From nobody Sat Jul 25 20:47:29 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=oss.qualcomm.com ARC-Seal: i=1; a=rsa-sha256; t=1783966031; cv=none; d=zohomail.com; s=zohoarc; b=HWPJJebci/JrHWKmrfmNvjoVLtuv9oJV+aN/2oYeCkR3q7wg7an4rsrnfwdE4eBazS9eDCnNCd0j7S/76QjTP4Z5FvrN2/j7MiUnJ6ji0UtaqbJ0ba3clQTIM4Z4P/lMUxWLkvV6P2S37+2o59TktEsZ/BggvS4CpEM+DxRdbN0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783966031; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4K+ocDlAE85321hooxQqx2ALuMnvYzwLEQVdi5i1raw=; b=R51QDcm8tA6sgL+8ObWsgdx7Q92t/dcLCyolkK5c1JIVag7L7YZhKPqvB1+Y7zvv/CKbn1Srvh/1XE0RKRqc1W5AaFDY1XDk5jAMGvEb2QkC1O7cJQyJziLb4qsW4dFxdFE4nFceOz3RFtXOoiKhn2lW9/GF5dnDPaekLji9Aow= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783966031177979.6575506295094; Mon, 13 Jul 2026 11:07:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wjL3J-00036b-UD; Mon, 13 Jul 2026 14:06:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjL3I-000368-DL for qemu-devel@nongnu.org; Mon, 13 Jul 2026 14:06:48 -0400 Received: from mx0b-0031df01.pphosted.com ([205.220.180.131]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjL3G-0006dd-S8 for qemu-devel@nongnu.org; Mon, 13 Jul 2026 14:06:48 -0400 Received: from pps.filterd (m0279873.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66DF8UFG1803676 for ; Mon, 13 Jul 2026 18:06:45 GMT Received: from mail-pg1-f197.google.com (mail-pg1-f197.google.com [209.85.215.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fcwu4sy99-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Mon, 13 Jul 2026 18:06:45 +0000 (GMT) Received: by mail-pg1-f197.google.com with SMTP id 41be03b00d2f7-c8895156101so2509549a12.1 for ; Mon, 13 Jul 2026 11:06:45 -0700 (PDT) Received: from QCOM-qjMf8PBlDw.qualcomm.com (216-71-219-44.dyn.novuscom.net. [216.71.219.44]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13b8a5992c9sm27501109c88.4.2026.07.13.11.06.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 13 Jul 2026 11:06:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=qcppdkim1; bh=4K+ocDlAE85 321hooxQqx2ALuMnvYzwLEQVdi5i1raw=; b=dJzNZRhybAhVI9ab0bt8XZTeuQI pH9IxDJAVqo+l0Mxp/yt2EnauDgNncaGc6paQUOGrSpzOSCacqjEuLfa5HHX4xxq oGONNgmaV4LD4huRWneoDr4+w4UF7TL3VZ9fIjlf+w//5GP/yEP2K8skymGYZahQ 6cFoeQU+gn+/LUjFS/5An3lIZDaYL/Sh0Y7FpHU/bgFARioY2bh9Af7WxxXzNj4g 3NBxCPZO9RSF50gYE487p/MjMxJ2hf5Yx33rV2vsXP8m/chGSCT5jq9S56Gwc8Fy LnxWl4LDEmy+TMrRk8SCpVn4vJnyrt7noQAT1cbfq8hiVi3BGh8OftmVT3Q== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1783966005; x=1784570805; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=4K+ocDlAE85321hooxQqx2ALuMnvYzwLEQVdi5i1raw=; b=HB/lE/6uFpDFevCyqIW1n1fVxUun04puSTZsKLf+2qt6PfvZXSB+01+WBzI4J5HOwS TxJ+lKDWo2mdOlKffAtqyWtK6BsEbDXKqL+O8XC293IxpR/8EFThTPwoe2/xsraeKksH 681HvyPFuJ/c55xvmG+mhqZf3vxhuL7gJMdZgkbonD/8iXhb6V7Vd9OQ3Sh3k2JoFmik q0CILpNOmE6SLTXm+PH4+m6uMFGy7fHFtIfU9l3BhIoIN0atrNeGoMt7P9NGri40WRXc +Ro1IuvWQQhW0RPgP1SlRWDRipAvCnGbNV+eCAFcbjvHzNBSE3MlWsAZzxvMnVFtjQFN m6rg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783966005; x=1784570805; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=4K+ocDlAE85321hooxQqx2ALuMnvYzwLEQVdi5i1raw=; b=D4a1sXAzw2q9qIqF7IH4MGdT6lKOEZOHuKITfh5yMcB+rV1r9q0cEyEg2B2aC+02AA UnAFy8rhBkSEnYaY+puOQa2FMmrORuMDqbQI9NwYIIVehZy1jQ/Vi7msCt7AQ6EPUvD2 cFnqtB2PFQA5cvRLDlkuBa87yUOQ7FrpCIAD0qbVoqkuH/7b410cxRaD80qCMMFX7aSl t6p9507WTa5D9pAuj6iedvfZ9OQlJqNESMNJLOIeZYqa8BgjWtLaMppqM6HdtluWtK8G oRkgPSytxxo4C5wmHyaEytQwezmmusl7oYHfTRo2yDAd4xg7a/WbtTKs2lAbUv3SMyMj 0zNA== X-Gm-Message-State: AOJu0YwTGlIXndGO2kgGdGgL17pIsnXKEqCsyTSVMyNYSQwbukaFTzu0 C3f/cV2vtuCR9qALI0AD3XLiMTvBH3Goj5W5nOvMIVbOTIN9WM0DckTMp8N4qC7Xhnw9MYQMHiT +ZKhKmkDBc5m4h96fu5GJ+tK0/V2NpDLiWHBHCuHkJPwwP2gOxGe8HfhVKM6ZebHOAw== X-Gm-Gg: AfdE7cnXaHgfLzzgAT13WFywrxFRgaKJczed4mpyYriNKLNaTfnoQwidpDAtXiEr+LG ZY5glQAWbJZm0n1MNjNLSFX/If5wtvths7lUCzo2kRsjhchaaH7jh1DozQe114VeZTMldBIS5Ij pMpipEzugpTb4IjfEYtLIP3x+KYGRnF1lhL0RICx2HAYfioQlna72hcEu9Am9GvuUOT0/wdn+d4 VN8i/FDiuQ/ul57BrM+10DV5FgfiodwTlgXg6z+sRdcX0Iqsdt1wyonXr3ZVNMHQ7hDErpJHNxa nzM2TohPJNLzSmhC+9e3KYDlPQQPTYfmPdngRwhMIE1iKqNbfaihIWNwqaMh6//q3IrZZKFIri7 +9lErcoKkyMIfTwxwcry5AQHIE28BRkNfykMnG94pJ7X3+DP+69wLd7FgJ2ZfyMN+V8t+rw8Gd+ zULkagyA== X-Received: by 2002:a05:6a21:6e86:b0:3b4:9168:d9e6 with SMTP id adf61e73a8af0-3c1108993b5mr10077460637.37.1783966004591; Mon, 13 Jul 2026 11:06:44 -0700 (PDT) X-Received: by 2002:a05:6a21:6e86:b0:3b4:9168:d9e6 with SMTP id adf61e73a8af0-3c1108993b5mr10077437637.37.1783966004179; Mon, 13 Jul 2026 11:06:44 -0700 (PDT) From: Pierrick Bouvier To: qemu-devel@nongnu.org, peter.maydell@linaro.org, richard.henderson@linaro.org, pbonzini@redhat.com, stefanha@redhat.com Cc: pierrick.bouvier@oss.qualcomm.com Subject: [PULL 1/3] uftrace: riscv privilege level Date: Mon, 13 Jul 2026 11:06:36 -0700 Message-ID: <20260713180638.2228609-2-pierrick.bouvier@oss.qualcomm.