From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383106; cv=none; d=zohomail.com; s=zohoarc; b=BQb0+GawwSiNJA5kB1O9Ad0xYXBKDrRpmSlIkKR+qG+9HpUT40qsqpDTq6JAhSsPB0WE04aKBz3dwOMtZkRtVB99cDRg2JqYpWVlP6LcSYZKQvGjWj7SrU4sdgh12ssF/ZpN6/FYMvga2aQfrZxmGytlThWfA6rTq6EeDUeRLHo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383106; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yHRf+bmo/i+DJ2Gq684jxsdIlfgq4gkPQEZA+Pp1OO4=; b=m5iA+idna9LVDn7QSCjCBQHMAhos4UEZ86Jpp+B2eiJtqUG50O7o+GBtQscvIRWALxsIT3t+b7p52rKUucWwx5CEzbm9TKS1ay149BmtEEN6pTP283T6ONyOlKu/L3MFnBKtPvSGPzuyPD+Gx3UF4v1qKsfh9Tmgm/mUmFp3kes= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383106720771.9186186447727; Sat, 13 Jun 2026 13:38:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV5t-0001W6-2j; Sat, 13 Jun 2026 16:36:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5l-0001Og-Pl; Sat, 13 Jun 2026 16:36:35 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5h-000398-FA; Sat, 13 Jun 2026 16:36:32 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 5F12D1B6EDB; Sat, 13 Jun 2026 23:36:02 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C59A53CE92D; Sat, 13 Jun 2026 23:36:20 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382962; bh=sIl/tdh7IsN9ArdeDKreQuQNxHNbY82eRu4BG+AwbgQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=kJhtb8M6HZIPj3GHvrxFptpkUTGhgMbKeqPSo92/YGMsgcSXFSfWarQSWm1a8p0gC Y5yoJeChv5bvv1r6n/uOjdvQckLbKEyAc8ewu8jYORp+JkMlPSSxbNbBtpWTBFY4IG CK8Lejzq2j+tQuAVoOXpbMFfGgr4tBAUkybLJdY9feVfgIXo466b1MotIN56r2pfFk Am+04UMG2fHQ41kf06qEexbmdZ74tO4xmkzq3gJ+9MT1484b+QMhipHKqRF3vLwpEK BhiUIng83bJLH4dSm+iDpd4WXzpoGh4e/LWABR+nkoabNNI6UuYY6SILea4lee5W9M 1UzSMAQ//wRxg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , "Maciej S. Szmigiero" , Michael Tokarev Subject: [Stable-11.0.2 01/72] crypto: fix client side anonymous TLS credentials Date: Sat, 13 Jun 2026 23:34:27 +0300 Message-ID: <20260613203542.1809153-1-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383107471158500 From: Daniel P. Berrang=C3=A9 The previous refactoring of credential creation failed to allocate storage fo the anonymous TLS credentials on the client endpoint. Fixes: 70f9fd8dbf7233bee497055a9b7825e3729ce853 Reported-by: Maciej S. Szmigiero Signed-off-by: Daniel P. Berrang=C3=A9 (cherry picked from commit 27b127d7348a922ef91ce607776407407f9c2a3e) Signed-off-by: Michael Tokarev diff --git a/crypto/tlscredsanon.c b/crypto/tlscredsanon.c index 1551382e1f..190c9833a7 100644 --- a/crypto/tlscredsanon.c +++ b/crypto/tlscredsanon.c @@ -73,6 +73,8 @@ qcrypto_tls_creds_anon_load(QCryptoTLSCredsAnon *creds, box->dh_params); } } else { + box =3D qcrypto_tls_creds_box_new_client(GNUTLS_CRD_ANON); + ret =3D gnutls_anon_allocate_client_credentials(&box->data.anoncli= ent); if (ret < 0) { error_setg(errp, "Cannot allocate credentials: %s", diff --git a/tests/unit/test-crypto-tlssession.c b/tests/unit/test-crypto-t= lssession.c index 0d06a6892e..dc7a01bb06 100644 --- a/tests/unit/test-crypto-tlssession.c +++ b/tests/unit/test-crypto-tlssession.c @@ -24,6 +24,7 @@ #include "crypto-tls-psk-helpers.h" #include "crypto/tlscredsx509.h" #include "crypto/tlscredspsk.h" +#include "crypto/tlscredsanon.h" #include "crypto/tlssession.h" #include "qom/object_interfaces.h" #include "qapi/error.h" @@ -190,6 +191,121 @@ static void test_crypto_tls_session_psk(void) } =20 =20 +static QCryptoTLSCreds *test_tls_creds_anon_create( + QCryptoTLSCredsEndpoint endpoint) +{ + Object *parent =3D object_get_objects_root(); + Object *creds =3D object_new_with_props( + TYPE_QCRYPTO_TLS_CREDS_ANON, + parent, + (endpoint =3D=3D QCRYPTO_TLS_CREDS_ENDPOINT_SERVER ? + "testtlscredsserver" : "testtlscredsclient"), + &error_abort, + "endpoint", (endpoint =3D=3D QCRYPTO_TLS_CREDS_ENDPOINT_SERVER ? + "server" : "client"), + "priority", "NORMAL", + NULL + ); + return QCRYPTO_TLS_CREDS(creds); +} + + +static void test_crypto_tls_session_anon(void) +{ + QCryptoTLSCreds *clientCreds; + QCryptoTLSCreds *serverCreds; + QCryptoTLSSession *clientSess =3D NULL; + QCryptoTLSSession *serverSess =3D NULL; + int channel[2]; + bool clientShake =3D false; + bool serverShake =3D false; + int ret; + + /* We'll use this for our fake client-server connection */ + ret =3D qemu_socketpair(AF_UNIX, SOCK_STREAM, 0, channel); + g_assert(ret =3D=3D 0); + + /* + * We have an evil loop to do the handshake in a single + * thread, so we need these non-blocking to avoid deadlock + * of ourselves + */ + qemu_set_blocking(channel[0], false, &error_abort); + qemu_set_blocking(channel[1], false, &error_abort); + + clientCreds =3D test_tls_creds_anon_create( + QCRYPTO_TLS_CREDS_ENDPOINT_CLIENT); + g_assert(clientCreds !=3D NULL); + + serverCreds =3D test_tls_creds_anon_create( + QCRYPTO_TLS_CREDS_ENDPOINT_SERVER); + g_assert(serverCreds !=3D NULL); + + /* Now the real part of the test, setup the sessions */ + clientSess =3D qcrypto_tls_session_new( + clientCreds, NULL, NULL, + QCRYPTO_TLS_CREDS_ENDPOINT_CLIENT, &error_abort); + g_assert(clientSess !=3D NULL); + + serverSess =3D qcrypto_tls_session_new( + serverCreds, NULL, NULL, + QCRYPTO_TLS_CREDS_ENDPOINT_SERVER, &error_abort); + g_assert(serverSess !=3D NULL); + + /* For handshake to work, we need to set the I/O callbacks + * to read/write over the socketpair + */ + qcrypto_tls_session_set_callbacks(serverSess, + testWrite, testRead, + &channel[0]); + qcrypto_tls_session_set_callbacks(clientSess, + testWrite, testRead, + &channel[1]); + + /* + * Finally we loop around & around doing handshake on each + * session until we get an error, or the handshake completes. + * This relies on the socketpair being nonblocking to avoid + * deadlocking ourselves upon handshake + */ + do { + int rv; + if (!serverShake) { + rv =3D qcrypto_tls_session_handshake(serverSess, + &error_abort); + g_assert(rv >=3D 0); + if (rv =3D=3D QCRYPTO_TLS_HANDSHAKE_COMPLETE) { + serverShake =3D true; + } + } + if (!clientShake) { + rv =3D qcrypto_tls_session_handshake(clientSess, + &error_abort); + g_assert(rv >=3D 0); + if (rv =3D=3D QCRYPTO_TLS_HANDSHAKE_COMPLETE) { + clientShake =3D true; + } + } + } while (!clientShake || !serverShake); + + + /* Finally make sure the server & client validation is successful. */ + g_assert(qcrypto_tls_session_check_credentials(serverSess, + &error_abort) =3D=3D 0); + g_assert(qcrypto_tls_session_check_credentials(clientSess, + &error_abort) =3D=3D 0); + + object_unparent(OBJECT(serverCreds)); + object_unparent(OBJECT(clientCreds)); + + qcrypto_tls_session_free(serverSess); + qcrypto_tls_session_free(clientSess); + + close(channel[0]); + close(channel[1]); +} + + struct QCryptoTLSSessionTestData { const char *servercacrt; const char *clientcacrt; @@ -421,9 +537,11 @@ int main(int argc, char **argv) test_tls_init(KEYFILE); test_tls_psk_init(PSKFILE); =20 - /* Simple initial test using Pre-Shared Keys. */ + /* Simple initial tests using Pre-Shared Keys & anon creds */ g_test_add_func("/qcrypto/tlssession/psk", test_crypto_tls_session_psk); + g_test_add_func("/qcrypto/tlssession/anon", + test_crypto_tls_session_anon); =20 /* More complex tests using X.509 certificates. */ # define TEST_SESS_REG(name, caCrt, \ --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383011; cv=none; d=zohomail.com; s=zohoarc; b=YoSJhMO/iP94KqmQln87EM2yKVF33+tXMAMtcSG6dNt5QZsCQs8UroKsGwoYQEx57TNvPfgq+fHUcLzaC4cTDH8MdUYjF+g5fR1BjAIjn5V2RssdhVJbra+3UIupFF+GP25yzPHOQ1w9DTGA9mh0ySTbPs+2n5XiOXjPHzVgGvc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383011; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ewAhXTeSCf5dYK5UwmxQgVBXYrxBDhyrOyifKt+Stl4=; b=Jh1BK/EywCLa78imEXYPJkjP2bioLDWA26pFkKjy82WYX+9IF2ywS/b2Zv9J7A9B+k1cZredWIG4Xf3G7lyKZ/05ognxxeDjzV9tD4Ds7JTejIAv4njG3t6DgaO3Jw148MKQHvI6a36VFo17cOftOTHF9h8B1F/euNWugsTnK9E= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383011913588.0321827426401; Sat, 13 Jun 2026 13:36:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV5q-0001Tj-G2; Sat, 13 Jun 2026 16:36:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5l-0001OU-P3; Sat, 13 Jun 2026 16:36:35 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5h-00039B-DZ; Sat, 13 Jun 2026 16:36:30 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 712AC1B6EDC; Sat, 13 Jun 2026 23:36:02 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D6D803CE92E; Sat, 13 Jun 2026 23:36:20 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382962; bh=ruH2hkT0kSahVJDVkJVWgjKgRpyoHENjlyJWh/U7KsQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=FesZH91FsLWovD1yWFxoKFyqz1GMlmq+2dLSlrQJEQxe2AhHl0qLsh9tH2Sg09HWI Cp4S8MnZL39vbHyVzBPI+HeG5r51FrOGaE+QWzG1co8ieemdJZq+0gdzX4DYyZB8XL UVc0pcXA9GCh3z1Mkq672TS+IWpX2lToXsBImHhHm2Wi5hpJ5hBdcz0NdgZz6zvPTJ PHFOQb35AAIH7hOs8ifTe2DYXUOFYESMb2S+6+yChW8/Y8PPq9p+exfRMVE9lwrl2C D39KMsbEfb6FwGC1I/9x9t5rlNfllZt0RTO3uLwAtMETOIWRjUcBbOdcKPypbe+/SS 1jKAbunAEq0Yg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Max Chou , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 02/72] target/riscv: Update MISA.C for Zc* extensions Date: Sat, 13 Jun 2026 23:34:28 +0300 Message-ID: <20260613203542.1809153-2-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383012913158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang MISA.C is set if the following extensions are selected: * Zca and not F. * Zca, Zcf and F (but not D) is specified (RV32 only). * Zca, Zcf and Zcd if D is specified (RV32 only). * Zca, Zcd if D is specified (RV64 only). Therefore, MISA.C must be set according to the Zc* extension rules. Warn the user if RVC is explicitly disabled but MISA.C is required by the rules above. Signed-off-by: Frank Chang Reviewed-by: Max Chou Reviewed-by: Alistair Francis Message-ID: <20260424050509.3935180-2-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit f0433a8bc4ac5626499ff09ba5d165dbf7a4a980) Signed-off-by: Michael Tokarev diff --git a/target/riscv/tcg/tcg-cpu.c b/target/riscv/tcg/tcg-cpu.c