From nobody Mon Sep 28 01:17:51 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178635088298638.98579003362238; Mon, 10 Aug 2026 01:34:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtLSb-0001bb-5o; Mon, 10 Aug 2026 04:34:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRk-0001QF-TU for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:33 -0400 Received: from [115.124.28.146] (helo=out28-146.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRh-0005Bp-1U for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:23 -0400 Received: from localhost.localdomain(mailfrom:zhang_wei@open-hieco.net fp:SMTPD_---.iiL7hJD_1786350659 cluster:ay29) by smtp.aliyun-inc.com; Mon, 10 Aug 2026 16:30:59 +0800 X-Alimail-AntiSpam: AC=CONTINUE; BC=0.07436259|-1; CH=green; DM=|CONTINUE|false|; DS=CONTINUE|ham_alarm|0.0320193-0.00123147-0.966749; FP=16717333417464172249|0|0|0|0|-1|-1|-1; HT=maildocker-contentspam033037006180; MF=zhang_wei@open-hieco.net; NM=1; PH=DS; RN=9; RT=9; SR=0; TI=SMTPD_---.iiL7hJD_1786350659; From: Tina Zhang To: qemu-devel@nongnu.org Cc: kvm@vger.kernel.org, "Michael S . Tsirkin" , Paolo Bonzini , Marcelo Tosatti , Zhao Liu , Yanjing Zhou , Tina Zhang , Yongwei Xu Subject: [PATCH v2 1/9] target/i386: Sync AMD CPUID aliases for Hygon Date: Mon, 10 Aug 2026 16:29:48 +0800 Message-ID: <20260810082956.1768042-2-zhang_wei@open-hieco.net> X-Mailer: git-send-email 2.43.7 In-Reply-To: <20260810082956.1768042-1-zhang_wei@open-hieco.net> References: <20260810082956.1768042-1-zhang_wei@open-hieco.net> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.28.146 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.28.146; envelope-from=zhang_wei@open-hieco.net; helo=out28-146.mail.aliyun.com X-Spam_score_int: -10 X-Spam_score: -1.1 X-Spam_bar: - X-Spam_report: (-1.1 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1786350885231158500 Content-Type: text/plain; charset="utf-8" AMD defines CPUID[0x80000001].EDX bits as aliases for a subset of CPUID[1].EDX. QEMU currently synchronizes those aliases only when the guest CPU vendor is AuthenticAMD. Hygon Dhyana uses the HygonGenuine vendor string, but implements the same AMD-compatible extended CPUID feature aliases. This can leave QEMU advertising a feature in CPUID[1].EDX while the matching extended alias in CPUID[0x80000001].EDX stays clear. This inconsistent CPUID state can confuse guest OS feature detection. Apply the alias synchronization to Hygon CPUs as well. Gate the new behavior with x-hygon-vendor-abi-fixes and disable it for pc-11.0 and older machine types, because the CPUID result is guest-visible ABI and must remain migration-compatible. Add qtest coverage for the Dhyana model, including the compat property. Signed-off-by: Tina Zhang Tested-by: Yongwei Xu --- hw/i386/pc.c | 5 ++ hw/i386/pc_piix.c | 1 + hw/i386/pc_q35.c | 1 + include/hw/i386/pc.h | 3 ++ target/i386/cpu.c | 10 ++-- target/i386/cpu.h | 13 +++++ tests/qtest/test-x86-cpuid-compat.c | 76 +++++++++++++++++++++++++++++ 7 files changed, 106 insertions(+), 3 deletions(-) diff --git a/hw/i386/pc.c b/hw/i386/pc.c index f064aa2b3e..2b4e322b2f 100644 --- a/hw/i386/pc.c +++ b/hw/i386/pc.c @@ -74,6 +74,11 @@ #include "hw/xen/xen-bus.h" #endif =20 +GlobalProperty pc_compat_11_1[] =3D { + { TYPE_X86_CPU, "x-hygon-vendor-abi-fixes", "false" }, +}; +const size_t pc_compat_11_1_len =3D G_N_ELEMENTS(pc_compat_11_1); + GlobalProperty pc_compat_11_0[] =3D {}; const size_t pc_compat_11_0_len =3D G_N_ELEMENTS(pc_compat_11_0); =20 diff --git a/hw/i386/pc_piix.c b/hw/i386/pc_piix.c index 82457bdb16..8e58f2a7ee 100644 --- a/hw/i386/pc_piix.c +++ b/hw/i386/pc_piix.c @@ -438,6 +438,7 @@ DEFINE_I440FX_MACHINE_AS_LATEST(11, 1); static void pc_i440fx_machine_11_0_options(MachineClass *m) { pc_i440fx_machine_11_1_options(m); + compat_props_add(m->compat_props, pc_compat_11_1, pc_compat_11_1_len); compat_props_add(m->compat_props, hw_compat_11_0, hw_compat_11_0_len); compat_props_add(m->compat_props, pc_compat_11_0, pc_compat_11_0_len); } diff --git a/hw/i386/pc_q35.c b/hw/i386/pc_q35.c index 6c1e4eff5f..fd4366f51f 100644 --- a/hw/i386/pc_q35.c +++ b/hw/i386/pc_q35.c @@ -393,6 +393,7 @@ DEFINE_Q35_MACHINE_AS_LATEST(11, 1); static void pc_q35_machine_11_0_options(MachineClass *m) { pc_q35_machine_11_1_options(m); + compat_props_add(m->compat_props, pc_compat_11_1, pc_compat_11_1_len); compat_props_add(m->compat_props, hw_compat_11_0, hw_compat_11_0_len); compat_props_add(m->compat_props, pc_compat_11_0, pc_compat_11_0_len); } diff --git a/include/hw/i386/pc.h b/include/hw/i386/pc.h index d4b6d3ed57..ac03da97b6 100644 --- a/include/hw/i386/pc.h +++ b/include/hw/i386/pc.h @@ -209,6 +209,9 @@ void pc_system_parse_ovmf_flash(uint8_t *flash_ptr, siz= e_t flash_size); /* sgx.c */ void pc_machine_init_sgx_epc(PCMachineState *pcms); =20 +extern GlobalProperty pc_compat_11_1[]; +extern const size_t pc_compat_11_1_len; + extern GlobalProperty pc_compat_11_0[]; extern const size_t pc_compat_11_0_len; =20 diff --git a/target/i386/cpu.c b/target/i386/cpu.c index 5805d33ab9..2d1542ad17 100644 --- a/target/i386/cpu.c +++ b/target/i386/cpu.c @@ -10147,10 +10147,12 @@ static void x86_cpu_realizefn(DeviceState *dev, E= rror **errp) } } =20 - /* On AMD CPUs, some CPUID[8000_0001].EDX bits must match the bits on - * CPUID[1].EDX. + /* + * CPUs that use AMD-compatible extended CPUID aliases must keep selec= ted + * CPUID[0x80000001].EDX bits synchronized with CPUID[1].EDX. */ - if (IS_AMD_CPU(env)) { + if (IS_AMD_CPU(env) || + (cpu->hygon_vendor_abi_fixes && IS_HYGON_CPU(env))) { env->features[FEAT_8000_0001_EDX] &=3D ~CPUID_EXT2_AMD_ALIASES; env->features[FEAT_8000_0001_EDX] |=3D (env->features[FEAT_1_EDX] & CPUID_EXT2_AMD_ALIASES); @@ -10810,6 +10812,8 @@ static const Property x86_cpu_properties[] =3D { DEFINE_PROP_BOOL("cpuid-0xb", X86CPU, enable_cpuid_0xb, true), DEFINE_PROP_BOOL("x-vendor-cpuid-only", X86CPU, vendor_cpuid_only, tru= e), DEFINE_PROP_BOOL("x-vendor-cpuid-only-v2", X86CPU, vendor_cpuid_only_v= 2, true), + DEFINE_PROP_BOOL("x-hygon-vendor-abi-fixes", X86CPU, + hygon_vendor_abi_fixes, true), DEFINE_PROP_BOOL("x-amd-topoext-features-only", X86CPU, amd_topoext_fe= atures_only, true), DEFINE_PROP_BOOL("lmce", X86CPU, enable_lmce, false), DEFINE_PROP_BOOL("l3-cache", X86CPU, enable_l3_cache, true), diff --git a/target/i386/cpu.h b/target/i386/cpu.h index e6a197602d..491c911139 100644 --- a/target/i386/cpu.h +++ b/target/i386/cpu.h @@ -1281,6 +1281,9 @@ uint64_t x86_cpu_get_supported_feature_word(X86CPU *c= pu, FeatureWord w); #define CPUID_VENDOR_ZHAOXIN1 "CentaurHauls" #define CPUID_VENDOR_ZHAOXIN2 " Shanghai " =20 +#define CPUID_VENDOR_HYGON_1 0x6f677948 /* "Hygo" */ +#define CPUID_VENDOR_HYGON_2 0x6e65476e /* "nGen" */ +#define CPUID_VENDOR_HYGON_3 0x656e6975 /* "uine" */ #define CPUID_VENDOR_HYGON "HygonGenuine" =20 #define IS_INTEL_CPU(env) ((env)->cpuid_vendor1 =3D=3D CPUID_VENDOR_INTEL_= 1 && \ @@ -1289,6 +1292,9 @@ uint64_t x86_cpu_get_supported_feature_word(X86CPU *c= pu, FeatureWord w); #define IS_AMD_CPU(env) ((env)->cpuid_vendor1 =3D=3D CPUID_VENDOR_AMD_1 &&= \ (env)->cpuid_vendor2 =3D=3D CPUID_VENDOR_AMD_2 &&= \ (env)->cpuid_vendor3 =3D=3D CPUID_VENDOR_AMD_3) +#define IS_HYGON_CPU(env) ((env)->cpuid_vendor1 =3D=3D CPUID_VENDOR_HYGON_= 1 && \ + (env)->cpuid_vendor2 =3D=3D CPUID_VENDOR_HYGON_= 2 && \ + (env)->cpuid_vendor3 =3D=3D CPUID_VENDOR_HYGON_= 3) #define IS_ZHAOXIN1_CPU(env) \ ((env)->cpuid_vendor1 =3D=3D CPUID_VENDOR_ZHAOXIN1_1 && \ (env)->cpuid_vendor2 =3D=3D CPUID_VENDOR_ZHAOXIN1_2 && \ @@ -2461,6 +2467,13 @@ struct ArchCPU { */ bool vendor_cpuid_only_v2; =20 + /* + * Compatibility bit for old machine types: if true, apply Hygon + * vendor-specific ABI fixes. Old machine types disable this to prese= rve + * the guest-visible CPU ABI. + */ + bool hygon_vendor_abi_fixes; + /* Only advertise TOPOEXT features that AMD defines */ bool amd_topoext_features_only; =20 diff --git a/tests/qtest/test-x86-cpuid-compat.c b/tests/qtest/test-x86-cpu= id-compat.c index 17c0965827..b7f8834052 100644 --- a/tests/qtest/test-x86-cpuid-compat.c +++ b/tests/qtest/test-x86-cpuid-compat.c @@ -113,6 +113,21 @@ typedef struct FeatureTestArgs { bool expected_value; } FeatureTestArgs; =20 +typedef struct BoolPropTestArgs { + /* Test name */ + const char *name; + /* CPU type */ + const char *cpu; + /* CPU features (may be NULL) */ + const char *cpufeat; + /* machine type (may be NULL to use default machine) */ + const char *machine; + /* CPU property to read */ + const char *property; + /* expected value of the property */ + bool expected_value; +} BoolPropTestArgs; + /* Get the value for a feature word in a X86CPUFeatureWordInfo list */ static uint32_t get_feature_word(QList *features, uint32_t eax, uint32_t e= cx, const char *reg) @@ -170,6 +185,38 @@ static void test_feature_flag(const void *data) g_free(cmdline); } =20 +static void test_bool_prop(const void *data) +{ + const BoolPropTestArgs *args =3D data; + char *cmdline; + char *save; + char *path; + bool value; + + cmdline =3D g_strdup_printf("-cpu %s", args->cpu); + + if (args->cpufeat) { + save =3D cmdline; + cmdline =3D g_strdup_printf("%s,%s", cmdline, args->cpufeat); + g_free(save); + } + if (args->machine) { + save =3D cmdline; + cmdline =3D g_strdup_printf("-machine %s %s", args->machine, cmdli= ne); + g_free(save); + } + + qtest_start(cmdline); + path =3D get_cpu0_qom_path(); + value =3D qom_get_bool(path, args->property); + qtest_end(); + + g_assert_cmpint(value, =3D=3D, args->expected_value); + + g_free(path); + g_free(cmdline); +} + static void test_plus_minus_subprocess(void) { char *path; @@ -407,6 +454,28 @@ static const FeatureTestArgs feature_tests[] =3D { "max", "mmx=3Doff", 1, 0, "EDX", 23, false, }, + { + "x86/cpuid/features/dhyana/ext-mmx", + "Dhyana", NULL, + 0x80000001, 0, "EDX", 23, true, + }, + { + "x86/cpuid/features/dhyana/ext-mmx/compat-off", + "Dhyana", "x-hygon-vendor-abi-fixes=3Doff", + 0x80000001, 0, "EDX", 23, false, + }, +}; + +static const BoolPropTestArgs bool_prop_tests[] =3D { + { + "x86/cpuid/props/dhyana/hygon-vendor-abi-fixes/default", + "Dhyana", NULL, NULL, "x-hygon-vendor-abi-fixes", true, + }, + { + "x86/cpuid/props/dhyana/hygon-vendor-abi-fixes/pc-i440fx-11.0", + "Dhyana", NULL, "pc-i440fx-11.0", + "x-hygon-vendor-abi-fixes", false, + }, }; =20 int main(int argc, char **argv) @@ -433,6 +502,13 @@ int main(int argc, char **argv) qtest_add_data_func(feature_tests[i].name, &feature_tests[i], test_feature_flag); } + for (int i =3D 0; i < ARRAY_SIZE(bool_prop_tests); i++) { + if (!qtest_has_cpu_model(bool_prop_tests[i].cpu)) { + continue; + } + qtest_add_data_func(bool_prop_tests[i].name, + &bool_prop_tests[i], test_bool_prop); + } =20 return g_test_run(); } --=20 2.43.7 From nobody Mon Sep 28 01:17:51 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786350907169532.1871539012527; Mon, 10 Aug 2026 01:35:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtLSe-0001cF-5w; Mon, 10 Aug 2026 04:34:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRn-0001QM-1F for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:33 -0400 Received: from [115.124.28.99] (helo=out28-99.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRh-0005Bw-4N for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:26 -0400 Received: from localhost.localdomain(mailfrom:zhang_wei@open-hieco.net fp:SMTPD_---.iiL7hK3_1786350659 cluster:ay29) by smtp.aliyun-inc.com; Mon, 10 Aug 2026 16:31:00 +0800 X-Alimail-AntiSpam: AC=CONTINUE; BC=0.07438566|-1; CH=green; DM=|CONTINUE|false|; DS=CONTINUE|ham_alarm|0.0855287-0.00298891-0.911482; FP=7196578113995211987|1|1|1|0|-1|-1|-1; HT=maildocker-contentspam033032023038; MF=zhang_wei@open-hieco.net; NM=1; PH=DS; RN=8; RT=8; SR=0; TI=SMTPD_---.iiL7hK3_1786350659; From: Tina Zhang To: qemu-devel@nongnu.org Cc: kvm@vger.kernel.org, "Michael S . Tsirkin" , Paolo Bonzini , Marcelo Tosatti , Zhao Liu , Yanjing Zhou , Tina Zhang Subject: [PATCH v2 2/9] target/i386: Hide Intel cache CPUID leaves for Hygon Date: Mon, 10 Aug 2026 16:29:49 +0800 Message-ID: <20260810082956.1768042-3-zhang_wei@open-hieco.net> X-Mailer: git-send-email 2.43.7 In-Reply-To: <20260810082956.1768042-1-zhang_wei@open-hieco.net> References: <20260810082956.1768042-1-zhang_wei@open-hieco.net> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.28.99 