From nobody Sun Jul 26 11:54:47 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=oracle.com ARC-Seal: i=1; a=rsa-sha256; t=1782331286; cv=none; d=zohomail.com; s=zohoarc; b=Dx/bKqK8XyIDNi+YcN7/b9Lo6oJPd0TsF+wuEjpZs+Motyrd4dsUb+RR3cAGIqtkRHYZcjQVkaauvmPS6Ab0uexZieYhPW2QHWniuiYaCgwUoBG9TsXAEpRPCfEuTTzUrQ7UWozPdB0hKRStUbenzp5oAEAdvO6vDhk+dazE5Pc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782331286; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=IpaBH6rQs/JVSlvo2pJdyMQwFZskYQ/gRorcE+dtrDo=; b=EV45oJkNTK+7mtx905KxHIjWeNvjk0uRJhCQnQve1w03jIH11CoOs8kdWs/iWs9Xp/OGxYvWm+HNB/OPbqCl8VKyNc0R0B0AusTZOrRJ/tNKCJmfVT/+0hfZebGZ/8qZkAPEkfOVIbcm+tAj3YjRpEaAWpGebRZ6We/OzJT/uVM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782331286905993.2114284388866; Wed, 24 Jun 2026 13:01:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcTlD-0005ap-ST; Wed, 24 Jun 2026 15:59:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcTl0-0005XA-Nq for qemu-devel@nongnu.org; Wed, 24 Jun 2026 15:59:34 -0400 Received: from mx0b-00069f02.pphosted.com ([205.220.177.32]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcTky-00083j-1N for qemu-devel@nongnu.org; Wed, 24 Jun 2026 15:59:34 -0400 Received: from pps.filterd (m0246632.ppops.net [127.0.0.1]) by mx0b-00069f02.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 65OEVGEU2562366; Wed, 24 Jun 2026 19:59:28 GMT Received: from iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta01.appoci.oracle.com [130.35.100.223]) by mx0b-00069f02.pphosted.com (PPS) with ESMTPS id 4ewjfue1vu-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 24 Jun 2026 19:59:27 +0000 (GMT) Received: from pps.filterd (iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (8.18.1.7/8.18.1.7) with ESMTP id 65OJwck4009044; Wed, 24 Jun 2026 19:59:27 GMT Received: from pps.reinject (localhost [127.0.0.1]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTPS id 4ewhas3kx8-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 24 Jun 2026 19:59:26 +0000 (GMT) Received: from iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by pps.reinject (8.18.1.12/8.18.1.12) with ESMTP id 65OJuO8E004335; Wed, 24 Jun 2026 19:59:26 GMT Received: from alaljime-e5-test-20240903-1847.osdevelopmeniad.oraclevcn.com (alaljime-e5-test-20240903-1847.allregionaliads.osdevelopmeniad.oraclevcn.com [100.100.250.206]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTP id 4ewhas3kwx-2; Wed, 24 Jun 2026 19:59:26 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=corp-2025-04-25; bh=IpaBH 6rQs/JVSlvo2pJdyMQwFZskYQ/gRorcE+dtrDo=; b=A5e8gtDB+5Muzw9HPirrf ouykxjjhSaE8H2iPc641JA4I2v8L4vRCh6PZuvjulqUiUothtMwWtFvpLDhxW8jD rQCuRgzHlgGO49LolJiCjFtLnfdIGh8gyMfTGBjJmPRqnjSE2RITRsRpG1pzxNZf f9Zdq6Bj87KGKdXXttuHy7/BQfUGf/GLGFq4hyxNBWMOWxkxWv8bMDGyUENZXpAY CHojUtYHG2zuD8pAcBv5uQFoI9k3sWqmiAt7tjLAkahs1gPid2BTkRGVVGOQN//J ny5vgKfwcA1BWghb187lwunKE8wpxO54gWqKQkmhRxEdWBbvCnaXROYYgfbtDXgp Q== From: Alejandro Jimenez To: qemu-devel@nongnu.org Cc: peter.maydell@linaro.org, mst@redhat.com, sarunkod@amd.com, pbonzini@redhat.com, richard.henderson@linaro.org, alejandro.j.jimenez@oracle.com Subject: [PATCH v2 1/4] amd_iommu: Return int from page walk status helpers Date: Wed, 24 Jun 2026 19:59:22 +0000 Message-ID: <20260624195925.1254462-2-alejandro.j.jimenez@oracle.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260624195925.1254462-1-alejandro.j.jimenez@oracle.com> References: <20260624195925.1254462-1-alejandro.j.jimenez@oracle.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-06-24_04,2026-06-24_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 phishscore=0 adultscore=0 malwarescore=0 mlxlogscore=999 mlxscore=0 suspectscore=0 bulkscore=0 spamscore=0 lowpriorityscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2606160000 definitions=main-2606240167 X-Proofpoint-Spam-Info: AW1haW4tMjYwNjI0MDE2NyBTYWx0ZWRfX1oRu+IW4PD0P Z1apk0LR5qFn/zOWWVd8kx1E4tK5I7nAAPIUpe+qnKk0YpgN26p5cahpStDBBAjo4c09IBKv9F3 nxo4aOHjv3EhQy+YShglw+n4r5gB2X2V7M8XTCgzr5KMelK/yEUc X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNjI0MDE2NyBTYWx0ZWRfX/KPnt16M+XrO 0UqGQAFGJtYup95SE3/hFDjn8KSsjsLEybMuzy0LYAzRGF6LOvfvIokZ2v4IgRrqZqt5aV+diLj bPyN9O/2tSpzqT4np5GU+/7/16t2g4GfI0IyvxyWhTL4bZju+Er1NGdDPGaKXVcwmUvyYh2ttiX GFI3gzy0/s0OQe0IUNxprUYYRuQPpRmnnNYXo+Rs7Fa4fRVrE+YOCRF5E3JCMyV6bFyQZ8Ak29c qBkt+87Wo2PQ3KU4gXVhuxAftREwD2HzIRODrEyQmM1iuHwFInPb15NHNl1SSg5KI48C1Pw251E 7tOj8tNl9VkaBhglvsVqcDtlgbil0hz1QwTVOcsblEx6m4TAl/3zcfgz/itcAvhE/NrE3emWkGB B5oVUWjIfj0Uu0cMvQtGXRm7r3ImeC7P43TMdnUMwfH/uTXgHwk= X-Proofpoint-ORIG-GUID: YBvAnb2Wb4X14QIHAjm9LrREzmp9P2zN X-Proofpoint-GUID: YBvAnb2Wb4X14QIHAjm9LrREzmp9P2zN X-Authority-Analysis: v=2.4 cv=FtI1OWrq c=1 sm=1 tr=0 ts=6a3c371f b=1 cx=c_pps a=zPCbziy225d3KhSqZt3L1A==:117 a=zPCbziy225d3KhSqZt3L1A==:17 a=FelO9ux0wxsA:10 a=VkNPw1HP01LnGYTKEx00:22 a=jiCTI4zE5U7BLdzWsZGv:22 a=3I1J8UUJPc9JN9BFgKH3:22 a=KKAkSRfTAAAA:8 a=yPCof4ZbAAAA:8 a=CPMDAz_8QbydQVlharwA:9 a=cvBusfyB2V15izCimMoJ:22 a=5yU3S35YU4bGjq-dph-N:22 a=Bho9c0fBagfJEIQBS7DQ:22 cc=ntf awl=host:12312 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=205.220.177.32; envelope-from=alejandro.j.jimenez@oracle.com; helo=mx0b-00069f02.