From nobody Sat Jul 25 07:28:25 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1784769527; cv=none; d=zohomail.com; s=zohoarc; b=FTNwtkni4nStg7+p3a95XhmdYH2fkdEAS12jtnbWn9arHFhYLKk+P5+cckCdqunTePDE19eo1xAhFdQox00ns8byd1CEeYPsHT/vPRjn4tyz2XaiwiAzW0UrP98cM97JCZztP+Rq+oQLvhQAZzaFt7fCyS1VFanePkAUMQOgBkA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784769527; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RLiGSnpxZU+nxcUeuinl0o98Pomq83HOQ6iKOlUVsfw=; b=f+Bo7Jotbez3zULMSv1ZyOj+vfhjFHOhfiXPzEL0opZ2t0EhK5O8aI2y/QppeawoS+dFzCd51Oe898a/QGNG8YrGteEGDDjN3iDHXZpM6uXPxvYn19DJEOg5tTb2d1klG/xesW/n+VIFoDllpGocqS0HmdjSMT4WDZuVUrEUAvs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784769527112750.9030054591441; Wed, 22 Jul 2026 18:18:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmi3s-0004Xv-QA; Wed, 22 Jul 2026 21:17:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi3q-0004XO-Ap; Wed, 22 Jul 2026 21:17:18 -0400 Received: from mgamail.intel.com ([192.198.163.9]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi3o-0002xF-Ni; Wed, 22 Jul 2026 21:17:18 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa103.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:14 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:13 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1784769436; x=1816305436; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=bUy4y8HW0wfdIIGwFykmmFvUk5kLIyAYGJ6OVufZCcQ=; b=R4+H8p8Z7k3OMBns6NGX0mgiytTvBGp4RQsB+Tn9UAI9UVKf4gDfAOW9 b8UIGP1cahP8rsK3gKUbbj3SlbIawrF1EoUpdLhUrolYj7rRDqRWtFnbZ /SE89P/EgL2eg35Rukiid+g19BQQKYP0trriLvaMLAWf4M8/ib0Q9ALzU DWNH4V0oMU6ntHw9DjalWX3Uks8D9tzO6+u4rRM8iWySCSfjIj2KnRsVw o4rSbLZd3vfXcJwZoa6tpGkHJn2pNrDy4pNSWU9wMtAw+ckkRyyQtl/t8 0lQAc8FzU+HeVWJHmGcAGhfnZPSEBYBbRG2HytRHb3nDI5wi7JruFDsAV A==; X-CSE-ConnectionGUID: 6E/9qsR/TQmg3+Isu1fYnA== X-CSE-MsgGUID: AZ2kEZdyRNewKC38W2BsYA== X-IronPort-AV: E=McAfee;i="6800,10657,11854"; a="96074831" X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="96074831" X-CSE-ConnectionGUID: WBJjti8ISJmASN3vb3+jRg== X-CSE-MsgGUID: 6/5Q7KSLR2+GFgXFsMn6SA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="251943345" From: Junjie Cao To: Jonathan Cameron Cc: qemu-devel@nongnu.org, linux-cxl@vger.kernel.org, qemu-stable@nongnu.org Subject: [PATCH v2 1/6] hw/cxl: fix timer leak in cxl_destroy_cci() Date: Thu, 23 Jul 2026 09:16:20 +0800 Message-ID: <20260723011625.1117034-2-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260723011625.1117034-1-junjie.cao@intel.com> References: <20260723011625.1117034-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.9; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1784769528919158500 Content-Type: text/plain; charset="utf-8" cxl_init_cci() allocates a QEMUTimer via timer_new_ms() but cxl_destroy_cci() never frees it. This leaks a timer object on every device exit path and, more critically, on every device reset cycle since the secondary CCIs (vdm_fm_owned_ld_mctp_cci, ld0_cci) are destroyed and re-initialized each time ct3d_reset() runs. Tear the CCI down in the reverse of cxl_init_cci()'s setup order: destroy the mutex, then free the timer. timer_free() cancels any pending expiry via timer_del() internally and tolerates a NULL pointer; clear the field afterwards so that a repeated timer_free() on the same CCI is a safe no-op. (The function as a whole is still not idempotent: qemu_mutex_destroy() asserts on an already-destroyed mutex. Callers must not invoke cxl_destroy_cci() twice; the .initialized guard added in the next patch enforces that.) Fixes: 98cbac128f1c ("hw/cxl: Support aborting background commands") Cc: qemu-stable@nongnu.org Signed-off-by: Junjie Cao Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- hw/cxl/cxl-mailbox-utils.