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.28.99; envelope-from=zhang_wei@open-hieco.net; helo=out28-99.mail.aliyun.com X-Spam_score_int: -10 X-Spam_score: -1.1 X-Spam_bar: - X-Spam_report: (-1.1 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1786350909025158500 Content-Type: text/plain; charset="utf-8" When x-vendor-cpuid-only is enabled, QEMU suppresses CPUID leaves 2 and 4 for AuthenticAMD CPUs because those leaves describe Intel cache information. Hygon Dhyana uses the HygonGenuine vendor string, so it currently skips that filtering and can expose Intel cache leaves together with AMD/Hygon extended cache leaves. That is inconsistent guest-visible CPUID: Hygon Dhyana provides cache information through the extended cache leaves, so it should not also advertise the Intel cache descriptor and deterministic cache parameter leaves. Apply the same leaf 2 and leaf 4 filtering to Hygon CPUs when the vendor CPU ABI compat gate is enabled. The gate keeps the old CPUID output for pc-11.0 and older machine types. Signed-off-by: Tina Zhang Reviewed-by: Zhao Liu --- target/i386/cpu.c | 19 +++++++++++++++++-- 1 file changed, 17 insertions(+), 2 deletions(-) diff --git a/target/i386/cpu.c b/target/i386/cpu.c index 2d1542ad17..ad94fa755c 100644 --- a/target/i386/cpu.c +++ b/target/i386/cpu.c @@ -8608,6 +8608,21 @@ uint32_t cpu_x86_virtual_addr_width(CPUX86State *env) } } =20 +/* + * CPUID leaves 2 and 4 describe Intel cache information. AMD CPUs use + * extended cache leaves instead, and Hygon Dhyana follows that AMD/Hygon + * convention. Enable the corrected Hygon behavior only for machine types + * where the CPU ABI compat gate is on. + */ +static bool x86_cpu_filter_intel_cache_leaves(const X86CPU *cpu) +{ + const CPUX86State *env =3D &cpu->env; + + return cpu->vendor_cpuid_only && + (IS_AMD_CPU(env) || + (cpu->hygon_vendor_abi_fixes && IS_HYGON_CPU(env))); +} + void cpu_x86_cpuid(CPUX86State *env, uint32_t index, uint32_t count, uint32_t *eax, uint32_t *ebx, uint32_t *ecx, uint32_t *edx) @@ -8693,7 +8708,7 @@ void cpu_x86_cpuid(CPUX86State *env, uint32_t index, = uint32_t count, if (cpu->cache_info_passthrough) { x86_cpu_get_cache_cpuid(index, 0, eax, ebx, ecx, edx); break; - } else if (cpu->vendor_cpuid_only && IS_AMD_CPU(env)) { + } else if (x86_cpu_filter_intel_cache_leaves(cpu)) { *eax =3D *ebx =3D *ecx =3D *edx =3D 0; break; } @@ -8729,7 +8744,7 @@ void cpu_x86_cpuid(CPUX86State *env, uint32_t index, = uint32_t count, CPU_TOPOLOGY_LEVEL_SOCKET), 4095) << 14; } } - } else if (cpu->vendor_cpuid_only && IS_AMD_CPU(env)) { + } else if (x86_cpu_filter_intel_cache_leaves(cpu)) { *eax =3D *ebx =3D *ecx =3D *edx =3D 0; } else { *eax =3D 0; --=20 2.43.7 From nobody Mon Sep 28 01:17:51 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786350883642942.9485489677053; Mon, 10 Aug 2026 01:34:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtLSY-0001WX-BI; Mon, 10 Aug 2026 04:34:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRl-0001QH-2j for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:33 -0400 Received: from [115.124.28.125] (helo=out28-125.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRh-0005Bx-Hs for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:24 -0400 Received: from localhost.localdomain(mailfrom:zhang_wei@open-hieco.net fp:SMTPD_---.iiL7hL8_1786350660 cluster:ay29) by smtp.aliyun-inc.com; Mon, 10 Aug 2026 16:31:01 +0800 X-Alimail-AntiSpam: AC=CONTINUE; BC=0.07441887|-1; CH=green; DM=|CONTINUE|false|; DS=CONTINUE|ham_regular_dialog|0.00345733-0.000296969-0.996246; FP=7196549941702542555|1|1|1|0|-1|-1|-1; HT=maildocker-contentspam033037026024; MF=zhang_wei@open-hieco.net; NM=1; PH=DS; RN=8; RT=8; SR=0; TI=SMTPD_---.iiL7hL8_1786350660; From: Tina Zhang To: qemu-devel@nongnu.org Cc: kvm@vger.kernel.org, "Michael S . Tsirkin" , Paolo Bonzini , Marcelo Tosatti , Zhao Liu , Yanjing Zhou , Tina Zhang Subject: [PATCH v2 3/9] target/i386: Hide ARCH_CAPABILITIES for Hygon Date: Mon, 10 Aug 2026 16:29:50 +0800 Message-ID: <20260810082956.1768042-4-zhang_wei@open-hieco.net> X-Mailer: git-send-email 2.43.7 In-Reply-To: <20260810082956.1768042-1-zhang_wei@open-hieco.net> References: <20260810082956.1768042-1-zhang_wei@open-hieco.net> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.28.125 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.28.125; envelope-from=zhang_wei@open-hieco.net; helo=out28-125.mail.aliyun.com X-Spam_score_int: -10 X-Spam_score: -1.1 X-Spam_bar: - X-Spam_report: (-1.1 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1786350885184158500 Content-Type: text/plain; charset="utf-8" IA32_ARCH_CAPABILITIES is an Intel-defined MSR. KVM can synthesize the CPUID bit and read-only MSR for non-Intel guests, and QEMU already hides that interface for AMD CPU models because Windows may not expect it on AMD-compatible CPUs. Hygon Dhyana uses the HygonGenuine vendor string, so it currently skips that AMD filter. If arch-capabilities=3Don is requested, QEMU can expose CPUID.7.0.EDX[ARCH_CAPABILITIES] and the associated MSR feature word to a Hygon guest. That creates a vendor-inconsistent CPU ABI: the guest sees an AMD-compatible vendor and cache/topology interface, but also sees an Intel-specific architectural capabilities MSR. Guests that choose CPU mitigation or feature paths from the vendor can mis-handle that combination; Windows is known to be sensitive to ARCH_CAPABILITIES on AMD-compatible CPUs. Apply the same ARCH_CAPABILITIES hiding rule to Hygon CPUs when the vendor CPU ABI compat gate is enabled. Keep arch_cap_always_on as the migration escape hatch, and keep the old Hygon CPUID/MSR output for pc-11.0 and older machine types via x-hygon-vendor-abi-fixes=3Dfalse. Signed-off-by: Tina Zhang Reviewed-by: Zhao Liu --- target/i386/cpu.c | 33 ++++++++++++++++++++++++--------- 1 file changed, 24 insertions(+), 9 deletions(-) diff --git a/target/i386/cpu.c b/target/i386/cpu.c index ad94fa755c..569ef785ca 100644 --- a/target/i386/cpu.c +++ b/target/i386/cpu.c @@ -8209,6 +8209,8 @@ static uint8_t x86_cpu_get_host_avx10_version(void) return ebx & 0xff; } =20 +static bool x86_cpu_should_hide_arch_capabilities(const X86CPU *cpu); + uint64_t x86_cpu_get_supported_feature_word(X86CPU *cpu, FeatureWord w) { FeatureWordInfo *wi =3D &feature_word_info[w]; @@ -8294,15 +8296,7 @@ uint64_t x86_cpu_get_supported_feature_word(X86CPU *= cpu, FeatureWord w) break; =20 case FEAT_7_0_EDX: - /* - * Windows does not like ARCH_CAPABILITIES on AMD machines at all. - * Do not show the fake ARCH_CAPABILITIES MSR that KVM sets up, - * except if needed for migration. - * - * When arch_cap_always_on is removed, this tweak can move to - * kvm_arch_get_supported_cpuid. - */ - if (cpu && IS_AMD_CPU(&cpu->env) && !cpu->arch_cap_always_on) { + if (cpu && x86_cpu_should_hide_arch_capabilities(cpu)) { unavail =3D CPUID_7_0_EDX_ARCH_CAPABILITIES; } break; @@ -8608,6 +8602,27 @@ uint32_t cpu_x86_virtual_addr_width(CPUX86State *env) } } =20 +/* + * Windows does not like ARCH_CAPABILITIES on AMD machines at all. + * Do not show the fake ARCH_CAPABILITIES MSR that KVM sets up, + * except if needed for migration. Apply the same rule to Hygon CPUs when + * the corrected vendor CPU ABI is enabled. + * + * When arch_cap_always_on is removed, this tweak can move to + * kvm_arch_get_supported_cpuid. + */ +static bool x86_cpu_should_hide_arch_capabilities(const X86CPU *cpu) +{ + const CPUX86State *env =3D &cpu->env; + + if (cpu->arch_cap_always_on) { + return false; + } + + return IS_AMD_CPU(env) || + (cpu->hygon_vendor_abi_fixes && IS_HYGON_CPU(env)); +} + /* * CPUID leaves 2 and 4 describe Intel cache information. AMD CPUs use * extended cache leaves instead, and Hygon Dhyana follows that AMD/Hygon --=20 2.43.7 From nobody Mon Sep 28 01:17:51 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786350913687888.9509796922174; Mon, 10 Aug 2026 01:35:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtLSe-0001ca-OD; Mon, 10 Aug 2026 04:34:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRl-0001QI-6Y for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:33 -0400 Received: from [115.124.28.51] (helo=out28-51.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRh-0005C2-4t for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:24 -0400 Received: from localhost.localdomain(mailfrom:zhang_wei@open-hieco.net fp:SMTPD_---.iiL7hML_1786350661 cluster:ay29) by smtp.aliyun-inc.com; Mon, 10 Aug 2026 16:31:01 +0800 X-Alimail-AntiSpam: AC=CONTINUE; BC=0.08302353|-1; CH=green; DM=|CONTINUE|false|; DS=CONTINUE|ham_regular_dialog|0.195864-0.0147222-0.789414; FP=3152376357097244031|1|1|1|0|-1|-1|-1; HT=maildocker-contentspam033045220102; MF=zhang_wei@open-hieco.net; NM=1; PH=DS; RN=8; RT=8; SR=0; TI=SMTPD_---.iiL7hML_1786350661; From: Tina Zhang To: qemu-devel@nongnu.org Cc: kvm@vger.kernel.org, "Michael S . Tsirkin" , Paolo Bonzini , Marcelo Tosatti , Zhao Liu , Yanjing Zhou , Tina Zhang Subject: [PATCH v2 4/9] target/i386/kvm: Use AMD MCE status encoding for Hygon Date: Mon, 10 Aug 2026 16:29:51 +0800 Message-ID: <20260810082956.1768042-5-zhang_wei@open-hieco.net> X-Mailer: git-send-email 2.43.7 In-Reply-To: <20260810082956.1768042-1-zhang_wei@open-hieco.net> References: <20260810082956.1768042-1-zhang_wei@open-hieco.net> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.28.51 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.28.51; envelope-from=zhang_wei@open-hieco.net; helo=out28-51.mail.aliyun.com X-Spam_score_int: -10 X-Spam_score: -1.1 X-Spam_bar: - X-Spam_report: (-1.1 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1786350915059158500 Content-Type: text/plain; charset="utf-8" QEMU's KVM memory-failure injection path builds synthetic MCI_STATUS records for the guest CPU. The status encoding is vendor-specific: Intel-style records use bits such as MCI_STATUS_S and MCI_STATUS_AR for action-required events, while the AMD path uses the AMD memory-failure encoding. Today QEMU selects the AMD status encoding only for AuthenticAMD guests. Hygon guests should use the AMD status encoding as well, but currently get Intel-style injected status bits, including MCI_STATUS_S and MCI_STATUS_AR for action-required events, and a non-deferred action-optional record. That can prevent a guest OS running on the Hygon CPU model from handling the injected MCE correctly. Use the AMD injected-memory-failure MCE status encoding for Hygon guests as well. This does not depend on Hygon exposing CPUID 0x80000007.EBX recovery features such as SUCCOR, and it does not advertise any new recovery capability. The change is limited to QEMU's synthetic KVM memory-failure MCE status; it does not change CPUID, MCE bank state, or migrated CPU state. Signed-off-by: Tina Zhang Reviewed-by: Zhao Liu --- target/i386/kvm/kvm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/target/i386/kvm/kvm.c b/target/i386/kvm/kvm.c index 4272b6770c..aa32b74f10 100644 --- a/target/i386/kvm/kvm.c +++ b/target/i386/kvm/kvm.c @@ -707,7 +707,7 @@ static void kvm_mce_inject(X86CPU *cpu, hwaddr paddr, i= nt code) uint64_t mcg_status =3D MCG_STATUS_MCIP | MCG_STATUS_RIPV; int flags =3D 0; =20 - if (!IS_AMD_CPU(env)) { + if (!IS_AMD_CPU(env) && !IS_HYGON_CPU(env)) { status |=3D MCI_STATUS_S | MCI_STATUS_UC; if (code =3D=3D BUS_MCEERR_AR) { status |=3D MCI_STATUS_AR | 0x134; --=20 2.43.7 From nobody Mon Sep 28 01:17:51 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786350896327577.1225351958121; Mon, 10 Aug 2026 01:34:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtLSY-0001WW-Bn; Mon, 10 Aug 2026 04:34:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRl-0001QJ-SI for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:33 -0400 Received: from [115.124.28.5] (helo=out28-5.