From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1783413395; cv=none; d=zohomail.com; s=zohoarc; b=RCq7T5sXJYAsIE51K5cTk1ompIAM/Uiep1ASj820+EYUxsXdtFQtBeVSgJnGPMOHJFCQdL/NwZi3/8ATm2cc+/1xrWJMEizgC2Dv8qidG9DorTF6wz51GPhLLhfTCukB23OQv4lO5TCChm+puJU4byRYcNfDVnWGb5Zt5P+zPLI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783413395; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=P9Lw79sO0i26l3geUFVoG2PMHuBvpLx6zQylyZ1cYC8=; b=fbAfMJbLsOOJkWm0/umMgFnrYTTbmh/UDRPy8bYoTx8G1L3xAl7h/jSiTRCBNisBR2j7+70MM/czDBYDLtvyd8XZbWiUcoVrFUaHRmDxjJnOWijqDEOLlehlT+UXJ92g2rFgWCdv5nT4Q7KqDVuk3ER9WsJurvQ/k/g9997Onuk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783413395602252.33580799227911; Tue, 7 Jul 2026 01:36:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wh1Hr-0005Zp-HK; Tue, 07 Jul 2026 04:36:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh1Hl-0005M3-80 for qemu-devel@nongnu.org; Tue, 07 Jul 2026 04:36:11 -0400 Received: from mail-pj2-x01.google.com ([2607:f8b0:4864:39::1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wh1Hj-0001x7-R2 for qemu-devel@nongnu.org; Tue, 07 Jul 2026 04:36:08 -0400 Received: by mail-pj2-x01.google.com with SMTP id 98e67ed59e1d1-380feaa05dcso969985a91.0 for ; Tue, 07 Jul 2026 01:36:07 -0700 (PDT) Received: from kotori-desktop ([2408:820c:8ffe:590::9a0]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3117483e0a2sm5435221eec.12.2026.07.07.01.36.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 07 Jul 2026 01:36:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783413366; x=1784018166; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=P9Lw79sO0i26l3geUFVoG2PMHuBvpLx6zQylyZ1cYC8=; b=HRQU5HRZ+Xp7ISsqcCnQaumuD2hkrdysh//dnc+3fty/2N0jDkcLDUyROEqvz0Atj6 bdTVjR5a5sYqJ1MtpgC8tEtrwRM2ozrSNIe8VNjskHYeWXP/4AtjeGQPjIH1WaSxfsgo 2/Y6/1MTlfkfuoIH2Qq3Y2ufaXHENR5Kw9f+udCxaaQVUi3SzrsRGmXFalyhmUz5Icde iDrbrGbEbtyIX4ZVV2Bzlp5MMRR1u11h79wgMDycyegJHPOnQVs9gbafbbIUTOFcDuWY aC6nW540Ka3KfG+eXgxDS+lMzZvphbzQX8nB1SHvFyEpPYvP2BYNfCZaB/8BRl0RGoUP 1AuA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783413366; x=1784018166; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=P9Lw79sO0i26l3geUFVoG2PMHuBvpLx6zQylyZ1cYC8=; b=Bq8MXUjuz9+N772H1k0U4EAPFxVeAaX7p0QCqHtvm2EnMiYZ8D34OKSSYSoPr2OzDq qZGDrFhoFG38ULMlwjLHZNRgmphWQg7YkjrbXzHlv7vQPi3FWkW4Il0zTESf/eog8f6X F8ExY5VExPD3ENF9EBhKzwmU98Hjdu0MV+Aut2Izvhk+mb+kQtVLpkRpxo2D11oLnqev +XC7VNidJbRZXNPdpJ/WZVb3N+nqKm4XwFIbzBl81iKr6ET91NR72uivnK9aHQLKbdcP v7pZUFDln886Bl3t6oi7TFerxTpD3dEwbjGBgfr6IlEzWzYFRqq1DtN3XjDvB/5P0Ism DERg== X-Gm-Message-State: AOJu0YwMbBraUdPS7nlKteV7Wnm/KpSDtOjq744gRxqDxdzkMoYEW3yY uqdusCfbwLRZyDbfeNtVAhN9PFW++oHp6VSnlnrW+EvpLuSXtgVihpa2jQygJbo= X-Gm-Gg: AfdE7cl9qDC9WhlymPhfyNSXl5UJjYT4hCSvzhbMKKcSlt/YLXiTjN/0qyZh1BRU4/4 oeDZi3PeuJ8oCMeojFCzkut8xvkOIf9DFE+Xo0M554Z4YBCV4xH0ZDMRQBYtJD5c/GGDxU7Pevc gFQOEcT/p5BHzoJ01FDcudJ3dr7tvrp0dKRKY9QCj11ggzKPwulflO8DL7melcek3GnYOS5OQ2c 7csvxB3Cbo7QRYyj6KR+vbZB/28xNabMNmp8lu7OxmBNHYVmPI898IyTkbsyqiFYwXhWRt1WTv+ F4kYtYbOcucXNGMEhcI0VIhkvciAlIIKS8MZAFUPjYxTnRKG2BOKMAfq7oVYNqPsuZ2CckgEjOs