From nobody Sun Jul 26 11:50:58 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1782457031; cv=none; d=zohomail.com; s=zohoarc; b=AK+j6HoVHz/fOog8XiLoU4DODuh4uIZDx3qkoIKKXss0Ne/851c9oji8dEYLuOuxDpFL9RKkbKkp909WPhiHi9Wc0k8vyenYv7BJFVq0t8iw4zXjas/bCc9cFG/TKSpm9upl5Geao1aD7GuuD5OODtxXH93zYjVfVtkwdZLtu8M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782457031; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=KKI3MERHGLrbihIgAoa5Qy/QpsAdKM6Q6ECbNHDSwIc=; b=b+8vvE/cO7NVTPJDc73bsBWxy1dmrh99xCc1q8u3DWnrZ0lKeJaFLu4KrP00xBtc13pZj3TgJpkBviyk7Tsz7zRwF2M/Nb1gb0KdNqs45TYKXgRiuo4Z3XT+uduTnun+obqc727y/0E42ba/y6ImFKJjRHh1nhMIo35+3xYhqg0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782457031358856.3100965813417; Thu, 25 Jun 2026 23:57:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wd0Tv-0008Om-Pq; Fri, 26 Jun 2026 02:56:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0Tu-0008Nd-8y; Fri, 26 Jun 2026 02:56:06 -0400 Received: from mgamail.intel.com ([192.198.163.13]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0Ts-0007vL-H1; Fri, 26 Jun 2026 02:56:06 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa107.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:02 -0700 Received: from junjie-desk-dev.bj.intel.com ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:00 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1782456965; x=1813992965; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=KBu100xg1Txpv8RJacu5T0T7HrIl9c2cdIu5LTVA4PE=; b=DMlTfPCNkLH0D6sGqLKdx9iqplVDnGxOFK8JAonmymxrcynGj4pIyz98 hp0HvzhwbLKuMUJP959+xiq0G4TsBqbPII/zCpzNShJw3AN9wJTJ01k4z hJy2hmNHvHU3Ay0cHrrxk/9pw93f/bB2PgfBwTNEJa4I/iXo+jdtUTqZt TrkNqXAeOEbATI8kE9oHWd4LPDxxCSmUjX+aKjdCaTivkQqvCC6BUdJaK 8caVpizP5HZrjaqg2C0gmNE74T0L51Mzrdneq2iHybFevBiZ7UJnhoxSS Gk99VBNfdwC3SkofPqHQmeQ/rPP+NvPylBTMrLplKHXSDmZJLfVKVKRs+ g==; X-CSE-ConnectionGUID: HffyPbHeSA+sss1n+ky1pQ== X-CSE-MsgGUID: s33ghX1FSfGrxrd08zfTLg== X-IronPort-AV: E=McAfee;i="6800,10657,11828"; a="85802330" X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="85802330" X-CSE-ConnectionGUID: Anq9gpsGSSiR2V1+eDjgnQ== X-CSE-MsgGUID: 4iJqnzP2T7WXbdJTS1ZPRA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="244865870" From: Junjie Cao To: qemu-devel@nongnu.org Cc: Jonathan Cameron , linux-cxl@vger.kernel.org, junjie.cao@intel.com, qemu-stable@nongnu.org Subject: [PATCH 1/6] hw/cxl: fix timer leak in cxl_destroy_cci() Date: Fri, 26 Jun 2026 14:21:44 +0800 Message-ID: <20260626062149.1844334-2-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260626062149.1844334-1-junjie.cao@intel.com> References: <20260626062149.1844334-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.13; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -47 X-Spam_score: -4.8 X-Spam_bar: ---- X-Spam_report: (-4.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1782457031878158500 Content-Type: text/plain; charset="utf-8" cxl_init_cci() allocates a QEMUTimer via timer_new_ms() but cxl_destroy_cci() never frees it. This leaks a timer object on every device exit path and, more critically, on every device reset cycle since the secondary CCIs (vdm_fm_owned_ld_mctp_cci, ld0_cci) are destroyed and re-initialized each time ct3d_reset() runs. Free the timer with timer_free(), which cancels any pending expiry via timer_del() internally and tolerates a NULL pointer, then clear the field so that a repeated timer_free() on the same CCI is a safe no-op. (The function as a whole is not idempotent: it also calls qemu_mutex_destroy(), which asserts on an already-destroyed mutex. Callers must not invoke cxl_destroy_cci() twice; the .initialized guard added in the next patch enforces that.) Fixes: 98cbac128f1c ("hw/cxl: Support aborting background commands") Cc: qemu-stable@nongnu.org Signed-off-by: Junjie Cao --- hw/cxl/cxl-mailbox-utils.