From nobody Sun Jul 26 11:05:40 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1782930143; cv=none; d=zohomail.com; s=zohoarc; b=eJzou0dvAeNtI6AxkuOLL04d0fL2hMdCoJWMCoQDAV7bk7//ku5CJahvBJYOa4D+l3Sibps2Q7Ri2LKE7793c2z8XBzgoPlLbk8UdYJYAJzjU5sYDuNgba+4+VLOJaFhiBGFGEMFjQTQfCMloMQn9PieFfzsE50whLadDvMLgM4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782930143; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Ghb/SNZpSBJ7yxU8U8gwuUxJ/trOYWhvix8hFHF3tTw=; b=hi16v5kwTwTpD4IA7rU20UD3a/zsKnNfmui5wvF0pVY4MdNcYiEdou1okYod6iLoem+8U06q2amlkMRAiUUhLyc7ycU92rfgvDASMu3uQBgm8G3y2VLy0xWhXMYzjQ+x7zV0rKcv6h/W3GtFc3XHO05aXC+ClpPfuN6gPC0rtKQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782930143367759.3080947837484; Wed, 1 Jul 2026 11:22:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wezYR-00086p-6H; Wed, 01 Jul 2026 14:20:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wezYK-00084R-Hn for qemu-devel@nongnu.org; Wed, 01 Jul 2026 14:20:54 -0400 Received: from mail-pj2-x02.google.com ([2607:f8b0:4864:39::2]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wezYI-0007H4-Fp for qemu-devel@nongnu.org; Wed, 01 Jul 2026 14:20:51 -0400 Received: by mail-pj2-x02.google.com with SMTP id 98e67ed59e1d1-37fd7db8cf1so469274a91.1 for ; Wed, 01 Jul 2026 11:20:50 -0700 (PDT) Received: from kotori-desktop ([2408:820c:8ffe:590:494:7c85:ae9c:cba8]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30f0bc27e0dsm187109eec.27.2026.07.01.11.20.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 01 Jul 2026 11:20:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782930049; x=1783534849; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=Ghb/SNZpSBJ7yxU8U8gwuUxJ/trOYWhvix8hFHF3tTw=; b=WsG7tjvLv8NSM0njGsySo22XThcy+JQ3CXJtRxNBY3Ul8LG62WlLC4/rKd2HQQML2L emlAFu5mHaA879/V9Luvew2tQKkK1lYwTFoVZt3YIjq3nt/OD2neCZJztM2Te+6RWuG4 DloSrMlQeVdWJWXvt3vmzfLHOVwYydqsK134spL5Jq45iEyMEpA3pnrabdfc174txsV0 acVXj85GbKK2nj5of/kZpmUdPN0yGABGmf6hA++o0TyvhAodtNxPp2o0zkuM+X7baWjy +/QQ5EEF9aRnrrMWJluOR7Bgtf3+wTTxd40S94YouMdy03sCav54+PWfgRFjHm3PGgUN WAIw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782930049; x=1783534849; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=Ghb/SNZpSBJ7yxU8U8gwuUxJ/trOYWhvix8hFHF3tTw=; b=tBn3qfqDycd2EcqwqQtLONTPwUNSiXK9UIpVuqw/1aoUEiBTP1nMhfSTaoJ+wS/ANt G//pP9vmipMCBREdZFtgtVzqD6zptebJhl0FFUbDFK5Y9mJzYJaOesz1hfyAWgHg3dVL r5uVYM7wKSNJDgLXzeabxllIf0SSoHO0dSvpxXe5lY/ixQP9n2cQPyvinxrfnMD45YbT ykaLHR59rJcGeYHalCtABQewxCzQjZzLaR0sNxUsiDkxM9YfiONnTRHcEltYCga+rBHI 8JYQjWpqnR1EUcciwGzz/zFvkyQedlp3vJNrA30LLsfqI/F8Bz8G1IUuoaUIlgph2a4g mnYA== X-Gm-Message-State: AOJu0YyXih0WSE8xTcIqH2bPhpB8hTdIO5DqC/2Vem4ojxyPesLPyhSn vnLrRHH3LzXlzD1203J5iBUeWRxbuKUbPxLKzEvNFzSJVGornDNu3Iy+tKWslQTxUA== X-Gm-Gg: AfdE7ckwrMIhZ667G8JQDG55Y7Nskl2tfbEISSpIRgInmgL0hwJkzQT1gt0W9LgP+kA dVp5ft7OutmtbwtO1QXb0FxI30rV3kxTS1NN+wm/vieGl9KCCxsi9RQbT/qnYfKT+Nt5k1WAz8B k6HNUyFGoHS3mEjxguMcF0Ns5mwyJjlq1rmz6bJHl2tx6bG5egKXBDV5I2Glipv+GsMpxXEi8eh 1Sf7MKuBOe9CE5XLvR6LQTA03NhqMg0SV3OVO9NVUw0ol/3gXqAVwAjNFhcP4PrqP5S+yp+7LTB LjLrvd6ViV5X9rWfGJDZLsd9npbQuGfeUSM5PGLK0lfILLVgNpsPoMXKeA+/hAeRq1fZoqdpjuC DQVXtpKxZS6UnxxJgls0Oes+7g7AXaF95fWz8E8nTT6oyKqW8D8c3uFYxzv4r8rbwGBossbb3U6 tAUQ4ohTzH4SsbZ1eP7g== X-Received: by 2002:a17:90b:5487:b0:37f:e1e9:2b0b with SMTP id 98e67ed59e1d1-380aa184626mr2732716a91.16.1782930049009; Wed, 01 Jul 2026 11:20:49 -0700 (PDT) From: Tomita Moeko To: qemu-devel@nongnu.org Cc: Alex Williamson , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , "Michael S. Tsirkin" , Tomita Moeko , K S Maan Subject: [PATCH v4 1/4] hw/pci: Introduce romfile_fixup hook in PCIDevice Date: Thu, 2 Jul 2026 02:20:32 +0800 Message-ID: <20260701182035.96010-2-tomitamoeko@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260701182035.96010-1-tomitamoeko@gmail.com> References: <20260701182035.96010-1-tomitamoeko@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:39::2; envelope-from=tomitamoeko@gmail.com; helo=mail-pj2-x02.