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRh-0005C5-3z for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:25 -0400 Received: from localhost.localdomain(mailfrom:zhang_wei@open-hieco.net fp:SMTPD_---.iiL7hNB_1786350662 cluster:ay29) by smtp.aliyun-inc.com; Mon, 10 Aug 2026 16:31:02 +0800 X-Alimail-AntiSpam: AC=CONTINUE; BC=0.07436259|-1; CH=green; DM=|CONTINUE|false|; DS=CONTINUE|ham_regular_dialog|0.00967293-0.000767904-0.989559; FP=7743778515548045655|1|1|1|0|-1|-1|-1; HT=maildocker-contentspam033037028158; MF=zhang_wei@open-hieco.net; NM=1; PH=DS; RN=8; RT=8; SR=0; TI=SMTPD_---.iiL7hNB_1786350662; From: Tina Zhang To: qemu-devel@nongnu.org Cc: kvm@vger.kernel.org, "Michael S . Tsirkin" , Paolo Bonzini , Marcelo Tosatti , Zhao Liu , Yanjing Zhou , Tina Zhang Subject: [PATCH v2 5/9] target/i386/kvm: Use AMD PMU MSR paths for Hygon Date: Mon, 10 Aug 2026 16:29:52 +0800 Message-ID: <20260810082956.1768042-6-zhang_wei@open-hieco.net> X-Mailer: git-send-email 2.43.7 In-Reply-To: <20260810082956.1768042-1-zhang_wei@open-hieco.net> References: <20260810082956.1768042-1-zhang_wei@open-hieco.net> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.28.5 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.28.5; envelope-from=zhang_wei@open-hieco.net; helo=out28-5.mail.aliyun.com X-Spam_score_int: -10 X-Spam_score: -1.1 X-Spam_bar: - X-Spam_report: (-1.1 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1786350897164158500 Content-Type: text/plain; charset="utf-8" On SVM, KVM uses the AMD PMU implementation and AMD PMU CPUID/MSR layout. Hygon guests that enable PMU and request AMD PMU CPUID features such as perfctr-core need QEMU's KVM PMU setup and MSR state paths to use that layout too. The relevant QEMU KVM PMU paths are currently restricted to AuthenticAMD guests: host/guest PMU compatibility checks, AMD PMU information initialization, and AMD PMU MSR save/restore. For a Hygon Dhyana guest with pmu=3Don, the compatibility check reports vPMU as unsupported solely because the guest vendor is HygonGenuine rather than AuthenticAMD. If the VM continues, QEMU still skips AMD PMU setup and never saves or restores the AMD PMU MSRs for the Hygon guest. Treat Hygon as using the AMD PMU CPUID/MSR layout for these KVM PMU paths. Because the PMU MSR layout is shared, accept both AMD and Hygon hosts for guests using that layout. This intentionally allows the PMU compatibility check to pass for AMD-host/Hygon-guest and Hygon-host/AMD-guest combinations. This does not enable PMU, perfctr-core, or perfmon-v2 by default for the Dhyana CPU model. On backward migration to older QEMU, Hygon PMU MSR state may still be dropped because older QEMU did not write that state back through the AMD PMU MSR KVM paths for Hygon guests. Signed-off-by: Tina Zhang --- target/i386/kvm/kvm.c | 73 +++++++++++++++++++++++++++++++++---------- 1 file changed, 56 insertions(+), 17 deletions(-) diff --git a/target/i386/kvm/kvm.c b/target/i386/kvm/kvm.c index aa32b74f10..6408254b67 100644 --- a/target/i386/kvm/kvm.c +++ b/target/i386/kvm/kvm.c @@ -2166,24 +2166,54 @@ static void kvm_init_pmu_info_amd(struct kvm_cpuid2= *cpuid, X86CPU *cpu) } } =20 -static bool is_host_compat_vendor(CPUX86State *env) +typedef enum X86PMUVendor { + X86_PMU_VENDOR_UNKNOWN, + X86_PMU_VENDOR_INTEL, + X86_PMU_VENDOR_AMD, +} X86PMUVendor; + +static X86PMUVendor x86_cpu_pmu_vendor(const CPUX86State *env) +{ + if (IS_INTEL_CPU(env) || IS_ZHAOXIN_CPU(env)) { + return X86_PMU_VENDOR_INTEL; + } + + if (IS_AMD_CPU(env) || IS_HYGON_CPU(env)) { + return X86_PMU_VENDOR_AMD; + } + + return X86_PMU_VENDOR_UNKNOWN; +} + +static X86PMUVendor x86_host_pmu_vendor(void) { char host_vendor[CPUID_VENDOR_SZ + 1]; =20 host_cpu_vendor_fms(host_vendor, NULL, NULL, NULL); =20 - /* - * Intel and Zhaoxin are compatible. - */ - if ((g_str_equal(host_vendor, CPUID_VENDOR_INTEL) || - g_str_equal(host_vendor, CPUID_VENDOR_ZHAOXIN1) || - g_str_equal(host_vendor, CPUID_VENDOR_ZHAOXIN2)) && - (IS_INTEL_CPU(env) || IS_ZHAOXIN_CPU(env))) { - return true; + if (g_str_equal(host_vendor, CPUID_VENDOR_INTEL) || + g_str_equal(host_vendor, CPUID_VENDOR_ZHAOXIN1) || + g_str_equal(host_vendor, CPUID_VENDOR_ZHAOXIN2)) { + return X86_PMU_VENDOR_INTEL; } =20 - return g_str_equal(host_vendor, CPUID_VENDOR_AMD) && - IS_AMD_CPU(env); + if (g_str_equal(host_vendor, CPUID_VENDOR_AMD) || + g_str_equal(host_vendor, CPUID_VENDOR_HYGON)) { + return X86_PMU_VENDOR_AMD; + } + + return X86_PMU_VENDOR_UNKNOWN; +} + +/* + * The guest vPMU can be virtualized only when the host and guest PMU + * architectures are compatible. + */ +static bool is_host_compat_vendor(CPUX86State *env) +{ + X86PMUVendor guest =3D x86_cpu_pmu_vendor(env); + + return guest !=3D X86_PMU_VENDOR_UNKNOWN && guest =3D=3D x86_host_pmu_= vendor(); } =20 static void kvm_init_pmu_info(struct kvm_cpuid2 *cpuid, X86CPU *cpu) @@ -2211,10 +2241,15 @@ static void kvm_init_pmu_info(struct kvm_cpuid2 *cp= uid, X86CPU *cpu) return; } =20 - if (IS_INTEL_CPU(env) || IS_ZHAOXIN_CPU(env)) { + switch (x86_cpu_pmu_vendor(env)) { + case X86_PMU_VENDOR_INTEL: kvm_init_pmu_info_intel(cpuid); - } else if (IS_AMD_CPU(env)) { + break; + case X86_PMU_VENDOR_AMD: kvm_init_pmu_info_amd(cpuid, cpu); + break; + case X86_PMU_VENDOR_UNKNOWN: + break; } } =20 @@ -4268,7 +4303,8 @@ static int kvm_put_msrs(X86CPU *cpu, KvmPutState leve= l) kvm_msr_entry_add(cpu, MSR_KVM_POLL_CONTROL, env->poll_control= _msr); } =20 - if ((IS_INTEL_CPU(env) || IS_ZHAOXIN_CPU(env)) && pmu_version > 0)= { + if (x86_cpu_pmu_vendor(env) =3D=3D X86_PMU_VENDOR_INTEL && + pmu_version > 0) { if (pmu_version > 1) { /* Stop the counter. */ kvm_msr_entry_add(cpu, MSR_CORE_PERF_FIXED_CTR_CTRL, 0); @@ -4300,7 +4336,8 @@ static int kvm_put_msrs(X86CPU *cpu, KvmPutState leve= l) } } =20 - if (IS_AMD_CPU(env) && pmu_version > 0) { + if (x86_cpu_pmu_vendor(env) =3D=3D X86_PMU_VENDOR_AMD && + pmu_version > 0) { uint32_t sel_base =3D MSR_K7_EVNTSEL0; uint32_t ctr_base =3D MSR_K7_PERFCTR0; /* @@ -4846,7 +4883,8 @@ static int kvm_get_msrs(X86CPU *cpu) kvm_msr_entry_add(cpu, MSR_KVM_POLL_CONTROL, 1); } =20 - if ((IS_INTEL_CPU(env) || IS_ZHAOXIN_CPU(env)) && pmu_version > 0) { + if (x86_cpu_pmu_vendor(env) =3D=3D X86_PMU_VENDOR_INTEL && + pmu_version > 0) { if (pmu_version > 1) { kvm_msr_entry_add(cpu, MSR_CORE_PERF_FIXED_CTR_CTRL, 0); kvm_msr_entry_add(cpu, MSR_CORE_PERF_GLOBAL_CTRL, 0); @@ -4862,7 +4900,8 @@ static int kvm_get_msrs(X86CPU *cpu) } } =20 - if (IS_AMD_CPU(env) && pmu_version > 0) { + if (x86_cpu_pmu_vendor(env) =3D=3D X86_PMU_VENDOR_AMD && + pmu_version > 0) { uint32_t sel_base =3D MSR_K7_EVNTSEL0; uint32_t ctr_base =3D MSR_K7_PERFCTR0; /* --=20 2.43.7 From nobody Mon Sep 28 01:17:51 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786350844030943.8120567029163; Mon, 10 Aug 2026 01:34:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtLS5-0001Rr-KR; Mon, 10 Aug 2026 04:33:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRh-0001Pi-3s for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:22 -0400 Received: from [115.124.28.4] (helo=out28-4.