From nobody Sat Sep 26 22:14:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296246; cv=none; d=zohomail.com; s=zohoarc; b=SaMS5OodwWovi0rJ9CZOoittFT2ITo99rNgiqPrZccfp8+OJCpdFw2x4sUCgUQtpJZSm5pUopc8ZdorMGOelq8+X5gQ0tFvm3qHl/CSzDDg/D/vvOJ1jUW2gPuaxQYN8nhFo7F15EdgP6Q9M4M/U8Fyuq3ljjyVEeodGbGRfPrY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296246; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RnuFdKKVpqFKDm4hZnFD0Rhn5+yJEZDo7nKlyDxdy9Q=; b=IszNrr0XbYizBZLAMrWjyDkPh14abfwckVLIYnwFg4jViSmH4LmDQ48AWFDXCYxh9amjCMDpBAqQpLFDMEHy+Vjel833hl2QG34tTp6YOVryz/HUDFCVukOiYqoZSeaPhZf93onudtCcOUDpnAFG/QEqvtG0bWkgh2wyrUt6/5Y= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296246658139.82872357503118; Sun, 13 Sep 2026 03:44:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hfl-0005cE-PZ; Sun, 13 Sep 2026 06:42:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hfj-0005bZ-Lx for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:42:55 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hfi-0008Ab-Bp for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:42:55 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-240-XNJjXC5SMG-vh56EtB0KIA-1; Sun, 13 Sep 2026 06:42:51 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id AB3BB1944DD2 for ; Sun, 13 Sep 2026 10:42:50 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id A8F8930001B9; Sun, 13 Sep 2026 10:42:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296173; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=RnuFdKKVpqFKDm4hZnFD0Rhn5+yJEZDo7nKlyDxdy9Q=; b=Zz2RDetwHRW6HUspTC9VdJtgqGjuM7zWgZMB+7STCb3+Dei9slFcRCN4OXwbLPN3pzCYwZ 7zOD7nnxa6RcSyJRHBkqvi9T03HtMltZGAwymDPNrttgAswRbSWIbWXYtssiZZSm6ngIa3 1C6IA9dO76MOGEA4DagCh/ZOluo9gDc= X-MC-Unique: XNJjXC5SMG-vh56EtB0KIA-1 X-Mimecast-MFC-AGG-ID: XNJjXC5SMG-vh56EtB0KIA_1789296170 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:19 +0400 Subject: [GIT PULL 01/14] ui/dbus: fix cursor race, copy cursor data MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-1-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org Cc: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= X-Developer-Signature: v=1; a=openpgp-sha256; l=1260; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=llMUUGzcjuqZBsgOy2Q3nKSAiYWuK9mpFKVJ6lb5KHc=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4i1ljhUZSHw1zx3L0r8N2MD9TDVY6LWhCHh h0cJBPmwViJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IgAKCRDa6OEJdZac 5YoTD/9Nchyttb1XTgKLZTwZuoAuHmkGkTJh7kh7iwqxSG/1YrFBbk7KsOq+SViHotrwfYV4CwI RcJIwsrlanOfQgiBEmP+faGGmNxrRvPwMQ3sKF2WR3jMnS9N8xoB2fsgSCfQwVK8GZQB6rgYC5V xxxO3Ki2XDZX0HYFFNovoKA3jtWlTtpECHEuxFM9vzNY9nM7J5ZUvr/Px4qPeI6sQgxCyjzTN4I KN6Wp2cu0AbF7O0VM7AKOIFIXlqbq3ZXTxuMtqmB+iWlgM7kuJH9UYEcnz9Fjang18sK0CDOfZ8 ePHLjtoMBgFw3QkGJlspO9jGKrGAxSWQ6ebk0O3LtVzZewKTkPTx11W6puPnunY2jX7xhN0288s ZC5Odpnpcua7LCgQ+6XnmECMsZY/L1U2tmHgnfqt8nazbgO+RfcwF/zBiUGZhnWuUmirJQWR5Yw qBZ971ddd2N3wigjiGxpOsJ5gsAN8FHue61JuFyFsOdFuoTLdgTGY206HKidaBi77Dj6xC0XS4m p+rmPLkkp3BRbo9yqOiIzIT5VCz8Ng5XyuMUtzpAiZfD2p18Toob5X8J03yridgnYhSnaHww6Re EHxA8riytmVhJhyYZoqlMi8HG/7msYAOjlmweIccK24GBICxhVTAqTkzDKrNrMBLZUhtXtkm11j Hpw+9vl6qNAZ+LA== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296246946158500 Eliminates the undefined behavior where virtio-gpu's memcpy() overwrites the buffer that an in-flight gvariant still references. Fixes the data race where the GDBus worker thread calls cursor_unref() concurrently with main thread. Fixes: 142ca628a733 ("ui: add a D-Bus display backend") Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260904123020.3108205-1-marcandre.lureau@redhat.com> --- ui/dbus-listener.c | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/ui/dbus-listener.c b/ui/dbus-listener.c index c1e86648384c..624d0fb71d6b 100644 --- a/ui/dbus-listener.c +++ b/ui/dbus-listener.c @@ -926,13 +926,11 @@ static void dbus_cursor_define(DisplayChangeListener = *dcl, =20 ddl_discard_cursor_messages(ddl); =20 - v_data =3D g_variant_new_from_data( - G_VARIANT_TYPE("ay"), + v_data =3D g_variant_new_fixed_array( + G_VARIANT_TYPE_BYTE, c->data, c->width * c->height * 4, - TRUE, - (GDestroyNotify)cursor_unref, - cursor_ref(c)); + 1); =20 qemu_dbus_display1_listener_call_cursor_define( ddl->proxy, --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296275; cv=none; d=zohomail.com; s=zohoarc; b=VdDOHNxL4jrp8e9biyze83/hv8MGFKBsFa0y/qsbvfaxgzv7KzGMtFL/Dd5nC0z2EvkPuhOoaNmjYirOZFw5tFRaw2wSDKjP3cEJ3238ijyqH8i3e7T3EFOGl0rNgC1Tf74HF1VIbcxUwFH8AF0af1Ixe/09MZrbwlDICgIYgUo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296275; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=sJkQCQIatVsaPiJOeebh4Zf8nzIyMHM83NavLHCqpq0=; b=gxOUbMlosuHxZl50ks4F8vgaObmK9XZTmTrkLp9VLnx2g2vdIKntVMhcWEHu9sD/5YLDjY2ww0szwWyV5U80MnGAS6EuhTNfF7ETM5qmpx3Brx7wARLIriJtWQpFViOufLLAwiB9U/fB17VEgVETkWUg9Flonlm+1r1RqFLyAnI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296275710681.8848979542022; Sun, 13 Sep 2026 03:44:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hfo-0005cW-J0; Sun, 13 Sep 2026 06:43:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hfn-0005cH-13 for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:42:59 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hfl-0008Aq-Jf for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:42:58 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-223--At99X9vMXOowE-0RaTg8Q-1; Sun, 13 Sep 2026 06:42:55 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 2D7C81802167 for ; Sun, 13 Sep 2026 10:42:54 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 6342530001A2 for ; Sun, 13 Sep 2026 10:42:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296176; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=sJkQCQIatVsaPiJOeebh4Zf8nzIyMHM83NavLHCqpq0=; b=MwjAcJQvyvWthG0R+EcHxIlvFao5BlJMMksCEfgRfULNIKsKkrOqkutvNaUBxR5NTFTwcg dopOYw1Zw8kw+oDO9MHpB2M9AMcNFvKZRkSoJii1tXKPWxAHBmdv2OBCdNtdtbp/yKoNn9 k1kBxG1zWqCkWuU/EfD0MkkEKhepFMw= X-MC-Unique: -At99X9vMXOowE-0RaTg8Q-1 X-Mimecast-MFC-AGG-ID: -At99X9vMXOowE-0RaTg8Q_1789296174 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:20 +0400 Subject: [GIT PULL 02/14] hw/display/qxl: hold ssd.lock while replacing ssd.cursor MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-2-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=2035; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=ebhqjU8jopkHN1A11WgEVxvOloJVZIhxPQ6IXf3q9pw=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4inmjjrrx58hISqgIw1pqNPtOxsdn9Jw/Nq J5J7HAgSGCJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IgAKCRDa6OEJdZac 5T2BD/9lOdG0eqJW9K0RmP7938KiY2LHcL2rdMeJ9IdN/m8Mi7yvnQzVNsXUElA5G0p4Mg34WLu CkmBK7DomySXQCIY2TUZsc7j+Of0UNcNrkQMH650qCouvET8ORPY5yV32j1Vn4a+DSz+NWDHyeF dloZ1GrkBOV4LitnFv5NmnUiQ05Xh8jdM7OpGjunkUtxg9ZS3FwhMKXOz1xtU3EkrLf4MahQ+fk XBVu7Cc1/QkVPNjEcYqbORfLsXmnoaIy+rlzh7CkL4ubUVcnzoM1FUBZxQmI5eSu31LGOOBMk92 U1/PWvkqzNEx+301Pz7KB7/wR1vUKtUY1Tkp1gBRdP9zbFtdfTfGsj1ZcKrj94+1JI4LOnmGTsp QEJuaIykETxwcRzzfY3JoUcnGSb8npQDf0AeyXaT8AZG7u4wFpAiMe+Vcbn/wiPtONOfLqb0Nrk IivilnMDUqtVjHHVofq0PVNqfEcR/ETUmFBhxoJuoXMcKOYpHJ7TNtlaOTu8Or02ENu+e2nnp2t dZvPCcj1Gk44YUjGwfP/xQj2G5vGdsRZQV3pHsLAYJoLTFrbKzrrFwanow51UW7I7O0t9PpdFbI /6UYZml4mK9F7T/bSy5c7tH7OsdmvxX7bxS3QNMtwTVr97QU2QWhm9bBmyx3w6PgihlynnGClkS j5imcZzr3+Oxj0g== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296277142158500 From: "Denis V. Lunev" qxl_spice_reset_cursor() unrefs qxl->ssd.cursor and installs the hidden cursor without holding qxl->ssd.lock. Every other writer of that field takes it: qxl_render_cursor(), display_mouse_define() and qemu_spice_cursor_refresh_bh(). The unlocked path runs on a vCPU thread, reached from ioport_write() on QXL_IO_DESTROY_PRIMARY and QXL_IO_DESTROY_PRIMARY_ASYNC, and holds only the BQL, which the SPICE display worker never takes. Unlike qxl_hard_reset(), it leaves that worker running. spice_qxl_reset_cursor() does round trip through the dispatcher, but the worker is free again as soon as it returns, so it can enter qxl_render_cursor() and unref the same QEMUCursor a few instructions later. Both threads then drop one reference for what is a single reference, freeing a cursor that another user still holds. The store to ssd.cursor races the same way, and a guest that keeps this up also ends up waiting forever in qxl_fence_wait(). A guest reaches this by switching QXL mode while it also updates the pointer shape. Fixes: 958c2bceba06 ("qxl: fix cursor reset") Cc: qemu-stable@nongnu.org Cc: Marc-Andr=C3=A9 Lureau Signed-off-by: Denis V. Lunev Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260903192647.2677279-2-den@openvz.org> --- hw/display/qxl.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/hw/display/qxl.c b/hw/display/qxl.c index 384b8767b8e6..c4f547e88bd5 100644 --- a/hw/display/qxl.c +++ b/hw/display/qxl.c @@ -294,10 +294,12 @@ void qxl_spice_reset_cursor(PCIQXLDevice *qxl) qemu_mutex_lock(&qxl->track_lock); qxl->guest_cursor =3D 0; qemu_mutex_unlock(&qxl->track_lock); + qemu_mutex_lock(&qxl->ssd.lock); if (qxl->ssd.cursor) { cursor_unref(qxl->ssd.cursor); } qxl->ssd.cursor =3D cursor_builtin_hidden(); + qemu_mutex_unlock(&qxl->ssd.lock); } =20 static uint32_t qxl_crc32(const uint8_t *p, unsigned len) --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296326; cv=none; d=zohomail.com; s=zohoarc; b=joIgANqB8grV3/IrVQMYHmqMaJeWFexd7GMe+rKOCRwgVcKB9sVKCX8phXcejpnykdPbkydpcEzDovnpsgjYSwJkPax+tcaaEkxa26YMmWDesJ0UfpGMst6ZTg8SiIWNp70Vi9tGsNeF18WuonJRxWySDy+4iZjUnWoHatkCpSs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296326; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=z93E6IXBNGFUNnjsorYP5n1hNGuSXYTnO5wPKuWfQeQ=; b=S5a8ZSxOWqdSy7FmeR0obxoWYkX2YXx6v940ZpZvU6ORUuj/W/9WTl0+pt/2R5IeZ5t8DqbPC0f2pYfhipLk14hhVsBT3lBDKSqoipBtvgQHzfOaXNCTMzbLFN5XPK4TFYq4Oey4cX35e8PUxcUfejyR4BOeC6i6m8GOnfJXVWE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296326542687.5019439340506; Sun, 13 Sep 2026 03:45:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hfr-0005cy-CJ; Sun, 13 Sep 2026 06:43:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hfq-0005cq-MV for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:02 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hfp-0008B9-2c for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:02 