From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830093; cv=none; d=zohomail.com; s=zohoarc; b=CuSfbPv5oNYdkXQIkvK6bnBVloJYvsFQq64/M+AF02hUqKWeeEfun0n3wJh8tstCMT+Rj5f7cl59F0qnMEDMiAszJ50Sjt+kI3eevbyIUMH7ITlMpdM99iEl11a1c98ByUVRVKK4zmRIqLl5iXo1Ql9Lc75Gv8tvZlioe3pzzig= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830093; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=uma4zQXzLW/U8yb998w0EvVoqf1xZCoxHsnVWNdPDBY=; b=T0JcdF1wh+omMSQm21FvroUifSyD3ARHc8j3sExDcunoX3o6phRZic/JkBHmHrSKnN8eBqR4oO4X8DVxHxahXrrqCQf1Dkv3cj9xYq56xU/H1ytEgq1SN7HlOPjznPzjJ3vFSQv3hP/l1TgjLZrdQn7BLbHoRsP4MIruWnAr7Zg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383009309970.28057248213554; Sat, 11 Jul 2026 21:21:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilcI-0001ZZ-PW; Sun, 12 Jul 2026 00:16:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcH-0001ZG-TC; Sun, 12 Jul 2026 00:16:33 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcG-0006EH-D7; Sun, 12 Jul 2026 00:16:33 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 8B2B21C0BDC; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id BF0073EB93C; Sun, 12 Jul 2026 07:16:30 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 17015133BB; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=YhgUOMCovio1tSVnOLU0Wg0SjUUuqrQZhhnk1E6pEcU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=RzqfP1UjgmlPnxb9EAsWkzvfhriQjyzE1ut2iTctSCjrygvnqPgKYy3vwNr9lDWMS khkoAO+U8YvpkRiZ/o41M2LksyHzlXL6/h3Vw0pJIx9Z+Zql+szhExZ6e/rqWQO0YK 6Stc8GDLhDY8VTHk7557Fo/eagl1Ja+BF9aGKDi/Di2qXrOFGSfG4PiaOmxH/IWF67 +6IfjCYraTpTrNgiQVqe7adr/VfilSIcDSM2i8kVQXfNT5kFVzU4s8maKPjU4TdvlN vpZssfgkq7ol/r/dUPYayR5+Lef2thff5oa5HZ1c2jq9TsEq09dyMDHw/6KGGdokpw hFQWy8YoLCqQA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Akihiko Odaki , Michael Tokarev Subject: [Stable-10.0.12 01/75] ui/gtk: fix bad widget realize on non-GFX VC Date: Sun, 12 Jul 2026 07:14:19 +0300 Message-ID: <20260712041539.108341-1-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830094389158500 From: Marc-Andr=C3=A9 Lureau The GTK VirtualConsole is a union, it may be .gfx or .vte depending on the type. Fixes: 565f85a9c2 ("ui/gtk: force realization of drawing area") Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260623-b4-ui-v4-1-4656aec3398d@redhat.com> (cherry picked from commit 27f6d5ba9c97f57d1c7ce67bc01ffe8df0e11c34) Signed-off-by: Michael Tokarev diff --git a/ui/gtk.c b/ui/gtk.c index fe0a2249ffb..86ee8df2d5e 100644 --- a/ui/gtk.c +++ b/ui/gtk.c @@ -2552,7 +2552,9 @@ static void gtk_display_init(DisplayState *ds, Displa= yOptions *opts) if (!con) { break; } - gtk_widget_realize(s->vc[idx].gfx.drawing_area); + if (s->vc[idx].type =3D=3D GD_VC_GFX) { + gtk_widget_realize(s->vc[idx].gfx.drawing_area); + } } =20 if (opts->u.gtk.has_show_menubar && --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783829856; cv=none; d=zohomail.com; s=zohoarc; b=NGLkhVUzRfm2P6Lz3SiFK8EJpqXdYJAX7eqOowlbox0iipWWu9J5g4EnzkijAnJsaDseB+ZxjRyQuvZ62vPT6BBkSgbtuDckAngyCiEPmpfqbs2tJksy8w3ZfnK8ienNQCr4NQnWGKRj8rtl/8gnkLy3D0xYzHrunGxOimvw9eU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783829856; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fUab7iUHpqhsFOUkFBW0fFjxuf0mEH2sxYj/3sLIPfU=; b=kfUkACIQE9lDdOS6PCuTboPpIOnz70dMrhyQIzVQfdh/lGT+2E4TWNXMdirBr/H8RSxt6g9pN/y1GdUGWXQ2ikxy8XZgdUJoHg523HTZXBPOoIfv8Rfk+koOd9NtEdddkK5P81U4xDm/qOM3ZhBoAlDAfbXFNdwB3ph8484FXpA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17838298549607.595364120043428; Sat, 11 Jul 2026 21:17:34 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilcL-0001ap-8I; Sun, 12 Jul 2026 00:16:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcI-0001ZR-Au; Sun, 12 Jul 2026 00:16:34 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcG-0006EK-Pc; Sun, 12 Jul 2026 00:16:34 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9CEAB1C0BDD; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id CC7B03EB93D; Sun, 12 Jul 2026 07:16:30 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 19B5D133BD; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=GZZXjdQ7qK8evYR70ND7UaRLPa6dfHqrQe3CEWX6Glk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=RHexoCaLfrdkNhGbhp/a9rUbLhay1fzgfWxfYYbZUjYPngsDdyPmO/7MQYcEjaZsg LDn6+9C66OF6NZODscGn/61l366Tv7AN27p27wyPv22mKrBUWueukmBY5QPf811owM LF7UDy+uFTaNt0/Rw6nYHTMmkdrYIjmg1hWVzDirx8+Lnko8wVOTXzLhZsiUExwmBE TKE+s5qzedzbyA+5O/F7Ru3gu5vs/LTuB9QqTLkW+OiocB4M9UopAd6OA/Gsi8fRkK YilOOioQqsXL6Tof8N1bRJ53zgQPsSmQ9P7blsh87AB1lDBB44pjN55PhO12BE+zdx HpoV3xw7dWG0g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Borntraeger , Eric Farman , Cornelia Huck , Michael Tokarev Subject: [Stable-10.0.12 02/75] s390x/kvm: clamp stsi 3.2.2 size Date: Sun, 12 Jul 2026 07:14:20 +0300 Message-ID: <20260712041539.108341-2-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783829859404158500 Content-Type: text/plain; charset="utf-8" From: Christian Borntraeger The stsi 3.2.2 page is being prepared by the kvm module and the size is clamped by the kernel. As the memory is mapped in the guest, another guest VCPU could race and overwrite the count and messing up the move operation. For any out of bound count, fall back to the kernel buffer. Cc: qemu-stable@nongnu.org Signed-off-by: Christian Borntraeger Reviewed-by: Eric Farman Message-ID: <20260622092035.400959-1-borntraeger@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit a57e4612b61da20ddab196502c76b4dc05da1de8) Signed-off-by: Michael Tokarev diff --git a/target/s390x/kvm/kvm.c b/target/s390x/kvm/kvm.c index 4d56e653ddf..81b8282939c 100644 --- a/target/s390x/kvm/kvm.c +++ b/target/s390x/kvm/kvm.c @@ -1792,6 +1792,15 @@ static void insert_stsi_3_2_2(S390CPU *cpu, __u64 ad= dr, uint8_t ar) } else if (s390_cpu_virt_mem_read(cpu, addr, ar, &sysib, sizeof(sysib)= )) { return; } + + /* + * The memory was filled by the kernel but mapped into the guest. + * If something is fishy, do not touch the buffer. + */ + if (sysib.count =3D=3D 0 || sysib.count > ARRAY_SIZE(sysib.ext_names))= { + return; + } + /* Shift the stack of Extended Names to prepare for our own data */ memmove(&sysib.ext_names[1], &sysib.ext_names[0], sizeof(sysib.ext_names[0]) * (sysib.count - 1)); --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783829857; cv=none; d=zohomail.com; s=zohoarc; b=SxdIlKBTE9XXOtwF739OOqxWY2HqdnhDoAxivogprQ6y9kOxek+3LFmrCCMyN9N0HNiK8WLJxTRgqh/WReSRbAP+86HBe7O4bcNcBdUrzBBvzABoS14dqzLqpzrHqoYQP9ECdTKdf/HeIOkKNuCHcC7BtJXhnis7IAEy5GrEaFc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783829857; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lWiYyh/uZqLvLhT8a+ioYstZ78ItYeqAbll3hFYeAls=; b=MiLeUrJ/7iT9mrtO1pLrbB/F/XkAUSxCElFJrBzlIHphu8w0UNc549TJqXrP9SP1apb/hf3zuPwL7ux5E9Bn+v4WXYf79HQC0M4QBcTK5Xlg0fg7WJy+DtVVbThM6sw5WpCjyO8u5BrE0YFfnj2MDCHoB4wF/IoZeoIGLvQtEj4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783829854951335.1489718115172; Sat, 11 Jul 2026 21:17:34 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilcN-0001bv-KS; Sun, 12 Jul 2026 00:16:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcL-0001au-7d; Sun, 12 Jul 2026 00:16:37 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcJ-0006Eh-HC; Sun, 12 Jul 2026 00:16:36 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A88FF1C0BDE; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id D92ED3EB93E; Sun, 12 Jul 2026 07:16:30 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 1C4C4133BF; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=cGtgySVNMmES5ZCARjyRWzqDlJ9yTk1+cOw7Ki4QPLw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=AhpcJWfkZoZBL1BxpxCNuHm5P4or3v3I8kP9z1oDi+CIQIpBl3yK04CIjRp0FesDD w73CLam66/IPK6funDbexaDSmKk16Hn2YbdHPyB603GMH3ZEUt2kwFKU9OdPYJM3Q+ bJFVCceG1mRtryqB5twPmJzXfMOURepHUesg1fZzb5nQlgewGxHWmxc2qPpOsN6Xb8 RVF6BsCXxfCYtxNJpDemFwzaRZPK8FH5CvUyPruh1PzDtJ9hpRq2I8qRTAjjJc1fnI KHdKu3cfEKzfZqHDPKHRE/znShCvFU9N3rjdb+QakCrWiZsv+uOtCA+60YE0xqMZjz 6hafsT2idCdGQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 03/75] 9pfs: Don't use file descriptors in core code Date: Sun, 12 Jul 2026 07:14:21 +0300 Message-ID: <20260712041539.108341-3-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_PDS_OTHER_BAD_TLD=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783829859583158500 Content-Type: text/plain; charset="utf-8" From: Greg Kurz v9fs_getattr() currently peeks into V9fsFidOpenState to know if a fid has a valid file descriptor or directory stream. Even though the fields are accessible, this is an implementation detail of the local backend that should not be manipulated directly by the server code. Abstract that with a new has_valid_file_handle() backend operation. Signed-off-by: Greg Kurz Reviewed-by: Christian Schoenebeck Message-Id: <20250312152933.383967-3-groug@kaod.org> Signed-off-by: Christian Schoenebeck (cherry picked from commit f2bb367d2b265c6c0ead1e0d4a8f7c43310b3107) (Mjt: pick this one up so subsequent commits are applied cleanly) Signed-off-by: Michael Tokarev diff --git a/fsdev/file-op-9p.h b/fsdev/file-op-9p.h index c453b6494be..29057d0d363 100644 --- a/fsdev/file-op-9p.h +++ b/fsdev/file-op-9p.h @@ -164,6 +164,7 @@ struct FileOperations { int (*renameat)(FsContext *ctx, V9fsPath *olddir, const char *old_name, V9fsPath *newdir, const char *new_name); int (*unlinkat)(FsContext *ctx, V9fsPath *dir, const char *name, int f= lags); + bool (*has_valid_file_handle)(int fid_type, V9fsFidOpenState *fs); }; =20 #endif diff --git a/hw/9pfs/9p-local.c b/hw/9pfs/9p-local.c index 5167c43609b..c5309c5ba45 100644 --- a/hw/9pfs/9p-local.c +++ b/hw/9pfs/9p-local.c @@ -1584,6 +1584,13 @@ static int local_parse_opts(QemuOpts *opts, FsDriver= Entry *fse, Error **errp) return 0; } =20 +static bool local_has_valid_file_handle(int fid_type, V9fsFidOpenState *fs) +{ + return + (fid_type =3D=3D P9_FID_FILE && fs->fd !=3D -1) || + (fid_type =3D=3D P9_FID_DIR && fs->dir.stream !=3D NULL); +} + FileOperations local_ops =3D { .parse_opts =3D local_parse_opts, .init =3D local_init, @@ -1621,4 +1628,5 @@ FileOperations local_ops =3D { .name_to_path =3D local_name_to_path, .renameat =3D local_renameat, .unlinkat =3D local_unlinkat, + .has_valid_file_handle =3D local_has_valid_file_handle, }; diff --git a/hw/9pfs/9p-synth.c b/hw/9pfs/9p-synth.c index 2abaf3a2918..be0492b400e 100644 --- a/hw/9pfs/9p-synth.c +++ b/hw/9pfs/9p-synth.c @@ -615,6 +615,11 @@ static int synth_init(FsContext *ctx, Error **errp) return 0; } =20 +static bool synth_has_valid_file_handle(int fid_type, V9fsFidOpenState *fs) +{ + return false; +} + FileOperations synth_ops =3D { .init =3D synth_init, .lstat =3D synth_lstat, @@ -650,4 +655,5 @@ FileOperations synth_ops =3D { .name_to_path =3D synth_name_to_path, .renameat =3D synth_renameat, .unlinkat =3D synth_unlinkat, + .has_valid_file_handle =3D synth_has_valid_file_handle, }; diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 34ac2c3c9af..52806670235 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -1607,6 +1607,11 @@ out_nofid: pdu_complete(pdu, err); } =20 +static bool fid_has_valid_file_handle(V9fsState *s, V9fsFidState *fidp) +{ + return s->ops->has_valid_file_handle(fidp->fid_type, &fidp->fs); +} + static void coroutine_fn v9fs_getattr(void *opaque) { int32_t fid; @@ -1629,9 +1634,7 @@ static void coroutine_fn v9fs_getattr(void *opaque) retval =3D -ENOENT; goto out_nofid; } - if ((fidp->fid_type =3D=3D P9_FID_FILE && fidp->fs.fd !=3D -1) || - (fidp->fid_type =3D=3D P9_FID_DIR && fidp->fs.dir.stream)) - { + if (fid_has_valid_file_handle(pdu->s, fidp)) { retval =3D v9fs_co_fstat(pdu, fidp, &stbuf); } else { retval =3D v9fs_co_lstat(pdu, &fidp->path, &stbuf); --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830068; cv=none; d=zohomail.com; s=zohoarc; b=HUctIxKfzICbI1vTKRxABBM3wDAT1q/8SKfnSLrJRZtF8gpIgxnNQj148vtYgHA8nKYz4n1EOdkcn5DjjVSjYQRG7LaKbGzfE4PEw9DE8GG6qgUVPffLq4hWkQISoWcOAmrRzJFueQADu//6w6CYWaUm95X36aDYFNLLyw76m7s= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830068; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LwpcuRKv3km0ZO8Og8HFvAYRj0q8hf5Y7H/O2hxv2MA=; b=kn7LJ67IH2ukMczKMblz3BiTbrnHK6sgaCEiMlSc2yhGtsh3J1Rf1ZYt0+RiQauLIh6y7K4ipWSwTsCjPbrdjzF1fbkpkeh8H35DBeuH5JCPJHQSTv1Q1gS4Uqp0YH2zQ3thSKfkTFvPi42dCV0vr4Nx2p0O17Sb5sFmuF1wzLo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830068435319.67726854545015; Sat, 11 Jul 2026 21:21:08 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilcj-0001yY-Qd; Sun, 12 Jul 2026 00:17:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcL-0001at-7V; Sun, 12 Jul 2026 00:16:37 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcJ-0006Eq-Pt; Sun, 12 Jul 2026 00:16:36 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id AFCAD1C0BDF; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id DFB823EB93F; Sun, 12 Jul 2026 07:16:30 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 1E923133C1; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=NbeN2u3UDyR2EUcnxTJxRfHiBeXPCU5gXQbgJwpyrb8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=kNk0edk2LkSbgs6Fs/KHK3Yk33CKThytCsbS0JQeF9H8gY+VX/9xxe4153ssPBNv6 h3tOcqAUz7nslZxo/bTbPUz/UEXFr64cH6f9zy1nG+2cdhWxJ7/04p/Dg677CLgQUJ pQagwKr74LUKNkV7H8bVAlbHz+++afbQYk+w9aFBR6s81NqvBRcUGFvJwAvghyYEuc OAagh4vsCFe5hERJ7gKBxR66DVEdZEo9QMQ+Fg1vzoLpPIv6j2e/Ac4MCA7zTgeG6w YWkNNFGlkDwwxfRcjj4Hg+AGDx2EDP9X6bB7CTcD0zEabNloCbjzHpk+u9Gw3Vq0u0 XN7tMasXPJiqQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Greg Kurz , Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 04/75] 9pfs: local : Introduce local_fid_fd() helper Date: Sun, 12 Jul 2026 07:14:22 +0300 Message-ID: <20260712041539.108341-4-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830069994158500 Content-Type: text/plain; charset="utf-8" From: Greg Kurz Factor out duplicated code to a single helper. More users to come. Signed-off-by: Greg Kurz Reviewed-by: Christian Schoenebeck Message-Id: <20250312152933.383967-2-groug@kaod.org> Signed-off-by: Christian Schoenebeck (cherry picked from commit 4f82ce8cd94f2601fb2b2e4cfe0cf5b44131817e) (Mjt: pick this one up so subsequent commits are applied cleanly) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p-local.c b/hw/9pfs/9p-local.c index c5309c5ba45..cba3e945f99 100644 --- a/hw/9pfs/9p-local.c +++ b/hw/9pfs/9p-local.c @@ -766,16 +766,19 @@ out: return err; } =20 -static int local_fstat(FsContext *fs_ctx, int fid_type, - V9fsFidOpenState *fs, struct stat *stbuf) +static int local_fid_fd(int fid_type, V9fsFidOpenState *fs) { - int err, fd; - if (fid_type =3D=3D P9_FID_DIR) { - fd =3D dirfd(fs->dir.stream); + return dirfd(fs->dir.stream); } else { - fd =3D fs->fd; + return fs->fd; } +} + +static int local_fstat(FsContext *fs_ctx, int fid_type, + V9fsFidOpenState *fs, struct stat *stbuf) +{ + int err, fd =3D local_fid_fd(fid_type, fs); =20 err =3D fstat(fd, stbuf); if (err) { @@ -1167,13 +1170,7 @@ out: static int local_fsync(FsContext *ctx, int fid_type, V9fsFidOpenState *fs, int datasync) { - int fd; - - if (fid_type =3D=3D P9_FID_DIR) { - fd =3D dirfd(fs->dir.stream); - } else { - fd =3D fs->fd; - } + int fd =3D local_fid_fd(fid_type, fs); =20 if (datasync) { return qemu_fdatasync(fd); --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830183; cv=none; d=zohomail.com; s=zohoarc; b=QKV8ujyaHFH/iwlQYwQSdC72y5AAM/S7PhJkQQGBynuMGFlJTAncCcyBD7dkXMG7//s7eLchBghmJKTU35+m77AY6vZ/jo8xfx5a1cW7l/T5faHpiQBXbvm5AtbG7cMdGRjnxx8a8kxPcKnZyC8AiK5YySDriFU6ajSku8Fivo4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830183; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3AOFfcFboytKuFGBcc6MBx5+blwGI5qiTfkAqJSawn4=; b=nlCA7z0FaTrW7nZZ+DKKjQVMjRjgPz/jyZKdFatA0DoKORPIOzFhBWsdRxFrH5iIIb0G9yJ8SXcSTqFLzaWlmZEiJPS6NfLHGvuuIM9FRoW/EEnbBruKQ0IJHL+PYU5I97quRr+czAh3hqILTN6GvWP+mBTkr4W2t7nJN1AvapE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383018311299.05082680180283; Sat, 11 Jul 2026 21:23:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilcn-00029K-R5; Sun, 12 Jul 2026 00:17:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcO-0001d1-Mj; Sun, 12 Jul 2026 00:16:41 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcM-0006FZ-Mo; Sun, 12 Jul 2026 00:16:40 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B39481C0BE0; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id E53B83EB940; Sun, 12 Jul 2026 07:16:30 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 20CCB133C3; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=hU82KUVs7r0uV1CuQQBBYe00HlzyamewboyrZdlPX8c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=X2TkcpS8TGU298/I6kZ2X/vepZrXnd7VaOnJZivdziwWCh5VILA2EErciN/MlsW8l JQQK/TApS1KTh0ss13ScxKu33NbDEFJjX426O7i1A4e0w6oSBoquQG+99x/78944AK EVfgB9RtOFDKkVoNfXPvje7sayxpxA42zLvkqUWqec86wjolG1xADVdNxvmxkIzU8c R+nqUkF3ETSbogKD+eDOQufY89uofyfrL2Cqn3mYbxhW3PycMF9rrmV56MJDCnlcf/ qJuda4bJlzoY3FkFMH4TYzhyOlzUn+I3J69A/3sw/WPVAR8G/w6xVghlccQ8ZO3cfa 2zlnxlvDSZGkQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 05/75] hw/9pfs: add msize_limit transport callback Date: Sun, 12 Jul 2026 07:14:23 +0300 Message-ID: <20260712041539.108341-5-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830184356158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add a new callback 'msize_limit' to the V9fsTransport structure. This allows each transport implementation to provide its theoretical maximum 'msize' value, which will be used to cap the negotiated msize during Tversion handshake. Link: https://lore.kernel.org/qemu-devel/7c4e53eb73c0580d7a321dbf3823ba5647= 652298.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit a1c0e5a73740566d4b9eac1f97f78b8ce470116a) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index b2df659b0e8..d8f364fafdb 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -481,6 +481,7 @@ struct V9fsTransport { void (*init_out_iov_from_pdu)(V9fsPDU *pdu, struct iovec **piov, unsigned int *pniov, size_t size); void (*push_and_notify)(V9fsPDU *pdu); + size_t (*msize_limit)(V9fsState *s); }; =20 #endif --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783829831; cv=none; d=zohomail.com; s=zohoarc; b=Ysat5SFTlK4B8b/zoJk6J26952aNFRz4Jl7cJdJ+LWSveY27YfQvuHycISTJW94LXizSZvGR3+NfEUEGdvRrK2mVHA9441CaJXCpAMBU980peiMN0mueNO4INdF0vHKqKGvj+wwIkcpjVbA7t6FE0X5alJuP9VwT5qigEdupy5Y= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783829831; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=plBzdPcQ8NqrHbmQ2iYde5cA2TpmCnq5VBPhXbEYcLU=; b=MzViC0IAYidK9lSrs6MMFpi0aQsDtE6eu2etW4NeaZqeby2VlbD7gQtsessZqQdyID5j9SMmReIgFZh0RGTTHuvD9limJw8+YX8Qdv7K+wFsovqgEmgGXF9rn/WXPoL0hYVeK7UKfxsL0vI3XKZr7c/aflZOo+fza12t7E3k2MQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783829831151159.6173905992813; Sat, 11 Jul 2026 21:17:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilcf-0001im-DI; Sun, 12 Jul 2026 00:16:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcO-0001d0-Le; Sun, 12 Jul 2026 00:16:41 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcM-0006Fa-Mn; Sun, 12 Jul 2026 00:16:40 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B8EF61C0BE1; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id EBC173EB941; Sun, 12 Jul 2026 07:16:30 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 22E06133C5; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=zRD+QVA80sL83toDeo+Ol2aI282UyE5YlSlhUqOBuWg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=oMWMeTtbRBqiGBGXD53edSe4kJEcLqySw2sR9Djknmq9h/BUNV29JT2l+URpoOkqC 6gNvWoAUtMX/9pm/4O2bxlih/qa2jxIcJzpdts/FWAFPIqLUynBMc746C5T2MMBapK 4F3wLAHXjqGbTSSYryWov9At6XpFHmsfXXxXJSC9uCt1UpgfA8n6PLHc+2DiFoI50R bK0cy5awgPWygokeuwJLrou31yIivnZt02v/8H70lxBwxMIuVv2XmmSZzHRZozAUhB GSLz7VdRlaKyDKKqqbCofFj9cCXCB8JT2Xm3J3SKjddd5Y2uj5PIkMZ/2HYUPgzkDz lCJjh8MDgHSmw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 06/75] 9pfs/virtio: implement msize_limit callback Date: Sun, 12 Jul 2026 07:14:24 +0300 Message-ID: <20260712041539.108341-6-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783829839348158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add and implement the msize_limit callback for the virtio transport. This new callback function provides the theoretical maximum 'msize' value supported by this virtio transport. The limit is calculated as (VIRTQUEUE_MAX_SIZE - 2) * 4096 bytes, where 2 virtio descriptors are lost exactly for: - 1 descriptor for the original request (typically being small) - 1 descriptor as indirect table pointer (when used), which just contains a pointer to the separate sglist containing the response's actual payload data And 4096 bytes are assumed as standard page size used by Linux 9p client. This results in a maximum 'msize' of 4186112 bytes. Theoretically Linux client could support a much larger size, e.g. by using multiple consecutive pages per sg entry / descriptor. However that's currently not the case and unlikely to change any time soon. And due to recent security issues, let's handle this limit conservatively until really necessary to be raised. Link: https://lore.kernel.org/qemu-devel/4c34426bc906e19423e7e2389c419c2e97= 2d9b9b.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 4a1a2fa4d351ba85628064e4a2a9cbc0c72cdbd4) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/virtio-9p-device.c b/hw/9pfs/virtio-9p-device.c index bb2843da0f6..c795afa6440 100644 --- a/hw/9pfs/virtio-9p-device.c +++ b/hw/9pfs/virtio-9p-device.c @@ -192,12 +192,19 @@ static void virtio_init_out_iov_from_pdu(V9fsPDU *pdu= , struct iovec **piov, *pniov =3D elem->out_num; } =20 +static size_t virtio_9p_msize_limit(V9fsState *s) +{ + const size_t guestPageSize =3D 4096; + return (VIRTQUEUE_MAX_SIZE - 2) * guestPageSize; +} + static const V9fsTransport virtio_9p_transport =3D { .pdu_vmarshal =3D virtio_pdu_vmarshal, .pdu_vunmarshal =3D virtio_pdu_vunmarshal, .init_in_iov_from_pdu =3D virtio_init_in_iov_from_pdu, .init_out_iov_from_pdu =3D virtio_init_out_iov_from_pdu, .push_and_notify =3D virtio_9p_push_and_notify, + .msize_limit =3D virtio_9p_msize_limit, }; =20 static void virtio_9p_device_realize(DeviceState *dev, Error **errp) --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783829923; cv=none; d=zohomail.com; s=zohoarc; b=XBYP6lcWED73guOvNhAAIKPhF8cQAm/irljPSOgkM8fvuV9TzQNKJXo9AnkBtSHqcmyhIJFgHwaQ89IKPmK3ENC/2Apy20175dYRU5ZnswIqYpMCW7QztHo/dm+ZJCDKF+kbDHOFhNsbgYLPjt7uOTvoXDbWQCZ5MbpSasgqiYc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783829923; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gUCknAVkY5P/ulYAoyNJZgtNSuEAectmgseg5WmyOBQ=; b=Ozi7JpzexZDPogztg25RryDvDMeS1JTNwsXaRpJVwFotD7UBUOwkdd8TpVyq2Xm8GRDvGvh1y7U0/J2cM/sQrTAAewVpr4EY9JCfB7GY1o9pqajoODchw7kOGjxny6eGgjMHL9iv5a2lVWNXLxigDYwRKxTUHlF8pu301k3WgzM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783829923593503.96324660964274; Sat, 11 Jul 2026 21:18:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilci-0001w5-PC; Sun, 12 Jul 2026 00:17:01 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcT-0001gi-3b; Sun, 12 Jul 2026 00:16:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcQ-0006G7-2L; Sun, 12 Jul 2026 00:16:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BEAFE1C0BE2; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id F2D1C3EB942; Sun, 12 Jul 2026 07:16:30 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 2526E133C7; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=co03GFHPji+tzW8/TSZZLngqZ6kFf91s5aFiFGJfF+A=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=jyiGT8czrPz5nxKPkaz7uGFJ0DawzptyEnX0t2fklWzZ6bYdspo0DfMjmUUCCj5M4 JybneT/eEDyQ41wwHTf98WUZ3zWdh3Qh5GddhdGg3GLUM+Vgi+xFSpodBeVx3V+cRl EAZ104TAo9SiqriTB1bZoXmdeGCQiNKzP8Vg1YRuP2ZZL+qK8OjiZBmhL6CU/8ahxy uU2ECvHocJKIyisvWq8gmGuG8GlhexADDTo7MedWRepVTLp+hgx2r0h4epar3T+12i r5XFa3Li4fEp4ToC/udxo7PMRuZFTnLdzfIIhk9IWZndbFQOlaH4Hh9bZxypdeIBYZ ZKnmllKqlasfQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Stefano Stabellini , Michael Tokarev Subject: [Stable-10.0.12 07/75] 9pfs/xen: implement msize_limit callback Date: Sun, 12 Jul 2026 07:14:25 +0300 Message-ID: <20260712041539.108341-7-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783829925641158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add and implement the msize_limit callback for the Xen transport. The limit is calculated using XEN_FLEX_RING_SIZE() based on the negotiated ring_order. For the theoretical maximum ring_order of 9, this results in a maximum 'msize' of 1048576 bytes (1 MiB). The minimum limit of all rings is picked, because multiple rings could theoretically have different ring_orders. Reviewed-by: Stefano Stabellini Link: https://lore.kernel.org/qemu-devel/9471786bc47b93e822f6c6233a83f2b9f6= 1e6c82.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 815d1799c3d3d6cd058cb4634392ca5a34830450) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/xen-9p-backend.c b/hw/9pfs/xen-9p-backend.c index 79359d911a7..f168c6ef0ee 100644 --- a/hw/9pfs/xen-9p-backend.c +++ b/hw/9pfs/xen-9p-backend.c @@ -250,12 +250,31 @@ static void xen_9pfs_push_and_notify(V9fsPDU *pdu) qemu_bh_schedule(ring->bh); } =20 +static size_t xen_9p_msize_limit(V9fsState *s) +{ + Xen9pfsDev *xen_9pfs =3D container_of(s, Xen9pfsDev, state); + size_t limit; + int i; + + if (!xen_9pfs->num_rings) { + return 0; + } + + limit =3D XEN_FLEX_RING_SIZE(xen_9pfs->rings[0].ring_order); + for (i =3D 1; i < xen_9pfs->num_rings; i++) { + limit =3D MIN(limit, XEN_FLEX_RING_SIZE(xen_9pfs->rings[i].ring_or= der)); + } + + return limit; +} + static const V9fsTransport xen_9p_transport =3D { .pdu_vmarshal =3D xen_9pfs_pdu_vmarshal, .pdu_vunmarshal =3D xen_9pfs_pdu_vunmarshal, .init_in_iov_from_pdu =3D xen_9pfs_init_in_iov_from_pdu, .init_out_iov_from_pdu =3D xen_9pfs_init_out_iov_from_pdu, .push_and_notify =3D xen_9pfs_push_and_notify, + .msize_limit =3D xen_9p_msize_limit, }; =20 static int xen_9pfs_init(struct XenLegacyDevice *xendev) --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783829855; cv=none; d=zohomail.com; s=zohoarc; b=WVuOVWorzp3UR8oAU+2pP/u89KzGYhIh8yQZxLBAmIB4TJJwAgeyvglRg5MWqVD5frrPe8cKGRitgstDuciLl9wt0+9KLbJQmV3bQVCRviiLeWIkQO8ZNhmjQ/IXphG6/N5zubfRSz4i2btfEoBnnOArpXb9IAt0Ej31U+jAQlk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783829855; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ESHBi50mr6mZ8PYSKKLT39QmrAESmWfyhFVne/A7CQU=; b=jHTvkjCi0HQslQM1CwDxxo5EDoJ0woJw2KD3vrKQkx0bVKPWSqIYaEpAtENXwejzhglmZq/+EHZGHXxFnVtoZKDm292BEgZ6+Y+o1185vM56JoyE2+eIUpdtNcdm+U1iwjUJek2+6Up65tixOduNB/SDnvNB0k3GX9qaa09FVXA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783829852758311.46205208769754; Sat, 11 Jul 2026 21:17:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilcu-0002a3-65; Sun, 12 Jul 2026 00:17:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcT-0001gj-3f; Sun, 12 Jul 2026 00:16:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcQ-0006G9-3R; Sun, 12 Jul 2026 00:16:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C59E11C0BE3; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 0400E3EB943; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 2760A133C9; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=jQZ6mYPMk9HPQRINxHHqnJ2IAXWLkbOOp0Mtbm4nOIY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=xWifgLVc6hw937ZHolMxtV0XdHw1vSJKBoWkAurcbNqWr5FWUL9hW4j4dT1KEO3g3 tIYfKSd3h+a1l0O7LyWT3udDjCAgNEls4r+U0zB2arinfWo/shln/sLuA1+7TJjMM/ S4L0UX5uJR32fg3EoW1JtDSlH31uY3+53fa5GOCw5sbFBsWKwWlLmmSUz2BDpKBBul KqtuFtIDe63h5k6et4fky9UZdU8U41Nd+nXMMhW/jQsBEWey/FmFCONJoOIOxlRNdO SjLzPf0E0godvM5Mh7WMvVvRKQqTEpsC+XbzSACV5tz0Aork2T9a3jgsMNFdC86OpL 4iwUzyBOS4Sng== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 08/75] hw/9pfs: cap negotiated msize to transport limit Date: Sun, 12 Jul 2026 07:14:26 +0300 Message-ID: <20260712041539.108341-8-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783829859424158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck The 'msize' parameter negotiated during Tversion handshake can be arbitrarily large as requested by the guest. So far 9p server accepted any msize value suggested by guest, i.e. server did not cap it at all, no matter how large, as in practice the upper limit of msize is a client capability. But as subsequent's security patch shows, capping msize on server side makes sense as additional safety-net. Let's cap msize to transport's theoretical limit for msize, mainly to prevent a bad client from triggering excessive host memory allocations throughout the session. We intentionally don't cap msize to transport's current, real response buffer size, as the response buffer size may vary between individual requests. Link: https://lore.kernel.org/qemu-devel/2105e9a3578c6f751bb64af55c16dd953f= 393f20.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit bb5ab96e35a1b13a2485d239a44ff2d040e9b337) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 52806670235..f0bc1d71706 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -1459,6 +1459,16 @@ static void coroutine_fn v9fs_version(void *opaque) goto out; } =20 + /* cap msize to transport's theoretical limit */ + if (s->transport->msize_limit) { + size_t limit =3D s->transport->msize_limit(s); + if (s->msize > limit) { + s->msize =3D limit; + warn_report_once("9p: client msize capped to %zu (transport li= mit)", + limit); + } + } + /* 8192 is the default msize of Linux clients */ if (s->msize <=3D 8192 && !(s->ctx.export_flags & V9FS_NO_PERF_WARN)) { warn_report_once( --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830252; cv=none; d=zohomail.com; s=zohoarc; b=ay2NNHHfwAtP88NHQEbvq/OxApQUJGPhlKqzfc550p5ugV2p1KnCEKY0fhg4QYRGPAhl/mMAXU8nEFAJWKD95D6J7LPvlXziorN0RKyoF6VO/yeNModn8IgEYZmi+QawZzi3ULlGsWsbJSB4A6k7rx1zIiFuUU2PRS0BuUPbsQM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830252; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hRdGk4I5HpYIW9nIBQxcMRjhALJK1qHZPXHJocC7TGs=; b=MQubPd40+pO3iMC4x6hDjaosCsXQ8KBKEO1mkJWgrhiwpAHEUFxL6yecH/O7f9NDonivXK6m+1UBslyiUaOPMhVrebL4lMiYiUWVcbnIrUShSQCFMHZ2OV8tUrUhIm2jC/4hTmZhvrdJXeZrmg/NgtLSql0K1x9hi2xX/+DogN4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383025218616.131518605194742; Sat, 11 Jul 2026 21:24:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilcn-0002AK-RB; Sun, 12 Jul 2026 00:17:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcW-0001hB-5O; Sun, 12 Jul 2026 00:16:51 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcU-0006Gq-HU; Sun, 12 Jul 2026 00:16:47 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id CB2E81C0BE4; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 0A95B3EB944; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 29766133CB; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=hsiOAVI1pxA6gsTTT3L+Qtz9jOIhe5gxKl4Fs1a8qgU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=NoxqKGLa+CbOH3Fg4Dxs95zsD7t/qr6rDGAEh2hLIuWfEgkUl4vKaWzD1r5gM1Coa dgg4PDwGx8Npsu9HWCnjo9QunfMQeDdjDkJVWMwG5TALtD1FalXzsMcxaMXsUgRlTr BRjeYGX6ueptL+nRjGwinBv06O30+FYsfP9ijLAY8f+66oG6k77k9PMvQCL+RLIoEc 5No7sEz2VKpOpmm96r51vr8n32A8/g1uNaFzLVCHwoH+81z1cw70otBb6y5YgCzRnj iMbmQkjDIJNc6Y0IBwKh8ZileTGSDeSlfDqfGkhW8NkZBHw9b/6hU5xwJ8jhusaO/6 NvHFf6vaBqo6g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 09/75] hw/9pfs: add response_buffer_size transport callback Date: Sun, 12 Jul 2026 07:14:27 +0300 Message-ID: <20260712041539.108341-9-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830252515158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add a new callback to the V9fsTransport interface that allows each transport to provide the real size of its current response buffer. This is needed for subsequent safety guards that will limit generated responses appropriately before trying to allocate, generate, and send a response to guest. This is especially required for request handlers that need to allocate dynamic and potentially large host memory for generating a response. These safety guards are mandatory to counter bad clients that try to trick server by supplying response buffers being smaller than the previously negotiated msize value. Link: https://lore.kernel.org/qemu-devel/703ed8ce4401c4550ef2cd99f30ab80866= 5d6e85.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 4b615eaa1be4a54fb677c302e1a86fe09a94aecd) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index d8f364fafdb..1a309664f6e 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -482,6 +482,7 @@ struct V9fsTransport { unsigned int *pniov, size_t size); void (*push_and_notify)(V9fsPDU *pdu); size_t (*msize_limit)(V9fsState *s); + size_t (*response_buffer_size)(V9fsPDU *pdu); }; =20 #endif --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830041; cv=none; d=zohomail.com; s=zohoarc; b=YJoVSqV7Pkv485qxxz2oTLvOeBJmnsz5tKK0HkA6b+/B9jAot7vtZQJDYZOuSCqtg0hsyiBDTR4sLYbOPgfo7OhYfzDAhiNQHqVdDYLzVTXs17tUTV70k/mpBB1pbbjIcqloRcVadOLMBLiCrshgTiAF+M9ukGWucdzowSACv14= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830041; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=INQTjJimKho3gAL1AyKi/ew8UWjR553mSaxiJ11rBiQ=; b=i+9Ardlsm56EnezgQN385Lzd9zZyHuU/kLuHQbCSC7GLt8ukdTF33PWF5MS7SJKGHRWunY2GEi1WKunqvH28nciQXl27/U+0JXOa13S7Hgi73oWqkJwUX80Fs/dmEDnR6Z2lQYdoK17tYkRWePtNO8CRVPk+OJ6KzElrj6CGXiw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830041018704.8669544708774; Sat, 11 Jul 2026 21:20:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilcp-0002Im-Vo; Sun, 12 Jul 2026 00:17:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcX-0001hI-BF; Sun, 12 Jul 2026 00:16:51 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcU-0006Gr-HT; Sun, 12 Jul 2026 00:16:49 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D44A11C0BE5; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 135A53EB945; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 2C06B133CD; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=lyBZ07NxtE3rcnLIaPGI2DFdtsN8hOiuMjlmJt97RU0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=GlSfFFaA01R1IrwS9UNmpWmJmbW/CJlk6zO9HPjKRnlrmBKodlkt2Hdl/eB4DTjYo /bAyUVroKZPbvVyb1B9ybWbqG73+WWYlZNeahadOj/coBz7ryqHYYuLFjhvjFEfWY7 HDvu7uKt1n/hWxqVaNXDy+URbOLza4XZL31IZCbYMJcH2JMb34sTFkFhnRVE3ZFFc8 L3YJvEnrBPn8ZZPvZjmQN49KVRJgTCg2o+zIOLcD32NjGVNhY92RVCmtvD8U2fAkCu 6M75pF84WjppEGaRrUVWGpKPLzSEthCDGj0SUKGKkonMUkowoGngOzj/FxMA7R//ay LX8ltMxYOeZlA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 10/75] 9pfs/virtio: implement response_buffer_size callback Date: Sun, 12 Jul 2026 07:14:28 +0300 Message-ID: <20260712041539.108341-10-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830041916158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add and implement the response_buffer_size callback for the virtio transport. Returns the actual current virtio response buffer size for the supplied PDU, which will be used as safety guard for limiting the response size when generating a 9p response. Link: https://lore.kernel.org/qemu-devel/5bbed2768f7a0da8fa2be183e75928c5d1= ef691d.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 12bcbdca8ae9fcd5fec093e8ef5e70521e85e889) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/virtio-9p-device.c b/hw/9pfs/virtio-9p-device.c index c795afa6440..f3fabf2abd3 100644 --- a/hw/9pfs/virtio-9p-device.c +++ b/hw/9pfs/virtio-9p-device.c @@ -198,6 +198,15 @@ static size_t virtio_9p_msize_limit(V9fsState *s) return (VIRTQUEUE_MAX_SIZE - 2) * guestPageSize; } =20 +static size_t virtio_9p_response_buffer_size(V9fsPDU *pdu) +{ + V9fsState *s =3D pdu->s; + V9fsVirtioState *v =3D container_of(s, V9fsVirtioState, state); + VirtQueueElement *elem =3D v->elems[pdu->idx]; + + return iov_size(elem->in_sg, elem->in_num); +} + static const V9fsTransport virtio_9p_transport =3D { .pdu_vmarshal =3D virtio_pdu_vmarshal, .pdu_vunmarshal =3D virtio_pdu_vunmarshal, @@ -205,6 +214,7 @@ static const V9fsTransport virtio_9p_transport =3D { .init_out_iov_from_pdu =3D virtio_init_out_iov_from_pdu, .push_and_notify =3D virtio_9p_push_and_notify, .msize_limit =3D virtio_9p_msize_limit, + .response_buffer_size =3D virtio_9p_response_buffer_size, }; =20 static void virtio_9p_device_realize(DeviceState *dev, Error **errp) --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830381; cv=none; d=zohomail.com; s=zohoarc; b=jAe10OFdVJS4WuDq5vjQa2DEXOkCoeItzBqUaJN+2VxcAbehgGngwOWufbtTUfOOjjiNy3mZdwRpzxaMViPCuE7xc5Tt//10FiubFvC8j6ZWkRXYnXRz9HZg5bldymK5U0TelzW7CiCzgVFKR6hdQEjUn3CWL6XznYAs1PWOlXk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830381; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=zssdYCBUimK4cMsse5Elhc6jI4bSvssLKwC0iAKzHTc=; b=YgWHbgdFWIqMkoy9CDIUAxn1sHIMqLELvbduDhRPliqEmWe4Zm4U2th4xAgl6YjLfPKUJJ5BCRvQTd/iCrriwhnOkPT7ZB2jfgzu8qD+IlnGb2fG6tl/x4ksC5QEJdY9/OOb48KikDumE9BY+qd0Y1UoQnmhFFrHDjy5aYCx3Hk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383038150883.55163865804025; Sat, 11 Jul 2026 21:26:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilcr-0002TO-SN; Sun, 12 Jul 2026 00:17:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcZ-0001lg-Or; Sun, 12 Jul 2026 00:16:55 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcX-0006Hc-JO; Sun, 12 Jul 2026 00:16:51 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id DB2AF1C0BE6; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 190483EB946; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 2EA1B133CF; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=0LzW0jaYKGDQ4dkWaUYbNxBbsZkh2/L8H26i3L4a8Rc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=kDK0v/7dIFie0LCVUKzgAHk4b61Yt7n0ared8qCKXU4Xc0gZF/xeb3GMW8DBtE8Pl WUaOXEEfhN44QWYk4mL/yyMNFGDOzDBiSjoAs4+z9hYPeGz9Ajjk366Y/HL3zj0EKM l9vI6tg+yW0MuDAJHviMKUXtYUA33FVWqNPoTbq8ax/m/jRKPbbUWFXFC17j2gxnQF EfiWrD8n7fk6/8sIo3Ksp1DrDsITgdN3LGDfHOfFw1oRfftG0QGaXd3V7H3/YE9ULM w1UvPqdOnaQmgeOrvhEI1r++knqidGVwCNeG74Akzb2CNn0RzAGLoYi+6CIdnX7pOt RwKdjGUBPSEPA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Stefano Stabellini , Michael Tokarev Subject: [Stable-10.0.12 11/75] 9pfs/xen: implement response_buffer_size callback Date: Sun, 12 Jul 2026 07:14:29 +0300 Message-ID: <20260712041539.108341-11-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830382913158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add and implement the response_buffer_size callback for the Xen transport. Returns the size of the response buffer from the rings in_sg, as limit for 9p server while generating a response for supplied PDU. We use a local iovec array variable in_sg[2] instead of ring->sg, as ring->sg is only allocated by init_in_iov_from_pdu() and init_out_iov_from_pdu() during request / response processing. response_buffer_size() however may be called before those allocators, which would dereference ring->sg as NULL pointer. The local array avoids this. Reviewed-by: Stefano Stabellini Link: https://lore.kernel.org/qemu-devel/3b139769eb1d3f9d91ee5281228e6467f9= a08b99.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 69c8f5e6946f76a70b141a340c7aeb9d6a8e3c27) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/xen-9p-backend.c b/hw/9pfs/xen-9p-backend.c index f168c6ef0ee..029a623bf76 100644 --- a/hw/9pfs/xen-9p-backend.c +++ b/hw/9pfs/xen-9p-backend.c @@ -268,6 +268,17 @@ static size_t xen_9p_msize_limit(V9fsState *s) return limit; } =20 +static size_t xen_9pfs_response_buffer_size(V9fsPDU *pdu) +{ + Xen9pfsDev *priv =3D container_of(pdu->s, Xen9pfsDev, state); + Xen9pfsRing *ring =3D &priv->rings[pdu->tag % priv->num_rings]; + struct iovec in_sg[2]; + int num; + + xen_9pfs_in_sg(ring, in_sg, &num, pdu->idx, 0); + return iov_size(in_sg, num); +} + static const V9fsTransport xen_9p_transport =3D { .pdu_vmarshal =3D xen_9pfs_pdu_vmarshal, .pdu_vunmarshal =3D xen_9pfs_pdu_vunmarshal, @@ -275,6 +286,7 @@ static const V9fsTransport xen_9p_transport =3D { .init_out_iov_from_pdu =3D xen_9pfs_init_out_iov_from_pdu, .push_and_notify =3D xen_9pfs_push_and_notify, .msize_limit =3D xen_9p_msize_limit, + .response_buffer_size =3D xen_9pfs_response_buffer_size, }; =20 static int xen_9pfs_init(struct XenLegacyDevice *xendev) --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830040; cv=none; d=zohomail.com; s=zohoarc; b=asSgz09LJEUeE9hP3pCKYSNwuqhC8wjx93qfCT9aYo/JmnwygpSDm9JQAEE3/2YhR4irJ8GIF2dDKhRhRQAyvVFgOWlbjH18ScNWs0TjtqV4N9eWYpleOymXCifMl753ZxFaQ4+/QB+HVrDe2xtludyaEiNQ99I1mYGtxnHK0Kc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830040; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=QBQ8Ddw4xs62FJls4Y8SY0vdfBnww15uyxnvlPTIELM=; b=C/mb/Ipss+1mey7aOLlalToH8t7ziuNoQQecsb4XMjhoFjMoA6AUsh5PwQV6LBgrDokCbf8tkgK6Foa5XVYQDh+ULCyL3s1LuJMkbTpuZO2tDhEh5kHge3vV8cTH3xbPMGTjGVCLlC8NErwnxXWfbRGVcLZBETDwEvhKeIlcbzU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830040715925.7260518265876; Sat, 11 Jul 2026 21:20:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilcx-0002ic-Uf; Sun, 12 Jul 2026 00:17:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcu-0002cH-KI; Sun, 12 Jul 2026 00:17:12 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcs-0006JF-RR; Sun, 12 Jul 2026 00:17:12 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E19BA1C0BE7; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 2140F3EB947; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 31006133D1; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=iVhpOrfW5mJni5ZsXD7/88eECXnpM4z0jEKgB0xAty4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=tT1oIJSM9Mi+tPWOd9ZGvEQqmXsSGNzMdlF5p2QkRyhcoFtZ3H8/LQGij2mGYySzM +38BTbGbxGUaZtELlXNjmWQbApG4jgGPXogCJeiUgBsf2xKVbbsagPg84Xti9gKhnb 1YP/aMkWdeSPUFxGNOmt5z+AATGgSXCOVprvM4NRWXB7hN2p5eWcctaHvShCYxK4ES HrsSi/RFEjSTgHp1R8rRcZcrjf5jVGejI9cE+/48CsYJY4ld9dQ9X/M74/6wtX7JkT FKbHSSPQp/8t6k2RoL4BmhSXAuA7C/LcsGitINzjJK8FIIobhMMB6zpehiQ1RLvBFF bATORxlaDxzBA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Feifan Qian , Stefano Stabellini , Michael Tokarev Subject: [Stable-10.0.12 12/75] hw/9pfs: cap Treaddir allocation (CVE-2026-9238) Date: Sun, 12 Jul 2026 07:14:30 +0300 Message-ID: <20260712041539.108341-12-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830041937158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Constrain max_count in v9fs_readdir() to transport's current, real response buffer size before calling v9fs_do_readdir() to prevent excessive host memory allocation for specific, crafted, huge directories (large amount of entries) by bad clients. Client may send a Treaddir request with a large 'count' parameter, and while the negotiated 'msize' provides some limit, it accounts for guest being somewhat faithful on the negotiated 'msize' value throughout the session. A bad guest client could have negotiated a large 'msize' but provide a small reply buffer for Treaddir request, causing QEMU to allocate host memory proportional to 'msize' before discovering the reply cannot fit. Possible consequence was a potential DoS by a priviliged guest, causing a disconnection of guest communication due to transport device being marked as "broken", however QEMU process would have continued to run with potentially giant host memory allocation, which might have negative impact on other services running on host. Fixes: CVE-2026-9238 Fixes: 2149675b195f ("9pfs: add new function v9fs_co_readdir_many()") Reported-by: Feifan Qian Reviewed-by: Stefano Stabellini Link: https://lore.kernel.org/qemu-devel/f81a387a2de4f2172fd5830c5654f49d78= 102254.1781287774.