From nobody Mon Sep 28 02:01:04 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1785336521; cv=none; d=zohomail.com; s=zohoarc; b=ieQ8HfNNabFJygFTUl0ERpf8UVE2QD8J42E4vd4jDGlzFkBht2KOhWW3tKdqadGOC6BSj9CeA8bM+QUZKSmRdF0nCRD3U9Tppr0v7VbeiMJ6CcHWNGGHPxvYGb9fdaL+/D19Q54yYkPznUmZVlljDTm3TfnuX33wIca7MSf4aM4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785336521; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=TOYwMxUzNkLDJ75L6WFfVJqXtVG19J/Yt0ix0qDzJTc=; b=c9Jbl5WydM4vIbs8LrL8UgxTQiKelk76i3BnVYTc163iKsKZ4T+illilm7nVNxzFC7DmMdAtdY7zfpxXc4r8Y1gR+8nrjIzb37ni1Tb66Yml0wHbijZ2Qv0EsH3bMtgc1NGRRIjGIk6INX4v6Z3Ec/QtJIn7IhLnE/lrE+kirhA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785336521827723.7204779075945; Wed, 29 Jul 2026 07:48:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wp5a6-0004IF-CW; Wed, 29 Jul 2026 10:48:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5ZV-0004E5-24; Wed, 29 Jul 2026 10:47:49 -0400 Received: from mgamail.intel.com ([198.175.65.16]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5ZT-0000PG-44; Wed, 29 Jul 2026 10:47:48 -0400 Received: from orviesa010.jf.intel.com ([10.64.159.150]) by orvoesa108.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:44 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by orviesa010-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:43 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785336467; x=1816872467; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=5PnG4xRW/GZtwi7X3p6EKgSZ/dyG9T25icwTsVBZ8kU=; b=csp01CuRVcgX80EGuUAGdcN7GMRwO9yOPCRMdnWvK+95fTXttUsr0NMD ifop7S3SpVo6V3TIe3UuXEicOAS5bIzs0+olcYg408kF0zw0QqCGdxJgz ldi6ZsODv8fpprubya1wi0YTMCN6VN5X1bXtOHbFSOolIf3vNxoroSNcZ 3s2OMd4T73aNYdj/zkeYAiJRZxqIzHYPAMMuM0Svg7xbLYgT2VPmx6MyL wUnq+5uSLGYEFZQocUMJMbrvzlRoLFUpjZ5S5WKbttrkoE63OhT5aSq+j crJ8eRChoDroBOzPa2pTlrZ+16AUdjjJw2FDhDg+iGS1L4hIj/tqkDWBO A==; X-CSE-ConnectionGUID: ArNOROy8QSS7iBNnviEaGg== X-CSE-MsgGUID: nzBYWa0CQemKyg3dN8gDQQ== X-IronPort-AV: E=McAfee;i="6800,10657,11859"; a="86133608" X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="86133608" X-CSE-ConnectionGUID: uevd9xgMSBGKtfTotOA5eA== X-CSE-MsgGUID: D0SSyiZwQ8ScMosv1vsxtA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="258788797" From: Junjie Cao To: qemu-devel@nongnu.org Cc: jic23@kernel.org, linux-cxl@vger.kernel.org, philmd@oss.qualcomm.com, qemu-stable@nongnu.org Subject: [PATCH v3 1/7] hw/cxl: fix timer leak in cxl_destroy_cci() Date: Wed, 29 Jul 2026 22:46:39 +0800 Message-ID: <20260729144645.1552511-2-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260729144645.1552511-1-junjie.cao@intel.com> References: <20260729144645.1552511-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=198.175.65.16; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -59 X-Spam_score: -6.0 X-Spam_bar: ------ X-Spam_report: (-6.0 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1785336524235158500 cxl_init_cci() allocates a QEMUTimer via timer_new_ms() but cxl_destroy_cci() never frees it. This leaks a timer object on every device exit path and, more critically, on every device reset cycle since the secondary CCIs (vdm_fm_owned_ld_mctp_cci, ld0_cci) are destroyed and re-initialized each time ct3d_reset() runs. Tear the CCI down in the reverse of cxl_init_cci()'s setup order: destroy the mutex, then free the timer. timer_free() cancels any pending expiry via timer_del() internally and tolerates a NULL pointer; clear the field afterwards so that a repeated timer_free() on the same CCI is a safe no-op. (The function as a whole is still not idempotent: qemu_mutex_destroy() asserts on an already-destroyed mutex. Callers must not invoke cxl_destroy_cci() twice; the .initialized guard added in the next patch enforces that.) Fixes: 98cbac128f1c ("hw/cxl: Support aborting background commands") Cc: qemu-stable@nongnu.org Signed-off-by: Junjie Cao Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- hw/cxl/cxl-mailbox-utils.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/hw/cxl/cxl-mailbox-utils.c b/hw/cxl/cxl-mailbox-utils.c index ec18338b42..603677a97b 100644 --- a/hw/cxl/cxl-mailbox-utils.c +++ b/hw/cxl/cxl-mailbox-utils.c @@ -4795,6 +4795,8 @@ void cxl_init_cci(CXLCCI *cci, size_t payload_max) void cxl_destroy_cci(CXLCCI *cci) { qemu_mutex_destroy(&cci->bg.lock); + timer_free(cci->bg.timer); + cci->bg.timer =3D NULL; cci->initialized =3D false; } =20 --=20 2.43.0 From nobody Mon Sep 28 02:01:04 