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-39-_THofeDjP9OTKN9Aqod12A-1; Sun, 13 Sep 2026 06:42:58 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 813521944DD2 for ; Sun, 13 Sep 2026 10:42:57 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 800221956088; Sun, 13 Sep 2026 10:42:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296180; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=z93E6IXBNGFUNnjsorYP5n1hNGuSXYTnO5wPKuWfQeQ=; b=XksNKpFuhSAlfBnXYrWKQldzpnrSsnaKpCFkT1Fv4F/gvQ4TF1rOTlUG7j6FahNO6Yc3i3 mN98a4WLG/D73blc2j6lgYw+lRDRIbVuvLFWAJcJMwNSlJkSXE07Eqp1NjBQPP7EVb8xGv IdWYI/Yt2sMWbdjX7LI4/1GaG0pFgrQ= X-MC-Unique: _THofeDjP9OTKN9Aqod12A-1 X-Mimecast-MFC-AGG-ID: _THofeDjP9OTKN9Aqod12A_1789296177 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:21 +0400 Subject: [GIT PULL 03/14] ui/cursor: make the cursor refcount atomic MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-3-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org Cc: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= X-Developer-Signature: v=1; a=openpgp-sha256; l=3607; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=SyVY5i1CXa5BvoxxYtEGH1+tIIfPubg1hJOzybxXK5Y=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4iVV8DB/1dvXrKNbDFtx0aaPU286QGZsvUI H3E6NoLqkOJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IgAKCRDa6OEJdZac 5fR6D/sEhbIlTZTMAWOXxTNYd+UIoJ4qBh1uas0lXvYI2yKwtvIvcBI9bU0tU3Mntp6LAMUIGya BREGuX19Tx4ApaAyWCYyuJrvXs3B+O6Fl8TLX6vWJAPp2kCFNt1K13Ph3QtxP+RMP21Zm77OsWe Gxgv5RUMQVEyGC3i4mpKvVhvf7OkFhnEjNSPjdbxXag3hAUB/1fP++bD4dOHR4hNOoWT3IXOlLw NeEmyi/KepoDxZb+98LOPpJkGswSizM3WRa1CxDCDTWcDRQ8AfZWdRwNeQe5neYrtFUHcqBA4Ek XScAlgaUN5w9r48AdfSVo3bkTvVkFEyDhNQ1NAFVtE0z5nXr6JL084EdzEqkfbVYvhNQ7HS1xX9 lYY+kjmIBiM1HxCLBmBqHqeDqWcCUoEw96gHyI+mTFd6DjSlSNQdpyjf/KcrWFkFDNCQD2H5Ezn 8krSs6T/FntW1cywLAe77CKq+oBwB1FUcwDdVwOkJRud9kiTdAKB3eLj/blgSkUYwo2kp9XhqLD UR8Dva5pc3GNeigkiSIQCPFNuJByTDir4k4tjBOwSe7jLAsaFYr9S1Hd2INCshl7MRYQVWbRVAq rm0pOVIyHgq8L2NnwYE6KErCTrHgtFgbjKw/lBisxGZPNSjIOBNmGmhzcd8FU7HOtHgFJMLvJOP YVa7QPyQDHgWrKw== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296329354158501 From: "Denis V. Lunev" A QEMUCursor outlives the call that publishes it and is shared between threads, but its refcount was a plain int with no single lock covering every user. qemu_console_set_cursor() takes and drops references from the main loop under the BQL alone, hw/display/qxl-render.c does so from the SPICE display worker thread, and ui/spice-display.c does so under SimpleSpiceDisplay::lock. ui/cocoa.m and ui/dbus-listener.c add two more threads. The pair that collides is qemu_spice_cursor_refresh_bh(), which drops ssd->lock before calling qemu_console_set_cursor(), and the worker refcounting the same cursor under that lock. A lost increment frees the cursor while the console still points at it, so the console's next unref decrements memory the allocator has already handed out again. Locking ssd.cursor is not enough on its own: with that done, this is the race that remains. Assert on the value the decrement observed while here. Dropping a reference that was never taken used to be silent, because the decrement lands in the allocator metadata of the freed chunk: nothing is logged, the object is not freed twice, and the process runs on until some later allocation walks the damaged free list and faults, arbitrarily far from the code that caused it. Fixes: 0b2824e5e48a ("spice: use bottom half instead of refresh timer for c= ursor updates") Cc: qemu-stable@nongnu.org Cc: Marc-Andr=C3=A9 Lureau Signed-off-by: Denis V. Lunev Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260903192647.2677279-3-den@openvz.org> --- include/ui/console.h | 9 +++++++++ ui/cursor.c | 17 +++++++++++------ 2 files changed, 20 insertions(+), 6 deletions(-) diff --git a/include/ui/console.h b/include/ui/console.h index 29bf72288833..3634956949ac 100644 --- a/include/ui/console.h +++ b/include/ui/console.h @@ -126,6 +126,15 @@ typedef struct QEMUCursor { } QEMUCursor; =20 QEMUCursor *cursor_alloc(uint16_t width, uint16_t height); + +/* + * A cursor may be shared between the main loop, a vCPU thread and a + * display backend's own thread, so the refcount is atomic and these two + * may be called from any of them. The object itself is not otherwise + * thread-safe: take a reference before publishing the pointer anywhere + * another thread can reach it, and never dereference a cursor you do + * not hold a reference to. + */ QEMUCursor *cursor_ref(QEMUCursor *c); void cursor_unref(QEMUCursor *c); QEMUCursor *cursor_builtin_hidden(void); diff --git a/ui/cursor.c b/ui/cursor.c index 6e23244fbe6b..69d27d49a135 100644 --- a/ui/cursor.c +++ b/ui/cursor.c @@ -1,4 +1,5 @@ #include "qemu/osdep.h" +#include "qemu/atomic.h" #include "ui/console.h" =20 #include "cursor_hidden.xpm" @@ -103,24 +104,28 @@ QEMUCursor *cursor_alloc(uint16_t width, uint16_t hei= ght) c =3D g_malloc0(sizeof(QEMUCursor) + datasize); c->width =3D width; c->height =3D height; - c->refcount =3D 1; + qatomic_set(&c->refcount, 1); return c; } =20 QEMUCursor *cursor_ref(QEMUCursor *c) { - c->refcount++; + qatomic_inc(&c->refcount); return c; } =20 void cursor_unref(QEMUCursor *c) { + int refcount; + if (c =3D=3D NULL) return; - c->refcount--; - if (c->refcount) - return; - g_free(c); + + refcount =3D qatomic_fetch_dec(&c->refcount); + assert(refcount > 0); + if (refcount =3D=3D 1) { + g_free(c); + } } =20 int cursor_get_mono_bpl(QEMUCursor *c) --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296345; cv=none; d=zohomail.com; s=zohoarc; b=FNwCgJc8Va9Fz8qi/Aqu/C7ArS6wPMwQcZCdMxmidi/9rrYF5oBwP8WBZWEzU2yQAxhHWU7Xy5onzQywq5u73ocY2qWpqul68cwf0V484R0YuGjsL16+CIFRdfcXJMwQXOZSmDFpd3yR34QAuPU5TlLZB8ThAqSiEf0P7j9bD/o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296345; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bcKSBi+jmRqE5htd8Se064SEu8m4A1/y0EMDWs4R1ko=; b=iesiy9Qbr2zelOi9dUPLkrM1dL2A1Xs8Nd28NA6VzpxeMn7F4jT7ze/r21RYSaiP56jTEVs9P5zwVV1sl+Qr1uAIn1a4Zr2wlsIymf8yOFscaGRkURH68hlE0tBOmbuJhFglmI/Dpb04qXE710sksV90Xdk4/X1caYlWJAGHnAY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178929634532438.75162867371114; Sun, 13 Sep 2026 03:45:45 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hfy-0005dd-2E; Sun, 13 Sep 2026 06:43:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hfw-0005dP-Mh for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:08 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hfv-0008BK-3h for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:08 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-231-8u5uq3iPPVaFSbwCVzVqxg-1; Sun, 13 Sep 2026 06:43:02 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id AA32A1944F2C; Sun, 13 Sep 2026 10:43:01 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 4F49241B; Sun, 13 Sep 2026 10:42:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296186; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=bcKSBi+jmRqE5htd8Se064SEu8m4A1/y0EMDWs4R1ko=; b=CqPCkwAkvR4XOMVJLf5Ynbj0wIItbtQQgIOZkaO1M30qUHyuE94GLEpvtsESXle6jAvJRW JOGk2zjYmHaq9OA7Xr+rSHBlyR1BxZRSS5It9Dqhitk2DHyPMavNpMJ1TFtd59BKFP7/pj 4S4NmyHhVOj/t0dZaGAq3HhEWy7hims= X-MC-Unique: 8u5uq3iPPVaFSbwCVzVqxg-1 X-Mimecast-MFC-AGG-ID: 8u5uq3iPPVaFSbwCVzVqxg_1789296181 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:22 +0400 Subject: [GIT PULL 04/14] docs/sphinx/dbus: register build dependency MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-4-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org Cc: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= , John Snow , Peter Maydell , Mauro Carvalho Chehab , Pierrick Bouvier X-Developer-Signature: v=1; a=openpgp-sha256; l=793; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=0LnpK7lfop2gthbFTJXP4k9HCAgVrxc3YmPiFW8QRHU=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4ixP/TGPSh4xOaLTSdz0+v36n0W1gdw4LSd b+wc3bPTYOJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IgAKCRDa6OEJdZac 5SUnD/9jW81onn460MM1Nh8sJ4RKVmZxZqgiIM3lOiQSbSDgN/XLfcgSjd57+cE5kPTQynQrFuO bposV9BLjkCjxtChEscQ0H4LgpXTs1Dzo03eIV2ScPM19iALY8BtWnTnQh7j8OVH/9l8U6iuRgd EndJPZMx3Z0UWiv6DhrFA+iCyZIQJ9DXz/tIt0/Lf7Pvpxr3dv9HejB3ciyKslprjqaDlcQL+8w daBzC1EK4SVcd8C4FEroAvw5RxeZ2H/ujr+ddsUyxnatDbcUpYb+VAwNDUf/PXKKaDI35R789sk pj6xxb6I4mJRvDjXJJONUi7R05oYHFIps0aUx8zt8QlqBvHQB6gm2z1/OAi/jJnFqnYcxvdxEzg TyylrtbJJ4drxptQjsicnBg2RhBNbId5G1Va8MnNvsHiUSJRIPEXUUZshZMpPzoDOVHDNK7v6Bi mZfTLcKgCwj7Mww8HyLeY1hKv0EPWAY7C8LyULqm+Sn/gGZ5dMbDLXo3mDzLIMv6pwXkoLqS+ym +3GEGA3UgRYpbPlZg6ycw2syGWtBU6yNUIVnulPy5LrJW8uQJfmUfbhvJStPKCoPVfwMJhal/pz tOPBQKKaGzq4+0AtUjzq0+uT0UcPY1W0OxdLD3qqHZoGydgzZe2JJUa2c3LcZU3+gMOyyGkrs8+ 4XQYwFzkTyCjjxA== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296347434158500 Touching dbus xml file wasn't enough to trigger a new build because the file wasn't registered to the dependency system. Signed-off-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Mauro Carvalho Chehab --- docs/sphinx/dbusdoc.py | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/sphinx/dbusdoc.py b/docs/sphinx/dbusdoc.py index be284ed08fd7..2b086e2f583c 100644 --- a/docs/sphinx/dbusdoc.py +++ b/docs/sphinx/dbusdoc.py @@ -146,6 +146,7 @@ def run(self): =20 env =3D self.state.document.settings.env dbusfile =3D env.config.qapidoc_srctree + "/" + self.arguments[0] + env.note_dependency(os.path.abspath(dbusfile)) with open(dbusfile, "rb") as f: xml_data =3D f.read() xml =3D parse_dbus_xml(xml_data) --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296301; cv=none; d=zohomail.com; s=zohoarc; b=BTtImNDWJiyrRcmQP2Y1rv7VJcA5VEqZbrthRSQ9I2fcEFp8L7rKb/BR41uV3ITBIcwSN8+vWTXEec7k18kmUEdL7WgWTei7G4HsbtoHM1+oOSQlxKipsF+GOaRJJ6uJIERC//LQvGnmKcuTyV3/pkouFEuYhjHM/4px0SGUeiw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296301; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=b1kQehvGGYRVKpVI9ygv1umIB6Insz/gldoaKQQkoJE=; b=la9Gtu8ho3c0lShccpFMYcCcuwleqGgDHdV6Vksa1CVNTcZPCL8aRHLMTmG+oGp290hd0qKwZMy0qaTlQaec+176HM4uojavQDkNMFvvQsjReW1Ov1LIqdSoeC7elr0QZZgBgGUyZ9KuiyQaQs/JpEqR/LYLdkeymFlXeqdk2Us= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296301827636.2426128506935; Sun, 13 Sep 2026 03:45:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hg1-0005eO-9Z; Sun, 13 Sep 2026 06:43:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hfy-0005dv-QL