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260713180638.2228609-1-pierrick.bouvier@oss.qualcomm.com> References: <20260713180638.2228609-1-pierrick.bouvier@oss.qualcomm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Authority-Analysis: v=2.4 cv=FMErAeos c=1 sm=1 tr=0 ts=6a552935 cx=c_pps a=rz3CxIlbcmazkYymdCej/Q==:117 a=iLqgmErQAxjCjdq5jj1Aqg==:17 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=rJkE3RaqiGZ5pbrm-msn:22 a=VwQbUJbxAAAA:8 a=dZbOZ2KzAAAA:8 a=JF9118EUAAAA:8 a=EUspDBNiAAAA:8 a=YMXLwu6otX1WtmdEadMA:9 a=bFCP_H2QrGi7Okbo017w:22 a=xVlTc564ipvMDusKsbsT:22 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzEzMDE4NyBTYWx0ZWRfX1fyjfKwYWXrT QtneEo/6EQv6TyDsca20fgKwtGfPoEWSMSnV78+GD1Ra/qs1L3v+EE/CjlQcefPQ2E8TZUS42wb zpvb4/pU9XCGAd5GH1cF6dfHlPrOEuY= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzEzMDE4NyBTYWx0ZWRfX5S0Vfrhxpam2 nusfqQYCr7/uZ4Wz6lU0vfmI9Rx8E85+jhAoOxLxCPv4GFSSxv/pQJWM6auHa2UuDEc1U0xkzTC +7z89ee46Zf/0pJ8Atla2EnfbEic30GurVSglfLOAVrmrRoBK4kYv73v0XSP5Wga6k+3AQvE7ai irVmFEX0XQmJPzwCmILEo1NZzQbC6d/7f/24zePwh9JGN0Fxs0VlX6qa5rgSGzpUFqwSDxKeEdV KJQUy/zJPS7doeqGMolFQoUN8zRGRF3KWl003QkTZ8QSMhdH3pIqH3RV0dTNbBeIQUC/oKUoubd 74UKMVs6QvDpBXwjZmXxUHmUFaQJTWrHN3hFQsLBdcgcQnXyJ8KSEfgtZ0yObKYEYK2rYulWXv6 HKyyXZTPI0R6XR4ScKmfx6MuKFQSpGXAj9hoCdWa/iAwMCznquOB2mANqH/xpTf2gFE32h4tIN3 ui7/yhJ0+kJd4/kWHMQ== X-Proofpoint-ORIG-GUID: BvswbqY5ule4PePmNI1M4oI7MUG3wcuB X-Proofpoint-GUID: BvswbqY5ule4PePmNI1M4oI7MUG3wcuB X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-13_04,2026-07-10_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 adultscore=0 bulkscore=0 malwarescore=0 impostorscore=0 suspectscore=0 priorityscore=1501 phishscore=0 spamscore=0 lowpriorityscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607130187 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=205.220.180.131; envelope-from=pierrick.bouvier@oss.qualcomm.com; helo=mx0b-0031df01.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @qualcomm.com) X-ZM-MESSAGEID: 1783966033217158500 Content-Type: text/plain; charset="utf-8" From: Yanfeng Liu This adds RiscV virtual user and supervisor privilege levels to uftrace plugin to avoid crashing with H extension guests. Signed-off-by: Yanfeng Liu Reviewed-by: Alistair Francis Reviewed-by: Pierrick Bouvier Link: https://lore.kernel.org/qemu-devel/tencent_E17E8F6494EE130F71527C6BCE= 481AF33E08@qq.com Signed-off-by: Pierrick Bouvier --- contrib/plugins/uftrace.c | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/contrib/plugins/uftrace.c b/contrib/plugins/uftrace.c index 9b0a4963aee..063e32220b1 100644 --- a/contrib/plugins/uftrace.c +++ b/contrib/plugins/uftrace.c @@ -109,6 +109,8 @@ typedef enum { RISCV64_SUPERVISOR, RISCV64_RESERVED, RISCV64_MACHINE, + RISCV64_VUSER, + RISCV64_VSUPERVISOR, RISCV64_PRIVILEGE_LEVEL_MAX, } Riscv64PrivilegeLevel; =20 @@ -153,8 +155,10 @@ static void uftrace_write_map(bool system_emulation) const char *path =3D "./uftrace.data/sid-0.map"; =20 if (system_emulation && access(path, F_OK) =3D=3D 0) { - /* do not erase existing map in system emulation, as a custom one = might - * already have been generated by uftrace_symbols.py */ + /* + * do not erase existing map in system emulation, as a custom one = might + * already have been generated by uftrace_symbols.py + */ return; } =20 @@ -706,6 +710,8 @@ static const char *riscv64_get_privilege_level_name(uin= t8_t pl) case RISCV64_SUPERVISOR: return "Supervisor"; case RISCV64_RESERVED: return "Unknown"; case RISCV64_MACHINE: return "Machine"; + case RISCV64_VUSER: return "VUser"; + case RISCV64_VSUPERVISOR: return "VSupervisor"; default: g_assert_not_reached(); } @@ -986,7 +992,8 @@ QEMU_PLUGIN_EXPORT int qemu_plugin_install(qemu_plugin_= id_t id, =20 score =3D qemu_plugin_scoreboard_new(sizeof(Cpu)); qemu_plugin_register_vcpu_init_cb(id, vcpu_init, NULL); - qemu_plugin_register_atexit_cb(id, at_exit, (void *) info->system_emul= ation); + qemu_plugin_register_atexit_cb(id, at_exit, + (void *) info->system_emulation); qemu_plugin_register_vcpu_tb_trans_cb(id, vcpu_tb_trans, NULL); =20 return 0; --=20 2.47.3 From nobody Sat Jul 25 20:47:29 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=oss.qualcomm.com ARC-Seal: i=1; a=rsa-sha256; t=1783966029; cv=none; d=zohomail.com; s=zohoarc; b=nVN2eJ47QknoU6cywFaOwu4+5RiWt+SN9v+Rr9m0kw+7Xb75hQMbnrArncnGfvoGCrhemPnrJIzy3+F79I/3LBgJuQaLUgu0xz7eAXP1yL/9M/1bLMB8dEHaNDxJ5sSwFyH1/nlOBzdaQqisb3VtIizpk7xtHe85fqbcfRLigmU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783966029; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=AeYNuaxl3yHNN0qU6rIsG/7D7pj6cWSHdttKSmt5/N8=; b=BK/zkPKa+UxlsU+H92R0Ou3BTa7Q3QUpC7NGuBV9vY+KRhfXj+2IWP1xXs5JGllKsuMiQOTJVCLfs+7eKmMCfGFk/PV0+rHF0qbxF/FYhRbIU/y+6JEPgQRC/nax7u7EJa4Lxf0HHamzcUGih3ScaEq/Dbsllq/cuullKDQUzQg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783966029014242.6951995766659; Mon, 13 Jul 2026 11:07:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wjL3M-00037Q-Rg; Mon, 13 Jul 2026 14:06:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjL3K-00036q-Gz for qemu-devel@nongnu.org; Mon, 13 Jul 2026 14:06:50 -0400 Received: from mx0b-0031df01.pphosted.com ([205.220.180.131]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjL3I-0006e2-1a for qemu-devel@nongnu.org; Mon, 13 Jul 2026 14:06:50 -0400 Received: from pps.filterd (m0279868.