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1785336529; cv=none; d=zohomail.com; s=zohoarc; b=bULyAA9omMlz/Mb49ncGKF2WEEJRJ4ywfDooHqMhf0z2rCpdx80FVQ1m5QI76Wy9Feplr2gYHLU5cBKb6soEoCQne8JwVOP12OBV6LuO/LMOhgwnmecbPlCsJnKpMbA9ILZgZmV9AFv4n6HWEmIxpnc0rvxdhtH4EWynt9fvU6M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785336529; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=KvRrI0o9AArglghN8dd4kNlmnxBri0sUtv1zJaA9F0w=; b=Tm+M/X26RIoy/P2EUmvYfuwZaGM+tcyEDPEFobkBiT/JIMJKdIMWj3fu1E9fOXwyDcO4gpZg5KjcPnNUodL3OEEUYjcSks5lntpW/qNI+yAHUwlj7BuWMchlGyYt3wNkh6hqnjNe4EBLEjpXxx8W97/Lva4DXPVmBISekhBjbiY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785336529262769.5887282411212; Wed, 29 Jul 2026 07:48:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wp5aH-0004PB-Se; Wed, 29 Jul 2026 10:48:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5ZW-0004EL-3y; Wed, 29 Jul 2026 10:47:54 -0400 Received: from mgamail.intel.com ([198.175.65.16]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5ZU-0000PQ-Gq; Wed, 29 Jul 2026 10:47:49 -0400 Received: from orviesa010.jf.intel.com ([10.64.159.150]) by orvoesa108.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:47 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by orviesa010-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:45 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785336468; x=1816872468; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=EKJQjBaNTzDsYQ/c0wEU7XruIeRIsa+KlEE3cSskXJ0=; b=XSZgmrwOM/JPc5Nx0NfJ/ij6byUt6wB47ZY7A5tgPhxe8q5y1+VaQNAs vZffRGGYtaDFIxFiVVxUWKFKUpAObxrCWhAXJuaKNTXgSSqC35WnjXSSi 6bERumeK6D2I6JoJoC8xSS5a8aPz0nY1Nqntr8jtfoZIo449XI93RRZ+G MpwO7Ak/hRCDZKmpAvaWc/avFC7LgEeL3Fw5Y5dKQsTLwaEv0uJI8ID13 adgkz0/33Y+jUvpXxTl9P3T42IQHXxlQMg917s7f7sWM4N+HEHbluNdrV RhDQv6goEXt1w3xc6f203CPI0ud5jl5efqBUXZ7FdLddlRmSFjlhK5lLC w==; X-CSE-ConnectionGUID: uoQJ6+JOR1uGysR2rC5j3A== X-CSE-MsgGUID: vMWKd5PVTyiMArZk00PCrw== X-IronPort-AV: E=McAfee;i="6800,10657,11859"; a="86133616" X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="86133616" X-CSE-ConnectionGUID: XjlcosJtSieexzoMl42BEQ== X-CSE-MsgGUID: z4KMsdawQA2qAUSptPKG8Q== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="258788801" From: Junjie Cao To: qemu-devel@nongnu.org Cc: jic23@kernel.org, linux-cxl@vger.kernel.org, philmd@oss.qualcomm.com, qemu-stable@nongnu.org Subject: [PATCH v3 2/7] hw/cxl: destroy primary CCI before re-initialization on reset Date: Wed, 29 Jul 2026 22:46:40 +0800 Message-ID: <20260729144645.1552511-3-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260729144645.1552511-1-junjie.cao@intel.com> References: <20260729144645.1552511-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=198.175.65.16; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -59 X-Spam_score: -6.0 X-Spam_bar: ------ X-Spam_report: (-6.0 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1785336530313158500 Content-Type: text/plain; charset="utf-8" ct3d_reset() re-initializes the primary CCI through the call chain cxl_device_register_init_t3() -> cxl_initialize_mailbox_t3() -> cxl_init_cci(), but never calls cxl_destroy_cci() first. Each reset cycle therefore leaks the old timer and leaves the old mutex undestroyed while silently overwriting the CCI state. Per CXL r4.0, the "Mailbox Interfaces Ready" bit in the Memory Device Status register (Table 8-212) is set after a Conventional Reset or CXL Reset once the device has re-initialized its mailbox interfaces. The CCI is the software abstraction of these interfaces and must be properly torn down before re-initialization. The secondary CCIs (vdm_fm_owned_ld_mctp_cci, ld0_cci) already follow the correct destroy-before-reinit pattern in the same function; apply the same discipline to the primary CCI. Also destroy the secondary CCIs in ct3_exit() where they were previously leaked at device removal time. Guard the primary CCI teardown there with the same .initialized check used for the secondary CCIs: the primary CCI is only brought up from the reset path (cxl_device_register_init_t3()), so a device that is unrealized before its first reset would otherwise tear down a never-initialized CCI. Fixes: cac36a8faffc ("hw/cxl/mbox: Pull the CCI definition out of the CXLDe= viceState") Cc: qemu-stable@nongnu.org Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index 28f41fa623..d730a25645 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1076,7 +1076,15 @@ static void ct3_exit(PCIDevice *pci_dev) cxl_doe_cdat_release(cxl_cstate); msix_uninit_exclusive_bar(pci_dev); g_free(regs->special_ops); - cxl_destroy_cci(&ct3d->cci); + if (ct3d->cci.initialized) { + cxl_destroy_cci(&ct3d->cci); + } + if (ct3d->vdm_fm_owned_ld_mctp_cci.initialized) { + cxl_destroy_cci(&ct3d->vdm_fm_owned_ld_mctp_cci); + } + if (ct3d->ld0_cci.initialized) { + cxl_destroy_cci(&ct3d->ld0_cci); + } if (ct3d->dc.host_dc) { cxl_destroy_dc_regions(ct3d); address_space_destroy(&ct3d->dc.host_dc_as); @@ -1331,6 +1339,9 @@ static void ct3d_reset(DeviceState *dev) ct3d->flitmode); cxl_component_register_init_common(reg_state, write_msk, CXL2_TYPE3_DEVICE, ct3d->hdmdb); + if (ct3d->cci.initialized) { + cxl_destroy_cci(&ct3d->cci); + } cxl_device_register_init_t3(ct3d, CXL_T3_MSIX_MBOX); =20 /* --=20 2.43.0 From nobody Mon Sep 28 02:01:04 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1785336625; cv=none; d=zohomail.com; s=zohoarc; b=Y0T+4OJNPPUEQu+6PjfR9IB37RdbUEyUDReJ85IHAhJQP2Oky33rM6EnQiRcfqxzlkwn2QEGxPoJ8Ff/LUWqfysawC4w2gC+WNcfU9v9MY+fXb0UZaUa+ZAlGA30aaP9k3hKUiNN01YfguNvNMiHvFWgtqY1tmqek9MDbcYgfLY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785336625; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4dcUyim5Yji/i2GhaafoqM+LnErSZsbxM8jLFkqhyAc=; b=e1VdKiHRBPN2WoNa/ldiYjuKCjAPK1LiSRPKRp9in2ijAHl4FjnXXMKBCDFuLSIMTiNFnu80Y2sMddjhpyqoIqJye1+au41PWAfgf6pSHLBMYoiFdl3Gdw3UTW4a2EVzwbgyLuRtoo4G4epzwzmWdDJ9szaZIEKBcGi7GjwINKo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785336625164437.1951959361186; Wed, 29 Jul 2026 07:50:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wp5aL-0004YK-I8; Wed, 29 Jul 2026 10:48:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5ZY-0004GC-HE; Wed, 29 Jul 2026 10:47:58 -0400 Received: from mgamail.intel.com ([198.175.65.16]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5ZW-0000Pj-Uf; Wed, 29 Jul 2026 10:47:52 -0400 Received: from orviesa010.jf.intel.com ([10.64.159.150]) by orvoesa108.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:49 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by orviesa010-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:48 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785336471; x=1816872471; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=IZkVYtHbGkW+5yL2wuZYKdTkdZ36MHZfVxyXkH+h+HU=; b=gI2/w3TLkH/DJt4AdCtwezrKydzEn/7L2nqhT3rpdiOhbMP7xJ7QtJdh 1CwhDjMRIak3tySR0IQcXCwfP7fgOjWFMmxzIoy5hnCIpfNz4e3ztH1gk Kc9GE8WJsyMZdlIdnRBGJ7hiTjoeUesfeq/hivOirxUZ/fZMMdJu1ptns pmOKCG1LA+m52a+aLGU5bALNobmGhfKmAMLSUnu9V9QOEI8clKxBgWKOv DcyjGOx7GAM7szbl1Qbx9cbkisdCUKdlNWcIqrfQcMQxBQZQOkO4KBSDs g7/WMrEi3ijZ/FxN7bRxZaugDctLOtFijQJQCpX80ZKUNKJTfOXveK2mJ w==; X-CSE-ConnectionGUID: YLoRavJCRSellTxnqCr8+A== X-CSE-MsgGUID: vtPttHi0TYCjV1VhTGgM0Q== X-IronPort-AV: E=McAfee;i="6800,10657,11859"; a="86133622" X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="86133622" X-CSE-ConnectionGUID: TtCttvBERSuJ8I4sUEQB5g== X-CSE-MsgGUID: bl4qEm4nQ5azkvwTzO3sDw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="258788806" From: Junjie Cao To: qemu-devel@nongnu.org Cc: jic23@kernel.org, linux-cxl@vger.kernel.org, philmd@oss.qualcomm.com, qemu-stable@nongnu.org Subject: [PATCH v3 3/7] hw/cxl: convert cxl-type3 to three-phase reset Date: Wed, 29 Jul 2026 22:46:41 +0800 Message-ID: <20260729144645.1552511-4-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260729144645.1552511-1-junjie.cao@intel.com> References: <20260729144645.1552511-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=198.175.65.16; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -59 X-Spam_score: -6.0 X-Spam_bar: ------ X-Spam_report: (-6.0 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1785336626821158500 Replace the deprecated device_class_set_legacy_reset() registration with the three-phase resettable interface, following the pattern already established by the CXL root port (cxl_rp_reset_hold). Only the hold phase is needed; enter and exit are left NULL. The parent hold phase is chained for correctness: TYPE_PCI_DEVICE installs no hold phase today, so parent_phases.hold is currently NULL and the chained call is a no-op, but capturing and invoking it is the correct forward-compatible pattern and mirrors cxl_rp_reset_hold(). No functional change =E2=80=94 the reset body is identical; only the registration path and function signature change. Signed-off-by: Junjie Cao Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- hw/mem/cxl_type3.c | 16 ++++++++++++---- include/hw/cxl/cxl_device.h | 2 ++ 2 files changed, 14 insertions(+), 4 deletions(-) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index d730a25645..ce2cb6558c 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1329,13 +1329,18 @@ MemTxResult cxl_type3_write(PCIDevice *d, hwaddr ho= st_addr, uint64_t data, return address_space_write(as, dpa_offset, attrs, &data, size); } =20 -static void ct3d_reset(DeviceState *dev) +static void ct3d_reset_hold(Object *obj, ResetType type) { - CXLType3Dev *ct3d =3D CXL_TYPE3(dev); + CXLType3Dev *ct3d =3D CXL_TYPE3(obj); + CXLType3Class *cvc =3D CXL_TYPE3_GET_CLASS(obj); uint32_t *reg_state =3D ct3d->cxl_cstate.crb.cache_mem_registers; uint32_t *write_msk =3D ct3d->cxl_cstate.crb.cache_mem_regs_write_mask; =20 - pcie_cap_fill_link_ep_usp(PCI_DEVICE(dev), ct3d->width, ct3d->speed, + if (cvc->parent_phases.hold) { + cvc->parent_phases.hold(obj, type); + } + + pcie_cap_fill_link_ep_usp(PCI_DEVICE(obj), ct3d->width, ct3d->speed, ct3d->flitmode); cxl_component_register_init_common(reg_state, write_msk, CXL2_TYPE3_DEVICE, ct3d->hdmdb); @@ -2467,6 +2472,7 @@ static void ct3_class_init(ObjectClass *oc, const voi= d *data) DeviceClass *dc =3D DEVICE_CLASS(oc); PCIDeviceClass *pc =3D PCI_DEVICE_CLASS(oc); CXLType3Class *cvc =3D CXL_TYPE3_CLASS(oc); + ResettableClass *rc =3D RESETTABLE_CLASS(oc); =20 pc->realize =3D ct3_realize; pc->exit =3D ct3_exit; @@ -2480,9 +2486,11 @@ static void ct3_class_init(ObjectClass *oc, const vo= id *data) =20 set_bit(DEVICE_CATEGORY_STORAGE, dc->categories); dc->desc =3D "CXL Memory Device (Type 3)"; - device_class_set_legacy_reset(dc, ct3d_reset); device_class_set_props(dc, ct3_props); =20 + resettable_class_set_parent_phases(rc, NULL, ct3d_reset_hold, NULL, + &cvc->parent_phases); + cvc->get_lsa_size =3D get_lsa_size; cvc->get_lsa =3D get_lsa; cvc->set_lsa =3D set_lsa; diff --git a/include/hw/cxl/cxl_device.h b/include/hw/cxl/cxl_device.h index ba551fa5f9..b7e20e3fe4 100644 --- a/include/hw/cxl/cxl_device.h +++ b/include/hw/cxl/cxl_device.h @@ -805,6 +805,8 @@ struct CXLType3Class { /* Private */ PCIDeviceClass parent_class; =20 + ResettablePhases parent_phases; + /* public */ uint64_t (*get_lsa_size)(CXLType3Dev *ct3d); =20 --=20 2.43.0 From nobody Mon Sep 28 02:01:04 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1785336521; cv=none; d=zohomail.com; s=zohoarc; b=O1v0ZLubFzZ96KQmO6ul+klrLGS+AS2YDl65DoQhNW8tAz0s7ubVK9xSEePjOvxdQnTjf+sX0Yhod6wmzHMRVACGhWicgsJ4WryT64p1hx82X1u2+FJn03wrQbzIdknNmys/XD5liR7ZoopgKo+L4fCxbkLIYIEJu+PMIb3fyuc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785336521; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=SsL0OKW9eCsNXlXpZrGPih1EcPVxcM95tzixrcZ8ZVU=; b=Dj7tTYZ8KPb/lzwQ2i7ycNLalIUhFINsxM73Ee6AZy2iHdyH65jshvFwCQeiSabpLoKYk5APoWcx4Of1+H9b+jakO4nc8HiyEl2g5zS83rOWScl7PuR1NRp8cPCgJUn4X6/4Sba6yAswUGByiecYdTpBqWnjG66mZCRR0zL21Fc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785336521156550.43733309671; Wed, 29 Jul 2026 07:48:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wp5aD-0004LF-R6; Wed, 29 Jul 2026 10:48:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5Ze-0004GV-Tr; Wed, 29 Jul 2026 10:48:02 -0400 Received: from mgamail.intel.com ([198.175.65.16]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5Zb-0000PQ-77; Wed, 29 Jul 2026 10:47:58 -0400 Received: from orviesa010.jf.intel.com ([10.64.159.150]) by orvoesa108.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:51 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by orviesa010-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:50 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785336475; x=1816872475; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=+XEqTvJkhJL8Zjzo3UW1sPiWBb9hzsCcLzLQ1Vw9yso=; b=Sf5X/aOsR1N+djP5G63np0XML8QQoY2+mA+zJTdPvBhjwElEnp8jiyzo AP3mX4R0hIdQ6vzPlFnWT//1NS7JAvlgJbqk+lZqIs5OPsHSMRQDDc3kC dgBetPEcN/AHOu79FrM5mkxT2CB4j+MwPDT3lroBN3j+3dqHAebuvKuIQ jqxkLZtGPL749Sx0K08aiVrMLZwfiZGrHDyAxthBAhShcJF8alTh1hyAv k83Y74DbX5fQBn7Lh6S8UJNc6XveLHy2fvwOFiCAlRgUvPxdJZlAktojP JDpQ/HfNofN9D94GSPjt5fZoVUMfCe85zyoMbJepEZ95hCqYlIEe5TjMN w==; X-CSE-ConnectionGUID: E3x9Us+sSCaIb+ktoHLuvg== X-CSE-MsgGUID: BxT5VkXER7e+vTKnJfI/nA== X-IronPort-AV: E=McAfee;i="6800,10657,11859"; a="86133627" X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="86133627" X-CSE-ConnectionGUID: lNn4tTa/RfuIF7wDg75jtQ== X-CSE-MsgGUID: AEbLXD/WRHa2Js+/w/uCxg== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="258788810" From: Junjie Cao To: qemu-devel@nongnu.org Cc: jic23@kernel.org, linux-cxl@vger.kernel.org, philmd@oss.qualcomm.com, qemu-stable@nongnu.org Subject: [PATCH v3 4/7] hw/cxl: add cxl_destroy_mailbox_t3() as the mailbox teardown counterpart Date: Wed, 29 Jul 2026 22:46:42 +0800 Message-ID: <20260729144645.1552511-5-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260729144645.1552511-1-junjie.cao@intel.com> References: <20260729144645.1552511-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=198.175.65.16; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -59 X-Spam_score: -6.0 X-Spam_bar: ------ X-Spam_report: (-6.0 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1785336522214158500 The primary CCI teardown is open-coded, guarded by .initialized, at the two places that need it: the reset path (before cxl_device_register_init_t3() brings the mailbox back up) and ct3_exit(). Factor it into cxl_destroy_mailbox_t3(), the teardown counterpart of cxl_initialize_mailbox_t3(), keeping the .initialized guard inside the helper: the primary CCI is only brought up from the reset path, so the first reset after realize and an unrealize before any reset must both skip the teardown. No functional change. Suggested-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Junjie