From nobody Fri Aug 21 21:27:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1787237103; cv=none; d=zohomail.com; s=zohoarc; b=jLNFBbwmJUndvEhLEtd7jVv5UNoOR97MHDw0ArPoUJczzl5tylATpgHW0Ky32d9huecsFcyaJCdVwpt3GBrx8h9S7lMW4UxJS5jI296Ob6CTdp0TDClHF9XB3qtORQF+JEIHGQBFwcZMnvCWAWvsFdE5+QWkp0Y5YzglBfwDcVc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787237103; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=F31PMa12IiO/re93aMILk1LSzM11AyPxrVTqJ97tIV0=; b=fqtTA5rZHafkoiXPoRQTMB/8WABeJoitquYc0BUIoqPI1rU2zlyBrGMnCqzquVQk20xy2skUFxpw7suABZRyZ1d8sT07Lq4xDkINtE0x/gRBDO7E+EznrMW0HCBGdQIyxMfJDFpZ1uVuEwCxAFMr5g/8l4540v2t5lkUHETtl64= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787237103716624.3871452176736; Thu, 20 Aug 2026 07:45:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wx3zE-0000Xk-7W; Thu, 20 Aug 2026 10:43:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wx3zC-0000W8-6g for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:18 -0400 Received: from mail-wm1-x32e.google.com ([2a00:1450:4864:20::32e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wx3z9-000598-8T for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:17 -0400 Received: by mail-wm1-x32e.google.com with SMTP id 5b1f17b1804b1-4954dff6536so20176555e9.0 for ; Thu, 20 Aug 2026 07:43:14 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:a123:7b43:afd8:8b47]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499aa0dd620sm136791565e9.13.2026.08.20.07.43.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 07:43:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1787236994; x=1787841794; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=F31PMa12IiO/re93aMILk1LSzM11AyPxrVTqJ97tIV0=; b=ciky6r4NCbxwxxi9fj3TMBAhY+8zf1gFG2tNgbpoxuepEwM10c5UsivlqX5qslAVek Hb+UqEakbGBA2H0UowHkQEnNyXwfOBab3xpQ81oz1RqT/7WC0TJJnjME1BAfZvCFaYbn 9rWEJwzL85y4ufOkcDr9PbLyh5P7DBSu378XhnnfaIkjfrpYaL4vxxkTLfEXUprNLkrr e1oh89v4+OKGq07QFvTxF62wZkmqVikIVfCT4uJlJk/lv/JPQCUXU2or1GLEnRgmXEVu oz7IRZWpfnvJmOjP5rMXMjpJ1NYDCEHcpWxqE0l5UotbHyh1K7duePR3C9RK7ykYtKs0 xTnA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787236994; x=1787841794; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=F31PMa12IiO/re93aMILk1LSzM11AyPxrVTqJ97tIV0=; b=Rqq7cj98fhPb+VGTh/Ep4Ry8rvegqWT3oreQKmfdzza7MipCSYIDqdw3nzEhADEYyL dnUud0BAzJL1jR1wUk2L8xTHLy8A8VZg6RNVQdk9EStU+JrQF/dRtKaBy60EKqgiBXF3 mf90hehGewqFfK3gz6+tUJqsdvzNYmVufZ4wgrPALsWXjwwrGNGJ/vZ5FCzf42fZsPt7 ZGDFPmS1+mVEhfuAOGZ6SA5wAzWZad0m0SLIaXy+N4n2cKShRdV6Fkef4XK2DrZQghJm 2dISO8sNqwhTbSHdxWtWnigibdV2+6KzxT8xsaInRkF7hR+1u4mAgWhVbuUGafED+C9n Ej0w== X-Gm-Message-State: AOJu0YxCIRsbQqm0co9oXBaSuz73xaNVRWKgsGAKpz503b/d8n/kPnUh iA6XhWtzDhmWq6nBSa07madh7K2u/+tRGK8pzNlVD75CJs8yg3RcULPTCPo42DAw6gEi42QGXMd 7m8xV X-Gm-Gg: AR+sD11DgXFN09ihFnbhlnHCTnL+u/h0mQ9u3q0F2tp9zFu92M5pl+BM1Fv/JOUQl6t rvmYWJxZPulQgy/pB6x2UM8AU0e254xoAGSvGdhJABHx09ZmYAB8IS3A+sWI+PFk2hd6eX97Wp2 nFvlyR68BsSMlxNcxDfCYLG9M7jQw8fRMJk46MdKFd0GFHa5fs86XUTe4OEVtSUoHOGSLyCyAf6 xL6zbos6W1HbytU03q3gO4ifMWPK+tvjtZSskZC1LGM9tU6TsSA4L2vXEjnd+uIZohRA5vTXxWG bjg4qrRs0aAFlJli6NizlaywnGdA4V949NB/jQjXsX3xv0niwAUah43LyxC6f6F49lnlIL9jlf1 oRQnu0T5dbzkGRnkCujHAGmnhTxbt0xOn22igrvz1XH/z43+uMi1gunXMsznAkSkmpOJBaVn5AS Wq+jTm8AfJzSsWbTSP/Isn4DVwFw1mJ5a6/AsI9aiF5lt9Dwlud934AhXnSA== X-Received: by 2002:a05:600c:c168:b0:495:779a:ed33 with SMTP id 5b1f17b1804b1-499aa17d30cmr252497595e9.7.1787236993755; Thu, 20 Aug 2026 07:43:13 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , XlabAI Team of Tencent Xuanwu Lab , John Snow , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH 01/11] hw/ide: reject an out-of-range PIO transfer window on load Date: Thu, 20 Aug 2026 16:42:59 +0200 Message-ID: <20260820144309.835173-2-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260820144309.835173-1-den@openvz.org> References: <20260820144309.835173-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::32e; envelope-from=den@openvz.org; helo=mail-wm1-x32e.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1787237105189158500 From: Denis V. Lunev ide_drive_pio_post_load() validates end_transfer_fn_idx but takes cur_io_buffer_offset and cur_io_buffer_len straight from the migration stream, so data_ptr and data_end can be placed anywhere within +-2GB of the 131076-byte io_buffer allocation. Both fields are signed 32-bit. The subsection loader consumes every subsection present in the stream without consulting needed(), so a crafted stream can inject ide_drive/pio_state for a drive that was never in a DRQ state. Once data_end is out of bounds, ide_data_writew() only compares the guest's pointer against that same bogus data_end, and the resumed guest turns a repeated outw to the data port into a controlled 16-bit heap write. end_transfer_fn_idx picks the direction, so the read side of the same code path leaks host heap instead. Validate the window against io_buffer_total_len and fail the load. The subtraction form avoids overflowing the addition. Reported-by: XlabAI Team of Tencent Xuanwu Lab Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4179 Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3738 Cc: John Snow Cc: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Denis V. Lunev --- hw/ide/core.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/hw/ide/core.c b/hw/ide/core.c index 8190549ee8..0dca2b5c52 100644 --- a/hw/ide/core.c +++ b/hw/ide/core.c @@ -2898,6 +2898,12 @@ static int ide_drive_pio_post_load(void *opaque, int= version_id) if (s->end_transfer_fn_idx >=3D ARRAY_SIZE(transfer_end_table)) { return -EINVAL; } + if (s->cur_io_buffer_offset < 0 || s->cur_io_buffer_len < 0 || + s->cur_io_buffer_offset > s->io_buffer_total_len || + s->cur_io_buffer_len > + s->io_buffer_total_len - s->cur_io_buffer_offset) { + return -EINVAL; + } s->end_transfer_func =3D transfer_end_table[s->end_transfer_fn_idx]; s->data_ptr =3D s->io_buffer + s->cur_io_buffer_offset; s->data_end =3D s->data_ptr + s->cur_io_buffer_len; --=20 2.53.0 From nobody Fri Aug 21 21:27:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1787237034; cv=none; d=zohomail.com; s=zohoarc; b=gkfDBWPfCLzV4xbVptOYZLEKaolH0kwIZuAy7D1COd6SFfeMdl74yVYpyz/v2qmTQcpYbASdWLG+mJ93AB00NoYQdOKFtBirvora2eBDh9PoMKpKsskN/5kdryVphVoqgHtz/S9YxRpFLPt4R94fkQuoiFqK8wNDddEC5cH19Kc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787237034; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=0TnEHSu4TV5ed22Ma1QTV9Di4HsnlXd0KkLzkOy55/o=; b=LnhPnmmleK5qlP+rxT5cyi0rPUsKkQNZHlPXxSVz8sEJoFuBzOYT5BwL+7PgXV621OmfI3cqxahVPw7sJidTN4xAR2VVF68jPw5XKfqaHXCyfkpimK3TjMjJ4OJ4NYMhnEyBc71AJYrIr8yeyh/dE0VLMC9Y4z+NoyjfL/Zdavo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787237034912999.2369307844775; Thu, 20 Aug 2026 07:43:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wx3zE-0000Y3-MW; Thu, 20 Aug 2026 10:43:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wx3zD-0000XG-MF for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:19 -0400 Received: from mail-wm1-x336.google.com ([2a00:1450:4864:20::336]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wx3zA-00059K-TI for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:19 -0400 Received: by mail-wm1-x336.google.com with SMTP id 5b1f17b1804b1-499b2981a7bso10156875e9.3 for ; Thu, 20 Aug 2026 07:43:16 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:a123:7b43:afd8:8b47]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499aa0dd620sm136791565e9.13.2026.08.20.07.43.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 07:43:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1787236995; x=1787841795; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=0TnEHSu4TV5ed22Ma1QTV9Di4HsnlXd0KkLzkOy55/o=; b=EddOcT6LfOpWyIGvRqTDQzlQxWN2RTxfUYkYTmKLAks5RYF/cwzu6svWXKJneh/sW+ gmUEjpeiG5frjwd/O4J0+sc1Y6lEAbDUr/RnPhtEzAq0eXqCtJ/X6QksN5Flcvi0gtPt 3hnmbXuuALf5zgRz8Bstca+nmpgLxRpjoYMOCS/eOPkkHBzXP0x4XtD+hlszJ8zX2fwa 6TWVgqoKYuOozBiRQD7fPgl8JIjstQC+KKJ/4M9SUW1svpeqe0bcnGZHIqYC7+G05CKj HESt5IybLCNlCL0T+NIiH0asIG7Un+qh6XNZRN5wVzzadQZxCl4lZiN8x7NVaAoruNkD fW6w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787236995; x=1787841795; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=0TnEHSu4TV5ed22Ma1QTV9Di4HsnlXd0KkLzkOy55/o=; b=VJpbCdJ2tYrl96HphCR6ITs0VEV4WdIbWgF8EypJ0qnMXl7+9NYhGM12Aupuw4A4YJ IXsiRAzckkmemAFsI15bWKH3EIG3sODMzGX5YqVRd3z7XavckPPFBSksDP9L/bIazJkd GilrNehEltd6VsfuSJEm+5A/h3O9Y8iJ7TO9qXVbsQejnSrgTb2yNErl/zD8iRlfIna5 H1GinsOu0P3Y/pz/WimEetJ+mdcteTsJfJ2ibI8fhW7xE1qiH2C1rPtgFHn84t5tta+M AXvCmjYkzukwXw3tNsSWbawAd7MvtlWoBNLj5VGm4R/l6B9aT1tJk/5Ou2LBlpdEYZnA T+Xg== X-Gm-Message-State: AOJu0YzHZnIoKKcRhgo2GbK2HBMoxc6Q7Pt2fpCB+ZCsp3pgowfoW2/r dUFDLwOt1ftVbt9ezN4uh/45fj8hAYmU6JVFf+vw/o0DVbroGSOx0cFWlJKst2uvcgXuZ1YLED8 m+LYE X-Gm-Gg: AR+sD12fdjAxvlshgVYVhuS1QkDWcgLKfxRr5wWQvRfzbT5rhH90IXDJNw0DAQofVKn m2rNnm/CETD8/2eHJe3gFNJkh+riWMYOFkTQPmZw3jP/C2+VC6k51EHjE+h4UF7zSbqpnQAPSoj NIBtoz22sPxC2mwPgyAjjJwzT+OXK7EdD3yQR06ZQLmTuw2C4xgghZNa/BvoL6udWUrtk7oE1Rb s5j3z5YmLhpVx2xg1Uo9L3WKblk840Dqv18+pzBBX54j2h3YbghSHFtEvx3Sb1v7ey4/QUf1unI M8X/eOnrGMttMY4qF2UrhNR5A3VJsghqKThUHYF6woPNnTNcSa71ayzwvY0N4ZFdbAWLhpYz9Yv qBusV60kq/lHTVYHHgyPo4DOlQwBbYcJbH+owIqV/yfmuy8CkqqTNnGltv4IA1ROhnBMGVaqBmg 2YoekhbPmp6t0VEt6ZWkKE1LLTnq6biFBrOsvL4rJ8NRfHCiFgRDGCXRD68UmnLe3Dbj7n X-Received: by 2002:a05:600c:8b6e:b0:493:f140:c3fb with SMTP id 5b1f17b1804b1-499aa1a8bbcmr243513285e9.7.1787236995088; Thu, 20 Aug 2026 07:43:15 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , John Snow , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH 02/11] tests/qtest/ide-test: cover the migrated PIO transfer window Date: Thu, 20 Aug 2026 16:43:00 +0200 Message-ID: <20260820144309.835173-3-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260820144309.835173-1-den@openvz.org> References: <20260820144309.835173-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::336; envelope-from=den@openvz.org; helo=mail-wm1-x336.