From nobody Sat Sep 26 19:11:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1790240802; cv=none; d=zohomail.com; s=zohoarc; b=O6cW9ojdSp3FESm+wFsAdszX/gAnAolGPjr/uNYMo4dpcYT95LMF/GzZQ/dZ3HsGcphM8m5h38ZjOZiAWUjgpjqgJ2cd8K8yFnSwdu2M5mr0OhS7ehFdNz0MI9H+rjlQlqLtwtxF0LzCSNb/XT9tkgnVkPqLHH6ZajsUh94zqps= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790240802; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RgjsTVF6YPcLBBYzsKri/GP8jiY61+tzms6P3IEX53Y=; b=j1e9SNpH6YOisSJIx0oVXsA89L/tDDAI5Nw9KmB7FDjeXqqoFFumaggUNJ/Jc06YSnSokwrf9Tq7R2Q0erCCn84JxCPW7XAwgclxA2zP7T/eBKvNspL9QaYz7wMr9LIN7PJdyJkt7Flwz/SXNN/Rxe80qIgsGhUgcExT3Hkubbw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 179024080244248.2990761273569; Thu, 24 Sep 2026 02:06:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x9fPB-0008Du-Gj; Thu, 24 Sep 2026 05:06:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fP5-0008D9-SF for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:07 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fP4-0000iT-4U for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:07 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-612-ReQXyg4hNVCw_4ZjGj1qBQ-1; Thu, 24 Sep 2026 05:06:03 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 34EFC1883057; Thu, 24 Sep 2026 09:06:02 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id F310C195604C; Thu, 24 Sep 2026 09:06:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790240765; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=RgjsTVF6YPcLBBYzsKri/GP8jiY61+tzms6P3IEX53Y=; b=TCU9O0QBN/opgjcIi977QfZLLd+SGfyhhDHqK9eYjrAGwLKZKtVMzjcK7OsRdUeyCv7CHe yHiG9NZC4Yey+1tl/FPFFjiuf/57Hy8dfZgN7W/7jTTHq1b5fABbLzw8N/e411/dvS2P8k Vj75tIeMsdOa4jFFomUNqRzWXOsEloA= X-MC-Unique: ReQXyg4hNVCw_4ZjGj1qBQ-1 X-Mimecast-MFC-AGG-ID: ReQXyg4hNVCw_4ZjGj1qBQ_1790240762 From: Thomas Huth To: qemu-devel@nongnu.org, Richard Henderson Cc: XlabAI Team of Tencent Xuanwu Lab Subject: [PULL 1/7] hw/usb/hcd-xhci: Set reentrancy guard in timer functions (CVE-2026-17588) Date: Thu, 24 Sep 2026 11:05:52 +0200 Message-ID: <20260924090558.801845-2-thuth@redhat.com> In-Reply-To: <20260924090558.801845-1-thuth@redhat.com> References: <20260924090558.801845-1-thuth@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1790240804936158500 Content-Type: text/plain; charset="utf-8" The xHCI controller processes USB events from timer callbacks (xhci_mfwrap_timer and xhci_ep_kick_timer) outside of any MMIO handler context. The device's mem_reentrancy_guard is therefore not engaged during this processing. A malicious guest can exploit this by pointing the event ring base address (er_start) at the xHCI doorbell MMIO region. When xhci_write_event() performs a DMA write to deliver a transfer completion event, the write lands on doorbell register 0. If the written value is 0, this triggers xhci_process_commands() reentrantly. A CR_DISABLE_SLOT command prepared on the command ring then frees endpoint and transfer objects via xhci_disable_ep() / g_free() while the outer call stack still holds references to them, causing a heap use-after-free. Fix this by setting engaged_in_io on the device's mem_reentrancy_guard around the processing in these non-MMIO entry points. This mirrors the protection that EHCI, DWC2, and UHCI already have via qemu_bh_new_guarded(). With the guard active, the memory subsystem's automatic reentrancy check (system/memory.c) blocks DMA writes that would dispatch into the device's own MMIO handlers. CVE: CVE-2026-17588 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3926 Reported-by: XlabAI Team of Tencent Xuanwu Lab , Guannan Wang , Zhanpeng Liu , Jiashuo Liang <761232680@qq.com>, Guancheng Li Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4195 Reported By: Ken Hsu and Royce Lu of Palo Alto Networks Message-ID: <20260915112213.525283-1-thuth@redhat.com> Signed-off-by: Thomas Huth --- hw/usb/hcd-xhci.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/hw/usb/hcd-xhci.c b/hw/usb/hcd-xhci.c index d342aa2739e..12f8ffece0f 100644 --- a/hw/usb/hcd-xhci.c +++ b/hw/usb/hcd-xhci.c @@ -456,9 +456,15 @@ static void xhci_mfwrap_timer(void *opaque) { XHCIState *xhci =3D opaque; XHCIEvent wrap =3D { ER_MFINDEX_WRAP, CC_SUCCESS }; + MemReentrancyGuard *guard =3D &xhci->parent.mem_reentrancy_guard; + + assert(!guard->engaged_in_io); + guard->engaged_in_io =3D true; =20 xhci_event(xhci, &wrap, 0); xhci_mfwrap_update(xhci); + + guard->engaged_in_io =3D false; } =20 static void xhci_die(XHCIState *xhci) @@ -1086,7 +1092,14 @@ static void xhci_set_ep_state(XHCIState *xhci, XHCIE= PContext *epctx, static void xhci_ep_kick_timer(void *opaque) { XHCIEPContext *epctx =3D opaque; + MemReentrancyGuard *guard =3D &epctx->xhci->parent.mem_reentrancy_guar= d; + + assert(!guard->engaged_in_io); + guard->engaged_in_io =3D true; + xhci_kick_epctx(epctx, 0); + + guard->engaged_in_io =3D false; } =20 static XHCIEPContext *xhci_alloc_epctx(XHCIState *xhci, --=20 2.55.0 From nobody Sat Sep 26 19:11:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1790240802; cv=none; d=zohomail.com; s=zohoarc; b=Ohpz2p8DJvztDOfUiamfEBqe3TvADnBw6D/6pewqLszAqB0HZmGFRcU8M+FghSE8qPJ1vWGT9phTHAxnMJbhMvN6bEA4ETKEuBLDH3FKA9dNV3FCQkdLjIuIs0OMrwsfQei4+LurZZlJ1yi8lBQCAMm4i1CJHZiAaf26xgkFtXo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790240802; h=Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=e/y4tAkq6DY1jkS56knddMT7VM1YLyHbL7+VadZFxtw=; b=WtD+bsqngxZdJy+g0JIBO76lXbQYVJm991jfLWsjpqLu1M+oDD0egONb5O62uOzoFreErg4FhVTIcsV+QT7ZgqmG0W0ZnwtNTKn9CPfCGoA730uFkgjJZBfZ5GiSpO6PhtbJwCLIHmobKjK2tYD/vwedYFoGNLkFmNwHe9YL1Ec= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1790240802009169.74847538057384; Thu, 