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66DH6O2H2107720 for ; Mon, 13 Jul 2026 18:06:47 GMT Received: from mail-pf1-f199.google.com (mail-pf1-f199.google.com [209.85.210.199]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fd44j07xg-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Mon, 13 Jul 2026 18:06:46 +0000 (GMT) Received: by mail-pf1-f199.google.com with SMTP id d2e1a72fcca58-84857446424so7049720b3a.1 for ; Mon, 13 Jul 2026 11:06:46 -0700 (PDT) Received: from QCOM-qjMf8PBlDw.qualcomm.com (216-71-219-44.dyn.novuscom.net. [216.71.219.44]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13b8a5992c9sm27501109c88.4.2026.07.13.11.06.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 13 Jul 2026 11:06:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=qcppdkim1; bh=AeYNuaxl3yH NN0qU6rIsG/7D7pj6cWSHdttKSmt5/N8=; b=hrlgOM8fr7RcCy6VuBk3G9GSYZn yf9aeZ/zoR+kIqr0rTNnlQA6TRoa5xDoHT1w/QWb9CHoKrQuX+U6VbDgU6EM4R/f UfHUireTNG7N7X++YI8bHBKLMciQLQ4Xr3v5fhGv93ijrR0CUcj++XTW+WpDAxSc baXuFaohvweWOrBPg5XfDYlQ7FCS9m/EpteHVhBh2qfDYJwCQgAu9QD1+f7F2bxw ApKSWUboOEZ+c7ztL8WBuX0i3LuwExWqoISlvhSky5OLPDT0oWn5ZmOwwSyzQgQy C0OvJL5WVxHFJwh8HB+Uvz8gyZ/g8P5hJwwIt9K3QUHhQUVMxOqBJFEf/pg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1783966006; x=1784570806; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=AeYNuaxl3yHNN0qU6rIsG/7D7pj6cWSHdttKSmt5/N8=; b=CWm+9Bp6X1XT2nWzZi1w1uZ+vKiFHUDgqNoihg+yOklx97gP3m06+DFURKQW83vRM6 NG11LMVOKyUBV5TTHJIXnXmNe3lQKCrmV3zRKVTdLG0q/MXlaks/BzQ7Qg/8GsLyc09e zwqvl5ESNMCSmAdnExR6A+bWphRtc+g3UWK8HnRZ48t4lr3/B8pV+hVt9PtTJpdfgbMC S7T2hERafcp4vHPOZuwwNs5/4OnTTJxywq3+ND7too3gtOGIDbUM4tjDBfnTUHudzeqt nY4SkF5rlueQ9eTeqvouBYrPffopWjIfoQ0R8d5To9I35Yylf8RyDksENL9YWDpJ9vTq metw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783966006; x=1784570806; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=AeYNuaxl3yHNN0qU6rIsG/7D7pj6cWSHdttKSmt5/N8=; b=TGWkBV+6xuSJK65QrnXvxwgvn8At+3efwPBFxyqoUwPmZRU6Zr9nQ9tTLj1bmE6Uj2 JAFL/spYGTAaDp4L5w59gsFBi5zGH2eC8jkgC3118WEqWtzo9Y6OeQXr7vLMxfQ+q/Y9 ZMR00BZ3LlIlWiyhF4XiObHOCOwPN9/Aw2uP2slRwB2/yvVG9g8Qt3fApUp+JRaxm0ts BGpan5ZkxE6PWEC6XG8SK+VkRkaBDYBZj/3rQJBnu4eRWSzZLqGWijIhq1pzevMorTHz vGp72k2nnGIC9FLDKoR8a5d52I/HBiueOezD49O5sXiLTliTLqJHxtFlskHlcQvWpcGO GdUw== X-Gm-Message-State: AOJu0Yz+TgRz60Oh+ELEAVd6DijRVk0c1G9OUiA+9r5U5Wkp5zw+X3dp LZhl7ruQ5ZJG6BYFEvqyHIgTCUGSbTq+Rxr3/6P5uT1Gtu68aLrg1YDV0NRH5F4M53YJEsx5tHz Bql2fKXPE6QmEnZuTDNFBeTeOgKbxrDjmT3KGtNwLf2nU7dsf/TosLtgcYrptZkCDKQ== X-Gm-Gg: AfdE7clikxI4hFlq3rapfzQ9uJTF1wBlascl/EPetO+xF30ZLVhsfr9AYfMY9Dd+yUq tEmHB4l90Zs5lMU063i4JfFC6OO/KXmoIspevGEwUYxi9RBL/LP+s4ikswcmYCt6UQ3z5mV6Gy+ AS492Oz+hVxUNsUJjmbiPewJ84Em0p0NqMBbWrtFjSPVRk0xss32OwbbOpUFYYn4flOiEY/2G2w TN75UEgPVpugKGqUJbLkxUjwSGuaPoUtYypsJVf/jFe6fyWRInOCWRT/Gwapp42u5AnNE1rKE3p iEAJ32E+z0kDKOpHlKYXlZ/oRmCJ3WBhGMQ+sYqUqGQMcNLUIC77pf+U9rrvEAA84e6ihKiAK// hX690VlQ5jsDnsob8RqgSMO0yo3k+c7BcUoVShXR1HYz9mtKFkKa2SIUQfHMwHTH6Owc9MgXcDk Kqr7q9aw== X-Received: by 2002:a05:6300:2204:b0:3c0:9c19:65b0 with SMTP id adf61e73a8af0-3c110a57dcfmr11300373637.72.1783966005788; Mon, 13 Jul 2026 11:06:45 -0700 (PDT) X-Received: by 2002:a05:6300:2204:b0:3c0:9c19:65b0 with SMTP id adf61e73a8af0-3c110a57dcfmr11300334637.72.1783966005261; Mon, 13 Jul 2026 11:06:45 -0700 (PDT) From: Pierrick Bouvier To: qemu-devel@nongnu.org, peter.maydell@linaro.org, richard.henderson@linaro.org, pbonzini@redhat.com, stefanha@redhat.com Cc: pierrick.bouvier@oss.qualcomm.com Subject: [PULL 2/3] contrib/plugins: add a minimal dlcall plugin Date: Mon, 13 Jul 2026 11:06:37 -0700 Message-ID: <20260713180638.2228609-3-pierrick.bouvier@oss.qualcomm.