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 64c6c7e0df726055fac9ed12b30f712b115193f3) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index f0bc1d71706..a4f9544e13b 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -2647,6 +2647,7 @@ static void coroutine_fn v9fs_readdir(void *opaque) uint32_t max_count; V9fsPDU *pdu =3D opaque; V9fsState *s =3D pdu->s; + size_t max_resp_sz; =20 retval =3D pdu_unmarshal(pdu, offset, "dqd", &fid, &initial_offset, &max_count); @@ -2655,9 +2656,28 @@ static void coroutine_fn v9fs_readdir(void *opaque) } trace_v9fs_readdir(pdu->tag, pdu->id, fid, initial_offset, max_count); =20 + max_resp_sz =3D s->msize; + + /* + * Constrain max_count to transport's current, actual response buffer = size. + * A bad client might provide a response buffer < msize. + */ + if (s->transport->response_buffer_size) { + size_t buf_size =3D s->transport->response_buffer_size(pdu); + if (max_resp_sz > buf_size) { + max_resp_sz =3D buf_size; + } + } + /* Enough space for a R_readdir header: size[4] Rreaddir tag[2] count[= 4] */ - if (max_count > s->msize - 11) { - max_count =3D s->msize - 11; + if (max_resp_sz > 11) { + max_resp_sz -=3D 11; + } else { + max_resp_sz =3D 0; + } + + if (max_count > max_resp_sz) { + max_count =3D max_resp_sz; warn_report_once( "9p: bad client: T_readdir with count > msize - 11" ); --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830051; cv=none; d=zohomail.com; s=zohoarc; b=XMhN0y7YE/wvyQ0QTHiqIe4RJvPUXw8KYTkXHMTEMqbtEqgUngQGLs8GdBp00vUXT1fKM0/fBwHqaVoyxeEhg4IsVncM6/muisYqb+ZEcSvDGTPfoHPO0d5DTWVM8YoW8zRH7c/qiF/CBG4kxC/+aVgCjEwvyGA17efbFIh7jYc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830051; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Dv2WxJ+U3CJCI5fQjlnPkTjxQdZ1StTtAlb8/h2iYyU=; b=X94CgobEwgYz3bf7c66C3Tx8pbdWlzv1enZSRFXnyl0u+GWEAhCLWbjXyCyyf91EDq2rP0xK+ZtY3TZpboAdhbnGLaeLnUCUm7Q8c55EPnZR9cQsNN4hHm/O88TnFTt+ZBD7repcUedaEZwAiPNftzqImWYP9Vi1m+OMs1lo25E= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17838300516587.492041747449321; Sat, 11 Jul 2026 21:20:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wild0-0002oI-4g; Sun, 12 Jul 2026 00:17:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcx-0002hG-ES; Sun, 12 Jul 2026 00:17:15 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcv-0006Lj-E8; Sun, 12 Jul 2026 00:17:15 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E97201C0BE8; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 27A0C3EB948; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 335E6133D3; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=u1nWC9gQeIVwKTsz8GMyhTzE1qrL1/SscLdFG4jJ4Gs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=dDCSbln9OomYpWlyi1XYYx6Nq55b3DMBmRSiOdDLcgqTaaxAwcY/Rw1IQHxwa47uY JHsM1LHsnd7Jd/m1JTDtDdR75FeSPbeYWz4xD1ymzH7w8FfwrU5DdZCu1uTWGmImOG j4AWSn619EDE21qmzcgaONCNfeSocKO0YS/cuf1Q+5xI8fCgYwH0h/sphp52tscPUi PnWHEeMuWABdalzQ5vqOTWhYs3IlohM/TiEf7UbyQynq1hdUSiOOHhklJ0Hu2P6ojE 5Ts7H25PFGm5TlBD8V4i82oci6msni664SM2WBF6TJSObr+1KfQYwIcRZ8IIfE19A+ FrufeWKL0jbMg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Feifan Qian , Michael Tokarev Subject: [Stable-10.0.12 13/75] hw/9pfs: add xattr FID limit to prevent memory exhaustion Date: Sun, 12 Jul 2026 07:14:31 +0300 Message-ID: <20260712041539.108341-13-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830054091158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add a limit on the number of simultaneously open xattr FIDs to prevent host memory exhaustion attacks. Each xattr FID contains a buffer for the xattr value, and without a limit, a malicious priviliged guest with direct communication access to 9p server could create a huge number of xattr FIDs until host memory is eventually exhausted. Fix this by: - add xattr_fid_limit to struct FsContext for the max. amount - add xattr_fid_count to struct FsContext for the current amount - init xattr_fid_limit with 1024 - init xattr_fid_count with 0 - add function xattr_fid_count_inc() to increment the count - add function xattr_fid_count_decr() to decrement the count - call xattr_fid_count_inc() in Txattrcreate handler - call xattr_fid_count_inc() in Txattrwalk handler - call xattr_fid_count_decr() when a xattr FID is freed Additionally: - reset the xattr FID counter in virtfs_reset() When the limit is reached then xattr_fid_count_inc() returns -ENOSPC and the request handler is aborted on its error path without turning the FID into an xattr type and without allocating memory for the xattr. The default value of 1024 was chosen, as (sane usage of) xattr requests in the 9p protocol are usually very short-lived, and even machines with 128 cores with very high xattr activity should have plenty of head room without ever hitting this limit. Fixes: 10b468bdc5 ("virtio-9p: Implement TXATTRCREATE") Fixes: CVE-2026-8348 Reported-by: Feifan Qian Link: https://lore.kernel.org/qemu-devel/eb3787869745d47234fb662600187bf773= e1ef8a.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 693b296b176d1829b10855d9831bd2ad21b2cdcf) Signed-off-by: Michael Tokarev diff --git a/fsdev/file-op-9p.h b/fsdev/file-op-9p.h index 29057d0d363..f3800018954 100644 --- a/fsdev/file-op-9p.h +++ b/fsdev/file-op-9p.h @@ -79,6 +79,11 @@ typedef struct ExtendedOps { =20 #define V9FS_SEC_MASK 0x0000003C =20 +/* + * Limits the maximum amount of simultaneously open xattr FIDs to prevent + * host memory exhaustion (as each xattr FID contains a xattr value buffer= ). + */ +#define V9FS_MAX_XATTR_DEFAULT 1024 =20 typedef struct FileOperations FileOperations; typedef struct XattrOperations XattrOperations; @@ -107,6 +112,10 @@ struct FsContext { void *private; mode_t fmode; mode_t dmode; + /* max. amount of simultaneously open xattr FIDs */ + uint32_t xattr_fid_limit; + /* current amount of open xattr FIDs */ + uint32_t xattr_fid_count; }; =20 struct V9fsPath { diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index a4f9544e13b..1255f4ff920 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -263,6 +263,31 @@ static size_t v9fs_string_size(V9fsString *str) return str->size; } =20 +static int xattr_fid_count_inc(V9fsPDU *pdu) +{ + V9fsState *s =3D pdu->s; + + if (s->ctx.xattr_fid_limit > 0 && + s->ctx.xattr_fid_count >=3D s->ctx.xattr_fid_limit) { + error_report_once("9pfs: xattr_fid_count limit exceeded " + "(configurable by option 'max_xattr')."); + return -ENOSPC; + } + s->ctx.xattr_fid_count++; + return 0; +} + +static void xattr_fid_count_decr(V9fsPDU *pdu) +{ + V9fsState *s =3D pdu->s; + + if (s->ctx.xattr_fid_count > 0) { + s->ctx.xattr_fid_count--; + } else { + error_report_once("9pfs: xattr_fid_count underflow detected"); + } +} + /* * returns 0 if fid got re-opened, 1 if not, < 0 on error */ @@ -395,6 +420,7 @@ static int coroutine_fn free_fid(V9fsPDU *pdu, V9fsFidS= tate *fidp) } } else if (fidp->fid_type =3D=3D P9_FID_XATTR) { retval =3D v9fs_xattr_fid_clunk(pdu, fidp); + xattr_fid_count_decr(pdu); } v9fs_path_free(&fidp->path); g_free(fidp); @@ -624,6 +650,14 @@ static void coroutine_fn virtfs_reset(V9fsPDU *pdu) fidp->clunked =3D true; put_fid(pdu, fidp); } + + /* + * Explicitly reset the xattr FID counter. + * + * free_fid() already decrements the counter for each P9_FID_XATTR, so= the + * counter should already be zero, hence this is just a defensive meas= ure. + */ + s->ctx.xattr_fid_count =3D 0; } =20 #define P9_QID_TYPE_DIR 0x80 @@ -4027,6 +4061,14 @@ static void coroutine_fn v9fs_xattrwalk(void *opaque) clunk_fid(s, xattr_fidp->fid); goto out; } + + /* Check xattr FID limit */ + err =3D xattr_fid_count_inc(pdu); + if (err < 0) { + clunk_fid(s, xattr_fidp->fid); + goto out; + } + /* * Read the xattr value */ @@ -4034,6 +4076,7 @@ static void coroutine_fn v9fs_xattrwalk(void *opaque) xattr_fidp->fid_type =3D P9_FID_XATTR; xattr_fidp->fs.xattr.xattrwalk_fid =3D true; xattr_fidp->fs.xattr.value =3D g_malloc0(size); + if (size) { err =3D v9fs_co_llistxattr(pdu, &xattr_fidp->path, xattr_fidp->fs.xattr.value, @@ -4060,6 +4103,14 @@ static void coroutine_fn v9fs_xattrwalk(void *opaque) clunk_fid(s, xattr_fidp->fid); goto out; } + + /* Check xattr FID limit */ + err =3D xattr_fid_count_inc(pdu); + if (err < 0) { + clunk_fid(s, xattr_fidp->fid); + goto out; + } + /* * Read the xattr value */ @@ -4067,6 +4118,7 @@ static void coroutine_fn v9fs_xattrwalk(void *opaque) xattr_fidp->fid_type =3D P9_FID_XATTR; xattr_fidp->fs.xattr.xattrwalk_fid =3D true; xattr_fidp->fs.xattr.value =3D g_malloc0(size); + if (size) { err =3D v9fs_co_lgetxattr(pdu, &xattr_fidp->path, &name, xattr_fidp->fs.xattr.value, @@ -4158,6 +4210,12 @@ static void coroutine_fn v9fs_xattrcreate(void *opaq= ue) goto out_put_fid; } =20 + /* Check xattr FID limit */ + err =3D xattr_fid_count_inc(pdu); + if (err < 0) { + goto out_put_fid; + } + /* Make the file fid point to xattr */ xattr_fidp =3D file_fidp; xattr_fidp->fid_type =3D P9_FID_XATTR; @@ -4420,6 +4478,10 @@ int v9fs_device_realize_common(V9fsState *s, const V= 9fsTransport *t, =20 s->reclaiming =3D false; =20 + /* init xattr FID limit */ + s->ctx.xattr_fid_limit =3D V9FS_MAX_XATTR_DEFAULT; + s->ctx.xattr_fid_count =3D 0; + rc =3D 0; out: if (rc) { --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830099; cv=none; d=zohomail.com; s=zohoarc; b=TcTqMTRL+4xc/tFXubitN0ViL+TH7Su1gw8ITkjEgcByE7dLlcW9eWv/+YCEGgChJC7nMhuIkQ3lY1Fpz5KYd6HFB6I4+TGxM5tAAYIfVer2TI9wgqAY/aqDcRfx5itO8ylwv5E9Ep3djtCmKL7giPzk0jZcj4dAesj9zJKeOSU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830099; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=CKIypuIezrC45Fg7QbNQboKXD+RiBOEbkrbIwadcz3E=; b=Tdj3VRBDH660qPJPnbSG3jCYlP1R9dBnArtIeQTCF0Vta4yI+9ei//MIJgAKRZnH3yl6mqeq+SPy1fMezXr+HlYg1AYbZOAiVrWlPCZYJyzDrD/8J77xz2/+YnorO4TUUEcIyNJcUmGGQXoEiqysFpuFRbebu/5WOmY3GT1EDCw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830099146288.3195403296279; Sat, 11 Jul 2026 21:21:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wild1-0002uf-HJ; Sun, 12 Jul 2026 00:17:19 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcx-0002jX-Sk; Sun, 12 Jul 2026 00:17:15 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcw-0006RA-2c; Sun, 12 Jul 2026 00:17:15 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id EF1801C0BE9; Sun, 12 Jul 2026 07:16:20 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 2E63C3EB949; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 35C99133D5; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829780; bh=IMJf4l+7Nr4BDxzrgD6Hd3D8zLEjhRubAybnYMg/eGI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=DPIMyl3n4R8uInX82Xx3TRZNAz71DGAvg1VCvHHtEh31qpoYo2bwfzFKARyBjB+5W 5CIlb/nLgdSSZOidwqjy+cCYVHGJh5R0dvwdVkIzZZs6em8luMw5P7Y5e+sYLSO3JG GPGMFWPdnu9/C330Kpkw9wgCA9haHnXMPJ2Lk1AI3MyAK2PYi6lQEcqdw1MI3lPjLr XcDiayByvwcZJ7R93SSVpTY/QZdWEEKQANj5HxqJgDu5sO6C500JZ81spYjyNam3Jk IEqe8jWF6hzlQfrx5OrufIW9pIJejJDEoxBBvMbgPtO6cJ/kmmTs2BqfwqotxNUsMV EtKvWTe4xsOwQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 14/75] hw/9pfs: add max_xattr option Date: Sun, 12 Jul 2026 07:14:32 +0300 Message-ID: <20260712041539.108341-14-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830100075158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Previous patch introduced a limit of max. 1024 simultaneous xattr FIDs. This patch introduces an option "max_attr" that allows to override this limit, just for the case that some user might run into this limit for some reason, even if unlikely; or for reducing the limit further down (e.g. that default limit of 1024 would cap at max. 64 MiB host memory, at least on Linux hosts where the limit per xattr is 64k). This new "max_xattr" option can be specified with both -fsdev and -virtfs command line options, with the "local" and the "synth" fs drivers. The previous limit of 1024 is preserved as the default value. Link: https://lore.kernel.org/qemu-devel/b7631ac0d8dde0629bc7c4f2c4185d9f57= b962b4.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit e6116a81f04c48af9530d984d16ef4ed4346e865) Signed-off-by: Michael Tokarev diff --git a/fsdev/file-op-9p.h b/fsdev/file-op-9p.h index f3800018954..d32fd9dafd0 100644 --- a/fsdev/file-op-9p.h +++ b/fsdev/file-op-9p.h @@ -99,6 +99,8 @@ typedef struct FsDriverEntry { FsThrottle fst; mode_t fmode; mode_t dmode; + /* temporary storage for parse_opts only */ + uint32_t max_xattr; } FsDriverEntry; =20 struct FsContext { diff --git a/fsdev/qemu-fsdev-opts.c b/fsdev/qemu-fsdev-opts.c index 07a18c6e48d..c2c1e83611b 100644 --- a/fsdev/qemu-fsdev-opts.c +++ b/fsdev/qemu-fsdev-opts.c @@ -46,6 +46,9 @@ static QemuOptsList qemu_fsdev_opts =3D { }, { .name =3D "dmode", .type =3D QEMU_OPT_NUMBER, + }, { + .name =3D "max_xattr", + .type =3D QEMU_OPT_NUMBER, }, =20 THROTTLE_OPTS, @@ -92,6 +95,9 @@ static QemuOptsList qemu_virtfs_opts =3D { }, { .name =3D "dmode", .type =3D QEMU_OPT_NUMBER, + }, { + .name =3D "max_xattr", + .type =3D QEMU_OPT_NUMBER, }, =20 { /*End of list */ } diff --git a/fsdev/qemu-fsdev.c b/fsdev/qemu-fsdev.c index 57877dad0a7..f97103cf442 100644 --- a/fsdev/qemu-fsdev.c +++ b/fsdev/qemu-fsdev.c @@ -45,7 +45,7 @@ typedef struct FsDriverListEntry { static QTAILQ_HEAD(, FsDriverListEntry) fsdriver_entries =3D QTAILQ_HEAD_INITIALIZER(fsdriver_entries); =20 -#define COMMON_FS_DRIVER_OPTIONS "id", "fsdriver", "readonly" +#define COMMON_FS_DRIVER_OPTIONS "id", "fsdriver", "readonly", "max_xattr" =20 static FsDriverTable FsDrivers[] =3D { { diff --git a/hw/9pfs/9p-local.c b/hw/9pfs/9p-local.c index cba3e945f99..7c07e237378 100644 --- a/hw/9pfs/9p-local.c +++ b/hw/9pfs/9p-local.c @@ -1506,6 +1506,15 @@ static int local_parse_opts(QemuOpts *opts, FsDriver= Entry *fse, Error **errp) const char *path =3D qemu_opt_get(opts, "path"); const char *multidevs =3D qemu_opt_get(opts, "multidevs"); =20 + uint64_t val =3D qemu_opt_get_number(opts, "max_xattr", + V9FS_MAX_XATTR_DEFAULT); + if (val > UINT32_MAX) { + error_setg(errp, "max_xattr value '%s' too large", + qemu_opt_get(opts, "max_xattr")); + return -1; + } + fse->max_xattr =3D val; + if (!sec_model) { error_setg(errp, "security_model property not set"); error_append_security_model_hint(errp); diff --git a/hw/9pfs/9p-synth.c b/hw/9pfs/9p-synth.c index be0492b400e..4d1ddb9979a 100644 --- a/hw/9pfs/9p-synth.c +++ b/hw/9pfs/9p-synth.c @@ -25,6 +25,8 @@ #include "qemu/rcu_queue.h" #include "qemu/cutils.h" #include "system/qtest.h" +#include "qapi/error.h" +#include "qemu/option.h" =20 /* Root node for synth file system */ static V9fsSynthNode synth_root =3D { @@ -615,12 +617,27 @@ static int synth_init(FsContext *ctx, Error **errp) return 0; } =20 +static int synth_parse_opts(QemuOpts *opts, FsDriverEntry *fse, Error **er= rp) +{ + uint64_t val =3D qemu_opt_get_number(opts, "max_xattr", + V9FS_MAX_XATTR_DEFAULT); + if (val > UINT32_MAX) { + error_setg(errp, "max_xattr value '%s' too large", + qemu_opt_get(opts, "max_xattr")); + return -1; + } + fse->max_xattr =3D val; + + return 0; +} + static bool synth_has_valid_file_handle(int fid_type, V9fsFidOpenState *fs) { return false; } =20 FileOperations synth_ops =3D { + .parse_opts =3D synth_parse_opts, .init =3D synth_init, .lstat =3D synth_lstat, .readlink =3D synth_readlink, diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 1255f4ff920..51de5b8aa92 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -4478,8 +4478,8 @@ int v9fs_device_realize_common(V9fsState *s, const V9= fsTransport *t, =20 s->reclaiming =3D false; =20 - /* init xattr FID limit */ - s->ctx.xattr_fid_limit =3D V9FS_MAX_XATTR_DEFAULT; + /* init xattr FID limit from fsdev config */ + s->ctx.xattr_fid_limit =3D fse->max_xattr; s->ctx.xattr_fid_count =3D 0; =20 rc =3D 0; diff --git a/system/vl.c b/system/vl.c index ec93988a03a..37524179d86 100644 --- a/system/vl.c +++ b/system/vl.c @@ -3256,7 +3256,7 @@ void qemu_init(int argc, char **argv) QemuOpts *fsdev; QemuOpts *device; const char *writeout, *sock_fd, *socket, *path, *security_= model, - *multidevs; + *multidevs, *max_xattr_str; =20 olist =3D qemu_find_opts("virtfs"); if (!olist) { @@ -3320,6 +3320,11 @@ void qemu_init(int argc, char **argv) if (multidevs) { qemu_opt_set(fsdev, "multidevs", multidevs, &error_abo= rt); } + max_xattr_str =3D qemu_opt_get(opts, "max_xattr"); + if (max_xattr_str) { + qemu_opt_set(fsdev, "max_xattr", max_xattr_str, + &error_abort); + } device =3D qemu_opts_create(qemu_find_opts("device"), NULL= , 0, &error_abort); qemu_opt_set(device, "driver", "virtio-9p-pci", &error_abo= rt); --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783829927; cv=none; d=zohomail.com; s=zohoarc; b=DoClGviSCBFx7lZj83YOJk+5OKlDt9anpB6cI9s7HrO38IPMZ7u9ju2KNuohUz2NY5CCaqB5X/ZPw3jvFoW0raev0YmIS0A18MP8oiekVfrpPGmLVYgk26VwYokm5Pg0uYOF97NR+A84DBEYN4yoGMg465hZdBqZPDw20Pdq9Ug= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783829927; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9Jtar+d0aDZS9m0QkKw6JUr8wKJUJmI5SRgsISg9BL8=; b=YIXYuFeSe0TSI7hfkheOpSniW5EbszDKwxmLCCIr5KCV0cEUT/k98Pw37Aj87+jtAzbgUpRHFh+9BcAeWksyRxduVoM80oF2DbP7gjCReW25m6WgVWEt9/lxGtukFmK9tjh4DPzCf+4mmtX0j3BGNVy4zF1gt/WCJeo86O/AKFo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783829927394956.1492577342992; Sat, 11 Jul 2026 21:18:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wild2-0002zQ-Ew; Sun, 12 Jul 2026 00:17:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wild0-0002sf-Ut; Sun, 12 Jul 2026 00:17:18 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcy-0006RV-Tt; Sun, 12 Jul 2026 00:17:18 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 024661C0BEA; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 348813EB94A; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 3822B133D7; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=GGpXA3OlClduB2ARaBqwEAkziFOHlToCRRZqUnM93KI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Eo0KXY1GJFBD5KFb4oXhO/VV8eOJR2J4x5gqpzhfTVbfdsKZHjDM4qTv4PSDQSlt2 vqAkIAXG5VcokZEo6dbAWnXXZgQppy/Pb4NyuiWq9tf57suWcJMo3zo3YwyKZnZ8J8 0bxHoP0ZiibY+pDQuowQ8xb6ZekY/XjJm6il51NWw/xslN0wfbsFS+3YmV5GnEDI3j dWVeF/zh1OlmmBMUdC0ofxhz4RyWQLi9cdfo+GFHwaoo4C+IiCg0z34qgUCuGdPOh2 lpSRVoViUKhZ+drY3NYszDcob7opogFtz8lWgxofhCvGOae7yMMaGD6j0uWicRbntm Ffpn26pnA09xQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 15/75] qemu-options: document 9pfs max_xattr option Date: Sun, 12 Jul 2026 07:14:33 +0300 Message-ID: <20260712041539.108341-15-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783829929473158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add documentation for the new "max_xattr" command line option of 9pfs server, introduced by the previous commit. Link: https://lore.kernel.org/qemu-devel/b5a1a6ba299a49183d0032d9e4cd5e009d= 4aae47.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 44cb540d2d079ce2c785b130e163ab42b9e1a109) Signed-off-by: Michael Tokarev diff --git a/qemu-options.hx b/qemu-options.hx index 396eea7ef20..a2b9d15ba24 100644 --- a/qemu-options.hx +++ b/qemu-options.hx @@ -1801,19 +1801,19 @@ ERST =20 DEF("fsdev", HAS_ARG, QEMU_OPTION_fsdev, "-fsdev local,id=3Did,path=3Dpath,security_model=3Dmapped-xattr|mapped= -file|passthrough|none\n" - " [,writeout=3Dimmediate][,readonly=3Don][,fmode=3Dfmode][,dmode=3Ddmo= de]\n" + " [,writeout=3Dimmediate][,readonly=3Don][,fmode=3Dfmode][,dmode=3Ddmo= de][,max_xattr=3Dmax]\n" " [[,throttling.bps-total=3Db]|[[,throttling.bps-read=3Dr][,throttling= .bps-write=3Dw]]]\n" " [[,throttling.iops-total=3Di]|[[,throttling.iops-read=3Dr][,throttli= ng.iops-write=3Dw]]]\n" " [[,throttling.bps-total-max=3Dbm]|[[,throttling.bps-read-max=3Drm][,= throttling.bps-write-max=3Dwm]]]\n" " [[,throttling.iops-total-max=3Dim]|[[,throttling.iops-read-max=3Dirm= ][,throttling.iops-write-max=3Diwm]]]\n" " [[,throttling.iops-size=3Dis]]\n" - "-fsdev synth,id=3Did\n", + "-fsdev synth,id=3Did[,max_xattr=3Dmax]\n", QEMU_ARCH_ALL) =20 SRST -``-fsdev local,id=3Did,path=3Dpath,security_model=3Dsecurity_model [,write= out=3Dwriteout][,readonly=3Don][,fmode=3Dfmode][,dmode=3Ddmode] [,throttlin= g.option=3Dvalue[,throttling.option=3Dvalue[,...]]]`` +``-fsdev local,id=3Did,path=3Dpath,security_model=3Dsecurity_model [,write= out=3Dwriteout][,readonly=3Don][,fmode=3Dfmode][,dmode=3Ddmode][,max_xattr= =3Dmax] [,throttling.option=3Dvalue[,throttling.option=3Dvalue[,...]]]`` \=20 -``-fsdev synth,id=3Did[,readonly=3Don]`` +``-fsdev synth,id=3Did[,readonly=3Don][,max_xattr=3Dmax]`` Define a new file system device. Valid options are: =20 ``local`` @@ -1887,6 +1887,12 @@ SRST Let every is bytes of a request count as a new request for iops throttling purposes. =20 + ``max_xattr=3Dmax`` + Specifies the maximum number of concurrent xattr FIDs allowed for + this export. The default is 1024. Set to 0 for allowing an infinite + number of xattr FIDs. This limit prevents host memory exhaustion + attacks by capping the number of simultaneous xattr FIDs. + -fsdev option is used along with -device driver "virtio-9p-...". =20 ``-device virtio-9p-type,fsdev=3Did,mount_tag=3Dmount_tag`` @@ -1906,14 +1912,14 @@ ERST =20 DEF("virtfs", HAS_ARG, QEMU_OPTION_virtfs, "-virtfs local,path=3Dpath,mount_tag=3Dtag,security_model=3Dmapped-xat= tr|mapped-file|passthrough|none\n" - " [,id=3Did][,writeout=3Dimmediate][,readonly=3Don][,fmode=3Dfm= ode][,dmode=3Ddmode][,multidevs=3Dremap|forbid|warn]\n" - "-virtfs synth,mount_tag=3Dtag[,id=3Did][,readonly=3Don]\n", + " [,id=3Did][,writeout=3Dimmediate][,readonly=3Don][,fmode=3Dfm= ode][,dmode=3Ddmode][,multidevs=3Dremap|forbid|warn][,max_xattr=3Dmax]\n" + "-virtfs synth,mount_tag=3Dtag[,id=3Did][,readonly=3Don][,max_xattr=3D= max]\n", QEMU_ARCH_ALL) =20 SRST -``-virtfs local,path=3Dpath,mount_tag=3Dmount_tag ,security_model=3Dsecuri= ty_model[,writeout=3Dwriteout][,readonly=3Don] [,fmode=3Dfmode][,dmode=3Ddm= ode][,multidevs=3Dmultidevs]`` +``-virtfs local,path=3Dpath,mount_tag=3Dmount_tag ,security_model=3Dsecuri= ty_model[,writeout=3Dwriteout][,readonly=3Don] [,fmode=3Dfmode][,dmode=3Ddm= ode][,multidevs=3Dmultidevs][,max_xattr=3Dmax]`` \=20 -``-virtfs synth,mount_tag=3Dmount_tag`` +``-virtfs synth,mount_tag=3Dmount_tag[,max_xattr=3Dmax]`` Define a new virtual filesystem device and expose it to the guest using a virtio-9p-device (a.k.a. 9pfs), which essentially means that a certa= in directory on host is made directly accessible by guest as a pass-throu= gh @@ -1979,6 +1985,12 @@ SRST Specifies the tag name to be used by the guest to mount this export point. =20 + ``max_xattr=3Dmax`` + Specifies the maximum number of concurrent xattr FIDs allowed for + this export. The default is 1024. Set to 0 for allowing an infinite + number of xattr FIDs. This limit prevents host memory exhaustion + attacks by capping the number of simultaneous xattr FIDs. + ``multidevs=3Dremap|forbid|warn`` Specifies how to deal with multiple devices being shared with the same 9p export in order to avoid file ID collisions on guest. --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830053; cv=none; d=zohomail.com; s=zohoarc; b=hbZK13nF6U2X4J6Acun57G89UWyITchAMLFynMN25Pyn+bOa/y5YPUcbZJA4Z/4RgRDmez8LX5bof2ETIEd4q4W5PAntNo0NjaJwXAtzr/APmjTArbA1Dm4s2kQ2gpA7oX0hz9eOq7MLjxlFarYGTJxfCYul6FXoLbbFIWJj/5k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830053; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=D3KE9RG7RKA0JveA+0ovG3dHAjhCJVwjRdp6hpwA60Q=; b=AHUL2ioNbWp6kxhZOMovPnzDpy9+k0JuzngaaE6E5j9K7NaY6gBD86MpwBg8A+G0tZJphdl4E0MqfIET2FtVkrkUTvUNYSr3OhU2/2nrjCFrCNAujh0m6wvZ1Psti5NobXfJgEZFEFdN3AfOvUQzZCNw/qi/F0jyG6oxG3hRUuc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830052896589.6489696055789; Sat, 11 Jul 2026 21:20:52 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wild3-000341-Ke; Sun, 12 Jul 2026 00:17:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wild1-0002tj-4u; Sun, 12 Jul 2026 00:17:19 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilcz-0006Re-AO; Sun, 12 Jul 2026 00:17:18 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 0905E1C0BEB; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 3C0113EB94B; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 3A8EB133D9; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=Khjy8c154DF+/mev2cp945KvRTfUKn0Bm6J5UfJfPfE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ne43Szd1Lzm5jT1VAllmuY5zAlzF+5v9ec3OzQGPuUD6R2yUhFDEwDWJLOWz5xH85 Yw4v/h49mulpO/UMyE1YmGzLpQkZcjxK7BQyZhWmQwggullYMF/UxiY7aV44NIJict rTQ46mRDxMiTKeIS58UWbT2dH4ix9RnCXbd941YPeRcqIoCSWBwTTwEV/y+e8h9udD kgqyCttkB2Q5THrvV1L9RHrzSeCULLBYGMu6lu7yo3p471vzCzcNzgagxD9Cp7pKTC e3UcolCZ8SeJdX0gAdq76NX0dpAnp4N+MOZ5YlcuL33RQcdwDUAMzfhHmbpWhn8Fd3 y/hdSRj6XwOdQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 16/75] tests/9p: add Tread / Rread test client functions Date: Sun, 12 Jul 2026 07:14:34 +0300 Message-ID: <20260712041539.108341-16-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830055892158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add v9fs_tread() and v9fs_rread() functions to the 9P test client for reading files from 9pfs server in test cases. Link: https://lore.kernel.org/qemu-devel/049bdd1e66416f5200fb3d59d2da5e8ec1= 49926d.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 54b8f64c422d0ed6d992387f0de419420cdb9fea) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/libqos/virtio-9p-client.c b/tests/qtest/libqos/vir= tio-9p-client.c index 98b77db51d7..3493b46b71c 100644 --- a/tests/qtest/libqos/virtio-9p-client.c +++ b/tests/qtest/libqos/virtio-9p-client.c @@ -240,6 +240,7 @@ static const char *rmessage_name(uint8_t id) id =3D=3D P9_RUNLINKAT ? "RUNLINKAT" : id =3D=3D P9_RFLUSH ? "RFLUSH" : id =3D=3D P9_RREADDIR ? "RREADDIR" : + id =3D=3D P9_RREAD ? "RREAD" : ""; } =20 @@ -1053,3 +1054,47 @@ void v9fs_runlinkat(P9Req *req) v9fs_req_recv(req, P9_RUNLINKAT); v9fs_req_free(req); } + +/* size[4] Tread tag[2] fid[4] offset[8] count[4] */ +TReadRes v9fs_tread(TReadOpt opt) +{ + P9Req *req; + uint32_t err; + + g_assert(opt.client); + + uint32_t body_size =3D 4 + 8 + 4; + + req =3D v9fs_req_init(opt.client, body_size, P9_TREAD, opt.tag); + v9fs_uint32_write(req, opt.fid); + v9fs_uint64_write(req, opt.offset); + v9fs_uint32_write(req, opt.count); + v9fs_req_send(req); + + if (!opt.requestOnly) { + v9fs_req_wait_for_reply(req, NULL); + if (opt.expectErr) { + v9fs_rlerror(req, &err); + g_assert_cmpint(err, =3D=3D, opt.expectErr); + } else { + v9fs_rread(req, opt.rread.count, opt.rread.data); + } + req =3D NULL; /* request was freed */ + } + + return (TReadRes) { + .req =3D req, + .count =3D opt.rread.count ? *opt.rread.count : 0 + }; +} + +/* size[4] Rread tag[2] count[4] data[count] */ +void v9fs_rread(P9Req *req, uint32_t *count, void *data) +{ + v9fs_req_recv(req, P9_RREAD); + v9fs_uint32_read(req, count); + if (data && *count > 0) { + v9fs_memread(req, data, *count); + } + v9fs_req_free(req); +} diff --git a/tests/qtest/libqos/virtio-9p-client.h b/tests/qtest/libqos/vir= tio-9p-client.h index 78228eb97d9..8067dcb0990 100644 --- a/tests/qtest/libqos/virtio-9p-client.h +++ b/tests/qtest/libqos/virtio-9p-client.h @@ -441,6 +441,37 @@ typedef struct TunlinkatRes { P9Req *req; } TunlinkatRes; =20 +/* options for 'Tread' 9p request */ +typedef struct TReadOpt { + /* 9P client being used (mandatory) */ + QVirtio9P *client; + /* user supplied tag number being returned with response (optional) */ + uint16_t tag; + /* file ID of file to read from (required) */ + uint32_t fid; + /* start position of read from beginning of file (optional) */ + uint64_t offset; + /* how many bytes to read (required) */ + uint32_t count; + /* data being received from 9p server as 'Rread' response (optional) */ + struct { + uint32_t *count; + void *data; + } rread; + /* only send Tread request but not wait for a reply? (optional) */ + bool requestOnly; + /* do we expect an Rlerror response, if yes which error code? (optiona= l) */ + uint32_t expectErr; +} TReadOpt; + +/* result of 'Tread' 9p request */ +typedef struct TReadRes { + /* if requestOnly was set: request object for further processing */ + P9Req *req; + /* amount of bytes read */ + uint32_t count; +} TReadRes; + void v9fs_set_allocator(QGuestAllocator *t_alloc); void v9fs_memwrite(P9Req *req, const void *addr, size_t len); void v9fs_memskip(P9Req *req, size_t len); @@ -490,5 +521,7 @@ TlinkRes v9fs_tlink(TlinkOpt); void v9fs_rlink(P9Req *req); TunlinkatRes v9fs_tunlinkat(TunlinkatOpt); void v9fs_runlinkat(P9Req *req); +TReadRes v9fs_tread(TReadOpt opt); +void v9fs_rread(P9Req *req, uint32_t *count, void *data); =20 #endif diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index 1af02e9c7bb..a3f35d49426 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -30,6 +30,7 @@ #define tsymlink(...) v9fs_tsymlink((TsymlinkOpt) __VA_ARGS__) #define tlink(...) v9fs_tlink((TlinkOpt) __VA_ARGS__) #define tunlinkat(...) v9fs_tunlinkat((TunlinkatOpt) __VA_ARGS__) +#define tread(...) v9fs_tread((TReadOpt) __VA_ARGS__) =20 static void pci_config(void *obj, void *data, QGuestAllocator *t_alloc) { --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830057; cv=none; d=zohomail.com; s=zohoarc; b=fwFBmHTk9sphbFRxMFj/v+P9BbsL4uBRj3N83f9CJUHYiMP3lPmLgyqm7BaM338GImBz4BKibDBcBGNy588y34Ipk/xq3WKwS4CBve54R10otjCFuBILcibasWB90RhfSQmZgs+d4pKY93ypmTq5t+RlTKUQgwbljARgxSziuGA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830057; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LNCObqSI32V+mpymdNXDaaZyX8wermrLBGzD8zJxPaM=; b=eNwL0/xOoRiAMWRQ7dHseRzEFrKg7orvSzA6BhiCfgsCUyM1drfhk5dgDqJ+NdqQawR/jUJwnAwyJsVaNdZz4OLmZu2SCDwpyVuXcuUELRna85eIslkKfF3ZwKzC0A/u3+AdV43AdB3N25LnryMeOh31llOhX7OLd2KXyhwBLEE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830057168149.2829637790578; Sat, 11 Jul 2026 21:20:57 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wildU-0003pH-LQ; Sun, 12 Jul 2026 00:17:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildQ-0003Xe-Mp; Sun, 12 Jul 2026 00:17:44 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildM-0006SF-L2; Sun, 12 Jul 2026 00:17:44 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 0F8D51C0BEC; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 42CD73EB94C; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 3CEC0133DB; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=WGTkRAj5cySGX4FAmqNWOy5T4WGwmvhPcjO9mhMd8HU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=vULvLyjI0UFz4jWVKlzLnl0C4A6qzbjqTwf/lkPKIZpyVMe53rnjo0VVxqs4ffJji JNJ3UgeMHWwNuNT8kvcwqNNX7QlYcjFeU9WRHKmDjj4qgyBbOZRwevlshfSKzRUHxU CrlAvKLK7JrmVyKL3jK90Q/J9YWQrk1I47gjGj2hLSNP6yC19TcxK2UD+Scr/92Ea/ WA1qJFAWGt55eqYlRJw5eY0QKCx137BM8jvpBqB2lJxtWq4zyJ0kxs1k95AtatNAdl qfSlwSXHql4/RRu9zqYemBcHpmlalPk/JeN5N/P3jmgPUNWelV1JRfi60xbUIDVXr9 uwthQlJLgHvNg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 17/75] tests/9p: add Tclunk / Rclunk test client functions Date: Sun, 12 Jul 2026 07:14:35 +0300 Message-ID: <20260712041539.108341-17-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830057898158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add v9fs_tclunk() and v9fs_rclunk() functions to the 9P test client for closing file handles (or "FIDs") in test cases. Link: https://lore.kernel.org/qemu-devel/d53f0337eb7f8525a14e394599d809ecf6= 805e5e.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit c46150530b3dd6370affa3422f2175ac4668836a) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/libqos/virtio-9p-client.c b/tests/qtest/libqos/vir= tio-9p-client.c index 3493b46b71c..bfc11c9c347 100644 --- a/tests/qtest/libqos/virtio-9p-client.c +++ b/tests/qtest/libqos/virtio-9p-client.c @@ -241,6 +241,7 @@ static const char *rmessage_name(uint8_t id) id =3D=3D P9_RFLUSH ? "RFLUSH" : id =3D=3D P9_RREADDIR ? "RREADDIR" : id =3D=3D P9_RREAD ? "RREAD" : + id =3D=3D P9_RCLUNK ? "RCLUNK" : ""; } =20 @@ -1098,3 +1099,36 @@ void v9fs_rread(P9Req *req, uint32_t *count, void *d= ata) } v9fs_req_free(req); } + +/* size[4] Tclunk tag[2] fid[4] */ +TClunkRes v9fs_tclunk(TClunkOpt opt) +{ + P9Req *req; + uint32_t err; + + g_assert(opt.client); + + req =3D v9fs_req_init(opt.client, 4, P9_TCLUNK, opt.tag); + v9fs_uint32_write(req, opt.fid); + v9fs_req_send(req); + + if (!opt.requestOnly) { + v9fs_req_wait_for_reply(req, NULL); + if (opt.expectErr) { + v9fs_rlerror(req, &err); + g_assert_cmpint(err, =3D=3D, opt.expectErr); + } else { + v9fs_rclunk(req); + } + req =3D NULL; /* request was freed */ + } + + return (TClunkRes) { .req =3D req }; +} + +/* size[4] Rclunk tag[2] */ +void v9fs_rclunk(P9Req *req) +{ + v9fs_req_recv(req, P9_RCLUNK); + v9fs_req_free(req); +} diff --git a/tests/qtest/libqos/virtio-9p-client.h b/tests/qtest/libqos/vir= tio-9p-client.h index 8067dcb0990..2b40dce8c0f 100644 --- a/tests/qtest/libqos/virtio-9p-client.h +++ b/tests/qtest/libqos/virtio-9p-client.h @@ -472,6 +472,26 @@ typedef struct TReadRes { uint32_t count; } TReadRes; =20 +/* options for 'Tclunk' 9p request */ +typedef struct TClunkOpt { + /* 9P client being used (mandatory) */ + QVirtio9P *client; + /* user supplied tag number being returned with response (optional) */ + uint16_t tag; + /* file ID to clunk (required) */ + uint32_t fid; + /* only send Tclunk request but not wait for a reply? (optional) */ + bool requestOnly; + /* do we expect an Rlerror response, if yes which error code? (optiona= l) */ + uint32_t expectErr; +} TClunkOpt; + +/* result of 'Tclunk' 9p request */ +typedef struct TClunkRes { + /* if requestOnly was set: request object for further processing */ + P9Req *req; +} TClunkRes; + void v9fs_set_allocator(QGuestAllocator *t_alloc); void v9fs_memwrite(P9Req *req, const void *addr, size_t len); void v9fs_memskip(P9Req *req, size_t len); @@ -523,5 +543,7 @@ TunlinkatRes v9fs_tunlinkat(TunlinkatOpt); void v9fs_runlinkat(P9Req *req); TReadRes v9fs_tread(TReadOpt opt); void v9fs_rread(P9Req *req, uint32_t *count, void *data); +TClunkRes v9fs_tclunk(TClunkOpt opt); +void v9fs_rclunk(P9Req *req); =20 #endif diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index a3f35d49426..c6d6bed80cf 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -31,6 +31,7 @@ #define tlink(...) v9fs_tlink((TlinkOpt) __VA_ARGS__) #define tunlinkat(...) v9fs_tunlinkat((TunlinkatOpt) __VA_ARGS__) #define tread(...) v9fs_tread((TReadOpt) __VA_ARGS__) +#define tclunk(...) v9fs_tclunk((TClunkOpt) __VA_ARGS__) =20 static void pci_config(void *obj, void *data, QGuestAllocator *t_alloc) { --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830045; cv=none; d=zohomail.com; s=zohoarc; b=GS6HP+1Oa0UJ0rYP2xSen7ZJMff6aRDM8NmjlTRCC8oW0SDWMbxNxJqGyegnSvu3rPTG0oPKjgMu/V0K0fq2LBPHO5r3FVqzdppzBESUzdleyNRo6Zzq5w+go1RzAu9x8yVVX+LyuvJGmrrySMGSiQw9pm7GQtlVkXt864F2ekI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830045; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=js4fVn2PspSVRNFxFRO+wcoy2UjBGDfRHSrMzbAXg3A=; b=AMLzsujDeA3lzhmG2XT/oQXV1JaVJSu3S7SF8n7qIAyEpGkxxIzmzh3wiD3s/0Wpf3kn3HfWpjiIPSCaEsDAeunqN3+hX+erG7wP8xYiUniICQkXzhc2w+4WEOkQDxA/8u+f4tbxu1Jt5Zd7KtPNk6aCg8TshceSxOl7VhEzKuU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830045600434.8611631563416; Sat, 11 Jul 2026 21:20:45 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wildU-0003jj-2K; Sun, 12 Jul 2026 00:17:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildR-0003Zt-25; Sun, 12 Jul 2026 00:17:45 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildM-0006SM-L2; Sun, 12 Jul 2026 00:17:44 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 153421C0BED; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 493253EB94D; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 3F2C4133DD; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=9XS6VxmUhp4MZETHCgVw/1/lM/LF2wYYMaFTXjAttnU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=L72WX1ARjTpBLqigiK6dAH1qmOLNrrUiWVUZtoTUAsOZuYfX2XkfzHgg+GNWPWTxS 7j1pL59nOMp4LUiWRGGE1eMkjMBWgKOGVk+A613VU5PrY+2aZR9op8Yj+3ZHgiZaTc w4wb2KAod0Qrnb+tlpLimvEjpq9BjtqD9zSnDSrnqhIPCqCmA1SGv8vIeOnnGIgvy0 TfyntRUR62p93oBgrUYzWu8mlooJd4q5wo1CVgX7Fd/YtOmn4AtXmONANHJ4tWHVue 4X1GoekVac6JYdDGK5fISjKXHOT7BY8m1iMOpypvlVlFH+5X9B0bGQhHroGJRgJpOs 2x1p0Rfl7RDZw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 18/75] tests/9p: add Txattrcreate / Rxattrcreate test client functions Date: Sun, 12 Jul 2026 07:14:36 +0300 Message-ID: <20260712041539.108341-18-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830045881158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add v9fs_txattrcreate() and v9fs_rxattrcreate() functions to the 9P test client for testing creation of xattrs with 9pfs server. Link: https://lore.kernel.org/qemu-devel/5dbc5061dab1f7829fffc40bf89d7ff443= e4bcab.