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @oracle.com) X-ZM-MESSAGEID: 1782331287998158500 Content-Type: text/plain; charset="utf-8" fetch_pte() returns a status code 0 on success, and (small) negative values on failure. The PTE value itself is returned via an output parameter. amdvi_get_top_pt_level_and_perms() follows the same return convention. Both functions currently return uint64_t, which means any negative error values are returned as unsigned and then converted back to int by the callers. This does not cause any issues in the current implementation, but Coverity flags the type mismatch and potential overflow. Make both helpers return int, so the type matches what the return variable is (0 on success, small negative value on failure), and also the type used by all callers to store their return values. No functional changes are intended. Fixes: a1c97c395729 ("amd_iommu: Sync shadow page tables on page invalidati= on") Fixes: 786550e2d38a ("amd_iommu: Follow root pointer before page walk and u= se 1-based levels") Reported-by: Peter Maydell Suggested-by: Peter Maydell Signed-off-by: Alejandro Jimenez Reviewed-by: Peter Maydell --- hw/i386/amd_iommu.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/hw/i386/amd_iommu.c b/hw/i386/amd_iommu.c index 79216fb305..0d273fd33d 100644 --- a/hw/i386/amd_iommu.c +++ b/hw/i386/amd_iommu.c @@ -659,7 +659,7 @@ static uint64_t large_pte_page_size(uint64_t pte) * - IOVA exceeds the address width supported by DTE[Mode] * In all such cases a page walk must be aborted. */ -static uint64_t amdvi_get_top_pt_level_and_perms(hwaddr address, uint64_t = dte, +static int amdvi_get_top_pt_level_and_perms(hwaddr address, uint64_t dte, uint8_t *top_level, IOMMUAccessFlags *dte_per= ms) { @@ -702,7 +702,7 @@ static uint64_t amdvi_get_top_pt_level_and_perms(hwaddr= address, uint64_t dte, * page table walk. This means that the DTE has valid data, but one o= f the * lower level entries in the Page Table could not be read. */ -static uint64_t fetch_pte(AMDVIAddressSpace *as, hwaddr address, uint64_t = dte, +static int fetch_pte(AMDVIAddressSpace *as, hwaddr address, uint64_t dte, uint64_t *pte, hwaddr *page_size) { uint64_t pte_addr; --=20 2.47.3 From nobody Sun Jul 26 11:54:47 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=oracle.com ARC-Seal: i=1; a=rsa-sha256; t=1782331314; cv=none; d=zohomail.com; s=zohoarc; b=NCefhIFNayKRTK8RuGfyVZ1ZNOp8K/zlRcK5lnUIDY4BbNja5L7gxd1Q25cYL6EHtGh/c162T77tMykkE4+82ytJFrDnVrxi7W/x3UZJy5+PHr8SJ0SynZ7Ppi5xW5AAzMCqmzQt84fjdbUSKs5zT9a9MVc6KtgxXkoAnkKuXDw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782331314; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=uvRQ49MLRvXujpAUwRE0Buhp53NTNkhgCDHPLUJ/cj8=; b=RsODDk9CpE+tyhD662AsnC7+N2sfEJf19UcMsflwZzklkxKrazR/Irzog00Sk+XIG2sy+saoalhIEHPLEJfNCED7Pjy7eeCZmru0xpcg/UXGM4mbesvUTcww0kTFx5aevKCa4MMqq5ty4ZX7oirxvjFMEUmDnEwXMdAP1fdShNk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782331314035162.14224123618067; Wed, 24 Jun 2026 13:01:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcTl8-0005Zc-Iw; Wed, 24 Jun 2026 15:59:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcTl0-0005XC-OL for qemu-devel@nongnu.org; Wed, 24 Jun 2026 15:59:34 -0400 Received: from mx0b-00069f02.pphosted.com ([205.220.177.32]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcTkx-00083P-Tx for qemu-devel@nongnu.org; Wed, 24 Jun 2026 15:59:34 -0400 Received: from pps.filterd (m0333520.ppops.net [127.0.0.1]) by mx0b-00069f02.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 65OEUxN02701409; Wed, 24 Jun 2026 19:59:28 GMT Received: from iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta01.appoci.oracle.com [130.35.100.223]) by mx0b-00069f02.pphosted.com (PPS) with ESMTPS id 4ewjwce501-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 24 Jun 2026 19:59:27 +0000 (GMT) Received: from pps.filterd (iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (8.18.1.7/8.18.1.7) with ESMTP id 65OJwcfA009164; Wed, 24 Jun 2026 19:59:27 GMT Received: from pps.reinject (localhost [127.0.0.1]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTPS id 4ewhas3kxc-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 24 Jun 2026 19:59:27 +0000 (GMT) Received: from iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by pps.reinject (8.18.1.12/8.18.1.12) with ESMTP id 65OJuO8G004335; Wed, 24 Jun 2026 19:59:26 GMT Received: from alaljime-e5-test-20240903-1847.osdevelopmeniad.oraclevcn.com (alaljime-e5-test-20240903-1847.allregionaliads.osdevelopmeniad.oraclevcn.com [100.100.250.206]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTP id 4ewhas3kwx-3; Wed, 24 Jun 2026 19:59:26 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=corp-2025-04-25; bh=uvRQ4 9MLRvXujpAUwRE0Buhp53NTNkhgCDHPLUJ/cj8=; b=TdZS2Xapv9NCTB4N5F6nv 5l4VZeZuTyVr6QUKGcpSEbG5edFQp7gwlekJznQ5vHYdPQxWPnHXThN2qVNmuv8K IQPI2vdDSWv2cyrul2afjOJXz0asM995itTcJz4q2nRtOAqRFmiXM32sY677UOKR LyWCH8EgSfB3eyKV1+hbizCmXn2LEhy/hYx5nByyvpyR2iBY2AxC8VzNgDDXNw5Z gq/e/KZn73mvyYKUyAgEjZJi6JXaTDF2Ot8QlXnOMVVSuG9mRn0i4pp5M9DbRd5h 2s2UO2IITTPRIYc/ilvMTr4O1JGME1lO890qoIf9VeUXMMnoxVHj2nP9w+Cnreg1 A== From: Alejandro Jimenez To: qemu-devel@nongnu.org Cc: peter.maydell@linaro.org, mst@redhat.com, sarunkod@amd.com, pbonzini@redhat.com, richard.henderson@linaro.org, alejandro.j.jimenez@oracle.com Subject: [PATCH v2 2/4] amd_iommu: Decode XT interrupt control register without bitfields Date: Wed, 24 Jun 2026 19:59:23 +0000 Message-ID: <20260624195925.1254462-3-alejandro.j.jimenez@oracle.