24 Sep 2026 02:06:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x9fPI-0008F5-VX; Thu, 24 Sep 2026 05:06:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fP8-0008Db-Kl for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:11 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fP6-0000il-VQ for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:10 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-371-noaHclC8PpKPdDTBZbE4Jg-1; Thu, 24 Sep 2026 05:06:04 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7ACC91944EB7; Thu, 24 Sep 2026 09:06:03 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id AE5A5195604C; Thu, 24 Sep 2026 09:06:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790240767; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=e/y4tAkq6DY1jkS56knddMT7VM1YLyHbL7+VadZFxtw=; b=i7mKqNUK1pq3jTpBR6bBi7F3lwISIyPpRqxV0N0kEtQG02SRmCfKqjFeRZsXD4VT9vizdL IGF/Vefc7tRIbem5PPNq+QJ+zRX1A9N5YhA4UgcL/Iy0T41+dmk3KaUulZcm+NHnATnCHH oXGC+a78Sjcg9guOKXVEgHhUqsRhcBo= X-MC-Unique: noaHclC8PpKPdDTBZbE4Jg-1 X-Mimecast-MFC-AGG-ID: noaHclC8PpKPdDTBZbE4Jg_1790240763 From: Thomas Huth To: qemu-devel@nongnu.org, Richard Henderson Subject: [PULL 2/7] hw/usb/hcd-xhci: Limit DMA transfers to plain memory Date: Thu, 24 Sep 2026 11:05:53 +0200 Message-ID: <20260924090558.801845-3-thuth@redhat.com> In-Reply-To: <20260924090558.801845-1-thuth@redhat.com> References: <20260924090558.801845-1-thuth@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1790240804953158500 Content-Type: text/plain; charset="utf-8" XHCI is a complex controller, involving lots of descriptors that are written and read via DMA transfers. As some recent bugs like https://gitlab.com/qemu-project/qemu/-/work_items/3926 revealed, this can sometimes be exploited from the guest side to crash or stall QEMU. The code currently does DMA writes with the MEMTXATTRS_UNSPECIFIED attribute, i.e. the controller is allowed to write to other MMIO regions, too. However, in normal operation, this should not be necessary, all descriptors should reside in normal memory. So let's decrease the attack surface a little bit and limit the DMA writes to normal memory here. Signed-off-by: Thomas Huth Message-ID: <20260915123242.549150-1-thuth@redhat.com> --- hw/usb/hcd-xhci.c | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/hw/usb/hcd-xhci.c b/hw/usb/hcd-xhci.c index 12f8ffece0f..0ebf7a638a1 100644 --- a/hw/usb/hcd-xhci.c +++ b/hw/usb/hcd-xhci.c @@ -518,6 +518,7 @@ static inline void xhci_dma_write_u32s(XHCIState *xhci,= dma_addr_t addr, int i; uint32_t tmp[5]; uint32_t n =3D len / sizeof(uint32_t); + const MemTxAttrs memtx_attrs =3D { .memory =3D true }; =20 assert((len % sizeof(uint32_t)) =3D=3D 0); assert(n <=3D ARRAY_SIZE(tmp)); @@ -525,8 +526,7 @@ static inline void xhci_dma_write_u32s(XHCIState *xhci,= dma_addr_t addr, for (i =3D 0; i < n; i++) { tmp[i] =3D cpu_to_le32(buf[i]); } - if (dma_memory_write(xhci->as, addr, tmp, len, - MEMTXATTRS_UNSPECIFIED) !=3D MEMTX_OK) { + if (dma_memory_write(xhci->as, addr, tmp, len, memtx_attrs) !=3D MEMTX= _OK) { qemu_log_mask(LOG_GUEST_ERROR, "%s: DMA memory access failed!\n", __func__); xhci_die(xhci); @@ -613,6 +613,7 @@ static void xhci_write_event(XHCIState *xhci, XHCIEvent= *event, int v) XHCIInterrupter *intr =3D &xhci->intr[v]; XHCITRB ev_trb; dma_addr_t addr; + const MemTxAttrs memtx_attrs =3D { .memory =3D true }; =20 ev_trb.parameter =3D cpu_to_le64(event->ptr); ev_trb.status =3D cpu_to_le32(event->length | (event->ccode << 24)); @@ -629,7 +630,7 @@ static void xhci_write_event(XHCIState *xhci, XHCIEvent= *event, int v) =20 addr =3D intr->er_start + TRB_SIZE*intr->er_ep_idx; if (dma_memory_write(xhci->as, addr, &ev_trb, TRB_SIZE, - MEMTXATTRS_UNSPECIFIED) !=3D MEMTX_OK) { + memtx_attrs) !=3D MEMTX_OK) { qemu_log_mask(LOG_GUEST_ERROR, "%s: DMA memory access failed!\n", __func__); xhci_die(xhci); @@ -2453,6 +2454,7 @@ static void xhci_detach_slot(XHCIState *xhci, USBPort= *uport) static TRBCCode xhci_get_port_bandwidth(XHCIState *xhci, uint64_t pctx) { dma_addr_t ctx; + const MemTxAttrs memtx_attrs =3D { .memory =3D true }; =20 DPRINTF("xhci_get_port_bandwidth()\n"); =20 @@ -2461,9 +2463,9 @@ static TRBCCode xhci_get_port_bandwidth(XHCIState *xh= ci, uint64_t pctx) DPRINTF("xhci: bandwidth context at "DMA_ADDR_FMT"\n", ctx); =20 /* TODO: actually implement real values here. This is 80% for all port= s. */ - if (stb_dma(xhci->as, ctx, 0, MEMTXATTRS_UNSPECIFIED) !=3D MEMTX_OK || + if (stb_dma(xhci->as, ctx, 0, memtx_attrs) !=3D MEMTX_OK || dma_memory_set(xhci->as, ctx + 1, 80, xhci->numports, - MEMTXATTRS_UNSPECIFIED) !=3D MEMTX_OK) { + memtx_attrs) !=3D MEMTX_OK) { qemu_log_mask(LOG_GUEST_ERROR, "%s: DMA memory write failed!