tIRO/y8nTNjbrbxvsUB8LSou7BxdgmnRAb5WyGq1CCntP4I1DHEHDfNMONU3r+KlGR08jAatVNP o= X-Received: by 2002:a17:90b:57cd:b0:381:6c5:3f63 with SMTP id 98e67ed59e1d1-387557685demr4417372a91.6.1783413364493; Tue, 07 Jul 2026 01:36:04 -0700 (PDT) From: Tomita Moeko To: qemu-devel@nongnu.org Cc: Alex Williamson , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , "Michael S. Tsirkin" , Tomita Moeko , K S Maan Subject: [PATCH v5 1/3] hw/pci: Introduce romfile_fixup hook in PCIDevice Date: Tue, 7 Jul 2026 16:35:48 +0800 Message-ID: <20260707083550.25765-2-tomitamoeko@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260707083550.25765-1-tomitamoeko@gmail.com> References: <20260707083550.25765-1-tomitamoeko@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:39::1; envelope-from=tomitamoeko@gmail.com; helo=mail-pj2-x01.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1783413396490158500 Content-Type: text/plain; charset="utf-8" Some devices, such as VFIO IGD passthrough, require device-specific fixups on the romfile provided by user. Add an optional romfile_fixup hook to PCIDevice. When set, it is invoked from pci_add_option_rom() right after the image is loaded, receiving the ROM buffer and its size. This provides a place to post-process a loaded romfile without leaking device-specific logic into the generic PCI core. Reported-by: K S Maan Signed-off-by: Tomita Moeko Acked-by: Michael S. Tsirkin Tested-by: K S Maan --- hw/pci/pci.c | 4 ++++ include/hw/pci/pci_device.h | 1 + 2 files changed, 5 insertions(+) diff --git a/hw/pci/pci.c b/hw/pci/pci.c index d3191609e2..04372074ff 100644 --- a/hw/pci/pci.c +++ b/hw/pci/pci.c @@ -2639,6 +2639,10 @@ static void pci_add_option_rom(PCIDevice *pdev, bool= is_default_rom, /* Only the default rom images will be patched (if needed). */ pci_patch_ids(pdev, ptr, size); } + + if (pdev->romfile_fixup) { + pdev->romfile_fixup(pdev, ptr, size); + } } =20 pci_register_bar(pdev, PCI_ROM_SLOT, 0, &pdev->rom); diff --git a/include/hw/pci/pci_device.h b/include/hw/pci/pci_device.h index 5cac6e1688..a65e77018c 100644 --- a/include/hw/pci/pci_device.h +++ b/include/hw/pci/pci_device.h @@ -159,6 +159,7 @@ struct PCIDevice { bool has_rom; MemoryRegion rom; int32_t rom_bar; + void (*romfile_fixup)(PCIDevice *pdev, uint8_t *ptr, uint32_t size); =20 /* INTx routing notifier */ PCIINTxRoutingNotifier intx_routing_notifier; --=20 2.53.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1783413388; cv=none; d=zohomail.com; s=zohoarc; b=h5dIfuVep7qTrEKMKyTndjpC77CWvsg9yVl79Ieq/uKRCpBWOZPzQDCZzw2ielGll07upJD86nyA6NZi+vSLL0Lwr39IIPBneSughO1hvH9SN24Rz1egtvuS8jXJKbOpeFfMhHL+9Fxgka0RXLIgMJLLs+v3lfgJCwlo7O3C1lQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783413388; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=klsyONO/Cg3smq3LoYkvbuo2acmHos3YgPohgAu92xU=; b=DWOizXoJYpeTdbhYZwgd2df5pMF0/cSHoMClV4dwq/3dNtYHD1P552Thj2x3gLFAyuXe+r4R13VThZmAY+DrT0C0891IuW3wOFkAUvKFC1uFS8Ay/1AOMLkPVKPsFIAd44sELqPclBEo9CgSya1PbKJxVEeOifg3ltnUOikLaYg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783413388234317.3529285598851; Tue, 