for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:11 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hfw-0008BO-MB for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:10 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-342-UXizevtlMH6ug2ImaAtR6g-1; Sun, 13 Sep 2026 06:43:06 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 34A0518011DB for ; Sun, 13 Sep 2026 10:43:05 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 49E121956087; Sun, 13 Sep 2026 10:43:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296187; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=b1kQehvGGYRVKpVI9ygv1umIB6Insz/gldoaKQQkoJE=; b=e0+okKjgRITRCHf2WrSUZlfVBk8c6E+Xd1TmB4D/GeM/zJVWdQquOI+5jkmFSHpB20iYMz apW1sWm9iPJu0htvmrI66l095TjZDNrJOAcIis8e17P96oVj3hrm34A70WCJKN6g6yq6q+ mQqd41IU52hMwjZEERwUk5wMDgQ31hU= X-MC-Unique: UXizevtlMH6ug2ImaAtR6g-1 X-Mimecast-MFC-AGG-ID: UXizevtlMH6ug2ImaAtR6g_1789296185 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:23 +0400 Subject: [GIT PULL 05/14] ui/dbus: add org.qemu.Display1.UIInfo interface MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-5-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org Cc: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= X-Developer-Signature: v=1; a=openpgp-sha256; l=9221; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=uuMIKhltp7NgwfazxaG9tM38Oiycmen/Gb8pKcNxxCs=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4is6ZvFHfnNcbA5UuP5M5o+M8W0VLhr8nTF hgWmPBcPD6JAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IgAKCRDa6OEJdZac 5TDSD/4h9yxLu8KdnmKbZz3IJJUwd4SYXwPBhV6alA3ZaAFqODg5YnmEt70n+Ya39K4bbwNN9pY HHx4Oh1s6Eqsk6ro6d+lTScVIdZfEfk3RHZqkIEt7RE8iDiJY5/C18aEbKLNQhsauIKZQUVy3i4 1KpUVvpSiH/MR68/e5Fqr0LLSRRbAqsYKi02ImmB/hUUXFxWBaue1VY/O34rZskr3gWL356dUoz KAWNWWFp4LYY+DZq/avKZ/ZYgqeeK8DjfvfCY+P5TzW+T42OYZ5c750zFAdJ92ps+v5qxxm/sFy tZ7X3g5hDb5GQqAttHlISTZwPaAhwJJodkVhyKHgl5Hamv2xjly5n5HvJ0uhpwz5YZjFu+87ojS 36JMRRJ9ARF5txn35wQJli1s5cqRy40RdS/Ey0TBlhrBlXbkWB+KziG7xolpVCegeRDofozYcxH uw7DkjoV0rB1Ex5URofsc/McoyoDVPraJ4DCvZJUWKhzrzMIVU8UxaTvUJ6rlHPdBiCzTiR+QcK rd97Y3A/siMl+eGmwEMahKy0l3TF6GDre5NDVLQ6Wsm9ZRV9O+Hkv/mc64sV74LEkdHQeBhFNrs QbxbFhIKwfG19BIxRX6cRuUvZV4nSqx3qgbb2t5276kN/pzVXf9FOG3G/DwC13VOYObzmsvBmEK aug+EVuWBL2gBPg== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296303276158500 From: Chengyang Zhu Currently, the SetUIInfo method cannot set a refresh rate. Simply adding a refresh_rate argument would break the method signature. This patch adds the UIInfo interface containing * property `Supported` indicating whether console UI info is supported. * the method `Apply` taking a dictionary as input. * the method `Get` returning the current UI info as a dictionary. Message-ID: <20260830054641.45437-2-colazcyg@gmail.com> Signed-off-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Chengyang Zhu --- ui/dbus-console.c | 106 +++++++++++++++++++++++++++++++++++++++++++++++= ++++ ui/dbus-display1.xml | 55 ++++++++++++++++++++++++++ 2 files changed, 161 insertions(+) diff --git a/ui/dbus-console.c b/ui/dbus-console.c index e1ac06814ba8..947c3b3a545e 100644 --- a/ui/dbus-console.c +++ b/ui/dbus-console.c @@ -55,6 +55,8 @@ struct _DBusDisplayConsole { guint last_x; guint last_y; Notifier mouse_mode_notifier; + + QemuDBusDisplay1UIInfo *iface_ui_info; }; =20 G_DEFINE_TYPE(DBusDisplayConsole, @@ -155,6 +157,7 @@ dbus_display_console_dispose(GObject *object) qemu_input_led_notifier_remove(&ddc->led_notifier); qemu_console_unregister_listener(&ddc->dcl); qemu_remove_mouse_mode_change_notifier(&ddc->mouse_mode_notifier); + g_clear_object(&ddc->iface_ui_info); g_clear_object(&ddc->iface_touch); g_clear_object(&ddc->iface_mouse); g_clear_object(&ddc->iface_kbd); @@ -528,6 +531,98 @@ dbus_mouse_mode_change(Notifier *notify, void *data) dbus_mouse_update_is_absolute(ddc); } =20 +static gboolean +dbus_ui_info_get(DBusDisplayConsole *ddc, + GDBusMethodInvocation *invocation) +{ + QemuUIInfo ui_info; + GVariantDict dict; + + if (!qemu_console_ui_info_supported(ddc->dcl.con)) { + g_dbus_method_invocation_return_error(invocation, + DBUS_DISPLAY_ERROR, + DBUS_DISPLAY_ERROR_UNSUPPORT= ED, + "UIInfo is not supported"); + return DBUS_METHOD_INVOCATION_HANDLED; + } + + ui_info =3D *qemu_console_get_ui_info(ddc->dcl.con); + g_variant_dict_init(&dict, NULL); + + g_variant_dict_insert(&dict, "width_mm", "q", ui_info.width_mm); + g_variant_dict_insert(&dict, "height_mm", "q", ui_info.height_mm); + g_variant_dict_insert(&dict, "xoff", "i", ui_info.xoff); + g_variant_dict_insert(&dict, "yoff", "i", ui_info.yoff); + g_variant_dict_insert(&dict, "width", "u", ui_info.width); + g_variant_dict_insert(&dict, "height", "u", ui_info.height); + g_variant_dict_insert(&dict, "refresh_rate", "u", ui_info.refresh_rate= ); + + qemu_dbus_display1_uiinfo_complete_get(ddc->iface_ui_info, invocation, + g_variant_dict_end(&dict)); + + return DBUS_METHOD_INVOCATION_HANDLED; +} + +static bool +dbus_ui_info_apply_lookup(GDBusMethodInvocation *invocation, + GVariantDict *dict, + const gchar *key, + const gchar *fmt_str, + void *res) +{ + if (g_variant_dict_contains(dict, key) && + !g_variant_dict_lookup(dict, key, fmt_str, res)) { + g_dbus_method_invocation_return_error(invocation, + DBUS_DISPLAY_ERROR, + DBUS_DISPLAY_ERROR_INVALID, + "%s must have D-Bus signatur= e %s", + key, fmt_str); + return false; + } + return true; +} + +static gboolean +dbus_ui_info_apply(DBusDisplayConsole *ddc, + GDBusMethodInvocation *invocation, + GVariant *arg_ui_info) +{ + QemuUIInfo ui_info; + g_auto(GVariantDict) dict =3D G_VARIANT_DICT_INIT(arg_ui_info); + + if (!qemu_console_ui_info_supported(ddc->dcl.con)) { + g_dbus_method_invocation_return_error(invocation, + DBUS_DISPLAY_ERROR, + DBUS_DISPLAY_ERROR_UNSUPPORT= ED, + "UIInfo is not supported"); + return DBUS_METHOD_INVOCATION_HANDLED; + } + + ui_info =3D *qemu_console_get_ui_info(ddc->dcl.con); + + if (!dbus_ui_info_apply_lookup(invocation, &dict, "width_mm", "q", + &ui_info.width_mm) || + !dbus_ui_info_apply_lookup(invocation, &dict, "height_mm", "q", + &ui_info.height_mm) || + !dbus_ui_info_apply_lookup(invocation, &dict, "xoff", "i", + &ui_info.xoff) || + !dbus_ui_info_apply_lookup(invocation, &dict, "yoff", "i", + &ui_info.yoff) || + !dbus_ui_info_apply_lookup(invocation, &dict, "width", "u", + &ui_info.width) || + !dbus_ui_info_apply_lookup(invocation, &dict, "height", "u", + &ui_info.height) || + !dbus_ui_info_apply_lookup(invocation, &dict, "refresh_rate", "u", + &ui_info.refresh_rate)) { + return DBUS_METHOD_INVOCATION_HANDLED; + } + + qemu_console_set_ui_info(ddc->dcl.con, &ui_info, false); + qemu_dbus_display1_uiinfo_complete_apply(ddc->iface_ui_info, invocatio= n); + + return DBUS_METHOD_INVOCATION_HANDLED; +} + int dbus_display_console_get_index(DBusDisplayConsole *ddc) { return qemu_console_get_index(ddc->dcl.con); @@ -550,6 +645,7 @@ dbus_display_console_new(DBusDisplay *display, QemuCons= ole *con) "org.qemu.Display1.Keyboard", "org.qemu.Display1.Mouse", "org.qemu.Display1.MultiTouch", + "org.qemu.Display1.UIInfo", NULL }; =20 @@ -626,5 +722,15 @@ dbus_display_console_new(DBusDisplay *display, QemuCon= sole *con) qemu_add_mouse_mode_change_notifier(&ddc->mouse_mode_notifier); dbus_mouse_update_is_absolute(ddc); =20 + ddc->iface_ui_info =3D qemu_dbus_display1_uiinfo_skeleton_new(); + qemu_dbus_display1_uiinfo_set_supported(ddc->iface_ui_info, + qemu_console_ui_info_supported(ddc->dcl.con)); + g_object_connect(ddc->iface_ui_info, + "swapped-signal::handle-get", dbus_ui_info_get, ddc, + "swapped-signal::handle-apply", dbus_ui_info_apply, ddc, + NULL); + g_dbus_object_skeleton_add_interface(G_DBUS_OBJECT_SKELETON(ddc), + G_DBUS_INTERFACE_SKELETON(ddc->iface_ui_info)); + return ddc; } diff --git a/ui/dbus-display1.xml b/ui/dbus-display1.xml index d96bae2ed642..a23ca0b8b125 100644 --- a/ui/dbus-display1.xml +++ b/ui/dbus-display1.xml @@ -90,6 +90,10 @@ @height: console height, in pixels. =20 Modify the dimensions and display settings. + + .. seealso:: + + :dbus:iface:`org.qemu.Display1.UIInfo` which supports a superse= t of these properties. --> @@ -1159,4 +1163,55 @@ --> + + + + + + + + + + + + + + + + --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296351; cv=none; d=zohomail.com; s=zohoarc; b=fsZl8u0aQ8AH01ULofLmXTRY/9M7qoYlwtkaWATHGDk9Bn6Yur4vL0P1MwtWgNTL6fh7WBqWHymVyVsiNDK/bwGDJBXDhgP7GvRfY3d4QpDcWaFigo7Pwi8y6gwRl180HUwxLJ/zIAwB2EgbPX6/0IcYnna2dU2ldx9KKLDxGP8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296351; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=Qo5UBUa5Wq7reICBsnDuVY/Ka3F5JtSwMy+sXWo0EP0=; b=QDdIzGGMJaWMZnZWAZ45YF2qf21p0BE4hsCTV5eLo3rErppDJhVnyZn3N2QEqXFUPq78TJhxGo7NvRkQpQSGFhVij8JoynDBof15TakngUFUPQS6Lse0zNCMiOl3CTYN/qgWYI+FRlqR+agpbaHkeCOzkMhIGuqtmVQvYoWQAn0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296351549583.7145144312673; Sun, 13 Sep 2026 03:45:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hg4-0005er-05; Sun, 13 Sep 2026 06:43:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hg2-0005eV-8F for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:14 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hg0-0008CO-3A for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:14 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-676-MUQ8jYzYN4u5VFy4byKGWQ-1; Sun, 13 Sep 2026 06:43:09 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id ABC401944F2C for ; Sun, 13 Sep 2026 10:43:08 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id E1191180034C for ; Sun, 13 Sep 2026 10:43:07 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296191; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Qo5UBUa5Wq7reICBsnDuVY/Ka3F5JtSwMy+sXWo0EP0=; b=LhPZ0rsL2kq3ftxi9xHmfCc30FM/veMWiDP2LPsDC6W9aTVk25XltkZkY9fmm8i82SqSf4 NdxmReoZY09gUf8ZuGg5s/69hl1yFPtdVwlD5+D6R0hlzJKMgNrcBh2enmUreK5E9+VIam qqWoiqPMgf9hr445kwFQGkT/yAfbNpU= X-MC-Unique: MUQ8jYzYN4u5VFy4byKGWQ-1 X-Mimecast-MFC-AGG-ID: MUQ8jYzYN4u5VFy4byKGWQ_1789296188 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:24 +0400 Subject: [GIT PULL 06/14] hw/display/qxl: factor out qxl_guest_phys2virt() MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-6-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=6743; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=6o0iPNSXLAZxa0vvrSViy75OeaV1i5OvNEudE6qCI98=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4iIta/bi8VxX5rPUgEV6T2T3zyZFoDItA2K