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/hw/cxl/cxl-mailbox-utils.c b/hw/cxl/cxl-mailbox-utils.c index 20e0b7e476..a1b9f0243b 100644 --- a/hw/cxl/cxl-mailbox-utils.c +++ b/hw/cxl/cxl-mailbox-utils.c @@ -4771,6 +4771,8 @@ void cxl_init_cci(CXLCCI *cci, size_t payload_max) void cxl_destroy_cci(CXLCCI *cci) { qemu_mutex_destroy(&cci->bg.lock); + timer_free(cci->bg.timer); + cci->bg.timer =3D NULL; cci->initialized =3D false; } =20 --=20 2.43.0 From nobody Sat Jul 25 07:28:25 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1784769522; cv=none; d=zohomail.com; s=zohoarc; b=Njoxu9V4tzRwSG79+/YBZKvGuY89PwO0tdoPP7Y5D63RwW6QGODZqyyupZAMQkUcqsx73IaN/Pg7Z6/CnOxy5m6ld5YIuKodWD8wX9o9NApE6pzWp+PzPM/a9NH1sL6wmOXeiJTIqZEywfBTz7qTb//jGOH3yginS4NUMdElE+s= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784769522; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YxT7vM+Hm1IctxEuw5wmfgkXtwXT4x+aLwHcbP1c/50=; b=PXn+0vx5e1lOULJ21gs0otdqJHhPpjgR1CzT3wQdcML3og3nIfWzKsEFBeFu51J37CWinpcEzX387BAnzJAWP9NOYQrhp8PhKVuz2IpYiEtdjX/jEtBnqm83QPUOfkKvWzlwU+1l2NwYqPtU51G1vi/SR6roCpcNumqdCXf1shw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784769522308206.58946801779655; Wed, 22 Jul 2026 18:18:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmi3w-0004Yw-69; Wed, 22 Jul 2026 21:17:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi3u-0004YR-Q2; Wed, 22 Jul 2026 21:17:22 -0400 Received: from mgamail.intel.com ([192.198.163.9]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi3t-0002xZ-2A; Wed, 22 Jul 2026 21:17:22 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa103.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:19 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:18 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1784769441; x=1816305441; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=hBO3fzaslaoxTxxwV/97htR4gR1dlBLu3SsAm+it1ik=; b=mDKZKfe0cbGNtWDbsuQx4Eci7/269Av/SlbTWskNgHHPGs3kiYnHpe1E CIgirUh2LegTPtFCUg12kUVXMkLUl31SCmUCog72puiizOHrChUztfb0i Ep0Y/M12ESckL9gZHL69x1CjUW67xEvTIb/fU9qFTJfTWgkadSkM16GIe tnbGMGi9lZTj0JdIaHJV11VmvAeKTlY80ufqwKby9NN2NaltR3KcfOQxI xirTOYZDkaZBpSj2x7XCxHMOMPF9eDb0M5VTbZd5hQRl8VYx1GmJUXl7p geASVTGC2ivg0AdOdoVDGKYu+qhuZSYlVlBlljnSrRZmvXXus3josOPk5 Q==; X-CSE-ConnectionGUID: RT2Ag1JoRlumcK9S4aK0Ow== X-CSE-MsgGUID: x/gIbCiyTvemUYIJ97z+iw== X-IronPort-AV: E=McAfee;i="6800,10657,11854"; a="96074836" X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="96074836" X-CSE-ConnectionGUID: v6T75PnGRjaJSURpZP4Kfw== X-CSE-MsgGUID: nZ3kjDMaT3WZdOpqn0jw8g== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="251943349" From: Junjie Cao To: Jonathan Cameron Cc: qemu-devel@nongnu.org, linux-cxl@vger.kernel.org, qemu-stable@nongnu.org Subject: [PATCH v2 2/6] hw/cxl: destroy primary CCI before re-initialization on reset Date: Thu, 23 Jul 2026 09:16:21 +0800 Message-ID: <20260723011625.1117034-3-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260723011625.1117034-1-junjie.cao@intel.com> References: <20260723011625.1117034-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.9; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1784769524917158500 Content-Type: text/plain; charset="utf-8" ct3d_reset() re-initializes the primary CCI through the call chain cxl_device_register_init_t3() -> cxl_initialize_mailbox_t3() -> cxl_init_cci(), but never calls cxl_destroy_cci() first. Each reset cycle therefore leaks the old timer and leaves the old mutex undestroyed while silently overwriting the CCI state. Per CXL r4.0, the "Mailbox Interfaces Ready" bit in the Memory Device Status register (Table 8-212) is set after a Conventional Reset or CXL Reset once the device has re-initialized its mailbox interfaces. The CCI is the software abstraction of these interfaces and