7 Jul 2026 01:36:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wh1Hw-0005tJ-Kj; Tue, 07 Jul 2026 04:36:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh1Hn-0005Rp-Fi for qemu-devel@nongnu.org; Tue, 07 Jul 2026 04:36:13 -0400 Received: from mail-pz2-x01.google.com ([2607:f8b0:4864:3b::1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wh1Hl-00022I-J0 for qemu-devel@nongnu.org; Tue, 07 Jul 2026 04:36:11 -0400 Received: by mail-pz2-x01.google.com with SMTP id 41be03b00d2f7-c9fe62e0da3so573770a12.1 for ; Tue, 07 Jul 2026 01:36:09 -0700 (PDT) Received: from kotori-desktop ([2408:820c:8ffe:590::9a0]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3117483e0a2sm5435221eec.12.2026.07.07.01.36.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 07 Jul 2026 01:36:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783413368; x=1784018168; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=klsyONO/Cg3smq3LoYkvbuo2acmHos3YgPohgAu92xU=; b=Ktl7kSoNuDbypqyP5s+uXYjYdOFfg7hFxG3y+0oOXAO+6yr9knCrINkAjzaFJwcJge rCn3rhtCFDpMzBPTgMj63MmkpbvhNYELbnX1c/4lJDMlsU0q/1344Vl/AsYIxM6OEo2V Fsd3NINwM5O4Mfz+P8Gcfgeim6soOrTB/LDusBiTfjqgirnfCjJAORS4HpUH8HR8RZkT 5zU09A/N3iZYAV5Bx0WPHPDbvVrUKdiEG8gR1BOtZ+oy84haCrZYeNfuCbXFfKnyGF5t 3aTjGhG9qu3hOx/PDwow62sVz2kfvujtqQUe9CoE0f+y1QOOo6Paaf4W6Ah8xOlUxbWP 7V/Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783413368; x=1784018168; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=klsyONO/Cg3smq3LoYkvbuo2acmHos3YgPohgAu92xU=; b=mbxQmLn0mI/3nhgly4kwv3gJ3BJWvILCNNltvvjbnhujLmtujbI5RzaUGtPi9aTzsz M+8xGsfxzvg1qjaMTjVdDEVOdKAbKLibvUdic9aMH/1SJBnY1LDG8Yvod1oEnzxQWhQM 9EAW9m00YSEKSL/I5jLQyfEl0ymPmkrfiXQtcv5XxdA4ZHQR7Qb/kk0rG62jbKfky1lO vODcw4bup1LE7BFoqov1PGI56gRtydflDx5EZlqNhzmbfZKSAYUnNHHLd9GfkzJh1z0x tA0MP4sxY8aiNZ0L+Yxh8Oo7QdOwDGqtfQnyu9DKDESNKlIzztbYdijbBd+Nyu4juTIS QlfA== X-Gm-Message-State: AOJu0YwJTlugzzVgvralAIjzzM2MZ0DuCtThrHs3W8UTn7fAMGlDk+Dv SvlRou0spoNeDMdDj5Uw/TfNU4fgopR9U8NZH5Nv1SzljEQau3l5qK5BFZ8pGKc= X-Gm-Gg: AfdE7cnl03FZ9LQxzyKr0t/iL3odJ3li3ye8I+RP4Y6CtEHja+FVsd/KXk8np7dI8+y kzeO0aFWida4iVc5N/BbRfZ/M9S+R0c836yGUEDufOPQLFXh76hZKb0LGAnzSrKXyuEVdQQ6omA 8Wy6mi2SFzYPJm4i0/HAJ1AArdpVCRk6me8ajU04BLDHNtvvUflfiHNoX80h2hPjEAvlx1jwacF eg4I3DQ4VuaJvTTE9UIAzEcEnN8E0f2+gNvkMX+hNPupOlWdFLMg+Av2KHFKltUmwhCo1Rd5G2N iTSUX8bA6Tio5pg6AM7E0eAhfl+/pMVJXD1Uf+DdiE0G8zfMI/HrAB8twT44cOMhNJ5nzOuNZc0 Y/o5C+B6zdGp5cCZtvryOqw0NLeV0NzUgmmBzjJqybA+khZuIMwO04bGtKcecf5Dszc2NHeGodP 4= X-Received: by 2002:a05:6300:67c7:b0:3bf:b68f:4685 with SMTP id adf61e73a8af0-3c08ed41d5emr5007695637.23.1783413368210; Tue, 07 Jul 2026 01:36:08 -0700 (PDT) From: Tomita Moeko To: qemu-devel@nongnu.org Cc: Alex Williamson , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , "Michael S. Tsirkin" , Tomita Moeko , K S Maan Subject: [PATCH v5 2/3] vfio/igd: Patch device ID for romfile-provided VBIOS Date: Tue, 7 Jul 2026 16:35:49 +0800 Message-ID: <20260707083550.25765-3-tomitamoeko@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260707083550.25765-1-tomitamoeko@gmail.com> References: <20260707083550.25765-1-tomitamoeko@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:3b::1; envelope-from=tomitamoeko@gmail.com; helo=mail-pz2-x01.