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1787237036658158500 From: Denis V. Lunev /ide/migration/pio_state_rejected leaves a drive in DRQ so the source streams ide_drive/pio_state, rewrites cur_io_buffer_offset to the end of the io_buffer, and expects the destination to refuse the load. It asserts the window the source wrote before overwriting it, so a wrong guess at the stream layout fails the test rather than passing it for the wrong reason. Cc: John Snow Cc: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Denis V. Lunev --- tests/qtest/ide-test.c | 79 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 79 insertions(+) diff --git a/tests/qtest/ide-test.c b/tests/qtest/ide-test.c index f14a0851f0..a3109da908 100644 --- a/tests/qtest/ide-test.c +++ b/tests/qtest/ide-test.c @@ -1571,6 +1571,83 @@ static void test_migrate_chs_rejected(void) unlink(path); } =20 +/* A PIO transfer window reaching past the io_buffer has to be refused */ +static void test_migrate_pio_state_rejected(void) +{ + const char *name =3D "ide_drive/pio_state"; + /* IDE_DMA_BUF_SECTORS * 512 + 4, the length of the streamed io_buffer= */ + const gsize io_buffer_len =3D 256 * 512 + 4; + /* cur_io_buffer_offset and cur_io_buffer_len, big endian */ + const uint8_t in_bounds[8] =3D { 0, 0, 0, 0, 0, 0, 0x02, 0 }; + const uint8_t past_the_end[8] =3D { 0, 0x02, 0, 0x04, 0, 0, 0x10, 0 }; + QTestState *src, *dst; + QPCIDevice *dev; + QPCIBar bmdma_bar, ide_bar; + g_autofree char *path =3D NULL; + g_autofree char *uri =3D NULL; + g_autofree char *dst_args =3D NULL; + g_autofree char *stream =3D NULL; + char *window; + gsize len; + int fd; + + fd =3D g_file_open_tmp("qtest-ide-stream.XXXXXX", &path, NULL); + g_assert(fd >=3D 0); + close(fd); + uri =3D g_strdup_printf("file:%s", path); + + src =3D ide_test_start( + "-blockdev driver=3Dfile,node-name=3Dhda,filename=3D%s " + "-device ide-hd,drive=3Dhda,bus=3Dide.0,unit=3D0 ", + tmp_path[0]); + dev =3D get_pci_device(src, &bmdma_bar, &ide_bar); + + /* WRITE SECTOR(S) waits in DRQ for the data, so pio_state is streamed= */ + qpci_io_writeb(dev, ide_bar, reg_nsectors, 1); + qpci_io_writeb(dev, ide_bar, reg_lba_low, 0); + qpci_io_writeb(dev, ide_bar, reg_lba_middle, 0); + qpci_io_writeb(dev, ide_bar, reg_lba_high, 0); + qpci_io_writeb(dev, ide_bar, reg_device, LBA); + qpci_io_writeb(dev, ide_bar, reg_command, CMD_WRITE); + assert_bit_set(qpci_io_readb(dev, ide_bar, reg_status), DRQ); + + qtest_qmp_assert_success(src, "{ 'execute': 'migrate'," + " 'arguments': { 'uri': %s } }", uri); + qtest_qmp_eventwait(src, "STOP"); + ide_migration_wait(src, "completed"); + free_pci_device(dev); + ide_test_quit(src); + + /* + * Behind the name come the version and req_nb_sectors as big endian 32 + * bit, then the io_buffer array, then the transfer window this rewrit= es. + * Asserting the window the source streamed keeps that arithmetic hone= st. + */ + g_assert(g_file_get_contents(path, &stream, &len, NULL)); + window =3D ide_stream_find(stream, len, name); + g_assert(window); + window +=3D strlen(name) + 8 + io_buffer_len; + g_assert_cmpint(window - stream + sizeof(past_the_end), <=3D, len); + g_assert_cmpint(memcmp(window, in_bounds, sizeof(in_bounds)), =3D=3D, = 0); + memcpy(window, past_the_end, sizeof(past_the_end)); + g_assert(g_file_set_contents(path, stream, len, NULL)); + + dst_args =3D g_strdup_printf( + "-machine pc " + "-blockdev driver=3Dfile,node-name=3Dhda,filename=3D%s " + "-device ide-hd,drive=3Dhda,bus=3Dide.0,unit=3D0 -incoming defer", + tmp_path[0]); + dst =3D qtest_init(dst_args); + + qtest_qmp_assert_success(dst, "{ 'execute': 'migrate-incoming'," + " 'arguments': { 'uri': %s," + " 'exit-on-error': false } }", uri); + ide_migration_wait(dst, "failed"); + + qtest_quit(dst); + unlink(path); +} + /* Words 54 to 58 follow the translation even when the data was cached fir= st */ static void test_specify_identify(void) { @@ -1764,6 +1841,8 @@ int main(int argc, char **argv) test_migrate_chs_translation); qtest_add_func("/ide/migration/chs_snapshot", test_migrate_chs_snapsho= t); qtest_add_func("/ide/migration/chs_rejected", test_migrate_chs_rejecte= d); + qtest_add_func("/ide/migration/pio_state_rejected", + test_migrate_pio_state_rejected); =20 qtest_add_func("/ide/identify", test_identify); =20 --=20 2.53.0 From nobody Fri Aug 21 21:27:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1787237043; cv=none; d=zohomail.com; s=zohoarc; b=NStCGp7fR6lBOvD2DGtpbpePU8RXG2ghLbsBNjRcmOnOfOv/FdAjSmk+QZNgiuQCO/Ka2ojIvpNxlqqY/AZBo+CaUY7jt/GxFnhtvfER2SC+BioowPjL+jJCksR/fZslOStDA27rSlCtexSth1/RluONMDa1YtiPZholgyWFATk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787237043; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gCAdMlliwaTOQ8SN/agGDNBF/I8r2ygm3SMyD16FGPc=; b=SXWwWODnkOlVQ9bNYDqZ06gsht2QbgRh7GlFjxjWrPiMeupIiWyr4zYJLXLczpeIIymZC8AB4pulO40T3tevtK9z474w2+CCOXaQIrT8lDUMGQdkyw0H3g8YyXJYruiUKq3tZVteSL1mffhLAccTvb22ztKdqsPBrehCvRaIbOc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787237043530360.74889767582545; Thu, 20 Aug 2026 07:44:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wx3zJ-0000aG-WC; Thu, 20 Aug 2026 10:43:26 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wx3zE-0000Xg-06 for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:20 -0400 Received: from mail-wm1-x331.google.com ([2a00:1450:4864:20::331]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wx3zB-00059r-RS for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:19 -0400 Received: by mail-wm1-x331.google.com with SMTP id 5b1f17b1804b1-498028b3d5eso28364335e9.1 for ; Thu, 20 Aug 2026 07:43:17 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:a123:7b43:afd8:8b47]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499aa0dd620sm136791565e9.13.2026.08.20.07.43.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 07:43:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1787236996; x=1787841796; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=gCAdMlliwaTOQ8SN/agGDNBF/I8r2ygm3SMyD16FGPc=; b=QoPvopVrbeSnpNvCgXwnRqNC3443z+rcbwvjy8gkYNGueyu0em/qNIQ6/sKK7/49nY xGmc9++dOd6ynEr8PCKDvFSCAh5FCS8ItWA9oOOkY2KcnDL0Ifi/BkyyChvcaSddsAhp HnRjGGsCOMqnsHMV2DvmWwNJLJWXCFT+twUQ3ur7CygLUbvv085EXScvz0Fdc3IbiUC6 fbr4h2Po/cpj/sk5eR4BR6rL3SQJFlJh/W3jjbl8w9jjShLUxUMsi/uhE/whPi9rpQH+ wbWifB7bbvTZYtD7IWIeeQMw30487VuXmwA65d2DOd50X1ThHRWKVc049BZhHq9pm34a s5xQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787236996; x=1787841796; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=gCAdMlliwaTOQ8SN/agGDNBF/I8r2ygm3SMyD16FGPc=; b=XP9ZRCh4vLuRhmbkaFydNGXYpB9NS0oWw1VeYGyMkMg3DFb7jztbBq/6u79vbwQO5A gyONR9eGld35/Fa85M+2YoAlSxuEn/i2ysXNazcPfV3zqnLjhcuAbR/0lnV/GTb+7qfe FWcKnK4ExtQmS3wS0Jf+Rh2PmLhMArzBzU255gp062Yk2qaKSi7KCRXOA8t+2JAv+ClF sHwIacGQVE5D5749SBuOq1KpD4dL0PtkyxF4fY6QMhVHQeJDWGR+HYo2Ho401eghyaIF 0UQCIHWYnjypvg1ivEjfov6fHcGqkwDX5HimCVhD2ntEskxrSyw1xh/8S5A2Y+ooy9VI Vbvg== X-Gm-Message-State: AOJu0YzyDLxsUp6dsDxaPD9csE12iWIbxfvqvH8PP7zgviCPXxLTaYL9 p2xH3lp4hLENFtiDoKIhPK+Xe8FrAHKpeQaYLBjGEBoXEAfcsBg3o3NevbGpSLY2MhheDjuloqu rSdrW X-Gm-Gg: AR+sD11De7JGqcEKeA7Khyl4oIyyTSikWjUWmUDE0v3se5uGkJHm+OKFIi3hGBkZ6fe Hb0N31OnJl8Ypco1VcO59+rrSiryiVRxpeK0MjyfWBiDMScHPeE/CDb8oLbpRqPke6zON4AW3d1 4pcdMD/9+nVYxbdOu2ysx/GzwgCVszucbO+Gw5eIOghUEoolhvQtNr/ApFf6BNpXyNaVuViPfpW 8Fd/e/+IY0bcP+uHAUcJzkOfDZK85fAUNsCUFQC8kYHApWh5V2orlR6Kn00IeNnUMJ720RicGS1 e4DvBqDdVfqV9Dm7nu+Upwm9wfTXNb2ClO6Y5LIt6PTMxYFCQ/Cy88qs4uu5MmWBZ8FMWNAudVg xxVQoVBJRfFMItZQTUOu3f7B+iKrx2v4boJYypMtTDBVZfHAzJqYECUIYVb1MQNuXkcjFrW/d2k YaXvYlij0j75Z8xJs4ckOrGwjXua2u5aElpFTkvKaiam7udarI9v06fAW6Pg== X-Received: by 2002:a05:600c:3150:b0:499:900c:9c68 with SMTP id 5b1f17b1804b1-499aa1a471bmr216310095e9.6.1787236996190; Thu, 20 Aug 2026 07:43:16 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , John Snow , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH 03/11] hw/ide/ahci: refuse a PIO transfer with no command header Date: Thu, 20 Aug 2026 16:43:01 +0200 Message-ID: <20260820144309.835173-4-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260820144309.835173-1-den@openvz.org> References: <20260820144309.835173-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::331; envelope-from=den@openvz.org; helo=mail-wm1-x331.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1787237044699158500 From: Denis V. Lunev ahci_map_clb_address() already clears cur_cmd, so every consumer of it has to cope with there being no current command. ahci_pio_transfer(), ahci_commit_buf() and ahci_populate_sglist() all dereference it unconditionally instead. Give the three of them a NULL check. Declaring the data transferred anyway is not enough: ide_transfer_start() goes on to call the end transfer function, and for a multi-sector write that is ide_sector_write(), which commits an io_buffer the guest never refilled. Clearing PxCMD.ST during a WRITE SECTOR(S) of two sectors therefore writes the first sector's contents over the second, at a sector the guest chose. Let pio_transfer report that nothing was transferred and halt there, so no callback acts on a buffer that was never filled. Only the AHCI HBA implements the callback, so the signature change is local to it. Cc: John Snow Cc: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Denis V. Lunev --- hw/ide/ahci.c | 47 +++++++++++++++++++++++++++++++--------- hw/ide/core.c | 11 +++++++++- hw/ide/trace-events | 2 ++ include/hw/ide/ide-dma.h | 3 ++- 4 files changed, 51 insertions(+), 12 deletions(-) diff --git a/hw/ide/ahci.c b/hw/ide/ahci.c index 49f3047e6f..995b40efd5 100644 --- a/hw/ide/ahci.c +++ b/hw/ide/ahci.c @@ -906,12 +906,12 @@ static int prdt_tbl_entry_size(const AHCI_SG *tbl) static int ahci_populate_sglist(AHCIDevice *ad, QEMUSGList *sglist, AHCICmdHdr *cmd, int64_t limit, uint64_t o= ffset) { - uint16_t opts =3D le16_to_cpu(cmd->opts); - uint16_t prdtl =3D le16_to_cpu(cmd->prdtl); - uint64_t cfis_addr =3D le64_to_cpu(cmd->tbl_addr); - uint64_t prdt_addr =3D cfis_addr + 0x80; - dma_addr_t prdt_len =3D (prdtl * sizeof(AHCI_SG)); - dma_addr_t real_prdt_len =3D prdt_len; + uint16_t opts; + uint16_t prdtl; + uint64_t cfis_addr; + uint64_t prdt_addr; + dma_addr_t prdt_len; + dma_addr_t real_prdt_len; uint8_t *prdt; int i; int r =3D 0; @@ -923,6 +923,18 @@ static int ahci_populate_sglist(AHCIDevice *ad, QEMUSG= List *sglist, =20 trace_ahci_populate_sglist(ad->hba, ad->port_no); =20 + if (!cmd) { + trace_ahci_populate_sglist_no_cmd(ad->hba, ad->port_no); + return -1; + } + + opts =3D le16_to_cpu(cmd->opts); + prdtl =3D le16_to_cpu(cmd->prdtl); + cfis_addr =3D le64_to_cpu(cmd->tbl_addr); + prdt_addr =3D cfis_addr + 0x80; + prdt_len =3D (prdtl * sizeof(AHCI_SG)); + real_prdt_len =3D prdt_len; + if (!prdtl) { trace_ahci_populate_sglist_no_prdtl(ad->hba, ad->port_no, opts); return -1; @@ -1371,18 +1383,27 @@ out: } =20 /* Transfer PIO data between RAM and device */ -static void ahci_pio_transfer(const IDEDMA *dma) +static bool ahci_pio_transfer(const IDEDMA *dma) { AHCIDevice *ad =3D DO_UPCAST(AHCIDevice, dma, dma); IDEState *s =3D &ad->port.ifs[0]; uint32_t size =3D (uint32_t)(s->data_end - s->data_ptr); /* write =3D=3D ram -> device */ - uint16_t opts =3D le16_to_cpu(ad->cur_cmd->opts); - int is_write =3D opts & AHCI_CMD_WRITE; - int is_atapi =3D opts & AHCI_CMD_ATAPI; + uint16_t opts; + int is_write; + int is_atapi; int has_sglist =3D 0; bool pio_fis_i; =20 + if (ad->cur_cmd =3D=3D NULL) { + trace_ahci_pio_transfer_no_cmd(ad->hba, ad->port_no); + return false; + } + + opts =3D le16_to_cpu(ad->cur_cmd->opts); + is_write =3D opts & AHCI_CMD_WRITE; + is_atapi =3D opts & AHCI_CMD_ATAPI; + /* The PIO Setup FIS is received prior to transfer, but the interrupt * is only triggered after data is received. * @@ -1430,6 +1451,8 @@ out: if (pio_fis_i) { ahci_trigger_irq(ad->hba, ad, AHCI_PORT_IRQ_BIT_PSS); } + + return true; } =20 static void ahci_start_dma(const IDEDMA *dma, IDEState *s, @@ -1492,6 +1515,10 @@ static void ahci_commit_buf(const IDEDMA *dma, uint3= 2_t tx_bytes) { AHCIDevice *ad =3D DO_UPCAST(AHCIDevice, dma, dma); =20 + if (ad->cur_cmd =3D=3D NULL) { + return; + } + tx_bytes +=3D le32_to_cpu(ad->cur_cmd->status); ad->cur_cmd->status =3D cpu_to_le32(tx_bytes); } diff --git a/hw/ide/core.c b/hw/ide/core.c index 0dca2b5c52..06c18dbf09 100644 --- a/hw/ide/core.c +++ b/hw/ide/core.c @@ -80,6 +80,7 @@ static const char *IDE_DMA_CMD_str(enum ide_dma_cmd enval) } =20 static void ide_dummy_transfer_stop(IDEState *s); +static void ide_transfer_halt(IDEState *s); =20 const MemoryRegionPortio ide_portio_list[] =3D { { 0, 8, 1, .read =3D ide_ioport_read, .write =3D ide_ioport_write }, @@ -568,7 +569,15 @@ bool ide_transfer_start_norecurse(IDEState *s, uint8_t= *buf, int size, s->end_transfer_func =3D end_transfer_func; return false; } - s->bus->dma->ops->pio_transfer(s->bus->dma); + if (!s->bus->dma->ops->pio_transfer(s->bus->dma)) { + /* + * No data reached the buffer, so the caller must not act on it. A + * write would otherwise commit whatever the previous phase left + * there to the next sector. + */ + ide_transfer_halt(s); + return false; + } return true; } =20 diff --git a/hw/ide/trace-events b/hw/ide/trace-events index 57042cafdd..f1472f5852 100644 --- a/hw/ide/trace-events +++ b/hw/ide/trace-events @@ -85,6 +85,7 @@ ahci_reset_port(void *s, int port) "ahci(%p)[%d]: reset p= ort" ahci_unmap_fis_address_null(void *s, int port) "ahci(%p)[%d]: Attempt to u= nmap NULL FIS address" ahci_unmap_clb_address_null(void *s, int port) "ahci(%p)[%d]: Attempt to u= nmap NULL CLB address" ahci_populate_sglist(void *s, int port) "ahci(%p)[%d]" +ahci_populate_sglist_no_cmd(void *s, int port) "ahci(%p)[%d]: no command h= eader" ahci_populate_sglist_no_prdtl(void *s, int port, uint16_t opts) "ahci(%p)[= %d]: no sg list given by guest: 0x%04x" ahci_populate_sglist_no_map(void *s, int port) "ahci(%p)[%d]: DMA mapping = failed" ahci_populate_sglist_short_map(void *s, int port) "ahci(%p)[%d]: mapped le= ss than expected" @@ -109,6 +110,7 @@ handle_cmd_badfis(void *s, int port) "ahci(%p)[%d]: gue= st provided an invalid cm handle_cmd_badmap(void *s, int port, uint64_t len) "ahci(%p)[%d]: dma_memo= ry_map failed, 0x%02"PRIx64" !=3D 0x80" handle_cmd_unhandled_fis(void *s, int port, uint8_t b0, uint8_t b1, uint8_= t b2) "ahci(%p)[%d]: unhandled FIS type. cmd_fis: 0x%02x-%02x-%02x" ahci_pio_transfer(void *s, int port, const char *rw, uint32_t size, const = char *tgt, const char *sgl) "ahci(%p)[%d]: %sing %d bytes on %s w/%s sglist" +ahci_pio_transfer_no_cmd(void *s, int port) "ahci(%p)[%d]: PIO transfer wi= thout a command header" ahci_start_dma(void *s, int port) "ahci(%p)[%d]: start dma" ahci_dma_prepare_buf(void *s, int port, int32_t io_buffer_size, int32_t li= mit) "ahci(%p)[%d]: prepare buf limit=3D%"PRId32" prepared=3D%"PRId32 ahci_dma_prepare_buf_fail(void *s, int port) "ahci(%p)[%d]: sglist populat= ion failed" diff --git a/include/hw/ide/ide-dma.h b/include/hw/ide/ide-dma.h index 296010a4e0..34154b7cbc 100644 --- a/include/hw/ide/ide-dma.h +++ b/include/hw/ide/ide-dma.h @@ -10,6 +10,7 @@ typedef struct IDEDMA IDEDMA; =20 typedef void DMAStartFunc(const IDEDMA *, IDEState *, BlockCompletionFunc = *); typedef void DMAVoidFunc(const IDEDMA *); +typedef bool DMABoolFunc(const IDEDMA *); typedef int DMAIntFunc(const IDEDMA *, bool); typedef int32_t DMAInt32Func(const IDEDMA *, int32_t len); typedef void DMAu32Func(const IDEDMA *, uint32_t); @@ -17,7 +18,7 @@ typedef void DMAStopFunc(const IDEDMA *, bool); =20 struct IDEDMAOps { DMAStartFunc *start_dma; - DMAVoidFunc *pio_transfer; + DMABoolFunc *pio_transfer; DMAInt32Func *prepare_buf; DMAu32Func *commit_buf; DMAIntFunc *rw_buf; --=20 2.53.0 From nobody Fri Aug 21 21:27:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1787237025; cv=none; d=zohomail.com; s=zohoarc; b=Sere/fzWcKJWsBlGJqWYhqSQX9G04/hDfG48/wy1RAUiXmWGcJi7fcCUAS141D7uOBuyoUNdz6WdPZjiaq5EE30uewxuLD4xV3K1mCd5NWu73s8LWVd4iLEq4nglVEXrlM9LaHPJmDh8ptT7OAx1eIvsAwdAQEQZF862wgmPal0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787237025; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EOlP8ddaPlk71VLkEiYFvaBjk4ID6/66RcHruFcFYXo=; b=czEwOf07/YcFpmAjoSQ9OMv2+II2rgLInFj6fQQv/fawjJWF6qeKIdWqXLINazrGY9Hu+UDsqpb4XTnzwuzyoXeAPXzLF6pfPqfQ+chM2kRk3CSOzvz613OEYqs1k+OoWr+av95NXzHNH7LvGTUl6sIHaXv8tIZI21bFCsh7DOA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787237024865696.5968060200803; Thu, 20 Aug 2026 07:43:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wx3zG-0000Yv-2y; Thu, 20 Aug 2026 10:43:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wx3zE-0000Y1-Ie for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:20 -0400 Received: from mail-wm1-x334.google.com ([2a00:1450:4864:20::334]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wx3zC-0005A2-Py for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:20 -0400 Received: by mail-wm1-x334.google.com with SMTP id 5b1f17b1804b1-499b2981a7bso10158145e9.3 for ; Thu, 20 Aug 2026 07:43:18 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:a123:7b43:afd8:8b47]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499aa0dd620sm136791565e9.13.2026.08.20.07.43.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 07:43:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1787236997; x=1787841797; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=EOlP8ddaPlk71VLkEiYFvaBjk4ID6/66RcHruFcFYXo=; b=GqhhFv1l8liYJpvdyZEZJYEGXm4K5VpGZmnShDbYXjnITxYfU9Lb8SSR6L2D/f5442 JIuD0SD4OfV/xUrKqBb8wjYgGoFuMB1EbY8sWB968AhNkxaaYNigG19GvHnqq7rAGixp Ko3smDH397akXTFfWFxjX4phOY3Y+k98Y0xRLgQD2w6zMbjIK5g34CZN/CmRbuVLGctS BntUv9ga15BgaAhagjMg7r4ELXs/bAREij7M673RmKcpCBdhHqAoylpkz8pRNsn6hXMu KH7/Hrmp/rvp30zSNARX8NjIHoBirDgJOarPmuj5KBlkleEvGeLR1ndjXczrJP7tYMIr zTRA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787236997; x=1787841797; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=EOlP8ddaPlk71VLkEiYFvaBjk4ID6/66RcHruFcFYXo=; b=euon2FgICFqxjvfpBGuZ6+u+Ik5fmAdkbgfGsuzqwYtJJY+lZ88pM9S7we87BVBzro BhxPDIpx3C83cG+wMXj7r+xuBQ+KRk1A7bu7QmmwpXvKgx1886mKL2ICZc9cQmH0W3zH X+U8feCFoFiAspf5UFJ6Tb7vMBUimndKO2PgyIgfgLGUOJMYVd8u297sPxPW7ZLvyPEv Q5Oo3xfCmlu9DZBQqg7fpwT3BC0imzJFGYEDNNFHTWaUmVrgC9NuiEMF+8ve7GGqKEn5 sFuhlh7iKWeJDro55FjUrVsBOKyGcfIHQfrmcy/pVHyLjor8r8Ea4KkEcu70g+lbX5Ln qwfA== X-Gm-Message-State: AOJu0YxkBje8+uhNPuOLVaF1gbyefwFLLmqMGYmNHCLP+NQpml342jqq tNdoSJ5lYl0rMjoN6ZOehG6thIm165Jg1BVPYqCzpVhZU3NxmysbVXK0cBF0Y7zkx3TfBo96c6T 9DpC4 X-Gm-Gg: AR+sD10UEBMKYC8nwoTetA2BzC93PfOLG9JicD/ORVxK0/a2+rTNrcL/ymHwvTvJj7t Jq6e9RwWaYqGsnu9qcnQiVG0kff2qfwrSyfaiDVeXF7hMeAJDzoX8sBlSSS3S3hRMScVbfPgt1r uno+W54Q4oWx0Dq1jWMeuKZwXbqi2I1ZiBrMdHYWc6pYCnKnCRaEWCgP4DLh4oGZWPgAY8bUYd9 901XU4WtOsvwBnSin6OCdMHK5w7gtD2wZuUd0cwtQKQT+5+lpKokvN9NrAwXr5NmAsCS9r28XYO 5urZvXFH2X8NW2b7ZLY+K/Ky0FZQuTOhK1YQLfPJp39hNW42YzZjdx2TYSLcA8rrrrGIx26yv1X HkJRG3IufCL+nb8Jpjm12IUXQiXtBThTef3ujMiFyWMGEJ8UztqBUn4bQObboI2GBb7vuKY9wRN sWQiTASEYeOO8G0HJECF2ferD+9LFOKeQS0rgN92X+544Y9TUQnudu3ZDcy89dIuzA5Kin X-Received: by 2002:a05:600c:3b03:b0:496:bbce:fc with SMTP id 5b1f17b1804b1-499aa1f361emr201443685e9.12.1787236997287; Thu, 20 Aug 2026 07:43:17 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , Katherine Leaver , John Snow , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH 04/11] hw/ide/ahci: clear cur_cmd when the command list is unmapped Date: Thu, 20 Aug 2026 16:43:02 +0200 Message-ID: <20260820144309.835173-5-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260820144309.835173-1-den@openvz.org> References: <20260820144309.835173-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::334; envelope-from=den@openvz.org; helo=mail-wm1-x334.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1787237026843158500 From: Denis V. Lunev ahci_unmap_clb_address() drops the CLB mapping but leaves cur_cmd pointing into it. The cancel added by commit d9f78431d8 covers the buffered reads, and ide_cancel_dma_sync() drains bus->dma->aiocb, but neither reaches IDEState::pio_aiocb: a PIO write started before the guest cleared PxCMD.ST completes afterwards and runs its second DRQ phase against the stale header. That is harmless while the CLB is direct RAM, because unmapping it changes nothing. It is a use-after-free once PxCLB points at an MMIO region, where address_space_map() hands out a bounce buffer that dma_memory_unmap() then frees. Clear cur_cmd after the cancel, so nothing reachable from a later completion still refers to the freed mapping. Reported-by: Katherine Leaver Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3719 Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4043 Cc: John Snow Cc: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Denis V. Lunev --- hw/ide/ahci.