From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380346; cv=none; d=zohomail.com; s=zohoarc; b=ieF1EEjOC4WlaQZgX8TbBmYwLbcAthVXcSu8V6b1PDgBE5yKyRbBB9C30rqAmXUOEwuY/U1fxTsskPm34sq4dCzjZdVTXfYeCUoJIGLi6vbanZvXFIPAqCBSYIlWrMuKkWnrnyW0VKSEio59fzVQun01c1hM/YiDAsu4OEyFehk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380346; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GTSJAiddDtISeu9k0Rwqlp8hM6c3yLIOsb+F8HvEx5Y=; b=Vcv0OubsWn50NwDRq2LLJTVs2eQFNp7trdbTUV7+8Dz0zMTWbAUnTMHBfcUfPT0CvnUNNefvcZByCeyDTxV44fRVQDvh+txKJAbxxoWrsEpEUuEzfBAdq65wrOLM1e6HVp7XouzUC8djKhVpGSWcv4iLAgWQ7pGo81LhWohW6yI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380343978741.6355353808398; Sat, 13 Jun 2026 12:52:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUOR-0000gR-9V; Sat, 13 Jun 2026 15:51:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOE-0000fe-6w; Sat, 13 Jun 2026 15:51:37 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOB-0003Kp-Bh; Sat, 13 Jun 2026 15:51:33 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E42AC1B6E10; Sat, 13 Jun 2026 22:50:57 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 47ECC3CE88A; Sat, 13 Jun 2026 22:51:16 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380257; bh=D/ECPOIbeMuZELutml99RgtJz9N+zxsI2HnC8cHrciQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=U7nlKII4SsV7o7zodTHuLUPR/4y1IGJGOkVtKhNUjKN8mDXcsoT5YDgahEP8F3Sru waHz5E39Ch3ow+pduK1f3sOzPEcL4znOQZt8sWTlmNxe96vYyZTjx3Fln8boEyCf+3 I+1a7YCAUiznNmlsHOCC+eVFugrfDPwHXRaEDju0nIbwB4DDObmjDP64z56jI82LAu ED3i1MdqpJsW2UG8hpzWJfQCTQtz+e/aukmUW15GfAeP8qdL7+OpOkNX06tclO7FGL Emxe5y5TqallgLv8lQZS4jqXSJ4JdALCjK0EQnPs4I787JslCAFhg8ond3KiU3KhlF Jl38qfrupWHwg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Max Chou , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.11 01/56] target/riscv: Update MISA.C for Zc* extensions Date: Sat, 13 Jun 2026 22:50:15 +0300 Message-ID: <20260613195116.1807273-1-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380355175158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang MISA.C is set if the following extensions are selected: * Zca and not F. * Zca, Zcf and F (but not D) is specified (RV32 only). * Zca, Zcf and Zcd if D is specified (RV32 only). * Zca, Zcd if D is specified (RV64 only). Therefore, MISA.C must be set according to the Zc* extension rules. Warn the user if RVC is explicitly disabled but MISA.C is required by the rules above. Signed-off-by: Frank Chang Reviewed-by: Max Chou Reviewed-by: Alistair Francis Message-ID: <20260424050509.3935180-2-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit f0433a8bc4ac5626499ff09ba5d165dbf7a4a980) Signed-off-by: Michael Tokarev diff --git a/target/riscv/tcg/tcg-cpu.c b/target/riscv/tcg/tcg-cpu.c index 863aebec45..d8d82e69dc 100644 --- a/target/riscv/tcg/tcg-cpu.c +++ b/target/riscv/tcg/tcg-cpu.c @@ -972,6 +972,44 @@ static void riscv_cpu_enable_implied_rules(RISCVCPU *c= pu) } } =20 +/* + * MISA.C is set if the following extensions are selected: + * - Zca and not F. + * - Zca, Zcf and F (but not D) is specified on RV32. + * - Zca, Zcf and Zcd if D is specified on RV32. + * - Zca, Zcd if D is specified on RV64. + */ +static void riscv_cpu_update_misa_c(RISCVCPU *cpu) +{ + CPURISCVState *env =3D &cpu->env; + bool set_misa_c =3D false; + + if (riscv_has_ext(env, RVC)) { + return; + } + + if (cpu->cfg.ext_zca && !riscv_has_ext(env, RVF)) { + set_misa_c =3D true; + } else if (riscv_cpu_mxl(env) =3D=3D MXL_RV32 && + cpu->cfg.ext_zca && cpu->cfg.ext_zcf && + (riscv_has_ext(env, RVD) ? cpu->cfg.ext_zcd : + riscv_has_ext(env, RVF))) { + set_misa_c =3D true; + } else if (riscv_cpu_mxl(env) =3D=3D MXL_RV64 && + cpu->cfg.ext_zca && cpu->cfg.ext_zcd) { + set_misa_c =3D true; + } + + if (set_misa_c) { + if (cpu_misa_ext_is_user_set(RVC)) { + warn_report("RVC mandated by Zca/Zcf/Zcd extensions"); + return; + } + + riscv_cpu_set_misa_ext(env, env->misa_ext | RVC); + } +} + void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, Error **errp) { CPURISCVState *env =3D &cpu->env; @@ -979,6 +1017,7 @@ void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, Er= ror **errp) =20 riscv_cpu_init_implied_exts_rules(); riscv_cpu_enable_implied_rules(cpu); + riscv_cpu_update_misa_c(cpu); =20 riscv_cpu_validate_misa_priv(env, &local_err); if (local_err !=3D NULL) { --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380346; cv=none; d=zohomail.com; s=zohoarc; b=E7uLuTmzFSh3FP0W9AMvfDDWXTwH9zKY7zAa5LH2kXWtiB//Axr9n78lrYpzRcPz32Jep35TNbAS89F2lx8zfONM24nmRyUog8uFFemJHem9hAy2thpre2giWjq/J4DpS/jYKT+6GEIoSGBcPLDU0zav7J+g5Vb8v6p038QdMKw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380346; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Bn991LEjjvoXVNeYlhoKudAMPnhLXOVt1soXnOY+b4s=; b=iMUtVhG+AxMWT5MSC994YzGjzEPvO9iWc9OVlcIw4ScaOFpz7CHZjZorDZGDrMhG1W4HEOcXh6HIScEAqo2ILumiKMEhG+F76hAGd3oHXernkD+1GBWllFrdLhsT3hCObA9qpIKKdTq0RAeJjSyZxPlPzVa72mLN343FrwYh14E= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380343978836.1264193872368; Sat, 13 Jun 2026 12:52:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUOX-0000lb-Lf; Sat, 13 Jun 2026 15:51:53 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOJ-0000g1-K0; Sat, 13 Jun 2026 15:51:40 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOH-0003O7-Jb; Sat, 13 Jun 2026 15:51:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 021E11B6E11; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 588CA3CE88B; Sat, 13 Jun 2026 22:51:16 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=81kcofdFtNM2TMccI+ICeuSK1mwUKspB7GVZ1HeC8CY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=XYRllLSKaFtFz29T5u1va9dIg4Dmha783BkPYDZioiknj/mJj9u0t84QR5Pa6gtds mQMKO+DxC+Lpx1Zoh1zGg8thyovafpoeduun/z2Mhs/01TUNafcoPkPcOg1Gt4G+fJ GQhdlHW/5+st8HW5wkmwEBHsEyx5I7OcestDGxbTWPPxrvcU8ePT6knYqOBMshx/9c NpCW3YBcEnJZCCjMVMLat70kERqNrdu1pr2DGpbbzyCn9GpwgP1dLVJ/zhcF6l2jOi hGYxsNvkztMqAGb26yVbc90YEqWxPiV2/O9RSwVVu5it7o4b4wlmBB+Mi8C0Wlb/h4 rhoH9V/jsrPrw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Max Chou , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.11 02/56] target/riscv: Update MISA.X for non-standard extensions Date: Sat, 13 Jun 2026 22:50:16 +0300 Message-ID: <20260613195116.1807273-2-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380355135158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang MISA.X is set if there are any non-standard extensions. We should set MISA.X when any of the vendor extensions is enabled. Signed-off-by: Frank Chang Reviewed-by: Max Chou Reviewed-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260424050509.3935180-3-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit 613bb1949fffc4aeb9e554e35fecc7d6f7ddd27b) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu.h b/target/riscv/cpu.h index 71141f4ea6..6a89f00c49 100644 --- a/target/riscv/cpu.h +++ b/target/riscv/cpu.h @@ -73,6 +73,7 @@ typedef struct CPUArchState CPURISCVState; #define RVH RV('H') #define RVG RV('G') #define RVB RV('B') +#define RVX RV('X') =20 extern const uint32_t misa_bits[]; const char *riscv_get_misa_ext_name(uint32_t bit); diff --git a/target/riscv/tcg/tcg-cpu.c b/target/riscv/tcg/tcg-cpu.c index d8d82e69dc..533c511698 100644 --- a/target/riscv/tcg/tcg-cpu.c +++ b/target/riscv/tcg/tcg-cpu.c @@ -1010,6 +1010,20 @@ static void riscv_cpu_update_misa_c(RISCVCPU *cpu) } } =20 +/* MISA.X is set when any of the non-standard extensions is enabled. */ +static void riscv_cpu_update_misa_x(RISCVCPU *cpu) +{ + CPURISCVState *env =3D &cpu->env; + const RISCVCPUMultiExtConfig *arr =3D riscv_cpu_vendor_exts; + + for (int i =3D 0; arr[i].name !=3D NULL; i++) { + if (isa_ext_is_enabled(cpu, arr[i].offset)) { + riscv_cpu_set_misa_ext(env, env->misa_ext | RVX); + break; + } + } +} + void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, Error **errp) { CPURISCVState *env =3D &cpu->env; @@ -1018,6 +1032,7 @@ void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, E= rror **errp) riscv_cpu_init_implied_exts_rules(); riscv_cpu_enable_implied_rules(cpu); riscv_cpu_update_misa_c(cpu); + riscv_cpu_update_misa_x(cpu); =20 riscv_cpu_validate_misa_priv(env, &local_err); if (local_err !=3D NULL) { --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380448; cv=none; d=zohomail.com; s=zohoarc; b=evsYC6/Ukl7cKMKZdLTEWJEvdcZlzxoH53EXRtPA60Cdu4Ogu7ZH6wzHvg3+/gMM091UQZkxKs+8z2dUW4JoPGjIETPncCKTjmjP4JejQRs4pQZY1VdGT+4+FeN72Y3KAoUw3RBn+T5Y0t+TREnAJH5bQ+LHO65XUHtIe2KgrB4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380448; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=d3rN+545XCEFzelLVpq4Dx6GH7qcUySqOoCZlX58B7E=; b=hksL5ADO4dAVaEt1Flmtr8Nie8VYiIrprBLytgtQn5hMw9DXHEpwSr6HXAeK0jLdtOgg8YO6UVStgmj6TTesdgbUk7YQFd/F0B5bhXAfbhrCUSUyQH/QHRqwWmIaRZ/UhFDg/LJnvBqxqUeEwmCvdSdUCmdGb1M1vKpa8TfptxE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380448560374.59298305562356; Sat, 13 Jun 2026 12:54:08 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUOe-0000nY-Ly; Sat, 13 Jun 2026 15:52:01 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOJ-0000g0-Jx; Sat, 13 Jun 2026 15:51:40 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOH-0003OH-Ky; Sat, 13 Jun 2026 15:51:39 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 166401B6E12; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6B5FD3CE88C; Sat, 13 Jun 2026 22:51:16 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=sQpU8Vswr6SJPWvzmO4YEOhikEXlfhzJYrMt0/HMdtA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=sjIgbWhAtiUJbfDsyRDCA4vEAHp9dt3AK2w7WmPEluqv0EnarrZaVDiRCFLkIdNuJ Ll26ydruT6bBSMqrQnRfo4GWz/LGQl1eRYFJznj12z8lINZma4LWXTrbPUBEGzYZoE jKycfWbviJUpVi4xGGtzFE/sjT+5wRTuIOAlb1OLDYx7IDKfQjO0S/hqbA2vUnBYiJ Dd3QLkjC5iZ+pQDU/k+XbkJxg1Ci9E/jzlyXeSivC5K4tSN+S1ubEsZs5NMJo12DJa CWEaetQdTKYv7w3LvYvjvAzNq56B8y/2wLV6LhdBD66ei+EHm8n5MCufUfrUUwZwj7 +NdTax+s/k7rg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Andrew Jones , Daniel Henrique Barboza , Nutty Liu , Tomasz Jeznach , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.11 03/56] hw/riscv/riscv-iommu: Fix Svnapot 64KB pages Date: Sat, 13 Jun 2026 22:50:17 +0300 Message-ID: <20260613195116.1807273-3-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380450199158500 Content-Type: text/plain; charset="utf-8" From: Andrew Jones The Svnapot extension encodes a 64KB leaf PTE by setting PTE_N and storing bits [3:0] of the PPN as a NAPOT size indicator. The IOMMU model wasn't checking PTE_N and therefore was using the raw (NAPOT- encoded) PPN directly in the physical address, yielding an address 32 KB above the correct base. Fix both riscv_iommu_spa_fetch() and pdt_memory_read() by mirroring the Svnapot handling already present in target/riscv/cpu_helper.c: napot_bits =3D ctz64(ppn) + 1 /* 4 for 64KB */ napot_mask =3D (1 << napot_bits) - 1 /* 0xF */ phys_base =3D PPN_PHYS(ppn & ~napot_mask) page_offset =3D addr & (PPN_PHYS(napot_mask) | (TARGET_PAGE_SIZE - 1)) The spec only defines napot_bits =3D=3D 4 (64KB); any other value is treated as a reserved encoding. This is a fix, rather than new feature support, because the spec says "IOMMU implementations must support the Svnapot standard extension for NAPOT Translation Contiguity." Fixes: 0c54acb8243d ("hw/riscv: add RISC-V IOMMU base emulation") Cc: qemu-stable@nongnu.org Signed-off-by: Andrew Jones Reviewed-by: Daniel Henrique Barboza Reviewed-by: Nutty Liu Reviewed-by: Tomasz Jeznach Message-ID: <20260508205129.377032-1-andrew.jones@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit fcbd93e96be2ed0e5139542f54be31efa6d2b1dc) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index 92ba45bed7..91db1e1b46 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -234,6 +234,25 @@ static bool riscv_iommu_msi_check(RISCVIOMMUState *s, = RISCVIOMMUContext *ctx, return true; } =20 +/* Returns the NAPOT page mask, or 0 for reserved encodings. */ +static hwaddr riscv_iommu_napot_page_mask(hwaddr ppn, hwaddr addr, hwaddr = *out) +{ + int napot_bits =3D ctz64(ppn) + 1; + hwaddr napot_mask, page_mask; + + /* The spec only defines 64KB (napot_bits =3D=3D 4) */ + if (napot_bits !=3D 4) { + return 0; + } + + napot_mask =3D (1ULL << napot_bits) - 1; + page_mask =3D PPN_PHYS(napot_mask) | (TARGET_PAGE_SIZE - 1); + + *out =3D PPN_PHYS(ppn & ~napot_mask) | (addr & page_mask); + + return page_mask; +} + /* * RISCV IOMMU Address Translation Lookup - Page Table Walk * @@ -455,9 +474,20 @@ static int riscv_iommu_spa_fetch(RISCVIOMMUState *s, R= ISCVIOMMUContext *ctx, } else { /* Leaf PTE, translation completed. */ sc[pass].step =3D sc[pass].levels; - base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); - /* Update address mask based on smallest translation granulari= ty */ - iotlb->addr_mask &=3D (1ULL << va_skip) - 1; + + if (pte & PTE_N) { + hwaddr mask =3D riscv_iommu_napot_page_mask(ppn, addr, &ba= se); + + if (!mask) { + break; + } + iotlb->addr_mask &=3D mask; + } else { + base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + /* Update address mask based on smallest translation granu= larity */ + iotlb->addr_mask &=3D (1ULL << va_skip) - 1; + } + /* Continue with S-Stage translation? */ if (pass && sc[0].step !=3D sc[0].levels) { pass =3D S_STAGE; @@ -994,7 +1024,13 @@ static MemTxResult pdt_memory_read(RISCVIOMMUState *s, return MEMTX_ACCESS_ERROR; /* Misaligned PPN */ } else { /* Leaf PTE, translation completed. */ - base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + if (pte & PTE_N) { + if (!riscv_iommu_napot_page_mask(ppn, addr, &base)) { + return MEMTX_ACCESS_ERROR; + } + } else { + base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + } break; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380346; cv=none; d=zohomail.com; s=zohoarc; b=CCU/XVhbR0IOVxzMuDJfcbVKXRXnperOHWI6fuLmZ1qraj7DXvEfpERRt80yJTNyZu/h9tqSoPs4bWR1F2X/RG5T8nnNU9imlRSB42tVw3oxkKeHoy7b+ylzzViMf+mIIJyoQ+ddwex4j8uKeNSXSaFO1drTOJ9XDSuJtpscf4o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380346; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=iAJBE4MyVQ6Xu+t+jmNY8BS9w4RutC7UWTcMEqc6vSg=; b=dyc6jnU6B7ve8rZoaxGvZvEOQlLWfyw8QjYuAw2G3AV5VjQE/1zESNyqyS2rFgmIFwsAw5RDb3/9vCeMlT/7Q6Ow6PriMwpztlODPbLGW3LrzgPaEzbLHKuZ+xPukgPjWqoydAG708i01vKLsNHDYPT8m2rGOCII874LLPD5KmI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138034397528.678490102359433; Sat, 13 Jun 2026 12:52:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUOY-0000m9-Rk; Sat, 13 Jun 2026 15:51:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOQ-0000h2-Oi; Sat, 13 Jun 2026 15:51:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOL-0003Rq-Lo; Sat, 13 Jun 2026 15:51:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 283BD1B6E13; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7EF993CE88D; Sat, 13 Jun 2026 22:51:16 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=fzDKo9zyov0hk5KgycK5G+dWmqPyyUuiw1z/vOaNONo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=pbmeaMOC96kEixMpkQuzKyV4fh9sz8MYhdj+IvDKZvTDKwe6+dLdOJPYxdiYQe1IQ R/YPK0iELbhTdMtyD6/RfREoQAF9cGc5YsxsTFSFHsDSs2IZd6AmXM6AIP5vFZ2bPl CIw1EQiVocCSibUmkXlcOghIkY7Tmuu+mw7Tf0nmFEixpc1AYq5NF7e6bIvuhH0Gpg 810XO8dXZNth3lZ9uggTt2qQ2k2hWt/RcOz6AApbtFxbRajVIncPHcM7ftdBE82fFE iQ0pLpplBQ4xhdJPg0HlWXdKTEpfXsX1eT3fcJc4akocHPRjhCp9wNz6FIS6KQENP+ xefKJygGsSoFw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Chao Liu , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.11 04/56] target/riscv: Allow mseccfg access based on ext_zicfilp Date: Sat, 13 Jun 2026 22:50:18 +0300 Message-ID: <20260613195116.1807273-4-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380355167158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi The Zicfilp extension adds the MLPE field to the mseccfg CSR. According to the RISC-V Privileged Specification, mseccfg exists if any extension that adds a field to it is implemented. Currently, the `have_mseccfg()` predicate function checks for Smepmp, Zkr, and Smmpm, but misses Zicfilp. As a result, if a CPU is configured with `zicfilp=3Dtrue` but without the other extensions, accessing the mseccfg CSR will incorrectly raise an illegal instruction exception. This patch adds the missing check for `ext_zicfilp` to ensure the CSR is properly accessible when the Zicfilp extension is enabled. This issue was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-isa-m= anual/pr-2561/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Chao Liu Reviewed-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260511072705.3015986-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 249483623242c1b9ad4a1600083bea534620917a) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 7d4191c792..68036c79e0 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -767,6 +767,9 @@ static RISCVException have_mseccfg(CPURISCVState *env, = int csrno) if (riscv_cpu_cfg(env)->ext_smmpm) { return RISCV_EXCP_NONE; } + if (riscv_cpu_cfg(env)->ext_zicfilp) { + return RISCV_EXCP_NONE; + } =20 return RISCV_EXCP_ILLEGAL_INST; } --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380348; cv=none; d=zohomail.com; s=zohoarc; b=jWEHZzHDoC4JAJ1rz3xLO89OF9zja4LAPrTdAwgkmuZIY4Vdtjcpky3LSI3hG9q3UVT3bjcmWL5vQU8i1zciNj43Hz1hF/rtPT7qflpXc4/YatVKUTfW7zhyZ6B6oOh6LTnouR4G32WGjrcTYxv9BGb+RrZ0Q/ZzDjiuqNLas3c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380348; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6PSUk54VoOiAsYtjQ7U3vCTvYwZqMzfCrE+VU762BqY=; b=c6h0fLpyLczpI4RIgAjoQMqywV09EUxzpcdff661ZQgR74REXwaUVAeQwDZOMXwFIfAvPiH2iJRkZIzylf4DBeRR6zz8NsS7DuSI39VnveXB+jb2SMzVWj8v8/qJSEXzG/7hCfOP5mDYxoEIzJY9Yq+omBFvH1+FGTTYKSSA2do= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380344100138.05564682210286; Sat, 13 Jun 2026 12:52:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUOj-0000oI-A1; Sat, 13 Jun 2026 15:52:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUON-0000ge-CJ; Sat, 13 Jun 2026 15:51:46 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOL-0003Rr-Lx; Sat, 13 Jun 2026 15:51:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 362AD1B6E14; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 901B53CE88E; Sat, 13 Jun 2026 22:51:16 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=GJ8nDPknSaLTHenVPepcwqgkeXQtz0uFvdNGQXaODmA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=fQUpPYgTKwWG2nih6X3NnfOdbVQBAJuw2P6putVD9WVRSHTN++s4NaB85nFJr+hum iCpgF7wv1x6+5bn09uVhd0yd2kJrFEk7bPRYkjGw1mITBHqjUrDoHqpHcxWAtghb3/ l85bqM9i8uiSGY6rHnNdLQgWuYrmKHUYmjVgNRZx6b8K456KS1mlC1GhUvmkYtClp6 B24dJ+UzlsYovtcW+K2K1ipFxsG2amQhuNZW2J0jEuGOMf66czGbwW37KTpDqjNiGH SSXXlQdkyRHFKQkS+dlbqM+cndLcc6VPkO55Xxggy1R17D92r9HMYwGUVu9PGmFED+ uioNbs0nljTTg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Florian Lugou , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.11 05/56] hw/char: sifive_uart: Avoid infinite delay of async xmit function Date: Sat, 13 Jun 2026 22:50:19 +0300 Message-ID: <20260613195116.1807273-5-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380355126158500 Content-Type: text/plain; charset="utf-8" From: Florian Lugou The current handler for TXFIFO writes schedules an async callback to pop characters from the queue. When software writes to TXFIFO faster than the async callback delay (100ns), the timer may be pushed back while the previous character has not be dequeued yet. This happens in particular when using -icount with small shift values. This is especially worrysome when software repetitively issues amoor.w instructions (as suggested by SiFive specification) and the FIFO is full, leading to the callback being infinitly pushed back. This commit fixes the issue by never pushing back the timer, only updating it if it is not already active. Signed-off-by: Florian Lugou Reviewed-by: Alistair Francis Message-ID: <20250605101255.797162-1-florian.lugou@provenrun.com> Signed-off-by: Alistair Francis (cherry picked from commit 61240e3a06dc622d249b530557d5ce03c5854592) Signed-off-by: Michael Tokarev diff --git a/hw/char/sifive_uart.c b/hw/char/sifive_uart.c index 6da3401aa3..c4258c2ebf 100644 --- a/hw/char/sifive_uart.c +++ b/hw/char/sifive_uart.c @@ -128,8 +128,10 @@ static void sifive_uart_write_tx_fifo(SiFiveUARTState = *s, const uint8_t *buf, s->txfifo |=3D SIFIVE_UART_TXFIFO_FULL; } =20 - timer_mod(s->fifo_trigger_handle, current_time + - TX_INTERRUPT_TRIGGER_DELAY_NS); + if (!timer_pending(s->fifo_trigger_handle)) { + timer_mod(s->fifo_trigger_handle, current_time + + TX_INTERRUPT_TRIGGER_DELAY_NS); + } } =20 static uint64_t --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380583; cv=none; d=zohomail.com; s=zohoarc; b=MAEUOLpuLRn4w5pzk14qJpHwKw38A2mM9tyINbBwHyM6pfGVxsTEUVKhyF5JTv01isKgxZmOqCan7RJEcISbaAmUfadLDkeyXuoiUYIiJ9Bj3xnk81y/LRXGepyL+98u0d355P4BDYJfafGfgdjiEBg+Y8a4hqbE57F0njAXHLE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380583; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=7S4qmR0buXRSAs9aa4aPKfws/0N0vF9UDW1mVfPdnuE=; b=KoBCQO01C6lTKRtnP9dvd6dbVSEViqLEOWfL+TFpPszWZEt18rabLdPCFizseK6fgZXSduWe44MwIi6kNvXObsiz+nQ8YtucVsLUB+wQVqNj4BLewiuwB1yUx12Ex3TRDGMWOKog8CJdHDvE3rlSGJyPDLT1UTLvH5+h5yjvRfs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138058395030.898279079268377; Sat, 13 Jun 2026 12:56:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUPD-00014c-QA; Sat, 13 Jun 2026 15:52:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOS-0000hj-HX; Sat, 13 Jun 2026 15:51:49 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOQ-0003Su-PS; Sat, 13 Jun 2026 15:51:48 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 459A11B6E15; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9E5DA3CE88F; Sat, 13 Jun 2026 22:51:16 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=jL3Sl70exSH7G5xeGK3CC+IHQDNidsmUOqIu95etxZY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=cl4R4MuNkPuW1cc3G7FwO7JvbF2k4t3bSu9FmvjOx6Jcb/AS17qL1twExjyFZZnJF 2Nqu1fiHMwkkfHzCuG/7kEsxSTRyrHNVN+rTkb+vYXBg8C4GYnU7FEhGxii7Mi1eYi fygDrLmhAQZz5Nxaj73vc+BcBV/E3Fy35HrW8brPpXuqBaOrz97Xehq8GwFG8/KBdB A1ipLrqIB2Ag1aU3ZlYG87GH18b3ik6ds0pa7kqd1GGr1R6qn3PXZkX3Q7//IARW1L 4TOQJcfhzo3e8CLxXnKVmNePR1SAxbzbXJi6ERBYHjCN3I/FMTazxeXdCGyOU6dtnk /AZU4Yx/K890Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.11 06/56] hw/char: sifive_uart: Implement txctrl.txen and rxctrl.rxen Date: Sat, 13 Jun 2026 22:50:20 +0300 Message-ID: <20260613195116.1807273-6-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380584667158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang Implement txctrl.txen and rxctrl.rxen as follows: * txctrl.txen The txen bit controls whether the Tx channel is active. When cleared, transmission of Tx FIFO contents is suppressed, and the txd pin is driven high. * rxctrl.rxen: The rxen bit controls whether the Rx channel is active. When cleared, the state of the rxd pin is ignored, and no characters will be enqueued into the Rx FIFO. Therefore, the Tx FIFO should not be dequeued when txctrl.txen is cleared, and the Rx FIFO should not be enqueued when rxctrl.rxen is cleared. Signed-off-by: Frank Chang Reviewed-by: Alistair Francis Message-ID: <20260312033201.1619554-2-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit e6051fa61b9f6fe9c40d8392b6da1f33e9d88332) Signed-off-by: Michael Tokarev diff --git a/hw/char/sifive_uart.c b/hw/char/sifive_uart.c index c4258c2ebf..2efe0e02bd 100644 --- a/hw/char/sifive_uart.c +++ b/hw/char/sifive_uart.c @@ -84,6 +84,11 @@ static gboolean sifive_uart_xmit(void *do_not_use, GIOCo= ndition cond, return G_SOURCE_REMOVE; } =20 + /* Don't pop the FIFO if transmit is disabled. */ + if (!SIFIVE_UART_TXEN(s->txctrl)) { + return G_SOURCE_REMOVE; + } + /* Don't pop the FIFO in case the write fails */ characters =3D fifo8_peek_bufptr(&s->tx_fifo, fifo8_num_used(&s->tx_fifo), &numptr); @@ -112,11 +117,19 @@ static gboolean sifive_uart_xmit(void *do_not_use, GI= OCondition cond, return G_SOURCE_REMOVE; } =20 -static void sifive_uart_write_tx_fifo(SiFiveUARTState *s, const uint8_t *b= uf, - int size) +static void sifive_uart_trigger_tx_fifo(SiFiveUARTState *s) { uint64_t current_time =3D qemu_clock_get_ns(QEMU_CLOCK_VIRTUAL); =20 + if (!timer_pending(s->fifo_trigger_handle)) { + timer_mod(s->fifo_trigger_handle, current_time + + TX_INTERRUPT_TRIGGER_DELAY_NS); + } +} + +static void sifive_uart_write_tx_fifo(SiFiveUARTState *s, const uint8_t *b= uf, + int size) +{ if (size > fifo8_num_free(&s->tx_fifo)) { size =3D fifo8_num_free(&s->tx_fifo); qemu_log_mask(LOG_GUEST_ERROR, "sifive_uart: TX FIFO overflow"); @@ -128,10 +141,7 @@ static void sifive_uart_write_tx_fifo(SiFiveUARTState = *s, const uint8_t *buf, s->txfifo |=3D SIFIVE_UART_TXFIFO_FULL; } =20 - if (!timer_pending(s->fifo_trigger_handle)) { - timer_mod(s->fifo_trigger_handle, current_time + - TX_INTERRUPT_TRIGGER_DELAY_NS); - } + sifive_uart_trigger_tx_fifo(s); } =20 static uint64_t @@ -188,6 +198,9 @@ sifive_uart_write(void *opaque, hwaddr addr, return; case SIFIVE_UART_TXCTRL: s->txctrl =3D val64; + if (SIFIVE_UART_TXEN(s->txctrl) && !fifo8_is_empty(&s->tx_fifo)) { + sifive_uart_trigger_tx_fifo(s); + } return; case SIFIVE_UART_RXCTRL: s->rxctrl =3D val64; @@ -235,7 +248,7 @@ static int sifive_uart_can_rx(void *opaque) { SiFiveUARTState *s =3D opaque; =20 - return s->rx_fifo_len < sizeof(s->rx_fifo); + return SIFIVE_UART_RXEN(s->rxctrl) && (s->rx_fifo_len < sizeof(s->rx_f= ifo)); } =20 static void sifive_uart_event(void *opaque, QEMUChrEvent event) diff --git a/include/hw/char/sifive_uart.h b/include/hw/char/sifive_uart.h index 0846cf6218..33bb03b03b 100644 --- a/include/hw/char/sifive_uart.h +++ b/include/hw/char/sifive_uart.h @@ -51,6 +51,8 @@ enum { =20 #define SIFIVE_UART_TXFIFO_FULL 0x80000000 =20 +#define SIFIVE_UART_TXEN(txctrl) (txctrl & 0x1) +#define SIFIVE_UART_RXEN(rxctrl) (rxctrl & 0x1) #define SIFIVE_UART_GET_TXCNT(txctrl) ((txctrl >> 16) & 0x7) #define SIFIVE_UART_GET_RXCNT(rxctrl) ((rxctrl >> 16) & 0x7) =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380484; cv=none; d=zohomail.com; s=zohoarc; b=S2q1P2LShaF6wCa9sUi5jH9th1YI+1CQ4HOz0T0aMTdse7QHYgEyIN88iTlkWGc4+6AGcNRIb3K+Xc8/OApglF102Zj9C0NryJS0vRqli1t/22ko7Xbshb2+l3wEx+b97BoV5/aW8ULvVa9PdeLoNyHXxWXSL6DPblrxJq0xhug= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380484; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ge6wqg9UXXJSZlGzPs4OuU8LzWdAqhsWyOxkS7zsrQk=; b=abHIF089FNuBWlKS7SQINNkA3KuTRjD8YMujUYGkpPaVlCr61gExIMUYIK/qzsha1ioIsJakW5IvYUOorZ9SMzsgjeClGAStdbPASmdXCmwIwIu5KjqBBNppshWp29tYEvWEzkHVG9lt+FsRYZKXT+SOdIT0PTI89s63dVviA2M= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380484369441.79819830447263; Sat, 13 Jun 2026 12:54:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUOc-0000nS-2Y; Sat, 13 Jun 2026 15:51:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOU-0000ir-7b; Sat, 13 Jun 2026 15:51:50 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOS-0003Tg-Iw; Sat, 13 Jun 2026 15:51:49 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 54D301B6E16; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id AE5E63CE890; Sat, 13 Jun 2026 22:51:16 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=VI+FTEMQDasixsklhSAas2E/Qe0UoujHhKn+Z3uX80s=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=H7saQMvzmYL/WLHska5D2VcfD4Ih4Ll73jm50w2zI91O7pmNuDJyvONxxxy2lFvJO YQKBwIs0HZyql/UlPrakTSIn/mAidjuldroWxiP+i5gQgdOfkYuw04UH2fJo7NAgFZ UsAnVDvXPleZuVWUtsJqyeGs201f38+cNpLnfBReEBXyQjFlISEt4J1iL1igweWts/ 8Li1II7uK6VswaWvT06dz4irvTJD0LeDb4notxMgVOArJ79mDAWS5phhP1SyMh1kOx VJSWU+JCQU4bgDSKFIjs7JA/EX+T/FUzUIpaRcWE/3HKXCHgWgXBn9e0eqPmdMPnxw nfAqSSOoBfeww== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Abhigyan Kumar <314abh@gmail.com>, Alistair Francis , Michael Tokarev Subject: [Stable-10.0.11 07/56] target/riscv: Fix medeleg[11] read-only zero bit for M-mode ECALL Date: Sat, 13 Jun 2026 22:50:21 +0300 Message-ID: <20260613195116.1807273-7-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380486458158500 Content-Type: text/plain; charset="utf-8" From: Abhigyan Kumar <314abh@gmail.com> RISC-V Privileged Specification 3.1.8 (Machine Trap Delegation Registers (medeleg and mideleg)) mentions: "For exceptions that cannot occur in less privileged modes, the corresponding medeleg bits should be read-only zero. In particular, medeleg[11] is read-only zero." QEMU incorrectly included RISCV_EXCP_M_ECALL in DELEGABLE_EXCPS. It allowed the 11th bit to be written and read as set. Fixed by removing it from the DELEGABLE_EXCPS mask, adhering to the specification. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3438 Signed-off-by: Abhigyan Kumar <314abh@gmail.com> Reviewed-by: Alistair Francis Message-ID: <20260427060849.749179-2-314abh@gmail.com> [ Changes by AF: - Remove comment ] Signed-off-by: Alistair Francis (cherry picked from commit a0946caf1d9ec21446ebdcb5eab2400baa4323ae) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 68036c79e0..f8241ea3f4 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -1782,7 +1782,6 @@ static const uint64_t all_ints =3D M_MODE_INTERRUPTS = | S_MODE_INTERRUPTS | (1ULL << (RISCV_EXCP_U_ECALL)) | \ (1ULL << (RISCV_EXCP_S_ECALL)) | \ (1ULL << (RISCV_EXCP_VS_ECALL)) | \ - (1ULL << (RISCV_EXCP_M_ECALL)) | \ (1ULL << (RISCV_EXCP_INST_PAGE_FAULT)) | \ (1ULL << (RISCV_EXCP_LOAD_PAGE_FAULT)) | \ (1ULL << (RISCV_EXCP_STORE_PAGE_FAULT)) | \ --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380393; cv=none; d=zohomail.com; s=zohoarc; b=HK8djNI2FT4gXHFCPwE7Dknp3tWItdzbBeZ7k+6+PAKxTbb9zma46HzGifX0VhaSzRMILnbSRPHwylGqesTdzkfbUiIL5/7iCzULNK/R7U/Ry50fRXL56Ci77n4Tfo+ufYknO8OHX/JtAHOgPdF+tQNVt0zYzfJnkFk0moPNARY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380393; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=641hWEeguDTBrNVU4sotAnnfOfnf6GFxjjGiTkC3e/E=; b=dXNApyN5Rz2HUkpwicdv1Kb4v7aJpff9kAU5uHjWhcuSFqAyvV2ziGy1gxH36wniM2zx1s/qoblYzBATJPtprgKFTBDP9ByDdf0dAjt1DsT5g3Avt0twYOLbMV38HqTEyN1krGpcBwL+XOgHXvvE3hN5AKIn8edq0P18u35jZSw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380393972194.57725642500372; Sat, 13 Jun 2026 12:53:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUP7-00010U-7J; Sat, 13 Jun 2026 15:52:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOW-0000l6-0P; Sat, 13 Jun 2026 15:51:52 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOU-0003UH-Bk; Sat, 13 Jun 2026 15:51:51 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 65BAB1B6E17; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id BD3533CE891; Sat, 13 Jun 2026 22:51:16 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=FSDxJgB5a94ZrTn3uSY5GUCk4MSG0GfO9/srEkQby9c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=o+lrHAVfydr+Zu2C3vTceYoUfGHdkj9VCSTv9Q+puvZ47rgzw6DlIh+voEO5iFMj5 rSaC1PNCKA4bRUW+Y1LoVVV8AfLxCp9/KMi90D9kz102sX7Akhf171m6GzfwRTf5ad g96ErVyYzvWuaQDqlEYCYD5e0OQUcD74GnptrNw1O2+lYh4jtKZB90bzwAjUJF8LRe LN0OC0YG+PvSeX4kGfKSIENq7OqovNprAh50pMLLRqtBAz69XHSKLo9RVp1GxlCDeu h18MAir0/ZjrrP97DwiwkIVLSkAity9MsKGfCyoKsNs3iBN/Qnsc58QNCRKef6xGVa alM50bCWCpSbQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Alistair Francis , Daniel Henrique Barboza , Michael Tokarev Subject: [Stable-10.0.11 08/56] target/riscv/pmp: Fix integer overflow in TOR and NA4 address computation Date: Sat, 13 Jun 2026 22:50:22 +0300 Message-ID: <20260613195116.1807273-8-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380396674158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi According to the RISC-V Privileged Manual: "The Sv32 page-based virtual-memory scheme described in sv32 supports 34-bit physical addresses for RV32, so the PMP scheme must support addresses wider than XLEN for RV32." However, the current QEMU implementation uses `target_ulong` (which resolves to `uint32_t` on RV32) for PMP address variables. When shifting these addresses left (e.g., `this_addr << 2`), an integer overflow occurs, truncating the high bits of the 34-bit physical address. Fix this issue by changing the types of PMP address variables (`this_addr` and `prev_addr`) to `hwaddr`. This issue was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-isa-m= anual/pr-2472/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Alistair Francis Reviewed-by: Daniel Henrique Barboza Message-ID: <20260511102627.3120140-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 612f22c19db8adbe9b155f199ede01e86cc1546c) Signed-off-by: Michael Tokarev diff --git a/target/riscv/pmp.c b/target/riscv/pmp.c index a9e69de917..a3b0b90657 100644 --- a/target/riscv/pmp.c +++ b/target/riscv/pmp.c @@ -190,8 +190,8 @@ static void pmp_decode_napot(hwaddr a, hwaddr *sa, hwad= dr *ea) void pmp_update_rule_addr(CPURISCVState *env, uint32_t pmp_index) { uint8_t this_cfg =3D env->pmp_state.pmp[pmp_index].cfg_reg; - target_ulong this_addr =3D env->pmp_state.pmp[pmp_index].addr_reg; - target_ulong prev_addr =3D 0u; + hwaddr this_addr =3D env->pmp_state.pmp[pmp_index].addr_reg; + hwaddr prev_addr =3D 0u; hwaddr sa =3D 0u; hwaddr ea =3D 0u; =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380357; cv=none; d=zohomail.com; s=zohoarc; b=nBWMAFyoKsoPp/B/pIiK1UmUbVSgLcIyBr69NfZiArZMj4Ifvyu0Dmh2v8NWt6yzQcsifqFnBVAuIPbyRf21VFaBG8SH0w3E3xnAtJyXCKvZ4HR++N1UBtwqUbrqARkQoyw0p+AzhOHailsH/t2sZZUnjYbxLcZkxP8xU8ecaro= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380357; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=V1hM+ODGF810t+an3UFYnBPnSKE4jNEG0qx+6wiIDAs=; b=fEB09whPAd0lSqzY3I3wpt9anXtmuq4lOUZOJ019ShyjWwgilAsZ1SVGeAVCH74Ko5MbXjlafUMxZXL9v5Sc54EIb6dcNUXTjrrAQpnP3xVaIaCGuwmSJOdUcVXXW4ZDKthCBi9t1nuh9s62WTtLNhm/uPgUDtMAUNiBon3LJF0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380356706120.03027186036809; Sat, 13 Jun 2026 12:52:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUOt-0000rR-Ui; Sat, 13 Jun 2026 15:52:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOX-0000lg-GW; Sat, 13 Jun 2026 15:51:53 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOV-0003VA-TT; Sat, 13 Jun 2026 15:51:53 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 760BF1B6E18; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id CD9D93CE892; Sat, 13 Jun 2026 22:51:16 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=9Uq3dqxf3cVPlS1SXHwWc2aH29y8dP/f0umM7BLPiFw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Usji0buB/E1FNNJrxL0T6inuR8+ILpX5wfk0yQZ+n6KDcmvuw349bgF+8kqODfzLu Bhql2xj5XWxc5FwZQpfZOJ3jUNXlVE5IWGve/kIQW5pynAm40aDDoU1m8TSuU6y47k y6jvq1wvEhmSS2gX7xTuRi3I9SNyShW8tPemQAV9Sh97v+woe2QDHpDtCkr5JxWdxK p0WWf0c1XVwo7/bhjR8CAkUd66DQ7fHZ/JFH7fWLEMFEqdXWMe7C7PrMCQKt8TPg9a 4kIcmg7SDrDgCl1fFQF8IfdDoYiM0Ds2jxhSxjiub5CW6Dj8gPhk1VZBvIjTHAo5Jv LogmOlQm5koQQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, TANG Tiancheng , LIU Zhiwei , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.11 09/56] target/riscv: Save stimer and vstimer in CPU vmstate Date: Sat, 13 Jun 2026 22:50:23 +0300 Message-ID: <20260613195116.1807273-9-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380360023158500 Content-Type: text/plain; charset="utf-8" From: TANG Tiancheng vmstate_riscv_cpu was missing env.stimer and env.vstimer. Without migrating these QEMUTimer fields, active S/VS-mode timer events are lost after snapshot or migration. Add VMSTATE_TIMER_PTR() entries to save and restore them. Reviewed-by: LIU Zhiwei Reviewed-by: Daniel Henrique Barboza Signed-off-by: TANG Tiancheng Reviewed-by: Alistair Francis Message-ID: <20250911-timers-v3-4-60508f640050@linux.alibaba.com> Signed-off-by: Alistair Francis (cherry picked from commit b0daaa172a1cd7e8bc8320bfd6612edbebef157f) Signed-off-by: Michael Tokarev diff --git a/target/riscv/machine.c b/target/riscv/machine.c index 0697d813b7..4e0d1bcac7 100644 --- a/target/riscv/machine.c +++ b/target/riscv/machine.c @@ -400,6 +400,30 @@ static const VMStateDescription vmstate_ssp =3D { } }; =20 +static bool sstc_timer_needed(void *opaque) +{ + RISCVCPU *cpu =3D opaque; + CPURISCVState *env =3D &cpu->env; + + if (!cpu->cfg.ext_sstc) { + return false; + } + + return env->stimer !=3D NULL || env->vstimer !=3D NULL; +} + +static const VMStateDescription vmstate_sstc =3D { + .name =3D "cpu/timer", + .version_id =3D 1, + .minimum_version_id =3D 1, + .needed =3D sstc_timer_needed, + .fields =3D (const VMStateField[]) { + VMSTATE_TIMER_PTR(env.stimer, RISCVCPU), + VMSTATE_TIMER_PTR(env.vstimer, RISCVCPU), + VMSTATE_END_OF_LIST() + } +}; + const VMStateDescription vmstate_riscv_cpu =3D { .name =3D "cpu", .version_id =3D 10, @@ -476,6 +500,7 @@ const VMStateDescription vmstate_riscv_cpu =3D { &vmstate_elp, &vmstate_ssp, &vmstate_ctr, + &vmstate_sstc, NULL } }; --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380351; cv=none; d=zohomail.com; s=zohoarc; b=IfijnJFBzDLX/ZWIdMGb2ernXHvI0/WD8iEDNbmZfok76Sed2y4FKf9fWi2G04T0ulwpR/bZx5bDG6H0cpr8c49WXIbdLyzJEnUTMePkk4DCKdQ3r8/9HVm1fcZI+V8SDpLJPhp+cPqDrcskMM/+0FAB0XpBg4rPmXat+RIJWRM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380351; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9N7Tylsie/qSp2k+bTH5bV5LNZKY0wAFOU3pkJe2FGM=; b=FO4ykZR63OOPC4pmnDKO+WdO61RxvjO5fW30WsaYZI8Ns0ZeC6HX2gzTGc11zNPSFfteK9sRX3TG/lh3aMqm4NO5PPtIOlhJKkU7Ue5SByMqXuuLaWwf7gJdrL3iUBbCA51czdcNL7vV3nzWTJS+4PQ0tDoGDVz9paiQByDIjZg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380350974423.00505208718255; Sat, 13 Jun 2026 12:52:30 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUOy-0000sy-89; Sat, 13 Jun 2026 15:52:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOZ-0000mi-Bu; Sat, 13 Jun 2026 15:51:55 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOX-0003Vh-Ps; Sat, 13 Jun 2026 15:51:55 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 84A041B6E19; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id DE3B43CE893; Sat, 13 Jun 2026 22:51:16 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=C4xgLlIqUt7VST6yGXaSo6dn1xFvKzzcU0IK8pB6YDs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ViQx1l0cZl/sGOrSpO1aDDQKd+eDw0sjPWGM39ToPGj0qyF5vNMmM6XYReZoM7UR1 OGyRvKLGYvSKY+3SJnEmtkntjV20fRWjDj2D+LRF/zSw08Fm3s8OPrIjkT6ntthKvk TkhxOjuYPZycPCCEGgWypPMYNqQaRyMtS7RQVipXtVAF+dpt37JSSXVVKNvPHy7+MP b5UD9vOSw69hTUHg3jjW2JqC/zjyJmXvEOoLE2Euk2cCpb+3E1fKphpX9Ad4n+ydbp LPXcmtIawX9ghzUDZvRUPHdGfP6NpWRPOW6znv97hnMF1UKY66k0VTgaHwn6r/bV7K Cuao3UOCD7o2g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.11 10/56] target/riscv: Add mseccfg to VMStateDescription Date: Sat, 13 Jun 2026 22:50:24 +0300 Message-ID: <20260613195116.1807273-10-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380355128158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi Currently, the Machine Security Configuration Register (mseccfg) was missing from the live migration state. This omission causes the register to be reset to zero on the destination host after migration. Fixed by adding vmstate_mseccfg subsection This vulnerability was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/a22e4459cd026ae970791dfbd= 9cfe5d110fbd46b/output/riscv-isa-manual/pr-1879/qemu.txt#L121 Signed-off-by: Zishun Yi Reviewed-by: Alistair Francis Message-ID: <20260511124828.3210477-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit eccb1d6940256668109dc6dc42450ced9f324134) Signed-off-by: Michael Tokarev diff --git a/target/riscv/machine.c b/target/riscv/machine.c index 4e0d1bcac7..3e52dab690 100644 --- a/target/riscv/machine.c +++ b/target/riscv/machine.c @@ -424,6 +424,25 @@ static const VMStateDescription vmstate_sstc =3D { } }; =20 +static bool mseccfg_needed(void *opaque) +{ + RISCVCPU *cpu =3D opaque; + + return cpu->cfg.ext_smepmp || cpu->cfg.ext_zkr + || cpu->cfg.ext_smmpm || cpu->cfg.ext_zicfilp; +} + +static const VMStateDescription vmstate_mseccfg =3D { + .name =3D "cpu/mseccfg", + .version_id =3D 1, + .minimum_version_id =3D 1, + .needed =3D mseccfg_needed, + .fields =3D (const VMStateField[]) { + VMSTATE_UINTTL(env.mseccfg, RISCVCPU), + VMSTATE_END_OF_LIST() + } +}; + const VMStateDescription vmstate_riscv_cpu =3D { .name =3D "cpu", .version_id =3D 10, @@ -501,6 +520,7 @@ const VMStateDescription vmstate_riscv_cpu =3D { &vmstate_ssp, &vmstate_ctr, &vmstate_sstc, + &vmstate_mseccfg, NULL } }; --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380449; cv=none; d=zohomail.com; s=zohoarc; b=jKvMWcrvWS90SxBiL9TGzc2WdFpbcZDtFD/fAyG4he2/WTuAfL6PnUH8rukGsF1EXY69b/fgtbpsbvzM3fCHjWG8aKfEMSO82J/mHLGp2NVQubJ5iiTW7FMJI/9r8N/pCIJ6rKHn0qljEij7w57LmGtD+d7mcA/lJI2pnzlCZhY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380449; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=I6lKy0HEmXw6HR6JltPc8HUsKLV9akawKP4ykWhArRc=; b=O+ZQFKhMsnqgN7lbLbrhlaGOF6qSd/FbNAOcg/vqTer5fZZKf2hDprL87LjH1rCV0OvIPPe9+Oq8Ehdvxro6e8ekVdELgFQbvSwUrDH/492NSBMY6mZPUPEHH0CF0uSkusiVTARLoMqGRIpopSdy7sIkWlttN2pj7WQvxZGnYbs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380449701758.651598249945; Sat, 13 Jun 2026 12:54:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUP7-00010O-7K; Sat, 13 Jun 2026 15:52:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOb-0000nV-UT; Sat, 13 Jun 2026 15:51:58 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOZ-0003W7-7h; Sat, 13 Jun 2026 15:51:56 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 927D61B6E1A; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id ECDF13CE894; Sat, 13 Jun 2026 22:51:16 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=zsJVNZ1Rfy4icEIHnNZvc/oaxs0tIHiyU/YVug6Mbvk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=es9UKFvmXSkxcFzWkUN/O1adFA+rzWdnGImZgSP62l9HxAb3T1giGyUFKyCCeYUgC MGgUlHKlR1crqIKLbWb+CjHHbOgY6688oNqO+fof5J71b5/eihIZl4AncYpr+f2OGG c1lY2t/Uf8WVpQ4wqaPL6SPeWo48yxJjgia4UERykIRnYjGkClkxhtFaE9ndjXyePm cPCBu1VgBkHYhkWac38NakNKxGUhynhlQDKQLh2E+j2RNdoBRPrMjxdeiisamBp3Zd xF4b/b3WWVTarNQV7ZCmXXUNgqcZaHIQiTKd7NlgzwZLGC6s874PEkWTvD9VUo2mj6 VqZRPFZeL8kUg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alistair Francis , Daniel Henrique Barboza , Michael Tokarev Subject: [Stable-10.0.11 11/56] target/riscv: Update the local interrupt mask Date: Sat, 13 Jun 2026 22:50:25 +0300 Message-ID: <20260613195116.1807273-11-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380450171158500 Content-Type: text/plain; charset="utf-8" From: Alistair Francis The RISC-V spec describes bits 0-15 as standard fixed interrupts. The AIA spec on the other hand describes bits 0-12 as standard fixed interrupts. This conflict causes issues for us as we don't dynamically determine if AIA is enabled when setting the *delegable_ints consts. This means currently we incorrectly treat the LCOFIP bit as delegable, even if AIA is disabled, which is incorrect (see the issues mentioned below). The AIA spec indicates that implementations can determine which bits of 13-63 in mvien are writable, so let's just make it bits 15-63 to match the main spec. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3133 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3134 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3135 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3138 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3140 Signed-off-by: Alistair Francis Reviewed-by: Daniel Henrique Barboza Message-ID: <20260513051841.1671987-1-alistair.francis@wdc.com> Signed-off-by: Alistair Francis (cherry picked from commit 27f9566dcd98bdde045ef5ae7b8199456c8a51c1) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index f8241ea3f4..a62b16feae 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -1757,13 +1757,13 @@ static RISCVException write_stimecmph(CPURISCVState= *env, int csrno, #define VSTOPI_NUM_SRCS 5 =20 /* - * All core local interrupts except the fixed ones 0:12. This macro is for + * All core local interrupts except the fixed ones 0:15. This macro is for * virtual interrupts logic so please don't change this to avoid messing up * the whole support, For reference see AIA spec: `5.3 Interrupt filtering= and * virtual interrupts for supervisor level` and `6.3.2 Virtual interrupts = for * VS level`. */ -#define LOCAL_INTERRUPTS (~0x1FFFULL) +#define LOCAL_INTERRUPTS (~0xFFFFULL) =20 static const uint64_t delegable_ints =3D S_MODE_INTERRUPTS | VS_MODE_INTERRUPTS | MIP_LCOFIP; --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380423; cv=none; d=zohomail.com; s=zohoarc; b=kBHsCyAEALAadmKuvG4oky78IN9x2jE6nbjLz47CZ842fUo3XpW+sW1yjTrFWd2iilGohKb7ST/E/nnT3Hr0LuNFiP+NG76MwnDFavj4luYRDlTY74inqy0nPdK8Xr0qS9cQKnDdKUwqB074FJBGqq194FdiQ62o6oFBV1Kva4g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380423; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=SNZdCQCVJXrjp/s6wNrN2pq6yBUnfgy8xTC1dmWP/qM=; b=IJbJbE8BOZbsQFxYrK1k5MGxHlgkFwCMWz9R4ty6V71PJm6Um8shM+YlMMFjA3y3V+IJ2W6YpPYcsjrq4ZvHwyKuorxZkkfF9AB+GqRcUEP3CYLB2p6+FEStMo87G9/fZb3VxmUvly1jPGOaK9bRYDUito1TPYiqB8sjwAFVRXA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138042290354.40548984502266; Sat, 13 Jun 2026 12:53:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUPb-0001YA-TY; Sat, 13 Jun 2026 15:53:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOx-0000sv-Jk; Sat, 13 Jun 2026 15:52:19 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOv-0003Wj-Vl; Sat, 13 Jun 2026 15:52:19 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A2F5B1B6E1B; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0706A3CE895; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=Og0HyygInrFZE1Y0Zj4aatklk05kvCIP9+RnLzuxhzs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=DSj87jpEHK40KpH/stRw2uPqmbjy59FPHpnf6MFao1X9G+ZmHvdo3mtfmFG1GpPCM w5IjPDhC1jrQ9ehvhJ1vUHwEg5SnEUMQOBm6gmgbYoe1p168NN4iOIByqvzioBDUgQ +g0dDsE7o8vfx90vr3tQlJLPHC7iKzLQgONzJdefgouDOqpwWGiU9qHkxupV2MZhsU gC4si94G58BFnOlUgGHD6EPAsx0Ifc8f4uWWmsTmg6xDVrMolz6ouSfuDAP0SMt2Ku B2kr8HA6CWrrgzfZ5MlNLpoYmh+cYnCB1FGhc4bKCNuY9/kMJADU0ekI79JCUFaF7y q9zZsw/eb2tDQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.11 12/56] target/riscv: clear mseccfg on reset for all dependent extensions Date: Sat, 13 Jun 2026 22:50:26 +0300 Message-ID: <20260613195116.1807273-12-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380424016158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi Currently, the `mseccfg` CSR is only cleared to 0 during reset if the `ext_smepmp` is enabled. However, this register is now shared by several other extensions such as `zkr`, `smmpm`, and `zicfilp`. Fix by clearing `mseccfg` if any dependent extension is present, and adjusting the relevant comments. This vulnerability was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-svvpt= c/pr-134/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Daniel Henrique Barboza Message-ID: <20260512052240.330815-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 8158a74f0a0db8626d7836eb03eca7aba46c18b5) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu.c b/target/riscv/cpu.c index 2ff56bd017..9e4f54d250 100644 --- a/target/riscv/cpu.c +++ b/target/riscv/cpu.c @@ -1101,10 +1101,14 @@ static void riscv_cpu_reset_hold(Object *obj, Reset= Type type) =20 /* * Clear mseccfg and unlock all the PMP entries upon reset. - * This is allowed as per the priv and smepmp specifications - * and is needed to clear stale entries across reboots. + * This is required as per the priv, smepmp, and other security + * extension specifications that share this CSR, and is needed + * to clear stale entries across reboots. */ - if (riscv_cpu_cfg(env)->ext_smepmp) { + if (riscv_cpu_cfg(env)->ext_smepmp || + riscv_cpu_cfg(env)->ext_zkr || + riscv_cpu_cfg(env)->ext_smmpm || + riscv_cpu_cfg(env)->ext_zicfilp) { env->mseccfg =3D 0; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380449; cv=none; d=zohomail.com; s=zohoarc; b=JtAzK/yJ1DArjWF3lZvUJMQ74XS08TYYKugGaSlzqjcTT2tr1/dxRx/g8ISPm8Cba8Z/TK9isU0+lcPFereUllYkeoEeeSwRZw1xM6etYQ6/5c5WNnyjbqi1hN4DPXTaaghJ6VgIWeHTX91IhoRqZA+0gPFA5sQbkWLYlODpU84= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380449; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=klO2C5fuiH+pcM9N8CegDHYpQsR7G1+1pGiLzLuAgTU=; b=biM+V1j72WlloOniHUv4kKh57jIbNUGfWLml9tP4gRYPnrqNCAVSgSlbYWBE0d+szTjKMaYY0Ys54wE1AHBzQAHgYjiatwQgpB0Hbdp6VxEfGLqgQfSkWk54P8Zxf4jzmS3FI2gQuPSMKZp9lJVWSaFIorUz3OTQifpt3Om04pg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380449706592.4429211521506; Sat, 13 Jun 2026 12:54:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUPq-0001rg-W1; Sat, 13 Jun 2026 15:53:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOz-0000tj-8g; Sat, 13 Jun 2026 15:52:22 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOx-0003XP-NW; Sat, 13 Jun 2026 15:52:21 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B34711B6E1C; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 172163CE896; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=oeWCQUoPxo3Y5KEpbVvM3clq9pSKvlzk66CPh2w8/2o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=x2ypQAYk2eZAs2QBlAut4tM0KmKvV6HzNdHv/ynnEgkQW0/9M7P/y6Pfgsm+4OCPh M9aTS3NCxte54vmeh029Dt+FhlZiqz5bbLyNomM1EOZ0VmTH9/qRgLxAF0W3kFnL+5 PhJLFRsueT8HVgmdwVdT+Ob9EDKSO/BxmkVGYeoXH2WdbbwBiqosECbwQvpGZAr8D8 jhbtQxzYHxJvs4Jw4OCI0H/4up+yNlyx3KzA1ydfXoSg4KYiQ0f9zSYifXr3t4iInU NliQd0O9SCTDqJa2qxmoABmXwpB5JexsdDYe8n+MtMsVqHCTKo5W5Npqat4NPdyz/I Mir+9nNQjsmKA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-10.0.11 13/56] ui/vnc: fix OOB read access in VNC SASL mechname array Date: Sat, 13 Jun 2026 22:50:27 +0300 Message-ID: <20260613195116.1807273-13-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380450099158500 From: Daniel P. Berrang=C3=A9 When reading the SASL mechname array off the VNC connection, if malicious, the received data may contain embedded NULs. If this happens the memory buffer returned by g_strndup may be shorter than the original data. Unfortunately the code continued to index into this buffer with an offset equal to the original length. This is a potential OOB read of the array. Fixes: 5847d9e1 (ui/vnc: simplify and avoid strncpy) Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-2-berrange@redhat.com> (cherry picked from commit ae18df638fb4285c7b645f98c43f5ebc2e123a55) Signed-off-by: Michael Tokarev diff --git a/ui/vnc-auth-sasl.c b/ui/vnc-auth-sasl.c index 3f4cfc471d..9f15980fca 100644 --- a/ui/vnc-auth-sasl.c +++ b/ui/vnc-auth-sasl.c @@ -490,6 +490,8 @@ static int protocol_client_auth_sasl_mechname(VncState = *vs, uint8_t *data, size_ char *mechname =3D g_strndup((const char *) data, len); trace_vnc_auth_sasl_mech_choose(vs, mechname); =20 + /* If 'data' had embedded NUL the dup'd string might now be shorter */ + len =3D strlen(mechname); if (strncmp(vs->sasl.mechlist, mechname, len) =3D=3D 0) { if (vs->sasl.mechlist[len] !=3D '\0' && vs->sasl.mechlist[len] !=3D ',') { --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380399; cv=none; d=zohomail.com; s=zohoarc; b=H7uUA+UIJaOPxFH6hWHE7r/BsI5tr+9Lg1LrcX7v06xaVMkamnWdUdpUH0KTBufh0Agy3+UeVZCbLF+84IW6KheyjkmxdzIsKzHPA2f1+uPE7VNdySFja/fqtzpz5xLhraND/SniSPwY7B3WhaPd4VJ5hXSuZ1c7AgHxP0r6Kk0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380399; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tMEmmsGTVTF5IoUZ6CN1Sf2ssjhN/OOEuUhFrAvU1dM=; b=Tck3XzgTNmgBiAD8p7IVq+dV9xCS7gnFQ7Rslzpduw19mFBg6wnMVXnwo5y0WqZVu0flnyBRaZe8UdvbMR3JRSbP80CKHvZxlNau46ayWv+zxxXytHd3iwp6bc2HP+MwPL/W8wOIAs/0L8WiScAvSsyie8ZJYvVw2BWqiEIl460= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380399102554.7826394263544; Sat, 13 Jun 2026 12:53:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUPm-0001jm-LY; Sat, 13 Jun 2026 15:53:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUP1-0000zp-EP; Sat, 13 Jun 2026 15:52:26 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUOz-0003eQ-CA; Sat, 13 Jun 2026 15:52:23 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C2D2E1B6E1D; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 274193CE897; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=fa7MhmP6lwG06JdD8G4Q/4adpoF/HiNmdFW+cI6D8RQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Ex5f5qTFpkHzSRmmFpcIA2R4kNYNFFQtQH6tgiU5Pog74Fb15/KLQp67Gn2YCI/kx ysHxPKVHn55IKFaaEJygsvALU4OHAtgeB6TfnUkeZbWO1q6dadO2ONXSR8Kt1aMABJ xLhe7A2KPOs5WyXfA2wnrYBXQeaMMA6yJiyKLGvO66BPELphZPkM3LDlJR+YJfUE4Q k0uKih93/IeVrxfpY0176qFmU169xQneAWj1xe52HskD7FDiA2dWusEC000gc9voeu JnyP4LbcBKV4FhqzqQll+FN93jRAgpxUyzocD/sFxEOsBCWfiSPzcgVE9kdgPx3kK+ zWXyAOiIw9V0g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-10.0.11 14/56] ui/vnc: fix OOB write in VNC stats array Date: Sat, 13 Jun 2026 22:50:28 +0300 Message-ID: <20260613195116.1807273-14-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380399912158502 From: Daniel P. Berrang=C3=A9 The VncSurface struct maintains update statistics in an array: VncRectStat stats[VNC_STAT_ROWS][VNC_STAT_COLS]; where the dimensions are defined as: #define VNC_STAT_RECT 64 #define VNC_STAT_COLS (VNC_MAX_WIDTH / VNC_STAT_RECT) #define VNC_STAT_ROWS (VNC_MAX_HEIGHT / VNC_STAT_RECT) If VNC_MAX_WIDTH / VNC_MAX_HEIGHT are not an exact multiple of VNC_STAT_REC, the COLS/ROWS will be undersized by 1. Unfortunately: #define VNC_MAX_HEIGHT 2160 is not a multiple of 64, so there is potential for OOB reads and writes in the 'stats' array, if the guest surface is over 2112 pixels in height. An array overflow occurs when vnc_update_stats() records new statistics, either scribbling over data later in the VncDisplay struct that 'stats' is embedded in, or performing an OOB write on the allocated struct memory. Fixes: CVE-2026-48002 Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-3-berrange@redhat.com> (cherry picked from commit c3c6226fa48180edf9d4646d4112fb1becbc149b) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.h b/ui/vnc.h index 82b883bb69..12b5e3d965 100644 --- a/ui/vnc.h +++ b/ui/vnc.h @@ -92,8 +92,8 @@ typedef void VncSendHextileTile(VncState *vs, #define VNC_DIRTY_BPL(x) (sizeof((x)->dirty) / VNC_MAX_HEIGHT * BITS_PER_B= YTE) =20 #define VNC_STAT_RECT 64 -#define VNC_STAT_COLS (VNC_MAX_WIDTH / VNC_STAT_RECT) -#define VNC_STAT_ROWS (VNC_MAX_HEIGHT / VNC_STAT_RECT) +#define VNC_STAT_COLS DIV_ROUND_UP(VNC_MAX_WIDTH, VNC_STAT_RECT) +#define VNC_STAT_ROWS DIV_ROUND_UP(VNC_MAX_HEIGHT, VNC_STAT_RECT) =20 #define VNC_AUTH_CHALLENGE_SIZE 16 =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380642; cv=none; d=zohomail.com; s=zohoarc; b=MBqswCzmwtiksGYGcH3c7c1KOILuSpl+DAkMn4/fgliVUX2sJ9oj3OYtYAXAGblGKS7KGnwBUxYJftxEHyxXLeDOXb1boAG769AL9YZCx5ZyIFg+poL+t+VGYknNUO0VsoA16xzhexg4KnImCsAQEnhiMXK4m1yhP+WLuIbaAho= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380642; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yMxLi8NsqGlqZ0Oh5Dt8wwze7Amab/pqNduBYqRThcY=; b=NlzSjFe9XnbND7BLjFuUb3ooTuz9sVFbTh17Ytlbye3Iq+tLJiBtgq5cRbgE84Ete/XtZIp/wrWriLo87AvWsLZ8EX+m5WaZhsuiNyH2fRb6fW3Mt5nXD2EGTr/OpfEvZq92HMlfOVkJycojVgU1sHs+aYEN4Rx01A9kmoXVgMA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380642846424.9965535404733; Sat, 13 Jun 2026 12:57:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQ3-0002AY-7h; Sat, 13 Jun 2026 15:53:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUP2-0000zu-VD; Sat, 13 Jun 2026 15:52:26 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUP1-0003eg-Cj; Sat, 13 Jun 2026 15:52:24 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D28DA1B6E1E; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 37BAC3CE898; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=P+ldOx6p71KK0pnrGMTU1XVvbDZ3R2F3PIPmQhI+G20=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=K/Pkjj9ImJb9FEtW2hWYxnS1A5MeTu1bn6hdNKSaMXYnc8orVEj6aqdolFcQNAHKS L0JFNG6U+dYbryv/BGheJM/zFf/DRAheR06/uxOyJJR+T0cF1sE7BnnVPv+aFLxqPT ejwZLV2cc/krczwJSW9oHAEQU4I1uH4rEL3eIboLFf8V69zutLQr2GErrw6Q7WOOT8 Jr46wyIm4CzmdU4zCc5HHDEQwnKoEg8Wh21RRKtRDyJYgma/XJcW/HG3CXrBSG0piY 9I//hYXf+UuAlgooft1Tloxbjon1SUZuIL7ZfNpZ4YIEHFpoGk9tCVZC6vfqxHudIJ qFC+0oUQBfCzg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-10.0.11 15/56] ui/vnc: fix OOB write in lossy rect worker code Date: Sat, 13 Jun 2026 22:50:29 +0300 Message-ID: <20260613195116.1807273-15-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380644934158500 From: Daniel P. Berrang=C3=A9 Incorrect calculation of the boundary condition when tracking lossy rectangles in the worker thread will result in an OOB write which can corrupt further worker state, and/or trigger any guard pages that may lie beyond the VncWorker struct. This can be triggered through careful choice of the display resolution in the guest OS by an unprivileged user. Fixes: CVE-2026-48002 Reported-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-4-berrange@redhat.com> [Marc-Andr=C3=A9 - added assert() suggest by philmd@linaro.org] Signed-off-by: Marc-Andr=C3=A9 Lureau (cherry picked from commit 46ee49034d26d04d95ba8f3183d4fbfa9d2b89b4) (Mjt: context fixup for 10.0.x) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.c b/ui/vnc.c index ff683ba196..faff26454b 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -2968,13 +2968,15 @@ void vnc_sent_lossy_rect(VncState *vs, int x, int y= , int w, int h) { int i, j; =20 - w =3D (x + w) / VNC_STAT_RECT; - h =3D (y + h) / VNC_STAT_RECT; + w =3D DIV_ROUND_UP((x + w), VNC_STAT_RECT); + h =3D DIV_ROUND_UP((y + h), VNC_STAT_RECT); + assert(h <=3D VNC_STAT_ROWS); + assert(w <=3D VNC_STAT_COLS); x /=3D VNC_STAT_RECT; y /=3D VNC_STAT_RECT; =20 - for (j =3D y; j <=3D h; j++) { - for (i =3D x; i <=3D w; i++) { + for (j =3D y; j < h; j++) { + for (i =3D x; i < w; i++) { vs->lossy_rect[j][i] =3D 1; } } --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380684; cv=none; d=zohomail.com; s=zohoarc; b=m7EqqK1jU0puCrp3axNCo8az42EB4JrvgSe1J4sFws6C+EfRqLjkl46dlRdMgNFg7+63Gz+VoTAlzpebGyKstLhOzP3vG7ws9q0Z3iNB+yQ98Oyj8OnNHIkklq9uzMXgzPT6YHELCzdNXBkCl4aZSK66nwYAlfVghyhBv1EFg4o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380684; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=I2/nCiIEv5M9I/xlFTpfa3Muzeyn1k13szci7EhOLIA=; b=nk3Ojoun4xG4rni85AbNOfiX7eTWkX+pAJOIdIeZrF1lOXnV7dOVQ5BbRjKromysWyMaS1cu7XQHUpUt8YVmioR3T2t6/mJ7rj7af/2mkClyTpNlhSS6NQjCQVw8SatzwACQ9Rq087+VfJhqf02d/IAj70q5od6BurH4nYa6hq0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380684525256.2488743529515; Sat, 13 Jun 2026 12:58:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQE-0002fr-Td; Sat, 13 Jun 2026 15:53:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUP4-00010D-Sb; Sat, 13 Jun 2026 15:52:27 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUP3-0003fA-8I; Sat, 13 Jun 2026 15:52:26 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E3CE11B6E1F; Sat, 13 Jun 2026 22:50:58 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 46F293CE899; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380258; bh=D0bF6O6cglu36bF7WpkWqpGneCZGlOEdqNmPnjCqDPI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=vA1O74ejIM9TDO2+w9Tb0u36ciQtZEQVm5ihic0uljewBppzZByv2nOgvZEiKP2Ni SDc6AsiUMP2UXhFGKzBO029eauNY3qsc1Mif+XNlSq4d7Hen4H2ex7N9EtUibnfFRp qUgij/txw8voX0TENGzx7ufaGmR0QhfOviWCiKwnz13lOU9cGY7WcB3IE3lxVssgpK NLxqZzUo5Yp6AdikK/4dajbe9WWhgUqoAuCi0nopgWGCL/qibiFKDlrzlIJCPzMkug XY4/zKXVbR+6lCLsHaBVI0E25KHEjjn8bNN3uU2pJOIJESj4/QsQ4hDCPStp43z4c3 fNytWAyUcrAXg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-10.0.11 16/56] ui/vnc: fix OOB read updating VNC update frequency stats Date: Sat, 13 Jun 2026 22:50:30 +0300 Message-ID: <20260613195116.1807273-16-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380684970158500 From: Daniel P. Berrang=C3=A9 Incorrect loop bounds in vnc_update_freq result in iterating past the last row and past the last column in the VNC stats array. With suitably chosen dimensions this could be a OOB read that accesses memory beyond the VncDisplay struct that the stats array is embedded in. Should this hit a guard page, it could trigger a guest crash. If it does not, then the VNC frequency stats will be updated with garbage. Fixes: CVE-2026-48003 Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-5-berrange@redhat.com> (cherry picked from commit d0c7b82d3a89dd9c863f8aa69b07360c648ca9fb) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.c b/ui/vnc.c index faff26454b..3760afe564 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -3078,12 +3078,14 @@ double vnc_update_freq(VncState *vs, int x, int y, = int w, int h) int i, j; double total =3D 0; int num =3D 0; + int x_end =3D x + w; + int y_end =3D y + h; =20 x =3D QEMU_ALIGN_DOWN(x, VNC_STAT_RECT); y =3D QEMU_ALIGN_DOWN(y, VNC_STAT_RECT); =20 - for (j =3D y; j <=3D y + h; j +=3D VNC_STAT_RECT) { - for (i =3D x; i <=3D x + w; i +=3D VNC_STAT_RECT) { + for (j =3D y; j < y_end; j +=3D VNC_STAT_RECT) { + for (i =3D x; i < x_end; i +=3D VNC_STAT_RECT) { total +=3D vnc_stat_rect(vs->vd, i, j)->freq; num++; } --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380454; cv=none; d=zohomail.com; s=zohoarc; b=bUsHskuFlxTJ2Us85IBfeCIWIIGcQCtd7WkUkjlppekvLG6me8hFsZnYtVcC6zMxIP02mljepsn0Wjf2mrs2q38o+EwNObAz2JOVu7kKx+KXuqsWfRZECWo/wccE3EYMQweFr7oRc7qZaCoD84OSmAyBXCm92KOksTIX+P1d2lM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380454; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rRgLOsAbB8mV5Z02gJ9i58QdSd5GSpfsC9YvYb5PuSc=; b=nlVMxjG6Isfz97ttnnbHIoSsAtrSM161ooRDgBKfhfnwtfDBupipkerdQ9vocBt+rSMNU5SgfcinLrKczCTRRAv0piZUNDGSb7vi8VKFw6+NYvNdINRjb4froLrW2HzT/PUuWzQ8E2NUUdj4W/F1g9tvnP9EQX4geE6E5TGdDuE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380454233997.5112436049958; Sat, 13 Jun 2026 12:54:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUPz-00028D-Gm; Sat, 13 Jun 2026 15:53:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPS-0001Oo-2z; Sat, 13 Jun 2026 15:52:52 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPO-0003fm-O7; Sat, 13 Jun 2026 15:52:49 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 037801B6E20; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 594113CE89A; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=DJZuAd6uoTybgvHP17Px/QZ+fzo7XTUkf9sXHlZo+24=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=udShxeUPr+yw3ciew10KLuYyP9yMRf7HGNUIqtV5w0jXf+sIpYcnh+QHhra2fT8r7 29tdugRP4m2iiZwoJf8b6j//09dwaANvdO3+swtDC/I3N5AmknTDglDKF+P3+YW5Rq 70AYiJaBesi9b+NlGBsymgMR06SEM00rCBaIyyUzV0mKVHWY9Lbc7llyWo7WuLdnbo X037zdSA3r3QC9HBfybnxrZtWtOm9PLaHEQxSHS5D6QCxz0e7h7Ev9HQBf8dZKIaSr 1syp8EwvU2M+9UrIjBjTuPKzEjGKhaR0G+Jebh2jlbHgpKwiCtWyfzvWwDppCbIkXn rR1zOQ553bFtQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Heechan Kang , Feifan Qian , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-10.0.11 17/56] ui: fix validation of VNC extended clipboard data length Date: Sat, 13 Jun 2026 22:50:31 +0300 Message-ID: <20260613195116.1807273-17-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380456352158500 From: Heechan Kang QEMU's VNC extended clipboard handler inflates a client-controlled compressed clipboard payload. The code checks the declared text size against the total inflated buffer size: if (tsize < size) but then copies from: tbuf =3D buf + 4; qemu_clipboard_set_data(..., tsize, tbuf, true); The correct bound is the remaining data length after the 4-byte length field, not the total inflated buffer length. As a result, a VNC client can make QEMU copy up to 3 bytes past the end of the inflated heap buffer. With a second VNC client, those copied bytes are observable through the normal VNC extended clipboard PROVIDE path. Fixes: CVE-2026-8343 Reported-by: Heechan Kang Reported-by: Feifan Qian Reviewed-by: Daniel P. Berrang=C3=A9 Signed-off-by: Heechan Kang [DB: added #include and 'return' statements] Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260512095543.459949-1-berrange@redhat.com> (cherry picked from commit e56b4bbff1df260487b80abe1f967f687fa115d3) Signed-off-by: Michael Tokarev diff --git a/ui/vnc-clipboard.c b/ui/vnc-clipboard.c index 124b6fbd9c..fa05d86f42 100644 --- a/ui/vnc-clipboard.c +++ b/ui/vnc-clipboard.c @@ -23,6 +23,7 @@ */ =20 #include "qemu/osdep.h" +#include "qemu/error-report.h" #include "vnc.h" #include "vnc-jobs.h" =20 @@ -282,10 +283,16 @@ void vnc_client_cut_text_ext(VncState *vs, int32_t le= n, uint32_t flags, uint8_t buf && size >=3D 4) { uint32_t tsize =3D read_u32(buf, 0); uint8_t *tbuf =3D buf + 4; - if (tsize < size) { + if (tsize <=3D size - 4) { qemu_clipboard_set_data(&vs->cbpeer, vs->cbinfo, QEMU_CLIPBOARD_TYPE_TEXT, tsize, tbuf, true); + } else { + error_report("vnc: malformed extended clipboard payload " + "with text length %u exceeding available %u", + tsize, size - 4); + vnc_client_error(vs); + return; } } } --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380471; cv=none; d=zohomail.com; s=zohoarc; b=L7q2f9cd1uRFBEex1yuWq9nvOKbvu1KlmaX41PpsVKDxKXNRx56sIHZgTCEMbO4+dISCaM9R1N1oGZLqDy9cbm2ws11/gPLw1RkK6c8zek/4NGsTjGfjEhz+4m2hf35ewEkD7NiO9LYFbcUPTup+7ia3JJJv5EW2ffn0Z2YDK0U= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380471; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GlzjN0fgyw8wMjWT5mzrd10VSxOL0iJx2joRl0GaqA0=; b=D365qDESS6NLh0MlcQpD5UDPguWcKCAtD4N+pOpCjw8A+NlWatZXXmbqGfJeDfPUXuHm8ngH0mrK6/nt/xTrVBerSzNAG3b+i0ams9GzMR9OSpbBcRqzFbPa/2qxKq47IDkFCc2M4f6VQcUc79nV/jmL2USpMp81sGeqXUuWnbE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380471205637.0962757674762; Sat, 13 Jun 2026 12:54:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQC-0002Me-Po; Sat, 13 Jun 2026 15:53:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPS-0001P1-DE; Sat, 13 Jun 2026 15:52:52 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPQ-0003gT-OY; Sat, 13 Jun 2026 15:52:50 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 1377B1B6E21; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6C7B13CE89B; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=jRU+UtsBhamW6RptAMMY9hyEox4Us69tOuIZJ51dTHU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=oeklgcbi38l8Yr7uc7zhjIlAAWfRqBLDz8YrlEANzkuRDLnDiAM6YAnmXrm9mn97k k9LfCAH3pvDmD6IVHkpeZEQGPUQ3MEi2Nz+iD+0mCEK1uZM4kpDTAQguuYOXCiyEQm 3iHcx2v/zb+nSKkoxmAfCoWntmbi9rjNk7m+3DK6gJ+NkqEwKrjV9V2OBQQrj5ykKX JGbnQnY5lE5xw3+LaI6+JKRR75oeyYpHwM9X398j7XtNTaqRNOcf5kKUrtmXpnXCIg EDrvtg/NQ40DHKDnDW9A0Fc8U6VgvGTEzCFb4iyhzSM4nYW67o7KjP9yXkO/nmJ+Ek /x70aQggzYOAQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Wei Che Kao , Michael Tokarev Subject: [Stable-10.0.11 18/56] lsi53c895a: fix use-after-free of cancelled request Date: Sat, 13 Jun 2026 22:50:32 +0300 Message-ID: <20260613195116.1807273-18-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380472274158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini When processing the Message Out phase, the lsi53c895a controller can cancel a request and the continue by processing more messages. When this happens, it is important that a cancelled request is not processed further, because scsi_req_cancel can cause the request to be freed. Right now this is happening in two cases, but not when cancelling the entire queue of requests after an ABORT, CLEAR QUEUE or BUS DEVICE RESET message. In that case, a subsequent ABORT TAG message can use a dangling current_req. There are three possible fixes: - add a missing check inside the loop, clearing current_req if p->req =3D=3D current_req. This is obvious but complicates the code inside the foreach loop. - change the conditional prior to the loop from "if (s->current)" to "if (current_req)". This would work, because s->current !