From nobody Sat Jul 25 12:45:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=sjtu.edu.cn ARC-Seal: i=1; a=rsa-sha256; t=1784447374; cv=none; d=zohomail.com; s=zohoarc; b=G5yGgBsYzz3vDxjVUjmh1NW9wnBpVVgh0w3MS3uELUXewiles7GnVdlU4SY0oZqA29kbJqiVXJf8ZiPv6hbtcQujeb1/Pk6gi02TQtyYFHoJQ77atX06UFF5U1hIVmvF3eQICAlh2Nz7YCfwyDY4/IfI+fK4Xs6VzN+BNyZE9A4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784447374; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=5wsswar2A9TLlHNtOLkptRCYr4PuBEoAHkpZQwSOAQk=; b=VNIto3oqhVqDNSB5s3NihiIZDnk7vHga/UtgDt3ELYx41DU4kiaUJggj3iSiflDfguq/6qE89hlw6R546KWgXcKsIt08+VFrB6/xI4el/REaivU2VmEBG1D1BXMLz/a9tzYBkT480s1QyF6qmQYCQeLiQX09Dpu5ObLozKxz4Is= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784447373628578.0455061089853; Sun, 19 Jul 2026 00:49:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wlMGL-0007Vb-33; Sun, 19 Jul 2026 03:48:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wlMGI-0007Tu-Fb for qemu-devel@nongnu.org; Sun, 19 Jul 2026 03:48:34 -0400 Received: from smtp186.sjtu.edu.cn ([202.120.2.186]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wlMGE-00054V-7n for qemu-devel@nongnu.org; Sun, 19 Jul 2026 03:48:33 -0400 Received: from proxy188.sjtu.edu.cn (smtp188.sjtu.edu.cn [202.120.2.188]) by smtp186.sjtu.edu.cn (Postfix) with ESMTPS id 89DF62FF409; Sun, 19 Jul 2026 07:48:03 +0000 (UTC) Received: from pc.. (unknown [202.120.40.100]) by proxy188.sjtu.edu.cn (Postfix) with ESMTPSA id E33FC37C925; Sun, 19 Jul 2026 15:47:32 +0800 (CST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=sjtu.edu.cn; s=default; t=1784447283; bh=p5117I2X0BDpEQLindw53jpxrdPty0kND9gp4KaUWXI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=M8jtb1Z4XNM1jQAPmGcuv6zyXpmHsegA5bo7mLIFZE3ekIpgu28KmA72sXqVV5oEE wYtI3ftIdbP+YxaA1z6an+/33qcNAXWTI5E+xpKHhNJx3FsdAR/BGjEuy1sg0ddjfU 2/wx7ZUkb5Vj83a3BRJxGz2d2RieIxFDoGTTpRl1R/EsXCTqphKPjYqSxODSgaPJ55 +8Vj/S6JsW2q/hSQCO+E4iY/Ez7UjPr89gs6sZMm8bW2s+V4PvKop3LZ4RyXjIvLrE 6UbTEgkPjPSHj8WpJSAb8gcnWp4NGDOFAdLLunG8WFfX2wCsx/V13Ra+VPuUHik9ZR xs8/7O6ujcf/w== From: Ziyang Zhang To: qemu-devel Cc: Riku Voipio , Laurent Vivier , Alex Bennee , Alexandre Iooss , Mahmoud Mandour , Pierrick Bouvier , Florian Hofhammer , Richard Henderson , Zhengwei Qi , Yun Wang , Mingyuan Xia , Kailiang Xu , Ziyang Zhang Subject: [PATCH 1/3] contrib/plugins/dlcall: correct the syscall number claim, note the data model Date: Sun, 19 Jul 2026 15:47:28 +0800 Message-Id: <20260719074730.1520517-2-functioner@sjtu.edu.cn> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260719074730.1520517-1-functioner@sjtu.edu.cn> References: <20260719074730.1520517-1-functioner@sjtu.edu.cn> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=202.120.2.186; envelope-from=functioner@sjtu.edu.cn; helo=smtp186.sjtu.edu.cn X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @sjtu.edu.cn) X-ZM-MESSAGEID: 1784447376658158500 Content-Type: text/plain; charset="utf-8" The comment claimed every Linux ABI keeps its syscall numbers well below the minimum, and that the minimum is all N has to satisfy. Neither holds. MIPS O32 bases its numbering at 4000, so the default 4096 is its getpriorit= y. Raising N does not rescue it either, because O32 answers numbers its table = does not define with ENOSYS before the filter runs, which leaves no number that = is both free and reachable on that ABI. arm32 bounds N from above too, with EN= OSYS or SIGILL past ARM_NR_BASE. Say all of this, so the number can be chosen wi= th the target in mind. guest_base =3D=3D 0 is not the only requirement either. Host pointers are w= ritten back through the caller's out pointers, so the guest must match the host's pointer width and endianness. Fold that into the existing warning. Also assert the two out pointers that lacked it, and point