[Stable-10.0.11 00/56] Patch Round-up for stable 10.0.11, freeze on 2026-06-23

Michael Tokarev posted 56 patches 1 month, 1 week ago
Failed in applying to current master (apply log)
[Stable-10.0.11 00/56] Patch Round-up for stable 10.0.11, freeze on 2026-06-23
Posted by Michael Tokarev 1 month, 1 week ago
The following patches are queued for QEMU stable v10.0.11:

  https://gitlab.com/qemu-project/qemu/-/commits/staging-10.0

Patch freeze is 2026-06-23, and the release is planned for 2026-06-25:

  https://wiki.qemu.org/Planning/10.0

Please respond here or CC qemu-stable@nongnu.org on any additional patches
you think should (or shouldn't) be included in the release.

The changes which are staging for inclusion, with the original commit hash
from master branch, are given below the bottom line.

Thanks!

/mjt

--------------------------------------
01 f0433a8bc4ac Frank Chang:
   target/riscv: Update MISA.C for Zc* extensions
02 613bb1949fff Frank Chang:
   target/riscv: Update MISA.X for non-standard extensions
03 fcbd93e96be2 Andrew Jones:
   hw/riscv/riscv-iommu: Fix Svnapot 64KB pages
04 249483623242 Zishun Yi:
   target/riscv: Allow mseccfg access based on ext_zicfilp
05 61240e3a06dc Florian Lugou:
   hw/char: sifive_uart: Avoid infinite delay of async xmit function
06 e6051fa61b9f Frank Chang:
   hw/char: sifive_uart: Implement txctrl.txen and rxctrl.rxen
07 a0946caf1d9e Abhigyan Kumar:
   target/riscv: Fix medeleg[11] read-only zero bit for M-mode ECALL
08 612f22c19db8 Zishun Yi:
   target/riscv/pmp: Fix integer overflow in TOR and NA4 address computation
09 b0daaa172a1c TANG Tiancheng:
   target/riscv: Save stimer and vstimer in CPU vmstate
10 eccb1d694025 Zishun Yi:
   target/riscv: Add mseccfg to VMStateDescription
11 27f9566dcd98 Alistair Francis:
   target/riscv: Update the local interrupt mask
12 8158a74f0a0d Zishun Yi:
   target/riscv: clear mseccfg on reset for all dependent extensions
13 ae18df638fb4 Daniel P. Berrangé:
   ui/vnc: fix OOB read access in VNC SASL mechname array
14 c3c6226fa481 Daniel P. Berrangé:
   ui/vnc: fix OOB write in VNC stats array
15 46ee49034d26 Daniel P. Berrangé:
   ui/vnc: fix OOB write in lossy rect worker code
16 d0c7b82d3a89 Daniel P. Berrangé:
   ui/vnc: fix OOB read updating VNC update frequency stats
17 e56b4bbff1df Heechan Kang:
   ui: fix validation of VNC extended clipboard data length
18 5297a0fc6531 Paolo Bonzini:
   lsi53c895a: fix use-after-free of cancelled request
19 4494dec8c2bf Paolo Bonzini:
   lsi53c895a: clear tag byte when processing messages
20 153dc2fa7bbe Paolo Bonzini:
   apic: fix delivery bitmask with modified xAPIC ids
21 4b6c088c88cc Jinjie Ruan:
   mc146818rtc: Fix get_guest_rtc_ns() overflow bug
22 6864bec553b2 Denis V. Lunev:
   block/linux-aio: bound ioq_submit() recursion depth
23 446050c4dfe4 Peter Maydell:
   target/arm: SVE2 FMAXP, FMINP must honour AH=1
24 aa42300f86d1 Peter Maydell:
   target/arm: Use FPST_A64_F16 for SVE FCVTLT_hs
25 23ece2805f9a Peter Maydell:
   target/arm: Set correct fp flags for FLOGB when FPCR.AH = 1
26 bb957530471c Peter Maydell:
   target/arm: Don't assert if 64-bit EL2 AT insn sees a Domain fault
27 8526b7d6b67b Peter Maydell:
   hw/net/rocker_of_dpa: Check group ID pointers are not NULL
28 71d027cfee85 Peter Maydell:
   hw/net/rocker_of_dpa: Avoid unaligned accesses in _of_dpa_flow_match()
29 3f50dd46664b Matt Turner:
   linux-user/ppc: restore fp_status from FPSCR on sigreturn
30 84b920ccb5ee Matt Turner:
   linux-user/mips: save/restore FCSR across signal delivery
31 6bf4c0295ccc Matt Turner:
   linux-user/sh4: preserve T/M/Q bits across signal delivery
32 a740f17ed0fb Matt Turner:
   linux-user/sh4: restore FP rounding mode on sigreturn
33 2762cd51ee03 Matt Turner:
   linux-user/s390x: restore fpu_status rounding mode from FPC on sigreturn
34 44f51c1a3cf4 Sean Wei:
   hw/9pfs: move G_GNUC_PRINTF to header
35 abb0cc02fb56 Christian Schoenebeck:
   hw/9pfs: add NULL check in v9fs_path_is_ancestor()
36 dbaf84e148b0 Christian Schoenebeck:
   hw/9pfs: change V9fsPath.size to size_t and v9fs_path_sprintf() return 
   type
37 54dd352c5926 Christian Schoenebeck:
   hw/9pfs: add error handling to v9fs_fix_path()
38 3802c0e755a5 Christian Schoenebeck:
   hw/9pfs: let callers of v9fs_path_sprintf() and v9fs_fix_path() handle 
   errors
39 be33c56898f8 Christian Schoenebeck:
   tests/qtest/libqos: add qvirtqueue_reset_pool() for descriptor pool reset
40 198627807a6b Christian Schoenebeck:
   tests/9pfs: add deep absolute path test
41 5a8da7e979f1 sin99xx:
   9pfs: fix missing rename lock in v9fs_co_readdir_many (CVE-2026-48004)
42 c131ae56c13f Denis V. Lunev:
   util/envlist: fix prefix-match in envlist_unsetenv() name lookup
43 05221c600a5f Denis V. Lunev:
   tests/unit: add test-envlist covering setenv/unsetenv name matching
44 1f1ccb6f3c48 Alexandra Winter:
   target/s390x: Make container ids in SysIB_15x 1-based
45 442f727b8beb Farhan Ali:
   s390x/pci: Fix interrupt forwarding disable for interpreted devices
46 b4e28c304bc5 Fiona Ebner:
   block/io: fallback to bounce buffer if BLKZEROOUT is not supported 
   because of alignment
47 aeea0c2804c4 Stefan Hajnoczi:
   virtio-blk: add missing VIRTIO_BLK_T_SCSI_CMD size check (CVE-2026-48914)
48 7f8466e2ce62 Kevin Wolf:
   qemu-io: Add 'aio_discard' command
49 b8bfb1478d61 Kevin Wolf:
   qcow2: Fix corruption on discard during write with COW
50 389f5bcc744d Kevin Wolf:
   iotests/046: Test that discard/write_zeroes wait for dependencies
51 1d47eb689835 Thomas Lamprecht:
   qcow2: Fix data loss on zero write with detect-zeroes=unmap
52 7e573b660fef Fabiano Rosas:
   qed: Don't try to flush during incoming migration
53 163f9a4e0651 Munkhbaatar Enkhbaatar:
   hw/usb/hcd-ohci: Clean up USBPacket before freeing ISO TD packet
54 a6a1f92d5a23 Richard Henderson:
   fpu: Handle all rounding modes in partsN_uncanon_normal
55 767c32fe6983 Xinhui Yang:
   linux-user: implement fsmount(2) series of syscalls
56 6e0aa9f6c731 Xinhui Yang:
   linux-user/strace: add fsmount series of syscalls