Cao Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- hw/cxl/cxl-mailbox-utils.c | 7 +++++++ hw/mem/cxl_type3.c | 8 ++------ include/hw/cxl/cxl_device.h | 1 + 3 files changed, 10 insertions(+), 6 deletions(-) diff --git a/hw/cxl/cxl-mailbox-utils.c b/hw/cxl/cxl-mailbox-utils.c index 603677a97b..bc00fec9f8 100644 --- a/hw/cxl/cxl-mailbox-utils.c +++ b/hw/cxl/cxl-mailbox-utils.c @@ -4843,6 +4843,13 @@ void cxl_initialize_mailbox_t3(CXLCCI *cci, DeviceSt= ate *d, size_t payload_max) cxl_init_cci(cci, payload_max); } =20 +void cxl_destroy_mailbox_t3(CXLType3Dev *ct3d) +{ + if (ct3d->cci.initialized) { + cxl_destroy_cci(&ct3d->cci); + } +} + static const struct cxl_cmd cxl_cmd_set_t3_ld[256][256] =3D { [INFOSTAT][IS_IDENTIFY] =3D { "IDENTIFY", cmd_infostat_identify, 0, 0 = }, [LOGS][GET_SUPPORTED] =3D { "LOGS_GET_SUPPORTED", cmd_logs_get_support= ed, 0, diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index ce2cb6558c..3a5eea76f2 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1076,9 +1076,7 @@ static void ct3_exit(PCIDevice *pci_dev) cxl_doe_cdat_release(cxl_cstate); msix_uninit_exclusive_bar(pci_dev); g_free(regs->special_ops); - if (ct3d->cci.initialized) { - cxl_destroy_cci(&ct3d->cci); - } + cxl_destroy_mailbox_t3(ct3d); if (ct3d->vdm_fm_owned_ld_mctp_cci.initialized) { cxl_destroy_cci(&ct3d->vdm_fm_owned_ld_mctp_cci); } @@ -1344,9 +1342,7 @@ static void ct3d_reset_hold(Object *obj, ResetType ty= pe) ct3d->flitmode); cxl_component_register_init_common(reg_state, write_msk, CXL2_TYPE3_DEVICE, ct3d->hdmdb); - if (ct3d->cci.initialized) { - cxl_destroy_cci(&ct3d->cci); - } + cxl_destroy_mailbox_t3(ct3d); cxl_device_register_init_t3(ct3d, CXL_T3_MSIX_MBOX); =20 /* diff --git a/include/hw/cxl/cxl_device.h b/include/hw/cxl/cxl_device.h index b7e20e3fe4..608d05165a 100644 --- a/include/hw/cxl/cxl_device.h +++ b/include/hw/cxl/cxl_device.h @@ -325,6 +325,7 @@ CXL_DEVICE_CAPABILITY_HEADER_REGISTER(MEMORY_DEVICE, CXL_DEVICE_CAP_REG_SIZE * 2) =20 void cxl_initialize_mailbox_t3(CXLCCI *cci, DeviceState *d, size_t payload= _max); +void cxl_destroy_mailbox_t3(CXLType3Dev *ct3d); void cxl_initialize_mailbox_swcci(CXLCCI *cci, DeviceState *intf, DeviceState *d, size_t payload_max); void cxl_init_cci(CXLCCI *cci, size_t payload_max); --=20 2.43.0 From nobody Mon Sep 28 02:01:04 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1785336603; cv=none; d=zohomail.com; s=zohoarc; b=XZ+0jS90itRLHN/LhivCUcZdRZRB5qW/IAlsgqZ1I8A5GkqXlIRqAPRxzJ9/r0YmkaHvJYtUcbYJET2IgsinLXrzCLVPFPXEj/PBxYW5HoWKwOXLvK+P8Tt8sUInASW9CbaV+j/EYKNvgd0wERhhttn94sEqnLBn3gkNboHY3wQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785336603; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9oOSEt/5vHDOFtGnGtTsmWm9I8W60tH2R1aRJa2W6U4=; b=futq3iH/V2Ehk320CLdvfdmyRQoG8BFS80OV3QlSo0R21JiImOKoRLKdSiwgTJrxHbS7bID8Ujp4PEdw8NmOqhT/ngwEbzjQoq1b1wb5lsaxYG/rZ4LUkyIgJnXhqNZioFzVpn/An6BdenLzHey/3erYL3d8VEADWy5LRyRNdyY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785336603638295.1949531210073; Wed, 29 Jul 2026 07:50:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wp5aK-0004Uy-Kw; Wed, 29 Jul 2026 10:48:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5Zf-0004GW-AK; Wed, 29 Jul 2026 10:48:03 -0400 Received: from mgamail.intel.com ([198.175.65.16]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5Zb-0000Pj-7M; Wed, 29 Jul 2026 10:47:59 -0400 Received: from orviesa010.jf.intel.com ([10.64.159.150]) by orvoesa108.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:54 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by orviesa010-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:52 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785336475; x=1816872475; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=vbh6j/yVXhjUgJsuEkmBoPmh0Q2oLphjP1TzurM+BmM=; b=FkqVOPOJuuZsRtqkTm5M0rNQK6gMbDGNTV7Tl9Pu4JaZi+P3B7COlfez vwoX1yN9uSj+tduUUbk1R9sTBuc1KidvNW/IxbQETsdNifcwFSiyJuvkV b5VcHbDfbBcBQmRwYiWpN/1hZH6ozudMxWB8nq2vqScGfA4Jfcg5WsxqG +DwFqxkFc6x9AaEfKKn1NMrTEjuHJjz7gLnwa+2waKapYlXrf9nSdnEES Q8h1fKAv1FAo0Z7FQIA06vYGXDhgYDQqur6Kt4UvORO4TpEz3w43vScJX HXBe/DtXsJiYW86OA6wZH+c71iH87+fxDB2OZZiLd6o5E/Jc1wG6d/VG1 g==; X-CSE-ConnectionGUID: I4eLWUTcS/mibUi1kU5W3A== X-CSE-MsgGUID: gf2ln6PYSMyk96SeKfcsrQ== X-IronPort-AV: E=McAfee;i="6800,10657,11859"; a="86133634" X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="86133634" X-CSE-ConnectionGUID: d0yMF8R2RsqTRxp/mGLOKw== X-CSE-MsgGUID: t6i3EbevR36Zs68m4BAXkA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="258788811" From: Junjie Cao To: qemu-devel@nongnu.org Cc: jic23@kernel.org, linux-cxl@vger.kernel.org, philmd@oss.qualcomm.com, qemu-stable@nongnu.org Subject: [PATCH v3 5/7] hw/cxl: discard in-flight sanitize state on mailbox teardown Date: Wed, 29 Jul 2026 