From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657355; cv=none; d=zohomail.com; s=zohoarc; b=PGEwC4b5LsWBCbmYnVnAMbcB9BbzXWGnvN0oYJwkFrHmBa46SPUrsDt///7cbhJbjmjl10hlmyFlL3WJJWw6OeWiKjgHchOm9ajOLsfUiBEpDdDE1QlRn2PKA1W3aLDV16rN+a1qpZRAU/TD7WW3oDswOH1rgmQjnA10f/S0c5c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657355; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=C9SgPUAb5n42tStqTgmJc5gjPzoBxZIIp3aPLVSFDA4=; b=ium5/R2zYPYSjcfyUm+c5JrHQzGBC5u4L1loYOmd4ihdIg9wCZJY5o+ke75DVDkOMBS1xYymlRhUgXqAGTYhi3JJpKPUNkkGLbYGn13z1RjDE5KEXXarYbqyx/sOOUfPYATVkvGPbycNslRuZHP37KNBJGkhy+p/v5d9hSKW5yE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657355222979.571957967904; Tue, 25 Aug 2026 04:29:15 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypKz-0001pZ-SE; Tue, 25 Aug 2026 07:29:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypKw-0001mZ-1v for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:02 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypKq-0005b6-2N for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:28:59 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-684-gEYJoTIfOVywdLdbaQyw_Q-1; Tue, 25 Aug 2026 07:28:51 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id AF3BD195411D; Tue, 25 Aug 2026 11:28:50 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id A8B845B1; Tue, 25 Aug 2026 11:28:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657335; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=C9SgPUAb5n42tStqTgmJc5gjPzoBxZIIp3aPLVSFDA4=; b=DrTGieMF9WqU8E9vxdKu/ZnngxZaMXlafb8uaav90HoUaGM4y958Qm1DY5qUyDIsRv6w5y a/l6hQN2OZLRwaJsZNcvnLvwIvdXMgZ8VurVerPzg/SKuwv+RwRmqq34cccE73dBrIuWdQ Qc6CbzGbqpu3Zm04nVpzAzsXqOOCM8A= X-MC-Unique: gEYJoTIfOVywdLdbaQyw_Q-1 X-Mimecast-MFC-AGG-ID: gEYJoTIfOVywdLdbaQyw_Q_1787657330 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:20:51 +0400 Subject: [GIT PULL 01/19] hw/misc: fix trace-events MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-1-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org X-Developer-Signature: v=1; a=openpgp-sha256; l=1169; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=gf1MWHq6bMcGh66L17Lk8mRxvGUij2pMb/fjnDdEbEg=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrT3SVxXv22fOyegMIvU/bo/IEXVEX06hTzl Eezii7lNeiJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao160wAKCRDa6OEJdZac 5eBJEAC4b8WDY/KrgwU4prAT53Cp1xplM8Pg2g44y4XrPGXky1TzUwUlzKo8sfJ10dkHhxMGVyX BiGcdAyIKdxhdCJsa93tl2DdWR4nIpFHJdWTSyPC9PVKp6z2t6tiyUwrn9QvNkdYfhNIkE5i9nA 7gS8DJkD6hs+2Put8dGSz0LGH+MsHW1AGMmwQ7z5tppkI3Hr/bozOJ6h+jIdfc4j9dbDEJ5Iylp 6wKyaCqg0af+k/u/tRQ2lOGrlj9thWTu+6Rebv2BkZDedh6VgnzShcHbLE4Api749ZkVikcx8aq N5MThN1J5OZpegPfUBiCFcyw/H2nz0Gm1jVY+92nrlI2zubCy/2YAjyB2XhrnBk+V/2G6fw8Sn6 MTxY2mC4mKkhvZHRfS8YNfjjz923txqg+zoMMDRpodPHAziTOK4TFrPf4dQlfHdP/8fEk5yVSab NJNV1obknRMJIkFgXiiAqyj4TRu3El65HPEz6cznxYiVkswbC5AgXvjqZBraaPPlPNl7TRQvBrK 9sUTU2/a37rTeKAN3NIFj2kxyRCU3+cVI5fLWZ6h/Jc+eHZZbxF5Wj1L529hwaAP0mf6+YIGvVL 6VAfMzk7soz4yG439CFg5Xj2S1CF2zttLFjywiVL70/+arNPVKwpCaKuP+PVuqvJE+cYZqg6p37 IaIp88nHX8ZIsrw== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657357137158500 The commit 8041d1730871 accidentally removed the vmlaunchupdate.c trace events. Fixes: 8041d1730871 ("tests/qtest: add test for K230 gsdma") Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Luigi Leonardi Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260825074114.853069-1-marcandre.lureau@redhat.com> --- hw/misc/trace-events | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/hw/misc/trace-events b/hw/misc/trace-events index 16db4ba0cc17..0b8be3d0f226 100644 --- a/hw/misc/trace-events +++ b/hw/misc/trace-events @@ -446,3 +446,9 @@ iommu_testdev_dma_armed(bool armed) "armed=3D%d" # k230_decomp_gzip.c k230_decomp_gzip_read(uint64_t offset, unsigned int size, uint64_t value) = "K230 DECOMP GZIP read: [0x%"PRIx64"] size %u -> 0x%"PRIx64 k230_decomp_gzip_write(uint64_t offset, unsigned int size, uint64_t value)= "K230 DECOMP GZIP write: [0x%"PRIx64"] size %u <- 0x%"PRIx64 + +# vmlaunchupdate.c +launch_update_write(void) "" +vmlaunch_reset_enter(void) "" +vm_launchupdate_finalize(void) "" +restore_host_x86_igvm(void) "" --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657375; cv=none; d=zohomail.com; s=zohoarc; b=NLKS7O/QwhGg59UYjrlGRxzaXp48sZkX9nxqYaXVaNbju+qqceuRtCQaV14EPSrrJjqeVy52LCPxmrZRaf6aL6cNhDh+sByZKtwb1O5bLE1FHDq8G1MUrpezJ8LP3SvgOBNA2o0MM81C3r7v0HOkor9BllCuYFER4yi5DwGzpwU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657375; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Oawp+uuqwhnIwrwvrxKAKzVlHKk6YTGFE4uYRTt9AK8=; b=N5I+r2i/ad8dXl5FEmKk9qkUTjwIYDx7jjh0RzUQKLtfuRm7siajJ5CJuXbT0RG07WdeD0JyNidbw8TU1qyVvLbWE9rM+Oq9NZX0A9wTaVZr6xpTlDBRA4A5xaFvZeTtJtrSxFZ9WHvCbYUI5OFbV6vpBRfvCmkk4oeubGkY0BY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657375871916.0795953288568; Tue, 25 Aug 2026 04:29:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypL2-0001wK-LM; Tue, 25 Aug 2026 07:29:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypKx-0001pM-VF for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:05 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypKv-0005eA-Ob for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:02 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-260-4OIZuNQ-PqC21NWOqPH9cg-1; Tue, 25 Aug 2026 07:28:57 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B63E619539A3; Tue, 25 Aug 2026 11:28:55 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 73C6C19539B7; Tue, 25 Aug 2026 11:28:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657340; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Oawp+uuqwhnIwrwvrxKAKzVlHKk6YTGFE4uYRTt9AK8=; b=TH8ooWvTeR6gv8NolxHxDcisKce4BfUlNhXx9OHNUu0mLKa7hHgxTGCxOLvp00pjb50sBs d0BtKkvbO7DpOLnr7QIGlMCHeszTDdNaFyGC9g6DQ7WzYFzKrZAZxaPSqK9rpS2bkH7M8q YOqMAuWdZkJIO9trJf5hmFh67fAc1X8= X-MC-Unique: 4OIZuNQ-PqC21NWOqPH9cg-1 X-Mimecast-MFC-AGG-ID: 4OIZuNQ-PqC21NWOqPH9cg_1787657336 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:20:52 +0400 Subject: [GIT PULL 02/19] migration/multifd: fix Error leak in multifd_recv_terminate_threads() MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-2-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, Peter Xu , Fabiano Rosas X-Developer-Signature: v=1; a=openpgp-sha256; l=820; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=+LKimukLDsA97vQJORj8HNh0cTRzyFzAcZxyCRym8nY=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrTlgcUFo5mK7wQRr9kMkNuye5tjuWH/HIy7 HBhJkOICeOJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao160wAKCRDa6OEJdZac 5f1UD/4zeTIFPfpHGRY82STy3NwzXPV3P8o0B/MLZA7UVKYN0O8EBccqtK1SgCRgogmoLCHvoxH JzLe37+bXR8lqdk54HqlF776f6Ve3GJwKR5DSom/lDZ5xikJ1DW2u28Wn8zIGW6rvIaA29eERnl tHxwZscT/mWKGniia/BkjN7Daqu74Saf17h33xWDA2i6DVGocYjbju/bGS5R97BMKBj+lG9x5FM 74bfK5zUgLyX328oh5JGUo968xvLQd32HaQ1Brj81/pHuggxWSkxhoL4Qy8RNWXN2ZCfB2Ti/Vq gEhooIfY4NpmDOuDxh8fw9h8+dN6qF4bzOx7sIu8DSJopUpRPDTIqvdrEx6bJUprcuePPdoHnTO wvQqaC8lA1R/MWfUZMXx1dqMhwsFnvNp9CkthCoUO+3HHucgZ0jwLTfodI6gztlM8nir/K9zkoj bMcJkkr6mcvpuhlpTxIBNFu5XkOXt8ks5UuazU476J0IYgWRlmNPG3dT3DKpOp9c4cb14AafmRb qtkmdxh7AEyXZTQLtbxpQib4l9MBSPounkVS2MLpN3Z9aVNFUP7ULPEg3YFpOvNmorIJHkBpeEd wBvW8rW0tI9GOxKX2KXpA8ERXhMxMz7BvB8kgllR4F+80J2YH3Ti22KbsjMCIlGMwFHTJV1Zfpr k2fUjjwflARXhZg== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657376982158500 If err !=3D NULL, free it. Fixes: 11dd7be57524 ("migration/multifd: Remove p->quit from recv side") Reviewed-by: Fabiano Rosas Reviewed-by: Peter Xu Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260727-fix2-v2-11-d0c4831ed7ea@redhat.com> --- migration/multifd.c | 1 + 1 file changed, 1 insertion(+) diff --git a/migration/multifd.c b/migration/multifd.c index dbad525d2a28..503014f76ba5 100644 --- a/migration/multifd.c +++ b/migration/multifd.c @@ -1056,6 +1056,7 @@ static void multifd_recv_terminate_threads(Error *err) trace_multifd_recv_terminate_threads(err !=3D NULL); =20 if (qatomic_xchg(&multifd_recv_state->exiting, 1)) { + error_free(err); return; } =20 --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657375; cv=none; d=zohomail.com; s=zohoarc; b=L6tixP+LmFW1Ij64dJt/uD6MNrO2+PxpQBqPnrpzk+eT8+fG1wwjpg6dMh/8+QLL4I1Brordi5dZCHjX8jS0IEFycj1RFDc8+NvpstDBjb0InY+PX1XNmQMN1jm6/58UbHTyisj6n8t+KFefeeo7983g7xUTcfdY6/k1Y64Q2LU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657375; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fIWgkTtXHlop9N0eBts49XgxQSRwkff9LfqhjOfKMNQ=; b=UveKR98gjmh5yqFvzk8mz4H8ylmDoBBDG35f4t4UQ/6GboH9afwUOcMBFB9DB83Rz0g/QUbSPOV3B1N6wi6zIbXJ+f9Z5o/P0L97q3Ed3LV2v2Fyz7hTjktB9gJTXRxFEqykWJ22vb9EQhjF4eDIJSAAkh874paPpIYzm7+E0ao= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178765737545516.031421258441128; Tue, 25 Aug 2026 04:29:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypL4-0001xo-5G; Tue, 25 Aug 2026 07:29:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypL3-0001x3-32 for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:09 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypL1-0005ih-JD for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:08 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-232-vRyRKmTgPmu6pt6959eYzQ-1; Tue, 25 Aug 2026 07:29:01 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 58A0A195DBA2; Tue, 25 Aug 2026 11:29:00 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0318C1800643; Tue, 25 Aug 2026 11:28:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657346; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=fIWgkTtXHlop9N0eBts49XgxQSRwkff9LfqhjOfKMNQ=; b=fkLIGGOuvBe+e/A1B9SB0VOSiTcxFZ8MCpINum+wcU/kP3Kf9SVagIuYBPUqlwapH/eJEb 4B/4rGUKsr58D8uVC0oRiXIk4/wFwD5pWE23VxB/v234XVmUZeeley5pN/YTb4+OTDVBC1 EHvf2PNkZGj9kW5rfQgE7VWgCIQs72A= X-MC-Unique: vRyRKmTgPmu6pt6959eYzQ-1 X-Mimecast-MFC-AGG-ID: vRyRKmTgPmu6pt6959eYzQ_1787657340 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:20:53 +0400 Subject: [GIT PULL 03/19] hw/core/machine: fix fdt memory leak MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-3-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, =?utf-8?q?Philippe_Mathieu-Daud=C3=A9?= , Zhao Liu X-Developer-Signature: v=1; a=openpgp-sha256; l=969; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=bQisH5FZBJ2nMb07NbswCswDkAvlnIJEcdbaLo+TT1k=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrTLrD5mVNjRcmEg0mI5HbRkFcA8K+5Qw5un DLKhNIPfbCJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao160wAKCRDa6OEJdZac 5eZVD/oCfL6/oLnq/00TvY7vigOQH6NG110X35hK9c5iqMOvOGJSjmsSz3HcFRJV6SHDF8AdXH4 gw16jm0LhStIBpgwy8ycN6qXIpeIqfTj5xsiYMJhQXxcixmF55hyHq0PyzHKcc7quY9+eu1JRHH kyHWdpP+RhwYjoADAMK126nqv1kH9Qwu7R5OFImEyp/Bdpk6yLMaeuv/MNoklAOtvPJ0/hk5xOF cge8/RPTcWr2kQgicGJIUvc5fwP90AXxKsZhaGN54zm+WFmx767sjuDnsnH3REW8/IZIbLBUvHW cPuGEwNNw08u2JrMd+q0RNNAItOQgT0geOdoOOL+DmM86oz7yM8aHNeXyjIoxulp8zsibMvH95F tQiDLFpt2x3F4h6kBDATzcEyROnVru2fRG7wj6tQxSM9gGBoaiQhWQ95krQBbiMhkcLo8VeEsXM s3GPwBNVoMjlQzJwcehis1CU08oJny6mNiRi33t5ONM8CZKRdFLSQBmqibbjcWnrLCwBhVGiS89 RKgTBZwj/zV+fVU74qHtXytlvO4BNXynq20eChz4N84N9I0/bK8E6jKjUSSkQ1+y3W7ZI2ab6nq 0Rimkkm6YAwagvNOFdZ6DK92BqssLsOWB+tlejQsmv3lRr3YDOeJPlW1f9XNJk47VapwZV7+DPi Q20T3MNK8sEMEGw== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657376986158500 The MachineState fdt field is allocated by various machine types via create_device_tree(), load_device_tree(), or similar, but was never freed in machine_finalize(). Add the missing g_free() call. Reviewed-by: Zhao Liu Reviewed-by: Peter Maydell Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260709111249.1107640-1-marcandre.lureau@redhat.com> --- hw/core/machine.c | 1 + 1 file changed, 1 insertion(+) diff --git a/hw/core/machine.c b/hw/core/machine.c index e617f7804d4e..8939ae16666c 100644 --- a/hw/core/machine.c +++ b/hw/core/machine.c @@ -1314,6 +1314,7 @@ static void machine_finalize(Object *obj) g_free(ms->nvdimms_state); g_free(ms->numa_state); g_free(ms->audiodev); + g_free(ms->fdt); } =20 bool machine_usb(MachineState *machine) --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657375; cv=none; d=zohomail.com; s=zohoarc; b=hPPkjmNshkPRWxs9vQ2z/x+GoU2qC/NFdupE8n6vb46zbVhFoYzksXUGtEqt0j8aY1mHrELMbUwhTkypbdJu/GS0kNn8y4I+HUN6qsZ/s0Ht02VX+nz9ZYTUAZdqIwagraC3GUjhtWZ9DeJSfRJzHp7WxJVUDNvsdvE9VDGTShY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657375; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=XM1H1FHOC2W/oioIF8igGxh7G5i7VAS2DlX6Fo+p+rU=; b=Lms2pYxTXNwmzBZJlhYjxLVUcbXMlAxllnxeL4sXmLqhweaWm3V4l/rcCkznwVXSruu5jjoqAmjRTteIOLqvIXWD4fpT0KjqYc9seaRD47iYyYkTqX/e4QljnHjfAmKEzbf8Gm+y7SfrLCCfHFFt5Y3Ur3g3FNTZT14IvrHKFUc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657375090327.38336842415015; Tue, 25 Aug 2026 04:29:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypLH-0002AM-RB; Tue, 25 Aug 2026 07:29:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLB-00023c-JB for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:17 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypL9-0005oc-Da for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:17 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-551-JYKFMGvIM-KVJg11CZRoJw-1; Tue, 25 Aug 2026 07:29:08 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id DEAF819539A0; Tue, 25 Aug 2026 11:29:06 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0232F1800643; Tue, 25 Aug 2026 11:29:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657354; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XM1H1FHOC2W/oioIF8igGxh7G5i7VAS2DlX6Fo+p+rU=; b=LK4qOr7AcWd346H6pKjnZZSwnne2ULnfMnqDsH+csJ3hc9mFp8KxJoLErgWoAmgvw+ubO+ cAN2fM5CMD06LwvIB2UhDbeFgGw7VQAxslXiyXZ0w5kxjAAk+E6QNVje6ykj7z+r3B2UEm p9igTpuhiONMu5Uq3g6IU0teA+aMlTc= X-MC-Unique: JYKFMGvIM-KVJg11CZRoJw-1 X-Mimecast-MFC-AGG-ID: JYKFMGvIM-KVJg11CZRoJw_1787657347 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:20:54 +0400 Subject: [GIT PULL 04/19] hw/display/qxl: validate primary surface stride against width MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-4-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org