From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381130; cv=none; d=zohomail.com; s=zohoarc; b=Iu+9mG7QnrrHig6STccUwulRMC0TS5IICeeWamJFthwNCiCUyFVoXGWpnTUXuH1QsGpt0s6z5V3gWA0xpCdtWdk96Nlmpd7Q+7D8wYMNIz7PCiEPpnLoGt10fKnw6xiQy14lj/kZpn3q6HXRRgosdpzqUFWgSdOGlksSClVIWzY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381130; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3YvFzdsF3qTLWoLgwWwt9xhWZje5NQoBWIIF8EyQ1k4=; b=jHLH54gG0JeCFsEO4v6ezHPdZer0N/jZTWHqpc81625I0uSqxCuqIPb5qDIgtyOtFlq+K9d5ewm1ZdZ+UTRIAiWJLEbdcHcer83pCOJHWnWcJ8YB08BC/5ocU31MzbB7RDUIGGFgTJU7irp9vsa89a6eLNCTYPbsmksDUBjWZoA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381130427981.1603336403475; Sat, 13 Jun 2026 13:05:30 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUb7-0007yt-PI; Sat, 13 Jun 2026 16:04:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUb2-0007tX-SN; Sat, 13 Jun 2026 16:04:48 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUb1-0008AB-5C; Sat, 13 Jun 2026 16:04:48 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id DC22F1B6E68; Sat, 13 Jun 2026 23:04:26 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 424DA3CE8CB; Sat, 13 Jun 2026 23:04:45 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381066; bh=dhHlJAaTORu7C3UvV+NEVKgaFND271vwYTCYqrx0Res=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VyVcsXZ+dKzmImSdpAT2bR6wM1keB5k0WmAIT2GPRuTj/dRCU58vFuwEYqiCF/8xO BTIv1JinLoNg/7oyI5rxDTgv6uzm2BxEHA3r9Apo+9coR2VyS8+maPSfeMVKHTEyDS tXJ6JmIRzgOmizfPoD2uwV9cTNrDrTBpAAApOZ/pSzIW5ilnHV4aTNSKKZcj9WyoNV nVWTYcJHXy3kdysBC2AgsP+taTz/LUwdcwNTLPFi82xuaddErcjE++krWvXOe769FJ kvWVL/RpXWakLpOKEPzMlkYuBCvQdBDiqh+aynZWDCWJjlN8CuK9zKMlvlzZ2OFX1J /kcWa0YIvXnsw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Max Chou , Alistair Francis , Michael Tokarev Subject: [Stable-10.2.4 01/61] target/riscv: Update MISA.C for Zc* extensions Date: Sat, 13 Jun 2026 23:02:44 +0300 Message-ID: <20260613200411.1808021-1-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381131164158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang MISA.C is set if the following extensions are selected: * Zca and not F. * Zca, Zcf and F (but not D) is specified (RV32 only). * Zca, Zcf and Zcd if D is specified (RV32 only). * Zca, Zcd if D is specified (RV64 only). Therefore, MISA.C must be set according to the Zc* extension rules. Warn the user if RVC is explicitly disabled but MISA.C is required by the rules above. Signed-off-by: Frank Chang Reviewed-by: Max Chou Reviewed-by: Alistair Francis Message-ID: <20260424050509.3935180-2-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit f0433a8bc4ac5626499ff09ba5d165dbf7a4a980) Signed-off-by: Michael Tokarev diff --git a/target/riscv/tcg/tcg-cpu.c b/target/riscv/tcg/tcg-cpu.c index d3968251fa..6a094c921e 100644 --- a/target/riscv/tcg/tcg-cpu.c +++ b/target/riscv/tcg/tcg-cpu.c @@ -1120,6 +1120,44 @@ static void riscv_cpu_enable_implied_rules(RISCVCPU = *cpu) } } =20 +/* + * MISA.C is set if the following extensions are selected: + * - Zca and not F. + * - Zca, Zcf and F (but not D) is specified on RV32. + * - Zca, Zcf and Zcd if D is specified on RV32. + * - Zca, Zcd if D is specified on RV64. + */ +static void riscv_cpu_update_misa_c(RISCVCPU *cpu) +{ + CPURISCVState *env =3D &cpu->env; + bool set_misa_c =3D false; + + if (riscv_has_ext(env, RVC)) { + return; + } + + if (cpu->cfg.ext_zca && !riscv_has_ext(env, RVF)) { + set_misa_c =3D true; + } else if (riscv_cpu_mxl(env) =3D=3D MXL_RV32 && + cpu->cfg.ext_zca && cpu->cfg.ext_zcf && + (riscv_has_ext(env, RVD) ? cpu->cfg.ext_zcd : + riscv_has_ext(env, RVF))) { + set_misa_c =3D true; + } else if (riscv_cpu_mxl(env) =3D=3D MXL_RV64 && + cpu->cfg.ext_zca && cpu->cfg.ext_zcd) { + set_misa_c =3D true; + } + + if (set_misa_c) { + if (cpu_misa_ext_is_user_set(RVC)) { + warn_report("RVC mandated by Zca/Zcf/Zcd extensions"); + return; + } + + riscv_cpu_set_misa_ext(env, env->misa_ext | RVC); + } +} + void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, Error **errp) { CPURISCVState *env =3D &cpu->env; @@ -1127,6 +1165,7 @@ void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, E= rror **errp) =20 riscv_cpu_init_implied_exts_rules(); riscv_cpu_enable_implied_rules(cpu); + riscv_cpu_update_misa_c(cpu); =20 riscv_cpu_validate_misa_priv(env, &local_err); if (local_err !=3D NULL) { --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381203; cv=none; d=zohomail.com; s=zohoarc; b=Um4L0SVCVGO1yK7nxTt7U6BPGVTKK5cu04lSB8d7nEg1JMlazUO22fo/MBzzHuaU812OrfypGkQnnwt6990XKWzubE+gRPKKAOhTRBbgi2QXBq5I7E0miwOfMM3/6BJmERC1+A61MVY5AYKRWS28ws7mSHSr2zsAFwhpSlmzuAI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381203; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=g78Pj8K0dHa7dAy4m1JpV7jXyatb9SMp6zBN0LQ+t/I=; b=NWjaVdgchCtNlaIWx3G4s6wOmy+sUN5Yyod50DB/EF3hY2WhcDtQeWkuMgO6LqmxHasDa2B7sCsCU0vUuEbZw6WdYMe/aTMVpGpK7138StCXJXnqJ8H8ObG9jeOOQWRsCLzAo+GWNlYHlyfIDZp2TZtPrd4HBa5h7otfwfTRB0Y= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381203739461.082599396245; Sat, 13 Jun 2026 13:06:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUb7-0007yx-PH; Sat, 13 Jun 2026 16:04:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUb2-0007tY-St; Sat, 13 Jun 2026 16:04:48 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUb1-0008AN-5c; Sat, 13 Jun 2026 16:04:48 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id EEB151B6E69; Sat, 13 Jun 2026 23:04:26 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 550A73CE8CC; Sat, 13 Jun 2026 23:04:45 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381066; bh=rnQOGaMB0TvAzkIsOXg/THAk5Avc62ywt9gBn5zGPjM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=O+wZGwgsvjKUTMJ295Y2pUYRQkNYfzsw6ZY1fyqroAg1NpFuVzOyNnN039F70+Xj9 f8VpA9YOBRSX8UycSt3TnflnpC0+hftmsn1vurLLpQ+U4LysKEWQnRXkE2Tw78WKOy kQsaOO8rarIpMhxbjwk1qaGUCUgM+wFyYWsaikXoRIS0LeWG7HOp3MNDyDAHyGV9Ug nFbI1zDPxKS8CMacKAbpaaxy7OHOxYcT6yLrVzak1DSpb44UadHUqAm82JqtTOF6ls YhbaP/DfAx87s4URlUAmL7PPh7NuucyEDTAkNb8ee3Wf15FpNjP2O+Q3K47bcoqRMt n+upO2kq8Q89g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Max Chou , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.2.4 02/61] target/riscv: Update MISA.X for non-standard extensions Date: Sat, 13 Jun 2026 23:02:45 +0300 Message-ID: <20260613200411.1808021-2-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381205355158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang MISA.X is set if there are any non-standard extensions. We should set MISA.X when any of the vendor extensions is enabled. Signed-off-by: Frank Chang Reviewed-by: Max Chou Reviewed-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260424050509.3935180-3-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit 613bb1949fffc4aeb9e554e35fecc7d6f7ddd27b) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu.h b/target/riscv/cpu.h index 36e7f10037..ee93558668 100644 --- a/target/riscv/cpu.h +++ b/target/riscv/cpu.h @@ -69,6 +69,7 @@ typedef struct CPUArchState CPURISCVState; #define RVH RV('H') #define RVG RV('G') #define RVB RV('B') +#define RVX RV('X') =20 extern const uint32_t misa_bits[]; const char *riscv_get_misa_ext_name(uint32_t bit); diff --git a/target/riscv/tcg/tcg-cpu.c b/target/riscv/tcg/tcg-cpu.c index 6a094c921e..22ced1ed1b 100644 --- a/target/riscv/tcg/tcg-cpu.c +++ b/target/riscv/tcg/tcg-cpu.c @@ -1158,6 +1158,20 @@ static void riscv_cpu_update_misa_c(RISCVCPU *cpu) } } =20 +/* MISA.X is set when any of the non-standard extensions is enabled. */ +static void riscv_cpu_update_misa_x(RISCVCPU *cpu) +{ + CPURISCVState *env =3D &cpu->env; + const RISCVCPUMultiExtConfig *arr =3D riscv_cpu_vendor_exts; + + for (int i =3D 0; arr[i].name !=3D NULL; i++) { + if (isa_ext_is_enabled(cpu, arr[i].offset)) { + riscv_cpu_set_misa_ext(env, env->misa_ext | RVX); + break; + } + } +} + void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, Error **errp) { CPURISCVState *env =3D &cpu->env; @@ -1166,6 +1180,7 @@ void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, E= rror **errp) riscv_cpu_init_implied_exts_rules(); riscv_cpu_enable_implied_rules(cpu); riscv_cpu_update_misa_c(cpu); + riscv_cpu_update_misa_x(cpu); =20 riscv_cpu_validate_misa_priv(env, &local_err); if (local_err !=3D NULL) { --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381174; cv=none; d=zohomail.com; s=zohoarc; b=CuctYjfzeQ4lHwq0Dpe2jeKIgii3hfe9HJwOnk6VIK/k18+W1ovmoQOkJlMobrD/qxW6gKFprD1tfyWZT0TosX4KYYVcwfmHoCGZl9KeL8K36DFQrOX+WYj5btUQ6mR3hawQYDsffR7RudEVxGHhp2EPDcc062K/IgcauTMN8s8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381174; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ZzyD+uTQAMYS0/xTbpwIQ1iMKcQNw+bRK9qtKqSklUQ=; b=IIN99SwV1A7MoRthciyqdkZyQLiLUbOZfa0r9xKOy1jiwXnIZpjKbg3XuN68dU2NmnvvUmujPvHgOxK6JHBKxym+qAONDLfZ+U3hG5ijXdVJ2MDyP2x2TrtrpCgmbqAhplhg4NbYTPq3p5FBfqfvXKzKFJmuR0B3y9Ll9ElXAnc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138117407261.671021539619346; Sat, 13 Jun 2026 13:06:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUb9-00080P-J6; Sat, 13 Jun 2026 16:04:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUb7-0007z9-7F; Sat, 13 Jun 2026 16:04:53 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUb5-0008CJ-6l; Sat, 13 Jun 2026 16:04:52 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 0F6201B6E6A; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6847F3CE8CD; Sat, 13 Jun 2026 23:04:45 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=6hmJxsuVBwTPTwBAYCDjcaFtNZHOpPhIriJ3TcPkJcw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=u4qgg7IJ+lJYZbfvYOJKmbFpkQCRrOAzTlDiqvQu6TTTkamly2Vd25eegVS7hyRnG 7lF6pmqhhvsSH1p3ap75HzkE8o50Ec/KeSBdqwRuYtUGa6Lqfnl/e2pwSf/MYS5YHl IGYqxhOh+os5gIKrq7rrRo3enjsvU0D0JY80WstVM/b85Ha3fsgbJFixhzyLACIuTa tt/K3wiqKRSqYdkUmr+P1ei+zyNVFOsoTTpSb11aAzpTrsMFsHPuS4+PTmoc9FXsPc ushb39V/CTYn2wvEXiVWw4lIUYbALQyF0dJ3aMm/QjzuU2Jyz++j14wUtF5rgrittW FPnGux5n/g1Bw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Andrew Jones , Daniel Henrique Barboza , Nutty Liu , Tomasz Jeznach , Alistair Francis , Michael Tokarev Subject: [Stable-10.2.4 03/61] hw/riscv/riscv-iommu: Fix Svnapot 64KB pages Date: Sat, 13 Jun 2026 23:02:46 +0300 Message-ID: <20260613200411.1808021-3-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381175253158500 Content-Type: text/plain; charset="utf-8" From: Andrew Jones The Svnapot extension encodes a 64KB leaf PTE by setting PTE_N and storing bits [3:0] of the PPN as a NAPOT size indicator. The IOMMU model wasn't checking PTE_N and therefore was using the raw (NAPOT- encoded) PPN directly in the physical address, yielding an address 32 KB above the correct base. Fix both riscv_iommu_spa_fetch() and pdt_memory_read() by mirroring the Svnapot handling already present in target/riscv/cpu_helper.c: napot_bits =3D ctz64(ppn) + 1 /* 4 for 64KB */ napot_mask =3D (1 << napot_bits) - 1 /* 0xF */ phys_base =3D PPN_PHYS(ppn & ~napot_mask) page_offset =3D addr & (PPN_PHYS(napot_mask) | (TARGET_PAGE_SIZE - 1)) The spec only defines napot_bits =3D=3D 4 (64KB); any other value is treated as a reserved encoding. This is a fix, rather than new feature support, because the spec says "IOMMU implementations must support the Svnapot standard extension for NAPOT Translation Contiguity." Fixes: 0c54acb8243d ("hw/riscv: add RISC-V IOMMU base emulation") Cc: qemu-stable@nongnu.org Signed-off-by: Andrew Jones Reviewed-by: Daniel Henrique Barboza Reviewed-by: Nutty Liu Reviewed-by: Tomasz Jeznach Message-ID: <20260508205129.377032-1-andrew.jones@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit fcbd93e96be2ed0e5139542f54be31efa6d2b1dc) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index f8656ec04b..cecfd501be 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -237,6 +237,25 @@ static bool riscv_iommu_msi_check(RISCVIOMMUState *s, = RISCVIOMMUContext *ctx, return true; } =20 +/* Returns the NAPOT page mask, or 0 for reserved encodings. */ +static hwaddr riscv_iommu_napot_page_mask(hwaddr ppn, hwaddr addr, hwaddr = *out) +{ + int napot_bits =3D ctz64(ppn) + 1; + hwaddr napot_mask, page_mask; + + /* The spec only defines 64KB (napot_bits =3D=3D 4) */ + if (napot_bits !=3D 4) { + return 0; + } + + napot_mask =3D (1ULL << napot_bits) - 1; + page_mask =3D PPN_PHYS(napot_mask) | (TARGET_PAGE_SIZE - 1); + + *out =3D PPN_PHYS(ppn & ~napot_mask) | (addr & page_mask); + + return page_mask; +} + /* * RISCV IOMMU Address Translation Lookup - Page Table Walk * @@ -458,9 +477,20 @@ static int riscv_iommu_spa_fetch(RISCVIOMMUState *s, R= ISCVIOMMUContext *ctx, } else { /* Leaf PTE, translation completed. */ sc[pass].step =3D sc[pass].levels; - base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); - /* Update address mask based on smallest translation granulari= ty */ - iotlb->addr_mask &=3D (1ULL << va_skip) - 1; + + if (pte & PTE_N) { + hwaddr mask =3D riscv_iommu_napot_page_mask(ppn, addr, &ba= se); + + if (!mask) { + break; + } + iotlb->addr_mask &=3D mask; + } else { + base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + /* Update address mask based on smallest translation granu= larity */ + iotlb->addr_mask &=3D (1ULL << va_skip) - 1; + } + /* Continue with S-Stage translation? */ if (pass && sc[0].step !=3D sc[0].levels) { pass =3D S_STAGE; @@ -997,7 +1027,13 @@ static MemTxResult pdt_memory_read(RISCVIOMMUState *s, return MEMTX_ACCESS_ERROR; /* Misaligned PPN */ } else { /* Leaf PTE, translation completed. */ - base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + if (pte & PTE_N) { + if (!riscv_iommu_napot_page_mask(ppn, addr, &base)) { + return MEMTX_ACCESS_ERROR; + } + } else { + base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + } break; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381225; cv=none; d=zohomail.com; s=zohoarc; b=bMWNOpqwYBP7cijQ2QdCN3or6j9LdG8kuU6YiHydhzBDJrfOADQxGx7/hMK73tq5yj6Fw3SPWDChi8v/OunSeGMugvCr5/oU8Iv1CkCzKXrnOSMfJRQAy3nmQSmriR1HaGysAdxB7ob4Uq5/yERpkB5G2Y4VDh4TycFAOSCBmZM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381225; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=M/q1z9XG5fDcim3KfYpqPI4e2xAD6zgARLSGZVSa+ZE=; b=hLZqO6eIEP7evCqjW9+Mjl9ZDLZvu4KJttlVE5EQGgF724Tq2N4Tz3H8KRqpvYNEDjAapneeU5j2osVO2/7A4whzmI/oYZQCe32S9leB2oEOsz3p6nufri2V1gSrjJcmOFUyUXymBjMtrUC+CNBYXh3fON9xYSDmDGc5CHqx8DI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381225846374.9664947327649; Sat, 13 Jun 2026 13:07:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUbA-00080y-RF; Sat, 13 Jun 2026 16:04:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUb7-0007zC-BZ; Sat, 13 Jun 2026 16:04:53 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUb5-0008CL-6g; Sat, 13 Jun 2026 16:04:53 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 225CF1B6E6B; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7CA463CE8CE; Sat, 13 Jun 2026 23:04:45 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=AkqqE2GYjCUuzX0I74JcrJ3kkupa9cH9m9WQdzDjZZ0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=OgMQb1ZGo6G7JW88PTzndWZClbMmyHCkrKAU7xkj7Mi4dhkpTAeB5FFpClhZxG6zE q5ifG6V3K1RNOb+wsChjoC1YCvW8sVFVwIzOm4wsFND7LVQ37H9uQA3D0IviKvPYJC OHHoRgJk6hxnDBEBXcZHKiuXQeXSMJniZd0o2ZXiFJyOdg/u/iPvdGKdvsfyYpRBCA 4CN8vPdCjdRbh6qKqjZFymbhcX7dmo1fPWOTHKX3g+VXi3rTvqKHMjC6s9pwjB+6De QvvPliU6uNyXXQ+on6YWoSkEPz8HkUS7DUqxfyZPzyGhuRCkrygzeCtDYC7sd9dcnu ChTKEBTeGfL4A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Chao Liu , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.2.4 04/61] target/riscv: Allow mseccfg access based on ext_zicfilp Date: Sat, 13 Jun 2026 23:02:47 +0300 Message-ID: <20260613200411.1808021-4-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381227422158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi The Zicfilp extension adds the MLPE field to the mseccfg CSR. According to the RISC-V Privileged Specification, mseccfg exists if any extension that adds a field to it is implemented. Currently, the `have_mseccfg()` predicate function checks for Smepmp, Zkr, and Smmpm, but misses Zicfilp. As a result, if a CPU is configured with `zicfilp=3Dtrue` but without the other extensions, accessing the mseccfg CSR will incorrectly raise an illegal instruction exception. This patch adds the missing check for `ext_zicfilp` to ensure the CSR is properly accessible when the Zicfilp extension is enabled. This issue was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-isa-m= anual/pr-2561/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Chao Liu Reviewed-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260511072705.3015986-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 249483623242c1b9ad4a1600083bea534620917a) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 6da5aa47da..c52c35efc4 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -771,6 +771,9 @@ static RISCVException have_mseccfg(CPURISCVState *env, = int csrno) if (riscv_cpu_cfg(env)->ext_smmpm) { return RISCV_EXCP_NONE; } + if (riscv_cpu_cfg(env)->ext_zicfilp) { + return RISCV_EXCP_NONE; + } =20 return RISCV_EXCP_ILLEGAL_INST; } --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383730; cv=none; d=zohomail.com; s=zohoarc; b=PY8yBlmczgJdMVj2EUNH88qFFxjsnqZJ0Xjk+Q7o+1lbCuntUICdGqWAb+8Qb/PJQ58OZ9wcmfOTF8aiSYWbltBHIyXP6JR7TRoHBX17Bae+dkoYyHF6M737RWuUkSWSo8C0O4dejAF26V1He7vjPCVsC1oOawAo6JdSbR952fw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383730; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tHv70YS8/vYNZ/CEumHtSM6ByaEtJIE1CnT6KKuqbXM=; b=V39Xpg4NBkqttHIwiFGTGX7CV8Kk1QUGKqQ+w3cxmxTUq35PDYiMbIr7aGyFkHOjxus0ajY96QZn3mPVddyA9+SMMXJWXuilQbOnTUbNa7sSpiKYQ5tVrC3id08LoE+1r0zqDvYIWhiedB1+VWtji3uBNO8fhJjNUCxJD/BbcjM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383730564265.6578921503525; Sat, 13 Jun 2026 13:48:50 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUbE-00083e-Ej; Sat, 13 Jun 2026 16:05:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbB-00081q-Sz; Sat, 13 Jun 2026 16:04:57 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbA-0008EN-3O; Sat, 13 Jun 2026 16:04:57 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 323641B6E6C; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9052C3CE8CF; Sat, 13 Jun 2026 23:04:45 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=swJPghRYkB1uTjjPYnVOReACv00PfjlprlEMRvXDaTM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=AIK1AIVFg/XNrF6TuIgCAi8fct7sWMrpOVCN/qN1e7PIdgAJ2ug/7UEqJlXJOabuL 5bAtn5PaS1vd/T0MpyJiuYt/bOoJyZ16tZfiqJvpZUVkKT+iG3BQDR9Qx2bnb6pFVL CJ5ppl3yuEAyq3hIH2htH0FKRbg5d3e0tM06b5UbJkQE3DQ4QqN+A4M7FzshsrAPdR Jr4RwY3+h7rNUW1d4ti14LjkWJF/esC8L5i+f31y/c3bpZWoJ3gGNhOvlHg8r1WSXy f6xWKsWQhjukiILhtXcJtjbNkic/cMwwutzjVzrpxSTDS/Chgrmzqp2dNtaRRq6UJj uFTPwAOhhBMJQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Anton Blanchard , Alistair Francis , Michael Tokarev Subject: [Stable-10.2.4 05/61] target/riscv: rvv: Handle source overlap of vector widening reduction instructions Date: Sat, 13 Jun 2026 23:02:48 +0300 Message-ID: <20260613200411.1808021-5-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383731581158500 Content-Type: text/plain; charset="utf-8" From: Anton Blanchard Widening reductions read vs2 as a vector of SEW elements and vs1[0] as a scalar of 2*SEW. The ISA does not allow the same vector register to be read with different EEWs, so they must not overlap. vs1 is read as a scalar from element 0, so it is treated as a single vector register (independent of LMUL) when checking overlap. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3208 Signed-off-by: Anton Blanchard Acked-by: Alistair Francis Message-ID: <20260417080328.31918-1-antonb@tenstorrent.com> Signed-off-by: Alistair Francis (cherry picked from commit caf3bef5f01e85b8bbd24e1851b50616fa03a5bb) Signed-off-by: Michael Tokarev diff --git a/target/riscv/insn_trans/trans_rvv.c.inc b/target/riscv/insn_tr= ans/trans_rvv.c.inc index 2a487179f6..214b79d2ed 100644 --- a/target/riscv/insn_trans/trans_rvv.c.inc +++ b/target/riscv/insn_trans/trans_rvv.c.inc @@ -3090,6 +3090,7 @@ GEN_OPIVV_TRANS(vredxor_vs, reduction_check) static bool reduction_widen_check(DisasContext *s, arg_rmrr *a) { return reduction_check(s, a) && (s->sew < MO_64) && + !is_overlapped(a->rs1, 1, a->rs2, 1 << MAX(s->lmul, 0)) && ((s->sew + 1) <=3D (s->cfg_ptr->elen >> 4)); } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781394148; cv=none; d=zohomail.com; s=zohoarc; b=N3yg59HZNw3aKn95IJOLDLJtoENnI8o+TJ7SYtvp3NJfPththWc434fVcKwSNk97kH5N1IqvdEK76p0g8ggi0p7PlJsI5PNrULIMk/5rRenVV3+ye/pzTwOI/24xz1dzHZ0ObS52J0L+Rqzm7fmB7ZzYqzXpNtoNKi8ywxCEkBU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781394148; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lvNmrDhyA4GSXZmRaoUae3lEufjc3L9eWZvFomQasDc=; b=DlKN++pCuPJEdhfhn3vjBKi2hEWdoD5ui12Nieh7OvWa2uuVaNnxMMpCRVTUXosobKl58vIhJQ6GX79N6jV8nQ+6aVZraRXAFf6km3l3/39R29tkhT7dMTyuxIsRekGf5JwIIeEDrMAphSaxaztDUexQF7y/oET/7bh24pUPWZk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178139414606575.36673755515665; Sat, 13 Jun 2026 16:42:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUbD-00082Y-AL; Sat, 13 Jun 2026 16:04:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbB-00081i-K3; Sat, 13 Jun 2026 16:04:57 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUb9-0008EO-NI; Sat, 13 Jun 2026 16:04:57 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 40BB71B6E6D; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9EE0E3CE8D0; Sat, 13 Jun 2026 23:04:45 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=x6ZtgQ+6zjrGesV26uSaAeNNJSCCVlbzo0d7wJ+i2n8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=sraqqyC87HRbTScBi8waTs28dACGcmbJy1gCqMJz/+L5QN94VZYPulhM5eIduCw8a RTOXO+LGdaGkiAe3reWY6wpRUBANFRg7DUArnvsUWAqBTmZ7Ssy4mTM8F05+0zOkve JnRKPbtt9WPFZM3pbEFGiiqhi/g6zTI7Wk6sZClVCaAUMOgii4CRljvd4uv2g51LTZ P00e394p7ocdoFrjY8ohkE3cai4e2FzrD1hTvPbUoogIWXaQ6se2oyjMv94YxYZhr8 ObLfuRl0a3Bqomx06rn541v+gM+PejWkI/HXnMfiWCPDqCJwPESgajVrGgI3jfGdLW YWHOHsJ1drhog== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Alistair Francis , Michael Tokarev Subject: [Stable-10.2.4 06/61] hw/char: sifive_uart: Implement txctrl.txen and rxctrl.rxen Date: Sat, 13 Jun 2026 23:02:49 +0300 Message-ID: <20260613200411.1808021-6-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781394162440158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang Implement txctrl.txen and rxctrl.rxen as follows: * txctrl.txen The txen bit controls whether the Tx channel is active. When cleared, transmission of Tx FIFO contents is suppressed, and the txd pin is driven high. * rxctrl.rxen: The rxen bit controls whether the Rx channel is active. When cleared, the state of the rxd pin is ignored, and no characters will be enqueued into the Rx FIFO. Therefore, the Tx FIFO should not be dequeued when txctrl.txen is cleared, and the Rx FIFO should not be enqueued when rxctrl.rxen is cleared. Signed-off-by: Frank Chang Reviewed-by: Alistair Francis Message-ID: <20260312033201.1619554-2-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit e6051fa61b9f6fe9c40d8392b6da1f33e9d88332) Signed-off-by: Michael Tokarev diff --git a/hw/char/sifive_uart.c b/hw/char/sifive_uart.c index e7357d585a..4a54dd52a1 100644 --- a/hw/char/sifive_uart.c +++ b/hw/char/sifive_uart.c @@ -78,6 +78,11 @@ static gboolean sifive_uart_xmit(void *do_not_use, GIOCo= ndition cond, return G_SOURCE_REMOVE; } =20 + /* Don't pop the FIFO if transmit is disabled. */ + if (!SIFIVE_UART_TXEN(s->txctrl)) { + return G_SOURCE_REMOVE; + } + /* Don't pop the FIFO in case the write fails */ characters =3D fifo8_peek_bufptr(&s->tx_fifo, fifo8_num_used(&s->tx_fifo), &numptr); @@ -106,11 +111,19 @@ static gboolean sifive_uart_xmit(void *do_not_use, GI= OCondition cond, return G_SOURCE_REMOVE; } =20 -static void sifive_uart_write_tx_fifo(SiFiveUARTState *s, const uint8_t *b= uf, - int size) +static void sifive_uart_trigger_tx_fifo(SiFiveUARTState *s) { uint64_t current_time =3D qemu_clock_get_ns(QEMU_CLOCK_VIRTUAL); =20 + if (!timer_pending(s->fifo_trigger_handle)) { + timer_mod(s->fifo_trigger_handle, current_time + + TX_INTERRUPT_TRIGGER_DELAY_NS); + } +} + +static void sifive_uart_write_tx_fifo(SiFiveUARTState *s, const uint8_t *b= uf, + int size) +{ if (size > fifo8_num_free(&s->tx_fifo)) { size =3D fifo8_num_free(&s->tx_fifo); qemu_log_mask(LOG_GUEST_ERROR, "sifive_uart: TX FIFO overflow.\n"); @@ -124,10 +137,7 @@ static void sifive_uart_write_tx_fifo(SiFiveUARTState = *s, const uint8_t *buf, s->txfifo |=3D SIFIVE_UART_TXFIFO_FULL; } =20 - if (!timer_pending(s->fifo_trigger_handle)) { - timer_mod(s->fifo_trigger_handle, current_time + - TX_INTERRUPT_TRIGGER_DELAY_NS); - } + sifive_uart_trigger_tx_fifo(s); } =20 static uint64_t @@ -184,6 +194,9 @@ sifive_uart_write(void *opaque, hwaddr addr, return; case SIFIVE_UART_TXCTRL: s->txctrl =3D val64; + if (SIFIVE_UART_TXEN(s->txctrl) && !fifo8_is_empty(&s->tx_fifo)) { + sifive_uart_trigger_tx_fifo(s); + } return; case SIFIVE_UART_RXCTRL: s->rxctrl =3D val64; @@ -231,7 +244,7 @@ static int sifive_uart_can_rx(void *opaque) { SiFiveUARTState *s =3D opaque; =20 - return s->rx_fifo_len < sizeof(s->rx_fifo); + return SIFIVE_UART_RXEN(s->rxctrl) && (s->rx_fifo_len < sizeof(s->rx_f= ifo)); } =20 static void sifive_uart_event(void *opaque, QEMUChrEvent event) diff --git a/include/hw/char/sifive_uart.h b/include/hw/char/sifive_uart.h index 6486c3f4a5..e216cacf69 100644 --- a/include/hw/char/sifive_uart.h +++ b/include/hw/char/sifive_uart.h @@ -51,6 +51,8 @@ enum { =20 #define SIFIVE_UART_TXFIFO_FULL 0x80000000 =20 +#define SIFIVE_UART_TXEN(txctrl) (txctrl & 0x1) +#define SIFIVE_UART_RXEN(rxctrl) (rxctrl & 0x1) #define SIFIVE_UART_GET_TXCNT(txctrl) ((txctrl >> 16) & 0x7) #define SIFIVE_UART_GET_RXCNT(rxctrl) ((rxctrl >> 16) & 0x7) =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381409; cv=none; d=zohomail.com; s=zohoarc; b=OqJVJGqmpPqPunD3MIYaSulk2+59qoo82CQwXo4fw0mZ+oB6DmdWrBDCSa/5Kr2zL77WOwkY47hjxVUf1LNCI0jlRkpaUjlblCz0LZsh9YFTTnmPTkq/mpzx4gMbyI4Vi1Y6fIpBQlEwWAm/PZ6k8ELIXY1x+7hrw8p4ReLAFfs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381409; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9Mn5+THUW7Ej8uaaGYCizAHoLfVGFZZWzIBpV63gOAo=; b=TSht3eoo0e7EprGtI25DkWXK89fDkczOrzbNNMZzhREEtpUH9UGvvVMvZGXnP+lcreQgeoRBZDU8GbnqjZ2KE33RBIPtjnMG8ef0Rd0PS7OEvDMfk8gz5UXXh8phROc+1UEA7bD8e3gCUSZQnZCSJ26Qu6C8kMOHzCGwYcs0au8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381409099100.44628751042205; Sat, 13 Jun 2026 13:10:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUbH-000861-BA; Sat, 13 Jun 2026 16:05:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbF-00083l-Dc; Sat, 13 Jun 2026 16:05:01 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbD-0008HA-IN; Sat, 13 Jun 2026 16:05:00 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 52F3C1B6E6E; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id AE10B3CE8D1; Sat, 13 Jun 2026 23:04:45 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=4z7s1KUPov547AFUB0/0VKwnCG1xS0fdowh1v+qwB3k=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=h0y4WT4w9U82G39S9QDAzIdc9H72djADtJjeTSyxC0QtaVYwjmiCROCzAIEaSAZtj 4dxAk/AZ/lbIwy/Z9ylQoS9n1WAkZy1G1ZOg6AzzHhdMF8v2zUjONU6lF0ryDFC9MM sxtGdCzIhtWyjQaqNxUD8Ohe8FZD1chiaf6RFKL0GEl5P2VBsPMNGWpdmYG4G/haFa wmH5Rs5Iz2IMJxBqSqMw3X48zxfEKP1TRkgd+n6ZYXi5sDGTeCEyNHA3mKoH/CcK2G y/41yWhLH0UYDg4NBwHYgJhGq11PAi01mk6kGu43x+IU/h+djStNkJ7Y7xTPOaRNLF UNBDPFcRkr9JQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Chao Liu , Jim Shu , Alistair Francis , Michael Tokarev Subject: [Stable-10.2.4 07/61] hw/char: Check interrupt after txctrl register is written Date: Sat, 13 Jun 2026 23:02:50 +0300 Message-ID: <20260613200411.1808021-7-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381410180158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang It's possible that the transmit watermark level (txctrl.txcnt) is updated when the user writes to txctrl register, which may decrease the transmit watermark level to less than the number of entries in the transmit FIFO. In such a case, the interrupt should be raised so we need to call sifive_uart_update_irq() to check and update interrupt when txctrl register is written. Otherwise, the interrupt will have to be delayed until next TX FIFO transmission is processed. Suggested-by: Chao Liu Signed-off-by: Frank Chang Reviewed-by: Jim Shu Reviewed-by: Alistair Francis Message-ID: <20260513030503.3665414-1-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit e07077a766071418e76d1c7db7e51e344776eaf2) Signed-off-by: Michael Tokarev diff --git a/hw/char/sifive_uart.c b/hw/char/sifive_uart.c index 4a54dd52a1..b76213e157 100644 --- a/hw/char/sifive_uart.c +++ b/hw/char/sifive_uart.c @@ -197,6 +197,7 @@ sifive_uart_write(void *opaque, hwaddr addr, if (SIFIVE_UART_TXEN(s->txctrl) && !fifo8_is_empty(&s->tx_fifo)) { sifive_uart_trigger_tx_fifo(s); } + sifive_uart_update_irq(s); return; case SIFIVE_UART_RXCTRL: s->rxctrl =3D val64; --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381472; cv=none; d=zohomail.com; s=zohoarc; b=Psk7A9M+hNh6jHKnX1ISRJweR/wEK42+6LnLOC7QhzyeoVx/pvA0uq9E0svR8Lyq1OHBhwasBUN3MoN8k0iVEFvYDdaS8h7soD4iumNLO5AJ3nTWUlzfmlnw71vw5ArXyvOX4ctmzLPMdyfDFnTkAfZE8sg9SiBgOLFhJzKXsEw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381472; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=c4OXXdzpd9n/tC+iIYVRZ/bKlejm1cjWaTfvPoAcKPA=; b=Wr1OP4g7R018QEB3arlvhCMBrH1zZ36A5CaQIIRuVo484BqZ7rYllWfqKNV3iN/+V5CqQ+KgOh803O8UFh6pGEnJtZriitYKNpMoV0YlgQnpWqoouQbkr0X7fAYEUZfpUWzYYh2JU+wtRdfBUeXte6zF0NBA/jrJ7bhSXgGsA8g= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381472941183.16448764377117; Sat, 13 Jun 2026 13:11:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUbI-000871-EH; Sat, 13 Jun 2026 16:05:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbF-00083x-Oh; Sat, 13 Jun 2026 16:05:01 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbD-0008HF-Qy; Sat, 13 Jun 2026 16:05:01 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 620F91B6E6F; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C065B3CE8D2; Sat, 13 Jun 2026 23:04:45 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=NTPbAcRAk/i3e4hn3QAdPZgjwMMfgqEmn2fizpJcvU4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=oHctomOR5d13rE+ZLDu4EhNXDiVFCS5tfeDMcL2o1LT8AVyxnzYS/yFC6//3R2sBG nf5Ruv2ns6J0AXezk1sH/5IsLbqTq+BdYbIm4YJdSfdx8U6ae+0Y08XzpdNQoI6W+W IoIqGX3fy7O1wlZkFXFOBhLOHq6ciLbjFwRgB6IG0qVsnTEzhajt5WPiE3B1fKvyzo MrNJEc2NtShopsy5ZTYuITconxbN/KtQZNvqNL/yAy5xtHYR66ZIlLIY7/0HVfPzms ng4e9kdPPDLlvQk5stPCvXCyBlk/DAKpbcaC5cmVPO9hPvs4zTmrsgzmMrL2hzCJtL 2nbZkosS7hi4Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Abhigyan Kumar <314abh@gmail.com>, Alistair Francis , Michael Tokarev Subject: [Stable-10.2.4 08/61] target/riscv: Fix medeleg[11] read-only zero bit for M-mode ECALL Date: Sat, 13 Jun 2026 23:02:51 +0300 Message-ID: <20260613200411.1808021-8-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381474339158500 Content-Type: text/plain; charset="utf-8" From: Abhigyan Kumar <314abh@gmail.com> RISC-V Privileged Specification 3.1.8 (Machine Trap Delegation Registers (medeleg and mideleg)) mentions: "For exceptions that cannot occur in less privileged modes, the corresponding medeleg bits should be read-only zero. In particular, medeleg[11] is read-only zero." QEMU incorrectly included RISCV_EXCP_M_ECALL in DELEGABLE_EXCPS. It allowed the 11th bit to be written and read as set. Fixed by removing it from the DELEGABLE_EXCPS mask, adhering to the specification. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3438 Signed-off-by: Abhigyan Kumar <314abh@gmail.com> Reviewed-by: Alistair Francis Message-ID: <20260427060849.749179-2-314abh@gmail.com> [ Changes by AF: - Remove comment ] Signed-off-by: Alistair Francis (cherry picked from commit a0946caf1d9ec21446ebdcb5eab2400baa4323ae) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index c52c35efc4..c4d2ab0858 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -1790,7 +1790,6 @@ static const uint64_t all_ints =3D M_MODE_INTERRUPTS = | S_MODE_INTERRUPTS | (1ULL << (RISCV_EXCP_U_ECALL)) | \ (1ULL << (RISCV_EXCP_S_ECALL)) | \ (1ULL << (RISCV_EXCP_VS_ECALL)) | \ - (1ULL << (RISCV_EXCP_M_ECALL)) | \ (1ULL << (RISCV_EXCP_INST_PAGE_FAULT)) | \ (1ULL << (RISCV_EXCP_LOAD_PAGE_FAULT)) | \ (1ULL << (RISCV_EXCP_STORE_PAGE_FAULT)) | \ --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381396; cv=none; d=zohomail.com; s=zohoarc; b=FLBN/OLzevByDJhmy6+qg9dFnubZn+OevVutSy9D3kDuNq6Mi336IxTczvJrWo4x+WKcXpdigqI1tGetQbiTIPsOy/Ttr/nfCPAQ+GYar6rzM8QozZPNgBc/AjsRjqZnWdBlneZu9gM5pGn3UAN54duQ5A8PVqDmAUezEEN068g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381396; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=OFdWUcOe3TbA7qBswSiq/nzhoG3m7gw0kJeE3eglm88=; b=c7Wsl72n7rNH6PtUPdJYk0bghs6oQsMOjchsJt9DK3sEebqpvqcVFbdm0ZW66Safvnld/YiIDvgsMwibZQgR1C0RCpAVIojoi+lsOfDwPSnzGRxzAYBsPM+eOkmLLsnpGaw7EWlDWXoTFiwIUsMD7oeBeDBGuP8+hG1534N5Omg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381396186347.0418506632301; Sat, 13 Jun 2026 13:09:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUbL-000886-GA; Sat, 13 Jun 2026 16:05:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbJ-00087A-KI; Sat, 13 Jun 2026 16:05:05 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbH-0008Lj-H9; Sat, 13 Jun 2026 16:05:05 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 77B6A1B6E70; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id CF3E13CE8D3; Sat, 13 Jun 2026 23:04:45 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=K/2M/YfypKeoQSCUkywskKAY1uAxR35uq7wX055EdlE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=LQwzxBpkOM/8byeHLNKKtFDv9PX3DBMRRU7mpSL2Bm9O3WxmkYCm21HsJIvHMLwID xXo6/oHppksH/tOTYmirtI9OxYTlHN64jbI+4zg+WZN3w9wQ5BQpZ49rH+iqs0H6N/ TdtydQuTiUzlXjkoIVUxIvzqPBFkFmboNgvofVr0j5UnD1alKEk6mhN3f8RowhGL/M 4znNEP0GbnbGFjdv9Mf4YlKQ3t/7rWv03U0KoJO9FMngGmU7GE64pTEmaszm9c6zrn j//JumLEzkUkKaBsxNt4bTRO4GG0SWTBYGQ1QW+IGJ4eO6ViP9n2U//ukocDXQcRVJ 8qgpHfRAb+/QQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Alistair Francis , Daniel Henrique Barboza , Michael Tokarev Subject: [Stable-10.2.4 09/61] target/riscv/pmp: Fix integer overflow in TOR and NA4 address computation Date: Sat, 13 Jun 2026 23:02:52 +0300 Message-ID: <20260613200411.1808021-9-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381398387158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi According to the RISC-V Privileged Manual: "The Sv32 page-based virtual-memory scheme described in sv32 supports 34-bit physical addresses for RV32, so the PMP scheme must support addresses wider than XLEN for RV32." However, the current QEMU implementation uses `target_ulong` (which resolves to `uint32_t` on RV32) for PMP address variables. When shifting these addresses left (e.g., `this_addr << 2`), an integer overflow occurs, truncating the high bits of the 34-bit physical address. Fix this issue by changing the types of PMP address variables (`this_addr` and `prev_addr`) to `hwaddr`. This issue was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-isa-m= anual/pr-2472/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Alistair Francis Reviewed-by: Daniel Henrique Barboza Message-ID: <20260511102627.3120140-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 612f22c19db8adbe9b155f199ede01e86cc1546c) Signed-off-by: Michael Tokarev diff --git a/target/riscv/pmp.c b/target/riscv/pmp.c index 3ef62d26ad..f97b084efd 100644 --- a/target/riscv/pmp.c +++ b/target/riscv/pmp.c @@ -215,8 +215,8 @@ static void pmp_decode_napot(hwaddr a, hwaddr *sa, hwad= dr *ea) void pmp_update_rule_addr(CPURISCVState *env, uint32_t pmp_index) { uint8_t this_cfg =3D env->pmp_state.pmp[pmp_index].cfg_reg; - target_ulong this_addr =3D env->pmp_state.pmp[pmp_index].addr_reg; - target_ulong prev_addr =3D 0u; + hwaddr this_addr =3D env->pmp_state.pmp[pmp_index].addr_reg; + hwaddr prev_addr =3D 0u; hwaddr sa =3D 0u; hwaddr ea =3D 0u; int g =3D pmp_get_granularity_g(env); --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381396; cv=none; d=zohomail.com; s=zohoarc; b=Al+3ey68P78R0IlW8nwrXWZB5KoWKLm7QDunt8ipCkZ1IsrqCpt/vOIzU2oDtW4YE7RRFN2L8w5hYE8FPuuy9pEv94Ur4a5NyqipVh59ZtQoRNaqC5U06drtG0dCJJf6IhcntyCgu33UJVHzH+JEMRqPQVojHZxqc64zslndVhI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381396; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9R16Wc0mn73sA66GH7j5xz0E+Tfqd3K2Ow3LAHbE+7A=; b=Le6SYiBoNB+dKELV6Hg8VCycvk/qZG8pXTRuuhIgxoS9iMyMRx5NHCWZj66aBSc3VPqVNRkk7hu7vGKqEh/7JxmgKnvwAYuU8NUkAfKXUcetlKGSD7nVIpM4EQK99IoPwcShN2pfPai5yE2T6+7qSW9jJVlJo3iBliEyScVsRvo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381396713160.025738805498; Sat, 13 Jun 2026 13:09:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUbO-0008A8-5i; Sat, 13 Jun 2026 16:05:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbJ-00087O-Pi; Sat, 13 Jun 2026 16:05:05 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbH-0008MA-QZ; Sat, 13 Jun 2026 16:05:05 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 88CAB1B6E71; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E4ADC3CE8D4; Sat, 13 Jun 2026 23:04:45 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=6ihxfYXP3fuUJ0eR2tjhR/1P86781N2QdMQNSeeBnjI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=WVGtfCQ64q1QmpE5IiaK8ulO4EoSaUfLbEOrdhwx+LnB+pONz4lPCb0bXpcNYFRkZ byKtbiGGUeiofA0hj+kW2myHXcxLbAy1DeomaeDaZemlXuMzcC5lVPWgvsUBVeeMHj Qat32OFJlehS9jap+Nm5DzKfzvcl+78XWZKqZUVZyZ7XqMPm4ysYlLsLVToQsAK7sU Wnr6KioyaHbD4xMApo/iyS2LkXyXtaZq0CLwuhZAmqtGxCwWlY0p0XCkwhvo2HmeEH fJ4+NdREprD/oFGEM4kas2ex7fF59ggPIOVF1gpG+8b8ebMPgZ/K7JUo4x4aZcBqGu phnWzo0Je3O6A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Alistair Francis , Michael Tokarev Subject: [Stable-10.2.4 10/61] target/riscv: Add mseccfg to VMStateDescription Date: Sat, 13 Jun 2026 23:02:53 +0300 Message-ID: <20260613200411.1808021-10-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381398378158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi Currently, the Machine Security Configuration Register (mseccfg) was missing from the live migration state. This omission causes the register to be reset to zero on the destination host after migration. Fixed by adding vmstate_mseccfg subsection This vulnerability was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/a22e4459cd026ae970791dfbd= 9cfe5d110fbd46b/output/riscv-isa-manual/pr-1879/qemu.txt#L121 Signed-off-by: Zishun Yi Reviewed-by: Alistair Francis Message-ID: <20260511124828.3210477-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit eccb1d6940256668109dc6dc42450ced9f324134) Signed-off-by: Michael Tokarev diff --git a/target/riscv/machine.c b/target/riscv/machine.c index 18d790af0d..72d0668622 100644 --- a/target/riscv/machine.c +++ b/target/riscv/machine.c @@ -425,6 +425,25 @@ static const VMStateDescription vmstate_sstc =3D { } }; =20 +static bool mseccfg_needed(void *opaque) +{ + RISCVCPU *cpu =3D opaque; + + return cpu->cfg.ext_smepmp || cpu->cfg.ext_zkr + || cpu->cfg.ext_smmpm || cpu->cfg.ext_zicfilp; +} + +static const VMStateDescription vmstate_mseccfg =3D { + .name =3D "cpu/mseccfg", + .version_id =3D 1, + .minimum_version_id =3D 1, + .needed =3D mseccfg_needed, + .fields =3D (const VMStateField[]) { + VMSTATE_UINTTL(env.mseccfg, RISCVCPU), + VMSTATE_END_OF_LIST() + } +}; + const VMStateDescription vmstate_riscv_cpu =3D { .name =3D "cpu", .version_id =3D 10, @@ -502,6 +521,7 @@ const VMStateDescription vmstate_riscv_cpu =3D { &vmstate_ssp, &vmstate_ctr, &vmstate_sstc, + &vmstate_mseccfg, NULL } }; --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381214; cv=none; d=zohomail.com; s=zohoarc; b=mV7ulHqdtryskCkezv6jWG1szE8SYK5Pzss0luygHkc3kXixk8Rg2LUtvbMRLYke+lpHroLE5agKXqzSdwyDZ7BTAWxFJd/v9eye/qYM+lk6HoqebDINy9OLuQUxwNpJ454yZhFMGxuDm2ZdoF9VHweZ2aIn0LgpmCM0Yq7q24Y= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381214; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=G1dYxohIm7VenqrcoRVhVjL+vLE0tlDLgVBOJI5LGSE=; b=YIgnxJEgKd+MynHyahpHW9RAXipwxmGjPw41Olvz6HbbYMNyVAsAOwhh04fMZXV7H07hRaTfV/TQEFECAUgxlTieN9fKFFXRVcgEZIlK2TxL2IWgmQnE3YePw7Lry9gCmZTO81J/YCXtFUyt4zX3K1uHokKKvnZnCVDY//zj4ng= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381214580390.83301797555544; Sat, 13 Jun 2026 13:06:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUbk-0000kx-9K; Sat, 13 Jun 2026 16:05:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbi-0000jX-M2; Sat, 13 Jun 2026 16:05:30 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbg-00008J-PK; Sat, 13 Jun 2026 16:05:30 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 96CD41B6E72; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0103F3CE8D5; Sat, 13 Jun 2026 23:04:45 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=/8ifPBxZlwCsqlqjCb5a62kMT5TB9JBejzqETOq+3lk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ijyLG9DNEZn8mxujey/tkl7G2giEZb4O0selkaDH8MI+nKABgxWrx6ZYf79+0IZeA PtNwOT6lX2rwkgJXbwGngTrdUCqIqaEHt/Djle7HItEXRYxGssBIF/bYHBfkedtv81 h8V+mk+obKZB4OFXDba93ppxTNh7Yh+Un+wCionx5Kgo8YjxwZbLsS1FXvr3kj6N4J o11FJ9F+5YS/ircB1PvHxNkt9cGE1RqQn/fo1IM1BJMW+qHVrvh10tSlOMD4xsR8cQ TEFwcSwGLo9y+yF9lJFaQzUQjH5MTRsim6bDsfgaIqKc/VI31xNtRRx+2thF6tpPjb Ih63ORi0j+gPQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alistair Francis , Daniel Henrique Barboza , Michael Tokarev Subject: [Stable-10.2.4 11/61] target/riscv: Update the local interrupt mask Date: Sat, 13 Jun 2026 23:02:54 +0300 Message-ID: <20260613200411.1808021-11-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381215389158501 Content-Type: text/plain; charset="utf-8" From: Alistair Francis The RISC-V spec describes bits 0-15 as standard fixed interrupts. The AIA spec on the other hand describes bits 0-12 as standard fixed interrupts. This conflict causes issues for us as we don't dynamically determine if AIA is enabled when setting the *delegable_ints consts. This means currently we incorrectly treat the LCOFIP bit as delegable, even if AIA is disabled, which is incorrect (see the issues mentioned below). The AIA spec indicates that implementations can determine which bits of 13-63 in mvien are writable, so let's just make it bits 15-63 to match the main spec. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3133 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3134 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3135 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3138 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3140 Signed-off-by: Alistair Francis Reviewed-by: Daniel Henrique Barboza Message-ID: <20260513051841.1671987-1-alistair.francis@wdc.com> Signed-off-by: Alistair Francis (cherry picked from commit 27f9566dcd98bdde045ef5ae7b8199456c8a51c1) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index c4d2ab0858..c360f77c92 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -1765,13 +1765,13 @@ static RISCVException write_stimecmph(CPURISCVState= *env, int csrno, #define VSTOPI_NUM_SRCS 5 =20 /* - * All core local interrupts except the fixed ones 0:12. This macro is for + * All core local interrupts except the fixed ones 0:15. This macro is for * virtual interrupts logic so please don't change this to avoid messing up * the whole support, For reference see AIA spec: `5.3 Interrupt filtering= and * virtual interrupts for supervisor level` and `6.3.2 Virtual interrupts = for * VS level`. */ -#define LOCAL_INTERRUPTS (~0x1FFFULL) +#define LOCAL_INTERRUPTS (~0xFFFFULL) =20 static const uint64_t delegable_ints =3D S_MODE_INTERRUPTS | VS_MODE_INTERRUPTS | MIP_LCOFIP; --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381262; cv=none; d=zohomail.com; s=zohoarc; b=hh9FO1ikId+3Z5q+pk7iP8oklkCfYMzuhVqu/w5rDFuQK0lYs+3moOfHh8MmT/dGji8HHbCRXsKWvf95sZigiV5g+BKSKnFzb3IyZL+fG0yN1EoXFbpxSHd4dWpbNVKIFQxw1wm4XFx2h57oEhKM9qxvtFqZx03FdKJYTq1fdNk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381262; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4YuCGhlVkg9t5palDS87fjwUUzXBBFbja1oRwGAYegw=; b=fvtWh8tf3xiVjx9pf95E723EGlFnvmOlIlBPBh0O5zLPhycVRP1QiMltE1HmtQSVO5PdCBCLs0TrmcM8rAMRtOefSeFP+z+A2Kit2qqQ1yAGMRu0QRN4p/fh/yQgcHH8ITw5c9o2Fx8jUDvz41q3nV0kRxSrQ5PY3RSxR2jApgA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138126281777.37403029725374; Sat, 13 Jun 2026 13:07:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUbP-0008Gy-Ub; Sat, 13 Jun 2026 16:05:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbO-0008AD-64; Sat, 13 Jun 2026 16:05:10 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbM-00008M-Ay; Sat, 13 Jun 2026 16:05:09 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A6E8A1B6E73; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0FE1D3CE8D6; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=vN1tXsRI4q1sMHMFwDoc8WDDIJjrazVuNF6Lz6vNf2s=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=XpLL/8OCpV8EAhPWKQjiopwW5Gy+3XSl6pX7QX90hABninQ0ztcWjoVo1MSORyHhO 0ZMluJ6E7BU1U+4nwyujz/fwDqO+n2WgOJNWPZhOHgkka76ZTRGoAzC6zgJ+4cnBCe rACCakvEKxd2GbbSLVd3N9T1f0hbOpN54CQw6W/J0y1FpRMsLjYW8ei8ml6RDoZLep ETVqsQGBDbw7avZ/Rs2tkml7IYmkWMqjElkpMi2VVYLANgg7L9l+8ijFZVENPm3NSd NzDVKVh0Lsu6/vPchfhum/7/dmJlCFBYHQyLOpJzmaNJAUCFtoj5xFF4XNropsy4L5 Ofb2vIBvcV7Pw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.2.4 12/61] target/riscv: clear mseccfg on reset for all dependent extensions Date: Sat, 13 Jun 2026 23:02:55 +0300 Message-ID: <20260613200411.1808021-12-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381263566158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi Currently, the `mseccfg` CSR is only cleared to 0 during reset if the `ext_smepmp` is enabled. However, this register is now shared by several other extensions such as `zkr`, `smmpm`, and `zicfilp`. Fix by clearing `mseccfg` if any dependent extension is present, and adjusting the relevant comments. This vulnerability was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-svvpt= c/pr-134/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Daniel Henrique Barboza Message-ID: <20260512052240.330815-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 8158a74f0a0db8626d7836eb03eca7aba46c18b5) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu.c b/target/riscv/cpu.c index 73d4280d7c..b41c5a2c08 100644 --- a/target/riscv/cpu.c +++ b/target/riscv/cpu.c @@ -755,10 +755,14 @@ static void riscv_cpu_reset_hold(Object *obj, ResetTy= pe type) =20 /* * Clear mseccfg and unlock all the PMP entries upon reset. - * This is allowed as per the priv and smepmp specifications - * and is needed to clear stale entries across reboots. + * This is required as per the priv, smepmp, and other security + * extension specifications that share this CSR, and is needed + * to clear stale entries across reboots. */ - if (riscv_cpu_cfg(env)->ext_smepmp) { + if (riscv_cpu_cfg(env)->ext_smepmp || + riscv_cpu_cfg(env)->ext_zkr || + riscv_cpu_cfg(env)->ext_smmpm || + riscv_cpu_cfg(env)->ext_zicfilp) { env->mseccfg =3D 0; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381351; cv=none; d=zohomail.com; s=zohoarc; b=c0pwxU2eTCZKsL9uyrq/AWZtvEDHbx0OcEAA3UZD00ykK4BHiXxT4RHrqy9YYweFBK+hDQqpOQtAt5WPlmB9Ob5Ut/qmeMncNZU6uYMCNTD5L+dlYT24o7nroFvsT8BWSI+2gOYvRX8hi/YGC2NvfZIHCGE+0At12eWe7Z0DL3k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381351; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=phdAqy767+SUQIojItNPrPKrErNhFI4f4DooScsxB+Q=; b=YJ7/DqKhKR6ztzuI7YmJRVrUdaqz2Jke/aJAPO5AAWpFO/JjgsFtdnPaLO6CY+QC0aJ6ZAoe7nhI9FUxtb59VrJirJmahvRRHZTP9PdYiVpg+ujvRI5b4s/YGmILoNLtRCwlIfCPc3hAS80+m7AuqIQCOn22q5eWKf2p+1cisgo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381351621172.5101716475831; Sat, 13 Jun 2026 13:09:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUbr-0000rg-EQ; Sat, 13 Jun 2026 16:05:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbm-0000mo-Cj; Sat, 13 Jun 2026 16:05:35 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbk-0000DE-AD; Sat, 13 Jun 2026 16:05:34 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B5B8B1B6E74; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1F7273CE8D7; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=ip2pqWDKYOwxi3LwiZS0HA5t1/dp131pu1KfGKKzz+4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=NIVNb1ViKjKtpjuIIgg04XzVPUqadOdXgCtTOAUBu9Qy/1df1n0dqDJK8XDcttGV3 ztHvhtVth1i9YNYo8oy6RaRFXB4SFy9Nlf6NvXTMNlmshbH8mwHGzIE6iV2n/5AhyP t1h3QRk0VyO0XJJLkDfzt3exsewY5WpU8ZWjiGInIWeeK7ENVwwB/oMoQgLGHjbpeA vTrTO5AYrHkwSCxLY3/OiUIvFH3q3akT5Gw0GIYU07NnOFZdJ3lnTjgimgXrsIEsID KhgotmUzjce6IMpDiSka4f9iAlSWcJYV0OM0THQlm9bH+39+l7tUsanwh7PSOe7ofX heZes8gWxK/dQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-10.2.4 13/61] target/riscv/csr.c: fix read of pmpaddr(0-63) CSRs Date: Sat, 13 Jun 2026 23:02:56 +0300 Message-ID: <20260613200411.1808021-13-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381352110158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza The priv spec defines, for RV64, that the upper 10 bits of pmpaddr0-pmpaddr63 are WARL and are supposed to be cleared. After this patch, using the bug reproducer in [1], writing ffffffffffffffff in pmpaddr0 and reading it back now results in 003fffffffffffff. Here's the 'diff -cp' dump before and after this change: *************** IN: *** 5272,5278 **** pmpcfg10 0000000000000000 pmpcfg12 0000000000000000 pmpcfg14 0000000000000000 ! pmpaddr0 ffffffffffffffff pmpaddr1 0000000000000000 pmpaddr2 0000000000000000 pmpaddr3 0000000000000000 Reviewed-by: Alistair Francis Message-ID: <20260514123342.2139464-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 53cc9747ed7c9b95ba084d614976dd48c9a57a97) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index c360f77c92..9f81cd3960 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -5328,6 +5328,23 @@ static RISCVException read_pmpaddr(CPURISCVState *en= v, int csrno, target_ulong *val) { *val =3D pmpaddr_csr_read(env, csrno - CSR_PMPADDR0); + + /* + * For RV64, bits 54-63 of the address registers + * PMPAADDR(0-63) is a WARL zero field (priv spec, + * section "Physical Memory Protection CSRs"). + * + * We'll have to add an annoying TARGET_RISCV64 gate + * here to avoid complaints about masking bits 0-53 + * of a potential 32 bit target_ulong '*var'. + */ +#ifdef TARGET_RISCV64 + if (env->misa_mxl =3D=3D MXL_RV64 + && csrno >=3D CSR_PMPADDR0 && csrno <=3D CSR_PMPADDR63) { + target_ulong read_mask =3D MAKE_64BIT_MASK(0, 54); + *val &=3D read_mask; + } +#endif return RISCV_EXCP_NONE; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381155; cv=none; d=zohomail.com; s=zohoarc; b=ZoJlUTZ/u67x0wnsizS0OzUZ9/8WOkuGgMME6fIfPgHCKRcWPEvXQKefdZJIU/ciNlvOc0HHY0O7HgDS+nkG944EZ6AMKoDkkmJtsCrrsi43lKAAA/+yyjv+bmHHs2Yo32krX5hilE09ZVZVKIZHHVNz1M7UjPV/O2VHnnYgPPc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381155; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=pby/DNkEDKLCWfWpY4ntSB6WG9nu650GoJXazxzGKDk=; b=h8UJN0bJG+xMk8TzZMxkdk2pK/KwRTE0/bPdvq2W+gJkO5R0GPQYzfkt61CNqhfW6iXYNWD9s2s9HiPjtxswxfHX/aCQqk4Rrnhrw32sk4oNgoiKvJ/4oy8OiGnxZPQqJ5l6JGGHwr7uLXOztbmKV16ZxcwquVmJe910sndPTxY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381155907296.67800831638306; Sat, 13 Jun 2026 13:05:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUc0-00017J-Ur; Sat, 13 Jun 2026 16:05:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbn-0000nO-Sv; Sat, 13 Jun 2026 16:05:35 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbk-0000LY-Q4; Sat, 13 Jun 2026 16:05:34 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C578C1B6E75; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 2F0D53CE8D8; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=VpUXHEeZq4VCjeyy0rgRt2Of/KA2IN5KTxh0zZi1P0I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=SGr9nygYjurYFm2js2BTMkf0yH6sXDpkIelQN3cyGjkzIJgztONGQBC20LihF8KLc ipIX8isFbkUJdSB+/kb9b/0xx4b81kUoIAt2yd5gEzFeR6vFUapCeyvd6zGxSB0LZD 3bmSEZH6RVyAkTOifu6Xvbj8R1u88ceMg6Xl0YXNPKulRe90+y3SYo81m6dy/PGm5M hnNIOwcm2swIhgO9BcWEutGRmWeAqA5Y2oEpWuzBxCG+i+vQH50kEpQeCLqwZ5I8bq puSfqb59obqVm55gDnbp6ex6p+2dmNKDai7LVpCaM55qgzZaH+QS92lULfjFzdWOVJ 4uNKHQDG481ng== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-10.2.4 14/61] linux-user/mips64: fix elf_core_copy_regs register layout in core files Date: Sat, 13 Jun 2026 23:02:57 +0300 Message-ID: <20260613200411.1808021-14-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381157219158500 From: Matt Turner mips64/elfload.c uses #include "../mips/elfload.c" to share code. When the compiler processes mips/elfload.c the quoted #include "target_elf.h" resolves relative to the including file's directory, so it picks up mips/target_elf.h instead of mips64/target_elf.h. mips/target_elf.h pulls in mips/target_ptrace.h, whose target_pt_regs has a pad0[6] field before regs[]. As a result elf_core_copy_regs writes: r->pt.regs[i] -> reserved[6+i] (shifted by 6 from the correct index) r->pt.cp0_epc -> reserved[40] (correct mips64 N64 index is 34) The Linux kernel and glibc both use the mips64 N64 layout (no pad0): EPC at reserved[34]. Debuggers and libunwind reading the core with N64 constants therefore see a completely wrong register set =E2=80=94 EPC point= s to GP, RA holds the branch target instead of the link address, etc. Fix by: - Guarding the mips32 elf_core_copy_regs in mips/elfload.c with #ifndef TARGET_MIPS64 so it is not compiled for mips64/mipsn32 targets. - Providing a mips64-specific elf_core_copy_regs in mips64/elfload.c that writes directly to r->reserved[i] with the correct N64 indices, bypassing the struct field names that are tainted by the wrong header include. The mipsn32 (TARGET_ABI_MIPSN32) and mips64el targets are covered by the same mips64/elfload.c and benefit from the same fix. Signed-off-by: Matt Turner Cc: qemu-stable@nongnu.org Signed-off-by: Helge Deller (cherry picked from commit dd3a906d3505561d9cb3367b82c5475acca50b6b) Signed-off-by: Michael Tokarev diff --git a/linux-user/mips/elfload.c b/linux-user/mips/elfload.c index cc5bbf05ab..1a46e180cf 100644 --- a/linux-user/mips/elfload.c +++ b/linux-user/mips/elfload.c @@ -131,6 +131,7 @@ const char *get_elf_base_platform(CPUState *cs) #undef MATCH_PLATFORM_INSN =20 /* See linux kernel: arch/mips/kernel/process.c:elf_dump_regs. */ +#ifndef TARGET_MIPS64 void elf_core_copy_regs(target_elf_gregset_t *r, const CPUMIPSState *env) { for (int i =3D 1; i < ARRAY_SIZE(env->active_tc.gpr); i++) { @@ -146,3 +147,4 @@ void elf_core_copy_regs(target_elf_gregset_t *r, const = CPUMIPSState *env) r->pt.cp0_status =3D tswapl(env->CP0_Status); r->pt.cp0_cause =3D tswapl(env->CP0_Cause); } +#endif diff --git a/linux-user/mips64/elfload.c b/linux-user/mips64/elfload.c index b719555e65..9081ae8111 100644 --- a/linux-user/mips64/elfload.c +++ b/linux-user/mips64/elfload.c @@ -1 +1,30 @@ #include "../mips/elfload.c" + +/* + * mips/elfload.c defines elf_core_copy_regs guarded by #ifndef TARGET_MIP= S64. + * + * We must provide the mips64 version here. We cannot use r->pt.regs[] be= cause + * when mips/elfload.c is #include'd above its "#include "target_elf.h"" r= esolves + * to mips/target_elf.h (compiler searches the including file's directory = first), + * which pulls in mips/target_ptrace.h. That struct has pad0[6] before re= gs[], + * so r->pt.regs[i] writes to reserved[6+i] =E2=80=94 offset by 6 from wha= t the kernel + * and glibc expect for the N64 ABI (EPC at reserved[34], not reserved[40]= ). + * + * Write directly to reserved[] using the mips64 N64 index layout: + * R0-R31 at reserved[0..31], LO at [32], HI at [33], EPC at [34]. + */ +void elf_core_copy_regs(target_elf_gregset_t *r, const CPUMIPSState *env) +{ + /* R0 is always 0; r->reserved is zero-initialised by the caller */ + for (int i =3D 1; i < 32; i++) { + r->reserved[i] =3D tswap64(env->active_tc.gpr[i]); + } + r->reserved[26] =3D 0; /* k0 */ + r->reserved[27] =3D 0; /* k1 */ + r->reserved[32] =3D tswap64(env->active_tc.LO[0]); + r->reserved[33] =3D tswap64(env->active_tc.HI[0]); + r->reserved[34] =3D tswap64(env->active_tc.PC); + r->reserved[35] =3D tswap64(env->CP0_BadVAddr); + r->reserved[36] =3D tswap64(env->CP0_Status); + r->reserved[37] =3D tswap64(env->CP0_Cause); +} --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381170; cv=none; d=zohomail.com; s=zohoarc; b=ToZWz03BHO+UPZB9+eWYod240RPjCQYX6uY4JYVhx0lEb1FLfOP3tOMdSbDjP9Fkc+bDvxlanabJ7u47pa9AXSqZu54pvonQREPCjQfBPCREfgLdcqy3laj2cTqKAb1oIKSABIUR3r+xV89riyrqsaZkdIVpUQ1WF/XU5ZxkJ5M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381170; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rRd80eVCDzT4CYprjOUGBtpOF7UOLQaMHwId3i53lek=; b=GvC/GPUJLgFfDpaglOKvVobkg+KBtO8DiRd66b7eP8xGSp3oGb5iF7wCRK+ulbuFouv//Jp9PF/xSrmDj1HOUlODW0IDAmHUGF36M8h2TXlGf7i3AEn2Vp5/xpMIOq/sV+L3sEhvVYJEnTqkIBjWuZHd8ZCf8gmRvU7JFQYI2mY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381170381202.3195636804619; Sat, 13 Jun 2026 13:06:10 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUc9-0001Ov-Rk; Sat, 13 Jun 2026 16:05:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbr-0000xY-Nz; Sat, 13 Jun 2026 16:05:41 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbo-0000M7-ED; Sat, 13 Jun 2026 16:05:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D4CE91B6E76; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 3E93F3CE8D9; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=5LTbrdiZZKvPaIrNvB8ScBmmfWMVGkV6wGymiQXW1SQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=x1PUgjq30v7lgqMV1eOUiyRFySfJjD9gVCvs1qzXQRDn31tB5O9BoQgfPzcUt/K49 ssOJ2vf7X7Uc3UMmzv/ZDpgMzK4crBuvB2kwh01pJRkbYTqbOoBVtfDRXjCoDGyfPL ZmSiQiXnMlXHflZ749UwZ2pu3BULu4ZwhegN1yu7O8TRuQwljsHktEAZo5Up2Wojvi Eu7fFOuXiL3+l+e+gAgFVYRhDZv3vvC3ncMkI3FZ02LAZDjh99N3ihkwNQhzAZOmdo xCHJoWOZsYdJ/vD3u/GNUT7mudx9xhMCb0TWNak507Y7261YCFmM6eQuaUjRtTBf6m 1wiZYExJCyrow== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-10.2.4 15/61] linux-user/mips64: fix mipsn32 elf_core_copy_regs entry width Date: Sat, 13 Jun 2026 23:02:58 +0300 Message-ID: <20260613200411.1808021-15-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381171283158500 From: Matt Turner For mipsn32 (TARGET_ABI32=3Dy, TARGET_LONG_BITS=3D64): abi_ulong =3D uint32_t (4 bytes) =E2=80=94 for pointers and ABI-sized fie= lds target_ulong =3D uint64_t (8 bytes) =E2=80=94 for general-purpose registe= rs linux-user/elfload.c allocates target_elf_prstatus using the mips64/target_elf.h definition where target_elf_gregset_t has target_ulong reserved[45] (8 bytes each, 360 bytes total). However, in linux-user/mips64/elfload.c, #include "target_elf.h" inside the included mips/elfload.c resolves to mips/target_elf.h (compiler searches the file's own directory first), where the union uses abi_ulong reserved[45]. For mipsn32 this gives 4-byte entries (180 bytes), not the 8-byte entries (360 bytes) that elfload.c actually allocated. Writing via r->reserved[34] therefore lands at byte offset 34*4=3D136 instead of the correct 34*8=3D272, silently zeroing the EPC in the core file. Fix by casting the pointer to target_ulong * so writes always use 8-byte slots and land at the offsets matching the allocated layout. This does not change behavior for mips64 (N64) where abi_ulong already equals target_ulong (both 8 bytes). Signed-off-by: Matt Turner Cc: qemu-stable@nongnu.org Signed-off-by: Helge Deller (cherry picked from commit 6033df08e93df313771b6637230de2d66bdc09cb) Signed-off-by: Michael Tokarev diff --git a/linux-user/mips64/elfload.c b/linux-user/mips64/elfload.c index 9081ae8111..e4d84a7bd6 100644 --- a/linux-user/mips64/elfload.c +++ b/linux-user/mips64/elfload.c @@ -15,16 +15,31 @@ */ void elf_core_copy_regs(target_elf_gregset_t *r, const CPUMIPSState *env) { - /* R0 is always 0; r->reserved is zero-initialised by the caller */ + /* + * linux-user/elfload.c allocates target_elf_prstatus using the + * definition from mips64/target_elf.h, where target_elf_gregset_t + * has target_ulong reserved[45] (8 bytes each =3D 360 bytes total). + * + * But in this compilation unit, "#include target_elf.h" resolved to + * mips/target_elf.h (wrong directory), so our local target_elf_gregse= t_t + * has abi_ulong reserved[45] which is only 4 bytes each for mipsn32. + * Using r->reserved[i] would write to the wrong offsets for mipsn32. + * + * Cast to target_ulong * to always write 8-byte entries at the correct + * positions, matching the layout that elfload.c allocated. + */ + target_ulong *regs =3D (target_ulong *)r; + + /* R0 is always 0; buffer is zero-initialised by the caller */ for (int i =3D 1; i < 32; i++) { - r->reserved[i] =3D tswap64(env->active_tc.gpr[i]); + regs[i] =3D tswap64(env->active_tc.gpr[i]); } - r->reserved[26] =3D 0; /* k0 */ - r->reserved[27] =3D 0; /* k1 */ - r->reserved[32] =3D tswap64(env->active_tc.LO[0]); - r->reserved[33] =3D tswap64(env->active_tc.HI[0]); - r->reserved[34] =3D tswap64(env->active_tc.PC); - r->reserved[35] =3D tswap64(env->CP0_BadVAddr); - r->reserved[36] =3D tswap64(env->CP0_Status); - r->reserved[37] =3D tswap64(env->CP0_Cause); + regs[26] =3D 0; /* k0 */ + regs[27] =3D 0; /* k1 */ + regs[32] =3D tswap64(env->active_tc.LO[0]); + regs[33] =3D tswap64(env->active_tc.HI[0]); + regs[34] =3D tswap64(env->active_tc.PC); + regs[35] =3D tswap64(env->CP0_BadVAddr); + regs[36] =3D tswap64(env->CP0_Status); + regs[37] =3D tswap64(env->CP0_Cause); } --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381189; cv=none; d=zohomail.com; s=zohoarc; b=OurukNn1395qI5OHvI5kWUPDCeQzdIKyKomgoi4/LTefS3GlgB3k+4mgU/EQgqDLm/F5tu3ozzQWHMbf9wI0eS7HB7li2TkTatmMzZHmIHFr7msg4M38xAhckTMwXD2BejxdYR/2D6JUazQz3foj+c9yACPElF1DV2Qhsa5qGE0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381189; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=klO2C5fuiH+pcM9N8CegDHYpQsR7G1+1pGiLzLuAgTU=; b=NzkYqx7tjnR0nS58LZdx4vKQqLVtYjYds1ESqKZdPVYDaRHs7WoUanF7hKgrGABVyfvKvhQr5L0qJlYq3LuQAQG5GIr9Vk4gSZh1wUuHnnGstN/DdTh6jzv8bY634kGiiGStS8vKu74SlCAD9lrpvY4ljJzUpq0FxWtKKinS/Pc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381189496766.0743408839112; Sat, 13 Jun 2026 13:06:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUcF-0001RY-8x; Sat, 13 Jun 2026 16:06:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbt-00011C-4G; Sat, 13 Jun 2026 16:05:41 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbq-0000MQ-0P; Sat, 13 Jun 2026 16:05:40 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E70541B6E77; Sat, 13 Jun 2026 23:04:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 4E5F33CE8DA; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381067; bh=oeWCQUoPxo3Y5KEpbVvM3clq9pSKvlzk66CPh2w8/2o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=fs6rDEHQzKZ4tekiBAQsK9eUznHawWhSbpo82vy8ov14KKOzmOJG/8yrtOKB9ypyT oQmxp2DkkwIVdDR+u/NsQBi6ofrS1R/IYcrF5gYE+JeubBqT1a6HUnRM9YOCnQlis4 QvQwwKlO5+X+lbil2Apen2wN2hntlDsPxRctn+hGtgfvJimoyOYYVvqfXIyEwp2VQp YkGzoLdsN4q0FI10a5Gx3jD1J8DD2oWkIT3+viJ8Gq5tWeGkbK881ZK4OqZjSVAKZF qOXIcBlUj/tEvQv+FJd3GnvUEWLGturyqOXcs97dq33OQnSUYq644EizBRKN3UyOCO GXqs+PCUvDdUg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-10.2.4 16/61] ui/vnc: fix OOB read access in VNC SASL mechname array Date: Sat, 13 Jun 2026 23:02:59 +0300 Message-ID: <20260613200411.1808021-16-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381191260158500 From: Daniel P. Berrang=C3=A9 When reading the SASL mechname array off the VNC connection, if malicious, the received data may contain embedded NULs. If this happens the memory buffer returned by g_strndup may be shorter than the original data. Unfortunately the code continued to index into this buffer with an offset equal to the original length. This is a potential OOB read of the array. Fixes: 5847d9e1 (ui/vnc: simplify and avoid strncpy) Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-2-berrange@redhat.com> (cherry picked from commit ae18df638fb4285c7b645f98c43f5ebc2e123a55) Signed-off-by: Michael Tokarev diff --git a/ui/vnc-auth-sasl.c b/ui/vnc-auth-sasl.c index 3f4cfc471d..9f15980fca 100644 --- a/ui/vnc-auth-sasl.c +++ b/ui/vnc-auth-sasl.c @@ -490,6 +490,8 @@ static int protocol_client_auth_sasl_mechname(VncState = *vs, uint8_t *data, size_ char *mechname =3D g_strndup((const char *) data, len); trace_vnc_auth_sasl_mech_choose(vs, mechname); =20 + /* If 'data' had embedded NUL the dup'd string might now be shorter */ + len =3D strlen(mechname); if (strncmp(vs->sasl.mechlist, mechname, len) =3D=3D 0) { if (vs->sasl.mechlist[len] !=3D '\0' && vs->sasl.mechlist[len] !