22:46:43 +0800 Message-ID: <20260729144645.1552511-6-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260729144645.1552511-1-junjie.cao@intel.com> References: <20260729144645.1552511-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=198.175.65.16; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -59 X-Spam_score: -6.0 X-Spam_bar: ------ X-Spam_report: (-6.0 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1785336604907158500 Per CXL r4.0 Section 8.2.9.4, "Background commands do not continue to execute across Conventional Resets." If a Media Operations sanitize is in progress when the device is reset, the background timer is cancelled and freed via cxl_destroy_cci(), but the per-operation state (media_op_sanitize) is heap-allocated separately and would be leaked. Free it from cxl_destroy_mailbox_t3(): the timer that advances the operation lives in the CCI torn down there, so the operation can never complete once the mailbox is gone; preserving the heap state has no benefit and would leak it the next time media_op_sanitize is assigned. Routing the discard through the mailbox teardown also covers device unrealize, where ct3_exit() previously leaked an in-flight sanitize. The completion path in __do_sanitize() frees the same state; factor the free into a cxl_discard_media_op_sanitize() helper used by both places, so the whole media_op_sanitize lifecycle now stays within cxl-mailbox-utils.c. Note that Section 8.2.10.9.5.1 additionally requires a device whose Sanitize was interrupted by reset to remain in the Media Disabled state until a successful Sanitize completes. That latch is not modelled here (reset re-enables media via memdev_reg_init_common()) and is left for future work; this patch only addresses the resource leak. Suggested-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Junjie Cao --- hw/cxl/cxl-mailbox-utils.c | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/hw/cxl/cxl-mailbox-utils.c b/hw/cxl/cxl-mailbox-utils.c index bc00fec9f8..cbd6ebf9fe 100644 --- a/hw/cxl/cxl-mailbox-utils.c +++ b/hw/cxl/cxl-mailbox-utils.c @@ -2636,6 +2636,12 @@ static int sanitize_range(CXLType3Dev *ct3d, uint64_= t dpa_addr, size_t length, return address_space_set(as, dpa_addr, fill_value, length, mem_attrs); } =20 +static void cxl_discard_media_op_sanitize(CXLType3Dev *ct3d) +{ + g_free(ct3d->media_op_sanitize); + ct3d->media_op_sanitize =3D NULL; +} + /* Perform the actual device zeroing */ static void __do_sanitize(CXLType3Dev *ct3d) { @@ -2653,8 +2659,7 @@ static void __do_sanitize(CXLType3Dev *ct3d) } } exit: - g_free(ct3d->media_op_sanitize); - ct3d->media_op_sanitize =3D NULL; + cxl_discard_media_op_sanitize(ct3d); return; } =20 @@ -4848,6 +4853,12 @@ void cxl_destroy_mailbox_t3(CXLType3Dev *ct3d) if (ct3d->cci.initialized) { cxl_destroy_cci(&ct3d->cci); } + /* + * An in-flight Media Operations sanitize is only advanced by this CCI= 's + * background timer; with the CCI gone the operation can never complet= e, + * so its state would otherwise be leaked (CXL r4.0 Section 8.2.9.4). + */ + cxl_discard_media_op_sanitize(ct3d); } =20 static const struct cxl_cmd cxl_cmd_set_t3_ld[256][256] =3D { --=20 2.43.0 From nobody Mon Sep 28 02:01:04 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1785336613; cv=none; d=zohomail.com; s=zohoarc; b=bBJEYg72iftaDUjX38f5PfZDuYxd4qhSckTqoxhu9t2cOeLjXm/5cNlYAp6Mfgf1vCINI6Z+8+PhsInveFvCXjxAJnjGcye6+e7nZdlVf5FOPQEhSqrrnQ65I+hv3rB22JmIpfJyO4O7QOqAU9Yus5lHx9uZP899sWtp+N82LBY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785336613; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6gbxZbT5G0JCLWa/8N02BN2BRN/ssJO3o/8kTzHVbaY=; b=CCpz/Op8BLWTKBg+6mz9S9fTY/GNH+EcliOH/sFSlFDnOnDpWPj0wDkE/J4MSgpQbjMnZo1Q9Pakx/FvzpUnDf4WBzEs5u7bXpmi4P4uJvGfN8dTjuqI9amkA0WqJGTKtuKdbQALQma0GJcT0YWBBBSrNTs4l8RKMvVg6fQeXvU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785336613526861.0957142669392; Wed, 29 Jul 2026 07:50:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wp5aM-0004a7-3L; Wed, 29 Jul 2026 10:48:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5Zg-0004GX-12; Wed, 29 Jul 2026 10:48:03 -0400 Received: from mgamail.intel.com ([198.175.65.16]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5Ze-0000Qq-BI; Wed, 29 Jul 2026 10:47:59 -0400 Received: from orviesa010.jf.intel.com ([10.64.159.150]) by orvoesa108.