X-Developer-Signature: v=1; a=openpgp-sha256; l=10463; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=4UDCl8lex+MxXuYGkgLc9J338hwBSKTVbnExSWrIGN8=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrURBkt8KXzcL5On+NWHlnlNmSTvn7yx85h+ dBDs4hPI7mJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161AAKCRDa6OEJdZac 5TPYD/40gWKCdMuMcUizGaS8rB79GY0psW7B/l/nfdLcpW9ksITYPVj1NCr6ZtrFcxbz5Z2mML5 c3ltBUMf1q/tkhffoRPTGXDY4b213O1a3pl8XYuNlWSGaVfj4nWgIiaM/QzLxjyH/sSQGzo4ud2 PZzQR3Aa6rA6Jgp6A3xTX3WtZDAS1Q3CSl7a2m30QsfoLb4aqofSE01+11oDdJMai55ZMnyEzUF fGvO0bniImdS8jrtmY03W91HK9GeQqVtyI53ffFZ6XKaff6ZrzTVGsaGx1T1Q/ONBKDG6yacSro TZzA1a+W+6MxxREplY8EkSJmcLFwgOZYHd5kF/ZPhmNw7ejOxukYdc4cIz1woaGJc/I1VgrF3yL TH5boKIPFjiO0efPpi4mGTu6xAmjHorNkgjl81Us9Fzc3uynnZcwYGDMuN3lj3yWSVPRB907edQ t/6uqCfJ/kCIajBtsQkpk1Y5GsbWKBxARxMZwX5KVU4Oscwm6+qEfkNdsDyXr1ppxcMYQRU9ymN +JIrnvIR4thcxAV0J+ZnS6+XePnDBxziJGnx8UIqmwZaNBA42EWqjPld8CPfZhLHuyajPnXvWND My6AzXgDniqr2iiU9Alq7iggyCqX/911UGGyza9PBTMltkBmhtcG5t7tF2RIj7O4dk8O60oFO1F 8T0bzK+UTVP9eLw== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657377109158500 The existing validation in qxl_create_guest_primary() checks that abs(stride) * height fits in vgamem_size and that stride is 4-byte aligned, but never checks that abs(stride) is large enough to hold one row of pixels for the declared width and format. A malicious guest can create a primary surface with a stride much smaller than width * bytes_per_pixel (e.g. stride=3D4 for a 64-wide 32bpp surface). The spice server rejects this via red_validate_surface(), but the return is void and QEMU unconditionally proceeds to set up the local rendering state. On the next display refresh, VNC or SDL reads width * bytes_pp per scanline from a region backed by only stride bytes per row, causing a host-side out-of-bounds read. Add three checks in qxl_create_guest_primary() before creating the surface: - reject unknown surface formats - reject zero width or height - reject surfaces where abs(stride) < width * bytes_per_pixel Also fix three related issues in qxl-render.c: - qxl_blit() used abs_stride to advance the dst pointer into the DisplaySurface, but when stride is negative the DisplaySurface is a packed buffer whose stride may be smaller. Use surface_stride() instead. - qxl_render_update_area_unlocked() uses guest_head0_width (set via QXL_IO_MONITORS_CONFIG_ASYNC) without validating it against abs_stride, bypassing the new validation. Clamp the effective width to abs_stride / bytes_pp to prevent out-of-bounds access while tolerating the normal transient where the monitor config arrives before the primary surface is resized to match. - Similarly, guest_head0_height bypasses qxl_create_guest_primary() validation. Without clamping, abs_stride * height can overrun vgamem_size, and the product can also overflow 32 bits (e.g. abs_stride=3D16 MiB, height=3D256 wraps to zero), defeating the qxl_phys2virt() bounds check. Clamp height to vgamem_size / abs_stride to prevent both. While touch it, fix some endianness issues. Fixes: CVE-2026-16271 Fixes: a19cbfb34642 ("spice: add qxl device") Fixes: 979f7ef8966b ("qxl: use guest_monitor_config for local renderer.") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3637 Reported-by: huntr bubble Signed-off-by: Marc-Andre Lureau Reviewed-by: Akihiko Odaki Message-ID: <20260806094028.640676-1-marcandre.lureau@redhat.com> --- hw/display/qxl-render.c | 66 ++++++++++++++++++++++++++++++---------------= ---- hw/display/qxl.c | 59 +++++++++++++++++++++++++++++++++++++++++++ hw/display/qxl.h | 2 ++ 3 files changed, 101 insertions(+), 26 deletions(-) diff --git a/hw/display/qxl-render.c b/hw/display/qxl-render.c index 4799c9e8befd..348ddba76890 100644 --- a/hw/display/qxl-render.c +++ b/hw/display/qxl-render.c @@ -27,6 +27,7 @@ static void qxl_blit(PCIQXLDevice *qxl, QXLRect *rect) { DisplaySurface *surface =3D qemu_console_surface(qxl->vga.con); + int dst_stride =3D surface_stride(surface); uint8_t *dst =3D surface_data(surface); uint8_t *src; int len, i; @@ -45,14 +46,14 @@ static void qxl_blit(PCIQXLDevice *qxl, QXLRect *rect) } else { src +=3D rect->top * qxl->guest_primary.abs_stride; } - dst +=3D rect->top * qxl->guest_primary.abs_stride; + dst +=3D rect->top * dst_stride; src +=3D rect->left * qxl->guest_primary.bytes_pp; dst +=3D rect->left * qxl->guest_primary.bytes_pp; len =3D (rect->right - rect->left) * qxl->guest_primary.bytes_pp; =20 for (i =3D rect->top; i < rect->bottom; i++) { memcpy(dst, src, len); - dst +=3D qxl->guest_primary.abs_stride; + dst +=3D dst_stride; src +=3D qxl->guest_primary.qxl_stride; } } @@ -61,30 +62,13 @@ void qxl_render_resize(PCIQXLDevice *qxl) { QXLSurfaceCreate *sc =3D &qxl->guest_primary.surface; =20 - qxl->guest_primary.qxl_stride =3D sc->stride; - qxl->guest_primary.abs_stride =3D abs(sc->stride); + qxl->guest_primary.qxl_stride =3D le32_to_cpu(sc->stride); + qxl->guest_primary.abs_stride =3D abs(qxl->guest_primary.qxl_stride); qxl->guest_primary.resized++; - switch (sc->format) { - case SPICE_SURFACE_FMT_16_555: - qxl->guest_primary.bytes_pp =3D 2; - qxl->guest_primary.bits_pp =3D 15; - break; - case SPICE_SURFACE_FMT_16_565: - qxl->guest_primary.bytes_pp =3D 2; - qxl->guest_primary.bits_pp =3D 16; - break; - case SPICE_SURFACE_FMT_32_xRGB: - case SPICE_SURFACE_FMT_32_ARGB: - qxl->guest_primary.bytes_pp =3D 4; - qxl->guest_primary.bits_pp =3D 32; - break; - default: - fprintf(stderr, "%s: unhandled format: %x\n", __func__, - qxl->guest_primary.surface.format); - qxl->guest_primary.bytes_pp =3D 4; - qxl->guest_primary.bits_pp =3D 32; - break; - } + /* fallback to default bpp if format is unknown */ + qxl_format_bpp(qxl, le32_to_cpu(sc->format), + &qxl->guest_primary.bytes_pp, + &qxl->guest_primary.bits_pp); } =20 static void qxl_set_rect_to_surface(PCIQXLDevice *qxl, QXLRect *area) @@ -101,15 +85,45 @@ static void qxl_render_update_area_unlocked(PCIQXLDevi= ce *qxl) DisplaySurface *surface; int width =3D qxl->guest_head0_width ?: qxl->guest_primary.surface.wid= th; int height =3D qxl->guest_head0_height ?: qxl->guest_primary.surface.h= eight; + uint64_t map_height; int i; =20 + if (width <=3D 0 || height <=3D 0) { + goto end; + } + + if (qxl->guest_primary.bytes_pp > 0) { + int max_width =3D qxl->guest_primary.abs_stride + / qxl->guest_primary.bytes_pp; + width =3D MIN(width, max_width); + } + + if (qxl->guest_primary.qxl_stride < 0) { + /* qxl_blit() uses the primary height to find the first scanline. = */ + height =3D MIN(height, (int)qxl->guest_primary.surface.height); + } + + if (qxl->guest_primary.abs_stride > 0) { + int max_height =3D qxl->vgamem_size / qxl->guest_primary.abs_strid= e; + height =3D MIN(height, max_height); + } + + /* + * height limits the visible update, while map_height is the guest mem= ory + * span validated by qxl_phys2virt(). With a negative stride qxl_blit= () + * addresses scanlines from the declared primary height, so a shorter + * monitor still requires validating the full primary surface. + */ + map_height =3D qxl->guest_primary.qxl_stride < 0 ? + qxl->guest_primary.surface.height : height; + if (qxl->guest_primary.resized) { qxl->guest_primary.resized =3D 0; qxl->guest_primary.data =3D qxl_phys2virt(qxl, qxl->guest_primary.surface= .mem, MEMSLOT_GROUP_GUEST, qxl->guest_primary.abs_str= ide - * height); + * map_height); if (!qxl->guest_primary.data) { goto end; } diff --git a/hw/display/qxl.c b/hw/display/qxl.c index b7d871b9ee33..384b8767b8e6 100644 --- a/hw/display/qxl.c +++ b/hw/display/qxl.c @@ -1489,6 +1489,47 @@ static void qxl_create_guest_primary_complete(PCIQXL= Device *qxl) qxl_render_resize(qxl); } =20 +/* + * Convert a SpiceSurfaceFormat to bytes per pixel and bits per pixel. + * + * Only valid for surface suitable for rendering. + */ +bool qxl_format_bpp(PCIQXLDevice *qxl, SpiceSurfaceFmt format, + uint32_t *bytes_pp, uint32_t *bits_pp) +{ + uint32_t bypp =3D 4; + uint32_t bipp =3D 32; + bool ret =3D true; + + switch (format) { + case SPICE_SURFACE_FMT_16_555: + bypp =3D 2; + bipp =3D 15; + break; + case SPICE_SURFACE_FMT_16_565: + bypp =3D 2; + bipp =3D 16; + break; + case SPICE_SURFACE_FMT_32_xRGB: + case SPICE_SURFACE_FMT_32_ARGB: + bypp =3D 4; + bipp =3D 32; + break; + default: + ret =3D false; + qxl_set_guest_bug(qxl, "%s: unhandled format: %x", __func__, forma= t); + } + + if (bytes_pp !=3D NULL) { + *bytes_pp =3D bypp; + } + if (bits_pp !=3D NULL) { + *bits_pp =3D bipp; + } + + return ret; +} + static void qxl_create_guest_primary(PCIQXLDevice *qxl, int loadvm, qxl_async_io async) { @@ -1496,6 +1537,7 @@ static void qxl_create_guest_primary(PCIQXLDevice *qx= l, int loadvm, QXLSurfaceCreate *sc =3D &qxl->guest_primary.surface; uint32_t requested_height =3D le32_to_cpu(sc->height); int requested_stride =3D le32_to_cpu(sc->stride); + uint32_t bytes_pp; =20 if (requested_stride =3D=3D INT32_MIN || abs(requested_stride) * (uint64_t)requested_height @@ -1532,6 +1574,23 @@ static void qxl_create_guest_primary(PCIQXLDevice *q= xl, int loadvm, return; } =20 + if (!qxl_format_bpp(qxl, surface.format, &bytes_pp, NULL)) { + return; + } + + if (surface.width =3D=3D 0 || surface.height =3D=3D 0) { + qxl_set_guest_bug(qxl, "%s: zero dimension %ux%u", + __func__, surface.width, surface.height); + return; + } + + if ((uint64_t)surface.width * bytes_pp > abs(surface.stride)) { + qxl_set_guest_bug(qxl, "%s: stride too small for width:" + " stride %d width %u bpp %u", + __func__, surface.stride, surface.width, bytes_p= p); + return; + } + surface.mouse_mode =3D true; surface.group_id =3D MEMSLOT_GROUP_GUEST; if (loadvm) { diff --git a/hw/display/qxl.h b/hw/display/qxl.h index 48d664f77736..6f5b96fe86cc 100644 --- a/hw/display/qxl.h +++ b/hw/display/qxl.h @@ -181,6 +181,8 @@ void qxl_spice_oom(PCIQXLDevice *qxl); void qxl_spice_reset_memslots(PCIQXLDevice *qxl); void qxl_spice_reset_image_cache(PCIQXLDevice *qxl); void qxl_spice_reset_cursor(PCIQXLDevice *qxl); +bool qxl_format_bpp(PCIQXLDevice *qxl, SpiceSurfaceFmt format, + uint32_t *bytes_pp, uint32_t *bits_pp); =20 /* qxl-logger.c */ int qxl_log_cmd_cursor(PCIQXLDevice *qxl, QXLCursorCmd *cmd, int group_id); --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657379; cv=none; d=zohomail.com; s=zohoarc; b=aerVtmvhY4KzGNO+wHKQFb7Qp8+VHRoTTq1DCr7uS+ICvhK8w8OSi81A7nQOr2WEwQ+Fdx4Iao0Fy21Uqg5+LkwPQX+D9m0chdW5QG3RIh/GDPhn5Blm/qPuu4AFAnw6D7ceFuZmmoU+kmKY0ScJRVCY3N1yZR9JmPVTqBAY9fI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657379; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=qWIkY2mDIqLc80URhGK374g0ho5Fog2QF4giWIJoPQc=; b=AOFjJ6ER5k0dnCKzEm5/TTK4OGG4r0Ob9vhc+xOtgLsZzvQnPdJBLSzb7E5KCUf6zb7W9PSDmHMHL2dKqGyuoUl0anJZx86BR2pypXrSMtlmvzeHK2U5CVE9eYXR5w5C+2B0RvStNr9FZi6SmFHhojGNZt3H9K15XYk7eNvzMoM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657379957472.31181239696195; Tue, 25 Aug 2026 04:29:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypLN-0002NT-PF; Tue, 25 Aug 2026 07:29:29 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLH-00029Y-6d for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:23 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLE-0005ro-4j for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:21 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-632-h6L5c71uOwumOmmc64J_ig-1; Tue, 25 Aug 2026 07:29:15 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id F29C2190FFB7; Tue, 25 Aug 2026 11:29:12 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id E3AC71803A44; Tue, 25 Aug 2026 11:29:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657359; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=qWIkY2mDIqLc80URhGK374g0ho5Fog2QF4giWIJoPQc=; b=Jl784Hd5C5iui56BNXBl3vNhAVp+smOPrJuTA5gce+GJHGTxkRTavSr/OeTAnMpkPCn97r wy521x99A9UWMfCFZ88IYf97R66D2lFjd++z8CPoi9VX8MvzovfbHIgkJ8euGkpM90gZcd dzTp+TtCsVUsLZ+YOqzArpa9eThHUNc= X-MC-Unique: h6L5c71uOwumOmmc64J_ig-1 X-Mimecast-MFC-AGG-ID: h6L5c71uOwumOmmc64J_ig_1787657354 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:20:55 +0400 Subject: [GIT PULL 05/19] virtio-gpu: use g_try_malloc to avoid guest-triggered abort MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-5-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, "Michael S. Tsirkin" , Stefano Garzarella , =?utf-8?q?Marc-Andr=C3=A9_Lureau?= , =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko X-Developer-Signature: v=1; a=openpgp-sha256; l=9648; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=Iqs48Jt6oUfR5yFt7ojHwnDuLBUUzo2gnDuVxagRfhU=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrUL6Odt8SMBeYT5VZLT6d5Lj+5YggbdJkOd KXfOhl4L5+JAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161AAKCRDa6OEJdZac 5TDXD/4+a54p5CIJrPl09EaxgQ5aJREKLNtMgQsfqK2WSgahUK2bU5JZtK1L/PrRKElTr5a//WH 9TRBM2w0Ho1P0rX9we8i5YQx/poVN4bUYaztYtXWHTryg538tEi1iK7wP522drrG46jd1xJ1lwI 5LADgn/Rvb9138pv3FSw9QvOTEEqyohwr480bexdZ+/amSQmWpf9leT7JBR6kyJAiCE1uurdVfV e+amdtBtwUcOKubxhwLmERj99CWds3plL1m7XznIgTczLqeWWWI1X61ZTJS1y+0mgP+L7kmokYf 7kl2jcBDdHjPVi9mpWJb3kskFQo2Uez7wYUsA3giTuharcuShSUWs6s8xuTJIh9KHLA5H8atZVm 67aEZjlRw3gNt6DseXhz7HJUhbQKXj5Ugh6N7czEsU4uCa18CU/woZB001HX+8m2kKPcSUcDQBY YL9crZzVPW++nKnTob1RrJB7FvSQ25d7c0Dz9fKdoFd39ARkqSpCGqZkc0PT6WMq7JzjNRzvzMt SIhAt/stUbX2c62GdpDIKjwSYt2inNZc0MUis06Y9pSZgfgu/kWhCNButIZEY65CHy5ram8K3eG kTETBtdF4xE7fIS/QwVvyhCzdfP6WzlaygJe9eIZ2i8iZvo8YbYaV9/pnql3SLCv3itm9VhA/Jq x93urgfkZ0OYwCQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657381429158500 Use g_try_malloc/g_try_new0 for guest-controlled allocation, so failure returns an error to the guest rather than crashing the host (glib behaviour). Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3898 Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260805130141.211398-1-marcandre.lureau@redhat.com> --- contrib/vhost-user-gpu/vhost-user-gpu.c | 25 +++++++++++++------- contrib/vhost-user-gpu/virgl.c | 6 ++++- contrib/vhost-user-gpu/vugbm.c | 5 +++- hw/display/virtio-gpu-rutabaga.c | 14 +++++++++-- hw/display/virtio-gpu-udmabuf.c | 7 ++++-- hw/display/virtio-gpu-virgl.c | 6 ++++- hw/display/virtio-gpu.c | 42 ++++++++++++++++++++++++-----= ---- 7 files changed, 79 insertions(+), 26 deletions(-) diff --git a/contrib/vhost-user-gpu/vhost-user-gpu.c b/contrib/vhost-user-g= pu/vhost-user-gpu.c index 786488150932..933bdbb671c0 100644 --- a/contrib/vhost-user-gpu/vhost-user-gpu.c +++ b/contrib/vhost-user-gpu/vhost-user-gpu.c @@ -487,7 +487,7 @@ vg_create_mapping_iov(VuGpu *g, struct virtio_gpu_ctrl_command *cmd, struct iovec **iov) { - struct virtio_gpu_mem_entry *ents; + g_autofree struct virtio_gpu_mem_entry *ents =3D NULL; size_t esize, s; int i; =20 @@ -498,17 +498,22 @@ vg_create_mapping_iov(VuGpu *g, } =20 esize =3D sizeof(*ents) * ab->nr_entries; - ents =3D g_malloc(esize); + ents =3D g_try_malloc(esize); + if (!ents && esize) { + return -1; + } s =3D iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num, sizeof(*ab), ents, esize); if (s !=3D esize) { g_critical("%s: command data size incorrect %zu vs %zu", __func__, s, esize); - g_free(ents); return -1; } =20 - *iov =3D g_new0(struct iovec, ab->nr_entries); + *iov =3D g_try_new0(struct iovec, ab->nr_entries); + if (!*iov && ab->nr_entries) { + return -1; + } for (i =3D 0; i < ab->nr_entries; i++) { uint64_t len =3D ents[i].length; (*iov)[i].iov_len =3D ents[i].length; @@ -517,12 +522,10 @@ vg_create_mapping_iov(VuGpu *g, g_critical("%s: resource %d element %d", __func__, ab->resource_id, i); g_free(*iov); - g_free(ents); *iov =3D NULL; return -1; } } - g_free(ents); return 0; } =20 @@ -828,8 +831,14 @@ vg_resource_flush(VuGpu *g, PIXMAN_FORMAT_BPP(pixman_image_get_format(res->image)) / 8; size_t size =3D width * height * bpp; =20 - void *p =3D g_malloc(VHOST_USER_GPU_HDR_SIZE + - sizeof(VhostUserGpuUpdate) + size); + void *p =3D g_try_malloc(VHOST_USER_GPU_HDR_SIZE + + sizeof(VhostUserGpuUpdate) + size); + if (!p) { + pixman_region_fini(®ion); + pixman_region_fini(&finalregion); + cmd->error =3D VIRTIO_GPU_RESP_ERR_OUT_OF_MEMORY; + break; + } VhostUserGpuMsg *msg =3D p; msg->request =3D VHOST_USER_GPU_UPDATE; msg->size =3D sizeof(VhostUserGpuUpdate) + size; diff --git a/contrib/vhost-user-gpu/virgl.c b/contrib/vhost-user-gpu/virgl.c index 550fd03bf5c4..20bae57d0fe4 100644 --- a/contrib/vhost-user-gpu/virgl.c +++ b/contrib/vhost-user-gpu/virgl.c @@ -209,7 +209,11 @@ virgl_cmd_submit_3d(VuGpu *g, return; } =20 - buf =3D g_malloc(cs.size); + buf =3D g_try_malloc(cs.size); + if (!buf && cs.size) { + cmd->error =3D VIRTIO_GPU_RESP_ERR_OUT_OF_MEMORY; + return; + } s =3D iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num, sizeof(cs), buf, cs.size); if (s !=3D cs.size) { diff --git a/contrib/vhost-user-gpu/vugbm.c b/contrib/vhost-user-gpu/vugbm.c index 710d54529779..e2d8385fd857 100644 --- a/contrib/vhost-user-gpu/vugbm.c +++ b/contrib/vhost-user-gpu/vugbm.c @@ -13,7 +13,10 @@ static bool mem_alloc_bo(struct vugbm_buffer *buf) { - buf->mmap =3D g_malloc((uint64_t)buf->width * buf->height * 4); + buf->mmap =3D g_try_malloc((uint64_t)buf->width * buf->height * 4); + if (!buf->mmap && buf->width && buf->height) { + return false; + } buf->stride =3D buf->width * 4; return true; } diff --git a/hw/display/virtio-gpu-rutabaga.c b/hw/display/virtio-gpu-rutab= aga.c index a054f8117f14..041216a10d04 100644 --- a/hw/display/virtio-gpu-rutabaga.c +++ b/hw/display/virtio-gpu-rutabaga.c @@ -366,10 +366,20 @@ rutabaga_cmd_submit_3d(VirtIOGPU *g, return; } =20 - buf =3D g_new0(uint8_t, cs.size); + buf =3D g_try_new0(uint8_t, cs.size); + if (!buf && cs.size) { + cmd->error =3D VIRTIO_GPU_RESP_ERR_OUT_OF_MEMORY; + return; + } s =3D iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num, sizeof(cs), buf, cs.size); - CHECK(s =3D=3D cs.size, cmd); + if (s !=3D cs.size) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: size mismatch (%zu/%u)\n", + __func__, s, cs.size); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + return; + } =20 rutabaga_cmd.ctx_id =3D cs.hdr.ctx_id; rutabaga_cmd.cmd =3D buf; diff --git a/hw/display/virtio-gpu-udmabuf.c b/hw/display/virtio-gpu-udmabu= f.c index 5f08c855dde1..816f52a51457 100644 --- a/hw/display/virtio-gpu-udmabuf.c +++ b/hw/display/virtio-gpu-udmabuf.c @@ -39,8 +39,11 @@ static void virtio_gpu_create_udmabuf(struct virtio_gpu_= simple_resource *res) return; } =20 - list =3D g_malloc0(sizeof(struct udmabuf_create_list) + - sizeof(struct udmabuf_create_item) * res->iov_cnt); + list =3D g_try_malloc0(sizeof(struct udmabuf_create_list) + + sizeof(struct udmabuf_create_item) * res->iov_cnt= ); + if (!list) { + return; + } =20 for (i =3D 0; i < res->iov_cnt; i++) { rcu_read_lock(); diff --git a/hw/display/virtio-gpu-virgl.c b/hw/display/virtio-gpu-virgl.c index 6e298f997d66..9bda572426b2 100644 --- a/hw/display/virtio-gpu-virgl.c +++ b/hw/display/virtio-gpu-virgl.c @@ -620,7 +620,11 @@ static void virgl_cmd_submit_3d(VirtIOGPU *g, return; } =20 - buf =3D g_malloc(cs.size); + buf =3D g_try_malloc(cs.size); + if (!buf && cs.size) { + cmd->error =3D VIRTIO_GPU_RESP_ERR_OUT_OF_MEMORY; + return; + } s =3D iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num, sizeof(cs), buf, cs.size); if (s !=3D cs.size) { diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index fbb6fec7a0ad..9eb010082d0d 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -892,7 +892,10 @@ int virtio_gpu_create_mapping_iov(VirtIOGPU *g, } =20 esize =3D sizeof(*ents) * nr_entries; - ents =3D g_malloc(esize); + ents =3D g_try_malloc(esize); + if (!ents && esize) { + return -1; + } s =3D iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num, offset, ents, esize); if (s !=3D esize) { @@ -913,6 +916,7 @@ int virtio_gpu_create_mapping_iov(VirtIOGPU *g, hwaddr len; void *map; =20 + /* TODO: a common DMA map SG helper */ do { len =3D l; map =3D dma_memory_map(VIRTIO_DEVICE(g)->dma_as, a, &len, @@ -921,20 +925,27 @@ int virtio_gpu_create_mapping_iov(VirtIOGPU *g, if (!map) { qemu_log_mask(LOG_GUEST_ERROR, "%s: failed to map MMIO mem= ory for" " element %d\n", __func__, e); - virtio_gpu_cleanup_mapping_iov(g, *iov, v); - g_free(ents); - *iov =3D NULL; - if (addr) { - g_free(*addr); - *addr =3D NULL; - } - return -1; + goto err; } =20 if (!(v % 16)) { - *iov =3D g_renew(struct iovec, *iov, v + 16); + struct iovec *new_iov; + new_iov =3D g_try_renew(struct iovec, *iov, v + 16); + if (!new_iov) { + dma_memory_unmap(VIRTIO_DEVICE(g)->dma_as, map, len, + DMA_DIRECTION_TO_DEVICE, len); + goto err; + } + *iov =3D new_iov; if (addr) { - *addr =3D g_renew(uint64_t, *addr, v + 16); + uint64_t *new_addr; + new_addr =3D g_try_renew(uint64_t, *addr, v + 16); + if (!new_addr) { + dma_memory_unmap(VIRTIO_DEVICE(g)->dma_as, map, le= n, + DMA_DIRECTION_TO_DEVICE, len); + goto err; + } + *addr =3D new_addr; } } (*iov)[v].iov_base =3D map; @@ -952,6 +963,15 @@ int virtio_gpu_create_mapping_iov(VirtIOGPU *g, =20 g_free(ents); return 0; + +err: + virtio_gpu_cleanup_mapping_iov(g, *iov, v); + *iov =3D NULL; + if (addr) { + g_clear_pointer(addr, g_free); + } + g_free(ents); + return -1; } =20 void virtio_gpu_cleanup_mapping_iov(VirtIOGPU *g, --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657389; cv=none; d=zohomail.com; s=zohoarc; b=Y2QCWfITec19NVxxloU5JMTkka+Zrf63x048V7nSvudWxpXLsyVtcdJ+3psSkrhg6XwDi0ilPqmPlSI8iKjHyn5MiLF4YBPSduk+RceZ7zZ6uxwhWJP9okRihftb0++Jsvr6fnsrKBSo9CFgiw+qGA5V67PT3eM1W84149L4DOM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657389; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=HQtibtTkqPOV+4busv/ixyk3PWldIZMUlgw3IT5bBGM=; b=ktbiSc+w/6TxCHp4qogPcuyLqL60/h6TJEHpnFysH/yfLY+yyc+SGSozNGu/WoZ9PX+6NlJT6NqoMPkMoy/dCoc8lFIyrrHsykZzZYcPbZlpAbqrk5daKKyb8oIGMR6+MyGvgkNmzZPgebjMjat73QFzLKRhls0BoVDi5a9kr8g= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657389831898.7794749815248; Tue, 25 Aug 2026 04:29:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypLO-0002V7-Fn; Tue, 25 Aug 2026 07:29:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLI-0002Hg-RU for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:25 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLG-0005ss-Vy for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:24 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-271-OxrFeqWKMO-6ePjwVYxjtA-1; Tue, 25 Aug 2026 07:29:18 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7BC101921EDE; Tue, 25 Aug 2026 11:29:17 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id CFB641800644; Tue, 25 Aug 2026 11:29:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657360; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=HQtibtTkqPOV+4busv/ixyk3PWldIZMUlgw3IT5bBGM=; b=UPr/ECULw+unjPmGUZkiZkI8koaEgNljwnwtoydrXQ250iII3oMRbbzQZsusVVhSxr0rB1 oNXWpN/qg67RqbyaNzRrr7MyU3HmUIezYTaQTky5S4KVfFEnr99F1WjnxubqzR1KwRuuhG XRgI+jg5DC3TLKYsqcudoo3/41iGpqw= X-MC-Unique: OxrFeqWKMO-6ePjwVYxjtA-1 X-Mimecast-MFC-AGG-ID: OxrFeqWKMO-6ePjwVYxjtA_1787657357 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:20:56 +0400 Subject: [GIT PULL 06/19] crypto: fix build against nettle >= 4 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-6-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, =?utf-8?q?Daniel_P=2E_Berrang=C3=A9?= X-Developer-Signature: v=1; a=openpgp-sha256; l=885; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=KM+m0Y823YuKZGWN8r5j0so3rITSfA8JzFB/G31XLLM=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrUauTyEh4C6/09ocGMqyoDpUJPbniVVTtQD ZRq+9VdT1uJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161AAKCRDa6OEJdZac 5e7hD/9czqfbVIKEn57eoqPQfIgzLzzrVvWqX/DrVNCQSuXR5bOf+s4U7EUMNN+6H87gavJqIuR AcpAs+vpBbNrHrOs54skIKPaRurKyvJqvb1xyQiWCO7JVabATaKJU7WnFuqhcE9LOjqu8If4+UX bJ7kRIK1XI6GK6Ou4fvxvajFa5O6t2x7ZObubs4b5bsC8kY28JKHf52Zkk1bSLAqweuR792gDep TWYHxW1xM4f4OqK/5xTm+Ezqis4TLcyMOBVv7odwIWq85wNoL41V7/5GpaJ9mDEMG4o1+iMlJra PeQURyUYLvCAxy7bbNcqDF+AJZuAM1wUdJdBCTbt9eKSzU4dJECwFPTGHG+E6ohH8Zt2PsBuC1P rQxxVAT4loRA3hgGwcqseO/571KmpyvGHjYzXjHZTFPz2fF0Z0OM9ZsciIMJKUpTewp9ojtpZr4 5wk5kmXb+3492iL2PpNl/mey54WWxCgPTd10mJ/31d0siTsV+xc6vBzwwlBec9Oe19we1RazslN iPwOoEcjCSHy3yRaNdkCpgWsAOJqwMe9Xv/pcRTKn0uIImAEXOKHHERYBDMBMrJLT528pUtBTKm nhrzRobzKc9y0GR9Pfp6LL5tLMzmNxAirdLleA2ZuT6JybxecqBCRMtH8vyigJBS+MjoWuQf+wW aAXPLl7JuXfnESg== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657391064158500 sha.h has been deprecated. It seems we can rely on sha1.h/sha2.h since we depend on >=3D 3.7.3. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4184 Reviewed-by: Philippe Mathieu-Daud=C3=A9 Reviewed-by: Daniel P. Berrang=C3=A9 Signed-off-by: Marc-Andr=C3=A9 Lureau --- crypto/hash-nettle.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/crypto/hash-nettle.c b/crypto/hash-nettle.c index 53f68301efb5..2589bbf4c10e 100644 --- a/crypto/hash-nettle.c +++ b/crypto/hash-nettle.c @@ -24,7 +24,8 @@ #include "crypto/hash.h" #include "hashpriv.h" #include -#include +#include +#include #include #ifdef CONFIG_CRYPTO_SM3 #include --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657386; cv=none; d=zohomail.com; s=zohoarc; b=EOQz3DPeWH9XgyUfCX6l4n7uR57pvRUY/JTTa8Blj/qWxsM7CISQS8P7IoqR/9nZdyohlU+OoqBMEDALt9TYSneAK/QPwsaSGjkwL1DCSMONsTT8jJ6zOU8yDnGEx+S9CjZMdQG/Bj24RmO0EI1iBDXQZgRsAnYzLa5Y3FrR5wQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657386; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Tu9OjoAkb2kL7TySR/SgHNC8iaedkUFQv6ynJ1J+Cdk=; b=WytahHI9JP2XR7t3sD955DChsnkehqbBiaCG4p3bu9//fM6s6UppgpggRobhEJQPZhEEAlkV1FdnoWfBuEdhym2ao4HYrbJas4y/tElH6AGQtkZudBKz5dTAwifR/Lk4721yJ9ZaIxMyEaFElS4STQ3+0gi3UZH4D9Q2rSZPEvQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178765738683920.049183369025627; Tue, 25 Aug 2026 04:29:46 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypLR-0002i2-AM; Tue, 25 Aug 2026 07:29:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLN-0002QJ-H9 for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:29 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLK-0005uj-4L for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:29 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-177-O43WpaxHNgGOqq8T7VKjQQ-1; Tue, 25 Aug 2026 07:29:22 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 2B9F5187E5E4; Tue, 25 Aug 2026 11:29:21 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id DCE781800641; Tue, 25 Aug 2026 11:29:19 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657365; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Tu9OjoAkb2kL7TySR/SgHNC8iaedkUFQv6ynJ1J+Cdk=; b=JLPvvpEdf79i+hbPKHGKjAfk0f03nG+7bKCjVIfwOdWCQApHbafM0Uppv3rB1zVamI1YyY y2iJF7GOWuQJjoml06ejmt/J0FXmOAGE6X2ax+TE8p9KzY4aYfq/UlCfl6z2kl66JU1AAI DZHUh4+jYh+MbaolLjwhLj3PgXTN6hY= X-MC-Unique: O43WpaxHNgGOqq8T7VKjQQ-1 X-Mimecast-MFC-AGG-ID: O43WpaxHNgGOqq8T7VKjQQ_1787657361 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:20:57 +0400 Subject: [GIT PULL 07/19] tests: tag slow tests with 'slow' suite for easy filtering MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-7-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, Fabiano Rosas , Laurent Vivier , Paolo Bonzini X-Developer-Signature: v=1; a=openpgp-sha256; l=1888; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=QITPpiOZP5Uk5r6XkgWAklMllT4ehRNGnPcCX1K6Y3c=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrUN/nnqX13yoFYWrmQ1nCuOdAHLmuhkO6tx DBdbOOuzHyJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161AAKCRDa6OEJdZac 5VQCEACrSMBzGAm7EQYa5+sG7oX2/lVVLRT7C95m/OMXxELyM+jzSC6qF5h2mFV8sli9D+I8Hw7 Po60Kv1bRf9gFmwFZl8KGzi1pxaa30mJOy3HGLmvrbZsQVw/euN2CvMUGMv5JbFVFfZtrj9N6xL wLWelqMPL8/gR2NRseGQEdXPCeS6lsUcoYgh4E96jre5bfSOir/hqJfnMYbGFe/WeLw139wUxre C7PYoiOKUKexFxoMYWOiA2mhtM1N0C/uUY3pTb2UnAWwErA35UrLDKERJdgnbJcRxHY4T7rwAfN YwSRCd9qqZcxAk2solBclaT4Oj/NTg34fkP+VRvOHrudHUNhu0Z1If88zHV2jKic36iqHVGHcjK KyrVPawr25GEEltcs6pEP9M0PLVQ2fn6aJNvDBvzFGnb4usI9weoN4EeBFAmcs7IU3fXcBnKGNl ksMMs6fkujPmbLpIsworjnRiL2ijzr4fSnR6QAFaqycggRcDm4n22yzFbi9DD4RR2PXmNenyPRo 64h30O7XbNIjV9PRcnEn4bP3mPPDOQHyyylJTMEvGWZDaRwruFaypGh/OoosBmdP926J4T4gODH 3OsDEZIlEz+Id4TZYzS64GTDkln3qWFCqRhKg7Nh5zY02qhVP2frlh9oB3+z4vcPoIqQD0ATN+D bpBVJVuwfpcEMPQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657389076158500 