\n", __func__); return CC_TRB_ERROR; --=20 2.55.0 From nobody Sat Sep 26 19:11:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1790240802; cv=none; d=zohomail.com; s=zohoarc; b=nMdSf0BhU9dt1edfpYuPT4ggbzBmMSPOaE0W/kEFK+bej0YYiz6jhYbMDEyq3Slb1kQ8WNytfZEuDLSuQZFC65CLV7uor1yOB/vu4GYzPIDptK9iCXWDjvJG546gJ5jVIhq7L8qaHXwxU2W7Pjy5WKF6+W0EOB8XbGPs4o3Kg/k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790240802; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VCksZb64QNAQ2XaTcvhw+Dk+I6GAyFAGd2ZIk3fydX8=; b=bn5y4uzHFWTk26X1euB517sHDlxb7DM3CjQqaFwDNeXDV40CO1izt7S8FFb7C1Ch8Lt0+aOC7fEbjwVkc9V0WV0x0ZWyYXr5jwxUuRGM98o4SOXPCTpTR2XcxXd/2g6x4rVKmnrrVpq5sANkC2ahw+2LkpXmalqliLjtjsDqKu0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1790240802082655.9738893383925; Thu, 24 Sep 2026 02:06:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x9fPH-0008F0-Hv; Thu, 24 Sep 2026 05:06:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fPA-0008Dw-Cg for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:13 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fP8-0000iv-IT for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:12 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-330-ilczWVVOPhKtbJm1mbwzZg-1; Thu, 24 Sep 2026 05:06:05 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id D80641805A07; Thu, 24 Sep 2026 09:06:04 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D52BD195604C; Thu, 24 Sep 2026 09:06:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790240769; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=VCksZb64QNAQ2XaTcvhw+Dk+I6GAyFAGd2ZIk3fydX8=; b=OKrYzemTxuJRQ/8xCnWum1VDqMzfTKDzXZmvLVOPp0yI40zNseQtX7q4gPq/A0NVyAKKzi My5FAXypzO0Z8+9EANrYI5cTOjHEizJZcBT/TGz4KQ+Nu3EWDvwDTPNsFagtniXKI5V2kV NE4vy13FrwwZvjxsF3h7U8shiR6XwfY= X-MC-Unique: ilczWVVOPhKtbJm1mbwzZg-1 X-Mimecast-MFC-AGG-ID: ilczWVVOPhKtbJm1mbwzZg_1790240765 From: Thomas Huth To: qemu-devel@nongnu.org, Richard Henderson Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PULL 3/7] tests/vm: Drop the broken Haiku VM Date: Thu, 24 Sep 2026 11:05:54 +0200 Message-ID: <20260924090558.801845-4-thuth@redhat.com> In-Reply-To: <20260924090558.801845-1-thuth@redhat.com> References: <20260924090558.801845-1-thuth@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1790240804959158500 The Haiku VM has bitrotted again: At least since Haiku r1beta6 has been released, the image does not work anymore. I tried to update the script to use the r1beta6 repositories instead, but after the update, the Haiku kernel only crashes during reboot. Given the fact that hardly anybody seems to use this image and that it is more often broken than working, let's stop wasting our time here and simply remove it. Reviewed-by: Daniel P. Berrang=C3=A9 Signed-off-by: Thomas Huth Message-ID: <20260917062615.783485-1-thuth@redhat.com> --- tests/vm/haiku.x86_64 | 124 ------------------------------------------ 1 file changed, 124 deletions(-) delete mode 100755 tests/vm/haiku.x86_64 diff --git a/tests/vm/haiku.x86_64 b/tests/vm/haiku.x86_64 deleted file mode 100755 index 3ea48dc38a1..00000000000 --- a/tests/vm/haiku.x86_64 +++ /dev/null @@ -1,124 +0,0 @@ -#!/usr/bin/env python3 -# -# Haiku VM image -# -# Copyright 2020-2022 Haiku, Inc. -# -# Authors: -# Alexander von Gluck IV -# -# This code is licensed under the GPL version 2 or later. See -# the COPYING file in the top-level directory. -# - -import os -import re -import sys -import time -import socket -import subprocess -import basevm - -VAGRANT_KEY_FILE =3D os.path.join(os.path.dirname(__file__), - "..", "keys", "vagrant") - -VAGRANT_PUB_KEY_FILE =3D os.path.join(os.path.dirname(__file__), - "..", "keys", "vagrant.pub") - -HAIKU_CONFIG =3D { - 'cpu' : "max", - 'machine' : 'pc', - 'guest_user' : "vagrant", - 'guest_pass' : "", - 'root_user' : "vagrant", - 'root_pass' : "", - 'ssh_key_file' : VAGRANT_KEY_FILE, - 'ssh_pub_key_file': VAGRANT_PUB_KEY_FILE, - 'memory' : "4G", - 'extra_args' : [], - 'qemu_args' : "-device VGA", - 'dns' : "", - 'ssh_port' : 0, - 'install_cmds' : "", - 'boot_dev_type' : "block", - 'ssh_timeout' : 1, -} - -class HaikuVM(basevm.BaseVM): - name =3D "haiku" - arch =3D "x86_64" - - link =3D "https://app.vagrantup.com/haiku-os/boxes/r1beta4-x86_64/vers= ions/20230114/providers/libvirt.box" - csum =3D "6e72a2a470e03dbc3c5e808664e057bb4022b390dca88e4c7da6188f26f6= a3c9" - - poweroff =3D "shutdown" - - requirements =3D [ - "devel:libbz2", - "devel:libcapstone", - "devel:libcurl", - "devel:libfdt", - "devel:libgcrypt", - "devel:libgl", - "devel:libglib_2.0", - "devel:libgnutls", - "devel:libgpg_error", - "devel:libintl", - "devel:libjpeg", - "devel:liblzo2", - "devel:libncursesw", - "devel:libnettle", - "devel:libpixman_1", - "devel:libpng16", - "devel:libsdl2_2.0", - "devel:libslirp", - "devel:libsnappy", - "devel:libssh2", - "devel:libtasn1", - "devel:libusb_1.0", - "devel:libz", - "ninja", - "pip", - "tomli_python310", - "wheel_python310", - "setuptools_python310", - ] - - BUILD_SCRIPT =3D """ - set -e; - rm -rf /tmp/qemu-test.* - cd $(mktemp -d /tmp/qemu-test.XXXXXX); - mkdir src build; cd src; - tar -xf /dev/disk/virtual/virtio_block/1/raw; - mkdir -p /usr/bin - ln -s /boot/system/bin/env /usr/bin/env - cd ../build - ../src/configure {configure_opts}; - make --output-sync -j{jobs} {target} {verbose}; - """ - - def build_image(self, img): - self.print_step("Downloading disk image") - tarball =3D self._download_with_cache(self.link, sha256sum=3Dself.