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/hw/ide/ahci.c b/hw/ide/ahci.c index 995b40efd5..4c138b0c51 100644 --- a/hw/ide/ahci.c +++ b/hw/ide/ahci.c @@ -743,6 +743,12 @@ static void ahci_unmap_clb_address(AHCIDevice *ad) /* Cancel in-flight reads that would complete against a cleared cur_cm= d. */ ide_cancel_dma_sync(ide_bus_active_if(&ad->port)); =20 + /* + * Whatever survives the cancel must not be left pointing into the + * mapping this function is about to drop. + */ + ad->cur_cmd =3D NULL; + if (ad->lst =3D=3D NULL) { trace_ahci_unmap_clb_address_null(ad->hba, ad->port_no); return; --=20 2.53.0 From nobody Fri Aug 21 21:27:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1787237068; cv=none; d=zohomail.com; s=zohoarc; b=J/1hwTnFZEYRMfE9RLETsRCdbBVAkAm8IqJY23eJtcSo2ijhbyUBU4DpqWfnKpLz1J77UmLeJrjs7fMrK7ot9CtNbN8g8du4JBbB/DH8txi9pZq0hwc4fB9ItjYSI/uYDN9YRWbzCcVBA49idKAKsjy2eKbk1fOtlzoDyoXeO+Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787237068; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=URHXHuB5q+jdDgkSRrqqGTDtFQ6LaDVzcDRgrGWT+KY=; b=ZT+RsKJVi9TycCcXENMYfhIXRBNjroVai/loXNjY0uTKKr8PquNjOgMera+vVzDNMU5vsEek/pjY1Gq7fyRI+WJIvzn4m3HFrgGxP1zasFSCFj+MKj7VcDDJ6T2T4tgTgm5GbOG6fGEKsA5HfRZiQSHeAfmd1SM/XHwrUKkLoI4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787237068277780.4927986250236; Thu, 20 Aug 2026 07:44:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wx3zT-0000dR-HV; Thu, 20 Aug 2026 10:43:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wx3zG-0000ZI-D1 for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:23 -0400 Received: from mail-wm1-x32e.google.com ([2a00:1450:4864:20::32e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wx3zE-0005Aj-Mz for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:22 -0400 Received: by mail-wm1-x32e.google.com with SMTP id 5b1f17b1804b1-499ae1c6471so14258035e9.3 for ; Thu, 20 Aug 2026 07:43:20 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:a123:7b43:afd8:8b47]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499aa0dd620sm136791565e9.13.2026.08.20.07.43.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 07:43:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1787236999; x=1787841799; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=URHXHuB5q+jdDgkSRrqqGTDtFQ6LaDVzcDRgrGWT+KY=; b=CGYg3sY/Hrd0nGqVYg60nGP6R0Kx3V6VI27QFJzrcdg1vQply1WVDcEFXn9nlEeuk6 /JJfqvR1usZE3MVAx1dhRLFlJ7c87zAS/DL1NrDOqKps0w86jPwm4hDBR1sWDjOaJKBT FE+LAgQx2kaffilwkqbKaqVDe7vZYTaPai5cHoBuXfpn26I0bMNzGMhxxg27Y+yrL/SW TEgBawCn2NmHUXKzkxIREOnHAJhrKaPpLa6kj2BXvenYgpsqzD6ZCyz+xWAAh1d0toSj n0qwIj4tjZMElWSJO103z3GI+wGxcShHl3rskR0suPLfhaw6ug1qrTFmICZ7HdHSmUcw CXQg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787236999; x=1787841799; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=URHXHuB5q+jdDgkSRrqqGTDtFQ6LaDVzcDRgrGWT+KY=; b=AsVHtj/Gq8IPr3klCJjOWfEH3W99dhjIllBKtyCYjcJC3MD6UyCXroqUck/RpYGYaa 12A7ARG8ROaFm0n/b7NA9gkROmQgzSQcv/2thbrSm0Oyzo+osew4SmSvhH1uM8pCsKSY JTOM1qZk38+d/EFLcZI314t2pXxlpzV9QmoszI3LDPswjQipzorr0RsxbPLLYEpwp+iO jfzaPPXUzEZ/B25OZtKr1Hl6TCfpX2itApz3oI3i1KIWgCY2BSsoyBlVqTFYF+uT1STG 9Vyt/4JTJlivWUmZILyTEXvWc+b7NI3c8C4q+WiONUmeJFeSpavwKztMnoWHFXaRBe/h Gt+A== X-Gm-Message-State: AOJu0YysWijsFasfl7mS2mp5EavDAoa29+6bzBfhgVhYfpqq+xstfFWr kA2fer/bbJDRzGYNKh06t8YFTzR75NlkBYciul02Wjck/sMXBVfBJqhGo6fPNaH+O1SkWUw6VwD Fpk4D X-Gm-Gg: AR+sD13w6FV8M+rYcs14WUTMVg0DxYvmpBO+kBzxUL0qzfhA+cQJV9IQhtsfyVoCx/+ /TluaCjyEbk0M8f6HRGwdmbbr8HQbTPD0/G0DjQv08U1Xp/lBYFfBgxwlsu9dd3nh/1RQbiQgMT 6QE534OGh6aSLh4PByvo5UppxsRnVeNhdy8nZvxnrGOZ5wjthxz9qg0Lun4nZVlJ+hj02tgXDht Icg/GWeK9Mz7cmh5UyhiNKjivwQlvgIFZn8r+YS/LAKWjElR5e4EQoXiTVXGCBa04hal3gGOQnD n4xIBtwIACv9MOwf62lhEn9rT2Jg1V4oGYC2UnI0xNJm1V+VBGQv53aJrqfc7nU7dXo6jJb7dRb iebDM8uuzMm8x8PL1DxuRBsNZlnldUrzpliecxRJabG6DL1EjpOFMp9LxHnbFkqF5/MPN0snVjq M5MHJy6IQeVPDUJO1vgfE/DOwt/pe2RuvSj4tGqV6/NGJMVVe0I3hTtmjtjQ== X-Received: by 2002:a05:600c:3e0f:b0:499:a79a:694d with SMTP id 5b1f17b1804b1-499aa155e7dmr254530955e9.4.1787236999066; Thu, 20 Aug 2026 07:43:19 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , John Snow , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH 05/11] tests/qtest/ahci: regression test for a PIO write vs. engine stop Date: Thu, 20 Aug 2026 16:43:03 +0200 Message-ID: <20260820144309.835173-6-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260820144309.835173-1-den@openvz.org> References: <20260820144309.835173-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::32e; envelope-from=den@openvz.org; helo=mail-wm1-x32e.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1787237068738158500 From: Denis V. Lunev Add /ahci/io/pio/engine_stop: hold the backend write of a two-sector PIO write with a blkdebug breakpoint, clear PxCMD.ST so the command list is unmapped underneath it, then let the write complete. The second DRQ phase runs from that completion and reaches ahci_pio_transfer() with no command header. Cc: John Snow Cc: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Denis V. Lunev --- tests/qtest/ahci-test.c | 72 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 72 insertions(+) diff --git a/tests/qtest/ahci-test.c b/tests/qtest/ahci-test.c index 30d7005626..84d4e6b0a5 100644 --- a/tests/qtest/ahci-test.c +++ b/tests/qtest/ahci-test.c @@ -1793,6 +1793,76 @@ static void test_atapi_engine_restart_dma(void) test_atapi_engine_restart_in_flight(true); } =20 +/* + * Regression test: a PIO write outlives the command list it was issued fr= om. + * ide_cancel_dma_sync() does not reach s->pio_aiocb, so the second DRQ ph= ase + * runs from the write completion after PxCLB has been unmapped and must n= ot + * touch the command header any more. + */ +static void test_write_engine_stop_in_flight(void) +{ + AHCIQState *ahci; + AHCICommand *cmd; + unsigned char *tx; + unsigned char *rx; + uint64_t ptr; + uint8_t port; + size_t bufsize =3D AHCI_SECTOR_SIZE * 2; + size_t i; + + ahci =3D ahci_boot_and_enable("-drive file=3Dblkdebug::%s,if=3Dnone,id= =3Ddrive0," + "format=3D%s,cache=3Dwriteback " + "-M q35 " + "-device ide-hd,drive=3Ddrive0 ", + tmp_path, imgfmt); + port =3D ahci_port_select(ahci); + ahci_port_clear(ahci, port); + + tx =3D g_malloc(bufsize); + generate_pattern(tx, bufsize, AHCI_SECTOR_SIZE); + ptr =3D ahci_alloc(ahci, bufsize); + g_assert(ptr); + qtest_memwrite(ahci->parent->qts, ptr, tx, bufsize); + + /* Zero the second sector, which the abandoned command must not reach.= */ + rx =3D g_malloc0(AHCI_SECTOR_SIZE); + ahci_io(ahci, port, CMD_WRITE_DMA, rx, AHCI_SECTOR_SIZE, 1); + + /* Suspend the backend write so the first sector stays in flight. */ + g_free(qtest_hmp(ahci->parent->qts, + "qemu-io drive0 \"break write_aio wr\"")); + + cmd =3D ahci_command_create(CMD_WRITE_PIO); + ahci_command_adjust(cmd, 0, ptr, bufsize, 0); + ahci_command_commit(ahci, cmd, port); + ahci_command_issue_async(ahci, cmd); + + /* Drop the command list while the write is still outstanding. */ + ahci_px_clr(ahci, port, AHCI_PX_CMD, AHCI_PX_CMD_ST); + + g_free(qtest_hmp(ahci->parent->qts, "qemu-io drive0 \"resume wr\"")); + + /* Round-trip through the device to confirm qemu is still alive. */ + ahci_px_rreg(ahci, port, AHCI_PX_TFD); + + /* + * The second DRQ phase never fetched its data, so the sector it would + * have carried has to be untouched rather than hold a copy of the fir= st. + */ + ahci_px_set(ahci, port, AHCI_PX_CMD, AHCI_PX_CMD_ST); + memset(rx, 0xff, AHCI_SECTOR_SIZE); + ahci_io(ahci, port, CMD_READ_DMA, rx, AHCI_SECTOR_SIZE, 1); + for (i =3D 0; i < AHCI_SECTOR_SIZE; i++) { + g_assert_cmpint(rx[i], =3D=3D, 0); + } + + ahci_command_free(cmd); + ahci_free(ahci, ptr); + g_free(rx); + g_free(tx); + ahci_shutdown(ahci); +} + /* * Regression test: a multi-sector ATAPI read fetches its later sectors fr= om * inside the first read's completion; a concurrent drain (as a guest reset @@ -2281,6 +2351,8 @@ int main(int argc, char **argv) test_atapi_engine_restart_pio); qtest_add_func("/ahci/cdrom/engine_restart/dma", test_atapi_engine_restart_dma); + qtest_add_func("/ahci/io/pio/engine_stop", + test_write_engine_stop_in_flight); qtest_add_func("/ahci/cdrom/drain/pio", test_atapi_drain_pio); qtest_add_func("/ahci/cdrom/drain/dma", test_atapi_drain_dma); =20 --=20 2.53.0 From nobody Fri Aug 21 21:27:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1787237071; cv=none; d=zohomail.com; s=zohoarc; b=NpIau9Xx3OmDoyLGZt7R1YySAV4ejmTVFzaA6DWtCaRZsIqVHRYDzJMn+q2DPzEQpNfneSM7mjaGhE3w2nLns68UymjyqqZ+NBEw9S1cCPVf6/3Ru3s7vFS1va7sKrklB6LXGm9SB9zIjLsUZH5VTxG6yUynL3YMUV09VCXTF9Y= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787237071; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ZaviRMEZTGypIQA7N5P6+n+kL0KfH+GkmP5oLcPBN3A=; b=gN4LqjXPoVtLaq8V0D+8GxRsbmEUasn6CiTvmvkp/pmWg/+pHG71rYn9DaK0AdnqeJjaXIet/vFH4AZVhE7s4eqEI2T310gwy580Qg4/Px7UaW5cbiRMlUg+EIBT9IF0QWRB4umx1ORRitAdEaCIv3nl9Oitu4hUoFqTQXJnyHw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787237071612956.2841021486223; Thu, 20 Aug 2026 07:44:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wx3zN-0000bs-Vd; Thu, 20 Aug 2026 10:43:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wx3zH-0000ZQ-Pv for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:23 -0400 Received: from mail-wm1-x32a.google.com ([2a00:1450:4864:20::32a]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wx3zG-0005BG-0T for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:23 -0400 Received: by mail-wm1-x32a.google.com with SMTP id 5b1f17b1804b1-499b57cf2f3so3247305e9.0 for ; Thu, 20 Aug 2026 07:43:21 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:a123:7b43:afd8:8b47]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499aa0dd620sm136791565e9.13.2026.08.20.07.43.