From nobody Sat Sep 26 20:03:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=yandex-team.ru ARC-Seal: i=1; a=rsa-sha256; t=1788568980; cv=none; d=zohomail.com; s=zohoarc; b=OjQS/5vuWjpF9vXafW+lKSn0mjuzuTbtXi8RyRoHhQX3SDbi+FX3FhulizLMWsTbCRFWcXoh3kX5hvRS7oLK3ZBWypphmuWYcUIeze//VlKAa5iDLcVk/uPzk0LNsKV2atENOr7lgA02SjarSzBM2SxfUADSmRVtX1cmn4zbLQI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788568980; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=osJdLbs18BzXXDJuBf1vjeN7BoEwJBZGURyldnlUtLg=; b=hzGjZI9YdMYMlr6rQdcZzg38qWhKDUAxFRr3FaqAPSXxmdXctqsMTTZMtYhLZkGTX6B9KPpFkuT/NfAr67ktSz9xcyhumlnNV0Wf9heaLWOe4XwvFToM3jzU8kmaKOGiWJWuvFfZzUMXeH2YcFa9X/UqMF4+NFSR2xQTc9S63g8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788568980090457.2793936781396; Fri, 4 Sep 2026 17:43:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2eU8-0003vJ-VK; Fri, 04 Sep 2026 20:42:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2eU7-0003ue-9D for qemu-devel@nongnu.org; Fri, 04 Sep 2026 20:42:19 -0400 Received: from forwardcorp1b.mail.yandex.net ([178.154.239.136]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2eU5-0000Ev-AU for qemu-devel@nongnu.org; Fri, 04 Sep 2026 20:42:19 -0400 Received: from mail-nwsmtp-smtp-corp-main-34.sas.yp-c.yandex.net (mail-nwsmtp-smtp-corp-main-34.sas.yp-c.yandex.net [IPv6:2a02:6b8:c24:fa2:0:640:41ee:0]) by forwardcorp1b.mail.yandex.net (postfix) with ESMTPS id A219880AA3; Sat, 05 Sep 2026 03:42:13 +0300 (MSK) Received: from i101646577.yandex-team.ru (unknown [2a02:6bf:8080:11b::1:22]) by mail-nwsmtp-smtp-corp-main-34.sas.yp-c.yandex.net (smtpcorp) with ESMTPSA id 7g79b72ad0U0-AsKqJkyf; Sat, 05 Sep 2026 03:42:13 +0300 X-Yandex-Fwd: 1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yandex-team.ru; s=default; t=1788568933; bh=osJdLbs18BzXXDJuBf1vjeN7BoEwJBZGURyldnlUtLg=; h=Message-ID:Date:In-Reply-To:Cc:Subject:References:To:From; b=u27zFwnme9SjUorCCXo2N+mEP/PTo17P4G3wMsF/fuEqPXuwmyjvsrNP123OFuoPq P9ItRzCHaWX6bVM5JLHs2B1HeTgxXY37pE/jOC9Ouu64/Mba9SAqnM1bUIkiULk6+R EFnUCNMDpB+4Bg+MPO/R5RR9qjN5Y//CGnxLrIpQ= Authentication-Results: mail-nwsmtp-smtp-corp-main-34.sas.yp-c.yandex.net; dkim=pass header.i=@yandex-team.ru From: Daniil Tatianin To: "Michael S. Tsirkin" Cc: Daniil Tatianin , Paolo Bonzini , qemu-devel@nongnu.org, Richard Henderson Subject: [PATCH 1/2] hw/intc/apic: don't drop irq line re-evaluation when LINT0 is masked Date: Sat, 5 Sep 2026 03:41:51 +0300 Message-ID: <20260905004153.836866-2-d-tatianin@yandex-team.ru> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260905004153.836866-1-d-tatianin@yandex-team.ru> References: <20260905004153.836866-1-d-tatianin@yandex-team.ru> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=178.154.239.136; envelope-from=d-tatianin@yandex-team.ru; helo=forwardcorp1b.mail.yandex.net X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @yandex-team.ru) X-ZM-MESSAGEID: 1788568983368158500 Content-Type: text/plain; charset="utf-8" apic_update_irq() wouldn't be called at all in case the guest set LINT0 as masked, which would prevent a previously asserted CPU_INTERRUPT_HARD from an ExtINT source (like the legacy PIT) from getting cleared. This would usually go unnoticed since masking the PIC while LINT0 is still unmasked would clear said interrupt via pic_irq_request(). However, a guest that masks LINT0 first, and only then the PIC still keeps CPU_INTERRUPT_HARD asserted, which then fires on its first sti. Since APIC's IRR is empty, and the PIC is never even asked since LINT0 is masked, a -1 is returned from cpu_get_pic_interrupt(), which is then propagated all the way to IDT dispatch, which fails the IDT limit check against 0xFFFFFFFF (-1) and causes the guest to take a bogus #GP with an error code of 0xFFFFFFFA (aka -1 * 8 | (1 << 1)). This can be reproduced by simply booting via SeaBIOS, it leaves the PIT running, LINT0 unmasked and configured as ExtINT, and PIT unmasked at the PIC. A guest that then masks LINT0, and then the PIC, receives the #GP mentioned above following its first sti instruction. Fix this by calling apic_update_irq() unconditionally after a LINT0 write. Fixes: a94820ddc3 ("apic: Reevaluate pending interrupts on LVT_LINT0 change= s") Signed-off-by: Daniil Tatianin --- hw/intc/apic.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/hw/intc/apic.c b/hw/intc/apic.c index 0e8932005f..6fb941cc47 100644 --- a/hw/intc/apic.c +++ b/hw/intc/apic.c @@ -1007,7 +1007,8 @@ static int apic_register_write(APICCommonState *s, in= t index, uint64_t val) s->lvt[n] =3D val; if (n =3D=3D APIC_LVT_TIMER) { apic_timer_update(s, qemu_clock_get_ns(QEMU_CLOCK_VIRTUAL)= ); - } else if (n =3D=3D APIC_LVT_LINT0 && apic_check_pic(s)) { + } else if (n =3D=3D APIC_LVT_LINT0) { + apic_check_pic(s); apic_update_irq(s); } } --=20 2.43.0 From nobody Sat Sep 26 20:03:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=yandex-team.ru ARC-Seal: i=1; a=rsa-sha256; t=1788568976; cv=none; d=zohomail.com; s=zohoarc; b=Cafp/3FDiohYJvQOtpO2QxJD4IHMeVfQCIH2jLXDdg7qhycRajFpPx/8qfNYtIO9+81xdzi3EKxwzeRckjyoYR8a2gsB4hMafCZe+QDcXkorbZhKWySax2qzZj0I7F1AKK0JUMek8KN7j2xZjH6h9R/jfUBm4EmYnwPK79Yz/KM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1788568976; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Hx1+gsMbkV2GOHLR1F+fYKz6TYxQ6TxaJs0th/N9c94=; b=JErI410mFzbCgJ/oJ/qTywvZ5VT4W0PBT9nRK7/GQmBZTbz1hpQmF4GyMPzos47JtW06WvfKl7Qs4d3WO6JLIUrNZh+cB900hfoW/Z2Aul0TpjNlNSN/HPwIyeG2dLW7pqSULw/Sk4a9uiuCRBp43B+nV0cz6kv0i/wWp+uuAX0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1788568975172181.94747990118435; Fri, 4 Sep 2026 17:42:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x2eUA-0003vf-QF; Fri, 04 Sep 2026 20:42:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2eU8-0003vH-NY for qemu-devel@nongnu.org; Fri, 04 Sep 2026 20:42:20 -0400 Received: from forwardcorp1b.mail.yandex.net ([2a02:6b8:c02:900:1:45:d181:df01]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x2eU7-0000F2-3x