= csum) - - self.print_step("Extracting disk image") - - subprocess.check_call(["tar", "xzf", tarball, "box.img", "-O"], - stdout=3Dopen(img, 'wb')) - - self.print_step("Preparing disk image") - self.boot(img) - - # Wait for ssh to be available. - self.wait_ssh(wait_root=3DTrue, cmd=3D"exit 0") - - # Install packages - self.ssh_root("echo yes | pkgman add-repo https://eu.hpkg.haiku-os= .org/haiku/r1beta5/$(getarch)/current") - self.ssh_root("echo yes | pkgman add-repo https://eu.hpkg.haiku-os= .org/haikuports/r1beta5/$(getarch)/current") - self.ssh_root("pkgman install -y %s" % " ".join(self.requirements)) - self.graceful_shutdown() - - self.print_step("All done") - -if __name__ =3D=3D "__main__": - sys.exit(basevm.main(HaikuVM, config=3DHAIKU_CONFIG)) --=20 2.55.0 From nobody Sat Sep 26 19:11:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1790240862; cv=none; d=zohomail.com; s=zohoarc; b=nOY/PKwJWv8G5azC8tmo4djWYPa3NteEi/7gKPqeegqWLKdX+Kq4nCHog0BfbsDdQSL67iqrbXZzIpVeSZZZ2TFsaKivoQSyy0IVam4sfFCeHBAQMxDLCvJGhATL0Kh/cN6wNkMl6nawjAc1cPZjQDqg4V9pi1Y6abRlCyUKS94= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790240862; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6Iey1EbontVM7Gl3HcB40O7kEWHACWTZ8TmHMXJFCwc=; b=ZGK2vVKiugY2fyO9Uk8CamC5CJkD/6j8x73mInauB4RK4T69MfUBrx0r73ZgDk64/IRZPHUoymCAHT7Diak/tN7W9ihoUQQA4/raiKBkBVFXjZwHXC3VNLt6gpwP/6xJRT4PbkFCGq+mhNHNb6SEuPYMYmaQP5cNtPQJefzybg8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1790240862725225.34412869392577; Thu, 24 Sep 2026 02:07:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x9fPM-0008GA-Q5; Thu, 24 Sep 2026 05:06:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fPD-0008EM-Au for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:17 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fPB-0000jH-0M for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:14 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-690-6zxBTioKNZGpu-mnolXQhA-1; Thu, 24 Sep 2026 05:06:08 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C66081805A07; Thu, 24 Sep 2026 09:06:06 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 3D35D195604C; Thu, 24 Sep 2026 09:06:05 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790240772; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=6Iey1EbontVM7Gl3HcB40O7kEWHACWTZ8TmHMXJFCwc=; b=W9b7cY3eqiR50eOW6zuNPR4DbOtxNaRCRqtCppUGIOlbCRRmH172HurgoXjD6u7pBKjZCX 61vy+At37IDzRTRcFjq7bvPPNkaoskvX5IPEcDmeu0n+wK/KcSEUy7ctpqRnQCp8GsjjMX NjtyhV+v09ZScPsNBDGxruFgVVZyoCA= X-MC-Unique: 6zxBTioKNZGpu-mnolXQhA-1 X-Mimecast-MFC-AGG-ID: 6zxBTioKNZGpu-mnolXQhA_1790240767 From: Thomas Huth To: qemu-devel@nongnu.org, Richard Henderson Cc: Junjie Cao , qemu-stable@nongnu.org, =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PULL 4/7] hw/usb/hcd-xhci: fix interval alignment after MFINDEX passes 2^32 Date: Thu, 24 Sep 2026 11:05:55 +0200 Message-ID: <20260924090558.801845-5-thuth@redhat.com> In-Reply-To: <20260924090558.801845-1-thuth@redhat.com> References: <20260924090558.801845-1-thuth@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1790240864642158500 From: Junjie Cao epctx->interval is an unsigned int, so ~(epctx->interval - 1) is a 32-bit mask that is zero-extended when and-ed with the 64-bit microframe index. Once mfindex no longer fits in 32 bits (2^32 * 125us, about 6.2 days after the controller was started), asap loses its upper half and always compares below mfindex. Isoch TDs with SIA are then run at once instead of at the next interval boundary. xhci_calc_intr_kick() has the same expression. Use ROUND_UP(), which builds the mask in the type of mfindex. The interval is always a power of two. The reporter of #3973 also saw the symptom with UHCI. This change does not explain that. Fixes: 3d1396842d ("xhci: iso xfer support") Fixes: 4d7a81c06f ("xhci: emulate intr endpoint intervals correctly") Link: https://gitlab.com/qemu-project/qemu/-/issues/3973 Cc: qemu-stable@nongnu.org Signed-off-by: Junjie Cao Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-ID: <52c9f935428f2cfc65e4dee7e37638fcb965c6b2.1789968699.git.junjie= .cao@intel.com> Signed-off-by: Thomas Huth --- hw/usb/hcd-xhci.c | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/hw/usb/hcd-xhci.c b/hw/usb/hcd-xhci.c index 0ebf7a638a1..2f82b76272d 100644 --- a/hw/usb/hcd-xhci.c +++ b/hw/usb/hcd-xhci.c @@ -1756,8 +1756,7 @@ static int xhci_fire_ctl_transfer(XHCIState *xhci, XH= CITransfer *xfer) static void xhci_calc_intr_kick(XHCIState *xhci, XHCITransfer *xfer, XHCIEPContext *epctx, uint64_t mfindex) { - uint64_t asap =3D ((mfindex + epctx->interval - 1) & - ~(epctx->interval-1)); + uint64_t asap =3D ROUND_UP(mfindex, epctx->interval); uint64_t kick =3D epctx->mfindex_last + epctx->interval; =20 assert(epctx->interval !=3D 0); @@ -1768,8 +1767,7 @@ static void xhci_calc_iso_kick(XHCIState *xhci, XHCIT= ransfer *xfer, XHCIEPContext *epctx, uint64_t mfindex) { if (xfer->trbs[0].control & TRB_TR_SIA) { - uint64_t asap =3D ((mfindex + epctx->interval - 1) & - ~(epctx->interval-1)); + uint64_t asap =3D ROUND_UP(mfindex, epctx->interval); if (asap >=3D epctx->mfindex_last && asap <=3D epctx->mfindex_last + epctx->interval * 4) { xfer->mfindex_kick =3D epctx->mfindex_last + epctx->interval; --=20 2.55.0 From nobody Sat Sep 26 19:11:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1790240860; cv=none; d=zohomail.com; s=zohoarc; b=fWA8IDIIBLba5Hykf72iPsmp4HzGHF/475JXHYYrdTG8DtHrtnbtPB/4xbu7r/0/9HCUqDojxtGJdJQ/WUtB/gwbQIlH6ghalsA/ylnSROzlq00aA2J19qUXSrnQINFiUc9fH4ePCqohBqMrvcQQ4NxXQZHeWnQ7DkQB2uaHoNo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790240860; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=q5WQc7UCGNWpE427khC14ftuYg6kEP5837Fe2UUU48U=; b=JgsvNe2bTCbmry6PaZI51+ecNrcButJcnxYu3jzgxBXnhB7uzFfcALT6c1Huu3umeqP9dbqrVeKTF6OGYslunEkWEte+WlJ1AlJ47lqUx0F6RyLG+u/vGuUT8+cPuiAabFx8rMJFbSgnryBOhNlzypy0bbMhAX85UiH9rUPQYS8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1790240860715559.0799274597691; Thu, 