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRd-0005CA-Bz for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:20 -0400 Received: from localhost.localdomain(mailfrom:zhang_wei@open-hieco.net fp:SMTPD_---.iiL7hO7_1786350662 cluster:ay29) by smtp.aliyun-inc.com; Mon, 10 Aug 2026 16:31:03 +0800 X-Alimail-AntiSpam: AC=CONTINUE; BC=0.09693278|-1; CH=green; DM=|CONTINUE|false|; DS=CONTINUE|ham_regular_dialog|0.0628494-0.0109224-0.926228; FP=7187561936658883669|1|1|1|0|-1|-1|-1; HT=maildocker-contentspam033037031241; MF=zhang_wei@open-hieco.net; NM=1; PH=DS; RN=8; RT=8; SR=0; TI=SMTPD_---.iiL7hO7_1786350662; From: Tina Zhang To: qemu-devel@nongnu.org Cc: kvm@vger.kernel.org, "Michael S . Tsirkin" , Paolo Bonzini , Marcelo Tosatti , Zhao Liu , Yanjing Zhou , Tina Zhang Subject: [PATCH v2 6/9] target/i386: Do not broadcast injected MCEs for Hygon Date: Mon, 10 Aug 2026 16:29:53 +0800 Message-ID: <20260810082956.1768042-7-zhang_wei@open-hieco.net> X-Mailer: git-send-email 2.43.7 In-Reply-To: <20260810082956.1768042-1-zhang_wei@open-hieco.net> References: <20260810082956.1768042-1-zhang_wei@open-hieco.net> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.28.4 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.28.4; envelope-from=zhang_wei@open-hieco.net; helo=out28-4.mail.aliyun.com X-Spam_score_int: -10 X-Spam_score: -1.1 X-Spam_bar: - X-Spam_report: (-1.1 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1786350846558158500 Content-Type: text/plain; charset="utf-8" cpu_x86_support_mca_broadcast() excludes AMD CPUs because QEMU handles AMD injected MCEs as local machine checks, not as Intel-style broadcast MCEs. Hygon Dhyana missed that exclusion: it is not an AMD vendor CPU and its family is greater than 6, so QEMU reported MCA broadcast support. This affects QEMU's synthetic MCE injection paths. KVM memory-failure injection uses this helper to decide whether to set MCE_INJECT_BROADCAST. HMP 'mce -b' uses it to decide whether a broadcast request is valid. With a multi-vCPU Dhyana guest, QEMU could fan out an injected MCE to secondary vCPUs and populate extra bank records. Linux routes Hygon through the AMD MCE feature initialization path and does not use Intel/Zhaoxin LMCE broadcast handling for Hygon. Do not advertise Intel-style MCA broadcast support for Hygon in QEMU's injected MCE paths. This is limited to the MCE broadcast-support decision. It does not claim that all Hygon MCE/MCA behavior is identical to AMD. Signed-off-by: Tina Zhang Reviewed-by: Zhao Liu --- target/i386/helper.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/target/i386/helper.c b/target/i386/helper.c index 6836214162..c5bbe9715b 100644 --- a/target/i386/helper.c +++ b/target/i386/helper.c @@ -95,7 +95,7 @@ int cpu_x86_support_mca_broadcast(CPUX86State *env) int family =3D 0; int model =3D 0; =20 - if (IS_AMD_CPU(env)) { + if (IS_AMD_CPU(env) || IS_HYGON_CPU(env)) { return 0; } =20 --=20 2.43.7 From nobody Mon Sep 28 01:17:51 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786350915680308.3573713099727; Mon, 10 Aug 2026 01:35:15 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtLSa-0001bZ-Vm; Mon, 10 Aug 2026 04:34:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRk-0001QD-T7 for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:33 -0400 Received: from [115.124.28.98] (helo=out28-98.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRf-0005CH-4D for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:23 -0400 Received: from localhost.localdomain(mailfrom:zhang_wei@open-hieco.net fp:SMTPD_---.iiL7hP8_1786350663 cluster:ay29) by smtp.aliyun-inc.com; Mon, 10 Aug 2026 16:31:04 +0800 X-Alimail-AntiSpam: AC=CONTINUE; BC=0.07436353|-1; CH=green; DM=|CONTINUE|false|; DS=CONTINUE|ham_alarm|0.014778-0.000114728-0.985107; FP=7607367760908667379|1|1|1|0|-1|-1|-1; HT=maildocker-contentspam033037032089; MF=zhang_wei@open-hieco.net; NM=1; PH=DS; RN=8; RT=8; SR=0; TI=SMTPD_---.iiL7hP8_1786350663; From: Tina Zhang To: qemu-devel@nongnu.org Cc: kvm@vger.kernel.org, "Michael S . Tsirkin" , Paolo Bonzini , Marcelo Tosatti , Zhao Liu , Yanjing Zhou , Tina Zhang Subject: [PATCH v2 7/9] hw/i386: Reserve AMD IOMMU HT GPA range for Hygon Date: Mon, 10 Aug 2026 16:29:54 +0800 Message-ID: <20260810082956.1768042-8-zhang_wei@open-hieco.net> X-Mailer: git-send-email 2.43.7 In-Reply-To: <20260810082956.1768042-1-zhang_wei@open-hieco.net> References: <20260810082956.1768042-1-zhang_wei@open-hieco.net> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.28.98 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.28.98; envelope-from=zhang_wei@open-hieco.net; helo=out28-98.mail.aliyun.com X-Spam_score_int: -10 X-Spam_score: -1.1 X-Spam_bar: - X-Spam_report: (-1.1 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1786350916977158500 Content-Type: text/plain; charset="utf-8" pc_memory_init() avoids the AMD IOMMU HyperTransport range below 1 TiB only for AMD vCPUs. Dhyana therefore allows RAM, hotplug address space, or 64-bit PCI MMIO to overlap 0xfd00000000-0xffffffffff. Linux supports Dhyana platforms in the AMD IOMMU driver. The driver reports this range as reserved unless the IOMMU advertises FEATURE_HT_RANGE_IGNORE. A VFIO device cannot DMA to guest addresses that QEMU places in the reserved range: VFIO_DMA_MAP may fail with -EINVAL, or the IOMMU may report an INVALID_DEVICE_REQUEST fault. Apply the AMD IOMMU HT GPA layout to Hygon vCPUs. When the possible address space reaches the reserved range, move RAM above 4 GiB to 1 TiB; also expose the range as reserved in E820 when the vCPU can address it. Changing the GPA layout affects migration, so enable the Hygon behavior through x-hygon-vendor-abi-fixes. pc-11.0 and older machine types retain their previous Hygon layout. The existing enforce_amd_1tb_hole setting continues to preserve the AMD layout of pc/q35 machine types through 7.0. Add functional tests for Dhyana with the current q35 machine