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260624195925.1254462-1-alejandro.j.jimenez@oracle.com> References: <20260624195925.1254462-1-alejandro.j.jimenez@oracle.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-06-24_04,2026-06-24_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 phishscore=0 adultscore=0 malwarescore=0 mlxlogscore=999 mlxscore=0 suspectscore=0 bulkscore=0 spamscore=0 lowpriorityscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2606160000 definitions=main-2606240167 X-Authority-Analysis: v=2.4 cv=eJAjSnp1 c=1 sm=1 tr=0 ts=6a3c371f b=1 cx=c_pps a=zPCbziy225d3KhSqZt3L1A==:117 a=zPCbziy225d3KhSqZt3L1A==:17 a=FelO9ux0wxsA:10 a=VkNPw1HP01LnGYTKEx00:22 a=jiCTI4zE5U7BLdzWsZGv:22 a=BqU2WV_vvsyTyxaotp0D:22 a=KKAkSRfTAAAA:8 a=yPCof4ZbAAAA:8 a=RlXo0yPEHK3ZGNOOaAcA:9 a=cvBusfyB2V15izCimMoJ:22 a=5yU3S35YU4bGjq-dph-N:22 a=Bho9c0fBagfJEIQBS7DQ:22 cc=ntf awl=host:12312 X-Proofpoint-ORIG-GUID: hMw6gAjwt-MIkjkL8LJ2GpdmSr_SVf3W X-Proofpoint-GUID: hMw6gAjwt-MIkjkL8LJ2GpdmSr_SVf3W X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNjI0MDE2NyBTYWx0ZWRfX98d3Z2p+r/03 jsjOzQs328TFAI65bYhSTG1mdgY3+e+v4yDf6/vvFCpQ6Yf7jprP4PBq8zArc73YLYGld+ICuQn l48fClR0rc46R6HbwPtA/ey6wVwyox/QZ3jwMpEdSY7NKy3W7A39/v2DdL04l9xH4/ZllCuaXkk LC22xK52SUVQXFO+xjqhiEfG4ut/Pvv5q5srmwSj4isKJJf+6Wws1DoEVsTbdcW+ByZs9ki2Fb2 0JrsHEm59/Zf4m4VvVRLbUbgjqNy71JYalyIxU+PQ2UYFfZwnd0Rh3vrQjexoTDIUGO3tPl9/zr nQJeu9GusGqq1WIT5mognUU4rYiaHJehuPXHS3VPCMLEAir+yLpIp85JNY3mXFeEiWN9KNOevzu FQ1sZMIutzWRN0Va4o/0aEz3I1EYjRHuPoCJmIfuqf/dQRWbFQm3QAMaDWhA57rR+JpgKBBlbGe a5YmZ+u1pFy4xOmQx2RyZ6UGvG/G1WySpKyqSfzY= X-Proofpoint-Spam-Info: AW1haW4tMjYwNjI0MDE2NyBTYWx0ZWRfX0ddVYhKs+5ab Zqr8XLv9+C/dM0A7/j5MPdreuKsEsHDkq3HlCzxKVoP1OdtAC0zyknR54nMg6VWTf158VoXCCfk kN2KYjEdYpMVzHEC4wNVjKQyqHwI2ESUTyeHFoVlTbnq4Jxd/ouG Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=205.220.177.32; envelope-from=alejandro.j.jimenez@oracle.com; helo=mx0b-00069f02.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @oracle.com) X-ZM-MESSAGEID: 1782331315939158500 Content-Type: text/plain; charset="utf-8" The XT IOMMU General Interrupt Control Register is a guest-visible MMIO register. Decoding it with bitfields depends on host bitfield layout and is not portable to big-endian hosts. Fix this by removing union mmio_xt_intr and explicitly extracting fields with FIELD_EX64() from the full register value returned by amdvi_readq(), which has already been converted to host endianness. Using a designated initializer for X86IOMMUIrq also ensures fields not provided by the XT register (e.g. msi_addr_last_bits) are initialized before x86_iommu_irq_to_msi_message() uses them. CID: 1660056 Fixes: cf0210df65aa ("amd_iommu: Generate XT interrupts when xt support is = enabled") Reported-by: Peter Maydell Suggested-by: Peter Maydell Signed-off-by: Alejandro Jimenez Reviewed-by: Peter Maydell Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- hw/i386/amd_iommu.c | 28 ++++++++++++++++++---------- hw/i386/amd_iommu.h | 14 -------------- 2 files changed, 18 insertions(+), 24 deletions(-) diff --git a/hw/i386/amd_iommu.c b/hw/i386/amd_iommu.c index 0d273fd33d..c634928d3c 100644 --- a/hw/i386/amd_iommu.c +++ b/hw/i386/amd_iommu.c @@ -34,6 +34,7 @@ #include "hw/core/qdev-properties.h" #include "kvm/kvm_i386.h" #include "qemu/iova-tree.h" +#include "hw/core/registerfields.h" =20 struct AMDVIAddressSpace { PCIBus *bus; /* PCIBus (for bus number) */ @@ -88,6 +89,13 @@ typedef struct AMDVIIOTLBKey { uint16_t devid; } AMDVIIOTLBKey; =20 +/* XT IOMMU General Interrupt Control Register layout */ +FIELD(AMDVI_XT_GEN_INTR, DEST_MODE, 2, 1) +FIELD(AMDVI_XT_GEN_INTR, DEST_LO, 8, 24) +FIELD(AMDVI_XT_GEN_INTR, VECTOR, 32, 8) +FIELD(AMDVI_XT_GEN_INTR, DELIVERY_MODE, 40, 1) +FIELD(AMDVI_XT_GEN_INTR, DEST_HI, 56, 8) + uint64_t amdvi_extended_feature_register(AMDVIState *s) { uint64_t feature =3D AMDVI_DEFAULT_EXT_FEATURES; @@ -194,17 +202,17 @@ static void amdvi_assign_andq(AMDVIState *s, hwaddr a= ddr, uint64_t val) =20 static void amdvi_build_xt_msi_msg(AMDVIState *s, MSIMessage *msg) { - union mmio_xt_intr xt_reg; - struct X86IOMMUIrq irq; - - xt_reg.val =3D amdvi_readq(s, AMDVI_MMIO_XT_GEN_INTR); + uint64_t xt_reg =3D amdvi_readq(s, AMDVI_MMIO_XT_GEN_INTR); =20 - irq.vector =3D xt_reg.vector; - irq.delivery_mode =3D xt_reg.delivery_mode; - irq.dest_mode =3D xt_reg.destination_mode; - irq.dest =3D (xt_reg.destination_hi << 