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:56 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by orviesa010-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:55 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785336478; x=1816872478; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=0LPXenqXy+FBHwOhYVrUaTV2tGSOIChI14pMrmNyX60=; b=kEMtzvfH/4a/6P3DeoiMWh6GF4oFmSTo9l33dDUidZX4Xud47CZ/jkni qEEhzrxwTPsvaVam48PgkKBX/rulSc92ud1JKDk9D9UblBgXRNOKpkIMF DC5qApewiWsiNLjxGOYTlI5IBpJ7ZRGR/LsGrIsA0JMlfV11LjjdXRcwo RV6tJ+4ItKHG8+Ue8PUivi9dtmRlM00q1zF116jvzk4vkB03feHZgFJ2V wai6MzOjkwa/gZ8WQkJUJ9x0TmGm1IFTlJRLUT0cl8IEizg9p4au7g6Me BLy2na80V3j9pFaRlvIdBCfy1/N462odG9ckuVFPJ37Tws5sxgnP/A9T4 Q==; X-CSE-ConnectionGUID: A8WOmvzrQvyFt3PUg8WgpA== X-CSE-MsgGUID: ayPW1yOYTMSm90PQtL7xPg== X-IronPort-AV: E=McAfee;i="6800,10657,11859"; a="86133640" X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="86133640" X-CSE-ConnectionGUID: 254ZiHc/QHGUWJcThx+Qyw== X-CSE-MsgGUID: jgAzanGPQ7ylU6UXzgpNiA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="258788847" From: Junjie Cao To: qemu-devel@nongnu.org Cc: jic23@kernel.org, linux-cxl@vger.kernel.org, philmd@oss.qualcomm.com, qemu-stable@nongnu.org Subject: [PATCH v3 6/7] hw/cxl: clear event logs, scan media and interrupt policy on reset Date: Wed, 29 Jul 2026 22:46:44 +0800 Message-ID: <20260729144645.1552511-7-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260729144645.1552511-1-junjie.cao@intel.com> References: <20260729144645.1552511-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=198.175.65.16; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -59 X-Spam_score: -6.0 X-Spam_bar: ------ X-Spam_report: (-6.0 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1785336614801158500 Content-Type: text/plain; charset="utf-8" Event records, scan media results and event interrupt settings are device-internal dynamic state that should not survive a device reset. Per CXL r4.0 Section 8.2.10.9.4.6 (Get Scan Media Results), "If the Scan Media command has not been called since the last Conventional Reset, the device shall return the Unsupported return code." This explicitly invalidates scan media results across reset, so clear the scan_media_hasrun flag. Per CXL r4.0 Section 8.2.10.2.5 (Set Event Interrupt Policy), "All event log interrupt settings shall be reset to 00b (No Interrupts) by the device on Conventional Reset." Clear irq_enabled for every event log accordingly. For the event records there is no direct spec mandate to drop the stored records on reset; the Event Status register (Table 8-203) is non-sticky and resets to zero per Section 9.7, and no reset flavor requires the already-reported records to persist. Draining the queues is therefore a reasonable modelling choice that keeps the records consistent with the freshly-reset status register, rather than a spec requirement. Call the existing cxl_discard_all_event_records() helper to drain all event queues. The event log infrastructure itself (mutexes, IRQ vectors) remains intact as it is initialized once during device realize. This is also where reset-type gating begins: a wakeup from suspend-to-RAM (RESET_TYPE_WAKEUP) is not a Conventional or CXL Reset and must retain device-internal state, so the hold phase returns early for that type before discarding any records. This mirrors the RESET_TYPE_WAKEUP shortcut in virtio-mem and virtio-balloon. Only the unconditional mailbox interface re-initialization and the in-flight sanitize free (whose backing timer was already destroyed) run on a wakeup. Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index 3a5eea76f2..2392358071 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1360,6 +1360,23 @@ static void ct3d_reset_hold(Object *obj, ResetType t= ype) } cxl_initialize_t3_ld_cci(&ct3d->ld0_cci, DEVICE(ct3d), DEVICE(ct3d), 512); /* Max payload made up */ + + /* + * A wakeup from suspend-to-RAM is not a Conventional or CXL Reset. T= he + * device-internal dynamic state cleared below (event logs, scan media + * results, and the poison/feature-transfer state cleared in subsequent + * patches) must be preserved across resume, so stop here for a wakeup. + * virtio-mem and virtio-balloon take the same RESET_TYPE_WAKEUP short= cut. + */ + if (type =3D=3D RESET_TYPE_WAKEUP) { + return; + } + + cxl_discard_all_event_records(&ct3d->cxl_dstate); + for (int i =3D 0; i < CXL_EVENT_TYPE_MAX; i++) { + ct3d->cxl_dstate.event_logs[i].irq_enabled =3D false; + } + ct3d->scan_media_hasrun =3D false; } =20 static const Property ct3_props[] =3D { --=20 2.43.0 From nobody Mon Sep 28 02:01:04 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1785336542; cv=none; d=zohomail.com; s=zohoarc; b=GNPetFfOa4u3p2Aar0K6ZyzaU3uoEfkBFbghtAL8HDzvax07Vq+L+hNfpccPBmKdVN0SX77YtC2CsUjuI1fF+igaphw+Rl9afvaqGGEk4SKY48e6mF4w75gszwTeGiu8SCt1bod/nyiWQqRCv9+bjeAtVjdiuWN0LHyzcxgBnX4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785336542; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Ud25FsRPw/DBflFQNm2Ge4l96ZpEcVZDV04jki5jAHo=; b=UBaHVujek0LO5O4cAGUNyEs6dwo8lfLt/uYyplqsuR9R9CA7232NoWvfYxiL9qeLUGVNbO4XNf4sTHGtyNlp8Kr/5yBNyxd4roLFaruEhaZtaS2ONLU4BKMjjn2upri54a8h44bPUEAafbCF7zrkWyjGkCDd5yBor18Y/tvtSLQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785336542468243.2987045429777; Wed, 29 Jul 2026 07:49:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wp5aL-0004YU-Ju; Wed, 29 Jul 2026 10:48:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5Zh-0004Gk-Ew; Wed, 29 Jul 2026 10:48:03 -0400 Received: from mgamail.intel.com ([198.175.65.16]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wp5Zf-0000PQ-Pu; Wed, 29 Jul 2026 10:48:01 -0400 Received: from orviesa010.jf.intel.com ([10.64.159.150]) by orvoesa108.