index 988b2d905f..800b7dce5d 100644 --- a/target/riscv/tcg/tcg-cpu.c +++ b/target/riscv/tcg/tcg-cpu.c @@ -1150,6 +1150,44 @@ static void riscv_cpu_enable_implied_rules(RISCVCPU = *cpu) } } =20 +/* + * MISA.C is set if the following extensions are selected: + * - Zca and not F. + * - Zca, Zcf and F (but not D) is specified on RV32. + * - Zca, Zcf and Zcd if D is specified on RV32. + * - Zca, Zcd if D is specified on RV64. + */ +static void riscv_cpu_update_misa_c(RISCVCPU *cpu) +{ + CPURISCVState *env =3D &cpu->env; + bool set_misa_c =3D false; + + if (riscv_has_ext(env, RVC)) { + return; + } + + if (cpu->cfg.ext_zca && !riscv_has_ext(env, RVF)) { + set_misa_c =3D true; + } else if (riscv_cpu_mxl(env) =3D=3D MXL_RV32 && + cpu->cfg.ext_zca && cpu->cfg.ext_zcf && + (riscv_has_ext(env, RVD) ? cpu->cfg.ext_zcd : + riscv_has_ext(env, RVF))) { + set_misa_c =3D true; + } else if (riscv_cpu_mxl(env) =3D=3D MXL_RV64 && + cpu->cfg.ext_zca && cpu->cfg.ext_zcd) { + set_misa_c =3D true; + } + + if (set_misa_c) { + if (cpu_misa_ext_is_user_set(RVC)) { + warn_report("RVC mandated by Zca/Zcf/Zcd extensions"); + return; + } + + riscv_cpu_set_misa_ext(env, env->misa_ext | RVC); + } +} + void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, Error **errp) { CPURISCVState *env =3D &cpu->env; @@ -1157,6 +1195,7 @@ void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, E= rror **errp) =20 riscv_cpu_init_implied_exts_rules(); riscv_cpu_enable_implied_rules(cpu); + riscv_cpu_update_misa_c(cpu); =20 riscv_cpu_validate_misa_priv(env, &local_err); if (local_err !=3D NULL) { --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383152; cv=none; d=zohomail.com; s=zohoarc; b=iX1v+/7pu2kVEIT/ZXdmBG+KeOebGJld8JdLQFx0HSbs9REJIgwZNDbqsEoUNHZ83YbflAi+7rnfsJ7xlOdRnMZzQtGE4sRQBWfTilWJpgP2Ex7ByJlkkz4kSel1jnmub6dLVMsiQO4X0UudFckmXTMpAH68xvKEdqUIBTIXtcY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383152; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=TjaHev/Y+EfoaRW7QetxRsXNnbz8zRhbGITqt/bYlKc=; b=PaI1wJcOkiox0bWYJzWUZJo42jH5RdUWi2o3ZurW9v4TLwUQDpyzU7daOCYkawgjJlR9ntSrxe+qM4miB+KUnv+Lp8fv8nj5tjFyK0FzG1zX8P+ELPeb6wmrs8tjFgI8rrEUSdY3hzg5rydSkMWrQbB2i271GAoKCDJKVjcK3Pk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383152037386.8160682103801; Sat, 13 Jun 2026 13:39:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV60-0001ZH-DG; Sat, 13 Jun 2026 16:36:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5q-0001Ud-8M; Sat, 13 Jun 2026 16:36:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5n-0003B1-6w; Sat, 13 Jun 2026 16:36:37 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 8432C1B6EDD; Sat, 13 Jun 2026 23:36:02 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E905A3CE92F; Sat, 13 Jun 2026 23:36:20 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382962; bh=rsMHcXMYMMN7Tj2tvLEWxPX3ekn7XpT0o/qUhhvEK6Q=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=RMyHE17KAS6PwDuvWOEIVGsP3pacqIEVvuiUNX37HFt7vYtOXS8yolw18pr3ljoAa 9owaqLB0P/vra7KGATk18LU6STKEjfWahWk9jmQZZmua0G/yZtdJ3RAlR2dWrm4LL3 MvrTvhWdWMk1t1SOOP+7QWFo+HRKfQFygd3+6eyb33Xy4SN+A9einOXrwWtivD7dNS WRLMjucLG/PM7Ywrg3NL/MM2tzdalRqSEtAi3gDcFOMWm6tvR0x9stBV4gjcRAEabq FxC6fPdto0wC3B7BiDNuV/icCt8Y8lksO70Hc5xUkYyK1npHBkLcSRCy9I9JHB+FgB St2pzqop5AUqA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Max Chou , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 03/72] target/riscv: Update MISA.X for non-standard extensions Date: Sat, 13 Jun 2026 23:34:29 +0300 Message-ID: <20260613203542.1809153-3-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383153482158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang MISA.X is set if there are any non-standard extensions. We should set MISA.X when any of the vendor extensions is enabled. Signed-off-by: Frank Chang Reviewed-by: Max Chou Reviewed-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260424050509.3935180-3-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit 613bb1949fffc4aeb9e554e35fecc7d6f7ddd27b) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu.h b/target/riscv/cpu.h index 35d1f6362c..a6adf6efc6 100644 --- a/target/riscv/cpu.h +++ b/target/riscv/cpu.h @@ -69,6 +69,7 @@ typedef struct CPUArchState CPURISCVState; #define RVH RV('H') #define RVG RV('G') #define RVB RV('B') +#define RVX RV('X') =20 extern const uint32_t misa_bits[]; const char *riscv_get_misa_ext_name(uint32_t bit); diff --git a/target/riscv/tcg/tcg-cpu.c b/target/riscv/tcg/tcg-cpu.c index 800b7dce5d..c5505414ae 100644 --- a/target/riscv/tcg/tcg-cpu.c +++ b/target/riscv/tcg/tcg-cpu.c @@ -1188,6 +1188,20 @@ static void riscv_cpu_update_misa_c(RISCVCPU *cpu) } } =20 +/* MISA.X is set when any of the non-standard extensions is enabled. */ +static void riscv_cpu_update_misa_x(RISCVCPU *cpu) +{ + CPURISCVState *env =3D &cpu->env; + const RISCVCPUMultiExtConfig *arr =3D riscv_cpu_vendor_exts; + + for (int i =3D 0; arr[i].name !=3D NULL; i++) { + if (isa_ext_is_enabled(cpu, arr[i].offset)) { + riscv_cpu_set_misa_ext(env, env->misa_ext | RVX); + break; + } + } +} + void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, Error **errp) { CPURISCVState *env =3D &cpu->env; @@ -1196,6 +1210,7 @@ void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, E= rror **errp) riscv_cpu_init_implied_exts_rules(); riscv_cpu_enable_implied_rules(cpu); riscv_cpu_update_misa_c(cpu); + riscv_cpu_update_misa_x(cpu); =20 riscv_cpu_validate_misa_priv(env, &local_err); if (local_err !=3D NULL) { --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383120; cv=none; d=zohomail.com; s=zohoarc; b=Cqpsa/N8xFyNFxJ8mTFKwUJRhB3117Hw1OlKzd4lfMFes1lcP+KrCdOV9Gdv1jJw55WJf4vLsFasyhxs+rmMDH6paV9/GUKVTFrLiwtcmGC4CS21ouE4OOql1W7hh9PHYcmIg6F7rBUYHEE9b7dUGNQPs6++rjY/epzLQkVFi0M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383120; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=zVGoTtCWroKBy0DiSa/4XhoQIjB6LurM5lWqN1tUVGw=; b=NyCvq71EM6fbuc9fT2fjZTP/m4DiFkmcVltjUTUlr5jJUtfEYeTza4NnN8Xl/dYZaV9Xw109Mn5L7Q8SGxWDx9dQDtgMZ/jPr3hfsaCimXYy8OVl/MGJlk0V5EE9a7E4PnvgMLndrpRLajhng6z1NycNyM50QPDXcva8HiLqfwQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383120851810.5923722881947; Sat, 13 Jun 2026 13:38:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV5w-0001YP-JQ; Sat, 13 Jun 2026 16:36:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5p-0001SZ-2H; Sat, 13 Jun 2026 16:36:37 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5n-0003B2-6i; Sat, 13 Jun 2026 16:36:36 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9907C1B6EDE; Sat, 13 Jun 2026 23:36:02 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 07DBD3CE930; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382962; bh=qLusf94cp14bL3s613kWiuKwXIw/4+Fsc+S5U4dxtmA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=HNxwjqYDNKgQf1TEqqz4qL/39QZqGFnqaD0FjPQYmlCv2U2M6HsWAf0+Lbg7R5k8/ ogUBPOeO95HjvtN7D5fHZaLvkXS3eGV9NMR0EOl43NsyCZkq4F7U6iLZ+szWVpFtVm ZF+tMKJmisKW0TpONPJ1Lu+pQMrdzAhPIkPhn5yvgXcI6crMMoButl8ak9HaMkqDAo 6IX3hXeO/mHjqCoVAmjOnd9SImoXbqqQemplDCRNLiU/r7ceLdi2zojHUDqd72hQvZ 9acJdCIyvacFZ0ZyPUQ29GFY8gnA9BgalLEPROUQFANdcYlst5iuqCMIFJS2n5y3g6 a/llRPycvakzA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Andrew Jones , Daniel Henrique Barboza , Nutty Liu , Tomasz Jeznach , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 04/72] hw/riscv/riscv-iommu: Fix Svnapot 64KB pages Date: Sat, 13 Jun 2026 23:34:30 +0300 Message-ID: <20260613203542.1809153-4-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383121271158500 Content-Type: text/plain; charset="utf-8" From: Andrew Jones The Svnapot extension encodes a 64KB leaf PTE by setting PTE_N and storing bits [3:0] of the PPN as a NAPOT size indicator. The IOMMU model wasn't checking PTE_N and therefore was using the raw (NAPOT- encoded) PPN directly in the physical address, yielding an address 32 KB above the correct base. Fix both riscv_iommu_spa_fetch() and pdt_memory_read() by mirroring the Svnapot handling already present in target/riscv/cpu_helper.c: napot_bits =3D ctz64(ppn) + 1 /* 4 for 64KB */ napot_mask =3D (1 << napot_bits) - 1 /* 0xF */ phys_base =3D PPN_PHYS(ppn & ~napot_mask) page_offset =3D addr & (PPN_PHYS(napot_mask) | (TARGET_PAGE_SIZE - 1)) The spec only defines napot_bits =3D=3D 4 (64KB); any other value is treated as a reserved encoding. This is a fix, rather than new feature support, because the spec says "IOMMU implementations must support the Svnapot standard extension for NAPOT Translation Contiguity." Fixes: 0c54acb8243d ("hw/riscv: add RISC-V IOMMU base emulation") Cc: qemu-stable@nongnu.org Signed-off-by: Andrew Jones Reviewed-by: Daniel Henrique Barboza Reviewed-by: Nutty Liu Reviewed-by: Tomasz Jeznach Message-ID: <20260508205129.377032-1-andrew.jones@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit fcbd93e96be2ed0e5139542f54be31efa6d2b1dc) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index c3c9ed6469..917a969081 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -237,6 +237,25 @@ static bool riscv_iommu_msi_check(RISCVIOMMUState *s, = RISCVIOMMUContext *ctx, return true; } =20 +/* Returns the NAPOT page mask, or 0 for reserved encodings. */ +static hwaddr riscv_iommu_napot_page_mask(hwaddr ppn, hwaddr addr, hwaddr = *out) +{ + int napot_bits =3D ctz64(ppn) + 1; + hwaddr napot_mask, page_mask; + + /* The spec only defines 64KB (napot_bits =3D=3D 4) */ + if (napot_bits !=3D 4) { + return 0; + } + + napot_mask =3D (1ULL << napot_bits) - 1; + page_mask =3D PPN_PHYS(napot_mask) | (TARGET_PAGE_SIZE - 1); + + *out =3D PPN_PHYS(ppn & ~napot_mask) | (addr & page_mask); + + return page_mask; +} + /* * RISCV IOMMU Address Translation Lookup - Page Table Walk * @@ -458,9 +477,20 @@ static int riscv_iommu_spa_fetch(RISCVIOMMUState *s, R= ISCVIOMMUContext *ctx, } else { /* Leaf PTE, translation completed. */ sc[pass].step =3D sc[pass].levels; - base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); - /* Update address mask based on smallest translation granulari= ty */ - iotlb->addr_mask &=3D (1ULL << va_skip) - 1; + + if (pte & PTE_N) { + hwaddr mask =3D riscv_iommu_napot_page_mask(ppn, addr, &ba= se); + + if (!mask) { + break; + } + iotlb->addr_mask &=3D mask; + } else { + base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + /* Update address mask based on smallest translation granu= larity */ + iotlb->addr_mask &=3D (1ULL << va_skip) - 1; + } + /* Continue with S-Stage translation? */ if (pass && sc[0].step !