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1783413390304158500 Content-Type: text/plain; charset="utf-8" Multiple IGD devices of the same generation share the same rom, the device ID in its PCIR structure may not match. As SeaBIOS checks the device ID strictly and refuses to run the VBIOS on a mismatch, the ID has to be patched. For a ROM read from the kernel ROM BAR, vfio_pci_load_rom() already patches the device ID and recomputes the checksum. A VBIOS provided by the user via romfile, however, is loaded by the generic PCI core and does not receive this IGD-specific fixup. Introduce vfio_igd_legacy_rom_quirk() in igd.c, which patches the device ID and recomputes the (known bogus) checksum of a Gen 6-9 IGD legacy VBIOS. This is registered as romfile_fixup hook when a romfile is configured so that the romfile-provided VBIOS then receives the same fixup as one read from the kernel ROM BAR. Reported-by: K S Maan Signed-off-by: Tomita Moeko Tested-by: K S Maan --- hw/vfio/igd-stubs.c | 5 +++++ hw/vfio/igd.c | 53 ++++++++++++++++++++++++++++++++++++++++++++ hw/vfio/pci.h | 2 ++ hw/vfio/trace-events | 1 + 4 files changed, 61 insertions(+) diff --git a/hw/vfio/igd-stubs.c b/hw/vfio/igd-stubs.c index f7687d9091..29110f7568 100644 --- a/hw/vfio/igd-stubs.c +++ b/hw/vfio/igd-stubs.c @@ -18,3 +18,8 @@ bool vfio_probe_igd_config_quirk(VFIOPCIDevice *vdev, Err= or **errp) { return true; } + +void vfio_igd_legacy_rom_quirk(PCIDevice *pdev, uint8_t *ptr, uint32_t siz= e) +{ + return; +} diff --git a/hw/vfio/igd.c b/hw/vfio/igd.c index e091f21b6a..a5c1b57ce4 100644 --- a/hw/vfio/igd.c +++ b/hw/vfio/igd.c @@ -610,6 +610,10 @@ static bool vfio_pci_igd_config_quirk(VFIOPCIDevice *v= dev, Error **errp) goto error; } =20 + if (pdev->romfile) { + pdev->romfile_fixup =3D vfio_igd_legacy_rom_quirk; + } + /* * ASLS (OpRegion address) is read-only, emulated * It contains HPA, guest firmware need to reprogram it with GPA. @@ -724,3 +728,52 @@ bool vfio_probe_igd_config_quirk(VFIOPCIDevice *vdev, = Error **errp) =20 return vfio_pci_igd_config_quirk(vdev, errp); } + +void vfio_igd_legacy_rom_quirk(PCIDevice *pdev, uint8_t *ptr, uint32_t siz= e) +{ + VFIOPCIDevice *vdev =3D VFIO_PCI_DEVICE(pdev); + int gen; + uint16_t pcir_offset; + uint8_t checksum =3D 0; + uint32_t i; + + if (!vfio_pci_is(vdev, PCI_VENDOR_ID_INTEL, PCI_ANY_ID) || + !vfio_is_vga(vdev) || !vdev->vga) { + return; + } + + /* Only Gen 6~9 devices have legacy VBIOS as Option ROM */ + gen =3D igd_gen(vdev); + if (gen < 6 || gen > 9) { + return; + } + + if (pci_get_word(ptr) !=3D 0xaa55) { + return; + } + + /* Must be a legacy ROM */ + pcir_offset =3D pci_get_word(ptr + 0x18); + if (pcir_offset + 0x14 >=3D size || memcmp(ptr + pcir_offset, "PCIR", = 4) || + pci_get_byte(ptr + pcir_offset + 0x14) !