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260713180638.2228609-1-pierrick.bouvier@oss.qualcomm.com> References: <20260713180638.2228609-1-pierrick.bouvier@oss.qualcomm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Proofpoint-Spam-Info: AW1haW4tMjYwNzEzMDE4NyBTYWx0ZWRfX4kNKrq/R6KAu cMuoCDtSeUf5273Ki4fy0pDl5X27VQeTOi1Z3hVAPmb8oroIXRsxzVydIZcrQeSu6hE739wE228 htVhBej8lDCNHf4VbKZul2Rx+3S5a7s= X-Authority-Analysis: v=2.4 cv=N4UZ0W9B c=1 sm=1 tr=0 ts=6a552936 cx=c_pps a=WW5sKcV1LcKqjgzy2JUPuA==:117 a=iLqgmErQAxjCjdq5jj1Aqg==:17 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=ZpdpYltYx_vBUK5n70dp:22 a=VwQbUJbxAAAA:8 a=NEAV23lmAAAA:8 a=Lx1EvxgrAAAA:8 a=EUspDBNiAAAA:8 a=TBq7--GwHvIaXDVWMgMA:9 a=OpyuDcXvxspvyRM73sMx:22 a=ZFi1QaP_tuf8dODdgmj-:22 X-Proofpoint-GUID: gSWT0NcL9rb-p5W0NZjfAHDJJIlwU-5a X-Proofpoint-ORIG-GUID: gSWT0NcL9rb-p5W0NZjfAHDJJIlwU-5a X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzEzMDE4NyBTYWx0ZWRfXwGAkViTbkbFF dwRZg8X6vPE+1U6BkENTnzP4ZqYoyDibvLYH/REY90slIX5pedEm+YBVnmUxs88xMun/0YY0u+r sLlimJXkPYWqR9Y4b2zMNtY56r98pOQqmUniI+hZru/v+BQbkMl9UAXhRevSMQJ4HH/QQIOdg41 5Xwq9rJLPlZzZIhY/RzWE2BYhgQMw8ZNQxAbdWMsAo32iKQ9uzqb5M+QpFOi+bDnN5o4LW1XrN3 8Dkq8orGGLMfXeIvfOmfdV1Oxcs5KC4W9bZtL8B/C+PBdhQcwMxA5scAcErf/lVpi5hpOaUdsOY I9ILgWGKj4CbcmK1wMw3ATOf7Hy9gOHUkSzywnFph/GsniVqUX4Auf1E33YoevD9N1/kTfOI9AA 5/hImPw0l3eUd5NTOLJPTXcSSLHbFdZB9xUUSonsCTuBRyEIDshMoFBiXZ14woQBneJ7wgtW1nd AquYUy1hiHetKAc2xpA== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-13_04,2026-07-10_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 spamscore=0 phishscore=0 priorityscore=1501 suspectscore=0 bulkscore=0 malwarescore=0 adultscore=0 lowpriorityscore=0 impostorscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607130187 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=205.220.180.131; envelope-from=pierrick.bouvier@oss.qualcomm.com; helo=mx0b-0031df01.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @qualcomm.com) X-ZM-MESSAGEID: 1783966032382158500 Content-Type: text/plain; charset="utf-8" From: Ziyang Zhang Add a minimal dlcall plugin that lets the guest invoke host functions through magic system calls. The plugin registers a vCPU syscall filter callback that intercepts a reserved syscall number and dispatches a set of pass-through operations: querying host attributes, loading and freeing shared libraries, resolving symbols, retrieving the last library error, and invoking a host function through a common interface. The magic syscall number defaults to 4096 and can be overridden at load time with the "syscall_num=3DN" argument; values low enough to clash with a real syscall are rejected. Co-authored-by: Kailiang Xu Co-authored-by: Mingyuan Xia Signed-off-by: Ziyang Zhang Reviewed-by: Pierrick Bouvier Link: https://lore.kernel.org/qemu-devel/20260711094523.622997-2-functioner= @sjtu.edu.cn Signed-off-by: Pierrick Bouvier --- contrib/plugins/dlcall.c | 248 ++++++++++++++++++++++++++++++++++++ contrib/plugins/meson.build | 5 + 2 files changed, 253 insertions(+) create mode 100644 contrib/plugins/dlcall.c diff --git a/contrib/plugins/dlcall.c b/contrib/plugins/dlcall.c new file mode 100644 index 00000000000..9d2230b2d1a --- /dev/null +++ b/contrib/plugins/dlcall.c @@ -0,0 +1,248 @@ +/* + * Copyright (C) 2026, Ziyang Zhang + * + * dlcall (Dynamic Linking Call) plugin: lets a linux-user guest invoke ho= st + * functions by issuing a magic system call. The guest can ask QEMU to dlo= pen() + * a host shared library, dlsym() a symbol, and call it with guest-supplied + * arguments. + * + * The plugin intentionally keeps the QEMU side lightweight and prescribes + * nothing about how a library is thunked. Any toolchain can implement the + * userspace side. Lorelei is one end-to-end implementation (guest/host + * runtimes plus a thunk compiler that generates thunks from a library's + * headers): + * https://github.com/rover2024/lorelei + * + * See docs/about/emulation.rst|Dynamic Linking Call for details and examp= les. + * + * WARNING: trusted guests only. The guest can load arbitrary host librari= es + * and execute arbitrary host code with arbitrary arguments, i.e. full code + * execution in the QEMU host process. It is NOT a sandbox and provides no + * isolation; only load it for guests you fully trust. + * + * WARNING: requires guest_base =3D=3D 0, which is qemu-user's default. Po= inter + * operands are dereferenced as host addresses directly, and the invoked h= ost + * functions dereference guest pointers with no address translation, so gu= est + * and host must share a single address space. A non-zero guest_base (e.g.= set + * via -B/-R) would make every pointer off by guest_base and hit unrelated + * host memory. + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#include +#include +#include +#include +#include +#include + +#include + +QEMU_PLUGIN_EXPORT int qemu_plugin_version =3D QEMU_PLUGIN_VERSION; + +/* + * The magic system call number for dlcall. + * + * It defaults to DLCALL_SYSCALL_DEFAULT and can be overridden at load time + * with the "syscall_num=3DN" argument. To avoid hijacking a real syscall = the + * guest might issue, N must be at least DLCALL_SYSCALL_MIN: every Linux A= BI + * keeps its syscall numbers well below this; numbers from here up are fre= e. + */ +enum { + DLCALL_SYSCALL_DEFAULT =3D 4096, + DLCALL_SYSCALL_MIN =3D 4096, +}; + +static int64_t dlcall_syscall_num =3D DLCALL_SYSCALL_DEFAULT; + +/* + * dlcall calling convention. + * + * The guest issues the magic system call (dlcall_syscall_num). The first + * argument (a1) is one of the call IDs below; the remaining arguments (a2= , a3, + * a4, ...) are that ID's operands. All pointer operands are guest virtual + * addresses that the plugin dereferences as host addresses directly (see = the + * guest_base requirement above). Results are written back through + * caller-provided "out" pointers rather than returned in the syscall valu= e. + * + * The syscall return value (*sysret) only reports dispatch status: 0 on a + * recognised ID, -EINVAL for an unknown one. The actual success/failure o= f an + * operation (e.g. a NULL handle from dlopen) is delivered through its out + * pointer, exactly like the underlying libdl call. + * + * Operands per ID: + * + * DLCALL_ID_GET_HOST_ATTRIBUTE + * a2 const char *key in: attribute name to query + * a3 const char **attr_ptr out: matching value, or NULL if unknown + * + * DLCALL_ID_LOAD_LIBRARY (wraps dlopen) + * a2 const char *path in: library path + * a3 int flags in: dlopen() flags (e.g. RTLD_NOW) + * a4 void **handle_ptr out: library handle, or NULL on failure + * + * DLCALL_ID_GET_PROC_ADDRESS (wraps dlsym) + * a2 void *handle in: library handle + * a3 const char *name in: symbol name + * a4 void **entry_ptr out: symbol address, or NULL if not found + * + * DLCALL_ID_FREE_LIBRARY (wraps dlclose) + * a2 void *handle in: library handle + * a3 int *ret_ptr out: dlclose() return value (0 on succes= s) + * + * DLCALL_ID_GET_LIBRARY_ERROR (wraps dlerror) + * a2 const char **error_ptr out: last libdl error string, or NULL + * + * DLCALL_ID_INVOKE_PROC (calls the symbol) + * a2 void *proc in: function pointer, signature + * void (*)(void *arg1, void *arg2) + * a3 void *arg1 in: first argument forwarded to proc + * a4 void *arg2 in: second argument forwarded to proc + */ +enum DlcallID { + DLCALL_ID_GET_HOST_ATTRIBUTE, + DLCALL_ID_LOAD_LIBRARY, + DLCALL_ID_GET_PROC_ADDRESS, + DLCALL_ID_FREE_LIBRARY, + DLCALL_ID_GET_LIBRARY_ERROR, + DLCALL_ID_INVOKE_PROC, +}; + +static inline const char *query_host_attribute(const char *key) +{ + if (strcmp(key, "emu") =3D=3D 0) { + return "qemu"; + } + return NULL; +} + +static inline void invoke_proc(void *proc, void *arg1, void *arg2) +{ + typedef void (*Func)(void * /*arg1*/, void * /*arg2*/); + Func func =3D (Func) proc; + func(arg1, arg2); +} + +static bool vcpu_syscall_filter(unsigned int vcpu_index, + int64_t num, uint64_t a1, uint64_t a2, + uint64_t a3, uint64_t a4, uint64_t a5, + uint64_t a6, uint64_t a7, uint64_t a8, + int64_t *sysret, void *userdata) +{ + if (num =3D=3D dlcall_syscall_num) { + switch (a1) { + /* Query host attribute by a reserved key. */ + case DLCALL_ID_GET_HOST_ATTRIBUTE: { + const char *key =3D (const char *) a2; + const char **attr_ptr =3D (const char **) a3; + assert(attr_ptr); + *attr_ptr =3D query_host_attribute(key); + *sysret =3D 0; + break; + } + + /* Load a shared library. */ + case DLCALL_ID_LOAD_LIBRARY: { + const char *path =3D (const char *) a2; + int flags =3D (int) a3; + void **handle_ptr =3D (void **) a4; + assert(handle_ptr); + *handle_ptr =3D dlopen(path, flags); + *sysret =3D 0; + break; + } + + /* Get the address of a function in a shared library. */ + case DLCALL_ID_GET_PROC_ADDRESS: { + void *handle =3D (void *) a2; + const char *name =3D (const char *) a3; + void **entry_ptr =3D (void **) a4; + assert(entry_ptr); + *entry_ptr =3D dlsym(handle, name); + *sysret =3D 0; + break; + } + + /* Free a shared library. */ + case DLCALL_ID_FREE_LIBRARY: { + void *handle =3D (void *) a2; + int *ret_ptr =3D (int *) a3; + *ret_ptr =3D dlclose(handle); + *sysret =3D 0; + break; + } + + /* Get the last error message for a library event. */ + case DLCALL_ID_GET_LIBRARY_ERROR: { + const char **error_ptr =3D (const char **) a2; + *error_ptr =3D dlerror(); + *sysret =3D 0; + break; + } + + /* Invoke a function of a common interface. */ + case DLCALL_ID_INVOKE_PROC: { + void *proc =3D (void *) a2; + void *arg1 =3D (void *) a3; + void *arg2 =3D (void *) a4; + assert(proc); + invoke_proc(proc, arg1, arg2); + *sysret =3D 0; + break; + } + + default: + *sysret =3D -EINVAL; + break; + } + return true; + } + return false; +} + +QEMU_PLUGIN_EXPORT int qemu_plugin_install(qemu_plugin_id_t id, + const qemu_info_t *info, + int argc, char **argv) +{ + if (info->system_emulation) { + fprintf(stderr, "plugin dlcall: only useful for user emulation\n"); + return -1; + } + + for (int i =3D 0; i < argc; i++) { + char *opt =3D argv[i]; + g_auto(GStrv) tokens =3D g_strsplit(opt, "=3D", 2); + if (g_strcmp0(tokens[0], "syscall_num") =3D=3D 0) { + const char *val =3D tokens[1]; + char *endptr =3D NULL; + guint64 num; + if (!val || *val =3D=3D '\0') { + fprintf(stderr, + "plugin dlcall: missing value for syscall_num\n"); + return -1; + } + num =3D g_ascii_strtoull(val, &endptr, 0); + if (*endptr !=3D '\0' || g_strrstr(val, "-") !