GjDwC11ZtuJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IgAKCRDa6OEJdZac 5S35D/9eLFtRboCKLF3PcJTeZ4lgSXFmLjSY1YvFEIPmCNZjrNC3By7x/Ic+uK7kBpirwjRS2ZZ MpNtu2EXa/Hs8vnCNmuwLbWzUk6qpAWep4WViGX/pOCMz8l2MsyP4hkJUJM96ll/d0nqe2nlpli cXfyRwEdhc4ZhIBQAyN2K+QK1zwM2UuvvtluTAlHf6hw9uWNkp1aD/vfhC0UYqeAMGXgNLova0w 1JOnPqlQto33f90gdvJ4/1pwRYHyrhoTr05hfQTT2kGhCN2CucBi1P+/YimASWbHbCLtUllvUla +sVEgzyFWHZBeilVAIYwuJ4yZc5VzVraigUd+BTyeoxbagxuOOsXwZNVUMqwnx2dd30uCf1QMaV sj94850xyJMQ4WcfXvo6l3uobanYKyUifupTbg39oqJotznudo3Sz4VEXdJuVOs+5q3PjU8wbrB jQkGx9xPinMnyQ6T7CMejevo+Tk4Cc2s/UJsI3MMvxHXNuGbtNI1ysGDgczKfH6DvnA8Jkjgi7p BPxxVgw1g0x9TtZ2iquDgX8Cskf362FmXZ+3EBeLjGq4JtITQMiY3V8U/dZAv2KzjL76QJlAKhE b6GmWK/Lz3yUWaxxOaLXN2jiNVEW5E8wn2l0LebiBu3lJfPL49GTnyYlWI5CUqK+zBX1UB0v4AV aEertiBdL/yxo+A== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296353419158500 From: Andrey Drobyshev Split the GROUP_GUEST half of qxl_phys2virt() into the helper qxl_guest_phys2virt(). Also add a bool 'report_bug' param to the qxl_get_check_slot_offset() called from it: when it's false, a failing check just returns false without calling qxl_set_guest_bug(). All existing callers pass true, so there's no functional change. This is in preparation for a quiet caller that validates guest addresses which might be legitimately stale, when flagging a guest bug would be wrong. Message-ID: <20260825172051.435372-2-andrey.drobyshev@virtuozzo.com> Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Andrey Drobyshev --- hw/display/qxl.c | 83 ++++++++++++++++++++++++++++++++++------------------= ---- 1 file changed, 51 insertions(+), 32 deletions(-) diff --git a/hw/display/qxl.c b/hw/display/qxl.c index c4f547e88bd5..b6bc182fc2c3 100644 --- a/hw/display/qxl.c +++ b/hw/display/qxl.c @@ -1409,7 +1409,7 @@ static void qxl_reset_surfaces(PCIQXLDevice *d) /* can be also called from spice server thread context */ static bool qxl_get_check_slot_offset(PCIQXLDevice *qxl, QXLPHYSICAL pqxl, uint32_t *s, uint64_t *o, - size_t size_requested) + size_t size_requested, bool report_b= ug) { uint64_t phys =3D le64_to_cpu(pqxl); uint32_t slot =3D (phys >> (64 - 8)) & 0xff; @@ -1417,42 +1417,55 @@ static bool qxl_get_check_slot_offset(PCIQXLDevice = *qxl, QXLPHYSICAL pqxl, uint64_t size_available; =20 if (slot >=3D NUM_MEMSLOTS) { - qxl_set_guest_bug(qxl, "slot too large %d >=3D %d", slot, - NUM_MEMSLOTS); + if (report_bug) { + qxl_set_guest_bug(qxl, "slot too large %d >=3D %d", slot, + NUM_MEMSLOTS); + } return false; } if (!qxl->guest_slots[slot].active) { - qxl_set_guest_bug(qxl, "inactive slot %d\n", slot); + if (report_bug) { + qxl_set_guest_bug(qxl, "inactive slot %d\n", slot); + } return false; } if (offset < qxl->guest_slots[slot].delta) { - qxl_set_guest_bug(qxl, - "slot %d offset %"PRIu64" < delta %"PRIu64"\n", - slot, offset, qxl->guest_slots[slot].delta); + if (report_bug) { + qxl_set_guest_bug(qxl, + "slot %d offset %"PRIu64" < delta %"PRIu64"\= n", + slot, offset, qxl->guest_slots[slot].delta); + } return false; } offset -=3D qxl->guest_slots[slot].delta; if (offset > qxl->guest_slots[slot].size) { - qxl_set_guest_bug(qxl, - "slot %d offset %"PRIu64" > size %"PRIu64"\n", - slot, offset, qxl->guest_slots[slot].size); + if (report_bug) { + qxl_set_guest_bug(qxl, + "slot %d offset %"PRIu64" > size %"PRIu64"\n= ", + slot, offset, qxl->guest_slots[slot].size); + } return false; } size_available =3D memory_region_size(qxl->guest_slots[slot].mr); if (qxl->guest_slots[slot].offset + offset >=3D size_available) { - qxl_set_guest_bug(qxl, - "slot %d offset %"PRIu64" > region size %"PRIu64= "\n", - slot, qxl->guest_slots[slot].offset + offset, - size_available); + if (report_bug) { + qxl_set_guest_bug(qxl, + "slot %d offset %"PRIu64" > region size %"PR= Iu64 + "\n", slot, + qxl->guest_slots[slot].offset + offset, + size_available); + } return false; } size_available -=3D qxl->guest_slots[slot].offset + offset; if (size_requested > size_available) { - qxl_set_guest_bug(qxl, - "slot %d offset %"PRIu64" size %zu: " - "overrun by %"PRIu64" bytes\n", - slot, offset, size_requested, - size_requested - size_available); + if (report_bug) { + qxl_set_guest_bug(qxl, + "slot %d offset %"PRIu64" size %zu: " + "overrun by %"PRIu64" bytes\n", + slot, offset, size_requested, + size_requested - size_available); + } return false; } =20 @@ -1462,25 +1475,31 @@ static bool qxl_get_check_slot_offset(PCIQXLDevice = *qxl, QXLPHYSICAL pqxl, } =20 /* can be also called from spice server thread context */ -void *qxl_phys2virt(PCIQXLDevice *qxl, QXLPHYSICAL pqxl, int group_id, - size_t size) +static void *qxl_guest_phys2virt(PCIQXLDevice *qxl, QXLPHYSICAL pqxl, + size_t size, bool report_bug) { uint64_t offset; uint32_t slot; - void *ptr; + uint8_t *ptr; =20 + if (!qxl_get_check_slot_offset(qxl, pqxl, &slot, &offset, size, + report_bug)) { + return NULL; + } + ptr =3D memory_region_get_ram_ptr(qxl->guest_slots[slot].mr); + ptr +=3D qxl->guest_slots[slot].offset; + ptr +=3D offset; + return ptr; +} + +void *qxl_phys2virt(PCIQXLDevice *qxl, QXLPHYSICAL pqxl, int group_id, + size_t size) +{ switch (group_id) { case MEMSLOT_GROUP_HOST: - offset =3D le64_to_cpu(pqxl) & 0xffffffffffff; - return (void *)(intptr_t)offset; + return (void *)(intptr_t)(le64_to_cpu(pqxl) & 0xffffffffffff); case MEMSLOT_GROUP_GUEST: - if (!qxl_get_check_slot_offset(qxl, pqxl, &slot, &offset, size)) { - return NULL; - } - ptr =3D memory_region_get_ram_ptr(qxl->guest_slots[slot].mr); - ptr +=3D qxl->guest_slots[slot].offset; - ptr +=3D offset; - return ptr; + return qxl_guest_phys2virt(qxl, pqxl, size, true); } return NULL; } @@ -2003,7 +2022,7 @@ static void qxl_dirty_one_surface(PCIQXLDevice *qxl, = QXLPHYSICAL pqxl, bool rc; =20 size =3D (uint64_t)height * abs(stride); - rc =3D qxl_get_check_slot_offset(qxl, pqxl, &slot, &offset, size); + rc =3D qxl_get_check_slot_offset(qxl, pqxl, &slot, &offset, size, true= ); assert(rc =3D=3D true); trace_qxl_surfaces_dirty(qxl->id, offset, size); qxl_set_dirty(qxl->guest_slots[slot].mr, --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296262; cv=none; d=zohomail.com; s=zohoarc; b=PTBNCtNzOChdQXnWcQCeNWHjIgm2fL20eWt+z+TDuVzBW6JZnVpQ8lHgmzhurvwGtsBSQzGotx2p9w83xJehxN/qwaZi/QvDdrZEk+9eUoVuDIZVlsGbAArSJOw/DYCCHBPTYTyz0koWrWeE6CFB9+5/zAAjns/xDGaU/jWQFys= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296262; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=Ffn341LlTJcFicM5YT5PahGe5X1nuMJr/L7/6mA1AFA=; b=FHzT4707Cym3E5EYh94y0gm2GrQMX6de3IyyxhHxWCx81UbyONaAQmCk3nh5gAwikeeNmVMS4llfT9d3F+o9o8SnftblljnDQcllHVXvmMb7L9EDUKFPVE3hiT31WClVsiJ2VafSt+aZwLboNSE42FR6PyBEC8xD8MvEixOXUJY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296262572529.1722549579231; Sun, 13 Sep 2026 03:44:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hg5-0005f9-HA; Sun, 13 Sep 2026 06:43:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hg4-0005f1-6B for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:16 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hg2-0008DK-Ll for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:15 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-587-H-GH0wFGML-u5N6RMFGRTw-1; Sun, 13 Sep 2026 06:43:12 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B5EF718011F6 for ; Sun, 13 Sep 2026 10:43:11 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id EB8031956087 for ; Sun, 13 Sep 2026 10:43:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296194; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Ffn341LlTJcFicM5YT5PahGe5X1nuMJr/L7/6mA1AFA=; b=eZXEBDOneq/MCUOGHux8Carig9Jk9hejB+jLd7uSPyDQANSQNtqeuhzgIR6tPre10LfPSI cxhITklpHGAneB9HDw3gDziQIC5hyU9p2nlz7sW5k+PJUYLq9JahA0Uvdl9E9CDibXYRlA oHmzXG6y1HOzSRtzr9QiBHQgxgMcXX8= X-MC-Unique: H-GH0wFGML-u5N6RMFGRTw-1 X-Mimecast-MFC-AGG-ID: H-GH0wFGML-u5N6RMFGRTw_1789296191 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:25 +0400 Subject: [GIT PULL 07/14] hw/display/qxl: validate replayed commands in qxl_post_load MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-7-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=3425; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=s1f1LC/Q3DD/HRBujYP/N16KP0NEgC6UYpfjtotJyco=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4iKCVxTJSEQEhN26dmCk+5BH01dQu0lpb3L TqTmVMb/NaJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IgAKCRDa6OEJdZac 5ejZD/0cwbCKYlDLaU1wuJgjzeon2NATMNsf9Rr6JGrHXYoRAJdAxKXjN8GYT1NWUS/9XcQgCVQ PW5B8zh8dCJ78mgZ+FIt2w9p1ydh0Zu6D1h1yVGn8qBPWrlqr9c2JUFCPFnDlSeMLvc5PVXXqpi E69GZUPbTAFY2JDo+0yQYT//RM5JU0dYQeSypynvp/6PnNhn/XYU37LCMo6vgTEe1HcNkSAvq7F MDh3pemorXseaxrwO2tyztUKCAiCiRkdlj67baFhRD4c3nBLGv4OX1w0Ig+1dmtkkgHq+VVhcGK n9lNIculGUiLGbrfP4yU2HawnSyP5MQRMwrf9d9aFq3D/ssXtzAOPlYdNCJ01B/HCKEehjUsbi1 11EDNLCRMzqGIw6XsQcO8PUmHZgqUvAjS4TEu3EmeAzZ5KmAd1gZrK19eMJ8vES9+dHi9rJndYa 0UxglpCWS5zGBSVexhS9Jf46Xf+ZYApcMZjQdEkEuT8xo7W1YD32/op+6x50WCxvXFcSIYcVKq3 M4OqKPrTce9/6aA+xZ3tE04xVLgXGiG0npx7ZYkaKbARH4UWfEKbTcXIsapk3OowBqRKnnHL1Sk 8EUFVh0ugoH26aPe4NMcT0TsgAgfSMEErBYdMeZWGpvsK5Lq/IZ3yYdhtit4v7+i0grNrLlsNNr As48IBmbPJkw3qQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296263082158500 From: Andrey Drobyshev On incoming migration qxl_post_load() replays the tracked cursor and surface commands by handing their guest addresses straight to spice, without revalidating them. Those addresses were checked when the guest submitted them, but the guest may have freed or reused that memory before migration, so qxl's tracked pointer can be stale. spice-server then re-parses the command from that memory and, for a stale cursor, reads a garbage shape pointer -- aborting the target in memslot_get_virt() (again, spice-server function) and failing the migration. Validate each replayed command with qxl_guest_phys2virt(report_bug=3Dfalse) before adding it to the replay list, and for a cursor also validate the nested shape pointer. Commands that no longer resolve are skipped rather than replayed. report_bug is false so a stale pointer is not mistaken for a live guest error, which would needlessly disable a healthy guest's display. Message-ID: <20260825172051.435372-3-andrey.drobyshev@virtuozzo.com> Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Andrey Drobyshev --- hw/display/qxl.c | 38 +++++++++++++++++++++++++++++++++++++- 1 file changed, 37 insertions(+), 1 deletion(-) diff --git a/hw/display/qxl.c b/hw/display/qxl.c index b6bc182fc2c3..fb77f217b1c6 100644 --- a/hw/display/qxl.c +++ b/hw/display/qxl.c @@ -2390,6 +2390,37 @@ static void qxl_create_memslots(PCIQXLDevice *d) } } =20 +/* + * Validate a command tracked for loadvm replay before handing its guest + * address to spice-server. + */ +static bool qxl_loadvm_cmd_valid(PCIQXLDevice *d, QXLPHYSICAL data, + uint32_t type) +{ + switch (type) { + case QXL_CMD_SURFACE: + return qxl_guest_phys2virt(d, data, + sizeof(QXLSurfaceCmd), false) !