From nobody Mon Apr 13 11:20:05 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=unpredictable.fr ARC-Seal: i=1; a=rsa-sha256; t=1772858855; cv=none; d=zohomail.com; s=zohoarc; b=RPk9emdQEucQRSOPo+EbdcFKL9CeyDmmHVtsBp0sgnsHeP/pUI8lGaKEj0+n3cG4824havmkvXxoiDCvSEJmT6iEPmmE8StGT8r2NfOBo1UoCKQmtNSOdNaDpu7Nx8Jh59U5bR3Pj0jLOtJmr0OAoPAGZevbod00JK9/YmGwp1I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1772858855; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ZJVcSZc2jz1RmlBIDBoh7aztxEppw3g/w6m9qrnvZME=; b=KoRcaxYhQqRU/PJ771ekxm6yhoUf3XwYcHQoeesGvzfD0YYGYrSx9waZgZApOxH+uNC6DI7SYBXz1QX6GTLpGjR35foBVMJQf2vyzVKWrFy2vO6t27M8xNn+6G8dt/hZak1fOYZNvYCXjQ+x3TQBOKlgEfLgVPA/VhNyeFUKqPs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1772858855740616.32200741464; Fri, 6 Mar 2026 20:47:35 -0800 (PST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1vyjYj-0006ii-9N; Fri, 06 Mar 2026 23:46:37 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vyjYZ-0006bZ-Hr for qemu-devel@nongnu.org; Fri, 06 Mar 2026 23:46:27 -0500 Received: from p-west3-cluster5-host1-snip4-2.eps.apple.com ([57.103.72.65] helo=outbound.ms.icloud.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vyjYW-0004eB-4M for qemu-devel@nongnu.org; Fri, 06 Mar 2026 23:46:25 -0500 Received: from outbound.ms.icloud.com (unknown [127.0.0.2]) by p00-icloudmta-asmtp-us-west-3a-60-percent-4 (Postfix) with ESMTPS id 198A5180010E; Sat, 7 Mar 2026 04:46:19 +0000 (UTC) Received: from localhost.localdomain (unknown [17.57.154.37]) by p00-icloudmta-asmtp-us-west-3a-60-percent-4 (Postfix) with ESMTPSA id 253EA18000A7; Sat, 7 Mar 2026 04:46:16 +0000 (UTC) Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=unpredictable.fr; s=sig1; t=1772858782; x=1775450782; bh=ZJVcSZc2jz1RmlBIDBoh7aztxEppw3g/w6m9qrnvZME=; h=From:To:Subject:Date:Message-ID:MIME-Version:x-icloud-hme; b=Q5j3UWPBbs7VsVfJx2jS2jYTI/yFkZG35Qq4RUU6NntbIggDrlhV7mwrqDPjMTwZqpfiiyNttZOu+Paher0iaYkVm7kYV4rSuqvla1ZrhmfrVQucdACiqRKipjWLl1gdltl9f8m25Kon8gtBINR5cpBddgADXuIWtI5zB3Fsirtv7VCtk9MG+JnWI5jBaZwS17lfE6R7AFnOTWpkl12muhrhy+r63kmdkfGyL6ZgrNoTvSL58kTdtjH0rLKpSW+aQQxHtLuHjjZeMTbEHqBizdQi3LABHmcmTk/p93ynxwyelIWDW9XpLR0Q91PSL+kkiFPSyIzGsvngiKQ09x0P6Q== mail-alias-created-date: 1752046281608 From: Mohamed Mediouni To: qemu-devel@nongnu.org Cc: Paolo Bonzini , Akihiko Odaki , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Alexander Graf , qemu-arm@nongnu.org, Mads Ynddal , Peter Xu , Phil Dennis-Jordan , Peter Maydell , Roman Bolshakov , Mohamed Mediouni Subject: [PATCH v6 2/4] vmapple: apple-gfx: make it work on the latest macOS release Date: Sat, 7 Mar 2026 05:46:06 +0100 Message-ID: <20260307044608.25486-3-mohamed@unpredictable.fr> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260307044608.25486-1-mohamed@unpredictable.fr> References: <20260307044608.25486-1-mohamed@unpredictable.fr> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Authority-Info-Out: v=2.4 cv=M4pA6iws c=1 sm=1 tr=0 ts=69abad9d cx=c_apl:c_pps:t_out a=qkKslKyYc0ctBTeLUVfTFg==:117 a=XaNHVGzJZ3ayr3Wv:21 a=Yq5XynenixoA:10 a=VkNPw1HP01LnGYTKEx00:22 a=2lQx5wYd1WNrG3klcQkA:9 X-Proofpoint-GUID: 7bnagjSh0IGKi_pcSxEwtxbmvn94X3Xc X-Proofpoint-ORIG-GUID: 7bnagjSh0IGKi_pcSxEwtxbmvn94X3Xc