=3D sc[0].levels) { pass =3D S_STAGE; @@ -997,7 +1027,13 @@ static MemTxResult pdt_memory_read(RISCVIOMMUState *s, return MEMTX_ACCESS_ERROR; /* Misaligned PPN */ } else { /* Leaf PTE, translation completed. */ - base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + if (pte & PTE_N) { + if (!riscv_iommu_napot_page_mask(ppn, addr, &base)) { + return MEMTX_ACCESS_ERROR; + } + } else { + base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + } break; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383412; cv=none; d=zohomail.com; s=zohoarc; b=Mg0DavptpiVfhO/XFrsKJDIH7Nat7JgFzWvYf3kq+iXfyRlND01euiq7sOBTdHb41aki/0cItTOKLPNe2SsY2Pid/0miwrJ3QMuMQ+Hh8Nm/iRTbI3bf47i6sLe1BVqoTAMp1cGuOxYGQmtLpwR7PeFDBeBdHh3zgi/6Kzbktg8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383412; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=2b+g9SLUsxSVaeE8lDIdekpOIZT2llZuUAvsDin+GUM=; b=E57Tacv+od2oSKHwBNIZ7rbgvlVM5ogSh0sGVw7G6+I0ApbqexPiHocKE4QvA7ObEKMUknTn3g6wTrXxe0RuXlbkbvDQDCE3ixK5lZ2nxJOP9MvsFHfkvhW4N8D8L6zihht7ozHQ1/s47nbPuF7PCb4pDi1XXHO6uEy/+C32+cU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138341211557.69781645026228; Sat, 13 Jun 2026 13:43:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV5y-0001Z2-E1; Sat, 13 Jun 2026 16:36:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5t-0001WK-22; Sat, 13 Jun 2026 16:36:41 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5q-0003D5-In; Sat, 13 Jun 2026 16:36:40 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id AC0891B6EDF; Sat, 13 Jun 2026 23:36:02 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1CDE33CE931; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382962; bh=RRilm8J/FA34uAbj7pNEW/b/xFYBDEIAPFSEmcy+wOg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=icNRQL3WGh8mtYBzCljROb/csD1RgpgrJQ1IzVLKoy2Ypt6yZcJnyRtqcGBUAUdy+ 841u8laXK2LZTCbzVJzK5Q0DxnqienrdwiobeD6rPQhxgnq9lGbQZGfDtrtP2uicCP ULEa/4t9atD7LtBGuXTlcP+RLUUTpunlmo2dIIfKy/WeUboNDgdldWLCXqFYWKfArO zK4UlYInYA84ZEKF+X4aGIA2wWd94WqV+d33V756il4oORWsPOR4paDXmbg7pidc12 TSMF8Q48eSAdnbdzTCNoHml4QvvEUwI1v5jaCP+YYyDb+NdQeVSwzwbjahAajJH08v DDPNURWhpT1ng== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Chao Liu , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 05/72] target/riscv: Allow mseccfg access based on ext_zicfilp Date: Sat, 13 Jun 2026 23:34:31 +0300 Message-ID: <20260613203542.1809153-5-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383414194158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi The Zicfilp extension adds the MLPE field to the mseccfg CSR. According to the RISC-V Privileged Specification, mseccfg exists if any extension that adds a field to it is implemented. Currently, the `have_mseccfg()` predicate function checks for Smepmp, Zkr, and Smmpm, but misses Zicfilp. As a result, if a CPU is configured with `zicfilp=3Dtrue` but without the other extensions, accessing the mseccfg CSR will incorrectly raise an illegal instruction exception. This patch adds the missing check for `ext_zicfilp` to ensure the CSR is properly accessible when the Zicfilp extension is enabled. This issue was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-isa-m= anual/pr-2561/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Chao Liu Reviewed-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260511072705.3015986-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 249483623242c1b9ad4a1600083bea534620917a) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 29dd596ae4..51e668b46d 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -770,6 +770,9 @@ static RISCVException have_mseccfg(CPURISCVState *env, = int csrno) if (riscv_cpu_cfg(env)->ext_smmpm) { return RISCV_EXCP_NONE; } + if (riscv_cpu_cfg(env)->ext_zicfilp) { + return RISCV_EXCP_NONE; + } =20 return RISCV_EXCP_ILLEGAL_INST; } --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383160; cv=none; d=zohomail.com; s=zohoarc; b=k0wT9CdIzfwlaxseWhSppj28HqqB1/FED0itNKAEGPO0mb9HEAL/L5/I9o0VrBwqpNU1k+QDv6PuQ2YdpL+SQ+1EX2QrJU1F/N9tbxSlvHJWFm5APXKUb0e6joGrMbMcE8LeCyTIdCoLrvGrCmBN9OsDlGazluEU224lai0YaiY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383160; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VFa35nHRyANSJ/jW5W6xpj1HGEbyCNXlX90bNbDtFZI=; b=U5V1r7egxXiVxBxSLDzF/kX2yDcG93t5wJXevz9FZL2oa/+DLLlWlvYsZO4B4sPP1C64gFjrpJqrkx5ovzc3FvzMK3hoYREyIr94ypyuG0VUylJglcZaxihdWueZojx9jMu4lA+9u5tyxmVL/6Stmd/qt8nq4qxyo4YgUIJe5qo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383160603553.1501378343506; Sat, 13 Jun 2026 13:39:20 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV62-0001aK-Q1; Sat, 13 Jun 2026 16:36:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5u-0001Xl-TC; Sat, 13 Jun 2026 16:36:42 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5r-0003DR-NH; Sat, 13 Jun 2026 16:36:41 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BB06C1B6EE0; Sat, 13 Jun 2026 23:36:02 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 2F51D3CE932; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382962; bh=nmmnp3npEHERyKVMs7WdQEpW4jB59+5sjKmOfypT4CE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=CJ1if3FUZkdjWjOKiRamL2v0pSqXogrSqjsTSWUnvg+mv1dH2jR6MkvABjMB/nXtq E2Wvx3EwepHty+cIdau+EwwT+rrnLld5k85Uj/kbG00XCkbQoMXESh8P9oL+Gt8JPS eNVUJTL8bm3Z8rXm+Sh/4mPsLkSAdF9qtVvTv2pv5EGAH2QH+SUJYXrtCljJNoNE8M szr3nXRqdVnfyw0oH96Au1urFj3e+tNrxQg3AlM8jAs37L4GhQ6qMctOIyriBzzcJT I9VUm8ZOvxh3mSIjq2+SoTajsqk49TitUdvVY5mICWY88f6GElOPh+YeVktP2OpcJq RgKoeTLt0czng== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Anton Blanchard , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 06/72] target/riscv: rvv: Handle source overlap of vector widening reduction instructions Date: Sat, 13 Jun 2026 23:34:32 +0300 Message-ID: <20260613203542.1809153-6-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383161462158500 Content-Type: text/plain; charset="utf-8" From: Anton Blanchard Widening reductions read vs2 as a vector of SEW elements and vs1[0] as a scalar of 2*SEW. The ISA does not allow the same vector register to be read with different EEWs, so they must not overlap. vs1 is read as a scalar from element 0, so it is treated as a single vector register (independent of LMUL) when checking overlap. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3208 Signed-off-by: Anton Blanchard Acked-by: Alistair Francis Message-ID: <20260417080328.31918-1-antonb@tenstorrent.com> Signed-off-by: Alistair Francis (cherry picked from commit caf3bef5f01e85b8bbd24e1851b50616fa03a5bb) Signed-off-by: Michael Tokarev diff --git a/target/riscv/insn_trans/trans_rvv.c.inc b/target/riscv/insn_tr= ans/trans_rvv.c.inc index 4df9a40b44..d9a0027e0b 100644 --- a/target/riscv/insn_trans/trans_rvv.c.inc +++ b/target/riscv/insn_trans/trans_rvv.c.inc @@ -3062,6 +3062,7 @@ GEN_OPIVV_TRANS(vredxor_vs, reduction_check) static bool reduction_widen_check(DisasContext *s, arg_rmrr *a) { return reduction_check(s, a) && (s->sew < MO_64) && + !is_overlapped(a->rs1, 1, a->rs2, 1 << MAX(s->lmul, 0)) && ((s->sew + 1) <=3D (s->cfg_ptr->elen >> 4)); } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383303; cv=none; d=zohomail.com; s=zohoarc; b=ByKVUe5Uu2I9yo6r9A/qqvIBKAS7dZz/8D3togTJN+QYm3Ah8BxKR0sjicsAYgcSVGQgwMWVJxDVkH44HLvwNRBZWa3MfBBcuauzWsq9ZLqr65VI0fuoNKVpVZFrZivOoPDW/Bl7LEHsv9IE7OHH1kTvFWVhIgKFoe3WXif0p9E= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383303; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yLPBWjyAAPA5p9AnKtORONEjaqs5zrJJxLmnbbschaA=; b=T/72pnjrbosmZFMj32yREkNonR9YsFt9cT5bbLMJSio+h0KpB0ykv6QtEz0nacLs1NMwn7+I/sES/kVkvCL1+6y+BGCqsBXK69AXBkDVJ1RK9kbY9yYYgBxhJ87+/tDiaDJoy67G0oRzFLlkmFo1tHwaupkTZ1cKXKLxuZ5Qnh4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383303836623.2573224112267; Sat, 13 Jun 2026 13:41:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV66-0001fp-8H; Sat, 13 Jun 2026 16:36:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5w-0001Ya-I5; Sat, 13 Jun 2026 16:36:44 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5u-0003Dy-Vg; Sat, 13 Jun 2026 16:36:44 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id CD6801B6EE1; Sat, 13 Jun 2026 23:36:02 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 3F04F3CE933; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382962; bh=LTAxSberyWeoDcQ5ZuEoxEhrXnHV2K4/3Fs3fFdtb8o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=fXeercP4Jpedw94EZwL5YZSA+WtEeEdvN38LyyQz08ZJ9Gy8hnTr/hJC3r18Re5NL XfWMeQnPlIR7EN3+jJQNWAbyW/XHV3cKH0dd1xCIkM2neJX6pypwqgTBXV/wQpvYwK 1h16JTDo3W8XIzqi+QMuE9noMZuuOJULI7LdUxZ0Efs5eJWjt7J5/ihkEFp94BWvZJ t9zA2HG+cq0zrltn+W6er9SpWTqplZWZMqzHrAfLnQHK2do/eJKSXEpUqEEQ1WJufk /kWh/yFF9NQOi9ZaIhiHuE3TUNUqNffLxF9gh3lzFg5vcWG+PGHGcfQWO9mgFXwkuh nY9NN4FcMG5ig== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Chao Liu , Jim Shu , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 07/72] hw/char: Check interrupt after txctrl register is written Date: Sat, 13 Jun 2026 23:34:33 +0300 Message-ID: <20260613203542.1809153-7-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383305794158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang It's possible that the transmit watermark level (txctrl.txcnt) is updated when the user writes to txctrl register, which may decrease the transmit watermark level to less than the number of entries in the transmit FIFO. In such a case, the interrupt should be raised so we need to call sifive_uart_update_irq() to