at Lorelei for argument marshalling, callbacks and variadic functions. Co-authored-by: Kailiang Xu Co-authored-by: Mingyuan Xia Signed-off-by: Ziyang Zhang Reviewed-by: Pierrick Bouvier --- contrib/plugins/dlcall.c | 32 +++++++++++++++++++++++--------- 1 file changed, 23 insertions(+), 9 deletions(-) diff --git a/contrib/plugins/dlcall.c b/contrib/plugins/dlcall.c index 9d2230b2d1..b624735e62 100644 --- a/contrib/plugins/dlcall.c +++ b/contrib/plugins/dlcall.c @@ -10,7 +10,8 @@ * nothing about how a library is thunked. Any toolchain can implement the * userspace side. Lorelei is one end-to-end implementation (guest/host * runtimes plus a thunk compiler that generates thunks from a library's - * headers): + * headers), and how it handles argument marshalling, callbacks and variad= ic + * functions can serve as a reference: * https://github.com/rover2024/lorelei * * See docs/about/emulation.rst|Dynamic Linking Call for details and examp= les. @@ -20,12 +21,13 @@ * execution in the QEMU host process. It is NOT a sandbox and provides no * isolation; only load it for guests you fully trust. * - * WARNING: requires guest_base =3D=3D 0, which is qemu-user's default. Po= inter - * operands are dereferenced as host addresses directly, and the invoked h= ost - * functions dereference guest pointers with no address translation, so gu= est - * and host must share a single address space. A non-zero guest_base (e.g.= set - * via -B/-R) would make every pointer off by guest_base and hit unrelated - * host memory. + * WARNING: requires guest_base =3D=3D 0, which is qemu-user's default, an= d a + * guest whose pointer width and endianness match the host's. Pointer oper= ands + * are dereferenced as host addresses directly, and the invoked host funct= ions + * dereference guest pointers with no address translation, so guest and ho= st + * must share a single address space and agree on how a pointer is stored.= A + * non-zero guest_base (e.g. set via -B/-R) would make every pointer off by + * guest_base and hit unrelated host memory. * * SPDX-License-Identifier: GPL-2.0-or-later */ @@ -46,8 +48,18 @@ QEMU_PLUGIN_EXPORT int qemu_plugin_version =3D QEMU_PLUG= IN_VERSION; * * It defaults to DLCALL_SYSCALL_DEFAULT and can be overridden at load time * with the "syscall_num=3DN" argument. To avoid hijacking a real syscall = the - * guest might issue, N must be at least DLCALL_SYSCALL_MIN: every Linux A= BI - * keeps its syscall numbers well below this; numbers from here up are fre= e. + * guest might issue, N must be at least DLCALL_SYSCALL_MIN, which most Li= nux + * ABIs keep their syscall numbers well below. + * + * N also has to reach the filter at all, which bounds it from above in a + * target specific way: arm32 answers anything past ARM_NR_BASE (0xf0000) = with + * ENOSYS or SIGILL before do_syscall() runs, while aarch64 has no such bo= und. + * + * MIPS O32 bases its numbering at 4000, so the default is a real syscall = there + * (getpriority). Raising N does not help either, because O32 rejects numb= ers + * its table does not define, again before the filter runs, which leaves no + * number that is both free and reachable on that ABI. Its N32 and N64 ABIs + * base at 6000 and 5000 and have no such gate, so they are unaffected. */ enum { DLCALL_SYSCALL_DEFAULT =3D 4096, @@ -168,6 +180,7 @@ static bool vcpu_syscall_filter(unsigned int vcpu_index, case DLCALL_ID_FREE_LIBRARY: { void *handle =3D (void *) a2; int *ret_ptr =3D (int *) a3; + assert(ret_ptr); *ret_ptr =3D dlclose(handle); *sysret =3D 0; break; @@ -176,6 +189,7 @@ static bool vcpu_syscall_filter(unsigned int vcpu_index, /* Get the last error message for a library event. */ case DLCALL_ID_GET_LIBRARY_ERROR: { const char **error_ptr =3D (const char **) a2; + assert(error_ptr); *error_ptr =3D dlerror(); *sysret =3D 0; break; --=20 2.34.1 From nobody Sat Jul 25 12:45:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=sjtu.edu.cn ARC-Seal: i=1; a=rsa-sha256; t=1784447368; cv=none; d=zohomail.com; s=zohoarc; b=EvioDk2FLWBE+1zHNP9wQ6ThslNvY2gHdbQ7GUzKkZoWp2pX+HLEvBc/ZYReitBmfmGi+TIaTURCjrMOwGyV5bZk2H6jj5Aexji5b9bybNYmwQjsYxKID+TBpcQRH0fjNg2/2jIlX/nJhmOE/Syr/4VNgBdLR6ZyWrIagboh58M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784447368; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=+/ZfnvIy1hi19psQRWBqlDPBjNSMJb2Jc+EQZW2udR8=; b=HIk4+R9LYra/ZC1ADsHi/vG+U6aiQMv/1HpFr9MG/UqnjDtrFPswDkbiv+rKCZ7icT54QGwwRhFDThc9iEIWk/uyEc9pB4Qohj4knBaYk2qpeWvrUzWZO278Q44pSjh2h63Ec+1j9U6YNvMpMrLFN8+0sIrf6vGVH/Kb0SR3n6U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784447367708971.4841355858371; Sun, 19 Jul 2026 00:49:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wlMGV-0007Y8-IH; Sun, 19 Jul 2026 03:48:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wlMGT-0007Xh-7i for qemu-devel@nongnu.org; Sun, 19 Jul 2026 03:48:45 -0400 Received: from smtp186.sjtu.edu.cn ([202.120.2.186]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wlMGR-00055B-2T for qemu-devel@nongnu.org; Sun, 19 Jul 2026 03:48:44 -0400 Received: from proxy188.sjtu.edu.cn (smtp188.sjtu.edu.cn [202.120.2.188]) by smtp186.sjtu.edu.cn (Postfix) with ESMTPS id B3EF22FF40B; Sun, 19 Jul 2026 07:48:03 +0000 (UTC) Received: from pc.. (unknown [202.120.40.100]) by proxy188.sjtu.edu.cn (Postfix) with ESMTPSA id 223AD380C9A; Sun, 19 Jul 2026 15:47:33 +0800 (CST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=sjtu.edu.cn; s=default; t=1784447283; bh=C6oeDMfOTIgbx58ypYUNM4jUAg3K2SgDysWy+jhYObU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=cch0Aq4y7jG5NfZ5KCCqyQO7baBoHAqHKgp3tQL47ftemifHDzbVbxcO3tW5Alr8E JIQ1GGrWGlJUMc1KfVMdfevbaIHllZv+kpz2z00odXrssCb9S7Lw/f3h5s4cbt1jmp T//h1PtCgZ+7Oz5sxLAaSzhEQ8x11YPYzn1rAmqd3oxO38vSwU5RmG4P4G7itvWSpW QwmC5jxGtzSR5y2cAyDWrf3ritjYpTsq4zWqK7S/MktWH56FAqopFhtIr1vHI8YU7h OQG0SR8oIWlYrCoXZpE1gVu31Rev6YoL7yQ3IBk9+rgMSAo+zOWrD6iJprOGusyJsv we3lKx1zkEmyw== From: Ziyang Zhang To: qemu-devel Cc: Riku Voipio , Laurent Vivier , Alex Bennee , Alexandre Iooss , Mahmoud Mandour , Pierrick Bouvier , Florian Hofhammer , Richard Henderson , Zhengwei Qi , Yun Wang , Mingyuan Xia , Kailiang Xu , Ziyang Zhang Subject: [PATCH 2/3] tests/tcg: correct why the magic syscall number is safe here Date: Sun, 19 Jul 2026 15:47:29 +0800 Message-Id: <20260719074730.1520517-3-functioner@sjtu.edu.cn> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260719074730.1520517-1-functioner@sjtu.edu.cn> References: <20260719074730.1520517-1-functioner@sjtu.edu.cn> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=202.120.2.186; envelope-from=functioner@sjtu.edu.cn; helo=smtp186.sjtu.edu.cn X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @sjtu.edu.cn) X-ZM-MESSAGEID: 1784447373733158500 Content-Type: text/plain; charset="utf-8" The comment said 4096 was picked because no ISA in Linux uses it. The same comment already notes that mips 32 bits numbers from 4000, which makes 4096= its getpriority. What actually keeps this test safe is the filter, which matches on the first argument as well, so a real syscall carrying this number is left alone. Say that instead. Co-authored-by: Kailiang Xu Co-authored-by: Mingyuan Xia Signed-off-by: Ziyang Zhang Reviewed-by: Pierrick Bouvier --- tests/tcg/multiarch/test-plugin-syscall-filter.