=3D 0x00) { + return; + } + + /* + * Patch device ID as multiple IGD devices share the same rom with pos= sible + * non-matching IDs. This duplicates with vfio_pci_load_rom(), but req= uired + * for romfile. + */ + pci_set_word(ptr + pcir_offset + 6, vdev->device_id); + + /* + * IGD roms are known to have bogus checksums. No matter we changed the + * device ID or not, we need to recalculate the checksum and patch it. + */ + for (i =3D 0; i < size; i++) { + checksum +=3D ptr[i]; + } + ((uint8_t *)ptr)[6] -=3D checksum; + + trace_vfio_pci_igd_vbios_patched(vdev->vbasedev.name); +} diff --git a/hw/vfio/pci.h b/hw/vfio/pci.h index cf56711587..65a1385ce3 100644 --- a/hw/vfio/pci.h +++ b/hw/vfio/pci.h @@ -253,8 +253,10 @@ void vfio_setup_resetfn_quirk(VFIOPCIDevice *vdev); bool vfio_add_virt_caps(VFIOPCIDevice *vdev, Error **errp); void vfio_quirk_reset(VFIOPCIDevice *vdev); VFIOQuirk *vfio_quirk_alloc(int nr_mem); + void vfio_probe_igd_bar0_quirk(VFIOPCIDevice *vdev, int nr); bool vfio_probe_igd_config_quirk(VFIOPCIDevice *vdev, Error **errp); +void vfio_igd_legacy_rom_quirk(PCIDevice *pdev, uint8_t *ptr, uint32_t siz= e); =20 extern const PropertyInfo qdev_prop_nv_gpudirect_clique; =20 diff --git a/hw/vfio/trace-events b/hw/vfio/trace-events index 4c28b3291c..e472a65a44 100644 --- a/hw/vfio/trace-events +++ b/hw/vfio/trace-events @@ -90,6 +90,7 @@ vfio_pci_igd_bar4_write(const char *name, uint32_t index,= uint32_t data, uint32_ vfio_pci_igd_bdsm_enabled(const char *name, int size) "%s %dMB" vfio_pci_igd_host_bridge_enabled(const char *name) "%s" vfio_pci_igd_lpc_bridge_enabled(const char *name) "%s" +vfio_pci_igd_vbios_patched(const char *name) "%s" =20 # listener.c vfio_iommu_map_notify(const char *op, uint64_t iova_start, uint64_t iova_e= nd) "iommu %s @ 0x%"PRIx64" - 0x%"PRIx64 --=20 2.53.0 From nobody Sun Jul 26 11:01:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1783413415; cv=none; d=zohomail.com; s=zohoarc; b=oLSe6zccnMfUQETOG/hKyUyLlzy13IGWgRsiS4ejFKFdSeQhIt0lkdr0zLdgXz9R6z3OoelyTMOt4sOBB6Np2y/4UzBMR3BsZTYBh2zndlfB/84CB1hO341HLCAfjdXU9PklgRFfEQkLbmImQGX4fmt0MMUCL2HKeF2AP7g2/Cg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783413415; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=HslTUaRU9OgQSB6SuuY8D6TfTQmigTbw5XgMXVLte18=; b=YAcFgmN43gkOLnag6Q/5ebwh4hJL82dyv6owrXr6YAxxFAZkW+/XckOD7A66H+FrDbomEQokmxCXoxjDGNKWmxwdk56dYZeB36uZ1YCCFKrmNLXW2TT3RyLWQuMwze5ciDKjNa3hf67sVYBO8HkhH812Iv64mjqeXvsMJId/Y5k= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178341341534980.24591335332036; Tue, 7 Jul 2026 01:36:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wh1Hx-0005zM-5H; Tue, 07 Jul 2026 04:36:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh1Hr-0005ai-Gl for qemu-devel@nongnu.org; Tue, 07 Jul 2026 04:36:15 -0400 Received: from mail-pz2-x00.google.com ([2607:f8b0:4864:3b::]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wh1Hp-00029y-BI for qemu-devel@nongnu.org; Tue, 07 Jul 2026 04:36:15 -0400 Received: by mail-pz2-x00.google.com with SMTP id 41be03b00d2f7-c9a20e73d7cso1170657a12.1 for ; Tue, 07 Jul 2026 01:36:12 -0700 (PDT) Received: from kotori-desktop ([2408:820c:8ffe:590::9a0]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3117483e0a2sm5435221eec.12.2026.07.07.01.36.