check and update interrupt when txctrl register is written. Otherwise, the interrupt will have to be delayed until next TX FIFO transmission is processed. Suggested-by: Chao Liu Signed-off-by: Frank Chang Reviewed-by: Jim Shu Reviewed-by: Alistair Francis Message-ID: <20260513030503.3665414-1-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit e07077a766071418e76d1c7db7e51e344776eaf2) Signed-off-by: Michael Tokarev diff --git a/hw/char/sifive_uart.c b/hw/char/sifive_uart.c index b4de662d61..b9bbaaef59 100644 --- a/hw/char/sifive_uart.c +++ b/hw/char/sifive_uart.c @@ -213,6 +213,7 @@ sifive_uart_write(void *opaque, hwaddr addr, if (SIFIVE_UART_TXEN(s->txctrl) && !fifo8_is_empty(&s->tx_fifo)) { sifive_uart_trigger_tx_fifo(s); } + sifive_uart_update_irq(s); return; case SIFIVE_UART_RXCTRL: s->rxctrl =3D val64; --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383032; cv=none; d=zohomail.com; s=zohoarc; b=TX248wDBLJ5A1pJ1I+qqfpDTenOCDNlfXLOfB/YGOlp+A1JSnQe91dw75SkenXft4dPr2wPMEE7IjVaKTI7X+dsHIKv7SyUnr8cEPOD9CVyiwKywJvZP4c8mKGexkaQKVfyYcPvZGeS8wLVF01pXo8pAD/+HW4rTB3hffQ2o6/c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383032; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fHh1yD5B9Bp9c7LkGde5elhFscJ8YshIrJjC+/dxn4A=; b=M4FPBXmfDLjzrInlEQ+iIOTslat3sx371PcsrlNbr0vuse732IbX9dsZ6ofYJWa79p0x584BU1l9Kl7DhF3tsiJ/4ChiBbE8i1O3OjGK+8Ej3V2hBnq342S4sDw4pyeds3Wjf4SXyq0CD1ppW3IVrxCT2xyBrH1SxYcJHUyNsOo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383032791842.6396245473031; Sat, 13 Jun 2026 13:37:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV67-0001hj-Oe; Sat, 13 Jun 2026 16:36:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5y-0001ZD-51; Sat, 13 Jun 2026 16:36:46 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5w-0003EG-HU; Sat, 13 Jun 2026 16:36:45 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id DD9261B6EE2; Sat, 13 Jun 2026 23:36:02 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 50F613CE934; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382962; bh=x8Obbye/RcP9958V3Ik52SIuaNnuyPM0y+vpzi01500=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=wDYJxDKnLO1greEOexlb7aofV+2nFEtCWO7GGfBJV8xQynHW+4t3Gz0Z3IzGR7X2r bY0wfJlkIhpBAVnjrXCHV4iCh3+kv7imF71Cs94k9/vKhb1t9TmrMosvZffI0mR5pf aC/wfUy3GN7Yx3O9ObLchr07zzd0iN2kRsGR5RmhjBqyoRORw2sx/i1WIp6+R7/K+C swwUyJJbCzzE9IhGxFJp1wY5nXkVBhqbKgctKU21zBeTHOY8pLMLnU1wC6RchkWSKQ 3KDyEe3XK294iyH9ODmRVmIw2WZsmpUxEWWkm+O9sqDMWJeFXfTJcKvPBHbTyKPdy4 Agx/KL7ccz4Kw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Abhigyan Kumar <314abh@gmail.com>, Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 08/72] target/riscv: Fix medeleg[11] read-only zero bit for M-mode ECALL Date: Sat, 13 Jun 2026 23:34:34 +0300 Message-ID: <20260613203542.1809153-8-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383035119158500 Content-Type: text/plain; charset="utf-8" From: Abhigyan Kumar <314abh@gmail.com> RISC-V Privileged Specification 3.1.8 (Machine Trap Delegation Registers (medeleg and mideleg)) mentions: "For exceptions that cannot occur in less privileged modes, the corresponding medeleg bits should be read-only zero. In particular, medeleg[11] is read-only zero." QEMU incorrectly included RISCV_EXCP_M_ECALL in DELEGABLE_EXCPS. It allowed the 11th bit to be written and read as set. Fixed by removing it from the DELEGABLE_EXCPS mask, adhering to the specification. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3438 Signed-off-by: Abhigyan Kumar <314abh@gmail.com> Reviewed-by: Alistair Francis Message-ID: <20260427060849.749179-2-314abh@gmail.com> [ Changes by AF: - Remove comment ] Signed-off-by: Alistair Francis (cherry picked from commit a0946caf1d9ec21446ebdcb5eab2400baa4323ae) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 51e668b46d..35e98df420 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -1789,7 +1789,6 @@ static const uint64_t all_ints =3D M_MODE_INTERRUPTS = | S_MODE_INTERRUPTS | (1ULL << (RISCV_EXCP_U_ECALL)) | \ (1ULL << (RISCV_EXCP_S_ECALL)) | \ (1ULL << (RISCV_EXCP_VS_ECALL)) | \ - (1ULL << (RISCV_EXCP_M_ECALL)) | \ (1ULL << (RISCV_EXCP_INST_PAGE_FAULT)) | \ (1ULL << (RISCV_EXCP_LOAD_PAGE_FAULT)) | \ (1ULL << (RISCV_EXCP_STORE_PAGE_FAULT)) | \ --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383215; cv=none; d=zohomail.com; s=zohoarc; b=icg2TtNif5ObLiQuNCenc15vADranQFLdq17H0zQ1RA23x95Hp4PCXjJRN2QHVEu9Ns8E9Cu4svFqq71k2rWznx2fNQmzaVvag9/wTLlQC8g0Dd0KILD3SHpqYAHHaOOLpw6wZbdOc3/Zim0Qdt71EPIMuKTk0YQsru235UOL3Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383215; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=oeaq1lTffkqBhPb3OhXHSiRXMAlPQFw3Fhc0gUZ9ZlM=; b=msLYUoC1/OVJDOSt2UjxkDeGz+hfW8Y9PZoJ1l90M5belg68fC2yS7cGjoInRbkD63DcN/HmSD2OaQkWxDySrOQ+J7PeFqF0K17ADRxmo46etgU8nWvB4izTqSMJNXwU4JhSMXuYlQFpOneGpLF/joUrvWmxaDaVFt9VDDIR3v8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138321559923.486296631913547; Sat, 13 Jun 2026 13:40:15 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV68-0001sZ-UK; Sat, 13 Jun 2026 16:36:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV60-0001Zc-Hn; Sat, 13 Jun 2026 16:36:49 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5y-0003F2-16; Sat, 13 Jun 2026 16:36:47 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id ED01E1B6EE3; Sat, 13 Jun 2026 23:36:02 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 611CE3CE935; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382962; bh=UQO7+vmvaDWY9veMsChhE+30MJhvcboOLnQu6QDtjGI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=XQ8USwBHQupJuQMSSGrJthFzqel30tV4Y3yqHyhTVa5Z3oXInjXUhuyXEJusdTP9D eQAjsn/NJbGTb2ZlrRprysMFMQXBAc3y/xKu6dPTYChq2hT/7U6C90NIjMYTms+4TN cH7WPiPjFMYniAP4gYmLiDyy5BPWEEZoLP3vjEa3gy8Ce+4+BUGjrZRlSA0PAZfJut oBzHerGVdZEN12vKs/ivh7BcWtucnVDqylf6zZAIeQmuUi7frcxAvPlLjWZGPgo+KY esIa2Sxtxo5Flfqc0kR/9zZwQJ8BaCP3AhONGkrmYGO9yIqN67z4xqHbKNmQTiTt4F 8GtTQ8aSYuS9w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Alistair Francis , Daniel Henrique Barboza , Michael Tokarev Subject: [Stable-11.0.2 09/72] target/riscv/pmp: Fix integer overflow in TOR and NA4 address computation Date: Sat, 13 Jun 2026 23:34:35 +0300 Message-ID: <20260613203542.1809153-9-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383217507158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi According to the RISC-V Privileged Manual: "The Sv32 page-based virtual-memory scheme described in sv32 supports 34-bit physical addresses for RV32, so the PMP scheme must support addresses wider than XLEN for RV32." However, the current QEMU implementation uses `target_ulong` (which resolves to `uint32_t` on RV32) for PMP address variables. When shifting these addresses left (e.g., `this_addr << 2`), an integer overflow occurs, truncating the high bits of the 34-bit physical address. Fix this issue by changing the types of PMP address variables (`this_addr` and `prev_addr`) to `hwaddr`. This issue was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-isa-m= anual/pr-2472/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Alistair Francis Reviewed-by: Daniel Henrique Barboza Message-ID: <20260511102627.3120140-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 612f22c19db8adbe9b155f199ede01e86cc1546c) Signed-off-by: Michael Tokarev diff --git a/target/riscv/pmp.c b/target/riscv/pmp.c index 5391caa59c..a71091a316 100644 --- a/target/riscv/pmp.c +++ b/target/riscv/pmp.c @@ -227,8 +227,8 @@ static void pmp_decode_napot(hwaddr a, hwaddr *sa, hwad= dr *ea) void pmp_update_rule_addr(CPURISCVState *env, uint32_t pmp_index) { uint8_t this_cfg =3D env->pmp_state.pmp[pmp_index].cfg_reg; - target_ulong this_addr =3D env->pmp_state.pmp[pmp_index].addr_reg; - target_ulong prev_addr =3D 0u; + hwaddr this_addr =3D env->pmp_state.pmp[pmp_index].addr_reg; + hwaddr prev_addr =3D 0u; hwaddr sa =3D 0u; hwaddr ea =3D 0u; int g =3D pmp_get_granularity_g(env); --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383303; cv=none; d=zohomail.com; s=zohoarc; b=PzieZNQ6T3V1Gbf15PF6r/uqsMsQ2vqtQ+DgALsE/fLfO7vBfY3Btf+8gE8XISDOvTmLZ0HHMmVBszUlDBSfocqVldz0/M4aphdJqkNKLEAcWIFuiW5w9FSvBzpSK2dMgQn+WtPYFH0B9k9Gs+k6KA6ccKWmtuOoEzbZRU6oabA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383303; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9PLPBbNgAsG6FZGp1Ie6s5X4g7r4k274JqGJRoEYywQ=; b=kxCYVNcp2pmBQtKAq5Khdl5CGuTgZK7BGhX9QneLU8PIXkv/1AtuUJEmGEpc8wX+aHsh5uM31OTvjPjd8erxluMio95V8uwuGkkrOAVfKh8j3qkNF7Fv5rs9Dz+Ps8iCc0Algr6U9rQ86shqEXFPv5qQNjyxLxnUKWmKIUWWxhk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383303389808.7108918424267; Sat, 13 Jun 2026 13:41:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV68-0001oz-BK; Sat, 13 Jun 2026 16:36:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV62-0001aA-BT; Sat, 13 Jun 2026 16:36:50 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV5z-0003FR-LO; Sat, 13 Jun 2026 16:36:49 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 05A111B6EE4; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6FE313CE936; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=UHMqgPHGlj8+eniKPa2ZlWyJsrrz5RAQJ32gOb+/r4w=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=CC4ZwXco5tLHRiXr7JubdWcnmKleyzcdFMajfdkKEHZSTi5FSRq6YmlElXPH36ojr kWNDvrhfDqRaBcGKVD1JUh1EcYgfVGqy7LjQs6VGo6QzOf9x/kpIKDuCj4D+KrDRF7 N5Jlv8pDYkjB5DCWRQip+yGXHQLrtu1tt0lU5BtbD4Er/BMn/LaDuS7hCJj/twaacH hjXo/m6HhhLYnUNY0eh3IQkNaCUcIcg1NxryaaVsoAicVRHTX25Rz7kWNb2Q3VfsDl YXrXsUllYmJHSmu470fcvrEqpSVvCvOavqYIkR10gRXdCJwvd/HqdIxH/NKMTR8LIr QVB4DG6QBNryw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 10/72] target/riscv: Add mseccfg to VMStateDescription Date: Sat, 13 Jun 2026 23:34:36 +0300 Message-ID: <20260613203542.1809153-10-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383303949158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi Currently, the Machine Security Configuration Register (mseccfg) was missing from the live migration