=3D NULL implies current_req !=3D NULL, and would clear current_req correctly. However it is less obvious because the point of the code is to clear the entire queue, which consists of s->current and s->queue; current_req is not special here. - delay the retrieval of current_req until an ABORT TAG message is seen. This is the most correct option, because the SCSI protocol only deals with tags; requests are a QEMU concept that only makes sense for the purpose of calling into the SCSI layer. Reported-by: Wei Che Kao Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 5297a0fc65317ba7f79ef44ce7a44e41d15fdb27) Signed-off-by: Michael Tokarev diff --git a/hw/scsi/lsi53c895a.c b/hw/scsi/lsi53c895a.c index c845e0bee7..25fe437af1 100644 --- a/hw/scsi/lsi53c895a.c +++ b/hw/scsi/lsi53c895a.c @@ -1000,10 +1000,8 @@ static void lsi_do_msgout(LSIState *s) =20 if (s->current) { current_tag =3D s->current->tag; - current_req =3D s->current; } else { current_tag =3D s->select_tag; - current_req =3D lsi_find_by_tag(s, current_tag); } =20 trace_lsi_do_msgout(s->dbc); @@ -1058,9 +1056,13 @@ static void lsi_do_msgout(LSIState *s) case 0x0d: /* The ABORT TAG message clears the current I/O process only. = */ trace_lsi_do_msgout_abort(current_tag); + if (s->current) { + current_req =3D s->current; + } else { + current_req =3D lsi_find_by_tag(s, current_tag); + } if (current_req && current_req->req) { scsi_req_cancel(current_req->req); - current_req =3D NULL; } lsi_disconnect(s); break; @@ -1086,7 +1088,6 @@ static void lsi_do_msgout(LSIState *s) /* clear the current I/O process */ if (s->current) { scsi_req_cancel(s->current->req); - current_req =3D NULL; } =20 /* As the current implemented devices scsi_disk and scsi_gener= ic --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380794; cv=none; d=zohomail.com; s=zohoarc; b=M6r+41vwb9d3a7bV5AguGRncOUR7EepT26UhGTj0M/Jh2Jlf4ghVH2wnuVDyVOZaFUZjsH/Mue3aFMgH9tvWnD3cciLdmjFHEWeXg8bUNnnsDqv/MYV3EYkECgyHMjODFj2EJM4cGPiCNPn/eX0A0Z7bKeq0clt7Nw4/9ZLLrp4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380794; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Wo4JObaoqjG0G0P6OtSWb9bGCwAvlNza0jI4AOPCp0s=; b=anhiOvyfFJGnUfqcuK8HH090kCWVCOaytTr4rX5B1LZ2xhsAcowqp09BP/Ilge/EtWZO4bTOZn6kdcRbZpZOAVb3jwsb766t226HVIi2xBSJuefwgRDihvOgNHKyxcBdQXbG02M2psOz3rc1++uPKwypKpGq2ViIZVJGlWvkSZg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380794809489.1179253554543; Sat, 13 Jun 2026 12:59:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQI-0003GF-9l; Sat, 13 Jun 2026 15:53:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPV-0001QS-R3; Sat, 13 Jun 2026 15:52:54 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPT-0003o9-QF; Sat, 13 Jun 2026 15:52:53 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 2176E1B6E22; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7C3413CE89C; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=bNS+nLKNNLdtQaRNwsaiylm8WhpGpZ6VoY+X4/dTKI8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=saHZdreXvValSMLbCSnPQyr07KOId4bf+PhdyVhHG7RbdszpKk2hXGOKPL6Lssjlf 2PhvPCC/SzXUGqOGT/K7w9we9PB0ivBmJmVa3BLy6Fd4dWxXcFrXK1aknF3OILAnU6 lomKlixSPo1t5qTeHnRU4tuQnIKlkLA07kSnqNyCw41VSkxu52czogZhbXzJIFIrP9 8IdFn1iG21kRytY6l94bDDXkeg6dxiilK4kcsTvyokYBfMZ52lUoys+84qDzgctU/z yaFSsm2ADUIaQZhg03V3YXf8HGlGQXh6DvWUNqv/7anfno4CsvImXlhK4Bc+7NSj4A oqn4eB1TPP/zw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Michael Tokarev Subject: [Stable-10.0.11 19/56] lsi53c895a: clear tag byte when processing messages Date: Sat, 13 Jun 2026 22:50:33 +0300 Message-ID: <20260613195116.1807273-19-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380795369158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini Instead of simply ORing the message byte, clear what was there before. Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 4494dec8c2bfd8a5d9b1eabe4a26ab850a4f6700) Signed-off-by: Michael Tokarev diff --git a/hw/scsi/lsi53c895a.c b/hw/scsi/lsi53c895a.c index 25fe437af1..58042140c4 100644 --- a/hw/scsi/lsi53c895a.c +++ b/hw/scsi/lsi53c895a.c @@ -1041,16 +1041,19 @@ static void lsi_do_msgout(LSIState *s) } break; case 0x20: /* SIMPLE queue */ + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; trace_lsi_do_msgout_simplequeue(s->select_tag & 0xff); break; case 0x21: /* HEAD of queue */ qemu_log_mask(LOG_UNIMP, "lsi_scsi: HEAD queue not implemented= \n"); + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; break; case 0x22: /* ORDERED queue */ qemu_log_mask(LOG_UNIMP, "lsi_scsi: ORDERED queue not implemented\n"); + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; break; case 0x0d: --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380488; cv=none; d=zohomail.com; s=zohoarc; b=QZdCcY4/7fk6mMiUsoEuG153y2jwIxf68ZJYi+3ROxk87wl13v9KXmOntn1uwXXjPLVKcj/sxrHO15/n0BFKmmJm/RTnRNuTzDzPZMQqgbbYV0MiXSeUc909qYX5/nJpPOnqsL9I0UbnxDJYbzAGEXQSWEE5kePVLr/x9ssml6s= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380488; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gDvhNHthRKdoi0uKqFkiTNmiMHHGX6K8tQ3e5Yg9z8o=; b=Pzib95YjKN64pCtX23tLYk48ZqX0OOQStiVJAicppb59HouY9wYW/qBgk26XPcQ388iWqCyG79P1E0UmVlTTVKteMYtDB1wnO5SW+uLMRmesJpNpnhPC1ZD3QdyLRyQG/0cUiz1fxXCuxZhU7Rc90ap3Bxi73/ktiStkPaHfJQg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380488564325.3584665934544; Sat, 13 Jun 2026 12:54:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQJ-0003T4-GT; Sat, 13 Jun 2026 15:53:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPX-0001Uw-7D; Sat, 13 Jun 2026 15:52:58 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPU-0003oK-7a; Sat, 13 Jun 2026 15:52:54 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 311BE1B6E23; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 89EAA3CE89D; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=9cd+qIqqRsoqAEtIChB5CVkGwSasCRBjXO/60eZXsRQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=gI8f/Ph7AEMQGxKIPLr/bJjR3+LRnxoUHtrPjiKA7whu54NHiIU0D+cnzSyALyxYj F+FUg2Gph3qMHOsAinMXaMJ53Z+yh5OSFl8Atv+BSINm4YIte1AD5I3egI3QhEoZIU jGJOCb9qOz7/LmmugDzmJ2+5mGoD/2d08nsj4Jqa7R4J6+Nw0bx5G6HR+udegg/I0h gsr/JFDpU4Wj2I1xLvrsnBkwzNhDBc/cuttKoiXdfu0gGVHPuBiEPTYV0B9BCVAg5+ 6MMl7doExxPE1c8WsPV1hgfkgWVMy9r9aRDa/BcPPilLUBZruWDHW5T9kxYExyUUxB FRG3VbsyXdNtg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Wei Che Kao , Michael Tokarev Subject: [Stable-10.0.11 20/56] apic: fix delivery bitmask with modified xAPIC ids Date: Sat, 13 Jun 2026 22:50:34 +0300 Message-ID: <20260613195116.1807273-20-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380490274158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini Self-IPIs (or all-but-self IPIs) in QEMU can cause a out-of-bounds access to deliver_bitmask, because the access uses the APIC ID register which is writable by the guest. However, foreach_apic uses the delivery bitmask indexes to look up the local_apics[] array, which is indexed by *initial* APIC id. Using the right id fixes both a possible heap write overflow if the modified APIC id is too large for max_apic_words, and a mis-delivery of both self and all-but-self IPIs. Reported-by: Wei Che Kao Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 153dc2fa7bbe0491290d22c4bbb6807074f24260) (Mjt: fixup for 10.0.x) Signed-off-by: Michael Tokarev diff --git a/hw/intc/apic.c b/hw/intc/apic.c index b2a2b671b0..108fde5d5f 100644 --- a/hw/intc/apic.c +++ b/hw/intc/apic.c @@ -659,13 +659,6 @@ static void apic_deliver(DeviceState *dev, uint32_t de= st, uint8_t dest_mode, APICCommonState *apic_iter; uint32_t deliver_bitmask_size =3D max_apic_words * sizeof(uint32_t); g_autofree uint32_t *deliver_bitmask =3D g_new(uint32_t, max_apic_word= s); - uint32_t current_apic_id; - - if (is_x2apic_mode(dev)) { - current_apic_id =3D s->initial_apic_id; - } else { - current_apic_id =3D s->id; - } =20 switch (dest_shorthand) { case 0: @@ -673,14 +666,20 @@ static void apic_deliver(DeviceState *dev, uint32_t d= est, uint8_t dest_mode, break; case 1: memset(deliver_bitmask, 0x00, deliver_bitmask_size); - apic_set_bit(deliver_bitmask, current_apic_id); + /* + * The self and all-but-self cases do not use apic_match_dest() and + * directly fill in deliver_bitmask; the bitmask's indexes in turn + * map to local_apics[] slots which are never changed even if the + * xAPIC id is modified. So use s->initial_apic_id instead of s->= id. + */ + apic_set_bit(deliver_bitmask, s->initial_apic_id); break; case 2: memset(deliver_bitmask, 0xff, deliver_bitmask_size); break; case 3: memset(deliver_bitmask, 0xff, deliver_bitmask_size); - apic_reset_bit(deliver_bitmask, current_apic_id); + apic_reset_bit(deliver_bitmask, s->initial_apic_id); break; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380452; cv=none; d=zohomail.com; s=zohoarc; b=MChhsjCQJdY2JIR0+31IXiY7aAElyBGl6Adi9MMMCoaqNvGiEKwBwdLQxAfVEJ/Uqp97rg9TMVuWehxuik4yG6c5aLA84mFn4zleywFxVfUb0siUmogyUD6F473EnaWS5GSsBuscw8FXpp6x5pOixQVZaPwomwI4Uapaisj7Xz4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380452; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=jJtI2F6nsL7KL1q+AAqkaMx1EiUkgjx8TMdV3otgzzc=; b=Ws43PwNNsMmzN6kgMpFSIGDmuBt6yT4pt0CtvewnsE73CbMHaCuDC2kwxO3ghNS9dsFLZ+PkZHIp0yFJUMGeKhr4g1Z8E9gNKu9DrS46tO5F/wwNnK/odsFZiGYuKD8z4NBkbCLHQXby9V2KmCfs7kKBtf6CmUeecwbv4xoo6x8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380452408304.8210875172515; Sat, 13 Jun 2026 12:54:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQC-0002Jp-P6; Sat, 13 Jun 2026 15:53:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPZ-0001YF-HA; Sat, 13 Jun 2026 15:52:59 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPX-0003pC-Lr; Sat, 13 Jun 2026 15:52:57 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 419D51B6E24; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9A6C53CE89E; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=A7M3pKHlxT7cnq9vreXDZlVxJ1EGoHd1EvfuOA4VJR8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=pK50vCNO7h4N9ph0sfF49G4itqiyVFncSbkLrW8ZkaHgOS7McOuGGALhxsnq2ePxY 35q0QZRQOH6rLIlrpGy5g0jGXr6U/yjwoDJabchsK7vx7iGAKwAEGkZgMVNWShXze1 9WCU5XZq459mo1wl2lGOyQ8Nes+GquA9Y8JsUlbRrrV1TicDGj97zdCWmuX30tVCVx hFWwmuwr5pKniZ9hUhHimct66MRydFiy5wvLHco1hoLlGFvYuOiySBdxCKYVHGuihK AHWLGTWflFBm7X6ec9mYg7FTGRU3AOtMU8EoXu06Ogijg0z4F6zRlD0V++vqQPOXVu VQQ6Wrsw1B4hA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Jinjie Ruan , Paolo Bonzini , Michael Tokarev Subject: [Stable-10.0.11 21/56] mc146818rtc: Fix get_guest_rtc_ns() overflow bug Date: Sat, 13 Jun 2026 22:50:35 +0300 Message-ID: <20260613195116.1807273-21-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380454139158501 Content-Type: text/plain; charset="utf-8" From: Jinjie Ruan In get_guest_rtc_ns(), "s->base_rtc" is uint64_t, which multiplied by "NANOSECONDS_PER_SECOND" may overflow the uint64_t type, which will cause the QEMU Linux Virtual Machine's RTC time to jump and in turn triggers a kernel Soft Lockup and ultimately leads to a crash. Fix it by avoiding adding s->base_rtc in get_guest_rtc_ns_offset(), because get_guest_rtc_ns() is used either take the remainder of NANOSECONDS_PER_SECOND or take the quotient of NANOSECONDS_PER_SECOND. Fixes: 56038ef6234e ("RTC: Update the RTC clock only when reading it") Signed-off-by: Jinjie Ruan Link: https://lore.kernel.org/r/20260114013257.3500578-1-ruanjinjie@huawei.= com Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 4b6c088c88ccc9e7cafc72759c99742b3993f9f7) Signed-off-by: Michael Tokarev diff --git a/hw/rtc/mc146818rtc.c b/hw/rtc/mc146818rtc.c index e322fc2ffb..0bb4a6ccca 100644 --- a/hw/rtc/mc146818rtc.c +++ b/hw/rtc/mc146818rtc.c @@ -83,12 +83,13 @@ static inline bool rtc_running(MC146818RtcState *s) (s->cmos_data[RTC_REG_A] & 0x70) <=3D 0x20); } =20 -static uint64_t get_guest_rtc_ns(MC146818RtcState *s) +/* + * Note: get_rtc_ns_since_last_update() does not include the base_rtc seco= nds + * value. This does not matter if the caller only needs the nanoseconds p= art. + */ +static uint64_t get_rtc_ns_since_last_update(MC146818RtcState *s) { - uint64_t guest_clock =3D qemu_clock_get_ns(rtc_clock); - - return s->base_rtc * NANOSECONDS_PER_SECOND + - guest_clock - s->last_update + s->offset; + return qemu_clock_get_ns(rtc_clock) - s->last_update + s->offset; } =20 static void rtc_coalesced_timer_update(MC146818RtcState *s) @@ -264,7 +265,7 @@ static void check_update_timer(MC146818RtcState *s) return; } =20 - guest_nsec =3D get_guest_rtc_ns(s) % NANOSECONDS_PER_SECOND; + guest_nsec =3D get_rtc_ns_since_last_update(s) % NANOSECONDS_PER_SECON= D; next_update_time =3D qemu_clock_get_ns(rtc_clock) + NANOSECONDS_PER_SECOND - guest_nsec; =20 @@ -517,7 +518,7 @@ static void cmos_ioport_write(void *opaque, hwaddr addr, /* if disabling set mode, update the time */ if ((s->cmos_data[RTC_REG_B] & REG_B_SET) && (s->cmos_data[RTC_REG_A] & 0x70) <=3D 0x20) { - s->offset =3D get_guest_rtc_ns(s) % NANOSECONDS_PER_SE= COND; + s->offset =3D get_rtc_ns_since_last_update(s) % NANOSE= CONDS_PER_SECOND; rtc_set_time(s); } } @@ -630,10 +631,8 @@ static void rtc_update_time(MC146818RtcState *s) { struct tm ret; time_t guest_sec; - int64_t guest_nsec; =20 - guest_nsec =3D get_guest_rtc_ns(s); - guest_sec =3D guest_nsec / NANOSECONDS_PER_SECOND; + guest_sec =3D s->base_rtc + get_rtc_ns_since_last_update(s) / NANOSECO= NDS_PER_SECOND; gmtime_r(&guest_sec, &ret); =20 /* Is SET flag of Register B disabled? */ @@ -644,7 +643,7 @@ static void rtc_update_time(MC146818RtcState *s) =20 static int update_in_progress(MC146818RtcState *s) { - int64_t guest_nsec; + uint64_t guest_nsec; =20 if (!rtc_running(s)) { return 0; @@ -659,7 +658,7 @@ static int update_in_progress(MC146818RtcState *s) } } =20 - guest_nsec =3D get_guest_rtc_ns(s); + guest_nsec =3D get_rtc_ns_since_last_update(s); /* UIP bit will be set at last 244us of every second. */ if ((guest_nsec % NANOSECONDS_PER_SECOND) >=3D (NANOSECONDS_PER_SECOND - UIP_HOLD_LENGTH)) { --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380613; cv=none; d=zohomail.com; s=zohoarc; b=U9M+XR6jo9YDkfUQgItYsYfIuF4aTNzWBNiuqL7V/zRz+CKFr1HXWgAQv0+rWCfNjodtjqqZySZu9WVs7odU9CcQt3LCx/yRbWrdUWdS9kXY+rdaEgx7Lq3UWIi/vfxobizyy+AXcCwctp0mkprL5cJ0Uwk+ntXyD3uvUmeKxwA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380613; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=oZBG35/RdLdAE9byPdPB52mSVEnxvcdb/z0m+t+UjAw=; b=Hik9EamJKAvujnATVEikxDFwj8UCvIRCvEHvS8QsVOUu8p8Wf3ym4GDl70dl+qasb4THtBJ8z0z0iDZYW2YCc3pxVDxTyGFPu2IRcpPeeKMlbHme4n8Wznjn22Y168xPa1jU373pNRe07vJj9A1Q2cE4kE2iR+3XtkURGMtOHfs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380613874186.08692214045482; Sat, 13 Jun 2026 12:56:53 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQL-0003Xb-Cp; Sat, 13 Jun 2026 15:53:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPu-00022a-Um; Sat, 13 Jun 2026 15:53:19 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPt-0003pi-4H; Sat, 13 Jun 2026 15:53:18 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 56ED01B6E25; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id AAB4E3CE89F; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=IpFa7+QIKU+aijfHMlQQl7oLLzt0xPJpnWQaAj6Kelg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=smrCWrTmiwC6y0Dy26D8dqP0sAXSa5kkcK1j9cQIRxj8RjqoW/VW387hgFJ83adyQ dJR1n6XF44LOkO6P+PlkqWue+wbzHjGM+9v469nbhcAOqplk+pYQmLHotVW68U47jN sExuxveJ6TjC3voNETT1godTFJDZs+s6kou6EZAj86RXrQB9bxGFjhOzNYxBvdlsWE ISnwC4tEyzzoxenLb26L91Iqkse2ITo5zymbpIrtQiMM/VzkNwCTEzUASQwCCf3naS 0RVzM/SwU4OLuKbFO3GAIOjJWPo0YYru0YUpaZsrHm02Nu0u/PhkOkvX9uQsIw00oT yrYLJ/0CkdDXQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Kevin Wolf , Hanna Reitz , Stefan Hajnoczi , Paolo Bonzini , Michael Tokarev Subject: [Stable-10.0.11 22/56] block/linux-aio: bound ioq_submit() recursion depth Date: Sat, 13 Jun 2026 22:50:36 +0300 Message-ID: <20260613195116.1807273-22-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380614814158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" qemu_laio_process_completions() wraps its body in defer_call_begin / defer_call_end. Inside the section, completion callbacks wake coroutines that queue new aiocbs; laio_do_submit() defers laio_deferred_fn. At the bottom of qemu_laio_process_completions() the defer_call_end() fires laio_deferred_fn, which calls ioq_submit(), closing the cycle: ioq_submit -> io_submit(2) // some sync completions -> qemu_laio_process_completions // defer_call_begin -> aio_co_wake // resumes coroutine -> laio_do_submit -> defer_call(laio_deferred_fn, s) // enqueued -> defer_call_end // nesting drops to 0 -> laio_deferred_fn -> ioq_submit // +1 stack frame, loop When io_submit(2) returns asynchronously (O_DIRECT) the cycle terminates in one extra frame: the fresh aiocb is still in flight, no completion is drained, no coroutine wakes, no new submission queues. When submissions complete synchronously (non-O_DIRECT, or per-descriptor drivers such as vmdk) each level enqueues more work for the next defer_call_end() to drain, so recursion grows without bound and QEMU crashes with SIGSEGV on the thread guard page. The cycle was closed by two performance commits, each correct in isolation: 076682885d ("block/linux-aio: convert to blk_io_plug_call() API") -- introduced laio_deferred_fn and wired laio_do_submit -> defer_call(laio_deferred_fn, s). 84d61e5f36 ("virtio: use defer_call() in virtio_irqfd_notify()") -- added defer_call_begin/end around qemu_laio_process_completions so virtio-irqfd notifications batch across a completion pass. The supported aio=3Dnative + cache=3Dnone pairing keeps submissions asynchronous, so the cycle stays bounded; nothing in the code enforces that contract. Observed in production as a SIGSEGV during a backup job configured with --cached + aio=3Dnative; reproducible on upstream with qemu-io against vmdk. Cap ioq_submit() recursion with a counter on LaioQueue, which is only accessed from the AioContext home thread. On overflow, return without submitting. The pending work is drained by s->completion_bh, which qemu_laio_process_completions() has already scheduled on entry -- no work is lost; one event-loop round-trip of latency is paid only when the bound is hit, which cannot happen on a supported configuration. Signed-off-by: Denis V. Lunev CC: Kevin Wolf CC: Hanna Reitz CC: Stefan Hajnoczi CC: Paolo Bonzini Message-ID: <20260520142503.251959-2-den@openvz.org> Signed-off-by: Stefan Hajnoczi (cherry picked from commit 6864bec553b2e37699739615e604fc3c7bae0e1d) Signed-off-by: Michael Tokarev diff --git a/block/linux-aio.c b/block/linux-aio.c index d0f9bc389a..880549786d 100644 --- a/block/linux-aio.c +++ b/block/linux-aio.c @@ -36,6 +36,19 @@ /* Maximum number of requests in a batch. (default value) */ #define DEFAULT_MAX_BATCH 32 =20 +/* + * Bound on how deep ioq_submit() may recurse on a single LaioQueue via the + * ioq_submit -> qemu_laio_process_completions -> defer_call_end -> + * laio_deferred_fn -> ioq_submit cycle. The cycle terminates naturally + * when io_submit(2) returns asynchronously (O_DIRECT), but can grow + * without bound when submissions complete synchronously. On overflow + * the caller returns without submitting; the outermost + * qemu_laio_process_completions() has already scheduled s->completion_bh + * (via qemu_bh_schedule() at the top of that function), which resumes + * submission from the next event-loop dispatch. + */ +#define IOQ_SUBMIT_MAX_DEPTH 8 + struct qemu_laiocb { Coroutine *co; LinuxAioState *ctx; @@ -61,6 +74,7 @@ typedef struct { unsigned int in_queue; unsigned int in_flight; bool blocked; + unsigned int submit_depth; QSIMPLEQ_HEAD(, qemu_laiocb) pending; } LaioQueue; =20 @@ -331,6 +345,7 @@ static void ioq_init(LaioQueue *io_q) io_q->in_queue =3D 0; io_q->in_flight =3D 0; io_q->blocked =3D false; + io_q->submit_depth =3D 0; } =20 static void ioq_submit(LinuxAioState *s) @@ -340,6 +355,11 @@ static void ioq_submit(LinuxAioState *s) struct iocb *iocbs[MAX_EVENTS]; QSIMPLEQ_HEAD(, qemu_laiocb) completed; =20 + if (s->io_q.submit_depth >=3D IOQ_SUBMIT_MAX_DEPTH) { + return; + } + s->io_q.submit_depth++; + do { if (s->io_q.in_flight >=3D MAX_EVENTS) { break; @@ -385,6 +405,8 @@ static void ioq_submit(LinuxAioState *s) * pended requests will be submitted from there. */ } + + s->io_q.submit_depth--; } =20 static uint64_t laio_max_batch(LinuxAioState *s, uint64_t dev_max_batch) --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380739; cv=none; d=zohomail.com; s=zohoarc; b=b5oOy+z/mXu9uHUqHXK77Dbd1j9F1M93eAW34NEGPw8c7lwCg6BdLf5AaFYMkU9JCL0CYDbTXNDbv/lCnyKDCJz/4e67v05pooI4DOePVc1B8ha2QnqeuFVgqsW/HxWTfPuF07cwdU9+8HSsMISplxLweGSQgOX1ecZxh6v3x+w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380739; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yksATrbC4veFodMPLqykKTFHHBRL3X2dzZi0VitoMPE=; b=kXdivlyoOf6Pn2tPJyW0VUNSx17w+l83ixGJ/PP7445GU0IHclazka1lpZyBvlT3LHFFGNasY6D9GNxWsv0gxmq1k3zqMCToHlXKPcLTHtKZasKrQwXuSRhEZIjzxYS7Rj6gjmyAHhSKjBzfsop1nVfzpblJLfB3GyE8yeotWr4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380739645296.7494235731011; Sat, 13 Jun 2026 12:58:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQM-0003aR-LP; Sat, 13 Jun 2026 15:53:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPx-00028H-5r; Sat, 13 Jun 2026 15:53:22 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPv-0003qD-Ch; Sat, 13 Jun 2026 15:53:20 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 66CB41B6E26; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id BFE433CE8A0; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=WrtPf0nfxyN23GhsGSLuduvp38PumZWYYytwYcp1rys=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=h5SF2Au/cHvBuAsbAArgLkcE/yGH64K1dILZA5lAytigwgqB6JxATiEAZhLLFiTHZ EhaL/DYr1g9mIJ0AOWGbd4YVkZ4pugAs2rjMbHD6EHUCzEdjkqGMcHxOrRUNlwf2U8 IdppTpO4B994nBSZzm1FuRUelGatMXrAVdIEXqsSShk1n9+ydoN+nsbbifSbjU/wu9 8akzm4QjzFVaaHIZva4KP5LsIcjs1GytMhi8VCrd4Dp9in+MC0t+xc/vl/lE9yxtyd U0uEes8eyc1kvAjSJ9Bupu/vn6YEUTfYcjGiR+jlSbPaPqnOPJ/utzpEYCGwI72yLx CCboa6qj+LgtA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Michael Tokarev Subject: [Stable-10.0.11 23/56] target/arm: SVE2 FMAXP, FMINP must honour AH=1 Date: Sat, 13 Jun 2026 22:50:37 +0300 Message-ID: <20260613195116.1807273-23-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380741159158500 From: Peter Maydell The behaviour of floating-point maximum and minimum insns has some odd special cases when FPCR.AH=3D1. We get this right in most places (for instance, the ASIMD FMAXP, FMINP) but forgot about it for the SVE2 versions of FMAXP and FMINP. Cc: qemu-stable@nongnu.org Fixes: 384433e70983 ("target/arm: Implement FPCR.AH semantics for FMINP and= FMAXP") Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Message-id: 20260521122913.1565011-2-peter.maydell@linaro.org (cherry picked from commit 446050c4dfe4566ae3fcba9c6588c89a66ed4b33) (Mjt: fixup for lack of v10.2.0-1344-g895d4367d6 "target/arm/tcg: Use "or SME" feature checks where needed") Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/helper-sve.h b/target/arm/tcg/helper-sve.h index 0b1b588783..45ad81938e 100644 --- a/target/arm/tcg/helper-sve.h +++ b/target/arm/tcg/helper-sve.h @@ -2736,6 +2736,20 @@ DEF_HELPER_FLAGS_6(sve2_fminp_zpzz_s, TCG_CALL_NO_RW= G, DEF_HELPER_FLAGS_6(sve2_fminp_zpzz_d, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, fpst, i32) =20 +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_h, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_s, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_d, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) + +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_h, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_s, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_d, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) + DEF_HELPER_FLAGS_5(sve2_eor3, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, i= 32) DEF_HELPER_FLAGS_5(sve2_bcax, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, i= 32) DEF_HELPER_FLAGS_5(sve2_bsl1n, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, = i32) diff --git a/target/arm/tcg/sve_helper.c b/target/arm/tcg/sve_helper.c index d786b4b111..20accbc568 100644 --- a/target/arm/tcg/sve_helper.c +++ b/target/arm/tcg/sve_helper.c @@ -775,6 +775,14 @@ DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_h, float16, H1_2, floa= t16_min) DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_s, float32, H1_4, float32_min) DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_d, float64, H1_8, float64_min) =20 +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_h, float16, H1_2, helper_vfp_ah_maxh) +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_s, float32, H1_4, helper_vfp_ah_maxs) +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_d, float64, H1_8, helper_vfp_ah_maxd) + +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_h, float16, H1_2, helper_vfp_ah_minh) +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_s, float32, H1_4, helper_vfp_ah_mins) +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_d, float64, H1_8, helper_vfp_ah_mind) + #undef DO_ZPZZ_PAIR_FP =20 /* Three-operand expander, controlled by a predicate, in which the diff --git a/target/arm/tcg/translate-sve.c b/target/arm/tcg/translate-sve.c index 81616210aa..810c44b007 100644 --- a/target/arm/tcg/translate-sve.c +++ b/target/arm/tcg/translate-sve.c @@ -7022,8 +7022,8 @@ TRANS_FEAT_NONSTREAMING(HISTSEG, aa64_sve2, gen_gvec_= ool_arg_zzz, DO_ZPZZ_FP(FADDP, aa64_sve2, sve2_faddp_zpzz) DO_ZPZZ_FP(FMAXNMP, aa64_sve2, sve2_fmaxnmp_zpzz) DO_ZPZZ_FP(FMINNMP, aa64_sve2, sve2_fminnmp_zpzz) -DO_ZPZZ_FP(FMAXP, aa64_sve2, sve2_fmaxp_zpzz) -DO_ZPZZ_FP(FMINP, aa64_sve2, sve2_fminp_zpzz) +DO_ZPZZ_AH_FP(FMAXP, aa64_sve2, sve2_fmaxp_zpzz, sve2_ah_fmaxp_zpzz) +DO_ZPZZ_AH_FP(FMINP, aa64_sve2, sve2_fminp_zpzz, sve2_ah_fminp_zpzz) =20 /* * SVE Integer Multiply-Add (unpredicated) --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380786; cv=none; d=zohomail.com; s=zohoarc; b=a7PjQWsd5keOJ6aBAwwE1oGU1WQCX4XuLftGx+kgS9RhRLhL+jQ/EUZfcV1GnsB/KlOmbO/Jr5S1noN+9aIfJ6pt2WXu9nuYEw+apPKlxO1znsizCDanbXXNFs/Kwv/FeNrBeua/NSwb6jpGjYwVzoQ0rOwOBzz0mqjtiRHPKgU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380786; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=nya9fZQ6Mrcg+rYW5/K/G49Bbuo21YVtwaRX8iwKMWw=; b=LhidezncTy4qiVX9jIUPf3ynUpVuaEwr9cV+kCqlqUdxiEUwN01OLPlH0+fpXqLTz5ncP3uDO9r4umCIssO6aRdRef/InIimGb/9gu+DR8rdLyCUBySzM6iOCtdfbxeh0XHwpkW2XCjjxTakHl66QcuZlGAD/9BbHjOXbs/pxVg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380786777938.4544551538155; Sat, 13 Jun 2026 12:59:46 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQN-0003cK-Ua; Sat, 