type and with pc-q35-11.0 compatibility. Signed-off-by: Yanjing Zhou Signed-off-by: Tina Zhang --- hw/i386/pc.c | 18 ++++++--- .../functional/x86_64/test_mem_addr_space.py | 37 +++++++++++++++++++ 2 files changed, 50 insertions(+), 5 deletions(-) diff --git a/hw/i386/pc.c b/hw/i386/pc.c index 2b4e322b2f..04aef6c267 100644 --- a/hw/i386/pc.c +++ b/hw/i386/pc.c @@ -738,6 +738,12 @@ static hwaddr pc_max_used_gpa(PCMachineState *pcms, ui= nt64_t pci_hole64_size) #define AMD_ABOVE_1TB_START (AMD_HT_END + 1) #define AMD_HT_SIZE (AMD_ABOVE_1TB_START - AMD_HT_START) =20 +static bool x86_cpu_has_amd_iommu_ht_gpa_hole(const X86CPU *cpu) +{ + return IS_AMD_CPU(&cpu->env) || + (IS_HYGON_CPU(&cpu->env) && cpu->hygon_vendor_abi_fixes); +} + void pc_memory_init(PCMachineState *pcms, MemoryRegion *system_memory, MemoryRegion *rom_memory, @@ -762,12 +768,14 @@ void pc_memory_init(PCMachineState *pcms, linux_boot =3D (machine->kernel_filename !=3D NULL); =20 /* - * The HyperTransport range close to the 1T boundary is unique to AMD - * hosts with IOMMUs enabled. Restrict the ram-above-4g relocation - * to above 1T to AMD vCPUs only. @enforce_amd_1tb_hole is only false = in - * older machine types (<=3D 7.0) for compatibility purposes. + * The HyperTransport range close to the 1T boundary is reserved by the + * AMD IOMMU GPA layout. Apply the ram-above-4g relocation only to vC= PUs + * that use that layout. @enforce_amd_1tb_hole preserves older AMD + * machine types (<=3D 7.0), and x-hygon-vendor-abi-fixes preserves ol= der + * Hygon machine types (<=3D 11.0). */ - if (IS_AMD_CPU(&cpu->env) && pcmc->enforce_amd_1tb_hole) { + if (x86_cpu_has_amd_iommu_ht_gpa_hole(cpu) && + pcmc->enforce_amd_1tb_hole) { /* Bail out if max possible address does not cross HT range */ if (pc_max_used_gpa(pcms, pci_hole64_size) >=3D AMD_HT_START) { x86ms->above_4g_mem_start =3D AMD_ABOVE_1TB_START; diff --git a/tests/functional/x86_64/test_mem_addr_space.py b/tests/functio= nal/x86_64/test_mem_addr_space.py index 61b4a190b4..b80f9acd99 100755 --- a/tests/functional/x86_64/test_mem_addr_space.py +++ b/tests/functional/x86_64/test_mem_addr_space.py @@ -208,6 +208,25 @@ def test_phybits_low_tcg_q35_71_amd(self): self.assertEqual(self.vm.exitcode(), 1, "QEMU exit code should be = 1") self.assertRegex(self.vm.get_log(), r'phys-bits too low') =20 + def test_phybits_low_tcg_q35_hygon(self): + """ + Same as q35-7.1 AMD case except that here we check that Dhyana + follows the same AMD IOMMU HT reserved GPA range on new machine + types. + """ + self.ensure_64bit_binary() + self.set_machine('q35') + self.vm.add_args('-S', '-cpu', 'Dhyana,phys-bits=3D40', + '-m', '512,slots=3D1,maxmem=3D976G', + '-display', 'none', + '-object', 'memory-backend-ram,id=3Dmem1,size=3D1= G', + '-device', 'pc-dimm,id=3Dvm0,memdev=3Dmem1') + self.vm.set_qmp_monitor(enabled=3DFalse) + self.vm.launch() + self.vm.wait() + self.assertEqual(self.vm.exitcode(), 1, "QEMU exit code should be = 1") + self.assertRegex(self.vm.get_log(), r'phys-bits too low') + def test_phybits_ok_tcg_q35_70_amd(self): """ Same as q35-7.0 AMD case except that here we check that QEMU can @@ -225,6 +244,24 @@ def test_phybits_ok_tcg_q35_70_amd(self): self.vm.shutdown() self.assertNotRegex(self.vm.get_log(), r'phys-bits too low') =20 + def test_phybits_ok_tcg_q35_110_hygon(self): + """ + Same as q35-7.1 Dhyana case except that here we check that the + q35-11.0 compatibility setting keeps the old memory layout. + """ + self.ensure_64bit_binary() + self.set_machine('pc-q35-11.0') + self.vm.add_args('-S', '-cpu', 'Dhyana,phys-bits=3D40', + '-m', '512,slots=3D1,maxmem=3D976G', + '-display', 'none', + '-object', 'memory-backend-ram,id=3Dmem1,size=3D1= G', + '-device', 'pc-dimm,id=3Dvm0,memdev=3Dmem1') + self.vm.set_qmp_monitor(enabled=3DFalse) + self.vm.launch() + time.sleep(self.DELAY_Q35_BOOT_SEQUENCE) + self.vm.shutdown() + self.assertNotRegex(self.vm.get_log(), r'phys-bits too low') + def test_phybits_ok_tcg_q35_71_amd(self): """ Same as q35-7.1 AMD case except that here we check that QEMU can --=20 2.43.7 From nobody Mon Sep 28 01:17:51 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786350843418143.9846912327564; Mon, 10 Aug 2026 01:34:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtLS5-0001Rn-Jg; Mon, 10 Aug 2026 04:33:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRh-0001Pk-HC for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:22 -0400 Received: from [115.124.28.4] (helo=out28-4.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRd-0005CI-8c for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:21 -0400 Received: from localhost.localdomain(mailfrom:zhang_wei@open-hieco.net fp:SMTPD_---.iiL7hQN_1786350664 cluster:ay29) by smtp.aliyun-inc.com; Mon, 10 Aug 2026 16:31:04 +0800 X-Alimail-AntiSpam: AC=CONTINUE; BC=0.07985309|-1; CH=green; DM=|CONTINUE|false|; DS=CONTINUE|ham_alarm|0.0198397-0.00211061-0.97805; FP=16418793524219815007|1|1|1|0|-1|-1|-1; HT=maildocker-contentspam033068016216; MF=zhang_wei@open-hieco.net; NM=1; PH=DS; RN=8; RT=8; SR=0; TI=SMTPD_---.iiL7hQN_1786350664; From: Tina Zhang To: qemu-devel@nongnu.org Cc: kvm@vger.kernel.org, "Michael S . Tsirkin" , Paolo Bonzini , Marcelo Tosatti , Zhao Liu , Yanjing Zhou , Tina Zhang Subject: [PATCH v2 8/9] target/i386: Use AMD legacy cache fallback for Hygon Date: Mon, 10 Aug 2026 16:29:55 +0800 Message-ID: <20260810082956.1768042-9-zhang_wei@open-hieco.net> X-Mailer: git-send-email 2.43.7 In-Reply-To: <20260810082956.1768042-1-zhang_wei@open-hieco.net> References: <20260810082956.1768042-1-zhang_wei@open-hieco.net> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.28.4 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.28.4; envelope-from=zhang_wei@open-hieco.net; helo=out28-4.mail.aliyun.com X-Spam_score_int: -10 X-Spam_score: -1.1 X-Spam_bar: - X-Spam_report: (-1.1 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1786350845467158500 Content-Type: text/plain; charset="utf-8" When legacy-cache=3Don, x86_cpu_realizefn() builds a hardcoded cache model. It selected the AMD legacy cache table only for CPUs with the AuthenticAMD vendor ID. Dhyana uses the HygonGenuine vendor ID, so this explicit compatibility path fell back to QEMU's old Intel legacy cache table. The wrong table is visible through AMD extended cache leaves. With the Intel legacy table, Dhyana reports 32 KiB, 8-way L1 caches in CPUID 0x80000005 and a 4 MiB, 16-way L2 cache in CPUID 0x80000006. Linux uses the AMD/Hygon cache enumeration path for Hygon and reads these AMD extended cache leaves. Use the AMD legacy cache table for Hygon in this fallback path when the new vendor CPU ABI is enabled. Keep the old fallback for pc-11.0 and older machine types through x-hygon-vendor-abi-fixes=3Dfalse. The default Dhyana model is unchanged because it provides EPYC cache_info and therefore defaults legacy-cache to off. The guest-visible change is limited to users who explicitly configure legacy-cache=3Don on new machine types. Signed-off-by: Tina Zhang Reviewed-by: Zhao Liu --- target/i386/cpu.