state. This omission causes the register to be reset to zero on the destination host after migration. Fixed by adding vmstate_mseccfg subsection This vulnerability was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/a22e4459cd026ae970791dfbd= 9cfe5d110fbd46b/output/riscv-isa-manual/pr-1879/qemu.txt#L121 Signed-off-by: Zishun Yi Reviewed-by: Alistair Francis Message-ID: <20260511124828.3210477-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit eccb1d6940256668109dc6dc42450ced9f324134) Signed-off-by: Michael Tokarev diff --git a/target/riscv/machine.c b/target/riscv/machine.c index 09c032a879..6776e7bf5a 100644 --- a/target/riscv/machine.c +++ b/target/riscv/machine.c @@ -423,6 +423,25 @@ static const VMStateDescription vmstate_sstc =3D { } }; =20 +static bool mseccfg_needed(void *opaque) +{ + RISCVCPU *cpu =3D opaque; + + return cpu->cfg.ext_smepmp || cpu->cfg.ext_zkr + || cpu->cfg.ext_smmpm || cpu->cfg.ext_zicfilp; +} + +static const VMStateDescription vmstate_mseccfg =3D { + .name =3D "cpu/mseccfg", + .version_id =3D 1, + .minimum_version_id =3D 1, + .needed =3D mseccfg_needed, + .fields =3D (const VMStateField[]) { + VMSTATE_UINTTL(env.mseccfg, RISCVCPU), + VMSTATE_END_OF_LIST() + } +}; + const VMStateDescription vmstate_riscv_cpu =3D { .name =3D "cpu", .version_id =3D 11, @@ -499,6 +518,7 @@ const VMStateDescription vmstate_riscv_cpu =3D { &vmstate_ssp, &vmstate_ctr, &vmstate_sstc, + &vmstate_mseccfg, NULL } }; --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383328; cv=none; d=zohomail.com; s=zohoarc; b=lE4spXTalicH1GLB2PXJ4WjBNnugEJFMyn++ktj1QhVg11/KN8OAS/TybTAfXDLCTz3/ugJBajWDKgFnthSr4iw+ut2hUsJupgzPHkz5ZC5ky1jg4GRFAZFXDe3Op1MtzPrC/QQpux1a+wXZPn6K4o4YC3MIOfySLYGOVnP6QiU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383328; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=w8Hon4VGlvEsDUAAFagjoNEBiWAMe45DDhoCB4gjyCc=; b=d2QtUX7Pr6c8qnVsLq3w/qNR0QdjlZZI642tYgPpQY6hdtnGwnBj9Klwz0cfQMhc7QcDZDp6rtbon4MU00a+tS+jZWUeml8RlFDqPf9zostFgnDuAh8Dtf03h7e+rkVfm7QmJhZDRziV4KAPEF55Y/WMViuRl7It4flGBwlIJSM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383328350739.3675627073285; Sat, 13 Jun 2026 13:42:08 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV6E-00029v-59; Sat, 13 Jun 2026 16:37:02 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV64-0001cl-5w; Sat, 13 Jun 2026 16:36:53 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV62-0003HH-DT; Sat, 13 Jun 2026 16:36:51 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 132881B6EE5; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7C72B3CE937; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=y4R+0lv/Ip/IJfxR+IGI+lwzpO9fm3pE+KIrDmMRibo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=BrvpSCKXYxhf0H3OoggXlpMor/znEnXq8ajO+40CPzTc6dbt2O5i5O2iRoOQ3Jmfl mwjlL0ZEZXu7iY17hGLPso1ApZZadXhfpf/EbIHYfGb2YBHwMBAVuZvXGq6YsRFaQ+ 8XodHW5TnSp43Ftc/HJgSQhRcg3GZoaInvKEgS/VLqCmAdglFs6JeX5UKBpXf1Ggsw TprvS2xQWmKzFijehYbli0Uk7ZALDOqZsY25rxZNTcTTn4UQON4+ZgFLuiQA1zO8Sk TpnQChF1/6jCpP+ZnwiUWQBp/ZuO0Fl7GN1ChMHnK1QJLj2gACVRYJ/CtqsGtRBs74 hDvotAAfazXsg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alistair Francis , Daniel Henrique Barboza , Michael Tokarev Subject: [Stable-11.0.2 11/72] target/riscv: Update the local interrupt mask Date: Sat, 13 Jun 2026 23:34:37 +0300 Message-ID: <20260613203542.1809153-11-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383329897158500 Content-Type: text/plain; charset="utf-8" From: Alistair Francis The RISC-V spec describes bits 0-15 as standard fixed interrupts. The AIA spec on the other hand describes bits 0-12 as standard fixed interrupts. This conflict causes issues for us as we don't dynamically determine if AIA is enabled when setting the *delegable_ints consts. This means currently we incorrectly treat the LCOFIP bit as delegable, even if AIA is disabled, which is incorrect (see the issues mentioned below). The AIA spec indicates that implementations can determine which bits of 13-63 in mvien are writable, so let's just make it bits 15-63 to match the main spec. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3133 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3134 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3135 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3138 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3140 Signed-off-by: Alistair Francis Reviewed-by: Daniel Henrique Barboza Message-ID: <20260513051841.1671987-1-alistair.francis@wdc.com> Signed-off-by: Alistair Francis (cherry picked from commit 27f9566dcd98bdde045ef5ae7b8199456c8a51c1) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 35e98df420..d65d176fe8 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -1764,13 +1764,13 @@ static RISCVException write_stimecmph(CPURISCVState= *env, int csrno, #define VSTOPI_NUM_SRCS 5 =20 /* - * All core local interrupts except the fixed ones 0:12. This macro is for + * All core local interrupts except the fixed ones 0:15. This macro is for * virtual interrupts logic so please don't change this to avoid messing up * the whole support, For reference see AIA spec: `5.3 Interrupt filtering= and * virtual interrupts for supervisor level` and `6.3.2 Virtual interrupts = for * VS level`. */ -#define LOCAL_INTERRUPTS (~0x1FFFULL) +#define LOCAL_INTERRUPTS (~0xFFFFULL) =20 static const uint64_t delegable_ints =3D S_MODE_INTERRUPTS | VS_MODE_INTERRUPTS | MIP_LCOFIP; --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383280; cv=none; d=zohomail.com; s=zohoarc; b=GkPPRRYvzfJmvRyXux5nOlkUoXw4DdhQeKn+gpJRZQrecALGUMiZOdtOvbbxCJyAgEiY0P2oi+Vnvb4gSmm4tR3O17YefMQWse4qT0IL5+GIEN1CBE3tJrftCyXW+qSYju9B+ZQrlGPGhuQKKsHRGTDNpsT0iDm+Gd/lESMEhtg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383280; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=PmpxywzMWm5RBruQeJasC/yyvzMZ1TMb83FOQ6YwXdg=; b=IBEEfacSpHMC+Bzk/Uuv2k3d5aWfGkbk9vhr+m/4YqIx5rKklDi2cf0W+zQN1QYAFvv4hy/br6sXGvJ9MCO5R3gaPPi9fWC2MvHKxDqRnF4hBZuMj8h+Bt2JC2IF/EvWKO7lrheO9YgGuoxilLVFubQC4olxZYeZwh4A1RTsN2o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383280509475.81277332801176; Sat, 13 Jun 2026 13:41:20 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV6Y-0002vY-54; Sat, 13 Jun 2026 16:37:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6R-0002ss-3d; Sat, 13 Jun 2026 16:37:17 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6N-0003Hf-RP; Sat, 13 Jun 2026 16:37:14 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 2214B1B6EE6; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 8A3563CE938; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=nBTl9hK8MG28XPQTMfA9qQqImj/KPixRdgkMHL6YTeQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=BTLlTV9M8gshzFOvM0cU2x4iuKUrD649JJwHJJsAPa0nPMuXIpqB2w4JLQQeL8OY4 x+qonrGqczy7smdblq/+zjsnPaBGe8Pm51ukc7Fpdrp5LaFiXyZJvWTTvFcBh0dnOg 8ifBqRZJNK3AHg9rbVA2V/STh/AlXpDdNUZvB1op5TqermhLtk+VxyZ0nqEqrmS8/+ mane19jxa6xKJUUyVbBsqU6hCpE0VKsbg0kdzeTXYtvdFjLyZz2EPWyq5DlCkz6c+C TqWgpunOzNNGOSSZxGbBwBBvJV+8ZoF05WWSVcTuibgSoZ9eWQ2QDOw0A030GRj4/3 R3sY/RgFmBpDQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 12/72] target/riscv: clear mseccfg on reset for all dependent extensions Date: Sat, 13 Jun 2026 23:34:38 +0300 Message-ID: <20260613203542.1809153-12-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383281709158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi Currently, the `mseccfg` CSR is only cleared to 0 during reset if the `ext_smepmp` is enabled. However, this register is now shared by several other extensions such as `zkr`, `smmpm`, and `zicfilp`. Fix by clearing `mseccfg` if any dependent extension is present, and adjusting the relevant comments. This vulnerability was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-svvpt= c/pr-134/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Daniel Henrique Barboza Message-ID: <20260512052240.330815-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 8158a74f0a0db8626d7836eb03eca7aba46c18b5) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu.c b/target/riscv/cpu.c index 8ac935ac06..269ea35f6d 100644 --- a/target/riscv/cpu.c +++ b/target/riscv/cpu.c @@ -754,10 +754,14 @@ static void riscv_cpu_reset_hold(Object *obj, ResetTy= pe type) =20 /* * Clear mseccfg and unlock all the PMP entries upon reset. - * This is allowed as per the priv and smepmp specifications - * and is needed to clear stale entries across reboots. + * This is required as per the priv, smepmp, and other security + * extension specifications that share this CSR, and is needed + * to clear stale entries across reboots. */ - if (riscv_cpu_cfg(env)->ext_smepmp) { + if (riscv_cpu_cfg(env)->ext_smepmp || + riscv_cpu_cfg(env)->ext_zkr || + riscv_cpu_cfg(env)->ext_smmpm || + riscv_cpu_cfg(env)->ext_zicfilp) { env->mseccfg =3D 0; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383165; cv=none; d=zohomail.com; s=zohoarc; b=Wx1sSbWS+u8w15eSTnNvaPWW6qmL8x28nBeR23h7eUSmMr/3//UnFkoavNanYHiqRdux5D9q7v8u/7t6NH/J5faGhJyCwuhAGWbwtQACCjzQBaMIcAHBGc5N3vaeeE3icz4WK0g/ewTaASRJ73t1P1xnrBi9VIFs4+6xhWh/jlI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383165; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=uElaEYieXH0EcLg4ndfptWyUv+5+T5degTt/qcpdfxA=; b=L/XJBA/m1aIVXJsELRJSF0f33ar0+J2Ih/NMDluFvURBQ422lWsWHxRhbLPaCnq06wmGr+I1hTjY7RMmIuxh3L4+LBYvzZVwFp/yvKgbReXWycLrajbGGExMwG5NzVr66gTIvhBwj1OVkfUfdjGwt0EMtLEzQKVfhe7PMs4P4vk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383165234425.6098117402679; Sat, 13 Jun 2026 13:39:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV6j-0003JG-Mc; Sat, 13 Jun 2026 16:37:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6S-0002tE-PA; Sat, 13 Jun 2026 16:37:17 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6P-0003Hu-LI; Sat, 13 Jun 2026 16:37:16 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 2F7E11B6EE7; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 