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 07:43:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1787237000; x=1787841800; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=ZaviRMEZTGypIQA7N5P6+n+kL0KfH+GkmP5oLcPBN3A=; b=pBniTOKdE440QtkyGmvUSJB0TXQ2VgifwWyv8h4LcrcRppwUtDrBaXXWvSk1rlF6is KEI6EqDzZ0woPMK1aY/XD/Gk9JULssWPHu5SGl+5ugq5TgFXuPKwAvMa7tj0QVYbC62a yN2pzAdQVG2uQA8SuwcsoF9/AyaemDsSii3ucD6LIbEQgUAcVLSXGwpJwVt0JyM0fL/t YzdNZ/BHbxNoz+nX+d9pL/vftI7coCSmdckk9gKopd2YE7sHmPghWh7mmixEXJiUWGRK wqvbnAPMJ2g+sYXRm+LUV5g5wT3xfHVNgE+M6rtbPyjFEoecy11FKV78pE7g11HfUVdS F7rg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787237000; x=1787841800; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ZaviRMEZTGypIQA7N5P6+n+kL0KfH+GkmP5oLcPBN3A=; b=j5kl0p+SNH3MzRrmr54F51H/VTPezz1fySL+guZBplUEgaxBv+SoHL2rqgT0Ca47RD PyrLjewdK0KEiZ4zFKL9ugq3xu9e6lFys4etAaHQr4tJsa7fbI219U8n0YSOuGbkeifA pi6XvpTX9CZYjXKiyHRSZkm4KqRa5kcK1oO7+9Siv2FUoaRAEf5JPDR8VwOUIRCBvnqy dH8P8qhLHLhU2CKqEh5iubQurQneeXZAsqkbyG7vxyH0qimU0zX7ai0Q0etTroWEEgNW JiUdZEMw3CCMmeGqdvis3w619w5qSPhXYOqf/OBQzat694xDITnfnUxYk8luQr1fC31O MpPA== X-Gm-Message-State: AOJu0YwVDHDLARmqud9Td8eENkj0MeEGAKE33Q40eJDLfXbprDUb61T6 e90OXjtJgnZHa35k5vEWhNpcGuapEr50jwlXk2toeGj8Qgn3Q1eSwAtsqOozDnRpNPkSyTJtKEL 8z32b X-Gm-Gg: AR+sD13N8KqsHPh/KoBXiEkP187KkoDxa/s33GbTeCJVx/VpjhXZTe+aaKR/pYnmgcA WXpwA+Own8ovNFpqUZTTZ0LnsvRSoBILovIyYiQYtn1G4BYGATerPr7G1pc/DnkqaMnhjiMLOpi cFOsdWuej/yCgAhqD6U8h996Jqh95xjp+ITeOw7YvSoX8aC0eCDuSQuaIy5pIhUtVKkI4S2fa8q WL3/LR/Hrwq0YaJoYNWz2w68RJzPRe/r+fO5zxyfuaAuBnoxQ+aEKg+ZMmlHPhoMpvIT/VD9cep Nkl2WjlCoPSu4OfGeLxQcl8lYyTp9mU0vjL61K13MWO9zscjNDh9s7xcCwQfV+E/6u9JaYoAt+w 8kUv+kiiB/hLwWBu8x662Lr59OzJOetTbVcrBBf+rVOhXQtILxZzXhtBGPJhxj+tFW/RBP7LHR2 37ynnXtG3mBiPLtTSbxG2wSwRy0qOanZl7Z39NSxa+4G190EPwFqpJKtYu+w== X-Received: by 2002:a05:600c:674a:b0:499:5f80:83ac with SMTP id 5b1f17b1804b1-499b06cbaf2mr111834105e9.7.1787237000489; Thu, 20 Aug 2026 07:43:20 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , John Snow , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH 06/11] hw/ide/ahci: treat a failed PRDT walk as a PIO transfer failure Date: Thu, 20 Aug 2026 16:43:04 +0200 Message-ID: <20260820144309.835173-7-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260820144309.835173-1-den@openvz.org> References: <20260820144309.835173-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::32a; envelope-from=den@openvz.org; helo=mail-wm1-x32a.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1787237072798158500 From: Denis V. Lunev ahci_dma_prepare_buf() returns -1 when it cannot build a scatter-gather list, the PRDTL of zero case among them. ahci_pio_transfer() tests the result for truth, so a failure sets has_sglist and the transfer goes ahead against whatever s->sg holds. AHCI 1.3.1 is explicit about the zero case: "If this field is '0', then no data transfer shall occur with the command." Test for a positive byte count instead. A successful walk that yields nothing to transfer is already handled by the size check below. Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4043 Cc: John Snow Cc: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Denis V. Lunev --- hw/ide/ahci.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hw/ide/ahci.c b/hw/ide/ahci.c index 4c138b0c51..436a0eaab6 100644 --- a/hw/ide/ahci.c +++ b/hw/ide/ahci.c @@ -1428,7 +1428,7 @@ static bool ahci_pio_transfer(const IDEDMA *dma) goto out; } =20 - if (ahci_dma_prepare_buf(dma, size)) { + if (ahci_dma_prepare_buf(dma, size) > 0) { has_sglist =3D 1; } =20 --=20 2.53.0 From nobody Fri Aug 21 21:27:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1787237028; cv=none; d=zohomail.com; s=zohoarc; b=MxPHBGsyReVZbfFLIlEKhlh4Pb1rHBh+QbiMtmkOjQA6ewaGnDPMkWk6Lj9A0zce0GKlHSN+GD8farCEcTxJKxGstvmIz+9uxMRk5hEnP4G6h3pGkyGyk4Ru0M9hCaxlWc2F3M/W0tvP3UqLHGRbd3NqxUdacOanuCTRsGsNxc0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787237028; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=npJXYp5DKT7QgT0yXi+L+fK29HlTjiLNKlL3gTl+WQs=; b=JGrNmSfVnwOSEa9pqC0E1VKDER2WTkl9dHWIqnisyKWPdVIEy3UuUDiaynW6aPpcknHghFtHOhRSoOGTEVoHQTb19w6q+Za2B31L1vd3L9+zLMwYqxQmj/Xnu0pbSkKCCUxp/LeK/0SFYtTPli6vf7ps/1fsBOJ2XlKYpMu9V0g= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787237027963491.5303214791238; Thu, 20 Aug 2026 07:43:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wx3zW-0000ee-8U; Thu, 20 Aug 2026 10:43:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wx3zK-0000ab-4R for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:26 -0400 Received: from mail-wm1-x336.google.com ([2a00:1450:4864:20::336]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wx3zI-0005Bd-0B for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:25 -0400 Received: by mail-wm1-x336.google.com with SMTP id 5b1f17b1804b1-49800c6a846so25976905e9.3 for ; Thu, 20 Aug 2026 07:43:23 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:a123:7b43:afd8:8b47]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499aa0dd620sm136791565e9.13.2026.08.20.07.43.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 07:43:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1787237002; x=1787841802; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=npJXYp5DKT7QgT0yXi+L+fK29HlTjiLNKlL3gTl+WQs=; b=HVqOlBFIUyUISioDA++qff4qQcNeQcjOW42SBxRjXrGEQc4UA0t+PwfTsY7m3TSJ1q Bn6bLl89jZIkCwb/J0tP/+z7+Tg+IBx4I1eIp97FLtpEXQRGzOWdsJ619e/qbknzx3k4 X+nU/NCxBr4gxP0D48FZwOv0taPsk/aQ+md5kj47IduT07CtzS2K3jdyTkAhAfVQhOHu RiKj9iLsxyHgNyqOmKj8s2965/oWPCmyFQyZ3Jt4LucbsfNN+y9Fd4sxClGsZLGopEMi K2Axfu8OKTKxsSal9UbN6JqaAYVTy4SwKKLVNSVg3eIqBO/M7VoZne7QixXRDNJth43A M0nA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787237002; x=1787841802; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=npJXYp5DKT7QgT0yXi+L+fK29HlTjiLNKlL3gTl+WQs=; b=sqDU457sKuYfphbvDddo4LusyoUmf4tNKOkBPI//TeIkioBM3OCWiVhFF2YgRsSKtx R85G/SZlq3IByZ1NLMp7XEnUJB6m8w6rP4bGaxKT7n80TgrcT4Fa5MEiJvuXWhkkpQEi 3mFtaOxAsLDIdX7CrwaMgSnPiItEkIgbqYKeEfMGXS2LMu7CKyFMNNnfMEURerAmFAOz tigtfxlLURtvsLNPxxVoN/H/sySfulyRPdfNMDnuefZVqNwOZO4rEJcHPOqoCFso9/YH 5l5W64KMOtpOVfo4X5QD/Kbn9JeCYjCgKKACCXkJ2jLZYvzDBaAJhxTr0Sr36qttlf2D ku+w== X-Gm-Message-State: AOJu0Yy7haWRL/In+peBUjHNNRKne8iSoDyfpdG0MhS92QcK/kyLJ9Ae peKlMaoJHylQB/7EdRCFMUiRg4SRxnXKFfliA8G7asBiz1vGbiOKOHlmQEEeKqXJEJKIelO1EQD 2xPdo X-Gm-Gg: AR+sD11Fpa00PEXWdg7A2WRGsaRbs6D7K7MMNqZ2lhhJ3pd8safCpCRIWL3eSUM5UuW u7VN8mvUqZ682gy9pXC5vb0Rpqq+etqo5XQ1IX8tE8xoSkA/e037dt2Xew5g60h0Ocaxn7XpCo4 z9EZPRd/EPZJzdmM/1quXY8HUUBq3GLrdWPOJcY0fPrhO52rISfnL9W3Qs7zymiRAJG31LJlExm W/SZL6zzq4NFqDUqdIRwDN/zbeJZ1udBuuGNUvRXHWd4L1iysildCzsNH463qM33zaBuKqT0h5T 2kAtQiLzgCha+a1VF/Ta1jR6Lpd0SnssWbhegK2E8s+x2yufqzTYdZCLi0UHhsLkTJ9H79bkqC9 7z809w1jPgGWZNhglyCN+NBZ+Kn+kBZlJxXbM7IwLvVOq2Bh7z1dtPKSkHwGehGjyKh9zqYDGtW wA71EURRHAEtZ0qJQZus4dLOEDfkFKmvuG1hwoFg6W01fhglIWKwzjiOYPvFcsdv9W614B X-Received: by 2002:a05:600c:468c:b0:499:48bb:417e with SMTP id 5b1f17b1804b1-499aa14a72dmr194391465e9.2.1787237001601; Thu, 20 Aug 2026 07:43:21 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , John Snow , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH 07/11] hw/ide/ahci: reject a command header with an invalid FIS length Date: Thu, 20 Aug 2026 16:43:05 +0200 Message-ID: <20260820144309.835173-8-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260820144309.835173-1-den@openvz.org> References: <20260820144309.835173-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::336; envelope-from=den@openvz.org; helo=mail-wm1-x336.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1787237030508158500 From: Denis V. Lunev AHCI 1.3.1 defines CFL in the command header as the "Length of the Command FIS", where "A length of '0' or '1' is illegal" and "The maximum value allowed is 10h, or 16 DW". handle_cmd() never looks at it, so an all-zero command header is executable: its zero tbl_addr maps a command table at guest physical address 0, and a guest that has put a valid Register H2D FIS there gets it run. That is the reachability a guest gains by pointing PxCLB at an MMIO region, where the CLB is a zero-filled bounce buffer rather than anything the guest wrote. Reject a header whose CFL falls outside the legal range. Nothing else consults it; the command FIS is always mapped at its full 128 bytes. The slot is dropped without reporting anything, as the unmappable command table beside it already is. No PxIS bit describes a malformed command header: HBFS is for a host bus error, "such as a bad software pointer", which is why the short mapping below raises it and this does not. Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4043 Cc: John Snow Cc: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Denis V. Lunev --- hw/ide/ahci.c | 9 +++++++++ hw/ide/trace-events | 1 + 2 files changed, 10 insertions(+) diff --git a/hw/ide/ahci.c b/hw/ide/ahci.c index 436a0eaab6..2b2ef873e0 100644 --- a/hw/ide/ahci.c +++ b/hw/ide/ahci.c @@ -1334,6 +1334,7 @@ static void handle_cmd(AHCIState *s, int port, uint8_= t slot) AHCICmdHdr *cmd; uint8_t *cmd_fis; dma_addr_t cmd_len; + uint8_t cfl; =20 if (s->dev[port].port.ifs[0].status & (BUSY_STAT|DRQ_STAT)) { /* Engine currently busy, try again later */ @@ -1346,6 +1347,14 @@ static void handle_cmd(AHCIState *s, int port, uint8= _t slot) return; } cmd =3D get_cmd_header(s, port, slot); + + /* AHCI 1.3.1: a CFL below 2 dwords or above 16 is illegal */ + cfl =3D le16_to_cpu(cmd->opts) & AHCI_CMD_HDR_CMD_FIS_LEN; + if (cfl < 2 || cfl > 16) { + trace_handle_cmd_badcfl(s, port, le16_to_cpu(cmd->opts)); + return; + } + /* remember current slot handle for later */ s->dev[port].cur_cmd =3D cmd; =20 diff --git a/hw/ide/trace-events b/hw/ide/trace-events index f1472f5852..3ab5e7bd1d 100644 --- a/hw/ide/trace-events +++ b/hw/ide/trace-events @@ -106,6 +106,7 @@ handle_reg_h2d_fis_res(void *s, int port, char b0, char= b1, char b2) "ahci(%p)[% handle_cmd_busy(void *s, int port) "ahci(%p)[%d]: engine busy" handle_cmd_nolist(void *s, int port) "ahci(%p)[%d]: handle_cmd called with= out s->dev[port].lst" handle_cmd_badport(void *s, int port) "ahci(%p)[%d]: guest accessed unused= port" +handle_cmd_badcfl(void *s, int port, uint16_t opts) "ahci(%p)[%d]: guest p= rovided an invalid cmd FIS length: 0x%04x" handle_cmd_badfis(void *s, int port) "ahci(%p)[%d]: guest provided an inva= lid cmd FIS" handle_cmd_badmap(void *s, int port, uint64_t len) "ahci(%p)[%d]: dma_memo= ry_map failed, 0x%02"PRIx64" !