24) | xt_reg.destination_lo; - irq.trigger_mode =3D 0; - irq.redir_hint =3D 0; + X86IOMMUIrq irq =3D { + .vector =3D FIELD_EX64(xt_reg, AMDVI_XT_GEN_INTR, VECTOR), + .delivery_mode =3D FIELD_EX64(xt_reg, AMDVI_XT_GEN_INTR, DELIVERY_= MODE), + .dest_mode =3D FIELD_EX64(xt_reg, AMDVI_XT_GEN_INTR, DEST_MODE), + .dest =3D (FIELD_EX64(xt_reg, AMDVI_XT_GEN_INTR, DEST_HI) << 24) | + FIELD_EX64(xt_reg, AMDVI_XT_GEN_INTR, DEST_LO), + .trigger_mode =3D 0, + .redir_hint =3D 0, + }; =20 x86_iommu_irq_to_msi_message(&irq, msg); } diff --git a/hw/i386/amd_iommu.h b/hw/i386/amd_iommu.h index 3cab04a6d4..ca4440a4c1 100644 --- a/hw/i386/amd_iommu.h +++ b/hw/i386/amd_iommu.h @@ -340,20 +340,6 @@ struct irte_ga { union irte_ga_hi hi; }; =20 -union mmio_xt_intr { - uint64_t val; - struct { - uint64_t rsvd_1:2, - destination_mode:1, - rsvd_2:5, - destination_lo:24, - vector:8, - delivery_mode:1, - rsvd_3:15, - destination_hi:8; - }; -}; - #define TYPE_AMD_IOMMU_DEVICE "amd-iommu" OBJECT_DECLARE_SIMPLE_TYPE(AMDVIState, AMD_IOMMU_DEVICE) =20 --=20 2.47.3 From nobody Sun Jul 26 11:54:47 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=oracle.com ARC-Seal: i=1; a=rsa-sha256; t=1782331301; cv=none; d=zohomail.com; s=zohoarc; b=GxW2ZvhW+Eegh3Io1/pzEyFumXYe6bwdfxIRyF3VQwzlDV5OAdA9Cx3OkvASIpNk7SOyUnZal/PL5iaFqbvErPZQdr/VxYBZq+LkoicRuinQiM/kwaFcG3mXKcu7FgjDCkl/tJ2gAqBgwjd5xUVwnl7dGfrQyhKKW2pQiyzWZBU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782331301; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=OUFZtFg7qRiGCcLKQXHwRtNRRrNsoo0+mVnCRSt8Fx8=; b=bpGRBGLFWibUTH2RFC3m4CooABBLeJM5ADIvuZMYFnON1QZRD6LR/g4MBF4yt0EtyYYaeSY44TcR2PdzqVaH8x1DkNI7w2+8x+kwCGPFRcEuW8Y0r71hZRFmUB415fzdE0Q44lafRH/zIsscCjGA1ZXIBKPoCDT+SlA6UmICoww= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782331301535901.6135387116336; Wed, 24 Jun 2026 13:01:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcTl8-0005Zb-IK; Wed, 24 Jun 2026 15:59:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcTl1-0005XQ-27 for qemu-devel@nongnu.org; Wed, 24 Jun 2026 15:59:36 -0400 Received: from mx0b-00069f02.pphosted.com ([205.220.177.32]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcTkx-00083T-S9 for qemu-devel@nongnu.org; Wed, 24 Jun 2026 15:59:34 -0400 Received: from pps.filterd (m0246630.ppops.net [127.0.0.1]) by mx0b-00069f02.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 65OEVS6C2527729; Wed, 24 Jun 2026 19:59:29 GMT Received: from iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta01.appoci.oracle.com [130.35.100.223]) by mx0b-00069f02.pphosted.com (PPS) with ESMTPS id 4ewh9c627p-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 24 Jun 2026 19:59:28 +0000 (GMT) Received: from pps.filterd (iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (8.18.1.7/8.18.1.7) with ESMTP id 65OJwbBi009017; Wed, 24 Jun 2026 19:59:27 GMT Received: from pps.reinject (localhost [127.0.0.1]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTPS id 4ewhas3kxh-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 24 Jun 2026 19:59:27 +0000 (GMT) Received: from iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by pps.reinject (8.18.1.12/8.18.1.12) with ESMTP id 65OJuO8I004335; Wed, 24 Jun 2026 19:59:27 GMT Received: from alaljime-e5-test-20240903-1847.osdevelopmeniad.oraclevcn.com (alaljime-e5-test-20240903-1847.allregionaliads.osdevelopmeniad.oraclevcn.com [100.100.250.206]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTP id 4ewhas3kwx-4; Wed, 24 Jun 2026 19:59:27 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=corp-2025-04-25; bh=OUFZt Fg7qRiGCcLKQXHwRtNRRrNsoo0+mVnCRSt8Fx8=; b=H0GMNe45qVkcc0bz+YNn+ kPyDS1bvwjQ9iD7ckw3ykoRBOvQvViUxPOrVZJAXU+3VRBacmZyF4aRCv4j8jupZ xflM0x3t0mMd0USlKf7hmCfKY5Kl3jMpeJjxwZD5YSiA606JlKopSZfYM0Dq9j7X +8Kk7hODpZBFJzWufMiDZIGsg7d2VfBNoSZ9DWbKQPDK68nybwpsMoSdxizlt6By epZ5LwM43w2ZmvaaqJP6Cjtyj61SWMMOMbz4ZKr8TtSEMsD2NGqqQeYaH+E71XC6 aXAU1PQez/YjVpKbCJxPQkJ0E8x9USQZzkE1zOkY1ZE8j6PuYrPUNy7ZmQU1o7tX g== From: Alejandro Jimenez To: qemu-devel@nongnu.org Cc: peter.maydell@linaro.org, mst@redhat.com, sarunkod@amd.com, pbonzini@redhat.com, richard.henderson@linaro.org, alejandro.j.jimenez@oracle.com Subject: [PATCH v2 3/4] amd_iommu: Decode IRTEs without bitfields Date: Wed, 24 Jun 2026 19:59:24 +0000 Message-ID: <20260624195925.1254462-4-alejandro.j.jimenez@oracle.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260624195925.1254462-1-alejandro.j.jimenez@oracle.com> References: <20260624195925.1254462-1-alejandro.j.jimenez@oracle.