must be properly torn down before re-initialization. The secondary CCIs (vdm_fm_owned_ld_mctp_cci, ld0_cci) already follow the correct destroy-before-reinit pattern in the same function; apply the same discipline to the primary CCI. Also destroy the secondary CCIs in ct3_exit() where they were previously leaked at device removal time. Guard the primary CCI teardown there with the same .initialized check used for the secondary CCIs: the primary CCI is only brought up from the reset path (cxl_device_register_init_t3()), so a device that is unrealized before its first reset would otherwise tear down a never-initialized CCI. Fixes: cac36a8faffc ("hw/cxl/mbox: Pull the CCI definition out of the CXLDe= viceState") Cc: qemu-stable@nongnu.org Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index cba05ec57d..4ac6eaa950 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1073,7 +1073,15 @@ static void ct3_exit(PCIDevice *pci_dev) cxl_doe_cdat_release(cxl_cstate); msix_uninit_exclusive_bar(pci_dev); g_free(regs->special_ops); - cxl_destroy_cci(&ct3d->cci); + if (ct3d->cci.initialized) { + cxl_destroy_cci(&ct3d->cci); + } + if (ct3d->vdm_fm_owned_ld_mctp_cci.initialized) { + cxl_destroy_cci(&ct3d->vdm_fm_owned_ld_mctp_cci); + } + if (ct3d->ld0_cci.initialized) { + cxl_destroy_cci(&ct3d->ld0_cci); + } if (ct3d->dc.host_dc) { cxl_destroy_dc_regions(ct3d); address_space_destroy(&ct3d->dc.host_dc_as); @@ -1328,6 +1336,9 @@ static void ct3d_reset(DeviceState *dev) ct3d->flitmode); cxl_component_register_init_common(reg_state, write_msk, CXL2_TYPE3_DEVICE, ct3d->hdmdb); + if (ct3d->cci.initialized) { + cxl_destroy_cci(&ct3d->cci); + } cxl_device_register_init_t3(ct3d, CXL_T3_MSIX_MBOX); =20 /* --=20 2.43.0 From nobody Sat Jul 25 07:28:25 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1784769499; cv=none; d=zohomail.com; s=zohoarc; b=LIJ1oEjjcPQ5SKs563TOA+zE70l2r6KDVV2QQ2+FVEPKUqChPmCYO8IgRyMmlF/O9r5Tmk8YMllrANhKw6FlGRN5Km7f4boKrU9T1HknVxQ77aixhVfB4abaI5OCxLa4+pJnmv06hk6rLH0lc273iKeqNtYxeIUiRSL0yW+muD0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784769499; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LrnYOgunsVpAbtK2oZZq4Zz2JnAC6WZlIe89kbCq4S8=; b=N/BRz81aq0IS6fwMx3Vl9TdfKqPa/W3cXVHKuDywq2jl8PeAtxzEFUbzOTwYYKfLH1eXIFuLHGqbzxeKB/0LT1e7/jFs3723rxdyDOqXWMgE1tNQhFtEWjrc4e+plQ7XSO8Iuamg20TKjYasWHXHLpjY4GZ53EikCHVE+rNp1ss= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784769499681951.185322659584; Wed, 22 Jul 2026 18:18:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmi44-0004Zw-UD; Wed, 22 Jul 2026 21:17:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi3y-0004ZJ-9D; Wed, 22 Jul 2026 21:17:26 -0400 Received: from mgamail.intel.com ([192.198.163.9]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi3v-0002xZ-FN; Wed, 22 Jul 2026 21:17:24 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa103.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:22 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:21 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1784769443; x=1816305443; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=/QW+6bMVfdc3+/VQ5V93oBga9b/YPL0PkvFyIV5avEA=; b=fs0k7MYh5UJItd3U6xYeMY8cx869RiGxL6dWG1M2z2m6EymOO0MP7WFV nUKfuAkHgB72uWyWDAptVYI+DUc0nV8xql09u1otKffEXp/Bz9bQCsvzE Scix8ROt3Zf2Z9ukFcSbejcThqpziCuV2kjXJ85U8vTB118gO08crJL/i 8uT9i9aqdyLTkJ0VaO+mOquuN0qPzR+lDGEfOUJu4s6TmRtdf32Qq4Hqi d3F0wlp2SCIDUWBXPf3rV3/VtimFZN8Z456EdIOELQOsCSiArWsLNty9s ei1Dff7BFMz+FC1dQrzGzDDeKdkgixBPx4MUEu/TDXWeCVdjIGTlKUE47 Q==; X-CSE-ConnectionGUID: MvoRaanWTFOHiTEbLtC+fA== X-CSE-MsgGUID: Asq6tt/WTwe/kV7kGF+nSA== X-IronPort-AV: E=McAfee;i="6800,10657,11854"; a="96074842" X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="96074842" X-CSE-ConnectionGUID: cj7CMRtFSOqmc9+SVmQkLQ== X-CSE-MsgGUID: c1A9hUpoTTC97+e0urPpmw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="251943350" From: Junjie Cao To: Jonathan Cameron Cc: qemu-devel@nongnu.org, linux-cxl@vger.kernel.org, qemu-stable@nongnu.org Subject: [PATCH v2 3/6] hw/cxl: convert cxl-type3 to three-phase reset Date: Thu, 23 Jul 2026 09:16:22 +0800 Message-ID: <20260723011625.1117034-4-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260723011625.1117034-1-junjie.cao@intel.com> References: <20260723011625.1117034-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.9; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1784769500806158500 Replace the deprecated device_class_set_legacy_reset() registration with the three-phase resettable interface, following the pattern already established by the CXL root port (cxl_rp_reset_hold). Only the hold phase is needed; enter and exit are left NULL. The parent hold phase is chained for correctness: TYPE_PCI_DEVICE installs no hold phase today, so parent_phases.hold is currently NULL and the chained call is a no-op, but capturing and invoking it is the correct forward-compatible pattern and mirrors cxl_rp_reset_hold(). No functional change =E2=80=94 the reset body is identical; only the registration path and function signature change. Signed-off-by: Junjie Cao Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- hw/mem/cxl_type3.c | 16 ++++++++++++---- include/hw/cxl/cxl_device.h | 2 ++ 2 files changed, 14 insertions(+), 4 deletions(-) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index 4ac6eaa950..b842e71c66 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1326,13 +1326,18 @@ MemTxResult cxl_type3_write(PCIDevice *d, hwaddr ho= st_addr, uint64_t data, return address_space_write(as, dpa_offset, attrs, &data, size); } =20 -static void ct3d_reset(DeviceState *dev) +static void ct3d_reset_hold(Object *obj, ResetType type) { - CXLType3Dev *ct3d =3D CXL_TYPE3(dev); + CXLType3Dev *ct3d =3D CXL_TYPE3(obj); + CXLType3Class *cvc =3D CXL_TYPE3_GET_CLASS(obj); uint32_t *reg_state =3D ct3d->cxl_cstate.crb.cache_mem_registers; uint32_t *write_msk =3D ct3d->cxl_cstate.crb.cache_mem_regs_write_mask; =20 - pcie_cap_fill_link_ep_usp(PCI_DEVICE(dev), ct3d->width, ct3d->speed, + if (cvc->parent_phases.hold) { + cvc->parent_phases.hold(obj, type); + } + + pcie_cap_fill_link_ep_usp(PCI_DEVICE(obj), ct3d->width, ct3d->speed, ct3d->flitmode); cxl_component_register_init_common(reg_state, write_msk, CXL2_TYPE3_DEVICE, ct3d->hdmdb); @@ -2464,6 +2469,7 @@ static void ct3_class_init(ObjectClass *oc, const voi= d *data) DeviceClass *dc =3D DEVICE_CLASS(oc); PCIDeviceClass *pc =3D PCI_DEVICE_CLASS(oc); CXLType3Class *cvc =3D CXL_TYPE3_CLASS(oc); + ResettableClass *rc =3D RESETTABLE_CLASS(oc); =20 pc->realize =3D ct3_realize; pc->exit =3D ct3_exit; @@ -2477,9 +2483,11 @@ static void ct3_class_init(ObjectClass *oc, const vo= id *data) =20 set_bit(DEVICE_CATEGORY_STORAGE, dc->categories); dc->desc =3D "CXL Memory Device (Type 3)"; - device_class_set_legacy_reset(dc, ct3d_reset); device_class_set_props(dc, ct3_props); =20 + resettable_class_set_parent_phases(rc, NULL, ct3d_reset_hold, NULL, + &cvc->parent_phases); + cvc->get_lsa_size =3D get_lsa_size; cvc->get_lsa =3D get_lsa; cvc->set_lsa =3D set_lsa; diff --git a/include/hw/cxl/cxl_device.h b/include/hw/cxl/cxl_device.h index ba551fa5f9..b7e20e3fe4 100644 --- a/include/hw/cxl/cxl_device.h +++ b/include/hw/cxl/cxl_device.h @@ -805,6 +805,8 @@ struct CXLType3Class { /* Private */ PCIDeviceClass parent_class; =20 + ResettablePhases parent_phases; + /* public */ uint64_t (*get_lsa_size)(CXLType3Dev *ct3d); =20 --=20 2.43.0 From nobody Sat Jul 25 07:28:25 