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/hw/cxl/cxl-mailbox-utils.c b/hw/cxl/cxl-mailbox-utils.c index 20e0b7e476..18a455e89c 100644 --- a/hw/cxl/cxl-mailbox-utils.c +++ b/hw/cxl/cxl-mailbox-utils.c @@ -4770,6 +4770,8 @@ void cxl_init_cci(CXLCCI *cci, size_t payload_max) =20 void cxl_destroy_cci(CXLCCI *cci) { + timer_free(cci->bg.timer); + cci->bg.timer =3D NULL; qemu_mutex_destroy(&cci->bg.lock); cci->initialized =3D false; } --=20 2.43.0 From nobody Sun Jul 26 11:50:58 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1782457045; cv=none; d=zohomail.com; s=zohoarc; b=BdD65sK5EiHyNOXFLaV9+05OF07MLFLFR+Qk8R3igLvx7uonT7rQYpwjFfiWe8CvTdhUHwDMmoKPxq0ON/+psVbTHomTE2MQYdf+cKHXrxUTwmsuOHMDwxuqne+HoICb9QLGiJI79X+LFIjlo2ZfXrbiHMSS+yDwhoUqU1jydps= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782457045; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YxT7vM+Hm1IctxEuw5wmfgkXtwXT4x+aLwHcbP1c/50=; b=S0hj7tFrghLdjnpMVKhvwwEhVIVfBHk1v7s7zu7pJvIOlJfNCxLlmaH3Wq2ufxOLfH4fHP5SCXduiW80fGhlTwrFBKhKYG8q1JARcEaqQQZ279duEHQu7WK/KEZIoyEqC7x3BvNUtiUr5wFCj+NC336sRU/trGeBwT7XHZZhqJU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782457045677399.4896479572735; Thu, 25 Jun 2026 23:57:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wd0U0-0008Q1-TV; Fri, 26 Jun 2026 02:56:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0Tz-0008Pa-CZ; Fri, 26 Jun 2026 02:56:11 -0400 Received: from mgamail.intel.com ([192.198.163.13]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0Tx-0007vz-OG; Fri, 26 Jun 2026 02:56:11 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa107.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:08 -0700 Received: from junjie-desk-dev.bj.intel.com ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:06 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1782456970; x=1813992970; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=hBO3fzaslaoxTxxwV/97htR4gR1dlBLu3SsAm+it1ik=; b=Z6jL3ATKF6X17SZkCDg5vH6mnVTgr2KNU/P66uBzpTbvsi2zEK7gKjSs r9AvE5cpVStUYML145zdHaccQgJEbT2UBa0cl64vvoZ4UeMMkSCxsx68K 5Gl669V11XjKpTsHSmLiYc02ZVrODcbXn9bJuDdE1YqFYi8YZjiUJbaJl 6FAA1Zm0vSiFGcNhmnOtwwFSknG9U6IRvTNDVWmJKq7qx1EaARXfNL7rK 9Yy8wQ8hu3CpoloDaLp7cdudR9tkdqUqufznWO4+AoJWq1emVt4oWf8Tp XSfzNKO9Rw/ttC7N3uDA22JKLoyKJnRJGH8RjXjDuv8JG4CaOLz37pz7E A==; X-CSE-ConnectionGUID: b7lQVdCkRLGNAn4LboZXCQ== X-CSE-MsgGUID: d05GiOcLTtCiNlvHvjDWMg== X-IronPort-AV: E=McAfee;i="6800,10657,11828"; a="85802336" X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="85802336" X-CSE-ConnectionGUID: Z8FIXWuASSaPzL369Bc1Ug== X-CSE-MsgGUID: DI6gJO+qSrKvunDrRJuEHA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="244865876" From: Junjie Cao To: qemu-devel@nongnu.org Cc: Jonathan Cameron , linux-cxl@vger.kernel.org, junjie.cao@intel.com, qemu-stable@nongnu.org Subject: [PATCH 2/6] hw/cxl: destroy primary CCI before re-initialization on reset Date: Fri, 26 Jun 2026 14:21:45 +0800 Message-ID: <20260626062149.1844334-3-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260626062149.1844334-1-junjie.cao@intel.com> References: <20260626062149.1844334-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.13; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -47 X-Spam_score: -4.8 X-Spam_bar: ---- X-Spam_report: (-4.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1782457046252158500 Content-Type: text/plain; charset="utf-8" ct3d_reset() re-initializes the primary CCI through the call chain cxl_device_register_init_t3() -> cxl_initialize_mailbox_t3() -> cxl_init_cci(), but never calls cxl_destroy_cci() first. Each reset cycle therefore leaks the old timer and leaves the old mutex undestroyed while silently overwriting the CCI state. Per CXL r4.0, the "Mailbox Interfaces Ready" bit in the Memory Device Status register (Table 8-212) is set after a Conventional Reset or CXL Reset once the device has re-initialized its mailbox interfaces. The CCI is the software abstraction of these interfaces and