13 Jun 2026 15:53:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPy-00029a-De; Sat, 13 Jun 2026 15:53:23 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPw-0003x5-PP; Sat, 13 Jun 2026 15:53:22 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 77CF21B6E27; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id CF5063CE8A1; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=5t/3H5LYyaNQBI24gmPG2z2g7fM9f7Xz9Y439WAHR+8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=QB2HmIZBcNZGvHsw4B/fMyi1eskGCLbBOKbHFQ69i2QYcZlyB/9QbrJ2DBme9sk7W cSFW8S16KAERkyDEUXEBQ/m4uHpKTozvkAfBEVEbt717SY3cxOonBcl6YMRgGDy6AU 8U9yj7Q8tQcOjM/RG1xLF/7hGeXzISbQTJH5MPaLTg2auLYfaYRov1J0+0WjZXIaqq m6gjiSRSAuaO+KQeMDNM+yP2D0XxMIaRUo+Mt9IirHk1LOg8Eijf/qxAsyLEPzLnNG gihTXDL3PCNzW6/FCdLx9LI6MEJ2oX8VWxKx+sknO8jGXYv2x9scZobR0j8eH5pOiA 46M2PBFJf1J6A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Richard Henderson , Michael Tokarev Subject: [Stable-10.0.11 24/56] target/arm: Use FPST_A64_F16 for SVE FCVTLT_hs Date: Sat, 13 Jun 2026 22:50:38 +0300 Message-ID: <20260613195116.1807273-24-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380787351158500 From: Peter Maydell We should be using the F16-specific float_status for conversions from half-precision, because halfprec inputs never set Input Denormal. If we use the FPST_A64 fpstatus then we will incorrectly set FPCR.IDC for input-denormals when FPCR.AH=3D1. In commit e07b48995aaa we updated most of the halfprec-to-other conversion insns to use FPST_A64_F16 as part of implementing FEAT_AHP. However we missed the SVE FCVTLT instruction, which has a halfprec-to-single encoding. Correct the FPST we use for the hs variant of FCVTLT. Cc: qemu-stable@nongnu.org Fixes: e07b48995aaa ("target/arm: Use FPST_A64_F16 for halfprec-to-other co= nversions")a Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Reviewed-by: Richard Henderson Message-id: 20260521122913.1565011-3-peter.maydell@linaro.org (cherry picked from commit aa42300f86d172d7252f0cb95c2efd7570ad6b8f) (Mjt: context fixup across v10.2.0-1344-g895d4367d6 "target/arm/tcg: Use "or SME" feature checks where needed") Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/translate-sve.c b/target/arm/tcg/translate-sve.c index 810c44b007..1d5b06e391 100644 --- a/target/arm/tcg/translate-sve.c +++ b/target/arm/tcg/translate-sve.c @@ -7159,7 +7159,7 @@ TRANS_FEAT(BFCVTNT, aa64_sve_bf16, gen_gvec_fpst_arg_= zpz, s->fpcr_ah ? FPST_AH : FPST_A64) =20 TRANS_FEAT(FCVTLT_hs, aa64_sve2, gen_gvec_fpst_arg_zpz, - gen_helper_sve2_fcvtlt_hs, a, 0, FPST_A64) + gen_helper_sve2_fcvtlt_hs, a, 0, FPST_A64_F16) TRANS_FEAT(FCVTLT_sd, aa64_sve2, gen_gvec_fpst_arg_zpz, gen_helper_sve2_fcvtlt_sd, a, 0, FPST_A64) =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380622; cv=none; d=zohomail.com; s=zohoarc; b=a8qyswBnTC9bMUQLuMAOljgnkA4YkciZVtsMUCwwyyPFxUtUnDSWwsLfQPpiIUKX8ZQlERn2IcauooZUXwe2nk051psovgmuWvNDbEIgJeuHv9emzU+CPhAEFzhmHrIu1Hs3A48GaROFYKNakOwFY5w1/X/1ta/40P9TlaiOZ/w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380622; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=XfTz8op4zJXrBl5nCXOwk72c8o2E3Gk91IZIpKmIUrY=; b=EXkQTMHgzdRzTJ0nEcOjPux0Db60ftPIHgrhWW+S4CMX3IFsP3ui3VsWvAWDX6vniu9TyJwz5/PNd+mZTn5w/gNwgLkleBlEijZRWWLnlmxQEaY4gC9oFB8Zvf+Y0d1OCbDowEZM1A7afkI5t/FEKN8hY+stKQxa8hmvOs2ii8Q= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380622331503.06506779931567; Sat, 13 Jun 2026 12:57:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQH-00031S-0u; Sat, 13 Jun 2026 15:53:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQ0-0002BJ-HJ; Sat, 13 Jun 2026 15:53:25 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUPz-0003xc-10; Sat, 13 Jun 2026 15:53:24 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 87CF91B6E28; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E00663CE8A2; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=yD4AK9VhDi+yOSHsYzVOjhXAvYebuMP7cZnmRKzZfzU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Psg1jlureK3DtXoDWtKTiZObpTVK1uAIwxvu9vMdAZFagkSWeZF5oZEZ7gLzw4T4u 6z9e7OihyzQ5wPc3dnr/BaiZwi+lkaiWpD9l6LAxpGoiKBTYcnXwX1OIHKrDAbErZc XgZHbtA0lXdCrJS/bpexSCEKRjKkHOVPN1eoIYRSkwk71MKYU8qXbN7DYauxQePF7Q iOcMEM5iasy4bbyEwB/TF67NTor+MJuOvaLjEzTXvbopzuAyk+eSPeXOPxHJ06E8DB o0Sc35QBx16zj+LGRWFcg2kX9vGo62oPG8NCigLtMgrNwHBom7FR8VoACYwLYcZMRo PmjzL3GxXH8xQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Richard Henderson , Michael Tokarev Subject: [Stable-10.0.11 25/56] target/arm: Set correct fp flags for FLOGB when FPCR.AH = 1 Date: Sat, 13 Jun 2026 22:50:39 +0300 Message-ID: <20260613195116.1807273-25-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380622766158500 From: Peter Maydell Our implementation of the FLOGB insn does the operations entirely in the helper function, without needing to use fpu functions. This means it needs to handle all the fp status flags itself. We aren't setting float_flag_input_denormal_used when we use (i.e. do not flush to zero) an input denormal, which means that FPCR.IDC isn't set when it should be for FPCR.AH=3D1. We missed this when we added float_flag_input_denormal_used and made the fpu/ code set it. Add the missing float_raise(). Cc: qemu-stable@nongnu.org Fixes: d38a57a3f ("target/arm: Enable FEAT_AFP for '-cpu max'") Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Reviewed-by: Richard Henderson Message-id: 20260521122913.1565011-4-peter.maydell@linaro.org (cherry picked from commit 23ece2805f9a3f90f317aac1b49ee45783b57636) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/sve_helper.c b/target/arm/tcg/sve_helper.c index 20accbc568..57a8cfdccd 100644 --- a/target/arm/tcg/sve_helper.c +++ b/target/arm/tcg/sve_helper.c @@ -4740,6 +4740,7 @@ static int16_t do_float16_logb_as_int(float16 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -15 - clz32(frac); } /* flush to zero */ @@ -4768,6 +4769,7 @@ static int32_t do_float32_logb_as_int(float32 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -127 - clz32(frac); } /* flush to zero */ @@ -4796,6 +4798,7 @@ static int64_t do_float64_logb_as_int(float64 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -1023 - clz64(frac); } /* flush to zero */ --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380623; cv=none; d=zohomail.com; s=zohoarc; b=RVRQdkpj3ZWX1BHKh44oK8BThnInKRDdzaxA7lijtKdfOSPZi9s+of0z02plv54G7hZE/QNgouZfXG8iNOog6KgvXdXiCBnzoEbbnCxvF0374Bbh0Vx1V3dPV/Vog+I2Wuhcfzesqe/qZvct9eSH27nBWW769VDf7PKPuP3ADkQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380623; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=l52CNS/vgVdVTg0drsyOsrH/sMRxM/4BRBR6OHUK5dw=; b=i/Oim8g4qntgUsfRHTxJVrzW0fg5Y+ToIUVy2/TUh85tYhpyRgs5jyS90bu3bbdaw0KtPKV49CHIoEAj76UTqnEsP0Ytpbi5IrsygtsmhqTnCvzGaLuMUze9DKalxHQOmiv2iP7XuR1cAry+DzFUu0RcRHRSrc68RLJDqUL1tbI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380623481905.2909936483884; Sat, 13 Jun 2026 12:57:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQN-0003cL-T9; Sat, 13 Jun 2026 15:53:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQM-0003aH-0c; Sat, 13 Jun 2026 15:53:46 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQK-0003xq-9n; Sat, 13 Jun 2026 15:53:45 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 97C051B6E29; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id F0BE33CE8A3; Sat, 13 Jun 2026 22:51:17 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=oCUOghwyqox/Ni39juKEJFrLr96eGgowBgZInq2yojA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=eH0kzrzr3VxsaEkkcpRHaGyQqYzpHvM4xL+W5lgOk4xylvwLIwOkVL7FrMSkh/Cjv fO+yR58miGmfjMgcQVCg8BsU0TcWhrxwKhNF1r6cUJzmMVpd/VtXlaqJu2BdxEEAVy mIjAIpdNhsdRnriUyqIfoiT4QIdfLZl5DFYNKRaJTR+eWSQkpHcXbMav5GklMU0H2J /O3PH6hEJyD4nar8X1fnCCpWywkIdiHBrsX3e5t1pawfb07HEH60o69VBN9FV6U6Vt XmA5mn70+UARMLzb7xcLmc+6/imM6wvR2qvf2xihWt4qVfXtWvphRgICmq/O8Me5yu ZGuzNhpt58nrg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Richard Henderson , Michael Tokarev Subject: [Stable-10.0.11 26/56] target/arm: Don't assert if 64-bit EL2 AT insn sees a Domain fault Date: Sat, 13 Jun 2026 22:50:40 +0300 Message-ID: <20260613195116.1807273-26-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380624763158503 Content-Type: text/plain; charset="utf-8" From: Peter Maydell The Domain fault type can only happen for 32-bit short-format descriptors. This means that it almost never needs to be encoded in a long-format fault status code. However, there is one corner case where we do need to report it as a long-format FSC: if a 64-bit EL2 does an AT insn on an AArch32 EL1&0 translation regime that is using short-descriptors and that translation operation hits a Domain fault, then this is reported in the PAR_EL1 in long-format. The PAR_EL1 register description defines that this should be reported as 0b111101 for a level 1 Domain fault or 0b111110 for a level 2 Domain fault. The Arm ARM pseudocode special cases this in the function AArch64_PARFaultStatus() (because no other "fault to LFSC" code path can be a Domain fault). For QEMU, implement it in arm_fi_to_lfsc(). Cc: qemu-stable@nongnu.org Fixes: 1fa498fe0de97 ("target/arm: Provide fault type enum and FSR conversi= on functions") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3512 Signed-off-by: Peter Maydell Reviewed-by: Richard Henderson Message-id: 20260526174155.2491217-1-peter.maydell@linaro.org (cherry picked from commit bb957530471c792a9a51e822a6c2fa8398cc48f6) Signed-off-by: Michael Tokarev diff --git a/target/arm/internals.h b/target/arm/internals.h index e95f791ce0..cb940ce6b9 100644 --- a/target/arm/internals.h +++ b/target/arm/internals.h @@ -848,6 +848,16 @@ static inline uint32_t arm_fi_to_lfsc(ARMMMUFaultInfo = *fi) assert(fi->level >=3D 0 && fi->level <=3D 3); fsc =3D 0b001100 | fi->level; break; + case ARMFault_Domain: + /* + * This can only happen when doing an AT insn at EL2 for an AArch32 + * stage 1 EL1&0 translation regime using short-descriptors, and + * the translation hits a Domain fault. This needs to be reported = in + * the long-format PAR. Compare pseudocode AArch64_PARFaultStatus(= ). + */ + assert(fi->level =3D=3D 1 || fi->level =3D=3D 2); + fsc =3D 0b111100 | fi->level; + break; case ARMFault_Translation: assert(fi->level >=3D -1 && fi->level <=3D 3); if (fi->level < 0) { --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380730; cv=none; d=zohomail.com; s=zohoarc; b=DtUq4AijpM8+QUqA6VQr+1crH4wgnGJ1Aqs/ybDJWzkhS3tHpSlBH+KMqzdJ+zTo1yIVx0ltD6jIKIOa0cR7IpBLq3A28qT2I1VOvWLrm5CWB0TAIPROMVj7jDMA3mkRMcoPtNSXo8AAJJVZibZ7CaKiTmQyyVSPknHki6UP0Iw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380730; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=KqeB7Vr0I+EoKyuJQizWFop0REZ9706ONfcWRNWH9No=; b=iksRpmr1qwgQ5P/bw3hcNn40m8f1q4PjfT977J5WYm2Xk5a2aRMvxXT4lRbB+fSIJvTD2Vq/RduIigl2HmP5VmO/8WLorI8TEdWFhxRSuLaT6webuOIopDmrkmjYWNXQHyCjvlXxqi3bmZ2KNMm24sDFb1JUXPcVYKFAznpU7cQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380730155868.0065031587986; Sat, 13 Jun 2026 12:58:50 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQQ-0003ip-7n; Sat, 13 Jun 2026 15:53:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQO-0003dZ-Cw; Sat, 13 Jun 2026 15:53:48 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQM-0003yR-E6; Sat, 13 Jun 2026 15:53:48 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A76F81B6E2A; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0C5933CE8A4; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=XD1LPMK2wPincHYlBJSY1xOKD+wvkR4bcKatvgwgKhE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=wSejl2kEX2GrqMv1xBLqsAKbELFuX6MG44HFskS3Igp8sYhuad/ZyHQ2BWLOaS8DG /okPOT3AgPDXyNdjCKSxmvolIrEy3o+fDB3qaMI6Beavtz0Cu6ExFI0eFm1Y1BBtOp H4p2dFLPk4loXps1fMRFJm7kyM4GS7gVLhrwq9mFdE//peyJofUhiVgAscT4akk5tk yoq+OlmKgcT9MQthaGpZvxGHDlPnYIAP4N1wIK5K1XiELru96kf5XW4lvm7v/AR6Ng ZVoq7Wh70jDc0ZDTkuFcTctqFUjB8CJ9e5XDJH0HSYPRLV6hlmhG01Qdsu192ybN5D qPPmFXWsjNHkA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Jason Wang , Michael Tokarev Subject: [Stable-10.0.11 27/56] hw/net/rocker_of_dpa: Check group ID pointers are not NULL Date: Sat, 13 Jun 2026 22:50:41 +0300 Message-ID: <20260613195116.1807273-27-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380731241158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell In of_dpa_cmd_add_l2_flood(), we use rocker_tlv_parse_nested() to fill in a tlvs[] array. If the guest command is valid then the entries should be pointers to TLV data items with group IDs. However, if the guest gives us bogus data then rocker_tlv_parse_nested() indicates this by leaving the tlvs[] entries NULL. In the other places that use this function, we check for this before using the value, but here we forgot, and the result is that QEMU can crash: #0 __memcpy_avx_unaligned_erms () at ../sysdeps/x86_64/multiarch/memmove-v= ec-unaligned-erms.S:331 #1 0x00005555574f7137 in __asan_memcpy () #2 0x0000555558106792 in ldl_he_p (ptr=3D0x8) at /home/pm215/qemu/include/= qemu/bswap.h:278 #3 0x0000555558106755 in ldl_le_p (ptr=3D0x8) at /home/pm215/qemu/include/= qemu/bswap.h:311 #4 0x00005555580f85ed in rocker_tlv_get_le32 (tlv=3D0x0) at ../../hw/net/r= ocker/rocker_tlv.h:114 #5 0x000055555810a8ad in of_dpa_cmd_add_l2_flood (of_dpa=3D0x506000082e38,= group=3D0x503000b4e440, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2032 #6 0x0000555558108a74 in of_dpa_cmd_group_do (of_dpa=3D0x506000082e38, gro= up_id=3D1073741824, group=3D0x503000b4e440, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2115 #7 0x0000555558108730 in of_dpa_cmd_group_add (of_dpa=3D0x506000082e38, gr= oup_id=3D1073741824, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2135 #8 0x00005555580f66ec in of_dpa_group_cmd (of_dpa=3D0x506000082e38, info=3D0x514000072e40, buf=3D0x5070002356c0 "= \001", cmd=3D7, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2194 Check for NULL values and return an error. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/1851 Signed-off-by: Peter Maydell Signed-off-by: Jason Wang (cherry picked from commit 8526b7d6b67beda0c83e4a8aec1449475fe5dd65) Signed-off-by: Michael Tokarev diff --git a/hw/net/rocker/rocker_of_dpa.c b/hw/net/rocker/rocker_of_dpa.c index b4da3cc0ec..6f10212521 100644 --- a/hw/net/rocker/rocker_of_dpa.c +++ b/hw/net/rocker/rocker_of_dpa.c @@ -2033,6 +2033,10 @@ static int of_dpa_cmd_add_l2_flood(OfDpa *of_dpa, Of= DpaGroup *group, group_tlvs[ROCKER_TLV_OF_DPA_GROUP_IDS]); =20 for (i =3D 0; i < group->l2_flood.group_count; i++) { + if (!tlvs[i + 1]) { + err =3D -ROCKER_EINVAL; + goto err_out; + } group->l2_flood.group_ids[i] =3D rocker_tlv_get_le32(tlvs[i + 1]); } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380642; cv=none; d=zohomail.com; s=zohoarc; b=OdPhlVy67TvoPYLZPiRLVgTxDelzaXH6PuI8kFzAA9YMeMXYMbKQlUJ856/wP41+bwZkrW1bRgKeVW1xofQchSIs/bUjjyT2C4ewjC10bkqUw9btlamEuIjkFdRfyYc2XguHwpmzlVMyUylrrN7kp+fNZpDAGsqaJu7rj3FZm7g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380642; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gWcw/3YHu9kA1y0xbEhAvl8SzUluOnbijDu4xJ8X1s4=; b=ga7o1iKRlQ+IhDhwCCGvwQjteKPok87I3SMtNaplswhrb0UzGfrpkj2oGmvKk19Bt5Tg3wbAWddAjHvaiSRCUwkHd7zzwFKfkZtdRumd86vnBty/AhvtnwhQKzfbumld3vzMRyo7GQkqngSjUYYV4PwCkAud9HvaNaHk14zf8iM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380642247467.47372778036583; Sat, 13 Jun 2026 12:57:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQR-0003so-Kb; Sat, 13 Jun 2026 15:53:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQQ-0003j8-1c; Sat, 13 Jun 2026 15:53:50 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQO-00042R-7H; Sat, 13 Jun 2026 15:53:49 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B63381B6E2B; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1BB2A3CE8A5; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=W3NmWaZak4in+cLzAVIEJXDGO+x/8//dUqJPqZV7Euo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=i0mk9N5s9M05vBpQQReBQX7gvTTPUXYEuu2N6qGmlUl0Qr+PmmJyFTmsgGSSTDaHZ fgH7A0l1StbDWxDop+38/gUXw34S2fx94BzQbf0xnppcifFgFDqEQOSQT0dIEUT9NS tDR6+hLexyZTaEO6dz0Aalqhvel5Kjkbj4SUg0vGp6WxJhjSMEZNCVgYhb3oRLArBc wouB0tqNH7EmAHcNELtmpu4BrIV8poMi6CcQIOBk/HTld/9r0D8YvgbRK44vmOx/Vd w6zDGnDQ1O1tBX4cBnZAArN2EcHLBvveEINmikszrFjBJMDJMQJOx+3idOkjYhEdnm GEXSo+/d15EZQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Jason Wang , Michael Tokarev Subject: [Stable-10.0.11 28/56] hw/net/rocker_of_dpa: Avoid unaligned accesses in _of_dpa_flow_match() Date: Sat, 13 Jun 2026 22:50:42 +0300 Message-ID: <20260613195116.1807273-28-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380642840158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell _of_dpa_flow_match() tries to do masked comparisons of OfDpaFlowkey structs by casting pointers to them to uint64_t* and then doing the memory accesses as 64-bit. This is undefined behaviour because the pointers might not be 64-bit aligned, and the UB sanitizer spots this: ../../hw/net/rocker/rocker_of_dpa.c:321:20: runtime error: load of misalign= ed address 0x512000164044 for type 'uint64_t' (aka 'unsigned long'), which = requires 8 byte alignment 0x512000164044: note: pointer points here 02 00 00 00 00 00 ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00= 00 00 00 00 00 00 00 00 ^ We do know that OfDpaFlowKey structs must be at least aligned enough for uint32_t accesses, because that's the type of the first field. Switch to using uint32_t accesses in the loop. Because the "width" field is always set via the FLOW_KEY_WIDTH macro and not exposed to the guest, we can adjust the macro to store the number of uint32_t to be checked rather than needing to change the loop boundary in the match function. Cc: qemu-stable@nongnu.org Signed-off-by: Peter Maydell Signed-off-by: Jason Wang (cherry picked from commit 71d027cfee8553e2ec28efa1ddd7fd0ecbadcc86) Signed-off-by: Michael Tokarev diff --git a/hw/net/rocker/rocker_of_dpa.c b/hw/net/rocker/rocker_of_dpa.c index 6f10212521..74d00aef1c 100644 --- a/hw/net/rocker/rocker_of_dpa.c +++ b/hw/net/rocker/rocker_of_dpa.c @@ -99,13 +99,13 @@ typedef struct of_dpa_flow_key { } nd; } ipv6; }; - int width; /* how many uint64_t's in key? */ + int width; /* how many uint32_t's in key? */ } OfDpaFlowKey; =20 -/* Width of key which includes field 'f' in u64s, rounded up */ +/* Width of key which includes field 'f' in u32s, rounded up */ #define FLOW_KEY_WIDTH(f) \ DIV_ROUND_UP(offsetof(OfDpaFlowKey, f) + sizeof_field(OfDpaFlowKey, f)= , \ - sizeof(uint64_t)) + sizeof(uint32_t)) =20 typedef struct of_dpa_flow_action { uint32_t goto_tbl; @@ -308,9 +308,9 @@ static void _of_dpa_flow_match(void *key, void *value, = void *user_data) { OfDpaFlow *flow =3D value; OfDpaFlowMatch *match =3D user_data; - uint64_t *k =3D (uint64_t *)&flow->key; - uint64_t *m =3D (uint64_t *)&flow->mask; - uint64_t *v =3D (uint64_t *)&match->value; + uint32_t *k =3D (uint32_t *)&flow->key; + uint32_t *m =3D (uint32_t *)&flow->mask; + uint32_t *v =3D (uint32_t *)&match->value; int i; =20 if (flow->key.tbl_id =3D=3D match->value.tbl_id) { --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380623; cv=none; d=zohomail.com; s=zohoarc; b=X3LZ9OKIRPhq41+IyWbQndppgW1xcDqD2U+ViylLyyqk/6wHi+vbA2gS/08c65TPOOzPB4jzGcdx8G+/xZ/bZlKq0RPny9B6eKVAraFAzrzOYC+O9CbZGvEcF3OjLUP120HGGR67a95CMO9oOx/ZnprvL0dfufrZvFH9ciCO/y4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380623; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=HGxfuZJKsLe8+60uPCQZxke+PsDM5TGk+j/oBE/o73A=; b=jg6+dT4zSYau5eYNrkyDLeDICZGrp+3Lb1kc78qySYsaqsS5oM7dTblhprv9vQeFr/EHPQT7XTqb6/IBMQpMT8NIRsyhlDZVfVDEXwJDCDjwqog1Zr6qNhkgOUG3pPPu8Trj3CfY851fVl2f7eNTTIlIhlfcWU3mPWpvJw6MFdk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380623275852.7361525521154; Sat, 13 Jun 2026 12:57:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQU-00041w-2m; Sat, 13 Jun 2026 15:53:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQS-0003wx-3i; Sat, 13 Jun 2026 15:53:52 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQQ-00043C-9w; Sat, 13 Jun 2026 15:53:51 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C71A61B6E2C; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 2B0DB3CE8A6; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=LlFJ5MNrrFqn2jreYasQuWyv+SrH/nQ9Zgl3Dd/fIBM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Rz0928hAUh5jkcqtmz/QJnQIqtBSqkbe2msMMawW9ywbwOnI53wHsd5UKVU2xIQPb jxy7G38JZZ6g6BQTzoVzJyDwJwgJXmwqJhWv0VubJLFZcgabx9q9flnAxDBi3ksOTA X+/0OHV9r2VyQ11hYxw16ryJbV2VNDhdyV3tscEvN5+FoLmGIZGSsP6qA8XPmn/00J 35Tp55BnFJuDkH+3MzbQzFqed1UAGnoRTo9X2Tb5LJayQT+U+YNoktZnCx0moxoee+ NqhwBVRp8RabdDr6nkLymSz+6h0tC2puUrekmLzOlpfmFlpjqSTYYT/e6/VNgYsZkB 6XwmJiaB3LG4w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-10.0.11 29/56] linux-user/ppc: restore fp_status from FPSCR on sigreturn Date: Sat, 13 Jun 2026 22:50:43 +0300 Message-ID: <20260613195116.1807273-29-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380624763158501 Content-Type: text/plain; charset="utf-8" From: Matt Turner restore_user_regs() restores the PPC FPSCR with a direct assignment: env->fpscr =3D (uint32_t) fpscr; ppc_store_fpscr() exists precisely to write FPSCR and keep the derived env->fp_status in sync: it calls fpscr_set_rounding_mode() to update the softfloat rounding mode, and set_float_rebias_overflow/underflow() to reflect the FP_OE/FP_UE enable bits. The direct assignment bypasses all of this. On sigreturn, interrupted code resumes with whatever rounding mode and overflow/underflow-rebias state the signal handler last installed in fp_status, rather than the state that was saved at signal delivery. Replace the direct assign with ppc_store_fpscr(). The FPSCR_MTFS_MASK applied inside ppc_store_fpscr() only excludes the computed FP_FEX and FP_VX bits, which it re-derives correctly from the exception and enable bits in the restored value. Fixes: bcd4933a23 ("linux-user: ppc signal handling") Cc: qemu-stable@nongnu.org Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 3f50dd46664bdf94f10aca8b76dc4dcb9182a5ae) Signed-off-by: Michael Tokarev diff --git a/linux-user/ppc/signal.c b/linux-user/ppc/signal.c index a9c10e0987..ab1afea30a 100644 --- a/linux-user/ppc/signal.c +++ b/linux-user/ppc/signal.c @@ -420,7 +420,7 @@ static void restore_user_regs(CPUPPCState *env, __get_user(*fpr, &frame->mc_fregs[i]); } __get_user(fpscr, &frame->mc_fregs[32]); - env->fpscr =3D (uint32_t) fpscr; + ppc_store_fpscr(env, (uint32_t) fpscr); } =20 #if !defined(TARGET_PPC64) --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380473; cv=none; d=zohomail.com; s=zohoarc; b=eL1MHdjzxuJhKHrfesO5loUh4QtXHa7OSq9IW9RxIB3sj8Nw58D6vDJVRamqSSKB0weJoX69BuJ3jheSAhoul6X2f4jZFYyapuxCN0//Nggg4WMpAbn14h++DaxOC8+Z+y3fxD+qnGS2PBPkJukD1n4WnT9X0xhc14x+LsPqZb0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380473; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=KkvSn0j9bj4Au0dCdOZFkOWYx2VXM//nEr5rfySz6P4=; b=AohnmzXtuoUoaQ4HnD8qCRBcEG0Iw3Q7EAWPWz5MExxSrQ3Fo9bJssOt6uNTBMLyOgV9lzBN38pzfYz3Fe5XU7uyMt+SKS8BJzQx8XbocA3jRTswQjaTKCPseVtDYwWZ+Py1i0sQEqbUM/gg9CC3ZXNzIyPBZnf3dFvw1tWzWj0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380473259419.48201410269417; Sat, 13 Jun 2026 12:54:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQa-000493-GM; Sat, 13 Jun 2026 15:54:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQT-00043N-Rz; Sat, 13 Jun 2026 15:53:53 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQS-00043j-0p; Sat, 13 Jun 2026 15:53:53 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D73F61B6E2D; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 3C2E43CE8A7; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=sjwTMIMk1KhYJ9D5Q2FW52WytCeRspT0hTEheUQbs6Y=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=AIB57BAN9ctq46cIl1qnLH7mSuO3ox9yCGLHDaBwLpGzDIa0o1fIPYYudji8e9DBK JOkgQ1Ld1D0LNqztnGtbdCefdch/9P6NwY45O92hbmk409oBP7JwxYD205Y/ZoP4Iq w1pfO+V6mANSx1PX7uUHRrOyChYy8HnEY9AzC6P1DUhyjjsTU2+c3e6OUfPViH67j/ ckTmeHXqg/y9G2eBllDZQQF0cZci4OD62Dnc6y5uxhUKkKjukaxKTDE9jdk9J5lOBO 5p/8uBpNP7RX8SuBC926W1R3rSp/hmQ6QWK6DfJ9O6vQmcKdvYgFWpsBncyZucHrJf 3VWLzHV9CJT5A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-10.0.11 30/56] linux-user/mips: save/restore FCSR across signal delivery Date: Sat, 13 Jun 2026 22:50:44 +0300 Message-ID: <20260613195116.1807273-30-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380474220158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the MIPS FPU control/status register (FCSR, fcr31) in env->active_fpu.fcr31. The rounding mode, flush-to-zero (FS), and NaN-2008 mode bits in fcr31 are reflected into the derived env->active_fpu.fp_status via set_float_rounding_mode() and friends; every architectural write to FCSR goes through helper_ctc1() which calls restore_fp_status() to keep the two in sync. Both target_sigcontext variants (O32 and N32/N64) have an sc_fpc_csr field that holds FCSR, but setup_sigcontext() never wrote it and restore_sigcontext() never read it. As a result: - The signal frame always delivered sc_fpc_csr =3D=3D 0 to the handler, so sigaction(SA_SIGINFO) handlers that inspect the interrupted context see the wrong FCSR. - On sigreturn, active_fpu.fcr31 retained whatever value the signal handler last installed (if any), and active_fpu.fp_status was never resynced. Interrupted code resumed with the wrong rounding mode, FS flag, and NaN-2008 semantics. Fix setup_sigcontext() to save fcr31 into sc_fpc_csr. Fix restore_sigcontext() to read it back (masked to fcr31_rw_bitmask as the kernel does) and call cpu_mips_restore_fp_status() to resync fp_status from the restored fcr31. Add cpu_mips_restore_fp_status() in target/mips/fpu.c (which already defines ieee_rm and includes fpu_helper.h), and declare it in cpu.h. Fixes: 084d0497a0 ("mips-linux-user: Save and restore fpu and dsp from sigc= ontext") Cc: qemu-stable@nongnu.org Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 84b920ccb5ee5287747af2d36d1ece6367b6a40e) (Mjt: context fixup in target/mips/cpu.h) Signed-off-by: Michael Tokarev diff --git a/linux-user/mips/signal.c b/linux-user/mips/signal.c index d69a5d73dd..1b10012726 100644 --- a/linux-user/mips/signal.c +++ b/linux-user/mips/signal.c @@ -134,6 +134,7 @@ static inline void setup_sigcontext(CPUMIPSState *regs, for (i =3D 0; i < 32; ++i) { __put_user(regs->active_fpu.fpr[i].d, &sc->sc_fpregs[i]); } + __put_user(regs->active_fpu.fcr31, &sc->sc_fpc_csr); } =20 static inline void @@ -165,6 +166,12 @@ restore_sigcontext(CPUMIPSState *regs, struct target_s= igcontext *sc) for (i =3D 0; i < 32; ++i) { __get_user(regs->active_fpu.fpr[i].d, &sc->sc_fpregs[i]); } + { + uint32_t fcr31; + __get_user(fcr31, &sc->sc_fpc_csr); + regs->active_fpu.fcr31 =3D fcr31 & regs->active_fpu.fcr31_rw_bitma= sk; + cpu_mips_restore_fp_status(regs); + } } =20 /* diff --git a/target/mips/cpu.h b/target/mips/cpu.h index f6877ece8b..ae1fcad7bd 100644 --- a/target/mips/cpu.h +++ b/target/mips/cpu.h @@ -1377,6 +1377,9 @@ static inline void cpu_get_tb_cpu_state(CPUMIPSState = *env, vaddr *pc, MIPS_HFLAG_HWRENA_ULR); } =20 +/* fpu.c */ +void cpu_mips_restore_fp_status(CPUMIPSState *env); + /** * mips_cpu_create_with_clock: * @typename: a MIPS CPU type. diff --git a/target/mips/fpu.c b/target/mips/fpu.c index c7c487c1f9..8b661865ca 100644 --- a/target/mips/fpu.c +++ b/target/mips/fpu.c @@ -17,6 +17,11 @@ const FloatRoundMode ieee_rm[4] =3D { float_round_down }; =20 +void cpu_mips_restore_fp_status(CPUMIPSState *env) +{ + restore_fp_status(env); +} + const char fregnames[32][4] =3D { "f0", "f1", "f2", "f3", "f4", "f5", "f6", "f7", "f8", "f9", "f10", "f11", "f12", "f13", "f14", "f15", --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380640; cv=none; d=zohomail.com; s=zohoarc; b=FXwg5dC+D7N66vFTOD1cZAHmeLKIRc69fheTOCeepq7xd5gwBGPHor9t8M6kkwwRExh0kb4MVzRrN0sPDBs9qGd73ztwlfbcfv+HvvXHm/A4hiNskR8kNRvWkURq3LhTKFMzzPpwDCstJd2ocHnnzLKtNCQ+keRMmX1m8c6swCs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380640; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LPhyYccvzczMUvS1xg6EDqVdVvYUg9RiFt2CCvF1NVI=; b=T2XwraH0hrSJXF/x3lpbCQNk9GN3jdxTy9MERwF0uxjXucG7sDNwwpnvbk1JPOsn7kWEYxSLA6pG8oCBenBiKt6FQ9ArAMiDGMKHsp5UOcbx/gFW/pS4INaBalcToNfsMRFKDZr3O2XlMXyAZiax2Gc4c97OOip/gFgkBgEkqiE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380640324269.3983289035525; Sat, 13 Jun 2026 12:57:20 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUQv-0005L9-U9; Sat, 13 Jun 2026 15:54:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQp-00051P-Rw; Sat, 13 Jun 2026 15:54:15 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQn-000448-U9; Sat, 13 Jun 2026 15:54:15 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E89421B6E2E; Sat, 13 Jun 2026 22:50:59 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 4BA593CE8A8; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380259; bh=Wqggm+YI9CGOXrC37tB98c0M6KNUDE9ZIppSxjX+MCI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=rYB69xuLgW1OFh8fDOPQBvbQcbkBSCOyah2ieWY9t95q1SE9EUawi+9B2fPBJ+AX+ IGgzxJhAcY7qebuDs7a44LPpzuPeDmiq9NwelGQnWqzH2bXHNY6po5N99yxLGYdtN5 02YWXcLrDIOCRPgtyEVgBESPXAphvnF/WmzJCvgIEJMC2y83oPwG75oFd/j9//E010 eChbERPcuZdGCWLrCaFlEGdNZyEXE5fYtQU5S9RdKJ8hLG0DJijmYwY2ljy3w617Gb jzkmkwYUQAvaTFLOTqkMQnJnm3KQre/+URXMlW5cfQyhxRlX4AM+VEswetfEKxZUsj yN7i01bDPzkzg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Yoshinori Sato , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-10.0.11 31/56] linux-user/sh4: preserve T/M/Q bits across signal delivery Date: Sat, 13 Jun 2026 22:50:45 +0300 Message-ID: <20260613195116.1807273-31-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380640985158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the SH4 T, M and Q status-register bits outside env->sr, in the dedicated env->sr_t, env->sr_m and env->sr_q fields; cpu_read_sr() folds them back into the architectural SR value and cpu_write_sr() splits them back out. setup_sigcontext() saved the bare env->sr (so the T/M/Q bits were always zero in the signal frame) and restore_sigcontext() wrote the value straight back into env->sr without updating sr_t/sr_m/sr_q. As a result the T bit was never preserved across signal delivery: on sigreturn the interrupted code resumed with whatever T value the signal handler last left behind. Any conditional branch (or addc/subc/rotcl/div1, etc.) immediately following the interrupted instruction could then take the wrong path. This is the cause of the long-standing intermittent failures of the tests/tcg/multiarch/signals.c test on sh4, which was marked BROKEN. With a SIGRTMIN timer firing every millisecond across many threads, the race was hit a few percent of the time and corrupted the guest heap, surfacing as a SIGSEGV in memset, a malloc assertion, or an rseq registration abort. Traced on a deterministic rr recording: a cmp/hi set T=3D0, the timer signal interrupted the very next instruction (a bf), the handler left T=3D1, and the resumed bf took glibc calloc's MORECORE_CLEARS branch, using the old top-chunk size as the clear length for a freshly split small chunk and running memset off the end of the heap. Fix setup_sigcontext()/restore_sigcontext() to use cpu_read_sr() and cpu_write_sr() so the T, M and Q bits round-trip correctly, and drop the BROKEN annotation on the sh4 signals test. Fixes: c3b5bc8ab3 ("SH4: Signal handling for the user space emulator, by Ma= gnus Damm.") Cc: qemu-stable@nongnu.org Reviewed-by: Yoshinori Sato Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 6bf4c0295cccf74f3c5c0b674328b97d6fd1505c) Signed-off-by: Michael Tokarev diff --git a/linux-user/sh4/signal.c b/linux-user/sh4/signal.c index d70be24c38..cc36425c49 100644 --- a/linux-user/sh4/signal.c +++ b/linux-user/sh4/signal.c @@ -131,8 +131,10 @@ static void setup_sigcontext(struct target_sigcontext = *sc, COPY(gregs[14]); COPY(gregs[15]); COPY(gbr); COPY(mach); COPY(macl); COPY(pr); - COPY(sr); COPY(pc); + COPY(pc); #undef COPY + /* The T, M and Q bits live outside env->sr; fold them back in. */ + __put_user(cpu_read_sr(regs), &sc->sc_sr); =20 for (i=3D0; i<16; i++) { __put_user(regs->fregs[i], &sc->sc_fpregs[i]); @@ -159,8 +161,14 @@ static void restore_sigcontext(CPUSH4State *regs, stru= ct target_sigcontext *sc) COPY(gregs[14]); COPY(gregs[15]); COPY(gbr); COPY(mach); COPY(macl); COPY(pr); - COPY(sr); COPY(pc); + COPY(pc); #undef COPY + /* The T, M and Q bits live outside env->sr; unfold them. */ + { + uint32_t sr; + __get_user(sr, &sc->sc_sr); + cpu_write_sr(regs, sr); + } =20 for (i=3D0; i<16; i++) { __get_user(regs->fregs[i], &sc->sc_fpregs[i]); diff --git a/tests/tcg/sh4/Makefile.target b/tests/tcg/sh4/Makefile.target index 7852fa62d8..b7a8737be0 100644 --- a/tests/tcg/sh4/Makefile.target +++ b/tests/tcg/sh4/Makefile.target @@ -3,13 +3,6 @@ # SuperH specific tweaks # =20 -# This triggers failures for sh4-linux about 10% of the time. -# Random SIGSEGV at unpredictable guest address, cause unknown. -run-signals: signals - $(call skip-test, $<, "BROKEN") -run-plugin-signals-with-%: - $(call skip-test, $<, "BROKEN") - VPATH +=3D $(SRC_PATH)/tests/tcg/sh4 =20 test-macl: CFLAGS +=3D -O -g --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380551; cv=none; d=zohomail.com; s=zohoarc; b=DejaG9ofuNFm+wwnYsjE9NTTizeXMNxlrUI2sdBN5XVH9qITBRck/VoijfRnyeCUVfEIVIjuMrYA5x7TYoUDTglbgyk7v7gX3Dfj5ZuOD/QqqxtV54YensdwVO7NeVOdU4gKDsxONA8Mugy2SPHOEqH6ven0UMzmBx8CUOyTFTk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380551; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=c7A9Hfz8VLM/uWTpTK3pswsY3glxBhbXwR2r7K18H+k=; b=OKkCcSLkJkdIug1lMwU1k+sZ37BbdZ9YCMTsuZHFImziX5u0ciruNxqM14O9+SHLHw+9x/fSa+AcihvAZBKGa2+ADS13gJsjFzLOj65bTRh3SUmqzdLKvESZw/hzvA47BCdSfMurwkJj0AQG0bkbmt6nZ2DUncwYKzSXF89l9DI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380551986677.0053337654371; Sat, 13 Jun 2026 12:55:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUR4-0005cK-Pv; Sat, 13 Jun 2026 15:54:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQr-0005Ha-Kj; Sat, 13 Jun 2026 15:54:17 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQp-00044a-Jb; Sat, 13 Jun 2026 15:54:17 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 07E061B6E2F; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 5D7C43CE8A9; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=nuxwsAgdnZIL6F2A++Fdzh2BbY3cK18S5aJ3r5v1GUA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=cp+xpwOu3vadEMO/V15y6vHi4vctPs8yCiCydxVv9rB5kXP738BzGrGKlQzJ8nUP2 sSk03DpPlP/5SZDCtu0+flNa/crzSuuHooKzAWX1DnDqBvOjdvyoHjPcBN7XHtxGxY FvKCtPsziZbE8D+p0L6tOJ0qBDW01uxN1CDzkMNwuUjZdKxZI9SnygSdY94hbSuyD9 2Oxk9eHgXfRe5fLYe9hJNXqRSFYZnr4izYCg4+L5cResBGWjKf0EqcmnuOUAi8l3Ff 0Is/5YiuejNTofubThk+KCMK+Jl07W2qRnhQlCGb3+86NRCocjU/FRYoqizlMLz7kA 93DeHyLuwkX0Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Yoshinori Sato , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-10.0.11 32/56] linux-user/sh4: restore FP rounding mode on sigreturn Date: Sat, 13 Jun 2026 22:50:46 +0300 Message-ID: <20260613195116.1807273-32-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380554587158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner The SH4 FPSCR rounding-mode (RM) and denormal (DN) bits are not held only in env->fpscr: they are also reflected into the derived env->fp_status via set_float_rounding_mode()/set_flush_to_zero(). The guest keeps the two in sync by routing every write to FPSCR through helper_ld_fpscr(). restore_sigcontext() wrote the saved value straight into env->fpscr and never touched env->fp_status, so on sigreturn the interrupted code resumed with whatever FP rounding mode and flush-to-zero setting the signal handler last installed. (regs->flags =3D 0 forces the FR/SZ/PR TB flags to be recomputed, but fp_status is runtime float state, not a TB flag, so it was left stale.) This is the FP analogue of the T/M/Q bit problem just fixed for the integer status register. Factor the FPSCR -> fp_status synchronisation out of helper_ld_fpscr() into cpu_load_fpscr() and use it from restore_sigcontext() so the rounding mode round-trips correctly across signal delivery. Fixes: c3b5bc8ab3 ("SH4: Signal handling for the user space emulator, by Ma= gnus Damm.") Cc: qemu-stable@nongnu.org Reviewed-by: Yoshinori Sato Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit a740f17ed0fbc5cd38e3cb12136c58d38aba098d) (Mjt: context fixup in target/sh4/cpu.h) Signed-off-by: Michael Tokarev diff --git a/linux-user/sh4/signal.c b/linux-user/sh4/signal.c index cc36425c49..00290d6e40 100644 --- a/linux-user/sh4/signal.c +++ b/linux-user/sh4/signal.c @@ -173,7 +173,12 @@ static void restore_sigcontext(CPUSH4State *regs, stru= ct target_sigcontext *sc) for (i=3D0; i<16; i++) { __get_user(regs->fregs[i], &sc->sc_fpregs[i]); } - __get_user(regs->fpscr, &sc->sc_fpscr); + /* Resync the derived float_status state, not just env->fpscr. */ + { + uint32_t fpscr; + __get_user(fpscr, &sc->sc_fpscr); + cpu_load_fpscr(regs, fpscr); + } __get_user(regs->fpul, &sc->sc_fpul); =20 regs->tra =3D -1; /* disable syscall checks */ diff --git a/target/sh4/cpu.h b/target/sh4/cpu.h index d536d5d715..2ada25ee00 100644 --- a/target/sh4/cpu.h +++ b/target/sh4/cpu.h @@ -397,4 +397,7 @@ static inline void cpu_get_tb_cpu_state(CPUSH4State *en= v, vaddr *pc, #endif } =20 +/* Set FPSCR and the derived float_status rounding/flush-to-zero state. */ +void cpu_load_fpscr(CPUSH4State *env, uint32_t val); + #endif /* SH4_CPU_H */ diff --git a/target/sh4/op_helper.c b/target/sh4/op_helper.c index 99394b714c..d70587f328 100644 --- a/target/sh4/op_helper.c +++ b/target/sh4/op_helper.c @@ -202,7 +202,7 @@ void helper_macw(CPUSH4State *env, int32_t arg0, int32_= t arg1) } } =20 -void helper_ld_fpscr(CPUSH4State *env, uint32_t val) +void cpu_load_fpscr(CPUSH4State *env, uint32_t val) { env->fpscr =3D val & FPSCR_MASK; if ((val & FPSCR_RM_MASK) =3D=3D FPSCR_RM_ZERO) { @@ -213,6 +213,11 @@ void helper_ld_fpscr(CPUSH4State *env, uint32_t val) set_flush_to_zero((val & FPSCR_DN) !=3D 0, &env->fp_status); } =20 +void helper_ld_fpscr(CPUSH4State *env, uint32_t val) +{ + cpu_load_fpscr(env, val); +} + static void update_fpscr(CPUSH4State *env, uintptr_t retaddr) { int xcpt, cause, enable; --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380531; cv=none; d=zohomail.com; s=zohoarc; b=DnteyRfjpeWf0Fo96YFHiLva7VjrmDxSPr5HyoIEBAYrHuARH5yZLseqhgQLDefZk2pltAnon3ylzWuiW5qhrGOBDPitK1igW3Qp1n+9RXRVYpZAttqQgXIuhJjCk3NA/a+IykW7sohCOc8zYYaNDSyQUGqENUJXwc6dCE8VheY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380531; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lmuBmfZ7FoObCoN7EQdjB050T5jbXXe9KakeXPZoHCU=; b=PB1GfI3A24rAErVpfwLvc6id8cN13tA0J/qGUz1WOzEoAePpqZ5Gpm4jEleuBgqcPSRaj2kEeT1TeGrP9j66lCuwUcLsXnKj2fa9f4s+Emg3IZCXLEQVcmZ10cKAufbpiI6Ilxzs5YK/+qyKvUQruljmlh3VSaDAOOB9RWtexTc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17813805316091005.6753820668999; Sat, 13 Jun 2026 12:55:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUR4-0005Ww-25; Sat, 13 Jun 2026 15:54:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQu-0005Ng-Dz; Sat, 13 Jun 2026 15:54:21 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQs-0004D1-9F; Sat, 13 Jun 2026 15:54:19 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 16E3F1B6E30; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 70F5F3CE8AA; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=jzTERscFogQIAubT8OAwUrpBgRPGf1ywHEbZJuQg5x0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=SZPheyTtWfhPmdMc6GHgOBIbqd9jT7RuJ9ii7lp4xV56xuk4jj1E0fUVjdEkfreyq 9TKwDi6gppqf9i0D2eGA6SCFn0Z9Ae/Tq9+M3sXCKxpvkL9fkeRkqfvA3trihCFLOH KtEYHR4aeM8cEpgSmNIKSV9pufzYOZc8HpkeHnN+UQn/Q5RArXMOiDCpmYENQLNZf6 Zj/zCCh5GlL36enSeH/EOB0WJ/yAhH/ZvOvGnRGTWbrMObFQ8S7eq9Ma6h24scuYom J71SCRqFEz7udW7oy1MmHS/VINsxQ7h357KQKzrrml3/HLpBnkNEa3VZnaR7icq9gY xDYKvQXKuslfA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-10.0.11 33/56] linux-user/s390x: restore fpu_status rounding mode from FPC on sigreturn Date: Sat, 13 Jun 2026 22:50:47 +0300 Message-ID: <20260613195116.1807273-33-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380534584158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the s390x floating-point control register (FPC) in env->fpc. The rounding mode bits [2:0] of FPC are reflected into the derived env->fpu_status via set_float_rounding_mode(); every architectural write to FPC goes through HELPER(sfpc) which keeps the two in sync. restore_sigregs() restored FPC with a direct assignment: __get_user(env->fpc, &sc->fpregs.fpc); This wrote env->fpc correctly but never updated env->fpu_status, so on sigreturn the interrupted code resumed with whatever rounding mode the signal handler last installed in fpu_status. Factor the two-step "write fpc + sync fpu_status" logic out of HELPER(sfpc) into cpu_s390x_load_fpc(), declare it in cpu.h, and call it from restore_sigregs() in place of the direct assignment. cpu_s390x_load_fpc() partially reuses the sanity check from HELPER(sfpc): if the FPC value has an invalid rounding mode or reserved bits set, it falls back to 0, matching the kernel's fpu_lfpc_safe() behavior where a corrupt signal frame value causes a specification exception and 0 is used instead. HELPER(sfpc) now calls cpu_s390x_load_fpc() after its full specification-exception check, including the FEAT_FLOATING_POINT_EXT test that is not needed for the signal restore path. Fixes: 2941e0fa05 ("linux-user/s390x: Save/restore fpc when handling a sign= al") Cc: qemu-stable@nongnu.org Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 2762cd51ee033dccb3167110376dd125244cc819) Signed-off-by: Michael Tokarev diff --git a/linux-user/s390x/signal.c b/linux-user/s390x/signal.c index df49c24708..40455b6deb 100644 --- a/linux-user/s390x/signal.c +++ b/linux-user/s390x/signal.c @@ -331,7 +331,11 @@ static void restore_sigregs(CPUS390XState *env, target= _sigregs *sc) for (i =3D 0; i < 16; i++) { __get_user(env->aregs[i], &sc->regs.acrs[i]); } - __get_user(env->fpc, &sc->fpregs.fpc); + { + uint32_t fpc; + __get_user(fpc, &sc->fpregs.fpc); + cpu_s390x_load_fpc(env, fpc); + } for (i =3D 0; i < 16; i++) { __get_user(*get_freg(env, i), &sc->fpregs.fprs[i]); } diff --git a/target/s390x/cpu.h b/target/s390x/cpu.h index 5b7992deda..afd0d28bad 100644 --- a/target/s390x/cpu.h +++ b/target/s390x/cpu.h @@ -942,6 +942,7 @@ void s390_init_sigp(void); /* helper.c */ void s390_cpu_set_psw(CPUS390XState *env, uint64_t mask, uint64_t addr); uint64_t s390_cpu_get_psw_mask(CPUS390XState *env); +void cpu_s390x_load_fpc(CPUS390XState *env, uint32_t fpc); =20 /* outside of target/s390x/ */ S390CPU *s390_cpu_addr2state(uint16_t cpu_addr); diff --git a/target/s390x/tcg/fpu_helper.c b/target/s390x/tcg/fpu_helper.c index 5041c13962..6216e0accd 100644 --- a/target/s390x/tcg/fpu_helper.c +++ b/target/s390x/tcg/fpu_helper.c @@ -897,6 +897,19 @@ static const int fpc_to_rnd[8] =3D { float_round_to_odd, }; =20 +void cpu_s390x_load_fpc(CPUS390XState *env, uint32_t fpc) +{ + /* + * Mimic kernel fpu_lfpc_safe(): a corrupt signal frame value that wou= ld + * trigger a specification exception instead results in FPC being set = to 0. + */ + if (fpc_to_rnd[fpc & 0x7] =3D=3D -1 || fpc & 0x03030088u) { + fpc =3D 0; + } + env->fpc =3D fpc; + set_float_rounding_mode(fpc_to_rnd[fpc & 0x7], &env->fpu_status); +} + /* set fpc */ void HELPER(sfpc)(CPUS390XState *env, uint64_t fpc) { @@ -904,12 +917,7 @@ void HELPER(sfpc)(CPUS390XState *env, uint64_t fpc) (!s390_has_feat(S390_FEAT_FLOATING_POINT_EXT) && fpc & 0x4)) { tcg_s390_program_interrupt(env, PGM_SPECIFICATION, GETPC()); } - - /* Install everything in the main FPC. */ - env->fpc =3D fpc; - - /* Install the rounding mode in the shadow fpu_status. */ - set_float_rounding_mode(fpc_to_rnd[fpc & 0x7], &env->fpu_status); + cpu_s390x_load_fpc(env, fpc); } =20 /* set fpc and signal */ --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380706; cv=none; d=zohomail.com; s=zohoarc; b=PooT9OXM/2daTia3GW3prsxYOSQMO4tRd0JycdKoTGRe4eWN0M3nIndJg2O9+5KtE8OuPIGSMwqx2bwvEesnXhunwg+6eDe97nPLwrwSVGPyzcOn4AnaTDXNunezfxPyIaEPR+sw/Myux9A+9+ujdqLU6dqx3jsqtvvQuo5KxPM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380706; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=n5/RTjME5Bg0wLTahflcb+ZhNvEq1ejEwy735f5EjoQ=; b=Vy6+oSfFwdpAufAW6Lo3jYwO4WHyZdpmGbd+sSIwYe6h+yRPKtFxX+A04c4+tH6T9vYglkAWOSbvGVr7KQKYK0u2MCj7HtRXubRRgiYwN/Nj3WzohmSTDt12NWnmLjuhr8Phppoc5LgqqDljUhZ3+Tb9Fcf6f/JANZoYYbD1aps= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138070694168.31400357822997; Sat, 13 Jun 2026 12:58:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUR7-0005vl-5s; Sat, 13 Jun 2026 15:54:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQv-0005Os-SK; Sat, 13 Jun 2026 15:54:23 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQu-0004DQ-8B; Sat, 13 Jun 2026 15:54:21 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 27DE21B6E31; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7F6F23CE8AB; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=ljiZBRqzHv0X/sjo4RwbqU2uUMc/lkd7pP77zy4UuEs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TBSeaBUpg9/cIQ1HZsrlRfo2Cog+Ms9LVuw8nUnDP926tJwhFv1D0rcqACbVgBfXp oknI8sS94N3FTgl/oRMl8ZphcF+54kbwgPuR85PxcqLniwDjtWnuqzTaCt9iRsLbxO In16jNtm3MAUa6EWwl5RK+gZQFyRbvKPVnJDb2qA/49mbZgfjSXwHFki8GUGECj8HR qYT+o8rTbfBLV0k2h22otPYPlnLdAVVcIQFdK5aKpaMukpMnz0w/jfV0Hrd9YyVF/o 9fNT0+thn5PYAhBERTk3BJQJ5x3stelmA8SD0B1OsQYYhdbz4CLSXfas5r+bt3pWlc LujX/bf8xqUHw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Sean Wei , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.11 34/56] hw/9pfs: move G_GNUC_PRINTF to header Date: Sat, 13 Jun 2026 22:50:48 +0300 Message-ID: <20260613195116.1807273-34-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380707096158500 From: Sean Wei v9fs_path_sprintf() is annotated with G_GNUC_PRINTF(2, 3) in hw/9pfs/9p.c, but the prototype in hw/9pfs/9p.h is missing the attribute, so callers that include only the header do not get format checking. Move the annotation to the header and delete the duplicate in the source file. No behavior change. Signed-off-by: Sean Wei Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-ID: <20250613.qemu.9p.02@sean.taipei> [CS: fix code style (max. 80 chars per line)] Signed-off-by: Christian Schoenebeck (cherry picked from commit 44f51c1a3cf435daa82eb757740b59b1fd4fe71c) (Mjt: pick this harmless one up so the next changes applies cleanly) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 74dbf95a63..bf05b1b6c5 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -201,8 +201,7 @@ void v9fs_path_free(V9fsPath *path) } =20 =20 -void G_GNUC_PRINTF(2, 3) -v9fs_path_sprintf(V9fsPath *path, const char *fmt, ...) +void v9fs_path_sprintf(V9fsPath *path, const char *fmt, ...) { va_list ap; =20 diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index 259ad32ed1..65cc45e344 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -456,7 +456,8 @@ static inline uint8_t v9fs_request_cancelled(V9fsPDU *p= du) void coroutine_fn v9fs_reclaim_fd(V9fsPDU *pdu); void v9fs_path_init(V9fsPath *path); void v9fs_path_free(V9fsPath *path); -void v9fs_path_sprintf(V9fsPath *path, const char *fmt, ...); +void G_GNUC_PRINTF(2, 3) v9fs_path_sprintf(V9fsPath *path, const char *fmt, + ...); void v9fs_path_copy(V9fsPath *dst, const V9fsPath *src); size_t v9fs_readdir_response_size(V9fsString *name); int v9fs_name_to_path(V9fsState *s, V9fsPath *dirpath, --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380701; cv=none; d=zohomail.com; s=zohoarc; b=FQ0dtyYBzQbug6q5aPgFv8WZtj6BnRjUT9X63uL62S2X0WGdbDrpKLhXXimjSBAb3gqSmMyQqqm/YXGS36XhdjOcFHBveKLRDhEfNMYhvKSlJytwlm7CrI4DQUdwrHY0jrfcuTDdBqjel74s3k38HAYLuqLq/PyMTnG1J/iot9I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380701; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=pQWM2ANe19sRK5LRK+ja7u3IXt7MDarh0DULh8+eSUk=; b=UUfMevaUK1iCs3thBch23eAPAjccL0/CTc3no6wWyslqkrcPNZkvoKxmdSnb1uBLM2CzsVpwAcorpMUW5ZQO3VXRw1cGFXE2IdF5Nl0QnlGmerAhYsSlb3iG2HbZG/7wk1aItqOagLE4PmWgnmNLZueuWmEGnZlLU2tMLvKI21Y= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380701188409.28130709878724; Sat, 13 Jun 2026 12:58:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUR6-0005qs-FC; Sat, 13 Jun 2026 15:54:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQy-0005Qk-1e; Sat, 13 Jun 2026 15:54:25 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUQw-0004E8-4t; Sat, 13 Jun 2026 15:54:23 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 401721B6E32; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 90AA23CE8AC; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=qiPCt8dMH0b5By4gC1b3e2aCBQ8A4A8/xqo8O3Qw5f4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=WqlWydbJIKYPTOez8K5KCcFvhI/mIVurEar46iP7X4cCHnuP1xJTWqOw6k3R9OwOR +56bfmiv8xLbtW9tLymIwUtrw5h5o0PSZAZroiesjreEOflIpes5FZWjFJ+QW3HSfT /Znvh5Lv+7Mu1W84fBgDp/qb7voL12Lr6xmwudnLNVKcSk2KGzMsI2yE5QCDXBApUl 3guI/35gvQmwPR5ZHvL1v2op3FcHvHwB9FP+dZOwCupEsCIgEZaY/bQBnSED6kownj fpUwVUc38gljhSQcHC2fDkpAs/RsDEGinKJ0KBoS1P+c+A1UWRz3GCOQXZ9wonXB71 DKjJsTY+UDVnQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.11 35/56] hw/9pfs: add NULL check in v9fs_path_is_ancestor() Date: Sat, 13 Jun 2026 22:50:49 +0300 Message-ID: <20260613195116.1807273-35-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380703135158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add NULL check for s1->data and s2->data before using them in string operations. This prevents potential crashes when dealing with uninitialized paths. This is just a defensive measure. We are currently never passing NULL to this function. Link: https://lore.kernel.org/qemu-devel/3348c4d683f061c23083bd45994d527be4= fb7cbc.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit abb0cc02fb56e2432837e34b80fe68768f95e774) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index bf05b1b6c5..018402c1a1 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -239,6 +239,9 @@ int v9fs_name_to_path(V9fsState *s, V9fsPath *dirpath, */ static int v9fs_path_is_ancestor(V9fsPath *s1, V9fsPath *s2) { + if (!s1->data || !s2->data) { + return 0; + } if (!strncmp(s1->data, s2->data, s1->size - 1)) { if (s2->data[s1->size - 1] =3D=3D '\0' || s2->data[s1->size - 1] = =3D=3D '/') { return 1; --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380642; cv=none; d=zohomail.com; s=zohoarc; b=lYQpKTZ+N2Szu1987J4D4E0lbXNuEP6IE8iDWY7AuBYydhiwnX1U0EF0s/ceajn2NUnFlq+fZDhAvUZI3gUmzdPJS5zBUIpI620XvdJ48tQMH1Z3LfP9Kqq3X0WRpv6rmnaMWU3ozWkBsZp8GjOF3BJ2YzOYLeoDnZgV8/YK+zo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380642; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6mxP6554ofX0nOl/zVp/OnRiOoC1nh1l20y4a2MfW7I=; b=ONJ1OvL3l0sirlJkyzdy2T3nVgY0DbqqblbiakvaeZpueOjXayEbxfmrLH2eOrtw+QqCrKFqoKyGN7XQLJyIvblZclnfdU5mGnifup1B8zzgn6mWOxnNBjmoYrY8xbWsJuRSSHjy9yOkF6CQ9sj4ACHm/MGO4M4wYM5PJUjhd4U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380642537924.4589068922221; Sat, 13 Jun 2026 12:57:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYURL-0007Fz-7Z; Sat, 13 Jun 2026 15:54:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURJ-0007Cs-T8; Sat, 13 Jun 2026 15:54:45 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURI-0004EP-5r; Sat, 13 Jun 2026 15:54:45 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 4E5DD1B6E33; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id A8E703CE8AD; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=vMsRVCuwCDrEku/uByBfWnq0mU9pQrQJkKAYYpa+2IM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TICenNfoSMigDhEiggvRgxFRRpC3XjUdv9pdz9rLC/JkHy3CmFx1CVR8feczAY2z4 Ocr0pqO8u0jTz2DkYpLIwM76dqrVyd5rQUVTkV0WE+uQFV/EMw6TfJMjB33XY3ckHa oigF3gk8Pt+ZEzJMQugS78x4ysqtyU3/FKRnI3tEZDUzIQoe+Pqce7gE6ugPekxgq3 qbVeT4kt8VpZoGdneyAOcDZWZHQrgdZzregp+H6tRrcQIv9fS0wODgPkuaecYHRUA+ eSycpP+3XstrWZqOftGELSERo5Hr7E1n5n1qe+qAsbMb9ZWzpCqBcyV+0B5wvMw9Y/ C7QbxCT5FAlHg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.11 36/56] hw/9pfs: change V9fsPath.size to size_t and v9fs_path_sprintf() return type Date: Sat, 13 Jun 2026 22:50:50 +0300 Message-ID: <20260613195116.1807273-36-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380642827158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck - Change V9fsPath.size from uint16_t to size_t to support paths larger than 65536 bytes. - Change v9fs_path_sprintf() return type from void to int to allow error reporting. Link: https://lore.kernel.org/qemu-devel/2d2348d94ff43fbe4cc0aea24fb312c5c1= 5ee809.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit dbaf84e148b0c8b66dcb47788a6bb13806e401e4) Signed-off-by: Michael Tokarev diff --git a/fsdev/file-op-9p.h b/fsdev/file-op-9p.h index 4997677460..c453b6494b 100644 --- a/fsdev/file-op-9p.h +++ b/fsdev/file-op-9p.h @@ -110,7 +110,7 @@ struct FsContext { }; =20 struct V9fsPath { - uint16_t size; + size_t size; char *data; }; P9ARRAY_DECLARE_TYPE(V9fsPath); diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 018402c1a1..c439fecf5c 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -201,16 +201,24 @@ void v9fs_path_free(V9fsPath *path) } =20 =20 -void v9fs_path_sprintf(V9fsPath *path, const char *fmt, ...) +int v9fs_path_sprintf(V9fsPath *path, const char *fmt, ...) { va_list ap; + int ret; =20 v9fs_path_free(path); =20 va_start(ap, fmt); - /* Bump the size for including terminating NULL */ - path->size =3D g_vasprintf(&path->data, fmt, ap) + 1; + ret =3D g_vasprintf(&path->data, fmt, ap); va_end(ap); + if (ret < 0) { + error_report_once("9pfs: unusual path formatting failure; " + "invalidating associated FID"); + return -1; + } + /* Bump the size for including terminating NULL */ + path->size =3D ret + 1; + return 0; } =20 void v9fs_path_copy(V9fsPath *dst, const V9fsPath *src) diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index 65cc45e344..b2df659b0e 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -456,8 +456,8 @@ static inline uint8_t v9fs_request_cancelled(V9fsPDU *p= du) void coroutine_fn v9fs_reclaim_fd(V9fsPDU *pdu); void v9fs_path_init(V9fsPath *path); void v9fs_path_free(V9fsPath *path); -void G_GNUC_PRINTF(2, 3) v9fs_path_sprintf(V9fsPath *path, const char *fmt, - ...); +int G_GNUC_PRINTF(2, 3) v9fs_path_sprintf(V9fsPath *path, const char *fmt, + ...); void v9fs_path_copy(V9fsPath *dst, const V9fsPath *src); size_t v9fs_readdir_response_size(V9fsString *name); int v9fs_name_to_path(V9fsState *s, V9fsPath *dirpath, --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380646; cv=none; d=zohomail.com; s=zohoarc; b=DWV1T9YIT8U1fY6HNjo7jF3/G/dqNzwRzDn8tpIrd69SnrAu2kc7d/1GUdzyKOAKw0t1iOPjac/TKF6sukEks2uGtb5/ShzF8PhGzIppZiinoe9MJBEThfHr4saxrApuPB/DH7CEptcypsJaTbhUjFiTRi1Hm6+DBKJtb6S7w2M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380646; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6iaAV4wFvybvD5QYBHB7q4CD2DECrApmpioFeiEj8a0=; b=J4CbdODXEojXN2IEX+e4yA8+kJLlignSd0J7MkE/b6ZS/L6jJL4PC7oLNZrp96P0GZfqWt54ZwgZCMsTQIxBW7N0htoJ+Zf1219glWFTKCbeJGX1KgCFgva6XckG+RIHCDxf3mfchMrMUGmVQiZ61BMaJl7vErR5Ib/llb5NwMc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380646790208.04949521713274; Sat, 13 Jun 2026 12:57:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYURM-0007KG-VA; Sat, 13 Jun 2026 15:54:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURL-0007GZ-MZ; Sat, 13 Jun 2026 15:54:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURJ-0004Ex-US; Sat, 13 Jun 2026 15:54:47 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 675B31B6E34; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B6E3E3CE8AE; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=SdGDZFdD/4V4Mw/3tAMa7XZO+qTSfaLogGTks896J1I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=KffTiG5Wo1er651hR+NxH2Hnvy6A9n7mu1VxoxkcU6cOs8Z/TRlVfeBNakrYtXwGT mus2+jeIggW1fzjW2hdY9dLGxGYXZ4yjRu1J+7v2pjS6YPFuYcXeS7TB6+zPpWE75V QW6wb/Z/6iYaezoO8MjGCDDmp1uhjF3p8o53cHKJQ5nvUoQc39rgsdZlPussADvUNp bMG026fOTbjvNXC9aFj9g+q388hI0FqWFn9SBk1Avza4BUHUilS9mliNFEuEx8FjFW cwIsT1HMIt9e/hgfNW0u+lmqFcYDotjDElvdnJsKQRTBwopY9ct+c7XWexPb0M0XRs Q8t1cnei0StBg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.11 37/56] hw/9pfs: add error handling to v9fs_fix_path() Date: Sat, 13 Jun 2026 22:50:51 +0300 Message-ID: <20260613195116.1807273-37-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380648837158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Update v9fs_fix_path() to return int and propagate errors from v9fs_path_sprintf(). This allows callers to detect and handle path formatting failures. Link: https://lore.kernel.org/qemu-devel/a0592741a918b7cbe751980ec7ec0c03f5= 05924c.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 54dd352c59269fdb5241e7b6dbcecaff107e7f5a) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index c439fecf5c..a4ebbce5d6 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -1407,13 +1407,15 @@ static void print_sg(struct iovec *sg, int cnt) } =20 /* Will call this only for path name based fid */ -static void v9fs_fix_path(V9fsPath *dst, V9fsPath *src, int len) +static int v9fs_fix_path(V9fsPath *dst, V9fsPath *src, int len) { V9fsPath str; + int ret; v9fs_path_init(&str); v9fs_path_copy(&str, dst); - v9fs_path_sprintf(dst, "%s%s", src->data, str.data + len); + ret =3D v9fs_path_sprintf(dst, "%s%s", src->data, str.data + len); v9fs_path_free(&str); + return ret; } =20 static inline bool is_ro_export(FsContext *ctx) --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380805; cv=none; d=zohomail.com; s=zohoarc; b=jM3SR9uv7BpoLBBZRoHlfJHNQy9Ctb4FJ2ZEO8F3ilxVAFN3bM5GMn46WS2xM/jwDLTm0UasiqwtQwL6alh1OUbZW0lP567DDZ490FSZGxrLLPs1Fkvz2WdVmxyc1/72N4Aw+EYF7ZQfPzpiCYZh2YFavDhyAlKra5uodJobZ08= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380805; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gcKEV9wdCKosOp/nFQsPtU8RPejPq2Nt/154M46yYik=; b=EpaDkGbPjkrYljZSmijzWFYb/xom28zIt7aSzvl4sBXhSJKwTjXjZA1FYUMPVyYd51+g1cLvfiRgs+zEFC+kvPBY+hCmyOWc0IIhNZ60afO/O8XmOuA9IRA+egi3HsGS8UGZ5+BfkPswBuYzJJlzAGHgPbRHRbRKOfK+LPM8lGs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17813808054411023.0055557769368; Sat, 13 Jun 2026 13:00:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYURQ-0007Mx-16; Sat, 13 Jun 2026 15:54:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURN-0007Le-VC; Sat, 13 Jun 2026 15:54:49 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURM-0004JD-1Y; Sat, 13 Jun 2026 15:54:49 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 768BC1B6E35; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id CFFAC3CE8AF; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=Bm7Wys1D0tjjtNRwoqgFNMii+XlEExctWDXCQ/8d92A=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=FBOXm6mMCli8UiSgtTH5a9kicBMeteuGl2fnyaq4xd3VIjsd/HG5TI7ejP7Y0UsNO BdMLPg6zibqAhqlmXw6korSmChoqojCSZy70E3f7256oalsH/PrCbthzpiV6Y0Xi7O LYoXZoNJczujpjEDOqiZU936j1+Y2QwZSadJ1U0AUg0PanIYsK1C0QybQVnkSMpVHI t4schfQzwyonFjz624xUb/VDAmwmeOamkKwi8oEk1IcmLFurzdPcyi595w3RWtZBR1 lqp7yOv8FBcmQFuD89JW31g2kxHKqPV48vBc78tDSUkD/OfoamJ6g5/huwcFVArCUC AIoQL1jmWRC+w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Wang Jihe , Michael Tokarev Subject: [Stable-10.0.11 38/56] hw/9pfs: let callers of v9fs_path_sprintf() and v9fs_fix_path() handle errors Date: Sat, 13 Jun 2026 22:50:52 +0300 Message-ID: <20260613195116.1807273-38-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380807583158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck This patch mitigates issues with very large absolute paths. - Add error handling to all v9fs_path_sprintf() calls in local_name_to_path() - Update callers of v9fs_fix_path() to check return values. - When path formatting fails, clunk the affected FIDs to prevent use of invalid paths. - Use g_autofree for temporary variables to simplify code. Even though paths are usually limited to PATH_MAX (typically 4k) on guest, this limitation can be circumvented by using *at() functions on guest and creating very deep directory structures. This was a problem for QEMU 9p server, as it currently tracks the absolute path for each FID internally that always requires assembly of a (potentially ver large) absolute path. A true long-term fix would be getting rid of storing an absolute path for each FID internally. However that would likely be a massive change with uncertain implications. This patch therefore just mitigates the problem by immediately clunking (i.e. closing) all FIDs whose path exceed a limit that we could handle. As this only accounts to very unusual large absolute paths not ever been reported on (sane) production machines, this is currently considered an acceptable mitigation that should only (counter)affect malicious attempts. Fixes: 2f008a8c97e2 ("hw/9pfs: Use the correct signed type ...") Reported-by: Wang Jihe Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3358 Link: https://lore.kernel.org/qemu-devel/1d11dcbfc95b811dcdb48c6d7f3894d0eb= d073a2.