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1784769484; cv=none; d=zohomail.com; s=zohoarc; b=VK2HCPiJXB9scad8MtOxfItQBNMhIk+gcbtK7a6YoJKUjCu8iqTZ0fHzl7iI5xZJ0JOOI++dWeMU7whx3rtCsFZ56whAkX05Uz255c0jL+pazhOnwZSpwYrDf5zjx8YtidzavxvVuEC0tnll77DQVVeE1RZ2avq8HbyveWDcEfE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784769484; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=KfXtskmA0jrRccQJ5460fq3g9HeQ5X6Q8jyBo0DPrqs=; b=PL6mFtUOpDg83P2euCsuZL5OTB9qVIcp6LiKKOiP7c5TlhIUk0fX67a/meQITD6COHgEqUpuTu6C4oemMU5f2XNqlj/b6BE1vdxRhdJ7X6C9Ufa9acwEujvCh8Vx7wYLNqu8gfOmMPma/E5QrNq4AAWwlZFyOdXjf4T5AdDbHgU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784769483837610.4646095445289; Wed, 22 Jul 2026 18:18:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmi4G-0004dc-UF; Wed, 22 Jul 2026 21:17:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi44-0004a0-Hu; Wed, 22 Jul 2026 21:17:32 -0400 Received: from mgamail.intel.com ([192.198.163.9]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi41-0002y5-MP; Wed, 22 Jul 2026 21:17:30 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa103.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:27 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:26 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1784769449; x=1816305449; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=msD/IOsgmuLyQHdlEUt3k5JKbV4W8J9VzDhB5nHKV2I=; b=OwOqotLwrxt3w3B8Av9bqhCMJFwoDXZIuLt4Xb5BlLJY2EDeLgvcFTYo 8Xw9iT2x604FwPVAB+me5N5+a5WXiablxdrn1V/MWvRAjkqhME/Sy9kKx ofOPpcoVREsPBuD6xg866+AR/wB6CO7kmaC1BxzctjGxpRLuKEPhiQCa9 LFkQR8VyelDkegYayeb+gfeq18VT5ZWMmNGyuX0Evon/9LIynhUJf2uVF Kra/nuIpjakgvKmmb0OO/PQPxc4NMSpONPbc2Qtdp10gzfBDVSNlBxI1z P0dgfyPfTT1WHSzlImv2UTYSsXuqBAjkJQYKfHJUH2DSfEq3/foLoNOqM Q==; X-CSE-ConnectionGUID: MPaX3SlEQtKYarrp1OCUhA== X-CSE-MsgGUID: d3VdFXcMQmuTp1fwqidGxA== X-IronPort-AV: E=McAfee;i="6800,10657,11854"; a="96074849" X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="96074849" X-CSE-ConnectionGUID: Dl9Y9zC2RNaOcTDehEnZWA== X-CSE-MsgGUID: OvRJj6M5RqWgR14rnKSHsA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="251943358" From: Junjie Cao To: Jonathan Cameron Cc: qemu-devel@nongnu.org, linux-cxl@vger.kernel.org, qemu-stable@nongnu.org Subject: [PATCH v2 4/6] hw/cxl: free in-flight sanitize state on reset Date: Thu, 23 Jul 2026 09:16:23 +0800 Message-ID: <20260723011625.1117034-5-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260723011625.1117034-1-junjie.cao@intel.com> References: <20260723011625.1117034-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.9; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1784769486758158500 Content-Type: text/plain; charset="utf-8" Per CXL r4.0 Section 8.2.9.4, "Background commands do not continue to execute across Conventional Resets." If a sanitize or media operation is in progress when the device is reset, the background timer is already cancelled and freed via cxl_destroy_cci(), but the per-operation state (media_op_sanitize) is heap-allocated separately and would otherwise be leaked. Free it unconditionally at the end of the reset hold phase. The timer that advances the operation lives in the CCI that was just destroyed and re-initialized, so the operation can never complete after a reset of any type; preserving the heap state across reset has no benefit and would leak it the next time media_op_sanitize is assigned. Note that Section 8.2.10.9.5.1 additionally requires a device whose Sanitize was interrupted by reset to remain in the Media Disabled state until a successful Sanitize completes. That latch is not modelled here (reset re-enables media via memdev_reg_init_common()) and is left for future work; this patch only addresses the resource leak. Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index b842e71c66..a5e6df3033 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1361,6 +1361,16 @@ static void ct3d_reset_hold(Object *obj, ResetType t= ype) } cxl_initialize_t3_ld_cci(&ct3d->ld0_cci, DEVICE(ct3d), DEVICE(ct3d), 512); /* Max payload made up */ + + /* + * Free any in-flight sanitize state unconditionally. The background + * timer that would advance it lives in the CCI just torn down and + * re-initialized above, so the operation can never complete after this + * point regardless of the reset type; keeping the heap state would on= ly + * leak it on the next allocation. + */ + g_free(ct3d->media_op_sanitize); + ct3d->media_op_sanitize =3D NULL; } =20 static const Property ct3_props[] =3D { --=20 2.43.0 From nobody Sat Jul 25 07:28:25 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1784769531; cv=none; d=zohomail.com; s=zohoarc; b=SQ31OYR/xO2EDgT8cTRUIF6Mdxhlf1M0FaAq0AANa3BBa6dMlGw1D/N7CjqDKhWh8TqyQXGfb5WmSLbLI7SmSGGzhqcRnmgdlv/J9FgB8/DWABAC19+PXdt4DjSCHqprlMCEgVmO4zZAJXFWCgSoh4Lv1oP72XNrG+RgcCvL9UU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784769531; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EbHKDYcF+kPwsWjsB0kIFQ7xqBDViUto7Jl6ZodS3Vs=; b=AcL/JHpSmRjnkjhe/f4vlCXb9Y6gUhGdg4DK62w0q1HSWYmCeyoxVkaUDGYV4bEXFkR2OoxQG9bNEMMXoBH4+LkL4b9vnmLUdRVpp16LgtTvh07qtQfkNady1RZ8WZv6U0rDgFjT1agp76XmGgtW7TgtAK/RPzr9DO8ytsMMOzY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178476953129517.349347701309057; Wed, 22 Jul 2026 18:18:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmi4M-0004eR-Sf; Wed, 22 Jul 2026 21:17:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi47-0004aa-NN; Wed, 22 Jul 2026 21:17:39 -0400 Received: from mgamail.intel.com ([192.198.163.9]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi44-0002yF-RK; Wed, 22 Jul 2026 21:17:35 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa103.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:30 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:29 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1784769452; x=1816305452; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=LFZDeluVb0jYrFBCNzRihUZyA/8sIedwSTGxxS78Gns=; b=ecirhDrrE29HsCz6Llj0iPfauJSaZQ2lZx5DpEEox8T7C3zcQ0bde+XH e+quMHFAmOs6J+8KvF7OyFlhvzYU1r0YJrtQrtaNxBeeFYduIhY5jQbx9 jPWpa2iSIPQSdinxN+ek7vIy7Wp0OXWbD0vNjjfsPfbRiG/wElGxAz73X Mv/UhPN0lb5jDPTufXq/S2iC6ZFXe5i27E58JzITH95WaIqJ7EX08ojLi D6/Xb1KgytZJp/sFwBzwEB2DYkPK2P7pByffmJ5tnae7zngkWbRydOPME vFMsTPAP+2HtCV94f41f8kJAoh1NJJ6jJF3DIpMCiLohyOBt/HYVRz9EE g==; X-CSE-ConnectionGUID: PK6km9+iT7W+P67V1/lvkQ== X-CSE-MsgGUID: jFSuhACDTqCjDD8GAPPi6g== X-IronPort-AV: E=McAfee;i="6800,10657,11854"; a="96074857" X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="96074857" X-CSE-ConnectionGUID: H+h8YyNAQWKTeVFtEXdS3g== X-CSE-MsgGUID: yLavuJHuSj+zmx5W/s9Ezg== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="251943360" From: Junjie Cao To: Jonathan Cameron Cc: qemu-devel@nongnu.org, linux-cxl@vger.kernel.org, qemu-stable@nongnu.org Subject: [PATCH v2 5/6] hw/cxl: clear event logs, scan media and interrupt policy on reset Date: Thu, 23 Jul 2026 09:16:24 +0800 Message-ID: <20260723011625.1117034-6-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260723011625.1117034-1-junjie.cao@intel.com> References: <20260723011625.1117034-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.9; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1784769532858158500 Content-Type: text/plain; charset="utf-8" Event records, scan media results and event interrupt settings are device-internal dynamic state that should not survive a device reset. Per CXL r4.0 Section 8.2.10.9.4.6 (Get Scan Media Results), "If the Scan Media command has not been called since the last Conventional Reset, the device shall return the Unsupported return code." This explicitly invalidates scan