must be properly torn down before re-initialization. The secondary CCIs (vdm_fm_owned_ld_mctp_cci, ld0_cci) already follow the correct destroy-before-reinit pattern in the same function; apply the same discipline to the primary CCI. Also destroy the secondary CCIs in ct3_exit() where they were previously leaked at device removal time. Guard the primary CCI teardown there with the same .initialized check used for the secondary CCIs: the primary CCI is only brought up from the reset path (cxl_device_register_init_t3()), so a device that is unrealized before its first reset would otherwise tear down a never-initialized CCI. Fixes: cac36a8faffc ("hw/cxl/mbox: Pull the CCI definition out of the CXLDe= viceState") Cc: qemu-stable@nongnu.org Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index cba05ec57d..4ac6eaa950 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1073,7 +1073,15 @@ static void ct3_exit(PCIDevice *pci_dev) cxl_doe_cdat_release(cxl_cstate); msix_uninit_exclusive_bar(pci_dev); g_free(regs->special_ops); - cxl_destroy_cci(&ct3d->cci); + if (ct3d->cci.initialized) { + cxl_destroy_cci(&ct3d->cci); + } + if (ct3d->vdm_fm_owned_ld_mctp_cci.initialized) { + cxl_destroy_cci(&ct3d->vdm_fm_owned_ld_mctp_cci); + } + if (ct3d->ld0_cci.initialized) { + cxl_destroy_cci(&ct3d->ld0_cci); + } if (ct3d->dc.host_dc) { cxl_destroy_dc_regions(ct3d); address_space_destroy(&ct3d->dc.host_dc_as); @@ -1328,6 +1336,9 @@ static void ct3d_reset(DeviceState *dev) ct3d->flitmode); cxl_component_register_init_common(reg_state, write_msk, CXL2_TYPE3_DEVICE, ct3d->hdmdb); + if (ct3d->cci.initialized) { + cxl_destroy_cci(&ct3d->cci); + } cxl_device_register_init_t3(ct3d, CXL_T3_MSIX_MBOX); =20 /* --=20 2.43.0 From nobody Sun Jul 26 11:50:58 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1782457029; cv=none; d=zohomail.com; s=zohoarc; b=JxmWbpE71rdBELj1wdaebbr8lO3ZDY2si1EW+DvR+YTp76mYJgTwTAc/qXtA8PeJDxjHOty2HuGnDSeEkk9LLrw3unrDpKpBc6lfVPePOxpfmbJV/fzGIDfshh/6UcRsycc6FqqQ1DfjXcvA6ssSlOf3x0dMT/gpacic4/80dgo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782457029; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LrnYOgunsVpAbtK2oZZq4Zz2JnAC6WZlIe89kbCq4S8=; b=KqNxW7DHe/n6dV5PBkBgNVPPMRgp0dVrjgKMuYblYT6rtw+rJ5K1L6DKPM90tPJSsfYPLTMlFloxTxtUiPjttwHY9gOZykQhojHt1bAmTWf9fZJXJWdZANyVI1GFb+H1VJxEy0s9qeMXjRhkg16PVZ3sWqD91dxnxw02U/BWxpo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782457029202116.36928582803057; Thu, 25 Jun 2026 23:57:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wd0U3-0008QV-DC; Fri, 26 Jun 2026 02:56:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0U2-0008QL-J5 for qemu-devel@nongnu.org; Fri, 26 Jun 2026 02:56:14 -0400 Received: from mgamail.intel.com ([192.198.163.13]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0U1-0007vz-2i for qemu-devel@nongnu.org; Fri, 26 Jun 2026 02:56:14 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa107.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:13 -0700 Received: from junjie-desk-dev.bj.intel.com ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:11 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1782456973; x=1813992973; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=/QW+6bMVfdc3+/VQ5V93oBga9b/YPL0PkvFyIV5avEA=; b=NdAV3Z1kd0DYkGDDUfKaxiBhGo+jA0q6hRT/Yvxzi6C40XzPrx6BHJj/ cvhEFfO96wtLopw4dsRxfgse5Yms5DA+ZtXcc3cxNKufQWL1Ws2FriTzN GQtyAwcfAUg6Yt1Dvb9y/hlw3DfbqsoCQx2jNf3O5L0TiwZH0HmtvJnI2 YSNRiVNFzKx8wwDZZBSXLvomdMwQMfYB/FKX4wKIq2hCKeeVeIyUkAfn2 lbQ0lhzgVBRwtEdiXi/+QPmKg8GRfbPBIi3wol8UfYlbE2+K+qOriv7du vxiJ2jKemCxKvlq2iJrHc5vDKMmB10OLuwm/BtTUHbCWx9UWwjcFkZKRc Q==; X-CSE-ConnectionGUID: Jajs3V6qRSu5MH5ecmhtWQ== X-CSE-MsgGUID: lnDcoXNtQ0aUaD7Sk/GMOA== X-IronPort-AV: E=McAfee;i="6800,10657,11828"; a="85802341" X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="85802341" X-CSE-ConnectionGUID: TMJuD2DVTay8RCjH+dRcFQ== X-CSE-MsgGUID: lqAPK2OSS+OLTDQPKsm1Mw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="244865881" From: Junjie Cao To: qemu-devel@nongnu.org Cc: Jonathan Cameron , linux-cxl@vger.kernel.org, junjie.cao@intel.com Subject: [PATCH 3/6] hw/cxl: convert cxl-type3 to three-phase reset Date: Fri, 26 Jun 2026 14:21:46 +0800 Message-ID: <20260626062149.1844334-4-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260626062149.1844334-1-junjie.cao@intel.com> References: <20260626062149.1844334-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.13; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -47 X-Spam_score: -4.8 X-Spam_bar: ---- X-Spam_report: (-4.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1782457029895158501 Replace the deprecated device_class_set_legacy_reset() registration with the three-phase resettable interface, following the pattern already established by the CXL root port (cxl_rp_reset_hold). Only the hold phase is needed; enter and exit are left NULL. The parent hold phase is chained for correctness: TYPE_PCI_DEVICE installs no hold phase today, so parent_phases.hold is currently NULL and the chained call is a no-op, but capturing and invoking it is the correct forward-compatible pattern and mirrors cxl_rp_reset_hold(). No functional change =E2=80=94 the reset body is identical; only the registration path and function signature change. Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 16 ++++++++++++---- include/hw/cxl/cxl_device.h | 2 ++ 2 files changed, 14 insertions(+), 4 deletions(-) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index 4ac6eaa950..b842e71c66 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1326,13 +1326,18 @@ MemTxResult cxl_type3_write(PCIDevice *d, hwaddr ho= st_addr, uint64_t data, return address_space_write(as, dpa_offset, attrs, &data, size); } =20 -static void ct3d_reset(DeviceState *dev) +static void ct3d_reset_hold(Object *obj, ResetType type) { - CXLType3Dev *ct3d =3D CXL_TYPE3(dev); + CXLType3Dev *ct3d =3D CXL_TYPE3(obj); + CXLType3Class *cvc =3D CXL_TYPE3_GET_CLASS(obj); uint32_t *reg_state =3D ct3d->cxl_cstate.crb.cache_mem_registers; uint32_t *write_msk =3D ct3d->cxl_cstate.crb.cache_mem_regs_write_mask; =20 - pcie_cap_fill_link_ep_usp(PCI_DEVICE(dev), ct3d->width, ct3d->speed, + if (cvc->parent_phases.hold) { + cvc->parent_phases.hold(obj, type); + } + + pcie_cap_fill_link_ep_usp(PCI_DEVICE(obj), ct3d->width, ct3d->speed, ct3d->flitmode); cxl_component_register_init_common(reg_state, write_msk, CXL2_TYPE3_DEVICE, ct3d->hdmdb); @@ -2464,6 +2469,7 @@ static void ct3_class_init(ObjectClass *oc, const voi= d *data) DeviceClass *dc =3D DEVICE_CLASS(oc); PCIDeviceClass *pc =3D PCI_DEVICE_CLASS(oc); CXLType3Class *cvc =3D CXL_TYPE3_CLASS(oc); + ResettableClass *rc =3D RESETTABLE_CLASS(oc); =20 pc->realize =3D ct3_realize; pc->exit =3D ct3_exit; @@ -2477,9 +2483,11 @@ static void ct3_class_init(ObjectClass *oc, const vo= id *data) =20 set_bit(DEVICE_CATEGORY_STORAGE, dc->categories); dc->desc =3D "CXL Memory Device (Type 3)"; - device_class_set_legacy_reset(dc, ct3d_reset); device_class_set_props(dc, ct3_props); =20 + resettable_class_set_parent_phases(rc, NULL, ct3d_reset_hold, NULL, + &cvc->parent_phases); + cvc->get_lsa_size =3D get_lsa_size; cvc->get_lsa =3D get_lsa; cvc->set_lsa =3D set_lsa; diff --git a/include/hw/cxl/cxl_device.h b/include/hw/cxl/cxl_device.h index ba551fa5f9..b7e20e3fe4 100644 --- a/include/hw/cxl/cxl_device.h +++ b/include/hw/cxl/cxl_device.h @@ -805,6 +805,8 @@ struct CXLType3Class { /* Private */ PCIDeviceClass parent_class; =20 + ResettablePhases parent_phases; + /* public */ uint64_t (*get_lsa_size)(CXLType3Dev *ct3d); =20 --=20 2.43.0 From nobody Sun Jul 26 11:50:58 