=3D NULL) { + fprintf(stderr, + "plugin dlcall: invalid syscall_num '%s'\n", val); + return -1; + } + if (num < DLCALL_SYSCALL_MIN || num > G_MAXINT64) { + fprintf(stderr, + "plugin dlcall: syscall_num %s is out of range; " + "it must be >=3D %d to avoid clashing with a real " + "syscall\n", val, DLCALL_SYSCALL_MIN); + return -1; + } + dlcall_syscall_num =3D (int64_t) num; + } else { + fprintf(stderr, "plugin dlcall: unknown option '%s'\n", opt); + return -1; + } + } + + qemu_plugin_register_vcpu_syscall_filter_cb(id, vcpu_syscall_filter, N= ULL); + + return 0; +} diff --git a/contrib/plugins/meson.build b/contrib/plugins/meson.build index 099319e7a17..e7fc4d6d8f5 100644 --- a/contrib/plugins/meson.build +++ b/contrib/plugins/meson.build @@ -19,6 +19,11 @@ if host_os !=3D 'windows' contrib_plugins +=3D 'lockstep.c' endif =20 +if host_os =3D=3D 'linux' + # dlcall passes guest calls through to host libraries; linux-user only + contrib_plugins +=3D 'dlcall.c' +endif + if 'cpp' in all_languages contrib_plugins +=3D 'cpp.cpp' endif --=20 2.47.3 From nobody Sat Jul 25 20:47:29 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=oss.qualcomm.com ARC-Seal: i=1; a=rsa-sha256; t=1783966043; cv=none; d=zohomail.com; s=zohoarc; b=irUPJCySCPN4LQHWOdhU3C7JYTll9usOFVQX6mS1XXNYKN7NWp8zalOJ8EudMMZcRX8B16Kb8Sd6Qu81vo8FeGdmxPjLVGHnU4WiNnEx1JE7V3GVuMO+ickVHTiqfvTAMvrCXqanmglSRqaDdxXRjJvRBxRPXFGzV2XoXJbV8go= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783966043; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Bqk8mP195HNkw6fg3JtNDjDDd6rttLWS2pjOqiBhIvE=; b=lmM4cbQQBI52nxuORX1NTscWxTLIE0ykiHQUwASY9eMJdhqb9QvW4JrBdqTY9iN2lQ44i0AXKHNx5nURmiv+t5L6W9BwLlguGHKmarOec3GJnhpnYrJ3noxpKQhqWHIrwzPC5bCWtd4dzrFdvvLarsWXIsJ3odY9x6v5JWPp1vY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783966043729958.1487195108907; Mon, 13 Jul 2026 11:07:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wjL3O-00037d-GJ; Mon, 13 Jul 2026 14:06:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjL3M-00037P-Nz for qemu-devel@nongnu.org; Mon, 13 Jul 2026 14:06:52 -0400 Received: from mx0a-0031df01.pphosted.com ([205.220.168.131]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjL3K-0006eI-D8 for qemu-devel@nongnu.org; Mon, 13 Jul 2026 14:06:52 -0400 Received: from pps.filterd (m0279864.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66DF8DcG1611656 for ; Mon, 13 Jul 2026 18:06:48 GMT Received: from mail-pg1-f198.google.com (mail-pg1-f198.google.com [209.85.215.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fcw4qt52p-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Mon, 13 Jul 2026 18:06:48 +0000 (GMT) Received: by mail-pg1-f198.google.com with SMTP id 41be03b00d2f7-c890bac374eso8777034a12.1 for ; Mon, 13 Jul 2026 11:06:48 -0700 (PDT) Received: from QCOM-qjMf8PBlDw.qualcomm.com (216-71-219-44.dyn.novuscom.net. [216.71.219.44]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13b8a5992c9sm27501109c88.4.2026.07.13.11.06.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 13 Jul 2026 11:06:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=qcppdkim1; bh=Bqk8mP195HN kw6fg3JtNDjDDd6rttLWS2pjOqiBhIvE=; b=Ubb8iGlI/6byd8zhl2V/Y1EHrTx kTgap8b6b2nLA+pW0ddy1uT06vIEr4MlbeUGzq1f7AzjkNDHsYv2D/LkncT5gJM7 7mas0EhsqK0AZjocm9ldMEGPId7yO7Dly+/bhwoo8afyR6/6wa4K4GTg9XK4Kifw EfNtWi1HzzZISdjPD8O/2A0yJZAOS96YkrIw50ySFU/ngXCkNAOLQ9ezkL+ZhEzq 0hlKVg3Cs5qAyFHsGn5tj4XpnHBpIi5Y4KdyVk9SZ4R92DVsBJmjeOJKowd6tKJy wQwveD47Oh+jfw6zlQoTs7hJv71aiYiWc7AaXTKsuNZD2wpUhHsnNwvwdtQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1783966008; x=1784570808; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Bqk8mP195HNkw6fg3JtNDjDDd6rttLWS2pjOqiBhIvE=; b=e5S0IFQ2KVIs97LGCfYVwjq/6wLM6j+tqjK9dNBEyhABoLE4eJuP1DSwFUcBQtwmlb AO+qqWEDfvFsItmmbM9u1JcFxjSXf4SHAUoVY6EqYbO6wK3nXSPstUrveW1DDYnkP671 pJfZJAY/fauKYV1/vJmP4mXhCmX9sKoVl79nghDP5SPVP1HXpIw25yaAezhny8LCTMRl x66yKPkoUzArwUvaoQJiRr7ou8mfWF7tHnbpEUwLQz6n5ShzxgaPGsYhJQ13C58hAqcB njQxVrEozQDDW6nHldq2oLGIBhjMrQPhA3llP+7tcJi7Udfv8ar2xpvMM+YBFoA9YwZ2 yc1A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783966008; x=1784570808; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Bqk8mP195HNkw6fg3JtNDjDDd6rttLWS2pjOqiBhIvE=; b=HLPNf4JnD52fVl+7zfpxzRuK/nt4UiXWSHGeaecvYwRQ3kxiArBcFmrKE+PVFbTNKD EqHlYifYGJFDo9SnHRlA6cRQWsfPQ1mps7e+Gk5OZ81nPEPkhcnDKOqYPE3ztuyWhK2J PnvwsKJAVgYqH0UZtwad0/mbIjjGu3YISp/OPctlOI2wI6Hst1U1n0HW6MtNDmKizlEH zjQ90NIxEM/NIppP78s7k35XBZwZWd+aU4JeMjiCrkxR/ar4MkZQPayXoFWHQ14O16yG Py9i2dQAc+UAhFk9bd4u8jcUAPT8l7Xg5k24QHLY+0ivxWHAJndqeEe2hBCl68jai6Q3 A4+w== X-Gm-Message-State: AOJu0YzhKHKJvafX++qdEWTuyTT2vmbhYp6MVYaSsJvflEHZtuZUd13E l8TBEKb/jOkg36n6Dq7/rEN2DErk/p5C16JE/DB8Z1JCo/HO+fD/YzIWeFfcr6hIWlbGN5euT4o 2Xf+aEPX4YgfisK2aKnc1g/KOLIpFkvQVTeLNcyWsdTm8Vs1McON8BVcyjbsPaYUs7g== X-Gm-Gg: AfdE7ckiLbfdjbgRtFxjQImGtmrIndYp/TAOLuO9hkoA6touU4oQI2elpLdJcYwWbyM