media results across reset, so clear the scan_media_hasrun flag. Per CXL r4.0 Section 8.2.10.2.5 (Set Event Interrupt Policy), "All event log interrupt settings shall be reset to 00b (No Interrupts) by the device on Conventional Reset." Clear irq_enabled for every event log accordingly. For the event records there is no direct spec mandate to drop the stored records on reset; the Event Status register (Table 8-203) is non-sticky and resets to zero per Section 9.7, and no reset flavor requires the already-reported records to persist. Draining the queues is therefore a reasonable modelling choice that keeps the records consistent with the freshly-reset status register, rather than a spec requirement. Call the existing cxl_discard_all_event_records() helper to drain all event queues. The event log infrastructure itself (mutexes, IRQ vectors) remains intact as it is initialized once during device realize. This is also where reset-type gating begins: a wakeup from suspend-to-RAM (RESET_TYPE_WAKEUP) is not a Conventional or CXL Reset and must retain device-internal state, so the hold phase returns early for that type before discarding any records. This mirrors the RESET_TYPE_WAKEUP shortcut in virtio-mem and virtio-balloon. Only the unconditional mailbox interface re-initialization and the in-flight sanitize free (whose backing timer was already destroyed) run on a wakeup. Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index a5e6df3033..5bf0cffb72 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1371,6 +1371,23 @@ static void ct3d_reset_hold(Object *obj, ResetType t= ype) */ g_free(ct3d->media_op_sanitize); ct3d->media_op_sanitize =3D NULL; + + /* + * A wakeup from suspend-to-RAM is not a Conventional or CXL Reset. T= he + * device-internal dynamic state cleared below (event logs, scan media + * results, and the poison/feature-transfer state cleared in subsequent + * patches) must be preserved across resume, so stop here for a wakeup. + * virtio-mem and virtio-balloon take the same RESET_TYPE_WAKEUP short= cut. + */ + if (type =3D=3D RESET_TYPE_WAKEUP) { + return; + } + + cxl_discard_all_event_records(&ct3d->cxl_dstate); + for (int i =3D 0; i < CXL_EVENT_TYPE_MAX; i++) { + ct3d->cxl_dstate.event_logs[i].irq_enabled =3D false; + } + ct3d->scan_media_hasrun =3D false; } =20 static const Property ct3_props[] =3D { --=20 2.43.0 From nobody Sat Jul 25 07:28:25 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1784769530; cv=none; d=zohomail.com; s=zohoarc; b=YNjml8zT0jNoFnVqeDMOEwwVHCZK2fHswMfWcjv8bj+dze7ITZBaCwH1b6L5dngpu8Gh8bQRvyapOHHfykRvZoUHjVMNZ9/LDAu4DK9FGCS9D+Uh7ZhBqfB1H2AGr7iqWldQ5Z0AJKZ2nh9yYcdKZD/GlwJYSxgVYJOK3F05++w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784769530; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hKBxIwH7GIGftBXt/ixSyxNWfSkLWamXQntr0V6tWk0=; b=misUWBX8snCTxYAmbUBEs5WNnooOR8mY47+/uC+diN+31p9FIBD3T2OnzFzcUtg8TnXz524vpIN62iL9j9ma7BNhm7OKMPIekieas7g5KIBeGLr51y1PKRJrTKpir2mhyf/m4oJzR29DAg3WE2Bx8lwr146aIxOVFe3bwL7Qn6o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784769530449459.9195433953432; Wed, 22 Jul 2026 18:18:50 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmi4I-0004eB-TP; Wed, 22 Jul 2026 21:17:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi48-0004ac-Dj; Wed, 22 Jul 2026 21:17:39 -0400 Received: from mgamail.intel.com ([192.198.163.9]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmi46-0002y5-Mz; Wed, 22 Jul 2026 21:17:36 -0400 Received: from fmviesa009.fm.intel.com ([10.60.135.149]) by fmvoesa103.