=3D ',') { --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781386871; cv=none; d=zohomail.com; s=zohoarc; b=V9hYlYlyX+EshyfDnMIRehWxAswWkPaS+9Gs/0T5TReMourBrJRtnYuhPUkp7LvqMzMNFm7c5b+dJFM1mlsYfdPmGKrUZc+UU8trm32pfAEZM079y2l5NrJvtJKQes5fTk8NiWTObrYpHhcOufzsxg0aQBGohCe2g4PzgY1OxHM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781386871; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EhY38HvDVXyHmu318ZV4NMF/jUScLxYr7FlRgTwkWRg=; b=n4+i4GvwShUOrxlq0ilUxHI0Ev4QvV3YwbXhjWe5RrGfvyPa23M6hWuNW6gh3vj3VyAuLz3Eahqr5FyYb+rCJzsv7hPHG1ArnOsPNPk06VBFqNBtOZ1J8bZXDslNeqQXOo2Ru8kXu5wyD3qmtMhoc79LBxHy5+46RVvlUNujNXU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781386869757118.61783405580013; Sat, 13 Jun 2026 14:41:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUcV-0001pE-1h; Sat, 13 Jun 2026 16:06:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbw-00014c-KF; Sat, 13 Jun 2026 16:05:45 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUbu-0000N4-BH; Sat, 13 Jun 2026 16:05:44 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 037491B6E78; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 5F7FC3CE8DB; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=ZO2V1hRxjxtkQY97w81DzNP/KhHOgRzafHWy3erJ3rg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ensz0NUzweh+SbnHHifnBwRSJ3OS83vYmuMBuzNHwKKjMFbrPdD7mJ2lIEIVaoKTd MwY4lID/mEmi+hk6SzTr36S5lJblrcPqsDLsOCQD8SdW64Rsh1TCn2PJuRp+d4qDPi Ci24xgZvZNFv3vs8K9qKYeunTtixUytnAKE8MlOq/oeHoM/nRwRaPFgo14IiZEegkH i2UGFCkJEBO3QluavEkfym7Zyl0qRnUNAnHLmXQ/k1nOvyqDbtnCHbzP4xy0MeyMy6 yzSFJHe7OHZsuJYTcYhyWMYt5c3X35rVIjuQngl4vhapV3PArrXcFinwETvf9V5Ybb FiQUJjib7rcNQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-10.2.4 17/61] ui/vnc: fix OOB write in VNC stats array Date: Sat, 13 Jun 2026 23:03:00 +0300 Message-ID: <20260613200411.1808021-17-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781386878728158500 From: Daniel P. Berrang=C3=A9 The VncSurface struct maintains update statistics in an array: VncRectStat stats[VNC_STAT_ROWS][VNC_STAT_COLS]; where the dimensions are defined as: #define VNC_STAT_RECT 64 #define VNC_STAT_COLS (VNC_MAX_WIDTH / VNC_STAT_RECT) #define VNC_STAT_ROWS (VNC_MAX_HEIGHT / VNC_STAT_RECT) If VNC_MAX_WIDTH / VNC_MAX_HEIGHT are not an exact multiple of VNC_STAT_REC, the COLS/ROWS will be undersized by 1. Unfortunately: #define VNC_MAX_HEIGHT 2160 is not a multiple of 64, so there is potential for OOB reads and writes in the 'stats' array, if the guest surface is over 2112 pixels in height. An array overflow occurs when vnc_update_stats() records new statistics, either scribbling over data later in the VncDisplay struct that 'stats' is embedded in, or performing an OOB write on the allocated struct memory. Fixes: CVE-2026-48002 Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-3-berrange@redhat.com> (cherry picked from commit c3c6226fa48180edf9d4646d4112fb1becbc149b) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.h b/ui/vnc.h index ec8d0c91b5..ad41b418b9 100644 --- a/ui/vnc.h +++ b/ui/vnc.h @@ -92,8 +92,8 @@ typedef void VncSendHextileTile(VncState *vs, #define VNC_DIRTY_BPL(x) (sizeof((x)->dirty) / VNC_MAX_HEIGHT * BITS_PER_B= YTE) =20 #define VNC_STAT_RECT 64 -#define VNC_STAT_COLS (VNC_MAX_WIDTH / VNC_STAT_RECT) -#define VNC_STAT_ROWS (VNC_MAX_HEIGHT / VNC_STAT_RECT) +#define VNC_STAT_COLS DIV_ROUND_UP(VNC_MAX_WIDTH, VNC_STAT_RECT) +#define VNC_STAT_ROWS DIV_ROUND_UP(VNC_MAX_HEIGHT, VNC_STAT_RECT) =20 #define VNC_AUTH_CHALLENGE_SIZE 16 =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381512; cv=none; d=zohomail.com; s=zohoarc; b=XaNkQyWB3V4BMosmpusGRTvOVsA5UOEY9SgHK8Qi1XRk6igtTMZx8t8+6tvUIQMNDIwt0abJfuBMIH3SZq4t2wRJ3y024f7Ox3yF28xsfOi0xAQ3OaFL8c/GAAPj1vd2z7Sctg3fQ3Xk6Msv8sOnIugjE5RE3W2Mrj7XqrKfpE8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381512; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=NgesyBDSzN4iCMXceWO+CFAUjWvUc/zjVNBWLBeoeec=; b=FDkNPlWpUz6guCt1ADD5nJbPqSHbb4chSpwYv4OjboNyK9b+/ZxixkQzbb0LNhfcR5ZKqX9faLo9CYpRSPlDBvajGAiCufp3wePKhOHHTuNUymjz8/Vb+NwJOST0KjChxhnEiMFqKqk72HfW+5zU/u8WhWYntm4zwxG7vtRK3Ig= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381511998814.7506095006088; Sat, 13 Jun 2026 13:11:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUdI-0002ot-1e; Sat, 13 Jun 2026 16:07:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcI-0001YW-4w; Sat, 13 Jun 2026 16:06:08 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcF-0000NJ-D6; Sat, 13 Jun 2026 16:06:05 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 1240C1B6E79; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 70CBC3CE8DC; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=2DkJPZqgPQpVdCzNVIVk/r1VzeCc+R8NhjppcUCeL7c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Vc+KNOOQtivuS/I8URxqJq5d14R7/CnFYSJyokFF3OhpdcvFFXRH7oEQrX1LmAjOf Rmi5CQQ/JBuZPbL4y2cUK5PLj8t0HZxyXorV/Tn9KWD+QI+lDYzWYfyn+Zv+90nO25 sU5jq2Wo75z2DtkABeIU9i8u28q7GVXgsdryTrxJNPF1jqNYZ+LpjXFReHWs1weklq bkQC8MWIqRI/BEeA+xxh6DhxEqDzR0/VTbnvaermvCfsRWSqtZLY5rKtKgTedMJ1PI JTUGxD11r2cL4ndj90NEaEFuV5hEBSIpyhy8FsEGkHd/w9LW517p0T1BsDPGNtaxBf 1hVYES0SW0slw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-10.2.4 18/61] ui/vnc: fix OOB write in lossy rect worker code Date: Sat, 13 Jun 2026 23:03:01 +0300 Message-ID: <20260613200411.1808021-18-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381512481158500 From: Daniel P. Berrang=C3=A9 Incorrect calculation of the boundary condition when tracking lossy rectangles in the worker thread will result in an OOB write which can corrupt further worker state, and/or trigger any guard pages that may lie beyond the VncWorker struct. This can be triggered through careful choice of the display resolution in the guest OS by an unprivileged user. Fixes: CVE-2026-48002 Reported-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-4-berrange@redhat.com> [Marc-Andr=C3=A9 - added assert() suggest by philmd@linaro.org] Signed-off-by: Marc-Andr=C3=A9 Lureau (cherry picked from commit 46ee49034d26d04d95ba8f3183d4fbfa9d2b89b4) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.c b/ui/vnc.c index e6bcf0e1cf..b61d3d4b4e 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -3009,13 +3009,15 @@ void vnc_sent_lossy_rect(VncWorker *worker, int x, = int y, int w, int h) { int i, j; =20 - w =3D (x + w) / VNC_STAT_RECT; - h =3D (y + h) / VNC_STAT_RECT; + w =3D DIV_ROUND_UP((x + w), VNC_STAT_RECT); + h =3D DIV_ROUND_UP((y + h), VNC_STAT_RECT); + assert(h <=3D VNC_STAT_ROWS); + assert(w <=3D VNC_STAT_COLS); x /=3D VNC_STAT_RECT; y /=3D VNC_STAT_RECT; =20 - for (j =3D y; j <=3D h; j++) { - for (i =3D x; i <=3D w; i++) { + for (j =3D y; j < h; j++) { + for (i =3D x; i < w; i++) { worker->lossy_rect[j][i] =3D 1; } } --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381268; cv=none; d=zohomail.com; s=zohoarc; b=Ebq80UGsSGdUfZF96HRvz/P5R3+v467bByVs9c8fq1IJCl0cP5CLGXYeAL+fka4OaBaymaq+TIGfRFf2huy7UA9EoVm96g6Jnei0a6UGGss2bb5EawdsUvhP3+RDUW4xLNmZXUAmM4NTGrmAFfPPyvWlKFSJQ6LXe90WtRgJwBc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381268; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=MfpFCx5QGmiVgiJ6T/f1evrPUaWMGk4eLbjeqzl2cDg=; b=kETBl0YkGqOEKcdu9xm5LCs5Fvw0N6yygw6iNWUS1afAZ4dTtNbkY/MyNqS+QLqJaP3mNP1KYG4DMb9OjAkwICaQrLLeBay2WyLXUNxJ7062Vd4yFZ0WXgjunk1B5D9CKhBchI4cfIQDmM5pVhn1+7eNY+RAc21MVSCPRpd8ISg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381268343843.8562637373105; Sat, 13 Jun 2026 13:07:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUcW-0001mx-DA; Sat, 13 Jun 2026 16:06:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcM-0001fI-Vb; Sat, 13 Jun 2026 16:06:12 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcI-0000PP-O1; Sat, 13 Jun 2026 16:06:09 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 22E8D1B6E7A; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7F5B53CE8DD; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=GHZKx0C+59rQloebIY9bHopdX5r5N+kVkzRe3ZrhLE4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=vE8ZEeadVm0wtwyO5W5ptj8eON6re5yBVJ1GN25X7EmGzPzc2spRQ3y6ibJNPphSk lUBN/3z37m3/5hP3xu2RAF8KlZHJ2dWCLim9oYmROi3YjXPSH8yXILJ1VNskWCYsRK Z0AsR2Tcns2UFCX82AnFw8mYlpB3HzHXs7g/ONtiNgV9axsCvaRL/3pKDDMveIWBR4 yiR4jz9ffj9TuZZnKARoANeAFXRlzx07LSkqsQBhxhj5w5xWCzuS1B0jpM/BjFABRX +rm2nduqoMA1jcddAFFQ4GqwZHX1/x4KAXf+tQGx5daElxKMB6u6FKHPki299eyY9S Jn8Tn8s5FxKgg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-10.2.4 19/61] ui/vnc: fix OOB read updating VNC update frequency stats Date: Sat, 13 Jun 2026 23:03:02 +0300 Message-ID: <20260613200411.1808021-19-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381269576158500 From: Daniel P. Berrang=C3=A9 Incorrect loop bounds in vnc_update_freq result in iterating past the last row and past the last column in the VNC stats array. With suitably chosen dimensions this could be a OOB read that accesses memory beyond the VncDisplay struct that the stats array is embedded in. Should this hit a guard page, it could trigger a guest crash. If it does not, then the VNC frequency stats will be updated with garbage. Fixes: CVE-2026-48003 Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-5-berrange@redhat.com> (cherry picked from commit d0c7b82d3a89dd9c863f8aa69b07360c648ca9fb) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.c b/ui/vnc.c index b61d3d4b4e..848a335803 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -3120,12 +3120,14 @@ double vnc_update_freq(VncState *vs, int x, int y, = int w, int h) int i, j; double total =3D 0; int num =3D 0; + int x_end =3D x + w; + int y_end =3D y + h; =20 x =3D QEMU_ALIGN_DOWN(x, VNC_STAT_RECT); y =3D QEMU_ALIGN_DOWN(y, VNC_STAT_RECT); =20 - for (j =3D y; j <=3D y + h; j +=3D VNC_STAT_RECT) { - for (i =3D x; i <=3D x + w; i +=3D VNC_STAT_RECT) { + for (j =3D y; j < y_end; j +=3D VNC_STAT_RECT) { + for (i =3D x; i < x_end; i +=3D VNC_STAT_RECT) { total +=3D vnc_stat_rect(vs->vd, i, j)->freq; num++; } --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381349; cv=none; d=zohomail.com; s=zohoarc; b=eZnj5f0HU3OjhiN2eCfIXifySKEGMhxAPX1Hqv6iN2QxpPjs0uRgS8Pz1qcIdYIZWO2N/tKesJp+VWG4/0FBonVgJES4B2LclJiLgJIUjUomfJ6vnNOUT7BEiGvQe5RjEm4fxF7XXUKNU9LxKgZRGV1UjVybsjN/1UEzqMlrouU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381349; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rRgLOsAbB8mV5Z02gJ9i58QdSd5GSpfsC9YvYb5PuSc=; b=ATyhYHpja1QhKBSPV2sU6smIwGg/wB6cDWF9G75B23CIfTncHGbcwe0EQm9kjdBoZssDVNaCKfm6QDoRUgCGXnwkvJS5LPrBvUCIr9rupffiUA2RTll8BMr8TmjzNRny+9cdRtK0mbmCsuyK/KgqL2DLrcHj+tHdVLsdflahTDg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381349755391.1790114647604; Sat, 13 Jun 2026 13:09:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUdc-0003OH-98; Sat, 13 Jun 2026 16:07:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcM-0001fJ-Vz; Sat, 13 Jun 2026 16:06:12 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcK-0000bH-Mz; Sat, 13 Jun 2026 16:06:10 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 35D841B6E7B; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 8FC773CE8DE; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=DJZuAd6uoTybgvHP17Px/QZ+fzo7XTUkf9sXHlZo+24=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=tffcVPVdOIqYv1CY8KA9FmPUt3J+XOxdB28H1PomO8frHNIqOGs1RQprLBORkPiuY mQs+V8+xyrHfeY0NmoGRomzZCkq/bJGN4907Pos003WOr9mOaPvgYO7SJ8YRnaIGwb 4ySahaEvFsWgWAZy6nPJLbLmDZi7mxf88FpbzBPMV4lXEdGP1DMxDFk994sm97kzEW Tras/cqDBlLAxFHZoNvMUu0nOHsxPHqrt91ah1IOjLZquF4JW+UYjskDP0GblW+DVW wAtqmhZhSxS/meR3meJemuBrC/pcolBhhQS/zf5SylO3VZ3y/r6N31SLDgwafKzOHd Ox9NlEtuUXnzQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Heechan Kang , Feifan Qian , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-10.2.4 20/61] ui: fix validation of VNC extended clipboard data length Date: Sat, 13 Jun 2026 23:03:03 +0300 Message-ID: <20260613200411.1808021-20-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381352115158500 From: Heechan Kang QEMU's VNC extended clipboard handler inflates a client-controlled compressed clipboard payload. The code checks the declared text size against the total inflated buffer size: if (tsize < size) but then copies from: tbuf =3D buf + 4; qemu_clipboard_set_data(..., tsize, tbuf, true); The correct bound is the remaining data length after the 4-byte length field, not the total inflated buffer length. As a result, a VNC client can make QEMU copy up to 3 bytes past the end of the inflated heap buffer. With a second VNC client, those copied bytes are observable through the normal VNC extended clipboard PROVIDE path. Fixes: CVE-2026-8343 Reported-by: Heechan Kang Reported-by: Feifan Qian Reviewed-by: Daniel P. Berrang=C3=A9 Signed-off-by: Heechan Kang [DB: added #include and 'return' statements] Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260512095543.459949-1-berrange@redhat.com> (cherry picked from commit e56b4bbff1df260487b80abe1f967f687fa115d3) Signed-off-by: Michael Tokarev diff --git a/ui/vnc-clipboard.c b/ui/vnc-clipboard.c index 124b6fbd9c..fa05d86f42 100644 --- a/ui/vnc-clipboard.c +++ b/ui/vnc-clipboard.c @@ -23,6 +23,7 @@ */ =20 #include "qemu/osdep.h" +#include "qemu/error-report.h" #include "vnc.h" #include "vnc-jobs.h" =20 @@ -282,10 +283,16 @@ void vnc_client_cut_text_ext(VncState *vs, int32_t le= n, uint32_t flags, uint8_t buf && size >=3D 4) { uint32_t tsize =3D read_u32(buf, 0); uint8_t *tbuf =3D buf + 4; - if (tsize < size) { + if (tsize <=3D size - 4) { qemu_clipboard_set_data(&vs->cbpeer, vs->cbinfo, QEMU_CLIPBOARD_TYPE_TEXT, tsize, tbuf, true); + } else { + error_report("vnc: malformed extended clipboard payload " + "with text length %u exceeding available %u", + tsize, size - 4); + vnc_client_error(vs); + return; } } } --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781390178; cv=none; d=zohomail.com; s=zohoarc; b=jr/fNjv0xgZnN1uAA/KRROTLQcYQu+gbwgWDfU2jbV1WALECVwoy2/gpLjCSXbe/GNLTv8qV8Zkbe3guD/zgM3Tyr1mQInrKd6y4AXxjxjKG2RXawQMs6a1F8Q6GRtJJ1VSjjvZkf03qwVjDQ2/PbnLtxCPBAYDQEtIa++BZwoo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781390178; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bvWstUA8vrjDuIwILsMwLEKPhELABtpdUKSPvWv6Ijw=; b=NOHYHxRnQ1iXgI/vbu7ubjF078cxD8Y70tTZr4owJxIfQpDCBBoK97UdkjGDggX269YhWext1p8qTXbRQ+BZU2cvkGCDEKvoj1lBxfIjN4qGHN784kN3xKhTHYUtf89KDMhliYlttWq+X+twtMzpUe2iV2KQLD+NZv2fMFdUxyM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781390178076465.4432578929237; Sat, 13 Jun 2026 15:36:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUdv-00040X-V7; Sat, 13 Jun 2026 16:07:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcQ-0001jQ-Lc; Sat, 13 Jun 2026 16:06:14 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcO-0000cD-Ov; Sat, 13 Jun 2026 16:06:14 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 457221B6E7D; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id A35303CE8DF; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=o9fMaY0Ohs0C5BXwCWIik/svQPKJb9uyHH09GMXT8Z0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Q6uT7LNpHQkjYihtWfL45scXki+qhp9M5pKAK5NIH5w2XIztit4j+mGfTFWnEVw7z SCoKYtz76AQ+MlDUiR2T0VaAQIy5sphEspPJajgltvk5kBfM+GlOJ0itbzK9B3+p1S TYiPGFkMaxNCM64usPdVj9rAQOCO2ILjA5Woj0K8PEFivjv1P/yjWhRfoIU0wa/1EC BhHpGe6wviL9CwSaAcVXrgiAnu8qIfIjE+Gr+3S3C6p/0LCUe38SJx/dslkVXCn4WZ j/AoO202mCOWM2Pt47NXFHLoIvJkaXdf5ruiw9OgbeztzjC/d6LbukcDpjtsqXyUh8 IqwOu21GIxJMw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Wei Che Kao , Michael Tokarev Subject: [Stable-10.2.4 21/61] lsi53c895a: fix use-after-free of cancelled request Date: Sat, 13 Jun 2026 23:03:04 +0300 Message-ID: <20260613200411.1808021-21-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781390188562158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini When processing the Message Out phase, the lsi53c895a controller can cancel a request and the continue by processing more messages. When this happens, it is important that a cancelled request is not processed further, because scsi_req_cancel can cause the request to be freed. Right now this is happening in two cases, but not when cancelling the entire queue of requests after an ABORT, CLEAR QUEUE or BUS DEVICE RESET message. In that case, a subsequent ABORT TAG message can use a dangling current_req. There are three possible fixes: - add a missing check inside the loop, clearing current_req if p->req =3D=3D current_req. This is obvious but complicates the code inside the foreach loop. - change the conditional prior to the loop from "if (s->current)" to "if (current_req)". This would work, because s->current !=3D NULL implies current_req !=3D NULL, and would clear current_req correctly. However it is less obvious because the point of the code is to clear the entire queue, which consists of s->current and s->queue; current_req is not special here. - delay the retrieval of current_req until an ABORT TAG message is seen. This is the most correct option, because the SCSI protocol only deals with tags; requests are a QEMU concept that only makes sense for the purpose of calling into the SCSI layer. Reported-by: Wei Che Kao Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 5297a0fc65317ba7f79ef44ce7a44e41d15fdb27) Signed-off-by: Michael Tokarev diff --git a/hw/scsi/lsi53c895a.c b/hw/scsi/lsi53c895a.c index 0b1f68a40a..28a10aad19 100644 --- a/hw/scsi/lsi53c895a.c +++ b/hw/scsi/lsi53c895a.c @@ -1000,10 +1000,8 @@ static void lsi_do_msgout(LSIState *s) =20 if (s->current) { current_tag =3D s->current->tag; - current_req =3D s->current; } else { current_tag =3D s->select_tag; - current_req =3D lsi_find_by_tag(s, current_tag); } =20 trace_lsi_do_msgout(s->dbc); @@ -1058,9 +1056,13 @@ static void lsi_do_msgout(LSIState *s) case 0x0d: /* The ABORT TAG message clears the current I/O process only. = */ trace_lsi_do_msgout_abort(current_tag); + if (s->current) { + current_req =3D s->current; + } else { + current_req =3D lsi_find_by_tag(s, current_tag); + } if (current_req && current_req->req) { scsi_req_cancel(current_req->req); - current_req =3D NULL; } lsi_disconnect(s); break; @@ -1086,7 +1088,6 @@ static void lsi_do_msgout(LSIState *s) /* clear the current I/O process */ if (s->current) { scsi_req_cancel(s->current->req); - current_req =3D NULL; } =20 /* As the current implemented devices scsi_disk and scsi_gener= ic --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781387135; cv=none; d=zohomail.com; s=zohoarc; b=Lv3SmBtEM7e6atsTw/AphfuxNwsnFvuXIBCNNlcEc0TfqOUsdBSPYoimAUR2Kxd2s+iUkPUkcGHGM8d13zFhzrh7P2I3AOztkJFeRwOEurZpafiY3pvNs4ZQXSu2iXcKKWyGp/3Sz4BHZaiIPaVSseRvGy9x2sRR7gR7xkujUJs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781387135; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=cbf8249tqAo3CNZhmkNSvjNfj0LbeZMpxpBVynZ43C4=; b=B3QgJLIerPlrrH+WIZgwtHS2BKHyLMM+g3rkkxaVZhbWOYmTpTx2vA9H7kupbqeaLhBga5unwEF9G0OYFjQ3+RFfPPKY6TIbB9bMBFyHFZWrLM32pts5ONYdYbDhb0JrUTdRuAnwnM9+Pmwu836DCs1gvjBqyhY0zPNDsOcLaNE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781387135130172.20126044315157; Sat, 13 Jun 2026 14:45:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUdK-0002ue-8Y; Sat, 13 Jun 2026 16:07:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcS-0001qF-SF; Sat, 13 Jun 2026 16:06:18 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcO-0000cF-QY; Sat, 13 Jun 2026 16:06:15 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 535B51B6E7E; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B2A2E3CE8E0; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=TK4SlTaF6zr7OToS+ROaVrUc2rpi387eGAhpz7Mk+QA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VltxvA2Npx+/w8LmKnvasmlqAlQvLnaUd1DQb0cGDVB1mpzdhfKZKFJHN6uLZzdPP W/lvvSdcMWd7CMOUFEOJwxVN+KZ1qctrph7o/bzV++kve+SBGIjYZPNlpMoJAqgBh+ 7iA+3ugFDS4OPuxur2ro34igBkhIdRGmP1v4On1yCsc7mCJrZ1edLcHAvb2dW948Pe 6J8+KC1VXKlEJylxN+jtf40fxHGWX7Uh7IMFJ3hCLdWOBPVsCN8/aMow5cFE3vAMbp 9d5Y+EvdPCayScvnvPFr5ZUtdBxePU8HeexNAM5q6/koohp/HssNX4q4afAekecv0F QA6pd4hbXgjXQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Michael Tokarev Subject: [Stable-10.2.4 22/61] lsi53c895a: clear tag byte when processing messages Date: Sat, 13 Jun 2026 23:03:05 +0300 Message-ID: <20260613200411.1808021-22-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781387137814158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini Instead of simply ORing the message byte, clear what was there before. Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 4494dec8c2bfd8a5d9b1eabe4a26ab850a4f6700) Signed-off-by: Michael Tokarev diff --git a/hw/scsi/lsi53c895a.c b/hw/scsi/lsi53c895a.c index 28a10aad19..897929d357 100644 --- a/hw/scsi/lsi53c895a.c +++ b/hw/scsi/lsi53c895a.c @@ -1041,16 +1041,19 @@ static void lsi_do_msgout(LSIState *s) } break; case 0x20: /* SIMPLE queue */ + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; trace_lsi_do_msgout_simplequeue(s->select_tag & 0xff); break; case 0x21: /* HEAD of queue */ qemu_log_mask(LOG_UNIMP, "lsi_scsi: HEAD queue not implemented= \n"); + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; break; case 0x22: /* ORDERED queue */ qemu_log_mask(LOG_UNIMP, "lsi_scsi: ORDERED queue not implemented\n"); + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; break; case 0x0d: --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381263; cv=none; d=zohomail.com; s=zohoarc; b=KSf+7V97ArYIoOPXsmbx6TpB2FuApvcNn18zBNCuP8gnBlxmGTllZ8RzSXk9oo7gojp0Ln19LmwBNPljBNVz50aBkaS85xycHcM+0y3wYsuKAkIZvYOp0DTNdc1pnGVM2akgAvmBou4oBKshKNHS30CXKfg0lez5H56Asbf0ll4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381263; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GVYR8mWU0y2YPtezsKVUgVf0tiEuURvKMDAm5S8OtG0=; b=lyrk633x3TUd0sFEa+yiLwqwExevVb50TaCC7bec8DV7EebgCrvmOBz/66S/4iQLFt0hvyxjqIOUaxR/4gLDbzUn04DXXoYq9wzHo6BtsxfeUu8NsF28Y5uyYNTNM4ual5xyWxlWZsHTH1gG5jRxBRjQ7s+vQ+GLAPPxjPmYBcQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381263438550.0394757602064; Sat, 13 Jun 2026 13:07:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUdU-0003E4-TS; Sat, 13 Jun 2026 16:07:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUco-0002Ht-Nd; Sat, 13 Jun 2026 16:06:46 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcm-0000em-UK; Sat, 13 Jun 2026 16:06:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 62F541B6E7F; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C0C093CE8E1; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=n0YukLLGYQno0FZhxD8nDgudpOyPh15NVnvrjUIbGiA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=QG8Zf+XBaIS4hSR53DS45IIOZZZ3J59VJrJvYTcBJ1Og2Jg3YYzliQQfvPS4AA6xe BMgE80sJkcKyQy1fdzUkCNC2ymsiwMjGORwSUvZ/rbGDhnwJ4/mHNNmhkgedxrKluQ 9ucvzAhrxGDIoSz5EHVKktBxZA4ho3uGinKnAvcSKfmELCZhWIr1eBQoYHHSmvBXvs ai1fWu3L/3lJfVj/fV/tcZtyip4GR/UI48nLiWtwrTyOGSl6sOxWjpEFl4vbXFfjPx 088e3Bp4d2xNgtFmBGTTRQjQTJ40wBY0dY3EeqnXgr4B0PEVf4LrGjNSYzC5mL7SO1 kk8bMMejpkFOw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Wei Che Kao , Michael Tokarev Subject: [Stable-10.2.4 23/61] apic: fix delivery bitmask with modified xAPIC ids Date: Sat, 13 Jun 2026 23:03:06 +0300 Message-ID: <20260613200411.1808021-23-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381263573158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini Self-IPIs (or all-but-self IPIs) in QEMU can cause a out-of-bounds access to deliver_bitmask, because the access uses the APIC ID register which is writable by the guest. However, foreach_apic uses the delivery bitmask indexes to look up the local_apics[] array, which is indexed by *initial* APIC id. Using the right id fixes both a possible heap write overflow if the modified APIC id is too large for max_apic_words, and a mis-delivery of both self and all-but-self IPIs. Reported-by: Wei Che Kao Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 153dc2fa7bbe0491290d22c4bbb6807074f24260) Signed-off-by: Michael Tokarev diff --git a/hw/intc/apic.c b/hw/intc/apic.c index aad253af15..69162668eb 100644 --- a/hw/intc/apic.c +++ b/hw/intc/apic.c @@ -647,13 +647,6 @@ static void apic_deliver(APICCommonState *s, uint32_t = dest, uint8_t dest_mode, APICCommonState *apic_iter; uint32_t deliver_bitmask_size =3D max_apic_words * sizeof(uint32_t); g_autofree uint32_t *deliver_bitmask =3D g_new(uint32_t, max_apic_word= s); - uint32_t current_apic_id; - - if (is_x2apic_mode(s)) { - current_apic_id =3D s->initial_apic_id; - } else { - current_apic_id =3D s->id; - } =20 switch (dest_shorthand) { case 0: @@ -661,14 +654,20 @@ static void apic_deliver(APICCommonState *s, uint32_t= dest, uint8_t dest_mode, break; case 1: memset(deliver_bitmask, 0x00, deliver_bitmask_size); - apic_set_bit(deliver_bitmask, current_apic_id); + /* + * The self and all-but-self cases do not use apic_match_dest() and + * directly fill in deliver_bitmask; the bitmask's indexes in turn + * map to local_apics[] slots which are never changed even if the + * xAPIC id is modified. So use s->initial_apic_id instead of s->= id. + */ + apic_set_bit(deliver_bitmask, s->initial_apic_id); break; case 2: memset(deliver_bitmask, 0xff, deliver_bitmask_size); break; case 3: memset(deliver_bitmask, 0xff, deliver_bitmask_size); - apic_reset_bit(deliver_bitmask, current_apic_id); + apic_reset_bit(deliver_bitmask, s->initial_apic_id); break; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381343; cv=none; d=zohomail.com; s=zohoarc; b=NJ6G4RDPq4tnu3pe2LpQdRUI8bI+1p8yFD4FnQjNNpFAl0OxtxLu/8piNoNI9umLI24tkw/WWnzeJvKh4/jGLUEFWygKWmaYRneyi2uBXmxMgydkzk0CDG013ZYe4FJzY6PoWWvKCZmOY9NT7cTeLP4n1hIuKM0t4SANQ8zhlLY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381343; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rq9JbAyKfPvAys0DyRgI/Wgg8czLT7NZK3rg8Is19hw=; b=MlZru8ANIjfmgroboPOvH0vRp6nGs1I8MiO/KV4Q3p+Q+r5ChsEIygZO0C7A4o6NzXOo6nEOeXnesEoN9CsA5u6Y1O1kBgSscI6nmdjrrGsYAR/d8tLYTyI2ghY/Ia/pWDgk2fertklS3AU+urRq0squsv44q0jLORdXvpIx+Rc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381343831730.4873741888418; Sat, 13 Jun 2026 13:09:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUeX-0004vr-7y; Sat, 13 Jun 2026 16:08:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcs-0002I6-1l; Sat, 13 Jun 2026 16:06:46 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUco-0000h6-Vq; Sat, 13 Jun 2026 16:06:41 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 726AD1B6E80; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D04D83CE8E2; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=wxy35K4pdc3G9Rb1kvd/xkr870aM02UNR8jP5r7tZSw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=K7IHKcauUajz8onllXADFD21pVV7Wk5yaBRaMumZwIoMqPB3YuTnj51yqz4KDaC6b aI6SDqRzcTJlEY3PkCwseQMxb5SdnOOYeo/BRxMZccLkQOKnBHUAizv0M1itggAGRN iBbqgSzl0a9tKQAFIbrNCMB4kUGvhnHG4aSGi1D0efMFE8CWLT1wnBdW3As1MzBbmo 3WWn2KeKa+EDWeOjdGQbUwbN1VjIwPmNfV8bzTWZ1GjWn+6l1dcLchY6i7BPaQs8C5 L2rQE3uD47HxZ1E6VFy8O1xSFcDGMhTx/WXcIHLacISG/lCIvTCc+MS0xUL2s5LogY gLuAYsQToTbgw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Jinjie Ruan , Paolo Bonzini , Michael Tokarev Subject: [Stable-10.2.4 24/61] mc146818rtc: Fix get_guest_rtc_ns() overflow bug Date: Sat, 13 Jun 2026 23:03:07 +0300 Message-ID: <20260613200411.1808021-24-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381345887158500 Content-Type: text/plain; charset="utf-8" From: Jinjie Ruan In get_guest_rtc_ns(), "s->base_rtc" is uint64_t, which multiplied by "NANOSECONDS_PER_SECOND" may overflow the uint64_t type, which will cause the QEMU Linux Virtual Machine's RTC time to jump and in turn triggers a kernel Soft Lockup and ultimately leads to a crash. Fix it by avoiding adding s->base_rtc in get_guest_rtc_ns_offset(), because get_guest_rtc_ns() is used either take the remainder of NANOSECONDS_PER_SECOND or take the quotient of NANOSECONDS_PER_SECOND. Fixes: 56038ef6234e ("RTC: Update the RTC clock only when reading it") Signed-off-by: Jinjie Ruan Link: https://lore.kernel.org/r/20260114013257.3500578-1-ruanjinjie@huawei.= com Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 4b6c088c88ccc9e7cafc72759c99742b3993f9f7) Signed-off-by: Michael Tokarev diff --git a/hw/rtc/mc146818rtc.c b/hw/rtc/mc146818rtc.c index 8631386b9f..98da775d9f 100644 --- a/hw/rtc/mc146818rtc.c +++ b/hw/rtc/mc146818rtc.c @@ -77,12 +77,13 @@ static inline bool rtc_running(MC146818RtcState *s) (s->cmos_data[RTC_REG_A] & 0x70) <=3D 0x20); } =20 -static uint64_t get_guest_rtc_ns(MC146818RtcState *s) +/* + * Note: get_rtc_ns_since_last_update() does not include the base_rtc seco= nds + * value. This does not matter if the caller only needs the nanoseconds p= art. + */ +static uint64_t get_rtc_ns_since_last_update(MC146818RtcState *s) { - uint64_t guest_clock =3D qemu_clock_get_ns(rtc_clock); - - return s->base_rtc * NANOSECONDS_PER_SECOND + - guest_clock - s->last_update + s->offset; + return qemu_clock_get_ns(rtc_clock) - s->last_update + s->offset; } =20 static void rtc_coalesced_timer_update(MC146818RtcState *s) @@ -258,7 +259,7 @@ static void check_update_timer(MC146818RtcState *s) return; } =20 - guest_nsec =3D get_guest_rtc_ns(s) % NANOSECONDS_PER_SECOND; + guest_nsec =3D get_rtc_ns_since_last_update(s) % NANOSECONDS_PER_SECON= D; next_update_time =3D qemu_clock_get_ns(rtc_clock) + NANOSECONDS_PER_SECOND - guest_nsec; =20 @@ -510,7 +511,7 @@ static void cmos_ioport_write(void *opaque, hwaddr addr, /* if disabling set mode, update the time */ if ((s->cmos_data[RTC_REG_B] & REG_B_SET) && (s->cmos_data[RTC_REG_A] & 0x70) <=3D 0x20) { - s->offset =3D get_guest_rtc_ns(s) % NANOSECONDS_PER_SE= COND; + s->offset =3D get_rtc_ns_since_last_update(s) % NANOSE= CONDS_PER_SECOND; rtc_set_time(s); } } @@ -623,10 +624,8 @@ static void rtc_update_time(MC146818RtcState *s) { struct tm ret; time_t guest_sec; - int64_t guest_nsec; =20 - guest_nsec =3D get_guest_rtc_ns(s); - guest_sec =3D guest_nsec / NANOSECONDS_PER_SECOND; + guest_sec =3D s->base_rtc + get_rtc_ns_since_last_update(s) / NANOSECO= NDS_PER_SECOND; gmtime_r(&guest_sec, &ret); =20 /* Is SET flag of Register B disabled? */ @@ -637,7 +636,7 @@ static void rtc_update_time(MC146818RtcState *s) =20 static int update_in_progress(MC146818RtcState *s) { - int64_t guest_nsec; + uint64_t guest_nsec; =20 if (!rtc_running(s)) { return 0; @@ -652,7 +651,7 @@ static int update_in_progress(MC146818RtcState *s) } } =20 - guest_nsec =3D get_guest_rtc_ns(s); + guest_nsec =3D get_rtc_ns_since_last_update(s); /* UIP bit will be set at last 244us of every second. */ if ((guest_nsec % NANOSECONDS_PER_SECOND) >=3D (NANOSECONDS_PER_SECOND - UIP_HOLD_LENGTH)) { --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381439; cv=none; d=zohomail.com; s=zohoarc; b=NVjROe1qB32O5m5IDmmFgVSVMoc9m0msnBtKj8IRebUYwTMNfCZVPXCxfNfesD/Ltlkve/VOdLInm3/43tcPBwomqDUOmYCX6OQJbYHKgE8fktmPfDLX/4EWPPg4Umliu+QYDFQcT5i/iky1xZ2HBtdWx/4D8qwHf/MS/gGo0Do= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381439; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gtwr90EG5bjkMnZogbYfMuU4eH5zrc2YvukMSDnNfkM=; b=InRQcFI9xgr8gBiQCn3R4v2KEe97WSplZCAuzoeBgTivWRaeaAMUQt8TYDUCHHp6A+a6CjuzAHdjlJcDs3w9uinqvShRVyQS6tYFEM0merxZZdRnkSckHDXDAVW5gmHecyajx/zmeWExGwL/lij9gEpOc0pOn5u0os6zhbpGGmc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381439851676.5814888231049; Sat, 13 Jun 2026 13:10:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUd9-0002YI-4J; Sat, 13 Jun 2026 16:06:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcu-0002Mc-D1; Sat, 13 Jun 2026 16:06:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcq-0000qn-Dx; Sat, 13 Jun 2026 16:06:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 868F71B6E81; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id DFBEC3CE8E3; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=LxFgkd4O1lzKhVHiy8oCGWQNAqbCTIib1cX13DieIS8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=uCHbR+OG5bGqOiJDLZl/x9p9aNtmRz8hL3DYzA8LBO4ONgAbECtOdtGt2Y1A4Zsak nQNR9CyypgjJObZwsGmwgWjZc3ro9iq6wl+7GgmDVQCBQsHCB8LmyYwQswZDnm1MAQ xho1WUFkSxEOakx0rvm0SUxyBLSojTSIhbXyY38F46hOv5Xbm7EzB4u1Gu+3fwHjpr pxs0+/VRQ1JGaLL+aKjOwFkE4hBNBqh18yKh/BzybI5TtQsK527pUKStEmT+skTyz/ itn2sZiJZqpLsAXnvfVT0nnC9XHLJWAWurs21ObkaoF8yW6jNFqnq+oa9njB2ndEVb BxMuk7LA2r9sw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Kevin Wolf , Hanna Reitz , Stefan Hajnoczi , Paolo Bonzini , Michael Tokarev Subject: [Stable-10.2.4 25/61] block/linux-aio: bound ioq_submit() recursion depth Date: Sat, 13 Jun 2026 23:03:08 +0300 Message-ID: <20260613200411.1808021-25-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381440353158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" qemu_laio_process_completions() wraps its body in defer_call_begin / defer_call_end. Inside the section, completion callbacks wake coroutines that queue new aiocbs; laio_do_submit() defers laio_deferred_fn. At the bottom of qemu_laio_process_completions() the defer_call_end() fires laio_deferred_fn, which calls ioq_submit(), closing the cycle: ioq_submit -> io_submit(2) // some sync completions -> qemu_laio_process_completions // defer_call_begin -> aio_co_wake // resumes coroutine -> laio_do_submit -> defer_call(laio_deferred_fn, s) // enqueued -> defer_call_end // nesting drops to 0 -> laio_deferred_fn -> ioq_submit // +1 stack frame, loop When io_submit(2) returns asynchronously (O_DIRECT) the cycle terminates in one extra frame: the fresh aiocb is still in flight, no completion is drained, no coroutine wakes, no new submission queues. When submissions complete synchronously (non-O_DIRECT, or per-descriptor drivers such as vmdk) each level enqueues more work for the next defer_call_end() to drain, so recursion grows without bound and QEMU crashes with SIGSEGV on the thread guard page. The cycle was closed by two performance commits, each correct in isolation: 076682885d ("block/linux-aio: convert to blk_io_plug_call() API") -- introduced laio_deferred_fn and wired laio_do_submit -> defer_call(laio_deferred_fn, s). 