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1782930144753158500 Content-Type: text/plain; charset="utf-8" Some devices, such as VFIO IGD passthrough, require device-specific fixups on the romfile provided by user. Add an optional romfile_fixup hook to PCIDevice. When set, it is invoked from pci_add_option_rom() right after the image is loaded, receiving the ROM buffer and its size. This provides a place to post-process a loaded romfile without leaking device-specific logic into the generic PCI core. Reported-by: K S Maan Signed-off-by: Tomita Moeko Acked-by: Michael S. Tsirkin Tested-by: K S Maan --- hw/pci/pci.c | 4 ++++ include/hw/pci/pci_device.h | 1 + 2 files changed, 5 insertions(+) diff --git a/hw/pci/pci.c b/hw/pci/pci.c index 4298adf5a0..7d30d44411 100644 --- a/hw/pci/pci.c +++ b/hw/pci/pci.c @@ -2632,6 +2632,10 @@ static void pci_add_option_rom(PCIDevice *pdev, bool= is_default_rom, /* Only the default rom images will be patched (if needed). */ pci_patch_ids(pdev, ptr, size); } + + if (pdev->romfile_fixup) { + pdev->romfile_fixup(pdev, ptr, size); + } } =20 pci_register_bar(pdev, PCI_ROM_SLOT, 0, &pdev->rom); diff --git a/include/hw/pci/pci_device.h b/include/hw/pci/pci_device.h index 5cac6e1688..a65e77018c 100644 --- a/include/hw/pci/pci_device.h +++ b/include/hw/pci/pci_device.h @@ -159,6 +159,7 @@ struct PCIDevice { bool has_rom; MemoryRegion rom; int32_t rom_bar; + void (*romfile_fixup)(PCIDevice *pdev, uint8_t *ptr, uint32_t size); =20 /* INTx routing notifier */ PCIINTxRoutingNotifier intx_routing_notifier; --=20 2.53.0 From nobody Sun Jul 26 11:05:40 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1782930119; cv=none; d=zohomail.com; s=zohoarc; b=Y+/R/NDTYSnC9byh9G+AlrCVv6R8InboATqyVdCmZQfzErwWhWLftc9FH2DIMWGjKIYWPygzZvyiVp2AlbedqpRpPxqaKvVg9oPB6p3eIOua/jo7THSqbcCjOoQ8rbUMrdnPvtM6iUNvg4iv3flaIMyP6PzpJRyrmoihJ2Q6M2w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782930119; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bjpoGeyM7MVcEFSvfgEvbhz1WXidDgeVcdX+K/7OsJw=; b=bJROFOVtKFK+qes6ZAjj5VRTkwNmM/A+uz0qfnaZ12R1D8OG+L6sjzV+rKXqliP3WBFJFBd4h8yVDrOL3JquaSEIL52u6JglQasHPZILVxpHEgTIVxr7rykYsmwCWGcm4ICARZzPTyPQoIjzc5cxvczfhJYKBbr9xXmnsABSOLQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782930119457482.18425899323074; Wed, 1 Jul 2026 11:21:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wezYQ-00086K-ET; Wed, 01 Jul 2026 14:20:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wezYO-00084z-FZ for qemu-devel@nongnu.org; Wed, 01 Jul 2026 14:20:56 -0400 Received: from mail-pj2-x01.google.com ([2607:f8b0:4864:39::1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wezYM-0007JQ-GV for qemu-devel@nongnu.org; Wed, 01 Jul 2026 14:20:56 -0400 Received: by mail-pj2-x01.google.com with SMTP id 98e67ed59e1d1-37fc07868a1so418460a91.0 for ; Wed, 01 Jul 2026 11:20:54 -0700 (PDT) Received: from kotori-desktop ([2408:820c:8ffe:590:494:7c85:ae9c:cba8]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30f0bc27e0dsm187109eec.27.2026.07.01.11.20.