dHCL3laqxSkpDy3ED3I8oSxcB8c7qtJAnKLgOLffY39Ehe3B0GvcSmEYk9OzahnRvswixioTtgL DkwgJnBJPvAbt/SDenrq1ymXgPUvJzYSoGwRI/d3L1wys8Z0fw3BTSDf23LYCMxZPkGjKlXL6e2 QJNrxu79Qv3QDro0Aou+XGuT2KETEagbDtecjf/0jcSlIYshPD4tqQAIEjFPu+v1bNvoxLOa1LX 3wr1DexNQcz7dI0v7gPh6rQxhtyvy5Ztgdcgt2MDy9/okr8Vxgr1yb8gpY7C94M8/f+X5ZdAG8Q BV412WlT5sTpw6PKl7ZWHlcwlbOhswnvo00M6kdm32Tv9ARFkqH+v+GVFKjCWVokHIq70Ubxqpf ug3q18Fw== X-Received: by 2002:a05:6a21:46c5:b0:3bf:b40b:def2 with SMTP id adf61e73a8af0-3c11003092dmr10350031637.9.1783966007459; Mon, 13 Jul 2026 11:06:47 -0700 (PDT) X-Received: by 2002:a05:6a21:46c5:b0:3bf:b40b:def2 with SMTP id adf61e73a8af0-3c11003092dmr10350003637.9.1783966006934; Mon, 13 Jul 2026 11:06:46 -0700 (PDT) From: Pierrick Bouvier To: qemu-devel@nongnu.org, peter.maydell@linaro.org, richard.henderson@linaro.org, pbonzini@redhat.com, stefanha@redhat.com Cc: pierrick.bouvier@oss.qualcomm.com Subject: [PULL 3/3] docs/about/emulation: document the dlcall plugin Date: Mon, 13 Jul 2026 11:06:38 -0700 Message-ID: <20260713180638.2228609-4-pierrick.bouvier@oss.qualcomm.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260713180638.2228609-1-pierrick.bouvier@oss.qualcomm.com> References: <20260713180638.2228609-1-pierrick.bouvier@oss.qualcomm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzEzMDE4NyBTYWx0ZWRfX4TzqEQcaWczN OsxRYUHxOSJA11DLMRv7XBrOfWYfqKpuZcpy0iG+S/gg+GxbSS6jX9U8JU3NBZlUoyJYCBK247P YAlunByHNgr/bQvJlMJ6NFvecsljHqf5Dv+T8znF2Gkf/W3OZjj2w/pnhkpekVpBJVrWOELDxCk cfEn5xxpFrwnwEbUX4xBnIg6XgiQJC9leBln9OpCIljWPfZYj6dnxuVJXeMjZQCL4bGWmVp9jvY 8iWW6wL3y1NPLXYw67PJoAV6rvrhCnc9rzrowalxF4rXDzkEbD0sAUcXaUtDnDN2gNTgYaIVy8C Y7/wyVV0XfKwgCyHuFVicnBF31XWF/X0H24Iq0t9kG33AgiSWiIfHJ7truLoQVK7JXR4HU9FseN 4pog/QMiwFlYicXOZqkP35O7SU3qaotHla2/umz2+t27lUv8AYJPpd4DUvbnUJhMgHmwGQLg3f1 w5tIK/YO/uaQmh+CU5Q== X-Authority-Analysis: v=2.4 cv=HJrz0Itv c=1 sm=1 tr=0 ts=6a552938 cx=c_pps a=Qgeoaf8Lrialg5Z894R3/Q==:117 a=iLqgmErQAxjCjdq5jj1Aqg==:17 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=DJpcGTmdVt4CTyJn9g5Z:22 a=VwQbUJbxAAAA:8 a=NEAV23lmAAAA:8 a=jQIij1hyAAAA:20 a=Lx1EvxgrAAAA:8 a=EUspDBNiAAAA:8 a=jqyheP39vwLst_Jpb7sA:9 a=x9snwWr2DeNwDh03kgHS:22 a=ZFi1QaP_tuf8dODdgmj-:22 a=bA3UWDv6hWIuX7UZL3qL:22 X-Proofpoint-GUID: 2BeIc5CpQLOrP-EDCdWtsocuZ6U6ddLS X-Proofpoint-Spam-Info: AW1haW4tMjYwNzEzMDE4NyBTYWx0ZWRfXyYxA3h5l+bHh shwzhdmoS97HAdq5ChBt+WZUjtJyF0qaotKvmVaDGAz53syhhdX0iIgY5vGaZL2k8funZq6Or0U mYY9L87UVsPSKdnzhldjrykXiUDOozg= X-Proofpoint-ORIG-GUID: 2BeIc5CpQLOrP-EDCdWtsocuZ6U6ddLS X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-13_04,2026-07-10_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 impostorscore=0 lowpriorityscore=0 phishscore=0 adultscore=0 clxscore=1015 malwarescore=0 priorityscore=1501 suspectscore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607130187 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=205.220.168.131; envelope-from=pierrick.bouvier@oss.qualcomm.com; helo=mx0a-0031df01.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @qualcomm.com) X-ZM-MESSAGEID: 1783966045402158500 Content-Type: text/plain; charset="utf-8" From: Ziyang Zhang Document the dlcall plugin under Example Plugins: what it does, the trusted- guests and guest_base =3D=3D 0 constraints, how to load it, and a pointer to Lorelei, one end-to-end userspace implementation, for the toolchain and a runnable example. Co-authored-by: Kailiang Xu Co-authored-by: Mingyuan Xia Signed-off-by: Ziyang Zhang Reviewed-by: Pierrick Bouvier Link: https://lore.kernel.org/qemu-devel/20260711094523.622997-3-functioner= @sjtu.edu.cn Signed-off-by: Pierrick Bouvier --- docs/about/emulation.rst | 158 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 158 insertions(+) diff --git a/docs/about/emulation.rst b/docs/about/emulation.rst index 3b4c365933d..b861501e85e 100644 --- a/docs/about/emulation.rst +++ b/docs/about/emulation.rst @@ -1046,6 +1046,164 @@ Count traps This plugin counts the number of interrupts (asynchronous events), excepti= ons (synchronous events) and host calls (e.g. semihosting) per cpu. =20 +Dynamic Linking Call +.................... + +``contrib/plugins/dlcall.c`` + +This plugin provides a dynamic linking function call interception mechanism +for linux-user guests: the guest hands a call off to the host, where the p= lugin +runs native code in its place instead of the guest emulating it. Intercept= ion +alone enables several uses, for instance tracing or auditing guest calls. +One use is acceleration by leveraging the host's native shared libraries. = For +example, a thunk layer can run the stock zlib ``minizip`` utility under +emulation while forwarding its ``deflate`` calls to the host's native zlib +library (libz). This avoids emulating those selected library calls instruc= tion +by instruction. + +The guest issues a reserved "magic" system