84d61e5f36 ("virtio: use defer_call() in virtio_irqfd_notify()") -- added defer_call_begin/end around qemu_laio_process_completions so virtio-irqfd notifications batch across a completion pass. The supported aio=3Dnative + cache=3Dnone pairing keeps submissions asynchronous, so the cycle stays bounded; nothing in the code enforces that contract. Observed in production as a SIGSEGV during a backup job configured with --cached + aio=3Dnative; reproducible on upstream with qemu-io against vmdk. Cap ioq_submit() recursion with a counter on LaioQueue, which is only accessed from the AioContext home thread. On overflow, return without submitting. The pending work is drained by s->completion_bh, which qemu_laio_process_completions() has already scheduled on entry -- no work is lost; one event-loop round-trip of latency is paid only when the bound is hit, which cannot happen on a supported configuration. Signed-off-by: Denis V. Lunev CC: Kevin Wolf CC: Hanna Reitz CC: Stefan Hajnoczi CC: Paolo Bonzini Message-ID: <20260520142503.251959-2-den@openvz.org> Signed-off-by: Stefan Hajnoczi (cherry picked from commit 6864bec553b2e37699739615e604fc3c7bae0e1d) Signed-off-by: Michael Tokarev diff --git a/block/linux-aio.c b/block/linux-aio.c index 84397de54c..37de9b564b 100644 --- a/block/linux-aio.c +++ b/block/linux-aio.c @@ -36,6 +36,19 @@ /* Maximum number of requests in a batch. (default value) */ #define DEFAULT_MAX_BATCH 32 =20 +/* + * Bound on how deep ioq_submit() may recurse on a single LaioQueue via the + * ioq_submit -> qemu_laio_process_completions -> defer_call_end -> + * laio_deferred_fn -> ioq_submit cycle. The cycle terminates naturally + * when io_submit(2) returns asynchronously (O_DIRECT), but can grow + * without bound when submissions complete synchronously. On overflow + * the caller returns without submitting; the outermost + * qemu_laio_process_completions() has already scheduled s->completion_bh + * (via qemu_bh_schedule() at the top of that function), which resumes + * submission from the next event-loop dispatch. + */ +#define IOQ_SUBMIT_MAX_DEPTH 8 + struct qemu_laiocb { Coroutine *co; LinuxAioState *ctx; @@ -61,6 +74,7 @@ typedef struct { unsigned int in_queue; unsigned int in_flight; bool blocked; + unsigned int submit_depth; QSIMPLEQ_HEAD(, qemu_laiocb) pending; } LaioQueue; =20 @@ -331,6 +345,7 @@ static void ioq_init(LaioQueue *io_q) io_q->in_queue =3D 0; io_q->in_flight =3D 0; io_q->blocked =3D false; + io_q->submit_depth =3D 0; } =20 static void ioq_submit(LinuxAioState *s) @@ -340,6 +355,11 @@ static void ioq_submit(LinuxAioState *s) QEMU_UNINITIALIZED struct iocb *iocbs[MAX_EVENTS]; QSIMPLEQ_HEAD(, qemu_laiocb) completed; =20 + if (s->io_q.submit_depth >=3D IOQ_SUBMIT_MAX_DEPTH) { + return; + } + s->io_q.submit_depth++; + do { if (s->io_q.in_flight >=3D MAX_EVENTS) { break; @@ -385,6 +405,8 @@ static void ioq_submit(LinuxAioState *s) * pended requests will be submitted from there. */ } + + s->io_q.submit_depth--; } =20 static uint64_t laio_max_batch(LinuxAioState *s, uint64_t dev_max_batch) --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381344; cv=none; d=zohomail.com; s=zohoarc; b=M9gUrAmOEf2zb3Xcwnm3RKDeyHCK2N4ufzJd3lyCW1H7KcBM6plWFSLk6uo6sB2ySTidn5RAecG/TtBQXC9hmI6Lk59g6vmmEdTYone3YfmqQ1LUXpoplyLNdI4cPGpQKbMqxjaik/81oR1blw0JQYHs53LYjLPOaUxq1yhtJvY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381344; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/4Brz35Jn4mJZWgFEJUb9Ja8XEtYCs6nhsJ5U2zZlZo=; b=mbTGgm8nhS52jX8FcTf/+mN6CuKccaapNCIrf5JyTONYYtoq3MyLG2A7qGqopjgQCQ6XEA7bt4cciQ/dovd69141lQ1rw/DZO4kRUNQBQ8nOO46a53PmxkCRn3NwFqLT/RyRXOL5Lm96TVaLLCo/HlNZ+FjE3babhm9Gp++DYTA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17813813441021019.3397540941105; Sat, 13 Jun 2026 13:09:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUdg-0003WP-CL; Sat, 13 Jun 2026 16:07:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcw-0002Mk-0j; Sat, 13 Jun 2026 16:06:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUct-0000rQ-St; Sat, 13 Jun 2026 16:06:45 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 964181B6E82; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 001FA3CE8E4; Sat, 13 Jun 2026 23:04:46 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=Jmqc/U5B7Cs0Vvd3Lcu9kNMKZwNzLHBdFXsN6GmO6Jc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=oAxQYdDv8MWqQBGVIsIUCv928h5mO81S/Tkii/TIUiXvB+NfHp8VSXvgHurVZ8DYT ZAKARSbFA7Agn8m+tyVPBWFWDZsX3bAEepRjV20e3BixvVwnbkiX9vlnWOiSc1uWYW pKdjfD5/lIxJwXi61j7mMCmN5V3QfQaCbIln7FzQNE8HMr/oRfnNHSMp5zI/bHZH+C 14IVnLa46eUnCt+SaFUNVEze4qQsOtC9cIcr58bSOW+Nf8fojgyanso3Q2DHjju1bb KquVlJtc6Kpg5OElPXSNRO/9Oky4WDfndbimZQ8UDUCJnh2r/NmXWGy4Dnmd3Dli5p nN6eXAaQCeheA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Michael Tokarev Subject: [Stable-10.2.4 26/61] target/arm: SVE2 FMAXP, FMINP must honour AH=1 Date: Sat, 13 Jun 2026 23:03:09 +0300 Message-ID: <20260613200411.1808021-26-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381345834158500 From: Peter Maydell The behaviour of floating-point maximum and minimum insns has some odd special cases when FPCR.AH=3D1. We get this right in most places (for instance, the ASIMD FMAXP, FMINP) but forgot about it for the SVE2 versions of FMAXP and FMINP. Cc: qemu-stable@nongnu.org Fixes: 384433e70983 ("target/arm: Implement FPCR.AH semantics for FMINP and= FMAXP") Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Message-id: 20260521122913.1565011-2-peter.maydell@linaro.org (cherry picked from commit 446050c4dfe4566ae3fcba9c6588c89a66ed4b33) (Mjt: fixup for lack of v10.2.0-1344-g895d4367d6 "target/arm/tcg: Use "or SME" feature checks where needed") Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/helper-sve.h b/target/arm/tcg/helper-sve.h index c3541a8ca8..cd05dd0fb4 100644 --- a/target/arm/tcg/helper-sve.h +++ b/target/arm/tcg/helper-sve.h @@ -2914,6 +2914,20 @@ DEF_HELPER_FLAGS_6(sve2_fminp_zpzz_s, TCG_CALL_NO_RW= G, DEF_HELPER_FLAGS_6(sve2_fminp_zpzz_d, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, fpst, i32) =20 +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_h, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_s, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_d, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) + +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_h, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_s, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_d, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) + DEF_HELPER_FLAGS_5(sve2_eor3, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, i= 32) DEF_HELPER_FLAGS_5(sve2_bcax, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, i= 32) DEF_HELPER_FLAGS_5(sve2_bsl1n, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, = i32) diff --git a/target/arm/tcg/sve_helper.c b/target/arm/tcg/sve_helper.c index c442fcb540..7e547a7795 100644 --- a/target/arm/tcg/sve_helper.c +++ b/target/arm/tcg/sve_helper.c @@ -774,6 +774,14 @@ DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_h, float16, H1_2, floa= t16_min) DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_s, float32, H1_4, float32_min) DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_d, float64, H1_8, float64_min) =20 +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_h, float16, H1_2, helper_vfp_ah_maxh) +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_s, float32, H1_4, helper_vfp_ah_maxs) +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_d, float64, H1_8, helper_vfp_ah_maxd) + +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_h, float16, H1_2, helper_vfp_ah_minh) +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_s, float32, H1_4, helper_vfp_ah_mins) +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_d, float64, H1_8, helper_vfp_ah_mind) + #undef DO_ZPZZ_PAIR_FP =20 /* Three-operand expander, controlled by a predicate, in which the diff --git a/target/arm/tcg/translate-sve.c b/target/arm/tcg/translate-sve.c index 76e4a6c52c..b9dba6ec31 100644 --- a/target/arm/tcg/translate-sve.c +++ b/target/arm/tcg/translate-sve.c @@ -7665,8 +7665,8 @@ TRANS_FEAT_NONSTREAMING(HISTSEG, aa64_sve2, gen_gvec_= ool_arg_zzz, DO_ZPZZ_FP(FADDP, aa64_sve2, sve2_faddp_zpzz) DO_ZPZZ_FP(FMAXNMP, aa64_sve2, sve2_fmaxnmp_zpzz) DO_ZPZZ_FP(FMINNMP, aa64_sve2, sve2_fminnmp_zpzz) -DO_ZPZZ_FP(FMAXP, aa64_sve2, sve2_fmaxp_zpzz) -DO_ZPZZ_FP(FMINP, aa64_sve2, sve2_fminp_zpzz) +DO_ZPZZ_AH_FP(FMAXP, aa64_sve2, sve2_fmaxp_zpzz, sve2_ah_fmaxp_zpzz) +DO_ZPZZ_AH_FP(FMINP, aa64_sve2, sve2_fminp_zpzz, sve2_ah_fminp_zpzz) =20 static bool do_fmmla(DisasContext *s, arg_rrrr_esz *a, gen_helper_gvec_4_ptr *fn) --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381332; cv=none; d=zohomail.com; s=zohoarc; b=bJXQie4TCn5yepRixymSq/S3QiK89LMPwTDgl/Ytne4cQh69hyOKd/rXnuzQVEtGXggAuOUt/75TCbTOR3Uqz3a1gfBT3wg8meiptrt2Z1wVe6BA1Scb9UphizmQhrDL2L97ws4NSA8qU9QrKCZdpOQ8d3VBS7jPJZ64xm4iVfQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381332; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=jMNsUiuVzHCxD1362N6htyUoz/TrK6w3UThPw0LJ+HM=; b=QRccjaFH5pZHLNQ7+xXKihj9QnOE16eix63fU3Fyv59/yozacvrMKb3IhxAWFdBlgCjPeWf2c3a4kI0rC7bm29Kg9qptk/5LcEzwKr8ej3M2aVjmlBya5cdY3YZTWPy6/cqp10KsoMwJ2bn6kaSN8fNBvSUxV6ymhT5A8BV8XAU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381332214626.4475824595438; Sat, 13 Jun 2026 13:08:52 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUei-0005II-Ne; Sat, 13 Jun 2026 16:08:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcy-0002NP-14; Sat, 13 Jun 2026 16:06:49 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUcw-0000ty-6i; Sat, 13 Jun 2026 16:06:47 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A728F1B6E83; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0F8183CE8E5; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=1u4cWwjncfEDAZbvdKDFHxkIX4fuYmM1cM6NpQu0xQ8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=QxFKZARfEG8oOVegV0COfNoRDBINFyK4q3Lw2apTXlH+TJ4Vyly9K+i9tO4rH1YhQ 06t+2MHqTIq+0FJj3jCPdjJhqCf/fpPyN3Hq7BMgTNTARAnbzMqgIRkJFdZUIWJn9p ecssJvoZVAnfBlWeEHI9KOmocpuSxQDuLbkFGN0t+oVNiih/tXwBfSBD6ObA1Xpjnm 4o9NRh+TDGJsiXSM1QtokBNpzCk71s/8USLbDfjIbuAYnNhTGy+Go0N4q9X3z/1vC8 PsdoiCTwsb6K5WvuW+4OYnCgx/jCXpe+uW813/JAvpysLrVGMTOYbQxGWMq4qgTieJ PlZk1SwfT9O7w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Richard Henderson , Michael Tokarev Subject: [Stable-10.2.4 27/61] target/arm: Use FPST_A64_F16 for SVE FCVTLT_hs Date: Sat, 13 Jun 2026 23:03:10 +0300 Message-ID: <20260613200411.1808021-27-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381334150158500 From: Peter Maydell We should be using the F16-specific float_status for conversions from half-precision, because halfprec inputs never set Input Denormal. If we use the FPST_A64 fpstatus then we will incorrectly set FPCR.IDC for input-denormals when FPCR.AH=3D1. In commit e07b48995aaa we updated most of the halfprec-to-other conversion insns to use FPST_A64_F16 as part of implementing FEAT_AHP. However we missed the SVE FCVTLT instruction, which has a halfprec-to-single encoding. Correct the FPST we use for the hs variant of FCVTLT. Cc: qemu-stable@nongnu.org Fixes: e07b48995aaa ("target/arm: Use FPST_A64_F16 for halfprec-to-other co= nversions")a Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Reviewed-by: Richard Henderson Message-id: 20260521122913.1565011-3-peter.maydell@linaro.org (cherry picked from commit aa42300f86d172d7252f0cb95c2efd7570ad6b8f) (Mjt: context fixup across v10.2.0-1344-g895d4367d6 "target/arm/tcg: Use "or SME" feature checks where needed") Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/translate-sve.c b/target/arm/tcg/translate-sve.c index b9dba6ec31..a537d28c9f 100644 --- a/target/arm/tcg/translate-sve.c +++ b/target/arm/tcg/translate-sve.c @@ -7825,7 +7825,7 @@ TRANS_FEAT(BFCVTNT, aa64_sve_bf16, gen_gvec_fpst_arg_= zpz, s->fpcr_ah ? FPST_AH : FPST_A64) =20 TRANS_FEAT(FCVTLT_hs, aa64_sve2, gen_gvec_fpst_arg_zpz, - gen_helper_sve2_fcvtlt_hs, a, 0, FPST_A64) + gen_helper_sve2_fcvtlt_hs, a, 0, FPST_A64_F16) TRANS_FEAT(FCVTLT_sd, aa64_sve2, gen_gvec_fpst_arg_zpz, gen_helper_sve2_fcvtlt_sd, a, 0, FPST_A64) =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781390330; cv=none; d=zohomail.com; s=zohoarc; b=AEl/9kJ5RBYUeBaEBqyfHeGVH8gfNboL85LhJBkH8MQ57zVKQG0EhdQkInEF8C6Y2OHDVRtDIThwRpVZ7HB1Jhz4H/1ynxAm5StI8JbJ4tZsM887juVn+sPxFiLdocGoZzZZPeOLQUdzLkmu8BOZsBhx2qDZB9eqQ4FJQzZkOTs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781390330; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Ds0AA5gc7fDfUBF7z6tRHrwYFK+iKt7eckcizHQM4ZM=; b=OHhlfydiIJx9wVNOaNbpos4+53Q95X2jSU1C5dEnDXoSINhRSzGNvFQf0208IZRr/Dfrx9XH22V7Mu9EUjopWwjmRFHG0gPdHk5UvI8D6yskbj0cepfEetGBcFkCLxoa0Xom+Yk51R9xfkN23KN0Z1p1j8LI+9fzGH+8T+2oLCI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781390329714467.9681870035241; Sat, 13 Jun 2026 15:38:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUdy-00049s-JM; Sat, 13 Jun 2026 16:07:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdK-0002zF-2Y; Sat, 13 Jun 2026 16:07:10 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdI-0000vX-6a; Sat, 13 Jun 2026 16:07:09 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B894F1B6E84; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 20A3B3CE8E6; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=w02VivT/cF+Rutjk6NRJRm4HwYkPwmYx6ggLrW6L6O0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=hYeXB9RvKvPxRJMkhGIH9sOp1SeyXY1wwwpob407eLCWrrQreI9vjCSlUtHOurGeJ t04GfuirHtOUtFpqPn/3su1WPa2HzaW+X5eHX/6zk7Ro6MHVeCCvBjEkYtmUhQHtK4 RupUzEqg5Pk3vJJAhLBJdAq1Z9rt4/SXLsNomUNIzurRmgHdVjGQLdRwnpHn1qumMw /rlGgbfChgKQwTuPOzFmApSLcjSfCYQTxKxX/sUUnpaWKwYBAS8zmkKLe1EG8+3gsh Yg0zWmTAoikd8mYwAtaV8e5sx5UTnjAoAgD9DmvDfRs+KfRuRLOIODx6MqKSnkjO4v chujfZv/U9+eA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Richard Henderson , Michael Tokarev Subject: [Stable-10.2.4 28/61] target/arm: Set correct fp flags for FLOGB when FPCR.AH = 1 Date: Sat, 13 Jun 2026 23:03:11 +0300 Message-ID: <20260613200411.1808021-28-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781390335238158500 From: Peter Maydell Our implementation of the FLOGB insn does the operations entirely in the helper function, without needing to use fpu functions. This means it needs to handle all the fp status flags itself. We aren't setting float_flag_input_denormal_used when we use (i.e. do not flush to zero) an input denormal, which means that FPCR.IDC isn't set when it should be for FPCR.AH=3D1. We missed this when we added float_flag_input_denormal_used and made the fpu/ code set it. Add the missing float_raise(). Cc: qemu-stable@nongnu.org Fixes: d38a57a3f ("target/arm: Enable FEAT_AFP for '-cpu max'") Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Reviewed-by: Richard Henderson Message-id: 20260521122913.1565011-4-peter.maydell@linaro.org (cherry picked from commit 23ece2805f9a3f90f317aac1b49ee45783b57636) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/sve_helper.c b/target/arm/tcg/sve_helper.c index 7e547a7795..0da164c6dd 100644 --- a/target/arm/tcg/sve_helper.c +++ b/target/arm/tcg/sve_helper.c @@ -5032,6 +5032,7 @@ static int16_t do_float16_logb_as_int(float16 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -15 - clz32(frac); } /* flush to zero */ @@ -5060,6 +5061,7 @@ static int32_t do_float32_logb_as_int(float32 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -127 - clz32(frac); } /* flush to zero */ @@ -5088,6 +5090,7 @@ static int64_t do_float64_logb_as_int(float64 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -1023 - clz64(frac); } /* flush to zero */ --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381429; cv=none; d=zohomail.com; s=zohoarc; b=EyV7sCHPZUtf275e66AJG/j47gLByCUBquv7ZN573z+0/x4L1n8pmREKkKR93sskZd7kufKzTnK/LHTN8y9BqE3A2tN4tXdElHA8wXcqJVJwdWER5pwRsMuwSQRsqoOSG14/CEhXixphJpox6ZNw2t9q/lCNZjcHrc1vpfMS0GU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381429; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=X6cj0ORFPdV9oqrjGjVcxDuOiZe5+Bx92Z11vTvBMwE=; b=MpUe6YHDpeblBPHNBRQbehZxamSO6X7kiYkJzZp6BQ2BPzKNqeCOasDR6BT28QXcfg3PMqFA0aeYoF851+YUhtAbeFrfQb2KijP8N4GFOGcRfHdcXNnqla0kvwpL5HAgwiBzIPF7cHu0LXGj1wdTC5rbzCk5OjwAw7t71qS5HH0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381429448576.8923776803974; Sat, 13 Jun 2026 13:10:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUe8-0004IZ-9G; Sat, 13 Jun 2026 16:08:01 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdL-00036A-Pl; Sat, 13 Jun 2026 16:07:12 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdJ-0000y6-Vo; Sat, 13 Jun 2026 16:07:11 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C94881B6E85; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 310C53CE8E7; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=gTlxImFIhPbtXt9KMaAuMt3QHywOF5A0bgeUzttkpX8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Uy9Pq7cm05ElTdUM5OoVQFVj6G0YFnX9IRRROMzrbiFJibAx8WkpFNiQpIbe7dB4w bMUYF41qPfHy7xT/RWLV4VES1HS2H6j7apGerAQ9CksqqCYqsofigBnS2FXWqk46nw 3yBbmd67Lnioltd5vlO+pzJlIjMyDxp6UlmT+cIuIJ9/5omPOtDUsXnwKNiphtwLah SGw9PDDVKsxyI6G026Jy98bzgOuyGwANYA5/9LkaZgGxPcUZHeHvQr0KqLsRHeALC5 tRMDMMPaa7X36pYyeB+cqC9wczcSKyHlH0VOHSDXQcqifUCuPcAMtNFdfDaLQPcEY4 3FCTOIMGAuBMA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Chenyi Qiang , Farrah Chen , Zhenzhong Duan , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Michael Tokarev Subject: [Stable-10.2.4 29/61] vfio/container: Restrict dma_map_file() to shared RAM or RAM devices Date: Sat, 13 Jun 2026 23:03:12 +0300 Message-ID: <20260613200411.1808021-29-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381430208158500 From: Chenyi Qiang vfio_container_dma_map() uses dma_map_file() whenever a RAMBlock has an fd and the VFIO IOMMU backend supports file-based DMA mapping. That is not correct for private file-backed guest RAM. dma_map_file() resolves PFNs from the backing file, but private guest RAM mappings (MAP_PRIVATE) can run on different PFNs than the file because they are subject to copy-on-write (COW) anomalies. As a result, using dma_map_file() on a privately mapped RAMBlock can program DMA against pages that do not back QEMU's actual guest memory. Fix this by using dma_map_file() only for shared mapped RAMBlocks (MAP_SHARED) or RAM device regions. Fixes: fb32965b6dd8 ("vfio/iommufd: use IOMMU_IOAS_MAP_FILE") Reported-by: Farrah Chen Closes: https://bugzilla.kernel.org/show_bug.cgi?id=3D220776 Reviewed-by: Zhenzhong Duan Suggested-by: C=C3=A9dric Le Goater Signed-off-by: Chenyi Qiang Link: https://lore.kernel.org/qemu-devel/20260527101109.71781-1-chenyi.qian= g@intel.com Reviewed-by: C=C3=A9dric Le Goater Signed-off-by: C=C3=A9dric Le Goater (cherry picked from commit e6c47bebdf8628e635e1ba970919ca96d572dbbe) Signed-off-by: Michael Tokarev diff --git a/hw/vfio/container.c b/hw/vfio/container.c index 013a691bc5..6efec07e2d 100644 --- a/hw/vfio/container.c +++ b/hw/vfio/container.c @@ -74,15 +74,43 @@ void vfio_address_space_insert(VFIOAddressSpace *space, bcontainer->space =3D space; } =20 +static bool vfio_container_can_dma_map_file(VFIOContainer *bcontainer, + MemoryRegion *mr, int *fd) +{ + VFIOIOMMUClass *vioc =3D VFIO_IOMMU_GET_CLASS(bcontainer); + RAMBlock *rb =3D mr->ram_block; + + if (!vioc->dma_map_file || !rb) { + return false; + } + + *fd =3D qemu_ram_get_fd(rb); + if (*fd < 0) { + return false; + } + + /* + * We can use IOMMU DMA mapping (IOMMU_IOAS_MAP_FILE) for : + * + * 1) Guest RAM blocks explicitly configured as shared (MAP_SHARED) + * 2) RAM device sub-regions (MMIO BARs) + * + * Private RAM mappings (MAP_PRIVATE) are strictly excluded. Because + * they are subject to copy-on-write (COW) anomalies, their underlying + * PFNs can permanently diverge from the backing file + */ + return qemu_ram_is_shared(rb) || memory_region_is_ram_device(mr); +} + int vfio_container_dma_map(VFIOContainer *bcontainer, hwaddr iova, uint64_t size, void *vaddr, bool readonly, MemoryRegion *mr) { VFIOIOMMUClass *vioc =3D VFIO_IOMMU_GET_CLASS(bcontainer); - RAMBlock *rb =3D mr->ram_block; - int mfd =3D rb ? qemu_ram_get_fd(rb) : -1; + int mfd; =20 - if (mfd >=3D 0 && vioc->dma_map_file) { + if (vfio_container_can_dma_map_file(bcontainer, mr, &mfd)) { + RAMBlock *rb =3D mr->ram_block; unsigned long start =3D vaddr - qemu_ram_get_host_addr(rb); unsigned long offset =3D qemu_ram_get_fd_offset(rb); =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381396; cv=none; d=zohomail.com; s=zohoarc; b=JErMiN6zezVqWL0YBKLoKM0jutGWDbR6pJLKJnSr1URayCtzr/0CnbghcMHYJoAVoyZMXWG9KHP9ZzJGjyLytE18l9jDhR0aUWm/pMlif1HZuMb0gwKm1qQbNz8DHEGQPia6zqoYQp+Vup+k6vmJCyI6qCGJpMopR1wMvhp9MT8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381396; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=NeOsAps7QEnzxPJ/NbyVvWO77hqbN+KUBkFBUPQAnCA=; b=STXRyIMcTU1LP5BWPWaNvwtCkSVfFutoHQMLCnOUoqGJ4xYsG6Mc+Gi14yz8Z7eC2WT7qJGu4Gvwmy/0eQ56ROA2vKdGXqoopqL3EwMR3M26lX/S3jS76ra962r6cU2LC9uBk/21il6rgKJbaeXasZZb4FmGwJyJSrnRJPQpY20= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138139654482.03560486528454; Sat, 13 Jun 2026 13:09:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUek-0005gy-Hl; Sat, 13 Jun 2026 16:08:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdN-0003BO-SU; Sat, 13 Jun 2026 16:07:14 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdL-0001YL-NL; Sat, 13 Jun 2026 16:07:13 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E29FC1B6E86; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 419943CE8E8; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=uvHPQwPkwIYaloihdo82N87lRWAtIv9WtdKv3gWb44E=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=esHgqrlTbZbn/gNuyLpCguK+hWQOBQTWZ5YBZdCyoBLJP5G5Z4RANrGqdARd1Pr3L DfNXBgRGX8a+N3H9pDGRP75G/Z7fcMmWtWFqnTclmqatM0RmqJnnGI3JfPkDInRpM+ MrG89ZYxkXzDfLug8p21krRYmiAOHgDkiw6EcjfPBFuxthBP0TwRnVY57rrwP/rfve /s9Q/2PzuF6tLkECgVkRRLp5SS5umDwk50b8VtRlK8euG1zKlFpENWBD5jhem085HM skC6lb9h7St4CUafSD+mRGUhFFe+0V8R++kaxypLrBP8h4pEjkuuF39OIl4Kne8chf pnWxyFvDPBxAg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richard Henderson , Peter Maydell , Michael Tokarev Subject: [Stable-10.2.4 30/61] target/arm: Enable REVD for SVE2.1 Date: Sat, 13 Jun 2026 23:03:13 +0300 Message-ID: <20260613200411.1808021-30-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381398249158500 Content-Type: text/plain; charset="utf-8" From: Richard Henderson Cc: qemu-stable@nongnu.org Signed-off-by: Richard Henderson Message-id: 20260522220408.235438-1-richard.henderson@linaro.org Reviewed-by: Peter Maydell Signed-off-by: Peter Maydell (cherry picked from commit f12e7ba6f43803ec73c92b4ebeee6187113ba1fc) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/translate-sve.c b/target/arm/tcg/translate-sve.c index a537d28c9f..0f670f4834 100644 --- a/target/arm/tcg/translate-sve.c +++ b/target/arm/tcg/translate-sve.c @@ -2989,7 +2989,8 @@ TRANS_FEAT(REVH, aa64_sve, gen_gvec_ool_arg_zpz, revh= _fns[a->esz], a, 0) TRANS_FEAT(REVW, aa64_sve, gen_gvec_ool_arg_zpz, a->esz =3D=3D 3 ? gen_helper_sve_revw_d : NULL, a, 0) =20 -TRANS_FEAT(REVD, aa64_sme, gen_gvec_ool_arg_zpz, gen_helper_sme_revd_q, a,= 0) +TRANS_FEAT(REVD, aa64_sme_or_sve2p1, gen_gvec_ool_arg_zpz, + gen_helper_sme_revd_q, a, 0) =20 TRANS_FEAT(SPLICE, aa64_sve, gen_gvec_ool_arg_zpzz, gen_helper_sve_splice, a, a->esz) --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381345; cv=none; d=zohomail.com; s=zohoarc; b=j4+7rv+SzpYm4ytie7mDyDl+Ozmv5l2z9BXB7WGP+tFcFjmxzmszytgUpeELyM/Sijq78romAvCSXUEqepKLHyCZRDZmedWgBycAzNlwZWcMysdrZ7TFbZz7YOoAcpiWD5ZyTXDWxd2kEoHbUWdKLkXDZ2znaP+c6lwOMqB0NUQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381345; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YxnGtdOmw5T/MmLqyoq8AOoJyx24pHjw5T0vVpQkh3Q=; b=ks2+PgGXvc8sk4GpHqGD6+kt2kWTTn6q1c7PQQsI2qLQxJnY6JDvrF/FifmyYQ7dp+z6SsAHz/63D+yllaQQ/k6sV6ZN7BIzlYZNjeh/kPkbNfuVG3U57MBQlYiU+1dOwz7YxJoGiV6AAhVu0kvdCeuj9aw7LhGBm+ohbChspsI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381345840218.60898943943084; Sat, 13 Jun 2026 13:09:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUem-0005xy-Ab; Sat, 13 Jun 2026 16:08:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdP-0003Cd-BD; Sat, 13 Jun 2026 16:07:16 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdN-0001fV-Ho; Sat, 13 Jun 2026 16:07:15 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id F15B01B6E87; Sat, 13 Jun 2026 23:04:28 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 5B04E3CE8E9; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381068; bh=01u5170ETxPbIZHUjN6tH/hLORHcyT1482VamT7nDEg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=CIOZHXo8GaazIxFPn8pudmrRevnwRbTWKKNqCYUD+8gfcHQ6j0qkjLcWKPjR2/1ho ToDu1XBHAfhsbvmDwxN2q0vhUvGT6jvNxzkOq2rH9Cch85i1CxqHZxHZh4D+lrKtqT SHcV+oXZJYnazigU4E7SwZM0PbfmFPKW+bzwqi2sUmS+MkxOv4dVHBYvQJHyUU3HEM kdUHb57rdpLpZp3d+dl2CngH0EhThk6YAYKgSCX2i69Voz7wRGoJVZd8OzCP1nwNog f7ytn7O1rnNTHRE/S8HVog3XsDk0ppgQeXUq6RGNhlWf1769r7yDbvnKUfl/G+fVJj tkeJn9CdMwFBw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Richard Henderson , Michael Tokarev Subject: [Stable-10.2.4 31/61] target/arm: Don't assert if 64-bit EL2 AT insn sees a Domain fault Date: Sat, 13 Jun 2026 23:03:14 +0300 Message-ID: <20260613200411.1808021-31-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381347879158502 Content-Type: text/plain; charset="utf-8" From: Peter Maydell The Domain fault type can only happen for 32-bit short-format descriptors. This means that it almost never needs to be encoded in a long-format fault status code. However, there is one corner case where we do need to report it as a long-format FSC: if a 64-bit EL2 does an AT insn on an AArch32 EL1&0 translation regime that is using short-descriptors and that translation operation hits a Domain fault, then this is reported in the PAR_EL1 in long-format. The PAR_EL1 register description defines that this should be reported as 0b111101 for a level 1 Domain fault or 0b111110 for a level 2 Domain fault. The Arm ARM pseudocode special cases this in the function AArch64_PARFaultStatus() (because no other "fault to LFSC" code path can be a Domain fault). For QEMU, implement it in arm_fi_to_lfsc(). Cc: qemu-stable@nongnu.org Fixes: 1fa498fe0de97 ("target/arm: Provide fault type enum and FSR conversi= on functions") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3512 Signed-off-by: Peter Maydell Reviewed-by: Richard Henderson Message-id: 20260526174155.2491217-1-peter.maydell@linaro.org (cherry picked from commit bb957530471c792a9a51e822a6c2fa8398cc48f6) Signed-off-by: Michael Tokarev diff --git a/target/arm/internals.h b/target/arm/internals.h index 6434331ef2..7dc71776e7 100644 --- a/target/arm/internals.h +++ b/target/arm/internals.h @@ -871,6 +871,16 @@ static inline uint32_t arm_fi_to_lfsc(ARMMMUFaultInfo = *fi) assert(fi->level >=3D 0 && fi->level <=3D 3); fsc =3D 0b001100 | fi->level; break; + case ARMFault_Domain: + /* + * This can only happen when doing an AT insn at EL2 for an AArch32 + * stage 1 EL1&0 translation regime using short-descriptors, and + * the translation hits a Domain fault. This needs to be reported = in + * the long-format PAR. Compare pseudocode AArch64_PARFaultStatus(= ). + */ + assert(fi->level =3D=3D 1 || fi->level =3D=3D 2); + fsc =3D 0b111100 | fi->level; + break; case ARMFault_Translation: assert(fi->level >=3D -1 && fi->level <=3D 3); if (fi->level < 0) { --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781387335; cv=none; d=zohomail.com; s=zohoarc; b=gFQkQEKPmuACqkqUI6cqck2M3QlVINM++lfJ9iomc/uGdcF+CiXQk1bmAcHc0aJglmZThrZaAxf9akNjbga39mdOHpHBzgTGJDLEePgozeuv8R+rQaaViwoZodWIzZAGvf+0LAkSa99zrtGCOPIXiLbN8Sou1JZBor7ItAZle5I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781387335; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Gel4K5IchQiLQnsrSs0uj2oMcX9XgtQj/3aKYTKBLkc=; b=ZfGR8neTVfJk0bKONCqOP5kZEY51jly1rZAMWZ/b2k5Q7AVnbM1no9FwDjGKCXMfZf9hILc77KBcrxumeqlw06IQlsgMVxYo/7akLvoKfWcOqGDzBlDI1xyvfTAmXnBRqX1C61hBy0bm2VgaZl9CmZLCdFftzJVGTnuYjBRSQP8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781387335007210.3929801783769; Sat, 13 Jun 2026 14:48:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUeZ-0004wI-UJ; Sat, 13 Jun 2026 16:08:29 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdR-0003E5-CI; Sat, 13 Jun 2026 16:07:19 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdP-0001nW-IJ; Sat, 13 Jun 2026 16:07:17 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 0D3E31B6E88; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6A45A3CE8EA; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=2rNFmlkSpmLlwayTQ00o3VehZhrNYH28oiDRdsxui9E=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=R4UuaXMUZ0GZaRrPZZtHmiWH6/wYNrprRDhR6DGnaXCR2R4ispgqVN98qbQr3Nf/+ K1g0qhDal7gyboa+IkE1XYMfuN10vK7DK7g+fMqqy1QHD7hiuEYSjlH2s2wiHU2Vlu TC4FChQkMgbJ/7em4EF0jPQe/CXiccK9BImvPcVwKgyE1bv1CT5zy9djFKsSDM3LfW ZukdVEJ903WI2lIHUZKA1Tdxz77AtpEIcZ185gIfUt96utZ+xlLPH37tUhuIuyc5Jj teUkZhtzuUq6UCvuu/9CKykMXQ0Tc+W9AM1kdt/+oXvUT4ozlhWwxlKQDQmuOLss3a murSpZeASoFGA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Richard Henderson , Michael Tokarev Subject: [Stable-10.2.4 32/61] target/arm: SME BFCVT, BFCVTN have "Alternate BFloat16 behaviors" Date: Sat, 13 Jun 2026 23:03:15 +0300 Message-ID: <20260613200411.1808021-32-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781387336178158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell The Arm ARM A1.5.10 notes that some instructions have "Alternate Bfloat16 behaviors" when FPCR.AH =3D=3D 1. We implement these using the FPST_AH and FPST_AH_F16 fp_status words. The list includes the SME BFVCT (single-precision to BFloat16) and BFCVTN, but we forgot to make those use FPST_AH_F16 when we implemented them. (We get the ASIMD and SVE insns on the list right.) Add the missing logic to select the right FPST. Cc: qemu-stable@nongnu.org Fixes: 465d36db0e1 ("target/arm: Implement SME2 BFCVT, BFCVTN, FCVT, FCVTN") Reviewed-by: Richard Henderson Signed-off-by: Peter Maydell Message-id: 20260521180854.1744788-1-peter.maydell@linaro.org (cherry picked from commit ca33de98447c2c2825c1af73cfacf4f65a9bc6c6) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/translate-sme.c b/target/arm/tcg/translate-sme.c index 091c56da4f..e9ee8e3740 100644 --- a/target/arm/tcg/translate-sme.c +++ b/target/arm/tcg/translate-sme.c @@ -1415,9 +1415,9 @@ static bool do_zz_fpst(DisasContext *s, arg_zz_n *a, = int data, } =20 TRANS_FEAT(BFCVT, aa64_sme2, do_zz_fpst, a, 0, - FPST_A64, gen_helper_sme2_bfcvt) + s->fpcr_ah ? FPST_AH : FPST_A64, gen_helper_sme2_bfcvt) TRANS_FEAT(BFCVTN, aa64_sme2, do_zz_fpst, a, 0, - FPST_A64, gen_helper_sme2_bfcvtn) + s->fpcr_ah ? FPST_AH : FPST_A64, gen_helper_sme2_bfcvtn) TRANS_FEAT(FCVT_n, aa64_sme2, do_zz_fpst, a, 0, FPST_A64, gen_helper_sme2_fcvt_n) TRANS_FEAT(FCVTN, aa64_sme2, do_zz_fpst, a, 0, --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381335; cv=none; d=zohomail.com; s=zohoarc; b=U4EicXB3p2pwJ8/b6Fc+jirncnTLhBcaHOGddZogw9UVlojrx1iLmGRb6WUeEWq3Pm18VIkkQiwrNCshiTNyR1zoheYTCERHOQesTsqZzQcFXI2fBqWBjsw3b8crlDgKBUHJNa2EB8VqL2JSpQEky5zwj8TifIs9zkdVToVBG/g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381335; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ivf6Ak2safQzcT81GvJwbErpLDTL99yXYrufqJUnFww=; b=M4yw12xb70mnr6ouyQiiomhtH7pBFgOxi1nt9UpqjXScIwXZpM+rR0hb4Ege1/obAdj/y+Zl1pVS1ZXULyrFkXfQJpXjRUka4JI/vF4qF7/WUrlUtkF8c3/fJ0x3XG8B0YglIF3qlrFBlXch3jYhJFnnC1Ug7YCrF3tGYhSsC30= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138133501847.623781659910605; Sat, 13 Jun 2026 13:08:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUep-0006Vi-UN; Sat, 13 Jun 2026 16:08:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdm-0003oG-O3; Sat, 13 Jun 2026 16:07:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdl-0001qP-0K; Sat, 13 Jun 2026 16:07:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 1C79B1B6E89; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7A41D3CE8EB; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=fDOrCK2N6Pl6NIhKkdpC1+NkBaVzNlosKwWDNcpyHwA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=JuWNck3W6v8Kqc+2cTdH8KQfYG4ggmEmOqV2Odrmg5ITXynBhua8J9qM3p5V5hxcL Z8Yt8wjgOBIVcCXutZBPiQwmOfKBeWgBZwiDxk+JGkY4QOGLix3r2LkoyM6eec4kVw jgzAxmYREI+y8Kx2nRt//hO4a2ZzmMxUx9lQFurF7dmH/5NEG2Dj5tUIslTUdq+lR4 U++b99+826p/9W/8F1MUHTgYnU3U2nmzXWJIZU0zQC9ibZeZQ5xvCwWPh/LlIvYrK7 8Clf5QUlkGt4GDNURJMrUZe7CzZrVWm0MA+2g2qCOM/2g323aQK6Egtb7khF5pLAF3 9+/D1K4Jl+C4A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Jason Wang , Michael Tokarev Subject: [Stable-10.2.4 33/61] hw/net/rocker_of_dpa: Check group ID pointers are not NULL Date: Sat, 13 Jun 2026 23:03:16 +0300 Message-ID: <20260613200411.1808021-33-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381335848158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell In of_dpa_cmd_add_l2_flood(), we use rocker_tlv_parse_nested() to fill in a tlvs[] array. If the guest command is valid then the entries should be pointers to TLV data items with group IDs. However, if the guest gives us bogus data then rocker_tlv_parse_nested() indicates this by leaving the tlvs[] entries NULL. In the other places that use this function, we check for this before using the value, but here we forgot, and the result is that QEMU can crash: #0 __memcpy_avx_unaligned_erms () at ../sysdeps/x86_64/multiarch/memmove-v= ec-unaligned-erms.S:331 #1 0x00005555574f7137 in __asan_memcpy () #2 0x0000555558106792 in ldl_he_p (ptr=3D0x8) at /home/pm215/qemu/include/= qemu/bswap.h:278 #3 0x0000555558106755 in ldl_le_p (ptr=3D0x8) at /home/pm215/qemu/include/= qemu/bswap.h:311 #4 0x00005555580f85ed in rocker_tlv_get_le32 (tlv=3D0x0) at ../../hw/net/r= ocker/rocker_tlv.h:114 #5 0x000055555810a8ad in of_dpa_cmd_add_l2_flood (of_dpa=3D0x506000082e38,= group=3D0x503000b4e440, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2032 #6 0x0000555558108a74 in of_dpa_cmd_group_do (of_dpa=3D0x506000082e38, gro= up_id=3D1073741824, group=3D0x503000b4e440, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2115 #7 0x0000555558108730 in of_dpa_cmd_group_add (of_dpa=3D0x506000082e38, gr= oup_id=3D1073741824, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2135 #8 0x00005555580f66ec in of_dpa_group_cmd (of_dpa=3D0x506000082e38, info=3D0x514000072e40, buf=3D0x5070002356c0 "= \001", cmd=3D7, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2194 Check for NULL values and return an error. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/1851 Signed-off-by: Peter Maydell Signed-off-by: Jason Wang (cherry picked from commit 8526b7d6b67beda0c83e4a8aec1449475fe5dd65) Signed-off-by: Michael Tokarev diff --git a/hw/net/rocker/rocker_of_dpa.c b/hw/net/rocker/rocker_of_dpa.c index 262ceb35f6..005a29e6c1 100644 --- a/hw/net/rocker/rocker_of_dpa.c +++ b/hw/net/rocker/rocker_of_dpa.c @@ -2024,6 +2024,10 @@ static int of_dpa_cmd_add_l2_flood(OfDpa *of_dpa, Of= DpaGroup *group, group_tlvs[ROCKER_TLV_OF_DPA_GROUP_IDS]); =20 for (i =3D 0; i < group->l2_flood.group_count; i++) { + if (!tlvs[i + 1]) { + err =3D -ROCKER_EINVAL; + goto err_out; + } group->l2_flood.group_ids[i] =3D rocker_tlv_get_le32(tlvs[i + 1]); } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381397; cv=none; d=zohomail.com; s=zohoarc; b=MFvMCWoLk/cJyIWup1ObGs5vzAsL0fYJFQrIfVBQj0XGPViGtQ7kahZTGBPiAfEkvumqXT300KdYti5uEH2WX8KkSMYMb+A/UHmbJccN2X13uDeiCHiDYUTESBfgmxYV29/EN7NYcEs8ps7hJgcaPW+0WG5aiecMK9y42xzCMwo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381397; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=PPe7Z6G5iji//I2xKzzxlA+1Qy5J6JPq1XiwUUVdxMU=; b=hyPllPrF2uvMw91PzRFNwNz/Kl//UrryE8xTvFBAoCqvfqrC/Yh5UpZztLChfPFk51ejHQNYPve/nFWY/rn8t3ji5WAtc/oPfHPdiGBhqmd5bVxWWTT/X0bc4Qtim1X2sDS1RdBBuokdiHLSlK6R91X524qFPlRymI6GybFxrBg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381397182498.5759116838426; Sat, 13 Jun 2026 13:09:57 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUe9-0004Jr-Bi; Sat, 13 Jun 2026 16:08:01 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdp-0003p9-0b; Sat, 13 Jun 2026 16:07:41 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdn-0001uO-34; Sat, 13 Jun 2026 16:07:40 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 2BA331B6E8A; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 89CD03CE8EC; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=2R9oi2f4qa84URdd4Hxmb+R+qR4iwn/zveZIRjjeUgM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=HJvbsgIUe82uvPMKOS7vJCtHsyRCwFElsRZGCTMS0hOtOtZXQWBp/tuTc0VDw0sVC MGxcEBgqlFf48OxbanzdSmf89B/B7+o5DAqjRudQzjeuCFwBxyFOVHH3rhzaYiFf0j U7xLzo36gEZccNfibyH9zQN0PuRv6097tF9NMysL39Q7utWLMfGugeWHuRTFtmLobK h8i8a0QHioA1mXNRy8L0VUYCx+G+Z8IFnaEFUMjsFulfCAO9mmuOnYArbAla31e3mn /loXRPT6frq09Fpw6pVeWaKRr7Rg0VGMRXYV4r7QbZyCLCtBUwRuo2plfdcPMq836P RdmnR/2Vz/Rpg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Jason Wang , Michael Tokarev Subject: [Stable-10.2.4 34/61] hw/net/rocker_of_dpa: Avoid unaligned accesses in _of_dpa_flow_match() Date: Sat, 13 Jun 2026 23:03:17 +0300 Message-ID: <20260613200411.1808021-34-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381398297158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell _of_dpa_flow_match() tries to do masked comparisons of OfDpaFlowkey structs by casting pointers to them to uint64_t* and then doing the memory accesses as 64-bit. This is undefined behaviour because the pointers might not be 64-bit aligned, and the UB sanitizer spots this: ../../hw/net/rocker/rocker_of_dpa.c:321:20: runtime error: load of misalign= ed address 0x512000164044 for type 'uint64_t' (aka 'unsigned long'), which = requires 8 byte alignment 0x512000164044: note: pointer points here 02 00 00 00 00 00 ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00= 00 00 00 00 00 00 00 00 ^ We do know that OfDpaFlowKey structs must be at least aligned enough for uint32_t accesses, because that's the type of the first field. Switch to using uint32_t accesses in the loop. Because the "width" field is always set via the FLOW_KEY_WIDTH macro and not exposed to the guest, we can adjust the macro to store the number of uint32_t to be checked rather than needing to change the loop boundary in the match function. Cc: qemu-stable@nongnu.org Signed-off-by: Peter Maydell Signed-off-by: Jason Wang (cherry picked from commit 71d027cfee8553e2ec28efa1ddd7fd0ecbadcc86) Signed-off-by: Michael Tokarev diff --git a/hw/net/rocker/rocker_of_dpa.c b/hw/net/rocker/rocker_of_dpa.c index 005a29e6c1..6be2e253a0 100644 --- a/hw/net/rocker/rocker_of_dpa.c +++ b/hw/net/rocker/rocker_of_dpa.c @@ -99,13 +99,13 @@ typedef struct of_dpa_flow_key { } nd; } ipv6; }; - int width; /* how many uint64_t's in key? */ + int width; /* how many uint32_t's in key? */ } OfDpaFlowKey; =20 -/* Width of key which includes field 'f' in u64s, rounded up */ +/* Width of key which includes field 'f' in u32s, rounded up */ #define FLOW_KEY_WIDTH(f) \ DIV_ROUND_UP(offsetof(OfDpaFlowKey, f) + sizeof_field(OfDpaFlowKey, f)= , \ - sizeof(uint64_t)) + sizeof(uint32_t)) =20 typedef struct of_dpa_flow_action { uint32_t goto_tbl; @@ -299,9 +299,9 @@ static void _of_dpa_flow_match(void *key, void *value, = void *user_data) { OfDpaFlow *flow =3D value; OfDpaFlowMatch *match =3D user_data; - uint64_t *k =3D (uint64_t *)&flow->key; - uint64_t *m =3D (uint64_t *)&flow->mask; - uint64_t *v =3D (uint64_t *)&match->value; + uint32_t *k =3D (uint32_t *)&flow->key; + uint32_t *m =3D (uint32_t *)&flow->mask; + uint32_t *v =3D (uint32_t *)&match->value; int i; =20 if (flow->key.tbl_id =3D=3D match->value.tbl_id) { --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381362; cv=none; d=zohomail.com; s=zohoarc; b=X0M8EqKTPlSMIjklWBYEvcIIIXZ7zvpLtJ+TbrTc8JQwvMgXVnp2P+071/zA5tlqYydYJ0EMidSKiv1t8KWZ0L9HyeSdT/fnDSXdFiw5DbyQX6+9HST/JeW5vtoDxTUtpHisO2ZHGgkH+kb3jdVEQgUBB2flWlD59x9i6sE0+Fw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381362; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=HGxfuZJKsLe8+60uPCQZxke+PsDM5TGk+j/oBE/o73A=; b=d2nLezjaFbmFD3nu96SMFbgdJARhR/eotAeO7p1sM/TikT7oBPoMgylGTMQvfxW6So5nd5r8OvXkRt/Tq1pWAhTMx+NEE5P1lWZKkahHQHyG0I7JfA6azPa0gkRUhPg2ssod/PPkLsQrX+xsY7zPAlij+QNZEX27EDTGb79MUrM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381362425131.0838169594549; Sat, 13 Jun 2026 13:09:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUec-0004yf-Nn; Sat, 13 Jun 2026 16:08:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdq-0003r4-4N; Sat, 13 Jun 2026 16:07:43 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdo-0002Dt-D0; Sat, 13 Jun 2026 16:07:41 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 3BB841B6E8B; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 98D0A3CE8ED; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=LlFJ5MNrrFqn2jreYasQuWyv+SrH/nQ9Zgl3Dd/fIBM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=GPgrQJ6m6wRDRc5BGeG1cspEvjGxmLVlLKQSuOBYKmWD9fsBac1wkEHiIoakYhiOR U4izr9rlArrfuPbDFQjEaULxdEZhgPIeF2Gh2LLTLX+HcVetUS+eEKoYplTd0vENoZ EzIUyblnGASczp6qwW/BgbmjsVDj52HF5jPnUzP081nuyoYq4+zFbwi8VAnw735yOO yU1IDx/zZ34gOC9QF1RYxIlRu6WvvO/gg6iUoPR42bf8Rijoadr66X76Wn7GdjPAq+ Yh0WDKY1EaCKeXLZd3TFun0pjQTPi1XSJp9/rRnGIvVq5qzpWJ0ZqilZT/fwl/beli a+7Q6x7fMvnKA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-10.2.4 35/61] linux-user/ppc: restore fp_status from FPSCR on sigreturn Date: Sat, 13 Jun 2026 23:03:18 +0300 Message-ID: <20260613200411.1808021-35-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381363982158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner restore_user_regs() restores the PPC FPSCR with a direct assignment: env->fpscr =3D (uint32_t) fpscr; ppc_store_fpscr() exists precisely to write FPSCR and keep the derived env->fp_status in sync: it calls fpscr_set_rounding_mode() to update the softfloat rounding mode, and set_float_rebias_overflow/underflow() to reflect the FP_OE/FP_UE enable bits. The direct assignment bypasses all of this. On sigreturn, interrupted code resumes with whatever rounding mode and overflow/underflow-rebias state the signal handler last installed in fp_status, rather than the state that was saved at signal delivery. Replace the direct assign with ppc_store_fpscr(). The FPSCR_MTFS_MASK applied inside ppc_store_fpscr() only excludes the computed FP_FEX and FP_VX bits, which it re-derives correctly from the exception and enable bits in the restored value. Fixes: bcd4933a23 ("linux-user: ppc signal handling") Cc: qemu-stable@nongnu.org Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 3f50dd46664bdf94f10aca8b76dc4dcb9182a5ae) Signed-off-by: Michael Tokarev diff --git a/linux-user/ppc/signal.c b/linux-user/ppc/signal.c index a9c10e0987..ab1afea30a 100644 --- a/linux-user/ppc/signal.c +++ b/linux-user/ppc/signal.c @@ -420,7 +420,7 @@ static void restore_user_regs(CPUPPCState *env, __get_user(*fpr, &frame->mc_fregs[i]); } __get_user(fpscr, &frame->mc_fregs[32]); - env->fpscr =3D (uint32_t) fpscr; + ppc_store_fpscr(env, (uint32_t) fpscr); } =20 #if !defined(TARGET_PPC64) --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381432; cv=none; d=zohomail.com; s=zohoarc; b=ayjKQ0TnICnjdhchzdAyW/oKyWWk1LYJdLQ3fH8hlXjC69Sgtdqd7o0Gvn/bA2hE5LPB/fTeF8t346+hCRihzt0WlSJo7/nCcMRnWsAl3MTCJGaAHYjxg0ABUIVru+1LtnnTe7sH4nHEk5TbHkD6u7ak97YUV0QaJtbuLFTPHlU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381432; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=enO/ISmbamw0vCwRi8IJb6/xK3hszJncn/WnDY0PddU=; b=n4GFJ0PTd7kJNBnOkEibf5ijOn4g0PYHjzP7Nr91B4XnX4MCYw+7iPSGzZvJKjRfj2nFNCFy80HYdeW7OPALbQlI0qMNJojxr5XYJnhat61G26ghyuYpIId1xtNQeaDqreJ+iiJc75zl8CE2lgZdyCdWm/UAQVOBtJiC9wnS5yo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17813814320269.029495238722689; Sat, 13 Jun 2026 13:10:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUej-0005RU-HW; Sat, 13 Jun 2026 16:08:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUds-0003vh-DA; Sat, 13 Jun 2026 16:07:46 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUdq-0002ET-MX; Sat, 13 Jun 2026 16:07:44 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 4A5B21B6E8C; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id A89063CE8EE; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=9l0toHTc5UsExhdAtSaYAnSLE1MoQj8QuyNnODhrGOw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=rss5fLDnkSaRBON4QNRFcLPpv5TmrWcH//cFFpxYfsv5fkg8ZNbNIJDzmQCWMHkLZ 2oIdSXGlWl3TAZsxGJ2O8n+fqp0bpV/PmBkl2pbA3VMk6MfPkAmMMTXkUiwWEc3PqN gu10BBfP9ioPjrxVG2OXY78FyEh8pkW5SrMMAH1r5qVSfHRz8ohDarefCjLqUdqAyO 1ECfbe+hDFY1LtFgS/RKIMfkYz3S4E+slM2TbG2eaPYR/dmwUCDZo+WJik6KiESDOt XMS1LyU6PygRP8rxDW42iZXfsFzdqZ8etVqE7g7SsqzP4fMO0nliYLhytAl/0FJUTU R7Xen3DV6PebQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-10.2.4 36/61] linux-user/mips: save/restore FCSR across signal delivery Date: Sat, 13 Jun 2026 23:03:19 +0300 Message-ID: <20260613200411.1808021-36-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381432230158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the MIPS FPU control/status register (FCSR, fcr31) in env->active_fpu.fcr31. The rounding mode, flush-to-zero (FS), and NaN-2008 mode bits in fcr31 are reflected into the derived env->active_fpu.fp_status via set_float_rounding_mode() and friends; every architectural write to FCSR goes through helper_ctc1() which calls restore_fp_status() to keep the two in sync. Both target_sigcontext variants (O32 and N32/N64) have an sc_fpc_csr field that holds FCSR, but setup_sigcontext() never wrote it and restore_sigcontext() never read it. As a result: - The signal frame always delivered sc_fpc_csr =3D=3D 0 to the handler, so sigaction(SA_SIGINFO) handlers that inspect the interrupted context see the wrong FCSR. - On sigreturn, active_fpu.fcr31 retained whatever value the signal handler last installed (if any), and active_fpu.fp_status was never resynced. Interrupted code resumed with the wrong rounding mode, FS flag, and NaN-2008 semantics. Fix setup_sigcontext() to save fcr31 into sc_fpc_csr. Fix restore_sigcontext() to read it back (masked to fcr31_rw_bitmask as the kernel does) and call cpu_mips_restore_fp_status() to resync fp_status from the restored fcr31. Add cpu_mips_restore_fp_status() in target/mips/fpu.c (which already defines ieee_rm and includes fpu_helper.h), and declare it in cpu.h. Fixes: 084d0497a0 ("mips-linux-user: Save and restore fpu and dsp from sigc= ontext") Cc: qemu-stable@nongnu.org Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 84b920ccb5ee5287747af2d36d1ece6367b6a40e) Signed-off-by: Michael Tokarev diff --git a/linux-user/mips/signal.c b/linux-user/mips/signal.c index d69a5d73dd..1b10012726 100644 --- a/linux-user/mips/signal.c +++ b/linux-user/mips/signal.c @@ -134,6 +134,7 @@ static inline void setup_sigcontext(CPUMIPSState *regs, for (i =3D 0; i < 32; ++i) { __put_user(regs->active_fpu.fpr[i].d, &sc->sc_fpregs[i]); } + __put_user(regs->active_fpu.fcr31, &sc->sc_fpc_csr); } =20 static inline void @@ -165,6 +166,12 @@ restore_sigcontext(CPUMIPSState *regs, struct target_s= igcontext *sc) for (i =3D 0; i < 32; ++i) { __get_user(regs->active_fpu.fpr[i].d, &sc->sc_fpregs[i]); } + { + uint32_t fcr31; + __get_user(fcr31, &sc->sc_fpc_csr); + regs->active_fpu.fcr31 =3D fcr31 & regs->active_fpu.fcr31_rw_bitma= sk; + cpu_mips_restore_fp_status(regs); + } } =20 /* diff --git a/target/mips/cpu.h b/target/mips/cpu.h index 5cd4c6c818..b49db458c0 100644 --- a/target/mips/cpu.h +++ b/target/mips/cpu.h @@ -1366,6 +1366,9 @@ void cpu_mips_clock_init(MIPSCPU *cpu); /* helper.c */ target_ulong exception_resume_pc(CPUMIPSState *env); =20 +/* fpu.c */ +void cpu_mips_restore_fp_status(CPUMIPSState *env); + /** * mips_cpu_create_with_clock: * @typename: a MIPS CPU type. diff --git a/target/mips/fpu.c b/target/mips/fpu.c index c7c487c1f9..8b661865ca 100644 --- a/target/mips/fpu.c +++ b/target/mips/fpu.c @@ -17,6 +17,11 @@ const FloatRoundMode ieee_rm[4] =3D { float_round_down }; =20 +void cpu_mips_restore_fp_status(CPUMIPSState *env) +{ + restore_fp_status(env); +} + const char fregnames[32][4] =3D { "f0", "f1", "f2", "f3", "f4", "f5", "f6", "f7", "f8", "f9", "f10", "f11", "f12", "f13", "f14", "f15", --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381339; cv=none; d=zohomail.com; s=zohoarc; b=PPQiwq7c87JB161eic/iGT3vTGe0mXRGFSI13UtfKUugLjMnk8SjYLFu4Kp/3Hi7uOw0jR4lhcTjtLIr1qIBEbyumXKOwqhrMwtUNQq2QqYE9Z3cR6iH7CBurNVfS+XBV/sGS7bJo52b7YsYQOOOxmVKpb5WLwqoIxfe1E9H8bY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381339; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LPhyYccvzczMUvS1xg6EDqVdVvYUg9RiFt2CCvF1NVI=; b=I2KOJ+CtTqMhMKLAFVcS+b5I+UNW0fqknuiNIZj47ZmPEHWtcAmcdASjQBscuSzLdDAWfi9YecX4GicL1dJfppSOFg8ZUFZ0GOMO3Rd7ivSCHipkt30BOPuFezGCBJo8B7iK/vyytdXyNjh9pT0EWLKJfubOErvXialgLOwSYA0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381339926892.679212728363; Sat, 13 Jun 2026 13:08:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUeh-0005HB-Kp; Sat, 13 Jun 2026 16:08:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeE-0004fY-9X; Sat, 13 Jun 2026 16:08:06 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeB-0002En-Qj; Sat, 13 Jun 2026 16:08:05 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 5C50E1B6E8D; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B7A683CE8EF; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=Wqggm+YI9CGOXrC37tB98c0M6KNUDE9ZIppSxjX+MCI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=I9pW3OrS0CEJJGmi0aTM7FMMDzA4bgCmNUWDGTxQPSsVEfIhtI/DpQxV/BaJmsQro cdljc1DUS4YgQrclKH/VCkaABmHq+pnx3p71r/xGbobiSbYOg6kHWwWFrMl972KQ9Y +RsM/J1OegTvZVZDU+qnbmO5UZCQy7vr3xyFRK3rN0RyZ4Adw+PfwrtjLNSrQq1XcN 6GWCyrGG/ZfH33UtxH5ocBlhLp1cYgYyLLE5Kq626sHGE1x+IHgEkQzFtumwDeGLQE CemXaMjZ3VbgV60GHoAxY/qdbh6Gdaw+wKT/6J6iaoecCvraXB/f5YDRmrYoB6415B pYBuzY9xVwshw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Yoshinori Sato , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-10.2.4 37/61] linux-user/sh4: preserve T/M/Q bits across signal delivery Date: Sat, 13 Jun 2026 23:03:20 +0300 Message-ID: <20260613200411.1808021-37-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381342029158501 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the SH4 T, M and Q status-register bits outside env->sr, in the dedicated env->sr_t, env->sr_m and env->sr_q fields; cpu_read_sr() folds them back into the architectural SR value and cpu_write_sr() splits them back out. setup_sigcontext() saved the bare env->sr (so the T/M/Q bits were always zero in the signal frame) and restore_sigcontext() wrote the value straight back into env->sr without updating sr_t/sr_m/sr_q. As a result the T bit was never preserved across signal delivery: on sigreturn the interrupted code resumed with whatever T value the signal handler last left behind. Any conditional branch (or addc/subc/rotcl/div1, etc.) immediately following the interrupted instruction could then take the wrong path. This is the cause of the long-standing intermittent failures of the tests/tcg/multiarch/signals.c test on sh4, which was marked BROKEN. With a SIGRTMIN timer firing every millisecond across many threads, the race was hit a few percent of the time and corrupted the guest heap, surfacing as a SIGSEGV in memset, a malloc assertion, or an rseq registration abort. Traced on a deterministic rr recording: a cmp/hi set T=3D0, the timer signal interrupted the very next instruction (a bf), the handler left T=3D1, and the resumed bf took glibc calloc's MORECORE_CLEARS branch, using the old top-chunk size as the clear length for a freshly split small chunk and running memset off the end of the heap. Fix setup_sigcontext()/restore_sigcontext() to use cpu_read_sr() and cpu_write_sr() so the T, M and Q bits round-trip correctly, and drop the BROKEN annotation on the sh4 signals test. Fixes: c3b5bc8ab3 ("SH4: Signal handling for the user space emulator, by Ma= gnus Damm.") Cc: qemu-stable@nongnu.org Reviewed-by: Yoshinori Sato Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 6bf4c0295cccf74f3c5c0b674328b97d6fd1505c) Signed-off-by: Michael Tokarev diff --git a/linux-user/sh4/signal.c b/linux-user/sh4/signal.c index d70be24c38..cc36425c49 100644 --- a/linux-user/sh4/signal.c +++ b/linux-user/sh4/signal.c @@ -131,8 +131,10 @@ static void setup_sigcontext(struct target_sigcontext = *sc, COPY(gregs[14]); COPY(gregs[15]); COPY(gbr); COPY(mach); COPY(macl); COPY(pr); - COPY(sr); COPY(pc); + COPY(pc); #undef COPY + /* The T, M and Q bits live outside env->sr; fold them back in. */ + __put_user(cpu_read_sr(regs), &sc->sc_sr); =20 for (i=3D0; i<16; i++) { __put_user(regs->fregs[i], &sc->sc_fpregs[i]); @@ -159,8 +161,14 @@ static void restore_sigcontext(CPUSH4State *regs, stru= ct target_sigcontext *sc) COPY(gregs[14]); COPY(gregs[15]); COPY(gbr); COPY(mach); COPY(macl); COPY(pr); - COPY(sr); COPY(pc); + COPY(pc); #undef COPY + /* The T, M and Q bits live outside env->sr; unfold them. */ + { + uint32_t sr; + __get_user(sr, &sc->sc_sr); + cpu_write_sr(regs, sr); + } =20 for (i=3D0; i<16; i++) { __get_user(regs->fregs[i], &sc->sc_fpregs[i]); diff --git a/tests/tcg/sh4/Makefile.target b/tests/tcg/sh4/Makefile.target index 7852fa62d8..b7a8737be0 100644 --- a/tests/tcg/sh4/Makefile.target +++ b/tests/tcg/sh4/Makefile.target @@ -3,13 +3,6 @@ # SuperH specific tweaks # =20 -# This triggers failures for sh4-linux about 10% of the time. -# Random SIGSEGV at unpredictable guest address, cause unknown. -run-signals: signals - $(call skip-test, $<, "BROKEN") -run-plugin-signals-with-%: - $(call skip-test, $<, "BROKEN") - VPATH +=3D $(SRC_PATH)/tests/tcg/sh4 =20 test-macl: CFLAGS +=3D -O -g --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381529; cv=none; d=zohomail.com; s=zohoarc; b=Ab0MhAeCr638Ift0p8gzDmWbA4cVInqNNqEGx19/qKC32ipVt5I0wZE//XMI71FVzRm6xpUnw54yeaVd0nDYB8iTmPzMqVbGLiptz7BZf2GI8IT8X5A7u3HZWgjhvX/gucZTMx0r0lQvuDS6p1SrK3IdKSKibnZouCxUhOfiblk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381529; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3/+PVPeD75rB12z6D1vp6z4XIsyLrHCI+DIWtarGGJQ=; b=knvBgTHITXZZCQnQl9F9frkWFAl9X9hpYq0kb5+Fmr2KHU2m9zG4eeY7vP+tZEc79RgdoDjv7hrd+Xtj43HeN8VwQDp3Yjwb7g14KqxnWYIKK9ig5Cuv4d1Q2CAB0du3xLGNtV2SB0/lNFMMZlR23ghVb2W3kchuPWzLQWSEQzk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381529754903.5846329180133; Sat, 13 Jun 2026 13:12:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUet-000797-N8; Sat, 13 Jun 2026 16:08:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeG-0004nF-7d; Sat, 13 Jun 2026 16:08:09 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeE-0002FI-3W; Sat, 13 Jun 2026 16:08:07 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 6FF3C1B6E8E; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C9EC03CE8F0; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=SZ1mxK3d+3kUREji8K1JEvm0X/1tdlieKxCu+ddyKkM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=lG4jVZON3hGZEzhGLiNjlDqJ3tmBol8tbncQ0IrBrMQ+XgzVaoTayFvempUGdq4yc c4otzZEPbeGoVZFQ+jvf0L8kFr4URpPAE89Imt+xCnqLogO6W+aosjsOj52mmcwNhM n//jjm8OW1E6J/1Ci04li/kA5ScmHe4JQNfWjXBc9e9sZJwvA4J7NwD6SHQz8u6IM9 0mjrInuLthBvXGtQB56ryXCjsePGHm/KC48qZydzQYZw7bT+dv2X0gSFxLvJnCs2sO 9gg4cpigbt0a73uOAq3FeNLrIMwfDKsUMxHDcdkcv03NaRqYSYWQ0G67GoFhNnIDBH 3kaHeisCu3sBg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Yoshinori Sato , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-10.2.4 38/61] linux-user/sh4: restore FP rounding mode on sigreturn Date: Sat, 13 Jun 2026 23:03:21 +0300 Message-ID: <20260613200411.1808021-38-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381530726158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner The SH4 FPSCR rounding-mode (RM) and denormal (DN) bits are not held only in env->fpscr: they are also reflected into the derived env->fp_status via set_float_rounding_mode()/set_flush_to_zero(). The guest keeps the two in sync by routing every write to FPSCR through helper_ld_fpscr(). restore_sigcontext() wrote the saved value straight into env->fpscr and never touched env->fp_status, so on sigreturn the interrupted code resumed with whatever FP rounding mode and flush-to-zero setting the signal handler last installed. (regs->flags =3D 0 forces the FR/SZ/PR TB flags to be recomputed, but fp_status is runtime float state, not a TB flag, so it was left stale.) This is the FP analogue of the T/M/Q bit problem just fixed for the integer status register. Factor the FPSCR -> fp_status synchronisation out of helper_ld_fpscr() into cpu_load_fpscr() and use it from restore_sigcontext() so the rounding mode round-trips correctly across signal delivery. Fixes: c3b5bc8ab3 ("SH4: Signal handling for the user space emulator, by Ma= gnus Damm.") Cc: qemu-stable@nongnu.org Reviewed-by: Yoshinori Sato Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit a740f17ed0fbc5cd38e3cb12136c58d38aba098d) Signed-off-by: Michael Tokarev diff --git a/linux-user/sh4/signal.c b/linux-user/sh4/signal.c index cc36425c49..00290d6e40 100644 --- a/linux-user/sh4/signal.c +++ b/linux-user/sh4/signal.c @@ -173,7 +173,12 @@ static void restore_sigcontext(CPUSH4State *regs, stru= ct target_sigcontext *sc) for (i=3D0; i<16; i++) { __get_user(regs->fregs[i], &sc->sc_fpregs[i]); } - __get_user(regs->fpscr, &sc->sc_fpscr); + /* Resync the derived float_status state, not just env->fpscr. */ + { + uint32_t fpscr; + __get_user(fpscr, &sc->sc_fpscr); + cpu_load_fpscr(regs, fpscr); + } __get_user(regs->fpul, &sc->sc_fpul); =20 regs->tra =3D -1; /* disable syscall checks */ diff --git a/target/sh4/cpu.h b/target/sh4/cpu.h index b0759010c4..fbecde13a9 100644 --- a/target/sh4/cpu.h +++ b/target/sh4/cpu.h @@ -380,4 +380,7 @@ static inline void cpu_write_sr(CPUSH4State *env, uint3= 2_t sr) env->sr =3D sr & ~((1u << SR_M) | (1u << SR_Q) | (1u << SR_T)); } =20 +/* Set FPSCR and the derived float_status rounding/flush-to-zero state. */ +void cpu_load_fpscr(CPUSH4State *env, uint32_t val); + #endif /* SH4_CPU_H */ diff --git a/target/sh4/op_helper.c b/target/sh4/op_helper.c index 557b1bf497..c2854d44de 100644 --- a/target/sh4/op_helper.c +++ b/target/sh4/op_helper.c @@ -201,7 +201,7 @@ void helper_macw(CPUSH4State *env, int32_t arg0, int32_= t arg1) } } =20 -void helper_ld_fpscr(CPUSH4State *env, uint32_t val) +void cpu_load_fpscr(CPUSH4State *env, uint32_t val) { env->fpscr =3D val & FPSCR_MASK; if ((val & FPSCR_RM_MASK) =3D=3D FPSCR_RM_ZERO) { @@ -212,6 +212,11 @@ void helper_ld_fpscr(CPUSH4State *env, uint32_t val) set_flush_to_zero((val & FPSCR_DN) !=3D 0, &env->fp_status); } =20 +void helper_ld_fpscr(CPUSH4State *env, uint32_t val) +{ + cpu_load_fpscr(env, val); +} + static void update_fpscr(CPUSH4State *env, uintptr_t retaddr) { int xcpt, cause, enable; --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381353; cv=none; d=zohomail.com; s=zohoarc; b=fvLvaXWXAPU4B9aZ5ItYUzs3u694WE8/koLxr0pOB+dV7YIObxdwIGUG/DwE3gMhSBsvon96QWM3Hqj9k8Ltg15MbMQDNcI1daplPuT9CabPIiUWiWBVtp/eFeUTb2mE6OoZjcZE8/A2vUxM0+GbYlbdGRowIvu9RdQP/8ToosM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381353; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=T4PtCkcX1iaNZ8EBepvHwc5g1n+dpk3GsXbbuS8Phqg=; b=YmkQINJtVuoA0ZS2yp2fziEddGgI0OiKPCCj4PDpkkhCUjBalRlrfcVI6O2Ktqs9PIAK2L6FfVlHqJjys3+S+bNq8JazVPLWdsMZlM7EqlgOgcAsjdxFQJMsNHW0remnFEb74K6vb65D8dsr/xExAuCXhGFxoD9I66VwCHHrkzA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381353944676.0412220117358; Sat, 13 Jun 2026 13:09:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUew-0007LE-5d; Sat, 13 Jun 2026 16:08:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeH-0004op-TY; Sat, 13 Jun 2026 16:08:10 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeG-0002XF-5e; Sat, 13 Jun 2026 16:08:09 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 7F07D1B6E8F; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id DD0483CE8F1; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=KvFtXIX1HFBGkwW0GZ3bAtgD4Ty2bNFPvJplYQFqrN4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=j149CcLj79tJCZjNoYQpTV1IP1S/JYbPV7ZsIYcGXXDcWrackcbI/8AiE9yMUQY68 R/OPwYxJrAWiS/kBg41YWqgRubSPj0Tt5NuYn3/kkhf77gsO5BHXYbj56lBWGsfYhE MYeu59V7A8RU1OYuM2relVsMlamnGyM2e1q0JHYD8Ja4411lHegQn1qt2tQ2kP96+O vYsaE9WPK/8oem6LdcM6Aautg/s+cT54z5SrLNWwv1cJ131j1CyXKVrtTnRLpyr1NW LZXB79MrNqiYIo/hC4QcjlsIxTQUVlSuQJUsONlNilw47uS+HnGZOifOr++4aqGesd 1kPgoShLhS/KQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-10.2.4 39/61] linux-user/s390x: restore fpu_status rounding mode from FPC on sigreturn Date: Sat, 13 Jun 2026 23:03:22 +0300 Message-ID: <20260613200411.1808021-39-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381355947158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the s390x floating-point control register (FPC) in env->fpc. The rounding mode bits [2:0] of FPC are reflected into the derived env->fpu_status via set_float_rounding_mode(); every architectural write to FPC goes through HELPER(sfpc) which keeps the two in sync. restore_sigregs() restored FPC with a direct assignment: __get_user(env->fpc, &sc->fpregs.fpc); This wrote env->fpc correctly but never updated env->fpu_status, so on sigreturn the interrupted code resumed with whatever rounding mode the signal handler last installed in fpu_status. Factor the two-step "write fpc + sync fpu_status" logic out of HELPER(sfpc) into cpu_s390x_load_fpc(), declare it in cpu.h, and call it from restore_sigregs() in place of the direct assignment. cpu_s390x_load_fpc() partially reuses the sanity check from HELPER(sfpc): if the FPC value has an invalid rounding mode or reserved bits set, it falls back to 0, matching the kernel's fpu_lfpc_safe() behavior where a corrupt signal frame value causes a specification exception and 0 is used instead. HELPER(sfpc) now calls cpu_s390x_load_fpc() after its full specification-exception check, including the FEAT_FLOATING_POINT_EXT test that is not needed for the signal restore path. Fixes: 2941e0fa05 ("linux-user/s390x: Save/restore fpc when handling a sign= al") Cc: qemu-stable@nongnu.org Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 2762cd51ee033dccb3167110376dd125244cc819) Signed-off-by: Michael Tokarev diff --git a/linux-user/s390x/signal.c b/linux-user/s390x/signal.c index 96d1c8d11c..28ad80bde4 100644 --- a/linux-user/s390x/signal.c +++ b/linux-user/s390x/signal.c @@ -332,7 +332,11 @@ static void restore_sigregs(CPUS390XState *env, target= _sigregs *sc) for (i =3D 0; i < 16; i++) { __get_user(env->aregs[i], &sc->regs.acrs[i]); } - __get_user(env->fpc, &sc->fpregs.fpc); + { + uint32_t fpc; + __get_user(fpc, &sc->fpregs.fpc); + cpu_s390x_load_fpc(env, fpc); + } for (i =3D 0; i < 16; i++) { __get_user(*get_freg(env, i), &sc->fpregs.fprs[i]); } diff --git a/target/s390x/cpu.h b/target/s390x/cpu.h index aa931cb674..af488cda17 100644 --- a/target/s390x/cpu.h +++ b/target/s390x/cpu.h @@ -924,6 +924,7 @@ void s390_init_sigp(void); /* helper.c */ void s390_cpu_set_psw(CPUS390XState *env, uint64_t mask, uint64_t addr); uint64_t s390_cpu_get_psw_mask(CPUS390XState *env); +void cpu_s390x_load_fpc(CPUS390XState *env, uint32_t fpc); =20 /* outside of target/s390x/ */ S390CPU *s390_cpu_addr2state(uint16_t cpu_addr); diff --git a/target/s390x/tcg/fpu_helper.c b/target/s390x/tcg/fpu_helper.c index 1ba43715ac..83aa88a754 100644 --- a/target/s390x/tcg/fpu_helper.c +++ b/target/s390x/tcg/fpu_helper.c @@ -896,6 +896,19 @@ static const int fpc_to_rnd[8] =3D { float_round_to_odd, }; =20 +void cpu_s390x_load_fpc(CPUS390XState *env, uint32_t fpc) +{ + /* + * Mimic kernel fpu_lfpc_safe(): a corrupt signal frame value that wou= ld + * trigger a specification exception instead results in FPC being set = to 0. + */ + if (fpc_to_rnd[fpc & 0x7] =3D=3D -1 || fpc & 0x03030088u) { + fpc =3D 0; + } + env->fpc =3D fpc; + set_float_rounding_mode(fpc_to_rnd[fpc & 0x7], &env->fpu_status); +} + /* set fpc */ void HELPER(sfpc)(CPUS390XState *env, uint64_t fpc) { @@ -903,12 +916,7 @@ void HELPER(sfpc)(CPUS390XState *env, uint64_t fpc) (!s390_has_feat(S390_FEAT_FLOATING_POINT_EXT) && fpc & 0x4)) { tcg_s390_program_interrupt(env, PGM_SPECIFICATION, GETPC()); } - - /* Install everything in the main FPC. */ - env->fpc =3D fpc; - - /* Install the rounding mode in the shadow fpu_status. */ - set_float_rounding_mode(fpc_to_rnd[fpc & 0x7], &env->fpu_status); + cpu_s390x_load_fpc(env, fpc); } =20 /* set fpc and signal */ --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381405; cv=none; d=zohomail.com; s=zohoarc; b=X199CTaKhgrZCoxC0WIDQvOzUZOSpyawkjdWvC9iqkexDvHD+3p02AfNo02iDqqamVtmiU6iyO3lfL989mGemKEK3FhKQ+VVYRmDk+Bp0J+O12ctnbsWKnz4uQU9rNfvb0o3tp2Kj8gdzo8fDg6hxABY8QehUWvNlmRuQbbhldc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381405; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hWwzS5j0eowTMpD6czSSfTyPe+Zb1l6DaLezlNUwiZc=; b=BBxgpZJjHp1y5Q8rNz/BuWnNn76dZl4yKOCjJ29We9YgGZdbdZGESx9TuhtZHdmEXe6Q43N1aDsFztt9w3sg/+65chs5wWkZ6QM48KStNj/3FzKR5OTsg2ooWMomu4OAe8LkmNLT1+0WepITJkZ07ZDD4ZkrEglKE6TkPGnDePs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381405285842.5923428704273; Sat, 13 Jun 2026 13:10:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUem-0005yy-C5; Sat, 13 Jun 2026 16:08:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeK-0004sh-Of; Sat, 13 Jun 2026 16:08:14 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeH-0002Xo-VU; Sat, 13 Jun 2026 16:08:11 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 987991B6E90; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id EC9123CE8F2; Sat, 13 Jun 2026 23:04:47 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=1vIekq1HxXQBcqCH3DQsHnz/vvWv4fnrf8UFSt91mhQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=AqyO2hYbdKZN9zSfQPPFqJMkaMMsX3s7GR5VlSP8iRuDz6Ky8NLxC6Wd9ky6mCOz/ 3Qsh66t2hsdpJJOAFnW0SJek3SxCVrpnYbxeo4PbpnX3JeZy/hIw9TEY9DPm9kkuNj 3raEZGRLMMYP95TePfBDVJRNd3kaAW8re/np7aPNjy4g7SMJwt9sUiypBZIcYV0a1W wMXw1tDvv8vU4mQxVzg2dI+Wm1NRIYafVFMqvK2Yjh5oYD85RT4TfOiFYI4z/D49G0 ttyqtdXgnrKJZ/iW6fVlvPBvzWIB5zKYNmM5tbS9jxVQr2BLhwujCXenHGbE8xD9du QxN5d0Fu0VtCQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.2.4 40/61] hw/9pfs: add NULL check in v9fs_path_is_ancestor() Date: Sat, 13 Jun 2026 23:03:23 +0300 Message-ID: <20260613200411.1808021-40-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381406073158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add NULL check for s1->data and s2->data before using them in string operations. This prevents potential crashes when dealing with uninitialized paths. This is just a defensive measure. We are currently never passing NULL to this function. Link: https://lore.kernel.org/qemu-devel/3348c4d683f061c23083bd45994d527be4= fb7cbc.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit abb0cc02fb56e2432837e34b80fe68768f95e774) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 9062a064fb..6ee1c08d0a 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -241,6 +241,9 @@ int v9fs_name_to_path(V9fsState *s, V9fsPath *dirpath, */ static int v9fs_path_is_ancestor(V9fsPath *s1, V9fsPath *s2) { + if (!s1->data || !s2->data) { + return 0; + } if (!strncmp(s1->data, s2->data, s1->size - 1)) { if (s2->data[s1->size - 1] =3D=3D '\0' || s2->data[s1->size - 1] = =3D=3D '/') { return 1; --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381405; cv=none; d=zohomail.com; s=zohoarc; b=Tx/IItVDQE2BQY+xWQs9JKPaL9HjvqLvcT1m7XL2dcSAIRnixPh77YBoitFrq2veWyKdf2cmIxkbfbPimt2IgjRWUmRXKdFH3VhTyD5dYHf1ESSTzQf8wA8rD8/lQGNM3E9lW3uZwRqjCnGqwVnQfyjzOPDEsWKGHuzM8EfWNkQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381405; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=66TALB242GSSz+cr1rEVeTpJKqi/eF4c8LqY91A3ekU=; b=A9LMElAwWGXrRySd9jkrLPhryhic5FxivlCiem4U90YrFquUJ9TSvomeY5rnGC5ZuWkUkOds8j+nmUCqLwyJ08cJqK39hHxc3RIrEmTm7kuYUsCLVY1QnMesg5lSxQFncXinNx4+bhJJRABLS1LAJJLwwl+QqansAQugEUNJFqI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381405164717.3624382924716; Sat, 13 Jun 2026 13:10:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUej-0005WM-OJ; Sat, 13 Jun 2026 16:08:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeM-0004vp-Hl; Sat, 13 Jun 2026 16:08:16 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeK-0002YG-QU; Sat, 13 Jun 2026 16:08:14 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A69371B6E92; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 116E03CE8F3; Sat, 13 Jun 2026 23:04:48 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=ucz4V6JP5lRfknuxDlu60gNWuS3zMx4gsfF/yjL0abs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=vuwDiG4uD8Msw62X3hXADzQdhZYc/Miu4/o628EhA59weXcPgpGSZ7j6iYpHRyaJA hQFcjZfsFr2u1oOzqq+YGj67BdqHOr2m4gZtEOCkMbANWIatxH5eEuAhS3st5+gFsH O50p9AolYdIBizyupjSHm+At0xaGCag4GbeV/Zkw/4wgNxtIXiN+ob/REt4TeGECcW R1HvWTjqTELk32Tc3agAicUgNVtbZpqCxvkp4gglR0UjLEW4eZ3zhXi3QDgx3jrDaO VLFJEwfhMN1fc+BossaO6K2nedFFh3f9Y4OQGCgtToWzvuIUblarku8WEF833Hj7Sf 2F6dsNpyNUTEQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.2.4 41/61] hw/9pfs: change V9fsPath.size to size_t and v9fs_path_sprintf() return type Date: Sat, 13 Jun 2026 23:03:24 +0300 Message-ID: <20260613200411.1808021-41-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381406099158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck - Change V9fsPath.size from uint16_t to size_t to support paths larger than 65536 bytes. - Change v9fs_path_sprintf() return type from void to int to allow error reporting. Link: https://lore.kernel.org/qemu-devel/2d2348d94ff43fbe4cc0aea24fb312c5c1= 5ee809.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit dbaf84e148b0c8b66dcb47788a6bb13806e401e4) Signed-off-by: Michael Tokarev diff --git a/fsdev/file-op-9p.h b/fsdev/file-op-9p.h index b85c9934de..e8d0661c4b 100644 --- a/fsdev/file-op-9p.h +++ b/fsdev/file-op-9p.h @@ -112,7 +112,7 @@ struct FsContext { }; =20 struct V9fsPath { - uint16_t size; + size_t size; char *data; }; P9ARRAY_DECLARE_TYPE(V9fsPath); diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 6ee1c08d0a..ec493f74a8 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -203,16 +203,24 @@ void v9fs_path_free(V9fsPath *path) } =20 =20 -void v9fs_path_sprintf(V9fsPath *path, const char *fmt, ...) +int v9fs_path_sprintf(V9fsPath *path, const char *fmt, ...) { va_list ap; + int ret; =20 v9fs_path_free(path); =20 va_start(ap, fmt); - /* Bump the size for including terminating NULL */ - path->size =3D g_vasprintf(&path->data, fmt, ap) + 1; + ret =3D g_vasprintf(&path->data, fmt, ap); va_end(ap); + if (ret < 0) { + error_report_once("9pfs: unusual path formatting failure; " + "invalidating associated FID"); + return -1; + } + /* Bump the size for including terminating NULL */ + path->size =3D ret + 1; + return 0; } =20 void v9fs_path_copy(V9fsPath *dst, const V9fsPath *src) diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index 65cc45e344..b2df659b0e 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -456,8 +456,8 @@ static inline uint8_t v9fs_request_cancelled(V9fsPDU *p= du) void coroutine_fn v9fs_reclaim_fd(V9fsPDU *pdu); void v9fs_path_init(V9fsPath *path); void v9fs_path_free(V9fsPath *path); -void G_GNUC_PRINTF(2, 3) v9fs_path_sprintf(V9fsPath *path, const char *fmt, - ...); +int G_GNUC_PRINTF(2, 3) v9fs_path_sprintf(V9fsPath *path, const char *fmt, + ...); void v9fs_path_copy(V9fsPath *dst, const V9fsPath *src); size_t v9fs_readdir_response_size(V9fsString *name); int v9fs_name_to_path(V9fsState *s, V9fsPath *dirpath, --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381590; cv=none; d=zohomail.com; s=zohoarc; b=Y2n/kC6LMs0e/W5bvPllymMeDK2vax/zFxrPCyiWTfZafiT/BZIAM42Yunpkt4T/BdcHBMwjKQO4wJ/cm4QAfEbJm1f3nDhCDuXbDcoOtzxPEiyTPkOU7NpQNLcxEaFmL50LqkZpXlzyTJBsPsb14BFvl/gqJRZg6us2NYPgJCs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381590; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=xhFPi6xjJt+W9h/rZ7/OxNzD0axUDd7afZnfYr+8zdI=; b=RTId6Q81HPu5gfHenTrxdB+b3tuN812u63B+gDi4GwhOe6gzuXCQP8K6YUXzUYykM9AD7uwjg8W6MaNSvKYNKRtiXbqGzffYuvbrgJ48zoVYKukINU++MBdtux1DGGbqRc9lJC5z731Gnm6kKgHBcum7EW970lsUcegGmCGpPZM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381590656916.1567765665334; Sat, 13 Jun 2026 13:13:10 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUen-00066Y-1v; Sat, 13 Jun 2026 16:08:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUei-0005Kn-G4; Sat, 13 Jun 2026 16:08:36 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeg-0002Yx-Id; Sat, 13 Jun 2026 16:08:36 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BD6641B6E94; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1F0F73CE8F4; Sat, 13 Jun 2026 23:04:48 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=GuFVx0cmuNzha1cFRS6vzUxrjZMJrsQl4zqv0yrBrKQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=lCrbLIo/uPUwpH3KTbTGeEDGeGcE2Dm3CjP9kt+igM1PyCUjwdIoQZ/XG+TAbzj+X j2YWzH7wlAIhJGzwFWIsCzaPSMCBkrFB7RkRz77DYV6LPeIOIX1W55QsROaQyFoL31 afwh9ATaEePEW4GtvPhHzMpot+PTstmARc/bz9Z1/Sp/ZBBAhlFL8jLWik/Y0ZooKa RQaRF3hiongvlEfQNKAiEGtsbJ/4TrgA3xmVN22syaVOAZiaag7oRlRqYuwGPgIqk1 H5+/Vp1MpJeJLp2ZVN6m1uOzrxQT6gqSjTEQt2ue0/GjSCH1Dve1pnuCU4wVeN1BuX xIcImXTAS1IRQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.2.4 42/61] hw/9pfs: add error handling to v9fs_fix_path() Date: Sat, 13 Jun 2026 23:03:25 +0300 Message-ID: <20260613200411.1808021-42-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381590765158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Update v9fs_fix_path() to return int and propagate errors from v9fs_path_sprintf(). This allows callers to detect and handle path formatting failures. Link: https://lore.kernel.org/qemu-devel/a0592741a918b7cbe751980ec7ec0c03f5= 05924c.