Add several RCU and thread-pool unit tests to the slow_tests dict, and tag all slow tests (both qtest and unit) with a 'slow' suite so they can be excluded or selected via meson test --suite/--no-suite. Acked-by: Fabiano Rosas Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260512065633.3542562-1-marcandre.lureau@redhat.com> --- tests/qtest/meson.build | 3 ++- tests/unit/meson.build | 9 ++++++++- 2 files changed, 10 insertions(+), 2 deletions(-) diff --git a/tests/qtest/meson.build b/tests/qtest/meson.build index 739df71d8d0b..cbdef5a54550 100644 --- a/tests/qtest/meson.build +++ b/tests/qtest/meson.build @@ -510,6 +510,7 @@ foreach dir : target_dirs protocol: 'tap', timeout: slow_qtests.get(test, 60), priority: slow_qtests.get(test, 60), - suite: ['qtest', 'qtest-' + target_base]) + suite: ['qtest', 'qtest-' + target_base] + + (slow_qtests.has_key(test) ? ['slow'] : [])) endforeach endforeach diff --git a/tests/unit/meson.build b/tests/unit/meson.build index dc3fb954c03a..3a9866c1f2be 100644 --- a/tests/unit/meson.build +++ b/tests/unit/meson.build @@ -184,6 +184,12 @@ slow_tests =3D { 'test-crypto-tlscredsx509': 90, 'test-crypto-tlssession': 90, 'test-replication': 60, + 'rcutorture': 30, + 'test-rcu-list': 30, + 'test-rcu-simpleq': 30, + 'test-rcu-tailq': 30, + 'test-rcu-slist': 30, + 'test-thread-pool': 30, } =20 foreach test_name, extra: tests @@ -205,5 +211,6 @@ foreach test_name, extra: tests protocol: 'tap', timeout: slow_tests.get(test_name, 30), priority: slow_tests.get(test_name, 30), - suite: ['unit']) + suite: ['unit'] + + (slow_tests.has_key(test_name) ? ['slow'] : [])) endforeach --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657388; cv=none; d=zohomail.com; s=zohoarc; b=THz9H1vswlArBj+dmiXqeODOD/e5yVEV2oDyGTeB+CPJBAL8B/ojECTWPqofvJdbH1OPkrqouhkjMcBPOleI5NGYAjwUZ6RyGw+RrbIpxh6N+DuZC1Xh6GAO17yTlp6sv0E5lB0685oSkHDOpfCg1uzEHwDvkD5cnuv3UaP3Rmk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657388; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=oOk/KZYABzKCZ+HHiMbNwb6PBXiMxNyrwHUaJrOc6Kw=; b=KF1u7n9UyL0+2lw6ZyvVXLBVcz+GTJ2gVY+wMsW3UuoUY7axl3knFS5/0BFKsR09GpHQnhK5LznO5ng7pBgHDiw1kRtkxnzZ+Q4VX/tMlzt8GDqkatxlWclr7aLmyv3j9WoaaXxNxzRpdh3Jx2PUVPnKTqDpLAn9sFmIoqAMG0A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178765738851453.8643988039878; Tue, 25 Aug 2026 04:29:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypLc-0003aF-Nl; Tue, 25 Aug 2026 07:29:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLa-0003O8-2x for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:42 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLY-0005z8-3F for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:41 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-657-wo1DuEWxPnCBE7t8j11rJQ-1; Tue, 25 Aug 2026 07:29:34 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 866FD19792DE; Tue, 25 Aug 2026 11:29:32 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id E0C001955F08; Tue, 25 Aug 2026 11:29:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657378; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=oOk/KZYABzKCZ+HHiMbNwb6PBXiMxNyrwHUaJrOc6Kw=; b=ZpMSRr1PEwbCjeoJX6n/EFEyLTAzVVQ/Q9ZXgP45ytzQ9shH+T17ZjuEv/t26qBBjowYw3 kLiEW2HlN7hC9Uc3hKrHFryq+jhviY2pnWeQ82RTvJicwVxDxs4UKU85g/mvhAM2V1v3yn 7RxyMLJFX7C3wVZLKTrV1YoaOktYdRs= X-MC-Unique: wo1DuEWxPnCBE7t8j11rJQ-1 X-Mimecast-MFC-AGG-ID: wo1DuEWxPnCBE7t8j11rJQ_1787657372 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:20:58 +0400 Subject: [GIT PULL 08/19] ui/egl: fix render node cleanup order MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-8-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, =?utf-8?q?Marc-Andr=C3=A9_Lureau?= X-Developer-Signature: v=1; a=openpgp-sha256; l=1493; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=4w7SX6jkh0t+zhJZWxe2pm3jQpJmCi5mIca5QpNB5q8=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrUa51mp18IThW76t11PsgeHgNWyitu3geYR 8Vcwvf/uoOJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161AAKCRDa6OEJdZac 5RLkD/sElXLsaaVgi+8yq+QeU5IIHsnFo3A49aOBX/gTq7LjqRpyDyYFPtLA+mmcKmfyLX0KEWf 91vtN5N9FR8O61aPN6iQIKJ+v1zEYV6iBYIptT6MgP28nvYNls99tMbwqjM7ppciTYYtutoKokw UfGvYPMytG4vRu0SVPw1K6d6vWBhOzEejU3F59qE+xUTwNecB/YxX3WUai+jcB//jkczxEbCEpV C1YCk7Uh5NHhZ8Q+A0hBySediQ6+uRQEUS1M+uzo55jOAMmNC1Vc292TuzAgS4plJMqq616z+5S Es6DTOSBdi9VNBHnDbC8GMeDpjP9cUIK+CpfEl2mLUvyI+cdwlq2soDvCY4FupcxQc0AQkVrK+k fB0LEN/IfEdld2NUpswiFybHypaDJZ0zKG7mh8lyT6683zqENsQlvTvs0e5bxOODv9tpSsUE+we HKBafK+Brujkn2eK0Ms6T6iQI+KPgW0xVYI3uzN7OOi6uSFi7l5gS5mBP16kW681yDwWQR8gGv7 JVoJZnMa9dKH3Nbb/5CuQb434rrYYWy33JbTlhndNBz3IsErOkzS2TcRDYuYiIstn/cTz8DvElG zIAGs1rVWRYjUjZwXthetTqD/mF+K9G/d5LbM+0jccw2ZVrn6U0+hYVc/Q4vjwX0VfI366fjiR2 wkpJ9ZxhMbYQHaQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657389065158500 ASAN detected some memory leaks when terminating. Release thread-bound EGL state first, destroy the context and terminate the display while the GBM device is still alive, then destroy GBM and close the render-node fd. Reviewed-by: Akihiko Odaki Fixes: a3cf9b55bbdc ("ui/egl: implement display and EGL cleanup") Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260820132014.2729748-1-marcandre.lureau@redhat.com> --- ui/egl-helpers.c | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/ui/egl-helpers.c b/ui/egl-helpers.c index d689f187c4e5..e89cc7c49af6 100644 --- a/ui/egl-helpers.c +++ b/ui/egl-helpers.c @@ -736,19 +736,22 @@ bool egl_init(const char *rendernode, DisplayGLMode m= ode, Error **errp) =20 void egl_cleanup(void) { + if (qemu_egl_display) { + eglReleaseThread(); + } + if (qemu_egl_rn_ctx) { eglDestroyContext(qemu_egl_display, qemu_egl_rn_ctx); qemu_egl_rn_ctx =3D NULL; } =20 + if (qemu_egl_display) { + eglTerminate(qemu_egl_display); + qemu_egl_display =3D NULL; + } + #ifdef CONFIG_GBM g_clear_pointer(&qemu_egl_rn_gbm_dev, gbm_device_destroy); g_clear_fd(&qemu_egl_rn_fd, NULL); #endif - - if (qemu_egl_display) { - eglReleaseThread(); - eglTerminate(qemu_egl_display); - qemu_egl_display =3D NULL; - } } --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657389; cv=none; d=zohomail.com; s=zohoarc; b=ihDdFJJHZJKU2JVUe5x6w48InYeR2ZdcxcwaM8d+LjwzZXWpdSXvOYmgZXtPDbDAkcNjRse1pNYVAHvaC8A5JEEJqAbDHLMADeUQM8lt07VMLthaeVEAdjyfMK4+JbrBywc24RKKQsmNmsVqVROULmdNbWUc6m3pRnNc6g5Li6k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657389; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bNlIBvz9vXULY0YURh0J5GIWI45xUL5THxgzjzMCUTM=; b=hI1uZfaCK4rBVOaebz39GqJEyj8R2LZDBT9g9GNPAVYc5ON6iIYYZI3J1pLfe2cfH85XXKms5Ceq5wfVj7AzpsbOLF+kcJaESafOEbFFdIB2dG+e+husupT04a4l1QiNskjQvD7/CUOSSsfzE/xw7lzZuHAv90Da9wQD+1ZMjtA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657389712600.4918145200915; Tue, 25 Aug 2026 04:29:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypLf-0003nO-HZ; Tue, 25 Aug 2026 07:29:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLc-0003dB-Q1 for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:44 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLb-00061P-28 for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:44 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-687-D2kBVfK8O6yUFE2GUR1LCg-1; Tue, 25 Aug 2026 07:29:38 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C781E191FCE9; Tue, 25 Aug 2026 11:29:37 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 413CE19539B7; Tue, 25 Aug 2026 11:29:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657382; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=bNlIBvz9vXULY0YURh0J5GIWI45xUL5THxgzjzMCUTM=; b=O2qroc5MRnjboRGH5qd6/g+pVBQKOQxmF3qA5tb554le6vrdMiZddSipv9GPIjDcUmDuQF qV4thw7XPephpGpxnEbaq5abNs+9VGLSnTTy9ZBk6n1kXTzIak2HuEkPh8FvED+os3w6g0 dYSPNNOgYrcy/DTVQY342u1kYvZQ9Fk= X-MC-Unique: D2kBVfK8O6yUFE2GUR1LCg-1 X-Mimecast-MFC-AGG-ID: D2kBVfK8O6yUFE2GUR1LCg_1787657377 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:20:59 +0400 Subject: [GIT PULL 09/19] ui/egl: fix qemu_egl_display type MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-9-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, =?utf-8?q?Marc-Andr=C3=A9_Lureau?= X-Developer-Signature: v=1; a=openpgp-sha256; l=1357; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=UyNdNiV0dG+DhwVXNcwxb79nxs6Z7XIzmMBiOXtFPV0=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrUH9Z0r4QzMDXxY8XrA/VHXEPioqGZQgeKe wUNFYnNWuOJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161AAKCRDa6OEJdZac 5WrPD/44Vo3RUZ3HukS7ADF7R8MHpuTGPzTg2elp2FqNfIExXHBRbUASIs83suy7rbA8JlXdw35 8JXRuZRtPih4BMXqUDivtwQbw5VC/JRMirTfzJB2zzLSquv1XjSJ8inI01fE8wcYTs/MgeNXKpu L98DtMkDKMNts7W0M99Wxhd8/o2WpTo/TqK1Iqk5JfeyAXPGQpH12ph/ADVLpGS4ED9jRCFvHnn pNuK8xICvBExke33vUzHSCwTXRis4JXtPtWaoB3OiIK/+C+9CkHULaK7v5fWI+Ut7ZsPf7Syu3A +5JE1b/hmDuVjqLjH7XNSDv/vl0dzu5dNksKevjGWa3RYZJBksZYtGUKCDOR/rZEJavkAQd2LQQ +Y5AG2RDAfY0oCTHdAmQ3Swmj31pklYZ0n5mH1/ysXAtmH9unin7o1TpCi8/ab4W0mGQxHdAcMU ApUm8TxwuRpcSLRnCuqFYkENpb6qYbX4PcEeQQk0onYeVq6jf9etnFRuFhR8VhQKOH05rhQwKY2 WmybQZxY1fID5A867dvnWr5d4iFRzIWZERcu0OCZZGV2QWS75HHtaTbE5/ZV81uSVAmn0Dib+vi LluMxdtHOFqZy+X6Z2l+s6+IM3U7ZzpSAUQqE5PsVdQmAuoIZKyaM6O6BU2f+dB5W6Ol90b54+o zxihiDzswczfpTQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657391049158500 EGLDisplay is already a pointer type (void *), so declaring qemu_egl_display as EGLDisplay * makes it void **, which doesn't match any of its usages. Fixes: 7ced9e9f6da2 ("ui: add egl-helpers") Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260820131933.2729240-1-marcandre.lureau@redhat.com> --- include/ui/egl-helpers.h | 2 +- ui/egl-helpers.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/include/ui/egl-helpers.h b/include/ui/egl-helpers.h index 405ddd912591..679c79eacd54 100644 --- a/include/ui/egl-helpers.h +++ b/include/ui/egl-helpers.h @@ -9,7 +9,7 @@ #include "ui/console.h" #include "ui/shader.h" =20 -extern EGLDisplay *qemu_egl_display; +extern EGLDisplay qemu_egl_display; extern EGLConfig qemu_egl_config; extern DisplayGLMode qemu_egl_mode; extern bool qemu_egl_angle_d3d; diff --git a/ui/egl-helpers.c b/ui/egl-helpers.c index e89cc7c49af6..8e3729a54d15 100644 --- a/ui/egl-helpers.c +++ b/ui/egl-helpers.c @@ -25,7 +25,7 @@ #include "trace.h" #include "standard-headers/drm/drm_fourcc.h" =20 -EGLDisplay *qemu_egl_display; +EGLDisplay qemu_egl_display; EGLConfig qemu_egl_config; DisplayGLMode qemu_egl_mode; bool qemu_egl_angle_d3d; --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657400; cv=none; d=zohomail.com; s=zohoarc; b=iP7My4ofxgmUi/CbhVjSAkD4K9WSpLajtDLfuD+5Ori/SXEi6y6/WYe7Rm1GSY0F3PYzdAz8aOP8y/1V1+LppKOKISm3wZcW/mIQvbc5a66H/ZmRxP3r2wPoQ3x2+afTBM+hpWFDpC4dTp3SPesqPHBLpetItXuWS98R6ewfHp8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657400; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=trSTfDehlJwFh5PvwUsL1efwjqahFszjfyfdVz4j3uA=; b=fGK7vEOY9vK/k0A6XCJ27NmU327NRXuPAeTRCEhfaj2n6ip1pZyejN2jB5hXkFBcxEdxvnvGl3tqUG1tXJz+hfPTNi9ZowZda0YHiephLMs5Gf+ZGzMewxFdUcpkKoPYrG56cf/V4rKur2yeJWb4at5CCYT5vmdPiSXaRFnh1r8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657400686618.2638350407636; Tue, 25 Aug 2026 04:30:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypLn-0004cA-DA; Tue, 25 Aug 2026 07:29:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLk-0004OL-Pt for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:52 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLj-000654-1U for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:52 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-171-l9saqlDtNwS8SXVtm2VECw-1; Tue, 25 Aug 2026 07:29:45 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 74510185BE92; Tue, 25 Aug 2026 11:29:43 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id A54EC195422E; Tue, 25 Aug 2026 11:29:42 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657390; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=trSTfDehlJwFh5PvwUsL1efwjqahFszjfyfdVz4j3uA=; b=dPUUPCcsDhKMxb5oqEsrwdolLywgga4gA8if4swbv3Ismn08V1lTk+c+dNLmT1AabrjCi7 emMwTlzSfnASDTr98TgpcgNAVufedG132mssQ/H+VDsN2LbU42fC0sHpFywi5xqr7FNBed 6gQbwlbMTpU4RK+fdcI2Q4OjL5TFJPQ= X-MC-Unique: l9saqlDtNwS8SXVtm2VECw-1 X-Mimecast-MFC-AGG-ID: l9saqlDtNwS8SXVtm2VECw_1787657384 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:21:00 +0400 Subject: [GIT PULL 10/19] tests/functional: fix pylint false positives for cv2 module MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-10-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, Thomas Huth , =?utf-8?q?Philippe_Mathieu-Daud=C3=A9?= , =?utf-8?q?Daniel_P=2E_Berrang=C3=A9?= X-Developer-Signature: v=1; a=openpgp-sha256; l=1324; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=ON8EwH+NM+YLICD9zMOhz/cNDHF0r3PX5tj/HxFjIb4=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrUeHm/1HQ/W3F7rTb/5gUG7er7BBsL+HybV q8Ys136CqGJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161AAKCRDa6OEJdZac 5WByD/4hazbWF+/F7IyzUjRKjP8sy4e/ZdLToxfnpyujuo2EPHcw8XXqKrOuDb9XeC3ot0y3uSk yQWeV8hJmpyogov9Gl5g4iZLeqaqAlMeglMn1pmiP89J96qHNC9476IatLGrgfi6+eWD8nlyAeR EkCzbxGwVEVcCGuioCC8wOAWp8aRLbR3/3vH00DbbB/dyn2FfTFBgCifqgd4ez2Ehj7ffeE1CBx j3VDDRQQMbxxJ+EU7z6da/X/lJdv8voj+2QDgJxV1queUGmbf4RL9+U0f2c9+F5cQ1epICefM1V xpbxs3ZDauyJkfpSQHKYUfZ9Iypv2my3WiNxOwA0rKs0m0Rh8W+42p3JeEvoZeOY7seZgWl/oCZ NQuWEjvbdKLmfb+SQmGK3Pc/gbRHlWCFzpze9XKzyu4JIBROJ5igz3GU+dWwiDjNr4vkhf/e4nP A/TBqZ+4oeiYPeiLLUQra2tEoxp8+OdjeJCQxuLq/x5xl3VzzWHreTMjGrxBw7kymVAeIJdWLAu 0Re6zesbt3ycScVjCtcxOuqn5FfnS/I7bN0pZr0PvP4kjHRG/re8tLJhJHjft8Z8gs73NO7mifU 7h8BJp5ipPIhY6iyYHr02Yfc4ke3qJdP2OtWF8DbTdsbQjpn875wvp/ZDrpLksWNBIEiVKzQFQd /qAOMv6oah8tjtA== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657401348158500 Add generated-members=3Dcv2.