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/tests/tcg/multiarch/test-plugin-syscall-filter.c b/tests/tcg/m= ultiarch/test-plugin-syscall-filter.c index 951e338a7c..089fb2a110 100644 --- a/tests/tcg/multiarch/test-plugin-syscall-filter.c +++ b/tests/tcg/multiarch/test-plugin-syscall-filter.c @@ -23,9 +23,12 @@ int main(int argc, char *argv[]) * "linux-user/arm/cpu_loop.c:cpu_loop". * As well, some arch expect a minimum, like 4000 for mips 32 bits. * - * Therefore, we pick 4096 because, as of now, no ISA in Linux uses th= is - * number. This is just a test case; replace this number as needed in = the - * future. + * Therefore, we pick 4096, which sits between those bounds. It is not + * unused everywhere though: mips 32 bits numbers from 4000, so 4096 i= s its + * getpriority. This test is unaffected because the filter also requir= es + * the first argument to be 0x66CCFF, so a real syscall carrying this + * number falls through untouched. This is just a test case, so replace + * this number as needed in the future. * * The corresponding syscall filter is implemented in * "tests/tcg/plugins/syscall.c". --=20 2.34.1 From nobody Sat Jul 25 12:45:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=sjtu.edu.cn ARC-Seal: i=1; a=rsa-sha256; t=1784447371; cv=none; d=zohomail.com; s=zohoarc; b=APR7ot4KV0WxFEaxnS+583WuFz4Ag3o4YDFMTbB+/35uO5dNk2t3p5yulbVHEO0hEjgpDuCauU+01kG7LtjbtuyfMseYaEiL3BpHC2q7fDlNcAN4gAgFn1Ji9gTpfU/FZaOuRaHqKjK8JL8ACcVj4nJX1HuKJbUF8lcALn+x3eI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784447371; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=0QwPpco6WO28UwqUfe/Ahv5AU4+uqZizDQsc3zg48mo=; b=NyTMqmuMyml5SpMB+DcZNSE3qZ3TJfU4LcPbhOkZKC9T2sW2rzamGCBbN9q20LmB/C7aiDnfJfk0QMkG08vBozw35YcsBA/xpFhmjE4eCQ0Mv+ibx7eQmhyILmomSpnIrI+SEe6lqbzcLgsJeiDK34fka0sDeqANiCnexq8y7k8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784447370706288.9519630233458; Sun, 19 Jul 2026 00:49:30 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wlMGf-0007by-FK; Sun, 19 Jul 2026 03:48:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wlMGe-0007bY-C5 for qemu-devel@nongnu.org; Sun, 19 Jul 2026 03:48:56 -0400 Received: from smtp186.sjtu.edu.cn ([202.120.2.186]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wlMGc-00055Y-5D for qemu-devel@nongnu.org; Sun, 19 Jul 2026 03:48:56 -0400 Received: from proxy188.sjtu.edu.cn (smtp188.sjtu.edu.cn [202.120.2.188]) by smtp186.sjtu.edu.cn (Postfix) with ESMTPS id D3E232FF40C; Sun, 19 Jul 2026 07:48:03 +0000 (UTC) Received: from pc.. (unknown [202.120.40.100]) by proxy188.sjtu.edu.cn (Postfix) with ESMTPSA id 45EB7380C9B; Sun, 19 Jul 2026 15:47:33 +0800 (CST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=sjtu.edu.cn; s=default; t=1784447283; bh=JpFxR/oOZtHQHbbjTkCGwxcezSCE6pTwm7ivEjov8/s=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=fMe/P1Aj9XoxcSCl61l1bgyO9sM3ImSB/VB3tqL0XdvhtjTVQ/U1oHyCIJRYs0S5i 2/+0L8Fg0Xj5sMl3y7NoDReKIMola3wlRzEuVFUtiqaWnDaYvzaguKeRXeVVqZiJEG 6NisjjXOUArNVEa2vq58WwN1vhiYJE5hGuvqWvxMLNpFdGLVHooD9EeNwu1MjaTowq x1GYnieRqJIcQEl4IpAcMEjFVPRnb2ONPWQlxGJ053Npi2W3S4DWbytfUIuw6i2bRn h9amrVZbO3Db0oMrtOxgPBL9vM5Flq1OBSY6Ac6oURjBtskyhpgiNJflyYUElFeK3V 8sl7M7E8097Rw== From: Ziyang Zhang To: qemu-devel Cc: Riku Voipio , Laurent Vivier , Alex Bennee , Alexandre Iooss , Mahmoud Mandour , Pierrick Bouvier , Florian Hofhammer , Richard Henderson , Zhengwei Qi , Yun Wang , Mingyuan Xia , Kailiang Xu , Ziyang Zhang Subject: [PATCH 3/3] docs/about/emulation: sharpen the dlcall boundary and its guest requirements Date: Sun, 19 Jul 2026 15:47:30 +0800 Message-Id: <20260719074730.1520517-4-functioner@sjtu.edu.cn> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260719074730.1520517-1-functioner@sjtu.edu.cn> References: <20260719074730.1520517-1-functioner@sjtu.edu.cn> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=202.120.2.186; envelope-from=functioner@sjtu.edu.cn; helo=smtp186.sjtu.edu.cn X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @sjtu.edu.cn) X-ZM-MESSAGEID: 1784447373763158500 Content-Type: text/plain; charset="utf-8" Record the same data model