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 54dd352c59269fdb5241e7b6dbcecaff107e7f5a) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index ec493f74a8..0800ac12a4 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -1417,13 +1417,15 @@ static void print_sg(struct iovec *sg, int cnt) } =20 /* Will call this only for path name based fid */ -static void v9fs_fix_path(V9fsPath *dst, V9fsPath *src, int len) +static int v9fs_fix_path(V9fsPath *dst, V9fsPath *src, int len) { V9fsPath str; + int ret; v9fs_path_init(&str); v9fs_path_copy(&str, dst); - v9fs_path_sprintf(dst, "%s%s", src->data, str.data + len); + ret =3D v9fs_path_sprintf(dst, "%s%s", src->data, str.data + len); v9fs_path_free(&str); + return ret; } =20 static inline bool is_ro_export(FsContext *ctx) --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381524; cv=none; d=zohomail.com; s=zohoarc; b=T44YpFDAyF79yT54v7jqdhKENLpWB1972CjbrMbMgrnPNz8A2u4KqSwFr5iuY9rCwMxTAwVm1vGNJEvWQMGlY1QcqxsxP3RKov2h6ZmxGegcLuV24xyBzlyHmLLiafUkiPsSuZqldIXyT1HOoq68G0TvesABV35XcdqDNqeUpzs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381524; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=d/ru6WPdH42/MOHp7OkQnJ1k6Rx7heh2ikz4XOMgdMc=; b=iN71V/4O8G+Qg0YAciTC7dxxoazJfP4w3Z8frh8bmM2Zr+sVfrm4H/7BFmpWjQACaIGyca+eREw2k+w/wPzoJYhORSy/fH6b7m7Z8lRK43z8KH8v9QQcp+ZjBIqcCiTqyCx85i4HBJ/enRCsmnHZnQv5LHVjApqFcVeBtoOpw50= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381524216169.07117124232002; Sat, 13 Jun 2026 13:12:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUf1-0007xT-LS; Sat, 13 Jun 2026 16:08:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUek-0005m1-MK; Sat, 13 Jun 2026 16:08:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUei-0002Zr-E2; Sat, 13 Jun 2026 16:08:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id CC8881B6E96; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 36F0F3CE8F5; Sat, 13 Jun 2026 23:04:48 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=cXaYsvnmzHqt768d4b00L4/YFji6YTxatS8VuLdNPGU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=AX1g3Atxp+Wcsa4aBuPP/assqRWlYWMjgn2iRuWDQMYXUd0UKn/53JDkTv563mYm2 gOJpGPANAGgjeG79I4Se1mPggO20UnQbxbMrczFS6YwpgAfz2LdK7E3IZ/RqnIkMy4 ShlwZOqGMCcM38yjNaEs5igmbtbd5dkTU9qTlbOYoq7pRWqhxLHSRFLig2FZ59NKIz bq2Ekjafv8tRwL48LwPdwa7Wl85UvM+wIhbkrp1AP2O2WpKUuRZ06Hl9igMx4Y7X0F s13/Yt/pyzrTDzfESVyPVUjZJNrXdpevBQj4BeoCZ8wf0Ig7AanB/aAzWPNTcHNwz4 sUk824tpjLlxQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Wang Jihe , Michael Tokarev Subject: [Stable-10.2.4 43/61] hw/9pfs: let callers of v9fs_path_sprintf() and v9fs_fix_path() handle errors Date: Sat, 13 Jun 2026 23:03:26 +0300 Message-ID: <20260613200411.1808021-43-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381524618158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck This patch mitigates issues with very large absolute paths. - Add error handling to all v9fs_path_sprintf() calls in local_name_to_path() - Update callers of v9fs_fix_path() to check return values. - When path formatting fails, clunk the affected FIDs to prevent use of invalid paths. - Use g_autofree for temporary variables to simplify code. Even though paths are usually limited to PATH_MAX (typically 4k) on guest, this limitation can be circumvented by using *at() functions on guest and creating very deep directory structures. This was a problem for QEMU 9p server, as it currently tracks the absolute path for each FID internally that always requires assembly of a (potentially ver large) absolute path. A true long-term fix would be getting rid of storing an absolute path for each FID internally. However that would likely be a massive change with uncertain implications. This patch therefore just mitigates the problem by immediately clunking (i.e. closing) all FIDs whose path exceed a limit that we could handle. As this only accounts to very unusual large absolute paths not ever been reported on (sane) production machines, this is currently considered an acceptable mitigation that should only (counter)affect malicious attempts. Fixes: 2f008a8c97e2 ("hw/9pfs: Use the correct signed type ...") Reported-by: Wang Jihe Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3358 Link: https://lore.kernel.org/qemu-devel/1d11dcbfc95b811dcdb48c6d7f3894d0eb= d073a2.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 3802c0e755a53b126e717415b54226a468bf7ddf) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p-local.c b/hw/9pfs/9p-local.c index 31e216227c..d7aeaededc 100644 --- a/hw/9pfs/9p-local.c +++ b/hw/9pfs/9p-local.c @@ -1256,26 +1256,35 @@ static int local_name_to_path(FsContext *ctx, V9fsP= ath *dir_path, } else if (!strcmp(name, "..")) { if (!strcmp(dir_path->data, ".")) { /* ".." relative to the root is "." */ - v9fs_path_sprintf(target, "."); + if (v9fs_path_sprintf(target, ".") < 0) { + return -1; + } } else { - char *tmp =3D g_path_get_dirname(dir_path->data); + g_autofree char *tmp =3D g_path_get_dirname(dir_path->data= ); /* Symbolic links are resolved by the client. We can assume * that ".." relative to "foo/bar" is equivalent to "foo" */ - v9fs_path_sprintf(target, "%s", tmp); - g_free(tmp); + if (v9fs_path_sprintf(target, "%s", tmp) < 0) { + return -1; + } } } else { assert(!strchr(name, '/')); - v9fs_path_sprintf(target, "%s/%s", dir_path->data, name); + if (v9fs_path_sprintf(target, "%s/%s", dir_path->data, name) <= 0) { + return -1; + } } } else if (!strcmp(name, "/") || !strcmp(name, ".") || !strcmp(name, "..")) { /* This is the root fid */ - v9fs_path_sprintf(target, "."); + if (v9fs_path_sprintf(target, ".") < 0) { + return -1; + } } else { assert(!strchr(name, '/')); - v9fs_path_sprintf(target, "./%s", name); + if (v9fs_path_sprintf(target, "./%s", name) < 0) { + return -1; + } } return 0; } diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 0800ac12a4..0c162614f8 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -3325,12 +3325,14 @@ static int coroutine_fn v9fs_complete_rename(V9fsPD= U *pdu, V9fsFidState *fidp, goto out; } } else { - char *dir_name =3D g_path_get_dirname(fidp->path.data); + g_autofree char *dir_name =3D g_path_get_dirname(fidp->path.data); V9fsPath dir_path; =20 v9fs_path_init(&dir_path); - v9fs_path_sprintf(&dir_path, "%s", dir_name); - g_free(dir_name); + err =3D v9fs_path_sprintf(&dir_path, "%s", dir_name); + if (err < 0) { + goto out; + } =20 err =3D v9fs_co_name_to_path(pdu, &dir_path, name->data, &new_path= ); v9fs_path_free(&dir_path); @@ -3351,7 +3353,10 @@ static int coroutine_fn v9fs_complete_rename(V9fsPDU= *pdu, V9fsFidState *fidp, while (g_hash_table_iter_next(&iter, &fid, (gpointer *) &tfidp)) { if (v9fs_path_is_ancestor(&fidp->path, &tfidp->path)) { /* replace the name */ - v9fs_fix_path(&tfidp->path, &new_path, strlen(fidp->path.data)= ); + if (v9fs_fix_path(&tfidp->path, &new_path, + strlen(fidp->path.data)) < 0) { + clunk_fid(s, tfidp->fid); + } } } out: @@ -3448,7 +3453,10 @@ static int coroutine_fn v9fs_fix_fid_paths(V9fsPDU *= pdu, V9fsPath *olddir, while (g_hash_table_iter_next(&iter, &fid, (gpointer *) &tfidp)) { if (v9fs_path_is_ancestor(&oldpath, &tfidp->path)) { /* replace the name */ - v9fs_fix_path(&tfidp->path, &newpath, strlen(oldpath.data)); + if (v9fs_fix_path(&tfidp->path, &newpath, + strlen(oldpath.data)) < 0) { + clunk_fid(s, tfidp->fid); + } } } out: --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381529; cv=none; d=zohomail.com; s=zohoarc; b=mdl61afQR0OO3kjAlmU+Cg01DQVPcAB0QJnzIiZH17x30dplSKt1R/gufo4JR2oYOoIarPNOgoIbZ9lnxTptpGBKtxNiC53EwbXKyX7GBRRldcf3hmtkphM7MsSh1R9H5B9S1O2XhQ/oZsOmxrnpDVHqNjJjJpHBzWEYdCniQiQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381529; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=deZHwNN5WIR4JTV2uTez3iP2bU6EN9kjhA9tphGZpPs=; b=jHiGc+iZ6NCWOBqb9H2LC1aAkl8MKBf49407rakjuRaHf0KyJ95KiSXNt1XGIGCp6r7rSp2LmeaaxC0zKOn2o37TCmfh2SgOedgsaklnS0XB9uDE2MFijYTV13c1Mh0GG67DclZACP9i3Y25MuivU5m7cwNAHaZZUCjosmdruVQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381529478821.9298419045521; Sat, 13 Jun 2026 13:12:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUf3-0008Fa-5C; Sat, 13 Jun 2026 16:08:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUem-00062S-C2; Sat, 13 Jun 2026 16:08:40 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUek-0002dM-A9; Sat, 13 Jun 2026 16:08:39 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id DBF6C1B6E98; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 454743CE8F6; Sat, 13 Jun 2026 23:04:48 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=y7G/QIRnRsuPk7/oRZJGZMI9BKG1yQA33e2zndC2EKs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=j+uPUeeIo8DKB05x5n/I5ztAX0/EIpvaAipRgQOar9ybeQa4IvTM4kfDqqoSRGk/y rsH2ha+36xFkt81vywvSVth4TssLrWreg5ETwOQg5QIwamyW+T7nzJ95nzDIpoJll+ B16wackGtKVh++njpmTuMrWqXrTn2AYma9leHrDV/tks46knZZ9Q/deO1GLP47EFBW AAO3O9CwKupz4epF5pyvbuEYETo4xLSxexpHV3OzQu0QCjtXzSwtfVzBBx5gzU+dKj szcnm8cpOGKTSprZd0EXeAbCLoZfvCnJsQCrIA43NxNq2SMFq1R6/ICekLjgr2u5dL SBhxSUTRdavdQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Fabiano Rosas , Michael Tokarev Subject: [Stable-10.2.4 44/61] tests/qtest/libqos: add qvirtqueue_reset_pool() for descriptor pool reset Date: Sat, 13 Jun 2026 23:03:27 +0300 Message-ID: <20260613200411.1808021-44-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381530577158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add a function to reset the virtqueue descriptor pool state without reinitializing the device. This is useful for tests that issue a high number of requests and are limited by the simplified virtio test driver's descriptor tracking, which decrements num_free but never increments it back. The function is safe for synchronous test code where requests are sent and completed before the next request is issued. Acked-by: Fabiano Rosas Link: https://lore.kernel.org/qemu-devel/96cf23eea1204b34443218fe76bd4a5eaf= 9163e8.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit be33c56898f8b18617cff91525f0b68abee8de07) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/libqos/virtio.c b/tests/qtest/libqos/virtio.c index 010ff40834..ccbb325222 100644 --- a/tests/qtest/libqos/virtio.c +++ b/tests/qtest/libqos/virtio.c @@ -464,6 +464,29 @@ bool qvirtqueue_get_buf(QTestState *qts, QVirtQueue *v= q, uint32_t *desc_idx, return true; } =20 +/* + * qvirtqueue_reset_pool: + * @vq: The virtqueue to reset + * + * Reset the descriptor pool state without reinitializing the device. + * This is useful for tests that issue a high number of requests and + * are limited by the simplified virtio test driver's descriptor tracking, + * which decrements num_free but never increments it back. + * + * This is only safe for synchronous test code where requests are + * sent and completed before the next request is issued. Do not use + * with asynchronous code where multiple requests may be in-flight. + * + * Note: This only resets the available descriptor pool (free_head, + * num_free). The used ring position (last_used_idx) is NOT reset + * and should continue to track consumed responses across iterations. + */ +void qvirtqueue_reset_pool(QVirtQueue *vq) +{ + vq->free_head =3D 0; + vq->num_free =3D vq->size; +} + void qvirtqueue_set_used_event(QTestState *qts, QVirtQueue *vq, uint16_t i= dx) { g_assert(vq->event); diff --git a/tests/qtest/libqos/virtio.h b/tests/qtest/libqos/virtio.h index e238f1726f..f17be0b9b6 100644 --- a/tests/qtest/libqos/virtio.h +++ b/tests/qtest/libqos/virtio.h @@ -150,6 +150,8 @@ void qvirtqueue_kick(QTestState *qts, QVirtioDevice *d,= QVirtQueue *vq, bool qvirtqueue_get_buf(QTestState *qts, QVirtQueue *vq, uint32_t *desc_id= x, uint32_t *len); =20 +void qvirtqueue_reset_pool(QVirtQueue *vq); + void qvirtqueue_set_used_event(QTestState *qts, QVirtQueue *vq, uint16_t i= dx); =20 void qvirtio_start_device(QVirtioDevice *vdev); --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381396; cv=none; d=zohomail.com; s=zohoarc; b=g7PSTid0VK3pzQxbBjRpW3wIvSCiDuEq4tuF4wA9oaf66Uz1VexTip/x3Q8DhLpd/jszp2MUvRu104P2Jh/Et28ZicLQolNP+7nHMg/89U087WAT5vhZtF+o1oy7pUardpWaFDPW+zE5TSn8Lv2YIP5MBmwv9IgoNKWQ8y+fln4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381396; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=nFx5ll5IjzEhD464BUHRMl4++7Dr6szIvCcYB7TYdsA=; b=SGZVKZ8VrhAIekdte26q+0zZxZslh/OvIbpc/3TMy3OfxobHGeytaH2jRTR9P46KfIJocda/rqzwU8KJq4seEdVVvLmAGYCXL2ZUDlxS6XgowZzmN9xMzzYje+quRDx4FaKvkZ2sBY9vx1arZvyivWpzFf8UQn4xv0cSdNM6BTg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381396391247.18556075976528; Sat, 13 Jun 2026 13:09:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUer-0006mq-Jl; Sat, 13 Jun 2026 16:08:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeo-0006RI-Ka; Sat, 13 Jun 2026 16:08:42 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUem-0002e8-Fz; Sat, 13 Jun 2026 16:08:42 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E86B01B6E9A; Sat, 13 Jun 2026 23:04:29 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 546703CE8F7; Sat, 13 Jun 2026 23:04:48 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381069; bh=sq3wfnIuv+1QgSiiJ3QDn+46DBYkyT99RJCkygeD7uc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=pI73XJkUcpy49pzSwoZMtirRrzaCF8kNul2P7eEwDkET+axdB/q1XeADsj9TEv3uM J1c7eE7WRwd9YzgtdU+Oot3/27Xk2QbwY+OhkzclRc7eFv6DsJk+9Cweyy2GCDjTur /la9+Z2/ABC2CRP0eTrYtuGHB7yJEAOs4BU/xtJ1zp9+hex0UYAiqLZrQw/ZKpOgde m9l+GV3R801vPQNZ4/3u0rELHWha8im1lxGW+5YWcAkc/WHEe7brZZvCajeB2lGnJl q6O6UmGIwV5tNmb9NPkiTPx3ShNfGQcN4oq6FvRnQL6HCcSn1rjlx3Hr7TSwu1uoy9 Q6Mx02Vf9tpow== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.2.4 45/61] tests/9pfs: add deep absolute path test Date: Sat, 13 Jun 2026 23:03:28 +0300 Message-ID: <20260613200411.1808021-45-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381398317158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add fs_deep_absolute_path test that creates a deep directory structure with an absolute path length exceeding 16-bit range (i.e. >65536) to verify the previous buffer overflow fix. This is a slow test (may take several seconds) and therefore registered as "slow" test and not running by default. Use -m slow to run this test. Link: https://gitlab.com/qemu-project/qemu/-/issues/3358 Link: https://lore.kernel.org/qemu-devel/933552b2cfc2c442fac7f4e68c777dce20= ee8d7e.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 198627807a6b94e2aab157cf345f98edb1ac1a7a) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index ac38ccf595..1c69d41e33 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -14,6 +14,7 @@ =20 #include "qemu/osdep.h" #include "qemu/module.h" +#include "libqos/virtio.h" #include "libqos/virtio-9p-client.h" =20 #define twalk(...) v9fs_twalk((TWalkOpt) __VA_ARGS__) @@ -752,6 +753,72 @@ static void fs_use_after_unlink(void *obj, void *data, g_assert_cmpint(attr.size, =3D=3D, 2001); } =20 +/* https://gitlab.com/qemu-project/qemu/-/issues/3358 */ +static void fs_deep_absolute_path(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + QVirtio9P *v9p =3D obj; + v9fs_set_allocator(t_alloc); + + if (!g_test_slow()) { + g_test_skip("This is a slow test, run with -m slow"); + return; + } + + GString *path =3D g_string_new("/"); + char name[256]; + uint32_t current_fid =3D 0; + + tattach({ .client =3D v9p }); + + /* Create deep directory structure until absolute path length + * exceeds 16-bit range. + */ + while (path->len <=3D 65536) { + /* use 255-byte name (NAME_MAX) to reduce iterations to ~257 */ + memset(name, 'A', 255); + name[255] =3D '\0'; + + /* create the directory relative to current FID */ + tmkdir({ + .client =3D v9p, + .dfid =3D current_fid, + .name =3D name + }); + + /* just for locally tracking the current path length */ + g_string_append(path, name); + g_string_append(path, "/"); + + /* acquire new FID for the newly created directory */ + char *wnames[] =3D { name }; + current_fid =3D twalk({ + .client =3D v9p, + .fid =3D current_fid, + .nwname =3D 1, + .wnames =3D wnames + }).newfid; + + /* Reset descriptor pool to avoid exhaustion. The simplified + * virtio test driver does never free descriptors back to the pool + * after use, so we must manually reset it for the required high + * amount of 9p requests here. + */ + qvirtqueue_reset_pool(v9p->vq); + } + + /* check if the deepest directory is accessible */ + v9fs_attr attr =3D {}; + tgetattr({ + .client =3D v9p, + .fid =3D current_fid, + .request_mask =3D P9_GETATTR_BASIC, + .rgetattr.attr =3D &attr + }); + + g_string_free(path, TRUE); +} + static void cleanup_9p_local_driver(void *data) { /* remove previously created test dir when test is completed */ @@ -819,6 +886,8 @@ static void register_virtio_9p_test(void) &opts); qos_add_test("local/use_after_unlink", "virtio-9p", fs_use_after_unlin= k, &opts); + qos_add_test("local/deep_absolute_path", "virtio-9p", + fs_deep_absolute_path, &opts); } =20 libqos_init(register_virtio_9p_test); --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381396; cv=none; d=zohomail.com; s=zohoarc; b=NdAyuIM7VDr/allUah0QRQ1JrGufNfn1tMoVtFSnsycWokciBeVAEwIsT+ttwbgT+A+8HP0nMPPW7k2DReIBsOIYbTVyTJnhTZSFUuldYMFv5i0/n/zAGWdPsmaPhRMQ15b+QtqyRtSiJaxnJlLT26paRhps4i606/s2H44U1eE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381396; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=QexvaD/MiGmJTC9cP/EjJxH5JoDHVk3sdWXGWFlh3Lk=; b=icCmCstMEzDEX15/YOgdjFflu+YKhj3KQDDGiIEwP5ejmuJ3MnsPCECabommCvy5l45RK3aU032sKSoQx3bKS1NIsfpsKalAgweN3cmqB+3r6EwpLqCwMEsLB9bTNvFWV8cf5QstzY527Fb2hNByGHprTsJPG8s4mw35+SaPQfg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381396800963.8128370859232; Sat, 13 Jun 2026 13:09:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUf6-0000Mv-LS; Sat, 13 Jun 2026 16:09:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeq-0006aY-3m; Sat, 13 Jun 2026 16:08:44 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUeo-0002ei-2L; Sat, 13 Jun 2026 16:08:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 033161B6E9C; Sat, 13 Jun 2026 23:04:30 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 617F53CE8F8; Sat, 13 Jun 2026 23:04:48 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381070; bh=ubdO+zpxQThsSC68lkwISaMv3bI5tKubzpj/X8KopDg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=GPOlGnl82gQUKRVcxdGUJuM3RB712979N+yEd/UACA67ufPO9Vc0wAyQ9vkgjzcrS KmaoZsrqmN/UQpyc60lMtSzS4R7EsA9DZkihBX1WwRg73f8W1mL1/uhRjI/dVM4i3P D8h5QTNHqXMv1DQWKTpvQSZR1vrf9BM3F4c6R0gSFj/2Bl4YDSsj6+4E2FAASyTGcy KxZ2/dVkhET/dZDN0hK+K5CiwsgEgBSz4DuXHnVIuGC3blMbQJB9hP5SJrFe+etUnh usRbtgBKdqrwlXu05vj/k70Sgcuxl7+b7hUX9uk53zINTCuOgS6r2Gi+ngeDhtyzAA ClwXzGTxleL2w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, sin99xx , Christian Schoenebeck , Michael Tokarev Subject: [Stable-10.2.4 46/61] 9pfs: fix missing rename lock in v9fs_co_readdir_many (CVE-2026-48004) Date: Sat, 13 Jun 2026 23:03:29 +0300 Message-ID: <20260613200411.1808021-46-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381398368158500 Content-Type: text/plain; charset="utf-8" From: sin99xx v9fs_co_readdir_many() dispatches do_readdir_many() to a worker thread that reads V9fsFidState's path.data without holding a rename lock. A concurrent rename request, e.g. of its parent dir, causes the FID's absolute path to be altered by freeing the old path string and assigning a new one. This causes a heap-use-after-free race condition while do_readdir_many() is still accessing the old object. This allows a DoS by an unprivileged guest user. Fix this by wrapping the worker thread dispatch block within a pair of v9fs_path_read_lock() and v9fs_path_unlock() calls, like it's done at other places. Fixes: 2149675b195f ("9pfs: add new function v9fs_co_readdir_many()") Fixes: CVE-2026-48004 Reported-by: sin99xx Signed-off-by: sin99xx [Christian Schoenebeck: add commit log message] Link: https://lore.kernel.org/qemu-devel/E1wPkYi-000adH-4E@kylie.crudebyte.= com Signed-off-by: Christian Schoenebeck (cherry picked from commit 5a8da7e979f1f56b1cab82c2354833f309f1a78f) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/codir.c b/hw/9pfs/codir.c index bce7dd96e9..5568399343 100644 --- a/hw/9pfs/codir.c +++ b/hw/9pfs/codir.c @@ -220,13 +220,16 @@ int coroutine_fn v9fs_co_readdir_many(V9fsPDU *pdu, V= 9fsFidState *fidp, bool dostat) { int err =3D 0; + V9fsState *s =3D pdu->s; =20 if (v9fs_request_cancelled(pdu)) { return -EINTR; } + v9fs_path_read_lock(s); v9fs_co_run_in_worker({ err =3D do_readdir_many(pdu, fidp, entries, offset, maxsize, dosta= t); }); + v9fs_path_unlock(s); return err; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381544; cv=none; d=zohomail.com; s=zohoarc; b=K+NsuLK6f0j9UYkXg6mgrAGkT+Dd9xwBbW6L9I8DWcxEIDfyxoNY3NEHKKBOp/4k+9kMI+8WGAbL67YitbHNjPPl6ZXvm3yYHrdft8a8YGvFV+JAEGCHwl2djqnk1rHAMBS2RlLCj5+HgX9QeWnCHTNqx6vYSmBnAkpOOCoFPgQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381544; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lEIED/Wc9tzJFjCP7matfedwXpt/sEA5sQFT6daDr6M=; b=lnoQ7pCo/+WXJkXqJTgUxKpWIwuc0p09AiLGWBuMTb5VpqOjZKrgI4ndzLY1Te1QuD5vBjcbr6xRfztp/IwIqbsKvN25I9hwZFEw1nEgvIbJSoWD6UJV+WoQBpMg8w/pcMv5oV4wKpxSd5EkGmbH7bnl5pZhK7FPc/ICjtOFOqg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138154453671.68997366302119; Sat, 13 Jun 2026 13:12:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUfD-0001BS-Qg; Sat, 13 Jun 2026 16:09:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfC-000132-AE; Sat, 13 Jun 2026 16:09:06 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfA-0002fT-Bb; Sat, 13 Jun 2026 16:09:05 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 15A431B6E9E; Sat, 13 Jun 2026 23:04:30 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 709643CE8F9; Sat, 13 Jun 2026 23:04:48 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381070; bh=L7RCWWMvQS+EFrMDUd1cQg3OODBBHJtF30sWO9d+Tds=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=fmtwGglstGdK5RGk/ZP0Xqai5IZx1EbS4EHhsSQg5j7WmDO+KVrG+r2D4x0bRHljl xnbYXvmn4E3w6JORhTq2joBuVGFaGys6f256rr8yGoBQd8jgO/lhYkhKzxjJm/9P0K hLa70rttf8GGy2haTmdk7WQQGfmXmrF9p+XkTYfj2BEaFZAVHG0rRsRgVQFpPPTAWh 3xZShfYnZlidyx7TllP0rpv+lTqusKQ0kpz9r3vkHWo/hSD8lCC2WMTngwEH8KvfQa 13BvsQasaN3IzlnwLqq9Ak1AwLpy/SW2eb9kpx+zj5dcK3RX9Pd1jVysTPY99NJx/x sEEoFqKHNk9Ug== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Markus Armbruster , Paolo Bonzini , Michael Tokarev Subject: [Stable-10.2.4 47/61] util/envlist: fix prefix-match in envlist_unsetenv() name lookup Date: Sat, 13 Jun 2026 23:03:30 +0300 Message-ID: <20260613200411.1808021-47-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381546654158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" envlist_unsetenv() looked up the entry to remove with strncmp(entry->ev_var, env, strlen(env)). The comparison length is the requested name's length, so any stored entry whose name *starts* with that name compares equal. envlist_setenv() inserts at the head of the list, so the first hit wins: with FOO=3D... stored first and FOOBAR=3D... stored afterward, envlist_unsetenv("FOO") iterates from the head, matches FOOBAR=3D... on the prefix, and drops it instead of FOO=3D... linux-user and bsd-user reach this code via the -U command-line switch, so the bug is reachable from a normal qemu-user invocation. envlist_setenv() used the same strncmp pattern but with envname_len =3D (eq_sign - env + 1), so the '=3D' byte sat inside the compared window and acted as an implicit boundary. setenv was therefore not buggy -- but the safety lived in the byte layout of ev_var rather than in the entry, so a future edit could easily drift the two sites apart again. Store the name length on each entry at insertion time and compare with explicit length equality plus memcmp via a small helper. Use the helper at both lookup sites so the boundary becomes a structural property of the entry: envlist_unsetenv() stops prefix-matching, and envlist_setenv()'s self-search no longer depends on the '=3D' byte serving as a sentinel. Fixes: 04a6dfebb6b5 ("linux-user: Add generic env variable handling") Signed-off-by: Denis V. Lunev Reviewed-by: Stefan Hajnoczi Message-id: 20260520212628.479772-2-den@openvz.org Cc: Stefan Hajnoczi Cc: Markus Armbruster Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi (cherry picked from commit c131ae56c13ffe6bd7089cf0d9bd00a7c2dbc71f) Signed-off-by: Michael Tokarev diff --git a/util/envlist.c b/util/envlist.c index 15fdbb109d..196c92c190 100644 --- a/util/envlist.c +++ b/util/envlist.c @@ -3,7 +3,8 @@ #include "qemu/envlist.h" =20 struct envlist_entry { - const char *ev_var; /* actual env value */ + const char *ev_var; /* actual env value: "NAME=3DVALUE" */ + size_t ev_name_len; /* length of NAME (offset of '=3D') */ QLIST_ENTRY(envlist_entry) ev_link; }; =20 @@ -12,6 +13,13 @@ struct envlist { size_t el_count; /* number of entries */ }; =20 +static inline bool envlist_name_eq(const struct envlist_entry *entry, + const char *name, size_t name_len) +{ + return entry->ev_name_len =3D=3D name_len && + memcmp(entry->ev_var, name, name_len) =3D=3D 0; +} + /* * Allocates new envlist and returns pointer to it. */ @@ -67,7 +75,7 @@ envlist_setenv(envlist_t *envlist, const char *env) /* find out first equals sign in given env */ if ((eq_sign =3D strchr(env, '=3D')) =3D=3D NULL) return (EINVAL); - envname_len =3D eq_sign - env + 1; + envname_len =3D eq_sign - env; =20 /* * If there already exists variable with given name @@ -76,8 +84,9 @@ envlist_setenv(envlist_t *envlist, const char *env) */ for (entry =3D envlist->el_entries.lh_first; entry !=3D NULL; entry =3D entry->ev_link.le_next) { - if (strncmp(entry->ev_var, env, envname_len) =3D=3D 0) + if (envlist_name_eq(entry, env, envname_len)) { break; + } } =20 if (entry !=3D NULL) { @@ -90,6 +99,7 @@ envlist_setenv(envlist_t *envlist, const char *env) =20 entry =3D g_malloc(sizeof(*entry)); entry->ev_var =3D g_strdup(env); + entry->ev_name_len =3D envname_len; QLIST_INSERT_HEAD(&envlist->el_entries, entry, ev_link); =20 return (0); @@ -119,8 +129,9 @@ envlist_unsetenv(envlist_t *envlist, const char *env) envname_len =3D strlen(env); for (entry =3D envlist->el_entries.lh_first; entry !=3D NULL; entry =3D entry->ev_link.le_next) { - if (strncmp(entry->ev_var, env, envname_len) =3D=3D 0) + if (envlist_name_eq(entry, env, envname_len)) { break; + } } if (entry !=3D NULL) { QLIST_REMOVE(entry, ev_link); --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381474; cv=none; d=zohomail.com; s=zohoarc; b=k+aJwYthERZJ7mN/ylXk0qcix2qrZbAG/fs78Phs5nxTopda8hEhvcC6fMfBZFpdy3QvbST8gbfiuaJICbvp4qtvKSKTFWxeLFkHkIk7lZdS/lX8R425snulhGeYZ+/mS8eNxr1N+vz7BDKiR1ulUq1PSmwKPNPHHhihX4pwZNE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381474; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=dXXzR8MAs3ADAI33D+yxYyA2Fa9eRvw7F8DYHCAA+wI=; b=m04/xh6PMkVbF6SgbebMvEkIkYPIEwa8WW/M9fOHZ7QQtHiCXu0uLyOOvrZPmyLWYabRoaFv5l7gbLZBcdZKIUds82FvxYj6MRYRb/YlbX1B7Y88Fg3lKMRnNsj86hAt7cugTrSM4gALlZ62NZn1PYYVDy7x0OnOjXbCBs05ZHA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381474456929.6485876190429; Sat, 13 Jun 2026 13:11:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUfG-0001QE-0w; Sat, 13 Jun 2026 16:09:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfD-0001Ca-SV; Sat, 13 Jun 2026 16:09:07 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfB-0002fx-QW; Sat, 13 Jun 2026 16:09:07 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 2914A1B6E9F; Sat, 13 Jun 2026 23:04:30 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 832753CE8FA; Sat, 13 Jun 2026 23:04:48 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381070; bh=WBscJ52Kswc1ZMYXolaPaqnmlI8GCz9M9YD2ob2apxU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=XOyR3K3ZD+LfMTeoc8e8BFOBR23DiXePF1OQkN4QeTcQtxY+GTYGdWDhS0WZdM/3y EMaW7bbz3dKDIx4p92dfKBtVUKddTWudXfK1JK0D8qFpOQcaXA+GJaZ9aeZoSSLQw7 Wz4eGrpsfSQ5pyNp6YufRIuVoCoqBcDiyWBg7ORQxye5upcN9TuX0EpLuCH/7lbQCy l0JX1qQU+9wpGdD0KUxL44xuDyUhqjg9YAPP1Z7oPOgsqWuzqLTbV5ls1jMgbH9rx1 a4j05nYYgjmtFegOQyes7T59tGW4q6Ee+lsYjiuCVfx7mvkMX1aujmhWxv153FB1nb E5NSd5eQA3nng== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Markus Armbruster , Paolo Bonzini , Michael Tokarev Subject: [Stable-10.2.4 48/61] tests/unit: add test-envlist covering setenv/unsetenv name matching Date: Sat, 13 Jun 2026 23:03:31 +0300 Message-ID: <20260613200411.1808021-48-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381476460158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" util/envlist had no test coverage. Add tests/unit/test-envlist exercising the public envlist API and pinning down the prefix-match hazard fixed in the previous commit: - envlist_unsetenv("FOO") must not remove an entry named "FOOBAR"; - envlist_setenv("FOO=3D...") must not replace an existing "FOOBAR=3D..." entry placed earlier in the list (envlist_setenv() inserts at the head, so the first prefix match wins under the old strncmp rule). Also cover the rest of the contract: head-insertion order observed through envlist_to_environ(), replacement of an existing variable, the count argument of envlist_to_environ(), and the documented EINVAL paths (NULL inputs, setenv without '=3D', unsetenv with '=3D'). Signed-off-by: Denis V. Lunev Reviewed-by: Stefan Hajnoczi Message-id: 20260520212628.479772-3-den@openvz.org Cc: Stefan Hajnoczi Cc: Markus Armbruster Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi (cherry picked from commit 05221c600a5f3ef657d71aeaea632c5f1bab3a2d) Signed-off-by: Michael Tokarev diff --git a/tests/unit/meson.build b/tests/unit/meson.build index bd58029060..24851335be 100644 --- a/tests/unit/meson.build +++ b/tests/unit/meson.build @@ -48,6 +48,7 @@ tests =3D { 'test-qapi-util': [], 'test-interval-tree': [], 'test-fifo': [], + 'test-envlist': [], } =20 if have_system or have_tools diff --git a/tests/unit/test-envlist.c b/tests/unit/test-envlist.c new file mode 100644 index 0000000000..53813dd4de --- /dev/null +++ b/tests/unit/test-envlist.c @@ -0,0 +1,196 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +/* + * envlist tests + * + * Copyright 2026 Virtuozzo International GmbH + * + * Authors: + * Denis V. Lunev + */ + +#include "qemu/osdep.h" +#include "qemu/envlist.h" + +static void free_environ(char **env) +{ + char **p; + + for (p =3D env; *p !=3D NULL; p++) { + g_free(*p); + } + g_free(env); +} + +static const char *find_env(char **env, const char *name) +{ + size_t name_len =3D strlen(name); + char **p; + + for (p =3D env; *p !