for qemu-devel@nongnu.org; Fri, 04 Sep 2026 20:42:20 -0400 Received: from mail-nwsmtp-smtp-corp-main-34.sas.yp-c.yandex.net (mail-nwsmtp-smtp-corp-main-34.sas.yp-c.yandex.net [IPv6:2a02:6b8:c24:fa2:0:640:41ee:0]) by forwardcorp1b.mail.yandex.net (postfix) with ESMTPS id CE11780796; Sat, 05 Sep 2026 03:42:16 +0300 (MSK) Received: from i101646577.yandex-team.ru (unknown [2a02:6bf:8080:11b::1:22]) by mail-nwsmtp-smtp-corp-main-34.sas.yp-c.yandex.net (smtpcorp) with ESMTPSA id 7g79b72ad0U0-x8InsZv8; Sat, 05 Sep 2026 03:42:16 +0300 X-Yandex-Fwd: 1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yandex-team.ru; s=default; t=1788568936; bh=Hx1+gsMbkV2GOHLR1F+fYKz6TYxQ6TxaJs0th/N9c94=; h=Message-ID:Date:In-Reply-To:Cc:Subject:References:To:From; b=iClxAq0g15YPfCDMdbe27xpUz5TqL44MjEfyCe2HGOtMh8LSqTKDEouux4waYju8P eN4M6yjx9Aez43+2MaKKT+6sOsEJygqnZxE90vRoQoeUUfXvMxuzqFnpzMjZZhWjI5 ukNtxe6U3LFDliGZlV6XS/XJpZlR5iGLJw9SRHo4= Authentication-Results: mail-nwsmtp-smtp-corp-main-34.sas.yp-c.yandex.net; dkim=pass header.i=@yandex-team.ru From: Daniil Tatianin To: "Michael S. Tsirkin" Cc: Daniil Tatianin , Paolo Bonzini , qemu-devel@nongnu.org, Richard Henderson Subject: [PATCH 2/2] target/i386: drop attempts to deliver an interrupt without a vector Date: Sat, 5 Sep 2026 03:41:52 +0300 Message-ID: <20260905004153.836866-3-d-tatianin@yandex-team.ru> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260905004153.836866-1-d-tatianin@yandex-team.ru> References: <20260905004153.836866-1-d-tatianin@yandex-team.ru> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a02:6b8:c02:900:1:45:d181:df01; envelope-from=d-tatianin@yandex-team.ru; helo=forwardcorp1b.mail.yandex.net X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @yandex-team.ru) X-ZM-MESSAGEID: 1788568982449158500 Content-Type: text/plain; charset="utf-8" cpu_get_pic_interrupt() returns -1 when neither PIC nor APIC has anything to deliver, and skipping this check produces a bogus #GP inside the guest with an error code of 0xFFFFFFFA (aka -1 * 8 | (1 << 1)) due to a failed IDT limit check in do_interrupt_x86_hardirq(). The KVM path already drops such interrupts in kvm_arch_pre_run(), so just do the same thing. Signed-off-by: Daniil Tatianin --- target/i386/tcg/system/seg_helper.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/target/i386/tcg/system/seg_helper.c b/target/i386/tcg/system/s= eg_helper.c index 8c7856be81..d1c626f120 100644 --- a/target/i386/tcg/system/seg_helper.c +++ b/target/i386/tcg/system/seg_helper.c @@ -204,6 +204,9 @@ bool x86_cpu_exec_interrupt(CPUState *cs, int interrupt= _request) cpu_svm_check_intercept_param(env, SVM_EXIT_INTR, 0, 0); cpu_reset_interrupt(cs, CPU_INTERRUPT_HARD | CPU_INTERRUPT_VIRQ); intno =3D cpu_get_pic_interrupt(env); + if (intno < 0) { + break; + } qemu_log_mask(CPU_LOG_INT, "Servicing hardware INT=3D0x%02x\n", intno); do_interrupt_x86_hardirq(env, intno, 1); --=20 2.43.0