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 01 Jul 2026 11:20:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782930053; x=1783534853; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=bjpoGeyM7MVcEFSvfgEvbhz1WXidDgeVcdX+K/7OsJw=; b=gLzmombHoin+TRSGnhbuEf1Y4JXF1hli9NgV9BivThgWyP8BtmUDf06Z9AGVWyObYi SK8d8kiPbyzP0D7V+J07topwr768YO5a0RgrQyW3rgJNKtC/PFWwoju74hpQTVLFpxSB Pn6aC2W7OwOOlEVfk4symR0ncyDFZ9X0lLWAIHV4lQtDB8s07Yg7iN7obM6DvVD9Nosd aVyQWlw6Owu/jinRgcYhBEfTkvsB0UTTK5b/1w3Ev/kN028GcK7bPgiheWcLedFF14UP Kntta8pEL9GjMzUJVsyNV2JLkQjhHvgJCCIWKWvZiEZ76XHPQ+TtJJ/IaTbjFye9JtuQ uM1g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782930053; x=1783534853; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=bjpoGeyM7MVcEFSvfgEvbhz1WXidDgeVcdX+K/7OsJw=; b=fjTVSW5Al4oaddqe4A6XFBaJAmeJET4s8Xe4HyQIL1BfZOamhT4Q+HkfZu08zRs/2P yO/4Upiaojf1TbZKdqKm+0UBgQ9D9FzoNLh4RVbCHwOObaGRgIgwqqI6TBMTcJbI45iT ZzerENfsrh8GA1d2betXRZlLakylQDqz+P+mg55X5HKXS+TUefy3pjw6MFZkCp8/09cT BNW1Aeybp0Ld5NQfhAD0kLRQmY5w9NQYVa5BhtKzaH/MKpUc3QmfAfgMVi5EXraheapk r8SXjn13yOPHsdCrmysqy6YWDaE5eFiTuOaZO0NXpH0EIU3hNtajHZ7ZaBswf8pM6e63 0+vw== X-Gm-Message-State: AOJu0YxjXoXf1cAnDVHbPWJkSfhr+SR1f1WRHJ7KbLpEQdRzt/SMcE8M xvZoQKaMu9ywas9FfiUeRh6x6FLpwXC8wq4FXVCDFYegOGeiHaT855AC+A5cbfeGaA== X-Gm-Gg: AfdE7ckfn8jhiMz7crSDGMAknXBjJa1OiDwsV7pUlzIiba22OGXtAftSOVYKWfGfA86 oG1R3Y4mT+s7ec08Xmsuh/akdmK8/4Dx8C6koxvLFLvADiZvg1hUEpYO6Q5+u9m83Ju0fAqX/Ke +MUaopUaojOinOab+aRWqi979Y5XoWQlYdlNtAdKn5e6oM20ri4wHDjNNioWSmQ9tPFvrk8+/a3 4Pes3pWWScCvsFRLIzIOfGTgO2yRJFZFXzQSTOVU9CMdM/zRjvBoax0X/nt6L6IHkp3kHKzl9Kd tlvWcrdu0AOzxk+ScEcxJ/svZX7npgIrGvG76oSuCfx8evfv82ITK17rm0dEE53IplhozagtMGS F6dc+zBTWWTtmY77OzIYKbW+z/pKctFoP47ensfmXPDCFlVaihyDPpzWJmHgGXJGqDZavc+jZWy sIbB7dQDsQNscATIGpuw== X-Received: by 2002:a17:90b:3cce:b0:380:9ef6:e8cc with SMTP id 98e67ed59e1d1-380aa07e1f3mr2583704a91.5.1782930052893; Wed, 01 Jul 2026 11:20:52 -0700 (PDT) From: Tomita Moeko To: qemu-devel@nongnu.org Cc: Alex Williamson , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , "Michael S. Tsirkin" , Tomita Moeko , K S Maan Subject: [PATCH v4 2/4] vfio/igd: Refactor option ROM patching Date: Thu, 2 Jul 2026 02:20:33 +0800 Message-ID: <20260701182035.96010-3-tomitamoeko@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260701182035.96010-1-tomitamoeko@gmail.com> References: <20260701182035.96010-1-tomitamoeko@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:39::1; envelope-from=tomitamoeko@gmail.com; helo=mail-pj2-x01.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1782930120439158500 Content-Type: text/plain; charset="utf-8" Currently the IGD-specific option ROM patching logic is embedded in vfio_pci_load_rom() rather than igd.c where IGD-specific code lives. Move this logic into a dedicated vfio_igd_legacy_rom_quirk() in igd.c. The refactored quirk patches the device ID and checksum on Gen 6~9 devices with legacy VBIOS as option ROM. A new trace event vfio_pci_igd_vbios_patched is also introduced. Arguments of vfio_igd_legacy_rom_quirk() are aligned with romfile_fixup of PCIDevice so that same logic can be reused on romfile later. Reported-by: K S Maan Signed-off-by: Tomita Moeko Tested-by: K S Maan --- hw/vfio/igd-stubs.c | 5 +++++ hw/vfio/igd.c | 48 ++++++++++++++++++++++++++++++++++++++++++++ hw/vfio/pci-quirks.c | 5 +++++ hw/vfio/pci.c | 30 +-------------------------- hw/vfio/pci.h | 3 +++ hw/vfio/trace-events | 1 + 6 files changed, 63 insertions(+), 29 deletions(-) diff --git a/hw/vfio/igd-stubs.c b/hw/vfio/igd-stubs.c index f7687d9091..29110f7568 100644 --- a/hw/vfio/igd-stubs.c +++ b/hw/vfio/igd-stubs.c @@ -18,3 +18,8 @@ bool vfio_probe_igd_config_quirk(VFIOPCIDevice *vdev, Err= or **errp) { return true; } + +void vfio_igd_legacy_rom_quirk(PCIDevice *pdev, uint8_t *ptr, uint32_t siz= e) +{ + return; +} diff --git a/hw/vfio/igd.c b/hw/vfio/igd.c index e091f21b6a..f597218164 100644 --- a/hw/vfio/igd.c +++ b/hw/vfio/igd.c @@ -724,3 +724,51 @@ bool vfio_probe_igd_config_quirk(VFIOPCIDevice *vdev, = Error **errp) =20 return vfio_pci_igd_config_quirk(vdev, errp); } + +void vfio_igd_legacy_rom_quirk(PCIDevice *pdev, uint8_t *ptr, uint32_t siz= e) +{ + VFIOPCIDevice *vdev =3D VFIO_PCI_DEVICE(pdev); + int gen; + uint16_t pcir_offset; + uint8_t checksum =3D 0; + uint32_t i; + + if (!vfio_pci_is(vdev, PCI_VENDOR_ID_INTEL, PCI_ANY_ID) || + !vfio_is_vga(vdev) || !vdev->vga) { + return; + } + + /* Only Gen 6~9 devices have legacy VBIOS as Option ROM */ + gen =3D igd_gen(vdev); + if (gen < 6 || gen > 9) { + return; + } + + if (pci_get_word(ptr) !=3D 0xaa55) { + return; + } + + /* Must be a legacy ROM */ + pcir_offset =3D pci_get_word(ptr + 0x18); + if (pcir_offset + 0x14 >=3D size || memcmp(ptr + pcir_offset, "PCIR", = 4) || + pci_get_byte(ptr + pcir_offset + 0x14) !=3D 0x00) { + return; + } + + /* + * Patch device ID as multiple IGD devices share the same rom with pos= sible + * non-matching IDs. + */ + pci_set_word(ptr + pcir_offset + 6, vdev->device_id); + + /* + * IGD roms are known to have bogus checksums. No matter we changed the + * device ID or not, we need to recalculate the checksum and patch it. + */ + for (i =3D 0; i < size; i++) { + checksum +=3D ptr[i]; + } + ((uint8_t *)ptr)[6] -=3D checksum; + + trace_vfio_pci_igd_vbios_patched(vdev->vbasedev.name); +} diff --git a/hw/vfio/pci-quirks.c b/hw/vfio/pci-quirks.c index bccf31751f..496a79a3ca 100644 --- a/hw/vfio/pci-quirks.c +++ b/hw/vfio/pci-quirks.c @@ -1592,3 +1592,8 @@ bool vfio_add_virt_caps(VFIOPCIDevice *vdev, Error **= errp) =20 return true; } + +void vfio_rom_quirk_setup(VFIOPCIDevice *vdev) +{ + vfio_igd_legacy_rom_quirk(PCI_DEVICE(vdev), vdev->rom, vdev->rom_size); +} diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c index 9c06b25e63..d321e6160a 100644 --- a/hw/vfio/pci.c +++ b/hw/vfio/pci.c @@ -1084,35 +1084,7 @@ static void vfio_pci_load_rom(VFIOPCIDevice *vdev) } } =20 - /* - * Test the ROM signature against our device, if the vendor is correct - * but the device ID doesn't match, store the correct device ID and - * recompute the checksum. Intel IGD devices need this and are known - * to have bogus checksums so we can't simply adjust the checksum. - */ - if (pci_get_word(vdev->rom) =3D=3D 0xaa55 && - pci_get_word(vdev->rom + 0x18) + 8 < vdev->rom_size && - !memcmp(vdev->rom + pci_get_word(vdev->rom + 0x18), "PCIR", 4)) { - uint16_t vid, did; - - vid =3D pci_get_word(vdev->rom + pci_get_word(vdev->rom + 0x18) + = 4); - did =3D pci_get_word(vdev->rom + pci_get_word(vdev->rom + 0x18) + = 6); - - if (vid =3D=3D vdev->vendor_id && did !=3D vdev->device_id) { - int i; - uint8_t csum, *data =3D vdev->rom; - - pci_set_word(vdev->rom + pci_get_word(vdev->rom + 0x18) + 6, - vdev->device_id); - data[6] =3D 0; - - for (csum =3D 0, i =3D 0; i < vdev->rom_size; i++) { - csum +=3D data[i]; - } - - data[6] =3D -csum; - } - } + vfio_rom_quirk_setup(vdev); } =20 /* "Raw" read of underlying config space. */ diff --git a/hw/vfio/pci.h b/hw/vfio/pci.h index c3a1f53d35..620baddda2 100644 --- a/hw/vfio/pci.h +++ b/hw/vfio/pci.h @@ -251,10 +251,13 @@ void vfio_bar_quirk_exit(VFIOPCIDevice *vdev, int nr); void vfio_bar_quirk_finalize(VFIOPCIDevice *vdev, int nr); void vfio_setup_resetfn_quirk(VFIOPCIDevice *vdev); bool vfio_add_virt_caps(VFIOPCIDevice *vdev, Error **errp); +void vfio_rom_quirk_setup(VFIOPCIDevice *vdev); void vfio_quirk_reset(VFIOPCIDevice *vdev); VFIOQuirk *vfio_quirk_alloc(int nr_mem); + void vfio_probe_igd_bar0_quirk(VFIOPCIDevice *vdev, int nr); bool vfio_probe_igd_config_quirk(VFIOPCIDevice *vdev, Error **errp); +void vfio_igd_legacy_rom_quirk(PCIDevice *pdev, uint8_t *ptr, uint32_t siz= e); =20 