requirement as the plugin: guest_base =3D=3D 0 is necessary but not sufficient. Describe the magic syscall number the way the plugin now does. It has to be= a number the guest ABI does not use and does not reject before the plugin sees it, rather than merely a high one, so show syscall_num=3D being used as wel= l. A library is not turned into thunks, it is left alone and the thunks are produced for it, so say that instead. Argument marshalling, callbacks and variadic functions are also what the plugin does not do, and listing them in its description blurs the boundary it draws. Move them to Lorelei, where th= ey are pointed at as a reference. Co-authored-by: Kailiang Xu Co-authored-by: Mingyuan Xia Signed-off-by: Ziyang Zhang Reviewed-by: Pierrick Bouvier --- docs/about/emulation.rst | 31 +++++++++++++++++++++---------- 1 file changed, 21 insertions(+), 10 deletions(-) diff --git a/docs/about/emulation.rst b/docs/about/emulation.rst index b861501e85..c58149086c 100644 --- a/docs/about/emulation.rst +++ b/docs/about/emulation.rst @@ -1072,14 +1072,13 @@ syscall, so the real kernel never sees it. Trusted guests only. The guest can load arbitrary host libraries and run arbitrary code in the QEMU host process. The plugin is not a sandbox and provides no isolation. It also requires ``guest_base =3D=3D 0`` (qemu-u= ser's - default), as guest pointers are dereferenced as host addresses with no - translation. + default) and a guest whose pointer width and endianness match the host'= s, as + guest pointers are dereferenced as host addresses with no translation. =20 The plugin intentionally keeps the QEMU side lightweight and knows nothing -about any particular library or its calling convention. Turning a real lib= rary -into working thunks, including argument marshalling, callbacks and variadic -functions, is done entirely in userspace, and any toolchain can implement = the -interface. +about any particular library or its calling convention. Producing the thun= ks +for a real library is done entirely in userspace, and any toolchain can +implement the interface. =20 Loading the plugin is all that is required from QEMU's side: =20 @@ -1087,11 +1086,21 @@ Loading the plugin is all that is required from QEM= U's side: =20 qemu-x86_64 -plugin contrib/plugins/libdlcall.so ... =20 +If the default number does not suit the guest ABI, pick another one, and b= uild +the userspace side to issue the same one: + +.. code-block:: shell + + qemu-x86_64 -plugin contrib/plugins/libdlcall.so,syscall_num=3D8192 \ + ... + `Lorelei `_ is one end-to-end usersp= ace implementation of this: it provides the guest and host runtimes and an automated toolchain that generates the thunks from a library's headers, so= guest -library calls run on the host's native libraries. It supports an x86_64 gu= est -running on an x86_64, aarch64 or riscv64 host. +library calls run on the host's native libraries. How it handles the parts= the +plugin leaves out, including argument marshalling, callbacks and variadic +functions, can serve as a reference. It supports an x86_64 guest running o= n an +x86_64, aarch64 or riscv64 host. =20 A minimal end-to-end example uses a one-function library, ``libhello.so``,= built two ways: the guest build tags its output ``(from the guest)`` and the host @@ -1201,8 +1210,10 @@ which prints:: * - Option - Description * - syscall_num=3DN - - The magic syscall number the guest issues (default 4096). Must be hi= gh - enough not to clash with a real syscall. + - The magic syscall number the guest issues (default 4096). It must be= a + number the guest ABI does not use for a real syscall, and does not + reject before the plugin sees it, which bounds the choice from both + sides. =20 Other emulation features ------------------------ --=20 2.34.1