call (4096 by default, configur= able +with ``syscall_num=3DN``) whose first argument selects a pass-through oper= ation: +dlopen/dlclose a host library, dlsym a symbol, and invoke a resolved host +function. The plugin performs the operation on the host and consumes the +syscall, so the real kernel never sees it. + +.. warning:: + + Trusted guests only. The guest can load arbitrary host libraries and run + arbitrary code in the QEMU host process. The plugin is not a sandbox and + provides no isolation. It also requires ``guest_base =3D=3D 0`` (qemu-u= ser's + default), as guest pointers are dereferenced as host addresses with no + translation. + +The plugin intentionally keeps the QEMU side lightweight and knows nothing +about any particular library or its calling convention. Turning a real lib= rary +into working thunks, including argument marshalling, callbacks and variadic +functions, is done entirely in userspace, and any toolchain can implement = the +interface. + +Loading the plugin is all that is required from QEMU's side: + +.. code-block:: shell + + qemu-x86_64 -plugin contrib/plugins/libdlcall.so ... + +`Lorelei `_ is one end-to-end usersp= ace +implementation of this: it provides the guest and host runtimes and an +automated toolchain that generates the thunks from a library's headers, so= guest +library calls run on the host's native libraries. It supports an x86_64 gu= est +running on an x86_64, aarch64 or riscv64 host. + +A minimal end-to-end example uses a one-function library, ``libhello.so``,= built +two ways: the guest build tags its output ``(from the guest)`` and the host +build ``(from the host)``. An unmodified guest program ``main`` calls +``hello("World", 7)``, and the thunk makes that same binary reach the host= build +in place of its own. The sources live under ``src/``: + +.. code-block:: c + + /* src/hello.h */ + void hello(const char *name, int lucky); + +.. code-block:: c + + /* src/hello_guest.c */ + #include "hello.h" + #include + + void hello(const char *name, int lucky) + { + printf("Hello, %s! Your lucky number is %d. (from the guest)\n", na= me, lucky); + } + +.. code-block:: c + + /* src/hello_host.c */ + #include "hello.h" + #include + + void hello(const char *name, int lucky) + { + printf("Hello, %s! Your lucky number is %d. (from the host)\n", nam= e, lucky); + } + +.. code-block:: c + + /* src/main.c */ + #include "hello.h" + + int main(void) + { + hello("World", 7); + return 0; + } + +Lorelei ships a prebuilt toolchain (a "devkit") in its releases. Download = the +one for your host and unpack it: + +.. code-block:: shell + + # ARCH is your host's architecture: x86_64, aarch64 or riscv64. This ex= ample uses aarch64. + # See https://github.com/rover2024/lorelei/releases + ARCH=3Daarch64 + VERSION=3D$(curl -fsSL -o /dev/null -w '%{url_effective}' \ + https://github.com/rover2024/lorelei/releases/latest | sed 's|.*/= tag/v||') + wget "https://github.com/rover2024/lorelei/releases/download/v$VERSION/= lorelei-devkit-$ARCH-$VERSION.tar.xz" + tar -xf lorelei-devkit-$ARCH-$VERSION.tar.xz + DEVKIT=3Dlorelei-devkit-$ARCH + +Build the guest ``libhello.so`` (x86_64) and the host ``libhello.so`` (this +host's architecture), then the guest program: + +.. code-block:: shell + + mkdir -p build/guest build/host + $DEVKIT/bin/x86_64-linux-gnu-clang -shared -fPIC src/hello_guest.c -o b= uild/guest/libhello.so + cc -shared -fPIC src/hello_host.c -o build/host/libhello.so + $DEVKIT/bin/x86_64-linux-gnu-clang src/main.c -Isrc -Lbuild/guest -lhel= lo -o build/guest/main + +Run it under qemu: + +.. code-block:: shell + + qemu-x86_64 -L /usr/x86_64-linux-gnu/ -E LD_LIBRARY_PATH=3Dbuild/guest = build/guest/main + +which prints:: + + Hello, World! Your lucky number is 7. (from the guest) + +Now generate the thunk from the host ``libhello.so``. This produces a gues= t-side +``libhello.so`` that stands in for the guest build, and a host-side thunk = library +that dispatches to the host build: + +.. code-block:: shell + + $DEVKIT/bin/LoreMakeThunk.py --name hello --lib build/host/libhello.so \ + --header hello.h -o thunks -- -Isrc + +Run the same ``main`` under the plugin. The call reaches the host build no= w: + +.. code-block:: shell + + LD_LIBRARY_PATH=3D$DEVKIT/lib:build/host \ + qemu-x86_64 -plugin contrib/plugins/libdlcall.so \ + -E LD_LIBRARY_PATH=3D$DEVKIT/x86_64/lib:thunks/x86_64 \ + -L /usr/x86_64-linux-gnu/ \ + build/guest/main + +which prints:: + + Hello, World! Your lucky number is 7. (from the host) + +.. list-table:: Dynamic Linking Call arguments + :widths: 20 80 + :header-rows: 1 + + * - Option + - Description + * - syscall_num=3DN + - The magic syscall number the guest issues (default 4096). Must be hi= gh + enough not to clash with a real syscall. + Other emulation features ------------------------ =20 --=20 2.47.3