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 7664feb26fef19caa4d72e07a9097fa625b593e5) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/libqos/virtio-9p-client.c b/tests/qtest/libqos/vir= tio-9p-client.c index bfc11c9c347..105e3bbf610 100644 --- a/tests/qtest/libqos/virtio-9p-client.c +++ b/tests/qtest/libqos/virtio-9p-client.c @@ -242,6 +242,7 @@ static const char *rmessage_name(uint8_t id) id =3D=3D P9_RREADDIR ? "RREADDIR" : id =3D=3D P9_RREAD ? "RREAD" : id =3D=3D P9_RCLUNK ? "RCLUNK" : + id =3D=3D P9_RXATTRCREATE ? "RXATTRCREATE" : ""; } =20 @@ -1132,3 +1133,47 @@ void v9fs_rclunk(P9Req *req) v9fs_req_recv(req, P9_RCLUNK); v9fs_req_free(req); } + +/* size[4] Txattrcreate tag[2] fid[4] name[s] attr_size[8] flags[4] */ +TXattrCreateRes v9fs_txattrcreate(TXattrCreateOpt opt) +{ + P9Req *req; + uint32_t err; + + g_assert(opt.client); + g_assert(opt.name); + + uint32_t body_size =3D 4 + 8 + 4; + uint16_t string_size =3D v9fs_string_size(opt.name); + + g_assert_cmpint(body_size, <=3D, UINT32_MAX - string_size); + body_size +=3D string_size; + + req =3D v9fs_req_init(opt.client, body_size, P9_TXATTRCREATE, opt.tag); + v9fs_uint32_write(req, opt.fid); + v9fs_string_write(req, opt.name); + v9fs_uint64_write(req, opt.size); + v9fs_uint32_write(req, opt.flags); + v9fs_req_send(req); + + err =3D 0; + if (!opt.requestOnly) { + v9fs_req_wait_for_reply(req, NULL); + if (opt.expectErr) { + v9fs_rlerror(req, &err); + g_assert_cmpint(err, =3D=3D, opt.expectErr); + } else { + v9fs_rxattrcreate(req); + } + req =3D NULL; /* request was freed */ + } + + return (TXattrCreateRes) { .req =3D req, .err =3D err }; +} + +/* size[4] Rxattrcreate tag[2] */ +void v9fs_rxattrcreate(P9Req *req) +{ + v9fs_req_recv(req, P9_RXATTRCREATE); + v9fs_req_free(req); +} diff --git a/tests/qtest/libqos/virtio-9p-client.h b/tests/qtest/libqos/vir= tio-9p-client.h index 2b40dce8c0f..aa7276d2c3a 100644 --- a/tests/qtest/libqos/virtio-9p-client.h +++ b/tests/qtest/libqos/virtio-9p-client.h @@ -492,6 +492,34 @@ typedef struct TClunkRes { P9Req *req; } TClunkRes; =20 +/* options for 'Txattrcreate' 9p request */ +typedef struct TXattrCreateOpt { + /* 9P client being used (mandatory) */ + QVirtio9P *client; + /* user supplied tag number being returned with response (optional) */ + uint16_t tag; + /* file ID to convert to xattr fid (required) */ + uint32_t fid; + /* name of the xattr (required) */ + const char *name; + /* size of the xattr value (required) */ + uint64_t size; + /* flags: P9_XATTR_CREATE or P9_XATTR_REPLACE (optional) */ + uint32_t flags; + /* only send Txattrcreate request but not wait for a reply? (optional)= */ + bool requestOnly; + /* do we expect an Rlerror response, if yes which error code? (optiona= l) */ + uint32_t expectErr; +} TXattrCreateOpt; + +/* result of 'Txattrcreate' 9p request */ +typedef struct TXattrCreateRes { + /* if requestOnly was set: request object for further processing */ + P9Req *req; + /* error code if Rlerror received */ + uint32_t err; +} TXattrCreateRes; + void v9fs_set_allocator(QGuestAllocator *t_alloc); void v9fs_memwrite(P9Req *req, const void *addr, size_t len); void v9fs_memskip(P9Req *req, size_t len); @@ -545,5 +573,7 @@ TReadRes v9fs_tread(TReadOpt opt); void v9fs_rread(P9Req *req, uint32_t *count, void *data); TClunkRes v9fs_tclunk(TClunkOpt opt); void v9fs_rclunk(P9Req *req); +TXattrCreateRes v9fs_txattrcreate(TXattrCreateOpt opt); +void v9fs_rxattrcreate(P9Req *req); =20 #endif diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index c6d6bed80cf..e383f8e4549 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -32,6 +32,7 @@ #define tunlinkat(...) v9fs_tunlinkat((TunlinkatOpt) __VA_ARGS__) #define tread(...) v9fs_tread((TReadOpt) __VA_ARGS__) #define tclunk(...) v9fs_tclunk((TClunkOpt) __VA_ARGS__) +#define txattrcreate(...) v9fs_txattrcreate((TXattrCreateOpt) __VA_ARGS__) =20 static void pci_config(void *obj, void *data, QGuestAllocator *t_alloc) { --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830077; cv=none; d=zohomail.com; s=zohoarc; b=aY7lwXxlFK2tjCDiwigPvHiyf+2NbZ3SW4J7nVLW9T8+LbCGS2LcDi6uCRjSvZ/KU7jDpiQrvyaY8ZeEXOFySxltJckU/+4+2KqrhybrUMk1465OowaGwFc5ATdlklf53trIu5SdoS2fbpNE6EFw6t9OdQuMpGAIEcB5VTm6Gzk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830077; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=nIuxQTKPYTGOQWEFatX5dq6/sC0KvkVW0sYlXUJPZMA=; b=AhY8sOJXeI/BtwkEbhIMc0jezUz8BpW4A1l6tDBlU8apUzlpSjG1V/DTD8fKHgrA3wEKWKwET1jgvUfd4EoLY6DMHTlTd+7rqeYJ4+YQF1AXiHGJNs0s2ARY6C/Q4ZtsZTJba1NgXxFBHAKslN0xDwPcOni1hvNI/X4r1JVkso8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830077587823.9945602998248; Sat, 11 Jul 2026 21:21:17 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wildY-00046R-AG; Sun, 12 Jul 2026 00:17:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildU-0003oO-9B; Sun, 12 Jul 2026 00:17:48 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildS-0006Th-CZ; Sun, 12 Jul 2026 00:17:47 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 1BFFE1C0BEE; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 4F3623EB94E; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 415C9133DF; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=CKKitLXQVQdtvni9ISKmivflqQB3pUtdzBd6TJngwvA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=PExqC+DQATzNBWHprWU3VvB7fJG/VtVfkem+Q2HXivwjyTGgILJJp7ZZfGMZ3mARI 0NpXRj1PKxutAZAc1dVkXfukvCX9rdVDfuggHeHFfhafQ9ndZWa2eIS99gQePa+uG8 PNDD4WfxNksvGE2eKn0RQHCGsnLy/VoeO2JwGIqkk60xuR9oZ1kPOJzfVa3jCI6BpI xuXWizqKYiDBcAphix49kG9HpFFDgPuxSv4H2dLbIB03DjW4Gn5nzY9BYFe3kcc6TY 2usHstmfICicsIXIW/3CSkMne7Lm5De8tTtpg3HfKGoyXekaiTE+2ITAbvAmLlrY+d 9P8accPKAnuiQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 19/75] hw/9pfs: enable xattr (mockup) support for synth fs driver Date: Sun, 12 Jul 2026 07:14:37 +0300 Message-ID: <20260712041539.108341-19-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830077935158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck The synth backend is used for testing only. Enable xattr operations by making lsetxattr and lremovexattr callbacks to return success result. They are still actually not doing anything, they just pretend to be working to prevent 9pfs server from erroring out on xattr requests. This allows the subsequent test case patches to verify xattr FID limit enforcement. Link: https://lore.kernel.org/qemu-devel/9c1c7128135f3bd9c2f62a3f64bb730b6a= 94ec7a.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 0e3085ddc7fb137b727829913c20ad9d08577bdb) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p-synth.c b/hw/9pfs/9p-synth.c index 4d1ddb9979a..af8b0474cf9 100644 --- a/hw/9pfs/9p-synth.c +++ b/hw/9pfs/9p-synth.c @@ -463,15 +463,15 @@ static int synth_lsetxattr(FsContext *ctx, V9fsPath *= path, const char *name, void *value, size_t size, int flags) { - errno =3D ENOTSUP; - return -1; + /* pretend it worked */ + return 0; } =20 static int synth_lremovexattr(FsContext *ctx, V9fsPath *path, const char *name) { - errno =3D ENOTSUP; - return -1; + /* pretend it worked */ + return 0; } =20 static int synth_name_to_path(FsContext *ctx, V9fsPath *dir_path, --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783829963; cv=none; d=zohomail.com; s=zohoarc; b=Lf7rofVvgpfXUnYTLVe9qMu7v4c3AULmrtU+55UYsE45b8rBbpT/sQ+S+BTS0eU16Ch0umBUtVtwJLLKYKsHbPgBPGAgPfm6JXmxAfzkX86AJcymYGDoF2nDlPeAJEu6nL5kLwXIm84MuBwx35cExOQvSV9fuXxr9vMl/GxViu0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783829963; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=UndOX+oqfjUG1SZ10KKGYC5CYf9TUuL7++n20S29ItM=; b=NwsznaNmQCxzPEWmRwRj0zpcDjs7It1NiKcd3yGVg4rQrQ6OxqPED+E5A+LiLB/QJDLsO1kzOzwZUdCUw5IQ1Yy7yKHl3R/eqpj/HD4QRf5NMSRGkyQknVRUafXJ+EPXDkwalqhDq9KtkqTCYptb2f2lLGbOQ0pod7IzUx/tZdo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783829963220188.33275001861716; Sat, 11 Jul 2026 21:19:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wildW-0003zr-8F; Sun, 12 Jul 2026 00:17:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildU-0003on-C0; Sun, 12 Jul 2026 00:17:48 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildS-0006Tq-Ji; Sun, 12 Jul 2026 00:17:48 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 221351C0BEF; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 555663EB94F; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 43935133E1; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=pe6ySvDiYfQAWynecStyW+Y8/yvqsIdBFLAlAEz5dFY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=tOCRwWeKNRzTKqiWsBiBCx+8pgmAXFfjEnDgbMG8sGE3oW+HFOCd5P27cGc0zRmoe bwEzcwXSdzaGnNvjsQSTwrDl5uFMlyE8AyCcYP0RCe2C6JffckMFPYT8JSoFZsIZJN 75C/HerqHohosf6xOP4Xww1FrGbRx5DP0mKRiWg9RvbohtlI4qQNywVSH7CpAAU8ho 0KrG3/g55CYso7qRb+tKldH9ccvbOFwGrTu9q8YRkWo+/43K9sIvH6cQGf5C1CkeJs s0AADuaZgajO1/xuGJPQWIL05vc4Z7J7FKrfSw9O3UidWr+KQMX9KWQukdjs+9YwVD qWlHRj+qODhgQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 20/75] hw/9pfs: add xattr count query interface to fs synth driver Date: Sun, 12 Jul 2026 07:14:38 +0300 Message-ID: <20260712041539.108341-20-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783829963532158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add a synthetic "/stat/xattr_count" file path that, if being read by 9p client, returns the 9p server internal xattr FID counter to client. This allows to test and verify that the xattr FID limit is being enforced correctly. Link: https://lore.kernel.org/qemu-devel/357c20fc244c04dcbd36b13aa20a5c9b20= 34e9f0.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 7e42d569a68aec6b0b6f1f068328c5c4ff20bc72) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p-synth.c b/hw/9pfs/9p-synth.c index af8b0474cf9..4f22bdacc3c 100644 --- a/hw/9pfs/9p-synth.c +++ b/hw/9pfs/9p-synth.c @@ -551,6 +551,19 @@ static ssize_t v9fs_synth_qtest_flush_write(void *buf,= int len, off_t offset, return 1; } =20 +/* transmits internal xattr counter to client */ +static ssize_t v9fs_synth_read_xattr_count(void *buf, int len, off_t offse= t, + void *arg) +{ + FsContext *ctx =3D arg; + size_t local_count =3D ctx->xattr_fid_count; + if (len < (int)sizeof(size_t)) { + return -ENOSPC; + } + memcpy(buf, &local_count, sizeof(size_t)); + return sizeof(size_t); +} + static int synth_init(FsContext *ctx, Error **errp) { QLIST_INIT(&synth_root.child); @@ -612,6 +625,19 @@ static int synth_init(FsContext *ctx, Error **errp) g_free(name); } } + + /* Directory for internal statistic queries */ + { + V9fsSynthNode *stat_dir =3D NULL; + ret =3D qemu_v9fs_synth_mkdir(NULL, 0755, "stat", &stat_dir); + assert(!ret); + + /* File for internal xattr count query */ + ret =3D qemu_v9fs_synth_add_file(stat_dir, 0444, "xattr_count", + v9fs_synth_read_xattr_count, + NULL, ctx); + assert(!ret); + } } =20 return 0; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783829906; cv=none; d=zohomail.com; s=zohoarc; b=TLxM35CunxGKNOE+A5mxvLpCOc/ueEbuh3EOfVPNxo4o9XXdoHq03Ja7/XV5crZjJzudpzxdr2wjnQLlwM/I+jL8/bhTyfT73v0QOubfU+QwYqHRjK8s4QxWPm+Hmr3HGCTOZK3GNljosK3uO1sphGfgSSOIrss1+1RkIu6X/U0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783829906; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=NT11i8TbwV6DTLj3HlzZQFTtNncnguP6ItcIwmSXMMc=; b=dafayGkXJa91eYou53oSztDLC/fVR2rqiSQRMoIroN2P9nnS9foOOdVUGWdZtWE2K+nv+Uxz5serzhYG2bEuJE0wonffi1yiVbBCLF+7zoW4O6cs+FPLXAuv0MvxSHpAVuVFd9VDRiEYPF2CoGOEQAatj3mEqPYFFXD2qwwe/ZA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783829906929985.3697809913207; Sat, 11 Jul 2026 21:18:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wildg-0004Cx-Cv; Sun, 12 Jul 2026 00:18:02 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildY-000470-0A; Sun, 12 Jul 2026 00:17:52 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildV-0006UH-V9; Sun, 12 Jul 2026 00:17:51 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 2A7991C0BF0; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 5B8F13EB950; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 45E55133E3; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=yirnsgBYBP+P5LTosEOX+6NsSsAkf1u82Z1cRgXB6/w=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=JCLjtJPtP0bQYM2EAvFxGxOYVliVTFoJg5qPMrf3ZTZQSOU3IvIKtBl5fCe/mpxL4 ruhqwqSQ8ubh3AQ/QtI5iDcbWHKHtCc6LeyzCEbpNU71kXdUzdRAm9/evIcTcCCiNQ uwk6+GlQf9EYkFvA7cx7miSRUQjKWyFE7UEKc+kfnDeoomuz8EBk00D3973+ZGicpl 3i4DcaZmSfCrwZCJ8+ad7XISEzJI/hYyUNQMcm/KsVAu0S+UZY9CiVHNLIL5YkPGpO y5T2RezdNTfP6Qmr2gsFdDtaCAzIgtRsAvC7Fjut5xgJRvAAq/sHOJZHnG6Y+B7fkQ 4K3DRmZVZ9UaA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 21/75] tests/9p: increase P9_MAX_SIZE for test client Date: Sun, 12 Jul 2026 07:14:39 +0300 Message-ID: <20260712041539.108341-21-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783829907561158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Increase the maximum 9P message size ('msize') of 9p test client from 4k to 32k to support larger messages. This is needed for the xattr tests being added with the subsequent patches which are going to transmit xattrs of size 8k. It would have also been possible to send them in multiple chunks, however let's not overcomplicate things. This new msize is still reasonable small compared to common msize values on production systems. Link: https://lore.kernel.org/qemu-devel/2dcb1243c80ea97d085af5171785850cf0= 12be36.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit df88255543667e7f14ac34d97e0ced142af18bdf) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/libqos/virtio-9p-client.h b/tests/qtest/libqos/vir= tio-9p-client.h index aa7276d2c3a..cbd298cc401 100644 --- a/tests/qtest/libqos/virtio-9p-client.h +++ b/tests/qtest/libqos/virtio-9p-client.h @@ -21,7 +21,8 @@ #include "qgraph.h" #include "tests/qtest/libqtest-single.h" =20 -#define P9_MAX_SIZE 4096 /* Max size of a T-message or R-message */ +/* Max size of a T-message or R-message */ +#define P9_MAX_SIZE (32 * 1024) =20 typedef struct { QTestState *qts; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783829956; cv=none; d=zohomail.com; s=zohoarc; b=Y5mzZug+mChN0vCtYfL4oFSgA65jHpNvsXZOr3WaflDjTH9HNBRYB9+E+g1wfblbbXORNUQ9eLiKAdR1mgZA+9lenP+chQk5i0V2SH3GvGDQM3ZcglFMRc1yKTBFQyLg/MCAgjd2tu7mAl/1VkpXyY5AdPQlFyIVvmxTsDvHzmQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783829956; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Tz50hIUdu0L+MYHqYN6GmvXwyD2hEkuyNZaAZlzlo5o=; b=LWA2VeUYvKDiV/DskUGyxgleEydAuEBnStQh3Y0JGSQHv91FXiEXpJkag5TkYu5OozRYX1Pvx2OvyAy97tWAs5ctBXhVjWySX6ypBPcymaz11Y4CLAAJ8N/zoMn/JEtdcUOPaxo9c3vByRAlxghNeoxGT037fH+HTSVYFM0WQsA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783829953600648.7433472873556; Sat, 11 Jul 2026 21:19:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wile5-0004ZK-Ic; Sun, 12 Jul 2026 00:18:26 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildr-0004Lc-K4; Sun, 12 Jul 2026 00:18:13 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildq-0006UJ-0I; Sun, 12 Jul 2026 00:18:11 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 309F01C0BF1; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 640273EB951; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 48181133E5; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=zubOijMCLi0QNYNubzThb5FX/Xsi0gKQolCwoOQOe9M=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=fX/SKPqZ1aruGflCx6jIimx5+ePGcMbafCbt2wR4is9jiMhz5HFzKbOJuMg63qWBX BK7Heu5Nc8J+vcIHGwGR7YjHX7sEL6EPlronKot9Mdd3PwlA03yxG9b42vQhtSWrkp gZEs6esGtw3Keviukx6yKD5LiL+MNGiA4Iox6FNDPID1z14CsaQsddaLXh0uOGUl7c FB9ugpw4qByf1vcv9i8V1CWlxFCHa+8aUsPnl6Id/Vwmkw6/YF7QXezvdr36cu6sHC 2U58eRt/PE6KQS/yizAvcPZXViEInQpQJduhD4i+pgUcXExNuEotxVtyShBEUpMF2t PTS3BFZ45mpZg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 22/75] tests/9p: add virtio_9p_add_synth_driver_args() test client function Date: Sun, 12 Jul 2026 07:14:40 +0300 Message-ID: <20260712041539.108341-22-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783829959581158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add virtio_9p_add_synth_driver_args() to allow appending custom QEMU options for individual 9p synth tests. Link: https://lore.kernel.org/qemu-devel/7fe3eca5d17292464676b68d0513052564= cd432a.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 84525ece6817f4e9760a1d484cab01123a546e92) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/libqos/virtio-9p.c b/tests/qtest/libqos/virtio-9p.c index 186fcc1141a..823756de8c4 100644 --- a/tests/qtest/libqos/virtio-9p.c +++ b/tests/qtest/libqos/virtio-9p.c @@ -228,6 +228,12 @@ static void regex_replace(GString *haystack, const cha= r *pattern, g_string_assign(haystack, s); } =20 +void virtio_9p_add_synth_driver_args(GString *cmd_line, const char *args) +{ + /* append passed args to '-fsdev ...' group */ + regex_replace(cmd_line, "(-fsdev \\w[^ ]*)", "\\1,%s", args); +} + void virtio_9p_assign_local_driver(GString *cmd_line, const char *args) { g_assert_nonnull(local_test_path); diff --git a/tests/qtest/libqos/virtio-9p.h b/tests/qtest/libqos/virtio-9p.h index 480727120ea..e7efeef7a1d 100644 --- a/tests/qtest/libqos/virtio-9p.h +++ b/tests/qtest/libqos/virtio-9p.h @@ -44,6 +44,12 @@ struct QVirtio9PDevice { QVirtio9P v9p; }; =20 +/** + * Add required test specific args to the QEMU command line for the 9pfs + * 'synth' fs driver. + */ +void virtio_9p_add_synth_driver_args(GString *cmd_line, const char *args); + /** * Creates the directory for the 9pfs 'local' filesystem driver to access. */ --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830149; cv=none; d=zohomail.com; s=zohoarc; b=g6yZTf0klnGUb1FGjP6APoWUYKmotbZWETZ3RrSfR9oO+9GtM2NKkAz4kh0SEQoo4uIjyTkMYBiRM/DEFqwOZP/RCftzLchjHBAgTqExi42C4k5iYextlV1Gcdi8ZoIc46sAD1ldpggWmh81f0XZh6vs0F59NTULO1YH7g6EE2I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830149; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=c4CKA5TJMAqw/B/ykZhcVg1VhYJdOkM7piQ27xHFSXw=; b=nytOtDb16z44iUL/hZBU/D0jJ4VEhs1PRQ0G2uBFeM4/krsXjRnU/juN89II+HFa4syyKXlEtRe7pd7nlOQmPbXEOvrBTY6HaMb/xGLbn7gicqtd7fka+lHCFrYrbm4RO9EhUCHXFcHqV/i7h8PyDighTxLmXpuket83df90OAE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383014925119.481388479893667; Sat, 11 Jul 2026 21:22:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wileH-00054U-TP; Sun, 12 Jul 2026 00:18:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildv-0004SL-OV; Sun, 12 Jul 2026 00:18:19 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildt-0006Ur-FB; Sun, 12 Jul 2026 00:18:15 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 378D61C0BF2; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 6B2E63EB952; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 4A799133E7; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=Z2HNYWF7B7awHbPsYzXXAih4lvIMj4vFy/VDQSVOX8o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Is7dPzei530fX8n87v4Y4DZohMfMtJjekfMtXpZn21YSQ4JqxjmOW6ZQRImMfjy9G G8QXG0J1L1c16GzH4ZIURcLSQ/l7Gb4j8nM5mCQycT9zWeeFV69Aegs6CqslVQ1CUn YVJZnlvY4vsHLdHl4yu2gFqFJ/Ian8z9+logUvnTWUMYQw2C5hG64tZ27a2KyLOQZf kmsH4mR6b0LJ05p2iQUIcNDHNIhrAiGSwndT+XddKi+Q3K0HHFwlqUkCL39TLFYI13 nj/ZPPYhuPgtKrQ3VW20r9ZRIGFt04agRnv1aOhJGUXQuPv79PSurHNRmWR+mjvuJG ON6aP6E1V+shQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 23/75] tests/9p: add 3 xattr FID limit test cases (synth fs driver) Date: Sun, 12 Jul 2026 07:14:41 +0300 Message-ID: <20260712041539.108341-23-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830150425158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add 3 test cases to verify correct xattr FID limit enforcement of 9pfs server. - 1. test with default max_xattr=3D1024 - 2. test with custom max_xattr=3D100 - 3. test with unlimited max_xattr=3D0 These are tests using the synth driver. Advantage: by using the synth driver the tests cannot only check when the xattr FID limit kicks in (server would return an Rlerror response with ENOSPC), but can also validate the current 9p server internal xattr FID counter at any moment. This is a slow test (may take several seconds) and therefore registered as "slow" test and not running by default. Use -m slow to run this test. Link: https://lore.kernel.org/qemu-devel/540c51faa074d9dd736bbf2170084a1228= 8e23ef.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 0e1085819e444365bc3160f7b1adae3843b2da79) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index e383f8e4549..eaab379df33 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -34,6 +34,15 @@ #define tclunk(...) v9fs_tclunk((TClunkOpt) __VA_ARGS__) #define txattrcreate(...) v9fs_txattrcreate((TXattrCreateOpt) __VA_ARGS__) =20 +/* + * xattr size to be used for xattr tests + * + * 64k is the max. xattr size supported by the Linux kernel, However btrfs + * for instance supports only 16219 bytes. So let's be conservative and + * just use 8k for the xattr tests. + */ +#define TEST_XATTR_SIZE (8 * 1024) + static void pci_config(void *obj, void *data, QGuestAllocator *t_alloc) { QVirtio9P *v9p =3D obj; @@ -106,6 +115,42 @@ static bool fs_dirents_contain_name(struct V9fsDirent = *e, const char* name) return false; } =20 +/* + * Returns the current internal xattr FID count (works with synth driver o= nly). + */ +static size_t get_xattr_count(QVirtio9P *v9p) +{ + uint16_t nwqid; + v9fs_qid *wqid; + const char *xattr_count_path[] =3D { "stat", "xattr_count" }; + size_t xattr_count; + uint32_t bytes_read; + + /* walk to /stat/xattr_count file */ + uint32_t fid =3D twalk({ + .client =3D v9p, .fid =3D 0, + .nwname =3D 2, .wnames =3D (char **)xattr_count_path, + .rwalk =3D { .nwqid =3D &nwqid, .wqid =3D &wqid } + }).newfid; + + /* open for read */ + tlopen({ + .client =3D v9p, .fid =3D fid, .flags =3D O_RDONLY, + .rlopen =3D { .qid =3D NULL, .iounit =3D NULL } + }); + + /* read the internal xattr FID count */ + tread({ + .client =3D v9p, .fid =3D fid, .offset =3D 0, .count =3D sizeof(xa= ttr_count), + .rread =3D { .count =3D &bytes_read, .data =3D &xattr_count } + }); + + /* cleanup */ + tclunk({ .client =3D v9p, .fid =3D fid }); + + return xattr_count; +} + /* basic readdir test where reply fits into a single response message */ static void fs_readdir(void *obj, void *data, QGuestAllocator *t_alloc) { @@ -247,6 +292,108 @@ static void do_readdir_split(QVirtio9P *v9p, uint32_t= count) g_free(wnames[0]); } =20 +/* + * Test 9p server's xattr FID count limit enforcement. + * + * Shared test code for both 'synth' and 'local' driver to verify correct + * behaviour of 9p server enforcing preconfigured xattr FID count limit + * correctly. + * + * @v9p: 9pfs client + * + * @max_xattr: max. allowed xattr FIDs, or -1 for infinite + * + * @check_counter: whether to verify 9p server internal xattr FID counter + * (only works with 'synth' fs driver) + */ +static void do_xattr_limit(QVirtio9P *v9p, int max_xattr, bool check_count= er) +{ + size_t count; + int i; + int limit =3D (max_xattr !=3D -1) ? max_xattr : V9FS_MAX_XATTR_DEFAULT= + 100; + g_autofree uint32_t *fids =3D g_new0(uint32_t, limit); + uint32_t err_fid =3D 0; + const char *file_path[] =3D { QTEST_V9FS_SYNTH_WRITE_FILE }; + g_autofree uint8_t *xattr_data =3D g_malloc(TEST_XATTR_SIZE); + + if (!g_test_slow()) { + g_test_skip("This is a slow test, run with -m slow"); + return; + } + + /* prepare xattr data with 'X' characters */ + memset(xattr_data, 'X', TEST_XATTR_SIZE); + + tattach({ .client =3D v9p }); + + /* create max. amount of permitted xattrs */ + for (i =3D 0; i < limit; i++) { + /* walk to create a new fid */ + fids[i] =3D twalk({ + .client =3D v9p, .fid =3D 0, + .nwname =3D 1, .wnames =3D (char **) file_path + }).newfid; + + /* create new xattr fid */ + txattrcreate({ + .client =3D v9p, .fid =3D fids[i], .name =3D "user.test", + .size =3D TEST_XATTR_SIZE, .flags =3D 0 + }); + + /* transfer the xattr data */ + twrite({ + .client =3D v9p, .fid =3D fids[i], .offset =3D 0, + .count =3D TEST_XATTR_SIZE, .data =3D xattr_data + }); + + /* verify server internal xattr counter */ + if (check_counter) { + count =3D get_xattr_count(v9p); + g_assert_cmpuint(count, =3D=3D, (i + 1)); + } + + /* avoid virtio descriptor exhaustion */ + qvirtqueue_reset_pool(v9p->vq); + } + + /* if xattrs are limited, the next xattr should fail */ + if (max_xattr !=3D -1) { + /* walk to create another fid */ + err_fid =3D twalk({ + .client =3D v9p, .fid =3D 0, + .nwname =3D 1, .wnames =3D (char **) file_path + }).newfid; + + /* try to create one more xattr fid - should fail */ + txattrcreate({ + .client =3D v9p, .fid =3D err_fid, .name =3D "user.test_exceed= ", + .size =3D TEST_XATTR_SIZE, .flags =3D 0, + .expectErr =3D ENOSPC + }); + + /* verify internal xattr counter hasn't changed */ + if (check_counter) { + count =3D get_xattr_count(v9p); + g_assert_cmpuint(count, =3D=3D, limit); + } + } + + /* clunk all fids (should decrement xattr counter) */ + for (i =3D 0; i < limit; i++) { + tclunk({ .client =3D v9p, .fid =3D fids[i] }); + qvirtqueue_reset_pool(v9p->vq); + } + if (err_fid) { + tclunk({ .client =3D v9p, .fid =3D err_fid }); + } + + /* verify internal xattr counter is zero */ + if (check_counter) { + count =3D get_xattr_count(v9p); + g_assert_cmpuint(count, =3D=3D, 0); + } +} + static void fs_walk_no_slash(void *obj, void *data, QGuestAllocator *t_all= oc) { QVirtio9P *v9p =3D obj; @@ -507,6 +654,27 @@ static void fs_readdir_split_512(void *obj, void *data, do_readdir_split(obj, 512); } =20 +static void fs_synth_xattr_limit_default(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_xattr_limit(obj, V9FS_MAX_XATTR_DEFAULT, true); +} + +static void fs_synth_xattr_limit_custom(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_xattr_limit(obj, 100, true); +} + +static void fs_synth_xattr_limit_unlimited(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_xattr_limit(obj, -1, true); +} + =20 /* tests using the 9pfs 'local' fs driver */ =20 @@ -807,6 +975,18 @@ static void fs_deep_absolute_path(void *obj, void *dat= a, g_string_free(path, TRUE); } =20 +static void *synth_max_xattr_custom_opt(GString *cmd_line, void *arg) +{ + virtio_9p_add_synth_driver_args(cmd_line, "max_xattr=3D100"); + return arg; +} + +static void *synth_max_xattr_unlimited_opt(GString *cmd_line, void *arg) +{ + virtio_9p_add_synth_driver_args(cmd_line, "max_xattr=3D0"); + return arg; +} + static void cleanup_9p_local_driver(void *data) { /* remove previously created test dir when test is completed */ @@ -857,7 +1037,14 @@ static void register_virtio_9p_test(void) fs_readdir_split_256, &opts); qos_add_test("synth/readdir/split_128", "virtio-9p", fs_readdir_split_128, &opts); - + qos_add_test("synth/xattr_limit/default", "virtio-9p", + fs_synth_xattr_limit_default, &opts); + opts.before =3D synth_max_xattr_custom_opt; + qos_add_test("synth/xattr_limit/custom", "virtio-9p", + fs_synth_xattr_limit_custom, &opts); + opts.before =3D synth_max_xattr_unlimited_opt; + qos_add_test("synth/xattr_limit/unlimited", "virtio-9p", + fs_synth_xattr_limit_unlimited, &opts); =20 /* 9pfs test cases using the 'local' filesystem driver */ opts.before =3D assign_9p_local_driver; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830284; cv=none; d=zohomail.com; s=zohoarc; b=mivG0idTVRlh/wS3I6dInjAmCERU33RBtGsyaKUQeA99Kk+uGo9q5g+rUAxzlnLQVHN/eHgQTeQbtZUiXRAerdbLs4NWjbeVdu7hBWiVq+6/h7JKBvIBbAk/oiEE3e2gTQcMmA59RboK5HeO2/M7lgw7W4KC0fDb0glvoGicwEU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830284; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tSxxo2/PMhe4ZdWdQlYKg0E5YB+vD/fkHcltwKilv1c=; b=V+8Byg0TZDSbMXgP/0Q/F1ASYcADmHDLLn21sQ/w3BdeeUpePMe8o2F+51CaHxPN6JrOSbFQQliCF8JYLcqXxR98KNWaNmQr/mZphkrW91Irz/i0MXSjB0p3Of96LEztQ8ET28M9rE19+rNdxk+op/xdRGgmuno2dJE4alfcV3E= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830284268296.0555096363323; Sat, 11 Jul 2026 21:24:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wileI-00056Q-2o; Sun, 12 Jul 2026 00:18:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildv-0004QA-JG; Sun, 12 Jul 2026 00:18:18 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildt-0006Vm-RQ; Sun, 12 Jul 2026 00:18:15 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 3D4151C0BF3; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 712B33EB953; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 4CBA4133E9; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=ZDD45Ac+9TANBLbwYfP8sJUJkq3AvyVrE4IvIKkGe4U=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=MMfVbIFqN0YeaEGDf+NlnOf1hPT0NUeHbNqjtlB10BcgVSJLJRQOV6GWh7UosSZvl HX3QLpTLQwVN2dLk9dkKQNwrqNkSXJpuYprCPL6UUUsfZw0TYIgXbF6z9nUiDkvcHA Gh69zv4Lto1saIMkqXPkL+3LaEEj5byZFcnO11ojazCflXbTpi8wM6U/Ppp0OyDN/6 30oCpwas3ofYQ40J88mMaIQtAC0fUhpnbm/fk7R1a+I6jZxDDaxj/xGswWheNovSzX 7SR78VOc3/mHxiCGcWu6sI/k3CQbPoAq7Cyx4uajzJcpGdSQHCpc07zVOXUBA7y+PD toFZ1YQaHANpQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 24/75] tests/9p: add 3 xattr FID limit test cases (local fs driver) Date: Sun, 12 Jul 2026 07:14:42 +0300 Message-ID: <20260712041539.108341-24-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830284671158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Analogue to the previously added 3 synth tests, add (similar) 3 test cases using the "local" fs driver to verify correct xattr FID limit enforcement of 9pfs server with a real filesystem. These 3 new local tests use the shared test code of the previously added 3 synth tests. The only difference is that the local fs driver does not expose the current internal xattr FID counter, so we can't verify this with the local tests. This is a slow test (may take several seconds) and therefore registered as "slow" test and not running by default. Use -m slow to run this test. Link: https://lore.kernel.org/qemu-devel/d23fa874df4f474ee7cbe738a35c148342= 6057f0.1781361555.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 04a62cdfe873d07a5f264d03372bfc34bbcdddf0) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index eaab379df33..ba607f1d98b 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -394,6 +394,19 @@ static void do_xattr_limit(QVirtio9P *v9p, int max_xat= tr, bool check_counter) } } =20 +static void do_local_xattr_limit(QVirtio9P *v9p, int max_xattr) +{ + g_autofree char *test_file =3D virtio_9p_test_path("WRITE"); + + /* + * this file must be created for the test to work with the 'local' fs = driver + */ + g_file_set_contents(test_file, "", 0, NULL); + + /* the actual test code shared with the 'synth' fs driver tests */ + do_xattr_limit(v9p, max_xattr, false); +} + static void fs_walk_no_slash(void *obj, void *data, QGuestAllocator *t_all= oc) { QVirtio9P *v9p =3D obj; @@ -975,6 +988,27 @@ static void fs_deep_absolute_path(void *obj, void *dat= a, g_string_free(path, TRUE); } =20 +static void fs_local_xattr_limit_default(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_local_xattr_limit(obj, V9FS_MAX_XATTR_DEFAULT); +} + +static void fs_local_xattr_limit_custom(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_local_xattr_limit(obj, 100); +} + +static void fs_local_xattr_limit_unlimited(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + v9fs_set_allocator(t_alloc); + do_local_xattr_limit(obj, -1); +} + static void *synth_max_xattr_custom_opt(GString *cmd_line, void *arg) { virtio_9p_add_synth_driver_args(cmd_line, "max_xattr=3D100"); @@ -993,20 +1027,42 @@ static void cleanup_9p_local_driver(void *data) virtio_9p_remove_local_test_dir(); } =20 -static void *assign_9p_local_driver(GString *cmd_line, void *arg) +static void assign_9p_local_driver_with_args(GString *cmd_line, + const char *extra_opts) { /* make sure test dir for the 'local' tests exists */ virtio_9p_create_local_test_dir(); =20 - virtio_9p_assign_local_driver(cmd_line, "security_model=3Dmapped-xattr= "); + g_autofree char *opts =3D + (extra_opts) ? + g_strdup_printf("security_model=3Dmapped-xattr,%s", extra_opts= ) : + g_strdup("security_model=3Dmapped-xattr"); + + virtio_9p_assign_local_driver(cmd_line, opts); =20 g_test_queue_destroy(cleanup_9p_local_driver, NULL); +} + +static void *assign_9p_local_driver(GString *cmd_line, void *arg) +{ + assign_9p_local_driver_with_args(cmd_line, NULL); return arg; } =20 -static void register_virtio_9p_test(void) +static void *local_max_xattr_custom_opt(GString *cmd_line, void *arg) { + assign_9p_local_driver_with_args(cmd_line, "max_xattr=3D100"); + return arg; +} =20 +static void *local_max_xattr_unlimited_opt(GString *cmd_line, void *arg) +{ + assign_9p_local_driver_with_args(cmd_line, "max_xattr=3D0"); + return arg; +} + +static void register_virtio_9p_test(void) +{ QOSGraphTestOptions opts =3D { }; =20 @@ -1063,6 +1119,14 @@ static void register_virtio_9p_test(void) &opts); qos_add_test("local/deep_absolute_path", "virtio-9p", fs_deep_absolute_path, &opts); + qos_add_test("local/xattr_limit/default", "virtio-9p", + fs_local_xattr_limit_default, &opts); + opts.before =3D local_max_xattr_custom_opt; + qos_add_test("local/xattr_limit/custom", "virtio-9p", + fs_local_xattr_limit_custom, &opts); + opts.before =3D local_max_xattr_unlimited_opt; + qos_add_test("local/xattr_limit/unlimited", "virtio-9p", + fs_local_xattr_limit_unlimited, &opts); } =20 libqos_init(register_virtio_9p_test); --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783829939; cv=none; d=zohomail.com; s=zohoarc; b=Djg7M12E+/rXh2G2wHhPZUJtLwPxL5t7A+eALlWVrXtx5sPPyj3swC9qT3JecH+VZv4Net4vpxfDS85cpB4UrJuwAsSReGXFotbUUI6ObpwD3HfnffL/xHHJfFmPbN2wq6c+YgXp/NThs+SyMtg0ELRC6J4gDOg/IoiTrJsenmc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783829939; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=C01CJF2fC6q1eXL9qkzXS5k8BVurW6wnoxS5tiPUP00=; b=nxTmUf5zo4Agk7bcLhmFxmDnE8ai0OQ2sVb/J+tzUBtVWuY99AXYVfQvj8kCIHsytSYZwK8Z3hlyX4gXmfIRAHuR9johX+FFcvHXyd+HlZ4nEPF/14HPK/0OE6YrQ6U//YTAU9g+bmgS2FNBEDnBzo8bqjwT2ZwP1WUe7LINfwc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783829938675497.4799601380688; Sat, 11 Jul 2026 21:18:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wileJ-0005KM-BA; Sun, 12 Jul 2026 00:18:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildz-0004Vy-88; Sun, 12 Jul 2026 00:18:21 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wildx-0006WE-25; Sun, 12 Jul 2026 00:18:18 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 437D61C0BF4; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 76AF73EB954; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 4F0E8133EB; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=7EMrUXPB7ZaJo6Qxenp01a256ZZT8o5HU5j7/FIoGok=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=xgTvCb5lFaTlzxEF8B+XtF/aaiNFhUkxfsBy71QXgqc5R753qbrb3b7/ZqNxFhnei epeEdFEylBFKad1TR851cu2X73ux7hL1W9/lXaWJoMxwR5A1NeBlac5ww/tfvtXwtJ vzjaJlRCDM450UEtrTxtiQYqp8S7TkhLAVlSUjgCBQ7m4Mrd8l0URGBkMQ6bBL4D1l X1LLKmEfqUp3MWBMXG4TOy8nkoJPjXdOP9mzx8RkHImjsOHqf7HJqazSp8IngwZryA sfJ2g/MGxGqLc+oHxk3KA0300IoVQqAITLb98hiwvAWKFkrxCFpDkYV+exLHlO7mJK X4aFYmfCAXb/g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Feifan Qian , Michael Tokarev Subject: [Stable-10.0.12 25/75] hw/9pfs: fix invalid union access by v9fs_co_fsync() Date: Sun, 12 Jul 2026 07:14:43 +0300 Message-ID: <20260712041539.108341-25-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783829941702158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck The individual FID types (P9_FID_NONE, P9_FID_FILE, P9_FID_DIR, P9_FID_XATT= R) share union V9fsFidOpenState with FID-type specific fields. Accessing any of the union fields must comply with the FID-type to avoid undefined behaviour or information disclosure. Fix this in v9fs_fsync() and v9fs_wstat() by checking if FID has a valid fi= le descriptor before calling v9fs_co_fsync(). Fixes: 10b468bdc533 ("virtio-9p: Implement TXATTRCREATE") Reported-by: Feifan Qian Link: https://lore.kernel.org/qemu-devel/b583e29d5a0776e41263732c93ac9f0da0= a6016d.1781621428.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 32cae47c332f88241632905e0a3abcbb35b019c3) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 51de5b8aa92..06ee09cccbe 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -2273,10 +2273,15 @@ static void coroutine_fn v9fs_fsync(void *opaque) err =3D -ENOENT; goto out_nofid; } + if (!fid_has_valid_file_handle(pdu->s, fidp)) { + err =3D -EBADF; + goto out; + } err =3D v9fs_co_fsync(pdu, fidp, datasync); if (!err) { err =3D offset; } +out: put_fid(pdu, fidp); out_nofid: pdu_complete(pdu, err); @@ -3630,6 +3635,10 @@ static void coroutine_fn v9fs_wstat(void *opaque) } /* do we need to sync the file? */ if (donttouch_stat(&v9stat)) { + if (!fid_has_valid_file_handle(s, fidp)) { + err =3D -EBADF; + goto out; + } err =3D v9fs_co_fsync(pdu, fidp, 0); goto out; } --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830429; cv=none; d=zohomail.com; s=zohoarc; b=TQcHCjE/8GDJKVFi1RGSS7K4LhzvogY7ulnutt+M8misn+A+t3XTnBUUl2E4hFQFoRELIWH8guauFRySOgLDz9lr/PBWn0m0wzgsxMy8MMEG7g61rvmdiXiLjhjOWBa64DuU6MHOzlo5oQ5rmI+7YT0cVozV9/5b+jhlU1UkaAY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830429; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=j07qE2QjUf23HBWaql+PpVKuHCbtkw7BzbrDxzfMarU=; b=dHEpqG/RXnD9IweBR06drtPueHBHc0tz6ttf3Qbncn7i/Mj/dGhRWea7J0dBIe9uEiiSky2CSn69m6kuN6pBvejuk+gC/lh75Ob4jAjjQ0ROOORwRRBw9+zZ4AfvztPAWCY45fa/RUleo4i8azKqD0S0Ue8Of9+LfYXbsV1IRLY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383042936247.232322471920156; Sat, 11 Jul 2026 21:27:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wileL-0005ds-6d; Sun, 12 Jul 2026 00:18:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileJ-0005Nt-CN; Sun, 12 Jul 2026 00:18:39 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileH-0006WH-8l; Sun, 12 Jul 2026 00:18:39 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 497461C0BF5; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 7CB7B3EB955; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 5141B133ED; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=30XHb7JEmG+SgbZ3jo4sw/f8oaEHifujpMYdiu7biGE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=UV+9zqVsZZloz3TZBLAZyORsC/oDh8Y+DmFJ30ExQSxLIJYL9rhenl9mUQ0kJ86IL IBSLoOwRu4s5oApmLsvxX1ZfT9oF0xyolEnhJZ302FCYqL9twRGWmSjCJx/cXndCgQ OUHQoW75j9JFvCFZAbuiWFgFYY5tcrbnEHNesg3iDQO/fB985s5KziJLV4hbX7WWTu QU+BN+t3iWJ4Dsx8pTIP28TEZ4lmhhAxuq0kM8KXRD+vNsvUDRq22khJ3rFZvmpsQo X7JT3hynGrxOilqeA2nmeOpkr1Qw8gVODr3pfDBUsIPWPifZBR5JUPEcj+yDhsQ7mS iEL14RDHEeyqQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 26/75] hw/9pfs: fix invalid union access by v9fs_co_fstat() Date: Sun, 12 Jul 2026 07:14:44 +0300 Message-ID: <20260712041539.108341-26-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830431158158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck The individual FID types (P9_FID_NONE, P9_FID_FILE, P9_FID_DIR, P9_FID_XATT= R) share union V9fsFidOpenState with FID-type specific fields. Accessing any of the union fields must comply with the FID-type to avoid undefined behaviour or information disclosure. Fix this in v9fs_lock() and v9fs_getlock() by checking if FID has a valid file descriptor before calling v9fs_co_fstat(). Fixes: 10b468bdc533 ("virtio-9p: Implement TXATTRCREATE") Link: https://lore.kernel.org/qemu-devel/4b33cd1aaa2551efda220a6f651e3660d2= 7f4746.1781621428.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit c3aa2491cd2cd89e2f484d32f323ee447e782984) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 06ee09cccbe..e337b45517f 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -3907,6 +3907,10 @@ static void coroutine_fn v9fs_lock(void *opaque) err =3D -ENOENT; goto out_nofid; } + if (!fid_has_valid_file_handle(pdu->s, fidp)) { + err =3D -EBADF; + goto out; + } err =3D v9fs_co_fstat(pdu, fidp, &stbuf); if (err < 0) { goto out; @@ -3952,6 +3956,10 @@ static void coroutine_fn v9fs_getlock(void *opaque) err =3D -ENOENT; goto out_nofid; } + if (!fid_has_valid_file_handle(pdu->s, fidp)) { + err =3D -EBADF; + goto out; + } err =3D v9fs_co_fstat(pdu, fidp, &stbuf); if (err < 0) { goto out; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830336; cv=none; d=zohomail.com; s=zohoarc; b=cHU51Xd/sMj6QogHQHBsEKb7Fb+EXyXqWfkBqIgcdRm+kWd3Ara9pYrkxXRxBUos4qK/GQlcANM/3m6zBaWNcxGlsVMsm/nfJSliB9WwASSwu+GBA8sVnqX3cI79afHEmxV9Pd0pX77PkiErAfHFTSJcJ3SYjmzbaiqZumh7A5I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830336; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=SCjHbwuWaq07f3HRDllPsmYNazDn/ruG30LWz0CwrZk=; b=IgKjp990VtY3wYLEOwzJ0bvXhJWJaAWx+WVXA70IHd4VfxwToAtCO41HZZTIrx/fOuNkenEjJrBLLWOTcSC72KXBRNTgHJ0mmXu0AVdnLdA8b0MUCA4jfZiyT7JjevZgUmyMStHW9BxMa5zt4kZiW55rNLYJ7xrrfTqCqsbz3ws= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830336900660.2609726867076; Sat, 11 Jul 2026 21:25:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wileQ-0006Sc-3y; Sun, 12 Jul 2026 00:18:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileO-000661-4m; Sun, 12 Jul 2026 00:18:44 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileL-0006Wc-Ds; Sun, 12 Jul 2026 00:18:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 4F8641C0BF6; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 830183EB956; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 537E5133EF; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=b/nz2/ugZBvFSEZyMTBGl95mo19acreaKAdqUkQNV9c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=QznRPFNei/EY0T30YYDPtTfHpMdp1qQEXqX2SJgX7+vI6Rb5ClXNP2juQC2EGZAVa Wdg+g6ONMoEO4phX4wZEMcYOCPvMLUYO7WNmgCqntk87PxKFPO5OmguTih3C7iK8oe /vagO8fMKwrEWOpSLkXVXDqLFsrkBRisp3CASYiYv61jlL66fwVTLjmHqeyHZkrxO9 JPv/VeuAhFgdV9hVjig/jOK7bhxgRpz8Ddri4XlbgZWOVzJZP25Hh4fIUH/YWUc3up tRocug6M72xSqNdYtL77AONVIXQCp08lAj3Z+JZJ4lq+EE17NifjITPcotivVHzclI dl/SeITUr+xwQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.0.12 27/75] hw/9pfs/local: harden local_fid_fd() on FID types Date: Sun, 12 Jul 2026 07:14:45 +0300 Message-ID: <20260712041539.108341-27-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830338765158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck local_fid_fd() returns fs->fd for any FID type that is not P9_FID_DIR. Since P9_FID_XATTR and P9_FID_NONE share union V9fsFidOpenState, calling local_fid_fd() on these types misinterprets xattr state as a file descriptor, potentially leading to undefined behaviour or information disclosure. Even though we are catching these FID type mismatches on protocol level in 9p.c already, previous patches proofed this to be error prone. So let's add another safety layer in local_fid_fd() that would return -1 if the FID type would not possess a valid file descriptor, to prevent wrong file descriptors from reaching fs backend calls. Link: https://lore.kernel.org/qemu-devel/531f6b81bc1bf1a48c3d4afaa60a65db10= 511041.1781621428.