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-06-24_04,2026-06-24_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 phishscore=0 adultscore=0 malwarescore=0 mlxlogscore=922 mlxscore=0 suspectscore=0 bulkscore=0 spamscore=0 lowpriorityscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2606160000 definitions=main-2606240167 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNjI0MDE2NyBTYWx0ZWRfX0gPnhCJAZtmA PntliiVjhVIHGaKwSRIxeWgX6sM6zfsCTy0MXgIkiffJ1AH35UVK8oq4gLGp5iU4Y8ARoXr7m7C teIc04fKyrJlsdbL/BaqVFBFLYVw8oBHInrMu+RMnm4HZOS/tytAI1vBjianwGjvSt5kacXDZqS Fw2NShEgflN0Y5pHJIIsI5tVU5eBmpyefOMy11vrCfhQLIHdXDMQF082NXjHZcWYgu2PmlxcksU HFDATk3SDX/RPaeeYzweS37dUULsD/VTJGfB3YETbr6JgPfD1lBGvb1RN8m5MWZ9INIlDMEU3/9 jOWs0JJjPYSOn/7FJw+DwX9TanvoDzXLN1Fyhw9uwS6fm3kAmIuh04PG3xb/O0ZZPjZvTHVJq8j ErY87VlocTRm/tn5IKcQXzqAIWEBhuKOqplRzOpnwtxY1av/8ck= X-Authority-Analysis: v=2.4 cv=Rd+gzVtv c=1 sm=1 tr=0 ts=6a3c3720 b=1 cx=c_pps a=zPCbziy225d3KhSqZt3L1A==:117 a=zPCbziy225d3KhSqZt3L1A==:17 a=FelO9ux0wxsA:10 a=VkNPw1HP01LnGYTKEx00:22 a=jiCTI4zE5U7BLdzWsZGv:22 a=x4eqshVgHu-cdnggieHk:22 a=KKAkSRfTAAAA:8 a=yPCof4ZbAAAA:8 a=iN8GYCbXJNbl4wqCgcoA:9 a=cvBusfyB2V15izCimMoJ:22 a=5yU3S35YU4bGjq-dph-N:22 a=Bho9c0fBagfJEIQBS7DQ:22 cc=ntf awl=host:12312 X-Proofpoint-GUID: XtwmcBG-sQICpxAwhxih42mVl3x4zIGT X-Proofpoint-Spam-Info: AW1haW4tMjYwNjI0MDE2NyBTYWx0ZWRfX7YyUSGlX5PMe HkoEEK+hmGdKALdyJx7mO9oRkEn0IDgIbUL6xTnxu9EQkbi0Ton0F1X6vuKBeme2Azg+9ZRCiFt LuPW1fCAdy1AC4eaQmSulg5urL6vfpRtMfUpHctMTeC4Lt8qcpFM X-Proofpoint-ORIG-GUID: XtwmcBG-sQICpxAwhxih42mVl3x4zIGT Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=205.220.177.32; envelope-from=alejandro.j.jimenez@oracle.com; helo=mx0b-00069f02.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @oracle.com) X-ZM-MESSAGEID: 1782331301736158500 Content-Type: text/plain; charset="utf-8" Interrupt remapping table entries are data stored in guest memory in little-endian format. Decoding them with bitfields depends on host bitfield layout and the value returned from dma_memory_read() is not portable to big-endian hosts. Replace the legacy and GA IRTE bitfield definitions with explicit FIELD() definitions. Convert the guest memory values returned from dma_memory_read() with le32_to_cpu() or le64_to_cpu(), then extract relevant fields using FIELD_EX32() or FIELD_EX64() as appropriate to match the IRTE format. Fixes: b44159fe0078 ("x86_iommu/amd: Add interrupt remap support when VAPIC= is not enabled") Fixes: 135f866e609c ("x86_iommu/amd: Add interrupt remap support when VAPIC= is enabled") Reported-by: Peter Maydell Suggested-by: Peter Maydell Signed-off-by: Alejandro Jimenez Reviewed-by: Peter Maydell --- hw/i386/amd_iommu.c | 93 +++++++++++++++++++++++++++++++++------------ hw/i386/amd_iommu.h | 49 ------------------------ 2 files changed, 69 insertions(+), 73 deletions(-) diff --git a/hw/i386/amd_iommu.c b/hw/i386/amd_iommu.c index c634928d3c..fdd05d9171 100644 --- a/hw/i386/amd_iommu.c +++ b/hw/i386/amd_iommu.c @@ -89,6 +89,11 @@ typedef struct AMDVIIOTLBKey { uint16_t devid; } AMDVIIOTLBKey; =20 +typedef struct AMDVIIrteGA { + uint64_t ga_lo; + uint64_t ga_hi; +} AMDVIIrteGA; + /* XT IOMMU General Interrupt Control Register layout */ FIELD(AMDVI_XT_GEN_INTR, DEST_MODE, 2, 1) FIELD(AMDVI_XT_GEN_INTR, DEST_LO, 8, 24) @@ -96,6 +101,37 @@ FIELD(AMDVI_XT_GEN_INTR, VECTOR, 32, 8) FIELD(AMDVI_XT_GEN_INTR, DELIVERY_MODE, 40, 1) FIELD(AMDVI_XT_GEN_INTR, DEST_HI, 56, 8) =20 +/* Interrupt Remapping Table Fields Formats */ + +/* Basic 32-bit IRTE layout (GAEn=3D0) */ +FIELD(AMDVI_IRTE, VALID, 0, 1) +FIELD(AMDVI_IRTE, SUP_IOPF, 1, 1) +FIELD(AMDVI_IRTE, INT_TYPE, 2, 3) +FIELD(AMDVI_IRTE, RQ_EOI, 5, 1) +FIELD(AMDVI_IRTE, DM, 6, 1) +FIELD(AMDVI_IRTE, GUEST_MODE, 7, 1) +FIELD(AMDVI_IRTE, DESTINATION, 8, 8) +FIELD(AMDVI_IRTE, VECTOR, 16, 8) + +/* 128-bit IRTE layout (GAEn=3D1) */ +FIELD(AMDVI_IRTE_GA_LO, VALID, 0, 1) +FIELD(AMDVI_IRTE_GA_LO, SUP_IOPF, 1, 1) +FIELD(AMDVI_IRTE_GA_LO, INT_TYPE, 2, 3) +FIELD(AMDVI_IRTE_GA_LO, RQ_EOI, 5, 1) +FIELD(AMDVI_IRTE_GA_LO, DM, 6, 1) +FIELD(AMDVI_IRTE_GA_LO, GUEST_MODE, 7, 1) +/* + * In the 128-bit IRTE format, XT mode uses IRTE_GA_LOW.Destination[23:0] + * together with IRTE_GA_HI.DestinationHi[7:0] to construct a 32-bit x2APIC + * destination. + * Without XTEn (i.e. when x2APIC support is not enabled), only + * IRTE_GA_LOW.Destination[7:0] is used. + */ +FIELD(AMDVI_IRTE_GA_LO, DESTINATION, 8, 24) + +FIELD(AMDVI_IRTE_GA_HI, VECTOR, 0, 8) +FIELD(AMDVI_IRTE_GA_HI, DESTINATION_HI, 56, 8) + uint64_t amdvi_extended_feature_register(AMDVIState *s) { uint64_t feature =3D AMDVI_DEFAULT_EXT_FEATURES; @@ -1983,7 +2019,7 @@ static IOMMUTLBEntry amdvi_translate(IOMMUMemoryRegio= n *iommu, hwaddr addr, } =20 static int amdvi_get_irte(AMDVIState *s, MSIMessage *origin, uint64_t *dte, - union irte *irte, uint16_t devid) + uint32_t *irte, uint16_t devid) { uint64_t irte_root, offset; =20 @@ -1998,7 +2034,8 @@ static int amdvi_get_irte(AMDVIState *s, MSIMessage *= origin, uint64_t *dte, return -AMDVI_IR_GET_IRTE; } =20 - trace_amdvi_ir_irte_val(irte->val); + *irte =3D le32_to_cpu(*irte); + trace_amdvi_ir_irte_val(*irte); =20 return 0; } @@ -2010,8 +2047,9 @@ static int amdvi_int_remap_legacy(AMDVIState *iommu, X86IOMMUIrq *irq, uint16_t sid) { + uint8_t int_type; + uint32_t irte; int ret; - union irte irte; =20 /* get interrupt remapping table */ ret =3D amdvi_get_irte(iommu, origin, dte, &irte, sid); @@ -2019,32 +2057,33 @@ static int amdvi_int_remap_legacy(AMDVIState *iommu, return ret; } =20 - if (!irte.fields.valid) { + if (!FIELD_EX32(irte, AMDVI_IRTE, VALID)) { trace_amdvi_ir_target_abort("RemapEn is disabled"); return -AMDVI_IR_TARGET_ABORT; } =20 - if (irte.fields.guest_mode) { + if (FIELD_EX32(irte, AMDVI_IRTE, GUEST_MODE)) { error_report_once("guest mode is not zero"); return -AMDVI_IR_ERR; } =20 - if (irte.fields.int_type > AMDVI_IOAPIC_INT_TYPE_ARBITRATED) { + int_type =3D FIELD_EX32(irte, AMDVI_IRTE, INT_TYPE); + if (int_type > AMDVI_IOAPIC_INT_TYPE_ARBITRATED) { error_report_once("reserved int_type"); return -AMDVI_IR_ERR; } =20 - irq->delivery_mode =3D irte.fields.int_type; - irq->vector =3D irte.fields.vector; - irq->dest_mode =3D irte.fields.dm; - irq->redir_hint =3D irte.fields.rq_eoi; - irq->dest =3D irte.fields.destination; + irq->delivery_mode =3D int_type; + irq->vector =3D FIELD_EX32(irte, AMDVI_IRTE, VECTOR); + irq->dest_mode =3D FIELD_EX32(irte, AMDVI_IRTE, DM); + irq->redir_hint =3D FIELD_EX32(irte, AMDVI_IRTE, RQ_EOI); + irq->dest =3D FIELD_EX32(irte, AMDVI_IRTE, DESTINATION); =20 return 0; } =20 static int amdvi_get_irte_ga(AMDVIState *s, MSIMessage *origin, uint64_t *= dte, - struct irte_ga *irte, uint16_t devid) + AMDVIIrteGA *irte, uint16_t devid) { uint64_t irte_root, offset; =20 @@ -2058,7 +2097,9 @@ static int amdvi_get_irte_ga(AMDVIState *s, MSIMessag= e *origin, uint64_t *dte, return -AMDVI_IR_GET_IRTE; } =20 - trace_amdvi_ir_irte_ga_val(irte->hi.val, irte->lo.val); + irte->ga_lo =3D le64_to_cpu(irte->ga_lo); + irte->ga_hi =3D le64_to_cpu(irte->ga_hi); + trace_amdvi_ir_irte_ga_val(irte->ga_hi, irte->ga_lo); return 0; } =20 @@ -2069,8 +2110,9 @@ static int amdvi_int_remap_ga(AMDVIState *iommu, X86IOMMUIrq *irq, uint16_t sid) { + AMDVIIrteGA irte; + uint8_t int_type; int ret; - struct irte_ga irte; =20 /* get interrupt remapping table */ ret =3D amdvi_get_irte_ga(iommu, origin, dte, &irte, sid); @@ -2078,30 +2120,33 @@ static int amdvi_int_remap_ga(AMDVIState *iommu, return ret; } =20 - if (!irte.lo.fields_remap.valid) { + if (!FIELD_EX64(irte.ga_lo, AMDVI_IRTE_GA_LO, VALID)) { trace_amdvi_ir_target_abort("RemapEn is disabled"); return -AMDVI_IR_TARGET_ABORT; } =20 - if (irte.lo.fields_remap.guest_mode) { + if (FIELD_EX64(irte.ga_lo, AMDVI_IRTE_GA_LO, GUEST_MODE)) { error_report_once("guest mode is not zero"); return -AMDVI_IR_ERR; } =20 - if (irte.lo.fields_remap.int_type > AMDVI_IOAPIC_INT_TYPE_ARBITRATED) { + int_type =3D FIELD_EX64(irte.ga_lo, AMDVI_IRTE_GA_LO, INT_TYPE); + if (int_type > AMDVI_IOAPIC_INT_TYPE_ARBITRATED) { error_report_once("reserved int_type is set"); return -AMDVI_IR_ERR; } =20 - irq->delivery_mode =3D irte.lo.fields_remap.int_type; - irq->vector =3D irte.hi.fields.vector; - irq->dest_mode =3D irte.lo.fields_remap.dm; - irq->redir_hint =3D irte.lo.fields_remap.rq_eoi; + irq->delivery_mode =3D int_type; + irq->vector =3D FIELD_EX64(irte.ga_hi, AMDVI_IRTE_GA_HI, VECTOR); + irq->dest_mode =3D FIELD_EX64(irte.ga_lo, AMDVI_IRTE_GA_LO, DM); + irq->redir_hint =3D FIELD_EX64(irte.ga_lo, AMDVI_IRTE_GA_LO, RQ_EOI); if (iommu->xten) { - irq->dest =3D irte.lo.fields_remap.destination | - (irte.hi.fields.destination_hi << 24); + irq->dest =3D FIELD_EX64(irte.ga_lo, AMDVI_IRTE_GA_LO, DESTINATION= ) | + (FIELD_EX64(irte.ga_hi, AMDVI_IRTE_GA_HI, DESTINATION_= HI) + << 24); } else { - irq->dest =3D irte.lo.fields_remap.destination & 0xff; + irq->dest =3D FIELD_EX64(irte.ga_lo, AMDVI_IRTE_GA_LO, DESTINATION= ) & + 0xff; } =20 return 0; diff --git a/hw/i386/amd_iommu.h b/hw/i386/amd_iommu.h index ca4440a4c1..687691ec1c 100644 --- a/hw/i386/amd_iommu.h +++ b/hw/i386/amd_iommu.h @@ -291,55 +291,6 @@ #define AMDVI_DEV_LINT0_PASS_MASK (1ULL << 62) #define AMDVI_DEV_LINT1_PASS_MASK (1ULL << 63) =20 -/* Interrupt remapping table fields (Guest VAPIC not enabled) */ -union irte { - uint32_t val; - struct { - uint32_t valid:1, - no_fault:1, - int_type:3, - rq_eoi:1, - dm:1, - guest_mode:1, - destination:8, - vector:8, - rsvd:8; - } fields; -}; - -/* Interrupt remapping table fields (Guest VAPIC is enabled) */ -union irte_ga_lo { - uint64_t val; - - /* For int remapping */ - struct { - uint64_t valid:1, - no_fault:1, - /* ------ */ - int_type:3, - rq_eoi:1, - dm:1, - /* ------ */ - guest_mode:1, - destination:24, - rsvd_1:32; - } fields_remap; -}; - -union irte_ga_hi { - uint64_t val; - struct { - uint64_t vector:8, - rsvd_2:48, - destination_hi:8; - } fields; -}; - -struct irte_ga { - union irte_ga_lo lo; - union irte_ga_hi hi; -}; - #define TYPE_AMD_IOMMU_DEVICE "amd-iommu" OBJECT_DECLARE_SIMPLE_TYPE(AMDVIState, AMD_IOMMU_DEVICE) =20 --=20 2.47.3 From nobody Sun Jul 26 11:54:47 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=oracle.com ARC-Seal: i=1; a=rsa-sha256; t=1782331224; cv=none; d=zohomail.com; s=zohoarc; b=OjOBxc1pP9jcNhYgoi9Ust6l9Q58Bzp+iDewKABr8hNJdlZWURqVvI5xV501Py5WGch0mu1LaKa2iuSZgA8RMG7bhQDLZIz6CXJKNAfiPoRjcJaad3//VMLAkDRWQID2LWCDpF4EaUv7BUJQ8jKgcQeuV2fA2wnqfLww+Pq0UB4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782331224; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=kxcVevxi0wKQ/kmQccNPS48Jy2sKBGOPFWuf1+AGMkc=; b=mW8uGVVX3AaQ2PTiUnmM9YQEEKc3sHqRR6rdzc0F2xcyizTXeQmJ8bv2eX+UcuzSiy6XUjiO7Ko7zPg96fQ57pWkClGJNN54Skwquscq8JKDhsb928ZVJ+zkDFOw8afhe3j8W5ecC4Sc80uvz7k+RdPdE+CICI46lRQ4hYRPFzE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782331224013336.34011988574184; Wed, 