* to pylintrc so pylint skips member checking on the cv2 C extension module, whose members are not visible to static analysis. Silence: 2026-08-15 10:42:08,710 - INFO: qemu-test.test_pylint Checking files in /ho= me/elmarco/src/qemu.qom-qapi/tests/functional/arm with pylint 2026-08-15 10:42:10,941 - ERROR: qemu-test.test_pylint "/home/elmarco/src/q= emu.qom-qapi/tests/functional/arm/test_integratorcp.py:83: E1101: Module 'c= v2' has no 'imread' member (no-member)" Note: I also tried with extension-pkg-allow-list, but that didn't work for some reason. Reviewed-by: Thomas Huth Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260815072421.4117291-1-marcandre.lureau@redhat.com> --- tests/functional/pylintrc | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/tests/functional/pylintrc b/tests/functional/pylintrc index 949bea611fe4..373aabd6ca3f 100644 --- a/tests/functional/pylintrc +++ b/tests/functional/pylintrc @@ -79,6 +79,12 @@ disable=3Dbad-inline-option, useless-suppression, =20 =20 +[TYPECHECK] + +# cv2 is a C extension module whose members are not visible to pylint +generated-members=3Dcv2.* + + [SIMILARITIES] =20 # Minimum lines number of a similarity. --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657420; cv=none; d=zohomail.com; s=zohoarc; b=TQJO7FBMrAS5OP9OUHOGtsYUgjxW6n4CEjfZ9cNJbve6B7jBZ3WvesAgCOtHhmkB/A4Vlzuv08SkUSwmalvdFoMM3PdOYrBwJnBCAgGN4B278R2ZfttPZXT9SgM5Su+IybhFJTj9I8j7oyc6BDVVtUC0Q65yP7JPOCc/r3F14/k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657420; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=jWgAZ1AyegSTTW4gj89kS8+r1JbK1pHytcOIVnLqzyQ=; b=Wuc1Q/Rql/q6EwhZloZ+2sHdxA4U/5oKHSvGTpdLkAB6bzGzco7oTVYck7RBuPBMJg6/r2cOH61SwHfZIWe9XLHkBWymEtJLftdUq6Pphl+KQ3KRIuXcHwGYfsUnOyoD7Zo+N0j814tHp2c9tLbiDDWEYp/eCMTJ3NrWR/Ypmpo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178765742010375.11548867107194; Tue, 25 Aug 2026 04:30:20 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypLz-00055n-N7; Tue, 25 Aug 2026 07:30:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLp-0004r5-6Y for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:57 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLn-00066C-6F for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:56 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-605-EQOlTFwDMdCQ5FjpL2-xow-1; Tue, 25 Aug 2026 07:29:50 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 0C0E8185BE9B; Tue, 25 Aug 2026 11:29:50 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 1F69B30002EF; Tue, 25 Aug 2026 11:29:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657394; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=jWgAZ1AyegSTTW4gj89kS8+r1JbK1pHytcOIVnLqzyQ=; b=d+jUFggIIBRP/u4M/fIgwscI4WuNOffR+wSBc5EDxAvQUT7CiGgHTwxHj8LkUmKYDiz+U0 uap2j53yNbIGyZkviGWlSsaH0semCIY6zIYwp9LcvG7qIwwvB4ZcUmjfsnf1VzUE6ukRbn AjdW+nSqW4ov4OWXrQv7rtaJ7KoxVAM= X-MC-Unique: EQOlTFwDMdCQ5FjpL2-xow-1 X-Mimecast-MFC-AGG-ID: EQOlTFwDMdCQ5FjpL2-xow_1787657390 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:21:01 +0400 Subject: [GIT PULL 11/19] chardev: Don't unregister yank upon async path connection failure MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-11-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, =?utf-8?q?Marc-Andr=C3=A9_Lureau?= , Paolo Bonzini X-Developer-Signature: v=1; a=openpgp-sha256; l=1483; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=Gd0spWDHKZEABG/sZGft7YCGTAOdSumlGndxgUzlP/g=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrUEOnQPGIrT6mP3SfqplVtPuBf52POnBsVe ghw1hDpZd2JAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161AAKCRDa6OEJdZac 5Ri2EACowYh7xLznSd2mlfGWRDn8OHHR1WZlfHO0JLOQIlO3IpMCcDOl9qxxpHhaYZ9B7ODv7us j7Bn9rkDGqwPLlvt3hGljBeT97qS+vq3Ysr6/2vysGCpsJGCcqDiqGYDbhPDKzJx03RNb0DE8D2 xStWVRma/ih40D2QQHd1bZlBQRjaUWlm6GedOFKfucwIAXVCbtZlyLK0kknMrOPAamUof9rbv0C L5RJpxkrspL+kM70tesPNd4EBoGBldDIQivLEVCiPpmXNuJmqAJ41gp2ETIldCdhZ2iR+TONvMi X2xv+dv4O/kkgARkGd07bkVMbkWV3cp69jNUgA9OuapIlHBR18FUGYtKyptPeOp3j1q/2QvbDR6 KMdWXjnNDCSPR9rs7UXBEyKiOccFKIVqVeSOIB3tRDERXu/6qRNxUe6009jcVsvvWApMJZV7Xnt MQcN5yZiqLNRuKpYEfl0rHhmKCTgQqWrQUkFPEKbn+FEWr1YxK9wTp28v6RbPSXpjZeAzifPZV4 xLBxVERW/pMogL8K9KN380CWjNwuBbisXlM6PaJZDi0uaY9KYj+9nGG9qh5WXyw/WCK49QWYzOI Ehi5YzDdFUzWUuIO+euriOyO+zoSJKdF83opx9YALt9F+m/F7kyHYSDIs4rYJEm9U5FLxy7ZKam qhtqdU/mwQjn6Lg== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657421281158500 From: Fabiano Rosas Commit 5c102ac9 ("chardev: Consolidate yank registration") has moved yank registration in the tcp_chr_connect_client_async() path to after the connection is successful. If qio_channel_socket_connect_sync() fails early, there will be no yank registered to be unregistered in the error path, leading to assert. Remove the now-extraneous unregister. Cc: qemu-stable@nongnu.org Fixes: 5c102ac9 ("chardev: Consolidate yank registration") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3528 Signed-off-by: Fabiano Rosas Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260603141137.1108963-1-farosas@suse.de> --- chardev/char-socket.c | 5 ----- 1 file changed, 5 deletions(-) diff --git a/chardev/char-socket.c b/chardev/char-socket.c index b629575fcf80..81bac42a1587 100644 --- a/chardev/char-socket.c +++ b/chardev/char-socket.c @@ -1128,11 +1128,6 @@ static void qemu_chr_socket_connected(QIOTask *task,= void *opaque) =20 if (qio_task_propagate_error(task, &err)) { tcp_chr_change_state(s, TCP_CHARDEV_STATE_DISCONNECTED); - if (s->registered_yank) { - yank_unregister_function(CHARDEV_YANK_INSTANCE(chr->label), - char_socket_yank_iochannel, - QIO_CHANNEL(sioc)); - } check_report_connect_error(chr, err); goto cleanup; } --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657454; cv=none; d=zohomail.com; s=zohoarc; b=LVz6spo6ytWUEknLac2zuaQ9fWWBis2XYsSH81SRrQ1H0AungS4YAK4gNJhuXZsZsdxGeCY9s9oKCZN0bmc2P6PLysqthKQWZGiwY4jMvWvvQXzvH60evab4yh0CD8p6RJ8XCbrfyL/cLcygQZW0ehbHIn2lxgDAczlQr5cqGWE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657454; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wekiPFg1YpB8XRBQpidETX8GSUelcvkelnskzvbxTPQ=; b=JlV4jrR7L5HxcezYBcjXsoJHdLS/iYfKBlMV3biCP8hpOxbAyHftGRyiuz1jBaYri5RQcH5dT63DPhA5mIrEmDQGkn/rSpfVLkEB6Vll/i2Ii/8FOwX4FMEKw9fXIcX/eoWDcI/jrlB0+iEEWDiJbdd2ywqUpv7gOLCnmVCe+GY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657454964222.90788883762298; Tue, 25 Aug 2026 04:30:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypMY-0005e8-MV; Tue, 25 Aug 2026 07:30:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLs-00051A-8t for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:01 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLq-00067O-6U for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:29:59 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-82-2EzJ_QZSMQi1x1t7yj1cLQ-1; Tue, 25 Aug 2026 07:29:55 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id D9FB8191FCD7; Tue, 25 Aug 2026 11:29:54 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D332830002EF; Tue, 25 Aug 2026 11:29:52 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657397; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=wekiPFg1YpB8XRBQpidETX8GSUelcvkelnskzvbxTPQ=; b=RqhRLbL7q2chsBtqPLrFeX8RJrbzDJRnDt17BDW+DkTmf+IM83c2vC9T3lbNZFLwXs31au T00MGqr9ZmseYf8Z5uN3Y8WqZp5XW3hY3ouKH6hHHJvLomFcv3QdkRV0DGpmgeLRlJm3oy Hwxuyo/C8/RRqDo/ji+kuii2pQP2Sb8= X-MC-Unique: 2EzJ_QZSMQi1x1t7yj1cLQ-1 X-Mimecast-MFC-AGG-ID: 2EzJ_QZSMQi1x1t7yj1cLQ_1787657395 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:21:02 +0400 Subject: [GIT PULL 12/19] hw/display/vga: fix text-mode OOB write after a graphics surface switch MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-12-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, Gerd Hoffmann X-Developer-Signature: v=1; a=openpgp-sha256; l=6592; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=epeGVteNEbyd1wpjoz/1IoF0sVT1BmKTo/Iiu+dso9I=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrU9x5ToGWzF2dH/PEJkuTeCeQHo1UOZkyHl JNsue2z07mJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161AAKCRDa6OEJdZac 5c4XD/9UqJo5h+k1H2mQFCYlKG7xMh3mutmHMlmivx8qUx+3Wx2L3mqt9ZbP0lT4x/ScOkdq7Pe cYSGLFtYHIdQtZHpRzpZ1oOyl5zuPxpe+YlwOYFDhVT1sC/bWqdYJxf8wfD2/T6uWoxXH3cj3xe NFvS0Omo8UhK1OcxE58nD9Av/n9H06sUjD2fZKXzNv2PjO7Jg7yRH0UdsJ4485/IEmV8UQv/uN3 S3YBTc5yIzfv2ky7PJJ1TfYBWe84Ep+NbdEv3XTj1nSfwMIKIX7Y+MXLxvNG9J9nk77Qx/YpAVI qjUsnseinLNSHJtz81G+xoD1hcVO7BLcAAQp66GQ+OAkl8VrkzB6R0uZNbG3TQLaf5MDZZo3gmh SIVNRW+L3mi6kBuc9aBQ4wO8mGqGLZmtfEFuudZ/BYzhpdjKOb3iloCeurFbiqsB6iFqcSCaz7u s3vsJBg37Eq1SP+hcPsK+3gF7hq/El/xFqKLcxWPjFLrLUV/PbgTeYrp7cok5KjV2v6jqLkc25w NBVAgokOdJ2IemugMla09o1PTYwkFa65Npg50SPDDAAM9yH6yaYLyYtYskR3zk4z6t+U/5PCj/X rfmAhfFOXPb3tiF3fypTy8nMfklKObANZ2gvDP1psWfZlGtUizjOAcZeM2KxdffNFUoGF5VGt1j mND8toMAgl2ocMQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657455713158502 From: Warisjeet Singh vga_draw_text() decides whether the console surface needs a resize from its geometry cache, but none of the cache terms observe the graphics renderer having replaced the console surface in between: - last_width/last_height are shared with vga_draw_graphic(), which stores them in pixels while the text path stores characters; - last_depth stays 0 for legacy (non-VBE) graphics modes, because vga_get_bpp() only reports a depth when VBE is enabled, so the "s->last_depth" term that normally forces a resize after a graphics frame does not fire. So a graphics frame that shrinks the console surface (e.g. 80x25 pixels) followed by a text frame with matching character geometry (80x25 chars) skips the resize, and the glyph loop then paints width*cw x height*cheight pixels into the smaller surface, out of bounds, with guest-controlled (DAC palette) values, on every display refresh. Separate the geometry cache per renderer: text paths (vga_draw_text, vga_update_text, and the text handling in vga_invalidate_display / vga_common_reset) now only manipulate last_text_{width,height}, in characters; last_{width,height} become graphics-only, in pixels. Additionally, make the text path compare the pixel size it is about to paint against the console surface's actual dimensions. The surface check is the load-bearing term: caches in either unit cannot see the other renderer swapping the surface, the surface can. Fixes: CVE-2026-77913 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4215 Cc: qemu-stable@nongnu.org Signed-off-by: Warisjeet Singh (sin99xx) Message-ID: --- hw/display/vga.c | 37 ++++++++++++++++++++++--------------- hw/display/vga_int.h | 3 ++- 2 files changed, 24 insertions(+), 16 deletions(-) diff --git a/hw/display/vga.c b/hw/display/vga.c index da0c331486eb..cb0e28b79b6a 100644 --- a/hw/display/vga.c +++ b/hw/display/vga.c @@ -1241,7 +1241,10 @@ static void vga_draw_text(VGACommonState *s, int ful= l_update) return; } =20 - if (width !=3D s->last_width || height !=3D s->last_height || + if (surface =3D=3D NULL || + surface_width(surface) !=3D width * cw || + surface_height(surface) !=3D height * cheight || + width !=3D s->last_text_width || height !=3D s->last_text_height || cw !=3D s->last_cw || cheight !=3D s->last_ch || s->last_depth) { s->last_scr_width =3D width * cw; s->last_scr_height =3D height * cheight; @@ -1249,8 +1252,8 @@ static void vga_draw_text(VGACommonState *s, int full= _update) surface =3D qemu_console_surface(s->con); qemu_console_text_resize(s->con, width, height); s->last_depth =3D 0; - s->last_width =3D width; - s->last_height =3D height; + s->last_text_width =3D width; + s->last_text_height =3D height; s->last_ch =3D cheight; s->last_cw =3D cw; full_update =3D 1; @@ -1845,6 +1848,8 @@ static void vga_invalidate_display(void *opaque) =20 s->last_width =3D -1; s->last_height =3D -1; + s->last_text_width =3D -1; + s->last_text_height =3D -1; } =20 void vga_common_reset(VGACommonState *s) @@ -1887,6 +1892,8 @@ void vga_common_reset(VGACommonState *s) s->last_ch =3D 0; s->last_width =3D 0; s->last_height =3D 0; + s->last_text_width =3D 0; + s->last_text_height =3D 0; s->last_scr_width =3D 0; s->last_scr_height =3D 0; s->cursor_start =3D 0; @@ -1938,8 +1945,8 @@ static void vga_update_text(void *opaque, uint32_t *c= hardata) s->graphic_mode =3D graphic_mode; full_update =3D 1; } - if (s->last_width =3D=3D -1) { - s->last_width =3D 0; + if (s->last_text_width =3D=3D -1) { + s->last_text_width =3D 0; full_update =3D 1; } =20 @@ -1978,15 +1985,15 @@ static void vga_update_text(void *opaque, uint32_t = *chardata) break; } =20 - if (width !=3D s->last_width || height !=3D s->last_height || + if (width !=3D s->last_text_width || height !=3D s->last_text_heig= ht || cw !=3D s->last_cw || cheight !