 @@ #include "system/address-spaces.h" #include "system/dma.h" #include "migration/blocker.h" +#include "system/memory.h" #include "ui/console.h" #include "apple-gfx.h" #include "trace.h" @@ -596,6 +597,41 @@ void apple_gfx_common_init(Object *obj, AppleGFXState = *s, const char* obj_name) /* TODO: PVG framework supports serialising device state: integrate it= ! */ } =20 +@interface PGMemoryMapDescriptor : NSObject +-(void)addRange:(struct PGGuestPhysicalRange_s) range; +@end + +@interface PGDeviceDescriptor (IOSurfaceMapper) +@property (readwrite, nonatomic, copy, nullable) PGMemoryMapDescriptor* me= moryMapDescriptor; +@end + +bool apple_gfx_register_memory_cb(Int128 start, + Int128 len, + const MemoryRegion *mr, + hwaddr offset_in_region, + void *opaque) { + PGGuestPhysicalRange_t range; + PGMemoryMapDescriptor* memoryMapDescriptor =3D opaque; + if (mr->ram) { + range.physicalAddress =3D start; + range.physicalLength =3D len; + range.hostAddress =3D memory_region_get_ram_ptr(mr); + [memoryMapDescriptor addRange:range]; + } + return false; +} + +static void apple_gfx_register_memory(AppleGFXState *s, + PGDeviceDescriptor *d= esc) +{ + PGMemoryMapDescriptor* memoryMapDescriptor =3D [PGMemoryMapDescriptor = new]; + + FlatView* fv =3D address_space_to_flatview(&address_space_memory); + flatview_for_each_range(fv, apple_gfx_register_memory_cb, memoryMapDes= criptor); + + desc.memoryMapDescriptor =3D memoryMapDescriptor; +} + static void apple_gfx_register_task_mapping_handlers(AppleGFXState *s, PGDeviceDescriptor *d= esc) { @@ -763,7 +799,16 @@ bool apple_gfx_common_realize(AppleGFXState *s, Device= State *dev, =20 desc.device =3D s->mtl; =20 - apple_gfx_register_task_mapping_handlers(s, desc); + /*=20 + * The legacy memory management interface doesn't allow for + * vGPU sandboxing. As such, always use the new interface + * on macOS 15.4 onwards.=20 + */ + if (@available(macOS 15.4, *)) { + apple_gfx_register_memory(s, desc); + } else { + apple_gfx_register_task_mapping_handlers(s, desc); + } =20 s->cursor_show =3D true; =20 --=20 2.50.1 (Apple Git-155)