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 3802c0e755a53b126e717415b54226a468bf7ddf) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p-local.c b/hw/9pfs/9p-local.c index 928523afcc..5167c43609 100644 --- a/hw/9pfs/9p-local.c +++ b/hw/9pfs/9p-local.c @@ -1243,26 +1243,35 @@ static int local_name_to_path(FsContext *ctx, V9fsP= ath *dir_path, } else if (!strcmp(name, "..")) { if (!strcmp(dir_path->data, ".")) { /* ".." relative to the root is "." */ - v9fs_path_sprintf(target, "."); + if (v9fs_path_sprintf(target, ".") < 0) { + return -1; + } } else { - char *tmp =3D g_path_get_dirname(dir_path->data); + g_autofree char *tmp =3D g_path_get_dirname(dir_path->data= ); /* Symbolic links are resolved by the client. We can assume * that ".." relative to "foo/bar" is equivalent to "foo" */ - v9fs_path_sprintf(target, "%s", tmp); - g_free(tmp); + if (v9fs_path_sprintf(target, "%s", tmp) < 0) { + return -1; + } } } else { assert(!strchr(name, '/')); - v9fs_path_sprintf(target, "%s/%s", dir_path->data, name); + if (v9fs_path_sprintf(target, "%s/%s", dir_path->data, name) <= 0) { + return -1; + } } } else if (!strcmp(name, "/") || !strcmp(name, ".") || !strcmp(name, "..")) { /* This is the root fid */ - v9fs_path_sprintf(target, "."); + if (v9fs_path_sprintf(target, ".") < 0) { + return -1; + } } else { assert(!strchr(name, '/')); - v9fs_path_sprintf(target, "./%s", name); + if (v9fs_path_sprintf(target, "./%s", name) < 0) { + return -1; + } } return 0; } diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index a4ebbce5d6..7d53f070cc 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -3304,12 +3304,14 @@ static int coroutine_fn v9fs_complete_rename(V9fsPD= U *pdu, V9fsFidState *fidp, goto out; } } else { - char *dir_name =3D g_path_get_dirname(fidp->path.data); + g_autofree char *dir_name =3D g_path_get_dirname(fidp->path.data); V9fsPath dir_path; =20 v9fs_path_init(&dir_path); - v9fs_path_sprintf(&dir_path, "%s", dir_name); - g_free(dir_name); + err =3D v9fs_path_sprintf(&dir_path, "%s", dir_name); + if (err < 0) { + goto out; + } =20 err =3D v9fs_co_name_to_path(pdu, &dir_path, name->data, &new_path= ); v9fs_path_free(&dir_path); @@ -3330,7 +3332,10 @@ static int coroutine_fn v9fs_complete_rename(V9fsPDU= *pdu, V9fsFidState *fidp, while (g_hash_table_iter_next(&iter, &fid, (gpointer *) &tfidp)) { if (v9fs_path_is_ancestor(&fidp->path, &tfidp->path)) { /* replace the name */ - v9fs_fix_path(&tfidp->path, &new_path, strlen(fidp->path.data)= ); + if (v9fs_fix_path(&tfidp->path, &new_path, + strlen(fidp->path.data)) < 0) { + clunk_fid(s, tfidp->fid); + } } } out: @@ -3427,7 +3432,10 @@ static int coroutine_fn v9fs_fix_fid_paths(V9fsPDU *= pdu, V9fsPath *olddir, while (g_hash_table_iter_next(&iter, &fid, (gpointer *) &tfidp)) { if (v9fs_path_is_ancestor(&oldpath, &tfidp->path)) { /* replace the name */ - v9fs_fix_path(&tfidp->path, &newpath, strlen(oldpath.data)); + if (v9fs_fix_path(&tfidp->path, &newpath, + strlen(oldpath.data)) < 0) { + clunk_fid(s, tfidp->fid); + } } } out: --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380608; cv=none; d=zohomail.com; s=zohoarc; b=DmNh325nPbgUQ8xvafgTDbJEH/MymVdbcPMJVSRo6Z89yTg+In9Fqrn0bgXCUg8PA+bb5hMBNgcfOlCTCywYb5iCzXXz3eGx6Bw/C61QY7RUcO0jm95Nn0yE4tzz7ZgrVBkLhFHIc80pVQg7ZRTGzy5HxenJn6Kv+63N99jdZY4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380608; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=J6LCqzs9vIbfGq0lgiP1F9Qa3b0UeB7Teq8mNQghdl0=; b=MheDiNM9NGlu30JUilbygXS8dNQaogJsTHlgFT1aYMoogs9ZPETri8XP5BGEg47voTLql8/TDeg3d0aaekC4LQv8DHJNCc5RDCbm8KBoXycxT5QmjWMvmAugzR7cdo6TITc41KF0sZFc9zBYpUM7ryYdMJGD7jXhXMkhC6aAvKo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138060878665.29103088962336; Sat, 13 Jun 2026 12:56:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYURR-0007RG-4e; Sat, 13 Jun 2026 15:54:53 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURP-0007M6-15; Sat, 13 Jun 2026 15:54:51 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURN-0004L6-A7; Sat, 13 Jun 2026 15:54:50 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 85EEB1B6E36; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id DF2803CE8B0; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=VhI+fbgmarYkeYX4Ah1lvu9hKCxU9Pd13pZKpXtCVes=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=MW4FR9Vp/UtLeXqBXTzwMBF2Qwz5izi5VGeSt6bU7SoEBQgLMnHk0blY9lh93BIXQ 0W6t0/af8bXly19hBjZink5uXYnXGF5mtJDcKRgbL9m9Ko4oDifSnnrV0wX2jYabPR DgE+WYMuKJ2FGq9jeNWqIsI5l1ZKvBmpObvXwcen7V740NzxJr61lYrjRLc3V7CyKb pPEjijLf67xuB24In+2gH8p1x+klXaS83rjaC+J3E4R3CaVKsk6Ghp49XqvuvPhI5I pwe2bnyKPUWWWpEH73EaLewfNRf/OzZQPlsMWm+5Xt4cb08iQwwIApNbdSPVAsN5S0 B8Svr8VtyKK+g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Fabiano Rosas , Michael Tokarev Subject: [Stable-10.0.11 39/56] tests/qtest/libqos: add qvirtqueue_reset_pool() for descriptor pool reset Date: Sat, 13 Jun 2026 22:50:53 +0300 Message-ID: <20260613195116.1807273-39-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380610691158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add a function to reset the virtqueue descriptor pool state without reinitializing the device. This is useful for tests that issue a high number of requests and are limited by the simplified virtio test driver's descriptor tracking, which decrements num_free but never increments it back. The function is safe for synchronous test code where requests are sent and completed before the next request is issued. Acked-by: Fabiano Rosas Link: https://lore.kernel.org/qemu-devel/96cf23eea1204b34443218fe76bd4a5eaf= 9163e8.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit be33c56898f8b18617cff91525f0b68abee8de07) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/libqos/virtio.c b/tests/qtest/libqos/virtio.c index 2e7979652f..dfa94700cb 100644 --- a/tests/qtest/libqos/virtio.c +++ b/tests/qtest/libqos/virtio.c @@ -442,6 +442,29 @@ bool qvirtqueue_get_buf(QTestState *qts, QVirtQueue *v= q, uint32_t *desc_idx, return true; } =20 +/* + * qvirtqueue_reset_pool: + * @vq: The virtqueue to reset + * + * Reset the descriptor pool state without reinitializing the device. + * This is useful for tests that issue a high number of requests and + * are limited by the simplified virtio test driver's descriptor tracking, + * which decrements num_free but never increments it back. + * + * This is only safe for synchronous test code where requests are + * sent and completed before the next request is issued. Do not use + * with asynchronous code where multiple requests may be in-flight. + * + * Note: This only resets the available descriptor pool (free_head, + * num_free). The used ring position (last_used_idx) is NOT reset + * and should continue to track consumed responses across iterations. + */ +void qvirtqueue_reset_pool(QVirtQueue *vq) +{ + vq->free_head =3D 0; + vq->num_free =3D vq->size; +} + void qvirtqueue_set_used_event(QTestState *qts, QVirtQueue *vq, uint16_t i= dx) { g_assert(vq->event); diff --git a/tests/qtest/libqos/virtio.h b/tests/qtest/libqos/virtio.h index 7adc7cbd10..d6486ba7f9 100644 --- a/tests/qtest/libqos/virtio.h +++ b/tests/qtest/libqos/virtio.h @@ -148,6 +148,8 @@ void qvirtqueue_kick(QTestState *qts, QVirtioDevice *d,= QVirtQueue *vq, bool qvirtqueue_get_buf(QTestState *qts, QVirtQueue *vq, uint32_t *desc_id= x, uint32_t *len); =20 +void qvirtqueue_reset_pool(QVirtQueue *vq); + void qvirtqueue_set_used_event(QTestState *qts, QVirtQueue *vq, uint16_t i= dx); =20 void qvirtio_start_device(QVirtioDevice *vdev); --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380665; cv=none; d=zohomail.com; s=zohoarc; b=RXaABHd+87Ihzufk2Go+rQDI7eM77kKci8RcUmEmC8WNzVXFJ5eEGbr9dqtAV89Yt1HdpPF2RIm33DXqs2on77F59ESjyFlasRLJuH7HuojDgBt8uuaqEiBOlhXywjegJC566+p4p9VZPl02LnEWIbcNyI4Kan6pP0n8/GUt/NY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380665; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fqu6TxxYxK1K8O6Qg+3IpTx0W1JpiJpbxpjy+pa0u54=; b=eWbdhwPUWhK8x+IiZwvR9VykAH8ErGght8Vm2o0GGk3AU00akADOiBffHXa1SH0oCUr1uB9ta2bD7frrvHL7VScVb1IYXk7dCApy+dUZvS9tqaJf5ddJxk1RkBnXKGopbXmJuw5CZgBUjJXhxlqYRu+hpNjoVOFXmdKMeQgtMK0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380665047241.5564205594427; Sat, 13 Jun 2026 12:57:45 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYURo-0008Ie-Op; Sat, 13 Jun 2026 15:55:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURm-00085d-3M; Sat, 13 Jun 2026 15:55:14 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURj-0004Me-On; Sat, 13 Jun 2026 15:55:13 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9438D1B6E37; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id EEBB83CE8B1; Sat, 13 Jun 2026 22:51:18 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=zIjMO7cYvxNr5VKrgmQojc0T7AyXklUFu4iF5bq3erg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=kVorTBVfxC4PIEPzIUQC1Yw9V8oCfHD66QGlBDs4sYeKZ7BHQqn/OBjmyKgYERva0 0I8tU7JMYVLqxag+9vF6t9AGr8zZo0yf/+3SqyDx96tYXc64iAm3abUSTbLZTvHi4q AaWbGRRrZuEfupmYZUhP94X1XLC0I5Ldbs/zqb74R7Y0xC003DHn/wDf3r6Pzy4fqz GnvgQENCZBCQ2Cj9Uk0sr1hCiv0OeIpe2RvQ9g1veMzTZMssVkDb6lvqZml2tYo83R 5QCoxx6h1BOWAS9FvccIJO+qEc67oflSUbFKy3Fp0Y+AZw1wVLNmTzuFWWcVg1KDtW HtTsv0fXZ/9ZQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.11 40/56] tests/9pfs: add deep absolute path test Date: Sat, 13 Jun 2026 22:50:54 +0300 Message-ID: <20260613195116.1807273-40-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380666927158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add fs_deep_absolute_path test that creates a deep directory structure with an absolute path length exceeding 16-bit range (i.e. >65536) to verify the previous buffer overflow fix. This is a slow test (may take several seconds) and therefore registered as "slow" test and not running by default. Use -m slow to run this test. Link: https://gitlab.com/qemu-project/qemu/-/issues/3358 Link: https://lore.kernel.org/qemu-devel/933552b2cfc2c442fac7f4e68c777dce20= ee8d7e.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 198627807a6b94e2aab157cf345f98edb1ac1a7a) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index ab3a12c816..1af02e9c7b 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -14,6 +14,7 @@ =20 #include "qemu/osdep.h" #include "qemu/module.h" +#include "libqos/virtio.h" #include "libqos/virtio-9p-client.h" =20 #define twalk(...) v9fs_twalk((TWalkOpt) __VA_ARGS__) @@ -737,6 +738,72 @@ static void fs_use_after_unlink(void *obj, void *data, g_assert_cmpint(count, =3D=3D, write_count); } =20 +/* https://gitlab.com/qemu-project/qemu/-/issues/3358 */ +static void fs_deep_absolute_path(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + QVirtio9P *v9p =3D obj; + v9fs_set_allocator(t_alloc); + + if (!g_test_slow()) { + g_test_skip("This is a slow test, run with -m slow"); + return; + } + + GString *path =3D g_string_new("/"); + char name[256]; + uint32_t current_fid =3D 0; + + tattach({ .client =3D v9p }); + + /* Create deep directory structure until absolute path length + * exceeds 16-bit range. + */ + while (path->len <=3D 65536) { + /* use 255-byte name (NAME_MAX) to reduce iterations to ~257 */ + memset(name, 'A', 255); + name[255] =3D '\0'; + + /* create the directory relative to current FID */ + tmkdir({ + .client =3D v9p, + .dfid =3D current_fid, + .name =3D name + }); + + /* just for locally tracking the current path length */ + g_string_append(path, name); + g_string_append(path, "/"); + + /* acquire new FID for the newly created directory */ + char *wnames[] =3D { name }; + current_fid =3D twalk({ + .client =3D v9p, + .fid =3D current_fid, + .nwname =3D 1, + .wnames =3D wnames + }).newfid; + + /* Reset descriptor pool to avoid exhaustion. The simplified + * virtio test driver does never free descriptors back to the pool + * after use, so we must manually reset it for the required high + * amount of 9p requests here. + */ + qvirtqueue_reset_pool(v9p->vq); + } + + /* check if the deepest directory is accessible */ + v9fs_attr attr =3D {}; + tgetattr({ + .client =3D v9p, + .fid =3D current_fid, + .request_mask =3D P9_GETATTR_BASIC, + .rgetattr.attr =3D &attr + }); + + g_string_free(path, TRUE); +} + static void cleanup_9p_local_driver(void *data) { /* remove previously created test dir when test is completed */ @@ -804,6 +871,8 @@ static void register_virtio_9p_test(void) &opts); qos_add_test("local/use_after_unlink", "virtio-9p", fs_use_after_unlin= k, &opts); + qos_add_test("local/deep_absolute_path", "virtio-9p", + fs_deep_absolute_path, &opts); } =20 libqos_init(register_virtio_9p_test); --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380689; cv=none; d=zohomail.com; s=zohoarc; b=UEEKJqdzlF5huP5ThMdmIyCt8aLlCw+pgJCsx4WcqYZ9I7A3lisCIkSJ4qa1AXI/X6XDA2jyvnlvlkr9lgsrxfDJqVlHnlwH3JLx+//2XaNhhCzTukACm6zRdaL8oWclSwqkqa7wx091frZTobukcMseFjegYFw4W4/htPUhRec= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380689; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=pf6kZave+aYPhBygq+cYxHhIHxSPXK5O7sO8Jwo/slM=; b=FgxfsQyhPyZrmhfvfeoTtDIIGzzxTwYjNoIhbzAtStbLeqqiLk4x3wy3WTz25IpB0LREmyZmTKheS1phTSgwq8EuGbkaYsiDnEzRbF8J5rEFT4bQYeO3Wmd1F9CMY4TkI6Z96uQoLhlmJcWSgTJQXKv8e94dn8AWg9FqGOCtl2M= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380689163829.7797440103885; Sat, 13 Jun 2026 12:58:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYURv-0008Ti-CE; Sat, 13 Jun 2026 15:55:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURm-0008B2-Ok; Sat, 13 Jun 2026 15:55:14 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURk-0004Mu-Oh; Sat, 13 Jun 2026 15:55:14 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A2DA41B6E38; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0808B3CE8B2; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=BTqlEL4AFb9mrESs6c3B1it3riQ7IvgDAgb6lD8UHNU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=rqcMhirfG1JbxIT6ZIqnSUp3zrmspjMY9v9E2yYN5FLKjuGMPAymPNfQF33H1KCJ8 7zVl4qevUeVEhWtXBTCojwoRFtPni6msRpebxBJMGZ+qZySii7dGQgsy8FXxpn1r6Z Q3ZuEoUJmpQcbI7NXIW0zXvCT+rWGxVluWQxnkvtF7TpnoX/sX1N/HqnwV1Gzuj8aC 0gnhb1GJXM3stjchGmIt0N1JkuWFX5VcQb7WxOhEzv0366L7mSiPnbVrTryhDzTmYv nLWN7XyayG5l9FLAcPG1uuz2E6VOLdd2LT3eJhjR7dH3XezZJvgxlB5gsnjFPhZRFL qjRZs+ONxydiw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, sin99xx , Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.11 41/56] 9pfs: fix missing rename lock in v9fs_co_readdir_many (CVE-2026-48004) Date: Sat, 13 Jun 2026 22:50:55 +0300 Message-ID: <20260613195116.1807273-41-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380691010158500 Content-Type: text/plain; charset="utf-8" From: sin99xx v9fs_co_readdir_many() dispatches do_readdir_many() to a worker thread that reads V9fsFidState's path.data without holding a rename lock. A concurrent rename request, e.g. of its parent dir, causes the FID's absolute path to be altered by freeing the old path string and assigning a new one. This causes a heap-use-after-free race condition while do_readdir_many() is still accessing the old object. This allows a DoS by an unprivileged guest user. Fix this by wrapping the worker thread dispatch block within a pair of v9fs_path_read_lock() and v9fs_path_unlock() calls, like it's done at other places. Fixes: 2149675b195f ("9pfs: add new function v9fs_co_readdir_many()") Fixes: CVE-2026-48004 Reported-by: sin99xx Signed-off-by: sin99xx [Christian Schoenebeck: add commit log message] Link: https://lore.kernel.org/qemu-devel/E1wPkYi-000adH-4E@kylie.crudebyte.= com Signed-off-by: Christian Schoenebeck (cherry picked from commit 5a8da7e979f1f56b1cab82c2354833f309f1a78f) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/codir.c b/hw/9pfs/codir.c index 2068a4779d..2dd9206f1d 100644 --- a/hw/9pfs/codir.c +++ b/hw/9pfs/codir.c @@ -219,13 +219,16 @@ int coroutine_fn v9fs_co_readdir_many(V9fsPDU *pdu, V= 9fsFidState *fidp, bool dostat) { int err =3D 0; + V9fsState *s =3D pdu->s; =20 if (v9fs_request_cancelled(pdu)) { return -EINTR; } + v9fs_path_read_lock(s); v9fs_co_run_in_worker({ err =3D do_readdir_many(pdu, fidp, entries, offset, maxsize, dosta= t); }); + v9fs_path_unlock(s); return err; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380563; cv=none; d=zohomail.com; s=zohoarc; b=YUuSUFqMzRoSam/0nka+DyvzOeIjfvSje2sJ57CU9rEQ5B4bccDgkEVqoa9qJR3H9UXerF170+wUJNtvPhpFF2mG99U2lbN5RRVpZzoJ/rIEwpWeys1PZPEQGDK8IgiH8gGqci0hWXsmRzXlQP2Q4tF7M4ImrPJFt6P8apUy2iY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380563; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lEIED/Wc9tzJFjCP7matfedwXpt/sEA5sQFT6daDr6M=; b=lpB3IMdfpq3pRqBm0dM9HnzYTY458XuVXv2y8nB9eTKKhBQn+jAK7ZToDf99kyvpinB34lZJ5DOXYRLEprF8X2Fczblc9m43MOF+nImYZP4gTZnBuPiKHqS9nOFHWDqwI47dg0AIvg+BDsexM+Y8xII6RvaSuhrdedPLiK50GQg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380563508903.6196070954034; Sat, 13 Jun 2026 12:56:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUS0-0008Ve-TN; Sat, 13 Jun 2026 15:55:29 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURq-0008Rp-26; Sat, 13 Jun 2026 15:55:18 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURn-0004fO-R9; Sat, 13 Jun 2026 15:55:17 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B54071B6E39; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 17F8B3CE8B3; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=L7RCWWMvQS+EFrMDUd1cQg3OODBBHJtF30sWO9d+Tds=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=w6O2a+ajSmo2TgJjg7dM5wwuV35Wer6GhFTO2V0pY4RSFfoS7HtjukKrdW55GjXnn jnZ6HP+RQDQ8HJqJ7+ah1+YCXZ7ICut8XUr7z/qRMzaXXxfXpxW+VjHAbDv5Yj1Q4X hYr9Nk3NPCAUGvm9tkwuvbyB98Wyz+T665NRJYjXBczbNTPZYYug/aoCbJDnCiSGMK LWebTgMYORLVNu/HtW153bLc3y6zvaOgqiUCM5quMPz9i1DvLVJwLQTu6sULmiz2UN MZ4Ga/7Avl1UfCt0LnRetKwR326byktT5ZPyl+5ZO/VQ4hVqxy6DNXW82tVdD1CoSE 1ISYyCvAAO3kg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Markus Armbruster , Paolo Bonzini , Michael Tokarev Subject: [Stable-10.0.11 42/56] util/envlist: fix prefix-match in envlist_unsetenv() name lookup Date: Sat, 13 Jun 2026 22:50:56 +0300 Message-ID: <20260613195116.1807273-42-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380564680158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" envlist_unsetenv() looked up the entry to remove with strncmp(entry->ev_var, env, strlen(env)). The comparison length is the requested name's length, so any stored entry whose name *starts* with that name compares equal. envlist_setenv() inserts at the head of the list, so the first hit wins: with FOO=3D... stored first and FOOBAR=3D... stored afterward, envlist_unsetenv("FOO") iterates from the head, matches FOOBAR=3D... on the prefix, and drops it instead of FOO=3D... linux-user and bsd-user reach this code via the -U command-line switch, so the bug is reachable from a normal qemu-user invocation. envlist_setenv() used the same strncmp pattern but with envname_len =3D (eq_sign - env + 1), so the '=3D' byte sat inside the compared window and acted as an implicit boundary. setenv was therefore not buggy -- but the safety lived in the byte layout of ev_var rather than in the entry, so a future edit could easily drift the two sites apart again. Store the name length on each entry at insertion time and compare with explicit length equality plus memcmp via a small helper. Use the helper at both lookup sites so the boundary becomes a structural property of the entry: envlist_unsetenv() stops prefix-matching, and envlist_setenv()'s self-search no longer depends on the '=3D' byte serving as a sentinel. Fixes: 04a6dfebb6b5 ("linux-user: Add generic env variable handling") Signed-off-by: Denis V. Lunev Reviewed-by: Stefan Hajnoczi Message-id: 20260520212628.479772-2-den@openvz.org Cc: Stefan Hajnoczi Cc: Markus Armbruster Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi (cherry picked from commit c131ae56c13ffe6bd7089cf0d9bd00a7c2dbc71f) Signed-off-by: Michael Tokarev diff --git a/util/envlist.c b/util/envlist.c index 15fdbb109d..196c92c190 100644 --- a/util/envlist.c +++ b/util/envlist.c @@ -3,7 +3,8 @@ #include "qemu/envlist.h" =20 struct envlist_entry { - const char *ev_var; /* actual env value */ + const char *ev_var; /* actual env value: "NAME=3DVALUE" */ + size_t ev_name_len; /* length of NAME (offset of '=3D') */ QLIST_ENTRY(envlist_entry) ev_link; }; =20 @@ -12,6 +13,13 @@ struct envlist { size_t el_count; /* number of entries */ }; =20 +static inline bool envlist_name_eq(const struct envlist_entry *entry, + const char *name, size_t name_len) +{ + return entry->ev_name_len =3D=3D name_len && + memcmp(entry->ev_var, name, name_len) =3D=3D 0; +} + /* * Allocates new envlist and returns pointer to it. */ @@ -67,7 +75,7 @@ envlist_setenv(envlist_t *envlist, const char *env) /* find out first equals sign in given env */ if ((eq_sign =3D strchr(env, '=3D')) =3D=3D NULL) return (EINVAL); - envname_len =3D eq_sign - env + 1; + envname_len =3D eq_sign - env; =20 /* * If there already exists variable with given name @@ -76,8 +84,9 @@ envlist_setenv(envlist_t *envlist, const char *env) */ for (entry =3D envlist->el_entries.lh_first; entry !=3D NULL; entry =3D entry->ev_link.le_next) { - if (strncmp(entry->ev_var, env, envname_len) =3D=3D 0) + if (envlist_name_eq(entry, env, envname_len)) { break; + } } =20 if (entry !=3D NULL) { @@ -90,6 +99,7 @@ envlist_setenv(envlist_t *envlist, const char *env) =20 entry =3D g_malloc(sizeof(*entry)); entry->ev_var =3D g_strdup(env); + entry->ev_name_len =3D envname_len; QLIST_INSERT_HEAD(&envlist->el_entries, entry, ev_link); =20 return (0); @@ -119,8 +129,9 @@ envlist_unsetenv(envlist_t *envlist, const char *env) envname_len =3D strlen(env); for (entry =3D envlist->el_entries.lh_first; entry !=3D NULL; entry =3D entry->ev_link.le_next) { - if (strncmp(entry->ev_var, env, envname_len) =3D=3D 0) + if (envlist_name_eq(entry, env, envname_len)) { break; + } } if (entry !=3D NULL) { QLIST_REMOVE(entry, ev_link); --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380641; cv=none; d=zohomail.com; s=zohoarc; b=C+Oxv/jV4DsWWLG9jhSQAgqtS6tzSuyra0f0gWQizX1b69qY9bImNRb67ve+lp3u6Az31+5IITYVe2u+o1fy15HnAS6mHR+d08gHadlh9aF07GwJRGYbY80cVI9Cg9X/GsVcBN+gub1zk1uTpk+OrOPtzDksRxJS5toSe5CJ6iU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380641; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hN60S8v4GpCT4dbT4Yfx73EnrDfGE16D5EOkm59e+2w=; b=feStRqeLgwwnYDFszLemQ3EUZG4YXIlW4S+LeHostFD41g7emKppGgH4O0EwbjK0NiFkrIRfE7X2Id+V+52Kd+mMj7S/j48ZKXlmATE6FV0vTW4L8PQQMV2u2q1eG15jiJ+pALh76PAzelShAV9wNaEh7u3kPAf+JMwMhjG7sM0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380641393281.06186919825564; Sat, 13 Jun 2026 12:57:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUSK-0000W5-Eb; Sat, 13 Jun 2026 15:55:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURr-0008Tp-Dn; Sat, 13 Jun 2026 15:55:22 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURo-0004fg-Li; Sat, 13 Jun 2026 15:55:19 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C61601B6E3A; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 297DE3CE8B4; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=rpvjZq/2pzh5O9kB+yE4Ip4VINuiyEDjuByKZP0xWxM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VbEas/il91NBintHdq7rBhIt/kU0fG5zKXVshDYOfuoBhctz8bKaM8/kc2SBfjpWq BoQDYMdOBuvrJdrjYvgLC4COntv5uHoFvJg1Wl/EWc9khey/3fJVQr/Fde+Uq4GWtY a8N3y2U1kIWPrWlxqh/c6iaPkzptrVXh5rqyWBN72xNOFPJAt5CBZjoHFQtUZ0fm3I fjKwULiXO1EY8tiSCvwUbq1y5odSB2x0zszH8rSkLtjMVJALDv0q/wjQe0ZIP2miaf PUqurelTDmC7O9pADiJ0KiQdyvk6OJs1TDhrLPU90eIu+F6C4Uy/jdAG8JV9tKhSjf Mk4MacLSS13tA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Markus Armbruster , Paolo Bonzini , Michael Tokarev Subject: [Stable-10.0.11 43/56] tests/unit: add test-envlist covering setenv/unsetenv name matching Date: Sat, 13 Jun 2026 22:50:57 +0300 Message-ID: <20260613195116.1807273-43-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380642930158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" util/envlist had no test coverage. Add tests/unit/test-envlist exercising the public envlist API and pinning down the prefix-match hazard fixed in the previous commit: - envlist_unsetenv("FOO") must not remove an entry named "FOOBAR"; - envlist_setenv("FOO=3D...") must not replace an existing "FOOBAR=3D..." entry placed earlier in the list (envlist_setenv() inserts at the head, so the first prefix match wins under the old strncmp rule). Also cover the rest of the contract: head-insertion order observed through envlist_to_environ(), replacement of an existing variable, the count argument of envlist_to_environ(), and the documented EINVAL paths (NULL inputs, setenv without '=3D', unsetenv with '=3D'). Signed-off-by: Denis V. Lunev Reviewed-by: Stefan Hajnoczi Message-id: 20260520212628.479772-3-den@openvz.org Cc: Stefan Hajnoczi Cc: Markus Armbruster Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi (cherry picked from commit 05221c600a5f3ef657d71aeaea632c5f1bab3a2d) Signed-off-by: Michael Tokarev diff --git a/tests/unit/meson.build b/tests/unit/meson.build index d5248ae51d..1a85f85d18 100644 --- a/tests/unit/meson.build +++ b/tests/unit/meson.build @@ -48,6 +48,7 @@ tests =3D { 'test-qapi-util': [], 'test-interval-tree': [], 'test-fifo': [], + 'test-envlist': [], } =20 if have_system or have_tools diff --git a/tests/unit/test-envlist.c b/tests/unit/test-envlist.c new file mode 100644 index 0000000000..53813dd4de --- /dev/null +++ b/tests/unit/test-envlist.c @@ -0,0 +1,196 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +/* + * envlist tests + * + * Copyright 2026 Virtuozzo International GmbH + * + * Authors: + * Denis V. Lunev + */ + +#include "qemu/osdep.h" +#include "qemu/envlist.h" + +static void free_environ(char **env) +{ + char **p; + + for (p =3D env; *p !=3D NULL; p++) { + g_free(*p); + } + g_free(env); +} + +static const char *find_env(char **env, const char *name) +{ + size_t name_len =3D strlen(name); + char **p; + + for (p =3D env; *p !=3D NULL; p++) { + if (strncmp(*p, name, name_len) =3D=3D 0 && (*p)[name_len] =3D=3D = '=3D') { + return *p + name_len + 1; + } + } + return NULL; +} + +static void test_envlist_basic(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + /* empty list */ + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 0); + g_assert_null(env[0]); + free_environ(env); + + /* add */ + g_assert_cmpint(envlist_setenv(el, "A=3D1"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "B=3D2"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "A"), =3D=3D, "1"); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* replace */ + g_assert_cmpint(envlist_setenv(el, "A=3D42"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "A"), =3D=3D, "42"); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* unset existing */ + g_assert_cmpint(envlist_unsetenv(el, "A"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + g_assert_null(find_env(env, "A")); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* unset non-existing is a no-op success */ + g_assert_cmpint(envlist_unsetenv(el, "NOPE"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + free_environ(env); + + envlist_free(el); +} + +/* + * envlist_setenv() inserts at the head; envlist_to_environ() walks + * head-to-tail, so the last setenv comes out first. + */ +static void test_envlist_head_insertion_order(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "A=3D1"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "B=3D2"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "C=3D3"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 3); + g_assert_cmpstr(env[0], =3D=3D, "C=3D3"); + g_assert_cmpstr(env[1], =3D=3D, "B=3D2"); + g_assert_cmpstr(env[2], =3D=3D, "A=3D1"); + g_assert_null(env[3]); + + free_environ(env); + envlist_free(el); +} + +static void test_envlist_einval(void) +{ + envlist_t *el =3D envlist_create(); + + /* NULL list */ + g_assert_cmpint(envlist_setenv(NULL, "A=3D1"), =3D=3D, EINVAL); + g_assert_cmpint(envlist_unsetenv(NULL, "A"), =3D=3D, EINVAL); + + /* NULL string */ + g_assert_cmpint(envlist_setenv(el, NULL), =3D=3D, EINVAL); + g_assert_cmpint(envlist_unsetenv(el, NULL), =3D=3D, EINVAL); + + /* setenv: missing '=3D' */ + g_assert_cmpint(envlist_setenv(el, "NOEQ"), =3D=3D, EINVAL); + + /* unsetenv: name must not contain '=3D' */ + g_assert_cmpint(envlist_unsetenv(el, "A=3DB"), =3D=3D, EINVAL); + + envlist_free(el); +} + +/* + * Regression: envlist_unsetenv("FOO") must not remove an entry named + * "FOOBAR" -- the previous strncmp(entry, name, strlen(name)) lookup + * prefix-matched. To trigger the bug, the longer-named entry has to + * be ahead of the target in the list: envlist_setenv() inserts at + * the head, so we add FOO first and FOOBAR last. + */ +static void test_envlist_unsetenv_no_prefix_match(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "FOO=3Dy"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "FOOBAR=3Dx"), =3D=3D, 0); + + g_assert_cmpint(envlist_unsetenv(el, "FOO"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + g_assert_cmpstr(find_env(env, "FOOBAR"), =3D=3D, "x"); + g_assert_null(find_env(env, "FOO")); + + free_environ(env); + envlist_free(el); +} + +/* + * envlist_setenv() must not replace a prior FOOBAR=3D... entry when + * setting FOO=3D... The pre-fix code happened to be safe here only + * because it included the trailing '=3D' byte in its strncmp length; + * this test pins down the post-fix contract that the name boundary + * is a property of the entry, not of the encoded form. + */ +static void test_envlist_setenv_no_prefix_match(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "FOOBAR=3Dx"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "FOO=3Dy"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "FOOBAR"), =3D=3D, "x"); + g_assert_cmpstr(find_env(env, "FOO"), =3D=3D, "y"); + + free_environ(env); + envlist_free(el); +} + +int main(int argc, char *argv[]) +{ + g_test_init(&argc, &argv, NULL); + + g_test_add_func("/envlist/basic", test_envlist_basic); + g_test_add_func("/envlist/head_insertion_order", + test_envlist_head_insertion_order); + g_test_add_func("/envlist/einval", test_envlist_einval); + g_test_add_func("/envlist/unsetenv_no_prefix_match", + test_envlist_unsetenv_no_prefix_match); + g_test_add_func("/envlist/setenv_no_prefix_match", + test_envlist_setenv_no_prefix_match); + + return g_test_run(); +} --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380664; cv=none; d=zohomail.com; s=zohoarc; b=BLdK3xH7GS7F9QCMjz561/1M/p5jcFEqQ+AHTzsVImgzvR6YxLRis2/nSfgN8Aat5UZ5/H+1RMzRsYkPlXWbdJXCSUcog5vVYovlh8ZKQAAjwKuhFyX8QNxfxRxBtEMS8jRvdQ0ZhQjTV2WAypXl3mYffK8txiuAaz2ufdJuq00= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380664; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8yarpF3uFCTgUZucjlrToJ5iK4crFWl2kfvhEgnIJMY=; b=U6wVkIj6PXE2ysN0OyodOREY5HUHJknpNZzZIWAaKCGzfSJNlNFUXKiZ8rC26yMA7pZmJFU1UVq7/oUupt0bAZUhebmaz4auA66HY3SJ2ZbjWZV8Gi6UVJaMNxHi/f9y7MtFC1iEMbjfefH6ILs+Vm2R+JpYJaPLcXxpWEU+wwU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380664434875.6130514636425; Sat, 13 Jun 2026 12:57:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUS7-00007o-E7; Sat, 13 Jun 2026 15:55:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURt-0008Tv-IW; Sat, 13 Jun 2026 15:55:23 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYURr-0004go-PZ; Sat, 13 Jun 2026 15:55:21 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id DA7951B6E3B; Sat, 13 Jun 2026 22:51:00 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 3A5D53CE8B5; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380260; bh=/yCG3jEExQpedxSgTR2/aw27BcSv2Xz3e8r7g1a46fI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=nsIMFkMXBOnEYeLl4IPNGnPdw3desYd7sJ89cMkYPKxbUjlpDO5445paGG+1Rj4kc h/b2Ve5FtLHih1Q7a6ztlp5yuZeN/eY3a6D+hC5/GfUbthLbCKYtXnB3h40XcWLUnQ w2Hz6QZsj0Y9HlCxjP9wt1syfCrcND1M2BCnZJvwt+fHdt/S33ydqCOWB9jjJorAx5 oEewSuQB2W8WYQf+u3aEcjpOZIvU5w8bbpldzsHgHBn0VkgaN1X4sS6nnbLx8L2f47 wLY5CKEzuszkxHVz7EY/7Fnap8FTQR9MGImyOYXeFvjtlogUFmUt4OaiEtz4xgH24x kZw13fYsk3i4A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alexandra Winter , Hendrik Brueckner , Christian Borntraeger , Gautam Gala , Cornelia Huck , Michael Tokarev Subject: [Stable-10.0.11 44/56] target/s390x: Make container ids in SysIB_15x 1-based Date: Sat, 13 Jun 2026 22:50:58 +0300 Message-ID: <20260613195116.1807273-44-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380665163158500 Content-Type: text/plain; charset="utf-8" From: Alexandra Winter The Container Id in a container-type TLE of SysIB_15x is defined as 8-bit unsigned nonzero integer. Make stsi fc 15 emulation architecture compliant, by starting the container ids at 1 for the lowest numbered container. The qemu misbehaviour without this patch becomes obvious due to a recently proposed kernel fix. Older linux kernels pass the container ids from stsi fc15 unchanged to sysfs, i.e. starting at 1 on s390 hardware. This resulted in off-by-one values when compared to the values from