=3D NULL; + + case QXL_CMD_CURSOR: { + QXLCursorCmd *cmd =3D qxl_guest_phys2virt(d, data, sizeof(QXLCurso= rCmd), + false); + + if (!cmd) { + return false; + } + if (le32_to_cpu(cmd->type) =3D=3D QXL_CURSOR_SET) { + return qxl_guest_phys2virt(d, le64_to_cpu(cmd->u.set.shape), + sizeof(QXLCursor), false) !=3D NULL; + } + return true; + } + + default: + g_assert_not_reached(); + } +} + static int qxl_post_load(void *opaque, int version) { PCIQXLDevice* d =3D opaque; @@ -2428,12 +2459,17 @@ static int qxl_post_load(void *opaque, int version) if (d->guest_surfaces.cmds[in] =3D=3D 0) { continue; } + if (!qxl_loadvm_cmd_valid(d, d->guest_surfaces.cmds[in], + QXL_CMD_SURFACE)) { + continue; + } cmds[out].cmd.data =3D d->guest_surfaces.cmds[in]; cmds[out].cmd.type =3D QXL_CMD_SURFACE; cmds[out].group_id =3D MEMSLOT_GROUP_GUEST; out++; } - if (d->guest_cursor) { + if (d->guest_cursor && + qxl_loadvm_cmd_valid(d, d->guest_cursor, QXL_CMD_CURSOR)) { cmds[out].cmd.data =3D d->guest_cursor; cmds[out].cmd.type =3D QXL_CMD_CURSOR; cmds[out].group_id =3D MEMSLOT_GROUP_GUEST; --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296216; cv=none; d=zohomail.com; s=zohoarc; b=d/Wg5zSlrDIWLxw86i+vxbA09ny1lcA4QEpLuXrGZXzEwj/atz5ByabrjRi5a353H4ptV8AxGM3AQ/UMciHZdraqwIHjsPNMfAk/oWHRML8Jk1ji0pmVhhvjoF/aDiDXGES7PG5CwIMG6mGhNhyU0tnH3f1eTEnxZexqwIhS8lo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296216; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=T7J7qfBqXlqHx3WOzneFvz6UOQQbOJ3xwxFjUEp/l0c=; b=NH7UIR21lrlWW5NQxxCxQN1NQiE7HEu0h5qIIEX7zkC6ogpCBT0r0fhv4tF2xNZlcXYBVqLVerh43IRxVEKu+QQYF5BG+Wh4ZR4vWQg4Yf+ayrR8+7cKTtvzMLlieFx6J8ruNSVguJKN48v6SJqnbjX/cs4kZPAWXjiOnx1Dadg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296216819475.10388929351905; Sun, 13 Sep 2026 03:43:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hg9-0005fi-OM; Sun, 13 Sep 2026 06:43:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hg8-0005fX-8s for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:20 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hg6-0008GZ-QP for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:20 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-226-v8ZE5lZpMDOedtXqo0Kpfw-1; Sun, 13 Sep 2026 06:43:16 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 4AB351802163 for ; Sun, 13 Sep 2026 10:43:15 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 8020F1956087 for ; Sun, 13 Sep 2026 10:43:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296198; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=T7J7qfBqXlqHx3WOzneFvz6UOQQbOJ3xwxFjUEp/l0c=; b=RXUFNqYqbHCBIA2UPMaMGGsxeJrJconD0Jyvch7zKsitpScZDh9AjBuQdTmResPg1TrdKU oXo+uUF+tNLGMV31JJxTXwxbCpadoEd8IJO9kC5SMH0Yb+PPb8Yh2HyqFw8uKutID/t9q+ nPYX6za8lks4AwdXTA/qo9DytWaB3+Q= X-MC-Unique: v8ZE5lZpMDOedtXqo0Kpfw-1 X-Mimecast-MFC-AGG-ID: v8ZE5lZpMDOedtXqo0Kpfw_1789296195 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:26 +0400 Subject: [GIT PULL 08/14] hw/display/qxl: trace skipped stale loadvm commands MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-8-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=2982; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=HbbMPGUZlXjzI38UEv8FHA4H8pYuzPQ5mOVIV6ZMolA=; b=owEBbAKT/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4i0i/Fig/pzfRyFwfZoI2QXnX8WYtjnBj1j 7n4O/+vJ5iJAjIEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IgAKCRDa6OEJdZac 5ZAHD/de1n60uEz9z7Keo7a4Fflvzj7ZHWKUa7V0C1xDMrcCquK13Twclal4e+ZluQJuz7t2L/B lkdo0TRP4D4zzSICPIg8h/N17PV/JKXsnE2GtDIGC8bHtcFdpTIxQHzTeJ8IO+u+dMQrHJTBuD6 znV4stU9qXbJFhQjSVybkJgKJ8FR54TqQ9p6ztfk9pi3l7879H5FJyU1hDjoCe1S0O7xsfDKlfK X7PNfqHDH2QvGMZxfoItVUHICxBswVkdH5zfYQGBYDJ74RKpEU51FY8MepCGE3LBK01Sj7w8Ype XrBJK2Pv1sQ2jjZPtZb0ADqerRmK9xYFYDX3aqvKCNGWBEnKebjKu5a05FbhLox5/QRqO4Qaev+ DXoRV9V1uyP/GKvdO4te6zEw/DmrCJfafYLYqq5dgnS4TEmHnwtd450gI+cUFoSr48Q1UsYNVBN kYYqFfiwi0bLBmPsAU5cDgezYAy6/FpbmnecGvszrVXUJ217lcm75zc28BlkUMqIbUupkPVxBd1 0AG5bCpEBhUztlE8NhgIDcLtUwHe9ltwj11SMyr6Z7v7hoFFHtvjA0rQq8ezWTZZjoXX4Cvcmdm wIY73SJjoWi2UtYJdd0IgfeXGZMQJeAL6CniBsHKqbyQuUeM8/8ElEyWCPOe45+xscpxS3lDgN1 kAR9tIIviarDx X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296219608158500 From: Andrey Drobyshev Emit a trace event when qxl_post_load() drops a cursor or surface command whose guest address no longer resolves, so a migration that lands on a stale tracked pointer is visible instead of silent. Message-ID: <20260825172051.435372-4-andrey.drobyshev@virtuozzo.com> Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Andrey Drobyshev --- hw/display/qxl.c | 17 +++++++++++------ hw/display/trace-events | 1 + 2 files changed, 12 insertions(+), 6 deletions(-) diff --git a/hw/display/qxl.c b/hw/display/qxl.c index fb77f217b1c6..d5f9771f5af2 100644 --- a/hw/display/qxl.c +++ b/hw/display/qxl.c @@ -2461,6 +2461,8 @@ static int qxl_post_load(void *opaque, int version) } if (!qxl_loadvm_cmd_valid(d, d->guest_surfaces.cmds[in], QXL_CMD_SURFACE)) { + trace_qxl_post_load_stale_cmd(d->id, "surface", + d->guest_surfaces.cmds[in]); continue; } cmds[out].cmd.data =3D d->guest_surfaces.cmds[in]; @@ -2468,12 +2470,15 @@ static int qxl_post_load(void *opaque, int version) cmds[out].group_id =3D MEMSLOT_GROUP_GUEST; out++; } - if (d->guest_cursor && - qxl_loadvm_cmd_valid(d, d->guest_cursor, QXL_CMD_CURSOR)) { - cmds[out].cmd.data =3D d->guest_cursor; - cmds[out].cmd.type =3D QXL_CMD_CURSOR; - cmds[out].group_id =3D MEMSLOT_GROUP_GUEST; - out++; + if (d->guest_cursor) { + if (qxl_loadvm_cmd_valid(d, d->guest_cursor, QXL_CMD_CURSOR)) { + cmds[out].cmd.data =3D d->guest_cursor; + cmds[out].cmd.type =3D QXL_CMD_CURSOR; + cmds[out].group_id =3D MEMSLOT_GROUP_GUEST; + out++; + } else { + trace_qxl_post_load_stale_cmd(d->id, "cursor", d->guest_cu= rsor); + } } qxl_spice_loadvm_commands(d, cmds, out); g_free(cmds); diff --git a/hw/display/trace-events b/hw/display/trace-events index 4bfc457fbac1..c5e7e42af23b 100644 --- a/hw/display/trace-events +++ b/hw/display/trace-events @@ -82,6 +82,7 @@ qxl_io_unexpected_vga_mode(int qid, uint64_t addr, uint64= _t val, const char *des qxl_io_write(int qid, const char *mode, uint64_t addr, const char *aname, = uint64_t val, unsigned size, int async) "%d %s addr=3D%"PRIu64 " (%s) val= =3D%"PRIu64" size=3D%u async=3D%d" qxl_memslot_add_guest(int qid, uint32_t slot_id, uint64_t guest_start, uin= t64_t guest_end) "%d %u: guest phys 0x%"PRIx64 " - 0x%" PRIx64 qxl_post_load(int qid, const char *mode) "%d %s" +qxl_post_load_stale_cmd(int qid, const char *kind, uint64_t data) "%d skip= stale %s cmd 0x%"PRIx64 qxl_pre_load(int qid) "%d" qxl_pre_save(int qid) "%d" qxl_reset_surfaces(int qid) "%d" --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296294; cv=none; d=zohomail.com; s=zohoarc; b=IGZIK3H0/JJhK6ZbQnFyqfiOIYwjx+Of9yisngrQTwrXlaN62HrJG8ltRMAuwbKuI+L0byCGlCg2T/YEfXT+IqgHgPJIhCh4NVqwpETKnTqJEBzJupdBk8Llt6R4iiQGT3yUMKN+7whNKRlUBPBfAK7du7mjx5FRT0j5IXVfBXU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296294; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=mplfvlplDsIbQ8CMTjUFhZCHSDsPoCfX4+C9HdFifGo=; b=LVPledb4WsHdtOevrEzCY6vifiyRe6SBh4XjGI7g1UF1ZeAws9xSg4Bd7RAfmRnJM7iselqkns4XXdxIw7E5+qRhcb4vQgwX9hrv0slYRJKKZKJclZHe9Zk4MXW4anciszaG4jZ+qowzG/9OflSAuclfszJha68zSmurwrJik58= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17892962944931009.3428044541939; Sun, 13 Sep 2026 03:44:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hgE-0005gR-0g; Sun, 13 Sep 2026 06:43:26 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hgB-0005fy-HA for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:23 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hg9-0008Gp-Ul for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:23 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-543-j1njv5XfM06zOWd5yR8loQ-1; Sun, 13 Sep 2026 06:43:19 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id ACF7B180216A for ; Sun, 13 Sep 2026 10:43:18 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id B609019560AB; Sun, 13 Sep 2026 10:43:17 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296201; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=mplfvlplDsIbQ8CMTjUFhZCHSDsPoCfX4+C9HdFifGo=; b=QHMPb9SQ9t/9qxitVJMrluOFeuS4VUOKeY43xquCFKNkFOYOm+YUs56BN9qX+/2y9xqRlN kraAM47nqsQ7NRxZni6f/5Ifz4xMJlXDMIzqTdAT8AXDA8d6/pvEiH7qegDXFSsDU2+r7L uDf436UXgnhsV+nxLWa0YBBhMbZsVHI= X-MC-Unique: j1njv5XfM06zOWd5yR8loQ-1 X-Mimecast-MFC-AGG-ID: j1njv5XfM06zOWd5yR8loQ_1789296198 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:27 +0400 Subject: [GIT PULL 09/14] ui/gtk: Remove glFlush() after eglSwapBuffers() MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-9-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org Cc: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= X-Developer-Signature: v=1; a=openpgp-sha256; l=1005; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=DnWtgdAB0TNC1em2ijioKVEwDSkKLW8GRb8IIzQ74vo=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4irjd7NS9zKmxhoRC+k2kU22uNAPq3ggVZd /jsAR7R/MWJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IgAKCRDa6OEJdZac 5SdzEACAUk0S44pLL/q/yeqY1vxqrqqIgl+6PCTDXZceXGycNRRPikTRCpgKpudPoJe+orXLD9q +1Um1wT6+WvuOUpnFpqOL64CaWjtbnxUS1CdrEpGERsEpRbLZ5Q2fMjjAJFsiG9lJBfJUmbH6fF 9gGIjYhWJzFYXupT+7WnkCp87+z/W0GchD0i64aWBd6W3q+l7jEo82j2WXT1T4fAvGZ4KDEXiKZ x4kyLi5xHHzmT98L+eqbLAH3jTN5DQdO/EHpXRJYxV4SRSuFC3ykzUEUxpzJ9LpHGrGGJAy3WMc MUy0epkh9wjjrMzmUm8cLGUJPpKHatK+u22vYe8Y9xSN4DX0gN1aJXmBMJtElT2MagKdvvdfJUo jQb2EYoCuKwp6w+ZgTa7+wBCsI+4y0rap71oaUCk3lNsecMFb+YGnzxQiHc1grtmYkr2ZeJYbfa 2mVBC8oN8d8KXv+2FmYuKkvnIDCq/q3EXVKd9Ji0CjaO35RIHPo3MuiUwdYGk2a16orr81LFCGO d/I2bGErwJVmeJZe9bCvPjkKeZccZ7iBnsxrpYrJEk310RXXvh3wjdVCXuPKqzWKpGP7wIct64E