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1782457056; cv=none; d=zohomail.com; s=zohoarc; b=oKWRn3Afyw8VxiiOKt0+x8rwd9d5Q30/OqvaVhtU1kyx/e0me/yEJPw2qL54YzzgFHBGUyF3AUPQQ5IrnFx116yFs0dNgqN2vGjJQZ+xZiFn8aEIDKrgxnh7jduyIEooKueBtyNelPLWN2WdVdCGoa/p80vZW1hsW9/ALwWwIfQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782457056; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=KfXtskmA0jrRccQJ5460fq3g9HeQ5X6Q8jyBo0DPrqs=; b=jlobUyfeESFpGJXy7pWuLGHGcsIf2T6LkX0dL3u5Ek39NFF27HMMWf2x7ECwTYiAsZyWOCYT6Abek6WqOCRj34Sc7ZNyPE/19F3wtdVD7N7sQ4hkOXuGdm7YycRV/tqwrrZgyaScZlUs9nEapeXJJzlKuA0TfsAz5Exi2QeRtrk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782457056418619.4971794848009; Thu, 25 Jun 2026 23:57:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wd0U8-0008RE-Q4; Fri, 26 Jun 2026 02:56:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0U6-0008Qw-RI for qemu-devel@nongnu.org; Fri, 26 Jun 2026 02:56:18 -0400 Received: from mgamail.intel.com ([192.198.163.13]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0U5-0007vz-0h for qemu-devel@nongnu.org; Fri, 26 Jun 2026 02:56:18 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa107.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:17 -0700 Received: from junjie-desk-dev.bj.intel.com ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:15 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1782456977; x=1813992977; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=msD/IOsgmuLyQHdlEUt3k5JKbV4W8J9VzDhB5nHKV2I=; b=BC8XyDXRLZHuOB22Zm26yBr5KGbghObsZynVPgsahEa/F9q+Mg3a6dtr raVYNBwdl3i5JE3ux+I68O760vQ5Y/r/nabVocdJn9gIrCDlAxFYtlG8+ n9QSXwGH2BtA669BO5Qc0MCuJyYWwo9+VujitSiCpeOwn163v56R8pNr8 YjW3r0Rbhid4nfHDG2N4qjEHH3uQIIBNK7Mx//WPQzJ8Bu6gKKor2fX8m LbIgGcBvy1qOZlKxuBhI1rOwVuLuMSSYhYj+FyyUd2uqoYqVxCJG/3PbQ 24pIZDquk1HEvUNCnQn5zT4VgtznKUcod9+AIkrS69ubJQdiFRXHhNGaV A==; X-CSE-ConnectionGUID: V+E72utuQhqE4SGtAmmYWg== X-CSE-MsgGUID: w7sJWFztQWeKJTnOnwsDCg== X-IronPort-AV: E=McAfee;i="6800,10657,11828"; a="85802345" X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="85802345" X-CSE-ConnectionGUID: RE1eX4R+QEm8ZMh339y7FA== X-CSE-MsgGUID: pYhZOP3aTlmyINgEoZUj/Q== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="244865887" From: Junjie Cao To: qemu-devel@nongnu.org Cc: Jonathan Cameron , linux-cxl@vger.kernel.org, junjie.cao@intel.com Subject: [PATCH 4/6] hw/cxl: free in-flight sanitize state on reset Date: Fri, 26 Jun 2026 14:21:47 +0800 Message-ID: <20260626062149.1844334-5-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260626062149.1844334-1-junjie.cao@intel.com> References: <20260626062149.1844334-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.13; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -47 X-Spam_score: -4.8 X-Spam_bar: ---- X-Spam_report: (-4.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1782457058223158500 Content-Type: text/plain; charset="utf-8" Per CXL r4.0 Section 8.2.9.4, "Background commands do not continue to execute across Conventional Resets." If a sanitize or media operation is in progress when the device is reset, the background timer is already cancelled and freed via cxl_destroy_cci(), but the per-operation state (media_op_sanitize) is heap-allocated separately and would otherwise be leaked. Free it unconditionally at the end of the reset hold phase. The timer that advances the operation lives in the CCI that was just destroyed and re-initialized, so the operation can never complete after a reset of any type; preserving the heap state across reset has no benefit and would leak it the next time media_op_sanitize is assigned. Note that Section 8.2.10.9.5.1 additionally requires a device whose Sanitize was interrupted by reset to remain in the Media Disabled state until a successful Sanitize completes. That latch is not modelled here (reset re-enables media via memdev_reg_init_common()) and is left for future work; this patch only addresses the resource leak. Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index b842e71c66..a5e6df3033 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1361,6 +1361,16 @@ static void ct3d_reset_hold(Object *obj, ResetType t= ype) } cxl_initialize_t3_ld_cci(&ct3d->ld0_cci, DEVICE(ct3d), DEVICE(ct3d), 512); /* Max payload made up */ + + /* + * Free any in-flight sanitize state unconditionally. The background + * timer that would advance it lives in the CCI just torn down and + * re-initialized above, so the operation can never complete after this + * point regardless of the reset type; keeping the heap state would on= ly + * leak it on the next allocation. + */ + g_free(ct3d->media_op_sanitize); + ct3d->media_op_sanitize =3D NULL; } =20 static const Property ct3_props[] =3D { --=20 2.43.0 From nobody Sun Jul 26 11:50:58 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1782457026; cv=none; d=zohomail.com; s=zohoarc; b=gIgmkoGIco9yG14VVuoywLjeYytGhYyO7lDX7IWTYVcru6qs9FfosDhEoLrMTbF/nV+xPwFA7RTzKPRB5txi6DklpMdYFMHmvvOgdBFz7SargNmtmeYRnSGMHWAuWPbuF43ANskPUX8czbmKVmNypmoYq8MExwgJwJpsH9h4r7s= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782457026; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EbHKDYcF+kPwsWjsB0kIFQ7xqBDViUto7Jl6ZodS3Vs=; b=cSJGq3AVELGZaED/Vm2X0uSIg2Wlylv+wh2Fqtz3ADj93RyiTx+cmKIod6WsM73C8mbfVklE/rD7QN0zLJq/JyZ9Z7pvTlG2+/up9AM2E2VbdiNzl+Af3qhYdZvyk+mAIT//gUyMun36atWBcypeyAfKc9lgx9bGvershPI8jMI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782457026924687.8572561154712; Thu, 25 Jun 2026 23:57:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wd0UB-0008Rc-4V; Fri, 26 Jun 2026 02:56:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0UA-0008RT-Gd for qemu-devel@nongnu.org; Fri, 26 Jun 2026 02:56:22 -0400 Received: from mgamail.intel.com ([192.198.163.13]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0U8-0007vz-Ub for qemu-devel@nongnu.org; Fri, 26 Jun 2026 02:56:22 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa107.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:20 -0700 Received: from junjie-desk-dev.bj.intel.com ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:18 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1782456981; x=1813992981; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=LFZDeluVb0jYrFBCNzRihUZyA/8sIedwSTGxxS78Gns=; b=hfxUme5r6748hnqci+D158gDWHlh87s27xFtXbNI4ixYyobejJucwCq0 M44tQE15PxVEtiAyHIPW3dWGZO9nOX9cUBmZU9IvSYUu4aoB86hMv2s4c 2OP18mPlNEQW0X2Raz8IMeODbEaiZSWRQyCxZlc9JTJV2Jd8BhcvlmgTe /fm9yeK3tG/aqg+CmoX5uRFLoKLcn2h0eyR9koJyYwd0whwzNJUf0evyn ifcgzJ4JT4w9kr8bFws8WEh780YpITJDMmpT4M2E9L1urrEWUxLquB5I6 39l7zm6EldLfSw3SdPfrUXKtGHFNHWlkfVB/KASwiWgEAKyaoWPtJU04c w==; X-CSE-ConnectionGUID: 17KyRSkXQw6pjZ//4Kc7Dg== X-CSE-MsgGUID: xQhcrnp7SFamS70Lf2GmXg== X-IronPort-AV: E=McAfee;i="6800,10657,11828"; a="85802355" X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="85802355" X-CSE-ConnectionGUID: ZsEt5uf4TjWAgb5WATCW/g== X-CSE-MsgGUID: xxUVM1IpSFaUxXRvE21K9Q== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="244865896" From: Junjie Cao To: qemu-devel@nongnu.org Cc: Jonathan Cameron , linux-cxl@vger.kernel.org, junjie.cao@intel.com Subject: [PATCH 5/6] hw/cxl: clear event logs, scan media and interrupt policy on reset Date: Fri, 26 Jun 2026 14:21:48 +0800 Message-ID: <20260626062149.1844334-6-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260626062149.1844334-1-junjie.cao@intel.com> References: <20260626062149.1844334-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.13; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -47 X-Spam_score: -4.8 X-Spam_bar: ---- X-Spam_report: (-4.