extern const PropertyInfo qdev_prop_nv_gpudirect_clique; =20 diff --git a/hw/vfio/trace-events b/hw/vfio/trace-events index 2049159015..7dc334ccb3 100644 --- a/hw/vfio/trace-events +++ b/hw/vfio/trace-events @@ -90,6 +90,7 @@ vfio_pci_igd_bar4_write(const char *name, uint32_t index,= uint32_t data, uint32_ vfio_pci_igd_bdsm_enabled(const char *name, int size) "%s %dMB" vfio_pci_igd_host_bridge_enabled(const char *name) "%s" vfio_pci_igd_lpc_bridge_enabled(const char *name) "%s" +vfio_pci_igd_vbios_patched(const char *name) "%s" =20 # listener.c vfio_iommu_map_notify(const char *op, uint64_t iova_start, uint64_t iova_e= nd) "iommu %s @ 0x%"PRIx64" - 0x%"PRIx64 --=20 2.53.0 From nobody Sun Jul 26 11:05:40 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1782930100; cv=none; d=zohomail.com; s=zohoarc; b=KjoKcRwzm/Z0NXCU327mkNFZtbQtIWKcGi/US9Kr+cQucPBh2I66ZX1TrAkeHwh0jBGYLCGr5M0SU/gUTFfyTto+HsdlFQNSAU7bJXDV0SGr7HpkLINom/MHTehRL8roC0Ni2y0B7YwikRnphnPzJ/AxfmSem0odAQRkYvLAH2o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782930100; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=owmkKHbIcXAuoU6ZOyy29E3Q7cNJi9sW3UC/cj3gxuw=; b=nr+ki2uMW+IyV91sBymbx2YtvfkZzbEX0oji0mJZ89Z0mq2g3cSI67FeOF7MkXTR5Prc+6vuIwOySBG2FU8oo1HWMT/oS6MJLFhpKrzIkwJsugpWvI4neQDO/IDwzvrT0jJ+wnJ/HUV+9UyctfU2iXkU1Jh6Ztu1WL/OKS8+94Q= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17829301004851004.1226295508403; Wed, 1 Jul 2026 11:21:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wezYT-00087U-7l; Wed, 01 Jul 2026 14:21:01 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wezYR-00086s-Db for qemu-devel@nongnu.org; Wed, 01 Jul 2026 14:20:59 -0400 Received: from mail-pj2-x02.google.com ([2607:f8b0:4864:39::2]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wezYQ-0007Ny-07 for qemu-devel@nongnu.org; Wed, 01 Jul 2026 14:20:59 -0400 Received: by mail-pj2-x02.google.com with SMTP id 98e67ed59e1d1-380a00aae61so664278a91.0 for ; Wed, 01 Jul 2026 11:20:57 -0700 (PDT) Received: from kotori-desktop ([2408:820c:8ffe:590:494:7c85:ae9c:cba8]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30f0bc27e0dsm187109eec.27.2026.07.01.11.20.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 01 Jul 2026 11:20:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782930057; x=1783534857; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=owmkKHbIcXAuoU6ZOyy29E3Q7cNJi9sW3UC/cj3gxuw=; b=mBKNNUZk86+9ifTfkVL+W/o5F2Jjmpo9WCWvXkydFKD+AQ+ZgzzpeN67seFagkXINP 99z5CUxG9DqaGGbs38/WYT8y2C7Oc0NfpxSymaEwVhEAyq/pLK0vrHqHn09tf368MVfw 5P2yBHeCY7TR21drMIc57JJeJa5c1ylJYOjqZpebx4blJDV5go34+I3Cg5A60IW7YjLr WT3ezY6tvdgIx/fRjRluPb4BBo6X3ExRPQnC4LzV1c+YGqHsk84/YGTI8enYMGO0Nikx gndpE6IGH/tPeXVlAxERlUwRyIKXfrnxcfq1ROtXdiPe4G1vPxPA4WpxTltwac0ikH0D K8lQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782930057; x=1783534857; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=owmkKHbIcXAuoU6ZOyy29E3Q7cNJi9sW3UC/cj3gxuw=; b=clcmawWf68hd/4TrQjknGP0e28xKdSdABmpXj2w5jPv65qdKj0W9tmk8yd1/WMx0ng d9If2WGi6bIdW0WmkDqXJ2AzBVdjUhs5FMBr+nP1h6JOP1zKiM7B7RPRDyph+Pq8iDIb UC2iw2sY7KD3ERLQUvYHQuRA0q2G0NqJfT94DV4bZwS4kBl7pYT46CotDwg9ADdH8Oy3 QworcL8r+NuBAhWU9zlTH5P+tz8O7ylfl2i31+Y6bnIkOeiGwPxfuWSc61zIGj+jnwF6 jh0cIR071oczjmUW98xzOxLULNQ1OQcTaSvpkDjIJkzpYPpGFU80U0j0QPghRhPFsZAx y/Dw== X-Gm-Message-State: AOJu0YzZBNx7xdhjbR5rMs7fn4O/kqrDzDmvIIInMu+Cjg2EQCg/bGRb X7LIHybXSp762IGE6toxEM/Cu8N9hHQmLWEMRwX7eCEhSkL96ZL0fdQKZzImaqndSg== X-Gm-Gg: AfdE7ckaU76puxsmuHg5S8u+jP50C6LH6vA7zckGZLPrbqP04LBn6SA/D6yZPfVhSne VTFGpTfT5F7g6+WoPZtnY+/5OkWPKVSEMKIXMRQBxkhxeiQC0E9y6sUf5r+h/Yn8Tx3ceepLVOT noAgC8Onx/VZjrxAhgzhEeevPHa6U+DGp1qNBwms/hO2s2e0xxEP0AzP1KGkYTokUK4yFcVS/Vh