24 Sep 2026 02:07:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x9fPM-0008Fy-M4; Thu, 24 Sep 2026 05:06:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fPE-0008EU-UL for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:17 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fPD-0000jg-40 for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:16 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-387-tbE4g3QWNo-nMcfi47z2QA-1; Thu, 24 Sep 2026 05:06:10 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 0D3C31954B21; Thu, 24 Sep 2026 09:06:09 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 5E89E195604C; Thu, 24 Sep 2026 09:06:06 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790240773; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=q5WQc7UCGNWpE427khC14ftuYg6kEP5837Fe2UUU48U=; b=XFDbZgAJdXBaiBsN/rP0mnDsjoE8j2Ze/DBo1nzn9COlMbUWxUfKR62V5Spz5hF4zDTn9H rHNyWCnDo1iVmdl2i8sJy0+wMFspnvo43GdqtWCWG3XUGt/2Re8xowhCRime4sBL6IgClL 9K+UhEJKsOuWh/lkz0ErLsUHY8MVVL0= X-MC-Unique: tbE4g3QWNo-nMcfi47z2QA-1 X-Mimecast-MFC-AGG-ID: tbE4g3QWNo-nMcfi47z2QA_1790240769 From: Thomas Huth To: qemu-devel@nongnu.org, Richard Henderson Cc: Junjie Cao , Feifan Qian , qemu-stable@nongnu.org Subject: [PULL 5/7] hw/usb/hcd-xhci: don't assert on NAK when retrying an isoch transfer Date: Thu, 24 Sep 2026 11:05:56 +0200 Message-ID: <20260924090558.801845-6-thuth@redhat.com> In-Reply-To: <20260924090558.801845-1-thuth@redhat.com> References: <20260924090558.801845-1-thuth@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1790240862642158500 Content-Type: text/plain; charset="utf-8" From: Junjie Cao The endpoint type in the xHCI endpoint context comes from the guest and is not checked against the device. A guest can configure the interrupt IN endpoint of usb-kbd as Isoch IN. The idle HID endpoint NAKs, and as soon as the transfer goes through the retry path in xhci_kick_epctx() it hits assert(xfer->packet.status !=3D USB_RET_NAK); No device model NAKs on an isoch endpoint, so this only triggers with a mismatched endpoint type. The two retry branches differ only in what they do on NAK: the isoch one asserts, the other keeps the transfer pending. Merge them. Fixes: 3d1396842d ("xhci: iso xfer support") Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3886 Reported-by: Feifan Qian Cc: qemu-stable@nongnu.org Signed-off-by: Junjie Cao Reviewed-by: Thomas Huth Message-ID: <44227b05b22064a22f4c135e025ff0b1d838b9e3.1789968699.git.junjie= .cao@intel.com> Signed-off-by: Thomas Huth --- hw/usb/hcd-xhci.c | 27 ++++++++------------------- 1 file changed, 8 insertions(+), 19 deletions(-) diff --git a/hw/usb/hcd-xhci.c b/hw/usb/hcd-xhci.c index 2f82b76272d..376bc00264d 100644 --- a/hw/usb/hcd-xhci.c +++ b/hw/usb/hcd-xhci.c @@ -1926,26 +1926,15 @@ static void xhci_kick_epctx(XHCIEPContext *epctx, u= nsigned int streamid) xfer->timed_xfer =3D 0; xfer->running_retry =3D 1; } - if (xfer->iso_xfer) { - /* retry iso transfer */ - if (xhci_setup_packet(xfer) < 0) { - return; - } - usb_handle_packet(xfer->packet.ep->dev, &xfer->packet); - assert(xfer->packet.status !=3D USB_RET_NAK); - xhci_try_complete_packet(xfer); - } else { - /* retry nak'ed transfer */ - if (xhci_setup_packet(xfer) < 0) { - return; - } - usb_handle_packet(xfer->packet.ep->dev, &xfer->packet); - if (xfer->packet.status =3D=3D USB_RET_NAK) { - xhci_xfer_unmap(xfer); - return; - } - xhci_try_complete_packet(xfer); + if (xhci_setup_packet(xfer) < 0) { + return; + } + usb_handle_packet(xfer->packet.ep->dev, &xfer->packet); + if (xfer->packet.status =3D=3D USB_RET_NAK) { + xhci_xfer_unmap(xfer); + return; } + xhci_try_complete_packet(xfer); assert(!xfer->running_retry); if (xfer->complete) { /* update ring dequeue ptr */ --=20 2.55.0 From nobody Sat Sep 26 19:11:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1790240848; cv=none; d=zohomail.com; s=zohoarc; b=Od40pfwagbGhZUscOakACRiOaABClWz8ekgHXwWrWMFacGUnWToB/dYL0mjwbZLsV2GkNGtctyc72JZ5qFdxjnDIjIr2nRmIwULjer/41NPlV59rAwXQoOZ1z/u0qGT6+TaDb4oaI5tUiQMOaAgNpvt+7NQwvAQ7LPEh3WsK7as= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790240848; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=l/SxgC1zmWs3HvFnqp5PyVOpbHDjsYSAe5OLY55qu/M=; b=djJ0n4QzQ8Xts/26YIDgEhuX4qa87tjuv5mp0CHfyQWExvqqcNHJscQx7BDMJa3Q0z0/06oYsJxxtEeGzwgDiIiOXryTkSS5quEQsflb/Ggpjz1IxZMDUsaBRwAdbwEj7oKLT8DVBC4dBCLXBRpM4bWjN6JXHa6kipLyUVLk8mw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1790240848960529.5841219309799; Thu, 24 Sep 2026 02:07:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x9fQ2-0000FF-Sx; Thu, 24 Sep 2026 05:07:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fPJ-0008FZ-3u for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:21 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fPG-0000kT-5J for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:20 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-154-KJMhew2uNrOMzNDLU6jvbw-1; Thu, 24 Sep 2026 05:06:11 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 99ED91955BDC; Thu, 24 Sep 2026 09:06:10 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 