X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwMzA3MDA0MCBTYWx0ZWRfXwTFq53vsVQyZ XSFM1Sik8jSj13ioXPyZ9/rkXDeRsK7mWsVpBbKYnYzb2DUUzSidEMCvYh0zbEeudIIV8HpknW2 IxbQb73ENPzZhSaCGf0ybVUann/8jhSGdGF+KVwAZg3TxwbkaVosUivRkGigcdHFM/WbEhBrpkM SbIZMseQIGbRPz24r+g8ytO8nS++G4srXdfSWhQEI7K+HDP1aVImSOa5vWpIDJSNM63BBc55Js0 +R4w0UTPMe0BMIXjaqXvUTSYsq5NOy2y/ptpKx8cNriZpKwCOSqIVjFECBLzlI/pH+ZJfXoxlxd DnU7SZeuYnPjX+KNUOOR5UTb8k/L0zcUM1bVu6hdJntMUDdx6oVd1ErrryjCw8= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-03-07_02,2026-03-06_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxlogscore=999 bulkscore=0 phishscore=0 mlxscore=0 malwarescore=0 adultscore=0 clxscore=1030 lowpriorityscore=0 suspectscore=0 spamscore=0 classifier=spam authscore=0 adjust=0 reason=mlx scancount=1 engine=8.22.0-2601150000 definitions=main-2603070040 X-JNJ: AAAAAAABUaXafqnRoceutUA+TZcn1W7TZ/r3Es9kQQCKrfPv7Tjl80yKaYk7scZ2+GhXfRRAsRcfON2ZDNervZPP+0PwGC3hM6RhpRu6zYOehf8GNZzPYWtA/HcJJKisYaNCbFsnR4B20UsnTLhz/9wvx2Dc2ArLBOkNkK7jGQz2MmtELDOWbcSsGcaCHkjIOaLxkv0QQe1S45tGQ+9Q86ML9lcZ7/HnukESzLSWdBv0HmXmDAVAz2dF+KiLYvI5qxZO4yqqV9NCZIpWyxOZdvHAA3f0f+4bYXSyVlLdb0f7q8tn//ZXytF2r0QugMlCP3qcQ7rNlXRm4MSicLLgXopdjkQ4IyzADSZ6EjveMdHYMhtDLRJ6/hat8AxvTkQn+oKswH3rma17nz37kDrOZfjUAcVkQQNIGI0Ey0YevukMehvI8A3l/R5141AHSYDgoT5846IFwNcrtwIqSB6N1DFSIw+eL54kQJDOKJVLWAPs+2ctMnD+NjHfTjTx8hOAAD1gRZij++gV0tSJ58/UcW7WG9bFrbos5w0kWuTEG7JEsDtIXbgQmeYTedgvpjJhaQrlZ/hPj/3fFEgcRJLYZXHi3q0KjvXyoqsHQeqRvpC2vrNhKGCuMXKEc8zBK2MpyradTPMJziMtmsrguc62C9mc+TyfVkZi5gh+7Xom0ZwA1aO90o5Qof9V+qzs8LH3dRRnQavuhrZcbSlmKPHDNaZfnZ6wfJqpBt5hkDyWsVwZuvxCTmDfMrFuekD5SMHmtsg+XmeAiYMGwbf+wgml6uRpSw== Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=57.103.72.65; envelope-from=mohamed@unpredictable.fr; helo=outbound.ms.icloud.com X-Spam_score_int: -9 X-Spam_score: -1.0 X-Spam_bar: - X-Spam_report: (-1.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.411, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.679, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @unpredictable.fr) X-ZM-MESSAGEID: 1772858857110158500 Content-Type: text/plain; charset="utf-8" Follow changes in memory management introduced on macOS 15.4. The legacy memory management API has been removed for the IOSurface mapper = on that macOS version. Also enable process isolation for a sandboxed GPU process when on a new OS. Signed-off-by: Mohamed Mediouni --- hw/display/apple-gfx-mmio.m | 59 ++++++++++++++++++++++++++++--------- hw/display/apple-gfx.h | 16 ++++++++++ hw/display/apple-gfx.m | 42 +++++++++++++++++++++++++- 3 files changed, 102 insertions(+), 15 deletions(-) diff --git a/hw/display/apple-gfx-mmio.m b/hw/display/apple-gfx-mmio.m index 58beaadd1f..cc1f8cfcad 100644 --- a/hw/display/apple-gfx-mmio.m +++ b/hw/display/apple-gfx-mmio.m @@ -19,6 +19,7 @@ #include "hw/core/irq.h" #include "apple-gfx.h" #include "trace.h" +#include "system/address-spaces.h" =20 #import =20 @@ -36,12 +37,19 @@ typedef bool(^IOSFCMapMemory)(uint64_t phys, uint64_t l= en, bool ro, void **va, =20 @interface PGDeviceDescriptor (IOSurfaceMapper) @property (readwrite, nonatomic) bool usingIOSurfaceMapper; +@property (readwrite, nonatomic) bool enableArgumentBuffers; +@property (readwrite, nonatomic) bool