=3D 0x80" handle_cmd_unhandled_fis(void *s, int port, uint8_t b0, uint8_t b1, uint8_= t b2) "ahci(%p)[%d]: unhandled FIS type. cmd_fis: 0x%02x-%02x-%02x" --=20 2.53.0 From nobody Fri Aug 21 21:27:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1787237076; cv=none; d=zohomail.com; s=zohoarc; b=QG8Wu9YurBOYE9sBURswORoKtBk/hzRwFMI/Gc02AqdKq1/gRV8NEsgdPU+LQj3Wc3I/LWtGs7bnozn0cSNmZKY4ccz4GvmrGG+uOHrTaPgB3Dif3i01dHYEPi4jLeHmKM4KVBgV2ZIbblGajFB22hC2UuYKayaiycLetKdwkrY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787237076; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=UBFPtGvi7DqI4Ui5hNdIN9aVXsLQeDDR8Rmf7GilLVY=; b=PaF7fyMLY0zl9Aokmm8lqQIAaPkZhsPbrBAo4gWKVJqym5Wd9OT5RnOjNROvGSZgttgTHAvfsvzY1ycdsbyDfW4jqaBwaLXQFG6rF/WiMCG5PTimojAYA9ZyJvxH38gVepKxhP34GYIzbfUteP8Cx8tzZOc657Q+9M1ptugyDUk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178723707664759.94437369735533; Thu, 20 Aug 2026 07:44:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wx3zT-0000dS-Ih; Thu, 20 Aug 2026 10:43:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wx3zM-0000b6-4v for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:28 -0400 Received: from mail-wm1-x332.google.com ([2a00:1450:4864:20::332]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wx3zI-0005Bh-7f for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:27 -0400 Received: by mail-wm1-x332.google.com with SMTP id 5b1f17b1804b1-4998b5a63e2so24339575e9.1 for ; Thu, 20 Aug 2026 07:43:23 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:a123:7b43:afd8:8b47]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499aa0dd620sm136791565e9.13.2026.08.20.07.43.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 07:43:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1787237003; x=1787841803; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=UBFPtGvi7DqI4Ui5hNdIN9aVXsLQeDDR8Rmf7GilLVY=; b=WbkaWgs72yMQ/ayr3iM+Aqe4xsjMhrIwRcFAEnngI4yUS7n69Avg3CoWGfs6kaZasg Jri439s9qQMKyK2MJZc3E4U105HKqlfu+TWqROUhpaBY6RxvV0XtKaikyHUL8ASLF8sP sJH21lfLpD2DG93RPnFSWht6z0NXxySjAtmUCKBMLsq6NUJbAbj/n2ls1rqZAY19O7jL vnNSc418yi/Gx/OuZI8CDyzh+xFcVmw5bbV893H5bxFD4OKQHqzOuu/4jNn4OoHPmbCz /UpLK2xwp6NNBOElb2Xj8JEfhvU0xLVW/Y8q7qxt9EkMjJaoQXb2Ai7O6koStzD3H3DM JDwA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787237003; x=1787841803; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=UBFPtGvi7DqI4Ui5hNdIN9aVXsLQeDDR8Rmf7GilLVY=; b=S5xICK6WsUrPmJySzvZxwDz/f87LfVlvVhiyaolMq13TRFWIy6yn0AatRh+TZoZVq0 8l5z7UCaHKfEuvNntk32rcLn6FDiJUJ9JDGT59m5+G777Zu8W85WpzHlG9LEgt8hdnZ3 l5rmwxfOn74bN7HCZNxbqJ8va6ePuYmh+XYeEQp4eSJto0JypZoyED2bhKjouSfKjesP ixZXj9Rh9Rvlv1bB+NKGpQgGmLyv2krTa0Fz/wNTWJVW2vJPmvRHtsHEEcFdIoPetPnr JShSoVz450s5MR9c8ktDZNFYlugE42uWDKFh4LtCMVBBa1yjjCRj309bH423oOJLZadW MB4g== X-Gm-Message-State: AOJu0YySo4mE8o0adarTfO2O0ArzDLaD1JSDhFeIXu81e0P2iKWEpi6J GwEFZietLgWhfI4R8hY1dHsYrow34MyqWmqJhBvlL8BZDl38XOtazhvEXQMpDtUbU+Sp9ejUWG/ 5UxGu X-Gm-Gg: AR+sD10w0EWq8oAROXnMT1NNuAP+9MbHTF3oNteDnfwHI0H0rGwuDBrErW0rN8354d/ 10PK0YB1+iQBeEJ0+JfjKcw7GI1vGuOP07Gl8phb5nSH7qDxfJSQbT2NezeH9bpepmoD+OKquU0 qWlEbL/FsaubGeMyu/O1q5rxwHu/Z+raSJ/lTVv1G1Fp4P2lO5ht0SsdWAuXOL/RVu4XpdJu6Pn oZaaJE7BW9sdlZxeC+xW4AgrBS0mtqZLhcWSlfa8AhNZKLGYAdGGxbDsIcxs26e55id1yscX0Hx z6FFcTtAlWmpUOXhmIEX31+QBIcSl5UOh5LqnvBZhx4fPA+Mx2YVkks3FtoDJq6VKRTiCjXisU3 FkKJtjBeh9OFP7+vuOfRAfv2p0cQa0Uo8llgfl2Lfll5E3TjoV96GrcyiOMvo7ovdlXDRj//FQ2 k4YF4OQB7I1xivOKFsg445GGvxdPt31gcXiKyac37TwZ51vfpZlk6axcfbSA== X-Received: by 2002:a05:600c:628d:b0:499:8ae1:b900 with SMTP id 5b1f17b1804b1-499aa1c9610mr245799395e9.12.1787237002714; Thu, 20 Aug 2026 07:43:22 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , John Snow , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH 08/11] hw/ide/ahci: drain the ports on teardown Date: Thu, 20 Aug 2026 16:43:06 +0200 Message-ID: <20260820144309.835173-9-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260820144309.835173-1-den@openvz.org> References: <20260820144309.835173-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::332; envelope-from=den@openvz.org; helo=mail-wm1-x332.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1787237078718158500 From: Denis V. Lunev ahci_uninit() frees s->dev without touching the requests still in flight. The only blk_aio_cancel() for them lives in ahci_reset_port(), which the unplug path does not run, and the ide-hd child's own drain is deferred through call_rcu so it happens after the free. A guest that powers the root port slot off through SLTCTL, or writes the ACPI ejection register, while a read is outstanding therefore leaves the completion to run against freed memory. A plain device_del is not affected: the pciehp attention-button flow resets the secondary bus first, which cancels through the reset path. Surprise removal is what skips it. Cancelling the NCQ requests alone is not enough. IDEDMA and IDEBus are embedded in AHCIDevice, so a plain DMA read reaches the freed array through dma_blk_cb() and a PIO read through ide_buffered_readv_cb(), neither of which the NCQ bookkeeping covers. ide_exit() drains nothing and frees io_buffer, which an outstanding request may still target. Move the NCQ cancel loop into a helper, run it from ahci_uninit() too, and drain each port before ide_exit() so no class of request can outlive the allocation. Delete check_bh there as well; qemu_bh_new_guarded() in check_cmd() has no counterpart on this path either. Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4069 Cc: John Snow Cc: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Denis V. Lunev --- hw/ide/ahci.c | 72 +++++++++++++++++++++++++++++++++++---------------- 1 file changed, 49 insertions(+), 23 deletions(-) diff --git a/hw/ide/ahci.c b/hw/ide/ahci.c index 2b2ef873e0..6b04762c4a 100644 --- a/hw/ide/ahci.c +++ b/hw/ide/ahci.c @@ -619,12 +619,37 @@ static void ahci_set_signature(AHCIDevice *ad, uint32= _t sig) s->lcyl, s->hcyl, sig); } =20 +static void ahci_cancel_ncq_requests(AHCIDevice *ad) +{ + int i; + + for (i =3D 0; i < AHCI_MAX_CMDS; i++) { + NCQTransferState *ncq_tfs =3D &ad->ncq_tfs[i]; + ncq_tfs->halt =3D false; + if (!ncq_tfs->used) { + continue; + } + + if (ncq_tfs->aiocb) { + blk_aio_cancel(ncq_tfs->aiocb); + ncq_tfs->aiocb =3D NULL; + } + + /* Maybe we just finished the request thanks to blk_aio_cancel() */ + if (!ncq_tfs->used) { + continue; + } + + qemu_sglist_destroy(&ncq_tfs->sglist); + ncq_tfs->used =3D 0; + } +} + static void ahci_reset_port(AHCIState *s, int port, IDEResetKind kind) { AHCIDevice *d =3D &s->dev[port]; AHCIPortRegs *pr =3D &d->port_regs; IDEState *ide_state =3D &d->port.ifs[0]; - int i; =20 trace_ahci_reset_port(s, port); =20 @@ -645,27 +670,7 @@ static void ahci_reset_port(AHCIState *s, int port, ID= EResetKind kind) return; } =20 - /* reset ncq queue */ - for (i =3D 0; i < AHCI_MAX_CMDS; i++) { - NCQTransferState *ncq_tfs =3D &s->dev[port].ncq_tfs[i]; - ncq_tfs->halt =3D false; - if (!ncq_tfs->used) { - continue; - } - - if (ncq_tfs->aiocb) { - blk_aio_cancel(ncq_tfs->aiocb); - ncq_tfs->aiocb =3D NULL; - } - - /* Maybe we just finished the request thanks to blk_aio_cancel() */ - if (!ncq_tfs->used) { - continue; - } - - qemu_sglist_destroy(&ncq_tfs->sglist); - ncq_tfs->used =3D 0; - } + ahci_cancel_ncq_requests(d); =20 s->dev[port].port_state =3D STATE_RUN; if (ide_state->drive_kind =3D=3D IDE_CD) { @@ -1659,8 +1664,29 @@ void ahci_uninit(AHCIState *s) for (i =3D 0; i < s->ports; i++) { AHCIDevice *ad =3D &s->dev[i]; =20 + /* + * Unplug does not go through a reset, so this is the only chance = to + * detach the requests and the bottom half that would otherwise wa= lk + * s->dev after it is freed below. + */ + ahci_cancel_ncq_requests(ad); + if (ad->check_bh) { + qemu_bh_delete(ad->check_bh); + ad->check_bh =3D NULL; + } + for (j =3D 0; j < 2; j++) { - ide_exit(&ad->port.ifs[j]); + IDEState *ide_state =3D &ad->port.ifs[j]; + + /* + * Everything the port still owns points into the allocation t= his + * function frees, io_buffer included, so nothing may be left = in + * flight once ide_exit() has run. + */ + if (ide_state->blk) { + blk_drain(ide_state->blk); + } + ide_exit(ide_state); } object_unparent(OBJECT(&ad->port)); } --=20 2.53.0 From nobody Fri Aug 21 21:27:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1787237064; cv=none; d=zohomail.com; s=zohoarc; b=eRdYp5AJ5I6ZYC8/Aunl/KWIe76JPZoT7TFvGQrLKrp8OgR1PI2HvH0XsJRBZ6gRb2CFd9NZEl5OHETMpqbhwaRGlDzb9510XtNmVbg4jrBNu+gZGEoQ1oES8EQZg8kW2IdyeXo3XKtFmE8NPz4XskDjy1zAToVoL95UZ0uqpz0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787237064; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=1VlpdsOBokS3SNvIYS8d4wFOPLdoOB4ncFQBcaVMfCo=; b=hSjORN6SfTA55HQM0QJatQHxB9QuLox/QaPqxAm5pUp6b+pXqvxTY2Jc9D9azm5liE7UdWhowvNGtrclYwTEo9+IclLyzWVVMCStHad/+a5wIbyh+aJPmT+oHb5dN4ZkYlgx951SKG2I/hZ3cK2MN7SHBl3skMhMxk+czplYMxk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787237064081557.6474800769075; Thu, 20 Aug 2026 07:44:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wx3zW-0000eO-1D; Thu, 20 Aug 2026 10:43:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wx3zN-0000bf-9T for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:29 -0400 Received: from mail-wm1-x329.google.com ([2a00:1450:4864:20::329]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wx3zJ-0005C6-Rc for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:29 -0400 Received: by mail-wm1-x329.google.com with SMTP id 5b1f17b1804b1-499b02fc590so10443475e9.2 for ; Thu, 20 Aug 2026 07:43:24 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:a123:7b43:afd8:8b47]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499aa0dd620sm136791565e9.13.2026.08.20.07.43.