668C3195604D; Thu, 24 Sep 2026 09:06:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790240777; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=l/SxgC1zmWs3HvFnqp5PyVOpbHDjsYSAe5OLY55qu/M=; b=SrA99xyf4ee5mexVAU6T4uxbG8BXu2v6TlbiFYYtm+BcH6kw1VL19qalYRPONK3KzPNF6e RVy8on3M8IIZ9C/fob/Rmp0HpWAm0eEiMeB1ThUl4XqnrodYyxEOA8ajv66oqVuASu4qWF 1iMRD+w1LDByIKkOMp0V1edxpU6F4ZQ= X-MC-Unique: KJMhew2uNrOMzNDLU6jvbw-1 X-Mimecast-MFC-AGG-ID: KJMhew2uNrOMzNDLU6jvbw_1790240770 From: Thomas Huth To: qemu-devel@nongnu.org, Richard Henderson Cc: Junjie Cao , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PULL 6/7] tests/qtest/usb-hcd-xhci: test isoch pacing with MFINDEX above 2^32 Date: Thu, 24 Sep 2026 11:05:57 +0200 Message-ID: <20260924090558.801845-7-thuth@redhat.com> In-Reply-To: <20260924090558.801845-1-thuth@redhat.com> References: <20260924090558.801845-1-thuth@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1790240850718158500 From: Junjie Cao Add the minimum needed to drive a transfer ring from the test. Use it to queue an isoch TD with SIA on usb-audio after stepping the clock past 2^32 microframes, and check that the TD waits for the next interval boundary. Before the ROUND_UP() change it completed as soon as the doorbell was rung. The machine is started with pit=3Doff. With the i8254 present the clock step takes 26s in an ASan build instead of well under a second. Signed-off-by: Junjie Cao Acked-by: Philippe Mathieu-Daud=C3=A9 Message-ID: Signed-off-by: Thomas Huth --- tests/qtest/usb-hcd-xhci-test.c | 283 ++++++++++++++++++++++++++++++++ 1 file changed, 283 insertions(+) diff --git a/tests/qtest/usb-hcd-xhci-test.c b/tests/qtest/usb-hcd-xhci-tes= t.c index b58fa1e2dae..61eca37b157 100644 --- a/tests/qtest/usb-hcd-xhci-test.c +++ b/tests/qtest/usb-hcd-xhci-test.c @@ -10,8 +10,68 @@ #include "qemu/osdep.h" #include "libqtest-single.h" #include "libqos/usb.h" +#include "libqos/malloc-pc.h" #include "qobject/qdict.h" =20 +/* capability registers */ +#define XHCI_CAPLENGTH 0x00 +#define XHCI_HCSPARAMS1 0x04 +#define XHCI_DBOFF 0x14 +#define XHCI_RTSOFF 0x18 +/* operational registers */ +#define XHCI_USBCMD 0x00 +#define XHCI_USBSTS 0x04 +#define XHCI_CRCR 0x18 +#define XHCI_DCBAAP 0x30 +#define XHCI_CONFIG 0x38 +#define XHCI_PORTSC(n) (0x400 + 0x10 * (n)) +/* interrupter 0, relative to the runtime registers */ +#define XHCI_ERSTSZ 0x28 +#define XHCI_ERSTBA 0x30 +#define XHCI_ERDP 0x38 + +#define USBCMD_RS (1 << 0) +#define USBCMD_HCRST (1 << 1) +#define USBSTS_HCH (1 << 0) +#define PORTSC_CCS (1 << 0) +#define PORTSC_PR (1 << 4) +#define PORTSC_PP (1 << 9) +#define CRCR_RCS (1 << 0) +#define ERDP_EHB (1 << 3) + +#define TRB_C (1 << 0) +#define TRB_TR_IOC (1 << 5) +#define TRB_TR_SIA (1U << 31) +#define TRB_TYPE(t) ((t) << 10) +#define TRB_GET_TYPE(control) (((control) >> 10) & 0x3f) +#define TRB_GET_CCODE(status) ((status) >> 24) +#define TRB_GET_SLOT(control) ((control) >> 24) + +#define TR_ISOCH 5 +#define CR_ENABLE_SLOT 9 +#define CR_ADDRESS_DEVICE 11 +#define CR_CONFIGURE_ENDPOINT 12 +#define ER_TRANSFER 32 +#define ER_COMMAND_COMPLETE 33 +#define CC_SUCCESS 1 + +#define EP_TYPE_ISOCH_OUT 1 +#define EP_TYPE_CONTROL 4 + +#define XHCI_RING_TRBS 64 +#define XHCI_MICROFRAME_NS 125000 + +typedef struct XHCITest { + QTestState *qts; + QGuestAllocator alloc; + QPCIBus *bus; + struct qhc hc; + uint32_t oper, runtime, doorbell; + uint64_t cmd_ring, event_ring, input_ctx; + unsigned int cmd_idx, event_idx; + unsigned int port, slot; +} XHCITest; + static void wait_device_deleted_event(QTestState *qtest, const char *id) { QDict *resp, *data; @@ -109,6 +169,227 @@ static void test_usb_ccid_hotplug(void) qtest_qmp_device_del(qts, "ccid"); } =20 +static uint32_t xhci_readl(XHCITest *x, uint32_t off) +{ + return qpci_io_readl(x->hc.dev, x->hc.bar, off); +} + +static void xhci_writel(XHCITest *x, uint32_t off, uint32_t val) +{ + qpci_io_writel(x->hc.dev, x->hc.bar, off, val); +} + +static void xhci_writeq(XHCITest *x, uint32_t off, uint64_t val) +{ + xhci_writel(x, off, val); + xhci_writel(x, off + 4, val >> 32); +} + +static uint64_t xhci_alloc_page(XHCITest *x) +{ + uint64_t addr =3D guest_alloc(&x->alloc, 0x1000); + + qtest_memset(x->qts, addr, 0, 0x1000); + return addr; +} + +static void xhci_write_trb(XHCITest *x, uint64_t addr, uint64_t parameter, + uint32_t status, uint32_t control) +{ + qtest_writeq(x->qts, addr, parameter); + qtest_writel(x->qts, addr + 8, status); + qtest_writel(x->qts, addr + 12, control); +} + +/* Fetch the next event if there is one. Does not advance the clock. */ +static bool xhci_next_event(XHCITest *x, uint32_t *status, uint32_t *contr= ol) +{ + uint64_t addr =3D x->event_ring + 16 * x->event_idx; + uint32_t c =3D qtest_readl(x->qts, addr + 12); + + if (!