996813CE939; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=Buh3wzvyJ5YPdIEyfbrsL/XcS/pQ3fOnyg/b6Lqqf10=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Hk2Hs7qxdMth1iuzpb2xtMblN/M3CtlZTed2w/mQmiuZdNgxHGMJzC8UM4OmGzFOV Hf6RgRt3em7HnrxpRZzBR4BVUBO6zZzIpOQjmAH+cHUTYTRLudjkO+XGWTxF+jNXmV 24o4uvccUQ+pk+NlOSflJHrTs4BYGIzGzn2DH91Hj2nhATsxdyotmklyIsfozohFWx W6Ou2SZdH8Pn8KVDnqdGsKu/j+rRxEsI2zXfUWpmsDRnzlbdMAtkC9Mwn/3tUdhPHO ZmKlSTaS/K8awkpVJa43hSkpvLowSSYCZurRzp1M/ehcS9cTwDQDuLFGFwKdciFQ6u nX/4TUJVMKq9w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 13/72] target/riscv/csr.c: fix read of pmpaddr(0-63) CSRs Date: Sat, 13 Jun 2026 23:34:39 +0300 Message-ID: <20260613203542.1809153-13-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383167304158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza The priv spec defines, for RV64, that the upper 10 bits of pmpaddr0-pmpaddr63 are WARL and are supposed to be cleared. After this patch, using the bug reproducer in [1], writing ffffffffffffffff in pmpaddr0 and reading it back now results in 003fffffffffffff. Here's the 'diff -cp' dump before and after this change: *************** IN: *** 5272,5278 **** pmpcfg10 0000000000000000 pmpcfg12 0000000000000000 pmpcfg14 0000000000000000 ! pmpaddr0 ffffffffffffffff pmpaddr1 0000000000000000 pmpaddr2 0000000000000000 pmpaddr3 0000000000000000 Reviewed-by: Alistair Francis Message-ID: <20260514123342.2139464-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 53cc9747ed7c9b95ba084d614976dd48c9a57a97) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index d65d176fe8..cf1fe6041c 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -5304,6 +5304,23 @@ static RISCVException read_pmpaddr(CPURISCVState *en= v, int csrno, target_ulong *val) { *val =3D pmpaddr_csr_read(env, csrno - CSR_PMPADDR0); + + /* + * For RV64, bits 54-63 of the address registers + * PMPAADDR(0-63) is a WARL zero field (priv spec, + * section "Physical Memory Protection CSRs"). + * + * We'll have to add an annoying TARGET_RISCV64 gate + * here to avoid complaints about masking bits 0-53 + * of a potential 32 bit target_ulong '*var'. + */ +#ifdef TARGET_RISCV64 + if (env->misa_mxl =3D=3D MXL_RV64 + && csrno >=3D CSR_PMPADDR0 && csrno <=3D CSR_PMPADDR63) { + target_ulong read_mask =3D MAKE_64BIT_MASK(0, 54); + *val &=3D read_mask; + } +#endif return RISCV_EXCP_NONE; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383172; cv=none; d=zohomail.com; s=zohoarc; b=M7IH73JBlmi90lAMYru0vT6r81Xe6rADS4puC47OFCUgM3fUoaE34Qa3dPCW05V0/900KienPq5PpaDQJZGryShbUXNSTXz1ITtROMV/cJiQ3yPe7k9RhR7SyXWBIHh4FzrEli4Cj3GfrMY+HDOH9ZdusXq8YpjGKGltSqrHws4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383172; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fvJWXPv5E60JZC/gtStCwcqftPG2fmvhKsFmUu+T5jA=; b=JcsUXXzxQBK0tD9weRQZFKroOIf9BjtE4U5njR1/1ncX0jmGwK2r7P7Xoa9sKYStRyApMczark22WolYhnU4X5/0pXW8pTFxxzsv4n96y1sFP01ElcGOvvWq1ftMN2M0OzsEYwXI70YaTdrKTkcV0+z/ExSmAmon4emimNMkQVk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383172083158.29653058037673; Sat, 13 Jun 2026 13:39:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV6m-0003Qj-70; Sat, 13 Jun 2026 16:37:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6X-0002wZ-D6; Sat, 13 Jun 2026 16:37:21 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6S-0003QU-Rk; Sat, 13 Jun 2026 16:37:20 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 3CA6B1B6EE8; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id A647B3CE93A; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=EQ1/T6K5U0ItJX7O+kcFKps+jhA1+1znygudWJ+5mdI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=H19mQ0RScvm1etEUmSe4J6iDl+jVNFCoHJ1XGZ0UagQR5qQpwDj82vrF9j7EY4ETC cs6ZQW6HxdERPNUbdEtygsB4P8uz81gsAT1YnAoYowyu7J1Fly9cHfUpocWFmoX0La 3zGM3ZF4iRdrMjjB/4jrTLVsRJfmbl6Um6u5E+tlVMzu1OxPG0SqRpFv40aCdRqPIr SsuHwMdLcKWUkSdICw6tmnajKC3WwVMaAxsRziRQl5FbehKUoQCcgBdscMUyV2pLRu JMG4tzv+KWYeWj+kaF2SqfqMfmHNUpCzxp+4QQ2ckJt33fiErBUHM2BTheG+J/o2iE O/Wy6MJRpT86A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Portia Stephens , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 14/72] target/riscv: Make hpmcounterh return the upper 32-bits Date: Sat, 13 Jun 2026 23:34:40 +0300 Message-ID: <20260613203542.1809153-14-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383173335158500 Content-Type: text/plain; charset="utf-8" From: Portia Stephens The counter value was not being bitshifted for a hpmcounterh read resulting in hpmcounterh returning the bottom 32-bits. Fixes: cfc96df65e01 ("target/riscv: Remove upper_half from riscv_pmu_ctr_g= et_fixed_counters_val") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3498 Cc: qemu-stable@nongnu.org Signed-off-by: Portia Stephens Reviewed-by: Alistair Francis Message-ID: <20260519043352.3685866-1-stephensportia@gmail.com> Signed-off-by: Alistair Francis (cherry picked from commit 02284108376a6bcfdd56a11de1c6e0bcc3d0e53b) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index cf1fe6041c..0f14ea4689 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -1392,8 +1392,9 @@ RISCVException riscv_pmu_read_ctr(CPURISCVState *env,= target_ulong *val, */ if (riscv_pmu_ctr_monitor_cycles(env, ctr_idx) || riscv_pmu_ctr_monitor_instructions(env, ctr_idx)) { - *val =3D riscv_pmu_ctr_get_fixed_counters_val(env, ctr_idx) - - ctr_prev + ctr_val; + uint64_t cntr =3D riscv_pmu_ctr_get_fixed_counters_val(env, ctr_id= x) - + ctr_prev + ct= r_val; + *val =3D extract64(cntr, start, length); } else { *val =3D ctr_val; } --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383226; cv=none; d=zohomail.com; s=zohoarc; b=Pgt5Fvkp5qEworxM5Hn3u1coISZC5Z3/coby7jWgek+mx+zufLas6WuiZGHR895yxWXFJEX6OkTRfDx3w8iYKlhYQOX6pg4Qb2D+710aGan8bmVMHeEUkDvAyighPtC5NcLNgg5oKcq76uadz5mXSwxUofmK0AXdStebFSTCT9Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383226; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=pby/DNkEDKLCWfWpY4ntSB6WG9nu650GoJXazxzGKDk=; b=aSaP9/323K/gStyzCwb8IxDtJ+dk/mtPXyj1eGZmTe8//V46ny0rA+vWqS6MzYHIe0Vu/JH0TmNybF3pWbyqqRhOgO1o0uR349dr5mfC4reWJE9C9bN93IBQqJOxgKFBzbFA+ZVUYl3DBM3TmL96igsiaMD39wCoAbxEtTHuZ7o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383226953858.256840553944; Sat, 13 Jun 2026 13:40:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV6h-0003Bm-43; Sat, 13 Jun 2026 16:37:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6X-0002wP-CR; Sat, 13 Jun 2026 16:37:21 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6V-0003Qo-CG; Sat, 13 Jun 2026 16:37:21 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 4ABCB1B6EE9; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B3E393CE93B; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=VpUXHEeZq4VCjeyy0rgRt2Of/KA2IN5KTxh0zZi1P0I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=bSfIWwWFHHuQlJunLczgY6xvEHF9XFpoqkO74CW+UwDS9ECX7ZW1UyfbyF0PC1A1L RgZ9V/eQsRfAzdlZ+WPmGLkMMotx8v3CR/ZgfWhnAYIHBT9oZ+so8/k0ubwq/CB2c3 OZQjmp+1PrRDU3tfBNtQvxlefrisOXxlvnyLJvSaTdxvaK0HEK2vnOLHL9WVz6NVMe 58+94XL89sbXnWaiEThAHq8QSDXeFHm7EU52IcESzbpadHV3Zm9InraSv+q+hFsNTb aIwwdy9o1vq6bWdWIFaDIpi27kKw+lEVy8/0VDDl3YIJ+IwDDZYObAXUHjiQZrUhvC 0MtQuLjG7ugiA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 15/72] linux-user/mips64: fix elf_core_copy_regs register layout in core files Date: Sat, 13 Jun 2026 23:34:41 +0300 Message-ID: <20260613203542.1809153-15-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383227783158500 From: Matt Turner mips64/elfload.c uses #include "../mips/elfload.c" to share code. When the compiler processes mips/elfload.c the quoted #include "target_elf.h" resolves relative to the including file's directory, so it picks up mips/target_elf.h instead of mips64/target_elf.h. mips/target_elf.h pulls in mips/target_ptrace.h, whose target_pt_regs has a pad0[6] field before regs[]. As a result elf_core_copy_regs writes: r->pt.regs[i] -> reserved[6+i] (shifted by 6 from the correct index) r->pt.cp0_epc -> reserved[40] (correct mips64 N64 index is 34) The Linux kernel and glibc both use the mips64 N64 layout (no pad0): EPC at reserved[34]. Debuggers and libunwind reading the core with N64 constants therefore see a completely wrong register set =E2=80=94 EPC point= s to GP, RA holds the branch target instead of the link address, etc. Fix by: - Guarding the mips32 elf_core_copy_regs in mips/elfload.c with #ifndef TARGET_MIPS64 so it is not compiled for mips64/mipsn32 targets. - Providing a mips64-specific elf_core_copy_regs in mips64/elfload.c that writes directly to r->reserved[i] with the correct N64 indices, bypassing the struct field names that are tainted by the wrong header include. The mipsn32 (TARGET_ABI_MIPSN32) and mips64el targets are covered by the same mips64/elfload.c and benefit from the same fix. Signed-off-by: Matt Turner Cc: qemu-stable@nongnu.org Signed-off-by: Helge Deller (cherry picked from commit dd3a906d3505561d9cb3367b82c5475acca50b6b) Signed-off-by: Michael Tokarev diff --git a/linux-user/mips/elfload.c b/linux-user/mips/elfload.c index cc5bbf05ab..1a46e180cf 100644 --- a/linux-user/mips/elfload.c +++ b/linux-user/mips/elfload.c @@ -131,6 +131,7 @@ const char *get_elf_base_platform(CPUState *cs) #undef MATCH_PLATFORM_INSN =20 /* See linux kernel: arch/mips/kernel/process.c:elf_dump_regs. */ +#ifndef TARGET_MIPS64 void elf_core_copy_regs(target_elf_gregset_t *r, const CPUMIPSState *env) { for (int i =3D 1; i < ARRAY_SIZE(env->active_tc.gpr); i++) { @@ -146,3 +147,4 @@ void elf_core_copy_regs(target_elf_gregset_t *r, const = CPUMIPSState *env) r->pt.cp0_status =3D tswapl(env->CP0_Status); r->pt.cp0_cause =3D tswapl(env->CP0_Cause); } +#endif diff --git a/linux-user/mips64/elfload.c b/linux-user/mips64/elfload.c index b719555e65..9081ae8111 100644 --- a/linux-user/mips64/elfload.c +++ b/linux-user/mips64/elfload.c @@ -1 +1,30 @@ #include "../mips/elfload.c" + +/* + * mips/elfload.c defines elf_core_copy_regs guarded by #ifndef TARGET_MIP= S64. + * + * We must provide the mips64 version