NYlc7crb/IU6MEW7hES6fxf6y+ezVBmcb6ERug8ZbjtttH3BG6GRgksp2IifcnmIXf84ypYMiAV 1iMBkiuHq62npjw== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296295165158500 From: Akihiko Odaki It is redundant since eglSwapBuffers() implicitly performs glFlush(). Message-ID: <20260913-flush-v1-1-229efa3f1e53@rsg.ci.i.u-tokyo.ac.jp> Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Akihiko Odaki --- ui/gtk-egl.c | 3 --- 1 file changed, 3 deletions(-) diff --git a/ui/gtk-egl.c b/ui/gtk-egl.c index d595916476d9..0eec06826bdd 100644 --- a/ui/gtk-egl.c +++ b/ui/gtk-egl.c @@ -104,7 +104,6 @@ void gd_egl_draw(VirtualConsole *vc) surface_width(vc->gfx.ds), surface_height(vc->gfx.ds)); =20 - glFlush(); #ifdef CONFIG_GBM if (dmabuf) { gd_gl_wait_sync(vc, sync); @@ -122,8 +121,6 @@ void gd_egl_draw(VirtualConsole *vc) gd_update_scale(vc, ww, wh, surface_width(vc->gfx.ds), surface_height(vc->gfx.ds)); - - glFlush(); } } =20 --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296283; cv=none; d=zohomail.com; s=zohoarc; b=f+AXKSm//3Ik2H3paL8FTftNQoccEaaIgv2pmoo/yk9se2RtPih1d2nN8D7A5BDLT7LrVExk1sQXkIx1Z0EJyOYa2UQrjsYT83omOyCzMDhPTF3wBIijX+9g0d6oEXDNfC9f6y7MKayQtULYrwnfsjtn/YFEZ3DeI5n+g9yn7Gk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296283; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=X2w/82IAJNSu6luYuSTo2QbhSwZBWj4t6EkrQbFgAcI=; b=GONmUcO/OZjAcanwuWBiHS+jOUyxkneZF4NS1LAWjZy3rS/Q4+UshW6M6t0K4rHHC7xFB1WvUbZWxUcap/fPzqFopLOHduAD1yas01sRLDnDw+0MZ6FNQCX5RiG+E7FmlrwEJnZPcytk3XosCNgM2sh8NvziTkvrEhGZmLe8lmg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296283563872.1528640395871; Sun, 13 Sep 2026 03:44:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hgG-0005gn-5i; Sun, 13 Sep 2026 06:43:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hgE-0005gU-Li for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:26 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hgD-0008HU-5y for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:26 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-416-ujfk3N96NUiGGvYgwqn6YA-1; Sun, 13 Sep 2026 06:43:23 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 3E6EA18011ED for ; Sun, 13 Sep 2026 10:43:22 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 73C3A19560AB; Sun, 13 Sep 2026 10:43:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296204; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=X2w/82IAJNSu6luYuSTo2QbhSwZBWj4t6EkrQbFgAcI=; b=M1KFDr9qLlWyls4dDNv3A+tg6k0WRVs4OYeT5ibUsXDvtc4AWzrUVK9h6qXF1HFL1OKZ5i hHwiUaYBo6zOOn01A25Ln9IltbE1LQe20bSByc7eBNVf0Re0gxQ3FWcDNnD61XM3eBR/VF Emgybh0pgW5rcrbGDBhyvv3wEEXmLeo= X-MC-Unique: ujfk3N96NUiGGvYgwqn6YA-1 X-Mimecast-MFC-AGG-ID: ujfk3N96NUiGGvYgwqn6YA_1789296202 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:28 +0400 Subject: [GIT PULL 10/14] ui/gtk: Work around the gtk-menu-bar-accel leak MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-10-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org Cc: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= X-Developer-Signature: v=1; a=openpgp-sha256; l=1130; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=QSGYLAEuOVNKuO/0oYNvTJK7sT8eRkII3yvwZCdQ8MM=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4j5ziMO7eIsJPS7cgmHK+47Vux5cRw5T+ON dzsUeKoiCGJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IwAKCRDa6OEJdZac 5cavD/4h560UzyKhXtXp9swQ5o56L1gv7AzD67anajIoOJh9pHCvaPlzPLUXv8ME+A9loJhEvI7 wyyvJOfIcjWkJZm3aVeSJODXRL0CbL0lk+q4Xwe4xWrcbr0x0MFUAGoY0z9uo3xPIhJGA7NfycU FPHKJaias/l24SpiZ+0mQ12DEScCsrasZcB815mUbIfpPXDFb35RIARVhXBYTKLJBi2rV3qlUPK 4jc5355/sLX1VFxRDO55v7zcN31KX+02rtAYK7xHogbnRycIIUZBShFa4nPGPjiyxB4qoiJsl5S R2Rq5OCHbGhtBbDHvESN2VAKFFBnWRgDsI0rfbb9D1wfVlHQOUw5m4tv14NwITAJLWSpgXENhC6 trXxew9vg8StovddkdXHLFrTLyzt1Cfi3HrQbmXVSFgqphfuucRPcS11cnTM2CkbWEDaKyXStGP xrVFO6HRTO3xtm/+yLXLgpWdFdakxLMt4QPlPRIH4meia7ux/WsVTAeDAm9ytaPoPsR3XQWu4oX bMFm5mOyrcrW30/IzywSqPK8mG5JpZ6uW6gXP15N/MLhY3iS4pwjXvjdtbhWENHjnskglm4xo9P x2bgkqdeJFSDbmSly2d9Y4uuXWeEHNAkumBio3bwUju/+Z8py/yGtiKvcyl2ssjlwKhhGfkvRfy Ws/i+1ZnyBaFTzw== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296287341158500 From: Akihiko Odaki The implementation of the gtk-menu-bar-accel property had a bug that leaks memory when the set value is an empty string, which was fixed with: https://gitlab.gnome.org/GNOME/gtk/-/commit/44bf10c4a2a0463891884a105fa27cf= 36b73f119 To work around the issue for old GTK versions, replace the empty string with NULL, which has the same meaning for the property. Message-ID: <20260913-gtk-v1-1-3e4ac542e054@rsg.ci.i.u-tokyo.ac.jp> Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Akihiko Odaki --- ui/gtk.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ui/gtk.c b/ui/gtk.c index c615d35451b6..ae28f1fbb89b 100644 --- a/ui/gtk.c +++ b/ui/gtk.c @@ -2645,7 +2645,7 @@ static void gd_create_menus(GtkDisplayState *s, Displ= ayOptions *opts) =20 /* Disable the default "F10" menu shortcut. */ settings =3D gtk_widget_get_settings(s->window); - g_object_set(G_OBJECT(settings), "gtk-menu-bar-accel", "", NULL); + g_object_set(G_OBJECT(settings), "gtk-menu-bar-accel", NULL, NULL); } =20 =20 --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296266; cv=none; d=zohomail.com; s=zohoarc; b=XCNeRx6SxiuNVj3Fvad2P2CYSKcVyvWPQ/+bUYR3isp/pk+82WsDaN84qFSWzQiKT30Bg2Ia0iaLNTMVoezLMOjpqneKwZeDFp98KIrra0hxmQ3N0ilx8GV8OPk1mbIEEfahGmuhLblNflakFs5R4fBqu7MT5DXomCikenq6MN4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296266; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=7vqTlefAxjAaewqSyIMELLJSZMDNGtwP6wkFMJUuz3E=; b=NZ/S9VWWJ5iVDwSpU0+uNe0kEC+Er/keSA+E5NiQyWtHxV2Pm8i4oE+RZiq7YbbhXNmahKs2vTkvO8xh3whUtxm0Hv83NN8vJ0BwoEOUYDAD/aNgHf1/0KxvA+dPLZkhyuCYk4z6rjFADZA9pimb+1vNF5VjMK+e/BY9F58n6xE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296266260189.51772952482872; Sun, 13 Sep 2026 03:44:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hgK-0005he-1t; Sun, 13 Sep 2026 06:43:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hgI-0005hM-HQ for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:30 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hgH-0008Hi-0H for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:30 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-588-Lk8Iqx59NbSPlufZ5Lsg0w-1; Sun, 13 Sep 2026 06:43:26 -0400 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id F0B351802154 for ; Sun, 13 Sep 2026 10:43:25 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id C428918004D4; Sun, 13 Sep 2026 10:43:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296208; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=7vqTlefAxjAaewqSyIMELLJSZMDNGtwP6wkFMJUuz3E=; b=AkPdNbQMCJ0PBOqszndZDjBH959UmU17WHmj9A4o69YQc0DiH9kV05xU1+qH5p4vVs/Cha oKC4AWMiI0qXzPTSpe2n74QMfZFxtPWz7e73xrHDHuZ3RWMg39nqhD8O3BInM9Wjk+Xgkw /CwggtDimy2YDdIFqQxuNGa104dmoO4= X-MC-Unique: Lk8Iqx59NbSPlufZ5Lsg0w-1 X-Mimecast-MFC-AGG-ID: Lk8Iqx59NbSPlufZ5Lsg0w_1789296206 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:29 +0400 Subject: [GIT PULL 11/14] vhost-user-gpu: validate command buffer size in submit_3d MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-11-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org Cc: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= , "Michael S. Tsirkin" , Stefano Garzarella X-Developer-Signature: v=1; a=openpgp-sha256; l=2181; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=eCgsOIk/89OdUDCfj2vNyKj3/4yi2096UmPlVIK4C9s=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4jcwPihWQbwOaegZcvigN2fMFN3habKWKdk YGPmOKM1FeJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IwAKCRDa6OEJdZac 5WAcD/457qIj9a7qfSyYRHpk679LtcZL9DVFVJQ+ofkFNA7MUujv/n8kA5zigi1j5hSflvS9Kry 9ULaXhS5ekkOgzOcrX+H7Rn7qVi7dUkjNXZXA2RdiNMSq0qMWo6C/PmCiS+vRJT4mNTLaWv1jLH 1/loYKpdqDHa778calIAus2/ozrxoPlG0JJDT9mUR3Sph73fgPqfy+MHtneSLEeNZt7zrSTd+on JgWMthiyUza14PxrknkGG7KZ3tw8nUNmaJZivZNyt2C1oOvlaW5exsfonG1m7y3EST8BwY6T2Ts Ew21hvsAIQXvR06AcpftkjPFI8rrU9Y0oLFAuL93z/oXeifQGZzEh3wzbTYaJ+sSrVTTgGFHJiY PJz6cYxhOYRW10MwHVW+IcOKURKwBI4tQyH5NnoP0IwFZ7iYbybIYiHBRPTnl+mCnJnBy2upyny AS/y0IEEapXvXuas5V+EGR+VhPS1zrZB89Z05UVIjjN3zeXCCnnfwyRh/C1uBXbRRmI5c4bWklY 7uQd6XR2VjImu2IOQjRV3ckbcOqLv/5+NTcNRnjh1FclTeVJ9+QpDKUXOVfWryLiFPHBJ5PfNTC afN/QoteXtpxmzjpbden8Geb2UvRhKo+Ac/jdZp8iNemmyyTbG2ndYJUZ4zXAh7Z8CvN7YBn5zO +1EjVBw4Eh/0Zhw== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296267051158500 virgl_cmd_submit_3d() passes the guest-controlled cs.size directly to g_malloc() without any bounds check. A malicious guest can set this field to an arbitrarily large value (up to 4GB), causing an OOM abort that crashes the vhost-user-gpu daemon. Validate cs.size against the actual descriptor payload size before allocating, rejecting values that exceed what the virtqueue entry can carry. Fixes: d52c454aadc ("contrib: add vhost-user-gpu") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3776 Reported-by: admin@fluentlogic.org Signed-off-by: Marc-Andr=C3=A9 Lureau Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-ID: <20260713125431.107278-1-marcandre.lureau@redhat.com> Message-ID: <67f10fb88d3c75da3ba7fa5a37f7d6bcfcf3ce9e.1789071042.git.mst@re= dhat.com> --- contrib/vhost-user-gpu/virgl.c | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/contrib/vhost-user-gpu/virgl.c b/contrib/vhost-user-gpu/virgl.c index 5a5f9f14c80c..0ef4b9d8c903 100644 --- a/contrib/vhost-user-gpu/virgl.c +++ b/contrib/vhost-user-gpu/virgl.c @@ -209,20 +209,24 @@ virgl_cmd_submit_3d(VuGpu *g, struct virtio_gpu_ctrl_command *cmd) { struct virtio_gpu_cmd_submit cs; + size_t iov_len; void *buf; size_t s; =20 VUGPU_FILL_CMD(cs); =20 - if (cs.size > VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE) { - g_critical("%s: command buffer too large (%u)", - __func__, cs.size); + iov_len =3D iov_size(cmd->elem.out_sg, cmd->elem.out_num); + if (cs.size =3D=3D 0 || iov_len < sizeof(cs) || + cs.size > iov_len - sizeof(cs) || + cs.size > VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE) { + g_critical("%s: size out of range (%u/%zu)", + __func__, cs.size, iov_len); cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; return; } =20 buf =3D g_try_malloc(cs.size); - if (!buf && cs.size) { + if (!buf) { cmd->error =3D