X+pyxGg6iLVpPuLZ0f0nwcdtry/tlzQFPpa7h//t2j6aTIGbeb8OzI6Lj3H7oqzGQfbrMaTG/Ct jVWKAJRBvWs6rj74z7oH0vdX64y40WaV0Eoq7Tsc9U0UcBeeEB6Zv5QAKkp5WRDnXjyE/1/gBAf 8uvsC96NXlrn4iosfgp6ASwQPDFDSvrMfnqn5mp9/cDtycCtKX4ZqPaaX9C5qUM4rVkIUQ2cjVU 7leBdwpyo4dMkwH4ixNw== X-Received: by 2002:a17:90b:2683:b0:37f:9ce3:ca92 with SMTP id 98e67ed59e1d1-380aa1d77e1mr2483798a91.27.1782930056681; Wed, 01 Jul 2026 11:20:56 -0700 (PDT) From: Tomita Moeko To: qemu-devel@nongnu.org Cc: Alex Williamson , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , "Michael S. Tsirkin" , Tomita Moeko , K S Maan Subject: [PATCH v4 3/4] vfio/igd: Setup romfile_fixup hook Date: Thu, 2 Jul 2026 02:20:34 +0800 Message-ID: <20260701182035.96010-4-tomitamoeko@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260701182035.96010-1-tomitamoeko@gmail.com> References: <20260701182035.96010-1-tomitamoeko@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:39::2; envelope-from=tomitamoeko@gmail.com; helo=mail-pj2-x02.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1782930102562158500 Content-Type: text/plain; charset="utf-8" Install vfio_igd_legacy_rom_quirk() as the PCIDevice romfile_fixup hook when romfile is set so that a romfile-supplied VBIOS receives the same IGD fixup as the image read from the kernel ROM BAR. Reported-by: K S Maan Signed-off-by: Tomita Moeko Tested-by: K S Maan --- hw/vfio/igd.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/hw/vfio/igd.c b/hw/vfio/igd.c index f597218164..6fa8b26201 100644 --- a/hw/vfio/igd.c +++ b/hw/vfio/igd.c @@ -610,6 +610,10 @@ static bool vfio_pci_igd_config_quirk(VFIOPCIDevice *v= dev, Error **errp) goto error; } =20 + if (pdev->romfile) { + pdev->romfile_fixup =3D vfio_igd_legacy_rom_quirk; + } + /* * ASLS (OpRegion address) is read-only, emulated * It contains HPA, guest firmware need to reprogram it with GPA. --=20 2.53.0 From nobody Sun Jul 26 11:05:40 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1782930100; cv=none; d=zohomail.com; s=zohoarc; b=H+hKhKZrjgrUuYwZoGI129n/61Klz7+mPbKjZQzcKM5xlNr5GAd42Lg1c8ZoUUlIyH8jz7WqilnxYIKn4GPs1LwVMAw77XXRiKq9gWeU5419vuEEj4tL0nEsTgQ7jq/m7JPvmDgerbFwIRx701qbqmq4JjbgMM683qwMe8I9v9Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782930100; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Tfb2whMGpacDTSDAoeZ/x3H7tnheiu8op3PndOS9tgU=; b=X4LrbU0LCUF2A0XFZJOw6R5gqlLQRc9OuYUkL/odMWfNuc5xXpk3p2CRKadp8bcKAmVqoRDBfwPPbU7rxoxio3sFRiT96zd6UkaAI3097QVBRDAClW6TNGOllCAB6iFxL+4dRRMs2Z6vz5/dloOI+ocHt1nRH9U4sI5FT66rPKw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782930100354469.95604891525386; Wed, 1 Jul 2026 11:21:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wezYY-00089Q-3E; Wed, 01 Jul 2026 14:21:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wezYW-00088s-Cq for qemu-devel@nongnu.org; Wed, 01 Jul 2026 14:21:04 -0400 Received: from mail-pj2-x01.google.com ([2607:f8b0:4864:39::1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wezYU-0007QB-FL for qemu-devel@nongnu.org; Wed, 01 Jul 2026 14:21:04 -0400 Received: by mail-pj2-x01.google.com with SMTP id 98e67ed59e1d1-37fb1883fbfso127701a91.0 for ; Wed, 01 Jul 2026 11:21:02 -0700 (PDT) Received: from kotori-desktop ([2408:820c:8ffe:590:494:7c85:ae9c:cba8]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30f0bc27e0dsm187109eec.27.2026.07.01.11.20.