here. We cannot use r->pt.regs[] be= cause + * when mips/elfload.c is #include'd above its "#include "target_elf.h"" r= esolves + * to mips/target_elf.h (compiler searches the including file's directory = first), + * which pulls in mips/target_ptrace.h. That struct has pad0[6] before re= gs[], + * so r->pt.regs[i] writes to reserved[6+i] =E2=80=94 offset by 6 from wha= t the kernel + * and glibc expect for the N64 ABI (EPC at reserved[34], not reserved[40]= ). + * + * Write directly to reserved[] using the mips64 N64 index layout: + * R0-R31 at reserved[0..31], LO at [32], HI at [33], EPC at [34]. + */ +void elf_core_copy_regs(target_elf_gregset_t *r, const CPUMIPSState *env) +{ + /* R0 is always 0; r->reserved is zero-initialised by the caller */ + for (int i =3D 1; i < 32; i++) { + r->reserved[i] =3D tswap64(env->active_tc.gpr[i]); + } + r->reserved[26] =3D 0; /* k0 */ + r->reserved[27] =3D 0; /* k1 */ + r->reserved[32] =3D tswap64(env->active_tc.LO[0]); + r->reserved[33] =3D tswap64(env->active_tc.HI[0]); + r->reserved[34] =3D tswap64(env->active_tc.PC); + r->reserved[35] =3D tswap64(env->CP0_BadVAddr); + r->reserved[36] =3D tswap64(env->CP0_Status); + r->reserved[37] =3D tswap64(env->CP0_Cause); +} --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383180; cv=none; d=zohomail.com; s=zohoarc; b=FoqLjEgfryIoSpU0VKg3tOm6tl2ZCFLnV8VDMjlntjJpcJ+h1qXDgAf3+TJqolVSZivy4QeccR+0+LNw3+g12ryBzfW1LESNxvCcRz/YEIbuFapokun/Ymxu3EWh2lx6kocuElYZvGToRErhlyrsNUFMk5lpTZRrj6r5KiUofbM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383180; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rRd80eVCDzT4CYprjOUGBtpOF7UOLQaMHwId3i53lek=; b=WlBJw7vzpuzQjm5+iDOIApa3rIeVAJMfFRCaoMbr6DT2pawbqEGd69sB13BgrSuERkYuqQDIRw5SYPTRZ9kz0qjPuDrvNy6Av7NAZs7vMyKO+S8ThncRhZ76AcbpSg8tbC1q22c52VYKx6F3zwC/x8PZvUOQTlybesIQWbObIkU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383180465122.76635232547278; Sat, 13 Jun 2026 13:39:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV6i-0003F4-6C; Sat, 13 Jun 2026 16:37:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6b-000377-Qy; Sat, 13 Jun 2026 16:37:26 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6Z-0003SY-CS; Sat, 13 Jun 2026 16:37:24 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 597941B6EEA; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C2A813CE93C; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=5LTbrdiZZKvPaIrNvB8ScBmmfWMVGkV6wGymiQXW1SQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=mYg5117z4+yfqRm3ebhzhPWzslfU4nLsSaLvcC4Z/5UWqhbb46RX1UKNLMldgQOIS 6evwpO2vPGxmp0TeXc9zkkDuwlx+G+d0I86hrl0rjfPfAezfV4rIKeLQ9y3rW5WVNW pzBfqfYTNaBDoS0aJXsKwgANe+dWyBNA4xrDvISMRANFLu2hM03iwbP24cASOrPiI/ tVUPKuCGMp5LThaWAIebCS5alyA+llRYTwK9saZTSNP2Wi8SN1mgzkSgwRjGelxztn YEJLYhB8WReV235ktdv40/pwhx/E1454OSdxswMwiWGIqIwAe6WqKLMI3XffABDdIl /VBjimRe9vg7g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 16/72] linux-user/mips64: fix mipsn32 elf_core_copy_regs entry width Date: Sat, 13 Jun 2026 23:34:42 +0300 Message-ID: <20260613203542.1809153-16-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383181399158500 From: Matt Turner For mipsn32 (TARGET_ABI32=3Dy, TARGET_LONG_BITS=3D64): abi_ulong =3D uint32_t (4 bytes) =E2=80=94 for pointers and ABI-sized fie= lds target_ulong =3D uint64_t (8 bytes) =E2=80=94 for general-purpose registe= rs linux-user/elfload.c allocates target_elf_prstatus using the mips64/target_elf.h definition where target_elf_gregset_t has target_ulong reserved[45] (8 bytes each, 360 bytes total). However, in linux-user/mips64/elfload.c, #include "target_elf.h" inside the included mips/elfload.c resolves to mips/target_elf.h (compiler searches the file's own directory first), where the union uses abi_ulong reserved[45]. For mipsn32 this gives 4-byte entries (180 bytes), not the 8-byte entries (360 bytes) that elfload.c actually allocated. Writing via r->reserved[34] therefore lands at byte offset 34*4=3D136 instead of the correct 34*8=3D272, silently zeroing the EPC in the core file. Fix by casting the pointer to target_ulong * so writes always use 8-byte slots and land at the offsets matching the allocated layout. This does not change behavior for mips64 (N64) where abi_ulong already equals target_ulong (both 8 bytes). Signed-off-by: Matt Turner Cc: qemu-stable@nongnu.org Signed-off-by: Helge Deller (cherry picked from commit 6033df08e93df313771b6637230de2d66bdc09cb) Signed-off-by: Michael Tokarev diff --git a/linux-user/mips64/elfload.c b/linux-user/mips64/elfload.c index 9081ae8111..e4d84a7bd6 100644 --- a/linux-user/mips64/elfload.c +++ b/linux-user/mips64/elfload.c @@ -15,16 +15,31 @@ */ void elf_core_copy_regs(target_elf_gregset_t *r, const CPUMIPSState *env) { - /* R0 is always 0; r->reserved is zero-initialised by the caller */ + /* + * linux-user/elfload.c allocates target_elf_prstatus using the + * definition from mips64/target_elf.h, where target_elf_gregset_t + * has target_ulong reserved[45] (8 bytes each =3D 360 bytes total). + * + * But in this compilation unit, "#include target_elf.h" resolved to + * mips/target_elf.h (wrong directory), so our local target_elf_gregse= t_t + * has abi_ulong reserved[45] which is only 4 bytes each for mipsn32. + * Using r->reserved[i] would write to the wrong offsets for mipsn32. + * + * Cast to target_ulong * to always write 8-byte entries at the correct + * positions, matching the layout that elfload.c allocated. + */ + target_ulong *regs =3D (target_ulong *)r; + + /* R0 is always 0; buffer is zero-initialised by the caller */ for (int i =3D 1; i < 32; i++) { - r->reserved[i] =3D tswap64(env->active_tc.gpr[i]); + regs[i] =3D tswap64(env->active_tc.gpr[i]); } - r->reserved[26] =3D 0; /* k0 */ - r->reserved[27] =3D 0; /* k1 */ - r->reserved[32] =3D tswap64(env->active_tc.LO[0]); - r->reserved[33] =3D tswap64(env->active_tc.HI[0]); - r->reserved[34] =3D tswap64(env->active_tc.PC); - r->reserved[35] =3D tswap64(env->CP0_BadVAddr); - r->reserved[36] =3D tswap64(env->CP0_Status); - r->reserved[37] =3D tswap64(env->CP0_Cause); + regs[26] =3D 0; /* k0 */ + regs[27] =3D 0; /* k1 */ + regs[32] =3D tswap64(env->active_tc.LO[0]); + regs[33] =3D tswap64(env->active_tc.HI[0]); + regs[34] =3D tswap64(env->active_tc.PC); + regs[35] =3D tswap64(env->CP0_BadVAddr); + regs[36] =3D tswap64(env->CP0_Status); + regs[37] =3D tswap64(env->CP0_Cause); } --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383123; cv=none; d=zohomail.com; s=zohoarc; b=imvcGLaehUTAEe14GmXYfvjOiiuONlk7icYqfZ2xcFxxkVII/IxlodbbydL7LXtiXfmBxGVDa2ML+o1Cq8bvHL3HAEJ1OVGyLHSR9OrO2L35hwhrhGiaa2Tv22ctAOEFIL9cnLQO92fJLOLd5z9sreNdSMhwaZmVNgFXFjWcAsE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383123; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=klO2C5fuiH+pcM9N8CegDHYpQsR7G1+1pGiLzLuAgTU=; b=CEYkZtxiMdVsycK0S0otColTPVWdfZVtayh7EguDfAGNzrEarVxYGzoLEyuHsjZ3XF7meftaZTltBrnInAa6DJ1iqlO1W78+jpuU1XveG3sSEqahXR2Mz/zK7ZO0H9ExOVC0gJjqZnDW7VuFYxzi0KFPLUMdgEvywi9o7NBMW0w= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383123394151.68387440395202; Sat, 13 Jun 2026 13:38:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV6x-0004Du-Nz; Sat, 13 Jun 2026 16:37:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6u-00048Y-Tp; Sat, 13 Jun 2026 16:37:44 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6t-0003Sa-DT; Sat, 13 Jun 2026 16:37:44 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 68C841B6EEB; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D0AEF3CE93D; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=oeWCQUoPxo3Y5KEpbVvM3clq9pSKvlzk66CPh2w8/2o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=lVtE0b8pjV1Qqb/e1J0b8HPbmpKrz1k3QuFBOatjvtc9hstb7HIyMExbYt5u5+PrF jYt50rOBXAONF8qC7ngZ4q2LxbQipUfw9z59CmSokwHUxCe90XltXwe6ttsaTc/E0Y iH+2ZwyokEPX5TVYVWu8pw2gySt7iRWmRsOyp8UofWUzWuG95fCOZM+D+Kylv5A6Kr 7A6Pa4kxY8y1tKSVm0Glx6Qp0JFbEJls2/xX8jd2rCBGgdoYMB+ZobIWu9F4j+qvVK VeixeobHHOhQ82Po3NmKF+g9KBo92hoYE6DHEgT0pVVV+bMgzF+aqR3AFNr4zzHOiC kXqliyXqMNlzA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 17/72] ui/vnc: fix OOB read access in VNC SASL mechname array Date: Sat, 13 Jun 2026 23:34:43 +0300 Message-ID: <20260613203542.1809153-17-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383125277158501 From: Daniel P. Berrang=C3=A9 When reading the SASL mechname array off the VNC connection, if malicious, the received data may contain embedded NULs. If this happens the memory buffer returned by g_strndup may be shorter than the original data. Unfortunately the code continued to index into this buffer with an offset equal to the original length. This is a potential OOB read of the array. Fixes: 5847d9e1 (ui/vnc: simplify and avoid strncpy) Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-2-berrange@redhat.com> (cherry picked from commit ae18df638fb4285c7b645f98c43f5ebc2e123a55) Signed-off-by: Michael Tokarev diff --git a/ui/vnc-auth-sasl.c b/ui/vnc-auth-sasl.c index 3f4cfc471d..9f15980fca 100644 --- a/ui/vnc-auth-sasl.c +++ b/ui/vnc-auth-sasl.c @@ -490,6 +490,8 @@ static int protocol_client_auth_sasl_mechname(VncState = *vs, uint8_t *data, size_ char *mechname =3D g_strndup((const char *) data, len); trace_vnc_auth_sasl_mech_choose(vs, mechname); =20 + /* If 'data' had embedded NUL the dup'd string might now be shorter */ + len =3D strlen(mechname); if (strncmp(vs->sasl.mechlist, mechname, len) =3D=3D 0) { if (vs->sasl.mechlist[len] !=3D '\0' && vs->sasl.mechlist[len] !