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 75893c058b21d87d1ec66bbd4e8bf84e1fd616d1) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p-local.c b/hw/9pfs/9p-local.c index 7c07e237378..bf72a40a420 100644 --- a/hw/9pfs/9p-local.c +++ b/hw/9pfs/9p-local.c @@ -770,8 +770,11 @@ static int local_fid_fd(int fid_type, V9fsFidOpenState= *fs) { if (fid_type =3D=3D P9_FID_DIR) { return dirfd(fs->dir.stream); - } else { + } else if (fid_type =3D=3D P9_FID_FILE) { return fs->fd; + } else { + errno =3D EBADF; + return -1; } } =20 --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830264; cv=none; d=zohomail.com; s=zohoarc; b=Hpy2pL8zNq8Uo/2+BFlJOiHTYtvcD0AKLwcZ5Eqblo9KwlWsZOKc/pRI4SCSJfUf0C9KefQL0Bj8cCtLy1jkSzPoz8t3sRgMDDnY06QQzaP0l4Q8fQ2K/6hPpyAaS4bVzCCSujBqPW6zYhDkZb3b9hGkcLJkdZ4YlRGdbuabdZQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830264; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Te1F3qm95ZTIYZNCMxw9Frj5142TaPPAQ0lK6zgKL4E=; b=BqN+UMLdHPvkRpGJbjWGS6uofiu/JiR9HnhR5x01SqXkgw7znDlXrl0dhM9/BpRSTdR0pNmq+EghWIMwleFoYGQLs7BLRmQGjPRaDhglwIZIv+EFXHs0kYWG2v1jSRjhvCLiQew4JQspxefwAAuH5J8vF7yLqyOlTFJTwVgSw4w= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830264851484.7503280771749; Sat, 11 Jul 2026 21:24:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wileP-0006Qx-Tn; Sun, 12 Jul 2026 00:18:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileN-00063Q-V2; Sun, 12 Jul 2026 00:18:43 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileK-0006Zh-UB; Sun, 12 Jul 2026 00:18:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 54BF21C0BF7; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 88CBC3EB957; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 55C46133F1; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=7CkpURgUQObkG1LyBH77Mo2ekz62gASGNgmcwBX63Sc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=dCx1iqRjETY9J9FEuzCZx6DMrKsBo6tLzgxomGsrMYYnNwzGzM3mG15mylFqmwoZY w5QOAcmUlv8E0GLlzSzYb67tNL0z6ulcSJ1BKaO+QNCLTZp/Jd7BnGne5xX5Dzu8I5 hSM+KU7bs6Bu6Lbtw5v9Uqppg+k6p34m2RgY6EfO+mMSZa+CGHZzWQnDKeOAjgCVIY cHGxvp9ll5Dhqcq5R0ZMyJVewa3Ywxjm7F49qoCwcZdBmZJk3XAks/08eL4zZ6c4WG LMAUhkh7nv8kw72Lh3wlVd0pC37DrkQVs1blgh9/b3yIiG3uEwyOKXimNMz8P6kvix 98e0TF64CVxjw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Inochi Amaoto , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 28/75] target/riscv: Check PMP before updating PTE Date: Sun, 12 Jul 2026 07:14:46 +0300 Message-ID: <20260712041539.108341-28-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830266558158500 Content-Type: text/plain; charset="utf-8" From: Inochi Amaoto According to the RISC-V spec, the PTE update is a supervisor write operations, and it should also follow the CPU PMP configuration like the PTE read. Cc: qemu-stable@nongnu.org Signed-off-by: Inochi Amaoto Reviewed-by: Alistair Francis Message-ID: <20260622113402.563196-1-inochiama@gmail.com> Signed-off-by: Alistair Francis (cherry picked from commit fa2cf7488379d9b14041a7bcd76867c9bdad2b5e) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu_helper.c b/target/riscv/cpu_helper.c index 5e0d436c73a..0ac10835fed 100644 --- a/target/riscv/cpu_helper.c +++ b/target/riscv/cpu_helper.c @@ -1695,10 +1695,18 @@ static int get_physical_address(CPURISCVState *env,= hwaddr *physical, =20 /* Page table updates need to be atomic with MTTCG enabled */ if (updated_pte !=3D pte && !is_debug) { + int pmp_prot, pmp_ret; + if (!adue) { return TRANSLATE_FAIL; } =20 + pmp_ret =3D get_physical_address_pmp(env, &pmp_prot, pte_addr, + sxlen_bytes, MMU_DATA_STORE, PR= V_S); + if (pmp_ret !=3D TRANSLATE_SUCCESS) { + return TRANSLATE_PMP_FAIL; + } + /* * - if accessed or dirty bits need updating, and the PTE is * in RAM, then we do so atomically with a compare and swap. --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830198; cv=none; d=zohomail.com; s=zohoarc; b=KxtoHC4JFt6KZBBvzO0m6Rg5SYpLINFh579j06NBJy8hg8OpRmiX4izbkQRNLFlr8NVohTIAc51B4iA1LfUJvouanEYTX0CXWeepXmSYRFCK8/oq7PXNAEZc9KPL6B1OVICeGZc4Oelyfp4UHI7F4yU34HZyQJg57ooEJYBdo2M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830198; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=oLES8fufsN6LtmEarGIQdMmTlYqzSTZQay9DMtFNII0=; b=UIQeSZPHCtlBusGyw8nw+qcusAACAjIXnz40wB7wxxfwn4bEktoxs8fGAhdd8HfIUlxx6AGa1Gugbn5glnZTA6OeMXeWF59emFClo/xWdT9iXxh1YKBG0v/OHNRhwPGM9tVQEnqNjo/1YBmRVMSodBnA6+ZsJPmPPl0dlw79MJ0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17838301986591006.3103176120903; Sat, 11 Jul 2026 21:23:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wileR-0006d8-Vb; Sun, 12 Jul 2026 00:18:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileR-0006am-3Z; Sun, 12 Jul 2026 00:18:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileP-0006ag-Ft; Sun, 12 Jul 2026 00:18:46 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 5B3301C0BF8; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 8DF443EB958; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 58363133F3; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=+FR8wz4KKUliuwCuouh/wAFEggyzulrk6oUFPWA1z5w=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=MeaY17z36ehtBMB2KOKMd114h4J/9gSRsGvIzG4iOnVKX9NPkP2DoqJt2gh82yuy0 3tfhneN7p8V8bDSF5o0GBfEwUuzVHsnlrpDDexU+See4H2UNefhJKQGLbjpKCjzTfQ wdZfR6Q7EzBSeDwkNapAILojSFvVMLeaothIQl/+srasY5eUku4oTvsVJxsA8vvM4f lwNg96ii4NuoA4rJQ+z0o8+/vnCdJX8j2hod3t57LSjM8QmApZbXDY6GTxLkGbgzTl 1MxWSj31lQfIBKDUggbY8Y36BJ4p8kU06h+JqI+jrDJ66BuSmX9veTWge50fRS5A1V NrKAwpxOaLtcA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Qingwei Hu , Nutty Liu , Sunil V L , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 29/75] hw/riscv/virt-acpi-build: Fix RINTC PLIC context ID for KVM Date: Sun, 12 Jul 2026 07:14:47 +0300 Message-ID: <20260712041539.108341-29-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830200393158500 Content-Type: text/plain; charset="utf-8" From: Qingwei Hu Each RISC-V MADT RINTC entry contains an External Interrupt Controller ID field. On the virt machine without AIA, this field identifies the S-mode PLIC context associated with the hart. TCG virt has both M-mode and S-mode PLIC contexts, so the S-mode context ID is odd and 2 * local_cpu_id + 1 is correct. KVM virt exposes only S-mode PLIC contexts, and those contexts are numbered contiguously from 0. Reporting the TCG context ID for KVM makes the guest enable a different PLIC context from the one used by QEMU. With ACPI enabled, this can leave PCI INTx interrupts pending in QEMU while the guest-programmed PLIC context remains disabled. A virtio-blk root disk can then stall during boot because its first interrupt is never delivered. Use local_cpu_id for KVM and keep the existing odd S-mode context ID for TCG. Fixes: d641da6ed43 ("hw/riscv/virt-acpi-build.c: Add PLIC in MADT") Signed-off-by: Qingwei Hu Reviewed-by: Nutty Liu Reviewed-by: Sunil V L Message-ID: <20260604120017.398890-1-qingwei.hu@bytedance.com> Signed-off-by: Alistair Francis (cherry picked from commit fdfcd98f6656b0cf425475bd8ce7f4c08adf8ca6) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/virt-acpi-build.c b/hw/riscv/virt-acpi-build.c index e2b8229168d..b14c1c8e8c5 100644 --- a/hw/riscv/virt-acpi-build.c +++ b/hw/riscv/virt-acpi-build.c @@ -100,6 +100,8 @@ static void riscv_acpi_madt_add_rintc(uint32_t uid, build_append_int_noprefix(entry, ACPI_BUILD_INTC_ID( arch_ids->cpus[uid].props.node_id, + kvm_enabled() ? + local_cpu_id : 2 * local_cpu_id + 1), 4); } else { --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830298; cv=none; d=zohomail.com; s=zohoarc; b=Qz6XHP1u5YIKtMLXNS4Ck0rlpam+wreGCtyuwNFOCSdjg82/mNqIyR4wFomPG5qteYD3pq3SxHCVBgTwb6bI2QS+uKWLIIHDuBT/kWnVNLPj9XP1AXEEJyE5T7axBSaFY2gkKmBVOj/47VK/sePOU4EIxRCtLrgClUt6Kf77M+c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830298; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=w/fHU+grTnTUdfQMW5GGc10TAyoXRVRoxeaoS0pxcac=; b=g4ZjXwUIV7asGsrFhN6t8FxKtrYTIW+Q1QYCst6/MBCJWlNgAUNtt25m3XmsVCRdvyAUd1nRXX6P4JoE6doI6t9Or8dP6Nle8r6i8hU0MLYKZ//IVfvacG+3zWGbEJXCNDWXDAN8lylYxMT+fZggJ2es87TYlhy+U/aGhRr8IVU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830298953154.71926844812253; Sat, 11 Jul 2026 21:24:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wileS-0006fe-VU; Sun, 12 Jul 2026 00:18:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileR-0006bg-B4; Sun, 12 Jul 2026 00:18:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileP-0006an-KG; Sun, 12 Jul 2026 00:18:47 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 608BC1C0BF9; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 947F03EB959; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 5A854133F5; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=8tvbo7R8D3FJVz7Rst07ERGgZegYTk/poZ6DLCMFnQc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=L9NF39jUBZQl8AMzkJqy8atwHaZXabeQ0X1hVWV8uaLHtacHhSS4aC+R3GhAY4ny4 9/03KM6oBIQ59ilIZ6apwrVgVqtsSyWV4n5JuvP+7H/qudx5wtP7jBn9bdr1dAPlnt XejAkelp19eoaIDfpvqKiZqYqGsIl9vJDr9NakgmKdS1Z6nwbk9yeDIzq1yM6P8Jmi I4gd890klgiZBx4JaS5aDhdARnINxvW+FqP1oUIDdfXgxMMD86y6QxHYKTwWX3kGx+ 3XGoK6xkjXBx7XqyItMWX4uq5lZgn/vczInRSXCjOMzaczZdVwwHffxQYxuKveq3zz tNpb2OZ37kKqA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, ZhengXiang Qin , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 30/75] target/riscv: avoid abort when reading vtype before env->xl is set Date: Sun, 12 Jul 2026 07:14:48 +0300 Message-ID: <20260712041539.108341-30-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830300670158500 Content-Type: text/plain; charset="utf-8" From: ZhengXiang Qin TCG plugins may read registers from the vcpu_init_cb() callback. For vtype, this reaches read_vtype() before env->xl has been initialized. In that case read_vtype() currently hits g_assert_not_reached() because env->xl is zero. Fall back to the CPU's maximum XLEN only for this early-init case. Fixes: 638181a180bd ("core/cpu-common: initialise plugin state before threa= d creation") Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3545 Signed-off-by: ZhengXiang Qin Reviewed-by: Daniel Henrique Barboza Message-ID: Signed-off-by: Alistair Francis (cherry picked from commit 46d96da1309869af6261d1997623b7a5212814d8) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index a5c1143a7b4..607dd385d69 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -914,7 +914,16 @@ static RISCVException read_vtype(CPURISCVState *env, i= nt csrno, target_ulong *val) { uint64_t vill; - switch (env->xl) { + int xl =3D env->xl; + /* + * TCG plugins can read registers before env->xl is initialized. + * Fall back to the CPU's maximum XLEN in that early-init case. + */ + if (xl =3D=3D 0) { + xl =3D riscv_cpu_mxl(env); + } + + switch (xl) { case MXL_RV32: vill =3D (uint32_t)env->vill << 31; break; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830056; cv=none; d=zohomail.com; s=zohoarc; b=jJ4VFCnqCIN0k1WzrJrXagTUjt6Lgb3qlkhOwoL5p3Q/XhYb0KGmodMBslwOwC7SL8os7+Kr8zhvb2L/Wfpl1XxTelo294TA9Htm5FnFJeHeZefFakiM2vUR0YHr7BuGvLJ0mqLW7tlzjIBB9F3aSJTdRxMrJv9pgdlF7c7iyiI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830056; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=T4koy7FRp/g/pY1VXYyMFiUqHA7VUoKi0Dbm803ZvxM=; b=iq+kMuvTWTUgmOH57ODNwsqk3Zj/CyM5PdyMAZYEATS8V2NMflOrU/GbDk5KoAWaZmcB+BGXU48gSCPvuTVZVFMd1XMVY6YAIvUF9vkIhUGtqKX4opEnaxO/OdIocYTvHHREx2oMaoeo0R/2h+6oIxtAT2vr6CxuUqZ9V5FcocE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830056933342.19371880331335; Sat, 11 Jul 2026 21:20:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilep-0007PM-K9; Sun, 12 Jul 2026 00:19:11 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileo-0007Le-2t; Sun, 12 Jul 2026 00:19:10 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilem-0006bB-Hg; Sun, 12 Jul 2026 00:19:09 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 693081C0BFA; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 99E6A3EB95A; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 5CE7E133F7; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=EptcEFh39e78+w7OE7pe9PJs66bWeotQHn82eKcHa4A=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=KMrB6kyM1B/h0B+4jQ+994xUQbIKvI6t51gVtBW/XsOuDKatRONPoHMFRu06cUZJf vnCH30l/Ox0MaBnkxUzSBg32NOd7t6j+Xyu0Yx74VpeeSvB/wE5Z2SlKOHGRrTxO0e Ci5EPW+KWj8KqBa8gMQ5LquR1VMCI3n6g9J/5NotfaXk2uQ5mhkqCwCLjydnGU/sEw BOyFALQHvSjF+Jsoj0S+LmDbhznkAfcekslXA1xcOxq2FXAYmriW3uB8mt0CZaM6BD 1wmkienU2gK6tLXSmmS8Vbt0jGOD+ohP6Q9w8UHMhr6CitJFGvVAA+hcJzFk/cojl2 Yz/RqHMIi3ywg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, SeungJu Cheon , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 31/75] target/riscv: Apply UXL WARL handling to vsstatus Date: Sun, 12 Jul 2026 07:14:49 +0300 Message-ID: <20260712041539.108341-31-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830057959158500 Content-Type: text/plain; charset="utf-8" From: SeungJu Cheon write_mstatus() already handles the reserved UXL value by writing a legal value instead. Apply the same handling when writing vsstatus so that reserved UXL values follow the same WARL behavior. Factor the common logic into a local helper riscv_write_uxl() and use it for both mstatus and vsstatus. Suggested-by: Daniel Henrique Barboza Fixes: f310df58bd2 ("target/riscv: Enable uxl field write") Signed-off-by: SeungJu Cheon Reviewed-by: Daniel Henrique Barboza Message-ID: <20260625081521.595683-1-suunj1331@gmail.com> Signed-off-by: Alistair Francis (cherry picked from commit dcd028517749835a618bb1fe8dca32d82318e1c1) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 607dd385d69..c41f23c0f96 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -1978,6 +1978,20 @@ static target_ulong legalize_mpp(CPURISCVState *env,= target_ulong old_mpp, return val; } =20 +static uint64_t riscv_write_uxl(CPURISCVState *env, uint64_t val, + uint64_t field) +{ + RISCVMXL xl =3D riscv_cpu_mxl(env); + uint64_t uxl =3D get_field(val, field); + + if (uxl =3D=3D MXL_RV128) { + uxl =3D xl =3D=3D MXL_RV128 ? MXL_RV64 : xl; + val =3D set_field(val, field, uxl); + } + + return val; +} + static RISCVException write_mstatus(CPURISCVState *env, int csrno, target_ulong val) { @@ -2024,17 +2038,8 @@ static RISCVException write_mstatus(CPURISCVState *e= nv, int csrno, =20 if (xl !=3D MXL_RV32 || env->debugger) { if ((val & MSTATUS64_UXL) !=3D 0) { - uint64_t uxl =3D val & MSTATUS64_UXL >> 32; mask |=3D MSTATUS64_UXL; - - /* - * uxl =3D 3 is reserved so write the current xl instead. - * In case xl =3D MXL_RV128 (3) write MXL_RV64. - */ - if (uxl =3D=3D 3) { - uxl =3D xl =3D=3D MXL_RV128 ? MXL_RV64 : xl; - val =3D deposit64(val, 32, 2, uxl); - } + val =3D riscv_write_uxl(env, val, MSTATUS64_UXL); } } =20 @@ -5109,6 +5114,8 @@ static RISCVException write_vsstatus(CPURISCVState *e= nv, int csrno, uint64_t mask =3D (target_ulong)-1; if ((val & VSSTATUS64_UXL) =3D=3D 0) { mask &=3D ~VSSTATUS64_UXL; + } else { + val =3D riscv_write_uxl(env, val, VSSTATUS64_UXL); } if ((env->henvcfg & HENVCFG_DTE)) { if ((val & SSTATUS_SDT) !=3D 0) { --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830005; cv=none; d=zohomail.com; s=zohoarc; b=UCHJFyDDNvbHPVhk/eGlRLP9mlSxN8qOclYWItgCzncX2+xl4KV5Ww8qFyX70Qm+JBTx65fqdMS3vxlY51vXPV7HrifQK59fpYY71IzJk/eF/fpCO87b7auWV8/55bOSPE6l/KrNVWrx514YraKHlL4hX/L2aoIr9TP+T4aiqvI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830005; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=kUr5d/uVZlRWCwdt/eo73cSWv3saHwKcVRWaxtS7sZY=; b=O0CXh+m4dXdNlkgKi621yeHeXF94E45wWTW87lmJyKg562ymLpPI3wVba/eyAzeGnh+DdllFHutmjA1ZJhtj0jarzHtrvEtBvK8jozkuZ99V9s6trrOpUTKm+1UBCqK7lmO7+llNnOOiQfx7d8zNLJnz0DA8mAzeb4bGtPSve6Y= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830005753902.8526895360334; Sat, 11 Jul 2026 21:20:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiler-0007Sz-BZ; Sun, 12 Jul 2026 00:19:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileo-0007Nk-GM; Sun, 12 Jul 2026 00:19:10 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilem-0006bI-PB; Sun, 12 Jul 2026 00:19:10 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 6D7CC1C0BFB; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id A18023EB95B; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 5F3F2133F9; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=6YqqRM1vMduxP0+/2Szgo/xmolZQSzs95QGJi3t9Pmo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=CHpW1HUezz3yLYLON9waiZTWTwRpTlCWDyuLibxPIACYGk/LsCxZu99tqzfcINa3Q 9uKL2R524UtYsxmAmXKMsITO4VDNF1UwcXtQ87ZNqRVF38c+A5u/JsP198z5wZrxXU 63YADVyepfsYFSDjiRW8hOrYCeWEyfw+gq94/d1JCsJlHjY+XxcSw5474H9vK3f0yi 4/iTiQl+Z2xU8UCHlhV75CjOrWHMWOkLpNjyPJPzV48MH+veC3sIhueKMo93K+4+HZ 9AXx9EboD+iBZKr3M0zM9GTA73kSdZgBKv66tXRVl6lRKaQou0DojA3FK2i7DSypp6 Cp83z9IKFcVSg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Nutty Liu , Michael Tokarev Subject: [Stable-10.0.12 32/75] hw/riscv/riscv-iommu.c: always fault with SADE=0 and A=0 Date: Sun, 12 Jul 2026 07:14:50 +0300 Message-ID: <20260712041539.108341-32-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830007777158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza riscv-iommu spec: "If SADE is 1, the IOMMU updates A and D bits in first-stage PTEs atomically. If SADE is 0, the IOMMU causes a page-fault corresponding to the original access type if the A bit is 0 or if the memory access is a store and the D bit is 0.". Note that SADE=3D0 and A=3D0 will always cause a fault regardless of the original access type. Right now we're faulting in this case just for reads. Fixes: 0c54acb8243d ("hw/riscv: add RISC-V IOMMU base emulation") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3551 Signed-off-by: Daniel Henrique Barboza Acked-by: Alistair Francis Reviewed-by: Nutty Liu Message-ID: <20260630211044.82894-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 64ce9ac18757d79f3b5b337f7bcbdd0dabef3ce1) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index 91db1e1b464..d7ae03246fd 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -467,7 +467,7 @@ static int riscv_iommu_spa_fetch(RISCVIOMMUState *s, RI= SCVIOMMUContext *ctx, break; /* Read access check failed */ } else if ((iotlb->perm & IOMMU_WO) && !(pte & PTE_W)) { break; /* Write access check failed */ - } else if ((iotlb->perm & IOMMU_RO) && !ade && !(pte & PTE_A)) { + } else if (!ade && !(pte & PTE_A)) { break; /* Access bit not set */ } else if ((iotlb->perm & IOMMU_WO) && !ade && !(pte & PTE_D)) { break; /* Dirty bit not set */ --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830408; cv=none; d=zohomail.com; s=zohoarc; b=SkY/m7yaJjZfcWoa3Zc5DLjxNpO4aOaKAnH2Y+ZrJCGgowQApVE+Xm9BB+INUYCKFkPCkl/puWRjopoptqjzOyV85O/yo3UI8vTXRXw7Bk+sllUZjsVHINvVtDM9vxMaGyfLV7GAzox7nriv02HrsuUhhJbWw56nLkyqBMpd3Zw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830408; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=UV9Nnmr51SqlFnqJ/vgi5nBXtGhdpbe2Dzj9o3yyYNM=; b=TMO7j1cmM+s9peG3bP/7tD58+y7kKOoToukjfb3GQLZ/fFy4rsz5o/GTZFzvhHY/Jr++zqBqnUTCnnaDk8UpKUcuJHkfwTfw/87CpfmVn57jfZOp2UF5O2ICRlM77bNcbq7Y1usTP4eSkb7CgsAuGD1+TX1gncJ3zyRczhlCDZI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383040839321.71771257381306; Sat, 11 Jul 2026 21:26:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiles-0007Uo-KL; Sun, 12 Jul 2026 00:19:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wiler-0007TK-AR; Sun, 12 Jul 2026 00:19:13 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilep-0006eZ-IY; Sun, 12 Jul 2026 00:19:13 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 737A11C0BFC; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id A6DBC3EB95C; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 61935133FB; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=SYI3iUcKaL4s5MTd7299MvGnOPoQEPZa6++hzhNoVho=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=HMeUUSBZ9zRsFI/H60TmhQSIkOtjrdej3P/b7JIQq7f+2bhFLRkZt56Nkrw2mnIpv 7o7Nop05aYtgEKDrv8GcjuSApptgNuPqTT+UvALQK9zDDdTi87XdCEOZsHbEHTT/FV nN8QpnYX8lzM1xxgKoDvt0MzGVtSDkQAqHiAy87gOVV9/AI7rDTqlZWjFslo5kvOw+ goujc0oMYVCmAyUlzbSC9wK7mDfjGVHBq5NE4pc0uDIUo1lgKs5aaO47wHo+gPiHJJ fdAb4rbpbRkMXuvIxx5LbY1woFX3yv/A5PiXnbU+vwdTgvfgkJWG/AVIHNQS/7F0hY NXqj+mbwcqCkg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Laurent Vivier , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-10.0.12 33/75] hw/char/virtio-serial-bus: fix guest-triggerable OOM in control_out() Date: Sun, 12 Jul 2026 07:14:51 +0300 Message-ID: <20260712041539.108341-33-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830409046158500 Content-Type: text/plain; charset="utf-8" From: Laurent Vivier A malicious guest can craft virtqueue descriptors with arbitrary lengths. control_out() calls iov_size() on the guest-supplied scatter-gather list and passes the result directly to g_malloc(), allowing a guest to force QEMU to attempt multi-gigabyte allocations and crash the host process. Fix this by copying at most sizeof(struct virtio_console_control) into a stack-local variable instead of allocating a buffer sized by the guest. handle_control_message() only accesses the fixed-size id, event, and value fields, so no data beyond the struct was ever needed. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3585 Signed-off-by: Laurent Vivier Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-ID: <20260622161144.2883799-1-lvivier@redhat.com> (cherry picked from commit 36b37f8494800ed9c5d4b6ef03924bd1636cb810) Signed-off-by: Michael Tokarev diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c index b6d2743a9c6..0c180646c86 100644 --- a/hw/char/virtio-serial-bus.c +++ b/hw/char/virtio-serial-bus.c @@ -344,22 +344,16 @@ void virtio_serial_throttle_port(VirtIOSerialPort *po= rt, bool throttle) } =20 /* Guest wants to notify us of some event */ -static void handle_control_message(VirtIOSerial *vser, void *buf, size_t l= en) +static void handle_control_message(VirtIOSerial *vser, + struct virtio_console_control *gcpkt) { VirtIODevice *vdev =3D VIRTIO_DEVICE(vser); struct VirtIOSerialPort *port; VirtIOSerialPortClass *vsc; - struct virtio_console_control cpkt, *gcpkt; + struct virtio_console_control cpkt; uint8_t *buffer; size_t buffer_len; =20 - gcpkt =3D buf; - - if (len < sizeof(cpkt)) { - /* The guest sent an invalid control packet */ - return; - } - cpkt.event =3D virtio_lduw_p(vdev, &gcpkt->event); cpkt.value =3D virtio_lduw_p(vdev, &gcpkt->value); =20 @@ -457,41 +451,27 @@ static void control_in(VirtIODevice *vdev, VirtQueue = *vq) =20 static void control_out(VirtIODevice *vdev, VirtQueue *vq) { + struct virtio_console_control cpkt; VirtQueueElement *elem; VirtIOSerial *vser; - uint8_t *buf; size_t len; =20 vser =3D VIRTIO_SERIAL(vdev); =20 - len =3D 0; - buf =3D NULL; for (;;) { - size_t cur_len; - elem =3D virtqueue_pop(vq, sizeof(VirtQueueElement)); if (!elem) { break; } =20 - cur_len =3D iov_size(elem->out_sg, elem->out_num); - /* - * Allocate a new buf only if we didn't have one previously or - * if the size of the buf differs - */ - if (cur_len > len) { - g_free(buf); - - buf =3D g_malloc(cur_len); - len =3D cur_len; + len =3D iov_to_buf(elem->out_sg, elem->out_num, 0, &cpkt, sizeof(c= pkt)); + if (len =3D=3D sizeof(cpkt)) { + handle_control_message(vser, &cpkt); } - iov_to_buf(elem->out_sg, elem->out_num, 0, buf, cur_len); =20 - handle_control_message(vser, buf, cur_len); virtqueue_push(vq, elem, 0); g_free(elem); } - g_free(buf); virtio_notify(vdev, vq); } =20 --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830432; cv=none; d=zohomail.com; s=zohoarc; b=MPlNmk5Xt1xQ7U32cbzS8W0YcZt+7Zm0D+odZLI2GARJFuHFvGZA7Ze24Pk1N5SXRlj8pMpqHxW5k6U1MBU5p2dkndMgsp8huqEAvAEEO5eSugGlxIGB55Iq74GG1KHteP0RZ8Do8FjA1W50OqG+YQoH5O8bkcgf7Hmb4QuaHaE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830432; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VJkE+8I/xeWi4KILwjO9ltrW4Yahn30j95gWY/4AjuU=; b=ldOZoh+ZdZO+QydTuE3ivlfR380+8dvrLPeon/lx63T0CwlSxWcaLn6SIyih5SKD72a17yoiaDxGlVNAkVLKBjyMszQNM3LEjXmOrlA75AkJtvpcN3BU8KwMj0u8AKCKt4l0kD3UHJSWFKsah3n94EVEIa4KBthuGaawKjbPWZA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830432081915.3248429040289; Sat, 11 Jul 2026 21:27:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wileu-0007W7-8D; Sun, 12 Jul 2026 00:19:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wiler-0007Tz-O9; Sun, 12 Jul 2026 00:19:13 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilep-0006ei-V2; Sun, 12 Jul 2026 00:19:13 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 78F3C1C0BFD; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id AD0B03EB95D; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 63FEC133FD; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=QYHQ7G2YuETgliYXSQgUncOsag2yxaK68Try0VpqxXU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=UUelikT68/qWNzboY9V69NYkkzx1iEoG8e+OGNnFw0ueiLm/WOT0UyN1xDHPXE+Lu KTagu0K5EhLRebY0sKc+CEAbzhpxiAIwBBig5WNd7J/J6l2uLitXzK6GFA+DX7ipUx X2GEgbaZQTQgTbMzCV4MPzLV8pTVqfN5bcxWfCzV5RxxObuTtItZgoJU9AWIiOnYn9 hHblFlQfEua7imc8leUjQsIN1O3q3VGCWJ6lap3IS1mW23/BeNN3tpKg33drRfIGPN NPhZJGw988Lhu7oquw8D3rPi1fd7uJgMrd6vd4yGRNwXnhDDK6ldprkQMFtiqOkx7V V4EK5W7cEVauw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Junjie Cao , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-10.0.12 34/75] virtio-net: validate RSS indirections_len in post_load Date: Sun, 12 Jul 2026 07:14:52 +0300 Message-ID: <20260712041539.108341-34-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830433146158500 From: Junjie Cao virtio_net_handle_rss() enforces that indirections_len is a non-zero power of two no larger than VIRTIO_NET_RSS_MAX_TABLE_LEN, but virtio_net_rss_post_load() applies none of these checks to values restored from the migration stream. A corrupted save file or crafted migration stream can set indirections_len to 0. Even if it also clears redirect, virtio_load() calls set_features_nocheck() after the device vmstate (including the RSS subsection and its post_load) has already been loaded, re-deriving redirect from the negotiated guest features. When VIRTIO_NET_F_RSS was negotiated, redirect is set back to true regardless of the migration stream value. The receive path then computes hash & (indirections_len - 1) /* wraps to 0xFFFFFFFF via int promotio= n */ and uses the result to index into indirections_table, which was not allocated by the VMState loader when the element count is zero (see vmstate_handle_alloc()), resulting in a NULL pointer dereference that crashes QEMU: #0 virtio_net_process_rss ../hw/net/virtio-net.c:1901 #1 virtio_net_receive_rcu ../hw/net/virtio-net.c:1921 #2 virtio_net_do_receive ../hw/net/virtio-net.c:2061 #3 nc_sendv_compat ../net/net.c:823 #4 qemu_deliver_packet_iov ../net/net.c:870 The RSS subsection is only loaded when rss_data.enabled is true (via virtio_net_rss_needed()), and the command path always produces indirections_len in {1, 2, 4, =E2=80=A6, 128}, so an unconditional check cannot reject a legitimate migration stream. Factor the validation into virtio_net_rss_indirections_len_valid() and call it from both virtio_net_handle_rss() and virtio_net_rss_post_load(). Fixes: e41b711485e5 ("virtio-net: add migration support for RSS and hash re= port") Cc: qemu-stable@nongnu.org Signed-off-by: Junjie Cao Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-ID: <20260324060100.1997-1-junjie.cao@intel.com> (cherry picked from commit 32a90850e1e4222091df07b4b46d5f46a8b90d24) (Mjt: backport to 10.0.x series, introducing small parts of commit v10.0.0-2242-g7b6e7e4990 "virtio-net: Retrieve peer hashing capability" which added virtio_net_rss_post_load() method to vmstate_virtio_net_rss) Signed-off-by: Michael Tokarev diff --git a/hw/net/virtio-net.c b/hw/net/virtio-net.c index 8a0ea4cff58..c04626dd3bf 100644 --- a/hw/net/virtio-net.c +++ b/hw/net/virtio-net.c @@ -1380,6 +1380,11 @@ static void virtio_net_unload_ebpf(VirtIONet *n) ebpf_rss_unload(&n->ebpf_rss); } =20 +static bool virtio_net_rss_indirections_len_valid(uint16_t len) +{ + return is_power_of_2(len) && len <=3D VIRTIO_NET_RSS_MAX_TABLE_LEN; +} + static uint16_t virtio_net_handle_rss(VirtIONet *n, struct iovec *iov, unsigned int iov_cnt, @@ -1417,14 +1422,9 @@ static uint16_t virtio_net_handle_rss(VirtIONet *n, if (!do_rss) { n->rss_data.indirections_len =3D 0; } - if (n->rss_data.indirections_len >=3D VIRTIO_NET_RSS_MAX_TABLE_LEN) { - err_msg =3D "Too large indirection table"; - err_value =3D n->rss_data.indirections_len; - goto error; - } n->rss_data.indirections_len++; - if (!is_power_of_2(n->rss_data.indirections_len)) { - err_msg =3D "Invalid size of indirection table"; + if (!virtio_net_rss_indirections_len_valid(n->rss_data.indirections_le= n)) { + err_msg =3D "Invalid indirection table length"; err_value =3D n->rss_data.indirections_len; goto error; } @@ -3311,6 +3311,20 @@ static const VMStateDescription vmstate_virtio_net_h= as_vnet =3D { }, }; =20 +static int virtio_net_rss_post_load(void *opaque, int version_id) +{ + VirtIONet *n =3D VIRTIO_NET(opaque); + + if (!virtio_net_rss_indirections_len_valid(n->rss_data.indirections_le= n)) { + error_report("virtio-net: saved image has invalid RSS " + "indirections_len: %u", + n->rss_data.indirections_len); + return -EINVAL; + } + + return 0; +} + static bool virtio_net_rss_needed(void *opaque) { return VIRTIO_NET(opaque)->rss_data.enabled; @@ -3320,6 +3334,7 @@ static const VMStateDescription vmstate_virtio_net_rs= s =3D { .name =3D "virtio-net-device/rss", .version_id =3D 1, .minimum_version_id =3D 1, + .post_load =3D virtio_net_rss_post_load, .needed =3D virtio_net_rss_needed, .fields =3D (const VMStateField[]) { VMSTATE_BOOL(rss_data.enabled, VirtIONet), --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830092; cv=none; d=zohomail.com; s=zohoarc; b=Bix/fTn6VkQzSua41quzgD+fgSvQc8b9jo8QywbOr38KAZURdPoVCrO71vWrtzfTsq+azdaVeeuQKdDU6npFSN3qbp5GVAIVOi+7NPiHV3osMEWd6S+hJcOhwfOxdGyyZ2eRtRPeEjIdZrsJfMlvxHhEToJcrhEn17n9Oob4sMg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830092; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=7+tyFv9T4IqmGj6hPeM6gEKElqP6qywiBvBR7SR5cZM=; b=U2qHnrWCXRluz4vG5qpPmegXrIOjwSBiKPPJtplUFpurMghJ5595fSo//DrFRmLQ5/X5K3E7e4RZkj0Psz4QIOZzkT8V4bcfWD7ZVqdZ62GssU3xrnvGaZmSeDsBDj4XHdf9PUjkOTykDPvPxG1x21k4APq/YTUpmeAgPlWRvGQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830092948305.2998434979943; Sat, 11 Jul 2026 21:21:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilew-0007Wc-2S; Sun, 12 Jul 2026 00:19:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wileu-0007WF-HW; Sun, 12 Jul 2026 00:19:16 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wiles-0006f7-Pk; Sun, 12 Jul 2026 00:19:16 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 7F1431C0BFE; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id B29C63EB95E; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 66612133FF; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=ecttReK+P46PyGJqyXiC1PlVTFgf1qDWXVT0lWQTRRc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=JhGJrshZICZg8AqPyscgDgw49DyQXLT9VUoJbX0SolJrrtrbx7qm2anS3Gx4mnZcl Oczg8TKywSKZFeNbz/NjuQtl3hL3SF/qNepuXuTJbDu/1RSxcXdlpCaHOCi+Rhqfu1 nowNjKh4m7JL+epu23BY57u3GyxhqhcbHioptL26vkMTzHWYq0CZ/Fy8ZKpqGRwuTC aDyc42sXY3/fmPaiuNdIrEs9fKL0N3yOeq6q9w59VBbCCDbi9hf+y95PgetWBPi0jj IGt4tPCUA4oG23T7YGp1MJdlblt3y0OsGOTokDm994r0V0yitIoJyiJNdya9llo5Nq 7y1MF+Ek6qVZw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Feifan Qian , Peter Maydell , Michael Tokarev Subject: [Stable-10.0.12 35/75] hw/net/fsl_etsec: validate FCB offsets in process_tx_fcb() Date: Sun, 12 Jul 2026 07:14:53 +0300 Message-ID: <20260712041539.108341-35-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830094040158500 Content-Type: text/plain; charset="utf-8" From: Feifan Qian The TX Frame Control Block (FCB) is prepended to a TX frame when BD_TX_TOEUN is set. It contains two guest-controlled u8 offset fields that process_tx_fcb() uses to locate L3/L4 headers within the frame buffer: l3_header_offset =3D FCB byte 3 (0..255) l4_header_offset =3D FCB byte 2 (0..255) These offsets are applied without any bounds check. When the UDP-no-CTU branch is taken, the function writes zero to l4_header[6] and l4_header[7]. With both offsets set to 0xFF the write target is: tx_buffer + 8 + 255 + 255 + 6/7 =3D tx_buffer + 525 A malicious guest can therefore corrupt up to 509 bytes of heap memory beyond a minimally-sized (16 B) TX frame. Fix: reject the frame and log a guest error when the minimum required buffer length 8 (FCB) + l3_header_offset + l4_header_offset + 8 exceeds tx_buffer_len. Move the l3_header and l4_header pointer declarations past the new guard so that out-of-bounds pointers are never materialised. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3517 Signed-off-by: Feifan Qian Reviewed-by: Peter Maydell Signed-off-by: Peter Maydell (cherry picked from commit bc22c7e4187a619bf9ff7776288b588322e9ee41) Signed-off-by: Michael Tokarev diff --git a/hw/net/fsl_etsec/rings.c b/hw/net/fsl_etsec/rings.c index 42216de6c9a..7dd364364ea 100644 --- a/hw/net/fsl_etsec/rings.c +++ b/hw/net/fsl_etsec/rings.c @@ -175,15 +175,30 @@ static void tx_padding_and_crc(eTSEC *etsec, uint32_t= min_frame_len) static void process_tx_fcb(eTSEC *etsec) { uint8_t flags =3D (uint8_t)(*etsec->tx_buffer); - /* L3 header offset from start of frame */ + /* L3 header offset from start of frame (FCB byte 3) */ uint8_t l3_header_offset =3D (uint8_t)*(etsec->tx_buffer + 3); - /* L4 header offset from start of L3 header */ + /* L4 header offset from start of L3 header (FCB byte 2) */ uint8_t l4_header_offset =3D (uint8_t)*(etsec->tx_buffer + 2); + uint8_t *l3_header; + uint8_t *l4_header; + int csum =3D 0; + + /* + * Validate FCB header offsets before pointer arithmetic. The highest + * byte accessed is l4_header[7], at offset + * 8 (FCB size) + l3_header_offset + l4_header_offset + 7 + * from tx_buffer. Drop the frame if this exceeds the buffer length. + */ + if (etsec->tx_buffer_len < 8u + l3_header_offset + l4_header_offset + = 8u) { + qemu_log_mask(LOG_GUEST_ERROR, + "eTSEC: FCB offsets exceed frame length, dropping\n"= ); + return; + } + /* L3 header */ - uint8_t *l3_header =3D etsec->tx_buffer + 8 + l3_header_offset; + l3_header =3D etsec->tx_buffer + 8 + l3_header_offset; /* L4 header */ - uint8_t *l4_header =3D l3_header + l4_header_offset; - int csum =3D 0; + l4_header =3D l3_header + l4_header_offset; =20 /* if packet is IP4 and IP checksum is requested */ if (flags & FCB_TX_IP && flags & FCB_TX_CIP) { --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830109; cv=none; d=zohomail.com; s=zohoarc; b=iL2CDRLHKbiK3xTGuQ2eEHsLuZDGC4ClWca+AL+3FGArywtLWCXVQ3Bwj4+etEGwmipMeTgG5MQkW9jgnl1h6SKaY6SGK8qyJ1exfheNX1SsxQmM6xBVgi0onaxDLxGhaAM2/yZoN+G7pRqJS7Zo0LczoKoQxWipekGZzJYRNE8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830109; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ViJkb1Hc1TPIbTSZ7vj4lwT8OXAZPvK/qVP9qeir8BQ=; b=Zg5dO2ZpL855ff7oBJnLza71RDj12Mgl+9ngu5U/iS5Em65vBybs79KWxKIHEoZ9GQs4wynHo5blmHHhfgSwZl1UKkuF2vWJgTHbrqw9no48fZtLoRwfHkkwJkx0BZzVeZhIxPA24vwpCIFerXxBBzhmW0M+qlKK7a/yYg9jPu0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830109383519.6562281751259; Sat, 11 Jul 2026 21:21:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilfG-0007jr-IT; Sun, 12 Jul 2026 00:19:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfE-0007jJ-UR; Sun, 12 Jul 2026 00:19:37 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfD-0006fJ-73; Sun, 12 Jul 2026 00:19:36 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 844E41C0BFF; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id B84843EB95F; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 68DE513401; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=rwHB9Wx6/k3yBTD97O4Rs3DdBFw05JDK0wI7ZDLgj9E=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=LCHrnpXXdgT6Bnmuqc9pPUTyncaBxWgrJCvHPNc9dtpvHEPiZSSemwTgklo15pakW dNVDX0xN47a2/ty6QRjDCjAZNhISbqf3P8ljrqCW8vkhl7efK2MIYvI5yu3idW9w2i hvGAMYfraSF469AxDgmzUR69sQPqmjEHUfAYtYjRpmMpDW4UG6m/bn8t96UccaEpQ/ tmAYTcmMpWR0RvUugYUqb1O08HTru+2eKqjkvzSd018Q3H7+SYoc2ab9AZWxe0lMSl eM2+8R2CeMWX96GnHcQEnfrWg1k5R2k73NbGL/Zz1+gejjloprBUcfCmFHCCmp5p9v WHHagqKDZG/YQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Alex=20Benn=C3=A9e?= , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Arnd Bergmann , Michael Tokarev Subject: [Stable-10.0.12 36/75] hw/arm: use cortex-a9 mpcore base for CBAR on npcm7xx machines Date: Sun, 12 Jul 2026 07:14:54 +0300 Message-ID: <20260712041539.108341-36-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830110136158500 From: Alex Benn=C3=A9e CBAR is an IMPDEF register and according to the A9 TRM [1]: In Cortex-A9 MPCore implementations, the base address is reset to PERIPHBASE[31:13] so that software can determine the location of the private memory region [2]. If it doesn't we will confuse the Linux kernel as it probes the system SCU registers [3] and erroneously assumes the system is a buggy Aegis SOC and nerf the emission of SEV instructions, deadlocking any WFE's in the kernel (or QEMU smpboot code). [1] https://developer.arm.com/documentation/ddi0388/i/system-control/regist= er-descriptions/configuration-base-address-register [2] https://developer.arm.com/documentation/ddi0407/g/Introduction/Private-= Memory-Region [3] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree= /arch/arm/kernel/head.S?h=3Dv7.1#n550 Fixes: 2d8f048c25ab ("hw/arm: Add NPCM730 and NPCM750 SoC models") Cc: qemu-stable@nongnu.org Signed-off-by: Alex Benn=C3=A9e Reviewed-by: Peter Maydell Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-id: 20260624103049.884930-2-alex.bennee@linaro.org Suggested-by: Arnd Bergmann Reviewed-by: Peter Maydell Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Peter Maydell (cherry picked from commit 62b425bec3d52a326781025d1c51eb4d65ece49e) Signed-off-by: Michael Tokarev diff --git a/hw/arm/npcm7xx.c b/hw/arm/npcm7xx.c index 2d6e08b72ba..92767209d56 100644 --- a/hw/arm/npcm7xx.c +++ b/hw/arm/npcm7xx.c @@ -492,7 +492,7 @@ static void npcm7xx_realize(DeviceState *dev, Error **e= rrp) /* CPUs */ for (i =3D 0; i < nc->num_cpus; i++) { object_property_set_int(OBJECT(&s->cpu[i]), "reset-cbar", - NPCM7XX_GIC_CPU_IF_ADDR, &error_abort); + NPCM7XX_CPUP_BA, &error_abort); object_property_set_bool(OBJECT(&s->cpu[i]), "reset-hivecs", true, &error_abort); =20 --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830100; cv=none; d=zohomail.com; s=zohoarc; b=mpQcYA+jbqYL+4a+QmuFQr7KqsGPZfft7Oo5C/j8FB4fDFoAU2GejC9CUlMkAAxsObGrspNQerYn5XfYpZL2+o55bkEBMU7ErSwkNy9Rkx89i/hfUYs9mPlW5sX4FCmO1Q20HIpfieAUSDnwAJI5X+Od2Sq+fTTI8cFKsNvmEGE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830100; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=NJ2i5qWRtz/nGEoMFi/KY1V4eQ70/8rJLd1FQXrEl8w=; b=O+jKlqTXYHOr3ICyNzuEObqHLG97s2JrOUmz2xSxcS4dPZ5w61vtrrUMsRTMUgK7i/fxrludUCbsV2+NkG/Bnj1sJOa2sqBfx8FulbvglTGYNbh3FJ7SR2+Btwl7nYqPl9ZXogBWa5fcet5xbm6L42HEmsborJrPoTC5jFGJlOg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830100779836.0078199670229; Sat, 11 Jul 2026 21:21:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilfY-0007oJ-0i; Sun, 12 Jul 2026 00:19:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfH-0007kA-Rp; Sun, 12 Jul 2026 00:19:42 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfG-0006fc-0t; Sun, 12 Jul 2026 00:19:39 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 8A0D01C0C00; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id BDA8E3EB960; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 6B5CD13403; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=rTbqI+rqzA3GF2F4gQQ3jRLOngJrG9OCYTzCL0FpM2U=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ENH72WOmFyzmIfuNU779s6FQ6umbnFo3HoUt4ZmoiOwXm4pT2md8GYWym5Jtob617 p8Pan81WE3ssXn9uPSeWNKwkzOje63x7Pr01X0eBurvdTDw14wDSLZaNDXKiSFA4Vg 2SaMhm3ZobdEWeItD1t2BYFj+U8XX3Iwnd9lX+gLVdo0BE+Ic++wv0ywHvGyNQPJ9G JkquVFDnZ0yshg5rhGx/bquv/D1MTl4dTQagxEEAjgOwAmWKsJarWVTZqMpRVzwgu4 qTeSrj0tr10sQwIcUHlr9K7l3z2d3+hoKEgmpt3Bitk5h5eBlAm29af0YrMfhNe4SO ZfLKQU78vhl6A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Jesper Wendel Devantier , jaeyeong , Jesper Wendel Devantier , Klaus Jensen , Michael Tokarev Subject: [Stable-10.0.12 37/75] hw/nvme: fix FDP set FDP events Date: Sun, 12 Jul 2026 07:14:55 +0300 Message-ID: <20260712041539.108341-37-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830102382158500 Content-Type: text/plain; charset="utf-8" From: Jesper Wendel Devantier Addresses an issue reported whereby user-provided event type values could trigger two issues: 1. if provided event_type =3D=3D 0xff -> out-of-bounds access 2. if provided event_type > 7 -> generate a value too large for the u8 event mask. This patch fixes (1) by correctly adjusting the length of the look-up array to be 256 values. This patch fixes (2) by: a. changing the event_type mask to 64bit, matching NvmeRuHandle.event_filter b. Matching the behavior of Get Feature - FDP Events by skipping event type values which we do not support. 