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:58 -0700 Received: from junjie-desk-dev.bj.intel.com (HELO junjie-desk-dev.tail2c02c1.ts.net) ([10.238.152.71]) by orviesa010-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2026 07:47:57 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785336479; x=1816872479; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=TTMOY2fZFNZ9to25DAyguXipu7ZylHJM05ZnvGrBuk0=; b=j6qC1yXkgab+Kas29py0IrrYtXUohQoJuu8oD8hWVwktxNQt165hH0TQ vq3L0gCB4On+fsd3T4TlgCJPtAFFGqxrln/384sZmOpdQMD5Efq5Itcaz BkJPM0S/xmDEYCYG1Szx5FBwku176m+k4qZMMd7UIpLePfMM+J7Yu8luU h42pyxHDn2YXqMNCaLyTystJDvM3oAn2v5jDBKd+kdCxXi/tInrmJANq1 d6XLI5pI/s/xR/dfHv4yG9kF6ZidCZINLCSqCSwKCfkDXmA0ZuSagPj/c 8MiREyEsbqFWWy+Y7WK0EFtG3q8CWOAHIEDVR5tN8s/RW354PgCPM1puH Q==; X-CSE-ConnectionGUID: kvvga2BnS4iXZF10zQx2/A== X-CSE-MsgGUID: a82qhxr/R3iZxJGfwxDaXA== X-IronPort-AV: E=McAfee;i="6800,10657,11859"; a="86133649" X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="86133649" X-CSE-ConnectionGUID: DIRx8iN+TkyZQuHNiBIh1g== X-CSE-MsgGUID: xxtaG2MHSyege38di/25Zg== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,192,1779174000"; d="scan'208";a="258788881" From: Junjie Cao To: qemu-devel@nongnu.org Cc: jic23@kernel.org, linux-cxl@vger.kernel.org, philmd@oss.qualcomm.com, qemu-stable@nongnu.org Subject: [PATCH v3 7/7] hw/cxl: clear poison lists and feature transfer state on reset Date: Wed, 29 Jul 2026 22:46:45 +0800 Message-ID: <20260729144645.1552511-8-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260729144645.1552511-1-junjie.cao@intel.com> References: <20260729144645.1552511-1-junjie.cao@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=198.175.65.16; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -59 X-Spam_score: -6.0 X-Spam_bar: ------ X-Spam_report: (-6.0 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1785336544358158500 The poison lists (active, backup, and scan-media results), their associated overflow tracking, and the Set Feature partial-transfer state are all device-internal dynamic state that accumulates during the device's lifetime. Per CXL r4.0 Table 8-309 (Identify Memory Device), the "Injects Persistent Poison" capability bit (offset 41h, Bit[0]) controls poison retention across reset. When cleared =E2=80=94 the QEMU default =E2=80=94 = "a Conventional Reset or CXL Reset shall automatically clear the injected poison." Clear all poison lists accordingly, reusing the existing cxl_clear_poison_list_overflowed() helper for the overflow tracking. For the Set Feature transfer state, CXL r4.0 Section 8.2.10.6.3 (Set Feature) requires: "If the Feature data transfer is interrupted by a Conventional Reset or a CXL Reset, the Feature data transfer shall be aborted by the device [...] the device shall require the Feature data transfer to be started from the beginning." Zero set_feat_info on reset so any partially transferred Set Feature is abandoned and must restart from the beginning. Both clears run after the RESET_TYPE_WAKEUP early-return added in the previous patch, so this state is preserved across a suspend-to-RAM wakeup. Signed-off-by: Junjie Cao --- hw/mem/cxl_type3.c | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index 2392358071..0b36485344 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1327,6 +1327,16 @@ MemTxResult cxl_type3_write(PCIDevice *d, hwaddr hos= t_addr, uint64_t data, return address_space_write(as, dpa_offset, attrs, &data, size); } =20 +static void ct3d_clear_poison_list(CXLPoisonList *list) +{ + CXLPoison *ent, *next; + + QLIST_FOREACH_SAFE(ent, list, node, next) { + QLIST_REMOVE(ent, node); + g_free(ent); + } +} + static void ct3d_reset_hold(Object *obj, ResetType type) { CXLType3Dev *ct3d =3D CXL_TYPE3(obj); @@ -1377,6 +1387,14 @@ static void ct3d_reset_hold(Object *obj, ResetType t= ype) ct3d->cxl_dstate.event_logs[i].irq_enabled =3D false; } ct3d->scan_media_hasrun =3D false; + + ct3d_clear_poison_list(&ct3d->poison_list); + ct3d_clear_poison_list(&ct3d->poison_list_bkp); + ct3d_clear_poison_list(&ct3d->scan_media_results); + ct3d->poison_list_cnt =3D 0; + cxl_clear_poison_list_overflowed(ct3d); + + memset(&ct3d->set_feat_info, 0, sizeof(ct3d->set_feat_info)); } =20 static const Property ct3_props[] =3D { --=20 2.43.0