24 Jun 2026 13:00:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcTl5-0005Y0-NO; Wed, 24 Jun 2026 15:59:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcTkz-0005Ww-OS for qemu-devel@nongnu.org; Wed, 24 Jun 2026 15:59:34 -0400 Received: from mx0b-00069f02.pphosted.com ([205.220.177.32]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcTkx-00083S-Rv for qemu-devel@nongnu.org; Wed, 24 Jun 2026 15:59:33 -0400 Received: from pps.filterd (m0333520.ppops.net [127.0.0.1]) by mx0b-00069f02.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 65OEVKCc2701763; Wed, 24 Jun 2026 19:59:28 GMT Received: from iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta01.appoci.oracle.com [130.35.100.223]) by mx0b-00069f02.pphosted.com (PPS) with ESMTPS id 4ewjwce503-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 24 Jun 2026 19:59:28 +0000 (GMT) Received: from pps.filterd (iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (8.18.1.7/8.18.1.7) with ESMTP id 65OJwbLm008998; Wed, 24 Jun 2026 19:59:28 GMT Received: from pps.reinject (localhost [127.0.0.1]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTPS id 4ewhas3kxn-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 24 Jun 2026 19:59:28 +0000 (GMT) Received: from iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by pps.reinject (8.18.1.12/8.18.1.12) with ESMTP id 65OJuO8K004335; Wed, 24 Jun 2026 19:59:27 GMT Received: from alaljime-e5-test-20240903-1847.osdevelopmeniad.oraclevcn.com (alaljime-e5-test-20240903-1847.allregionaliads.osdevelopmeniad.oraclevcn.com [100.100.250.206]) by iadpaimrmta01.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTP id 4ewhas3kwx-5; Wed, 24 Jun 2026 19:59:27 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=corp-2025-04-25; bh=kxcVe vxi0wKQ/kmQccNPS48Jy2sKBGOPFWuf1+AGMkc=; b=jgbubEWJMQC64j+fr7hFX J5gNibvzJHJ+zVoX9n+ejSeO2u0yeayAEMjWAmmMEVHXj31n8qJg3aOo9Ntg8EXU yikW45dCq4OyJ+VnvNW9yAC8unoR9chylTaGcSa773bXjdiVdxTCcONi+dKo6Mcb tho7z6d8RHdGX6L8q6S7od8B2zfo5/vNBk5/tvkH+8ek5t+wj0AqyvOd/3Yu6NeE 3nW83qlTcqHswhGJUWcqGWv5qF05/Uk+DsumnddI48VQ1XM5pM9/U4heBb0o/QpY YgbNDylxWW/32bKcuqoWfXyOdMyFbgX2muYM0qoZ3iEPiDZEU1xsMc7aUDCj/w+f g== From: Alejandro Jimenez To: qemu-devel@nongnu.org Cc: peter.maydell@linaro.org, mst@redhat.com, sarunkod@amd.com, pbonzini@redhat.com, richard.henderson@linaro.org, alejandro.j.jimenez@oracle.com Subject: [PATCH v2 4/4] amd_iommu: Fix endianness handling for command buffer entries Date: Wed, 24 Jun 2026 19:59:25 +0000 Message-ID: <20260624195925.1254462-5-alejandro.j.jimenez@oracle.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260624195925.1254462-1-alejandro.j.jimenez@oracle.com> References: <20260624195925.1254462-1-alejandro.j.jimenez@oracle.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-06-24_04,2026-06-24_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 phishscore=0 adultscore=0 malwarescore=0 mlxlogscore=768 mlxscore=0 suspectscore=0 bulkscore=0 spamscore=0 lowpriorityscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2606160000 definitions=main-2606240167 X-Authority-Analysis: v=2.4 cv=eJAjSnp1 c=1 sm=1 tr=0 ts=6a3c3720 b=1 cx=c_pps a=zPCbziy225d3KhSqZt3L1A==:117 a=zPCbziy225d3KhSqZt3L1A==:17 a=FelO9ux0wxsA:10 a=VkNPw1HP01LnGYTKEx00:22 a=jiCTI4zE5U7BLdzWsZGv:22 a=BqU2WV_vvsyTyxaotp0D:22 a=yPCof4ZbAAAA:8 a=raE-tf0XYUPIjkF9jFQA:9 a=O8hF6Hzn-FEA:10 a=5yU3S35YU4bGjq-dph-N:22 a=Bho9c0fBagfJEIQBS7DQ:22 cc=ntf awl=host:12312 X-Proofpoint-ORIG-GUID: rPegPwQNWk6mHP4DmpgrEpVcgjaGKbTq X-Proofpoint-GUID: rPegPwQNWk6mHP4DmpgrEpVcgjaGKbTq X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNjI0MDE2NyBTYWx0ZWRfX86SNiySSHadf prO7KPGOSUQqBJy1ymkU7fpf1BZwqH5/8ZToNUH/Mvu1WR5acw8LMcJjkgmtzXs7nB1chNW2gk5 tIZxjryeLhdDSl6Y3Y/cAV6NphWH4ioh+r9WQ4qBPpJC0zlzDhklD7SynC5Be7u62zOi496Lel/ HuCg2Hmk6YObV2TRKAhT+S1GfXeB4vXN2M4wSZ/reJf2gNeoPgCzj6W21wems8g9oSmBJhhQzVZ JeR33yW+yAeMZfHH5SYyTVFwKU5eybhRcx39shPMcBrmteKvN4xXliraprJEv1VTh9UwwJApCMj GOb594jDJyE4/j9TFNrv2PEv+oszKtoR8WXKNd/iJDdCbrsrqR5DIhNJ6ZxrISoCuwWG25PgmHs tpVl2TRkHbC3rLaIcW6JhFemSBQMB1fQTXZHk7fHXrJq9e7dhHQc7zCm7uyezNdC/XTOqZzVQ6C IWh9vmhyiLdKVnn9bQEzyRsq1eQ0FHhE+evQ10Bo= X-Proofpoint-Spam-Info: AW1haW4tMjYwNjI0MDE2NyBTYWx0ZWRfX00NnReL979Ld YGYEzw0Oj/AnzrwOOqDRDKsfv0TfuUgIQeWy7qm9sMgyqESqbbf9KM7lmPJ5WVRk/V6GgwE9O2q lemnFy3ErdVFWk4FwGyErU7SMEVuIwTHVILaQkWWfbPm+87IDICX Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=205.220.177.32; envelope-from=alejandro.j.jimenez@oracle.com; helo=mx0b-00069f02.