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 01 Jul 2026 11:20:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782930061; x=1783534861; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Tfb2whMGpacDTSDAoeZ/x3H7tnheiu8op3PndOS9tgU=; b=VymftgxuLnLBaXzX+uT1c/DBp2w3GWtj5kT9TaMs+3fIheQXK3Y0x5NAKabEo67/ay gatkAEA3MDotmkdl7Wo6qvPF3sXoZw/QAtqGBuWZC4s1YFVEnFKoNck3J3dwnd1583ED 2zUdogwpGQQJJDTRkyFW/fZp9jiFradbzon7bLp/ZAex4AaXu33VytxPoSttuUywsnS3 9AAPhEzadA2TO4XWNjRLQOmba8UMgtcCWxOpOVBcf5RDNsbptOlYX0DAm6oFtinMXcvG sBOVU5OMFeDa47wSXBWbDq2RRrENCGPqC5mjyRFA2Ay1+1Z6oXTjhmr1JRSfhXzqclsZ RKgg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782930061; x=1783534861; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Tfb2whMGpacDTSDAoeZ/x3H7tnheiu8op3PndOS9tgU=; b=OybfKcJX7PGtT+56p1pVzXs4w/wfjGaFJP7cV4Ruj0NvHP6WktbP+BJK7iFa4T7uMc ndZmFmfNF5WFk/pMsqO+lBzH9tYI1UgSs5Yid6D25JAU3iiLDjRAhi/VBundtvjx3uoR lO1+Ys56aTcT5dASQ3KNkxO2xECdUVB7Sy58sb/4er883iOLKOrglZO3kr/vECD/EyDx MTwXmC0h5EmOcbFZWATdqQ81dmA+HqsQpNL/Fl8ZCIKINC56rSXnwecBTckPsdcoQmzw tL/ITRW2IkXpPDMQDX/JaBjuv2fLQTeXV4PWVGd3C7yMT9AC8uN5miFgCvC/bg3LeWGn Rn6Q== X-Gm-Message-State: AOJu0YzrAYfOKiaf2DlTir1xgT6FvbaWZSjzzQlZ2jCvbLpdbOwdB9oh AQMr4XjOu2ECQrRbh2AuwaXKht2J6yE4rkt1+NwHFVaf2hRvQ1+2ekIMzld8pxnFUA== X-Gm-Gg: AfdE7clto5361yJEsBdm5qkVP9kERkU4BdNZaBgZ1r70Q2yscjiYQvVZCpclBxUY6XX /70rlVB3SjcDqDrt/vepa6n0lSgGxLP5eb28qliZmpppAj0fvx7111qFgkNBUNOCGrcr8LTJqIB A+UK1SpZ8J+2hPEEx1zv7ykg/+LxRk+997654tJoUD069yG0HwJ4OxzCO22B3amcnXnOWRzl8Zs 9O3oLf/eqjfbJQzCBvDdq8h86IiKmtV0IZQ8RmuCuOKqVOLM5beBYHxqiEdW/Hs2hTMgYLnlhMn J0cB35srR0Ymr1aXR7tGubJhGmfCpGgQtagxdVK2SXwNwUlnpwhLoAH6wHMTMa48hHvsygs6zRZ nUwOl7BGur8SHVmpYqeHFNPo10qd2XxgKW7HycYZDj9Tb0HGUwh2O/S2xUeLwsbHvuf5ovpoEMh P+xjIg6uH+wJiNdHFjIvnva1K0fTAx X-Received: by 2002:a05:6a20:5493:b0:39b:d5f1:4ff with SMTP id adf61e73a8af0-3bff40a53d7mr2516447637.20.1782930061070; Wed, 01 Jul 2026 11:21:01 -0700 (PDT) From: Tomita Moeko To: qemu-devel@nongnu.org Cc: Alex Williamson , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , "Michael S. Tsirkin" , Tomita Moeko , K S Maan Subject: [PATCH v4 4/4] vfio/igd: Clear saved BDSM in legacy VBIOS ROM at load time Date: Thu, 2 Jul 2026 02:20:35 +0800 Message-ID: <20260701182035.96010-5-tomitamoeko@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260701182035.96010-1-tomitamoeko@gmail.com> References: <20260701182035.96010-1-tomitamoeko@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:39::1; envelope-from=tomitamoeko@gmail.com; helo=mail-pj2-x01.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1782930102615158500 Content-Type: text/plain; charset="utf-8" IGD does not come with a ROM BAR [1], the ROM BAR read by default from kernel is actually the host VBIOS shadow RAM region that contains host modifications on boot. With AI-assisted reverse engineering on VBIOS binaries, it is observed that VBIOS saves BDSM register value on first access and uses saved value if present. When the image is executed in guest, since there is already a saved HPA in VBIOS, it keeps using that value instead of the GPA programmed by SeaBIOS in BDSM register in PCI config space, causing VBIOS to program GTT entries with wrong address, resulting in garbled output in BIOS POST and the error below detected by i915 driver. i915 0000:00:02.0: [drm] *ERROR* Initial plane programming using invalid ra= nge, dma_addr=3D0x00000000db200000 ((null) [0x00000000baf00000-0x00000000be= efffff]) The previous solution, c4c45e943e51 ("vfio/pci: Intel graphics legacy mode assignment"), adjusts GTT entry addresses to (addr - host BDSM + guest BDSM) to workaround that. But it is removed in 5aed8b0f0be2 ("vfio/igd: Remove GTT write quirk in IO BAR 4") due to inconsistent values in MMIO BAR0 and IO BAR4. Considering it's unsafe to expose HPA to guest, a ROM quirk clearing the saved value in VBIOS image is introduced. It searches the BDSM accessor routine by matching a 19-byte signature anchored on the unique `mov $0x105e,%ax` instruction, then locate