=3D s->last_ch) { s->last_scr_width =3D width * cw; s->last_scr_height =3D height * cheight; qemu_console_resize(s->con, s->last_scr_width, s->last_scr_hei= ght); qemu_console_text_resize(s->con, width, height); s->last_depth =3D 0; - s->last_width =3D width; - s->last_height =3D height; + s->last_text_width =3D width; + s->last_text_height =3D height; s->last_ch =3D cheight; s->last_cw =3D cw; full_update =3D 1; @@ -2071,22 +2078,22 @@ static void vga_update_text(void *opaque, uint32_t = *chardata) } =20 /* Display a message */ - s->last_width =3D 60; - s->last_height =3D height =3D 3; + s->last_text_width =3D 60; + s->last_text_height =3D height =3D 3; qemu_console_text_set_cursor(s->con, -1, -1); - qemu_console_text_resize(s->con, s->last_width, height); + qemu_console_text_resize(s->con, s->last_text_width, height); =20 - for (dst =3D chardata, i =3D 0; i < s->last_width * height; i ++) + for (dst =3D chardata, i =3D 0; i < s->last_text_width * height; i ++) *dst++ =3D ' '; =20 size =3D strlen(msg_buffer); - width =3D (s->last_width - size) / 2; - dst =3D chardata + s->last_width + width; + width =3D (s->last_text_width - size) / 2; + dst =3D chardata + s->last_text_width + width; for (i =3D 0; i < size; i ++) *dst++ =3D ATTR2CHTYPE(msg_buffer[i], QEMU_COLOR_BLUE, QEMU_COLOR_BLACK, 1); =20 - qemu_console_text_update(s->con, 0, 0, s->last_width, height); + qemu_console_text_update(s->con, 0, 0, s->last_text_width, height); } =20 static uint64_t vga_mem_read(void *opaque, hwaddr addr, diff --git a/hw/display/vga_int.h b/hw/display/vga_int.h index 5664317ecd6d..ca69ae981521 100644 --- a/hw/display/vga_int.h +++ b/hw/display/vga_int.h @@ -122,7 +122,8 @@ typedef struct VGACommonState { uint32_t plane_updated; uint32_t last_line_offset; uint8_t last_cw, last_ch; - uint32_t last_width, last_height; /* in chars or pixels */ + uint32_t last_width, last_height; /* in pixels (graphics renderer) */ + uint32_t last_text_width, last_text_height; /* in chars (text renderer= ) */ uint32_t last_scr_width, last_scr_height; /* in pixels */ uint32_t last_depth; /* in bits */ bool last_byteswap; --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657472; cv=none; d=zohomail.com; s=zohoarc; b=S7F+XB2AhJ5712vJllzjsqtsx+viDi9qHUvuW+yM/49WvQEqDNsZ9Ih8UKF1hu7UfgVt2NGqNnTKYqzxNopyQ7rsVz1Dzm3S4x4ZRaLKQV+FcPraGh9D8zl+E+KwnPwFNevlRQ8nh/Xd3R3mEkYg6ticuqWFcyMod+qdyCLDQSQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657472; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gKaNsru6hkhZt3cN1qHI96LC98GzN1H3C/XNNF5U03Q=; b=SSF0gEvkDhZMCZ2e4zzA9XGmcVRsJW39tYyScKbSew8baST2HoZZhOZNZVINKWDOLPoq/Zge+z4exor0lFrTXsKOROfL8rMWYcVjMXA2B1M1mQ9oISteJjcYa7dq+1JDAMfi0T11WnlIg7XK71B74XCQ9grioXaC1Nr5sdNVNpo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657472888996.3911416931711; Tue, 25 Aug 2026 04:31:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypMv-00061f-6f; Tue, 25 Aug 2026 07:31:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypM0-0005Da-26 for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:09 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypLy-0006Gb-7o for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:07 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-15-sQ1R_VOtOBuWzDu7e0FbXw-1; Tue, 25 Aug 2026 07:30:01 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id CE8831954231; Tue, 25 Aug 2026 11:29:59 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 242F71955F0A; Tue, 25 Aug 2026 11:29:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657404; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=gKaNsru6hkhZt3cN1qHI96LC98GzN1H3C/XNNF5U03Q=; b=aQDKf3SxwHwiQe2zojtE5+hphD5jyCQta+mEvGoQCug9woJYkh5eQ3IYfQggpB3uyFDTd/ JUAFRD5nBmElInTpOoPVaBP61Mi6xmUzHC/Oq6z5xnP9gurNNqwZHEDWaSLWCgfj1x4ElS aUiqiCGnWlO2lpt/iBGsNEovRLu4pH8= X-MC-Unique: sQ1R_VOtOBuWzDu7e0FbXw-1 X-Mimecast-MFC-AGG-ID: sQ1R_VOtOBuWzDu7e0FbXw_1787657400 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:21:03 +0400 Subject: [GIT PULL 13/19] hw/display/virtio-gpu: Avoid creating empty udmabuf MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-13-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, "Michael S. Tsirkin" , =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko X-Developer-Signature: v=1; a=openpgp-sha256; l=5448; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=Wqe+xF+yjNAiBPztDXQ8vnlkBdfrVe6QHG6gLhMbSQE=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrVjh8UpAEhcTc7+sIly4FodjH/O2uiyrwdY xF+IWgKY0CJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161QAKCRDa6OEJdZac 5aHtD/9RLm4U35xF5YgLNdnqPvgDBzzZnqJU+vIRuqHbul5w94CFV3E5Uok8iFLPq0Idly5/AZz puZ78ViQ8q7HcArqGRWLVBUmliqdCRsp1eQD1KRiqAgayEQcWwtc83Yv6WDwORL6lprScjlPTqt 2u27LGTiD4HCK2i6+xyk4kOnd1QQzK0MG4ko5As0aWgV4+7VXa6rb53m4BeI5bRiezFtEWw16OZ SoBVE0bLuQ9kQr6UEy6mmSq/IcBY6+Xh/msihbN8KPhsbA7D24dQqcEgsYXBk7WmMLz0r5IvNE9 vSUfm8dFYzebJw/hLtPKQ4whWc3aMZAwMCscjJeDpSWp0jQWFfEtKuTPvYf03EJYImtdxDXlzX8 3tSurIqozjvdxde1QDmwDL4OOzZmhEm0UoTnqWX7Qtzu13KndP+aiLYyOoRn2y0MqoR0LLw66yw M7T05zwcXixquoUZuMckdrp3IRR4oHA9pvmtpfMOACWyIQ+jdia99qntcO9/xHXEilyAA2sTv+m keTol+dXXUiCNRUx+2JHFcOIWus2AcNEbhhlZVjhO9mbqq/NVS5Q7gYIVuWDmCX9FAxJoa53qRH V+nypTBKI7PF3K1LTC/g4jHz3+YptKCtlMp3hPKovuDVoSUUx+nRWD8/31dd4uTBb6vuea0OVNY ZCzWaTNspabxN5g== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657473756158500 From: Akihiko Odaki The virtio specification allows creating a blob without backing storage attached. However, virtio-gpu attempts to create an empty udmabuf for such a blob. The ioctl fails with EINVAL and emits a spurious warning. Avoid the invalid ioctl. Fixes: e0933d91b1cd ("virtio-gpu: Add virtio_gpu_resource_create_blob") Fixes: f66767f75c9c ("virtio-gpu: add virtio-gpu/blob vmstate subsection") Signed-off-by: Akihiko Odaki Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260825-dmabuf-v2-1-b3d64d3b9a0e@rsg.ci.i.u-tokyo.ac.jp> --- hw/display/virtio-gpu.c | 102 +++++++++++++++++++++++++-------------------= ---- 1 file changed, 53 insertions(+), 49 deletions(-) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index 9eb010082d0d..50c4dcd408bb 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -363,27 +363,29 @@ static void virtio_gpu_resource_create_blob(VirtIOGPU= *g, res->resource_id =3D cblob.resource_id; res->blob_size =3D cblob.size; =20 - ret =3D virtio_gpu_create_mapping_iov(g, cblob.nr_entries, sizeof(cblo= b), - cmd, &res->addrs, &res->iov, - &res->iov_cnt); - if (ret < 0) { - cmd->error =3D VIRTIO_GPU_RESP_ERR_UNSPEC; - g_free(res); - return; + if (cblob.nr_entries) { + ret =3D virtio_gpu_create_mapping_iov(g, cblob.nr_entries, sizeof(= cblob), + cmd, &res->addrs, &res->iov, + &res->iov_cnt); + if (ret < 0) { + cmd->error =3D VIRTIO_GPU_RESP_ERR_UNSPEC; + g_free(res); + return; + } + + if (iov_size(res->iov, res->iov_cnt) < res->blob_size) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: backing storage smaller than blob size\n", + __func__); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + virtio_gpu_cleanup_mapping(g, res); + g_free(res); + return; + } + + virtio_gpu_init_udmabuf(res); } =20 - if (res->iov_cnt > 0 && - iov_size(res->iov, res->iov_cnt) < res->blob_size) { - qemu_log_mask(LOG_GUEST_ERROR, - "%s: backing storage smaller than blob size\n", - __func__); - cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; - virtio_gpu_cleanup_mapping(g, res); - g_free(res); - return; - } - - virtio_gpu_init_udmabuf(res); QTAILQ_INSERT_HEAD(&g->reslist, res, next); } =20 @@ -1389,8 +1391,6 @@ static bool virtio_gpu_load_restore_mapping(VirtIOGPU= *g, } } =20 - QTAILQ_INSERT_HEAD(&g->reslist, res, next); - g->hostmem +=3D res->hostmem; return true; } =20 @@ -1469,6 +1469,8 @@ static int virtio_gpu_load(QEMUFile *f, void *opaque,= size_t size, return -EINVAL; } =20 + QTAILQ_INSERT_HEAD(&g->reslist, res, next); + g->hostmem +=3D hostmem; resource_id =3D qemu_get_be32(f); } =20 @@ -1528,36 +1530,38 @@ static int virtio_gpu_blob_load(QEMUFile *f, void *= opaque, size_t size, res->blob_size =3D qemu_get_be32(f); res->iov_cnt =3D qemu_get_be32(f); =20 - res->addrs =3D g_try_new(uint64_t, res->iov_cnt); - res->iov =3D g_try_new(struct iovec, res->iov_cnt); - if (res->iov_cnt && (!res->addrs || !res->iov)) { - g_free(res->addrs); - g_free(res->iov); - g_free(res); - return -EINVAL; + if (res->iov_cnt) { + res->addrs =3D g_try_new(uint64_t, res->iov_cnt); + res->iov =3D g_try_new(struct iovec, res->iov_cnt); + if (!res->addrs || !res->iov) { + g_free(res->addrs); + g_free(res->iov); + g_free(res); + return -EINVAL; + } + + /* read data */ + for (i =3D 0; i < res->iov_cnt; i++) { + res->addrs[i] =3D qemu_get_be64(f); + res->iov[i].iov_len =3D qemu_get_be32(f); + } + + if (iov_size(res->iov, res->iov_cnt) < res->blob_size) { + g_free(res->addrs); + g_free(res->iov); + g_free(res); + return -EINVAL; + } + + if (!virtio_gpu_load_restore_mapping(g, res)) { + g_free(res); + return -EINVAL; + } + + virtio_gpu_init_udmabuf(res); } =20 - /* read data */ - for (i =3D 0; i < res->iov_cnt; i++) { - res->addrs[i] =3D qemu_get_be64(f); - res->iov[i].iov_len =3D qemu_get_be32(f); - } - - if (res->iov_cnt > 0 && - iov_size(res->iov, res->iov_cnt) < res->blob_size) { - g_free(res->addrs); - g_free(res->iov); - g_free(res); - return -EINVAL; - } - - if (!virtio_gpu_load_restore_mapping(g, res)) { - g_free(res); - return -EINVAL; - } - - virtio_gpu_init_udmabuf(res); - + QTAILQ_INSERT_HEAD(&g->reslist, res, next); resource_id =3D qemu_get_be32(f); } =20 --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657472; cv=none; d=zohomail.com; s=zohoarc; b=BM/wsVxyqiBvO2Vs267Mq68C2KL+ri3o0EVk4Kw1jBMsHZR8azBPGxTPP+54WfdNCuBCd7ZOurDsKWLB4gGnU7oCN3X7Jb/5fs5UVoELtDKCfPJnSb8141CdNsiZrN70U8GhfURoysD8GZn24lVv0kUFaRjbHuHFKbufAQ3bip0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657472; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=uL5jGEcrEpQzIIoThweWju+wfQbdFcsQO2Ybh3WmuEI=; b=DngxcsKCqtjlO50sZuFQzI4MDX++it2XLSQPR0tY8jvhDPwAHr2bOa3u/xSIXcVQsf+AUUQhbjZj4omjwY1P4/ZLUxkhRSKAXhSygtA6pzx767ZHDHA0McM40Cw2r/+D/VYxFkbXPV3+Yo3A/Utxv+onapvT7ujjIPA+totUIAI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657472330510.6572816906888; Tue, 25 Aug 2026 04:31:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypMs-0005wT-DR; Tue, 25 Aug 2026 07:31:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypM5-0005QJ-E3 for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:15 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypM2-0006N1-93 for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:13 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-441-xyMO5nrzPDWoHTlX24GxMw-1; Tue, 25 Aug 2026 07:30:04 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 9F99D1955BF1; Tue, 25 Aug 2026 11:30:03 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 8C440195422E; Tue, 25 Aug 2026 11:30:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657408; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=uL5jGEcrEpQzIIoThweWju+wfQbdFcsQO2Ybh3WmuEI=; b=RC59DmtYCObOlcpJY8oZUJS16SO/a2byHQAMnShmiijoI2sEKqWEJirvEgi2QHDdDfQ0tr CsJI0W58yQ897z2uMLlbdSFb+ykWlSdUsX2bxsdN7YpQfDoFg0iIQpt8ZExM3JITguevFi 1UayV1F38RF2nXfYVWz5tLWva4GTu0M= X-MC-Unique: xyMO5nrzPDWoHTlX24GxMw-1 X-Mimecast-MFC-AGG-ID: xyMO5nrzPDWoHTlX24GxMw_1787657403 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:21:04 +0400 Subject: [GIT PULL 14/19] hw/display/virtio-gpu: Avoid mmap() for empty blob MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-14-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, "Michael S. Tsirkin" , =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko X-Developer-Signature: v=1; a=openpgp-sha256; l=1045; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=1EjuhVLKQohCzphAuT6ig2Kmtuakt9951klpD1Q+Odg=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrVsBffrN8HoI0ps/iKWXdpcRFmqhHLjit7N s8IfFuDdhyJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161QAKCRDa6OEJdZac 5ZlvD/43pund8326utB75GwTUQMd1snvG3EoOVr2RnDs5ap1ZM0WjB3VepwKFLp1swxeB9dtzJ2 sUZxwv2F8uj1AvythkkroJShF2rlf2mqsbwwLIQjWs8V+WvrV7YU7OWcUmw7g5RQOnXhUOYfY/d WXaal1Cm0omPwzTsdqZPzdXSm77bRH9+Nd2e2t1x10mEbPuu9gfIlvbEDZDNY0otjrG0FojWihQ a1hOAppmSRNpCmIzmsZuQEJGmBOEqP1f5dwI83n8lLie3iO3SjP/J4PlxE/EFi73QZNi7Yx+tib rz2ua/BrTJ+JVt3hL9IPIYUIljkZVCSAGYPiROvWW6I07YJpyjO5zzY+bue3KrKZ/Bb4Y5k/6nO fz1AZgaVNMKCPp5pSRco/6b7/Yp+9KD+I4C2DG9ZEyM7LeoM15o8zBSi7I8uoWtspilahLblald eYhD4qgUK0HKttaEmpm39hSzx82qjmNjitiIFmjynXB9pZY4XjhF91Gu1fJZFm3jOTzbyPjb6BZ tfMzlSRdcLAnihWpn5WYoryjeoW+zFghE7Ms+8H2WqILAOVAVQ9vYlXgbeMKdaSd2sQ4BhQa1NL u6O+lpGmlkI7i6EMjvuOSOc7z0Syvg/WYf1Aziw8G0Ku84FgTzJOBCFKja5jvMg40hQcR8DeIwE k3t5wX5N+327YWQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657473688158500 From: Akihiko Odaki Calling mmap() for an empty blob fails with EINVAL, causing QEMU to emit a spurious warning. Fixes: e0933d91b1cd ("virtio-gpu: Add virtio_gpu_resource_create_blob") Signed-off-by: Akihiko Odaki Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260825-dmabuf-v2-2-b3d64d3b9a0e@rsg.ci.i.u-tokyo.ac.jp> --- hw/display/virtio-gpu-udmabuf.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hw/display/virtio-gpu-udmabuf.c b/hw/display/virtio-gpu-udmabu= f.c index 816f52a51457..ba02ba9e8616 100644 --- a/hw/display/virtio-gpu-udmabuf.c +++ b/hw/display/virtio-gpu-udmabuf.c @@ -139,7 +139,7 @@ void virtio_gpu_init_udmabuf(struct virtio_gpu_simple_r= esource *res) if (res->iov_cnt =3D=3D 1 && res->iov[0].iov_len < 4096) { pdata =3D res->iov[0].iov_base; - } else { + } else if (res->blob_size) { virtio_gpu_create_udmabuf(res); if (res->dmabuf_fd < 0) { return; --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657471; cv=none; d=zohomail.com; s=zohoarc; b=V7PYpOgLlTDGznr8P+mXTedxgo5x1cSwXJqUlBAYG8CzfulC1pgX1TLWK94M38fELyWl/CobDQ80ouEZuoFIAxOVjbYBWNYEvVzM91FhprOrdtISGzqLBJHEQvfYpHvktDgJypmGxMbGTDst0//6pHsIW1s9M+Q8Xrtu/CV4S4E= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657471; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RMCTKyk0xQSP+sGGG4Le4qa2X56Rh718aiy0BaZdxzo=; b=Uf1vNjtZAnw9JvTnYtyO4ueEOZ9XT0rQPR0YO0LIrxiOrsaYD20Q3tBw+DCAXM1j0VzzwUC0CjdNDL+tBF/kANzu9qa/t3SNSKm/s78d+mRrh/jhR58cqYSMBC1ewZkgjxBNnyyrr62HaLf2vVAqLKDaA3j+SpA6HLaJ9mp3Cv0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657471525906.162884870837; Tue, 25 Aug 2026 04:31:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypMc-0005kW-Er; Tue, 25 Aug 2026 07:30:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypM7-0005RP-Br for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:17 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypM5-0006OK-Jc for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:15 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-586-RiYze-_eMOmRhcirdBau9Q-1; Tue, 25 Aug 2026 07:30:09 -0400 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 4BC091801337; Tue, 25 Aug 2026 11:30:08 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id DF78018005B3; Tue, 25 Aug 2026 11:30:06 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657413; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=RMCTKyk0xQSP+sGGG4Le4qa2X56Rh718aiy0BaZdxzo=; b=aB7kg35lzB9wUQv/cLhcKRTk6PYuDuN5kv0IdhHIGOdGUMrTnRW0An7dHjPL42jL9GJAm2 eGppnWj+jDY/nYL2C0zlcgEXK6Q5ZTkqwge3vmHW332/OlY1WRAsCWM4tDSSDHhxs9lK8a 0yrOazoS58iBTN6wtNoKrOweF8P4x+8= X-MC-Unique: RiYze-_eMOmRhcirdBau9Q-1 X-Mimecast-MFC-AGG-ID: RiYze-_eMOmRhcirdBau9Q_1787657408 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:21:05 +0400 Subject: [GIT PULL 15/19] hw/display/virtio-gpu: Propagate udmabuf errors MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-15-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, "Michael S. Tsirkin" , =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko X-Developer-Signature: v=1; a=openpgp-sha256; l=4616; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=tskiFGwxTjjrGkMNH6cShz4T8hqExo7Om4UviQ1KgG8=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrV5C/n9i+XbGnT0kHILqkutpU1qvzJGdNSV ZucrbaDNYOJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161QAKCRDa6OEJdZac 5cOoD/9QDaXpzhSMF7HMp7aSHTsHZH6+q11u1OBig346tz8smuRbEERPA9PwZwRTlrGulhWdvED VMY8ZXkQ8MT1OlngvheAZetH3gW8Wsir/KDdY/Cg16P9+w3IpOaRVQFjnJTcFBopU6+nF0K9fJq H2vJSBa96Wq0j9QC8p3VCwSxJH36U9FeRU9zZkwSBcSjGKzoX+CrcKvN9zDvL+BxrlFgGdQ0U9k OfVbyBqgOThb39tDIp0wiIMOzruZA8+JGWi7EcaJrOms/E/oHzRv+MaNN63ZRE2phJmrzw6IW3E hQ706AwYVb6isuhtiLGV79bp46FrRZL7Y5so2zQocHPGhaOTp5hxHYmGn2IUjLphtYsPG7k7mDK T5j/OA54dgyIaE5SxpcuPLyvWoRUjtuqLmOwEpXqoStc8JkHjGAxtkWgWu95RwM1TDXnjajwMU3 zw0tZzELIRHLp8SyJtDk3dQmdYZ8GvjgmAhnyTcRq6ch6JJU3kPVnZR4Gz/g7Jojac2v+DhtPFq EBz1vzd+lFyoVtIBa+r4wRM9ZdbA3zPAg9yOGRIdNWvQdKXq/EDvz0Ln6A5sAfggYJVId+4bcv7 M2mrnVOCxmJr5rb7sI1MKRwhu2pVMCTZbS8D6l2BdFE3kS2dPteBUfC40iIqRTGZu2DCk/mRiwh eqC3kmXHV4ahFUQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657473707158500 From: Akihiko Odaki Propagate udmabuf errors so that the requested operation will be canceled instead of producing an incomplete result and the user can notice the failure. Fixes: e0933d91b1cd ("virtio-gpu: Add virtio_gpu_resource_create_blob") Fixes: f66767f75c9c ("virtio-gpu: add virtio-gpu/blob vmstate subsection") Fixes: 4ae1c5c7d6f3 ("hw/display/virtio-gpu: Initialize blob mapping for AT= TACH_BACKING") Signed-off-by: Akihiko Odaki Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260825-dmabuf-v2-3-b3d64d3b9a0e@rsg.ci.i.u-tokyo.ac.jp> --- hw/display/virtio-gpu-udmabuf-stubs.c | 3 ++- hw/display/virtio-gpu-udmabuf.c | 8 +++++--- hw/display/virtio-gpu.c | 18 ++++++++++++++---- include/hw/virtio/virtio-gpu.h | 2 +- 4 files changed, 22 insertions(+), 9 deletions(-) diff --git a/hw/display/virtio-gpu-udmabuf-stubs.c b/hw/display/virtio-gpu-= udmabuf-stubs.c index 85d03935a332..0883bf05fac1 100644 --- a/hw/display/virtio-gpu-udmabuf-stubs.c +++ b/hw/display/virtio-gpu-udmabuf-stubs.c @@ -7,9 +7,10 @@ bool virtio_gpu_have_udmabuf(void) return false; } =20 -void virtio_gpu_init_udmabuf(struct virtio_gpu_simple_resource *res) +bool virtio_gpu_init_udmabuf(struct virtio_gpu_simple_resource *res) { /* nothing (stub) */ + return false; } =20 void virtio_gpu_fini_udmabuf(VirtIOGPU *g, struct virtio_gpu_simple_resour= ce *res) diff --git a/hw/display/virtio-gpu-udmabuf.c b/hw/display/virtio-gpu-udmabu= f.c index ba02ba9e8616..c230509852ff 100644 --- a/hw/display/virtio-gpu-udmabuf.c +++ b/hw/display/virtio-gpu-udmabuf.c @@ -131,7 +131,7 @@ bool virtio_gpu_have_udmabuf(void) return memfd_backend; } =20 -void virtio_gpu_init_udmabuf(struct virtio_gpu_simple_resource *res) +bool virtio_gpu_init_udmabuf(struct virtio_gpu_simple_resource *res) { void *pdata =3D NULL; =20 @@ -142,17 +142,19 @@ void virtio_gpu_init_udmabuf(struct virtio_gpu_simple= _resource *res) } else if (res->blob_size) { virtio_gpu_create_udmabuf(res); if (res->dmabuf_fd < 0) { - return; + return false; } virtio_gpu_remap_udmabuf(res); if (!res->remapped) { virtio_gpu_destroy_udmabuf(res); - return; + return false; } pdata =3D res->remapped; } =20 res->blob =3D pdata; + + return true; } =20 static void virtio_gpu_free_dmabuf(VirtIOGPU *g, VGPUDMABuf *dmabuf) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index 50c4dcd408bb..7f3301a9ac57 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -383,7 +383,12 @@ static void virtio_gpu_resource_create_blob(VirtIOGPU = *g, return; } =20 - virtio_gpu_init_udmabuf(res); + if (!virtio_gpu_init_udmabuf(res)) { + cmd->error =3D VIRTIO_GPU_RESP_ERR_UNSPEC; + virtio_gpu_cleanup_mapping(g, res); + g_free(res); + return; + } } =20 QTAILQ_INSERT_HEAD(&g->reslist, res, next); @@ -1045,8 +1050,9 @@ virtio_gpu_resource_attach_backing(VirtIOGPU *g, return; } =20 - if (!res->image) { - virtio_gpu_init_udmabuf(res); + if (!res->image && !virtio_gpu_init_udmabuf(res)) { + cmd->error =3D VIRTIO_GPU_RESP_ERR_UNSPEC; + virtio_gpu_cleanup_mapping(g, res); } } =20 @@ -1558,7 +1564,11 @@ static int virtio_gpu_blob_load(QEMUFile *f, void *o= paque, size_t size, return -EINVAL; } =20 - virtio_gpu_init_udmabuf(res); + if (!virtio_gpu_init_udmabuf(res)) { + virtio_gpu_cleanup_mapping(g, res); + g_free(res); + return -EINVAL; + } } =20 QTAILQ_INSERT_HEAD(&g->reslist, res, next); diff --git a/include/hw/virtio/virtio-gpu.h b/include/hw/virtio/virtio-gpu.h index 220231ec9d43..69b5ee2e382f 100644 --- a/include/hw/virtio/virtio-gpu.h +++ b/include/hw/virtio/virtio-gpu.h @@ -388,7 +388,7 @@ bool virtio_gpu_scanout_blob_to_fb(struct virtio_gpu_fr= amebuffer *fb, =20 /* virtio-gpu-udmabuf.c */ bool virtio_gpu_have_udmabuf(void); -void virtio_gpu_init_udmabuf(struct virtio_gpu_simple_resource *res); +bool virtio_gpu_init_udmabuf(struct virtio_gpu_simple_resource *res); void virtio_gpu_fini_udmabuf(VirtIOGPU *g, struct virtio_gpu_simple_resource *res); int virtio_gpu_update_dmabuf(VirtIOGPU *g, --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657488; cv=none; d=zohomail.com; s=zohoarc; b=gcYgJqWIuxwUmd8YhwH1ImhWqWJHSVIG3LA7RmMBbK6WhzWv9OFLMUiyVb7qUP4tCXbvYsLkXcihVFPTJbPfhhWRwhIPLMBcNQ4CV85K9c9V5TaJuxdu8Oz47wLA6xNKghG4c8elZiMWbvPjr0jf1AEgHiMputvawcpGvKbQIMM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657488; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=mskKc6mSuvBAkzrTbpBf8DxVhn57z97dfknSFMXPne4=; b=MqTHYP2dPnFpQT/2jmrH3IUhnOOtRQUb3fvfNDP83aMhL4ouiHgQnFPNxEPFg0i2dHY+PVVqTPXuGsWedR4hJWtSl9g3LhnbjAQCja1yXiVnN0fc82UMPchh9A3nltCR7UfF2uUx5TNEyCtyB5D7UeWnxh+JH4VtA6uFOo+0CkU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657488769948.4913589478176; Tue, 25 Aug 2026 04:31:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypMv-00061g-5T; Tue, 25 Aug 2026 07:31:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypMB-0005Xc-AS for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:27 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypM9-0006P8-No for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:18 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-683-CRUK3GXjMd-VgTWK5kRcqQ-1; Tue, 25 Aug 2026 07:30:15 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 473591954237; Tue, 25 Aug 2026 11:30:14 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 44EA51801AEA; Tue, 25 Aug 2026 11:30:12 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657416; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=mskKc6mSuvBAkzrTbpBf8DxVhn57z97dfknSFMXPne4=; b=R46ndBU/FwRWDX86sy4cerVrv0wxvypZNa76HtvKEjyf9o9pA5VVYU0Cd0TNmO6BOElPg4 9MwcfwAHmDzC1x6SUqWlkcnp3l8hGzVuM8RHGMWhyHwzYMGK+V/ealyzbc1Lzx1+3sgD6a EzRWor5Ph5jciK6AHAU2vLTIrDxgZ/8= X-MC-Unique: CRUK3GXjMd-VgTWK5kRcqQ-1 X-Mimecast-MFC-AGG-ID: CRUK3GXjMd-VgTWK5kRcqQ_1787657414 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:21:06 +0400 Subject: [GIT PULL 16/19] hw/display/virtio-gpu: Check cursor data presence MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-16-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko , "Michael S. Tsirkin" X-Developer-Signature: v=1; a=openpgp-sha256; l=1123; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=RcZzO5KwMeF19XwWn0KZU91FWni8PQux3WPjJ2zqvkU=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrV22/QghIndSlQ0qWh+gWuhGwr4HJtzI5rc /zLxaKS0o+JAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161QAKCRDa6OEJdZac 5WyED/9QiLkKmk7Vi1E2M8FEQsNOO9+edCu+8I3+REMtjfGvRXvQlNJqpUHiUSFa9J0Gp0+7llZ xdKZlWPrN2YdeOSTKK4e4xQUhNw9alHyJdB8tYz206U+GV/Zf4Ns23L+eR87S2PDSwbvARq+jWv TfTWfBlpyoiPBfkeDDG3+EF5tdDjFc3PqXbdnQRcz2uJvVCV+D82dD06RAoAyQDLRm7Cvk/9w8a xYJCaYU/K3Z3p+NLdlpuNpzGSc8cMYAVXaoVXqRinDAkkPtRcrMefhrMlZRy1Pu7m0FnvBGfg8y RHZSnuL2XmFm9G35S2Xa11IPH+uxY+9VX0mwIC7Q1uEyv06Wo/YIzt26AEYxXiT7c7i7ZqgbFZw FG2JEMJlx87TxD8vqhjiwigJqx3mDzkXmJKnlxsorTbj2ZRzUu3XXC/cf6vU/Neuc14bbICGWZd q7BjawA+U+i0jnRuWk5UuFVgtyKXhytAXHoT2jj1KHjxrw/wJu3zHAUp1FI5JZ9KiAHG+9NAXlQ i0Xffxd16oBdcZaO7vKun/k8KMfmZxaZkEOKC3ss3YW+0podjm9L4u2A4ALjUXDVvs369K8g0Lw JcpZ9kvchT/nqkkX1PCPB7To7IrTlErb2mFiTD3b+iguySRbyw1CEZ8HizfAchcklAc0RqKwaGA 99vAI5kusRKTepA== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657489941158500 From: Akihiko Odaki Reject a blob that lacks the backing storage for VIRTIO_GPU_CMD_UPDATE_CURSOR. Fixes: bdd53f739273 ("virtio-gpu: Update cursor data using blob") Signed-off-by: Akihiko Odaki Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260825-dmabuf-v2-4-b3d64d3b9a0e@rsg.ci.i.u-tokyo.ac.jp> --- hw/display/virtio-gpu.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index 7f3301a9ac57..01549d29d8a2 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -63,8 +63,8 @@ void virtio_gpu_update_cursor_data(VirtIOGPU *g, } data =3D pixman_image_get_data(res->image); } else { - if (res->blob_size < (s->current_cursor->width * - s->current_cursor->height * 4)) { + if (!res->iov || res->blob_size < (s->current_cursor->width * + s->current_cursor->height * 4))= { return; } data =3D res->blob; --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657460; cv=none; d=zohomail.com; s=zohoarc; b=GE8j+5Z/5e/SBobx5w2bkhm7Ms8ZMPxrJvuA1SWnGmm/hiQw//sqRpFlvvyn8g0vZlBdTpHjyRToRmvxdYXLECv7kz9Bk/MuMdrfVrpUjSX2y9MI/Un3ZR5UCT/Uwbk64egsBq5F1om0tjO0aNuRk5KS+/VdUWeL9E2rNw9GFKU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657460; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RU+E0PxmQDtUNb+74H9rVkxLJkFU1YhVf4BZGlMGbH4=; b=nAxGqOL+CnVw7aJpome8yxjiTYKiFYijtmEWHkPjHTCZL3y0Da3MQXP/+I9HDDmd1ghICYRIucYuLEiesgVsYlXsm2keEtarPRxYkcfsT18U++mNs10qqrQ/S17wapLFQitJc3hJuvox9jo3HE6gFSFG7XK1PMRwx2j3kXYFGpM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657460635434.58190324038776; Tue, 25 Aug 2026 04:31:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypMj-0005ln-Md; Tue, 25 Aug 2026 07:30:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypMJ-0005ZQ-2j for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:29 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypMH-0006UN-C3 for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:26 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-302-0bdtCheSNVOiDSNquvM6Qg-1; Tue, 25 Aug 2026 07:30:20 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 17C791955DDF; Tue, 25 Aug 2026 11:30:19 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id C1D1C30002F0; Tue, 25 Aug 2026 11:30:17 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657423; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=RU+E0PxmQDtUNb+74H9rVkxLJkFU1YhVf4BZGlMGbH4=; b=PyZ7xOB6VzDGX6zCpf7fmLlZtT8lvwSjJi84qhqzdaVlVgbaOmIb6aXidD1tJ1WQYJbaVz txt8rdw2dCOW94CI2CX5hE0GD85/n2b4SR6EDHkEX8zXxPwf8JbTXHXbiPuxxBvUTwcqJv YYphPI1zcOE2qjqwvtlDqfH9I2B+ASY= X-MC-Unique: 0bdtCheSNVOiDSNquvM6Qg-1 X-Mimecast-MFC-AGG-ID: 0bdtCheSNVOiDSNquvM6Qg_1787657419 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:21:07 +0400 Subject: [GIT PULL 17/19] hw/display/virtio-gpu: Validate resource per command MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-17-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org, =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko , "Michael S. Tsirkin" X-Developer-Signature: v=1; a=openpgp-sha256; l=6715; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=b8AGFms1qm0EUGpts3LUCRJqtr768B/5CA4S3QHib+4=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrVHwzBflEgVPgR5I0aYMXHUt9hifoxdt57A HheXUWV1BSJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161QAKCRDa6OEJdZac 5a2DD/9//7iVSCMEOTQrNZtd1E7i4xUcH4oRh2a1rA9qHvzGRhHl0XKEGaW38/DVgDknXOsJ0wN oiwnQsBIfJ3voz75u1lvm+OrFSD/6TrRjEtmZJHHy1uV3pkHB0Fb56Be6+QcZ+j2RncdKPFPh69 LEH0zmy4GW3kAU3PSnuq0yLzlPkSPNILVr/YH8eIkovJGqqwMNZhI/RlzvcN8S+EU0b8Mn64yBt t4f6d+A+KZ8whHk0F38QvKiUTGSCW/OTiAJReifBNFzXd68eRlnQKR+eYU3DjmhyK6SvYB9XM5F Wu1lZwiWHcCn5uUuWbYtWUP8Ukdmz8toQNogCpJK1twrHlm6BqIFzsM+UctTc7sFm35UUp3pgl+ VU+BiFbHq72Thnw7kQkwyESoN++rb9K08g3366Y9S8SXLbRU/rD+aZQVISMRK+kQmAFwOIe8De+ 7DE1qIX0aFpdBN7TRh1aGILcIsAK/T3HvLwQ+mSg8OJphV5iCA7k+R7U/R/850OLt1rB9NVM7le A2CmLcc/yJi4vMvYh2ezqMWjmjtBVys+GmSTl6Qrz55tUmFURl2RLbpVuqbPyZcf/myfSV3egho /oqp4XCNtSXf8p3+nH8D7UYUXTeB4q/m1lmmi4HxozHX5mZiIfm7ZZ8rwWIF4gvXFfjJNW9LNa9 4yEmnN8qJQ4jq8A== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657461560158500 From: Akihiko Odaki virtio_gpu_find_check_resource() checks if the resource has backing storage if require_backing is true, but the condition conflates backing storage attachment with host representation; it checks !res->iov || (!res->image && !res->blob), but !res->iov is sufficient. Furthermore, its callers passing true as require_backing have different requirements: - virtio_gpu_transfer_to_host_2d() requires a non-blob with backing storage. - virtio_gpu_set_scanout() requires a non-blob but does not require backing storage. - virtio_gpu_set_scanout_blob() requires a blob with backing storage. - virtio_gpu_resource_detach_backing() accepts any resource. Remove the require_backing parameter and open-code checks appropriate for each function instead. Fixes: 25c001a40346 ("virtio-gpu: Add virtio_gpu_find_check_resource") Fixes: e0933d91b1cd ("virtio-gpu: Add virtio_gpu_resource_create_blob") Fixes: 32db3c63ae11 ("virtio-gpu: Add virtio_gpu_set_scanout_blob") Signed-off-by: Akihiko Odaki Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260825-dmabuf-v2-5-b3d64d3b9a0e@rsg.ci.i.u-tokyo.ac.jp> --- hw/display/virtio-gpu.c | 66 +++++++++++++++++++++++++++++++++------------= ---- 1 file changed, 45 insertions(+), 21 deletions(-) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index 01549d29d8a2..55a1c7f80fb8 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -37,7 +37,6 @@ =20 static struct virtio_gpu_simple_resource * virtio_gpu_find_check_resource(VirtIOGPU *g, uint32_t resource_id, - bool require_backing, const char *caller, uint32_t *error); =20 static void virtio_gpu_reset_bh(void *opaque); @@ -50,8 +49,7 @@ void virtio_gpu_update_cursor_data(VirtIOGPU *g, uint32_t pixels; void *data; =20 - res =3D virtio_gpu_find_check_resource(g, resource_id, false, - __func__, NULL); + res =3D