From nobody Sat Sep 26 20:01:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1790141191; cv=none; d=zohomail.com; s=zohoarc; b=ijLqGnczpmVK72mFy+WiE+zgvDm4ShLuvETyWp1EA6FGLSJaM5VEFxUmwHufQkdTrBmUSlNmTNKkb7B692nMa5Y2X6xtAAjodXUC1l3IxfDgLA0KSu8UKS3YDYZJbeznk7JJaPimzQqY8HY+0ud88X6uHsIGT6JOwuBGbeJE4/U= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790141191; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=xy2kazJ0sbOjLi1gO1kgKLLSyCDgqvuAyh6eKXPv1D0=; b=eLOMSD8mWVuXkzWS6lcTkgrfW4xpfCVR+5E0pIMYkdYhtyEnZv1wx1eBemk0Gy3HSqYcq+zmVAhSlOyW36QSV7RjiKSSqFQOLav1WL6jq+vq/cFtgXjqWA3jF3gkzHfclTNNd7Td/AfypfVBlwra51efw74Wjl5S9bRizgDxPu0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1790141191139779.8676291639977; Tue, 22 Sep 2026 22:26:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x9FUC-0006VB-0S; Wed, 23 Sep 2026 01:25:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9FU8-0006Us-6q for qemu-devel@nongnu.org; Wed, 23 Sep 2026 01:25:36 -0400 Received: from mgamail.intel.com ([192.198.163.16]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9FU2-0004nA-Rp for qemu-devel@nongnu.org; Wed, 23 Sep 2026 01:25:35 -0400 Received: from fmviesa008.fm.intel.com ([10.60.135.148]) by fmvoesa110.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Sep 2026 22:25:18 -0700 Received: from qat-wangyuan-17e.sh.intel.com ([10.239.92.81]) by fmviesa008.fm.intel.com with ESMTP; 22 Sep 2026 22:25:14 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1790141131; x=1821677131; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=GzdQ80VZCVhN3GNc9qsUbkA22r7r/Fl0uUBh6XnR5Lc=; b=Bocp47/PHsr4E2ArNsRFR5A/stf5ynZxiT1AOOTqpM+e7MH5qJySsiHf MvRTJxhQ8rqYkH71Pgj5VQQgtJNW009XgSe6AS4ozGm/u5xYQ/bhtczmO OHAfh5Hl2p2CDpt59rmS4e3ZQbt1ffoQ0YxchmCJZiX0uYzQGcmtKx61k Dn5AbdCzAsTmBrafah1PnkGHJaT8Hw3I52QFmhSa3oXCXHrb0B3pawEHs PKCxa9emKlbPmg6gU+l1EkH/QKId5fi0Xm6HeruFm8qAKKYUTjdw3hxMN WuXnJiyYLlGXeRLPrp7a7wYCH2Ef8iRIVUca9ORvhukgo8Q2aTYsh0Cb6 g==; X-CSE-ConnectionGUID: buuO3wfERn+o1uLg3bZrFg== X-CSE-MsgGUID: BK/gcwJHTaC/ADMeUHWYuA== X-IronPort-AV: E=McAfee;i="6800,10657,11913"; a="78354572" X-IronPort-AV: E=Sophos;i="6.27,117,1787036400"; d="scan'208";a="78354572" X-CSE-ConnectionGUID: gVN6XDQWSJ6JA/OLsYBCZg== X-CSE-MsgGUID: y99kgHvyQBe5eh0l2J1P4w== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.27,117,1787036400"; d="scan'208";a="273629384" From: Yuan Wang To: qemu-devel@nongnu.org Cc: alex@shazbot.org, clg@redhat.com, tomitamoeko@gmail.com, bosheng.xue@intel.com, junjie.cao@intel.com, Yuan Wang Subject: [PATCH v5] vfio/igd: Make MTL/ARL guests fall back to BAR-based framebuffer access Date: Wed, 23 Sep 2026 13:25:11 +0800 Message-Id: <20260923052511.2842596-1-yuan1.wang@intel.com> X-Mailer: git-send-email 2.34.1 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.16; envelope-from=yuan1.wang@intel.com; helo=mgamail.intel.com X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1790141194242158500 Meteor Lake and Arrow Lake GOP can read BAR0 MMIO offset 0x138914 to detect whether direct framebuffer access via DSM is available. In a VFIO passthrough VM, the guest cannot access the host DSM memory region via such a pointer. If the guest GOP enables that path, it may hand off a DSM-based framebuffer address that the guest cannot actually use. Intercept reads from the detection register and return 0 so the guest does not enable the DSM-based path and instead keeps using the standard BAR-based framebuffer address. Suggested-by: Tomita Moeko Reviewed-by: Tomita Moeko Reviewed-by: Bosheng Xue Reviewed-by: Junjie