VIRTIO_GPU_RESP_ERR_OUT_OF_MEMORY; return; } --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296227; cv=none; d=zohomail.com; s=zohoarc; b=BnW7E4VZvf5siuXA0srONVvtN5Vz/pwUOs4QaFKSSr5/czPlp79ODAgEEST1IJWNovHjYcExAJlCj+nowfXunTYgl6qFCMHr/60chRwKBNhNcIXZhhJGFCQqAYCQ1B+XOi2RjkcQieMlGVGZcRwxFYgNNFeDc6l7vS/eZzoV/Ec= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296227; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=D/MyPA+oqBcNz1p0kWs7kYIgcKYq/fY31KFsYZ6bLfE=; b=JU0DEUPbpmVr7jSWy3Vxp6XRq3eGPSFRir0tvlNyIXR8zcOROlOuP/zqsUu07bySBII2Gc65TQyKL3PuAe4/YKvlRTCjTkmIEgIyPTgf75FRM8AZWzFjC/yON05VWXZ/yYrauyRiZ00D8Jbyi/FxfCvVOxN1Z1ijLK4efBU/CSE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296227471343.48083564224044; Sun, 13 Sep 2026 03:43:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hgP-0005nd-IY; Sun, 13 Sep 2026 06:43:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hgO-0005lw-7e for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:36 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hgM-0008I2-Kq for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:35 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-625-gEduq3IhOn-B5CDhXVMaKw-1; Sun, 13 Sep 2026 06:43:31 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 0EF0D1964CE3; Sun, 13 Sep 2026 10:43:30 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D4B9430001A2; Sun, 13 Sep 2026 10:43:28 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296213; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=D/MyPA+oqBcNz1p0kWs7kYIgcKYq/fY31KFsYZ6bLfE=; b=WxmCJvGdu7Pg6xekH1y2KgO5Cu0mlX4EEBOpgTOeUI2xvMKY0aD1icHy89tHTLfkGkNgOm cgAKoqG3kaxlKgXO3CXtLDAMLKDxlq56gMad93Ney5z9/ci/0F4l/X9o7eUP7pRajSYxLW vQVuswgH03SGnuGxxOTp0gCxnOc5/cI= X-MC-Unique: gEduq3IhOn-B5CDhXVMaKw-1 X-Mimecast-MFC-AGG-ID: gEduq3IhOn-B5CDhXVMaKw_1789296210 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:30 +0400 Subject: [GIT PULL 12/14] virtio-gpu-virgl: guard new_blob with VIRGL_VERSION_MAJORS>=1 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-12-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org Cc: =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko , "Michael S. Tsirkin" X-Developer-Signature: v=1; a=openpgp-sha256; l=1481; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=qvP5Da7Pf/BfIlNBWy09+EyO9FeeA3aQsw3FezAkgXk=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4jTFwe5YX2L7kGQ1ktkPFmGP1wDBEiKQWwi b77hsT49LaJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IwAKCRDa6OEJdZac 5X1YD/90iSH9+HY1dHz6GBsuPiSgnb6wpBJwuCN/HDwui3Si1ta+gCWphXWlr9TS7HYGm14N80D Ie3a2rTAsaKWq8JDX9smjNt2ZxgvxX7LZ0y6coanApxTwQO7rmVktBa4+Zf/AWEWI/3y4TaPNuZ N1ivjxiauvW/lQhHtmZJbpdCTfj6Fg8zKJtn0M0kqF72yjeEnyDXn1RkPtK/5dISCaSaAf1QlFm E0ScI7H8+/7yp06mZvcnjDKZGE5JVltfFdWdnF/qEn3LSMGNsiMafy8/voj8xngrgjtgGFTIKwO Gx3OHz5TAJEPZM8nALTwGizvk68Np1pxueFFi9DigyC5sfl83HfIe+RSb0j0jdRZC7y5ABdvuVR KJ4NJf3vC+RHKdESwiUlI5aAk77EygMxcuOF57TCg7ImVKm9Kp0EzAV75wySO9ktQ1lIuXeCzs9 KKNkTAU2JXbavNAbA9mLR0WlSV5xYnW5sWkZ2ikRd+2tdDvkQf2gus+9EGITHdsdtu8rwv2vPkA JgSIeCIHIlry454F8CoBsKkDTrELRvA0Kv9MVg+0almHkzrRUnVo2nKHv6k1JhufHuBCeFW9crC kZfRVXYHMKgAdtxlY5DILG1LGulmVxZh/ohFo7Xb5GkYZfGNbnqHo04WTMBUsSh0P6rZZbnPyWu p9Rta5TZW3G7lMw== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296231420158500 virtio_gpu_virgl_resource_new_blob() is only called from virgl_cmd_resource_create_blob(), which is guarded by VIRGL_VERSION_MAJOR >=3D 1. Fixes: d814b44636d0 ("hw/display/virtio-gpu: introduce virtio_gpu_{simple,v= irgl}_resource_new()") Reviewed-by: Brian Cain Reviewed-by: Michael Tokarev Fixes: d814b44636d0 ("hw/display/virtio-gpu: introduce virtio_gpu_{simple,= virgl}_resource_new()") Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260911140645.56094-1-marcandre.lureau@redhat.com> --- hw/display/virtio-gpu-virgl.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/hw/display/virtio-gpu-virgl.c b/hw/display/virtio-gpu-virgl.c index 1c9380e2a6d2..f45571060fea 100644 --- a/hw/display/virtio-gpu-virgl.c +++ b/hw/display/virtio-gpu-virgl.c @@ -324,6 +324,7 @@ virtio_gpu_virgl_resource_new(uint32_t resource_id, uin= t32_t width, return res; } =20 +#if VIRGL_VERSION_MAJOR >=3D 1 static struct virtio_gpu_virgl_resource * virtio_gpu_virgl_resource_new_blob(uint32_t resource_id, uint64_t blob_siz= e) { @@ -335,6 +336,7 @@ virtio_gpu_virgl_resource_new_blob(uint32_t resource_id= , uint64_t blob_size) =20 return res; } +#endif =20 static void virgl_cmd_create_resource_2d(VirtIOGPU *g, struct virtio_gpu_ctrl_command *c= md) --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296240; cv=none; d=zohomail.com; s=zohoarc; b=ca/XTTcDTErlZlRUiY21r7eFHwMxFopKvRo/WZ1Qk82mGvkjllwpOmLSgJ7KaMOLjHdWcAZikC1YeR/7jVsvaQkE9By8V5DvQWlNu6Va7bvy8LaTcyjAspdscI4oHcvxhXAN8sa/I7RLREdnYqvUg/SjRM7COL3QHnaMRaSPFcQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296240; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=U5dCe2Luo46iFHPC9Z2GbpIJ3CpqnnchAWjtdO6rkMk=; b=IdSGfDYVOww7fArad0phUfbKQ4gkZQ8NQ6ITJBECC0z5wzxfkY/bcT/gIspF3PF93imhay6BrjzyIdbP3CxPChb2Nw8n3K4ftywYfLlPgwtAJiUkRttqy60vOytPzUMB1l8nXY0/s5SKDKQWFIBHHWy71E4DkiwGZgdArEDOEmI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296240457225.51092097293906; Sun, 13 Sep 2026 03:44:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hgS-0005pB-Sa; Sun, 13 Sep 2026 06:43:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hgQ-0005nx-Aa for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:38 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hgO-0008ID-JF for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:38 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-464-NqQF6D7yNMevsD80wWfOhQ-1; Sun, 13 Sep 2026 06:43:34 -0400 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 49B0D1954107 for ; Sun, 13 Sep 2026 10:43:33 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 6920C18004D4; Sun, 13 Sep 2026 10:43:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296215; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=U5dCe2Luo46iFHPC9Z2GbpIJ3CpqnnchAWjtdO6rkMk=; b=TwO6mUwvLZ8IFRzyFOUaBQ+Cc7nVndlcr2VoK87RBRupBxfnq08nYC/Y/pwTMNZehhyFGU Oh42JxJVRZhCVWvOFYk2t8DpS56KXZ48CVWatWiH5a5SYasQlNJCT8OxUyfScyVsvnvAgZ folsmTU0EEaceCjTZhurfEi8cxgLGO8= X-MC-Unique: NqQF6D7yNMevsD80wWfOhQ-1 X-Mimecast-MFC-AGG-ID: NqQF6D7yNMevsD80wWfOhQ_1789296213 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:31 +0400 Subject: [GIT PULL 13/14] ui/gtk: Handle empty notebook state in menu handlers MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-13-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org Cc: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= X-Developer-Signature: v=1; a=openpgp-sha256; l=6260; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=sLvAWFM1oOMDuI6batXscGLcxe2Yb8Nyq28bv/2gwa8=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4jH3an+T+ZfZmPff09Zvh0c5XriIhzhuDV6 eJF2EH77qyJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IwAKCRDa6OEJdZac 5R2CEACUk8sNvqXAg1e38ZcGtBNbHrg23S6vjgvxhyjpaZi/6VkHPmfFTbvFZ9bG7EH5VkyfBO3 FA03F7zldmfAJmFAIrmz1cD4vN2LQJmoJuY0u4Rfr9otrhnPqSXgL5TADd0rwDJ1pfjTo0Gl18v ks97mwosoaw0Hzk0jRVfR8GluYEghulm8CR93y7TFGPntCZQBX2jMgTVIpC8VPgS7/jZSdx9Jtx Wg31uiuweqnyKTunl3R6hbP2S9blWQvkLUlJL4GfFRxpHPq6fupGrNbnHtYc9rYdExH0i+DrcCh bNsvLKmEVlp1QgBQNj+ri9Zpe2zqhSk+gYS8LnXY8+Nc/n6EoR8fAtkmtd3n51V35JqXpa0pv92 A8ASdZ88oey8eRPVTKAd+6QlkkHOeiA98EsUjnCYgLxEk5ZN4Svpitp2thWWAWK+KuFxG4KNMbT LGkZIz0bKMsPd1574LViCUXZWmiOqMUVYIZ6Kct/oeS8ET3JoKjsxKBtwZRhatRsVPvXwgoRQ/P ld1ZQnampfTqW8+Lnp3Q9OL1mhkD/K2L0NUeWaQTrLC0YKtuWBTidpQKhKQzrVXgSGTMKW/S4V5 Ra/RiYh1w5+GdXineqq6b5mG8SO8Htav+QnwMl8yPXNgxPFuAWF3sF+ov8GZQmqjNIIonCniFAk IrIMDMwKZqRPPyA== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296243076158500 From: Dongwon Kim When all virtual console tabs are detached (untabified) from the main window, the notebook contains no active pages, causing gtk_notebook_get_current_page() to return -1. Because gtk_notebook_page_num() also returns -1 for any detached VC, gd_vc_find_by_page(s, -1) mistakenly matches the first detached console. As a result, gd_vc_find_current() incorrectly returns a detached VC instead of NULL. Menu actions executed on the empty main window then unintentionally operate on that detached VC. Fix this by having gd_vc_find_current() explicitly check for page < 0 and return NULL when the notebook has no active page. In addition, add NULL checks for the current VC across relevant UI menu callbacks so actions are properly bypassed or reset when no console tab is focused in the main window. Cc: Daniel P. Berrang=C3=A9 Cc: Marc-Andr=C3=A9 Lureau Signed-off-by: Dongwon Kim Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260729214456.3350-1-dongwon.kim@intel.com> --- ui/gtk.c | 56 ++++++++++++++++++++++++++++++++++++++++++++++++++------ 1 file changed, 50 insertions(+), 6 deletions(-) diff --git a/ui/gtk.c b/ui/gtk.c index ae28f1fbb89b..a194488a0cf3 100644 --- a/ui/gtk.c +++ b/ui/gtk.c @@ -184,6 +184,11 @@ static VirtualConsole *gd_vc_find_current(GtkDisplaySt= ate *s) gint page; =20 page =3D gtk_notebook_get_current_page(GTK_NOTEBOOK(s->notebook)); + + if (page < 0) { + return NULL; + } + return gd_vc_find_by_page(s, page); } =20 @@ -1469,7 +1474,10 @@ static void gd_menu_show_tabs(GtkMenuItem *item, voi= d *opaque) } else { gtk_notebook_set_show_tabs(GTK_NOTEBOOK(s->notebook), FALSE); } - gd_update_windowsize(vc); + + if (vc) { + gd_update_windowsize(vc); + } } =20 static int gd_vc_notebook_pos(GtkDisplayState *s, VirtualConsole *target) @@ -1542,6 +1550,10 @@ static void gd_menu_untabify(GtkMenuItem *item, void= *opaque) GtkDisplayState *s =3D opaque; VirtualConsole *vc =3D gd_vc_find_current(s); =20 + if (!vc) { + return; + } + if (vc->type =3D=3D GD_VC_GFX && qemu_console_is_graphic(vc->gfx.dcl.con)) { gtk_check_menu_item_set_active(GTK_CHECK_MENU_ITEM(s->grab_item), @@ -1595,7 +1607,10 @@ static void gd_menu_show_menubar(GtkMenuItem *item, = void *opaque) } else { gtk_widget_hide(s->menu_bar); } - gd_update_windowsize(vc); + + if (vc) { + gd_update_windowsize(vc); + } } =20 static void gd_accel_show_menubar(void *opaque) @@ -1612,7 +1627,7 @@ static void gd_menu_full_screen(GtkMenuItem *item, vo= id *opaque) if (!s->full_screen) { gtk_notebook_set_show_tabs(GTK_NOTEBOOK(s->notebook), FALSE); gtk_widget_hide(s->menu_bar); - if (vc->type =3D=3D GD_VC_GFX) { + if (vc && vc->type =3D=3D