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @oracle.com) X-ZM-MESSAGEID: 1782331225725158500 Content-Type: text/plain; charset="utf-8" AMD IOMMU command buffer entries are stored in guest memory in little-endian format. Convert command buffer with le64_to_cpu() after dma_memory_read(), so that command handlers can all operate using host native endianness. Remove the cpu_to_le*() conversions from command handlers, since the values are used internally by device emulation and do not need translation. Conversion is only necessary when reading or writing to guest memory e.g. writing completion-wait data and event log entries. The flow for command buffer handling is: - Retrieve command buffer (cmd[]) from guest memory (via dma_memory_read()) - Convert command buffer to host endianness (via le64_to_cpu()) - All handlers decode fields from cmd[] in host-endian format - All emulation code uses decoded values in host-endian format - Use cpu_to_le*() when writing back data to guest memory Fixes: d29a09ca6842 ("hw/i386: Introduce AMD IOMMU") Signed-off-by: Alejandro Jimenez Reviewed-by: Peter Maydell --- hw/i386/amd_iommu.c | 39 +++++++++++++++++++++++++++++---------- 1 file changed, 29 insertions(+), 10 deletions(-) diff --git a/hw/i386/amd_iommu.c b/hw/i386/amd_iommu.c index fdd05d9171..2821bf3260 100644 --- a/hw/i386/amd_iommu.c +++ b/hw/i386/amd_iommu.c @@ -278,6 +278,7 @@ static uint32_t get_next_eventlog_entry(AMDVIState *s) =20 static void amdvi_log_event(AMDVIState *s, uint64_t *evt) { + uint64_t le_evt[2]; uint32_t evtlog_tail_next; =20 /* event logging not enabled */ @@ -298,8 +299,14 @@ static void amdvi_log_event(AMDVIState *s, uint64_t *e= vt) return; } =20 + /* + * Convert event buffer to little-endian before writing it to guest me= mory. + */ + le_evt[0] =3D cpu_to_le64(evt[0]); + le_evt[1] =3D cpu_to_le64(evt[1]); + if (dma_memory_write(&address_space_memory, s->evtlog + s->evtlog_tail, - evt, AMDVI_EVENT_LEN, MEMTXATTRS_UNSPECIFIED)) { + le_evt, AMDVI_EVENT_LEN, MEMTXATTRS_UNSPECIFIED))= { trace_amdvi_evntlog_fail(s->evtlog, s->evtlog_tail); } =20 @@ -545,15 +552,18 @@ static void amdvi_update_iotlb(AMDVIState *s, uint16_= t devid, static void amdvi_completion_wait(AMDVIState *s, uint64_t *cmd) { /* pad the last 3 bits */ - hwaddr addr =3D cpu_to_le64(extract64(cmd[0], 3, 49)) << 3; - uint64_t data =3D cpu_to_le64(cmd[1]); + hwaddr addr =3D extract64(cmd[0], 3, 49) << 3; + uint64_t data =3D cmd[1]; + + /* Format the data to be written to guest memory as little-endian */ + uint64_t le_data =3D cpu_to_le64(data); =20 if (extract64(cmd[0], 52, 8)) { amdvi_log_illegalcom_error(s, extract64(cmd[0], 60, 4), s->cmdbuf + s->cmdbuf_head); } if (extract64(cmd[0], 0, 1)) { - if (dma_memory_write(&address_space_memory, addr, &data, + if (dma_memory_write(&address_space_memory, addr, &le_data, AMDVI_COMPLETION_DATA_SIZE, MEMTXATTRS_UNSPECIFIED)) { trace_amdvi_completion_wait_fail(addr); @@ -1281,7 +1291,7 @@ static void amdvi_update_addr_translation_mode(AMDVIS= tate *s, uint16_t devid) /* log error without aborting since linux seems to be using reserved bits = */ static void amdvi_inval_devtab_entry(AMDVIState *s, uint64_t *cmd) { - uint16_t devid =3D cpu_to_le16((uint16_t)extract64(cmd[0], 0, 16)); + uint16_t devid =3D extract64(cmd[0], 0, 16); =20 trace_amdvi_devtab_inval(PCI_BUS_NUM(devid), PCI_SLOT(devid), PCI_FUNC(devid)); @@ -1448,9 +1458,9 @@ static void amdvi_sync_domain(AMDVIState *s, uint16_t= domid, uint64_t addr, /* we don't have devid - we can't remove pages by address */ static void amdvi_inval_pages(AMDVIState *s, uint64_t *cmd) { - uint16_t domid =3D cpu_to_le16((uint16_t)extract64(cmd[0], 32, 16)); - uint64_t addr =3D cpu_to_le64(extract64(cmd[1], 12, 52)) << 12; - uint16_t flags =3D cpu_to_le16((uint16_t)extract64(cmd[1], 0, 3)); + uint16_t domid =3D extract64(cmd[0], 32, 16); + uint64_t addr =3D extract64(cmd[1], 12, 52) << 12; + uint16_t flags =3D extract64(cmd[1], 0, 3); =20 if (extract64(cmd[0], 20, 12) || extract64(cmd[0], 48, 12) || extract64(cmd[1], 3, 9)) { @@ -1497,7 +1507,7 @@ static void amdvi_inval_inttable(AMDVIState *s, uint6= 4_t *cmd) static void iommu_inval_iotlb(AMDVIState *s, uint64_t *cmd) { =20 - uint16_t devid =3D cpu_to_le16(extract64(cmd[0], 0, 16)); + uint16_t devid =3D extract64(cmd[0], 0, 16); if (extract64(cmd[1], 1, 1) || extract64(cmd[1], 3, 1) || extract64(cmd[1], 6, 6)) { amdvi_log_illegalcom_error(s, extract64(cmd[0], 60, 4), @@ -1509,7 +1519,7 @@ static void iommu_inval_iotlb(AMDVIState *s, uint64_t= *cmd) g_hash_table_foreach_remove(s->iotlb, amdvi_iotlb_remove_by_devid, &devid); } else { - amdvi_iotlb_remove_page(s, cpu_to_le64(extract64(cmd[1], 12, 52)) = << 12, + amdvi_iotlb_remove_page(s, extract64(cmd[1], 12, 52) << 12, devid); } trace_amdvi_iotlb_inval(); @@ -1527,6 +1537,15 @@ static void amdvi_cmdbuf_exec(AMDVIState *s) return; } =20 + /* + * Commands in guest memory are little-endian. Convert once after read= ing + * so that command handlers can decode values in host native endiannes= s. + * Convert back to little-endian only when writing data to guest memor= y via + * dma_memory_write(). + */ + cmd[0] =3D le64_to_cpu(cmd[0]); + cmd[1] =3D le64_to_cpu(cmd[1]); + switch (extract64(cmd[0], 60, 4)) { case AMDVI_CMD_COMPLETION_WAIT: amdvi_completion_wait(s, cmd); --=20 2.47.3