5.2.26.1.21 of the 2.3 Base specification does not explicitly tell us to reject unsupported event type values. c. Documenting in the event type lookup table, that supporting event types greater than 63 requires refactoring the masking code. Cc: qemu-stable@nongnu.org Reported-by: jaeyeong Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3631 Signed-off-by: Jesper Wendel Devantier Reviewed-by: Klaus Jensen Signed-off-by: Klaus Jensen (cherry picked from commit ec917cd49918b6135546b4f6c02658a1913e3d7c) Signed-off-by: Michael Tokarev diff --git a/hw/nvme/ctrl.c b/hw/nvme/ctrl.c index 27ade1c14f8..559d1c5d6c7 100644 --- a/hw/nvme/ctrl.c +++ b/hw/nvme/ctrl.c @@ -6240,10 +6240,6 @@ static uint16_t nvme_get_feature_fdp_events(NvmeCtrl= *n, NvmeNamespace *ns, for (uint8_t event_type =3D 0; event_type < FDP_EVT_MAX; event_type++)= { uint8_t shift =3D nvme_fdp_evf_shifts[event_type]; if (!shift && event_type) { - /* - * only first entry (event_type =3D=3D 0) has a shift value of= 0 - * other entries are simply unpopulated. - */ continue; } =20 @@ -6488,9 +6484,9 @@ static uint16_t nvme_set_feature_fdp_events(NvmeCtrl = *n, NvmeNamespace *ns, uint8_t noet =3D (cdw11 >> 16) & 0xff; uint16_t ret, ruhid; uint8_t enable =3D le32_to_cpu(cmd->cdw12) & 0x1; - uint8_t event_mask =3D 0; + uint64_t event_mask =3D 0; unsigned int i; - g_autofree uint8_t *events =3D g_malloc0(noet); + g_autofree uint8_t *events =3D NULL; NvmeRuHandle *ruh =3D NULL; =20 assert(ns); @@ -6503,15 +6499,29 @@ static uint16_t nvme_set_feature_fdp_events(NvmeCtr= l *n, NvmeNamespace *ns, return NVME_INVALID_FIELD | NVME_DNR; } =20 + if (unlikely(noet =3D=3D 0)) { + return NVME_SUCCESS; + } + ruhid =3D ns->fdp.phs[ph]; ruh =3D &n->subsys->endgrp.fdp.ruhs[ruhid]; =20 + events =3D g_malloc0(noet); + ret =3D nvme_h2c(n, events, noet, req); if (ret) { return ret; } =20 for (i =3D 0; i < noet; i++) { + /* + * We ignore requests to enable tracking of unsupported FDP event = types + */ + uint8_t event_type =3D events[i]; + uint8_t shift =3D nvme_fdp_evf_shifts[event_type]; + if (!shift && event_type) { + continue; + } event_mask |=3D (1 << nvme_fdp_evf_shifts[events[i]]); } =20 diff --git a/hw/nvme/nvme.h b/hw/nvme/nvme.h index 4bd64ae718b..bb0d369c28e 100644 --- a/hw/nvme/nvme.h +++ b/hw/nvme/nvme.h @@ -160,7 +160,14 @@ typedef struct NvmeZone { #define NVME_FDP_MAX_NS_RUHS 32u #define FDPVSS 0 =20 -static const uint8_t nvme_fdp_evf_shifts[FDP_EVT_MAX] =3D { +/* + * NOTE: Apart from event type 0, any event type with a shift value of 0 is + * considered unsupported and thus skipped in get/set features calls. + * + * NOTE: NvmeRuHandle uses a 64bit event mask - refactor to support event = types + * of 63 or greater. + */ +static const uint8_t nvme_fdp_evf_shifts[FDP_EVT_MAX + 1] =3D { /* Host events */ [FDP_EVT_RU_NOT_FULLY_WRITTEN] =3D 0, [FDP_EVT_RU_ATL_EXCEEDED] =3D 1, --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830460; cv=none; d=zohomail.com; s=zohoarc; b=i+MSVXNs8Df+ayfD3DHZ+EowxJppZN1rRsjkvu3lgagX+VI5ibCvZiKzqB7RQ4a5CYV3b6idUxEng9GSykUEdYxELXHJtfsCrO3ZdsdDS8toHumC9c5X8Ig97i6CRBTcLhubXMhGYwVxasCtVxhgjUauClBQ2++gU4SKdGqLVyc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830460; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ZPSpQ4DI2G2hJ0+7MKuiQeG1AuSjpJ7xvGlD3jHCJ6E=; b=C9Ektvk2FHsNlLACq8QS4iBRmtomQAqYlKV72TCyEHL5EzgQCsicM7yNFxX3+Vyb3iajgemZe9NnMHs+/vhWkljxlDQmQZJYfj9b3f0vDJu1Xqr4ip/1nJ8zpgJVeX1IJQ4Ru0APClNakehuunlfIXjYSHli0MQ8XI9inSzBvNg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830460297951.0369340858041; Sat, 11 Jul 2026 21:27:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilfa-0007uX-J5; Sun, 12 Jul 2026 00:19:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfH-0007kB-SM; Sun, 12 Jul 2026 00:19:42 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfG-0006kK-Br; Sun, 12 Jul 2026 00:19:39 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 904DC1C0C01; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id C2E2F3EB961; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 6DD0513405; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=Tu4H6AL24DwgGEbdDrKHT1Zb5tAk0N4S6Vikx02tcNw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=nPaCCDk/TXrJ6/2Qxn8nduXkCsUeW4+yJH9bPK1hH/k3/DCBIOcp65E5ZxWWSnWXb jFQTPghYXd43SdDu+6nUd4Jec+c2qNBMxgilR6IBzMbqu0V6c6MqqG1f/nQZfcER49 k0TiNqLPVIHLJwExP3i2yN36T4JbOFgI1yyKnoUjSXcRD6ou+DhLiM1zQ/BJatC3D7 e3J6kf2DZfgr2zMPC7DhXciZYYTCV5OXZkLDeVS+uxStdtlLKQMN0wG54NuJw3T1U5 +8I4IEK9UUhQgcO3mTUY8QkkslWAvbu3ILkNJrSi07dM1NcFKFFbqDhQy0RWJ98l/R Mw1gOdlr6xY1Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Keith Busch , Feifan Qian , boy juju , Klaus Jensen , Michael Tokarev Subject: [Stable-10.0.12 38/75] hw/nvme: ensure sgl forward progress Date: Sun, 12 Jul 2026 07:14:56 +0300 Message-ID: <20260712041539.108341-38-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830461225158500 Content-Type: text/plain; charset="utf-8" From: Keith Busch A degenerate host can create segment loops of zero-byte data descriptors that the controller never breaks out of. While the spec allows zero length segments, it provides no guidance on handling loops. It makes no sense for a host to submit such a descriptor anyway since it can and trivially should point to the next transfer segment, so don't even try to work with such behavior. Just reject the command, terminating the loop. Cc: qemu-stable@nongnu.org Reported-by: Feifan Qian Reported-by: boy juju Signed-off-by: Keith Busch Reviewed-by: Klaus Jensen Signed-off-by: Klaus Jensen (cherry picked from commit 034baf047fe143c2713f35fa640407d9da2f6fc3) Signed-off-by: Michael Tokarev diff --git a/hw/nvme/ctrl.c b/hw/nvme/ctrl.c index 559d1c5d6c7..a43407e37cd 100644 --- a/hw/nvme/ctrl.c +++ b/hw/nvme/ctrl.c @@ -1085,6 +1085,8 @@ static uint16_t nvme_map_sgl(NvmeCtrl *n, NvmeSg *sg,= NvmeSglDescriptor sgl, } =20 for (;;) { + size_t prev_len =3D len; + switch (NVME_SGL_TYPE(sgld->type)) { case NVME_SGL_DESCR_TYPE_SEGMENT: case NVME_SGL_DESCR_TYPE_LAST_SEGMENT: @@ -1165,6 +1167,17 @@ static uint16_t nvme_map_sgl(NvmeCtrl *n, NvmeSg *sg= , NvmeSglDescriptor sgl, if (status) { goto unmap; } + + /* + * Reject if this segment made no forward progress. The host should + * have skipped linking an empty segment. While not strictly spec + * compliant, allowing this makes it easy for a pathological host = to + * create an infinite loop. + */ + if (len =3D=3D prev_len) { + status =3D NVME_INVALID_SGL_SEG_DESCR | NVME_DNR; + goto unmap; + } } =20 out: --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830067; cv=none; d=zohomail.com; s=zohoarc; b=XduJJSm+NSUQIBhH4SYSxwQ+79hyGLsocbAYelzcPzUOqa//fHx9O/HfavUIPdzzv1MkvLzqivM6lGfbafiy6iZlZwHgTHaTwcJY3+wm28FduxwxzVNhgTaSjMyb3Exd3GfBE/7Zx6vo7i5L29X7VLGo5E8GVUFeRgywRoOLDBg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830067; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8jwPBhBwhzSUwHynGEZjdqGKTJVHLsWi1iOGy9tsbbY=; b=QmAKLqhFE81RU7a3jh0JCo6Y2a147i7/3X/P4sKZHxE0JsenBhn3J+yrxNLMajnH2ssryp+mDdLr49Ja3+BY0Ts9EKT7YHkdxuSmnsgvuKi3RUmmgr2pPrIIZ/PATddMYqOh5MpIIYUcv6I1GrrQRy2uRVf30Av7hbIxxmZQ5RU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830067112694.3354962416317; Sat, 11 Jul 2026 21:21:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilfY-0007of-3W; Sun, 12 Jul 2026 00:19:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfL-0007kL-1e; Sun, 12 Jul 2026 00:19:44 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfJ-0006kj-9j; Sun, 12 Jul 2026 00:19:42 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9538C1C0C02; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id C82643EB962; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 704E913407; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=mFsIrytqWquiBVni1uJmX1hOaQaKDbrkSNEfcG/ULyY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=SpJlrokgL9i1Y6ehIb2dus5NxrNs2GIwAsCfubzaYUo0fFFFMlZdbOUmw2FJVT+UY 1Fxll7VGjxZhOXCiAoudOA/yOmydaKejzTuOAhYvAFpA9rbgSq0ssddxYMnM6Gv13F 8002sAB60tO2MnApEwXoI2rSwaqVnwUx7lPUJ1EnTFBzqZPFHybX6x3WpqwDq1XWxb bL1wVKrgC2IXBFksYEiFfMdy1kKgSePXlXfHXr61d0n7J46PTU/Uxnoj9q9iv3Ipls Nl0dRIECLwiCcNDu0MFL2Gx5wJt0R1K9I+fr0Euj0mPNSr8VMZq6bbdDZQ6xHhi5zp rFnDRUvOq/5Gg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Borntraeger , Hendrik Brueckner , Matthew Rosato , Eric Farman , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Cornelia Huck , Michael Tokarev Subject: [Stable-10.0.12 39/75] s390x/sclp: reject invalid write event data headers Date: Sun, 12 Jul 2026 07:14:57 +0300 Message-ID: <20260712041539.108341-39-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830067965158500 From: Christian Borntraeger If a guest submits an sccb with a tiny header length but a large number of event mask entries, the write_event_mask handler will 1. return the wrong RC (ok instead of error) 2. write to memory after the allocated sccb in qemu host memory. Add the necessary checks. Cc: qemu-stable@nongnu.org Reviewed-by: Hendrik Brueckner Reviewed-by: Matthew Rosato Reviewed-by: Eric Farman Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Christian Borntraeger Message-ID: <20260707070728.147203-2-borntraeger@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit d88cd8f5570f4d6e08d62e098a8b7f53cdc75536) Signed-off-by: Michael Tokarev diff --git a/hw/s390x/event-facility.c b/hw/s390x/event-facility.c index 2b0332c20e2..18361a3bf45 100644 --- a/hw/s390x/event-facility.c +++ b/hw/s390x/event-facility.c @@ -291,6 +291,7 @@ static void read_event_data(SCLPEventFacility *ef, SCCB= *sccb) static void write_event_mask(SCLPEventFacility *ef, SCCB *sccb) { WriteEventMask *we_mask =3D (WriteEventMask *) sccb; + uint16_t sccb_length =3D be16_to_cpu(sccb->h.length); uint16_t mask_length =3D be16_to_cpu(we_mask->mask_length); sccb_mask_t tmp_mask; =20 @@ -300,6 +301,11 @@ static void write_event_mask(SCLPEventFacility *ef, SC= CB *sccb) return; } =20 + if (sccb_length < sizeof(WriteEventMask) + 4 * mask_length) { + sccb->h.response_code =3D cpu_to_be16(SCLP_RC_INSUFFICIENT_SCCB_LE= NGTH); + return; + } + /* * Note: We currently only support masks up to 8 byte length; * the remainder is filled up with zeroes. Older Linux --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830267; cv=none; d=zohomail.com; s=zohoarc; b=bieGiMSOZjCK3wH5602RB+BS4KqUibI5vnslpOLwzlaTvnwXjvbobCP4Tfu2RUOROFN2XwURoAdMeZHPeWwQtnUM2ucY0EhwKdViQ9zUTxd2DI9vI3iCrudhZ09efMH/XV/7y0CYWQ8Lht+34KSuo5WGCZS7tho5KSELYm6K6jA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830267; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fPHS/S8xZ+QcWFkt/v1+eomzCFwG8fL4qVkidjuCB4s=; b=ZKFgUd4bvv3zuvR5swJtER/PVvGNiZ1EIAQEKVD4xzsijXvjYtF+tB17qTx21BARMZGAAdtEg0xPx5/NKQkIYCwrInTWVf/TaJ3cH8lD30kJTjlqbZ3CC3QP6c5P7AyehO0JSeAnZqUOzV9skCSHGdYET8qgZUvN9xmxmU5/8RM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830267556260.9020451930637; Sat, 11 Jul 2026 21:24:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilfg-00083r-GI; Sun, 12 Jul 2026 00:20:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilff-00083M-Mg; Sun, 12 Jul 2026 00:20:03 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfd-0006kl-TO; Sun, 12 Jul 2026 00:20:03 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9B0811C0C03; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id CE2C83EB963; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 72BF713409; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=6i/c3rR/8Hak+rZpwou45hSXqserlaK1zB/y0AgaBUg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VUhqWfI2Kp56y679fKJ+8rKM7etzsavYN5cilxrDnBwiLyd7WQKgMXPWUK7tnF3cT vbzsB8z6o1gn84OR1AX/jSDjka1QmA76+VrJpN4WYDrwpP7QRSbpeH2CSKoxZW3nSP 2hx/mmPxhl0MMCHILqvTU2eSM7SRem9XrDDyYXl/D8i8FbMcZYz0w3jVL90csWPkwD S2kUi5HDiooQDJYMhk+nZzy13SJk8ZVF6SRRFIIbxuqm7WdYB1S3puYmvnqIlGlAMn /OFFdc775at1xc/hs4DnpEYIYDwtOY1HIAiCnvMHPRfWQho6rZJK9chYiLTwTNjA84 TGZQ8pqPqX74Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matthew Rosato , Christian Borntraeger , Farhan Ali , Cornelia Huck , Michael Tokarev Subject: [Stable-10.0.12 40/75] s390x/pci: Tighten region detection for BAR read/write Date: Sun, 12 Jul 2026 07:14:58 +0300 Message-ID: <20260712041539.108341-40-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830268593158500 Content-Type: text/plain; charset="utf-8" From: Matthew Rosato For PCISTG/PCISTB/PCILG instruction emulation, ensure that the offset and length provided by the guest does not overflow, and only return a memory region when the specified offset+length combination matches an existing subregion or the parent region. Cc: qemu-stable@nongnu.org Fixes: 4f6482bfe3 ("s390x/pci: search for subregion inside the BARs") Signed-off-by: Matthew Rosato Reviewed-by: Christian Borntraeger Reviewed-by: Farhan Ali Signed-off-by: Christian Borntraeger Message-ID: <20260707070728.147203-3-borntraeger@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit 2d709a70c75724e972126671b2e2c0fca0b6e239) Signed-off-by: Michael Tokarev diff --git a/hw/s390x/s390-pci-inst.c b/hw/s390x/s390-pci-inst.c index 6d95b96bef2..79a6a9c8524 100644 --- a/hw/s390x/s390-pci-inst.c +++ b/hw/s390x/s390-pci-inst.c @@ -390,13 +390,22 @@ static int zpci_endian_swap(uint64_t *ptr, uint8_t le= n) static MemoryRegion *s390_get_subregion(MemoryRegion *mr, uint64_t offset, uint8_t len) { + uint64_t last =3D offset + len; MemoryRegion *subregion; uint64_t subregion_size; =20 + /* + * Ensure the region is valid, the calculated address cannot wrap and = that + * it falls within this region. + */ + if (!mr || offset > last || last > memory_region_size(mr)) { + return NULL; + } + QTAILQ_FOREACH(subregion, &mr->subregions, subregions_link) { subregion_size =3D int128_get64(subregion->size); if ((offset >=3D subregion->addr) && - (offset + len) <=3D (subregion->addr + subregion_size)) { + (last) <=3D (subregion->addr + subregion_size)) { mr =3D subregion; break; } @@ -411,6 +420,10 @@ static MemTxResult zpci_read_bar(S390PCIBusDevice *pbd= ev, uint8_t pcias, =20 mr =3D pbdev->pdev->io_regions[pcias].memory; mr =3D s390_get_subregion(mr, offset, len); + if (!mr) { + return MEMTX_ERROR; + } + offset -=3D mr->addr; return memory_region_dispatch_read(mr, offset, data, size_memop(len) | MO_BE, @@ -511,6 +524,10 @@ static MemTxResult zpci_write_bar(S390PCIBusDevice *pb= dev, uint8_t pcias, =20 mr =3D pbdev->pdev->io_regions[pcias].memory; mr =3D s390_get_subregion(mr, offset, len); + if (!mr) { + return MEMTX_ERROR; + } + offset -=3D mr->addr; return memory_region_dispatch_write(mr, offset, data, size_memop(len) | MO_BE, @@ -898,6 +915,11 @@ int pcistb_service_call(S390CPU *cpu, uint8_t r1, uint= 8_t r3, uint64_t gaddr, =20 mr =3D pbdev->pdev->io_regions[pcias].memory; mr =3D s390_get_subregion(mr, offset, len); + if (!mr) { + s390_program_interrupt(env, PGM_OPERAND, ra); + return 0; + } + offset -=3D mr->addr; =20 for (i =3D 0; i < len; i +=3D 8) { --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830277; cv=none; d=zohomail.com; s=zohoarc; b=YAkTMkfhcUbQLJ/VTPcbyKD9tCKLUlG0rTKnzLYPy9MC1bsWr3It5NHTU+nGm0PCrXfircT2a++d4EeRv4omqCQE1HQXnCoHiMPSAJOZM3VBQ7k9cmS6njTqgS0LvYBcSMr6hkbEW16MX8VWBezhqmL3c3+F39X/LRslv8htebw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830277; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fumqYB0Tf/8B4XaXAUPJMmzKmKk4Vq/V9Sa0ygy1wHk=; b=cumn0xzrPxfYok3TLCI7/+1slaSrvpTc0ixBn4BSHwilaN5kGeBRbFxcot3qLmf1Zz/VOnsP/sU2Ry74f8B3elS3AIHjeARml/qNfiC4ltIP1+pddjn7aDS7LLfVpdOCI1z37TRwiKlB6kRq7fuCiB4lwR336W/Tur3zgzoBtmA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830277005935.4482790293512; Sat, 11 Jul 2026 21:24:37 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgC-0008Pe-UU; Sun, 12 Jul 2026 00:20:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfl-0008D2-RP; Sun, 12 Jul 2026 00:20:13 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfi-0006l1-Uf; Sun, 12 Jul 2026 00:20:08 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A465A1C0C04; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id D86533EB964; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 753041340B; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=mm91yPJYsa6MKzU1tlbZT2I4RmoF1YGHodRPBZVFnxc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Sz4siU+aBfSbmUmHGtGkyri2q2pJQGGCRoo0SO6ew+PorDjvtb5z4sK7kC11AcRMz R6lrWa034C6o1AVSi85gI01JkD/0KzK1T5X5kETqjVukrUiMH8gsrywiEXW+ykDs9k 3CBYmSNuHmMIqgFksMk6FuCr+fD2wSFepVnSHXmb8crLP5/dPqcOs8HQL3InN4EkeS P4Wht6lDSyB1Gbwq/J67iXVzZCva19SF9qJtqxYauU9/t52v/S91SX3gZp3HPivauf bFj0lkvuseEzcMpfYziBGpa9WRVXeW52fBQa0iD9FXDfK13TWHDIqTzLxv+bGDH5Bd 6AHvN6wI7bLag== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matthew Rosato , Christian Borntraeger , Farhan Ali , Cornelia Huck , Michael Tokarev Subject: [Stable-10.0.12 41/75] s390x/pci: Shrink RPCIT ranges to registered window Date: Sun, 12 Jul 2026 07:14:59 +0300 Message-ID: <20260712041539.108341-41-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830278675158500 Content-Type: text/plain; charset="utf-8" From: Matthew Rosato Today, if a RPCIT instruction is presented from the guest whose range exceeds the previously-registered IOAT, QEMU will process the range so long as 1) the specified range at least partially overlaps with what was previously registered and 2) the guest has valid IOAT entries in its table. If the entries are not present (invalid), then the RPCIT will unnecessarily spend time reporting the invalid region/segment entries. Optimize this path by exiting immediately if the requested range falls completely outside of the previously-registered range or if the requested range ends before it starts (which would only occur if the guest-specified address + length would overflow a u64). Otherwise, clamp the request to only the portion of the range that overlaps with what was previously registered, effectively ignoring the portion outside of the registered range. Cc: qemu-stable@nongnu.org Fixes: 5d1abf2344 ("s390x/pci: enforce zPCI state checking") Reviewed-by: Christian Borntraeger Reviewed-by: Farhan Ali Signed-off-by: Matthew Rosato Signed-off-by: Christian Borntraeger Message-ID: <20260707070728.147203-4-borntraeger@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit b8c8ec1d752661e1904d089c77d8617c4b6bfb5a) Signed-off-by: Michael Tokarev diff --git a/hw/s390x/s390-pci-inst.c b/hw/s390x/s390-pci-inst.c index 79a6a9c8524..3513a93b9d1 100644 --- a/hw/s390x/s390-pci-inst.c +++ b/hw/s390x/s390-pci-inst.c @@ -768,10 +768,16 @@ int rpcit_service_call(S390CPU *cpu, uint8_t r1, uint= 8_t r2, uintptr_t ra) goto err; } =20 - if (end < iommu->pba || start > iommu->pal) { + if (end < start || end < iommu->pba || start > iommu->pal) { error =3D ERR_EVENT_OORANGE; goto err; } + /* + * If the specified range at least partially overlaps the registered + * aperture, clamp the request to the aperture and ignore the rest. + */ + sstart =3D MAX(start, iommu->pba); + end =3D MIN(end, iommu->pal + 1); =20 retry: start =3D sstart; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830067; cv=none; d=zohomail.com; s=zohoarc; b=RQSAyuO68p0Ifp/WzPu4wuJSnw/U4QyvOga5iMz4IQfEsgcTEnttPomQjkRTgU6vfrihLEjRXA/xTgo+sMrUJMcLwB7+ua47amawj6K33wRB5JPpl8pCCfKh3tOYOWQ7syWexMyG9YfsK5j+h/G77Co3hrOaZ9jDbvdFyIbubUw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830067; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ycc9PaJDlKwGF0nb3v0BUoVs+ND1ZvFoO6CoRhEe0vk=; b=drMFq1BYFh6qineqXYV9kaRF68TtKp4wBr3BOL/Z9vB2M8srL2ixv6rRD3QjrveMIt/7MF77EqKXfcuf3BauFrQYw/mYIoB+KkSC+UD5egKwMdYcQ2BO0gY27S11DgJXonJ7fpwBsyM7pEd50Hx2TcC02KKp64M8DQY44L6Anfw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830067367769.2841853270804; Sat, 11 Jul 2026 21:21:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilg3-0008LA-EB; Sun, 12 Jul 2026 00:20:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfj-00089t-2I; Sun, 12 Jul 2026 00:20:07 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfh-0006rn-93; Sun, 12 Jul 2026 00:20:06 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id AA56C1C0C05; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id DDB7A3EB965; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 779D21340D; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=n/A//FhHq1qbkUfYPXbXVdYtFXN3CmgO/rsZi5KqWUE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=iU1/r9LtEpLNzCf4QwXZoCYvL9kiwm/syKsRgdwADbnioZWsdI5rksoReLcqnYNHO H/YOM1V3QjvK5EwitEGwur3VXkN8+s7VjsAColxudNQz2bzcCTk+CwxF3P9D7x8YoD e7FdBh11CdIsSsS4Li9rLOg1kFUompjnnowQpqf4ffmNyCTg2AgbpdSvqj60vNjH+C kp3FrobyhUauCngqBHZ51OZemcMUnT9ngRPI79PhkMXWTD7F8ijw/WKtslXPKail3u twhgRsQ1A1nAwKwTI5ZNibbWCR3DexIa+ZYb8FXgJfkJAVI0hgWAlPTT4vR8w8UDZF HQU8LMB5FTuTw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matthew Rosato , Christian Borntraeger , Farhan Ali , Eric Farman , Cornelia Huck , Michael Tokarev Subject: [Stable-10.0.12 42/75] s390x/ioinst: Require strict length and format for SEI CHSC handler Date: Sun, 12 Jul 2026 07:15:00 +0300 Message-ID: <20260712041539.108341-42-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830067915158502 Content-Type: text/plain; charset="utf-8" From: Matthew Rosato Ensure SEI commands that are received are of the appropriate length and format before handling. Cc: qemu-stable@nongnu.org Fixes: 8cba80c3a0 ("s390: Add PCI bus support") Reviewed-by: Christian Borntraeger Reviewed-by: Farhan Ali Reviewed-by: Eric Farman Signed-off-by: Matthew Rosato Signed-off-by: Christian Borntraeger Message-ID: <20260707070728.147203-5-borntraeger@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit 386268daea86e53d90baf99df5c7b8e2727ea783) Signed-off-by: Michael Tokarev diff --git a/target/s390x/ioinst.c b/target/s390x/ioinst.c index a944f16c254..2f94a29ac27 100644 --- a/target/s390x/ioinst.c +++ b/target/s390x/ioinst.c @@ -601,13 +601,27 @@ static int chsc_sei_nt2_have_event(void) =20 #define CHSC_SEI_NT0 (1ULL << 63) #define CHSC_SEI_NT2 (1ULL << 61) +#define CHSC_SEI_0_FMT 0x0f000000 static void ioinst_handle_chsc_sei(ChscReq *req, ChscResp *res) { uint64_t selection_mask =3D ldq_be_p(&req->param1); + uint32_t param0 =3D be32_to_cpu(req->param0); uint8_t *res_flags =3D (uint8_t *)res->data; + uint16_t len =3D be16_to_cpu(req->len); + uint16_t resp_code; int have_event =3D 0; int have_more =3D 0; =20 + if (len !=3D 0x0010) { + resp_code =3D 0x0003; + goto out_err; + } + + if (param0 & CHSC_SEI_0_FMT) { + resp_code =3D 0x0007; + goto out_err; + } + /* regarding architecture nt0 can not be masked */ have_event =3D !chsc_sei_nt0_get_event(res); have_more =3D chsc_sei_nt0_have_event(); @@ -634,6 +648,12 @@ static void ioinst_handle_chsc_sei(ChscReq *req, ChscR= esp *res) res->code =3D cpu_to_be16(0x0005); res->len =3D cpu_to_be16(CHSC_MIN_RESP_LEN); } + return; + + out_err: + res->code =3D cpu_to_be16(resp_code); + res->len =3D cpu_to_be16(CHSC_MIN_RESP_LEN); + res->param =3D 0; } =20 static void ioinst_handle_chsc_unimplemented(ChscResp *res) --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830056; cv=none; d=zohomail.com; s=zohoarc; b=KCmTsLPO761F0c/pyIVkMP+p5mXyLDD4fNTBnpe8mD9N6r9ujYvexa9z4vFZ1DYlNTCSWrjNmuQ0ndvITgWUqkIluvbPaVauCDgj+5R/juFu4ZdBfAm2wnAhnsX1CUAaLSQhGGe/Gj/egaiggj3LJg5lSoBQOBK8hLWv0hnxzDU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830056; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VXQQnmbmJ7GWstEsuVHGsbIXhLDLdnrNppVPl3e+CsQ=; b=TNt3gqmSXKsrKxsDMy95gQEbRaorLuTu8D/fBXOXkZ0QA49taCBOILoOne/uX85J51Xhh46M3WSaHiSGmoALpkV9vYAXaFEqOQEr1Rjl8/HHZSR8gHfI0t+0Md1PQ7nF7Yj7JhioHyjZ7ShVpZwCWxqSgBJA0jg4oOWZqfnBL4o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830056980194.8975509759557; Sat, 11 Jul 2026 21:20:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgF-0008S6-2E; Sun, 12 Jul 2026 00:20:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfn-0008Gi-VE; Sun, 12 Jul 2026 00:20:15 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfl-0006zi-Tv; Sun, 12 Jul 2026 00:20:11 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B15171C0C06; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id E42343EB966; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 7A1001340F; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=X2ep3Dgk2ND6fHIDdJKHfl3xtB71BL6tY0g4Gj3tTTQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=QtiPxGHRSPF/tJE5a0KMTjmPwsrjYgM4sUVK6MP4LLmMwicgbAYMP3ugQdpzwdF3l h4eoY88eX0OmrHe/1rwDAxIEXIjfNEn/EB8VvKI4PHYHUTS/NV3Sl5tmWlNn5NuRIt 81yiEI2An45vmpvHH7g2CYfxtijHxEIbY/jZk8REZY/AemCD6IHmAN9bG+aHxm+I02 SiFYRfpzxwwsk5ykaK9G2UyrPpZzZzGRTjBVPRcR2gAbB4zFGpzWfFLofDhRDvgdu7 HOATUW27QxMo2d7NUM8J1IjJbgI99CFheNvexC3kTcGwgIA1mwLv+0/bBJLjOA4xC9 nf5yfW9pTQS5A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Eric Farman , Christian Borntraeger , Matthew Rosato , Cornelia Huck , Michael Tokarev Subject: [Stable-10.0.12 43/75] s390x/css: limit number of CHPIDs in description Date: Sun, 12 Jul 2026 07:15:01 +0300 Message-ID: <20260712041539.108341-43-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830057868158500 Content-Type: text/plain; charset="utf-8" From: Eric Farman virtio-ccw uses a single virtual CHPID for all devices and device-types, but vfio-ccw (passthrough) shares real CHPID information with the guest. A sufficiently large passthrough configuration would exceed the defined response payload. Fix this by limiting the number of CHPID descriptions that are returned based on the given response format. Cc: qemu-stable@nongnu.org Reviewed-by: Christian Borntraeger Reviewed-by: Matthew Rosato Signed-off-by: Eric Farman Signed-off-by: Christian Borntraeger Message-ID: <20260707070728.147203-6-borntraeger@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit 22f2da06a8b291c975a7caf05dbd3b180c856741) Signed-off-by: Michael Tokarev diff --git a/hw/s390x/css.c b/hw/s390x/css.c index 738800c98df..38d2d90028c 100644 --- a/hw/s390x/css.c +++ b/hw/s390x/css.c @@ -1900,6 +1900,7 @@ int css_collect_chp_desc(int m, uint8_t cssid, uint8_= t f_chpid, uint8_t l_chpid, int i, desc_size; uint32_t words[8]; uint32_t chpid_type_word; + uint32_t max_chpids, chpid_count =3D 0; CssImage *css; =20 if (!m && !cssid) { @@ -1910,9 +1911,25 @@ int css_collect_chp_desc(int m, uint8_t cssid, uint8= _t f_chpid, uint8_t l_chpid, if (!css) { return 0; } + + if (rfmt =3D=3D 0) { + max_chpids =3D 256; + } else if (rfmt =3D=3D 1) { + max_chpids =3D 127; + } else { + /* Should be rejected by caller */ + return 0; + } + desc_size =3D 0; for (i =3D f_chpid; i <=3D l_chpid; i++) { if (css->chpids[i].in_use) { + /* Limit number of CHPIDs sent back */ + if (chpid_count =3D=3D max_chpids) { + break; + } + + chpid_count++; chpid_type_word =3D 0x80000000 | (css->chpids[i].type << 8) | = i; if (rfmt =3D=3D 0) { words[0] =3D cpu_to_be32(chpid_type_word); --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830138; cv=none; d=zohomail.com; s=zohoarc; b=eT9JxDgnTThu3/VQO/sjWJpxqE4b8m1DRDzNFQElr6YT/MRlyn9FCuLzIq2L3BAvrHhfMM2WX7kTrL969AWnqJHkjbSBY0t8zyoNYRI1GS3xAbfUL7B/Y8Kw5HyUIPLckk/5BHmuhfPHc2sLn/6cH9+OjSteHzMZFmRa/GFnAA4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830138; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YMV3yKHuxdr1HtYBlYbTefryk/7eOE0GlO4oBV81eIM=; b=Upqz9bH6qzrQx7+F/xdmmTAErZPU5M7zkJpe62rHOR3FlK8/C23SdLhE/+tPDd13cInCd6nf77LsGys/mr7iHbGPdzrKFs+HEDbZIOlsOjpDcdiifynrg1WcbJ8FHTeTQp50sna5XxJm7QfiI+QtNB6whrKHRbpbF75C0/4NTIE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830138429812.2414046321752; Sat, 11 Jul 2026 21:22:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgK-00008w-Hc; Sun, 12 Jul 2026 00:20:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfr-0008Kh-1P; Sun, 12 Jul 2026 00:20:17 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilfo-00070R-28; Sun, 12 Jul 2026 00:20:14 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B6ADC1C0C07; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id EAADB3EB967; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 7C81013411; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=ePzxAoLhO6DGp9DA26gIEJ0w+f878SHmY7UHPwbdxu4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ZA0vpMxtCWs8WMcujVLv+rF/rTvjvCJLjfMyHWEJoTdmgIg6sseFjI2QrLAupsIEw 6nlJkGGfii0+cVpzNvpkJZh95N6RNu8jHCpr/ggsOrUf2MaIsnAHlBFsr9WaH3XOF1 DBZfBi17uxQMLL3oER2alXG3zn7rJWC+GGtA5ReLcIMR3WAzfBjNZA+hYsPwwUwD3y xoAYv84FCjuCFNwlWLRtfngj88ZipcMjomPjPsMvCVwN7KTcU8M2QJpR2wo5C1GUrS ytXA+vPPg5W2D/5p/dRyCieibzdl+bpiWPg+wfhhQWId3DMsNz9KQ8dnAcTQRUdV9L nAc65nUj9LZ8w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Torin Carey , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.12 44/75] hw/misc/edu: restrict dma access to dma buffer Date: Sun, 12 Jul 2026 07:15:02 +0300 Message-ID: <20260712041539.108341-44-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830140561158500 From: Torin Carey The EDU device doesn't enforce any bound checks on the addresses provided, allowing users of the device to perform arbitrary reads and writes to QEMU's address space. Signed-off-by: Torin Carey Cc: qemu-stable@nongnu.org Fixes: 7b608e5d6c1 ("hw: misc: edu: use qemu_log_mask instead of hw_error") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3852 Reviewed-by: Peter Maydell Message-ID: Signed-off-by: Philippe Mathieu-Daud=C3=A9 (cherry picked from commit 42f599172ae023924f288e20af0ceed681674747) Signed-off-by: Michael Tokarev diff --git a/hw/misc/edu.c b/hw/misc/edu.c index 504178b4a22..41f1fe99499 100644 --- a/hw/misc/edu.c +++ b/hw/misc/edu.c @@ -103,7 +103,7 @@ static void edu_lower_irq(EduState *edu, uint32_t val) } } =20 -static void edu_check_range(uint64_t xfer_start, uint64_t xfer_size, +static bool edu_check_range(uint64_t xfer_start, uint64_t xfer_size, uint64_t dma_start, uint64_t dma_size) { uint64_t xfer_end =3D xfer_start + xfer_size; @@ -115,13 +115,15 @@ static void edu_check_range(uint64_t xfer_start, uint= 64_t xfer_size, */ if (dma_end >=3D dma_start && xfer_end >=3D xfer_start && xfer_start >=3D dma_start && xfer_end <=3D dma_end) { - return; + return true; } =20 qemu_log_mask(LOG_GUEST_ERROR, "EDU: DMA range 0x%016"PRIx64"-0x%016"PRIx64 " out of bounds (0x%016"PRIx64"-0x%016"PRIx64")!", xfer_start, xfer_end - 1, dma_start, dma_end - 1); + + return false; } =20 static dma_addr_t edu_clamp_addr(const EduState *edu, dma_addr_t addr) @@ -148,16 +150,18 @@ static void edu_dma_timer(void *opaque) =20 if (EDU_DMA_DIR(edu->dma.cmd) =3D=3D EDU_DMA_FROM_PCI) { uint64_t dst =3D edu->dma.dst; - edu_check_range(dst, edu->dma.cnt, DMA_START, DMA_SIZE); - dst -=3D DMA_START; - pci_dma_read(&edu->pdev, edu_clamp_addr(edu, edu->dma.src), - edu->dma_buf + dst, edu->dma.cnt); + if (edu_check_range(dst, edu->dma.cnt, DMA_START, DMA_SIZE)) { + dst -=3D DMA_START; + pci_dma_read(&edu->pdev, edu_clamp_addr(edu, edu->dma.src), + edu->dma_buf + dst, edu->dma.cnt); + } } else { uint64_t src =3D edu->dma.src; - edu_check_range(src, edu->dma.cnt, DMA_START, DMA_SIZE); - src -=3D DMA_START; - pci_dma_write(&edu->pdev, edu_clamp_addr(edu, edu->dma.dst), - edu->dma_buf + src, edu->dma.cnt); + if (edu_check_range(src, edu->dma.cnt, DMA_START, DMA_SIZE)) { + src -=3D DMA_START; + pci_dma_write(&edu->pdev, edu_clamp_addr(edu, edu->dma.dst), + edu->dma_buf + src, edu->dma.cnt); + } } =20 edu->dma.cmd &=3D ~EDU_DMA_RUN; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830113; cv=none; d=zohomail.com; s=zohoarc; b=n3zVDYSmm/kf32+5RotG+TDEqYP3FXvlF8phPKH87pq0uEASh+SYSOE5xtdKQvXQR5JutKrJho5sx2xO/5lCZTkbOVxKT9hDiRiQRLpYb+/OSnZpqP6Lhgv3WAsnFOfpBIgswgZ6wPoOAd9QeWFSrHdhvY4XxePxvivpWejxbZY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830113; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fr/iWRnadPOHVAcGA6HUmJVL1IGacxdbjbyXH1IeslA=; b=SuA/Bz0qDDgHDvB6tUQUZMY2SCEpEpAzxdR0xl5MDRfNl8y3DOLVVK2O8lx1UC06Z5qFBmF8Tk6WcouV1/lWtvpm3m7vgotbfAatnXQpVJZeE9FWNEllkHz9lioSkiA63tLUPbA1bGUJIIRz1y6MGJm/6o03SHgATwUcXU+mUtY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830113234837.2075058757814; Sat, 11 Jul 2026 21:21:53 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgQ-0000PE-Ve; Sun, 12 Jul 2026 00:20:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgB-0008QQ-CX; Sun, 12 Jul 2026 00:20:36 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilg9-00070d-M0; Sun, 12 Jul 2026 00:20:35 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BD0361C0C08; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id EFF713EB968; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 7EDDA13413; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=2rvXVRXM8ntr2Y84KJr8fZ5CcUZdKIMTJqDNb+YFNuI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=j1zhzdGXIJiDrWC0O1ETipI+U5J4HagikVloNo+vfEV7JMKZcHVSQK67pHInQLegt uuJ9iscjfInCEtS06dGqLfBQWUW4PHIiaMdHsnvEt3+8LJ9W+QnfcYooOBO22zPeuJ ijYyBnwwxNZIprSfWkafZQ52pQBEAACyYZFS+VAnVg7KMmpWpdnjcEvXeUW4mgtufc GvxJM+lbtzoeoc3+y9tZXObI1kRej6xP0nWlrQQLq+KDJcTD2ldLuyO2BU5yBtWpFr ZBvqeG5NV3iqFd9NOXeIgy1RATypp1ER7E5QTNGePi5QIZWh0rN/RV6LMFi4yqSV27 lKO0TIOG+ZCrw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.12 45/75] hw/ide/ahci: cancel in-flight buffered reads on command engine restart Date: Sun, 12 Jul 2026 07:15:03 +0300 Message-ID: <20260712041539.108341-45-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830114105158500 From: "Denis V. Lunev" ATAPI CD reads are issued through ide_buffered_readv() (cd_read_sector() and ide_atapi_cmd_read_dma_cb() in hw/ide/atapi.c). The PIO path discards the returned aiocb; the DMA path stores it in s->bus->dma->aiocb. A guest can stop and restart a port's command engine (PxCMD.ST 1 -> 0 -> 1) while such a read is still in flight. Stopping the engine unmaps the command list (ahci_unmap_clb_address()) and restarting it re-maps the list and clears AHCIDevice.cur_cmd to NULL, but nothing tears down the outstanding read. This path does not run ide_reset(), so the drive's transfer state is preserved and the read still completes. Its callbacks then dereference the stale or NULL cur_cmd in the AHCI transfer helpers: PIO: cd_read_sector_cb() -> ide_atapi_cmd_reply_end() -> ide_transfer_start_norecurse() -> ahci_pio_transfer() DMA: ide_atapi_cmd_read_dma_cb() -> ahci_dma_rw_buf() -> ahci_populate_sglist() Both crash with a NULL cur_cmd; the PIO variant has been seen in the field. Cancel the outstanding I/O when the command list is unmapped, reusing ide_cancel_dma_sync() as the ATAPI DEVICE RESET command does. It runs the completion callback with -ECANCELED (which tears down s->bus->dma->aiocb for the DMA case) and orphans the buffered request, so the eventual asynchronous completion is a no-op. Merely setting the orphaned flag is not enough: it would leave s->bus->dma->aiocb pointing at a freed aiocb that a later reset would cancel. Fixes: 1d8c11d63154 ("ide: add support for IDEBufferedRequest") Signed-off-by: Denis V. Lunev Message-ID: <20260619112158.304782-2-den@openvz.org> [PMD: Use ide_bus_active_if()] Signed-off-by: Philippe Mathieu-Daud=C3=A9 (cherry picked from commit d9f78431d8ebdc2d03ad74461138c1c9eb076aa5) Signed-off-by: Michael Tokarev diff --git a/hw/ide/ahci.c b/hw/ide/ahci.c index 1303c21cb70..8a8c28698ce 100644 --- a/hw/ide/ahci.c +++ b/hw/ide/ahci.c @@ -740,6 +740,9 @@ static bool ahci_map_clb_address(AHCIDevice *ad) =20 static void ahci_unmap_clb_address(AHCIDevice *ad) { + /* Cancel in-flight reads that would complete against a cleared cur_cm= d. */ + ide_cancel_dma_sync(ide_bus_active_if(&ad->port)); + if (ad->lst =3D=3D NULL) { trace_ahci_unmap_clb_address_null(ad->hba, ad->port_no); return; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830098; cv=none; d=zohomail.com; s=zohoarc; b=EqK/fvWwIwVMR+VEJPy93MUnjqjomBWUgHs65ApVg/fPa+TGoSKV6NyvlOqlGbJDmhAzvpASCMX53ZdPBsHbC+Y9kzhzCQ1BVSy/uVGSwA43/i2HIAwERZp3SgQ8PTSXlUAA0FP3PyrUU1P+zpn5rdRwvFTDwReagFKxFxMQc+c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830098; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=dy1NfnzdvFk5fqlAHtLLwdBn0XulIcKEM03WIlJlnCg=; b=cVVaCbURlkrUXWyvD1uTWSCsjW+fSBTwy75vVhdPdpnxys39vwdoszz8TSd8yPtom4kVl/+Ss7dzcHZT+IFAUl6096jTbbf8l97BUwb5MHbu4vf7Xbq1sDoHBuhs+Ew2ShqHrWleE3Wm5w+08jd1bg+GANwL/sP1xkJ3xjWl3RA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830098496860.9918684725365; Sat, 11 Jul 2026 21:21:38 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgQ-0000Nt-La; Sun, 12 Jul 2026 00:20:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgE-0008S9-CP; Sun, 12 Jul 2026 00:20:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgC-00070m-Gf; Sun, 12 Jul 2026 00:20:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C92911C0C09; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 020F33EB969; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 8164213415; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=eCdtIr4LxAwGMaOuVeEnmMgBDQGsxQQWflW0QRuga8c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=fQhP3tFVH1HqjgC7nqY0dim7kLV95Hrau/5Qi8mlazkZneDIvS5jL763Km2kF/a+5 pafLBvIGDUrp/CsvmWUta8IJNAfoRzajmGq5vR0Zqh+m5iPywq0p4V7AMlmwvFxpOR otVRPRtZvMV4hfsi9mn8Vvxq+lr/nGYKPQ3+DTLjSSmvpMjocIuiwtFZVZCxxRE+Ev FTg7U4UnFWmeZpRaqJDUsnjO+OWEjxtiMx0GBVNVLNf8ed5ok7g7ACwLr39cxl0SnL sVGvTIKzLWHHdGMkW+vnqJ6A7bePDBuKnyn1Rahz+ASH7SjFJ7v7mdlNsA/7lyPpBQ u1Bzli5nWfGEg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.12 46/75] tests/qtest/ahci: test ATAPI read completing after engine restart Date: Sun, 12 Jul 2026 07:15:04 +0300 Message-ID: <20260712041539.108341-46-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DIET_1=0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830100062158500 From: "Denis V. Lunev" Add a regression test for the crash that occurs when a buffered ATAPI read completes after the command engine has been restarted. Issue an ATAPI READ_10 against a blkdebug-backed CD, suspend the backend read so it stays in flight, stop and restart the port's command engine (which re-maps the command list and clears cur_cmd), then release the read. The PIO and DMA reply paths fault in different AHCI helpers (ahci_pio_transfer() vs ahci_dma_rw_buf()), so cover both. The DMA variant is the reliable guard: on engine restart check_cmd() can re-arm cur_cmd before the old read completes, so the PIO variant does not fault in every build. The test only asserts that qemu survives a subsequent register access; if the blkdebug breakpoint ever failed to park the read it would pass without exercising the bug, as with the existing break/resume tests. Signed-off-by: Denis V. Lunev Message-ID: <20260619112158.304782-3-den@openvz.org> Signed-off-by: Philippe Mathieu-Daud=C3=A9 (cherry picked from commit cb7bc10385f365c0792b77fc73b1d17a16cbaefd) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/ahci-test.c b/tests/qtest/ahci-test.c index 88ac6c66ce3..9bebc0e9577 100644 --- a/tests/qtest/ahci-test.c +++ b/tests/qtest/ahci-test.c @@ -1625,6 +1625,69 @@ static void test_cdrom_pio_multi(void) ahci_test_cdrom_read10(3, false); } =20 +/* + * Regression test: a buffered ATAPI read completing after a command + * engine restart must not dereference the cleared cur_cmd. Cover both + * PIO and DMA; the DMA variant is the reliable guard. + */ +static void test_atapi_engine_restart_in_flight(bool dma) +{ + AHCIQState *ahci; + AHCICommand *cmd; + unsigned char *tx; + char *iso; + int fd; + uint8_t port; + uint64_t buffer; + uint64_t iso_size =3D (uint64_t)ATAPI_SECTOR_SIZE * 2; + + fd =3D prepare_iso(iso_size, &tx, &iso); + + ahci =3D ahci_boot_and_enable("-drive if=3Dnone,id=3Ddrive0," + "file=3Dblkdebug::%s,format=3Draw,readonly= =3Don " + "-M q35 " + "-device ide-cd,drive=3Ddrive0 ", iso); + port =3D ahci_port_select(ahci); + + buffer =3D ahci_alloc(ahci, ATAPI_SECTOR_SIZE); + qtest_memset(ahci->parent->qts, buffer, 0x00, ATAPI_SECTOR_SIZE); + + /* Suspend the next backend read so the ATAPI read stays in flight. */ + g_free(qtest_hmp(ahci->parent->qts, + "qemu-io drive0 \"break read_aio rd\"")); + + cmd =3D ahci_atapi_command_create(CMD_ATAPI_READ_10, ATAPI_SECTOR_SIZE, + dma); + ahci_command_adjust(cmd, 0, buffer, ATAPI_SECTOR_SIZE, 0); + ahci_command_commit(ahci, cmd, port); + ahci_command_issue_async(ahci, cmd); + + /* Stop and restart the command engine to re-map the command list. */ + ahci_px_clr(ahci, port, AHCI_PX_CMD, AHCI_PX_CMD_ST); + ahci_px_set(ahci, port, AHCI_PX_CMD, AHCI_PX_CMD_ST); + + g_free(qtest_hmp(ahci->parent->qts, "qemu-io drive0 \"resume rd\"")); + + /* Round-trip through the device to confirm qemu is still alive. */ + ahci_px_rreg(ahci, port, AHCI_PX_TFD); + + ahci_command_free(cmd); + ahci_free(ahci, buffer); + g_free(tx); + ahci_shutdown(ahci); + remove_iso(fd, iso); +} + +static void test_atapi_engine_restart_pio(void) +{ + test_atapi_engine_restart_in_flight(false); +} + +static void test_atapi_engine_restart_dma(void) +{ + test_atapi_engine_restart_in_flight(true); +} + /* Regression test: Test that a READ_CD command with a BCL of 0 but a size= of 0 * completes as a NOP instead of erroring out. */ static void test_atapi_bcl(void) @@ -2043,6 +2106,10 @@ int main(int argc, char **argv) =20 qtest_add_func("/ahci/cdrom/pio/bcl", test_atapi_bcl); qtest_add_func("/ahci/cdrom/eject", test_atapi_tray); + qtest_add_func("/ahci/cdrom/engine_restart/pio", + test_atapi_engine_restart_pio); + qtest_add_func("/ahci/cdrom/engine_restart/dma", + test_atapi_engine_restart_dma); =20 ret =3D g_test_run(); =20 --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830278; cv=none; d=zohomail.com; s=zohoarc; b=RbSCWfOgEPTPKVzR4jmihUiQWQupdGodVstVhXBEDuDjUFe6bLaYX5Ic/X+4gyWKDb6dls/bkPOH3wG6QLUzoqM5OdVMrpa59A4oyLD9ut0h88e4AtZGca8NqZ1GxKA3C7JAgtuKFyeLArXeglxYZI6dPEEhaf/LB1NvFaBMNhc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830278; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=vg72vaIFsGVRq2i9107NK8oq6LMlTpNyRgLb/u6XGPU=; b=ONLmnKTHHJjwn+Lin1vivMJ6s0PciNOSSHW2EaZecUSLc2dWNwsMbd1KmKTP5p8tY3iV+6k06CsKKR8wVcZtecVN/brM3UnP6uuMm0OwhwYr14M0vy4+bR6Y7TNtT+mNFQsWkiz0rt+H6bFFt3DqjvL6jmbegsZwl5QxE78xFoM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830278005626.3792797849604; Sat, 11 Jul 2026 21:24:38 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgS-0000V5-Fc; Sun, 12 Jul 2026 00:20:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgE-0008SE-Nf; Sun, 12 Jul 2026 00:20:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgC-00073T-S7; Sun, 12 Jul 2026 00:20:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id CEB151C0C0A; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 0E9473EB96A; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 83C9813417; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=VBob9quS/XckzPP/Pi+ARP1J+R58gTqkmsspEOnmYMk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=B2Iri4E+LGhe9RZ8oJJv1Nu+6TdVhXvYzlL3PWPirsgHUz2y77nb7WJ5/zW13C0jj nr0jtNpS8JytVHgpld+0R0ulhC5CBiifi5psOD+szcSwbjV++MsdYkvL5KufJHPCft C89q00b562l2xwaJf8jF+GgLxaHwKmIIDemZ9H3sQjSBXGxg5h7jYD9kP73EauOhuS QnXdQS2FNq/fgeN3qKSsGgoK5FYrbWflgkg4FcivNP0P9Lv++DunzvAQ2qksT1PApC UkLOa/rfMq9Bf3lH3Et8mAuSMA2U1u4Tm56jBySVj9Ycyr8nMTx+oqU5nE2+HQfluT Xy/1K/VNHFj2A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.12 47/75] hw/dma/i8257: Return zeroes for read_memory in verify mode Date: Sun, 12 Jul 2026 07:15:05 +0300 Message-ID: <20260712041539.108341-47-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830278691158500 From: Peter Maydell The i8257 DMA controller has a "verify" mode, which the datasheet describes like this: > DMA verify, which does not actually involve the transfer of data. > When an 8257 channel is in the DMA verify mode, it will respond the > same as described for transfer operations, except that no memory or > I/O read/write control signals will be generated. When an 8257 > channel is in the DMA verify mode, it will respond the same as > described for transfer operations, except that no memory or I/O read > /write control signals will be generated, thus preventing the > transfer of data. The 8257, however, will gain control of the system > bus and will acknowledge the peripheral's DMA request for each DMA > cycle. The perihperal can use these acknowledge signals to enable an > internal access of each byte of a data block in order to execute some > verification procedure, such as the accumulation of a CRC check word. In practice, for QEMU's purposes the only real user of this is the floppy controller, which can be made to perform a "read data from floppy disk and check the checksum" by telling the fdc to do a read and the DMA controller to do a verify. This causes the fdc to do all the usual read actions including the checksum, but the data is never written to memory. However, it is possible for a guest doing something silly to program the DMA controller to do a verify operation for a device that wants to read from memory. Currently we simply return early from i8257_dma_read_memory() without writing to the buffer. None of the callers (the GUS, sb16 and cs4231a sound cards, plus the fdc) expect this, so they will take the uninitialized data as if it were from the guest. This can cause us to leak host data off the stack into the guest. Make i8257_dma_read_memory() fill the buffer with zeroes rather than leaving it untouched for a verify operation. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3487 Signed-off-by: Peter Maydell Reviewed-by: Daniel P. Berrang=C3=A9 Message-ID: <20260629140128.1900095-1-peter.maydell@linaro.org> Signed-off-by: Philippe Mathieu-Daud=C3=A9 (cherry picked from commit 03071f99a3e1549b3acc9b9534961632df016f76) Signed-off-by: Michael Tokarev diff --git a/hw/dma/i8257.c b/hw/dma/i8257.c index 74c38d2ee84..1d9898f5694 100644 --- a/hw/dma/i8257.c +++ b/hw/dma/i8257.c @@ -406,6 +406,19 @@ static int i8257_dma_read_memory(IsaDma *obj, int ncha= n, void *buf, int pos, hwaddr addr =3D ((r->pageh & 0x7f) << 24) | (r->page << 16) | r->now[A= DDR]; =20 if (i8257_is_verify_transfer(r)) { + /* + * If the device is expecting this verify operation then + * it won't care about the nonexistent data. But if it + * is expecting a real read (i.e. the guest has misprogrammed + * the DMA controller and the device) it's going to try to do + * something with the buffer contents. Give it zeroes. + * (It's not clear whether this is exactly what happens if + * you do this on real hardware. In practice no device QEMU + * emulates has a use for verify on a memory-read transfer, + * so we don't care beyond avoiding the guest being able to + * trigger the caller reading uninitialized data.) + */ + memset(buf, 0, len); return len; } =20 --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830093; cv=none; d=zohomail.com; s=zohoarc; b=m0xmLFIN+/nf8qkA7dRQvaA1XhSTyTuZM4pjtaapobYHxEy7YqkOjVrHiX80DxZSUeTWUY/V4SEV2d7EjP2uzfoFCXhaUDUrXWf/0dSMmUsenlnk8CglP+tg1+SMb9pkF+c4AT8KOzVnVnlmEv6/WT6B2wUb4wnGVQM/yzc5Tz8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830093; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RiYsJYEQfju7OnsQWQKActmdC0p9WroTHl3UTDOpnkE=; b=ZMzSOW5+1U45w3cBHzRh1mtYEbQVv+n8HqN6okF0uSiDGzEpnuUxue6/C1lH5I9uHue70xfS4PIpEH0MiGmMDX6DnyezxTLrETnCILZv/920lcBMOm5LejAKm7IHw8fw+U2r+4sJ3+0YHEDC+9oq+xHXS3Kd1+QWLQyt6T+2o2A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383009353450.25646276361567; Sat, 11 Jul 2026 21:21:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgT-0000eI-OY; Sun, 12 Jul 2026 00:20:53 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgH-00009f-HZ; Sun, 12 Jul 2026 00:20:44 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgF-00073o-Rc; Sun, 12 Jul 2026 00:20:41 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D549E1C0C0B; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 1492A3EB96B; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 861FB13419; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=tc+gDOY5VW16+p5jmG6OzerDXc3kw4V9NV/IBhw6beo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=kfB2fj5yJbgQjpjVfwTYIQk2LRU6PNKH45p04uVHoyeIP7EgyfTLC1s8RLDLmeQ+U 7RhnhOVr1HdJKVxYpHJmuUnluaVQpyAZVGitRyX9W9lR80cUuK54uxTm39ZceFdNDy db4rrYkHmmp0E6qOAL5RJdUEfu0PkpMgWN7oVmILZPjmHwSkRAmf0yhrnJljVi6URN WzbWPz4fmLevPoQZ+rVOfE1NKPvWMz5GNUQ82fHVrBkdU7NIl2HEK9G/aVHnrVaTE/ z0conoDHHsB+RVa610vT1yOWBmTiqc24UGtktiiSfGwTLmWJ5j0k+/aKkzvUEQosPZ iWKBGImzvnuoQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.12 48/75] hw/scsi/mptsas: Reset doorbell state on reset Date: Sun, 12 Jul 2026 07:15:06 +0300 Message-ID: <20260712041539.108341-48-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830094039158500 From: Peter Maydell Currently the mptsas reset function clears intr_status, but it doesn't reset the doorbell state machine. This means that the state machine and the interrupt state get out of sync, and the guest can trigger an assertion failure in mptsas_doorbell_read() where s->doorbell_state is still DOORBELL_READ but s->intr_status does not have MPI_HIS_DOORBELL_INTERRUPT set. Fix this by having reset also reset the doorbell state. Strictly speaking we don't need to also clear doorbell_reply_idx and doorbell_reply_size, because those are only read when in DOORBELL_READ state, and the code always sets them up before transitioning into that state. But it's less confusing to clear them out on reset. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/304 Signed-off-by: Peter Maydell Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-ID: <20260629185035.2138238-1-peter.maydell@linaro.org> Signed-off-by: Philippe Mathieu-Daud=C3=A9 (cherry picked from commit 831a13665ab1123b5ccd127820f287e41be137e9) Signed-off-by: Michael Tokarev diff --git a/hw/scsi/mptsas.c b/hw/scsi/mptsas.c index ba7a7d07707..4335ccd5003 100644 --- a/hw/scsi/mptsas.c +++ b/hw/scsi/mptsas.c @@ -811,6 +811,10 @@ static void mptsas_soft_reset(MPTSASState *s) s->intr_status =3D 0; s->intr_mask =3D save_mask; =20 + s->doorbell_state =3D DOORBELL_NONE; + s->doorbell_reply_idx =3D 0; + s->doorbell_reply_size =3D 0; + s->reply_free_tail =3D 0; s->reply_free_head =3D 0; s->reply_post_tail =3D 0; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830162; cv=none; d=zohomail.com; s=zohoarc; b=ThO9wR+1TucSPHZ1DxtoA+udsiRxgb9tjaYpOquynqSu5YkZQWPTvYQ3+B/tiFJspMMfLu7lgy8JDGeZGGFx7JAqxiOkj40XsJTqHoWZVe4ixPgmUtiUyaZkG9ue9D0omc1ITtWCl8KG0+Y7s7TH335Zj27BtBT4acwEh/fP53Y= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830162; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=OQw7/2scaV2hJ5Xxl+OghHZuSd8rped+rgiif1U3+E8=; b=R78WnfaWWGQlw7S5cPjab/CehRfjyp1VLTrlqizjLN/0WpbCBQ6fj1BI8oEKz8cUBvmamfNIS21hfgH82GgttRkl6EBL/lDqDaTB+vyGsF4wGcUPO675qgyzPI5Xzbm8HsHxypI3rMQjz3WMWm64nFzt4kKz5XQsYCZ+tsEL9U0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17838301620983.169962712834149; Sat, 11 Jul 2026 21:22:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgd-0001Nf-Pz; Sun, 12 Jul 2026 00:21:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgc-0001Gy-2S; Sun, 12 Jul 2026 00:21:02 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilga-00073u-8D; Sun, 12 Jul 2026 00:21:01 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id DB9261C0C0C; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 1B1923EB96C; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 888791341B; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=x+PfetWz0JUn+OwM6oI/vUJA8aiYexVFJ80TaWlBdP0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=npW87S9wrhP/EmXsUpzcae6GszUagX32GEFBcKVBVNoPUkHPZIQH8eWnxpONh+mmJ PirG6hIUQGCDqSCFwk/fy/cBNRqjx36yxNnpILYmVnNRqFOq1OBL0vZCeoH+XCpwbW 6QWyx5jRNaF+HotSC77PbSSMF1r3p2VWRwB2op7dZsMPxMd+Lk75aDLqtFByUSQ2xV Fc/xv573fVS4flqt6yKQUe/7NmnZ8CsDVT1mOt0k3Ri0xs4k3x6cbgar6G/oiQ4qcC z6+TmDh6eUlbDEwwwcUqjXkR4jJ5R8pcLrWIiYYnjl7+6QhJ3JGLlZdS+eoUAoyNtQ eHUT24iAInTSQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Thomas Huth , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.12 49/75] hw/display/qxl: Fix mono cursor validation that can read past a cursor chunk Date: Sun, 12 Jul 2026 07:15:07 +0300 Message-ID: <20260712041539.108341-49-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830164331158500 From: Thomas Huth qxl_render_cursor() maps the guest-provided QXLCursor object using the guest-controlled cursor->chunk.data_size. For a mono cursor, qxl_cursor() then validates the expected bitmap size against cursor->data_size, but it does not validate that the first chunk actually contains that many bytes. A guest could set cursor->data_size to the correct full mono cursor size while setting cursor->chunk.data_size to zero. In that case, cursor_set_mon= o() reads the AND/XOR masks starting at cursor->chunk.data. If the cursor object is placed at the end of the QXL RAM BAR, those reads cross the mapped RAM region and could crash the QEMU process (e.g. under ASan). Fix it by double-checking cursor->chunk.data_size for the correct size. This patch is based on the suggested changes by the reporter in the bug ticket. Reported-by: huntr bubble Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3646 Signed-off-by: Thomas Huth Acked-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260630101022.379057-1-thuth@redhat.com> Signed-off-by: Philippe Mathieu-Daud=C3=A9 (cherry picked from commit 0e51b71c7b7706923536c1f7923cace82877932b) Signed-off-by: Michael Tokarev diff --git a/hw/display/qxl-render.c b/hw/display/qxl-render.c index c6a9ac1da10..1fe63b6f5ca 100644 --- a/hw/display/qxl-render.c +++ b/hw/display/qxl-render.c @@ -272,9 +272,11 @@ static QEMUCursor *qxl_cursor(PCIQXLDevice *qxl, QXLCu= rsor *cursor, case SPICE_CURSOR_TYPE_MONO: /* Assume that the full cursor is available in a single chunk. */ size =3D 2 * cursor_get_mono_bpl(c) * c->height; - if (size !=3D cursor->data_size) { - fprintf(stderr, "%s: bad monochrome cursor %ux%u with size %u\= n", - __func__, c->width, c->height, cursor->data_size); + if (size !=3D cursor->data_size || cursor->chunk.data_size < size)= { + qxl_set_guest_bug(qxl, "%s: bad monochrome cursor %ux%u" + " data_size %u chunk_size %u", + __func__, c->width, c->height, + cursor->data_size, cursor->chunk.data_size); goto fail; } and_mask =3D cursor->chunk.data; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830075; cv=none; d=zohomail.com; s=zohoarc; b=ZxB5T4+xC/GVsfhLyXqynSXxAkzcCyzaEcYTwGCcwgG5ldBTd/S/5Drf8eZlLkpqAxWUi4dRmx9drP+edhAM12DMRn5NSzt0OXXdzTteazRLphpkdzNB0HOO8xTeZEyuKh98lOKwd3t4o8n/tKKUI1zfftu1tPMFmEg73oajk0Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830075; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=icf4sj4VehuMyAs1gB4JeZm7kt7lzZd8be+F3lY+9B8=; b=UhBWoqfscoZPf2DDFBc4Ax0U4UvrKtWlS8P8BRLsojxPAO++DTOFbsz9TA9wwBMz8ms1oM03kKMANnPfB6Xwc1W0Q4ffR6g9nLfNPziqz42dPRMBFlYaLg1SV6L7RYpjli6DSbm0KLr4DuLmzrXz71zQ7AJbQWyVck4/YkxsSt0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830075839508.8766002147088; Sat, 11 Jul 2026 21:21:15 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgf-0001TR-OJ; Sun, 12 Jul 2026 00:21:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilge-0001Rk-Pn; Sun, 12 Jul 2026 00:21:04 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgd-00074C-69; Sun, 12 Jul 2026 00:21:04 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E13191C0C0D; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 210793EB96D; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 8ADED1341D; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=2ZISP6v2jbn29AWFCGr+JsNW11hGlzIZ1/YbC/iUG2s=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ZJ6jfbqjN3SLrFSwA6hqpOphcEPFAYmJtvSJkdo+V47vDxbSAD9nCOyEyEOjybubE yIgqaoZoZ+KMBxiOuruGGndy2uWzw44w4+EL/hulmDIl27t8zEsorH5cXqCyCv+bY/ +VjiwgZvouZQCvlFNmTstp+q3+Ncx1OG0l3ZzRFiTUoyoLx6g56rEg7/OtSAnmecDT J7fs6n0y0f/ouavTuyNtxYUctqNl32jhU/42ifbXMQ35HTBEXZx2FE8w6bq2z7LXHb GQ2ZXWDUqqemhBByxksbJ7uWT9sdfZ5aoUVej8uRWgMWvUuIiDFMq0rx1TI9d9BcbB 3kaIYbb3XFtzQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, lizhaoxin04 , Miao Kezhan , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-10.0.12 50/75] vdpa: fix use-after-free of vqs in vhost_vdpa_device_unrealize Date: Sun, 12 Jul 2026 07:15:08 +0300 Message-ID: <20260712041539.108341-50-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830078019158500 Content-Type: text/plain; charset="utf-8" From: lizhaoxin04 vhost_vdpa_device_unrealize() frees s->dev.vqs before vhost_dev_cleanup(), but vhost_dev_cleanup() still accesses hdev->vqs while tearing down virtqueues. This leads to a use-after-free and may crash QEMU with SIGSEGV during vDPA hot-unplug. Save the vqs pointer in a local variable, call vhost_dev_cleanup(), and free it afterward. This matches the cleanup pattern used by vhost-scsi. Fixes: b430a2bd23 ("vdpa: add vdpa-dev support") Co-developed-by: Miao Kezhan Signed-off-by: Li Zhaoxin Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-ID: <20260622100145.18924-1-lizhaoxin04@baidu.com> (cherry picked from commit e03463812e74d1befc8d7f6f158eca531e2d6406) Signed-off-by: Michael Tokarev diff --git a/hw/virtio/vdpa-dev.c b/hw/virtio/vdpa-dev.c index a7e73b1c992..ee228af66f2 100644 --- a/hw/virtio/vdpa-dev.c +++ b/hw/virtio/vdpa-dev.c @@ -173,6 +173,7 @@ static void vhost_vdpa_device_unrealize(DeviceState *de= v) { VirtIODevice *vdev =3D VIRTIO_DEVICE(dev); VhostVdpaDevice *s =3D VHOST_VDPA_DEVICE(vdev); + struct vhost_virtqueue *vqs =3D s->dev.vqs; int i; =20 virtio_set_status(vdev, 0); @@ -184,8 +185,8 @@ static void vhost_vdpa_device_unrealize(DeviceState *de= v) virtio_cleanup(vdev); =20 g_free(s->config); - g_free(s->dev.vqs); vhost_dev_cleanup(&s->dev); + g_free(vqs); g_free(s->vdpa.shared); qemu_close(s->vhostfd); s->vhostfd =3D -1; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830265; cv=none; d=zohomail.com; s=zohoarc; b=cO/u7T1FTqQYNNnLdXyeEB7Vfn2yypjuWzYgGoLfgCkDvdvfn6Cdhhx8puUfGTlI2ly/BJCMBypQrHYfqvCmX3xxNpL6em909TiqljlM+PunfJ1ryP4oz9t6TYUJsogzMUY5WIyPZ+MkJ4IdyFdK84W2mXCnW0ZbJC4cZ2g+VYU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830265; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=1z4R1qe/Rjey+ZMEDimyCVCxzwKbfcT3lUItLj2o8Tk=; b=DMfA+c9PWkcHKNu1sDFwVlRnnfG5ejn9OvYBO/JVNA3vPG5kIAWmnU7m+JS+Lo49iFnPK9biExsRbAF4DZMKcmgEQMlNZxFSzPv5oid4eC7zgTTEa32Hc9fqbNXL2Q+TJP0218Za8gLP72tfWYKhsCM1LxnfMpG6OtYtokMIfuw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830265179987.9861970016003; Sat, 11 Jul 2026 21:24:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgh-0001Zf-V0; Sun, 12 Jul 2026 00:21:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgf-0001Tb-Me; Sun, 12 Jul 2026 00:21:05 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilge-00075Z-0I; Sun, 12 Jul 2026 00:21:05 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E75B21C0C0E; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 26A983EB96E; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 8D5191341F; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=M061+QEFVIGf6r7gv0s1GTPbsJs+oT8h+D5narosSDs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=qJGYiGJPXmETj8rAlXiv9HUrxsxLssQX0Ll3oOO+ksz3S4HJpCrCTdqvTamqE/p8R WyA/+//lyzEwHMtLxLigctwQjidfOGcE7Iad/6xPqjIAw3s96u/bqj9Xp2rlYTaXTX 5FZUVNkJLP/2zsFU/JcmhKKiuU703DRepRRqAx9zYprIfWbpHqfbHKVxP9kdUqE427 qZJdrw10o/JPrAMzyTWI4gLPFBJ0bSDaKRT+61EvOX5P6A3bUgGG0hNla0mBEACrkG F2ud9WL/QvGreR1YW6ZbsJJ43/dds8Pi1I94JWkyYkIuSi5m9osHAlcXNgSt7ZUeBJ 5cKJ6HkmCSPmg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "hemanshu.khilari.foss" , luc@lmichel.fr, peter.maydell@linaro.org, hemanshu_dev@proton.me, Michael Tokarev Subject: [Stable-10.0.12 51/75] hw/core/qdev-clock: Fix potential null pointer dereference Date: Sun, 12 Jul 2026 07:15:09 +0300 Message-ID: <20260712041539.108341-51-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830266901158500 Content-Type: text/plain; charset="utf-8" From: "hemanshu.khilari.foss" qdev_get_clocklist() function returns a pointer to the NamedClockList struct. This function is called in qdev_alias_clock() and the returned pointer is immediately dereferenced without a null check. Passing a clock name that doesn't exist to qdev_get_clocklist() is a programming error, and so this change is not fixing a bug, only making the reporting of that programming error a bit more helpful and bringing it in to line with qdev_get_clock_in() and qdev_get_clock_out(). Cc: luc@lmichel.fr Cc: peter.maydell@linaro.org Cc: hemanshu_dev@proton.me Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/2342 Signed-off-by: hemanshu.khilari.foss Message-id: 20260531153354.88909-2-hemanshu.khilari.foss@gmail.com Reviewed-by: Luc Michel Reviewed-by: Peter Maydell Signed-off-by: Peter Maydell (cherry picked from commit 7913b3b9463ffb4078d33c7ddaeacd1bb38aae3e) Signed-off-by: Michael Tokarev diff --git a/hw/core/qdev-clock.c b/hw/core/qdev-clock.c index dacafa4e036..968cf04e51d 100644 --- a/hw/core/qdev-clock.c +++ b/hw/core/qdev-clock.c @@ -157,7 +157,14 @@ Clock *qdev_alias_clock(DeviceState *dev, const char *= name, DeviceState *alias_dev, const char *alias_name) { NamedClockList *ncl =3D qdev_get_clocklist(dev, name); - Clock *clk =3D ncl->clock; + Clock *clk; + + if (!ncl) { + error_report("Can not find clock '%s' for device type '%s'", + name, object_get_typename(OBJECT(dev))); + abort(); + } + clk =3D ncl->clock; =20 ncl =3D qdev_init_clocklist(alias_dev, alias_name, true, ncl->output, = clk); =20 --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830245; cv=none; d=zohomail.com; s=zohoarc; b=T5Y6+6jKtYj7B3IYl+SZrsguqOQzNhvQGCC+mIeDQ+Z26H0V3EPAwmfgrgrIxUg6uqh1ieqTqkdNvQaavuXCpdbO0h8rOyn36FouhWN0nlLf4lGCJlZ43mxJRqx5l7HZkbRLtUeoCggvxefAO6hPFKXan2wTevD2fnEK6S8jxQQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830245; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wpSl2NjZ4mHVzTVbSNfcy1AtHyrgue7mu3vcIlPIBCE=; b=Bi5qwKvMRhv+lWjWZyDtoiNCHGDWx4W0YixmsBf25yU8toBlCcWjhzaaZldb0eMpRv9zlLEEZ2j8HB0zfs3FXoloA0Rt89rDa3BuwigVf0r8yDikVFMvL/xVQSuWzc+nv2YypRcwif3JN4DvIscB7dhas6dezYDUNqYFnfIbBbA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830245853802.2446977155439; Sat, 11 Jul 2026 21:24:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgj-0001fs-A0; Sun, 12 Jul 2026 00:21:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgh-0001bx-WA; Sun, 12 Jul 2026 00:21:08 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgg-00075q-9I; Sun, 12 Jul 2026 00:21:07 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id EC4611C0C0F; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 2C2BD3EB96F; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 8F9CE13421; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=7HMKc60spAKEu7etDQ7jsCDcdQ3mD5HIQYRCuhKKk/o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Jh2VX2Ka82tMM27v7uZ5a7vLlDsqy0PWg/7Hb66EaDRq2bEfmVRvFhhOXdTh24mqm 8sO5rWADgLFRfWf9dbfesguJuDiNhdAGEKovluEnRMXqTanI+tnSVkuVAJl4diaOaa 7eBKi5QHv4Knq5tinhl3/sNj/07rsymlxHKQ+YotdHMl5xlaiNF6UqTBVLfu86pSYs 84p5pncda8T7mEX7d2MF+S5tncHQsN2t2VGtCoDHMD5fbag5sigSKbYZaRrHhpQ3aM HzoDJpX01Dd1pZlcMSbcuLckS07mn5Im80LvKlHyNIsAAnCtYMD4A/8becf0iwOeNy SHptkW+Tyj75Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Sanjeeva Yerrapureddy , Akihiko Odaki , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.12 52/75] hw/net: fix e1000e/igb ip_len inflation by Ethernet minimum-frame padding Date: Sun, 12 Jul 2026 07:15:10 +0300 Message-ID: <20260712041539.108341-52-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830246576158500 From: Sanjeeva Yerrapureddy When a guest transmits a short Ethernet frame, iov_size() returns the padded wire length including any bytes added to reach the Ethernet minimum frame size of 60 bytes. net_tx_pkt_rebuild_payload() uses this inflated size as payload_len. net_tx_pkt_update_ip_hdr_checksum() then overwrites the IPv4 Total Length field with payload_len + l3_hdr_len, inflating it by the padding. The receiver interprets Ethernet padding as IP payload, producing a malformed packet. Fix by removing the ip_len write from net_tx_pkt_update_ip_hdr_checksum() so it only recomputes the checksum, and moving the ip_len assignment into net_tx_pkt_update_ip_checksums() where it is only performed for TSO (where ip_len must be derived from payload_len since the guest sets ip_len=3D0 per Intel 82574 datasheet =C2=A77.3.4 for super-packets the host will segment). Both e1000e and igb already call net_tx_pkt_update_ip_hdr_checksum() from their IXSM paths, so both are corrected by this single common- layer change. Signed-off-by: Sanjeeva Yerrapureddy Reivewed-by: Akihiko Odaki Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-ID: <20260629-net-tx-pkt-ip-length-padding-v5-1-16760e30252e@gmail.= com> Signed-off-by: Philippe Mathieu-Daud=C3=A9 (cherry picked from commit 9e41b5d22aeb942ad6ecc3174504ff645a10da6a) Signed-off-by: Michael Tokarev diff --git a/hw/net/net_tx_pkt.c b/hw/net/net_tx_pkt.c index 903238dca24..b134348fe80 100644 --- a/hw/net/net_tx_pkt.c +++ b/hw/net/net_tx_pkt.c @@ -93,9 +93,6 @@ void net_tx_pkt_update_ip_hdr_checksum(struct NetTxPkt *p= kt) uint16_t csum; assert(pkt); =20 - pkt->l3_hdr.ip.ip_len =3D cpu_to_be16(pkt->payload_len + - pkt->vec[NET_TX_PKT_L3HDR_FRAG].iov_len); - pkt->l3_hdr.ip.ip_sum =3D 0; csum =3D net_raw_checksum(pkt->l3_hdr.octets, pkt->vec[NET_TX_PKT_L3HDR_FRAG].iov_len); @@ -117,7 +114,9 @@ void net_tx_pkt_update_ip_checksums(struct NetTxPkt *pk= t) =20 if (gso_type =3D=3D VIRTIO_NET_HDR_GSO_TCPV4 || gso_type =3D=3D VIRTIO_NET_HDR_GSO_UDP) { - /* Calculate IP header checksum */ + /* Set ip_len and calculate IP header checksum */ + pkt->l3_hdr.ip.ip_len =3D cpu_to_be16(pkt->payload_len + + pkt->vec[NET_TX_PKT_L3HDR_FRAG].iov_len); net_tx_pkt_update_ip_hdr_checksum(pkt); =20 /* Calculate IP pseudo header checksum */ --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830283; cv=none; d=zohomail.com; s=zohoarc; b=Y/Ipyg8JoTB5o2HhvnC6Z1sSZMgjlInhpoZjG0FPqUunZOL2yy+O996MtKKjcUDR2+pkcDyKF7/f+pMmUtMsOypUdK/iU1j/kibpfIJdtHGBIbnr+Lh2JnUpulqRK8MMbFsaZXNR121qF5jG653riqhlmazr/kiYA2y4m+jStLU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830283; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9bIhlH5SMRA+2s9c3dpyeU4v6ukJ7Xyr9MUnRIKP4wg=; b=D0LTQFwxmQvplhlJiIHjalV0ZcJGfWfWpW6cQfm8oTfx51Je9Ef0cZSbIuh2tkhFchdOlgM9Uy9jnZtgKHxZhCheN/+tIxXtYQUFjRf4zWqS3PoZQ8qdoPwTJWyYiLATXdFBTHeM97x81/bp5rKebFbnAO1pEMcZEIpGgNmv6do= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830283422468.0045505782289; Sat, 11 Jul 2026 21:24:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilgk-0001nU-Ny; Sun, 12 Jul 2026 00:21:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgj-0001gO-CY; Sun, 12 Jul 2026 00:21:09 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilgh-000761-JZ; Sun, 12 Jul 2026 00:21:09 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id F1D7D1C0C10; Sun, 12 Jul 2026 07:16:21 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 30CCE3EB970; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 921CC13423; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829781; bh=GGl6GRvdpGpHwh79NUY1VdcPFATPO+2uyHh7V8lOcJw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ROj06CfWlM1/F6Sh1t4ihFA6eG6L6PYHUYO+CCZOx73H3W4dUJvMjp33M5RQtyR13 KHSWOsVxyw0BaPWv84+QtTivEGglxS1MJEOdp07uHJBG5AH3VWEtBJAKZKyd1pPdO2 UPBBSKg20JvfLhyUnnG2DqcVNvjS5vleDDk9pJdbKughhKRI7Jqpsp2JAalLEaNxcu kx5zy/TxIcMT7wNg6wpQr6JaM1290bWHHcJC8SthEFq6mjcUfEIZ23CJjFce8jxeTn vUpKIKQLKnwdBT0ryNRticu6f5ih274h3jabPfVezFnXim7OfC09oE7yvo/BpZLwt8 pTlJYyNyo2VxA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richard Henderson , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.12 53/75] accel/tcg: Use TLB_FORCE_SLOW not TLB_MMIO for user-only plugins Date: Sun, 12 Jul 2026 07:15:11 +0300 Message-ID: <20260712041539.108341-53-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830284625158500 From: Richard Henderson In 6d03226b422 we set TLB_MMIO to a non-zero value for user-only so that we could return a non-zero value from probe_* functions so that we could force callers like Arm SVE vector moves to use the slow path rather than direct access. All for the sake of exposing these accesses to plugins. Back then, TLB_FORCE_SLOW did not exist, so TLB_MMIO seemed like a reasonable solution. However, user-only doesn't really have MMIO and this has knock-on effects, like forcing Arm SVE first-fault vector loads to stop. Better to use TLB_FORCE_SLOW as a more exact trigger for plugins. Cc: qemu-stable@nongnu.org Fixes: 6d03226b422 ("plugins: force slow path when plugins instrument memor= y ops") Acked-by: Alex Benn=C3=A9e Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Richard Henderson Message-ID: <20260702171057.47998-1-richard.henderson@linaro.org> (cherry picked from commit b79a9b6e5b5657534615dd8e574d58305e16841c) (Mjt: backport to 10.0.x, move changes from include/exec/tlb-flags.h to cpu= -all.h across v10.0.0-145-g4d43552abe "exec/cpu-all: extract tlb flags defines to= exec/tlb-flags.h" and adjust for lack of subsequent changes in this area) Signed-off-by: Michael Tokarev diff --git a/accel/tcg/user-exec.c b/accel/tcg/user-exec.c index 2322181b151..b3a2b0697ef 100644 --- a/accel/tcg/user-exec.c +++ b/accel/tcg/user-exec.c @@ -807,7 +807,7 @@ static int probe_access_internal(CPUArchState *env, vad= dr addr, if (page_flags & acc_flag) { if (access_type !=3D MMU_INST_FETCH && cpu_plugin_mem_cbs_enabled(env_cpu(env))) { - return TLB_MMIO; + return TLB_FORCE_SLOW; } return 0; /* success */ } @@ -842,7 +842,7 @@ void *probe_access(CPUArchState *env, vaddr addr, int s= ize, =20 g_assert(-(addr | TARGET_PAGE_MASK) >=3D size); flags =3D probe_access_internal(env, addr, size, access_type, false, r= a); - g_assert((flags & ~TLB_MMIO) =3D=3D 0); + g_assert((flags & ~TLB_FORCE_SLOW) =3D=3D 0); =20 return size ? g2h(env_cpu(env), addr) : NULL; } diff --git a/include/exec/cpu-all.h b/include/exec/cpu-all.h index 47b14446b8f..808f79663a4 100644 --- a/include/exec/cpu-all.h +++ b/include/exec/cpu-all.h @@ -105,12 +105,14 @@ CPUArchState *cpu_copy(CPUArchState *env); static inline int cpu_mmu_index(CPUState *cs, bool ifetch); =20 /* - * Allow some level of source compatibility with softmmu. We do not - * support any of the more exotic features, so only invalid pages may - * be signaled by probe_access_flags(). + * Allow some level of source compatibility with softmmu. + * Invalid is set when the page does not have requested permissions. + * MMIO is set when we want the target helper to use the functional + * interface for load/store so that plugins see the access. */ #define TLB_INVALID_MASK (1 << (TARGET_PAGE_BITS_MIN - 1)) -#define TLB_MMIO (1 << (TARGET_PAGE_BITS_MIN - 2)) +#define TLB_FORCE_SLOW (1 << (TARGET_PAGE_BITS_MIN - 2)) +#define TLB_MMIO 0 #define TLB_WATCHPOINT 0 =20 static inline int cpu_mmu_index(CPUState *cs, bool ifetch) --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830263; cv=none; d=zohomail.com; s=zohoarc; b=RHiBmEhjupasjBg+CbWtzyo5FXuXf0q+RZjudZFEQTzQcHPQnn0H7C7NGMMlq7nHckdbz45OQBys4JNmfIoIhcTgHsmVW2CtSaRSROri8ibUTmqh+OG12F7+PmkvteKVKg70Ezr39TXLWRRyUj+/mRSp/MFsZj8GnZz8VxWCMN0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830263; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3tL9vxGTc86g1Pvxl5l/55iGpe2ZTCxTcRI5YyLv02w=; b=hbhc4U6JHMmmRHcaY/Ii0K50yNicrOmqPmcXg/0bcv+D6eSsCEJKgaSYhMq0BBo+tewWZk/PE5Al2j84NJMACdOOQpZE0s4Tqqwrn707rmM1YmAvc88UtN4c88qLMxxpBMHuzlVw1jjXx0TQqF88GS6KwmwUv5UwY+RRPDBsIq0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830263017329.09094127019716; Sat, 11 Jul 2026 21:24:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilhA-0003nR-AZ; Sun, 12 Jul 2026 00:21:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilh5-0003bb-UA; Sun, 12 Jul 2026 00:21:33 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilh3-00076e-KR; Sun, 12 Jul 2026 00:21:31 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 0257F1C0C11; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 35F733EB971; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 94C8013425; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=cwIa/Y6MQ+f2XSMbWfn7AwAYmvPWe5rUrTWJr/pt4XU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=mHEhm9QSigCcOH3TgKD2580TE4H/EBnusmXf1AGmT1a/QFgN5qiBl3s3uRzvlB0jL gvehv9WsFq0R86oR5lWJEwA+MDPWOefQJNdzmZlSLaBboz8MkDNM+ZZNq9Wm+8dDZS E0+AEQYY/P/6vj7Osumlwu/7FWjh3xrE76HykuOE2sKxVi471olo0dAL2f8NIwovoV suGVn4NrAGuEZFMdwR1RqT8L76548M8wNBpBK8fNEH4DHHnOoyNl8HmHKx0hSGigZs 0HK/Kose5u5luOh1yPEAuuaZqsfa5HalbRimR8sd0M3i6oyVX2JXg6NEWKRGmLAhYa Z3nt9P6eXeE4A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Ilya Leoshkevich , Alex Crichton , Ulrich Weigand , Richard Henderson , Pierrick Bouvier , Michael Tokarev Subject: [Stable-10.0.12 54/75] accel/tcg: Make PageFlagsNodes' start and last immutable Date: Sun, 12 Jul 2026 07:15:12 +0300 Message-ID: <20260712041539.108341-54-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830264757158500 Content-Type: text/plain; charset="utf-8" From: Ilya Leoshkevich page_check_range() may race with pageflags_set_clear() as follows: T1 T2 ------------------------------------- -------------------------------- p =3D pageflags_find(start, last= ); interval_tree_remove(&p->itree, ...); p->itree.start =3D last + 1; if (start < p->itree.start) { ret =3D false; interval_tree_insert(&p->itree, ...); leading to errors like fail indirect write 0x72f0a659aff0 (Bad address) in vma-pthread test. I am able to reliably reproduce this on a machine with 32 SMT threads as follows in about 25 seconds: jobs=3D32; \ seq "$jobs" | \ time -p parallel \ --jobs=3D"$jobs" \ --halt=3Dnow,done=3D1 \ --ungroup \ ' _=3D{}; while ./qemu-s390x tests/tcg/s390x-linux-user/vma-pthread; = do printf .; done ' Also wasmtime project reported a similar failure pattern in their CI [1] with a similar reproducer [2]. There are other races like this. In general, region bounds mutating underneath the reader are very hard to reason about. So fix this by preventing mutations and creating copies instead. Use RCU guards in readers to avoid uses-after-frees. Now, when the reader finds a node, it may fearlessly access its fields and be certain that at some point in time the respective region had the respective bounds and permissions. The downside is slightly more expensive mprotect(), but complexity reduction is worth it. Lockless field accesses should probably be wrapped in qatomic_read(), but this is a pre-existing issue, so do not change it here. [1] https://github.com/bytecodealliance/wasmtime/issues/10000 [2] https://gist.github.com/alexcrichton/f14f23a892ffb9df2522754572d51b1c Cc: qemu-stable@nongnu.org Reported-by: Alex Crichton Reported-by: Ulrich Weigand Fixes: 67ff2186b0a4 ("accel/tcg: Use interval tree for user-only page track= ing") Signed-off-by: Ilya Leoshkevich Reviewed-by: Richard Henderson Reviewed-by: Pierrick Bouvier Signed-off-by: Richard Henderson Message-ID: <20260706165445.57418-2-iii@linux.ibm.com> (cherry picked from commit e03b7dac65d96d7d9b34bb88803029cf5ec7e4a9) (Mjt: context fix for 10.0.x for lack of v10.1.0-1315-gf55fc1c092 "accel/tcg: Add clear_flags argument to page_set_flags") Signed-off-by: Michael Tokarev diff --git a/accel/tcg/user-exec.c b/accel/tcg/user-exec.c index b3a2b0697ef..b1ae2b832d9 100644 --- a/accel/tcg/user-exec.c +++ b/accel/tcg/user-exec.c @@ -222,13 +222,16 @@ void page_dump(FILE *f) =20 int page_get_flags(target_ulong address) { - PageFlagsNode *p =3D pageflags_find(address, address); + PageFlagsNode *p; + + RCU_READ_LOCK_GUARD(); =20 /* * See util/interval-tree.c re lockless lookups: no false positives but * there are false negatives. If we find nothing, retry with the mmap * lock acquired. */ + p =3D pageflags_find(address, address); if (p) { return p->flags; } @@ -327,15 +330,15 @@ static void pageflags_create_merge(target_ulong start= , target_ulong last, =20 if (prev) { if (next) { - prev->itree.last =3D next->itree.last; + pageflags_create(prev->itree.start, next->itree.last, flags); g_free_rcu(next, rcu); } else { - prev->itree.last =3D last; + pageflags_create(prev->itree.start, last, flags); } - interval_tree_insert(&prev->itree, &pageflags_root); + g_free_rcu(prev, rcu); } else if (next) { - next->itree.start =3D start; - interval_tree_insert(&next->itree, &pageflags_root); + pageflags_create(start, next->itree.last, flags); + g_free_rcu(next, rcu); } else { pageflags_create(start, last, flags); } @@ -405,8 +408,8 @@ static bool pageflags_set_clear(target_ulong start, tar= get_ulong last, if (set_flags !=3D merge_flags) { if (p_start < start) { interval_tree_remove(&p->itree, &pageflags_root); - p->itree.last =3D start - 1; - interval_tree_insert(&p->itree, &pageflags_root); + pageflags_create(p_start, start - 1, p_flags); + g_free_rcu(p, rcu); =20 if (last < p_last) { if (merge_flags) { @@ -428,11 +431,11 @@ static bool pageflags_set_clear(target_ulong start, t= arget_ulong last, } if (last < p_last) { interval_tree_remove(&p->itree, &pageflags_root); - p->itree.start =3D last + 1; - interval_tree_insert(&p->itree, &pageflags_root); + pageflags_create(last + 1, p_last, p_flags); if (merge_flags) { pageflags_create(start, last, merge_flags); } + g_free_rcu(p, rcu); } else { if (merge_flags) { p->flags =3D merge_flags; @@ -453,8 +456,8 @@ static bool pageflags_set_clear(target_ulong start, tar= get_ulong last, if (set_flags =3D=3D p_flags) { if (start < p_start) { interval_tree_remove(&p->itree, &pageflags_root); - p->itree.start =3D start; - interval_tree_insert(&p->itree, &pageflags_root); + pageflags_create(start, p_last, p_flags); + g_free_rcu(p, rcu); } if (p_last < last) { start =3D p_last + 1; @@ -466,8 +469,8 @@ static bool pageflags_set_clear(target_ulong start, tar= get_ulong last, /* Maybe split out head and/or tail ranges with the original flags. */ interval_tree_remove(&p->itree, &pageflags_root); if (p_start < start) { - p->itree.last =3D start - 1; - interval_tree_insert(&p->itree, &pageflags_root); + pageflags_create(p_start, start - 1, p_flags); + g_free_rcu(p, rcu); =20 if (p_last < last) { goto restart; @@ -476,8 +479,8 @@ static bool pageflags_set_clear(target_ulong start, tar= get_ulong last, pageflags_create(last + 1, p_last, p_flags); } } else if (last < p_last) { - p->itree.start =3D last + 1; - interval_tree_insert(&p->itree, &pageflags_root); + pageflags_create(last + 1, p_last, p_flags); + g_free_rcu(p, rcu); } else { g_free_rcu(p, rcu); goto restart; @@ -545,6 +548,8 @@ bool page_check_range(target_ulong start, target_ulong = len, int flags) return false; /* wrap around */ } =20 + RCU_READ_LOCK_GUARD(); + locked =3D have_mmap_lock(); while (true) { PageFlagsNode *p =3D pageflags_find(start, last); --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830199; cv=none; d=zohomail.com; s=zohoarc; b=nMd44OM7gEqCn/Uvjt/h0TGtbgRm/9TUsPN/YG8IVWx3shSqmOIGKoruNLEmq/6hEXP5iDozKIZ+p90xK1H0WPDbHfj5pvU7WS0bej/kSyv7dzwJ3F9ZXio6tvuS8M9ulEiN0ktESkimfmTYrvJnElLTSH76eAMYkUF6RAn7a9A= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830199; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=FgDc4SXUFwqFn4tT0Lbaq/v9POqE2H3zdFJwsm/3xgA=; b=nTPXnodu7GbFfBj4WFD1NRkPC8+yFiawWq75iykf26olSpXbxZwZC5GgYfleIk8s+oS71/dALkodPxCvO785F0XtOsyvOSR46MHU64kJZgQpz+4dAJzupmNa3A9BhM3xXWwd7SvYZemL+mKRiSjKnoxnLvWPian75Y+T+rlQvvQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830199030818.1062570225046; Sat, 11 Jul 2026 21:23:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilhA-0003oz-I4; Sun, 12 Jul 2026 00:21:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilh6-0003eS-Kh; Sun, 12 Jul 2026 00:21:33 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilh4-000774-Td; Sun, 12 Jul 2026 00:21:32 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 0964B1C0C12; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 3C6CA3EB972; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 971EF13427; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=qTlKMcp1/538st1InQe/VhKhpqkwgvvEzQtkZKNKcj4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=B9Pm5nFOvMP6FH/sTAABJ1tFPkt0tvhTrxekXGVcD18mHp7ofLG497S45Iwif9k7O HE/4GBAEbDwhEsl0FC3hPt4dSa1bl/ANT98OAlHfVZc3z81BpjVovKqGyL8jlEMosk oAv6ihSPcBXrCL1tPJYKue5y9c7OZfoNayHH8XxxIeKIptY13xzU2BrP1wEA9WEp7x GiGLuqRGKukfbxXPSSf7OjLIHXISlXssbIp0ZfP8SFeiQtM57uegdlwgaMkJSX3Mkc TNSLtuHjQT3JQY9gbZt6emNyfNQNm57IVemJfV9oB/AG7ZHDXwXnnms3RydcpkNzIe 63P54yVvvmKeQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richard Henderson , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.12 55/75] tcg/loongarch64: Fix vec_val computation in tcg_target_const_match Date: Sun, 12 Jul 2026 07:15:13 +0300 Message-ID: <20260712041539.108341-55-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830200350158500 From: Richard Henderson Only use vece for a vector constant. This avoids an assertion failure in sextract64 when vece contains garbage. Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Richard Henderson (cherry picked from commit a079836005fb92eb1fee19e59654b337a41fd0ff) Signed-off-by: Michael Tokarev diff --git a/tcg/loongarch64/tcg-target.c.inc b/tcg/loongarch64/tcg-target.= c.inc index cbd7642b58a..740b7c264d6 100644 --- a/tcg/loongarch64/tcg-target.c.inc +++ b/tcg/loongarch64/tcg-target.c.inc @@ -211,12 +211,14 @@ static bool tcg_target_const_match(int64_t val, int c= t, if ((ct & TCG_CT_CONST_WSZ) && val =3D=3D (type =3D=3D TCG_TYPE_I32 ? = 32 : 64)) { return true; } - int64_t vec_val =3D sextract64(val, 0, 8 << vece); - if ((ct & TCG_CT_CONST_VCMP) && -0x10 <=3D vec_val && vec_val <=3D 0x1= f) { - return true; - } - if ((ct & TCG_CT_CONST_VADD) && -0x1f <=3D vec_val && vec_val <=3D 0x1= f) { - return true; + if (ct & (TCG_CT_CONST_VCMP | TCG_CT_CONST_VADD)) { + int64_t vec_val =3D sextract64(val, 0, 8 << vece); + if ((ct & TCG_CT_CONST_VCMP) && -0x10 <=3D vec_val && vec_val <=3D= 0x1f) { + return true; + } + if ((ct & TCG_CT_CONST_VADD) && -0x1f <=3D vec_val && vec_val <=3D= 0x1f) { + return true; + } } return false; } --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830378; cv=none; d=zohomail.com; s=zohoarc; b=HVgtMr892m9E2soG/1YDff1S3giCgNP7Pd7ajSML9niVZ2CwXFLWw8kk2ufScAxCiDlSpdhzbeFMgheUDA77JLKCXODlqaCSX2G4ljwAkuQxIIjXCttZHG9cyf1QpXnwZntCVH0EaByiP/8ODsUpS6U6eLlLhAdvQKdV+jYXNhc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830378; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=0IrLjxKP9kOIcCQJtaG/Z9Hz2Gl2jrGr0dWoIgTXkN0=; b=CCkdqGXkAUGpCxtJjCTY5ORjogLowhVghnA8811EQ35QE3BGuCNtxrb7l9gjJezexQsJGfb7uZ7hr7ebOei89wboG8EWUXBmOUxPretJa2jR6vpun+XuQgtlyGlqdQLYNOyMk0vOlqU2vOrxiNYXHWZwn3BZHGIdmqrx6ZSL4lM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830378530798.1958419300795; Sat, 11 Jul 2026 21:26:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilhD-00043A-Gt; Sun, 12 Jul 2026 00:21:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilh9-0003iy-IA; Sun, 12 Jul 2026 00:21:35 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilh7-0007BM-FK; Sun, 12 Jul 2026 00:21:34 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 0F7C11C0C13; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 41DBD3EB973; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 9978A13429; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=sYKxVmO4YQTW0XtW00B+Xbv/33ZASvJMvAu41p8l4W4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=AghFx8MG7E5q/g89epeRgoUjhOzNbpRUw2i4KqOtaZxdNoZn4o4pFy1jcZ56WAXz/ zFGv22tkYNgTZVu2TySuOybV/CIJPIzs4LLIqs+fotCmZxdjNlfu97Tw70dQq4Rvg7 fDqT5shcE8wA0mPk8+950AqDoh3UeXYbEAPxOBd0kLZ3Y/bPkv8LgZi1L4Ac+tyj9y VHoKk6vuX2WpQqujXHd6cxvj+BFoxEJA5YWar62f7LaQ3yCXzEv7Eil9EdnUeixm/7 oiKzNieMlLrhRyTezrmoL7ML10OUeM2bRynqaNVrhcRUonc31gmDv5aaI0DCMjM+CL SnrQRikpvXvqw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richard Henderson , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.12 56/75] tcg/loongarch64: Improve constraints for TCG_CT_CONST_VCMP Date: Sun, 12 Jul 2026 07:15:14 +0300 Message-ID: <20260712041539.108341-56-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830378879158500 From: Richard Henderson Use the TCGCond given to tcg_target_const_match to exactly match the supported constant. Adjust the code generation to assume this has been done -- recall that encode_*_insn contain assertions that the constants are valid. Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Richard Henderson (cherry picked from commit 911f7328e9e9de80bf6b1a4697ecf83cc3661f5f) Signed-off-by: Michael Tokarev diff --git a/tcg/loongarch64/tcg-target.c.inc b/tcg/loongarch64/tcg-target.= c.inc index 740b7c264d6..879f66f2555 100644 --- a/tcg/loongarch64/tcg-target.c.inc +++ b/tcg/loongarch64/tcg-target.c.inc @@ -213,8 +213,18 @@ static bool tcg_target_const_match(int64_t val, int ct, } if (ct & (TCG_CT_CONST_VCMP | TCG_CT_CONST_VADD)) { int64_t vec_val =3D sextract64(val, 0, 8 << vece); - if ((ct & TCG_CT_CONST_VCMP) && -0x10 <=3D vec_val && vec_val <=3D= 0x1f) { - return true; + if (ct & TCG_CT_CONST_VCMP) { + switch (cond) { + case TCG_COND_EQ: + case TCG_COND_LE: + case TCG_COND_LT: + return -0x10 <=3D vec_val && vec_val <=3D 0x0f; + case TCG_COND_LEU: + case TCG_COND_LTU: + return 0x00 <=3D vec_val && vec_val <=3D 0x1f; + default: + return false; + } } if ((ct & TCG_CT_CONST_VADD) && -0x1f <=3D vec_val && vec_val <=3D= 0x1f) { return true; @@ -2029,28 +2039,22 @@ static void tcg_out_vec_op(TCGContext *s, TCGOpcode= opc, * Try vseqi/vslei/vslti */ int64_t value =3D sextract64(a2, 0, 8 << vece); - if ((cond =3D=3D TCG_COND_EQ || - cond =3D=3D TCG_COND_LE || - cond =3D=3D TCG_COND_LT) && - (-0x10 <=3D value && value <=3D 0x0f)) { + switch (cond) { + case TCG_COND_EQ: + case TCG_COND_LE: + case TCG_COND_LT: insn =3D cmp_vec_imm_insn[cond][lasx][vece]; tcg_out32(s, encode_vdvjsk5_insn(insn, a0, a1, value)); break; - } else if ((cond =3D=3D TCG_COND_LEU || - cond =3D=3D TCG_COND_LTU) && - (0x00 <=3D value && value <=3D 0x1f)) { + case TCG_COND_LEU: + case TCG_COND_LTU: insn =3D cmp_vec_imm_insn[cond][lasx][vece]; tcg_out32(s, encode_vdvjuk5_insn(insn, a0, a1, value)); break; + default: + g_assert_not_reached(); } - - /* - * Fallback to: - * dupi_vec temp, a2 - * cmp_vec a0, a1, temp, cond - */ - tcg_out_dupi_vec(s, type, vece, TCG_VEC_TMP0, a2); - a2 =3D TCG_VEC_TMP0; + break; } =20 insn =3D cmp_vec_insn[cond][lasx][vece]; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830306; cv=none; d=zohomail.com; s=zohoarc; b=H0XRvjMiMEj7OC7BBNQpZ9PNhtpyp6M+YEahGhChE75TDFGXCzhLiztOm7SuzjR3qnMt6MaMuenz/CYrSZzSgL3Axrnn2PAttlPskPXyrerTsGmvz/4n4FOn4jiF6pEOPQ8voM4b37nSxcc0C8dQK2B6RnPwhT+3X1zJFbo17GI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830306; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=IROE+WwAS3DQGRfoEAFn5AfA3OFraCgOE7fRPDDdvaw=; b=CGk718rW0vZTmKMizzBijI2ayslYdQ/nQpqRY+hbhPzGtvXb7zCSjep1/Pt6/81OGXr1lwaRya9bnFnwkbuxpC8Ro5NJak8lSQP8ZCGEzP/DUMlefqPxTRdE+WvPq96lfv8ozQQ8Zdpeep46b9tZt7ZH7Av73vVMIrIbPYgADnc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830306251818.2717064611852; Sat, 11 Jul 2026 21:25:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilhC-0003wo-EQ; Sun, 12 Jul 2026 00:21:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilh9-0003mG-W3; Sun, 12 Jul 2026 00:21:36 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilh8-0007BX-91; Sun, 12 Jul 2026 00:21:35 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 159F71C0C14; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 494D73EB974; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 9BD0F1342B; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=7sn6D8T0oh26eT6b9Kq8wyK87q1ciKICgmcw/SvJuVQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=P6AkqhljPYp4MHYgTFm2HU2XIcQMeY954oxORYb/QK/TvGfMReCqQskdQKjKjwCkH eNLwEy3TnpySypTqFjfTEshwEjs9bL8wOZDKVJl7AiqJJo6V4McXUaxkht4hMlHjgM ThkEcCKqMQMOivdabUI8KGjd3HK2BMQjtmLAUAhWbUWpDwO+J39aLJ/IHRe8kmqlKp /wBXTskspBd36qlMn0kwDV9tTZeTSb/R5whvV7LP+4Hi22w7VUAHAE3XvaF+aVQVkK AEdlUXs8p/S6o1xiSD7I6eGEL9UUhhIk5ZkCj0Pjq1L2rwevA+KnN2l5lFksGZV0Lm f7mAt3ydDUPMA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richard Henderson , Michael Tokarev Subject: [Stable-10.0.12 57/75] tcg/loongarch64: Fix cmp_vec with TCG_COND_NE Date: Sun, 12 Jul 2026 07:15:15 +0300 Message-ID: <20260712041539.108341-57-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830306694158500 Content-Type: text/plain; charset="utf-8" From: Richard Henderson For NE we need to invert EQ, not swap operands. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3589 Signed-off-by: Richard Henderson Message-ID: <20260623140609.645445-1-richard.henderson@linaro.org> (cherry picked from commit c56ebd64b82aa4d4a4e2144abbf9568ef593b836) Signed-off-by: Michael Tokarev diff --git a/tcg/loongarch64/tcg-target.c.inc b/tcg/loongarch64/tcg-target.= c.inc index 879f66f2555..743a6838392 100644 --- a/tcg/loongarch64/tcg-target.c.inc +++ b/tcg/loongarch64/tcg-target.c.inc @@ -2054,19 +2054,36 @@ static void tcg_out_vec_op(TCGContext *s, TCGOpcode= opc, default: g_assert_not_reached(); } - break; - } - - insn =3D cmp_vec_insn[cond][lasx][vece]; - if (insn =3D=3D 0) { - TCGArg t; - t =3D a1, a1 =3D a2, a2 =3D t; - cond =3D tcg_swap_cond(cond); - insn =3D cmp_vec_insn[cond][lasx][vece]; - tcg_debug_assert(insn !=3D 0); + } else { + switch (cond) { + case TCG_COND_EQ: + case TCG_COND_LE: + case TCG_COND_LEU: + case TCG_COND_LT: + case TCG_COND_LTU: + insn =3D cmp_vec_insn[cond][lasx][vece]; + tcg_out32(s, encode_vdvjvk_insn(insn, a0, a1, a2)); + break; + case TCG_COND_GE: + case TCG_COND_GEU: + case TCG_COND_GT: + case TCG_COND_GTU: + insn =3D cmp_vec_insn[tcg_swap_cond(cond)][lasx][vece]; + tcg_out32(s, encode_vdvjvk_insn(insn, a0, a2, a1)); + break; + case TCG_COND_NE: + /* ne -> not(eq) */ + insn =3D cmp_vec_insn[TCG_COND_EQ][lasx][vece]; + tcg_out32(s, encode_vdvjvk_insn(insn, a0, a1, a2)); + insn =3D lasx ? OPC_XVNOR_V : OPC_VNOR_V; + tcg_out32(s, encode_vdvjvk_insn(insn, a0, a0, a0)); + break; + default: + g_assert_not_reached(); + } } } - goto vdvjvk; + break; case INDEX_op_add_vec: tcg_out_addsub_vec(s, lasx, vece, a0, a1, a2, const_args[2], true); break; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830374; cv=none; d=zohomail.com; s=zohoarc; b=gtNx0Cse/4D7ZpmDY7E2vlc+fpj+TaaGs5dHRAlO68/JmBgfbdiTYfrxoT24O35PdXLeFd7LxOcM6lw3B4rBogYMzQmssOSKkk0XZxBu02GySjpgLf9HZYBlAwMSi/CRrpgCkT55+O58aKp1fwg+Ya2rv/31gKzmrQ2DMjvMBAI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830374; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4uGQG/Q++R445pIHskeTiGB6nLXWC9GnGcixUrV/Oto=; b=RlmNUqKMRxjQl3Dj0KSsC0MsYaemuzavSNXkQ8tCnUk87JyyO/IJNxS4wOxyd6vxuabgF+e03/6HMGRPo3Q+KhgvWUxu3fHQ5Xke3XY/2z5paTMucI1f8+1rdD2uo/BBCY3v/ilGvH+x+F4VvIAbaNRoIpt4zkYO4ArWwQ5fjE0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383037405498.55260960986493; Sat, 11 Jul 2026 21:26:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilhE-00044Z-7q; Sun, 12 Jul 2026 00:21:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilhC-000409-WF; Sun, 12 Jul 2026 00:21:39 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilhB-0007C3-9b; Sun, 12 Jul 2026 00:21:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 1B19C1C0C15; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 4EFB93EB975; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id 9E2161342D; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=0GuRFwIHnwinAmrPlPvfywXOhf75SQ9j6sHIL3hche0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Oie6y211My/MM/oCy1rcbohpdQK1FTbpgRpqrKuVc/mrO7CYl6UUYBez3aK0REISX W0NDM1NG0zOvLNWKMstRVsSPTHgnEvUE+HJq8HFm4oCbi0WPB2Fn1Z4yUCP0pn/xDz SGX7SLHNab2gBvpdebKrS18pRDAWt0KXxqX0hVP3YoZcryB51knSVwU8A/Foc7aGEI VsPMifYgXdOeQR03luB31mYB/XVfUKBKQasBU/XhvqJCkJm0iMJqfF+zZ86TT1tMBf /iQwpy8az+l+ptNbQiE2csNUXEHd+Oul2C8CDFaUpYHeXFHjDNYFP0exCXl2paomQR l2Pz428p8205A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Randy Schifflin , Yoshinori Sato , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.0.12 58/75] target/sh4: fixup tcg for sh4 fipr/ftrv instructions Date: Sun, 12 Jul 2026 07:15:16 +0300 Message-ID: <20260712041539.108341-58-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830374984158500 From: Randy Schifflin Fixes TCG generation for sh4 `fipr` and `ftrv` instructions. Updates the current logic for these instructions to check the FPSCR register appropriately (according to the sh4 cpu manual, `fipr` and `ftrv` are only defined when the FPSCR register PR flag is 0). Also fixes the mth/nth-vector operands by multiplying by 4 to convert to the correct floating point register offset. Signed-off-by: Randy Schifflin Reviewed-by: Yoshinori Sato Message-ID: <20260629-fixup-sh4-tcg-fpu-instructions-b4-v1-2-4356b305f971@g= mail.com> Signed-off-by: Philippe Mathieu-Daud=C3=A9 (cherry picked from commit 614a52cf549e6aefa656634b4d3fa0d4686125c6) Signed-off-by: Michael Tokarev diff --git a/target/sh4/op_helper.c b/target/sh4/op_helper.c index d70587f328d..bc3b7c44dde 100644 --- a/target/sh4/op_helper.c +++ b/target/sh4/op_helper.c @@ -485,7 +485,7 @@ void helper_ftrv(CPUSH4State *env, uint32_t n) float32 p; =20 bank_matrix =3D (env->sr & FPSCR_FR) ? 0 : 16; - bank_vector =3D (env->sr & FPSCR_FR) ? 16 : 0; + bank_vector =3D (env->sr & FPSCR_FR) ? 16 + n : n; set_float_exception_flags(0, &env->fp_status); for (i =3D 0 ; i < 4 ; i++) { r[i] =3D float32_zero; diff --git a/target/sh4/translate.c b/target/sh4/translate.c index bcdd5588183..6286862241e 100644 --- a/target/sh4/translate.c +++ b/target/sh4/translate.c @@ -377,11 +377,6 @@ static inline void gen_store_fpr64(DisasContext *ctx, = TCGv_i64 t, int reg) goto do_illegal; \ } =20 -#define CHECK_FPSCR_PR_1 \ - if (!(ctx->tbflags & FPSCR_PR)) { \ - goto do_illegal; \ - } - #define CHECK_SH4A \ if (!(ctx->features & SH_FEATURE_SH4A)) { \ goto do_illegal; \ @@ -1746,22 +1741,22 @@ static void _decode_opc(DisasContext * ctx) return; case 0xf0ed: /* fipr FVm,FVn */ CHECK_FPU_ENABLED - CHECK_FPSCR_PR_1 + CHECK_FPSCR_PR_0 { - TCGv m =3D tcg_constant_i32((ctx->opcode >> 8) & 3); - TCGv n =3D tcg_constant_i32((ctx->opcode >> 10) & 3); + TCGv m =3D tcg_constant_i32(((ctx->opcode >> 8) & 3) << 2); + TCGv n =3D tcg_constant_i32(((ctx->opcode >> 10) & 3) << 2); gen_helper_fipr(tcg_env, m, n); return; } break; case 0xf0fd: /* ftrv XMTRX,FVn */ CHECK_FPU_ENABLED - CHECK_FPSCR_PR_1 + CHECK_FPSCR_PR_0 { if ((ctx->opcode & 0x0300) !=3D 0x0100) { goto do_illegal; } - TCGv n =3D tcg_constant_i32((ctx->opcode >> 10) & 3); + TCGv n =3D tcg_constant_i32(((ctx->opcode >> 10) & 3) << 2); gen_helper_ftrv(tcg_env, n); return; } --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830443; cv=none; d=zohomail.com; s=zohoarc; b=lc5SwfTvr+58EbGPccHOUHE/mIDF31sMYLQGksJFzEabuTDFM0xFbrcTebW19++dmoV/JDTc4Rz6TojwqVezj4pkMd5Bbtbhgcn3guR+ugmNYnosD0RJC4n0UKsfvtorpHYWd8QCTh649uByksSELGMGeYJ0tQGeiYlvxkmE41A= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830443; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/HlYLjHKqZ8xwJd5AP2OoH0WCXYf+gBwSyIKZ8xJUuE=; b=MKot2uBy15CsETXfaolnLS5BTGeDsKzphoHtPalKDk/CoNZP/ARhKCgaPPi3I1i9RfNSs2ZRjBsAc4I8fSjvjf+2PtsHYg1RL9k+ybegd7noI0BHEaa6YNHce6KM0B3lqMfyQcWmr+hJd3VjBnGcVPdO7MdnEUMo3pMrwL6N3qU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383044398690.03992142668824; Sat, 11 Jul 2026 21:27:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilha-0005NN-GM; Sun, 12 Jul 2026 00:22:02 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilhY-0005HL-B8; Sun, 12 Jul 2026 00:22:00 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilhW-0007CN-M1; Sun, 12 Jul 2026 00:22:00 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 254981C0C16; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 58FEB3EB976; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id A098D1342F; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=Y82Aw5CHAWvj9oN/jQLzTCIqlkxiicEpPapUu3oe3hA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=jCZxo/Yh6oMJh308TiWUGWGh527mx4RM6vnNXEieqM3lTInXY9nH15zT7i5cobuPN oZ8+XwZ5orHLCjgvsTFp1esWLvqFRp+AMT3zd5S5ALe5ggJf3Wq5KfdNyjRgJhyvfg sZ87vkizORsYVjZ95dCmY1Bn6SMhc69RIHWg9arxdYnLbj+a4f7LIyEDpEel5jLOc+ rfgJ2DH737dTMXp/U397wUgt02ZxcoEdcoOTmGH8yu0aSNczSuHaRQn/5Ez4PshlWv csuzewdgBpiwzgVHmunotcCJTBrJpr/BS2hA7govX4V40IjjFKbtRIU39ovZkQ6QqR OEN5YFt7Tds6w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Jia Jia , Jeuk Kim , Michael Tokarev Subject: [Stable-10.0.12 59/75] hw/ufs: avoid double unref of wrapped scsi-hd Date: Sun, 12 Jul 2026 07:15:17 +0300 Message-ID: <20260712041539.108341-59-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830445339158500 Content-Type: text/plain; charset="utf-8" From: Jia Jia ufs_init_scsi_device() creates an internal scsi-hd and adds it as a child of lu->bus. qdev_realize_and_unref() then drops the construction reference, leaving the bus child ownership to tear it down. ufs_lu_unrealize() still unrefs lu->scsi_dev directly. If the UFS controller is ejected through ACPI PCI hotplug, the scsi-hd object can be finalized there and then the bus child removal RCU callback later unrefs the same object again. Keep lu->scsi_dev as a borrowed pointer and clear it during unrealize without unreffing it. Add a qtest that ejects the UFS controller through the x86 ACPI PCI hotplug eject register. On an ASAN build, the test reproduces the UAF before the fix. Fixes: 096434fea13a ("hw/ufs: Modify lu.c to share codes with SCSI subsyste= m") Cc: qemu-stable@nongnu.org Signed-off-by: Jia Jia Signed-off-by: Jeuk Kim (cherry picked from commit 90aacd5bc405cb71f77472616093f9e5ad9afd2b) (Mjt: tests/qtest/ufs-test.c: context fixup) Signed-off-by: Michael Tokarev diff --git a/hw/ufs/lu.c b/hw/ufs/lu.c index a16fe34e502..50549d35a0b 100644 --- a/hw/ufs/lu.c +++ b/hw/ufs/lu.c @@ -412,10 +412,7 @@ static void ufs_lu_unrealize(DeviceState *dev) { UfsLu *lu =3D DO_UPCAST(UfsLu, qdev, dev); =20 - if (lu->scsi_dev) { - object_unref(OBJECT(lu->scsi_dev)); - lu->scsi_dev =3D NULL; - } + lu->scsi_dev =3D NULL; } =20 static void ufs_lu_class_init(ObjectClass *oc, void *data) diff --git a/tests/qtest/ufs-test.c b/tests/qtest/ufs-test.c index ff9835735c3..eccf151c41a 100644 --- a/tests/qtest/ufs-test.c +++ b/tests/qtest/ufs-test.c @@ -33,6 +33,8 @@ #define TEST_QID 0 #define QUEUE_SIZE 32 #define UFS_MCQ_MAX_QNUM 32 +#define ACPI_PCIHP_ADDR 0xae00 +#define PCI_EJ_BASE 0x0008 =20 typedef struct QUfs QUfs; =20 @@ -634,6 +636,17 @@ static void ufstest_reg_read(void *obj, void *data, QG= uestAllocator *alloc) qpci_iounmap(&ufs->dev, ufs->bar); } =20 +static void ufstest_acpi_eject(void *obj, void *data, QGuestAllocator *all= oc) +{ + QUfs *ufs =3D obj; + QTestState *qts =3D ufs->dev.bus->qts; + + qtest_outl(qts, ACPI_PCIHP_ADDR + PCI_EJ_BASE, 1 << 4); + qtest_qmp_assert_success(qts, "{ 'execute': 'query-status' }"); + g_usleep(3 * G_USEC_PER_SEC); + qtest_qmp_assert_success(qts, "{ 'execute': 'query-status' }"); +} + static void ufstest_init(void *obj, void *data, QGuestAllocator *alloc) { QUfs *ufs =3D obj; @@ -1233,6 +1246,8 @@ static void ufs_register_nodes(void) .edge.extra_device_opts =3D "mcq=3Dtrue,mcq-maxq=3D1" }; =20 + QOSGraphTestOptions acpi_eject_test_opts =3D { .subprocess =3D true }; + add_qpci_address(&edge_opts, &(QPCIAddress){ .devfn =3D QPCI_DEVFN(4, = 0) }); =20 qos_node_create_driver("ufs", ufs_create); @@ -1250,6 +1265,10 @@ static void ufs_register_nodes(void) g_test_message("Skipping ufs io tests for ppc64"); return; } + if (!strcmp(arch, "i386") || !strcmp(arch, "x86_64")) { + qos_add_test("acpi-eject", "ufs", ufstest_acpi_eject, + &acpi_eject_test_opts); + } qos_add_test("init", "ufs", ufstest_init, NULL); qos_add_test("legacy-read-write", "ufs", ufstest_read_write, &io_test_= opts); qos_add_test("mcq-read-write", "ufs", ufstest_read_write, &mcq_test_op= ts); --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830378; cv=none; d=zohomail.com; s=zohoarc; b=C5K3sXv/qTPHvz4zAI/nsi4aSU2unppyfAiM8ds8NFKAEYRpRU+lmIVJSbsfrdm8tO3si/nlP7shas8pnKUW7Evxo6RHYSVoCMAo0xRisy3ppDWN2tJZueqTDHOpUtMNhQUNw/J3osiTVSbvWT3MJ5bdZrUqUFMHXCHfkgc+Ql0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830378; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=PqWqXzoQoDsYDL3RRzwB31i0VVYcqjvD3K+TPGNqf3s=; b=ZbAsxKvJcA0FAyjqy99z4VPI52xj5sT5nAHsRBUO74Dw9Kl31NrNuQwlJi4N1iomyM5mYS6ER8St8RIkNFQIwFXE8fw9FylQ+l2eBGmtIqdt3JmQdXnAiBUkUM9hPYa0eentFARlBRcsEovWq+RdVxW/+fsnm5sgCci5QUGRWQM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830378670695.706559897373; Sat, 11 Jul 2026 21:26:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilhc-0005Qk-MC; Sun, 12 Jul 2026 00:22:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilha-0005Ng-GE; Sun, 12 Jul 2026 00:22:02 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilhY-0007CZ-JA; Sun, 12 Jul 2026 00:22:02 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 29F321C0C17; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 5E04D3EB977; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id A318813431; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=aED+lkJdX8ThkfnqKjLoXN1kQq35jFVwegSiVR4Y/ww=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=psoHIh2eIXcgP/qXncCwHaJM6HNAdcde1BnRMYT9R98h3UounVmy5aWz23Yx0QAgx hHJw/s0HA6DQipmPMu83atPnmdxsNpjCnuEN6EBuN4gtyymBcjqs4e7mGHboIbq8pz o/7LobHlgYak1Zrx3QFmtREZUFUMY9JCEr6P8qDZFfx1R5HJil0fiQ5XyK2pbglY4c EF0DYMX/sz/AIAie0Lu13K0BFB/Tq//VCJHDe90fVSdLQeIhmb8Nm8VZFi8sl8Uqp+ 2PidjhmbOhR0uJRxiLALg23EAupId/LqzCCG4eAVwCyWh4LkTRd/MITi13R9EXNnPq +kUesLossRoPw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 60/75] hw/riscv/riscv-iommu.c: fix fault type for spa_fetch() faults Date: Sun, 12 Jul 2026 07:15:18 +0300 Message-ID: <20260712041539.108341-60-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830378941158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza Under certain circunstances, like the one described in [1] and [2], a read operation that faults will be logged as a write fault instead, and vice-versa, if they happen after the translation phase in riscv_iommu_spa_fetch(). The first problem is that we're overwriting iotlb->perm with PTE flags, so an IOMMU_RO access flag can be overwritten by whatever flags the PTE has. This will cause the wrong fault type to be thrown at the end of the function in case a fault happens. To solve the iotlb->perm overwrite we'll bit_and the original iotlb->perm access flags with the PTE access flags, preserving the original access type. So a IOMMU_RO access in a R+W PTE will result in a IOMMU_RO perm. Second, the resulting fault is received by riscv_iommu_translate(), which will then report the fault. To do that we require a transaction type (ttype). We're prioritizing checking "perm & IOMMU_RW" to set a UADDR_WR ttype, and then checking "perm & IOMMU_RO" to set UADDR_RD ttype. The issue with that is IOMMU_RO=3D1 and IOMMU_RW=3D3, thus checking "perm & IOMMU_RW" for a write then "perm & IOMMU_RO" for a read will cause the read fault to always be diagnosed as write. Make the iotlb->perm matches more strict: "perm & IOMMU_RW" must be exactly IOMMU_RW, ensuring that 'perm' has both flags. Then we can check perm & IOMMU_WO and perm & IOMMU_RO without worrying about overlapping with the RW flag. [1] https://gitlab.com/qemu-project/qemu/-/work_items/3557 [2] https://gitlab.com/qemu-project/qemu/-/work_items/3577 Fixes: 69a9ae4836 ("hw/riscv/riscv-iommu: add ATS support") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3557 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3577 Signed-off-by: Daniel Henrique Barboza Acked-by: Alistair Francis Message-ID: <20260701124034.552271-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit b18e3f0e2d0f301952ff3ae4cb73d0e9eb4ee697) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index d7ae03246fd..38af4aea906 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -269,6 +269,7 @@ static hwaddr riscv_iommu_napot_page_mask(hwaddr ppn, h= waddr addr, hwaddr *out) static int riscv_iommu_spa_fetch(RISCVIOMMUState *s, RISCVIOMMUContext *ct= x, IOMMUTLBEntry *iotlb) { + IOMMUAccessFlags pte_perm; dma_addr_t addr, base; uint64_t satp, gatp, pte; bool en_s, en_g; @@ -496,8 +497,16 @@ static int riscv_iommu_spa_fetch(RISCVIOMMUState *s, R= ISCVIOMMUContext *ctx, } /* Translation phase completed (GPA or SPA) */ iotlb->translated_addr =3D base; - iotlb->perm =3D (pte & PTE_W) ? ((pte & PTE_R) ? IOMMU_RW : IO= MMU_WO) - : IOMMU_RO; + + /* + * Do a bit_and between the PTE bits and the original + * request flags to determine the exact permission we + * need, i.e. if the original request is RO and the + * PTE has RW flags the actual perm is RO. + */ + pte_perm =3D (pte & PTE_W) ? ((pte & PTE_R) ? IOMMU_RW : IOMMU= _WO) + : IOMMU_RO; + iotlb->perm &=3D pte_perm; =20 /* Check MSI GPA address match */ if (pass =3D=3D S_STAGE && (iotlb->perm & IOMMU_WO) && @@ -1674,7 +1683,8 @@ done: if (fault) { unsigned ttype =3D RISCV_IOMMU_FQ_TTYPE_PCIE_ATS_REQ; =20 - if (iotlb->perm & IOMMU_RW) { + if ((iotlb->perm & IOMMU_RW) =3D=3D IOMMU_RW + || iotlb->perm & IOMMU_WO) { ttype =3D RISCV_IOMMU_FQ_TTYPE_UADDR_WR; } else if (iotlb->perm & IOMMU_RO) { ttype =3D RISCV_IOMMU_FQ_TTYPE_UADDR_RD; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830441; cv=none; d=zohomail.com; s=zohoarc; b=IwIjkyLtEvT6rEkYb4y2Z7eOGtbeMDTqdPEXoXMqjWVJdi3Z+ZxUzuZU3Q4G9QDNN6zOPM62suzY48oySJLjahGTr8ll1/Rh+Ipbpt5lW1fLVRYKjWB0FkeyoYtiyuqVjUayL7IIOQiGKc2OD4SL83LK61y2w4WEQIsgjzwB2m4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830441; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=1xnzwx9yUBpkVnLVSkO15EQY1/b8n7yiaOZ1Ws4m7YE=; b=GHB0fibCX4Tzyez5Sue4T+TEqriwuQFqJzQsfeyX74bqyvu34S0FhYFAxYrAX34nnj50riEPWvPD2mjErNX8Qx1mZuVKaKIWCVQy/LfhPdkFJ6bWH3LuCpYlci52Dox0RpADdOoGaU4meh4c3nBbza3j+QQt05HI/dZYmmjru8Q= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830441754291.88262291950116; Sat, 11 Jul 2026 21:27:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilhd-0005RM-NX; Sun, 12 Jul 2026 00:22:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilhb-0005PT-SE; Sun, 12 Jul 2026 00:22:03 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilhZ-0007Eb-R0; Sun, 12 Jul 2026 00:22:03 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 2E8711C0C18; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 62D173EB978; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id A577813433; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=MsFDBdw2wxYHj8Fccx6d493dz3EV1wVM9FFAttqBJ7g=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=XBrWLyyAHMBfMEUxccOpkih3S1U3Rcbno/HpiyaqEyW1PCewg0bdjyU7SRIsYtTfL pQBABIxT4+67PsfiqOzpc1m4/6i8s/EuJ2WY8pKxVwWrfB1ZxYXFnD6l1z6zaSJI26 E9ormEdvRrJwrQYIXcSCzY0mgq+l657ICf6SsTUH3pbI0vNv0SMZk6oqjNg4SS2MMY d1FjDJyXrussbw2mSC4HeBUohA7SQbzM7+lVBj/g8l4qyrx9l/WnVqOUWNITT3xt/T Oy5EhhrfoE+iXa3tOQ9jz/lqLpVKJwn2PouxKCsyfBj5SyhKuDOp9dCr/8p1zjyp/M z76nfoBrjF3LQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Nutty Liu , Chao Liu , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 61/75] hw/riscv/riscv-iommu.c: check for reserved PTE bits Date: Sun, 12 Jul 2026 07:15:19 +0300 Message-ID: <20260712041539.108341-61-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830443268158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza We need to fault if reserved PTE bits (60:54) are set. Fixes: 0c54acb8243d ("hw/riscv: add RISC-V IOMMU base emulation") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3554 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Nutty Liu Reviewed-by: Chao Liu Message-ID: <20260701121111.537654-2-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit c1d5ec3a2f4bbc9fdc120ba5697e8ad89e682e45) (Mjt: PTE_RESERVED was a constant in 10.0.x, not a macro) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index 38af4aea906..ca2c6f93572 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -456,6 +456,8 @@ static int riscv_iommu_spa_fetch(RISCVIOMMUState *s, RI= SCVIOMMUContext *ctx, =20 if (!(pte & PTE_V)) { break; /* Invalid PTE */ + } else if (pte & PTE_RESERVED) { + break; /* Reserved PTE bits set */ } else if (!(pte & (PTE_R | PTE_W | PTE_X))) { base =3D PPN_PHYS(ppn); /* Inner PTE, continue walking */ } else if ((pte & (PTE_R | PTE_W | PTE_X)) =3D=3D PTE_W) { --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830307; cv=none; d=zohomail.com; s=zohoarc; b=jeNFs7HMgcvO0DcWIPaH+JXjx7bu9Mnekjnd45trggppmrsyRhmbitr87HS3utphts/m6RiqLu8+NWhW/MDp+jSzc37qYJoiirYPoocLDpWrNW7ahKUDs5jPbLoUNSSgF/PLCL6eqwu6jBkC4YH6qKB1v1Ot+rQayVpMya2W40g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830307; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=NhIn+vawJX6ETpHygU24xLH5g6zAJJfTTrwysUOPHjw=; b=XBeK1IMXMcoumAgjno25VfViXQcDD4uD/HElBc4MuS18n+GeSFq7Ez3kSj1a9wdVMvs0TY/tRcHYuIxak0z71p+1nkBayW6WeOo2THLFlL5RW2KqoBOCMQbPnKjerx8/h/3wjkCZYd+2HfJqJpjzC4oBujqIvS4odDY8zifkNzA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830307081413.77885263735357; Sat, 11 Jul 2026 21:25:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilhg-0005Yl-1T; Sun, 12 Jul 2026 00:22:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilhe-0005Sy-5n; Sun, 12 Jul 2026 00:22:06 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilhc-0007FC-BO; Sun, 12 Jul 2026 00:22:05 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 348BE1C0C19; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 681563EB979; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id A7D8F13435; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=CkkvqrKkJMDykCzjeUSkvz1Eoq0QCZHXo1uQ0Sycca8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=OFi7x56iOkn2253X9uUw1k3x6jWGef53k8qz86QK+k66N2ZbjLxzzUCann8g2NSFo wMrBSCsffW8tzhE30JJXyMWimSn++boz1nNOld1JK84spqLWbre0cXl0Sm7SKWKlyq U6XXKytrC0Miu/j8g+OJSEUFwe3UVdpHpBZwF+t0W7pwvheDcB4cxXIKHwj1aK14q3 PIv2aInan3Hs7JOnDvj4zLCEnDwkzm81t6yE6bZSzItBnoA5zDuI4RMYoSU2Hiwp/W IBVeP/gsKxFl3LoioQtJZsgCuf3E5pyUCGurZydNK1yQISWWDfLV52Y2HerJjqrfvp V3FkpQZPmsCHw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 62/75] hw/riscv/riscv-iommu.c: fault for non-user PTE in G_STAGE Date: Sun, 12 Jul 2026 07:15:20 +0300 Message-ID: <20260712041539.108341-62-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830308711158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza riscv-iommu spec 1.0 says: "When checking the U bit in a second-stage PTE, the transaction is treated as not requesting supervisor privilege." We need to *always* fault in case we're on G_STAGE and PTE_U is cleared since we can't be on supervisor mode at this point. Fixes: 0c54acb8243d ("hw/riscv: add RISC-V IOMMU base emulation") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3555 Signed-off-by: Daniel Henrique Barboza Message-ID: <20260701121111.537654-4-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 9158c900ab308cbb8a70edcc7358efab7b34730e) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index ca2c6f93572..3e357c0b39c 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -474,6 +474,16 @@ static int riscv_iommu_spa_fetch(RISCVIOMMUState *s, R= ISCVIOMMUContext *ctx, break; /* Access bit not set */ } else if ((iotlb->perm & IOMMU_WO) && !ade && !(pte & PTE_D)) { break; /* Dirty bit not set */ + } else if (pass =3D=3D G_STAGE && !(pte & PTE_U)) { + /* + * riscv-iommu spec 1.0: "When checking the U bit in a + * second-stage PTE, the transaction is treated as + * not requesting supervisor privilege." + * + * I.e. we need to fault if this is a non-user PTE since + * we are always in user mode at this point. + */ + break; } else { /* Leaf PTE, translation completed. */ sc[pass].step =3D sc[pass].levels; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830301; cv=none; d=zohomail.com; s=zohoarc; b=bwXZD0f7AMra7HrH2+wEvuHX65iW5oLcQh5avOinPtxKly3t3IcO84L9ylXB4SWp5IqVNtSSXNutERy3V4uZpR+3MmXrynJZjgxEY/cIK/5kFYl6rtNRi4ojpEovorKF2fBKEhI2gAlslCjTGXocQQVQA4yXzn0mKgn4Sf93fg0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830301; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bdncqWnmMHnFG7sjN2fDkXRbF9oXvy9L2m/EwuJblDc=; b=W759V79/TN2jukldn2Zsm9kvG9pK3XtYF/wPPvfnZfyg/YMhkOsIaa23LDdh0I6aiCsz7Ju9J+Mi5XSkcxHsiR1puU6fDVPMoV/gMedisl+Zu+XrHhRGtlgNJATNPLwxQOwwOoRg2ZltpwXkVNorwDW4DMY/2JJZSQHUZnnO8y0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830301417742.724622617325; Sat, 11 Jul 2026 21:25:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiliQ-0006EV-CC; Sun, 12 Jul 2026 00:22:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wili2-0005zi-SP; Sun, 12 Jul 2026 00:22:32 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilhy-0007FW-8W; Sun, 12 Jul 2026 00:22:30 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 3C2AA1C0C1A; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 6E3793EB97A; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id AA67C13437; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=oHZsVuUaD+VJpQ0q2utAt7WKxN8bxXBK+Damo+PTnpI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=aEOD/zi29UhnmZCX/7eWAqh1vyTyn3PDZ/Mf++Wx/tJis6BdJmslWq2/KVb5Ym6kc uRsi167r2mVEA4ZdpBGr+v5uPe0qS4agl1+T73oKrRG50Ri2jiiDBOzYAm0++YcWDk ZpJV+I/dyTWSLPMV9JsoXtmiqufm1azGxDTMAMo/Scs7hQUQsTciZW+zBvXB9yFB6w 1NIPYAQXDq0/cpn1IQcCh1i7ergRGmbKbsTMAWtmrGtASGqpEszlwgW4Y9APBkjQKU 24fZGt+Ub1txhyD2JHnfh3bJ79pBL4IFL017lVI+ZZTYInbcwB6zlYvQLq0UDz09YH q6Ob0ZW60C3Lg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Nutty Liu , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 63/75] hw/riscv/riscv-iommu.c: check reserved MSI PTE basic bits Date: Sun, 12 Jul 2026 07:15:21 +0300 Message-ID: <20260712041539.108341-63-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830302679158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza We need to throw an MSI_MISCONFIGURED error when any of the reserved PTE bits (first doubleword only) are set. Fixes: Fixes: 0c54acb8243d ("hw/riscv: add RISC-V IOMMU base emulation") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3563 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Nutty Liu Message-ID: <20260629125719.679626-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 11486349ad9b8858d3f45a540fd48b7a15b2b61d) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index 3e357c0b39c..8055c6d707d 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -656,6 +656,27 @@ static MemTxResult riscv_iommu_msi_write(RISCVIOMMUSta= te *s, =20 switch (get_field(pte[0], RISCV_IOMMU_MSI_PTE_M)) { case RISCV_IOMMU_MSI_PTE_M_BASIC: + /* + * riscv-iommu spec MSI PTE basic translate mode: + * "When an MSI PTE has fields V =3D 1, C =3D 0, and M =3D 3 + * (basic translate mode), the PTE's complete format is: + * First doubleword: bit 63 C, =3D 0 + * bits 53:10 PPN + * bits 2:1 M, =3D 3 + * bit 0 V, =3D 1 + * All other bits of the first doubleword are reserved + * and must be set to zeros by software. The second + * doubleword is ignored by an IOMMU so is free for + * software to use." + * + * In other words, bits 62:54 and 9:3 of pte[0] are reserved. + */ + if (pte[0] & (GENMASK_ULL(62, 54) | GENMASK_ULL(9, 3))) { + res =3D MEMTX_DECODE_ERROR; + cause =3D RISCV_IOMMU_FQ_CAUSE_MSI_MISCONFIGURED; + goto err; + } + /* MSI Pass-through mode */ addr =3D PPN_PHYS(get_field(pte[0], RISCV_IOMMU_MSI_PTE_PPN)); =20 --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830341; cv=none; d=zohomail.com; s=zohoarc; b=GtQfbiaiAOxZbHstbF4X5CpQ1bjHfhJ0tyLlrkqFKAiScBnfCOeQYjYvDqBrOIfUy/c/6aSAuni2IVpGqQqeVtJq12aec0UGKCeSkop9nU3Gk7/7O+2Y8WINzAxh5L+e0fvkziKlLD8fxa+Z/dL1fyuQG24tAyBuYr9WjW4swdc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830341; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ZzPXWGOP4jjjUdlbld4apVyY3+dnA1foszxasUa0yVs=; b=CqZxxgLK3ilKZGcM8bg4/d+3N2IYJvPK9XR8ueYlseWmqL1Zb3VW0iaNal7BjG82xyj1kiPML1GlwntQpOaQtU1BxT9K0hJchyhIxkK7LPnerS9FKs6NIUhcYxwBhcIm+ejSDmS+zgzOKrlOxTnnAn90+ttySAuJzFdp6YwWWKo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383034112297.19892359731932; Sat, 11 Jul 2026 21:25:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiliE-00066Z-Uw; Sun, 12 Jul 2026 00:22:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wili3-0005zj-53; Sun, 12 Jul 2026 00:22:32 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilhz-0007Fy-LV; Sun, 12 Jul 2026 00:22:30 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 416D51C0C1B; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 752203EB97B; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id ACE3E13439; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=JANuhaWL2mWhp4BYpDrM0vxeLlVfhr+iERJocLJ2TDg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Gdnuf6/x5viCUqKXWU8BxFgrNBjO6HocqEYVu4LEJJc58TCT8/T4FLzp+raZcf6yv ZGJE2OiukLK7UVd5KNr/+fYizwN53Vo8nOaokoR77dqm/GOL7BDfgmvRlLGVQy63SS aGw7HM4knVHNDHvAORXts2KFW5l3VfLbjC5WYDS3682+69SzLaaE633ZPejC2khBLN H68BEfhds3cNOVgyhq5ABOZznA2JuaO0TomukRl9D1kQQJ0QyPYU4duthC/K8ISjgd K1Z/vJJXgVLwxR2uDdv9bAaBd3MvQk049G5yXdAp6ruhhVhBcQf0BHJV0Fgq7e8HzU h5EUMZoZfq7nQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Nutty Liu , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 64/75] hw/riscv/riscv-iommu-sys.c: record fault on IOMMU-generated MSI write Date: Sun, 12 Jul 2026 07:15:22 +0300 Message-ID: <20260712041539.108341-64-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830342803158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza The riscv-iommu spec requires that the IOMMU records its own generated MSI write faults. Fixes: 01c1caa9d1 ("hw/riscv/virt.c, riscv-iommu-sys.c: add MSIx support") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3572 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Nutty Liu Message-ID: <20260629165954.1018123-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 58e801f74e6a4ebd3a0cf3ab1a96e1676b263efd) (Mjt: include list context fixup in hw/riscv/riscv-iommu-sys.c) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu-sys.c b/hw/riscv/riscv-iommu-sys.c index 65b24fb07de..c40b89d3d20 100644 --- a/hw/riscv/riscv-iommu-sys.c +++ b/hw/riscv/riscv-iommu-sys.c @@ -27,6 +27,7 @@ #include "qemu/module.h" #include "qom/object.h" #include "exec/exec-all.h" +#include "target/riscv/cpu_bits.h" #include "trace.h" =20 #include "riscv-iommu.h" @@ -150,7 +151,20 @@ static void riscv_iommu_sysdev_send_MSI(RISCVIOMMUStat= eSys *s, =20 address_space_stl_le(&address_space_memory, msi_addr, msi_data, MEMTXATTRS_UNSPECIFIED, &result); - trace_riscv_iommu_sys_msi_sent(vector, msi_addr, msi_data, result); + + if (result =3D=3D MEMTX_OK) { + trace_riscv_iommu_sys_msi_sent(vector, msi_addr, msi_data, result); + } else { + /* Record an access fault error in the fault queue */ + struct riscv_iommu_fq_record ev =3D { 0 }; + RISCVIOMMUState *iommu =3D &s->iommu; + + ev.hdr =3D set_field(ev.hdr, RISCV_IOMMU_FQ_HDR_CAUSE, + RISCV_IOMMU_FQ_CAUSE_MSI_WR_FAULT); + ev.hdr =3D set_field(ev.hdr, RISCV_IOMMU_FQ_HDR_TTYPE, + RISCV_IOMMU_FQ_TTYPE_UADDR_WR); + riscv_iommu_fault(iommu, &ev); + } } =20 static void riscv_iommu_sysdev_notify(RISCVIOMMUState *iommu, diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index 8055c6d707d..9ba7cfaea6f 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -105,8 +105,7 @@ void riscv_iommu_notify(RISCVIOMMUState *s, int vec_typ= e) } } =20 -static void riscv_iommu_fault(RISCVIOMMUState *s, - struct riscv_iommu_fq_record *ev) +void riscv_iommu_fault(RISCVIOMMUState *s, struct riscv_iommu_fq_record *e= v) { uint32_t ctrl =3D riscv_iommu_reg_get32(s, RISCV_IOMMU_REG_FQCSR); uint32_t head =3D riscv_iommu_reg_get32(s, RISCV_IOMMU_REG_FQH) & s->f= q_mask; diff --git a/hw/riscv/riscv-iommu.h b/hw/riscv/riscv-iommu.h index a31aa62144f..c4d5c73aa8b 100644 --- a/hw/riscv/riscv-iommu.h +++ b/hw/riscv/riscv-iommu.h @@ -98,6 +98,7 @@ void riscv_iommu_pci_setup_iommu(RISCVIOMMUState *iommu, = PCIBus *bus, void riscv_iommu_set_cap_igs(RISCVIOMMUState *s, riscv_iommu_igs_mode mode= ); void riscv_iommu_reset(RISCVIOMMUState *s); void riscv_iommu_notify(RISCVIOMMUState *s, int vec_type); +void riscv_iommu_fault(RISCVIOMMUState *s, struct riscv_iommu_fq_record *e= v); =20 typedef struct RISCVIOMMUContext RISCVIOMMUContext; /* Device translation context state. */ --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830411; cv=none; d=zohomail.com; s=zohoarc; b=eke/56afDwTQj1A35bwQGId7WTI+FLauxpK1WEUbW6JzHn95G9VyELaItlEb5aelnXTjLDJfMVvt1DIM8p6p6Xrvb+ya+Jk6T74Wbs1zFTNI39634JCvT4KvD+1OAWr9Ic6ntzRMTzRk5Bz/9z6rx+IIKLeDS4TczsPdlXv95DM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830411; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=xECUPf+5rpSc7lMSjbJ25khV+jjg0txtE7dumdE2ggc=; b=liW54xmBvgLsUeQjAKKiKivS5FVBat4CwZUFXSl43NSHrD50SJEvXsN01wdVuppNhLDQQUUq7BDJr6LIPHHG8nDtmP/5jzND2qq1rm9QdSTwkBw5ahsgCU0xy96GkfVaXxhGN/oPnZnBb66f3uojZK5viNVz5YPZkJ5kjCqD3qU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830411898251.78517373781244; Sat, 11 Jul 2026 21:26:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wilii-0006XS-D3; Sun, 12 Jul 2026 00:23:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wili7-00062B-W8; Sun, 12 Jul 2026 00:22:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wili6-0007Hk-4Y; Sun, 12 Jul 2026 00:22:35 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 462A61C0C1C; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 7A7613EB97C; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id AF7741343B; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=y22mYGO/rUPwIWi0Va28U51rFgUaApaVa61QR2s7Eec=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Yuj30K+OIIjs29Hhhp7cSBl0QytQqWJJjQMrQqSycZGkYqrQ2zXGm//uq08hMFfaN /jVvfaqyJ3g9OvytwAqaHLIMYa+xbJrJ06HFVIPQ1P/FAIBUJxKXICD+SwHQlrhxwH bl7P9aSfprxPrpTzw6PHZx8h81/LwkOn99BJfF5ahAi3L/sN6WztNl/pZLRkfYOldb l6uZ8av4GwfG9KrnBnwWo5mLNxorwA9XyXKyPDxtgGhwf0Ve1V9W8XG0hzR99P1Ubz nlBVW3s2ujVMf9pLq9K8aaAL0zFfsY9n8wu6JO3KeWDhnDq3NwRdU+rSV8ygvT7DVp vgHe4mpIM6zWg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Chao Liu , Nutty Liu , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 65/75] hw/riscv/riscv-iommu.c: check for misaligned IOHGATP_PPN Date: Sun, 12 Jul 2026 07:15:23 +0300 Message-ID: <20260712041539.108341-65-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830413028158501 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza We must check if IOHGATP_PPN is 16kb aligned for non-bare GATP modes. Fixes: 69a9ae4836 ("hw/riscv/riscv-iommu: add ATS support") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3550 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Chao Liu Reviewed-by: Nutty Liu Message-ID: <20260702203616.1795588-2-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit bf274c54295c81aeda3835e2e0bc971f0bd57f47) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index 9ba7cfaea6f..b8120efc5ab 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -818,6 +818,21 @@ static bool riscv_iommu_validate_device_ctx(RISCVIOMMU= State *s, return false; } =20 + if (gatp !