From nobody Mon Sep 28 01:12:52 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785679169; cv=none; d=zohomail.com; s=zohoarc; b=laZuGqRUzp5s2zejfrEPjJ55qbam1g7kdZs4YBIPSG4EDENpk4obyuVOmSW18snac4XQPpmBPUFY8ka7wieY5Mltc+vPiOfns14J7kCLrPEshQhJi/8FJM/RZC7fMvB3p6dD9SdpKdwvk9Nvwh8FKSznRn7tOm0AQvRLrPtXk1U= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785679169; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=59CkK+F73vfPSocFJQz/NNuH2cbrOatJZOUKvDr9AI0=; b=FEvwYDLv2W+hhh8jIJBtdc+a7428qCLQFZ7poYg8awgL1FPXNGz69gzzVVPrqaM6BNWxt/vdg/Gt5oIYmOe0Dn79GPkdAukBmVnydXrogVPLditLmjZK7B/ebHtmtDgp+ZHXZqW5TatsZcgjJZi6tO7URarIA21Irld5UAFbExs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785679169362290.1321666412823; Sun, 2 Aug 2026 06:59:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wqWiS-0003fV-Mj; Sun, 02 Aug 2026 09:59:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wqWiO-0003eX-2V for qemu-devel@nongnu.org; Sun, 02 Aug 2026 09:58:57 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wqWiM-0002wE-Cf for qemu-devel@nongnu.org; Sun, 02 Aug 2026 09:58:55 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-458-7a25NvP3OnyV8a1HPefFYA-1; Sun, 02 Aug 2026 09:58:52 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 4DFB019560B2; Sun, 2 Aug 2026 13:58:51 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.32.25]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 117B430002E9; Sun, 2 Aug 2026 13:58:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785679133; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=59CkK+F73vfPSocFJQz/NNuH2cbrOatJZOUKvDr9AI0=; b=LocporsihnNo1Mu6qZy96+H6UUD9ZsXFCqOJYRrjPC+1pMi5DXQGYL3Hc+LtRczeLkdGxc AhNTwikjhYRe+Cb0bYh6/qlD5aCXrxhxzQhp9oUcEU6lSi3HlBJ+e/8wIyQw62WMGwawxX OtR1ExU270t2QEEJwQ62FbBmfYUh3+8= X-MC-Unique: 7a25NvP3OnyV8a1HPefFYA-1 X-Mimecast-MFC-AGG-ID: 7a25NvP3OnyV8a1HPefFYA_1785679131 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: "Tycho Andersen (AMD)" , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 1/2] hw/vfio: Fix liveness check in vfio_connect_kvm_msi_virq() Date: Sun, 2 Aug 2026 15:58:45 +0200 Message-ID: <20260802135846.328866-2-clg@redhat.com> In-Reply-To: <20260802135846.328866-1-clg@redhat.com> References: <20260802135846.328866-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 4 X-Spam_score: 0.4 X-Spam_bar: / X-Spam_report: (0.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.811, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785679172014158500 From: "Tycho Andersen (AMD)" While working on savevm/loadvm for a new vfio device, I encountered the crash below. Since vfio_connect_kvm_msi_virq() didn't check the ->use flag for the vector, it would pass an unused vector down to vfio_cpr_load_vector_fd() which would crash. Fix this by checking the ->use flag along with the virq number to detect whether a vector is valid or not. Thread 1 "qemu-system-x86" received signal SIGSEGV, Segmentation fault. 0x0000555555a891ef in vfio_cpr_load_vector_fd (vdev=3Dvdev@entry=3D0x0, name=3Dname@entry=3D0x555555eeb27e "kvm_interrupt", nr=3Dnr@entry=3D1) = at ../hw/vfio/cpr.c:44 44 g_autofree char *fdname =3D STRDUP_VECTOR_FD_NAME(vdev, name); (gdb) bt #0 0x0000555555a891ef in vfio_cpr_load_vector_fd (vdev=3Dvdev@entry=3D0x0, name=3Dname@entry=3D0x555555eeb27e "kvm_inter= rupt", nr=3Dnr@entry=3D1) at ../hw/vfio/cpr.c:44 #1 0x0000555555ce64a1 in vfio_notifier_init (vdev=3D0x0, e=3De@entry=3D0x5555586971b4, name=3Dname@entry=3D0x555555= eeb27e "kvm_interrupt", nr=3Dnr@entry=3D1, errp=3Derrp@entry=3D0x0) at ../h= w/vfio/pci.c:79 #2 0x0000555555ce721e in vfio_connect_kvm_msi_virq (vector=3D0x5555586971a= 8, nr=3Dnr@entry=3D1) at ../hw/vfio/pci.c:601 #3 0x0000555555cea5a5 in vfio_connect_kvm_msi_virq (nr=3D1, vector=3D) at ../hw/vfio/pci.c:597 #4 vfio_pci_commit_kvm_msi_virq_batch (vdev=3D0x55555906de40) at ../hw/vfi= o/pci.c:822 #5 0x0000555555cea9f2 in vfio_msix_enable (vdev=3Dvdev@entry=3D0x55555906d= e40) at ../hw/vfio/pci.c:850 #6 0x0000555555ceb152 in vfio_pci_load_config (vbasedev=3D0x55555906e900, = f=3D) at ../hw/vfio/pci.c:3088 #7 0x0000555555a8c765 in vfio_load_device_config_state (f=3D0x5555574a43d0= , opaque=3D0x55555906e900) at ../hw/vfio/migration.c:278 #8 0x0000555555b3a522 in vmstate_load (f=3Df@entry=3D0x5555574a43d0, se=3Dse@entry=3D0x5555591edd40, errp=3De= rrp@entry=3D0x7fffffffe130) at ../migration/savevm.c:971 #9 0x0000555555b3ab1a in qemu_loadvm_section_start_full (f=3Df@entry=3D0x5555574a43d0, type=3Dtype@entry=3D4 '\004', errp=3Derr= p@entry=3D0x7fffffffe130) at ../migration/savevm.c:2654 #10 0x0000555555b3e1ee in qemu_loadvm_state_main (f=3Df@entry=3D0x5555574a43d0, mis=3Dmis@entry=3D0x5555571de5a0, errp= =3D0x7fffffffe130, errp@entry=3D0x555557157c10 ) at ../migration/savevm.c:2973 #11 0x0000555555b3f7b7 in qemu_loadvm_state (f=3Df@entry=3D0x5555574a43d0, errp=3Derrp@entry=3D0x555557157c10 ) at ../migration/savevm.c:3058 #12 0x0000555555b40863 in load_snapshot (name=3D0x7fffffffecc9 "foo", vmstate=3Dvmstate@entry=3D0x0, has_device= s=3Dhas_devices@entry=3Dfalse, devices=3Ddevices@entry=3D0x0, errp=3Derrp@e= ntry=3D0x555557157c10 ) at ../migration/savevm.c:3452 #13 0x0000555555adc211 in qmp_x_exit_preconfig (errp=3D0x555557157c10 ) at ../system/vl.c:2817 #14 qmp_x_exit_preconfig (errp=3D0x555557157c10 ) at ../system= /vl.c:2802 #15 0x0000555555adf8ed in qemu_init (argc=3D, argv=3D) at ../system/vl.c:3849 #16 0x00005555558903fd in main (argc=3D, argv=3D) at ../system/main.c:71 Fixes: 30edcb4d4e7a ("vfio-pci: preserve MSI") Signed-off-by: Tycho Andersen (AMD) Reviewed-by: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260727150038.2684512-1-tycho@ker= nel.org Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio/pci.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c index 380dd8c15f8d5bb98b725075978eef2e4e1e6c2d..b5280c3d2a366cd7cff40699368= 58ac651afeb6d 100644 --- a/hw/vfio/pci.c +++ b/hw/vfio/pci.c @@ -589,7 +589,7 @@ static void vfio_connect_kvm_msi_virq(VFIOMSIVector *ve= ctor, int nr) { const char *name =3D "kvm_interrupt"; =20 - if (vector->virq < 0) { + if (!vector->use || vector->virq < 0) { return; } =20 --=20 2.55.0 From nobody Mon Sep 28 01:12:52 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785679169; cv=none; d=zohomail.com; s=zohoarc; b=fRu9/+kI6ZLUZht0/RXXM/7+YZXsPa+zWMJb6b3yN4FSn/3Rozlz7qIkBLeNA+Eh2W4/Dw6j7xNTHerZlrwk8SfuFlxc0qsyi+GZltlANpukJoEaN2oA/WChXD06Q9nKMMv3cQ4qAhM5tUZGew3FScpVQ/WvWF9Pp8nc9lRK/PM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785679169; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=oe30+pZLs7ebCtt568b7pWAkTjVmXsh5LCbTA0CdRNI=; b=IYr1rdEhUE4aIvuA68JgL+a3pum1Ik6nitFroH3t+MS/JtE3eKiiuuUw0V47ODiw2I5iWYljj36JqKgCVTGRyZoYiGVmoZjp/t1XaSJtL1LywxJUAqxdwoc+/uTfU2oJwSep2ChJF9Qb3LL5WIHNfAXVDKep7hUMl1T1yEJA5Jc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785679169169954.5250100622737; Sun, 2 Aug 2026 06:59:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wqWiS-0003fM-3x; Sun, 02 Aug 2026 09:59:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wqWiP-0003el-NZ for