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1782457028481158500 Content-Type: text/plain; charset="utf-8" Event records, scan media results and event interrupt settings are device-internal dynamic state that should not survive a device reset. Per CXL r4.0 Section 8.2.10.9.4.6 (Get Scan Media Results), "If the Scan Media command has not been called since the last Conventional Reset, the device shall return the Unsupported return code." This explicitly invalidates scan media results across reset, so clear the scan_media_hasrun flag. Per CXL r4.0 Section 8.2.10.2.5 (Set Event Interrupt Policy), "All event log interrupt settings shall be reset to 00b (No Interrupts) by the device on Conventional Reset." Clear irq_enabled for every event log accordingly. For the event records there is no direct spec mandate to drop the stored records on reset; the Event Status register (Table 8-203) is non-sticky and resets to zero per Section 9.7, and no reset flavor requires the already-reported records to persist. Draining the queues is therefore a reasonable modelling choice that keeps the records consistent with the freshly-reset status register, rather than a spec requirement. Call the existing cxl_discard_all_event_records() helper to drain all event queues. The event log infrastructure itself (mutexes, IRQ vectors) remains intact as it is initialized once during device realize. This is also where reset-type gating begins: a wakeup from suspend-to-RAM (RESET_TYPE_WAKEUP) is not a Conventional or CXL Reset and must retain device-internal state, so the hold phase returns early for that type before discarding any records. This mirrors the RESET_TYPE_WAKEUP shortcut in virtio-mem and virtio-balloon. Only the unconditional mailbox interface re-initialization and the in-flight sanitize free (whose backing timer was already destroyed) run on a wakeup. Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index a5e6df3033..5bf0cffb72 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1371,6 +1371,23 @@ static void ct3d_reset_hold(Object *obj, ResetType t= ype) */ g_free(ct3d->media_op_sanitize); ct3d->media_op_sanitize =3D NULL; + + /* + * A wakeup from suspend-to-RAM is not a Conventional or CXL Reset. T= he + * device-internal dynamic state cleared below (event logs, scan media + * results, and the poison/feature-transfer state cleared in subsequent + * patches) must be preserved across resume, so stop here for a wakeup. + * virtio-mem and virtio-balloon take the same RESET_TYPE_WAKEUP short= cut. + */ + if (type =3D=3D RESET_TYPE_WAKEUP) { + return; + } + + cxl_discard_all_event_records(&ct3d->cxl_dstate); + for (int i =3D 0; i < CXL_EVENT_TYPE_MAX; i++) { + ct3d->cxl_dstate.event_logs[i].irq_enabled =3D false; + } + ct3d->scan_media_hasrun =3D false; } =20 static const Property ct3_props[] =3D { --=20 2.43.0 From nobody Sun Jul 26 11:50:58 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1782457042; cv=none; d=zohomail.com; s=zohoarc; b=SIR799PPMlTvkb9GiIH20FpC585md5/DdOeJISCZ2wyyPITKqWSuH0k7NvppgB7MI2x1p5RsZ8adyFT4qYKTwj5gSVwGeWc3VRO1Hsf4/9sAlLdrJdZzavXLbvZ0qr3Wbsq4ctsXcCbW5kTAzy65+ST7/7wgH9v+jY8UNI1vKks= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782457042; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hKBxIwH7GIGftBXt/ixSyxNWfSkLWamXQntr0V6tWk0=; b=BZ7ODMiI2PP6dPUEGtXjaL+QteITpS3dxQoufh1NEQsLFoHdjnJ31+z4Vnf1EK7LdMq18o1O5zHSvEvfIfX8nt+lMYnXbITZgbcm0IZLfWCW3K3leG8XoNENgVFBC+OSO/NuS/vcYXPiNbecTOql7h+lSGB2FO2/OmPsBuWvgos= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782457042986208.89045305737898; Thu, 25 Jun 2026 23:57:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wd0UF-0008SR-NZ; Fri, 26 Jun 2026 02:56:27 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0UD-0008S0-UL for qemu-devel@nongnu.org; Fri, 26 Jun 2026 02:56:26 -0400 Received: from mgamail.intel.com ([192.198.163.13]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wd0UC-0007vz-50 for qemu-devel@nongnu.org; Fri, 26 Jun 2026 02:56:25 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa107.