(c & TRB_C)) { + return false; + } + if (status) { + *status =3D qtest_readl(x->qts, addr + 8); + } + if (control) { + *control =3D c; + } + x->event_idx++; + g_assert_cmpuint(x->event_idx, <, XHCI_RING_TRBS); + xhci_writeq(x, x->runtime + XHCI_ERDP, (addr + 16) | ERDP_EHB); + return true; +} + +static unsigned int xhci_command(XHCITest *x, uint64_t parameter, + uint32_t control) +{ + uint32_t status; + + g_assert_cmpuint(x->cmd_idx, <, XHCI_RING_TRBS); + xhci_write_trb(x, x->cmd_ring + 16 * x->cmd_idx++, parameter, 0, + control | TRB_C); + xhci_writel(x, x->doorbell, 0); + + g_assert_true(xhci_next_event(x, &status, &control)); + g_assert_cmpuint(TRB_GET_TYPE(control), =3D=3D, ER_COMMAND_COMPLETE); + g_assert_cmpuint(TRB_GET_CCODE(status), =3D=3D, CC_SUCCESS); + return TRB_GET_SLOT(control); +} + +/* + * Start qemu-xhci with one USB device, run the controller and bring the + * device to the Addressed state. + */ +static void xhci_test_start(XHCITest *x, const char *usb_device) +{ + uint64_t dcbaa, erst, ep0_ring; + unsigned int maxports; + + memset(x, 0, sizeof(*x)); + /* pit=3Doff: a long clock step would run the i8254 timer all the way = */ + x->qts =3D qtest_initf("-machine pc,pit=3Doff -nodefaults " + "-device qemu-xhci,id=3Dxhci,addr=3D04.0 %s", usb= _device); + pc_alloc_init(&x->alloc, x->qts, ALLOC_NO_FLAGS); + x->bus =3D qpci_new_pc(x->qts, NULL); + qusb_pci_init_one(x->bus, &x->hc, QPCI_DEVFN(4, 0), 0); + + x->oper =3D qpci_io_readb(x->hc.dev, x->hc.bar, XHCI_CAPLENGTH); + x->runtime =3D xhci_readl(x, XHCI_RTSOFF) & ~0x1f; + x->doorbell =3D xhci_readl(x, XHCI_DBOFF) & ~0x3; + maxports =3D xhci_readl(x, XHCI_HCSPARAMS1) >> 24; + + xhci_writel(x, x->oper + XHCI_USBCMD, USBCMD_HCRST); + g_assert_false(xhci_readl(x, x->oper + XHCI_USBCMD) & USBCMD_HCRST); + + dcbaa =3D xhci_alloc_page(x); + erst =3D xhci_alloc_page(x); + x->cmd_ring =3D xhci_alloc_page(x); + x->event_ring =3D xhci_alloc_page(x); + x->input_ctx =3D xhci_alloc_page(x); + + xhci_writel(x, x->oper + XHCI_CONFIG, 1); + xhci_writeq(x, x->oper + XHCI_DCBAAP, dcbaa); + qtest_writeq(x->qts, erst, x->event_ring); + qtest_writel(x->qts, erst + 8, XHCI_RING_TRBS); + xhci_writel(x, x->runtime + XHCI_ERSTSZ, 1); + xhci_writeq(x, x->runtime + XHCI_ERSTBA, erst); + xhci_writeq(x, x->runtime + XHCI_ERDP, x->event_ring | ERDP_EHB); + xhci_writeq(x, x->oper + XHCI_CRCR, x->cmd_ring | CRCR_RCS); + xhci_writel(x, x->oper + XHCI_USBCMD, USBCMD_RS); + g_assert_false(xhci_readl(x, x->oper + XHCI_USBSTS) & USBSTS_HCH); + + for (x->port =3D 0; x->port < maxports; x->port++) { + if (xhci_readl(x, x->oper + XHCI_PORTSC(x->port)) & PORTSC_CCS) { + break; + } + } + g_assert_cmpuint(x->port, <, maxports); + xhci_writel(x, x->oper + XHCI_PORTSC(x->port), PORTSC_PP | PORTSC_PR); + while (xhci_next_event(x, NULL, NULL)) { + /* drop the port status change events */ + } + + x->slot =3D xhci_command(x, 0, TRB_TYPE(CR_ENABLE_SLOT)); + qtest_writeq(x->qts, dcbaa + 8 * x->slot, xhci_alloc_page(x)); + + /* input control context: add slot and ep0 */ + qtest_writel(x->qts, x->input_ctx + 0x04, 0x3); + /* slot context: one context entry, root hub port */ + qtest_writel(x->qts, x->input_ctx + 0x20, 1 << 27); + qtest_writel(x->qts, x->input_ctx + 0x24, (x->port + 1) << 16); + /* ep0 context */ + ep0_ring =3D xhci_alloc_page(x); + qtest_writel(x->qts, x->input_ctx + 0x44, + (64 << 16) | (EP_TYPE_CONTROL << 3)); + qtest_writeq(x->qts, x->input_ctx + 0x48, ep0_ring | 1); + xhci_command(x, x->input_ctx, + TRB_TYPE(CR_ADDRESS_DEVICE) | (x->slot << 24)); +} + +/* Returns the address of the transfer ring. */ +static uint64_t xhci_configure_ep(XHCITest *x, unsigned int epid, + unsigned int type, unsigned int interval, + unsigned int max_packet) +{ + uint64_t ring =3D xhci_alloc_page(x); + uint64_t epctx =3D x->input_ctx + 0x20 * (epid + 1); + + qtest_memset(x->qts, x->input_ctx, 0, 0x1000); + qtest_writel(x->qts, x->input_ctx + 0x04, (1 << epid) | 1); + qtest_writel(x->qts, x->input_ctx + 0x20, epid << 27); + qtest_writel(x->qts, x->input_ctx + 0x24, (x->port + 1) << 16); + qtest_writel(x->qts, epctx + 0x00, interval << 16); + qtest_writel(x->qts, epctx + 0x04, (max_packet << 16) | (type << 3)); + qtest_writeq(x->qts, epctx + 0x08, ring | 1); + xhci_command(x, x->input_ctx, + TRB_TYPE(CR_CONFIGURE_ENDPOINT) | (x->slot << 24)); + return ring; +} + +static void xhci_test_end(XHCITest *x) +{ + g_free(x->hc.dev); + qpci_free_pc(x->bus); + alloc_destroy(&x->alloc); + qtest_quit(x->qts); +} + +static bool xhci_test_supported(const char *usb_device) +{ + const char *arch =3D qtest_get_arch(); + + if (strcmp(arch, "i386") !=3D 0 && strcmp(arch, "x86_64") !=3D 0) { + g_test_skip("Test only runs on x86 (pc machine)"); + return false; + } + if (!qtest_has_device("qemu-xhci") || !qtest_has_device(usb_device)) { + g_test_skip("Devices not available"); + return false; + } + return true; +} + +/* + * An isoch TD with SIA set is run at the next interval boundary. That has= to + * hold once the microframe index no longer fits in 32 bits as well. + */ +static void test_xhci_isoch_mfindex_32bit(void) +{ + const unsigned int interval =3D 6; + uint32_t control; + uint64_t ring; + XHCITest x; + + if (!xhci_test_supported("usb-audio")) { + return; + } + + xhci_test_start(&x, "-audiodev none,id=3Dsnd0 " + "-device usb-audio,audiodev=3Dsnd0"); + ring =3D xhci_configure_ep(&x, 2, EP_TYPE_ISOCH_OUT, interval, 64); + + /* Go past 2^32 microframes and stop off an interval boundary. */ + qtest_clock_step(x.qts, (1ULL << 32) * XHCI_MICROFRAME_NS); + qtest_clock_step(x.qts, 5 * XHCI_MICROFRAME_NS); + + xhci_write_trb(&x, ring, xhci_alloc_page(&x), 64, + TRB_TYPE(TR_ISOCH) | TRB_TR_SIA | TRB_TR_IOC | TRB_C); + xhci_writel(&x, x.doorbell + 4 * x.slot, 2); + g_assert_false(xhci_next_event(&x, NULL, NULL)); + + /* + * The streaming interface has not been enabled, so usb-audio stalls t= he + * TD. What matters is when that happens. + */ + qtest_clock_step(x.qts, XHCI_MICROFRAME_NS << interval); + g_assert_true(xhci_next_event(&x, NULL, &control)); + g_assert_cmpuint(TRB_GET_TYPE(control), =3D=3D, ER_TRANSFER); + + xhci_test_end(&x); +} + int main(int argc, char **argv) { int ret; @@ -123,6 +404,8 @@ int main(int argc, char **argv) if (qtest_has_device("usb-ccid")) { qtest_add_func("/xhci/pci/hotplug/usb-ccid", test_usb_ccid_hotplug= ); } + qtest_add_func("/xhci/pci/isoch/mfindex-32bit", + test_xhci_isoch_mfindex_32bit); =20 qtest_start("-device nec-usb-xhci,id=3Dxhci" " -drive id=3Ddrive0,if=3Dnone,file=3Dnull-co://," --=20 2.55.0 From nobody Sat Sep 26 19:11:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1790240841; cv=none; d=zohomail.com; s=zohoarc; b=DOX6icVUOmPe0NOWJ6knvZQgzSybxqt+dnltoaGnScFikibIIu0fZhjS3ybgqzpeF9cQLMVHlPImgMiT4DtmK7te7fevoP6te9/vtwf3lSSRLD/lLvXQebiSJCRx5nfyAFZjMP2H8a9UFE2VpOgquoERfVfvUmZX7qcn9Rcrdjk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790240841; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=JcWcPE7FohJ4oBJ9imAYYpTxgR7PhSPCSzr+yu/w12E=; b=J7Rj0dbWtJo6m54qxAlJi2JCY2ojxAdcte5fsP5//iJUUAlqDYxPH88/TXTb15N/HXapG2+gUHy85lFJi/YmJ5PJM3BCDQHdmsBFZzKKCmlqfQxJgZ3LtTSOLcHcpEnX2YjTgoWtbm0R1xCjetbzvXHRmGidL3GHzrvwLD7ZmU4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1790240841069254.52615416201547; Thu, 24 Sep 2026 02:07:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x9fPk-0008H0-RW; Thu, 24 Sep 2026 05:06:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fPH-0008F1-6m for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:19 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x9fPF-0000kP-K9 for qemu-devel@nongnu.org; Thu, 24 Sep 2026 05:06:18 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-495-dIGYbfO0OtKRm63GY4z49g-1; Thu, 24 Sep 2026 05:06:13 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 551C9195420D; Thu, 24 Sep 2026 09:06:12 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id F3190195604C; Thu, 24 Sep 2026 09:06:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790240777; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=JcWcPE7FohJ4oBJ9imAYYpTxgR7PhSPCSzr+yu/w12E=; b=WRzXBKCutaoctqN3xYlLZueXk866/wgkLLUKPYOiQyZ6Gx89r7QroHy+YuIEkRhmC+Dy0p /JQDMHhXUgYp7x/DXl5CxQ0C4AE/Vy7rdZAz45y+7F6FyrKvRusqkgzQF+XYGmaZqyECk8 iXQP17ZijxLS2sG/eUtrQz31Sw2w3GA= X-MC-Unique: dIGYbfO0OtKRm63GY4z49g-1 X-Mimecast-MFC-AGG-ID: dIGYbfO0OtKRm63GY4z49g_1790240772 From: Thomas Huth To: qemu-devel@nongnu.org, Richard Henderson Cc: Junjie Cao Subject: [PULL 7/7] tests/qtest/usb-hcd-xhci: test isoch endpoint type mismatch Date: Thu, 24 Sep 2026 11:05:58 +0200 Message-ID: <20260924090558.801845-8-thuth@redhat.com> In-Reply-To: <20260924090558.801845-1-thuth@redhat.com> References: <20260924090558.801845-1-thuth@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1790240842704158500 Content-Type: text/plain; charset="utf-8" From: Junjie Cao Configure the interrupt IN endpoint of usb-kbd as Isoch IN and queue one TD. The TD is deferred by a microframe, the kick timer retries it, usb-kbd NAKs, and a second doorbell retries it again. The TD has to stay pending both times and the controller has to keep running. Without the fix QEMU aborts in the timer retry. The endpoint setup is taken from the reproducer attached to #3886. Signed-off-by: Junjie Cao Message-ID: Signed-off-by: Thomas Huth --- tests/qtest/usb-hcd-xhci-test.c | 35 +++++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) diff --git a/tests/qtest/usb-hcd-xhci-test.c b/tests/qtest/usb-hcd-xhci-tes= t.c index 61eca37b157..2e173af7506 100644 --- a/tests/qtest/usb-hcd-xhci-test.c +++ b/tests/qtest/usb-hcd-xhci-test.c @@ -33,6 +33,7 @@ #define USBCMD_RS (1 << 0) #define USBCMD_HCRST (1 << 1) #define USBSTS_HCH (1 << 0) +#define USBSTS_HCE (1 << 12) #define PORTSC_CCS (1 << 0) #define PORTSC_PR (1 << 4) #define PORTSC_PP (1 << 9) @@ -57,6 +58,7 @@ =20 #define EP_TYPE_ISOCH_OUT 1 #define EP_TYPE_CONTROL 4 +#define EP_TYPE_ISOCH_IN 5 =20 #define XHCI_RING_TRBS 64 #define XHCI_MICROFRAME_NS 125000 @@ -390,6 +392,37 @@ static void test_xhci_isoch_mfindex_32bit(void) xhci_test_end(&x); } =20 +/* + * The endpoint type in the endpoint context is whatever the guest says. T= ell + * the controller that the interrupt endpoint of usb-kbd is isoch. The idle + * keyboard NAKs, and the TD has to stay pending when first the kick timer= and + * then a doorbell retry it. + */ +static void test_xhci_isoch_ep_type_mismatch(void) +{ + uint64_t ring; + XHCITest x; + + if (!xhci_test_supported("usb-kbd")) { + return; + } + + xhci_test_start(&x, "-device usb-kbd"); + ring =3D xhci_configure_ep(&x, 3, EP_TYPE_ISOCH_IN, 0, 8); + + xhci_write_trb(&x, ring, xhci_alloc_page(&x), 8, + TRB_TYPE(TR_ISOCH) | TRB_TR_SIA | TRB_TR_IOC | TRB_C); + xhci_writel(&x, x.doorbell + 4 * x.slot, 3); + qtest_clock_step(x.qts, 2 * XHCI_MICROFRAME_NS); + xhci_writel(&x, x.doorbell + 4 * x.slot, 3); + + g_assert_false(xhci_next_event(&x, NULL, NULL)); + g_assert_cmphex(xhci_readl(&x, x.oper + XHCI_USBSTS) & + (USBSTS_HCH | USBSTS_HCE), =3D=3D, 0); + + xhci_test_end(&x); +} + int main(int argc, char **argv) { int ret; @@ -406,6 +439,8 @@ int main(int argc, char **argv) } qtest_add_func("/xhci/pci/isoch/mfindex-32bit", test_xhci_isoch_mfindex_32bit); + qtest_add_func("/xhci/pci/isoch/ep-type-mismatch", + test_xhci_isoch_ep_type_mismatch); =20 qtest_start("-device nec-usb-xhci,id=3Dxhci" " -drive id=3Ddrive0,if=3Dnone,file=3Dnull-co://," --=20 2.55.0