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:33 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by fmviesa009-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Jul 2026 18:17:32 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1784769454; x=1816305454; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=X6xEQGmKsqT36tEuVzuNvndUEQfjM0ecSdHXQUXdAaw=; b=nGUP4oXtUDYK3Km3cCX2bt2rJMIHN8eklBe7cNcQ1mWrNuIlQi+xVS/B o45ruruUQHfbSsIZcFjUA4GMB75x52YKYzYSv/XSdlhkwW5eqkO6NQA5G DbCaaAZOVo9LzwlNsnUyL+kLPAWheKUBhPVwJGstzva2uQI+5lUTR7UH+ UzNmku6P0VCMj7rw4BPIe3SCJxJOFsKHJyBfYjVUhaN8jt+09ZAqsPys3 tfH55DvdBwm7L3hQ8LzG/2sSya9uCnezMf/NTZo0toGR7pAaNjK4gmDkd 8B7dBxWeWE+QKc1VG3djZJOZUAgUUhaVLfmmmwn0822dt+XNphMhUmEfe A==; X-CSE-ConnectionGUID: cEA2sAU2QAuZt2F0AQPT+Q== X-CSE-MsgGUID: q3IIPM7bQqOjyfS397GLIg== X-IronPort-AV: E=McAfee;i="6800,10657,11854"; a="96074860" X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="96074860" X-CSE-ConnectionGUID: eyUgdSFDREWExWZcDxv3bA== X-CSE-MsgGUID: sZ11ZRZrR5Ga6XQpKQRfHg== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,179,1779174000"; d="scan'208";a="251943363" From: Junjie Cao To: Jonathan Cameron Cc: qemu-devel@nongnu.org, linux-cxl@vger.kernel.org, qemu-stable@nongnu.org Subject: [PATCH v2 6/6] hw/cxl: clear poison lists and feature transfer state on reset Date: Thu, 23 Jul 2026 09:16:25 +0800 Message-ID: <20260723011625.1117034-7-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260723011625.1117034-1-junjie.cao@intel.com> References: <20260723011625.1117034-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.9; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1784769530760158500 The poison lists (active, backup, and scan-media results), their associated overflow tracking, and the Set Feature partial-transfer state are all device-internal dynamic state that accumulates during the device's lifetime. Per CXL r4.0 Table 8-309 (Identify Memory Device), the "Injects Persistent Poison" capability bit (offset 41h, Bit[0]) controls poison retention across reset. When cleared =E2=80=94 the QEMU default =E2=80=94 = "a Conventional Reset or CXL Reset shall automatically clear the injected poison." Clear all poison lists accordingly, reusing the existing cxl_clear_poison_list_overflowed() helper for the overflow tracking. For the Set Feature transfer state, CXL r4.0 Section 8.2.10.6.3 (Set Feature) requires: "If the Feature data transfer is interrupted by a Conventional Reset or a CXL Reset, the Feature data transfer shall be aborted by the device [...] the device shall require the Feature data transfer to be started from the beginning." Zero set_feat_info on reset so any partially transferred Set Feature is abandoned and must restart from the beginning. Both clears run after the RESET_TYPE_WAKEUP early-return added in the previous patch, so this state is preserved across a suspend-to-RAM wakeup. Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index 5bf0cffb72..1fe4d56762 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1326,6 +1326,16 @@ MemTxResult cxl_type3_write(PCIDevice *d, hwaddr hos= t_addr, uint64_t data, return address_space_write(as, dpa_offset, attrs, &data, size); } =20 +static void ct3d_clear_poison_list(CXLPoisonList *list) +{ + CXLPoison *ent, *next; + + QLIST_FOREACH_SAFE(ent, list, node, next) { + QLIST_REMOVE(ent, node); + g_free(ent); + } +} + static void ct3d_reset_hold(Object *obj, ResetType type) { CXLType3Dev *ct3d =3D CXL_TYPE3(obj); @@ -1388,6 +1398,14 @@ static void ct3d_reset_hold(Object *obj, ResetType t= ype) ct3d->cxl_dstate.event_logs[i].irq_enabled =3D false; } ct3d->scan_media_hasrun =3D false; + + ct3d_clear_poison_list(&ct3d->poison_list); + ct3d_clear_poison_list(&ct3d->poison_list_bkp); + ct3d_clear_poison_list(&ct3d->scan_media_results); + ct3d->poison_list_cnt =3D 0; + cxl_clear_poison_list_overflowed(ct3d); + + memset(&ct3d->set_feat_info, 0, sizeof(ct3d->set_feat_info)); } =20 static const Property ct3_props[] =3D { --=20 2.43.0