Cao Reviewed-by: C=C3=A9dric Le Goater Signed-off-by: Yuan Wang --- Changes: v5: - Rebased on top of C=C3=A9dric's vfio-next branch to resolve conflicts with Mike's commit. v4: - Address review comments from Tomita Moeko (update macro/variable names and comments). - Pick up Reviewed-by tags from Tomita Moeko and C=C3=A9dric Le Goater. v3: - Emulated register 0x138914 to return 0x0, which signals the guest GOP driver to fall back to BAR-based mapping since DSM is unavailable in the VM. v2: - Resending because the v1 patch was sent with an incorrect future system timestamp due to an unsynchronized local clock. No code changes. Notes: MTL/ARL device IDs remain in igd_gen(). This is required because vfio_probe_igd_bar0_quirk() checks the generation before installing BAR0 quirks, and the 0x138914 quirk is added afterward. Meanwhile, we also plan to remove the bdsm-size check in the OVMF offline patches. --- hw/vfio/igd.c | 49 ++++++++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 46 insertions(+), 3 deletions(-) diff --git a/hw/vfio/igd.c b/hw/vfio/igd.c index 5e6160763c..4c7d654592 100644 --- a/hw/vfio/igd.c +++ b/hw/vfio/igd.c @@ -96,6 +96,8 @@ static int igd_gen(VFIOPCIDevice *vdev) case 0x4C00: /* Rocket Lake */ case 0x4600: /* Alder Lake */ case 0xA700: /* Raptor Lake */ + case 0x7D00: /* Meteor Lake / Arrow Lake */ + case 0xB600: /* Arrow Lake */ return 12; } =20 @@ -452,8 +454,30 @@ static bool vfio_pci_igd_override_gms(int gen, uint32_= t gms, uint32_t *gmch) return ret; } =20 -#define IGD_GGC_MMIO_OFFSET 0x108040 -#define IGD_BDSM_MMIO_OFFSET 0x1080C0 +#define IGD_GGC_MMIO_OFFSET 0x108040 +#define IGD_BDSM_MMIO_OFFSET 0x1080C0 +#define IGD_MTL_PCODE_STOLEN_ACCESS 0x138914 + +#define IGD_IS_MTL_OR_ARL(vdev) \ + ((((vdev)->device_id & 0xff00) =3D=3D 0x7d00) || \ + (((vdev)->device_id & 0xff00) =3D=3D 0xb600)) + +static uint64_t vfio_igd_pcode_stolen_access_read(void *opaque, hwaddr add= r, + unsigned size) +{ + return 0; +} + +static void vfio_igd_pcode_stolen_access_write(void *opaque, hwaddr addr, + uint64_t data, unsigned siz= e) +{ +} + +static const MemoryRegionOps vfio_igd_pcode_stolen_access_quirk =3D { + .read =3D vfio_igd_pcode_stolen_access_read, + .write =3D vfio_igd_pcode_stolen_access_write, + .endianness =3D DEVICE_LITTLE_ENDIAN, +}; =20 /* * IGD BAR0 DBUF_CTL sanitize quirk. @@ -547,7 +571,7 @@ static const MemoryRegionOps igd_dbuf_ctl_ops =3D { =20 void vfio_probe_igd_bar0_quirk(VFIOPCIDevice *vdev, int nr) { - VFIOQuirk *ggc_quirk, *bdsm_quirk; + VFIOQuirk *ggc_quirk, *bdsm_quirk, *pcode_stolen_access_quirk; VFIOConfigMirrorQuirk *ggc_mirror, *bdsm_mirror; int gen; =20 @@ -562,6 +586,25 @@ void vfio_probe_igd_bar0_quirk(VFIOPCIDevice *vdev, in= t nr) return; } =20 + /* + * MTL/ARL guests must keep using the BAR-based framebuffer address. + * Return 0 for PCODE stolen memory access detection (0x138914) so GOP + * stays on the standard access path in the VM. + */ + if (IGD_IS_MTL_OR_ARL(vdev)) { + pcode_stolen_access_quirk =3D vfio_quirk_alloc(1); + memory_region_init_io(pcode_stolen_access_quirk->mem, OBJECT(vdev), + &vfio_igd_pcode_stolen_access_quirk, vdev, + "vfio-igd-pcode-stolen-access-quirk", 4); + memory_region_add_subregion_overlap(vdev->bars[nr].region.mem, + IGD_MTL_PCODE_STOLEN_ACCESS, + pcode_stolen_access_quirk->mem, + 1); + + QLIST_INSERT_HEAD(&vdev->bars[nr].quirks, + pcode_stolen_access_quirk, next); + } + if (vdev->igd_gms) { ggc_quirk =3D vfio_quirk_alloc(1); ggc_mirror =3D ggc_quirk->data =3D g_malloc0(sizeof(*ggc_mirror)); --=20 2.34.1