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 07 Jul 2026 01:36:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783413372; x=1784018172; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=HslTUaRU9OgQSB6SuuY8D6TfTQmigTbw5XgMXVLte18=; b=NXGV1d0znLKXPox0ZiN0rs3/HOc9KaSelv/l2bOBkHSEJDqqUgXQXXEb12AhhOyWm3 TuD6b0nUEGhv7J4VP0sKyOdpHnL19eW8XhUWzYuGiLYnba6JL6KKTsc1onpC6MSVVZ88 v0iH7GIwuRB976amHBcDvq1LhuGrelnd6FizKIlePcB9Ll1SdW6hkU33dZFeSP/bOGlH YcnjJiDxBLFrgh45j5O8R6XyWtMvl/b+SqonIisRzeU0w5zY6NJtrjf5xl9Wrxfmkwlj ObHYUspovjWUUI5ZrsV8Q/hFj3B3BUVS+3IiwASbijqS+IIqR2ucqLwCMjwOa+QwTwPR bo6w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783413372; x=1784018172; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=HslTUaRU9OgQSB6SuuY8D6TfTQmigTbw5XgMXVLte18=; b=fp5CBZSM89ipmhkDaRvT4BA1znt/V/zhv0+dJ4WBofcwvqoiPpeh4Omzx5ieom7UNG gFB/M58BZqw+X/ahV3gfAITDdo5iufQ+6gKIzyi+2z6H6aEas8BSFYUF8ZT/9hgC76tq CTcmJiD0G9uYNs5al0Yldw8syMODd0y6l2RaIpVePpB6O0gFoKY9HJQVSsAmF4TBi7Qy JaEcMqiDeGEJ4WwGgN11YQEVeDG9wvS6fQEBZrI7IHuAtiwaXX5RlsnnyJYe5TTHEAWk Hvis3hZKjtUgemWDvNNUnpDtGyS5q3s3h2Lwae6nn9FCaBwnGnu9ZPkcpIU4tiWwiblj ykHg== X-Gm-Message-State: AOJu0YyE7NVe2/5oQwtKimnimRXSAnTZtDps0opiOrOJGWBqQERgDsu9 RlPlN0+L+Jzcy1jPOALSjX3k6RvKqZJB6B9MV2npADVVoZeX1+6v6ojTxaAGzy8= X-Gm-Gg: AfdE7clRoVpirFTKuTgXxqynOUJC7UHcrBLknGuLMjAyIrHrIx1NvdUk4QYYiOIqfgR 210VS3a2gNIdEPJBWZS9ur+y6b3QvuE4C4p9JpLpYEHLd2do8/pMRf3jt2TZAuYg16qEC5jsPQU lC6dxDWVUF+gJdbZjbcRFXrpDLZtqIgbW9sp5v9O37dimx2yMmSHd8oVAC1WnXB9EbVUZ6d+7mD IhgRi+8gsWPYwlUUZ4WW+ZxLaxj/JpaF6Rm7bDTl19PZiB9eKJO0TuBSq3vo+fps59S2f08sC+p zOjnrmiBPWpoIqg3CJMKI9FL83eN/nB2/ci39R3MmNkLeDNkFx3A8xUkfcpST2EEbvPXEAAtXQv oMJsaSvs8lj2pUWBfNG1eJsAmvgqPCYBZQZ++wOmmagxW+mcd+7CWzGRHQ+71fUz2xMY0XteT3o Y= X-Received: by 2002:a05:6a20:7491:b0:3bf:ba2a:6a8e with SMTP id adf61e73a8af0-3c08edbe498mr5340709637.21.1783413371786; Tue, 07 Jul 2026 01:36:11 -0700 (PDT) From: Tomita Moeko To: qemu-devel@nongnu.org Cc: Alex Williamson , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , "Michael S. Tsirkin" , Tomita Moeko , K S Maan Subject: [PATCH v5 3/3] vfio/igd: Clear saved BDSM in legacy VBIOS ROM at load time Date: Tue, 7 Jul 2026 16:35:50 +0800 Message-ID: <20260707083550.25765-4-tomitamoeko@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260707083550.25765-1-tomitamoeko@gmail.com> References: <20260707083550.25765-1-tomitamoeko@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:3b::; envelope-from=tomitamoeko@gmail.com; helo=mail-pz2-x00.