qemu-devel@nongnu.org; Sun, 02 Aug 2026 09:58:57 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wqWiO-0002wO-3a for qemu-devel@nongnu.org; Sun, 02 Aug 2026 09:58:57 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-26-a5_nIiiOOGKVvJnWbEgjCA-1; Sun, 02 Aug 2026 09:58:53 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 01A061956089; Sun, 2 Aug 2026 13:58:53 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.32.25]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id BD65130002E9; Sun, 2 Aug 2026 13:58:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785679135; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=oe30+pZLs7ebCtt568b7pWAkTjVmXsh5LCbTA0CdRNI=; b=FztpZSXOtR97HJrIIYEmeGvkaStpYSK71Ehwtx0WjxOsLtbjZ0ZIjuQr1UbzwZuG6cJmiz 7REl1X0aremipDuINWtHYug2nZ3DUZOlE6MIo8Vk7rP56DjGeBb6hrcSU/TllvjVlVlx0P vFY3gyNKq8CpjEa87MAJ1NZEb3aXdCA= X-MC-Unique: a5_nIiiOOGKVvJnWbEgjCA-1 X-Mimecast-MFC-AGG-ID: a5_nIiiOOGKVvJnWbEgjCA_1785679133 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Magnus Kulke Subject: [PULL 2/2] vfio/pci: Guard accel_irqchip_begin_route_changes() calls Date: Sun, 2 Aug 2026 15:58:46 +0200 Message-ID: <20260802135846.328866-3-clg@redhat.com> In-Reply-To: <20260802135846.328866-1-clg@redhat.com> References: <20260802135846.328866-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 4 X-Spam_score: 0.4 X-Spam_bar: / X-Spam_report: (0.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.811, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785679171981158500 Since commit 49b2dcbd2422 ("accel/accel-irq: add generic begin_route_changes"), accel_irqchip_begin_route_changes() aborts when no accelerator irqchip is available. This causes a fatal error when running VFIO passthrough devices under TCG emulation: qemu-system-aarch64: can't initiate route change, no accel irqchip availa= ble The previous kvm_irqchip_begin_route_changes() was a simple inline that did not have a fatal path. The VFIO code already handles the absence of KVM MSI routing gracefully by falling back to userspace handling, but the new generic function aborts before that fallback can take effect. Guard the call sites in hw/vfio/pci.c with accel_msi_via_irqfd_enabled() so that route changes are only initiated when an accelerator irqchip is actually present. Fixes: 49b2dcbd2422 ("accel/accel-irq: add generic begin_route_changes") Cc: Magnus Kulke Link: https://lore.kernel.org/qemu-devel/20260721105026.3932297-1-clg@redha= t.com Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio/pci.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c index b5280c3d2a366cd7cff4069936858ac651afeb6d..428ab2f06983ba9ecb306975a4a= ca7f6efe1b855 100644 --- a/hw/vfio/pci.c +++ b/hw/vfio/pci.c @@ -699,7 +699,7 @@ static int vfio_msix_vector_do_use(PCIDevice *pdev, uns= igned int nr, if (msg) { if (vdev->defer_kvm_irq_routing) { vfio_pci_add_kvm_msi_virq(vdev, vector, nr, true); - } else { + } else if (accel_msi_via_irqfd_enabled()) { vfio_route_change =3D accel_irqchip_begin_route_changes(); vfio_pci_add_kvm_msi_virq(vdev, vector, nr, true); accel_irqchip_commit_route_changes(&vfio_route_change); @@ -801,7 +801,9 @@ void vfio_pci_prepare_kvm_msi_virq_batch(VFIOPCIDevice = *vdev) { assert(!vdev->defer_kvm_irq_routing); vdev->defer_kvm_irq_routing =3D true; - vfio_route_change =3D accel_irqchip_begin_route_changes(); + if (accel_msi_via_irqfd_enabled()) { + vfio_route_change =3D accel_irqchip_begin_route_changes(); + } } =20 void vfio_pci_commit_kvm_msi_virq_batch(VFIOPCIDevice *vdev) --=20 2.55.0