HMC. A Linux kernel fix is being proposed to correct the sysfs topology ids by -1, so they start at 0, e.g. when displayed by 'lscpu -ye'. In case a KVM guest with a fixed kernel runs on a host with a qemu without this fix, this can result in container ids erroneously being shown as 255. Example (Fixed guest on unfixed qemu): $ lscpu -ye CPU NODE DRAWER BOOK SOCKET CORE L1d:L1i:L2 ONLINE CONFIGURED POLARIZATION = ADDRESS 0 0 255 255 255 0 0:0:0 yes yes vert-medium 0 1 0 255 255 0 1 1:1:1 yes yes vert-medium 1 After this fix: $ lscpu -ye CPU NODE DRAWER BOOK SOCKET CORE L1d:L1i:L2 ONLINE CONFIGURED POLARIZATION = ADDRESS 0 0 0 0 0 0 0:0:0 yes yes vert-medium 0 1 0 0 0 1 1 1:1:1 yes yes vert-medium 1 Fixes: f4f54b582f ("target/s390x/cpu topology: handle STSI(15) and build th= e SYSIB") Signed-off-by: Alexandra Winter Acked-by: Hendrik Brueckner Acked-by: Christian Borntraeger Reviewed-by: Gautam Gala Message-ID: <20260511134909.43802-1-wintera@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit 1f1ccb6f3c48a2cd80e874d66afeef2dc28a65f3) Signed-off-by: Michael Tokarev diff --git a/target/s390x/kvm/stsi-topology.c b/target/s390x/kvm/stsi-topol= ogy.c index c8d6389cd8..af3fd8ad1b 100644 --- a/target/s390x/kvm/stsi-topology.c +++ b/target/s390x/kvm/stsi-topology.c @@ -90,9 +90,9 @@ static int stsi_topology_fill_sysib(S390TopologyList *top= ology_list, int last_drawer =3D -1; int last_book =3D -1; int last_socket =3D -1; - int drawer_id =3D 0; - int book_id =3D 0; - int socket_id =3D 0; + int drawer_id =3D 1; + int book_id =3D 1; + int socket_id =3D 1; int n =3D sizeof(SysIB_151x); =20 QTAILQ_FOREACH(entry, topology_list, next) { @@ -103,12 +103,12 @@ static int stsi_topology_fill_sysib(S390TopologyList = *topology_list, if (level > 3 && drawer_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); p =3D fill_container(p, 3, drawer_id++); - book_id =3D 0; + book_id =3D 1; } if (level > 2 && book_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); p =3D fill_container(p, 2, book_id++); - socket_id =3D 0; + socket_id =3D 1; } if (socket_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380658; cv=none; d=zohomail.com; s=zohoarc; b=bV0xCxn1Xxn3pZ11t/ObSM5lSBIJ/cmEoZdMj4RRv85JHw67OHZCLWBm0pi+7W12/qxHEo0V/DfLKOThggMg7Kkv9kiPEZh2UKAqQXUcMN8pee7WQxJTqC4C26GSRCaIksXB83DhOZpBLLq3PbBKi9vPrDzko/Tm5l3npw+7PHo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380658; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=E+YZf1QtSTYO6YPy/8p3z+THZHpGYPfzlYiAjXEWkl8=; b=Q6+3FKvL8Rk96ze9NHD6LFFAHwwItLd5swNSx8Y5y90l3x7FaqJtdXuIWOFP8zAUHlTGJE9BsWuy0xKnkFt6ZzXmd8pCn2av9cZ71V03yKof3X8HYbvqQdqc9MueHUdEcI5OvJkrmsWzi8mnKujGXuDe06fGtEUtAK6QX+cn3uY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380658745186.53242658814884; Sat, 13 Jun 2026 12:57:38 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUSL-0000hP-Iq; Sat, 13 Jun 2026 15:55:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSG-0000NG-62; Sat, 13 Jun 2026 15:55:45 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSD-0004h8-5m; Sat, 13 Jun 2026 15:55:42 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 03A0A1B6E3C; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 4E3423CE8B6; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=5/rsleK4VKiBqumnsjYhUN9Uc6/t1nX/VfUewIfRMcc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=RcDCt4CGlMKVb46QqVCU0g0v9OQBaKLu0CjsSsZM1SJe6Baqz1rrz4C6/jJjGLoKt FL+vs8xOaAu1hYKA1hlavsDhsqPG0KaHW0IzymTh/0GS40bP+NMRLxvdT8MIgdSQ2V 8nY68SvJtT6AAXyNhC5HICvVImmxcPMv10WIZjL8+7GnbWMKdsLlXhzWnDy1ZlUqff 3guAh1ScuC+qMgZgkXzF00wUwFmQLN1r1uLdBoRxfYSKK48qqaTcNrDgS1ZvsX0gCw gm42nDCwNOyCvluTh/gnf1uOWNNsQEn94h3mh40OwASgezuPu99sUSZ5WL7QhR9za/ TPF9uz6IKIXew== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Farhan Ali , Niklas Schnelle , Matthew Rosato , Omar Elghoul , Cornelia Huck , Michael Tokarev Subject: [Stable-10.0.11 45/56] s390x/pci: Fix interrupt forwarding disable for interpreted devices Date: Sat, 13 Jun 2026 22:50:59 +0300 Message-ID: <20260613195116.1807273-45-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380659018158500 Content-Type: text/plain; charset="utf-8" From: Farhan Ali Remove the FH_MASK_ENABLE check when disabling interrupt forwarding during device reset. This check was broken for the default case in the switch statement above, preventing proper cleanup of interrupt forwarding. The pbdev->aif check in s390_pci_kvm_aif_disable() already guards against double-disabling of interrupt forwarding. Cc: qemu-stable@nongnu.org Reported-by: Niklas Schnelle Signed-off-by: Farhan Ali Reviewed-by: Matthew Rosato Tested-by: Omar Elghoul Message-ID: <20260521182946.1607-1-alifm@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit 442f727b8bebabf20a4f6a7536a4ff2885402030) Signed-off-by: Michael Tokarev diff --git a/hw/s390x/s390-pci-bus.c b/hw/s390x/s390-pci-bus.c index 2591ee49c1..8b63156c30 100644 --- a/hw/s390x/s390-pci-bus.c +++ b/hw/s390x/s390-pci-bus.c @@ -1492,7 +1492,7 @@ static void s390_pci_device_reset(DeviceState *dev) break; } =20 - if (pbdev->interp && (pbdev->fh & FH_MASK_ENABLE)) { + if (pbdev->interp) { /* Interpreted devices were using interrupt forwarding */ s390_pci_kvm_aif_disable(pbdev); } else if (pbdev->summary_ind) { --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380769; cv=none; d=zohomail.com; s=zohoarc; b=lQvjILC0kALPe76yPf3VXjvzktvY0nDTToowuqlDe0Zxshewfju1oHVdJrZDd5mDZe1p90mzAalyNWEMckcTNsjrcDdUE9idlzgeIEcL9UZNHQidRzsvTS+QhzmwJlD2pjZMiBzmfsOHUnaMymgXLg5BHw+5eTqUK7ZJu9AokwY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380769; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wVSw/BJg/2ZPsTP3OXAostc3joYaDo4rbxsIRra3M1w=; b=cxkBD9uizSZmEqVPKF81b09og7xklprtkVfLFHKOEPnVcevetJWJeU0yH1F5D6KN07FdMc/1cWbhdG2y4mIziYcAr82s364lMT3BwRi/BuzfUHUDlQMohDqV3NK7a6JlxKvqsWzoWj9c1s5T9peEKKGHohAMgAh4jGWkWAsQRhc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380769011326.48635057459694; Sat, 13 Jun 2026 12:59:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUSN-0000xX-1f; Sat, 13 Jun 2026 15:55:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSI-0000RL-2o; Sat, 13 Jun 2026 15:55:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSF-0004jI-9j; Sat, 13 Jun 2026 15:55:45 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 12B4D1B6E3D; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6BF343CE8B7; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=9UsS+6X8RHNSf6lJpyS8ito1RuJtNyGBg4nwcbWTApE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TQ4wnvebqty1iRYigf7Wp7OS5JwTEWjDdPomiZrEViNgxk0nbrbAWNYqZPhBVUaqk 04QMw6W8p9aRfcBWCs9g+J6R5QZf5415RBwCKgmvpLD6QaTJBOp+HGY44Vn1Pdboo9 NsRWUZZuERrLb7fhqIHRBsOCKrAXZntIXhgpNRt/Ju6V1vVDxYQl9Os77BTauLreC/ 1O+49K/uHdPQsYEMqxVihLstnVmi9qagBbLcLaoOZDve7opL5aaNrMB6FczT93IBxR Ld7YXyOSX/WzJnrhkOr5UdSVgNoU4R5ugQosUU+l6w4QRMqPLz8FH6+wvMg9D2ArZV o31q/W6K9peog== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fiona Ebner , Stefan Hajnoczi , Michael Tokarev Subject: [Stable-10.0.11 46/56] block/io: fallback to bounce buffer if BLKZEROOUT is not supported because of alignment Date: Sat, 13 Jun 2026 22:51:00 +0300 Message-ID: <20260613195116.1807273-46-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380769507158500 Content-Type: text/plain; charset="utf-8" From: Fiona Ebner Commit 5634622bcb ("file-posix: allow BLKZEROOUT with -t writeback") enables the BLKZEROOUT ioctl when using 'writeback' cache, regressing certain 'qemu-img convert' invocations, because of a pre-existing issue. Namely, the BLKZEROOUT ioctl might fail with errno EINVAL when the request is shorter than the block size of the block device. Fallback to the bounce buffer, similar to when the ioctl is not supported at all, rather than treating such an error as fatal. Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3257 Resolves: https://bugzilla.proxmox.com/show_bug.cgi?id=3D7197 Cc: qemu-stable@nongnu.org Signed-off-by: Fiona Ebner Message-ID: <20260105143416.737482-1-f.ebner@proxmox.com> [Added TODO comment describing a larger fix that could be implemented in the future. --Stefan] Signed-off-by: Stefan Hajnoczi (cherry picked from commit b4e28c304bc58325f8f712cb25e5d700826caa25) Signed-off-by: Michael Tokarev diff --git a/block/io.c b/block/io.c index 29d1e84ea7..1e7c8658da 100644 --- a/block/io.c +++ b/block/io.c @@ -1920,7 +1920,18 @@ bdrv_co_do_pwrite_zeroes(BlockDriverState *bs, int64= _t offset, int64_t bytes, assert(!bs->supported_zero_flags); } =20 - if (ret =3D=3D -ENOTSUP && !(flags & BDRV_REQ_NO_FALLBACK)) { + /* + * TODO The ret =3D=3D -EINVAL && num < alignment case is a workar= ound for + * when request_alignment is 1 on files with cache=3Dwriteback. Th= e Linux + * ioctl(BLKZEROOUT) requires block alignment and will fail with + * EINVAL. The block layer should align the request to + * write_zeroes_alignment instead of trying the syscall, failing, = and + * falling back to a bounce buffer. Doing that is not easy so for = now + * we use a bounce buffer: + * https://lore.kernel.org/qemu-devel/20260109120837.2772961-1-f.e= bner@proxmox.com/ + */ + if ((ret =3D=3D -ENOTSUP || (ret =3D=3D -EINVAL && num < alignment= )) && + !(flags & BDRV_REQ_NO_FALLBACK)) { /* Fall back to bounce buffer if write zeroes is unsupported */ BdrvRequestFlags write_flags =3D flags & ~BDRV_REQ_ZERO_WRITE; =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380776; cv=none; d=zohomail.com; s=zohoarc; b=X7bHHPEC5Tnvay4ZNwgAyMvq3wmi9tTNxdZPKD5/p3Ouv+pPP77N95D6Noas+rf3/uz63rvjwABfBL02JR3Dk1VlJb9Qfn+QK76czqBdUFpYWAkaAPCsyVYM0W6Imyf24G8lMhmXzXsHASTeCeqHnZdkpoO3SdUlHqeYplmsaIk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380776; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4/WsRsuf/0C0rKwsnEwRAQwyzyyuqFDDbD/dv1ag8fw=; b=THdPq4bGLmaX1ACrQ/np8cCCgDQWXE/koRNbpnP1JREuavEoFf0GD+RY6ySnNUaEnv5+Yy1wctdvwskMnNpFYOYq815bLMqfmmZ/isFn95Q/qIvOpxU77r+bKmjk80GHvbzNuWHocedBlk3Ui4rjIJ5H1lRGwWgG+MhAuAvdS3E= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138077676311.393908845079636; Sat, 13 Jun 2026 12:59:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUSM-0000vA-QC; Sat, 13 Jun 2026 15:55:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSJ-0000Vf-Oq; Sat, 13 Jun 2026 15:55:48 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSI-0004n4-66; Sat, 13 Jun 2026 15:55:47 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 257FC1B6E3E; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7B4EF3CE8B8; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=LkH5qk2YoO9eDK46e5ppGBdSzMNPpSzzsoNyAuBkG9k=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=KY75LCAYv8sO8438vFU+RgsiW6HAmsFt3wvya39kRjkcGc6ee9mYpCc2LWBCoYk1c 4ZuOicaHQR8PQwo9E+Kg4r9lodzMj38SUcwI/I4hr2arf+i7ab2pRoBVqYgJitaaTG orUN9T7t3J4wFvhFoNdo49w2djdgu8plKIkK0A/KP72VTCitR4ZzPhBiiy3RqiauDY 2qT0RcASPJTsXVfL77CgYBlPdpDeIJgAGqGJHwSJGvzVkvYBKd/VrxxUM3CjNe7yvG 4+rA1X67qWiB8b1uWlCokV7hsmy0DNWDW9pvix/vSmPgWoMg24B+0vtQTcfEEwQpPK +X7omTkYftSYg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Stefan Hajnoczi , Feifan Qian , Paolo Bonzini , Kevin Wolf , Michael Tokarev Subject: [Stable-10.0.11 47/56] virtio-blk: add missing VIRTIO_BLK_T_SCSI_CMD size check (CVE-2026-48914) Date: Sat, 13 Jun 2026 22:51:01 +0300 Message-ID: <20260613195116.1807273-47-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380777306158500 Content-Type: text/plain; charset="utf-8" From: Stefan Hajnoczi Check that the iovec containing struct virtio_scsi_inhdr is large enough before storing an error value there. Feifan Qian pointed out that this can be used to corrupt heap memory when the descriptor uses an MMIO address and a length of 1, forcing QEMU to allocate a 1-byte heap bounce buffer. virtio_stl_p() stores 4 bytes and therefore corrupts whatever is beyond the bounce buffer. Fixes: CVE-2026-48914 Fixes: f34e73cd69bd ("virtio-blk: report non-zero status when failing SG_IO= requests") Reported-by: Feifan Qian Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi Message-ID: <20260526154957.1741622-1-stefanha@redhat.com> Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit aeea0c2804c42f24915467a1e4c70e649e39b8e0) Signed-off-by: Michael Tokarev diff --git a/hw/block/virtio-blk.c b/hw/block/virtio-blk.c index add6ad9d55..8b9739c2c3 100644 --- a/hw/block/virtio-blk.c +++ b/hw/block/virtio-blk.c @@ -203,10 +203,16 @@ static void virtio_blk_handle_scsi(VirtIOBlockReq *re= q) =20 /* * The scsi inhdr is placed in the second-to-last input segment, just - * before the regular inhdr. + * before the regular inhdr. VIRTIO implementations normally do not re= ly on + * the precise message framing, but legacy implementations did and so = we do + * too for the legacy virtio-blk SCSI request type. * * Just put anything nonzero so that the ioctl fails in the guest. */ + if (elem->in_sg[elem->in_num - 2].iov_len !=3D sizeof(*scsi)) { + status =3D VIRTIO_BLK_S_IOERR; + goto fail; + } scsi =3D (void *)elem->in_sg[elem->in_num - 2].iov_base; virtio_stl_p(vdev, &scsi->errors, 255); status =3D VIRTIO_BLK_S_UNSUPP; --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380685; cv=none; d=zohomail.com; s=zohoarc; b=W4RcYppvhFrsrrqQ7ehu2RsvfsH68rEXnXh4OxFt6CeiwKaYY2D3WyWCDXhdseaoVgSLbJlXer4Ux5v4umwCHaEenZagl4/E1dqqiTB71LOY/dc5foRLE0hvejTEZ1ChoK94hzHqnQVamjgHyAZpEe0rp2ko4MglRKZ75Wb7tP4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380685; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=kPRoR6Y4vKY65iZQNM4x0/upq0V5iiOWNlAtuLI6rO8=; b=UgeoIH7VkfTqF7dl1w6AUGo4x/WmJanBwBkC0ThYkkRHrvp8OtIBC6IETUQPVCFchuTKF4Nqobj72c9US6H8G4xObvo6NdwEikH7YtlM8Vr446NDT0P16yDiKTXqsKs3E3bU0lFt2cwpxBOIvGa/j01BAKQDTHntVFFgtxfFsc0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380685847102.55703075563179; Sat, 13 Jun 2026 12:58:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUSO-0001CP-8d; Sat, 13 Jun 2026 15:55:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSL-0000ml-Vm; Sat, 13 Jun 2026 15:55:50 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSJ-0004nP-U4; Sat, 13 Jun 2026 15:55:49 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 347DE1B6E3F; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 8E7633CE8B9; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=yBluAs/gE8DSO3TfUiji3YFG4b/s0M7RfG8jpYCyV4I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=vr7NYSZmZa/AsmSXkMCSgNYvecVtTOZpQcgQnuFvr6qSBZ4K6Up9PJdKweqrd9RVu UXIAcoBH5fmEQC0GnbxYEUCxs9SJrNCdK9OXJkex6rIE8q/HpyiY+pzHtRwm2tfrK0 12dGavwn33cESXBfEfdFmthsu1v6dreXecPtuiOLzpYTc/3lC7nXxChDcaqnDk+6zk 5kKlaPmjM85PSmvLSVAPxUOvkJc/B4vfGkL3dQZhbXedyjChmHPXCyktEq7POpRASQ uPBNkB9tazxDzFLHmNX+wjDjQHSzYgeb+ybXtmwk6f3e9FePc5CTZF6GMreSRAUBBq dipXz9ZNp/kQA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-10.0.11 48/56] qemu-io: Add 'aio_discard' command Date: Sat, 13 Jun 2026 22:51:02 +0300 Message-ID: <20260613195116.1807273-48-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380687043158500 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf Testing interactions between multiple requests that include discard requests require that qemu-io can do the discard asynchronously, like it already does for reads and writes. To this effect, add an 'aio_discard' command. Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-3-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit 7f8466e2ce620e3c6a6e2f32d616367174d4dbe9) Signed-off-by: Michael Tokarev diff --git a/qemu-io-cmds.c b/qemu-io-cmds.c index f6d077908f..de4c1966fe 100644 --- a/qemu-io-cmds.c +++ b/qemu-io-cmds.c @@ -2218,6 +2218,120 @@ static int discard_f(BlockBackend *blk, int argc, c= har **argv) return 0; } =20 +static void aio_discard_help(void) +{ + printf( +"\n" +" asynchronously discards a range of bytes from the given offset\n" +"\n" +" Example:\n" +" 'aio_discard 512 1k' - discards 1 kilobyte from 512 bytes into the file\= n" +"\n" +" Discards a segment of the currently open file.\n" +" -C, -- report statistics in a machine parsable format\n" +" -q, -- quiet mode, do not show I/O statistics\n" +" The discard is performed asynchronously and the aio_flush command must b= e\n" +" used to ensure all outstanding aio requests have been completed.\n" +" Note that due to its asynchronous nature, this command will be\n" +" considered successful once the request is submitted, independently\n" +" of potential I/O errors.\n" +"\n"); +} + +static int aio_discard_f(BlockBackend *blk, int argc, char **argv); + +static const cmdinfo_t aio_discard_cmd =3D { + .name =3D "aio_discard", + .cfunc =3D aio_discard_f, + .perm =3D BLK_PERM_WRITE, + .argmin =3D 2, + .argmax =3D -1, + .args =3D "[-Cq] off len", + .oneline =3D "asynchronously discards a number of bytes", + .help =3D aio_discard_help, +}; + +static void aio_discard_done(void *opaque, int ret) +{ + struct aio_ctx *ctx =3D opaque; + struct timespec t2; + + clock_gettime(CLOCK_MONOTONIC, &t2); + + if (ret < 0) { + printf("aio_discard failed: %s\n", strerror(-ret)); + block_acct_failed(blk_get_stats(ctx->blk), &ctx->acct); + goto out; + } + + block_acct_done(blk_get_stats(ctx->blk), &ctx->acct); + + if (ctx->qflag) { + goto out; + } + + /* Finally, report back -- -C gives a parsable format */ + t2 =3D tsub(t2, ctx->t1); + print_report("discarded ", &t2, ctx->offset, ctx->qiov.size, + ctx->qiov.size, 1, ctx->Cflag); +out: + g_free(ctx); +} + +static int aio_discard_f(BlockBackend *blk, int argc, char **argv) +{ + int c, ret; + int64_t count; + struct aio_ctx *ctx =3D g_new0(struct aio_ctx, 1); + + ctx->blk =3D blk; + + while ((c =3D getopt(argc, argv, "Cq")) !=3D -1) { + switch (c) { + case 'C': + ctx->Cflag =3D true; + break; + case 'q': + ctx->qflag =3D true; + break; + default: + g_free(ctx); + qemuio_command_usage(&aio_discard_cmd); + return -EINVAL; + } + } + + if (optind !=3D argc - 2) { + g_free(ctx); + qemuio_command_usage(&aio_discard_cmd); + return -EINVAL; + } + + ctx->offset =3D cvtnum(argv[optind]); + if (ctx->offset < 0) { + ret =3D ctx->offset; + print_cvtnum_err(ret, argv[optind]); + g_free(ctx); + return ret; + } + optind++; + + count =3D cvtnum(argv[optind]); + if (count < 0) { + print_cvtnum_err(count, argv[optind]); + g_free(ctx); + return count; + } + + clock_gettime(CLOCK_MONOTONIC, &ctx->t1); + ctx->qiov.size =3D count; + block_acct_start(blk_get_stats(blk), &ctx->acct, ctx->qiov.size, + BLOCK_ACCT_UNMAP); + blk_aio_pdiscard(blk, ctx->offset, count, aio_discard_done, ctx); + + return 0; +} + static int alloc_f(BlockBackend *blk, int argc, char **argv) { BlockDriverState *bs =3D blk_bs(blk); @@ -2800,6 +2914,7 @@ static void __attribute((constructor)) init_qemuio_co= mmands(void) qemuio_add_command(&length_cmd); qemuio_add_command(&info_cmd); qemuio_add_command(&discard_cmd); + qemuio_add_command(&aio_discard_cmd); qemuio_add_command(&alloc_cmd); qemuio_add_command(&map_cmd); qemuio_add_command(&reopen_cmd); --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380781; cv=none; d=zohomail.com; s=zohoarc; b=cu3DXzt3DR2hhZN9B+Y3iGndARBZmRjBHtg1ru7JCROQVtzwn8V7yZba/irFTPusZ/ZYSJx0ohZs2AK4tXwfP5C27p/svDR01X5BC32ifynyVna+nV7MDMUv4lBtsj4yWgrRQR9yQlEsNwzf27dntoeBlqsAY2JblT7GrbR6g2s= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380781; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Tzj32r9wyBaPC0iVqlpZB9gQaz9Z+HwLge4UIAG+asE=; b=Ku5hTIYk0uVb1CBzbiCe8vhBTA2t7cpoXd3f3Iy+1ypmMKLr56kM9PJ3YsCpnh/lBye5OsvVKp6Fx/BUu2C7UpI3oz6GTGsTZ7RbPAXlM11lJiP57Y+M8PFfTuKVKTVHBcvetI0AowRAQPRl2JIZJBzygT6eb7J7igz2naUFaWI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380781106194.88264787207106; Sat, 13 Jun 2026 12:59:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUSQ-0001No-0J; Sat, 13 Jun 2026 15:55:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSN-000182-Oc; Sat, 13 Jun 2026 15:55:51 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSL-0004ni-NF; Sat, 13 Jun 2026 15:55:51 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 431071B6E40; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9D4A43CE8BA; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=3eStd9tzp10nIvgv3uD2QnV70tB8KVSRJ2k3TMOWGvA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=qSzNYNvMdC61SXM+3uCyQ0je8ZYxNX0jj+qU3lAXs9GyXikrvTrM1QB3sS/ieSGx0 uzhrDLUVCYqSCPWJg2iaWteVZf9yX52r+kS8So67AyfUXUz+lPZ76v4bmgauIk9+fz VkHdqi2mLl8B1v4BPofG2pX10xli1BmMYPQkX1NTGbSzLdHdfGAI11wwQajIkBi424 Oe/yDsrMho8l8B53UaLpBRGwA49804Oy5nTQhV6bIj34PIx/XfHPJ7INgfD5AnaLFQ OinJVVo6XquFKPvnJgnKBHPoRwYZyIWUFfvg5t58NJS1a38vg7SRgehvx/bZeOYsSq 97AT/SrOxEqHQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-10.0.11 49/56] qcow2: Fix corruption on discard during write with COW Date: Sat, 13 Jun 2026 22:51:03 +0300 Message-ID: <20260613195116.1807273-49-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380781387158500 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf Most code in qcow2 that accesses (and potentially modifies) L2 tables does so while holding s->lock. There is one exception, which is allocating writes. They hold the lock initially while allocating clusters, but drop it for writing the guest payload before taking the lock again for updating the L2 tables. This allows concurrent requests that touch other parts of the image file to continue in parallel and is an important performance optimisation. However, this means that other requests that run while the lock is dropped for writing guest data must synchronise with the list of allocating requests in s->cluster_allocs and wait if they would overlap. For writes, this is done in handle_dependencies(), but discard and write zeros operations neglect to synchronise with s->cluster_allocs. This means that discard can free a cluster whose L2 entry will already be modified in qcow2_alloc_cluster_link_l2() by a previously started write. In the case of a pre-allocated zero cluster that is in the process of being overwritten, this means that discard can lead to a situation where the cluster is still mapped (because the write will restore the L2 entry just without the zero flag), but its refcount has been decreased, resulting in a corrupted image. Add the missing synchronisation to qcow2_cluster_discard() and qcow2_subcluster_zeroize() to fix the problem. Cc: qemu-stable@nongnu.org Reported-by: Denis V. Lunev Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-4-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit b8bfb1478d61512f851badd0d912c6661a2efee7) Signed-off-by: Michael Tokarev diff --git a/block/qcow2-cluster.c b/block/qcow2-cluster.c index ce8c0076b3..c20011d34c 100644 --- a/block/qcow2-cluster.c +++ b/block/qcow2-cluster.c @@ -1392,6 +1392,9 @@ count_single_write_clusters(BlockDriverState *bs, int= nb_clusters, * the same cluster. In this case we need to wait until the previous * request has completed and updated the L2 table accordingly. * + * If allow_shortening =3D=3D true, instead of waiting for a dependency, *= cur_bytes + * can be shortened so that the cluster allocations don't overlap. + * * Returns: * 0 if there was no dependency. *cur_bytes indicates the number of * bytes from guest_offset that can be read before the next @@ -1403,7 +1406,9 @@ count_single_write_clusters(BlockDriverState *bs, int= nb_clusters, */ static int coroutine_fn handle_dependencies(BlockDriverState *bs, uint64_t guest_offset, - uint64_t *cur_bytes, QCowL2Met= a **m) + uint64_t *cur_bytes, + bool allow_shortening, + QCowL2Meta **m) { BDRVQcow2State *s =3D bs->opaque; QCowL2Meta *old_alloc; @@ -1434,7 +1439,7 @@ static int coroutine_fn handle_dependencies(BlockDriv= erState *bs, =20 /* Conflict */ =20 - if (start < old_start) { + if (start < old_start && allow_shortening) { /* Stop at the start of a running allocation */ bytes =3D old_start - start; } else { @@ -1469,6 +1474,29 @@ static int coroutine_fn handle_dependencies(BlockDri= verState *bs, return 0; } =20 +static void coroutine_mixed_fn wait_for_dependencies(BlockDriverState *bs, + uint64_t guest_offset, + uint64_t bytes) +{ + BDRVQcow2State *s =3D bs->opaque; + QCowL2Meta *m =3D NULL; + int ret; + + /* + * Discard has some non-coroutine callers (creating internal snapshots= and + * make empty). They are calling from qemu-img or in a drained section= , so + * we know that no writes can be in progress. + */ + if (!qemu_in_coroutine()) { + assert(QLIST_EMPTY(&s->cluster_allocs)); + return; + } + + do { + ret =3D handle_dependencies(bs, guest_offset, &bytes, false, &m); + } while (ret =3D=3D -EAGAIN); +} + /* * Checks how many already allocated clusters that don't require a new * allocation there are at the given guest_offset (up to *bytes). @@ -1840,7 +1868,7 @@ again: * the right synchronisation between the in-flight request= and * the new one. */ - ret =3D handle_dependencies(bs, start, &cur_bytes, m); + ret =3D handle_dependencies(bs, start, &cur_bytes, true, m); if (ret =3D=3D -EAGAIN) { /* Currently handle_dependencies() doesn't yield if we already= had * an allocation. If it did, we would have to clean up the L2M= eta @@ -2002,6 +2030,15 @@ int qcow2_cluster_discard(BlockDriverState *bs, uint= 64_t offset, int64_t cleared; int ret; =20 + /* + * If we're touching a cluster for which allocating writes are in flig= ht, + * wait for them to complete to avoid conflicting metadata updates. + * + * We don't need to allocate a QCowL2Meta for the discard operation be= cause + * s->lock is held for the duration of the whole operation. + */ + wait_for_dependencies(bs, offset, bytes); + /* Caller must pass aligned values, except at image end */ assert(QEMU_IS_ALIGNED(offset, s->cluster_size)); assert(QEMU_IS_ALIGNED(end_offset, s->cluster_size) || @@ -2164,6 +2201,15 @@ int coroutine_fn qcow2_subcluster_zeroize(BlockDrive= rState *bs, uint64_t offset, int64_t cleared; int ret; =20 + /* + * If we're touching a cluster for which allocating writes are in flig= ht, + * wait for them to complete to avoid conflicting metadata updates. + * + * We don't need to allocate a QCowL2Meta for the zeroize operation be= cause + * s->lock is held for the duration of the whole operation. + */ + wait_for_dependencies(bs, offset, bytes); + /* If we have to stay in sync with an external data file, zero out * s->data_file first. */ if (data_file_is_raw(bs)) { --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380644; cv=none; d=zohomail.com; s=zohoarc; b=B64Im9nNNSrUbcuflVogL8csNWfFttgBiS3KDsZL7f/eiziGeUpSaq0bgvvyPo8nvoTfIp6pTIz7eb+oQlcwEs6s9YTuLk0dhzUXhiXIaWtSn2pHLezBJBBF8bqxwSoecjsY6TcT7RY1F+jgpNoHR3f3EXYD5iIkDDwo+Ov9VZc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380644; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=t3bebmnC8aHOfy8MMBLbDFnLegLK3bhqmi9Ry6uHOB4=; b=Odh52Afe5NY9xjxHAK+N+7bd/Ym25SFW2jfTzgziVHcqF4EP+S0zrEc50dzvz9dpZ37mx63ubxfQFrOvPejqEhBqD2WSTURp0zHTCM1AwH1SC/ycfTqOdaUKVQnNxsEKPiEemlY2F+hOIE42FWU4oqs27/eJepVntodM22RBoEo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380644763555.0878841577963; Sat, 13 Jun 2026 12:57:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUSk-0001lv-Ot; Sat, 13 Jun 2026 15:56:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSj-0001hr-Dz; Sat, 13 Jun 2026 15:56:13 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSh-0004o6-Kj; Sat, 13 Jun 2026 15:56:13 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 524BC1B6E41; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id ABED93CE8BB; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=NeizuiU9CNw1ZzTV6M1T2A/yYQYGEMCvWTUWZVtOwzs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=xRgCyRlZkETLnHTslSW/2hze50Lfx16dd8b8tau/cIU94aSKCI44nOSmSQ9++mVXF 9cz7p4l9Qh98u35U8rk0dFAisN66+7xUrMpGgazsJp89dmWl1VZEFgjl5ekcNX9SLU bNxpKKzv57KcGdhm81qhhPhV6tHNypQgML17FIld0ce30naoxXWsn55LtJ3S9KygYg pNYPLVnN5ZMSjZ6nUQyRKVPQ1mRw9udh5ZvOSf2wC4bWVGkuf50lqGEN8mrjzUgdLl 71GeKTGkUkUV8AVh1LKvnhJNFsVZyknel6Oj7BI+zgQJbN9LGLB8/xtABZX0sSoXUQ LIpIo5/vcMhSA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-10.0.11 50/56] iotests/046: Test that discard/write_zeroes wait for dependencies Date: Sat, 13 Jun 2026 22:51:04 +0300 Message-ID: <20260613195116.1807273-50-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380646884158500 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf This is a regression test for the bug fixed in the previous commit where discard and write_zeroes operations wouldn't consider their dependencies in s->cluster_allocs. Without the fix, this results in a corrupted image. Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-5-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit 389f5bcc744d3ddc127d550a57261aed9bbba1f3) Signed-off-by: Michael Tokarev diff --git a/tests/qemu-iotests/046 b/tests/qemu-iotests/046 index 4c9ed4d26e..e03dd40147 100755 --- a/tests/qemu-iotests/046 +++ b/tests/qemu-iotests/046 @@ -184,6 +184,48 @@ aio_write -P 160 0x104000 0x18000 resume A aio_flush EOF + +# Create a pre-allocated zero cluster, then start a write on it and discar= d it +# before the L2 update is made +cat < Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380692404675.1967061951996; Sat, 13 Jun 2026 12:58:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUSn-0001nB-Fa; Sat, 13 Jun 2026 15:56:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSl-0001mm-VS; Sat, 13 Jun 2026 15:56:15 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSj-0004oQ-J9; Sat, 13 Jun 2026 15:56:15 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 638441B6E42; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id BB43E3CE8BC; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=1tPYqxfalQvrH6IzMDSuSMzVqSC8HCP4VLvVLuJifHw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=gOTzF19DBo45pzwcC17L5shKocUZfx0wmeLdTMKKXezBJgRj4LYFtDfr8TwsiW8DJ lfBCM3cbG5JScIR/8u1H/ZnuctDLI23Wdie58Eoh0TUhBvwEblHe1qqFC2yIm9ERMc taKAFPNU8e/vnKnLzhz/Uu1GzF+mhOE2eWtpQKtQTbKGfzRhR6f3ntBLvk2RpuSBK0 VwFk4r83QGjJzzCLEqDrg6q1bD7blpnUnSyYY45/VPlbdeaYq9b0k0Dh5jDLFa1mOj CSXbNJxA6YTos/KH6PktNitVXvwe5QrlrrYA8G2EW5p9hoSYDXP+xpUVdbZynw7+f4 QxYvnMpIUF0sw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Thomas Lamprecht , Fiona Ebner , Kevin Wolf , Michael Tokarev Subject: [Stable-10.0.11 51/56] qcow2: Fix data loss on zero write with detect-zeroes=unmap Date: Sat, 13 Jun 2026 22:51:05 +0300 Message-ID: <20260613195116.1807273-51-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380693286158500 Content-Type: text/plain; charset="utf-8" From: Thomas Lamprecht Commit b8bfb1478d ("qcow2: Fix corruption on discard during write with COW") added a wait_for_dependencies() at the start of qcow2_subcluster_zeroize(). That fixes the inconsistency it set out to fix, but turns the lock-protected pre-check in the caller, qcow2_co_pwrite_zeroes(), into a stale one: the wait yields s->lock, so an in-flight allocating write whose QCowL2Meta is already on s->cluster_allocs (but whose L2 entry is not yet linked) gets to link its entry during the yield. When the zeroize wakes, the cluster is now NORMAL, and with BDRV_REQ_MAY_UNMAP the free path in zero_in_l2_slice() unmaps the just-written cluster, silently dropping the data write's payload. This is reachable with detect-zeroes=3Dunmap (the default for VirtIO disks with discard on in Proxmox VE), under which the block layer auto-promotes all-zero buffers to BDRV_REQ_ZERO_WRITE | BDRV_REQ_MAY_UNMAP. A memory-constrained Debian guest running 'apt full-upgrade' on such a disk reproduces it as random SIGSEGVs: swapped-out code pages come back as zero. Wait for in-flight dependencies before the lock-protected check in qcow2_co_pwrite_zeroes(). If a write linked its L2 entry during the wait, the type check now fails and the block layer falls back to a bounce-buffered zero write that only touches the requested subrange, preserving the racing write's data. Promote wait_for_dependencies() to qcow2_wait_for_dependencies() so qcow2.c can call it. Fixes: b8bfb1478d ("qcow2: Fix corruption on discard during write with COW") Fixes: 9c3d7bf39f ("qcow2: Fix corruption on discard during write with COW"= ) in 10.0.x series Cc: qemu-stable@nongnu.org Tested-by: Fiona Ebner Reviewed-by: Fiona Ebner Signed-off-by: Thomas Lamprecht Message-ID: <20260522151318.238064-1-t.lamprecht@proxmox.com> [kwolf: Reverted unnecessary change to 'nr' assignment] Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit 1d47eb68983577a4e06fe1c165d90e128b191b86) Signed-off-by: Michael Tokarev diff --git a/block/qcow2-cluster.c b/block/qcow2-cluster.c index c20011d34c..23eeb9fc56 100644 --- a/block/qcow2-cluster.c +++ b/block/qcow2-cluster.c @@ -1474,9 +1474,9 @@ static int coroutine_fn handle_dependencies(BlockDriv= erState *bs, return 0; } =20 -static void coroutine_mixed_fn wait_for_dependencies(BlockDriverState *bs, - uint64_t guest_offset, - uint64_t bytes) +void coroutine_mixed_fn qcow2_wait_for_dependencies(BlockDriverState *bs, + uint64_t guest_offset, + uint64_t bytes) { BDRVQcow2State *s =3D bs->opaque; QCowL2Meta *m =3D NULL; @@ -2037,7 +2037,7 @@ int qcow2_cluster_discard(BlockDriverState *bs, uint6= 4_t offset, * We don't need to allocate a QCowL2Meta for the discard operation be= cause * s->lock is held for the duration of the whole operation. */ - wait_for_dependencies(bs, offset, bytes); + qcow2_wait_for_dependencies(bs, offset, bytes); =20 /* Caller must pass aligned values, except at image end */ assert(QEMU_IS_ALIGNED(offset, s->cluster_size)); @@ -2208,7 +2208,7 @@ int coroutine_fn qcow2_subcluster_zeroize(BlockDriver= State *bs, uint64_t offset, * We don't need to allocate a QCowL2Meta for the zeroize operation be= cause * s->lock is held for the duration of the whole operation. */ - wait_for_dependencies(bs, offset, bytes); + qcow2_wait_for_dependencies(bs, offset, bytes); =20 /* If we have to stay in sync with an external data file, zero out * s->data_file first. */ diff --git a/block/qcow2.c b/block/qcow2.c index 7774e7f090..6f1612a5d8 100644 --- a/block/qcow2.c +++ b/block/qcow2.c @@ -4088,10 +4088,16 @@ qcow2_co_pwrite_zeroes(BlockDriverState *bs, int64_= t offset, int64_t bytes, } =20 qemu_co_mutex_lock(&s->lock); - /* We can have new write after previous check */ offset -=3D head; bytes =3D s->subcluster_size; nr =3D s->subcluster_size; + /* + * Wait for in-flight allocating writes first: otherwise the type + * check below could pass on UNALLOCATED while a yet-to-link_l2 wr= ite + * completes during qcow2_subcluster_zeroize()'s own wait, letting= the + * resumed MAY_UNMAP discard the just-written data. + */ + qcow2_wait_for_dependencies(bs, offset, bytes); ret =3D qcow2_get_host_offset(bs, offset, &nr, &off, &type); if (ret < 0 || (type !=3D QCOW2_SUBCLUSTER_UNALLOCATED_PLAIN && diff --git a/block/qcow2.h b/block/qcow2.h index a9e3481c6e..e1cd91df19 100644 --- a/block/qcow2.h +++ b/block/qcow2.h @@ -958,6 +958,10 @@ int coroutine_fn GRAPH_RDLOCK qcow2_subcluster_zeroize(BlockDriverState *bs, uint64_t offset, uint64_t b= ytes, int flags); =20 +void coroutine_mixed_fn +qcow2_wait_for_dependencies(BlockDriverState *bs, uint64_t guest_offset, + uint64_t bytes); + int GRAPH_RDLOCK qcow2_expand_zero_clusters(BlockDriverState *bs, BlockDriverAmendStatusCB *status_cb, diff --git a/tests/qemu-iotests/046 b/tests/qemu-iotests/046 index e03dd40147..0d84b5c1c7 100755 --- a/tests/qemu-iotests/046 +++ b/tests/qemu-iotests/046 @@ -226,6 +226,26 @@ aio_write -z 0x140000 0x10000 resume A aio_flush EOF + +# Start an allocating write to a previously unallocated cluster and, before +# its L2 update is linked, issue a concurrent sub-cluster zero write with +# MAY_UNMAP that targets a disjoint range within the same cluster. The zero +# write's head/tail are zero (cluster is unallocated), so qcow2_co_pwrite_= zeroes +# would expand it to the full subcluster. Without waiting for dependencies +# before the zero write's "unallocated" type check, that check passes, +# qcow2_subcluster_zeroize then yields in wait_for_dependencies, the alloc= ating +# write links its L2 entry, and the resumed zeroize unmaps the cluster - +# silently discarding the just-written data. Waiting first makes the zero = write +# fall back to a bounce-buffered real write, which only touches its own +# subrange. +cat < Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380691934505.8647816020068; Sat, 13 Jun 2026 12:58:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUSr-0001sk-DO; Sat, 13 Jun 2026 15:56:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSn-0001nt-Mg; Sat, 13 Jun 2026 15:56:17 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSl-0004uU-A7; Sat, 13 Jun 2026 15:56:17 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 73DAD1B6E43; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id CC36C3CE8BD; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=QOOCDw+z6uidYOH1zEIlqJ50MIz7h1OpLNgNEKkZT2w=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=JmmJ/+WiuuwFv0I/8tEpwVwr983xkfNMdBKpAiJVGv8wwmH4wbUANY8+/WXYqb/ES IVAUzLyJui6PPrZ0M4zTa93MEb9vBg3K0H9ZERA1vLDd7umDkgUPELJ3DtWX+3fc6X XpH1QLJNW3efCp6Pg3YHSwTnTJ/EomzwLZiISUOQfiGpq/isQYQUb57+4iFOp759Qv 0yvVVBH4NZYHUrbKcQf4ruSFSa5S1HNXsVEENUxQqyHfT7sdLRWfWghrkMdtf33m/P IHJP6huSOnyQx1dBTRX0PvsgmDnNpYzHPVd1nq2ZNFwEorwn5Cue8bbUkSYJ1c5y8f HjV8N7wvDTV1g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fabiano Rosas , Stefan Hajnoczi , Kevin Wolf , Michael Tokarev Subject: [Stable-10.0.11 52/56] qed: Don't try to flush during incoming migration Date: Sat, 13 Jun 2026 22:51:06 +0300 Message-ID: <20260613195116.1807273-52-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380693128158500 Content-Type: text/plain; charset="utf-8" From: Fabiano Rosas It's not possible to access the image file while there is an incoming migration in progress, the QEMU process doesn't hold any locks to the storage at this point so nodes are inactive. Attempting to flush leads to an assert at bdrv_co_write_req_prepare(): assert(!(bs->open_flags & BDRV_O_INACTIVE)) The issue is reproducible by running iotest 181 on a host under cpu load. The migration must coincide with the header already containing the QED_F_NEED_CHECK flag. The sequence of events is as follows, with the respective call stacks referenced below: During block device init, bdrv_qed_attach_aio_context() starts the 'need_check' timer. The timer will not fire during incoming migration as it uses QEMU_CLOCK_VIRTUAL (to avoid this very issue, as the code comment indicates). (0) However, there's still bdrv_qed_drain_begin() which uses the fact that the timer is live to decide whether to start the qed_need_check_timer_entry() directly. (1) The qed_need_check_timer_entry() eventually calls into qed_write_header() -> bdrv_co_pwrite() leading to the assert. (2) Skip creating the 'need_check' timer whenever the image is inactive. The stacks: (0) =3D=3D issues timer_mod =3D=3D #6 in qed_start_need_check_timer at ../block/qed.c:340 #7 in bdrv_qed_attach_aio_context at ../block/qed.c:373 #8 in bdrv_qed_do_open at ../block/qed.c:556 #9 in bdrv_qed_open_entry at ../block/qed.c:582 #10 in coroutine_trampoline at ../util/coroutine-ucontext.c:175 #0 in qemu_coroutine_switch<+120> at ../util/coroutine-ucontext.c:321 #1 in qemu_aio_coroutine_enter<+356> at ../util/qemu-coroutine.c:293 #2 in aio_co_enter<+179> at ../util/async.c:710 #3 in aio_co_wake<+53> at ../util/async.c:695 #4 in thread_pool_co_cb<+47> at ../util/thread-pool.c:283 #5 in thread_pool_completion_bh<+241> at ../util/thread-pool.c:202 #6 in aio_bh_call<+109> at ../util/async.c:173 #7 in aio_bh_poll<+299> at ../util/async.c:220 #8 in aio_poll<+690> at ../util/aio-posix.c:745 #9 in bdrv_qed_open<+392> at ../block/qed.c:607 #10 in bdrv_open_driver<+327> at ../block.c:1678 #11 in bdrv_open_common<+1619> at ../block.c:2008 #12 in bdrv_open_inherit<+2556> at ../block.c:4191 #13 in bdrv_open<+118> at ../block.c:4286 #14 in blk_new_open<+199> at ../block/block-backend.c:458 #15 in blockdev_init<+2011> at ../blockdev.c:612 #16 in drive_new<+3008> at ../blockdev.c:1008 #17 in drive_init_func<+51> at ../system/vl.c:662 #18 in qemu_opts_foreach<+227> at ../util/qemu-option.c:1148 #19 in configure_blockdev<+350> at ../system/vl.c:721 #20 in qemu_create_early_backends<+343> at ../system/vl.c:2076 #21 in qemu_init<+12483> at ../system/vl.c:3778 #22 in main<+46> at ../system/main.c:71 (1) =3D=3D sees timer_pending =3D=3D #6 in bdrv_qed_drain_begin at ../block/qed.c:391 #7 in bdrv_do_drained_begin at ../block/io.c:366 #8 in bdrv_do_drained_begin_quiesce at ../block/io.c:386 #9 in bdrv_child_cb_drained_begin at ../block.c:1207 #10 in bdrv_parent_drained_begin_single at ../block/io.c:133 #11 in bdrv_parent_drained_begin at ../block/io.c:64 #12 in bdrv_do_drained_begin at ../block/io.c:364 #13 in bdrv_drained_begin at ../block/io.c:393 #14 in blk_drain at ../block/block-backend.c:2101 #15 in blk_unref at ../block/block-backend.c:544 #16 in bdrv_open_inherit at ../block.c:4197 #17 in bdrv_open at ../block.c:4286 #18 in blk_new_open at ../block/block-backend.c:458 #19 in blockdev_init at ../blockdev.c:612 #20 in drive_new at ../blockdev.c:1008 #21 in drive_init_func at ../system/vl.c:662 #22 in qemu_opts_foreach at ../util/qemu-option.c:1148 #23 in configure_blockdev at ../system/vl.c:721 #24 in qemu_create_early_backends at ../system/vl.c:2076 #25 in qemu_init at ../system/vl.c:3778 #26 in main at ../system/main.c:71 (2) =3D=3D crashes =3D=3D #5 in __assert_fail (assertion=3D"!(bs->open_flags & BDRV_O_INACTIVE)", f= ile=3D"../block/io.c", line=3D1977 #6 in bdrv_co_write_req_prepare at ../block/io.c:1977 #7 in bdrv_aligned_pwritev at ../block/io.c:2099 #8 in bdrv_co_pwritev_part at ../block/io.c:2316 #9 in bdrv_co_pwritev at ../block/io.c:2233 #10 in bdrv_co_pwrite at ../include/block/block_int-io.h:77 #11 in qed_write_header at ../block/qed.c:128 #12 in qed_need_check_timer at ../block/qed.c:305 #13 in qed_need_check_timer_entry at ../block/qed.c:319 Note that this issue is not exactly the same as what's been reported in Gitlab, but given how easily this reproduces, I imagine it has to be happening in that setup as well. Link: https://gitlab.com/qemu-project/qemu/-/work_items/3515 Signed-off-by: Fabiano Rosas Message-ID: <20260603193813.2327596-1-farosas@suse.de> Reviewed-by: Stefan Hajnoczi Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit 7e573b660fefdebd21cb755d0d34bb5942fd3af3) Signed-off-by: Michael Tokarev diff --git a/block/qed.c b/block/qed.c index ac24449ffb..c9c0c01d22 100644 --- a/block/qed.c +++ b/block/qed.c @@ -351,16 +351,22 @@ static void bdrv_qed_detach_aio_context(BlockDriverSt= ate *bs) { BDRVQEDState *s =3D bs->opaque; =20 - qed_cancel_need_check_timer(s); - timer_free(s->need_check_timer); - s->need_check_timer =3D NULL; + if (s->need_check_timer) { + qed_cancel_need_check_timer(s); + timer_free(s->need_check_timer); + s->need_check_timer =3D NULL; + } } =20 -static void bdrv_qed_attach_aio_context(BlockDriverState *bs, - AioContext *new_context) +static void GRAPH_RDLOCK bdrv_qed_attach_aio_context(BlockDriverState *bs, + AioContext *new_conte= xt) { BDRVQEDState *s =3D bs->opaque; =20 + if (bdrv_is_inactive(bs)) { + return; + } + s->need_check_timer =3D aio_timer_new(new_context, QEMU_CLOCK_VIRTUAL, SCALE_NS, qed_need_check_timer_cb, s); --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380726; cv=none; d=zohomail.com; s=zohoarc; b=G8Qmpf8L9+8nr8CcEOO/daJ0aDSW7drOv4YQgSC+vGnevAVa2/SR+GUkS0OAQg9JbSXGJzr+B6qbEbwfvcoFgmoB5sG0/buyW6FnBYaTAnidOVm2ZRTjAp7qDUm+ILl1M2Tc38dORFzEvdP3cy8zSsMZzHdvTLwBWxNzigqoG2I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380726; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=sUIFc0jPvfXONrfgTMPam6QURnbfNAauQQtypicJ73c=; b=j69JkcsZr8LG5LZ1cJqH83ELoDO0opPOFiP4YndYkcnadz+Am2gbAxzFuX2y7UGORkFwjhNvnfiQzmjsEyTWmqBjJCOohyC8giEAnWxSj/tjJiGPpmoNE6+j1KNcYviz0sFe2Z6Ac/JP4gOWFapDL6yev9MhcIgqnKWp9UDQo8I= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380726971196.55541505432382; Sat, 13 Jun 2026 12:58:46 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUSv-00020p-K1; Sat, 13 Jun 2026 15:56:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSp-0001sl-Hn; Sat, 13 Jun 2026 15:56:21 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSn-0004vU-PO; Sat, 13 Jun 2026 15:56:19 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 8FBCB1B6E44; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id DC3D13CE8BE; Sat, 13 Jun 2026 22:51:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=wFgYv/PwAt0u78hux03pZXLxBHjnBUUTcA3SqqslMOQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=xMWbUbef0BZuVk7fMMSvhesrhH4pY/e8AF3CMR2fzFxSNUrN42K1t2zR7DQaT+z0W nr7CrcYpFbZ1060pUSS/VlcTwwH1JicPzyuYGMWz5LnhEbx8N8VqASWzizCx4stvdY 1U+KwFF3spv0dQNlsJAB1VHJ945XOuiuLNe6n+tXYxvnIdbW0I3I8FNYV1GaC0P+IA z50jJwvBR4woPBKCcrSHVjD4xG+mnprnvdBj/JkFXgUSlMWqIyeWJw+Ux2Dy727xyp vytjxSToFUWl3ILP1TQFltFZzhSYnI/qBe6vUq9przPUUWWqa3/C3uH3t7P+ga8pnF t/MhqgEfzemCg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Munkhbaatar Enkhbaatar , Peter Maydell , Michael Tokarev Subject: [Stable-10.0.11 53/56] hw/usb/hcd-ohci: Clean up USBPacket before freeing ISO TD packet Date: Sat, 13 Jun 2026 22:51:07 +0300 Message-ID: <20260613195116.1807273-53-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380727145158500 Content-Type: text/plain; charset="utf-8" From: Munkhbaatar Enkhbaatar ohci_service_iso_td() allocates a USBPacket and frees it after synchronous completion, but it does not call usb_packet_cleanup() first. Call usb_packet_cleanup() before g_free() so resources owned by USBPacket are released. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3463 Signed-off-by: Munkhbaatar Enkhbaatar Reviewed-by: Peter Maydell Signed-off-by: Peter Maydell (cherry picked from commit 163f9a4e0651b3b4a1438d919489a200d3646ba3) Signed-off-by: Michael Tokarev diff --git a/hw/usb/hcd-ohci.c b/hw/usb/hcd-ohci.c index adf400a18a..b7296ae036 100644 --- a/hw/usb/hcd-ohci.c +++ b/hw/usb/hcd-ohci.c @@ -756,6 +756,7 @@ static int ohci_service_iso_td(OHCIState *ohci, struct = ohci_ed *ed) } else { ret =3D pkt->status; } + usb_packet_cleanup(pkt); g_free(pkt); =20 trace_usb_ohci_iso_td_so(start_offset, end_offset, start_addr, end_add= r, --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380642; cv=none; d=zohomail.com; s=zohoarc; b=W9b7PHd2E8J3V7evmSA6ohc2j5pSS4UoQmaiAVaCAB9cCXiVJZUCVd9tAA35X3XaTIXisTz43jbsP/NUooBKTvKozFHYHsTDgDNRb4s0xZTeNB4jc6K5PV6bgemgVsNx29dFadzwxZdK4zeSZdpdOrPdIzGdEnizg9i/hwS30Qo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380642; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hXsnJYL0oYyBNx+w744VjiXmIrXoqkAAnKFe3fH1C6E=; b=hLzgquahoAzQxN/vg3A8qiqFysb/YpbkPrUp3Erd3QS+RmIMCwQpL2IVpBBkFHNw5yh2kDVznVfaoNGLqYGLedtG1abxNSWEwM8J1KYxJXkPFsTEV1TauYQYZkgcafmscq5OPmVYGvetJaqey8lgV4CtyGjPpzZYsaQGHste7xg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380642149306.9530062047388; Sat, 13 Jun 2026 12:57:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUT0-0002DP-Fn; Sat, 13 Jun 2026 15:56:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSr-0001tR-Hp; Sat, 13 Jun 2026 15:56:22 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUSp-0004vr-Ql; Sat, 13 Jun 2026 15:56:21 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A99C11B6E45; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 042D93CE8BF; Sat, 13 Jun 2026 22:51:20 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=01hGNxMjvygUiqDA9u2xDGE1FinFk29jK5+QXTOF9Ww=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=hRi0TV359fGzdKsL/7DbjsAQPQ0Lr2eDmToUClVzeW8h8N/sabXOLJO7J8iJHSkhO s0as/exJV+UJY7rFnthygaRQOMlK39KWOlEiT+qOW2ev7jlHkIjmbNQpMcy0DPWhha X7e/lf8tXtEA24SPYiEzcYK58mK25jNmNOgXzqQzgJc9Q0UM8JrzQ2B3F4UmDBOZ4Z 0gPopAiA6HMYbCJ9m4yKz9m8jK5pwks6bUYzPfy7WU/Aw2XYsDmZPAPeEqbnh0HxFv Zfb1I6CvzcYydrlG6OlzNsQPn6hVpJEYzM75XoAJkYhMldq9lw/vPAA4N/dBOFR8a4 x0Jhb1tbsqmuA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richard Henderson , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.11 54/56] fpu: Handle all rounding modes in partsN_uncanon_normal Date: Sat, 13 Jun 2026 22:51:08 +0300 Message-ID: <20260613195116.1807273-54-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380642814158500 From: Richard Henderson Missed float_round_nearest_even_max when recomputing round. CC: qemu-stable@nongnu.org Fixes: 72330260cdb ("softfloat: Add float_round_nearest_even_max") Reported-by: Peter Maydell Signed-off-by: Richard Henderson Reviewed-by: Peter Maydell Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-id: 20260608190155.637067-2-richard.henderson@linaro.org Signed-off-by: Peter Maydell (cherry picked from commit a6a1f92d5a2368882e9b6851b6ab8b9a56d71a8c) Signed-off-by: Michael Tokarev diff --git a/fpu/softfloat-parts.c.inc b/fpu/softfloat-parts.c.inc index 171bfd06e3..2388e5d3fa 100644 --- a/fpu/softfloat-parts.c.inc +++ b/fpu/softfloat-parts.c.inc @@ -375,6 +375,7 @@ static void partsN(uncanon_normal)(FloatPartsN *p, floa= t_status *s, /* Need to recompute round-to-even/round-to-odd. */ switch (s->float_rounding_mode) { case float_round_nearest_even: + case float_round_nearest_even_max: if (N > 64 && frac_lsb =3D=3D 0) { inc =3D ((p->frac_hi & 1) || (p->frac_lo & round_mask) !=3D frac_lsbm1 --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380768; cv=none; d=zohomail.com; s=zohoarc; b=XZZacIdQ8Gs/5jfC0vkA/pyb/JzFO2IhOeHGBsWC9/XXfgsTUYURFpu7b6lIbTnNPZn3BzUwLVNGzuCINzNHYmCeHkP6XgcIURAt9MOvp2PqqITsKh1bZQSkIvNW48EpiZsSrAweFIRgjX8KDEJqbNuBUNe9WeHkkbViOObQvVs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380768; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=qbulxR4j0RFwWre112hViZTiwdO8nzdW3Xb2Biw9OTw=; b=G4Gfl+CrvY9WhY0yQhFG+dNGXTpOYQv0eIFFTYe7vbbzsoHyRayuIeeeJmpwYEqLics2YDIwESF4KaKJze16mFVLrU2yHnJw7+5G43CDmVIWIMV3h+ZCiYPIBCBBjpTyu8QSU4NRrKy1NmxAyxSwrPiDOGSC/Ymc1Clv9Enllcc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380768838611.6952908765119; Sat, 13 Jun 2026 12:59:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUTI-0002ti-SI; Sat, 13 Jun 2026 15:56:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUTD-0002h8-6s; Sat, 13 Jun 2026 15:56:44 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUTB-0004wB-EK; Sat, 13 Jun 2026 15:56:42 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BA6641B6E46; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1DDD83CE8C0; Sat, 13 Jun 2026 22:51:20 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=NZ+Mhu6Z96gvc4DmqJNbFF6QmeSk/gIiawR81JtuNfk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VjLtqHTU/7O3sLRHKhMyb/mAQV5Fp/qnkfS3rypYmSjgMo9zEsS11Tv764KQE0Kes YzEMBqRmBx4wxXvA0z/g88bS1163rIQRstE7VHEW+J9gWmpd36RG5vyv9GHXmWAR9A KRytjLcZw+oVYg64c14nhsaXaRpVIGaW5LZsP9kUAZtRsfGqdV5aBoxF3ACISzfsGN 8zIm3zKlCs96g0ipXHmWJjvNm+kx41BW96Oj9PkTPGB2y6mJ1yJOlJppL6sO6Ty++j nZWZIZ2sqQksvTWPdYMKuXEK4ALHxk2P/2fND1b9HQJREDmQgyfZMN51NaGyE5NMs2 eWRraqC9nc98g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Xinhui Yang , Pierrick Bouvier , Helge Deller , Michael Tokarev Subject: [Stable-10.0.11 55/56] linux-user: implement fsmount(2) series of syscalls Date: Sat, 13 Jun 2026 22:51:09 +0300 Message-ID: <20260613195116.1807273-55-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380769337158500 Content-Type: text/plain; charset="utf-8" From: Xinhui Yang This series of syscalls replaces the old mount(2) syscall with a series of syscalls that operates around a filesystem context. This series of syscalls is available since Linux 5.2 and glibc 2.36+. Their users include systemd since v259 and libmount from util-linux, and possibly other widely used projects. Preliminary checks are implemented to ensure the validity of the interface. v2: Add syscall wrappers in case the build machine does not support the fsmount() syscalls. (added by Helge Deller) Signed-off-by: Xinhui Yang Reviewed-by: Pierrick Bouvier Signed-off-by: Helge Deller (cherry picked from commit 767c32fe69834344bf71f4071ff33292cd46f626) (Mjt: context fixup) Signed-off-by: Michael Tokarev diff --git a/linux-user/syscall.c b/linux-user/syscall.c index 9204dc64ad..710c1b5e38 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -9431,6 +9431,19 @@ _syscall5(int, sys_move_mount, int, __from_dfd, cons= t char *, __from_pathname, int, __to_dfd, const char *, __to_pathname, unsigned int, flag) #endif =20 +#if defined(TARGET_NR_fsopen) && defined(NR_fsopen) +#define __NR_sys_fsopen __NR_fsopen +_syscall2(int, sys_fsopen, const char *, fs_name, unsigned int, flags); +#define __NR_sys_fsconfig __NR_fsconfig +_syscall5(int, sys_fsconfig, int, fs_fd, unsigned int, cmd, const char *, = key, + const void *, value, int, aux) +#define __NR_sys_fsmount __NR_fsmount +_syscall3(int, sys_fsmount, int, fs_fd, unsigned int, flags, + unsigned int, ms_flags) +#define __NR_sys_fspick __NR_fspick +_syscall3(int, sys_fspick, int, dfd, const char *, path, unsigned int, fla= gs) +#endif + /* This is an internal helper for do_syscall so that it is easier * to have a single return point, so that actions, such as logging * of syscall results, can be performed. @@ -14111,6 +14124,97 @@ static abi_long do_syscall1(CPUArchState *cpu_env,= int num, abi_long arg1, return do_riscv_hwprobe(cpu_env, arg1, arg2, arg3, arg4, arg5); #endif =20 +#if defined(TARGET_NR_fsopen) && defined(NR_fsopen) + case TARGET_NR_fsopen: + { + p =3D lock_user_string(arg1); + if (!p) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsopen(p, arg2)); + unlock_user(p, arg1, 0); + } + return ret; + case TARGET_NR_fsconfig: + { + /* + * fsconfig(int, int, char *, void *, int) + * NOTE: p4 is nullable and its type might not be a string. + */ + void *p3, *p4; + int cmd =3D (int) arg2; + switch (cmd) { + case FSCONFIG_SET_BINARY: + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + p3 =3D lock_user_string(arg3); + if (!p3) { + return -TARGET_EFAULT; + } + if (cmd !=3D FSCONFIG_SET_BINARY) { + /* key and value must be strings. */ + p4 =3D lock_user_string(arg4); + } else { + /* + * Otherwise the value must be a raw buffer with its + * length specified in arg5 (aux). + */ + p4 =3D lock_user(VERIFY_READ, arg4, arg5, 1); + } + if (!p4) { + unlock_user(p3, arg3, 0); + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, p3, p4, arg5)); + unlock_user(p3, arg3, 0); + unlock_user(p4, arg4, 0); + break; + + case FSCONFIG_SET_FLAG: + case FSCONFIG_SET_FD: + /* arg4 (value) must be NULL. */ + if (arg4) { + return -TARGET_EFAULT; + } + p3 =3D lock_user_string(arg3); + if (!p3) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, p3, NULL, arg5)= ); + unlock_user(p3, arg3, 0); + break; + case FSCONFIG_CMD_CREATE: + case FSCONFIG_CMD_RECONFIGURE: +#ifdef FSCONFIG_CMD_CREATE_EXCL + /* + * FSCONFIG_CMD_CREATE_EXCL is only available since Linux + * 6.6. Guarding it to allow building with pre-6.6 headers. + */ + case FSCONFIG_CMD_CREATE_EXCL: +#endif + /* key and value must be NULL, aux must be 0. */ + if (arg3 || arg4 || arg5) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, NULL, NULL, 0)); + break; + default: + return -TARGET_EFAULT; + } + } + return ret; + case TARGET_NR_fsmount: + ret =3D get_errno(sys_fsmount(arg1, arg2, arg3)); + return ret; + case TARGET_NR_fspick: + { + p =3D lock_user_string(arg2); + ret =3D get_errno(sys_fspick(arg1, p, arg3)); + unlock_user(p, arg2, 0); + } + return ret; +#endif default: qemu_log_mask(LOG_UNIMP, "Unsupported syscall: %d\n", num); return -TARGET_ENOSYS; --=20 2.47.3 From nobody Sun Jul 26 13:30:35 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781380715; cv=none; d=zohomail.com; s=zohoarc; b=dmVLC+umm22/lX3G6rBlu+o0ZSlHTECabTgGrO5WagghUE0PZ76/mk6m5dPd2tNdTFobdkIGTrSk7mgjzCVkDw+KDvHOKUvS4DAGpJlkRJCMowNrhhoAeK2JffaRxOv3CvU3X6IzEUrHIG1WjRd58M+VphkuPMXQJ/tCwjO2cl8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781380715; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LHO8Gv/XSYm2DQR5cD4vC8Qcg851pgnxVKu0CVkC9Jk=; b=Dj/eQso4fAtf8igTXq+Dr9Cvpfgb1YJIjQ2JjzQ0EoF3BuzeYySoec1D7a7GgHMt3ygA5oTEbP3ALTqJrnI8hlEkYmCKN87kjdjUg68F2ZtA5jXMmnWBf+mxXUcYLv7lEVcLwG5mia0RHH4vr9DpDxHzZlUWtiGdKrv7tXaHjVs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781380715864999.0523054018175; Sat, 13 Jun 2026 12:58:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUTO-0003DR-OO; Sat, 13 Jun 2026 15:56:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUTH-0002ph-6h; Sat, 13 Jun 2026 15:56:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUTD-0004wX-Bg; Sat, 13 Jun 2026 15:56:46 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id CCC981B6E47; Sat, 13 Jun 2026 22:51:01 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 2F69A3CE8C1; Sat, 13 Jun 2026 22:51:20 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781380261; bh=52mgHuOYV72k5JITNEEH1OI21YJm+owe7x1R64olfXk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ChPx3XSn3AnodTe9fqukG7qYL/eqyMY9X8zuOOCQwS4WPEAsdI1VmWj4Cr6VbSuLy 6MRvTFVS0dMZzIVB8FAl7Qsr+mz/tGryGTg1HspyyzZnvIuREzk9W43aDwSney0bMT 12M2dHo7svcEO7coa4UJC3wOq987Gmyy4lbl+xdd8HfudXVdv7WhUg56aLkkhrKbqb ayP+dWmPfNk4kvAaquCs0E2Kn5KWQOeYitA1Ou+yujvQmu9HesqOvSht+qbvCYZxUR K8ID200xn6ZPbiCIgeaWcibBIB7GRYubRpH8jpab4AO6L+Q2odpK3aTX8ohGqfhSa+ 7mFLU9q8leVAw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Xinhui Yang , Pierrick Bouvier , Helge Deller , Michael Tokarev Subject: [Stable-10.0.11 56/56] linux-user/strace: add fsmount series of syscalls Date: Sat, 13 Jun 2026 22:51:10 +0300 Message-ID: <20260613195116.1807273-56-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781380717171158500 Content-Type: text/plain; charset="utf-8" From: Xinhui Yang Following the addition of fsmount(2) series of syscalls in the syscall handler, strace support is added, with a dedicated function to print the parameters of fsconfig(2), which contains parameters that can be interpreted as multiple types. Snippet of the strace dump when running `mount -t tmpfs tmpfs /media`: 18 fsopen(tmpfs,1) =3D 3 18 read(3,0x407fcf1c,8191) =3D -1 errno=3D61 (No data available) 18 fsconfig(3,FSCONFIG_SET_STRING,"source","tmpfs",0) =3D 0 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 fsconfig(3,FSCONFIG_CMD_CREATE,NULL,NULL,0) =3D 0 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 fsmount(3,1,0) =3D 4 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 statx(4,"",AT_EMPTY_PATH|AT_STATX_SYNC_AS_STAT,0x1000,0x407fee98) =3D 0 18 move_mount(4,,-100,/media,4) =3D 0 18 read(3,0x407fcfcc,8191) =3D -1 errno=3D61 (No data available) 18 close(3) =3D 0 18 close(4) =3D 0 v2: Fixed build on RHEL9 due to missing syscalls (Helge) Signed-off-by: Xinhui Yang Reviewed-by: Pierrick Bouvier Signed-off-by: Helge Deller (cherry picked from commit 6e0aa9f6c731df3f8d1071cfd5ec63fe7b923713) Signed-off-by: Michael Tokarev diff --git a/linux-user/strace.c b/linux-user/strace.c index 13c88dd0bb..d103ac0030 100644 --- a/linux-user/strace.c +++ b/linux-user/strace.c @@ -4312,6 +4312,111 @@ print_statx(CPUArchState *cpu_env, const struct sys= callname *name, } #endif =20 +#if defined(TARGET_NR_fsconfig) && defined(NR_fsconfig) +static void +print_fsconfig_cmd_name(int cmd) +{ + switch (cmd) { + case FSCONFIG_SET_FLAG: + qemu_log("%s%s", "FSCONFIG_SET_FLAG", get_comma(0)); + break; + case FSCONFIG_SET_STRING: + qemu_log("%s%s", "FSCONFIG_SET_STRING", get_comma(0)); + break; + case FSCONFIG_SET_BINARY: + qemu_log("%s%s", "FSCONFIG_SET_BINARY", get_comma(0)); + break; + case FSCONFIG_SET_PATH: + qemu_log("%s%s", "FSCONFIG_SET_PATH", get_comma(0)); + break; + case FSCONFIG_SET_PATH_EMPTY: + qemu_log("%s%s", "FSCONFIG_SET_PATH_EMPTY", get_comma(0)); + break; + case FSCONFIG_SET_FD: + qemu_log("%s%s", "FSCONFIG_SET_FD", get_comma(0)); + break; + case FSCONFIG_CMD_CREATE: + qemu_log("%s%s", "FSCONFIG_CMD_CREATE", get_comma(0)); + break; + case FSCONFIG_CMD_RECONFIGURE: + qemu_log("%s%s", "FSCONFIG_CMD_RECONFIGURE", get_comma(0)); + break; +#ifdef FSCONFIG_CMD_CREATE_EXCL + case FSCONFIG_CMD_CREATE_EXCL: + /* Only available since Linux 6.6. */ + qemu_log("%s%s", "FSCONFIG_CMD_CREATE_EXCL", get_comma(0)); + break; +#endif + default: + qemu_log("%s (%d)%s", "UNKNOWN_CMD", cmd, get_comma(0)); + break; + } +} + +static void +print_fsconfig(CPUArchState *cpu_env, const struct syscallname *name, + abi_long arg0, abi_long arg1, abi_long arg2, + abi_long arg3, abi_long arg4, abi_long arg5) +{ + /* + * fsconfig(int fd, int cmd, char* key, void* value, int aux) + * Where: + * fd: file descriptor returned by fsopen(). + * cmd: integer constant specifying a command. + * key: a string, can be NULL on certain commands. + * value: any data in a buffer, can be NULL, raw buffer or a string. + * aux: axillary values such as flags for FSCONFIG_SET_PATH. + */ + int cmd =3D (int) arg1; + print_syscall_prologue(name); + print_raw_param("%d", arg0, 0); + print_fsconfig_cmd_name(cmd); + /* Process arg2 (key). */ + switch (cmd) { + case FSCONFIG_SET_FLAG: + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_BINARY: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + case FSCONFIG_SET_FD: + print_string(arg2, 0); + break; + default: + print_pointer(arg2, 0); + break; + } + /* Process arg3 (value). */ + switch (cmd) { + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + print_string(arg3, 0); + break; + default: + print_pointer(arg3, 0); + break; + } + /* + * Process arg4 (aux). + * On FSCONFIG_SET_PATH and FSCONFIG_SET_PATH_EMPTY, aux can + * be either 0 or AT_FDCWD. + * On FSCONFIG_SET_BINARY, aux is an integer to state the length + * of the buffer pointed by arg3. + * Otherwise, it must be 0. + */ + switch (cmd) { + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + print_at_dirfd(arg4, 1); + break; + default: + print_raw_param("%d", arg4, 1); + break; + } + print_syscall_epilogue(name); +} +#endif + #ifdef TARGET_NR_ioctl static void print_ioctl(CPUArchState *cpu_env, const struct syscallname *name, diff --git a/linux-user/strace.list b/linux-user/strace.list index eb1a414004..6a5b27d4ac 100644 --- a/linux-user/strace.list +++ b/linux-user/strace.list @@ -1722,3 +1722,18 @@ #ifdef TARGET_NR_rseq { TARGET_NR_rseq, "rseq" , "%s(%p,%u,%d,%#x)", NULL, NULL }, #endif +#ifdef TARGET_NR_fsopen +{ TARGET_NR_fsopen, "fsopen", "%s(%s,%d)", NULL, NULL }, +#endif +#if defined(TARGET_NR_fsconfig) && defined(NR_fsconfig) +{ TARGET_NR_fsconfig, "fsconfig", NULL, print_fsconfig, NULL }, +#endif +#ifdef TARGET_NR_fsmount +{ TARGET_NR_fsmount, "fsmount", "%s(%d,%d,%d)", NULL, NULL }, +#endif +#ifdef TARGET_NR_move_mount +{ TARGET_NR_move_mount, "move_mount", "%s(%d,%s,%d,%s,%d)", NULL, NULL }, +#endif +#ifdef TARGET_NR_fspick +{ TARGET_NR_fspick, "fspick", "%s(%d,%s,%d)", NULL, NULL }, +#endif --=20 2.47.3