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 07:43:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1787237004; x=1787841804; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=1VlpdsOBokS3SNvIYS8d4wFOPLdoOB4ncFQBcaVMfCo=; b=OdaQ72PdB2eWOIkZH55A/psAcEWljEzxh/L3v6TRD/r2tknYv+JwlFYLsmkFZFDRKa SuUE/EyfpE5p27l67leE5TjTUHBKbA3WnIFJN7173k6MeevN7cnPXiZVncNyhkLvtETs yeORNjako700TzTvI3dNUFqUlIbDhWeAqzSGygLbFjuDjI2KMNrPltFpqOgsyh6hNtpw rWqEQzgvxlmUbnPYKjKMh2/PmL89FHtOZRJvjZUk9Q0+9HvZQkUizibY4fdpYLKQYj44 YfPlqLn6wjodusjYP9sJaiQT60JNnoR5P4ADHiCG18KojIcmXzbHsbiJg0mdakf2kyls jL6g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787237004; x=1787841804; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=1VlpdsOBokS3SNvIYS8d4wFOPLdoOB4ncFQBcaVMfCo=; b=oc1Ov0LF9XLazZk/bcDWKwi9B4QxG3ZVF/MUI2w0fONfVcjmYMx9lUhSxyLifKHtkV CF3YKvcQEmlml5vWDDkIUNVjUgkvgRPbpE+dztktQ2MKOyicpYNd6T67XkbnrlwhfJ+C 6grNPN8R7y5o9NVDfTTU3vAp9euKhMWSdLpFPcakPYgCoe4kF2jiPyH8oi+5lNFhUGJ1 QPjucPzOFnDL0aXyIsbNoXNMn3EybHGYO2PPAAUAPKcAr3NEAnOvdNJCWp7ZWGZ3xaRj Gx19OkYW2Ycmb0vrBJaHsoDydSp1+nSVjMxPkaD/59ZFq30KD23hsXAu7kHchUTKwTeP BStw== X-Gm-Message-State: AOJu0Yw3z5wFKX+arhpe664+uNpwF0OD23qqUfNoiTFvfMWMDlr/T5sF 1+9lAMX4aZna62CdhP8VuvVy5GSLl1x8wVK+0J3VLhpnhNNLpyZN2zZNjrAli54knDGYCyNglq6 LiDqL X-Gm-Gg: AR+sD12w6RBDTUIFw8NB2cvLgqYJvhMy6EWDKvIzEUChpigBUU8b7+qEoZFlyQ/H9LG rV3NK0QD1fi38iXAJw4/Tttsw5chTg2FyARFvUKVcCCxbpzMGtRVbVwpSRzsc/56p6m2/i80Nln BtO0fs/ctfQgoBKPYhnjSVuT6eAseKnMqOkz+TgFt3dyu8ogKD7Gs554V20etLh9haXIuS2YOLW GB8e8JLUoYL6emX14DVMf9x5Attors3dadmRtpLcjNCShwfpr0uFfK5e2UhOFiOUOKSUUkwZqb8 V+eycBy1d/S0wqf+38F7CQfNbMSnzdYmoKv1crJxwfaY3abdPW1S4G7WWEm9DBCAYSRANBjyhGY WfgazfZGPTKCdeEXHILByEyB9ebSevvRCpyWq2I3Q5+XLLEjJHW2tJcsgkQEzvQjDtmftqau58n xKdTRC44l2iQswfd1rmDWonIKGtyOVcqwS7h7W2MCMowm3ZuezjqFmuAW0lQ== X-Received: by 2002:a05:600c:a402:b0:499:b65d:1250 with SMTP id 5b1f17b1804b1-499b65d127bmr16572435e9.2.1787237003785; Thu, 20 Aug 2026 07:43:23 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , John Snow , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH 09/11] tests/qtest/ahci: regression test for a request outliving an unplug Date: Thu, 20 Aug 2026 16:43:07 +0200 Message-ID: <20260820144309.835173-10-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260820144309.835173-1-den@openvz.org> References: <20260820144309.835173-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::329; envelope-from=den@openvz.org; helo=mail-wm1-x329.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1787237064711158500 From: Denis V. Lunev Add /ahci/io/{ncq,dma,pio}/unplug: arm a read against a null-co backend whose latency keeps it in flight, then eject the controller through the ACPI ejection register. Each of the three reaches the freed AHCIDevice array by a different route, so covering one command class would leave the other two untested. That register is what a guest writes to finish a PCI unplug, and unlike the pciehp attention button it reaches ahci_uninit() with no secondary bus reset, so nothing cancels the request on the way. It also dictates the machine: q35 has no ACPI hotplug on pcie.0, so the eject has no effect there. The latency is what holds the request; a blkdebug breakpoint cannot stand in for it, because cancelling a suspended request waits for it and the unplug would never return. Unfixed, all three fail reliably under AddressSanitizer. On a plain build the use-after-free only faults when the freed page has been returned, so expect the odd pass there. Cc: John Snow Cc: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Denis V. Lunev --- tests/qtest/ahci-test.c | 75 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 75 insertions(+) diff --git a/tests/qtest/ahci-test.c b/tests/qtest/ahci-test.c index 84d4e6b0a5..b143862ce7 100644 --- a/tests/qtest/ahci-test.c +++ b/tests/qtest/ahci-test.c @@ -1793,6 +1793,78 @@ static void test_atapi_engine_restart_dma(void) test_atapi_engine_restart_in_flight(true); } =20 +/* + * Regression test: an unplug runs no device reset, so it is the last chan= ce to + * detach an outstanding request. Its completion would otherwise walk the + * AHCIDevice array that ahci_uninit() has freed, which each of the NCQ, D= MA + * and PIO completions reaches by a different route. + * + * The ACPI ejection register is what a guest writes to finish a PCI unplu= g. + * -M pc is what puts it in reach: q35 has no ACPI hotplug on pcie.0, so t= he + * unplug never happens there. Unlike the pciehp attention button this rea= ches + * the unplug with no secondary bus reset, which is the ordering that leav= es a + * request outstanding. + */ +static void test_unplug_in_flight(uint8_t ide_cmd) +{ + AHCIQState *ahci; + AHCICommand *cmd; + uint64_t ptr; + uint8_t port; + QTestState *qts; + + /* + * The latency keeps the backend read in flight across the unplug. A + * blkdebug breakpoint cannot stand in for it: cancelling a suspended + * request waits for it, so the unplug would never return. + */ + ahci =3D ahci_boot_and_enable( + "-M pc " + "-blockdev driver=3Dnull-co,node-name=3Ddrive0,read-zeroes=3Don," + "latency-ns=3D100000000 " + "-device ich9-ahci,addr=3D1f.2,id=3Dahci0 " + "-device ide-hd,drive=3Ddrive0,bus=3Dahci0.0 "); + qts =3D ahci->parent->qts; + port =3D ahci_port_select(ahci); + ahci_port_clear(ahci, port); + + ptr =3D ahci_alloc(ahci, AHCI_SECTOR_SIZE); + g_assert(ptr); + + cmd =3D ahci_command_create(ide_cmd); + ahci_command_adjust(cmd, 0, ptr, AHCI_SECTOR_SIZE, 0); + ahci_command_commit(ahci, cmd, port); + ahci_command_issue_async(ahci, cmd); + + /* Eject slot 0x1f of the root bus, which frees the AHCIDevice array. = */ + qtest_outl(qts, 0xae10, 0); + qtest_outl(qts, 0xae08, 1u << 0x1f); + qtest_qmp_eventwait(qts, "DEVICE_DELETED"); + + /* Four times the backend latency, so the completion has surely run. */ + g_usleep(400 * 1000); + qtest_qmp_assert_success(qts, "{ 'execute': 'query-status' }"); + + ahci_command_free(cmd); + ahci_free(ahci, ptr); + ahci_shutdown(ahci); +} + +static void test_unplug_ncq(void) +{ + test_unplug_in_flight(READ_FPDMA_QUEUED); +} + +static void test_unplug_dma(void) +{ + test_unplug_in_flight(CMD_READ_DMA); +} + +static void test_unplug_pio(void) +{ + test_unplug_in_flight(CMD_READ_PIO); +} + /* * Regression test: a PIO write outlives the command list it was issued fr= om. * ide_cancel_dma_sync() does not reach s->pio_aiocb, so the second DRQ ph= ase @@ -2351,6 +2423,9 @@ int main(int argc, char **argv) test_atapi_engine_restart_pio); qtest_add_func("/ahci/cdrom/engine_restart/dma", test_atapi_engine_restart_dma); + qtest_add_func("/ahci/io/ncq/unplug", test_unplug_ncq); + qtest_add_func("/ahci/io/dma/unplug", test_unplug_dma); + qtest_add_func("/ahci/io/pio/unplug", test_unplug_pio); qtest_add_func("/ahci/io/pio/engine_stop", test_write_engine_stop_in_flight); qtest_add_func("/ahci/cdrom/drain/pio", test_atapi_drain_pio); --=20 2.53.0 From nobody Fri Aug 21 21:27:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1787237113; cv=none; d=zohomail.com; s=zohoarc; b=Iqmmx71Lg2dZd6OBnqX0CvTrk74buU/vco0l1fY5wDbxNled59nasIulTXQ0nf+KrjGBPSKZTa+drZ1+oM4pPHQHExiB0W0cfcrNwYAPJBPzTdW+TmI9bXswEirTjaluQT9W4YuFEx23yISvofubBxFkrtakuiZyLSApbTGshq4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787237113; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=TJBKDx/NPPo3M962XW23quyF1pb9lG1A3xeKFPd765A=; b=CRLoh5r4lexbX9WTwMnwiIj339tiF3pxfPt6m7nbvPCVRMZJSaDMh0A0esy0pRiqm99M+BqwUmM4cT6uFwSwWPEeil2PL0425eJwII9o0X1twA6RqhDikaxt1fNh+vgRmAFjtmfnFss6bBfPwYYHXZC/95RltjxD1K/pq5/Nk88= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787237113623525.808447755524; Thu, 20 Aug 2026 07:45:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wx3zW-0000fJ-Qg; Thu, 20 Aug 2026 10:43:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wx3zN-0000bi-Ck for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:29 -0400 Received: from mail-wm1-x331.google.com ([2a00:1450:4864:20::331]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wx3zK-0005CG-5e for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:29 -0400 Received: by mail-wm1-x331.google.com with SMTP id 5b1f17b1804b1-495437bb891so8373205e9.1 for ; Thu, 20 Aug 2026 07:43:25 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:a123:7b43:afd8:8b47]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499aa0dd620sm136791565e9.13.2026.08.20.07.43.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 07:43:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1787237005; x=1787841805; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=TJBKDx/NPPo3M962XW23quyF1pb9lG1A3xeKFPd765A=; b=LWR3vaJHqSTxMiVpucbUMNLqTugemSyDHaMcNxBhV1sEPSAbXopE56L92oeN50QDOQ yYM5ehLvrPCyxCRj+JIsKfvjXvaWF0ah0xkqEkhPM8qTvCWs6bp1aYnDolY/Mi744pwF 1+mhAVpbvXC66Pr0WfrZTcgPeRVVfxN1ggxqQUaCAyUc5Qac0UtLL/eGAYgwX/4Xg3rS jgy9dDfmgocElWhzatKRp8iKYHAT9zuMguOGrmOcKgmZvZivCKQriaihkZ2RcC7L8mIz TY4J3ELV8TlUe4qCYEKW7ZfEz1gowK3sqDQy0xDB3HevTGmCkPhxS9HlE7C43QIiT18i GC+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787237005; x=1787841805; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=TJBKDx/NPPo3M962XW23quyF1pb9lG1A3xeKFPd765A=; b=P/CI+WAbjeAzjfCuM6G5jWwpkqXKDNPOoko43Z6Td3vqaUHnkyvztMaMrGbNKOtlfF 9+S3Y/1c42JB77jMixqtouDbxDU0zO9rJrR5cLdt9ybe32HyJ83KzlGNett1n7fPDV0l NziRSkr12bhApQcjLSt2awdvvrGb4apgF72ToKTB0OoFs+AIsFoz/qHsPoM8lgd9shyM v7Ujre7rdSUdHqRb96Mp8ErMCvisESbgnufy50YrIgJ29xrUnmBKPNpA5yd+vCGqn+/+ G7uZ6t0HOJrsyD0OzI5ID2zLJJQ2TqY+u0/2YIEfVveDSqeYhQvsbpt8ouG7OsRQctn8 oCGw== X-Gm-Message-State: AOJu0YwlxK4DJ7vQmyI//tAq4xt1Tg9iTBnMNZGxT7i+ThYbDVM3P4sD inAevpgfIcVwKQGUVHgt4XiCvop61Y0idyhJIe41j6rZOWDBmTRauazEnHd/VDa8vIIV4IG5lPC FrI2N X-Gm-Gg: AR+sD10n2W9k3Dw5c4Y8lqxsJTL9wdX2fkApWOUzP0xbCE6iQswV/7ANiBytLk5yv2S pOkWJkkRp8PsaZuuLaddxiK62MiXuSZoZz4oBSxMXXHwSZ75F/wueyw3u6MTbIPm5pJ6wbsYIPp ihOVbVypqo8i2zQJL+aYMLL74FgQHhIWMRLygH9IGH56+zwxnB8ToLDWR9r/y2lhLynIZYYuBGT D+a3ZS7p4P7r/Xq+C5/+mYDzK3wRXQTeCU7f5C4xuga68tggx/ukfveiH9K+JexhMY0R96Qmn5e FkDfbWU7TtQQ4XUag6Xs+9a45OuJyg/q3eZuFb1dhca+tVPxrSJpG5uL0VXvlRRErnYoarYTLxc ZGznkYdObdh/BT4zBBRCDNyLbGybgX6tPbtpxG74LAdIkk8/HilGskRxpAN+8fhTQQpLAK8gvOp 8IhsqeC0nmd6s2a+TOeKQvbBZT8Tn8evuy5+vlHjzX8Jn4+xs+DY9o9nGXsTZ8rLv/trLv X-Received: by 2002:a05:600c:674a:b0:499:5f80:83ac with SMTP id 5b1f17b1804b1-499b06cbaf2mr111842375e9.7.1787237004806; Thu, 20 Aug 2026 07:43:24 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , John Snow , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH 10/11] hw/ide: report ATAPI UDMA5 with a matching standard and cable Date: Thu, 20 Aug 2026 16:43:08 +0200 Message-ID: <20260820144309.835173-11-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260820144309.835173-1-den@openvz.org> References: <20260820144309.835173-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::331; envelope-from=den@openvz.org; helo=mail-wm1-x331.