=3D RISCV_IOMMU_DC_IOHGATP_MODE_BARE) { + uint64_t iohgatp_ppn =3D get_field(ctx->gatp, + RISCV_IOMMU_DC_IOHGATP_PPN); + + /* + * One of the conditions for a misconfigured DDT entry + * according to the riscv-spec: "DC.iohgatp.MODE is not + * Bare and the root page table (address) determined by + * DC.iohgatp.PPN is not aligned to a 16-KiB boundary." + */ + if (PPN_PHYS(iohgatp_ppn) & ((1ULL << 14) - 1)) { + return false; + } + } + fsc_mode =3D get_field(ctx->satp, RISCV_IOMMU_DC_FSC_MODE); =20 if (ctx->tc & RISCV_IOMMU_DC_TC_PDTV) { --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830292; cv=none; d=zohomail.com; s=zohoarc; b=GanuAT0PIc81tt9TkaKxt8kJ1Vl5tLG/Oq2S2WSwpIfXGhQDp/RYmsFiczEmkIxVbvxQl7fjJ3xx8/7fManQfHGMGAjTDhv+E4EBqapfCGntUL4g53DrLEDcA3ljAUTPXmP9iwRPerwDztIX10eiHi4gDbiSFjI3og/T2G8fEAM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830292; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=q95zqTZBUGQKJ2X6mZvo/L3FwBE8lW2vWuDMikmyyns=; b=bZVWXm9RPux/NKun8K/FosMlf7nvqOPCp4aOOGr6/e06uYCjAYieeBOHL92Tb8CnVYXlukXWH+HJFNFHGjgbPWxCvxqqlXSkYIyWER09qQXPLmzYgz8JmvspMZBOqStstGjiOrGq9xgB7xEse1sJjPbvOLL1qz62gGhjEbreB5U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830292828505.6322053193044; Sat, 11 Jul 2026 21:24:52 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiliU-0006HO-RK; Sun, 12 Jul 2026 00:22:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wili6-000610-NU; Sun, 12 Jul 2026 00:22:35 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wili5-0007Hf-2h; Sun, 12 Jul 2026 00:22:34 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 4B8E61C0C1D; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 7F2573EB97D; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id B1EA01343D; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=gGkAMl1Z6zPv1Q5fbIBJQaI9b4jZnu2XGQ1emVPJGys=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=asd8QqvECHBCkoiV+dg/UUZCDQ/DhQD4SECEmYv9yU7udHSpEOlE7dg+2eOwcB7xB 4Krq6IC2ezw7DRL2Z9WgKCYlK63bpz9yYNFBOlVXcD2NLcr2IIK3uTxl/LhcQV6NZt pTTRSodEDgW/KJGwRAzEsA3Nfdu26MPeLUS+NyprW4tTQ4bUoZyF8rSLJRhZJMd4PR srznHmVuRpODBZZ5H1eVsbRE57aYVFuzjy4BNoDZzV4B0b6GUYjfwXaOK3KSqmMHBl NT2zeD21b1mo8zODP8Cbc/JSk1SCx8aXGdJ9WkGr6IfsyOFdEJkYyTlKGAwbyBi9mo KwTsWHLfgsexA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 66/75] hw/riscv/riscv-iommu.c: update ioval2 when faulting in spa_fetch() Date: Sun, 12 Jul 2026 07:15:24 +0300 Message-ID: <20260712041539.108341-66-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830294755158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza riscv_iommu_translate(), the only caller of riscv_iommu_spa_fetch(), will use riscv_iommu_report_fault() for all faults it detects. And it will use iotlb->translated_addr as 'iotval2' every time. At this moment we're updating iotlb->translated_addr only after a translation step is completed, meaning any fault that occur before that will have a zeroed iotlb->translated_addr, and as a result iotval2 will also be zero later on. Keep iotlb->translated_addr updated with the latest translated addr we have. Fixes: 0c54acb8243d ("hw/riscv: add RISC-V IOMMU base emulation") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3559 Signed-off-by: Daniel Henrique Barboza Acked-by: Alistair Francis Message-ID: <20260702171202.1322493-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 79616dd6e499c4eed0af534872f3ff0e3c133c04) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index b8120efc5ab..9dd2cb3715b 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -553,6 +553,14 @@ static int riscv_iommu_spa_fetch(RISCVIOMMUState *s, R= ISCVIOMMUContext *ctx, } } while (1); =20 + /* + * riscv_iommu_translate() will receive a fault and then call + * riscv_iommu_report_fault() using iotlb->translated_addr + * as iotval2. Update translated_addr it with the latest + * translated addr we have. + */ + iotlb->translated_addr =3D addr; + return (iotlb->perm & IOMMU_WO) ? (pass ? RISCV_IOMMU_FQ_CAUSE_WR_FAULT_VS : RISCV_IOMMU_FQ_CAUSE_WR_FAULT_S) : --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830332; cv=none; d=zohomail.com; s=zohoarc; b=JEZ4vt8OIeYff1lejr4NwqaRvyajE3zL/plbaXvLQ3++5l+VAxeCyq+utTqI1TXztRPFi6h6EoIhXcKxQ+/6ykLPxfpRb+Aa/kUNqOKaXOV2DksyKgP4wstrvKGkeYrdbiin/yzOMLl5d+4ZJAteUwSfBfaZKHKBiQP8ah1/naQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830332; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=qxVJkTpUKJZAPR+M+V/BwZhwwjP06bt6vcXzYvCNd8A=; b=XZ2Ekf6fk0zixptrrSoCZfWoFlZx8KLHlriG7MhRPQhup5l60XYLmfejGAYOd0cdWSt0b0FTciUJl1ytRY7N5Q2tzqWxIR6q24ydugV4nwr4ZQai4rlUmZLsGS/3NmA30oCVW9bhY4BgABFPSc7bZIcC7nCEa9/NYVKzSNYfgNQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830332978514.3005631896888; Sat, 11 Jul 2026 21:25:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiljV-00073m-W7; Sun, 12 Jul 2026 00:24:02 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wiliA-00062r-96; Sun, 12 Jul 2026 00:22:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wili8-0007JS-8K; Sun, 12 Jul 2026 00:22:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 51CC51C0C1E; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 85B6F3EB97E; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id B481A1343F; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=lpxzC36il+QnOfujvKJIboRQbnhV0Fk6x1YfYFP7tQc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TlPYZzz9RsB73u3aB2wW81EKb0XE2d1tyichSMiZaI/GHz8D3gNAI0Ieg8iYQ+bgQ GlxIkTm9ca6/+yGEdb6fpAT89tTWJwS4XIyaSBUIG9yHRuvynnHtnEPQJpH4JvU7Ia QCN5cBTOSivgvk1NcSeKYBr7vcvDLQt23JNL3ciMhiBj8hH3mtjTTQOL2BLYgH81jD 36E9Ya//jf5gUGg4oZUI2UaJ0wieW75FvLhrnji+N+z5oFZif5K3RTWgpebayscNIE 54oeTgiOsDQnOMiPiyl1F/ThXxpvTOHLXsoFCciOaJhRnpdaGte7KcDrk8oDelVlVv h0LJQs19ov0Ng== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Nutty Liu , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 67/75] hw/riscv/riscv-iommu: forbid GATE/SADE if caps.AMO_HWADD is zero Date: Sun, 12 Jul 2026 07:15:25 +0300 Message-ID: <20260712041539.108341-67-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830334781158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza When capabilities.AMO_HWADD isn't set, DC.tc.GADE and DC.tc.SADE are reserved bits and setting them throws a DDT_MISCONFIGURED error. Fixes: 0c54acb8243d ("hw/riscv: add RISC-V IOMMU base emulation") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3549 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Nutty Liu Message-ID: <20260630172110.1866951-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 6d2b9d542fe2cec17eec71bdb33e45bee8805105) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu-bits.h b/hw/riscv/riscv-iommu-bits.h index 1017d73fc6e..1446d4bdd71 100644 --- a/hw/riscv/riscv-iommu-bits.h +++ b/hw/riscv/riscv-iommu-bits.h @@ -85,6 +85,7 @@ struct riscv_iommu_pq_record { #define RISCV_IOMMU_CAP_SV57X4 BIT_ULL(19) #define RISCV_IOMMU_CAP_MSI_FLAT BIT_ULL(22) #define RISCV_IOMMU_CAP_MSI_MRIF BIT_ULL(23) +#define RISCV_IOMMU_CAP_AMO_HWAD BIT_ULL(24) #define RISCV_IOMMU_CAP_ATS BIT_ULL(25) #define RISCV_IOMMU_CAP_T2GPA BIT_ULL(26) #define RISCV_IOMMU_CAP_IGS GENMASK_ULL(29, 28) diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index 9dd2cb3715b..a7b0ab6d887 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -403,6 +403,11 @@ static int riscv_iommu_spa_fetch(RISCVIOMMUState *s, R= ISCVIOMMUContext *ctx, const bool ade =3D ctx->tc & (pass ? RISCV_IOMMU_DC_TC_GADE : RISCV_IOMMU_DC_TC_S= ADE); =20 + if (ade && !(s->cap & RISCV_IOMMU_CAP_AMO_HWAD)) { + /* GADE/SADE are reserved bits if AMO_HWAD is cleared. */ + return RISCV_IOMMU_FQ_CAUSE_DDT_MISCONFIGURED; + } + /* Address range check before first level lookup */ if (!sc[pass].step) { const uint64_t va_len =3D va_skip + va_bits; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830310; cv=none; d=zohomail.com; s=zohoarc; b=NUJX44yL72Ylp1xTOoryE3qNboVr7i4vSamGEzb50wZiAjYWskoLOtSc4kladU743DZr2XLmrqFLp/KjNfM/6pZcxksyv3r+OJxNG2ZlLg3lY6c1K9XMK58SMCObpv1E0QK/DAW+r9iteJmvkr7C9WUm8RRr73hFDnxi798himE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830310; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=M5RpQJ7vryHJL0W0o+0YFk9vWhlbjmQux1k9PO0C+Cg=; b=TreYfzFCO3p3tFjjECtoNkjPC4VvMheBOQXI+wwZWl06DabMfPCRsdlV6u9t7j5MSfvzXzZjjHA9C/nUoGPqlXaps8yedMdD+L9lc7sYWRGw3cZUln+PEAINLwB78zdZI5OKRejSG03RNvc1zeHfv+/vONE9lqoMXdsDh60BA6g= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830310128721.8282153558998; Sat, 11 Jul 2026 21:25:10 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiljs-0007nV-1x; Sun, 12 Jul 2026 00:24:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilib-0006PI-0B; Sun, 12 Jul 2026 00:23:05 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wiliY-0007M0-Cm; Sun, 12 Jul 2026 00:23:04 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 5776B1C0C1F; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 8B2383EB97F; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id B70E513441; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=SHH8SSUEZ0aYdLzJIEDv3hjtuTI4QUCllenGHZLjTHE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=EBeJFJ10rFgPDD50Jq+nAsNGwGuf8mrQEIOHYDkUSC7AKD+y4XuLnlTWvEb/FdzLl u78ohX4u24kvpWls8unbNgBP1F8ADYk39F1nGXJgMtTMPl8bflr+WBruPAf5Mz77cH QknyF6L1cznjj2YX2tY1Xmkny4WeKka5cZtG6P/m19vFMYHpgaGsJqZaZswBTrMTwn IWrkxRlGyzC83ofYa7aabee0lIvHREIx4Wn1TE/6LY2XehfCpMB+slGR4tA+7CyLVh 2gQO9+RvjjGMWXYegJt23y1XqcCMtg0Cbm4+sgLvmnz11u1pimkRy9rNkWY3Z6QmzQ Tp6Wbb+tXVZsQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Chengbo Gao , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 68/75] hw/riscv/riscv-iommu: Avoid caching PCI device IDs Date: Sun, 12 Jul 2026 07:15:26 +0300 Message-ID: <20260712041539.108341-68-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830311033158500 Content-Type: text/plain; charset="utf-8" From: Chengbo Gao PCI bus numbers may still be unassigned when QEMU initializes a PCI device's bus-master address space. For devices behind bridges, pci_bus_num() can return 0 at that point because the guest has not yet programmed the bridge Secondary Bus Number register. The RISC-V IOMMU currently stores a fixed device_id in RISCVIOMMUSpace when the address space is created. If the guest later enumerates the device on a non-zero bus, DMA translation still uses the stale device_id and may look up the wrong device context in the DDT. Store the stable PCIBus pointer and devfn in RISCVIOMMUSpace instead, and compute the device_id from the current bus number when it is needed. This keeps DMA translation and ATS invalidation in sync with guest PCI bus enumeration. Signed-off-by: Chengbo Gao Reviewed-by: Daniel Henrique Barboza Message-ID: <20260514020637.2819308-1-gaochengbo@bosc.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit ca7bac51e04fa1ad384963577fabd3a58355ae23) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index a7b0ab6d887..8e649b77752 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -46,7 +46,8 @@ struct RISCVIOMMUSpace { IOMMUMemoryRegion iova_mr; /* IOVA memory region for attached device = */ AddressSpace iova_as; /* IOVA address space for attached device = */ RISCVIOMMUState *iommu; /* Managing IOMMU device state */ - uint32_t devid; /* Requester identifier, AKA device_id */ + PCIBus *bus; /* PCI bus of the requester */ + uint8_t devfn; /* Requester identifier, AKA device_id */ bool notifier; /* IOMMU unmap notifier enabled */ QLIST_ENTRY(RISCVIOMMUSpace) list; }; @@ -71,6 +72,15 @@ struct RISCVIOMMUEntry { /* IOMMU index for transactions without process_id specified. */ #define RISCV_IOMMU_NOPROCID 0 =20 +static uint32_t riscv_iommu_space_devid(RISCVIOMMUSpace *as) +{ + uint32_t devid =3D PCI_BUILD_BDF(pci_bus_num(as->bus), as->devfn); + + /* FIXME: PCIe bus remapping for attached endpoints. */ + devid |=3D as->iommu->bus << 8; + return devid; +} + static uint8_t riscv_iommu_get_icvec_vector(uint32_t icvec, uint32_t vec_t= ype) { switch (vec_type) { @@ -1440,15 +1450,13 @@ static void riscv_iommu_ctx_put(RISCVIOMMUState *s,= void *ref) } =20 /* Find or allocate address space for a given device */ -static AddressSpace *riscv_iommu_space(RISCVIOMMUState *s, uint32_t devid) +static AddressSpace *riscv_iommu_space(RISCVIOMMUState *s, PCIBus *bus, + int devfn) { RISCVIOMMUSpace *as; =20 - /* FIXME: PCIe bus remapping for attached endpoints. */ - devid |=3D s->bus << 8; - QLIST_FOREACH(as, &s->spaces, list) { - if (as->devid =3D=3D devid) { + if (as->bus =3D=3D bus && as->devfn =3D=3D devfn) { break; } } @@ -1458,10 +1466,11 @@ static AddressSpace *riscv_iommu_space(RISCVIOMMUSt= ate *s, uint32_t devid) as =3D g_new0(RISCVIOMMUSpace, 1); =20 as->iommu =3D s; - as->devid =3D devid; + as->bus =3D bus; + as->devfn =3D devfn; =20 snprintf(name, sizeof(name), "riscv-iommu-%04x:%02x.%d-iova", - PCI_BUS_NUM(as->devid), PCI_SLOT(as->devid), PCI_FUNC(as->devi= d)); + pci_bus_num(bus), PCI_SLOT(devfn), PCI_FUNC(devfn)); =20 /* IOVA address space, untranslated addresses */ memory_region_init_iommu(&as->iova_mr, sizeof(as->iova_mr), @@ -1471,8 +1480,8 @@ static AddressSpace *riscv_iommu_space(RISCVIOMMUStat= e *s, uint32_t devid) =20 QLIST_INSERT_HEAD(&s->spaces, as, list); =20 - trace_riscv_iommu_new(s->parent_obj.id, PCI_BUS_NUM(as->devid), - PCI_SLOT(as->devid), PCI_FUNC(as->devid)); + trace_riscv_iommu_new(s->parent_obj.id, pci_bus_num(bus), + PCI_SLOT(devfn), PCI_FUNC(devfn)); } return &as->iova_as; } @@ -1797,7 +1806,7 @@ static void riscv_iommu_ats(RISCVIOMMUState *s, pid =3D get_field(cmd->dword0, RISCV_IOMMU_CMD_ATS_PID); =20 QLIST_FOREACH(as, &s->spaces, list) { - if (as->devid =3D=3D devid) { + if (riscv_iommu_space_devid(as) =3D=3D devid) { break; } } @@ -2800,8 +2809,9 @@ static IOMMUTLBEntry riscv_iommu_memory_region_transl= ate( .addr_mask =3D ~0ULL, .perm =3D flag, }; + uint32_t devid =3D riscv_iommu_space_devid(as); =20 - ctx =3D riscv_iommu_ctx(as->iommu, as->devid, iommu_idx, &ref); + ctx =3D riscv_iommu_ctx(as->iommu, devid, iommu_idx, &ref); if (ctx =3D=3D NULL) { /* Translation disabled or invalid. */ iotlb.addr_mask =3D 0; @@ -2813,8 +2823,8 @@ static IOMMUTLBEntry riscv_iommu_memory_region_transl= ate( } =20 /* Trace all dma translations with original access flags. */ - trace_riscv_iommu_dma(as->iommu->parent_obj.id, PCI_BUS_NUM(as->devid), - PCI_SLOT(as->devid), PCI_FUNC(as->devid), iommu_= idx, + trace_riscv_iommu_dma(as->iommu->parent_obj.id, PCI_BUS_NUM(devid), + PCI_SLOT(devid), PCI_FUNC(devid), iommu_idx, IOMMU_FLAG_STR[flag & IOMMU_RW], iotlb.iova, iotlb.translated_addr); =20 @@ -2862,7 +2872,7 @@ static AddressSpace *riscv_iommu_find_as(PCIBus *bus,= void *opaque, int devfn) =20 /* Find first matching IOMMU */ while (s !=3D NULL && as =3D=3D NULL) { - as =3D riscv_iommu_space(s, PCI_BUILD_BDF(pci_bus_num(bus), devfn)= ); + as =3D riscv_iommu_space(s, bus, devfn); s =3D s->iommus.le_next; } =20 --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830424; cv=none; d=zohomail.com; s=zohoarc; b=NjCEZK2lEsMfZCe/d8Z5a9xsRZMcpcvJIasLj5O62ritn42/TrrfAlJ3Rt/LhCV4uEXBDJhEXQa8+nFxqgWtjB/7FgcA4+8QgQuIvOitep6uLgPYi46oOHT2hr+nqBTDQuUXOWdzrW0QXOK/XT1ZJ8jaZyw66BM4roAyDmew+l8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830424; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=FeJi8TmbDxJheWkgZVp0GqJRaAaFBLhz4FaM/sVdKzk=; b=OHzmZ5YHWYFqBhVV2BdHbUdi0CJmoBPdBbtf/Nc8N4iBYyb/A9azYM/SmKfmLII+3c/PSfsIzcySHLcO/56EC/2LFf1LdCeXQTqFtnrktXkw4wr2HC4ef07xBVT1RklRYF99o0qya60q7Nv2z12mbw2vwMrxcfyU8syurLj4isY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830424688750.3732708792909; Sat, 11 Jul 2026 21:27:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiliW-0006KL-7O; Sun, 12 Jul 2026 00:23:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wiliD-00069j-CE; Sun, 12 Jul 2026 00:22:42 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wiliB-0007MD-NE; Sun, 12 Jul 2026 00:22:41 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 5CEB61C0C20; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 9128F3EB980; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id B980013443; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=LUsT4hMutUyFKLtzirU44K1z143A6xYWET/Tns34LWk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Nh5GTvjf7M8mC/EwOU42Yv9jAQAvA0JOcVmLy7rLkLET1NaO9MPjq1s9xBdluBpen jfTwTgjI2pihPaVdgOzvk0iulipiNdvHRSjdkIFAX84i7Rdkzwbp55OjqiZa/C4UFv bzJk6Ppio+VExPTd2IlVKbdlKPO76y1zD0gMOCWyQI/NLFpDbbykZvCJGEj6WgSJn+ BLIeagVqMh2BNMAEjr+NLGRs9O8TNlW3cPSNK05psuKuChWBciVvHsyAxh0pzjPMfh hOXHjdNpTjQ784Hn6Se+//jAK1/aR4DVVN55iLx66LuJ4d/vi3aTNckmEhJyDypKvK zkGg5QoUXmnyQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Alistair Francis , Daniel Henrique Barboza , Jim Shu , Michael Tokarev Subject: [Stable-10.0.12 69/75] hw/riscv: riscv-iommu: Don't look up DDT cache in Off and Bare modes Date: Sun, 12 Jul 2026 07:15:27 +0300 Message-ID: <20260712041539.108341-69-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830425194158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang According to the RISC-V IOMMU specification: * When ddtp.iommu_mode is set to Off, there is no DDT look-up, and an "All inbound transactions disallowed" fault (cause =3D 256) is reported for any inbound transaction. * When ddtp.iommu_mode is set to Bare, there is no DDT look-up, and the translated address is the same as the IOVA, unless the transaction type is disallowed (cause =3D 260). In the current implementation, the DDT cache is incorrectly looked up even when ddtp.iommu_mode is set to Off or Bare. This may result in unintended cache hits. Therefore, the DDT cache must not be looked up when ddtp.iommu_mode is set to Off or Bare. For other modes, software is required to issue cache invalidation commands before any inbound transactions. Signed-off-by: Frank Chang Acked-by: Alistair Francis Reviewed-by: Daniel Henrique Barboza Reviewed-by: Jim Shu Message-ID: <20251028085032.2053569-1-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit 15406cc593a76f075f23e4113b2723190e6a0d1a) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index 8e649b77752..f11698f02f0 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -1404,13 +1404,18 @@ static RISCVIOMMUContext *riscv_iommu_ctx(RISCVIOMM= UState *s, .devid =3D devid, .process_id =3D process_id, }; + unsigned mode =3D get_field(s->ddtp, RISCV_IOMMU_DDTP_MODE); =20 ctx_cache =3D g_hash_table_ref(s->ctx_cache); - ctx =3D g_hash_table_lookup(ctx_cache, &key); =20 - if (ctx && (ctx->tc & RISCV_IOMMU_DC_TC_V)) { - *ref =3D ctx_cache; - return ctx; + if (mode !=3D RISCV_IOMMU_DDTP_MODE_OFF && + mode !=3D RISCV_IOMMU_DDTP_MODE_BARE) { + ctx =3D g_hash_table_lookup(ctx_cache, &key); + + if (ctx && (ctx->tc & RISCV_IOMMU_DC_TC_V)) { + *ref =3D ctx_cache; + return ctx; + } } =20 ctx =3D g_new0(RISCVIOMMUContext, 1); --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830248; cv=none; d=zohomail.com; s=zohoarc; b=C7+PUm3mm7IoRs2BI/TaWjbHkrhJNjZA3EHGHnhjP4oP8fV9cCyt90zO85tkRhCCfyfxxT2Qxu7sS6tPX392roGnJUqANK5cmuuzvnAsHMT6XKUWjfHZpnytp+BXx66WZCBDyA46M0WE2+MNB3HHrUG4oGjG+AE9sA6cBxKX2jc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830248; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Oj5x+3hG6ddGEihy0E5ii8HBBTlPYcpbzgFsq4bUV00=; b=ZNrYoMGHbCzjKpuMwIsqusDhVWi2DM6BR1l9ybGeI19uvMIujmZaewR8hprGy4vTV/imxjabNf9NO3AS2Wlfe+foURfGeZDUu20b3cscsq2rxPGYaXNUkyjaJF16ISSJK0uGxnlkgYcSWCsO8KzDR6OZO8j4iy8Q8d1a1e/l1Vs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830248941738.8033190093469; Sat, 11 Jul 2026 21:24:08 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiliq-0006eD-JY; Sun, 12 Jul 2026 00:23:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilia-0006PH-Q9; Sun, 12 Jul 2026 00:23:05 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wiliY-0007NW-Q6; Sun, 12 Jul 2026 00:23:04 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 632A11C0C21; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 963BA3EB981; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id BC1A613445; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=DWSw3n0zgUiKquuD73IAyqoUNmyQ/BCsCpXWdxx/d0g=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=p8qg/kfmoVuP7ia6HyKRs7NiyBJw4JIqVKMQ5uXdkkcr1WKlSIkI0wWzT1gJ1Ybv6 XnJ8giNRTeXTRu5sOynMdRSPZNP/tG3HUgdUIX9bIoG2OdG87BrJVXN6pS43lHKxjr xjYlrB8RFU90CftzyhdykwItr14EDTbEGnUoiQdeFt6GuWdBlLmPoFsVt+uB1EK7OL wUzeOzU18C0TultKfVLdESiPMXauZkiL+MDDqN7PfXx3SFa21jwy75gJwAtGKm7nF/ 9Ptou0tSQtjwvEnjydSBhdp9kzpCPwqZ1Z2QS0G+L/ktEjLKSIuVGcAOVzy8RPL6vO hnRY5SPFWXPGw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 70/75] hw/riscv/riscv-iommu.c: set ftype and iova in riscv_iommu_ctx() Date: Sun, 12 Jul 2026 07:15:28 +0300 Message-ID: <20260712041539.108341-70-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830250577158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza We're hardcoding faulting type as READ, where it could very well be a write access, and we're not recording the faulting addr/iova. A note was added in the fault_type logic because I wasn't able to trivially handle a probable code repeitition it in this same patch. Something to do in a later date. Fixes: 0c54acb8243d ("hw/riscv: add RISC-V IOMMU base emulation") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3564 Signed-off-by: Daniel Henrique Barboza Message-ID: <20260701092241.307801-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit ce7fb3282756c04433274e3abcd59407f77c4923) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index f11698f02f0..4ba4164df41 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -1396,6 +1396,7 @@ static void riscv_iommu_ctx_inval(RISCVIOMMUState *s,= GHFunc func, /* Find or allocate translation context for a given {device_id, process_id= } */ static RISCVIOMMUContext *riscv_iommu_ctx(RISCVIOMMUState *s, unsigned devid, unsigned process= _id, + IOMMUAccessFlags perm, uint64_t = iova, void **ref) { GHashTable *ctx_cache; @@ -1405,6 +1406,7 @@ static RISCVIOMMUContext *riscv_iommu_ctx(RISCVIOMMUS= tate *s, .process_id =3D process_id, }; unsigned mode =3D get_field(s->ddtp, RISCV_IOMMU_DDTP_MODE); + uint32_t fault_type; =20 ctx_cache =3D g_hash_table_ref(s->ctx_cache); =20 @@ -1440,8 +1442,21 @@ static RISCVIOMMUContext *riscv_iommu_ctx(RISCVIOMMU= State *s, g_hash_table_unref(ctx_cache); *ref =3D NULL; =20 - riscv_iommu_report_fault(s, ctx, RISCV_IOMMU_FQ_TTYPE_UADDR_RD, - fault, !!process_id, 0, 0); + /* + * TODO: (1) do we need to distinguish other fault types + * for ctx fetching and (2) evaluate putting the 'fault_type' + * logic inside riscv_iommu_report_fault() - there's at + * least one other place (end of riscv_iommu_translate()) + * that does something similar. + */ + if (perm & IOMMU_RO) { + fault_type =3D RISCV_IOMMU_FQ_TTYPE_UADDR_RD; + } else { + fault_type =3D RISCV_IOMMU_FQ_TTYPE_UADDR_WR; + } + + riscv_iommu_report_fault(s, ctx, fault_type, fault, + !!process_id, iova, 0); =20 g_free(ctx); return NULL; @@ -2172,6 +2187,8 @@ static void riscv_iommu_process_dbg(RISCVIOMMUState *= s) uint64_t ctrl =3D riscv_iommu_reg_get64(s, RISCV_IOMMU_REG_TR_REQ_CTL); unsigned devid =3D get_field(ctrl, RISCV_IOMMU_TR_REQ_CTL_DID); unsigned pid =3D get_field(ctrl, RISCV_IOMMU_TR_REQ_CTL_PID); + IOMMUAccessFlags perm =3D ctrl & RISCV_IOMMU_TR_REQ_CTL_NW + ? IOMMU_RO : IOMMU_RW; RISCVIOMMUContext *ctx; void *ref; =20 @@ -2179,7 +2196,7 @@ static void riscv_iommu_process_dbg(RISCVIOMMUState *= s) return; } =20 - ctx =3D riscv_iommu_ctx(s, devid, pid, &ref); + ctx =3D riscv_iommu_ctx(s, devid, pid, perm, iova, &ref); if (ctx =3D=3D NULL) { riscv_iommu_reg_set64(s, RISCV_IOMMU_REG_TR_RESPONSE, RISCV_IOMMU_TR_RESPONSE_FAULT | @@ -2187,7 +2204,7 @@ static void riscv_iommu_process_dbg(RISCVIOMMUState *= s) } else { IOMMUTLBEntry iotlb =3D { .iova =3D iova, - .perm =3D ctrl & RISCV_IOMMU_TR_REQ_CTL_NW ? IOMMU_RO : IOMMU_= RW, + .perm =3D perm, .addr_mask =3D ~0, .target_as =3D NULL, }; @@ -2526,7 +2543,7 @@ static MemTxResult riscv_iommu_trap_write(void *opaqu= e, hwaddr addr, /* FIXME: PCIe bus remapping for attached endpoints. */ devid |=3D s->bus << 8; =20 - ctx =3D riscv_iommu_ctx(s, devid, 0, &ref); + ctx =3D riscv_iommu_ctx(s, devid, 0, IOMMU_RW, addr, &ref); if (ctx =3D=3D NULL) { res =3D MEMTX_ACCESS_ERROR; } else { @@ -2816,7 +2833,7 @@ static IOMMUTLBEntry riscv_iommu_memory_region_transl= ate( }; uint32_t devid =3D riscv_iommu_space_devid(as); =20 - ctx =3D riscv_iommu_ctx(as->iommu, devid, iommu_idx, &ref); + ctx =3D riscv_iommu_ctx(as->iommu, devid, iommu_idx, flag, addr, &ref); if (ctx =3D=3D NULL) { /* Translation disabled or invalid. */ iotlb.addr_mask =3D 0; --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830410; cv=none; d=zohomail.com; s=zohoarc; b=ZBge2TZNtpqh2VuimnP10UZHFlcCG1R6Cn19WmY8CWG55ZRXi5+ymeKiAzpgNTQ4A04PCAHZPDiAmuAY3ducN6fhGX/Vd1ZH3nH81Xwt0qdXZZ+ufRXJ/6bmHCj7oOx0OpZ98xMJ9ZGkUiMkRWw2FNw2UjnilkqbuzRyPPjA2to= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830410; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8dwDPdhT+uBTf3cnC8i2PrvsJg2soc8fSdBGF//E4LU=; b=ScFhs7LD0u+F+2TA/+XK1UlRbroJBb3euDtGAzVc2MkyKyHMi0vtav/SxbKd4zj12SJCxfem5XhS3xyXyfag3fNN3h39t5PkBIsJGta0wkyDKI8LDlJLzivJY4UoA+kplkeNJFE/XwR7D6l66sycgpECn9CjDRZ5/T/E1oiEB/g= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830410986487.2204843914436; Sat, 11 Jul 2026 21:26:50 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiljW-00073j-DU; Sun, 12 Jul 2026 00:24:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilie-0006SP-1w; Sun, 12 Jul 2026 00:23:10 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilic-0007OQ-DQ; Sun, 12 Jul 2026 00:23:07 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 683E51C0C22; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id 9B8413EB982; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id BE83C13447; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=sI8JXGq3VqxVi4Opq2z8HbORYmN7Lmcw/PF0bnI3xeI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=C4asYaPiC5elTfkKnMjYfv1epIJuz5AujAeXYjNqmlGb3AehpL9aIFzshVOa+S4Zd Po9/XYcz7npGvSxeQO3Q1L9euRCdtLDg6Y9Ibls9h8tkqSbMyh+wiCI8WKgpu7h4S6 sPu+N5sJuTgPj2cfmuHtmgLr1JWg/JRnkyo/M6IdTjKm13YrZ5ABR6qU3NDrvJKk1I HqTRj2BICpzjkG8ptykzn2G95hF6UGzwzcBkarV7D0jpZvQ8jHjgdI/a4KkauNFtYW 1PJUs6nGD4c5owaFYJ04DQx6msO5OwkxLsJLktwVLAvHUhhaE1iYOoRR2fi38cCE4D pm0lAGLnNMDoA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Akihiko Odaki , Daniel Henrique Barboza , Nutty Liu , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 71/75] hw/riscv/riscv-iommu: Fix MemoryRegion owner Date: Sun, 12 Jul 2026 07:15:29 +0300 Message-ID: <20260712041539.108341-71-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830413370158500 From: Akihiko Odaki as points to the MemoryRegion itself. s is the device that owns the MemoryRegion. Signed-off-by: Akihiko Odaki Reviewed-by: Daniel Henrique Barboza Reviewed-by: Nutty Liu Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-ID: <20251027-iommu-v1-1-0fc52a02a273@rsg.ci.i.u-tokyo.ac.jp> Signed-off-by: Alistair Francis (cherry picked from commit c497ef6739cfb44b4fdb410ad997e3d2ea506788) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index 4ba4164df41..5a7f3c783dc 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -1495,7 +1495,7 @@ static AddressSpace *riscv_iommu_space(RISCVIOMMUStat= e *s, PCIBus *bus, /* IOVA address space, untranslated addresses */ memory_region_init_iommu(&as->iova_mr, sizeof(as->iova_mr), TYPE_RISCV_IOMMU_MEMORY_REGION, - OBJECT(as), "riscv_iommu", UINT64_MAX); + OBJECT(s), "riscv_iommu", UINT64_MAX); address_space_init(&as->iova_as, MEMORY_REGION(&as->iova_mr), name= ); =20 QLIST_INSERT_HEAD(&s->spaces, as, list); --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830348; cv=none; d=zohomail.com; s=zohoarc; b=dKimNqpKCp9eHDNc26jwq66NFOGjOme7MMpVNcCpvJdqWcys9kizdmkc0ozbtoOuv3R51Coaxer/MDidAopdg9jr1mGkqNH3jsQozs07+J4c59svbQm9F1eLWy0BTuToWhNXUrLsu0Br9qZowvuJl67IgqQifsGeI0X7SmeyAhY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830348; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ciSgBKSv+v3guQQ3oNcl1Bgqz+M953jK6+TiC7VvB4c=; b=hyuqAk0DOeqjJgVfXbL2/i++/HC6hoJnyIqzR4jTC4DFBQUfbZifNCgSq8mbhiDb112478j6b4YpqhCDk2KBAemd/0LzgVuqX+EK/c9WhppmleTGIkBh8LboiRg9Larlzf3mmUauQJDR1QCa9E9mfy5gtzBBNd8kH1j2rw3n51Y= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178383034873617.423369599858233; Sat, 11 Jul 2026 21:25:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiljp-0007Xk-OK; Sun, 12 Jul 2026 00:24:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilie-0006SQ-MQ; Sun, 12 Jul 2026 00:23:10 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilic-0007OT-V8; Sun, 12 Jul 2026 00:23:08 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 6E7AD1C0C23; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id A18783EB983; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id C0E8313449; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=IIyXBgs7Q7EyMmBK59bS0SPSGlYTJC1VKc2b5fdm0AI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=gxfkh7nZyDMHlZXxREu9k/BRcwQo5ZqaX7Ty6WTQtDNMdF4LGyjQRIRgvKAKDnpTg g7sQ3gP2j145oD24B3fztgsW6lxDRnUZxBwSTSjZ9z+h4j0nnwlzKU7CxGjesSDQUW lYYrfs7ZKbt+E5GusSZgk7f7S4LJU/qNKVsQXGrCLNnbpqYcx7xgbDOGs4Nic8lkPS XAm/Djq74KNOfMfZL9mzxejZKRzwGH6r0YSpVGmVAZC+Y8nVqIraSudD8jcRMcwkUT 5B+KU8BZPjxu1/ABi8dMHrrrbEbHwL/8DuOJenN7iBR39X67j5kCbL6VqhQaaSubRQ L15sEg+BkvBVA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alistair Francis , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Tao Tang , Michael Tokarev Subject: [Stable-10.0.12 72/75] hw/pci/pcie_doe: Check mailbox length for overflows Date: Sun, 12 Jul 2026 07:15:30 +0300 Message-ID: <20260712041539.108341-72-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830351121158500 From: Alistair Francis It was possible that a guest could overflow the `doe_cap->write_mbox` buffer by writing more then PCI_DOE_DW_SIZE_MAX dwords. `doe_cap->write_mbox_len` would continue to increment and there were no bounds checks on the length when offsetting into doe_cap->write_mbox. This patch adds a check and reports a guest error if we would overflow. On an overflow we also silenty discard the entire object as instructed to do in the PCIe spec when the length specified in the header (up to PCI_DOE_DW_SIZE_MAX dwords) doesn't match the length of the object. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3679 Signed-off-by: Alistair Francis Reviewed-by: Philippe Mathieu-Daud=C3=A9 Reviewed-by: Tao Tang Message-ID: <20260707020750.788960-1-alistair.francis@wdc.com> Signed-off-by: Alistair Francis (cherry picked from commit c7e61854544be3ebcc001a33d41807947866a739) Signed-off-by: Michael Tokarev diff --git a/hw/pci/pcie_doe.c b/hw/pci/pcie_doe.c index 2210f869681..1bc2b457816 100644 --- a/hw/pci/pcie_doe.c +++ b/hw/pci/pcie_doe.c @@ -78,14 +78,21 @@ static bool pcie_doe_discovery(DOECap *doe_cap) return true; } =20 +static void pcie_doe_reset_write_mbox(DOECap *st) +{ + st->write_mbox_len =3D 0; + + memset(st->write_mbox, 0, PCI_DOE_DW_SIZE_MAX * DWORD_BYTE); +} + static void pcie_doe_reset_mbox(DOECap *st) { st->read_mbox_idx =3D 0; st->read_mbox_len =3D 0; - st->write_mbox_len =3D 0; =20 memset(st->read_mbox, 0, PCI_DOE_DW_SIZE_MAX * DWORD_BYTE); - memset(st->write_mbox, 0, PCI_DOE_DW_SIZE_MAX * DWORD_BYTE); + + pcie_doe_reset_write_mbox(st); } =20 void pcie_doe_init(PCIDevice *dev, DOECap *doe_cap, uint16_t offset, @@ -356,8 +363,20 @@ void pcie_doe_write_config(DOECap *doe_cap, if (size !=3D DWORD_BYTE) { return; } - doe_cap->write_mbox[doe_cap->write_mbox_len] =3D val; - doe_cap->write_mbox_len++; + if (doe_cap->write_mbox_len < PCI_DOE_DW_SIZE_MAX) { + doe_cap->write_mbox[doe_cap->write_mbox_len] =3D val; + doe_cap->write_mbox_len++; + } else { + qemu_log_mask(LOG_GUEST_ERROR, + "Mailbox write length (%d) overflow\n", + doe_cap->write_mbox_len); + /* + * Too much data has been written, it can't + * "match the Length indicated in DOE Data Object Header 2" + * so we drop the entire object. + */ + pcie_doe_reset_write_mbox(doe_cap); + } break; case PCI_EXP_DOE_CAP: /* fallthrough */ --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830379; cv=none; d=zohomail.com; s=zohoarc; b=UymEGXpboL7P2ul002z+pgBXHMbqTpYSyF452bPw7L0dVbCPcx2WmKrIl5Ao6KjRdTEV9X8ZhsgiBb7YUGj1RpmR3GHeoWQPCWSS+zMEbVhf1qdD48vL2ul95GNPvSJO/TkjvSsKT23cbVw1vQYmqRhbOLEGVxoXizlTSKfohvU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830379; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=h8pmFV9PL6cDjf2+wah/fRUBTcAu8wa24ERqsJ7Z9X0=; b=jHDIk6Vp0tQztbG95fLgjaxsSQM8r6cLUogHd3M4pro6cT3m+S+C7Ebf6qGykoDFwawVPjo3WrQKS7hc1ibvjpq3MhnjJY/k/QwcRFz7pVfX5LFp3LPpB+iBCA+1tcoiYGEhNUfb1ZgNKsJB0hGES+FIBfI5V1tJJZxsWrsRC18= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830379117995.8927725186885; Sat, 11 Jul 2026 21:26:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiljr-0007kw-W7; Sun, 12 Jul 2026 00:24:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilj7-0006oo-QD; Sun, 12 Jul 2026 00:23:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilj5-0007Ox-Ez; Sun, 12 Jul 2026 00:23:37 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 7326F1C0C24; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id A74EC3EB984; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id C34D41344B; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=0Hai+S8iJIKj4VhNBwatACETSTtOwjdmJGjzk75GIYc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=YXlKaC7zO1Q2wxwt/bZifUwx1f7PKPM39M1RD9jfdKHBOFkB1022cjxqajgWdRs3i xgRWqxCgwbNWkc0eOustYsc3wu+LSpSDNJiJMSYx3TciTU27VWjBZTC5FOiIhoTQLQ 8LC//3hWmWWjJCsZBZYRXIMaFnRpleW3vcYaBd26y+GpNNp7g/yba4bawPdsWmAcc6 uskJ4y09a2qYftFbmIpaJH6247loeDhnSYRhH9GUa9UXMlWbKuXtu4zykkVuIeTMhr 0tDzECUnzm6clYUAcKITBiaTetJ39b5iSedW9JxqYnGGAv28ci5beeo/x0LnuhUvb7 60a5yErOwjNjg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Heinrich Schuchardt , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 73/75] tests: allow differences in SPCR Date: Sun, 12 Jul 2026 07:15:31 +0300 Message-ID: <20260712041539.108341-73-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830380895158500 Content-Type: text/plain; charset="utf-8" From: Heinrich Schuchardt For easier bisection add the SPCR table to bios-tables-test-allowed-diff.h. Signed-off-by: Heinrich Schuchardt Acked-by: Alistair Francis Message-ID: <20260705063147.199732-2-heinrich.schuchardt@canonical.com> Signed-off-by: Alistair Francis (cherry picked from commit 18a5220990900ea53539f2f35ac042edacdbdbea) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/bios-tables-test-allowed-diff.h b/tests/qtest/bios= -tables-test-allowed-diff.h index dfb8523c8bf..2c7086d9de1 100644 --- a/tests/qtest/bios-tables-test-allowed-diff.h +++ b/tests/qtest/bios-tables-test-allowed-diff.h @@ -1 +1,3 @@ /* List of comma-separated changed AML files to ignore */ +"tests/data/acpi/loongarch64/virt/SPCR", +"tests/data/acpi/riscv64/virt/SPCR", --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830400; cv=none; d=zohomail.com; s=zohoarc; b=PmH0PmxhaYAqOXZdKbQm8YPVCm90xrrQBzD2ZzOhXX4XhqC7VHqKVNLbwf52dGy+tk7PHFFnzjST27YW+jqg4KzUvc+21PdetIhnLawXut5/8R2sdjhxlfNsL/BWtOJ/UqKMTGdBooq6pwq3AufCiA3rhRrBsi3uRdbnfTLMZ/w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830400; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=IE1+e0zUjWM85CXnatzydbWuIZk9+fHWA8/46PD8cbA=; b=mLJyawrt1GQHk2NQDuGme6Z2Zm8o5P5iVV5uB+EqXma0IZZp24+J0w85k+pMuE77f5zP6+2KGq5u0HaTa24KzYF5u6Y5GjwloDzSrxe+kmjioryNrXu7Pf9F/PSwOUljINsqd3i+j1H1lnTMOFViRTbi2sssWfeP5rxuMHgi5K4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830400827517.5052093687964; Sat, 11 Jul 2026 21:26:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiljo-0007OK-P9; Sun, 12 Jul 2026 00:24:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilii-0006Zm-3H; Sun, 12 Jul 2026 00:23:12 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilig-0007Or-8H; Sun, 12 Jul 2026 00:23:11 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 77ECB1C0C25; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id ABDDE3EB985; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id C5D3D1344D; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=4EY9QpGglyE7INnukWKzC/c7sRDlWWVeoZ4CT5WSZ0A=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=UCjvB9H3n7CRql2s9KizcON4PQIGB+Bi7FmGDQFB0TWENLyFy/tG8yBaeasSP8O60 N+fDRDdqBgeI9pifYhRwhTIdX9zFJFs7a/8JN6Mxbp8lqKXrY4V2xPTN/hgwthsPjr qilYyRYbBIBX1fTFl2jR6HMHK6HFZ58KbtJP79zG3hFPfTi1gt36szH+ByVgYMDDDb 6T0mJxzEafIP7uwI0woSEL+YXt2L7hbExk5Q4YGiKOusY7JHqR7WGpx2btpWc8lfpK RA3d6FSj4hUXz/m9nmRdaqJK1lHX5cXznYo439JVOOdc5jZAH9T3/1gKuwT8RGzeOp IAgZ16hMrzDbQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Heinrich Schuchardt , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 74/75] hw/acpi: correct field sequence in SPCR table Date: Sun, 12 Jul 2026 07:15:32 +0300 Message-ID: <20260712041539.108341-74-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830401016158500 Content-Type: text/plain; charset="utf-8" From: Heinrich Schuchardt On LoongArch and RISC-V invalid SPCR tables are created: Terminal Type : 00 Language : 03 The correct values are: Terminal Type : 03 Language : 00 This is due to commit 7dd0b070fa09 ("hw/arm/virt-acpi-build.c: Migrate SPCR creation to common location") that swapped the fields. See the specification of the table in https://learn.microsoft.com/en-us/windows-hardware/drivers/bringup/serial-p= ort-console-redirection-table This page shows version 1.10. But the sequence of the fields was not changed since version 1.0. Our LoongArch and ARM code uses version 1.07 of the specification. Our RISC-V code uses version 1.10 of the specification. Fixes: 7dd0b070fa09 ("hw/arm/virt-acpi-build.c: Migrate SPCR creation to co= mmon location") Origin: https://lore.kernel.org/qemu-devel/20260326121947.51200-1-heinrich.= schuchardt@canonical.com/T/#u Bug-Ubuntu: https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/2146419 Signed-off-by: Heinrich Schuchardt Reviewed-by: Alistair Francis Message-ID: <20260705063147.199732-3-heinrich.schuchardt@canonical.com> Signed-off-by: Alistair Francis (cherry picked from commit 15c73b0f17d27956b47812124b646d52181517bf) Signed-off-by: Michael Tokarev diff --git a/hw/acpi/aml-build.c b/hw/acpi/aml-build.c index f8f93a9f66c..dc17f47b9b9 100644 --- a/hw/acpi/aml-build.c +++ b/hw/acpi/aml-build.c @@ -2106,10 +2106,10 @@ void build_spcr(GArray *table_data, BIOSLinker *lin= ker, build_append_int_noprefix(table_data, f->stop_bits, 1); /* Flow Control */ build_append_int_noprefix(table_data, f->flow_control, 1); - /* Language */ - build_append_int_noprefix(table_data, f->language, 1); /* Terminal Type */ build_append_int_noprefix(table_data, f->terminal_type, 1); + /* Language */ + build_append_int_noprefix(table_data, f->language, 1); /* PCI Device ID */ build_append_int_noprefix(table_data, f->pci_device_id, 2); /* PCI Vendor ID */ --=20 2.47.3 From nobody Sat Jul 25 23:07:59 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1783830308; cv=none; d=zohomail.com; s=zohoarc; b=OEAqHp9LSJv694fM5TBWT2eSYCZMYlMrh06okprvyRzTGIwJY1CDNZkTVd1QU3mpfAJTkevE46DyonwhscEUg4MKT6doPEOzCTAGI1Oq4xjgbHtbH+/2CWHx84hI3vfo5ym9wLdce/5BbqyPPPmf8vpuKPRJfNzrozf1lcu700c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783830308; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=USIDh2naqLDtOvALyWnIBUGr5vMI7yMk0MoK6338kEw=; b=UPCKjHDdSGaO8w4Swld7XnE6CQYCmtEOINLp/Speo4hpICC2vhklqwK3H1vK71/9uZ2+bLUPXSptWkd2kUFfXSkTfJ8VGmXrENXqLvHbu/K3shvhqdT/k20n4XnNxeOLU2mWMcOHs1aEQ4DSigIO1NSvk79AjxwPUQpo9cVXMNg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783830308346341.5132209784422; Sat, 11 Jul 2026 21:25:08 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wiljp-0007Y3-NB; Sun, 12 Jul 2026 00:24:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilj7-0006ot-QU; Sun, 12 Jul 2026 00:23:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wilj3-0007P6-Gc; Sun, 12 Jul 2026 00:23:37 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 7D9D01C0C26; Sun, 12 Jul 2026 07:16:22 +0300 (MSK) Received: from gandalf.tls.msk.ru (mjt.wg.tls.msk.ru [192.168.177.130]) by tsrv.corpit.ru (Postfix) with ESMTP id B12143EB986; Sun, 12 Jul 2026 07:16:32 +0300 (MSK) Received: by gandalf.tls.msk.ru (Postfix, from userid 1000) id C86191344F; Sun, 12 Jul 2026 07:16:31 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1783829782; bh=wlooV9fJ8IftEORL9kCTKCepGrzG41THZk7fKbV7OAs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=BmKelAQSE6gYdkwIsnQ3UW16fHtFyLaCNrJy4vRPld/qJhZWB/TANTLicnvEsL3sz F2N79p4VWhYD5boK4tRs7lKUAUBnXMrCHxbgmY6q9o/GaPOVW4qigSBiXPiwMt5j2I 4qX/IIfUp82/ZFB76FGY9UZ81HdILdiPovyL0isSiMphK45rtf8Xvgr1uBiCuBvV/1 Simxp0R7UFOEpyO4LgM1S8m0U66HCXR0Zb7rEL2HeX/dW7XOPIVxXyd/SZD18VzaXK WwrrmXXwoW1o+y4XL0FIiGPNljuVv/nay/dkp6QgiNw97+DX7duIL58Ff9g+oA1XRl 2OQ3r8tZmhyUg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Heinrich Schuchardt , Alistair Francis , Michael Tokarev Subject: [Stable-10.0.12 75/75] tests: update SPCR loongarch64 and riscv64 test data Date: Sun, 12 Jul 2026 07:15:33 +0300 Message-ID: <20260712041539.108341-75-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1783830308821158500 Content-Type: text/plain; charset="utf-8" From: Heinrich Schuchardt On LoongArch and RISC-V the SPCR test data contained: Terminal Type : 00 Language : 03 The corrected values are: Terminal Type : 03 Language : 00 See the specification of the table in https://learn.microsoft.com/en-us/windows-hardware/drivers/bringup/serial-p= ort-console-redirection-table The ACPI table data was rebuilt with tests/data/acpi/rebuild-expected-aml.sh. Remove SPCR expections from tests/qtest/bios-tables-test-allowed-diff.h. Signed-off-by: Heinrich Schuchardt Acked-by: Alistair Francis Message-ID: <20260705063147.199732-4-heinrich.schuchardt@canonical.com> Signed-off-by: Alistair Francis (cherry picked from commit ec7d32428757d5813935cbe099449f6201980d80) (Mjt: for 10.0.x, keep risv table only, loongarch is not there yet) Signed-off-by: Michael Tokarev diff --git a/tests/data/acpi/riscv64/virt/SPCR b/tests/data/acpi/riscv64/vi= rt/SPCR index 09617f8793a..59d2c8f7f21 100644 Binary files a/tests/data/acpi/riscv64/virt/SPCR and b/tests/data/acpi/risc= v64/virt/SPCR differ diff --git a/tests/qtest/bios-tables-test-allowed-diff.h b/tests/qtest/bios= -tables-test-allowed-diff.h index 2c7086d9de1..dfb8523c8bf 100644 --- a/tests/qtest/bios-tables-test-allowed-diff.h +++ b/tests/qtest/bios-tables-test-allowed-diff.h @@ -1,3 +1 @@ /* List of comma-separated changed AML files to ignore */ -"tests/data/acpi/loongarch64/virt/SPCR", -"tests/data/acpi/riscv64/virt/SPCR", --=20 2.47.3