virtio_gpu_find_check_resource(g, resource_id, __func__, NULL); if (!res) { return; } @@ -128,7 +126,6 @@ virtio_gpu_find_resource(VirtIOGPU *g, uint32_t resourc= e_id) =20 static struct virtio_gpu_simple_resource * virtio_gpu_find_check_resource(VirtIOGPU *g, uint32_t resource_id, - bool require_backing, const char *caller, uint32_t *error) { struct virtio_gpu_simple_resource *res; @@ -143,17 +140,6 @@ virtio_gpu_find_check_resource(VirtIOGPU *g, uint32_t = resource_id, return NULL; } =20 - if (require_backing) { - if (!res->iov || (!res->image && !res->blob)) { - qemu_log_mask(LOG_GUEST_ERROR, "%s: no backing storage %d\n", - caller, resource_id); - if (error) { - *error =3D VIRTIO_GPU_RESP_ERR_UNSPEC; - } - return NULL; - } - } - return res; } =20 @@ -474,9 +460,24 @@ static void virtio_gpu_transfer_to_host_2d(VirtIOGPU *= g, virtio_gpu_t2d_bswap(&t2d); trace_virtio_gpu_cmd_res_xfer_toh_2d(t2d.resource_id); =20 - res =3D virtio_gpu_find_check_resource(g, t2d.resource_id, true, + res =3D virtio_gpu_find_check_resource(g, t2d.resource_id, __func__, &cmd->error); - if (!res || res->blob) { + if (!res) { + return; + } + + if (!res->image) { + qemu_log_mask(LOG_GUEST_ERROR, "%s: resource %d is a blob\n", + __func__, t2d.resource_id); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_RESOURCE_ID; + return; + } + + if (!res->iov) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: resource %d has no backing storage\n", + __func__, t2d.resource_id); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_RESOURCE_ID; return; } =20 @@ -533,7 +534,7 @@ static void virtio_gpu_resource_flush(VirtIOGPU *g, trace_virtio_gpu_cmd_res_flush(rf.resource_id, rf.r.width, rf.r.height, rf.r.x, rf.r.y= ); =20 - res =3D virtio_gpu_find_check_resource(g, rf.resource_id, false, + res =3D virtio_gpu_find_check_resource(g, rf.resource_id, __func__, &cmd->error); if (!res) { return; @@ -771,12 +772,19 @@ static void virtio_gpu_set_scanout(VirtIOGPU *g, return; } =20 - res =3D virtio_gpu_find_check_resource(g, ss.resource_id, true, + res =3D virtio_gpu_find_check_resource(g, ss.resource_id, __func__, &cmd->error); if (!res) { return; } =20 + if (!res->image) { + qemu_log_mask(LOG_GUEST_ERROR, "%s: resource %d is a blob\n", + __func__, ss.resource_id); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_RESOURCE_ID; + return; + } + fb.format =3D pixman_image_get_format(res->image); bytes_pp =3D virtio_gpu_format_bytes_pp(fb.format); fb.width =3D pixman_image_get_width(res->image); @@ -866,12 +874,28 @@ static void virtio_gpu_set_scanout_blob(VirtIOGPU *g, return; } =20 - res =3D virtio_gpu_find_check_resource(g, ss.resource_id, true, + res =3D virtio_gpu_find_check_resource(g, ss.resource_id, __func__, &cmd->error); if (!res) { return; } =20 + if (res->image) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: resource %d is not a blob\n", + __func__, ss.resource_id); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_RESOURCE_ID; + return; + } + + if (!res->iov) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: resource %d has no backing storage\n", + __func__, ss.resource_id); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_RESOURCE_ID; + return; + } + if (!virtio_gpu_scanout_blob_to_fb(&fb, &ss, res->blob_size)) { cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; return; @@ -1067,7 +1091,7 @@ virtio_gpu_resource_detach_backing(VirtIOGPU *g, virtio_gpu_bswap_32(&detach, sizeof(detach)); trace_virtio_gpu_cmd_res_back_detach(detach.resource_id); =20 - res =3D virtio_gpu_find_check_resource(g, detach.resource_id, true, + res =3D virtio_gpu_find_check_resource(g, detach.resource_id, __func__, &cmd->error); if (!res) { return; --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657470; cv=none; d=zohomail.com; s=zohoarc; b=LeUq579wEOMkVP6fZ2ra3jIILKv9oMhUMy0/5lxXFnIttY5FaC0XhqJg581d2aIKszge51pcooDMtZ7P/Ja2qDdQX3W86uFwpzyN+x5Irzq4RYD01ZAdZ0h3/XxYsboyZe91gyRUoFV+eQKOuFi5+FK0xBF/uPW5fYvYC0Oi4Ns= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657470; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/EF15DLJHuyxxg2Wx4TIr/vf8/Y8SRHbXy9M4qOyPP8=; b=N46Ga6zNNY48pqujeKIVqUfUC2+j8DkKeppNLVucMJRDOXYiwvhu+i5IbkArHuxGcESaIUisBdHBtTwTbppCU6ID/gR37LDRJQCMYMFukd6A1ZdYuV6pVK0f6pQruITQXSdUiAdR5txAKCyVDshSQiSYr+NLbHVaVclzRY/NZOE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17876574705186.092816917887831; Tue, 25 Aug 2026 04:31:10 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypMw-0006CA-Rp; Tue, 25 Aug 2026 07:31:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypMK-0005Zn-AN for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:30 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypMI-0006VP-Ks for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:27 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-90-chVzuRhiPMuv3UfoEuah6A-1; Tue, 25 Aug 2026 07:30:23 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 96D55187E5E4; Tue, 25 Aug 2026 11:30:22 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id CA6DF1800641; Tue, 25 Aug 2026 11:30:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657425; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/EF15DLJHuyxxg2Wx4TIr/vf8/Y8SRHbXy9M4qOyPP8=; b=VuY9GsySEF/FBcILKM5peguhnz52N70sDqWmizbqWpLsr5x4m3KIq0vUttUmY0dPFkA0eZ rJJHbPQihc8KYBCk54iqqcBRnS2rSbKLDj5COYXDM6bL1MVPRu5y8l8dJjK1npme/0Vct1 6owT91J9tnc+HOjYsIkVp1HIMaUEzfE= X-MC-Unique: chVzuRhiPMuv3UfoEuah6A-1 X-Mimecast-MFC-AGG-ID: chVzuRhiPMuv3UfoEuah6A_1787657422 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:21:08 +0400 Subject: [GIT PULL 18/19] hw/input/ps2: answer unknown mouse commands with a resend MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-18-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org X-Developer-Signature: v=1; a=openpgp-sha256; l=3100; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=vqPBZIR/UTG1l+75KrnAJ+h+vmcAhTrHiaqlz5DLOgw=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrV07ry58ZYV9nhWOlhV5QjRH6rMytA3U3Gm JaLEiCWtQqJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161QAKCRDa6OEJdZac 5W9QD/9wwXNLWW8lANbqYZvPIslyYO+LzFi7JdPPXSMqWp4GPEDj8HM+/2dXjbYVJ2fyNRsEe8M zjIwoZZMppnFC1n89x5Nv2Elj6bJSQRls2SbWHfWaAuiNmFq8OkTSI1zU+gXKND3ctuOj6Okytf c9cCEwrGKzCKYkuccz7QaLXtLHh9XP0KwoZrTKkpvDKISS7HnBomzLa92WihIYTRVZN/ZA54rJ6 OndsPJ0i/o6B6taj+0Y7cI2F9box5xwsOqBtn+hzgUCnBz9dXEs5ubQNRd+XafTvZNMbqaCuhjc KeL6tyxUkkFJM5xmfmWAhjJd2djpb5C00YuBaIH76F9ausAiPLKrI8LYdrl8H1mCs1Aiu5Y5xdg iwMKDOeTTqZiTj/onE3Vld/w/uDOWoeIH4gwndtSV7nBJvDB7sxo5UeOPEqPR20vCkpU+8dbrys 5ooYEcLDkup3bO5OqEADdIt+YQN0AasFhu/N1mQStWyLtYl4CJuKvUp8zwsa3quGNjwguaP//XJ gVNZFvVN7j9v3Ytu2OzZyLYBwAIZ/fmgXjqAKzGoVuwm3HMUGHHjL10bRfOVQ8a9jOsQynVjos4 fSizCNqVUMUvq6hQ3YaJQZOzRfu3JV82/vBnq1E45Om8weJBnnyilqXHKnVQn+STtJtpvFRty2E 0+DZPEYKiDo4lgw== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657471674158500 From: Christian Quante ps2_write_mouse() ends its command switch with a bare "default: break;", so an unknown command draws no reply at all. A real PS/2 device answers every byte it is given -- ACK (0xFA) when it understood one, resend (0xFE) when it did not -- and a guest that gets nothing back is left waiting out its reply timeout. The keyboard path in the same file has answered unknown commands with KBD_REPLY_RESEND since commit 06b3611fc2a3 ("ps2: reject unknown commands, instead of blindly accepting them"). Two guests were measured on this. OS/2 probes the mouse with the vendor command 0xBB, which QEMU does not implement, and then polls the status port until its own timeout runs out. On a Warp 3 guest that wait costs about 25 ms of every boot under TCG, and 2.1 s under KVM, where each of those polls leaves the guest. With this patch the wait ends on the first read: the guest takes the same error path an unexpected reply would, and does not retry. Linux runs into two of them while probing the mouse: the ALPS probe sends 0xEC (reset wrap mode), which ps2_write_mouse() only answers while the mouse is in wrap mode, and the TrackPoint probe sends 0xE1. Each costs libps2 a 200 ms reply timeout. Timing the psmouse detection from a mark written to /dev/kmsg to the kernel's "input:" line, three boots each of a 6.18.35 kernel under TCG: 426.7/428.8/441.6 ms without this patch, 21.4/21.6/21.2 ms with it. The mouse is detected identically either way; only the error the probe ends in changes, from -EIO (nothing came back at all) to -EPROTO (libps2 gives up after its second attempt). The specification's second stage -- 0xFC (Error) when the byte after a rejected one is invalid as well -- is deliberately left out. It would need state that has to survive migration, no guest is known to test for it, and the keyboard path does without it as well. Cc: qemu-stable@nongnu.org Signed-off-by: Christian Quante Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Akihiko Odaki Message-ID: <20260825075127.34876-2-christian@quante.one> --- hw/input/ps2.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/hw/input/ps2.c b/hw/input/ps2.c index 5516eb262d70..e8300d2d8308 100644 --- a/hw/input/ps2.c +++ b/hw/input/ps2.c @@ -73,6 +73,7 @@ #define AUX_SET_DEFAULT 0xF6 #define AUX_RESET 0xFF /* Reset aux device */ #define AUX_ACK 0xFA /* Command byte ACK. */ +#define AUX_RESEND 0xFE /* Command NACK, send the cmd again */ =20 #define MOUSE_STATUS_REMOTE 0x40 #define MOUSE_STATUS_ENABLED 0x20 @@ -955,6 +956,11 @@ void ps2_write_mouse(PS2MouseState *s, int val) s->mouse_type); break; default: + /* + * A PS/2 device answers every command it is given; an unknown + * one draws a resend. + */ + ps2_queue(ps2, AUX_RESEND); break; } break; --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:15:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1787657473; cv=none; d=zohomail.com; s=zohoarc; b=cEOQPRhorCZG+t0SU8XqPXi2Ss3vjTwFWWmb9i1x5p9P8JFpjummx5CHrOeGI+v3TpDHCWmbidW6MBm8jajPPpj0C3MSBY8ZutdNjDIYNytUNnI9R14hTYbmcih1eLx/l5suh2MFsD4t4iQCsLHwAQTvyGTqsH462gAwDuPuXmg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787657473; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=30yn/c+wt/bT8D/y3U/P9jFrQ+FxGSkq4u+zKm/7UQc=; b=AKXYpByZdthWWVIZqeykrtdV3vV+Oio6dCOWSLcGIEKqbeCwbFO5OqK/HHKpr8eMquV0zQlXjU+z6R8VDwQOrACSSR+dBI7gg0U3+KwjrnQTudYknGrwmIYVeRbVv1HUaOTIQ9e+6EEkVFn1Max+lZIrv/lFJIvzy7KWUMVpplU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1787657473720817.8835061098479; Tue, 25 Aug 2026 04:31:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wypMz-0006NG-SX; Tue, 25 Aug 2026 07:31:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypMR-0005eD-Ix for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:38 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wypMN-0006Wp-As for qemu-devel@nongnu.org; Tue, 25 Aug 2026 07:30:34 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-35-7bDGwIqnPWG6xuyR7imlDw-1; Tue, 25 Aug 2026 07:30:27 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 1AB321800877; Tue, 25 Aug 2026 11:30:27 +0000 (UTC) Received: from localhost (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id CC45230002EF; Tue, 25 Aug 2026 11:30:25 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787657430; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=30yn/c+wt/bT8D/y3U/P9jFrQ+FxGSkq4u+zKm/7UQc=; b=EUScvauJBRUFtdoZ2k+rUH76uck4HZSHDlHAbczBRBgyl5wkM0mIaObwkBhC2dpawHHqxe yfy8op5WJ+KeoM+ErzRd49Y9mxicFwJux7rsXuWGpuTFEmVxsFTMu4yRDfql4FIr21mujg 6wDOQ97rspTSMnlX5nug9iBDacy39NI= X-MC-Unique: 7bDGwIqnPWG6xuyR7imlDw-1 X-Mimecast-MFC-AGG-ID: 7bDGwIqnPWG6xuyR7imlDw_1787657427 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 25 Aug 2026 15:21:09 +0400 Subject: [GIT PULL 19/19] hw/input/ps2: say why unknown keyboard commands draw a resend MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260825-fixes-v1-19-c59e8a620836@redhat.com> References: <20260825-fixes-v1-0-c59e8a620836@redhat.com> In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com> To: qemu-devel@nongnu.org Cc: richard.henderson@linaro.org X-Developer-Signature: v=1; a=openpgp-sha256; l=1209; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=BTCwLkEhXu+eBXujb6Fbe5sGYtMzBGPyeDMAYsbUyS0=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqjXrVVMowQ6YgR7nqdZXzDD4gjnS/zJh82xGQF TimzfPdvPKJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCao161QAKCRDa6OEJdZac 5RgID/9zDb6/oGRgu/Ah2TJ8IK+tbgCprN6voaBqheuvyyYnO48UXjuEsdyBRzt/OhzRoPP+AB4 EULYOel8oSCPkOhUvAAapa7uCi+NOFwJAHKnnStcbcasjygTr/LflRdi7TSbQvcuS0CnQ8hZoOp 18wBR2O+N1EiAzaqWROMkGHOHylojqb2sHpqt6n38kjTv6tFx3wmLHcDyxs8OC9p7WFQ3/DZKRg hWEwzMKrK77MeZmGQqm9uI0pb6C1bUFQQiYayjZrGM7Cf7bKXoYb8IlrPCu1Cug08ooU5H1K7uJ z4GkuvHzJRl5GE/+Af6P/fXSivDgwI+o0yZXBk0HU0TeWWFTuo4tA/aa9+vD2i9rS5X6hEq2McQ d0MUUPxx/KjxK2ypz/pLECLAmZUbxBOP8F4XtyqjRuDv2Kc9VSih+z2dlJYSQYenzT1OOceg3r4 Mg9nlWbRIYiN6PJBHDUF34QpaJon1Lg6Qcbx5M41MUJ0WdbizGNZ/MPrQq3EqvlN/b6/WQZctT7 sgrswurKNvKC9RG2OU5XY4/dgntqWnguIO2eChfsvgsXAtTfMbRqwGz5N33ctGTV8hEf9bOgTpX Z7dskfzt8+dy0rp0m1eW68aq4lXxfKR4B0AiRvbey+VHpLbbT7fY+sVR9J33UdsM4cL5uOglamg ZL9hydcZCApMsYg== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1787657475709158500 From: Christian Quante The keyboard path has answered unknown commands with KBD_REPLY_RESEND since commit 06b3611fc2a3 ("ps2: reject unknown commands, instead of blindly accepting them"), but never said why. Give it the comment the mouse path just gained, so the reasoning is written down in both places. Suggested-by: Akihiko Odaki Signed-off-by: Christian Quante Reviewed-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Akihiko Odaki Message-ID: <20260825075127.34876-3-christian@quante.one> --- hw/input/ps2.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/hw/input/ps2.c b/hw/input/ps2.c index e8300d2d8308..01af4350b3bc 100644 --- a/hw/input/ps2.c +++ b/hw/input/ps2.c @@ -647,6 +647,10 @@ void ps2_write_keyboard(PS2KbdState *s, int val) ps2_cqueue_1(ps2, KBD_REPLY_ACK); break; default: + /* + * A PS/2 device answers every command it is given; an unknown + * one draws a resend. + */ ps2_cqueue_1(ps2, KBD_REPLY_RESEND); break; } --=20 2.55.0.543.g5ebe2ebe4ea8