the offset of saved BDSM and clears it. This makes the routine fall through to the PCI config read on the first call inside the guest. [1] 3.5.15, 4th Generation Intel Core Processor Family Datasheet Vol. 2 https://www.intel.com/content/dam/www/public/us/en/documents/datasheets= /4th-gen-core-family-desktop-vol-2-datasheet.pdf Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3093 Reported-by: K S Maan Signed-off-by: Tomita Moeko Tested-by: K S Maan --- hw/vfio/igd.c | 76 +++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 76 insertions(+) diff --git a/hw/vfio/igd.c b/hw/vfio/igd.c index 6fa8b26201..9a2f2a3c73 100644 --- a/hw/vfio/igd.c +++ b/hw/vfio/igd.c @@ -729,11 +729,81 @@ bool vfio_probe_igd_config_quirk(VFIOPCIDevice *vdev,= Error **errp) return vfio_pci_igd_config_quirk(vdev, errp); } =20 +/* + * IGD ROM BAR read from kernel is actually the host VBIOS shadow RAM regi= on, + * which contains host modifications. In Gen 6-9 VBIOS, the routine below = is + * used to get BDSM value when programming the initial GTT. + * xx xx xx xx v: .long ? # saved value + * 66 53 push %ebx + * 66 2e 83 3e xx xx 00 cmpl $0x0,%cs:v # is saved value em= pty? + * 74 07 je 1f # if zero, go compu= te + * 66 2e a1 xx xx mov %cs:v,%eax # else return saved= value + * eb 0f jmp 2f + * b8 5e 10 1: mov $0x105e,%ax # dev 00:02.0, offs= et 5E + * e8 xx xx call pci_read_cfg_word + * 66 c1 e0 10 shl $0x10,%eax # left shift 16 bits + * 66 2e a3 xx xx mov %eax,%cs:v # save the result + * 66 5b 2: pop %ebx + * c3 ret + * When running the VBIOS in guest, saved value still reflects the host st= olen + * memory base address, which is not correct in guest. So we need to patch= the + * VBIOS to clear the saved value. + * + * The unique 19-byte starts at `cmpl $0,%cs:v` and ends at `mov $0x105e,%= ax` + * anchors the match to the routine. Both `cs:` displacements must referen= ce + * the same offset. + */ +static int igd_vbios_find_saved_bdsm(const uint8_t *rom, size_t rom_size, + uint16_t *bdsm_offset) +{ + static const uint8_t start[] =3D { 0x66, 0x2e, 0x83, 0x3e }; + static const uint8_t middle[] =3D { 0x00, 0x74, 0x07, 0x66, 0x2e, 0xa1= }; + static const uint8_t end[] =3D { 0xeb, 0x0f, 0xb8, 0x5e, 0x10 }; + uint16_t val; + size_t i; + bool found =3D false; + + if (rom_size < 19) { + return -ENOENT; + } + + for (i =3D 0; i + 19 <=3D rom_size; i++) { + if (memcmp(rom + i, start, sizeof(start)) !=3D 0 || + memcmp(rom + i + 6, middle, sizeof(middle)) !=3D 0 || + memcmp(rom + i + 14, end, sizeof(end)) !=3D 0) { + continue; + } + + /* same saved value address? */ + if (rom[i + 4] !=3D rom[i + 12] || rom[i + 5] !=3D rom[i + 13]) { + continue; + } + + if (found) { + return -EEXIST; + } + + val =3D rom[i + 4] | ((uint16_t)rom[i + 5] << 8); + if (val + sizeof(uint32_t) <=3D rom_size) { + *bdsm_offset =3D val; + found =3D true; + } + } + + if (!found) { + return -ENOENT; + } + + return 0; +} + void vfio_igd_legacy_rom_quirk(PCIDevice *pdev, uint8_t *ptr, uint32_t siz= e) { VFIOPCIDevice *vdev =3D VFIO_PCI_DEVICE(pdev); int gen; uint16_t pcir_offset; + int ret; + uint16_t bdsm_offset =3D 0; uint8_t checksum =3D 0; uint32_t i; =20 @@ -765,6 +835,12 @@ void vfio_igd_legacy_rom_quirk(PCIDevice *pdev, uint8_= t *ptr, uint32_t size) */ pci_set_word(ptr + pcir_offset + 6, vdev->device_id); =20 + /* Search and clear the saved BDSM value */ + ret =3D igd_vbios_find_saved_bdsm(ptr, size, &bdsm_offset); + if (ret =3D=3D 0) { + memset(ptr + bdsm_offset, 0, sizeof(uint32_t)); + } + /* * IGD roms are known to have bogus checksums. No matter we changed the * device ID or not, we need to recalculate the checksum and patch it. --=20 2.53.0