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1783413416494158500 Content-Type: text/plain; charset="utf-8" IGD does not come with a ROM BAR [1], the ROM BAR read by default from kernel is actually the host VBIOS shadow RAM region that contains host modifications on boot. With AI-assisted reverse engineering on VBIOS binaries, it is observed that VBIOS saves BDSM register value on first access and uses saved value if present. When the image is executed in guest, since there is already a saved HPA in VBIOS, it keeps using that value instead of the GPA programmed by SeaBIOS in BDSM register in PCI config space, causing VBIOS to program GTT entries with wrong address, resulting in garbled output in BIOS POST and the error below detected by i915 driver. i915 0000:00:02.0: [drm] *ERROR* Initial plane programming using invalid ra= nge, dma_addr=3D0x00000000db200000 ((null) [0x00000000baf00000-0x00000000be= efffff]) The previous solution, c4c45e943e51 ("vfio/pci: Intel graphics legacy mode assignment"), adjusts GTT entry addresses to (addr - host BDSM + guest BDSM) to workaround that. But it is removed in 5aed8b0f0be2 ("vfio/igd: Remove GTT write quirk in IO BAR 4") due to inconsistent values in MMIO BAR0 and IO BAR4. Considering it's unsafe to expose HPA to guest, a ROM quirk clearing the saved value in VBIOS image is introduced. It searches the BDSM accessor routine by matching a 19-byte signature anchored on the unique `mov $0x105e,%ax` instruction, then locate the offset of saved BDSM and clears it. This makes the routine fall through to the PCI config read on the first call inside the guest. The quirk is now also invoked from vfio_pci_load_rom(), so the fix applies to the VBIOS whether it is read from the kernel ROM BAR or supplied through romfile. [1] 3.5.15, 4th Generation Intel Core Processor Family Datasheet Vol. 2 https://www.intel.com/content/dam/www/public/us/en/documents/datasheets= /4th-gen-core-family-desktop-vol-2-datasheet.pdf Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3093 Reported-by: K S Maan Signed-off-by: Tomita Moeko Tested-by: K S Maan --- hw/vfio/igd.c | 76 ++++++++++++++++++++++++++++++++++++++++++++ hw/vfio/pci-quirks.c | 5 +++ hw/vfio/pci.c | 2 ++ hw/vfio/pci.h | 1 + 4 files changed, 84 insertions(+) diff --git a/hw/vfio/igd.c b/hw/vfio/igd.c index a5c1b57ce4..d26744a6c6 100644 --- a/hw/vfio/igd.c +++ b/hw/vfio/igd.c @@ -729,11 +729,81 @@ bool vfio_probe_igd_config_quirk(VFIOPCIDevice *vdev,= Error **errp) return vfio_pci_igd_config_quirk(vdev, errp); } =20 +/* + * IGD ROM BAR read from kernel is actually the host VBIOS shadow RAM regi= on, + * which contains host modifications. In Gen 6-9 VBIOS, the routine below = is + * used to get BDSM value when programming the initial GTT. + * xx xx xx xx v: .long ? # saved value + * 66 53 push %ebx + * 66 2e 83 3e xx xx 00 cmpl $0x0,%cs:v # is saved value em= pty? + * 74 07 je 1f # if zero, go compu= te + * 66 2e a1 xx xx mov %cs:v,%eax # else return saved= value + * eb 0f jmp 2f + * b8 5e 10 1: mov $0x105e,%ax # dev 00:02.0, offs= et 5E + * e8 xx xx call pci_read_cfg_word + * 66 c1 e0 10 shl $0x10,%eax # left shift 16 bits + * 66 2e a3 xx xx mov %eax,%cs:v # save the result + * 66 5b 2: pop %ebx + * c3 ret + * When running the VBIOS in guest, saved value still reflects the host st= olen + * memory base address, which is not correct in guest. So we need to patch= the + * VBIOS to clear the saved value. + * + * The unique 19-byte starts at `cmpl $0,%cs:v` and ends at `mov $0x105e,%= ax` + * anchors the match to the routine. Both `cs:` displacements must referen= ce + * the same offset. + */ +static int igd_vbios_find_saved_bdsm(const uint8_t *rom, size_t rom_size, + uint16_t *bdsm_offset) +{ + static const uint8_t start[] =3D { 0x66, 0x2e, 0x83, 0x3e }; + static const uint8_t middle[] =3D { 0x00, 0x74, 0x07, 0x66, 0x2e, 0xa1= }; + static const uint8_t end[] =3D { 0xeb, 0x0f, 0xb8, 0x5e, 0x10 }; + uint16_t val; + size_t i; + bool found =3D false; + + if (rom_size < 19) { + return -ENOENT; + } + + for (i =3D 0; i + 19 <=3D rom_size; i++) { + if (memcmp(rom + i, start, sizeof(start)) !=3D 0 || + memcmp(rom + i + 6, middle, sizeof(middle)) !=3D 0 || + memcmp(rom + i + 14, end, sizeof(end)) !=3D 0) { + continue; + } + + /* same saved value address? */ + if (rom[i + 4] !=3D rom[i + 12] || rom[i + 5] !=3D rom[i + 13]) { + continue; + } + + if (found) { + return -EEXIST; + } + + val =3D rom[i + 4] | ((uint16_t)rom[i + 5] << 8); + if (val + sizeof(uint32_t) <=3D rom_size) { + *bdsm_offset =3D val; + found =3D true; + } + } + + if (!found) { + return -ENOENT; + } + + return 0; +} + void vfio_igd_legacy_rom_quirk(PCIDevice *pdev, uint8_t *ptr, uint32_t siz= e) { VFIOPCIDevice *vdev =3D VFIO_PCI_DEVICE(pdev); int gen; uint16_t pcir_offset; + int ret; + uint16_t bdsm_offset =3D 0; uint8_t checksum =3D 0; uint32_t i; =20 @@ -766,6 +836,12 @@ void vfio_igd_legacy_rom_quirk(PCIDevice *pdev, uint8_= t *ptr, uint32_t size) */ pci_set_word(ptr + pcir_offset + 6, vdev->device_id); =20 + /* Search and clear the saved BDSM value */ + ret =3D igd_vbios_find_saved_bdsm(ptr, size, &bdsm_offset); + if (ret =3D=3D 0) { + memset(ptr + bdsm_offset, 0, sizeof(uint32_t)); + } + /* * IGD roms are known to have bogus checksums. No matter we changed the * device ID or not, we need to recalculate the checksum and patch it. diff --git a/hw/vfio/pci-quirks.c b/hw/vfio/pci-quirks.c index bccf31751f..496a79a3ca 100644 --- a/hw/vfio/pci-quirks.c +++ b/hw/vfio/pci-quirks.c @@ -1592,3 +1592,8 @@ bool vfio_add_virt_caps(VFIOPCIDevice *vdev, Error **= errp) =20 return true; } + +void vfio_rom_quirk_setup(VFIOPCIDevice *vdev) +{ + vfio_igd_legacy_rom_quirk(PCI_DEVICE(vdev), vdev->rom, vdev->rom_size); +} diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c index 4d822b96b5..c40a6f7ca6 100644 --- a/hw/vfio/pci.c +++ b/hw/vfio/pci.c @@ -1114,6 +1114,8 @@ static void vfio_pci_load_rom(VFIOPCIDevice *vdev) data[6] =3D -csum; } } + + vfio_rom_quirk_setup(vdev); } =20 /* "Raw" read of underlying config space. */ diff --git a/hw/vfio/pci.h b/hw/vfio/pci.h index 65a1385ce3..fb70113e3a 100644 --- a/hw/vfio/pci.h +++ b/hw/vfio/pci.h @@ -251,6 +251,7 @@ void vfio_bar_quirk_exit(VFIOPCIDevice *vdev, int nr); void vfio_bar_quirk_finalize(VFIOPCIDevice *vdev, int nr); void vfio_setup_resetfn_quirk(VFIOPCIDevice *vdev); bool vfio_add_virt_caps(VFIOPCIDevice *vdev, Error **errp); +void vfio_rom_quirk_setup(VFIOPCIDevice *vdev); void vfio_quirk_reset(VFIOPCIDevice *vdev); VFIOQuirk *vfio_quirk_alloc(int nr_mem); =20 --=20 2.53.0