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/target/i386/cpu.c b/target/i386/cpu.c index 569ef785ca..4d8364f1ef 100644 --- a/target/i386/cpu.c +++ b/target/i386/cpu.c @@ -10329,7 +10329,8 @@ static void x86_cpu_realizefn(DeviceState *dev, Err= or **errp) env->enable_legacy_vendor_cache =3D true; } =20 - if (IS_AMD_CPU(env)) { + if (IS_AMD_CPU(env) || + (IS_HYGON_CPU(env) && cpu->hygon_vendor_abi_fixes)) { env->cache_info =3D legacy_amd_cache_info; } else { env->cache_info =3D legacy_intel_cache_info; --=20 2.43.7 From nobody Mon Sep 28 01:17:51 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786350868465505.5606142870996; Mon, 10 Aug 2026 01:34:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wtLSN-0001Sh-DI; Mon, 10 Aug 2026 04:34:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRk-0001QG-U7 for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:33 -0400 Received: from [115.124.28.75] (helo=out28-75.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wtLRh-0005Cd-3n for qemu-devel@nongnu.org; Mon, 10 Aug 2026 04:33:23 -0400 Received: from localhost.localdomain(mailfrom:zhang_wei@open-hieco.net fp:SMTPD_---.iiL7hRH_1786350665 cluster:ay29) by smtp.aliyun-inc.com; Mon, 10 Aug 2026 16:31:05 +0800 X-Alimail-AntiSpam: AC=CONTINUE; BC=0.07436348|-1; CH=green; DM=|CONTINUE|false|; DS=CONTINUE|ham_system_inform|0.00378828-0.000704797-0.995507; FP=16568555282154128715|1|1|1|0|-1|-1|-1; HT=maildocker-contentspam033032053168; MF=zhang_wei@open-hieco.net; NM=1; PH=DS; RN=8; RT=8; SR=0; TI=SMTPD_---.iiL7hRH_1786350665; From: Tina Zhang To: qemu-devel@nongnu.org Cc: kvm@vger.kernel.org, "Michael S . Tsirkin" , Paolo Bonzini , Marcelo Tosatti , Zhao Liu , Yanjing Zhou , Tina Zhang Subject: [PATCH v2 9/9] target/i386: Use AMD ucode-rev default for Hygon Date: Mon, 10 Aug 2026 16:29:56 +0800 Message-ID: <20260810082956.1768042-10-zhang_wei@open-hieco.net> X-Mailer: git-send-email 2.43.7 In-Reply-To: <20260810082956.1768042-1-zhang_wei@open-hieco.net> References: <20260810082956.1768042-1-zhang_wei@open-hieco.net> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.28.75 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.28.75; envelope-from=zhang_wei@open-hieco.net; helo=out28-75.mail.aliyun.com X-Spam_score_int: -10 X-Spam_score: -1.1 X-Spam_bar: - X-Spam_report: (-1.1 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZM-MESSAGEID: 1786350868906158500 Content-Type: text/plain; charset="utf-8" QEMU currently gives named Hygon Dhyana CPUs the non-AMD default ucode-rev value, 0x100000000. That is the Intel/KVM-VMX-shaped encoding, where the visible revision is in the high 32 bits. Linux reads MSR 0x8b for Hygon CPUs through the AMD patch-level path, using MSR_AMD64_PATCH_LEVEL and storing the low 32 bits as cpuinfo_x86.microcode. With the old QEMU default, a Dhyana guest sees microcode revision 0. Use the AMD/KVM-SVM-shaped default, 0x01000065, for Hygon on this specific MSR 0x8b default path. This does not route Hygon through AMD microcode loading and does not claim that Hygon CPUs are otherwise identical to AMD CPUs. Preserve migration ABI through the vendor CPU ABI compatibility gate used by this Hygon bug-fix group. pc-11.0 and older machine types leave that gate off, so they retain the previous ucode-rev default. Explicit user-provided ucode-rev values still override the default. Add qtest coverage for the new default, the compatibility cases, and an explicit user override. Signed-off-by: Tina Zhang Reviewed-by: Zhao Liu --- target/i386/cpu.c | 8 ++++++-- tests/qtest/test-x86-cpuid-compat.c | 19 +++++++++++++++++++ 2 files changed, 25 insertions(+), 2 deletions(-) diff --git a/target/i386/cpu.c b/target/i386/cpu.c index 4d8364f1ef..eb4295e562 100644 --- a/target/i386/cpu.c +++ b/target/i386/cpu.c @@ -10219,10 +10219,14 @@ static void x86_cpu_realizefn(DeviceState *dev, E= rror **errp) if (cpu->ucode_rev =3D=3D 0) { /* * The default is the same as KVM's. Note that this check - * needs to happen after the evenual setting of ucode_rev in + * needs to happen after the eventual setting of ucode_rev in * accel-specific code in cpu_exec_realizefn. + * + * Hygon uses the AMD patch-level MSR 0x8b encoding, where the vis= ible + * microcode revision is in the low 32 bits. */ - if (IS_AMD_CPU(env)) { + if (IS_AMD_CPU(env) || + (IS_HYGON_CPU(env) && cpu->hygon_vendor_abi_fixes)) { cpu->ucode_rev =3D 0x01000065; } else { cpu->ucode_rev =3D 0x100000000ULL; diff --git a/tests/qtest/test-x86-cpuid-compat.c b/tests/qtest/test-x86-cpu= id-compat.c index b7f8834052..06cbf35d76 100644 --- a/tests/qtest/test-x86-cpuid-compat.c +++ b/tests/qtest/test-x86-cpuid-compat.c @@ -404,6 +404,25 @@ static const CpuidTestArgs cpuid_tests[] =3D { "486", "xlevel2=3D0xC0000002,xstore=3Don", NULL, "xlevel2", 0xC0000002, }, + { + "x86/cpuid/props/dhyana/ucode-rev/default", + "Dhyana", NULL, NULL, "ucode-rev", 0x01000065, + }, + { + "x86/cpuid/props/dhyana/ucode-rev/compat-off", + "Dhyana", "x-hygon-vendor-abi-fixes=3Doff", NULL, + "ucode-rev", 0x100000000LL, + }, + { + "x86/cpuid/props/dhyana/ucode-rev/pc-i440fx-11.0", + "Dhyana", NULL, "pc-i440fx-11.0", + "ucode-rev", 0x100000000LL, + }, + { + "x86/cpuid/props/dhyana/ucode-rev/user", + "Dhyana", "ucode-rev=3D0x12345678", NULL, + "ucode-rev", 0x12345678, + }, }; =20 /* --=20 2.43.7