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1787237115099158500 From: Denis V. Lunev IDENTIFY PACKET DEVICE claims UDMA mode 5 in word 88 while word 80 reports support only up to ATA/ATAPI-4. UDMA5 first appears in ATA/ATAPI-6; ATA/ATAPI-5 stops at mode 4. Bits 3:1 of word 80 are obsolete in IDENTIFY PACKET DEVICE data as well, so the old 001eh claimed three standards that mean nothing for a packet device. Report 0070h, ATA/ATAPI-4 through ATA/ATAPI-6. Word 93 was left unset, so nothing reported the 80-conductor cable that UDMA5 needs. Fill it in, but only for a parallel attachment: ACS-3 7.13.6.41 gives word 93 of IDENTIFY PACKET DEVICE data the meaning of word 93 of IDENTIFY DEVICE data, where "For SATA devices, word 93 shall be set to the value 0000h". A cleared ncq_queues is how both identify paths already tell a parallel attachment from an AHCI one. The device 0 reset result is 0fh rather than the 01h ide_identify() reports: bit 3 says diagnostics passed, which they did, and bits 2:1 say the device number came from some other method, the only one of the four encodings that is not a jumper, CSEL or reserved. Raising word 80 has a second effect. Linux decides a device is SATA in ata_id_is_sata(), which wants word 93 clear and word 80 at ATA/ATAPI-5 or later. An AHCI CD-ROM satisfied neither condition before and was taken for a parallel device; now it satisfies both. Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4038 Cc: John Snow Cc: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Denis V. Lunev --- hw/ide/core.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/hw/ide/core.c b/hw/ide/core.c index 06c18dbf09..ef573798d9 100644 --- a/hw/ide/core.c +++ b/hw/ide/core.c @@ -292,7 +292,7 @@ static void ide_atapi_identify(IDEState *s) put_le16(p + 76, (1 << 8)); } =20 - put_le16(p + 80, 0x1e); /* support up to ATA/ATAPI-4 */ + put_le16(p + 80, 0x70); /* support up to ATA/ATAPI-6 */ if (s->wwn) { put_le16(p + 84, (1 << 8)); /* supports WWN for words 108-111 */ put_le16(p + 87, (1 << 8)); /* WWN enabled */ @@ -300,6 +300,10 @@ static void ide_atapi_identify(IDEState *s) =20 #ifdef USE_DMA_CDROM put_le16(p + 88, 0x3f | (1 << 13)); /* udma5 set and supported */ + if (!s->ncq_queues) { + /* word 93 is parallel ATA only, a SATA device reports zero */ + put_le16(p + 93, 0x600f); + } #endif =20 if (s->wwn) { --=20 2.53.0 From nobody Fri Aug 21 21:27:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=openvz.org ARC-Seal: i=1; a=rsa-sha256; t=1787237109; cv=none; d=zohomail.com; s=zohoarc; b=jJTZ9bhEt+3tlVh38ppslyiugDPO9vFf3H4UEBLAZaAHcSKMKpQJIxROCN1/O9E/4CFBRwZeWT7GGCwlwjJk8/5RnHKaTxmpvRqA5NTpA/VtjcAQEX8aGQ+HQItNJvOY2QLRsyhqYTsFwenRLlaX6Az2QhBg26Ug2d/r2HR7IqI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787237109; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=JkvYru+AQEGMlynpUI5Ee0eR/pHZUMGShiT/2sIrv9g=; b=U7kAcgD5nlkCo1Hv9q/Axjf86cWduAsbcdzrQKt0B2b/ipo494srq4d6MBTbFnUs8n1Ec1KdZAeAruIFHceePeGiD6cVYBD+Sl/BUZjsdLQ35/AqmGLw7NPt+txBD9nwHtCo0AxbVX3D5lVhV1yS/D6naTnFGaX0WBayQzDWeE4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178723710961764.12537256689984; Thu, 20 Aug 2026 07:45:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wx3zY-0000gV-H2; Thu, 20 Aug 2026 10:43:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wx3zN-0000bh-Bv for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:29 -0400 Received: from mail-wm1-x336.google.com ([2a00:1450:4864:20::336]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wx3zL-0005CX-4f for qemu-devel@nongnu.org; Thu, 20 Aug 2026 10:43:29 -0400 Received: by mail-wm1-x336.google.com with SMTP id 5b1f17b1804b1-4953de5be0aso20259005e9.0 for ; Thu, 20 Aug 2026 07:43:26 -0700 (PDT) Received: from athena.sw.ru ([2a06:5b06:b600:300:a123:7b43:afd8:8b47]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499aa0dd620sm136791565e9.13.2026.08.20.07.43.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 07:43:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openvz.org; s=google; t=1787237006; x=1787841806; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=JkvYru+AQEGMlynpUI5Ee0eR/pHZUMGShiT/2sIrv9g=; b=YBBEHcsd1fKtFOslb5emliU64yWH1AcY/5yQgTlM4YL0IRGZIHYbp/3ZucGyCk1cqg 3ASIjY7C49Hm73lgzOOHYQW6QIRVmnkPmKsKfkTQvGYSTAH9yO7BmA1ehNbv9+7eURWw woWI14pP1BTXOGWei3Q/392K/d4KrqMnZyeBiOwuszKrYyc3NJQTwHDUHmqTipvkBL6k /3QwxDJsODQDq5KlpiKTG5rHNPLgojocTni41deaUD20i0gMypESOXE8XROJTnaBdWqu A/5U83zf6XOK+MX+pBjZda74XqQ6m5rwCmZ6sTX/9fztgKV+EgMIqSeKxaVCytQXojEo aBZQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787237006; x=1787841806; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=JkvYru+AQEGMlynpUI5Ee0eR/pHZUMGShiT/2sIrv9g=; b=oSzTCUStkmKgBcCK/zyJTz0UA0PQ4hhNGlXQegv4QcHgTEQYMe07RCNs2lReOIaoRa ysMTvKTtlP76HVDNWkp5MRxqDnLu2CXefsq8mKrYSDqt91f0R008WifBJmyy4HixJUW8 6J5hE/DE6poUYprIDtXhApuiIvV4dLmwgg8kbbLaWGnfK+mc/Si4keoEQWf49oBvn6Qh NAuik2a3dZV7+eHucBcMLMnL/6YmHt02yy/SOlW5lLYJYztszVHkmGEBYRPPFMpUtiWX 6qIx7fxevGt6Q4qa6KyTEfRBY3xTum0yG5awrWyAdRzk/4iiKoWj75J23wMjl0Mmai20 sXgw== X-Gm-Message-State: AOJu0YzS0btzy6qpQrKimZuvdtM9q4ox6Sp/UFT4VRsLTFFwBMS7Cl3K OJj4IYoPbGdajSMkNKrsxIJVRlvGUPntiN6DPC1rAYBDxRwxJ76cdi8Nmji2KQsgb8rqtu85QnK LR8KD X-Gm-Gg: AR+sD12QkaV6d4HTKynDKaq4vsDBLliketqORKr0AGfhXZQA+gLQG6RB44Db2JuoDqi cB8EJOnKe+2Td3ukQY1Yk++Mx0IeJIiD9PLrnokr1XFvGnCsaaQZTcVYaobwqDsDMxSK7iC0ZVy 2w6j2Inn6yTxWNPQ5jSiXMspmLTTAYFqHFrXuP0qHv0/tuu5BDtvzX5VX7vrmKFo8bek6NyI1EC vkYN6zB7L/BdWQHg67kJGprWdGyJBa7KphtjP+Eggy8jVp4E/a3ttvtcX6lBNTQqpXdAAkiIVvu Fmww/InizhfQrZd2MCNvj1gKdP7H/7THexeNIpCw2PqRRMWC16POfloCfhwgPjkP0v+BYVLcIto K+zAcQZBkx14LARRKCWSSun1tH5akSb5gp5KzxE576QbHr8rTZOns5weDAVbjLnI9rKOxhBEbLR 7YSHjcTHdL18BGJIcjyug0WJ9vEwrEEJt4WgF5SKMyBoCNAoyrvwvvGZqVtQ== X-Received: by 2002:a05:600c:6308:b0:499:80d0:8b73 with SMTP id 5b1f17b1804b1-499aa171fd8mr240538595e9.4.1787237005754; Thu, 20 Aug 2026 07:43:25 -0700 (PDT) From: "Denis V. Lunev" To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, "Denis V. Lunev" , John Snow , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH 11/11] tests/qtest/ide-test: cover the UDMA5 identify words Date: Thu, 20 Aug 2026 16:43:09 +0200 Message-ID: <20260820144309.835173-12-den@openvz.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260820144309.835173-1-den@openvz.org> References: <20260820144309.835173-1-den@openvz.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::336; envelope-from=den@openvz.org; helo=mail-wm1-x336.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @openvz.org) X-ZM-MESSAGEID: 1787237110814158500 From: Denis V. Lunev /ide/identify/udma and /ide/identify/udma_atapi check that a device advertising UDMA mode 5 claims a standard that defines it and reports the hardware reset result, on the disk and on the CD-ROM. The ATAPI case also checks that the words obsolete in IDENTIFY PACKET DEVICE data stay clear, and that the reset result reports a passed diagnostic, which only the packet path does so far. Cc: John Snow Cc: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Denis V. Lunev --- tests/qtest/ide-test.c | 69 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 69 insertions(+) diff --git a/tests/qtest/ide-test.c b/tests/qtest/ide-test.c index a3109da908..92e3d9b343 100644 --- a/tests/qtest/ide-test.c +++ b/tests/qtest/ide-test.c @@ -104,6 +104,7 @@ enum { CMD_FLUSH_CACHE =3D 0xe7, CMD_IDENTIFY =3D 0xec, CMD_PACKET =3D 0xa0, + CMD_IDENTIFY_PACKET =3D 0xa1, CMD_READ_NATIVE =3D 0xf8, /* READ NATIVE MAX ADDRESS */ =20 CMDF_ABORT =3D 0x100, @@ -1571,6 +1572,72 @@ static void test_migrate_chs_rejected(void) unlink(path); } =20 +/* + * A device advertising UDMA5 has to claim a standard that defines it, and= a + * parallel attachment has to report the cable word (ACS-3 7.12.7.47). + */ +static void test_identify_udma(bool packet) +{ + QTestState *qts; + QPCIDevice *dev; + QPCIBar bmdma_bar, ide_bar; + uint16_t buf[256]; + int i; + + if (packet) { + qts =3D ide_test_start("-device ide-cd,bus=3Dide.0"); + } else { + qts =3D ide_test_start( + "-blockdev driver=3Dfile,node-name=3Dhda,filename=3D%s " + "-device ide-hd,drive=3Dhda,bus=3Dide.0,unit=3D0 ", + tmp_path[0]); + } + dev =3D get_pci_device(qts, &bmdma_bar, &ide_bar); + + qpci_io_writeb(dev, ide_bar, reg_device, 0); + qpci_io_writeb(dev, ide_bar, reg_command, + packet ? CMD_IDENTIFY_PACKET : CMD_IDENTIFY); + for (i =3D 0; i < 256; i++) { + buf[i] =3D qpci_io_readw(dev, ide_bar, reg_data); + } + + /* UDMA5 supported and selected */ + assert_bit_set(buf[88], 1 << 5); + assert_bit_set(buf[88], 1 << 13); + + /* UDMA5 arrived in ATA/ATAPI-6, so word 80 has to reach bit 6 */ + assert_bit_set(buf[80], 1 << 6); + if (packet) { + /* Bits 3:1 are obsolete in IDENTIFY PACKET DEVICE data */ + assert_bit_clear(buf[80], 0x0e); + } + + /* Word 93: reserved bit clear, fixed bit set, 80-conductor cable */ + assert_bit_clear(buf[93], 1 << 15); + assert_bit_set(buf[93], 1 << 14); + assert_bit_set(buf[93], 1 << 13); + assert_bit_set(buf[93], 1 << 0); + /* Device 0 clears the device 1 result */ + assert_bit_clear(buf[93], 0x1f00); + if (packet) { + /* the disk path has yet to gain this */ + assert_bit_set(buf[93], 1 << 3); + } + + free_pci_device(dev); + ide_test_quit(qts); +} + +static void test_identify_udma_ata(void) +{ + test_identify_udma(false); +} + +static void test_identify_udma_atapi(void) +{ + test_identify_udma(true); +} + /* A PIO transfer window reaching past the io_buffer has to be refused */ static void test_migrate_pio_state_rejected(void) { @@ -1843,6 +1910,8 @@ int main(int argc, char **argv) qtest_add_func("/ide/migration/chs_rejected", test_migrate_chs_rejecte= d); qtest_add_func("/ide/migration/pio_state_rejected", test_migrate_pio_state_rejected); + qtest_add_func("/ide/identify/udma", test_identify_udma_ata); + qtest_add_func("/ide/identify/udma_atapi", test_identify_udma_atapi); =20 qtest_add_func("/ide/identify", test_identify); =20 --=20 2.53.0