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:24 -0700 Received: from junjie-desk-dev.bj.intel.com ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 25 Jun 2026 23:56:22 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1782456984; x=1813992984; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=X6xEQGmKsqT36tEuVzuNvndUEQfjM0ecSdHXQUXdAaw=; b=e+D1h3EHW2i1O3F8VDIr4yPBAqtlzVd6SQS5RdeR+CBUV+MjvUf+Eg+9 WhIl8xGAha5PmVsxd+DEzNTuMXXatlI3VDS9K2aNFFq+vRYPsLFMNO2Ny G3Xets31Fs0kOpFZtIcr62TGmHIN45f2eRAjGKHX8oX4IcNWZx9Ab8Ase CBxCP8Ipj7luyk9n/jmT+5lY+wcT7IF9nCpq2kIgz1pnk+u0GZCyCPvET HqNtmue3R51NcW3//oFkIR5e0X2UankWiEeNWo6izZ5ngzHnZ6OCt5JpJ WCcSc4tkQCFbRVjX6jOTmvxgI0fvW+32WBqbxCtnt5EMc/Me6anIOHWi9 w==; X-CSE-ConnectionGUID: 3DrTJVGfTCO2klA0RBgIAQ== X-CSE-MsgGUID: ldiiVBijRjym8oeZpl7rsA== X-IronPort-AV: E=McAfee;i="6800,10657,11828"; a="85802362" X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="85802362" X-CSE-ConnectionGUID: GRpNmuGqSe2wG5uo1eUbfg== X-CSE-MsgGUID: 5DOEQNMSRgCPp2qTpYFN2A== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.24,226,1774335600"; d="scan'208";a="244865904" From: Junjie Cao To: qemu-devel@nongnu.org Cc: Jonathan Cameron , linux-cxl@vger.kernel.org, junjie.cao@intel.com Subject: [PATCH 6/6] hw/cxl: clear poison lists and feature transfer state on reset Date: Fri, 26 Jun 2026 14:21:49 +0800 Message-ID: <20260626062149.1844334-7-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260626062149.1844334-1-junjie.cao@intel.com> References: <20260626062149.1844334-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.13; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -47 X-Spam_score: -4.8 X-Spam_bar: ---- X-Spam_report: (-4.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1782457044036158500 The poison lists (active, backup, and scan-media results), their associated overflow tracking, and the Set Feature partial-transfer state are all device-internal dynamic state that accumulates during the device's lifetime. Per CXL r4.0 Table 8-309 (Identify Memory Device), the "Injects Persistent Poison" capability bit (offset 41h, Bit[0]) controls poison retention across reset. When cleared =E2=80=94 the QEMU default =E2=80=94 = "a Conventional Reset or CXL Reset shall automatically clear the injected poison." Clear all poison lists accordingly, reusing the existing cxl_clear_poison_list_overflowed() helper for the overflow tracking. For the Set Feature transfer state, CXL r4.0 Section 8.2.10.6.3 (Set Feature) requires: "If the Feature data transfer is interrupted by a Conventional Reset or a CXL Reset, the Feature data transfer shall be aborted by the device [...] the device shall require the Feature data transfer to be started from the beginning." Zero set_feat_info on reset so any partially transferred Set Feature is abandoned and must restart from the beginning. Both clears run after the RESET_TYPE_WAKEUP early-return added in the previous patch, so this state is preserved across a suspend-to-RAM wakeup. Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index 5bf0cffb72..1fe4d56762 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1326,6 +1326,16 @@ MemTxResult cxl_type3_write(PCIDevice *d, hwaddr hos= t_addr, uint64_t data, return address_space_write(as, dpa_offset, attrs, &data, size); } =20 +static void ct3d_clear_poison_list(CXLPoisonList *list) +{ + CXLPoison *ent, *next; + + QLIST_FOREACH_SAFE(ent, list, node, next) { + QLIST_REMOVE(ent, node); + g_free(ent); + } +} + static void ct3d_reset_hold(Object *obj, ResetType type) { CXLType3Dev *ct3d =3D CXL_TYPE3(obj); @@ -1388,6 +1398,14 @@ static void ct3d_reset_hold(Object *obj, ResetType t= ype) ct3d->cxl_dstate.event_logs[i].irq_enabled =3D false; } ct3d->scan_media_hasrun =3D false; + + ct3d_clear_poison_list(&ct3d->poison_list); + ct3d_clear_poison_list(&ct3d->poison_list_bkp); + ct3d_clear_poison_list(&ct3d->scan_media_results); + ct3d->poison_list_cnt =3D 0; + cxl_clear_poison_list_overflowed(ct3d); + + memset(&ct3d->set_feat_info, 0, sizeof(ct3d->set_feat_info)); } =20 static const Property ct3_props[] =3D { --=20 2.43.0