GD_VC_GFX) { gtk_widget_set_size_request(vc->gfx.drawing_area, -1, -1); } gtk_window_fullscreen(GTK_WINDOW(s->window)); @@ -1625,14 +1640,16 @@ static void gd_menu_full_screen(GtkMenuItem *item, = void *opaque) gtk_widget_show(s->menu_bar); } s->full_screen =3D FALSE; - if (vc->type =3D=3D GD_VC_GFX) { + if (vc && vc->type =3D=3D GD_VC_GFX) { vc->gfx.scale_x =3D vc->gfx.preferred_scale; vc->gfx.scale_y =3D vc->gfx.preferred_scale; gd_update_windowsize(vc); } } =20 - gd_update_cursor(vc); + if (vc) { + gd_update_cursor(vc); + } } =20 static void gd_accel_full_screen(void *opaque) @@ -1646,6 +1663,10 @@ static void gd_menu_zoom_in(GtkMenuItem *item, void = *opaque) GtkDisplayState *s =3D opaque; VirtualConsole *vc =3D gd_vc_find_current(s); =20 + if (!vc) { + return; + } + gtk_check_menu_item_set_active(GTK_CHECK_MENU_ITEM(s->zoom_fit_item), FALSE); =20 @@ -1666,6 +1687,10 @@ static void gd_menu_zoom_out(GtkMenuItem *item, void= *opaque) GtkDisplayState *s =3D opaque; VirtualConsole *vc =3D gd_vc_find_current(s); =20 + if (!vc) { + return; + } + gtk_check_menu_item_set_active(GTK_CHECK_MENU_ITEM(s->zoom_fit_item), FALSE); =20 @@ -1683,6 +1708,10 @@ static void gd_menu_zoom_fixed(GtkMenuItem *item, vo= id *opaque) GtkDisplayState *s =3D opaque; VirtualConsole *vc =3D gd_vc_find_current(s); =20 + if (!vc) { + return; + } + vc->gfx.scale_x =3D vc->gfx.preferred_scale; vc->gfx.scale_y =3D vc->gfx.preferred_scale; =20 @@ -1694,6 +1723,10 @@ static void gd_menu_zoom_fit(GtkMenuItem *item, void= *opaque) GtkDisplayState *s =3D opaque; VirtualConsole *vc =3D gd_vc_find_current(s); =20 + if (!vc) { + return; + } + if (gtk_check_menu_item_get_active(GTK_CHECK_MENU_ITEM(s->zoom_fit_ite= m))) { s->free_scale =3D TRUE; } else { @@ -1807,6 +1840,11 @@ static void gd_menu_grab_input(GtkMenuItem *item, vo= id *opaque) VirtualConsole *vc =3D gd_vc_find_current(s); =20 if (gd_is_grab_active(s)) { + if (!vc) { + gtk_check_menu_item_set_active(GTK_CHECK_MENU_ITEM(s->grab_ite= m), + FALSE); + return; + } gd_grab_keyboard(vc, "user-request-main-window"); gd_grab_pointer(vc, "user-request-main-window"); } else { @@ -1814,7 +1852,9 @@ static void gd_menu_grab_input(GtkMenuItem *item, voi= d *opaque) gd_ungrab_pointer(s); } =20 - gd_update_cursor(vc); + if (vc) { + gd_update_cursor(vc); + } } =20 static void gd_change_page(GtkNotebook *nb, gpointer arg1, guint arg2, @@ -1990,6 +2030,10 @@ static void gd_menu_copy(GtkMenuItem *item, void *op= aque) GtkDisplayState *s =3D opaque; VirtualConsole *vc =3D gd_vc_find_current(s); =20 + if (!vc) { + return; + } + #if VTE_CHECK_VERSION(0, 50, 0) vte_terminal_copy_clipboard_format(VTE_TERMINAL(vc->vte.terminal), VTE_FORMAT_TEXT); --=20 2.55.0.543.g5ebe2ebe4ea8 From nobody Sat Sep 26 22:14:45 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1789296296; cv=none; d=zohomail.com; s=zohoarc; b=mkvgcynmpLS8itClBaAMkkziRjx+ERIvZ5FFUoiufAyZmBfOZ8+K4NnEVWQmR8CNVDTD84rTc6IXlRQ9EK4D2eSBbzxaxsZcLa0WuhQU22v9Xf0oW4KrS3sjk7ZlMtFYnXPXNqctL69UbXfw9iWylusA4Q67fwa5z309hzLMuQc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789296296; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=pZCywqz+vhDR3FMIArWEl+c1mXnNGS588f6R6cn+Z8k=; b=bCbtCK/DDy5O8L4eYZlPxzoxSQPjH79egE5o3a8yQ50xztX7Gg/VlzJ1TxqIqoeHSKRW+RThYbDMiLI9wRX7wMp4y59dgXRg20uQIbidFRLf+fnflQsLnAT1edAfzURIDLVK3YclJTZAc79VsVVGMWwIEomlJiAmUMAzMIJv/so= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789296296460599.8443306803945; Sun, 13 Sep 2026 03:44:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x5hgV-0005pf-98; Sun, 13 Sep 2026 06:43:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hgT-0005pO-O1 for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:41 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x5hgS-0008Ia-32 for qemu-devel@nongnu.org; Sun, 13 Sep 2026 06:43:41 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-684-ov6jmawPNh-dTT_ZdttC7w-1; Sun, 13 Sep 2026 06:43:38 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 2D95F1953951 for ; Sun, 13 Sep 2026 10:43:37 +0000 (UTC) Received: from localhost (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 1DCBF30001A2; Sun, 13 Sep 2026 10:43:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789296219; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=pZCywqz+vhDR3FMIArWEl+c1mXnNGS588f6R6cn+Z8k=; b=HM1LgYwliiV9VB0zbmGTzEeMPTUvUD5M/HMfaueWtdHGr4GnmqKVQ4BkYjFMlathZsZswb 1+3/wOXZGS+0SYliUS2FOv/mjta3r4DPnvFyaishem+amGgNCe9lak5uWLCvQbleCRQxF0 bnCmhr1Qw1SRPH+R9qvB1Nd9ILxJrXc= X-MC-Unique: ov6jmawPNh-dTT_ZdttC7w-1 X-Mimecast-MFC-AGG-ID: ov6jmawPNh-dTT_ZdttC7w_1789296217 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Sun, 13 Sep 2026 14:41:32 +0400 Subject: [GIT PULL 14/14] ui/gtk: Clean up GL resources on tab detach, re-attach, and VC free MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260913-ui-v1-14-7a8d89d0423a@redhat.com> References: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com> To: qemu-devel@nongnu.org Cc: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= X-Developer-Signature: v=1; a=openpgp-sha256; l=5024; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=EiEaQKJ2IjJ2NJt0VKa7papXMumQRcV1BPgrXUq7QbA=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqpn4jiZucOHaCFZk1PuQ6aqPe8gboo89QJ50Wt r8uEN/wqKKJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaqZ+IwAKCRDa6OEJdZac 5WA2D/0S9LJA9dctn4d6sZiGObG+Sx+XRfGZp+qnK8sQv5TcW7Xcgh1o7Af61QIeTsoS+zEXgpl 5IbrmM3qIPyeceYz2RispnNf/4h8OW+bZK0U1+esDayhjCMH/b3Y9V5l44Ha5eW2Hr75lY0XZ6m Hkebk2n3roZvdnBD1K/rqzYDihSaTbidwZPKuJHtnTI/WAMMwJgrmiYUfB1aS4FgaixeMLGhCix wFiVPEbv0rt/UXfrG9r5TjwedvaVXq9rdprvWhGZuw5GQofEgziFQzWNcsFPb8MFZRTHFFsMmQK ntVy69B0pLcfTgwp602k6fnd+w59HFxB3ULbtzSKqFTgWb4V7djcNG9f/a9AEGWCbYY32uhc8vW EUyhPvUwlTjYCFeVEt+O7UnK8vaoVYOVWueAuwC+Zs1U+FctK9KQtAxWS96MlQm+69nB9Sq1kr4 3k3gw7v2PWbRZJSKR2gdM+/7szjqCZ45NJq35NjkOmTM8HxYGLGzS7QnPMeD62jG1cofwGy1N/n 3CsjEoH6QRIzo811BhitWuk3IvIOM6AcPoG6leQorqXx0xFKvUSKTxlJGy+Ulrq909zcWsK0Q5m 8v1WJFgHIrGsdxaKhxvgBCjWbVoI1L1WDAlX4oBhWVtGdZAwGwje3avf7HmBuGroG6W/LN5XYU9 1sQTi01/hybwHHQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1789296297172158500 From: Dongwon Kim When a VC is detached into an independent window or re-attached back to the main window via gd_tab_window_close(), its underlying EGL surface and context are destroyed and recreated. However, the associated FB objects (guest_fb, win_fb, cursor_fb), display surface textures, and shader instances were not being cleaned up during these transitions, leading to potential resource leaks. Introduce a helper function, gd_gl_release_resources(), to make the appropriate GL context current, delete the textures and framebuffers, release the shader instance, and reset state pointers. Use this helper in gd_tab_window_close(), gd_menu_untabify(), and refactor gd_vc_free() to use it as well. Cc: Daniel P. Berrang=C3=A9 Cc: Marc-Andr=C3=A9 Lureau Signed-off-by: Dongwon Kim Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260729134759.2877-1-dongwon.kim@intel.com> --- ui/gtk.c | 67 ++++++++++++++++++++++++++++++++++++++++--------------------= ---- 1 file changed, 42 insertions(+), 25 deletions(-) diff --git a/ui/gtk.c b/ui/gtk.c index a194488a0cf3..ed7ffc06b154 100644 --- a/ui/gtk.c +++ b/ui/gtk.c @@ -1497,6 +1497,28 @@ static int gd_vc_notebook_pos(GtkDisplayState *s, Vi= rtualConsole *target) g_assert_not_reached(); } =20 +#if defined(CONFIG_OPENGL) +static void gd_gl_release_resources(VirtualConsole *vc) +{ + if (vc->gfx.ectx) { + eglMakeCurrent(qemu_egl_display, vc->gfx.esurface, + vc->gfx.esurface, vc->gfx.ectx); + } else if (gtk_use_gl_area) { + gtk_gl_area_make_current(GTK_GL_AREA(vc->gfx.drawing_area)); + } + + if (vc->gfx.gls) { + surface_gl_destroy_texture(vc->gfx.gls, vc->gfx.ds); + qemu_gl_fini_shader(vc->gfx.gls); + vc->gfx.gls =3D NULL; + } + + egl_fb_destroy(&vc->gfx.guest_fb); + egl_fb_destroy(&vc->gfx.win_fb); + egl_fb_destroy(&vc->gfx.cursor_fb); +} +#endif + static gboolean gd_tab_window_close(GtkWidget *widget, GdkEvent *event, void *opaque) { @@ -1513,13 +1535,17 @@ static gboolean gd_tab_window_close(GtkWidget *widg= et, GdkEvent *event, gtk_widget_destroy(vc->window); vc->window =3D NULL; #if defined(CONFIG_OPENGL) - if (vc->gfx.esurface) { - eglDestroySurface(qemu_egl_display, vc->gfx.esurface); - vc->gfx.esurface =3D NULL; - } - if (vc->gfx.ectx) { - eglDestroyContext(qemu_egl_display, vc->gfx.ectx); - vc->gfx.ectx =3D NULL; + if (vc->type =3D=3D GD_VC_GFX) { + gd_gl_release_resources(vc); + + if (vc->gfx.esurface) { + eglDestroySurface(qemu_egl_display, vc->gfx.esurface); + vc->gfx.esurface =3D NULL; + } + if (vc->gfx.ectx) { + eglDestroyContext(qemu_egl_display, vc->gfx.ectx); + vc->gfx.ectx =3D NULL; + } } #endif =20 @@ -1556,12 +1582,9 @@ static void gd_menu_untabify(GtkMenuItem *item, void= *opaque) =20 if (vc->type =3D=3D GD_VC_GFX && qemu_console_is_graphic(vc->gfx.dcl.con)) { - gtk_check_menu_item_set_active(GTK_CHECK_MENU_ITEM(s->grab_item), - FALSE); - } - if (!vc->window) { - vc->window =3D gtk_window_new(GTK_WINDOW_TOPLEVEL); #if defined(CONFIG_OPENGL) + gd_gl_release_resources(vc); + if (vc->gfx.esurface) { eglDestroySurface(qemu_egl_display, vc->gfx.esurface); vc->gfx.esurface =3D NULL; @@ -1571,6 +1594,11 @@ static void gd_menu_untabify(GtkMenuItem *item, void= *opaque) vc->gfx.ectx =3D NULL; } #endif + gtk_check_menu_item_set_active(GTK_CHECK_MENU_ITEM(s->grab_item), + FALSE); + } + if (!vc->window) { + vc->window =3D gtk_window_new(GTK_WINDOW_TOPLEVEL); gd_widget_reparent(s->notebook, vc->window, vc->tab_item); =20 g_signal_connect(vc->window, "delete-event", @@ -2707,19 +2735,8 @@ static void gd_vc_free(void *p) if (display_opengl) { qemu_console_set_display_gl_ctx(vc->gfx.dcl.con, NULL); } - if (vc->gfx.ectx) { - eglMakeCurrent(qemu_egl_display, vc->gfx.esurface, - vc->gfx.esurface, vc->gfx.ectx); - } else if (gtk_use_gl_area) { - gtk_gl_area_make_current(GTK_GL_AREA(vc->gfx.drawing_area)); - } - if (vc->gfx.gls) { - surface_gl_destroy_texture(vc->gfx.gls, vc->gfx.ds); - qemu_gl_fini_shader(vc->gfx.gls); - } - egl_fb_destroy(&vc->gfx.guest_fb); - egl_fb_destroy(&vc->gfx.win_fb); - egl_fb_destroy(&vc->gfx.cursor_fb); + gd_gl_release_resources(vc); + if (vc->gfx.esurface) { eglDestroySurface(qemu_egl_display, vc->gfx.esurface); } --=20 2.55.0.543.g5ebe2ebe4ea8