=3D NULL; p++) { + if (strncmp(*p, name, name_len) =3D=3D 0 && (*p)[name_len] =3D=3D = '=3D') { + return *p + name_len + 1; + } + } + return NULL; +} + +static void test_envlist_basic(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + /* empty list */ + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 0); + g_assert_null(env[0]); + free_environ(env); + + /* add */ + g_assert_cmpint(envlist_setenv(el, "A=3D1"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "B=3D2"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "A"), =3D=3D, "1"); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* replace */ + g_assert_cmpint(envlist_setenv(el, "A=3D42"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "A"), =3D=3D, "42"); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* unset existing */ + g_assert_cmpint(envlist_unsetenv(el, "A"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + g_assert_null(find_env(env, "A")); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* unset non-existing is a no-op success */ + g_assert_cmpint(envlist_unsetenv(el, "NOPE"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + free_environ(env); + + envlist_free(el); +} + +/* + * envlist_setenv() inserts at the head; envlist_to_environ() walks + * head-to-tail, so the last setenv comes out first. + */ +static void test_envlist_head_insertion_order(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "A=3D1"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "B=3D2"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "C=3D3"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 3); + g_assert_cmpstr(env[0], =3D=3D, "C=3D3"); + g_assert_cmpstr(env[1], =3D=3D, "B=3D2"); + g_assert_cmpstr(env[2], =3D=3D, "A=3D1"); + g_assert_null(env[3]); + + free_environ(env); + envlist_free(el); +} + +static void test_envlist_einval(void) +{ + envlist_t *el =3D envlist_create(); + + /* NULL list */ + g_assert_cmpint(envlist_setenv(NULL, "A=3D1"), =3D=3D, EINVAL); + g_assert_cmpint(envlist_unsetenv(NULL, "A"), =3D=3D, EINVAL); + + /* NULL string */ + g_assert_cmpint(envlist_setenv(el, NULL), =3D=3D, EINVAL); + g_assert_cmpint(envlist_unsetenv(el, NULL), =3D=3D, EINVAL); + + /* setenv: missing '=3D' */ + g_assert_cmpint(envlist_setenv(el, "NOEQ"), =3D=3D, EINVAL); + + /* unsetenv: name must not contain '=3D' */ + g_assert_cmpint(envlist_unsetenv(el, "A=3DB"), =3D=3D, EINVAL); + + envlist_free(el); +} + +/* + * Regression: envlist_unsetenv("FOO") must not remove an entry named + * "FOOBAR" -- the previous strncmp(entry, name, strlen(name)) lookup + * prefix-matched. To trigger the bug, the longer-named entry has to + * be ahead of the target in the list: envlist_setenv() inserts at + * the head, so we add FOO first and FOOBAR last. + */ +static void test_envlist_unsetenv_no_prefix_match(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "FOO=3Dy"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "FOOBAR=3Dx"), =3D=3D, 0); + + g_assert_cmpint(envlist_unsetenv(el, "FOO"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + g_assert_cmpstr(find_env(env, "FOOBAR"), =3D=3D, "x"); + g_assert_null(find_env(env, "FOO")); + + free_environ(env); + envlist_free(el); +} + +/* + * envlist_setenv() must not replace a prior FOOBAR=3D... entry when + * setting FOO=3D... The pre-fix code happened to be safe here only + * because it included the trailing '=3D' byte in its strncmp length; + * this test pins down the post-fix contract that the name boundary + * is a property of the entry, not of the encoded form. + */ +static void test_envlist_setenv_no_prefix_match(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "FOOBAR=3Dx"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "FOO=3Dy"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "FOOBAR"), =3D=3D, "x"); + g_assert_cmpstr(find_env(env, "FOO"), =3D=3D, "y"); + + free_environ(env); + envlist_free(el); +} + +int main(int argc, char *argv[]) +{ + g_test_init(&argc, &argv, NULL); + + g_test_add_func("/envlist/basic", test_envlist_basic); + g_test_add_func("/envlist/head_insertion_order", + test_envlist_head_insertion_order); + g_test_add_func("/envlist/einval", test_envlist_einval); + g_test_add_func("/envlist/unsetenv_no_prefix_match", + test_envlist_unsetenv_no_prefix_match); + g_test_add_func("/envlist/setenv_no_prefix_match", + test_envlist_setenv_no_prefix_match); + + return g_test_run(); +} --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381433; cv=none; d=zohomail.com; s=zohoarc; b=a79Q3Eqk3USCve9L01VwoCEgMTHR2nG2QC9OYi2XNjQmtkIAw1F6Qvg7SSj/+BycrpElUtfp8bEe3jn7Y/tI/QOacVIzJ+BWT0Gu52OcetSolJ5UMjTsOlemylGMMxa+cr2gwMhi86PFVsVqXTj80da3ALo155ly1K0MfcyioA4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381433; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8yarpF3uFCTgUZucjlrToJ5iK4crFWl2kfvhEgnIJMY=; b=Fu1515A7p6wr3w0Ntu/xgC+0ye1osvfSZtov0p+GVgtTURbov3SX9fcdlUmMbfKQItP8HnsTU9yQ8soJdLQJ8VExJkY+5HOPzEngcBtMqXMOqbfL4jy4jVHvoWBBvTDwiqCt6HnYxtW2cyEi5Qur7lumrZm7hmJ4sIr1vPQvh2c= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138143336061.42634533869443; Sat, 13 Jun 2026 13:10:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUfH-0001Wz-Ds; Sat, 13 Jun 2026 16:09:11 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfF-0001QQ-T1; Sat, 13 Jun 2026 16:09:09 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfE-0002k0-1S; Sat, 13 Jun 2026 16:09:09 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 3DA521B6EA0; Sat, 13 Jun 2026 23:04:30 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9650E3CE8FB; Sat, 13 Jun 2026 23:04:48 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381070; bh=/yCG3jEExQpedxSgTR2/aw27BcSv2Xz3e8r7g1a46fI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=wEIeufgZZsHODNGgA16tMmv9yppioxxAHLz7mh4g99X8fD9kzvpaxBeUrk2IWxjk4 tcD6BHaMZYqPhjyur5W2baUOeCMdjQRR5FrZpwafyjGpkkR7tVcURv5sbpp3DSRRGl OEH229SIxJ2mpMxoYOHrnOmB7UgyeN/vcpL6F1Fboik6hVpMs2Y6J9AHM420WX8NQ/ pbtX79J6JFGXxPmMMLfR3ouRoYYV3EYpeqni1CAaadijVL6uIDRqK5OWvXtXgVFUyi H1J7bW0wInpxts6RLHpt5M50e3UJ/jyZiLebyGiDpoLLMHI9Zo7GyXZSjM/DtKVIm9 L/L4a/oWIG9zg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alexandra Winter , Hendrik Brueckner , Christian Borntraeger , Gautam Gala , Cornelia Huck , Michael Tokarev Subject: [Stable-10.2.4 49/61] target/s390x: Make container ids in SysIB_15x 1-based Date: Sat, 13 Jun 2026 23:03:32 +0300 Message-ID: <20260613200411.1808021-49-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381434341158500 Content-Type: text/plain; charset="utf-8" From: Alexandra Winter The Container Id in a container-type TLE of SysIB_15x is defined as 8-bit unsigned nonzero integer. Make stsi fc 15 emulation architecture compliant, by starting the container ids at 1 for the lowest numbered container. The qemu misbehaviour without this patch becomes obvious due to a recently proposed kernel fix. Older linux kernels pass the container ids from stsi fc15 unchanged to sysfs, i.e. starting at 1 on s390 hardware. This resulted in off-by-one values when compared to the values from HMC. A Linux kernel fix is being proposed to correct the sysfs topology ids by -1, so they start at 0, e.g. when displayed by 'lscpu -ye'. In case a KVM guest with a fixed kernel runs on a host with a qemu without this fix, this can result in container ids erroneously being shown as 255. Example (Fixed guest on unfixed qemu): $ lscpu -ye CPU NODE DRAWER BOOK SOCKET CORE L1d:L1i:L2 ONLINE CONFIGURED POLARIZATION = ADDRESS 0 0 255 255 255 0 0:0:0 yes yes vert-medium 0 1 0 255 255 0 1 1:1:1 yes yes vert-medium 1 After this fix: $ lscpu -ye CPU NODE DRAWER BOOK SOCKET CORE L1d:L1i:L2 ONLINE CONFIGURED POLARIZATION = ADDRESS 0 0 0 0 0 0 0:0:0 yes yes vert-medium 0 1 0 0 0 1 1 1:1:1 yes yes vert-medium 1 Fixes: f4f54b582f ("target/s390x/cpu topology: handle STSI(15) and build th= e SYSIB") Signed-off-by: Alexandra Winter Acked-by: Hendrik Brueckner Acked-by: Christian Borntraeger Reviewed-by: Gautam Gala Message-ID: <20260511134909.43802-1-wintera@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit 1f1ccb6f3c48a2cd80e874d66afeef2dc28a65f3) Signed-off-by: Michael Tokarev diff --git a/target/s390x/kvm/stsi-topology.c b/target/s390x/kvm/stsi-topol= ogy.c index c8d6389cd8..af3fd8ad1b 100644 --- a/target/s390x/kvm/stsi-topology.c +++ b/target/s390x/kvm/stsi-topology.c @@ -90,9 +90,9 @@ static int stsi_topology_fill_sysib(S390TopologyList *top= ology_list, int last_drawer =3D -1; int last_book =3D -1; int last_socket =3D -1; - int drawer_id =3D 0; - int book_id =3D 0; - int socket_id =3D 0; + int drawer_id =3D 1; + int book_id =3D 1; + int socket_id =3D 1; int n =3D sizeof(SysIB_151x); =20 QTAILQ_FOREACH(entry, topology_list, next) { @@ -103,12 +103,12 @@ static int stsi_topology_fill_sysib(S390TopologyList = *topology_list, if (level > 3 && drawer_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); p =3D fill_container(p, 3, drawer_id++); - book_id =3D 0; + book_id =3D 1; } if (level > 2 && book_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); p =3D fill_container(p, 2, book_id++); - socket_id =3D 0; + socket_id =3D 1; } if (socket_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381520; cv=none; d=zohomail.com; s=zohoarc; b=aXITJmFkK3uAEXyJEjCLLcWB6SHHSeniR4tSJG6s6pkszDf62AF1mjt3dYk6QaO3XW0Zpg2CihaE5Q7u29F+caoN+xUf3ybbvo8M/67tAmxWBpG9Z0OVtrqApU50SKoCTe5zPFxmpakon1A8Lo8kz9/DsjrnFADYI9BYrP8o46I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381520; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fBHP0eEzvyLq/tp6pQRAvDm8TwiBTmLk8DkXXVYFOIo=; b=eXPxIwrFuOgY1WI7Tsg6da5u0E+LpG2GoOBt3SqukaCKjBFJhjAIX4c4PV2bIyfgIm+lpjxbITTJq5i+b/KVC0WJMW5nu2iUqBwMkQeEzQSF1lAxBcL87cYDDkXvOOfbsJCbtF/URgWu3/JThuGGooXAKvd4Wz2ELGjFrU0Dbrk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381520939379.37127800518454; Sat, 13 Jun 2026 13:12:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUfK-0001cc-HX; Sat, 13 Jun 2026 16:09:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfH-0001X0-9f; Sat, 13 Jun 2026 16:09:11 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfF-0002kH-ME; Sat, 13 Jun 2026 16:09:11 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 5B03F1B6EA1; Sat, 13 Jun 2026 23:04:30 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id AB0F93CE8FC; Sat, 13 Jun 2026 23:04:48 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381070; bh=Rw04CJ7iJKVLfo5V6cQGHcttrvSihQhZJ9mGh5ztY7w=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=NsE/DJjjaJPqHU1Px9oXLF1LOr2FKzlQcqxCJeadKZUxB3AGq6iE8O8hJyK+aqVBF 3SX3gEo9y1rh2utKPdZX1VlCER1tLVspwWAQSUlQpQlxGMzC6bFbI+knOhuaPhT0ul bWBwmoGNnxU4/8JDzqaRspco7RPetxhzEtNU1J9eL23txAyZjt76WkHu+lvV/vnQYA pMCXop1XDgDmZcrHPiCLugfhdBO2ZyR9xXG6VvCVqeCHIuTZfWlIaTSn1ya4Pa9Mix 4SgikOXdqcUTfIWqvQ4IzLSnV/16cKLbGuLnYziYjjdvJgsMGRmOomT6HZ2S8o6I45 8TTzvk7luvIZA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Farhan Ali , Niklas Schnelle , Matthew Rosato , Omar Elghoul , Cornelia Huck , Michael Tokarev Subject: [Stable-10.2.4 50/61] s390x/pci: Fix interrupt forwarding disable for interpreted devices Date: Sat, 13 Jun 2026 23:03:33 +0300 Message-ID: <20260613200411.1808021-50-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381522578158500 Content-Type: text/plain; charset="utf-8" From: Farhan Ali Remove the FH_MASK_ENABLE check when disabling interrupt forwarding during device reset. This check was broken for the default case in the switch statement above, preventing proper cleanup of interrupt forwarding. The pbdev->aif check in s390_pci_kvm_aif_disable() already guards against double-disabling of interrupt forwarding. Cc: qemu-stable@nongnu.org Reported-by: Niklas Schnelle Signed-off-by: Farhan Ali Reviewed-by: Matthew Rosato Tested-by: Omar Elghoul Message-ID: <20260521182946.1607-1-alifm@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit 442f727b8bebabf20a4f6a7536a4ff2885402030) Signed-off-by: Michael Tokarev diff --git a/hw/s390x/s390-pci-bus.c b/hw/s390x/s390-pci-bus.c index 52820894fa..4ed4e45cb9 100644 --- a/hw/s390x/s390-pci-bus.c +++ b/hw/s390x/s390-pci-bus.c @@ -1504,7 +1504,7 @@ static void s390_pci_device_reset(DeviceState *dev) break; } =20 - if (pbdev->interp && (pbdev->fh & FH_MASK_ENABLE)) { + if (pbdev->interp) { /* Interpreted devices were using interrupt forwarding */ s390_pci_kvm_aif_disable(pbdev); } else if (pbdev->summary_ind) { --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381606; cv=none; d=zohomail.com; s=zohoarc; b=bqCadAzgVWMzL+nN1Ua3urv0FLJ6RUtwrRFRop1DHtuWNMUECB4wtUX1OcwkziaXiLu9JbCRhvsQZe3XbVXR+3zPtkjLOE06Gxe+3AEatCTfkYz5t5oL10QpMLOWZRXoHqbvvLj0NzEqs/IksTR8W9/ilttd7OisD05xXVUUf4k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381606; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wzfwR7hcwyjNsXrmahNs4Vr3iFcwqZlT15ItG7UNE54=; b=BURFzaXQvq227mVeaCcoEhPV2K1oi2aCyGCRyMaiG8CJ7FIWRJ49/TzI3iS/JRZAAfTdZpBI3myKKfcwqDZA8Ryc6jiTl/wK1mskCFCTsESnMpfDrLb7r2ik16zkq+XUDb3l8R9ZBFVhWFT8A7hCD0ZbmQZq7RezDteirvOQ0W4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381606223699.1782585613129; Sat, 13 Jun 2026 13:13:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUfv-00020y-Hx; Sat, 13 Jun 2026 16:09:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfg-0001xB-Cl; Sat, 13 Jun 2026 16:09:39 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfb-0002kn-Os; Sat, 13 Jun 2026 16:09:33 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9F88D1B6EA2; Sat, 13 Jun 2026 23:04:30 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C818E3CE8FD; Sat, 13 Jun 2026 23:04:48 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381070; bh=2JSzfA8Q4mBWTQsJt3J+K9E/6xfb1l5lRRiTnsafi30=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=UvUwDdq/f8Kl6b0ohxknmMGf1gdIIB6Hh5ur3ZpAAmPEoycYBOu6mQpK7rsIIsFxb bMy6ikqJGxDKEWW0oPHofvHBW0tFCJ2UdYSLuS8bgCKGbfeCg3eW6JH+cbKHhFuD3r 9FRjBEPoTHMg2rYtmpe5XZJd6370RM3URiXNXmDxAKhLAiFVme0M22kvX3FcdiBShb 9mpq6hUd/DEHG3sv/bj2Qg7DYhkVTpY2PAcENmmm+PgcWURlAOzjuY5sBM5FFqWHqu EpSXgJz9FsNGq99/WGw1j01sPXJYvOYDHea+V8XWwfPJ4/3icTnMrJZWvkvyj3Ir9d 9Sq2a4pXoqbwQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fiona Ebner , Stefan Hajnoczi , Michael Tokarev Subject: [Stable-10.2.4 51/61] block/io: fallback to bounce buffer if BLKZEROOUT is not supported because of alignment Date: Sat, 13 Jun 2026 23:03:34 +0300 Message-ID: <20260613200411.1808021-51-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381607248158500 Content-Type: text/plain; charset="utf-8" From: Fiona Ebner Commit 5634622bcb ("file-posix: allow BLKZEROOUT with -t writeback") enables the BLKZEROOUT ioctl when using 'writeback' cache, regressing certain 'qemu-img convert' invocations, because of a pre-existing issue. Namely, the BLKZEROOUT ioctl might fail with errno EINVAL when the request is shorter than the block size of the block device. Fallback to the bounce buffer, similar to when the ioctl is not supported at all, rather than treating such an error as fatal. Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3257 Resolves: https://bugzilla.proxmox.com/show_bug.cgi?id=3D7197 Cc: qemu-stable@nongnu.org Signed-off-by: Fiona Ebner Message-ID: <20260105143416.737482-1-f.ebner@proxmox.com> [Added TODO comment describing a larger fix that could be implemented in the future. --Stefan] Signed-off-by: Stefan Hajnoczi (cherry picked from commit b4e28c304bc58325f8f712cb25e5d700826caa25) Signed-off-by: Michael Tokarev diff --git a/block/io.c b/block/io.c index c4a4301321..8f193c29e5 100644 --- a/block/io.c +++ b/block/io.c @@ -1917,7 +1917,18 @@ bdrv_co_do_pwrite_zeroes(BlockDriverState *bs, int64= _t offset, int64_t bytes, assert(!bs->supported_zero_flags); } =20 - if (ret =3D=3D -ENOTSUP && !(flags & BDRV_REQ_NO_FALLBACK)) { + /* + * TODO The ret =3D=3D -EINVAL && num < alignment case is a workar= ound for + * when request_alignment is 1 on files with cache=3Dwriteback. Th= e Linux + * ioctl(BLKZEROOUT) requires block alignment and will fail with + * EINVAL. The block layer should align the request to + * write_zeroes_alignment instead of trying the syscall, failing, = and + * falling back to a bounce buffer. Doing that is not easy so for = now + * we use a bounce buffer: + * https://lore.kernel.org/qemu-devel/20260109120837.2772961-1-f.e= bner@proxmox.com/ + */ + if ((ret =3D=3D -ENOTSUP || (ret =3D=3D -EINVAL && num < alignment= )) && + !(flags & BDRV_REQ_NO_FALLBACK)) { /* Fall back to bounce buffer if write zeroes is unsupported */ BdrvRequestFlags write_flags =3D flags & ~BDRV_REQ_ZERO_WRITE; =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381595; cv=none; d=zohomail.com; s=zohoarc; b=TlgvywWS9IJvHKwycp5Qr1GLjZ9Q/+H5FyOtKgL7RPHMOXKDlNUoC2yIRZVl3YDNJ28NQ55GdA3ULDTlCLQAP9JYqmz4JJnjPVqTBxzot6ShvpNbqJxr1bH6e52xxpTiRUPQUoXHNz0kkLyi0CFZRl2MLww+12Jx8ZMxdIgQHCA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381595; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=IkpeY5+WiZIluQl8ALPDDZpHgwFO4RK+tkqRbcSacxA=; b=Ss0JxIrBn0QhLjD5LI0Ay62olZqZbSznVSVDSBB26vYg26URh/dJ39Hxj8L2L4SUwxfwFcxHJCAR9mzV7TBeZolvpw/cYWVgmzoPrIzaHw2oNeXZz54H3Ih3uGquMwhjZ4qKLpYre9u5vwG1y6YJ61m/5/oBN45+pxd/wc0RJsE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381595088123.61236198500774; Sat, 13 Jun 2026 13:13:15 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUfy-0002LO-7e; Sat, 13 Jun 2026 16:09:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfk-0001xg-S2; Sat, 13 Jun 2026 16:09:44 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfe-0002lJ-2Z; Sat, 13 Jun 2026 16:09:37 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B3AC01B6EA3; Sat, 13 Jun 2026 23:04:30 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 18F463CE8FE; Sat, 13 Jun 2026 23:04:49 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381070; bh=vpSwl0/wKEuLSNmbrgsPgxoD8nEahv3mQTobcLyg8ms=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=u3Vpb88sbwRYg4xNBj9hUAMWVhXjVm2Eh1k3L525n3SqmbWY9OtBvWHcsbtz77PMv YovEYDFCqaPCrZlGoo2h4HRnFYk/L1p4u7htUtgz9iFxB17GxB757EKyZNIBBT0q0o 4h0EgGkYW+BE/pacjsuETvwNcXRddaK6Oo4A4DghtWrvG1Vf7VHVXPSi8OEk50b4Bz PTFJ3b41FxEJBTdcStBdc7WF5sRN/lV9JYkpRO6UkC4XDPlBaTawkGSMGaKNqjUfg6 JVRP0zmNL4rqqPqPvG96s2Y1cDtVzzaX3x4rxKAy5dSyTbHD7juHcu5vrlvBF5+oBO dsAjffPHphY9A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Stefan Hajnoczi , Feifan Qian , Paolo Bonzini , Kevin Wolf , Michael Tokarev Subject: [Stable-10.2.4 52/61] virtio-blk: add missing VIRTIO_BLK_T_SCSI_CMD size check (CVE-2026-48914) Date: Sat, 13 Jun 2026 23:03:35 +0300 Message-ID: <20260613200411.1808021-52-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381596799158500 Content-Type: text/plain; charset="utf-8" From: Stefan Hajnoczi Check that the iovec containing struct virtio_scsi_inhdr is large enough before storing an error value there. Feifan Qian pointed out that this can be used to corrupt heap memory when the descriptor uses an MMIO address and a length of 1, forcing QEMU to allocate a 1-byte heap bounce buffer. virtio_stl_p() stores 4 bytes and therefore corrupts whatever is beyond the bounce buffer. Fixes: CVE-2026-48914 Fixes: f34e73cd69bd ("virtio-blk: report non-zero status when failing SG_IO= requests") Reported-by: Feifan Qian Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi Message-ID: <20260526154957.1741622-1-stefanha@redhat.com> Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit aeea0c2804c42f24915467a1e4c70e649e39b8e0) Signed-off-by: Michael Tokarev diff --git a/hw/block/virtio-blk.c b/hw/block/virtio-blk.c index 065373cc59..7c4c803a8c 100644 --- a/hw/block/virtio-blk.c +++ b/hw/block/virtio-blk.c @@ -199,10 +199,16 @@ static void virtio_blk_handle_scsi(VirtIOBlockReq *re= q) =20 /* * The scsi inhdr is placed in the second-to-last input segment, just - * before the regular inhdr. + * before the regular inhdr. VIRTIO implementations normally do not re= ly on + * the precise message framing, but legacy implementations did and so = we do + * too for the legacy virtio-blk SCSI request type. * * Just put anything nonzero so that the ioctl fails in the guest. */ + if (elem->in_sg[elem->in_num - 2].iov_len !=3D sizeof(*scsi)) { + status =3D VIRTIO_BLK_S_IOERR; + goto fail; + } scsi =3D (void *)elem->in_sg[elem->in_num - 2].iov_base; virtio_stl_p(vdev, &scsi->errors, 255); status =3D VIRTIO_BLK_S_UNSUPP; --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381470; cv=none; d=zohomail.com; s=zohoarc; b=gzziVHG287x19rHzZAIjjri9yy0m1DJncFO99vX4hqU46Q6PEUtEHWD2uVJBgoIabb6IFpNdWiCicN/PkALrF7dyPb2Evw7+sXvl8v+m3b23g6DCysdE5JUtiTa9smi30r81zz6NPcg6O9ej8NUa3SRDnheNbEwaY655X2LJGHA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381470; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=kPRoR6Y4vKY65iZQNM4x0/upq0V5iiOWNlAtuLI6rO8=; b=l7fMnN5b9dWcDVA2C9iFTPuwVgk0h7J7aHgbneVWGmdPfWp+sim0vcxTecXbMQXYIxrgpixnpPHNsCnuOas2i/gOmcVz4WHPDacJhvje9mFFniVAme+GwywWlI8goAmZPjl07h0SpvIVC5XdvBJFCK8CbPTEa1oj1Sp6qvNSg5I= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381470553479.3817719345808; Sat, 13 Jun 2026 13:11:10 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUfw-0002Fq-VD; Sat, 13 Jun 2026 16:09:53 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfo-0001xp-A0; Sat, 13 Jun 2026 16:09:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfj-0002x3-E8; Sat, 13 Jun 2026 16:09:42 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C378E1B6EA5; Sat, 13 Jun 2026 23:04:30 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 2D4A23CE8FF; Sat, 13 Jun 2026 23:04:49 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381070; bh=yBluAs/gE8DSO3TfUiji3YFG4b/s0M7RfG8jpYCyV4I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=PL8IWbn/9N31gfm8spleXI8phTtKFtwjkkl4UHMVvE556YswKuEubYRXLd+qq4ySp +JpG9WAIOuXRGZ+ven3+2quypW0zm9ZvMHbwEeypDBQSGrzKYWHRTlyHhJCoiim/BF xJxcuLM7fFdj5bmGM6liidSVwO2y4HUoJQrVQi0y4TpLD/fTBpRMy/DCvpFoezZN+i roKp24dvTxOuPISAX+ArLlEWvA4mZ6a+OT4lGDYafbyevcBa+8HnmOrAUya4L4R0r5 Wfpv+SJmb4qlHRt6cyiPnlazFZa2JigBRBWBe1BVp72hrR2sw08DB/aWflpJ81TPlP aWIdruolwVWRw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-10.2.4 53/61] qemu-io: Add 'aio_discard' command Date: Sat, 13 Jun 2026 23:03:36 +0300 Message-ID: <20260613200411.1808021-53-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381472382158500 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf Testing interactions between multiple requests that include discard requests require that qemu-io can do the discard asynchronously, like it already does for reads and writes. To this effect, add an 'aio_discard' command. Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-3-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit 7f8466e2ce620e3c6a6e2f32d616367174d4dbe9) Signed-off-by: Michael Tokarev diff --git a/qemu-io-cmds.c b/qemu-io-cmds.c index f6d077908f..de4c1966fe 100644 --- a/qemu-io-cmds.c +++ b/qemu-io-cmds.c @@ -2218,6 +2218,120 @@ static int discard_f(BlockBackend *blk, int argc, c= har **argv) return 0; } =20 +static void aio_discard_help(void) +{ + printf( +"\n" +" asynchronously discards a range of bytes from the given offset\n" +"\n" +" Example:\n" +" 'aio_discard 512 1k' - discards 1 kilobyte from 512 bytes into the file\= n" +"\n" +" Discards a segment of the currently open file.\n" +" -C, -- report statistics in a machine parsable format\n" +" -q, -- quiet mode, do not show I/O statistics\n" +" The discard is performed asynchronously and the aio_flush command must b= e\n" +" used to ensure all outstanding aio requests have been completed.\n" +" Note that due to its asynchronous nature, this command will be\n" +" considered successful once the request is submitted, independently\n" +" of potential I/O errors.\n" +"\n"); +} + +static int aio_discard_f(BlockBackend *blk, int argc, char **argv); + +static const cmdinfo_t aio_discard_cmd =3D { + .name =3D "aio_discard", + .cfunc =3D aio_discard_f, + .perm =3D BLK_PERM_WRITE, + .argmin =3D 2, + .argmax =3D -1, + .args =3D "[-Cq] off len", + .oneline =3D "asynchronously discards a number of bytes", + .help =3D aio_discard_help, +}; + +static void aio_discard_done(void *opaque, int ret) +{ + struct aio_ctx *ctx =3D opaque; + struct timespec t2; + + clock_gettime(CLOCK_MONOTONIC, &t2); + + if (ret < 0) { + printf("aio_discard failed: %s\n", strerror(-ret)); + block_acct_failed(blk_get_stats(ctx->blk), &ctx->acct); + goto out; + } + + block_acct_done(blk_get_stats(ctx->blk), &ctx->acct); + + if (ctx->qflag) { + goto out; + } + + /* Finally, report back -- -C gives a parsable format */ + t2 =3D tsub(t2, ctx->t1); + print_report("discarded ", &t2, ctx->offset, ctx->qiov.size, + ctx->qiov.size, 1, ctx->Cflag); +out: + g_free(ctx); +} + +static int aio_discard_f(BlockBackend *blk, int argc, char **argv) +{ + int c, ret; + int64_t count; + struct aio_ctx *ctx =3D g_new0(struct aio_ctx, 1); + + ctx->blk =3D blk; + + while ((c =3D getopt(argc, argv, "Cq")) !=3D -1) { + switch (c) { + case 'C': + ctx->Cflag =3D true; + break; + case 'q': + ctx->qflag =3D true; + break; + default: + g_free(ctx); + qemuio_command_usage(&aio_discard_cmd); + return -EINVAL; + } + } + + if (optind !=3D argc - 2) { + g_free(ctx); + qemuio_command_usage(&aio_discard_cmd); + return -EINVAL; + } + + ctx->offset =3D cvtnum(argv[optind]); + if (ctx->offset < 0) { + ret =3D ctx->offset; + print_cvtnum_err(ret, argv[optind]); + g_free(ctx); + return ret; + } + optind++; + + count =3D cvtnum(argv[optind]); + if (count < 0) { + print_cvtnum_err(count, argv[optind]); + g_free(ctx); + return count; + } + + clock_gettime(CLOCK_MONOTONIC, &ctx->t1); + ctx->qiov.size =3D count; + block_acct_start(blk_get_stats(blk), &ctx->acct, ctx->qiov.size, + BLOCK_ACCT_UNMAP); + blk_aio_pdiscard(blk, ctx->offset, count, aio_discard_done, ctx); + + return 0; +} + static int alloc_f(BlockBackend *blk, int argc, char **argv) { BlockDriverState *bs =3D blk_bs(blk); @@ -2800,6 +2914,7 @@ static void __attribute((constructor)) init_qemuio_co= mmands(void) qemuio_add_command(&length_cmd); qemuio_add_command(&info_cmd); qemuio_add_command(&discard_cmd); + qemuio_add_command(&aio_discard_cmd); qemuio_add_command(&alloc_cmd); qemuio_add_command(&map_cmd); qemuio_add_command(&reopen_cmd); --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381616; cv=none; d=zohomail.com; s=zohoarc; b=VsYfJcbTZtel6DpbWKusSMlcr9kzKEBvqxD9/7UIRBzK3LXi///xyTPUJv46NykgdZbA7PgKagOTbFNE7Rcu0ZSC0FvtuYroOEf0tLhnpe4/qLYw4CDQW75Z3Bf4EkBx/2ACYHD2EmeteP5Vy2y0rwxWcJmqQMIS/VGr1xHnYFU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381616; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=XG/QBUMXO+x5S9OgxaerXGYMSJsNzM/EDXUGasQPzHg=; b=K0Ki/2u1PEFsKKhgTw5bxTJVBdPcjUjpEEhD9ZiC6HlUVsvafSfh45dCUlfMC6uEv9oq6KyhhhuGrffgcvc1TmwWtOfg4zu1eyd2Y8aGWxcEcy89Y9uV6+3wBn89/S3H1Xtwbajt6fTnctzQRI/krVbFZJzebWtMZaWODtymRJE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381616457974.3308571223371; Sat, 13 Jun 2026 13:13:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUfy-0002LW-7W; Sat, 13 Jun 2026 16:09:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfq-0001y3-T6; Sat, 13 Jun 2026 16:09:48 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfo-00030Y-GL; Sat, 13 Jun 2026 16:09:46 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D29831B6EA6; Sat, 13 Jun 2026 23:04:30 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 3CEF23CE900; Sat, 13 Jun 2026 23:04:49 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381070; bh=8146qO6KFVKscfnp7ME4DCWZ2VVfJ/m5ZGh/Be/5xEg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=mbECX2fry5EcztkAI2XctKRYwdz23ludqs+0oFjI53SWecCveQR5+m7wlinlozxft yRX1s96ZmuLtTh1LJ5cn/1YnnA8VQiuE7LklwwwOmf9nwW5a/PwIawWVEwLdbfkyFy XLwmaj1WI7nEiA2hbuIhCRh+uv2zO5i8V7jHRYgFa6nP2YM9R7g6WMW8axQ70YiR1S HzTshgejP0WcM4Zc7nPA7EkjDX89KSrlfxU9vI/PE4U9BKA3zeCU9ZYiPJMpYS0QiW T0Iffk4qlWEuuOXI6fNdm1DNmuS3T8e8Vrbw+bwZlXvOrWcdzIAeW7XK01MgLvBP6W s314HWdTtWz7w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-10.2.4 54/61] qcow2: Fix corruption on discard during write with COW Date: Sat, 13 Jun 2026 23:03:37 +0300 Message-ID: <20260613200411.1808021-54-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381617021158500 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf Most code in qcow2 that accesses (and potentially modifies) L2 tables does so while holding s->lock. There is one exception, which is allocating writes. They hold the lock initially while allocating clusters, but drop it for writing the guest payload before taking the lock again for updating the L2 tables. This allows concurrent requests that touch other parts of the image file to continue in parallel and is an important performance optimisation. However, this means that other requests that run while the lock is dropped for writing guest data must synchronise with the list of allocating requests in s->cluster_allocs and wait if they would overlap. For writes, this is done in handle_dependencies(), but discard and write zeros operations neglect to synchronise with s->cluster_allocs. This means that discard can free a cluster whose L2 entry will already be modified in qcow2_alloc_cluster_link_l2() by a previously started write. In the case of a pre-allocated zero cluster that is in the process of being overwritten, this means that discard can lead to a situation where the cluster is still mapped (because the write will restore the L2 entry just without the zero flag), but its refcount has been decreased, resulting in a corrupted image. Add the missing synchronisation to qcow2_cluster_discard() and qcow2_subcluster_zeroize() to fix the problem. Cc: qemu-stable@nongnu.org Reported-by: Denis V. Lunev Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-4-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit b8bfb1478d61512f851badd0d912c6661a2efee7) Signed-off-by: Michael Tokarev diff --git a/block/qcow2-cluster.c b/block/qcow2-cluster.c index c655bf6df4..8b1e80bd0b 100644 --- a/block/qcow2-cluster.c +++ b/block/qcow2-cluster.c @@ -1392,6 +1392,9 @@ count_single_write_clusters(BlockDriverState *bs, int= nb_clusters, * the same cluster. In this case we need to wait until the previous * request has completed and updated the L2 table accordingly. * + * If allow_shortening =3D=3D true, instead of waiting for a dependency, *= cur_bytes + * can be shortened so that the cluster allocations don't overlap. + * * Returns: * 0 if there was no dependency. *cur_bytes indicates the number of * bytes from guest_offset that can be read before the next @@ -1403,7 +1406,9 @@ count_single_write_clusters(BlockDriverState *bs, int= nb_clusters, */ static int coroutine_fn handle_dependencies(BlockDriverState *bs, uint64_t guest_offset, - uint64_t *cur_bytes, QCowL2Met= a **m) + uint64_t *cur_bytes, + bool allow_shortening, + QCowL2Meta **m) { BDRVQcow2State *s =3D bs->opaque; QCowL2Meta *old_alloc; @@ -1434,7 +1439,7 @@ static int coroutine_fn handle_dependencies(BlockDriv= erState *bs, =20 /* Conflict */ =20 - if (start < old_start) { + if (start < old_start && allow_shortening) { /* Stop at the start of a running allocation */ bytes =3D old_start - start; } else { @@ -1469,6 +1474,29 @@ static int coroutine_fn handle_dependencies(BlockDri= verState *bs, return 0; } =20 +static void coroutine_mixed_fn wait_for_dependencies(BlockDriverState *bs, + uint64_t guest_offset, + uint64_t bytes) +{ + BDRVQcow2State *s =3D bs->opaque; + QCowL2Meta *m =3D NULL; + int ret; + + /* + * Discard has some non-coroutine callers (creating internal snapshots= and + * make empty). They are calling from qemu-img or in a drained section= , so + * we know that no writes can be in progress. + */ + if (!qemu_in_coroutine()) { + assert(QLIST_EMPTY(&s->cluster_allocs)); + return; + } + + do { + ret =3D handle_dependencies(bs, guest_offset, &bytes, false, &m); + } while (ret =3D=3D -EAGAIN); +} + /* * Checks how many already allocated clusters that don't require a new * allocation there are at the given guest_offset (up to *bytes). @@ -1840,7 +1868,7 @@ again: * the right synchronisation between the in-flight request= and * the new one. */ - ret =3D handle_dependencies(bs, start, &cur_bytes, m); + ret =3D handle_dependencies(bs, start, &cur_bytes, true, m); if (ret =3D=3D -EAGAIN) { /* Currently handle_dependencies() doesn't yield if we already= had * an allocation. If it did, we would have to clean up the L2M= eta @@ -2000,6 +2028,15 @@ int qcow2_cluster_discard(BlockDriverState *bs, uint= 64_t offset, int64_t cleared; int ret; =20 + /* + * If we're touching a cluster for which allocating writes are in flig= ht, + * wait for them to complete to avoid conflicting metadata updates. + * + * We don't need to allocate a QCowL2Meta for the discard operation be= cause + * s->lock is held for the duration of the whole operation. + */ + wait_for_dependencies(bs, offset, bytes); + /* Caller must pass aligned values, except at image end */ assert(QEMU_IS_ALIGNED(offset, s->cluster_size)); assert(QEMU_IS_ALIGNED(end_offset, s->cluster_size) || @@ -2160,6 +2197,15 @@ int coroutine_fn qcow2_subcluster_zeroize(BlockDrive= rState *bs, uint64_t offset, int64_t cleared; int ret; =20 + /* + * If we're touching a cluster for which allocating writes are in flig= ht, + * wait for them to complete to avoid conflicting metadata updates. + * + * We don't need to allocate a QCowL2Meta for the zeroize operation be= cause + * s->lock is held for the duration of the whole operation. + */ + wait_for_dependencies(bs, offset, bytes); + /* If we have to stay in sync with an external data file, zero out * s->data_file first. */ if (data_file_is_raw(bs)) { --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381405; cv=none; d=zohomail.com; s=zohoarc; b=FIGajtZLbkeJs9JZN06uoXaQUBzBDieb5efrHPjAjCtWaJWzKMEBsmyjqdLLeMKcHem44n2evsZA4XgBLSLmqC5i7nbVAVVGoJkytU4X9eYSvv+zNePiVAF5wWeeizzXfKL0Uo3Y2CIzKEVZm3Idax9viVC+bT9FrxZSYro5sNM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381405; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=t3bebmnC8aHOfy8MMBLbDFnLegLK3bhqmi9Ry6uHOB4=; b=gFj05zFmBox3yylZnVYhA+ZIPO9n8Gq+GZf93xI1/7CBKPQdrWGXoTIqhs3uW1exxEkr2RCv0fAtlWrHM4hWRRIoARfaq3A+AiBiEBhYpnNm8haAm7BxxJJdFlB5RYa7uJVq+xmN+L9OsQuGponVMPP31jXp/gP3WMwh6fnbD2U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138140567680.99846104994936; Sat, 13 Jun 2026 13:10:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUfz-0002Xe-HQ; Sat, 13 Jun 2026 16:09:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfu-000208-V4; Sat, 13 Jun 2026 16:09:51 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfr-00031m-07; Sat, 13 Jun 2026 16:09:49 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E2B411B6EA7; Sat, 13 Jun 2026 23:04:30 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 4BD6A3CE901; Sat, 13 Jun 2026 23:04:49 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381070; bh=NeizuiU9CNw1ZzTV6M1T2A/yYQYGEMCvWTUWZVtOwzs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=vSFGFoVgTSTrjY3K9nrE6jGcgHCWjEpY4W7Q3EGU3Wrcda8u66TfSktnONsdnnikZ Lnrw3YgoZZXkGOpna9kfr+U2yhzAgozpPQZaPMBzzC7b3A7Aff/6OPWsAJsFzPc5jU knCVH6szoG01X7DXbzQ9NZQcNjY3wBShajjhm4pczkZ2mFw/tGXnIPwxSQOORrP4mW S5cPg+K9RR3/qBLenRJis6Q0fkGYP0knmY2uM8Um0Ixw3XsFpwjODA5hbxE0+5+Ta4 hVfmk/0pCoIeYDx4596ZEEpmS0jGNFX0sVzQ2zblHRUffWcAGme5Upsma2hqMzbV/h 7rcR8HUjDbrUw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-10.2.4 55/61] iotests/046: Test that discard/write_zeroes wait for dependencies Date: Sat, 13 Jun 2026 23:03:38 +0300 Message-ID: <20260613200411.1808021-55-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381406133158500 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf This is a regression test for the bug fixed in the previous commit where discard and write_zeroes operations wouldn't consider their dependencies in s->cluster_allocs. Without the fix, this results in a corrupted image. Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-5-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit 389f5bcc744d3ddc127d550a57261aed9bbba1f3) Signed-off-by: Michael Tokarev diff --git a/tests/qemu-iotests/046 b/tests/qemu-iotests/046 index 4c9ed4d26e..e03dd40147 100755 --- a/tests/qemu-iotests/046 +++ b/tests/qemu-iotests/046 @@ -184,6 +184,48 @@ aio_write -P 160 0x104000 0x18000 resume A aio_flush EOF + +# Create a pre-allocated zero cluster, then start a write on it and discar= d it +# before the L2 update is made +cat < Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381537506557.964798586094; Sat, 13 Jun 2026 13:12:17 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUg2-0002vD-Ie; Sat, 13 Jun 2026 16:09:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfx-0002Hc-4l; Sat, 13 Jun 2026 16:09:53 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfu-00032W-Lt; Sat, 13 Jun 2026 16:09:52 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id F37AD1B6EA8; Sat, 13 Jun 2026 23:04:30 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 5BFBF3CE902; Sat, 13 Jun 2026 23:04:49 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381070; bh=JUAG6zDGYDxsWTGyZzH6MYTmtGx38FdR5L48dR4p0Ss=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=D2C3YqRYkUv5JnjcWHCkSwSj3rbJPmDiv10nohnxvYrYEdpP3ezWgEvf/buRK4GvS XjQ+A957vCfmh18F0qEb+OfbBf2Rw7R7uATbFdKFI3Vdg/crJUoxBqH/RbYwLJzRGA r5jIGKIme4QVczPmcajX8ZBy58A5gDp90xZvx5AtjROFvQ9JQR8Nq8oW51JYQemn/N DRp8aYuyKxDtyG8PkodZ3EiUIxDRPG8LiYPVFdUlDv4omHuCzn8H7Zbg4FdACed56f IpOlo2ZZ30IxH/rrtdWkSMoIBpyITyuC/Tq9Fe2eIvSn2Rq279ohka5uPKpelsgTZe RjjbHJ+MI5SWA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Thomas Lamprecht , Fiona Ebner , Kevin Wolf , Michael Tokarev Subject: [Stable-10.2.4 56/61] qcow2: Fix data loss on zero write with detect-zeroes=unmap Date: Sat, 13 Jun 2026 23:03:39 +0300 Message-ID: <20260613200411.1808021-56-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381538686158500 Content-Type: text/plain; charset="utf-8" From: Thomas Lamprecht Commit b8bfb1478d ("qcow2: Fix corruption on discard during write with COW") added a wait_for_dependencies() at the start of qcow2_subcluster_zeroize(). That fixes the inconsistency it set out to fix, but turns the lock-protected pre-check in the caller, qcow2_co_pwrite_zeroes(), into a stale one: the wait yields s->lock, so an in-flight allocating write whose QCowL2Meta is already on s->cluster_allocs (but whose L2 entry is not yet linked) gets to link its entry during the yield. When the zeroize wakes, the cluster is now NORMAL, and with BDRV_REQ_MAY_UNMAP the free path in zero_in_l2_slice() unmaps the just-written cluster, silently dropping the data write's payload. This is reachable with detect-zeroes=3Dunmap (the default for VirtIO disks with discard on in Proxmox VE), under which the block layer auto-promotes all-zero buffers to BDRV_REQ_ZERO_WRITE | BDRV_REQ_MAY_UNMAP. A memory-constrained Debian guest running 'apt full-upgrade' on such a disk reproduces it as random SIGSEGVs: swapped-out code pages come back as zero. Wait for in-flight dependencies before the lock-protected check in qcow2_co_pwrite_zeroes(). If a write linked its L2 entry during the wait, the type check now fails and the block layer falls back to a bounce-buffered zero write that only touches the requested subrange, preserving the racing write's data. Promote wait_for_dependencies() to qcow2_wait_for_dependencies() so qcow2.c can call it. Fixes: b8bfb1478d ("qcow2: Fix corruption on discard during write with COW") Fixes: d85e00dd03 ("qcow2: Fix corruption on discard during write with COW"= ) in 10.2.x series Cc: qemu-stable@nongnu.org Tested-by: Fiona Ebner Reviewed-by: Fiona Ebner Signed-off-by: Thomas Lamprecht Message-ID: <20260522151318.238064-1-t.lamprecht@proxmox.com> [kwolf: Reverted unnecessary change to 'nr' assignment] Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit 1d47eb68983577a4e06fe1c165d90e128b191b86) Signed-off-by: Michael Tokarev diff --git a/block/qcow2-cluster.c b/block/qcow2-cluster.c index 8b1e80bd0b..e02fae6a0c 100644 --- a/block/qcow2-cluster.c +++ b/block/qcow2-cluster.c @@ -1474,9 +1474,9 @@ static int coroutine_fn handle_dependencies(BlockDriv= erState *bs, return 0; } =20 -static void coroutine_mixed_fn wait_for_dependencies(BlockDriverState *bs, - uint64_t guest_offset, - uint64_t bytes) +void coroutine_mixed_fn qcow2_wait_for_dependencies(BlockDriverState *bs, + uint64_t guest_offset, + uint64_t bytes) { BDRVQcow2State *s =3D bs->opaque; QCowL2Meta *m =3D NULL; @@ -2035,7 +2035,7 @@ int qcow2_cluster_discard(BlockDriverState *bs, uint6= 4_t offset, * We don't need to allocate a QCowL2Meta for the discard operation be= cause * s->lock is held for the duration of the whole operation. */ - wait_for_dependencies(bs, offset, bytes); + qcow2_wait_for_dependencies(bs, offset, bytes); =20 /* Caller must pass aligned values, except at image end */ assert(QEMU_IS_ALIGNED(offset, s->cluster_size)); @@ -2204,7 +2204,7 @@ int coroutine_fn qcow2_subcluster_zeroize(BlockDriver= State *bs, uint64_t offset, * We don't need to allocate a QCowL2Meta for the zeroize operation be= cause * s->lock is held for the duration of the whole operation. */ - wait_for_dependencies(bs, offset, bytes); + qcow2_wait_for_dependencies(bs, offset, bytes); =20 /* If we have to stay in sync with an external data file, zero out * s->data_file first. */ diff --git a/block/qcow2.c b/block/qcow2.c index e29810d86a..fe628d4d27 100644 --- a/block/qcow2.c +++ b/block/qcow2.c @@ -4177,10 +4177,16 @@ qcow2_co_pwrite_zeroes(BlockDriverState *bs, int64_= t offset, int64_t bytes, } =20 qemu_co_mutex_lock(&s->lock); - /* We can have new write after previous check */ offset -=3D head; bytes =3D s->subcluster_size; nr =3D s->subcluster_size; + /* + * Wait for in-flight allocating writes first: otherwise the type + * check below could pass on UNALLOCATED while a yet-to-link_l2 wr= ite + * completes during qcow2_subcluster_zeroize()'s own wait, letting= the + * resumed MAY_UNMAP discard the just-written data. + */ + qcow2_wait_for_dependencies(bs, offset, bytes); ret =3D qcow2_get_host_offset(bs, offset, &nr, &off, &type); if (ret < 0 || (type !=3D QCOW2_SUBCLUSTER_UNALLOCATED_PLAIN && diff --git a/block/qcow2.h b/block/qcow2.h index 96db7c51ec..d831808bf7 100644 --- a/block/qcow2.h +++ b/block/qcow2.h @@ -965,6 +965,10 @@ int coroutine_fn GRAPH_RDLOCK qcow2_subcluster_zeroize(BlockDriverState *bs, uint64_t offset, uint64_t b= ytes, int flags); =20 +void coroutine_mixed_fn +qcow2_wait_for_dependencies(BlockDriverState *bs, uint64_t guest_offset, + uint64_t bytes); + int GRAPH_RDLOCK qcow2_expand_zero_clusters(BlockDriverState *bs, BlockDriverAmendStatusCB *status_cb, diff --git a/tests/qemu-iotests/046 b/tests/qemu-iotests/046 index e03dd40147..0d84b5c1c7 100755 --- a/tests/qemu-iotests/046 +++ b/tests/qemu-iotests/046 @@ -226,6 +226,26 @@ aio_write -z 0x140000 0x10000 resume A aio_flush EOF + +# Start an allocating write to a previously unallocated cluster and, before +# its L2 update is linked, issue a concurrent sub-cluster zero write with +# MAY_UNMAP that targets a disjoint range within the same cluster. The zero +# write's head/tail are zero (cluster is unallocated), so qcow2_co_pwrite_= zeroes +# would expand it to the full subcluster. Without waiting for dependencies +# before the zero write's "unallocated" type check, that check passes, +# qcow2_subcluster_zeroize then yields in wait_for_dependencies, the alloc= ating +# write links its L2 entry, and the resumed zeroize unmaps the cluster - +# silently discarding the just-written data. Waiting first makes the zero = write +# fall back to a bounce-buffered real write, which only touches its own +# subrange. +cat < Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381511393801.5614949822731; Sat, 13 Jun 2026 13:11:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUg2-0002sy-8x; Sat, 13 Jun 2026 16:09:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfz-0002RZ-1P; Sat, 13 Jun 2026 16:09:55 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUfw-00033D-Qe; Sat, 13 Jun 2026 16:09:54 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 1038A1B6EA9; Sat, 13 Jun 2026 23:04:31 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6C7153CE903; Sat, 13 Jun 2026 23:04:49 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381071; bh=sfQCC5CgFR1Bz1gV5P/NZ8E4hv3um15ceX7Klvs2YNc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ktL3pmfew1Lm+GjXVZ+jHUp7tqrnq5/pIJxMeni1tavEXQqKgA0vCLzmPF7CFZkJ7 x5Df9+ASRNWyC3gLr7Vv3gWkKDhFh9ughuV+SsBkvZxyg98C/WzWWGWK3rbR5bj6t7 tQ/ZiJqHLIcEJTrXlAcPVx4tedhHQ/Rv6XsprmNeM6QluutFe0UwBZZ8daUYE/E2DP U8hobSMGqdBNq4vdGyc+bZa4lzBZnRruO7jcGYKpe+ziVqM86NFJRPWqnaMwHUvCgn VInoQzQDDFCTQmHmEyp9BU5Bf2nj9oFgzIaWgQUCY4L3oaTu71LnVMSjrhTqCttNQE enyVoqNRH17Pg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fabiano Rosas , Stefan Hajnoczi , Kevin Wolf , Michael Tokarev Subject: [Stable-10.2.4 57/61] qed: Don't try to flush during incoming migration Date: Sat, 13 Jun 2026 23:03:40 +0300 Message-ID: <20260613200411.1808021-57-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381512566158500 Content-Type: text/plain; charset="utf-8" From: Fabiano Rosas It's not possible to access the image file while there is an incoming migration in progress, the QEMU process doesn't hold any locks to the storage at this point so nodes are inactive. Attempting to flush leads to an assert at bdrv_co_write_req_prepare(): assert(!(bs->open_flags & BDRV_O_INACTIVE)) The issue is reproducible by running iotest 181 on a host under cpu load. The migration must coincide with the header already containing the QED_F_NEED_CHECK flag. The sequence of events is as follows, with the respective call stacks referenced below: During block device init, bdrv_qed_attach_aio_context() starts the 'need_check' timer. The timer will not fire during incoming migration as it uses QEMU_CLOCK_VIRTUAL (to avoid this very issue, as the code comment indicates). (0) However, there's still bdrv_qed_drain_begin() which uses the fact that the timer is live to decide whether to start the qed_need_check_timer_entry() directly. (1) The qed_need_check_timer_entry() eventually calls into qed_write_header() -> bdrv_co_pwrite() leading to the assert. (2) Skip creating the 'need_check' timer whenever the image is inactive. The stacks: (0) =3D=3D issues timer_mod =3D=3D #6 in qed_start_need_check_timer at ../block/qed.c:340 #7 in bdrv_qed_attach_aio_context at ../block/qed.c:373 #8 in bdrv_qed_do_open at ../block/qed.c:556 #9 in bdrv_qed_open_entry at ../block/qed.c:582 #10 in coroutine_trampoline at ../util/coroutine-ucontext.c:175 #0 in qemu_coroutine_switch<+120> at ../util/coroutine-ucontext.c:321 #1 in qemu_aio_coroutine_enter<+356> at ../util/qemu-coroutine.c:293 #2 in aio_co_enter<+179> at ../util/async.c:710 #3 in aio_co_wake<+53> at ../util/async.c:695 #4 in thread_pool_co_cb<+47> at ../util/thread-pool.c:283 #5 in thread_pool_completion_bh<+241> at ../util/thread-pool.c:202 #6 in aio_bh_call<+109> at ../util/async.c:173 #7 in aio_bh_poll<+299> at ../util/async.c:220 #8 in aio_poll<+690> at ../util/aio-posix.c:745 #9 in bdrv_qed_open<+392> at ../block/qed.c:607 #10 in bdrv_open_driver<+327> at ../block.c:1678 #11 in bdrv_open_common<+1619> at ../block.c:2008 #12 in bdrv_open_inherit<+2556> at ../block.c:4191 #13 in bdrv_open<+118> at ../block.c:4286 #14 in blk_new_open<+199> at ../block/block-backend.c:458 #15 in blockdev_init<+2011> at ../blockdev.c:612 #16 in drive_new<+3008> at ../blockdev.c:1008 #17 in drive_init_func<+51> at ../system/vl.c:662 #18 in qemu_opts_foreach<+227> at ../util/qemu-option.c:1148 #19 in configure_blockdev<+350> at ../system/vl.c:721 #20 in qemu_create_early_backends<+343> at ../system/vl.c:2076 #21 in qemu_init<+12483> at ../system/vl.c:3778 #22 in main<+46> at ../system/main.c:71 (1) =3D=3D sees timer_pending =3D=3D #6 in bdrv_qed_drain_begin at ../block/qed.c:391 #7 in bdrv_do_drained_begin at ../block/io.c:366 #8 in bdrv_do_drained_begin_quiesce at ../block/io.c:386 #9 in bdrv_child_cb_drained_begin at ../block.c:1207 #10 in bdrv_parent_drained_begin_single at ../block/io.c:133 #11 in bdrv_parent_drained_begin at ../block/io.c:64 #12 in bdrv_do_drained_begin at ../block/io.c:364 #13 in bdrv_drained_begin at ../block/io.c:393 #14 in blk_drain at ../block/block-backend.c:2101 #15 in blk_unref at ../block/block-backend.c:544 #16 in bdrv_open_inherit at ../block.c:4197 #17 in bdrv_open at ../block.c:4286 #18 in blk_new_open at ../block/block-backend.c:458 #19 in blockdev_init at ../blockdev.c:612 #20 in drive_new at ../blockdev.c:1008 #21 in drive_init_func at ../system/vl.c:662 #22 in qemu_opts_foreach at ../util/qemu-option.c:1148 #23 in configure_blockdev at ../system/vl.c:721 #24 in qemu_create_early_backends at ../system/vl.c:2076 #25 in qemu_init at ../system/vl.c:3778 #26 in main at ../system/main.c:71 (2) =3D=3D crashes =3D=3D #5 in __assert_fail (assertion=3D"!(bs->open_flags & BDRV_O_INACTIVE)", f= ile=3D"../block/io.c", line=3D1977 #6 in bdrv_co_write_req_prepare at ../block/io.c:1977 #7 in bdrv_aligned_pwritev at ../block/io.c:2099 #8 in bdrv_co_pwritev_part at ../block/io.c:2316 #9 in bdrv_co_pwritev at ../block/io.c:2233 #10 in bdrv_co_pwrite at ../include/block/block_int-io.h:77 #11 in qed_write_header at ../block/qed.c:128 #12 in qed_need_check_timer at ../block/qed.c:305 #13 in qed_need_check_timer_entry at ../block/qed.c:319 Note that this issue is not exactly the same as what's been reported in Gitlab, but given how easily this reproduces, I imagine it has to be happening in that setup as well. Link: https://gitlab.com/qemu-project/qemu/-/work_items/3515 Signed-off-by: Fabiano Rosas Message-ID: <20260603193813.2327596-1-farosas@suse.de> Reviewed-by: Stefan Hajnoczi Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit 7e573b660fefdebd21cb755d0d34bb5942fd3af3) Signed-off-by: Michael Tokarev diff --git a/block/qed.c b/block/qed.c index da23a83d62..0eccfa21c9 100644 --- a/block/qed.c +++ b/block/qed.c @@ -351,16 +351,22 @@ static void bdrv_qed_detach_aio_context(BlockDriverSt= ate *bs) { BDRVQEDState *s =3D bs->opaque; =20 - qed_cancel_need_check_timer(s); - timer_free(s->need_check_timer); - s->need_check_timer =3D NULL; + if (s->need_check_timer) { + qed_cancel_need_check_timer(s); + timer_free(s->need_check_timer); + s->need_check_timer =3D NULL; + } } =20 -static void bdrv_qed_attach_aio_context(BlockDriverState *bs, - AioContext *new_context) +static void GRAPH_RDLOCK bdrv_qed_attach_aio_context(BlockDriverState *bs, + AioContext *new_conte= xt) { BDRVQEDState *s =3D bs->opaque; =20 + if (bdrv_is_inactive(bs)) { + return; + } + s->need_check_timer =3D aio_timer_new(new_context, QEMU_CLOCK_VIRTUAL, SCALE_NS, qed_need_check_timer_cb, s); --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381471; cv=none; d=zohomail.com; s=zohoarc; b=ljY1yHg7T/4hfiDSijuuZPMj2klQZySXzg5EUDADyvi1tq7DVXDIEWqWWEsl3KSs/8ST8+BcLPDffe5gmMHNEfa0TInvXiVQxva5H4cit8bxD3RoUm3KGNHi1+BlF++Wkmg52O8meXZdrzVCrKssw7bOCMDj8IgyHAhLxxbu76M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381471; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3u3qaIeN6Dqj56XNwlwgZkNzpymvlq0lHUuune3hiJM=; b=VGG6U2k2qaqor02YdRuMh64DhyDqJt3dsIWDq1i87j3NJJMP6ia0x4nF6CMewqdi9zG9LbEEHeLP+X2xh+uNMCN2RvrnkpW1hQkF2fel4YI5s6f4wozvyGpLy0d/l3gO7dDoBwI4ODPxI/yiakxSE778nNJJV8+439Bw8ekM8bM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381471741892.7553076747735; Sat, 13 Jun 2026 13:11:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUgT-0004Mk-1A; Sat, 13 Jun 2026 16:10:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUgK-0004HW-V6; Sat, 13 Jun 2026 16:10:17 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUgJ-00033t-3S; Sat, 13 Jun 2026 16:10:16 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 291A21B6EAA; Sat, 13 Jun 2026 23:04:31 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7CE6F3CE904; Sat, 13 Jun 2026 23:04:49 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381071; bh=AAH7Sf+1DjyfLt1oV2PXB7mUXaVH9euBh2Fe44O6az4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=q6l0sF2vEUom7EFenWXNJoewa0JlWDJD5ufW9TGGmshCtfv9C1Rs0JlLhQu2cNdX9 T91dQTHD5ybx8rIIYYjV38riWtCoc2J98n0HiyhHdnUBnynEG6IJCbZiYhIHEdLSkZ /QarCxJ+E+CfjJwSDtl6Q6guRty6mMKXQqCm+z7pnV9aRW+7UoBtVdrw9ywK9YnQyi AXksGe8yPmGqPi5/dMsj+FPpv3Uv57or/bpub3JWjNhqFHV1jxxyc514yzVGpApENw tkCTnO9hdPw1cB4M8pJKI7vvmPCCMFnnLdf0LzLKLfhCoeHgbzgtGFOM5tQpWjvA2r 1RsgbyzykCtCQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Munkhbaatar Enkhbaatar , Peter Maydell , Michael Tokarev Subject: [Stable-10.2.4 58/61] hw/usb/hcd-ohci: Clean up USBPacket before freeing ISO TD packet Date: Sat, 13 Jun 2026 23:03:41 +0300 Message-ID: <20260613200411.1808021-58-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381472329158500 Content-Type: text/plain; charset="utf-8" From: Munkhbaatar Enkhbaatar ohci_service_iso_td() allocates a USBPacket and frees it after synchronous completion, but it does not call usb_packet_cleanup() first. Call usb_packet_cleanup() before g_free() so resources owned by USBPacket are released. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3463 Signed-off-by: Munkhbaatar Enkhbaatar Reviewed-by: Peter Maydell Signed-off-by: Peter Maydell (cherry picked from commit 163f9a4e0651b3b4a1438d919489a200d3646ba3) Signed-off-by: Michael Tokarev diff --git a/hw/usb/hcd-ohci.c b/hw/usb/hcd-ohci.c index 15406c51f6..51b3adf52f 100644 --- a/hw/usb/hcd-ohci.c +++ b/hw/usb/hcd-ohci.c @@ -756,6 +756,7 @@ static int ohci_service_iso_td(OHCIState *ohci, struct = ohci_ed *ed) } else { ret =3D pkt->status; } + usb_packet_cleanup(pkt); g_free(pkt); =20 trace_usb_ohci_iso_td_so(start_offset, end_offset, start_addr, end_add= r, --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381475; cv=none; d=zohomail.com; s=zohoarc; b=fniplH5rP9bzJKvSk5peIJ13yzWLni4SBWB5yHZEDl/ILhaMi7IFmnf3rHFo5iN46do6IS9EyVnQQZ5Wx1b1JECA0EH5/GeZwncXmgGpl3dOBq8+FKEiljtlhhMFBk9ZS70occ60YI+NpsocDbMC5qS6OR5mnhmGvOgXDaLyJ38= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381475; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ch2Bs40jxZGDLOTWA3Zytgv39gJ7D+TgEV67AwoQz64=; b=nXWJ8j/3v4MR5AorsTuqGx3p6DsOy1Zi7azFhNC1kgVkkWvjrBdoEvnJFzH1xet9wD1iWflGvVCemrXeHuIzPVW0LW8k1PT/WAn0lkbILQGafqu1Rnmm7nQjpxw1v8l+xvYVUnCofKQbob8AqEqNNs2x+iDgqmmhdeIsp1i0qDM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381475076633.543209267255; Sat, 13 Jun 2026 13:11:15 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUgU-0004c3-Ma; Sat, 13 Jun 2026 16:10:26 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUgM-0004Im-Qt; Sat, 13 Jun 2026 16:10:18 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUgK-000359-WA; Sat, 13 Jun 2026 16:10:18 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 44B0D1B6EAB; Sat, 13 Jun 2026 23:04:31 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 966253CE905; Sat, 13 Jun 2026 23:04:49 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381071; bh=74FjXEQfqoGSiytNTqpkUThHlv28JADau+k5i8/mkWc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=gsOWJZfPHTfKZRylSGfRmr23Fo72Ent5ilXUoMk872lrIE2uiU/NcamBBvwPcdhOV t9kEUAAZ6wCqaQuxSWqudKzJlxhew9f9zl1fYgPYabDuCh4xcmX1D/tJqVo1xWTQ6n RQA1xhYgD/yVJYgxq1DXfT9yHaIvn2qtv77ejJWEDKI7CPVUNPGNZleFvBFSBebYjF V21rA3i3hYxHAOv7prThQaNTEqlzGeyf5ggoBZmBxaFkDSTW1+5Pe80uyvLqLSO6n0 9E/IBJ66K2ndV5H1NgvA1dpbkAt5qAr8/bjfCDbGwD+CWCMhrPid9P8rrQ+hjVi0tW 4pwdVmD4I5npQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richard Henderson , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.2.4 59/61] fpu: Handle all rounding modes in partsN_uncanon_normal Date: Sat, 13 Jun 2026 23:03:42 +0300 Message-ID: <20260613200411.1808021-59-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381476352158500 From: Richard Henderson Missed float_round_nearest_even_max when recomputing round. CC: qemu-stable@nongnu.org Fixes: 72330260cdb ("softfloat: Add float_round_nearest_even_max") Reported-by: Peter Maydell Signed-off-by: Richard Henderson Reviewed-by: Peter Maydell Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-id: 20260608190155.637067-2-richard.henderson@linaro.org Signed-off-by: Peter Maydell (cherry picked from commit a6a1f92d5a2368882e9b6851b6ab8b9a56d71a8c) Signed-off-by: Michael Tokarev diff --git a/fpu/softfloat-parts.c.inc b/fpu/softfloat-parts.c.inc index 5e0438fc0b..6bbea3d138 100644 --- a/fpu/softfloat-parts.c.inc +++ b/fpu/softfloat-parts.c.inc @@ -375,6 +375,7 @@ static void partsN(uncanon_normal)(FloatPartsN *p, floa= t_status *s, /* Need to recompute round-to-even/round-to-odd. */ switch (s->float_rounding_mode) { case float_round_nearest_even: + case float_round_nearest_even_max: if (N > 64 && frac_lsb =3D=3D 0) { inc =3D ((p->frac_hi & 1) || (p->frac_lo & round_mask) !=3D frac_lsbm1 --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381507; cv=none; d=zohomail.com; s=zohoarc; b=ayppaI8xa1yGQCUN7NvyEYebwP5v3ASn/kK4i/kidf3HF2uI8fLHgtq4GCe1bs5JKZivZYEq9pc8MSXbQlt5Vu/QRZrs0u1c50zblbynn2zA46kAm/D9D3NkyivLldUWBm9N4P6aFrDiMXUFXSZb4wVJ3G7AJz1aAWmLvpxLOwY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381507; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=g+yh9pHVjdRTukQknxOIygXkJOo73MwL6n2k46s7Fuk=; b=ncs01r6y5yugn8gpyjWkjgVxOiVw4ZFZOxDqGnniqPDphaGFNr0HhcJ4oV0uBZf1Ibe6kdduFJcobzT+e1niNAkXelSB/5NFgoCRqDNl/H2nHadV0UUA687wjrB4PiOa3b7Qvl7HPjulxLQ9hL6mYi+ir/sOlm32SsgJHh8VBXc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381507144719.5271711068197; Sat, 13 Jun 2026 13:11:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUgT-0004WJ-W0; Sat, 13 Jun 2026 16:10:26 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUgO-0004Jg-QS; Sat, 13 Jun 2026 16:10:21 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUgM-0003LV-Rt; Sat, 13 Jun 2026 16:10:20 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 572071B6EAC; Sat, 13 Jun 2026 23:04:31 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B1E133CE906; Sat, 13 Jun 2026 23:04:49 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381071; bh=c16rLqR84hExouEMXIa7sqFr1xa8jV1tLlpzpgH7I0U=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ZjkFJiz7cZ7+NhaFxaIsypYx4nPR/YTZzgSKFTJqUFWE88pVtSMwIdPN825cnUHOn 8Fpx5K5b3TocHlz3Er6FaNTr5WbeaAhnw+BN0U5DQ53o8YUkPBDd4sMV6taE/BU+Vo HLR7wiUK3ibiYqA6KZkMkZTP4kYJ81xSJimnJr7yvGqMeBxQ+OZFK8MWlEECZY+xSO 2E+KJBiXiU8kt9giDGSJcDyRRmsW0TbMOm1eEwfKf+IDtSW8i4qXUiyK7sUV2bFyGn rCBRxKdO1wkdSraxbfA5mQs+suiNPDSMi7GibkrxHyW83ucFQIeJK1iFp7jlDHSRmF KxMz/vuVuDrkQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Xinhui Yang , Pierrick Bouvier , Helge Deller , Michael Tokarev Subject: [Stable-10.2.4 60/61] linux-user: implement fsmount(2) series of syscalls Date: Sat, 13 Jun 2026 23:03:43 +0300 Message-ID: <20260613200411.1808021-60-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381508552158500 Content-Type: text/plain; charset="utf-8" From: Xinhui Yang This series of syscalls replaces the old mount(2) syscall with a series of syscalls that operates around a filesystem context. This series of syscalls is available since Linux 5.2 and glibc 2.36+. Their users include systemd since v259 and libmount from util-linux, and possibly other widely used projects. Preliminary checks are implemented to ensure the validity of the interface. v2: Add syscall wrappers in case the build machine does not support the fsmount() syscalls. (added by Helge Deller) Signed-off-by: Xinhui Yang Reviewed-by: Pierrick Bouvier Signed-off-by: Helge Deller (cherry picked from commit 767c32fe69834344bf71f4071ff33292cd46f626) Signed-off-by: Michael Tokarev diff --git a/linux-user/syscall.c b/linux-user/syscall.c index 5c101c19e4..d8c920bcff 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -9658,6 +9658,19 @@ _syscall5(int, sys_move_mount, int, __from_dfd, cons= t char *, __from_pathname, int, __to_dfd, const char *, __to_pathname, unsigned int, flag) #endif =20 +#if defined(TARGET_NR_fsopen) && defined(NR_fsopen) +#define __NR_sys_fsopen __NR_fsopen +_syscall2(int, sys_fsopen, const char *, fs_name, unsigned int, flags); +#define __NR_sys_fsconfig __NR_fsconfig +_syscall5(int, sys_fsconfig, int, fs_fd, unsigned int, cmd, const char *, = key, + const void *, value, int, aux) +#define __NR_sys_fsmount __NR_fsmount +_syscall3(int, sys_fsmount, int, fs_fd, unsigned int, flags, + unsigned int, ms_flags) +#define __NR_sys_fspick __NR_fspick +_syscall3(int, sys_fspick, int, dfd, const char *, path, unsigned int, fla= gs) +#endif + /* This is an internal helper for do_syscall so that it is easier * to have a single return point, so that actions, such as logging * of syscall results, can be performed. @@ -14349,6 +14362,97 @@ static abi_long do_syscall1(CPUArchState *cpu_env,= int num, abi_long arg1, return do_map_shadow_stack(cpu_env, arg1, arg2, arg3); #endif =20 +#if defined(TARGET_NR_fsopen) && defined(NR_fsopen) + case TARGET_NR_fsopen: + { + p =3D lock_user_string(arg1); + if (!p) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsopen(p, arg2)); + unlock_user(p, arg1, 0); + } + return ret; + case TARGET_NR_fsconfig: + { + /* + * fsconfig(int, int, char *, void *, int) + * NOTE: p4 is nullable and its type might not be a string. + */ + void *p3, *p4; + int cmd =3D (int) arg2; + switch (cmd) { + case FSCONFIG_SET_BINARY: + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + p3 =3D lock_user_string(arg3); + if (!p3) { + return -TARGET_EFAULT; + } + if (cmd !=3D FSCONFIG_SET_BINARY) { + /* key and value must be strings. */ + p4 =3D lock_user_string(arg4); + } else { + /* + * Otherwise the value must be a raw buffer with its + * length specified in arg5 (aux). + */ + p4 =3D lock_user(VERIFY_READ, arg4, arg5, 1); + } + if (!p4) { + unlock_user(p3, arg3, 0); + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, p3, p4, arg5)); + unlock_user(p3, arg3, 0); + unlock_user(p4, arg4, 0); + break; + + case FSCONFIG_SET_FLAG: + case FSCONFIG_SET_FD: + /* arg4 (value) must be NULL. */ + if (arg4) { + return -TARGET_EFAULT; + } + p3 =3D lock_user_string(arg3); + if (!p3) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, p3, NULL, arg5)= ); + unlock_user(p3, arg3, 0); + break; + case FSCONFIG_CMD_CREATE: + case FSCONFIG_CMD_RECONFIGURE: +#ifdef FSCONFIG_CMD_CREATE_EXCL + /* + * FSCONFIG_CMD_CREATE_EXCL is only available since Linux + * 6.6. Guarding it to allow building with pre-6.6 headers. + */ + case FSCONFIG_CMD_CREATE_EXCL: +#endif + /* key and value must be NULL, aux must be 0. */ + if (arg3 || arg4 || arg5) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, NULL, NULL, 0)); + break; + default: + return -TARGET_EFAULT; + } + } + return ret; + case TARGET_NR_fsmount: + ret =3D get_errno(sys_fsmount(arg1, arg2, arg3)); + return ret; + case TARGET_NR_fspick: + { + p =3D lock_user_string(arg2); + ret =3D get_errno(sys_fspick(arg1, p, arg3)); + unlock_user(p, arg2, 0); + } + return ret; +#endif default: qemu_log_mask(LOG_UNIMP, "Unsupported syscall: %d\n", num); return -TARGET_ENOSYS; --=20 2.47.3 From nobody Sun Jul 26 13:30:10 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781381532; cv=none; d=zohomail.com; s=zohoarc; b=nBdDsZaVsjF6653+KQtvaZXl5ch4bUTBe2IO1cFrVFfZZLh2uCUGU8NmzV4ssC25HlGMe0ow82DQkBVhMnPWDJvuCV5bTuntEAJ9hCK/eRP/59mhi3tr/u5bnKqzB+sUqHv7xnHw0S2YgDCzf5rSZo9ClpkMK0oC20a4nCE/GBI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781381532; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=qUWEPC49K90WFYJt6m73SlQ3XVhTSC7jLEgvIC1/P2c=; b=B0C5Z4mutKpwnMPJ0Jw+WgsxYZYNCq2KZTbi7CmsUagEoTjVLjR9603uVyZNYilVbB3hp7FAPXySXl+eJctsouW/Wp50BbOXdWWgYy7g+dEWyzj4XZj7C7wME0hlS0G8TyV/jnNJm15xNkiGKrJjuo4d0EuT4SmN7bdKq9S8hmI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781381532007363.7412151169045; Sat, 13 Jun 2026 13:12:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYUgW-0004s3-Lp; Sat, 13 Jun 2026 16:10:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUgQ-0004MH-Gc; Sat, 13 Jun 2026 16:10:22 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYUgO-0003Ll-G6; Sat, 13 Jun 2026 16:10:22 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 67A371B6EAD; Sat, 13 Jun 2026 23:04:31 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C47973CE907; Sat, 13 Jun 2026 23:04:49 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781381071; bh=/PcraITcXSEaBbY3ER/QY3XcfJVX8eCLy6SI3U2uqIQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=urvbwj8F3cwbsnbuBHzXXfPRhw7g+68nZHB6hjtiVmfE88gLBZ9g30VuwifGO8ReN l4fLTPij6ofjtz0PNERrGbz3GB+2OqM1sWN6Lg3S6uY7s6QsCts0trV2rTut980Ubl ypbFjTXMu6Ca9ybMU4QZc2znlMkM/YPw6fzGcPsgg6vrr7Ndkr4+cz1VhdX5EpkX5h G0X1aHpOVs3MOhA6mgCWkFKbTZiwmha+jqgUIOTRhKU0sXYcsZxNiN5N0b5nQnQPdn 39Vwzy9UmuO9kieILiClLmpCmhDPsj+ytDa0DK/EqMuTof6kVTRUE3xMqFNj3+Y0UT OX84L1A70ulnQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Xinhui Yang , Pierrick Bouvier , Helge Deller , Michael Tokarev Subject: [Stable-10.2.4 61/61] linux-user/strace: add fsmount series of syscalls Date: Sat, 13 Jun 2026 23:03:44 +0300 Message-ID: <20260613200411.1808021-61-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781381532622158500 Content-Type: text/plain; charset="utf-8" From: Xinhui Yang Following the addition of fsmount(2) series of syscalls in the syscall handler, strace support is added, with a dedicated function to print the parameters of fsconfig(2), which contains parameters that can be interpreted as multiple types. Snippet of the strace dump when running `mount -t tmpfs tmpfs /media`: 18 fsopen(tmpfs,1) =3D 3 18 read(3,0x407fcf1c,8191) =3D -1 errno=3D61 (No data available) 18 fsconfig(3,FSCONFIG_SET_STRING,"source","tmpfs",0) =3D 0 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 fsconfig(3,FSCONFIG_CMD_CREATE,NULL,NULL,0) =3D 0 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 fsmount(3,1,0) =3D 4 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 statx(4,"",AT_EMPTY_PATH|AT_STATX_SYNC_AS_STAT,0x1000,0x407fee98) =3D 0 18 move_mount(4,,-100,/media,4) =3D 0 18 read(3,0x407fcfcc,8191) =3D -1 errno=3D61 (No data available) 18 close(3) =3D 0 18 close(4) =3D 0 v2: Fixed build on RHEL9 due to missing syscalls (Helge) Signed-off-by: Xinhui Yang Reviewed-by: Pierrick Bouvier Signed-off-by: Helge Deller (cherry picked from commit 6e0aa9f6c731df3f8d1071cfd5ec63fe7b923713) Signed-off-by: Michael Tokarev diff --git a/linux-user/strace.c b/linux-user/strace.c index 18bc6c800c..96d4ce4aa9 100644 --- a/linux-user/strace.c +++ b/linux-user/strace.c @@ -4318,6 +4318,111 @@ print_statx(CPUArchState *cpu_env, const struct sys= callname *name, } #endif =20 +#if defined(TARGET_NR_fsconfig) && defined(NR_fsconfig) +static void +print_fsconfig_cmd_name(int cmd) +{ + switch (cmd) { + case FSCONFIG_SET_FLAG: + qemu_log("%s%s", "FSCONFIG_SET_FLAG", get_comma(0)); + break; + case FSCONFIG_SET_STRING: + qemu_log("%s%s", "FSCONFIG_SET_STRING", get_comma(0)); + break; + case FSCONFIG_SET_BINARY: + qemu_log("%s%s", "FSCONFIG_SET_BINARY", get_comma(0)); + break; + case FSCONFIG_SET_PATH: + qemu_log("%s%s", "FSCONFIG_SET_PATH", get_comma(0)); + break; + case FSCONFIG_SET_PATH_EMPTY: + qemu_log("%s%s", "FSCONFIG_SET_PATH_EMPTY", get_comma(0)); + break; + case FSCONFIG_SET_FD: + qemu_log("%s%s", "FSCONFIG_SET_FD", get_comma(0)); + break; + case FSCONFIG_CMD_CREATE: + qemu_log("%s%s", "FSCONFIG_CMD_CREATE", get_comma(0)); + break; + case FSCONFIG_CMD_RECONFIGURE: + qemu_log("%s%s", "FSCONFIG_CMD_RECONFIGURE", get_comma(0)); + break; +#ifdef FSCONFIG_CMD_CREATE_EXCL + case FSCONFIG_CMD_CREATE_EXCL: + /* Only available since Linux 6.6. */ + qemu_log("%s%s", "FSCONFIG_CMD_CREATE_EXCL", get_comma(0)); + break; +#endif + default: + qemu_log("%s (%d)%s", "UNKNOWN_CMD", cmd, get_comma(0)); + break; + } +} + +static void +print_fsconfig(CPUArchState *cpu_env, const struct syscallname *name, + abi_long arg0, abi_long arg1, abi_long arg2, + abi_long arg3, abi_long arg4, abi_long arg5) +{ + /* + * fsconfig(int fd, int cmd, char* key, void* value, int aux) + * Where: + * fd: file descriptor returned by fsopen(). + * cmd: integer constant specifying a command. + * key: a string, can be NULL on certain commands. + * value: any data in a buffer, can be NULL, raw buffer or a string. + * aux: axillary values such as flags for FSCONFIG_SET_PATH. + */ + int cmd =3D (int) arg1; + print_syscall_prologue(name); + print_raw_param("%d", arg0, 0); + print_fsconfig_cmd_name(cmd); + /* Process arg2 (key). */ + switch (cmd) { + case FSCONFIG_SET_FLAG: + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_BINARY: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + case FSCONFIG_SET_FD: + print_string(arg2, 0); + break; + default: + print_pointer(arg2, 0); + break; + } + /* Process arg3 (value). */ + switch (cmd) { + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + print_string(arg3, 0); + break; + default: + print_pointer(arg3, 0); + break; + } + /* + * Process arg4 (aux). + * On FSCONFIG_SET_PATH and FSCONFIG_SET_PATH_EMPTY, aux can + * be either 0 or AT_FDCWD. + * On FSCONFIG_SET_BINARY, aux is an integer to state the length + * of the buffer pointed by arg3. + * Otherwise, it must be 0. + */ + switch (cmd) { + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + print_at_dirfd(arg4, 1); + break; + default: + print_raw_param("%d", arg4, 1); + break; + } + print_syscall_epilogue(name); +} +#endif + #ifdef TARGET_NR_ioctl static void print_ioctl(CPUArchState *cpu_env, const struct syscallname *name, diff --git a/linux-user/strace.list b/linux-user/strace.list index eb1a414004..6a5b27d4ac 100644 --- a/linux-user/strace.list +++ b/linux-user/strace.list @@ -1722,3 +1722,18 @@ #ifdef TARGET_NR_rseq { TARGET_NR_rseq, "rseq" , "%s(%p,%u,%d,%#x)", NULL, NULL }, #endif +#ifdef TARGET_NR_fsopen +{ TARGET_NR_fsopen, "fsopen", "%s(%s,%d)", NULL, NULL }, +#endif +#if defined(TARGET_NR_fsconfig) && defined(NR_fsconfig) +{ TARGET_NR_fsconfig, "fsconfig", NULL, print_fsconfig, NULL }, +#endif +#ifdef TARGET_NR_fsmount +{ TARGET_NR_fsmount, "fsmount", "%s(%d,%d,%d)", NULL, NULL }, +#endif +#ifdef TARGET_NR_move_mount +{ TARGET_NR_move_mount, "move_mount", "%s(%d,%s,%d,%s,%d)", NULL, NULL }, +#endif +#ifdef TARGET_NR_fspick +{ TARGET_NR_fspick, "fspick", "%s(%d,%s,%d)", NULL, NULL }, +#endif --=20 2.47.3