enableProcessIsolation; +@property (readwrite, nonatomic) bool enableProtectedContent; + +@property (readwrite, nonatomic, copy, nullable) PGMemoryMapDescriptor* me= moryMapDescriptor; @end =20 @interface PGIOSurfaceHostDeviceDescriptor : NSObject -(PGIOSurfaceHostDeviceDescriptor *)init; @property (readwrite, nonatomic, copy, nullable) IOSFCMapMemory mapMemory; @property (readwrite, nonatomic, copy, nullable) IOSFCUnmapMemory unmapMem= ory; +@property (readwrite, nonatomic, copy, nullable) PGMemoryMapDescriptor* me= moryMapDescriptor; +@property (readwrite, nonatomic) unsigned long long mmioLength; @property (readwrite, nonatomic, copy, nullable) IOSFCRaiseInterrupt raise= Interrupt; @end =20 @@ -183,19 +191,32 @@ static bool apple_gfx_mmio_unmap_surface_memory(void = *ptr) [PGIOSurfaceHostDeviceDescriptor new]; PGIOSurfaceHostDevice *iosfc_host_dev; =20 - iosfc_desc.mapMemory =3D - ^bool(uint64_t phys, uint64_t len, bool ro, void **va, void *e, vo= id *f) { - *va =3D apple_gfx_mmio_map_surface_memory(phys, len, ro); - - trace_apple_gfx_iosfc_map_memory(phys, len, ro, va, e, f, *va); - - return *va !=3D NULL; - }; - - iosfc_desc.unmapMemory =3D - ^bool(void *va, void *b, void *c, void *d, void *e, void *f) { - return apple_gfx_mmio_unmap_surface_memory(va); - }; + /* + * The legacy memory management API is no longer present + * for the IOSurface mapper as of macOS 15.4. + */ + if (@available(macOS 15.4, *)) { + PGMemoryMapDescriptor *memory_map_descriptor =3D [PGMemoryMapDescr= iptor new]; + FlatView* fv =3D address_space_to_flatview(&address_space_memory); + flatview_for_each_range(fv, apple_gfx_register_memory_cb, memory_m= ap_descriptor); + /* the device model defines this as a single-page MMIO region, hen= ce 16KB */ + iosfc_desc.mmioLength =3D 0x10000; + iosfc_desc.memoryMapDescriptor =3D memory_map_descriptor; + } else { + iosfc_desc.mapMemory =3D + ^bool(uint64_t phys, uint64_t len, bool ro, void **va, void *e= , void *f) { + *va =3D apple_gfx_mmio_map_surface_memory(phys, len, ro); + + trace_apple_gfx_iosfc_map_memory(phys, len, ro, va, e, f, = *va); + + return *va !=3D NULL; + }; + + iosfc_desc.unmapMemory =3D + ^bool(void *va, void *b, void *c, void *d, void *e, void *f) { + return apple_gfx_mmio_unmap_surface_memory(va); + }; + } =20 iosfc_desc.raiseInterrupt =3D ^bool(uint32_t vector) { trace_apple_gfx_iosfc_raise_irq(vector); @@ -223,13 +244,23 @@ static void apple_gfx_mmio_realize(DeviceState *dev, = Error **errp) }; =20 desc.usingIOSurfaceMapper =3D true; - s->pgiosfc =3D apple_gfx_prepare_iosurface_host_device(s); + desc.enableArgumentBuffers =3D true; + /*=20 + * Process isolation needs PGMemoryMapDescriptor instead of + * the legacy memory management interface present in releases + * older than macOS 15.4. + */ + if (@available(macOS 15.4, *)) { + desc.enableProcessIsolation =3D true; + } =20 if (!apple_gfx_common_realize(&s->common, dev, desc, errp)) { [s->pgiosfc release]; s->pgiosfc =3D nil; } =20 + s->pgiosfc =3D apple_gfx_prepare_iosurface_host_device(s); + [desc release]; desc =3D nil; } diff --git a/hw/display/apple-gfx.h b/hw/display/apple-gfx.h index 3197bd853d..384aee0c5f 100644 --- a/hw/display/apple-gfx.h +++ b/hw/display/apple-gfx.h @@ -12,6 +12,7 @@ #include "system/memory.h" #include "hw/core/qdev-properties.h" #include "ui/surface.h" +#include "objc/NSObject.h" =20 #define TYPE_APPLE_GFX_MMIO "apple-gfx-mmio" #define TYPE_APPLE_GFX_PCI "apple-gfx-pci" @@ -23,6 +24,17 @@ @protocol MTLTexture; @protocol MTLCommandQueue; =20 +typedef struct PGGuestPhysicalRange_s +{ + uint64_t physicalAddress; + uint64_t physicalLength; + void *hostAddress; +} PGGuestPhysicalRange_t; + +@interface PGMemoryMapDescriptor : NSObject +-(void)addRange:(PGGuestPhysicalRange_t) range; +@end + typedef QTAILQ_HEAD(, PGTask_s) PGTaskList; =20 typedef struct AppleGFXDisplayMode { @@ -68,6 +80,10 @@ void *apple_gfx_host_ptr_for_gpa_range(uint64_t guest_ph= ysical, uint64_t length, bool read_only, MemoryRegion **mapping_in_region); =20 +bool apple_gfx_register_memory_cb(Int128 start, Int128 len, + const MemoryRegion *mr, + hwaddr offset_in_region, void *opaque); + extern const PropertyInfo qdev_prop_apple_gfx_display_mode; =20 #endif diff --git a/hw/display/apple-gfx.m b/hw/display/apple-gfx.m index e0a765fcb1..24584bca5b 100644 --- a/hw/display/apple-gfx.m +++ b/hw/display/apple-gfx.m @@ -21,6 +21,7 @@ #include "system/address-spaces.h" #include "system/dma.h" #include "migration/blocker.h" +#include "system/memory.h" #include "ui/console.h" #include "apple-gfx.h" #include "trace.h" @@ -596,6 +597,36 @@ void apple_gfx_common_init(Object *obj, AppleGFXState = *s, const char* obj_name) /* TODO: PVG framework supports serialising device state: integrate it= ! */ } =20 +@interface PGDeviceDescriptor (IOSurfaceMapper) +@property (readwrite, nonatomic, copy, nullable) PGMemoryMapDescriptor* me= moryMapDescriptor; +@end + +bool apple_gfx_register_memory_cb(Int128 start, Int128 len, + const MemoryRegion *mr, + hwaddr offset_in_region, void *opaque) { + PGGuestPhysicalRange_t range; + PGMemoryMapDescriptor *memory_map_descriptor =3D opaque; + if (memory_access_is_direct(mr, true, MEMTXATTRS_UNSPECIFIED)) { + range.physicalAddress =3D start; + range.physicalLength =3D len; + range.hostAddress =3D memory_region_get_ram_ptr(mr); + [memory_map_descriptor addRange:range]; + memory_region_ref(mr); + } + return false; +} + +static void apple_gfx_register_memory(AppleGFXState *s, + PGDeviceDescriptor *d= esc) +{ + PGMemoryMapDescriptor* memoryMapDescriptor =3D [PGMemoryMapDescriptor = new]; + + FlatView* fv =3D address_space_to_flatview(&address_space_memory); + flatview_for_each_range(fv, apple_gfx_register_memory_cb, memoryMapDes= criptor); + + desc.memoryMapDescriptor =3D memoryMapDescriptor; +} + static void apple_gfx_register_task_mapping_handlers(AppleGFXState *s, PGDeviceDescriptor *d= esc) { @@ -763,7 +794,16 @@ bool apple_gfx_common_realize(AppleGFXState *s, Device= State *dev, =20 desc.device =3D s->mtl; =20 - apple_gfx_register_task_mapping_handlers(s, desc); + /*=20 + * The legacy memory management interface doesn't allow for + * vGPU sandboxing. As such, always use the new interface + * on macOS 15.4 onwards.=20 + */ + if (@available(macOS 15.4, *)) { + apple_gfx_register_memory(s, desc); + } else { + apple_gfx_register_task_mapping_handlers(s, desc); + } =20 s->cursor_show =3D true; =20 --=20 2.50.1 (Apple Git-155)