=3D ',') { --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383510; cv=none; d=zohomail.com; s=zohoarc; b=Onn7kGOpBUbc4k+2zsFtL5YIzeEqKqIK/24iYU6JON0kKF7aMPQGI76kughiUV878ckSrDIPjVQE6kciAD10SyYogkRodX9mJLmbM+U8FqVtd1jdT8z3DnPYQ6mGjApTK2qMA92zu3TDOm0sV9fURpT9QEDjaJjhgzBNjh0hmW0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383510; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EhY38HvDVXyHmu318ZV4NMF/jUScLxYr7FlRgTwkWRg=; b=MvtieasMGvFnDYlsfrsiN7JGynFH/0Aj4Lg5Ch0KfTJ615wW8s7rXTAB2pXcgPqz8ZR6AvHbb+nTZQn5AlUNqD5R8BFVC/tO0b/pNhjNwNwF2VEmv56PiFr7n++NYFpyAWcyPdIMtplROIT1U5PaKYFnQLUa4XQ22LwTIwjvuG8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383510263228.81851823714203; Sat, 13 Jun 2026 13:45:10 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7M-0004SO-PK; Sat, 13 Jun 2026 16:38:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6y-0004FE-Ty; Sat, 13 Jun 2026 16:37:49 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6x-0003TD-Dj; Sat, 13 Jun 2026 16:37:48 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 789591B6EEC; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E05923CE93E; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=ZO2V1hRxjxtkQY97w81DzNP/KhHOgRzafHWy3erJ3rg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=dJ/OOzRmDx6HSiScSikd38QCe8xJ6CPv8TpYkVkMYXrfjiQTuDTJR4CzwnzPt1Sab 7KYWltOS8KTH8t3W9sDmwwIr3qSm2r0mBR3zYC2cSTRks/jOCEfXlNVHyanFJXnJKn S+LMQFeCpbLiVuAunAajBEjUFBBRYG21sp64s9ROLIys4GY3bWNpvWyAvjJIBRuuT2 MFAywvrnGGBaD0vAEZyst+vGihpvA2HJGAECXCslUdDHZITtnMpNEiTMPogi+mOmBR iRnpX+2R9PXWyFQwZdI5xqToEDvDd+hn3EiMbdJ8BlLbtBMYgUsBemHVnrtFyclzxS 59mgruLEaofHw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 18/72] ui/vnc: fix OOB write in VNC stats array Date: Sat, 13 Jun 2026 23:34:44 +0300 Message-ID: <20260613203542.1809153-18-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383510534158500 From: Daniel P. Berrang=C3=A9 The VncSurface struct maintains update statistics in an array: VncRectStat stats[VNC_STAT_ROWS][VNC_STAT_COLS]; where the dimensions are defined as: #define VNC_STAT_RECT 64 #define VNC_STAT_COLS (VNC_MAX_WIDTH / VNC_STAT_RECT) #define VNC_STAT_ROWS (VNC_MAX_HEIGHT / VNC_STAT_RECT) If VNC_MAX_WIDTH / VNC_MAX_HEIGHT are not an exact multiple of VNC_STAT_REC, the COLS/ROWS will be undersized by 1. Unfortunately: #define VNC_MAX_HEIGHT 2160 is not a multiple of 64, so there is potential for OOB reads and writes in the 'stats' array, if the guest surface is over 2112 pixels in height. An array overflow occurs when vnc_update_stats() records new statistics, either scribbling over data later in the VncDisplay struct that 'stats' is embedded in, or performing an OOB write on the allocated struct memory. Fixes: CVE-2026-48002 Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-3-berrange@redhat.com> (cherry picked from commit c3c6226fa48180edf9d4646d4112fb1becbc149b) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.h b/ui/vnc.h index ec8d0c91b5..ad41b418b9 100644 --- a/ui/vnc.h +++ b/ui/vnc.h @@ -92,8 +92,8 @@ typedef void VncSendHextileTile(VncState *vs, #define VNC_DIRTY_BPL(x) (sizeof((x)->dirty) / VNC_MAX_HEIGHT * BITS_PER_B= YTE) =20 #define VNC_STAT_RECT 64 -#define VNC_STAT_COLS (VNC_MAX_WIDTH / VNC_STAT_RECT) -#define VNC_STAT_ROWS (VNC_MAX_HEIGHT / VNC_STAT_RECT) +#define VNC_STAT_COLS DIV_ROUND_UP(VNC_MAX_WIDTH, VNC_STAT_RECT) +#define VNC_STAT_ROWS DIV_ROUND_UP(VNC_MAX_HEIGHT, VNC_STAT_RECT) =20 #define VNC_AUTH_CHALLENGE_SIZE 16 =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383129; cv=none; d=zohomail.com; s=zohoarc; b=UgQvcfnJOS6gsTU/8dA1NhxHlf4H9fdhXZ/NOneRvdlMtgQLLPejfidiuM9TJZsEoFFvbjp8eEkdwsTnoNDM+AhBFfMyDU05yYeFlQMDdvWNDSvFEezsWpFI69zEvdCM7wFsA/52gKj4x5FwPoWfBY8g/mcTF8umjM/Q13++PcE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383129; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GtcTReYH0pPdZNhR+J5vgPecDCjDxEA2wIYQWB4rR1c=; b=WOhnuosYGQB8TcOnbJmDo9XKBZtKE2UK14hB40ZWOjlf6+M8vHGyl3Jq46AMsbahkFEaq5XZItMofDVvlNP9XFPaw67JdZdVMCy1nsu6CPZH/LkXZ2mO0wkYl24ucMCco0jT8BGFpHT5acj2ahWbjgl8wpgpAeh8nXtX10OX0/0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383129557744.1617114127789; Sat, 13 Jun 2026 13:38:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7G-0004QC-Bx; Sat, 13 Jun 2026 16:38:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6x-0004EY-RB; Sat, 13 Jun 2026 16:37:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6w-0003WS-As; Sat, 13 Jun 2026 16:37:47 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 871141B6EED; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id EFE453CE93F; Sat, 13 Jun 2026 23:36:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=lGk/OGkifKx4LKSM9herBoN6ehFZjTS6Al80zJPhBAI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=aWyZ+QgWF1pj0184S2w+HEtpd3KphPSgdHTpxsR2FKZUSdo9v7yQ0+fcmFWwidKgE pgxRgP7tqFkoFzCONNS8mbq3pO9gLier1DrAUgqW4FaG0v50IIkjHt2S9H7/DQxrx5 Q0YNV2Hn9LhVK86K0lfEdI9qvLzmKbpPRvsTHgCD5OsXhzwwExdHFZDd0bX7A3yshc SM0CElrVemBnFOGLAJCe9HdS3WZPvDErqfF0pAJSurmNqwQE61ovt/B03f0XgQAomq XvreNPgXFDgLLmIu+Vxf8Yv5uN/r1ACII1em4lT9bnT3pNTF+Wa2Hg6ZtizMppqw3E VAb8dM2jkhOyg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 19/72] ui/vnc: fix OOB write in lossy rect worker code Date: Sat, 13 Jun 2026 23:34:45 +0300 Message-ID: <20260613203542.1809153-19-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383131358158500 From: Daniel P. Berrang=C3=A9 Incorrect calculation of the boundary condition when tracking lossy rectangles in the worker thread will result in an OOB write which can corrupt further worker state, and/or trigger any guard pages that may lie beyond the VncWorker struct. This can be triggered through careful choice of the display resolution in the guest OS by an unprivileged user. Fixes: CVE-2026-48002 Reported-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-4-berrange@redhat.com> [Marc-Andr=C3=A9 - added assert() suggest by philmd@linaro.org] Signed-off-by: Marc-Andr=C3=A9 Lureau (cherry picked from commit 46ee49034d26d04d95ba8f3183d4fbfa9d2b89b4) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.c b/ui/vnc.c index ccc73bd7aa..8ab44c830c 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -2994,13 +2994,15 @@ void vnc_sent_lossy_rect(VncWorker *worker, int x, = int y, int w, int h) { int i, j; =20 - w =3D (x + w) / VNC_STAT_RECT; - h =3D (y + h) / VNC_STAT_RECT; + w =3D DIV_ROUND_UP((x + w), VNC_STAT_RECT); + h =3D DIV_ROUND_UP((y + h), VNC_STAT_RECT); + assert(h <=3D VNC_STAT_ROWS); + assert(w <=3D VNC_STAT_COLS); x /=3D VNC_STAT_RECT; y /=3D VNC_STAT_RECT; =20 - for (j =3D y; j <=3D h; j++) { - for (i =3D x; i <=3D w; i++) { + for (j =3D y; j < h; j++) { + for (i =3D x; i < w; i++) { worker->lossy_rect[j][i] =3D 1; } } --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383273; cv=none; d=zohomail.com; s=zohoarc; b=S8QFSUt7VZpltoEAQ2WqzkNQ8/FCyrF/g630ssMtrO7E4swjF1pXj+NHFCtIlr2qJ0YsfQW4AB1EZDhpXmfU+67l0rGb3gjfkxQlP2ISW5MV/gPyJ0JOO3r7w6C51IUCBIEZtd/fomMZvzCF4pm2wdVaYreRzNkk0SkAHR9k99w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383273; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=FijibwZ9sddXPEJQ/3kJRJfBZ6n2UfWemTLlXpeDXBQ=; b=dGWegtFbBvNjK1RyyHMgZR9/1sm9FANjyF2eU+ePtoHpBM0EQN78OF+GZkSk+vQ7aU4q5AyjK4EO0+hYHHStqWgvFaZA6/kZlTRgkbDeHxZeg8YfmACguITtQxFe5hmlnGKnahjyFRreJ1ALSmDl0PzeSEtXghLYe9c1Jovz8hM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383273297624.8172632822096; Sat, 13 Jun 2026 13:41:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7l-0004sn-W1; Sat, 13 Jun 2026 16:38:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV73-0004GR-MY; Sat, 13 Jun 2026 16:37:55 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV6z-0003Ww-8e; Sat, 13 Jun 2026 16:37:52 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 972371B6EEE; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0ABC53CE940; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=OwdSBD4V2b4+B8glKB7Gyvjax4SKaYALuDPpDERSKxU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=k7WsgiofgxiJkFieTnG8lvii8H9Lp92V6VKb8nuWszTaHq3zYzJ5eUzqn8oXfl/jr AEHNBIMqGEL/LPxrV/sr+MAduNd4wqVtK7J14+X2PPHxtK3kuW9KYXSTFhOA+38LA/ Ay2dt+7PIvEFnTQcZ7JMLwZ4UCt2Zk72S7MTGpQLcHggKVkRObNZJ9KKN7sUv8Ian0 AiSCPc4lCNHqNe2D0xgwVCljWgZAd9JwE4TNZbilR3/FT/ZJR9QGbSjeu8tKDvkUnp ewxdhJ0n/6qfhibBgLpRNLYBwongpnORW4o+brSD1M1YmIJRs+tafs/yUdV7up+dT/ y7HuTPEWgJppQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 20/72] ui/vnc: fix OOB read updating VNC update frequency stats Date: Sat, 13 Jun 2026 23:34:46 +0300 Message-ID: <20260613203542.1809153-20-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383273792158500 From: Daniel P. Berrang=C3=A9 Incorrect loop bounds in vnc_update_freq result in iterating past the last row and past the last column in the VNC stats array. With suitably chosen dimensions this could be a OOB read that accesses memory beyond the VncDisplay struct that the stats array is embedded in. Should this hit a guard page, it could trigger a guest crash. If it does not, then the VNC frequency stats will be updated with garbage. Fixes: CVE-2026-48003 Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-5-berrange@redhat.com> (cherry picked from commit d0c7b82d3a89dd9c863f8aa69b07360c648ca9fb) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.c b/ui/vnc.c index 8ab44c830c..1b5fc8117a 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -3105,12 +3105,14 @@ double vnc_update_freq(VncState *vs, int x, int y, = int w, int h) int i, j; double total =3D 0; int num =3D 0; + int x_end =3D x + w; + int y_end =3D y + h; =20 x =3D QEMU_ALIGN_DOWN(x, VNC_STAT_RECT); y =3D QEMU_ALIGN_DOWN(y, VNC_STAT_RECT); =20 - for (j =3D y; j <=3D y + h; j +=3D VNC_STAT_RECT) { - for (i =3D x; i <=3D x + w; i +=3D VNC_STAT_RECT) { + for (j =3D y; j < y_end; j +=3D VNC_STAT_RECT) { + for (i =3D x; i < x_end; i +=3D VNC_STAT_RECT) { total +=3D vnc_stat_rect(vs->vd, i, j)->freq; num++; } --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383452; cv=none; d=zohomail.com; s=zohoarc; b=HNmRHp8S5ObGZIe0mDnNgehryI6uMQBYNXY/ypo70iD7Vxd3EDI8fZca2AIEg2gloNw4I4y9OcigCn63i7nvAkaQcdL69gDKFcIOtIvnBe6zXUaTCOLjowaMvoefTPNtovczxGmCYO+iePKe/2Se2dEDAm3KgIdffWJzo1wwXvA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383452; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rRgLOsAbB8mV5Z02gJ9i58QdSd5GSpfsC9YvYb5PuSc=; b=mxDCyEuucEno20X6vJ1xcAJjOfnrO0enggs8ymSGU+PC9rZtlDCTOyLtCjQvHVHBJBB5QvFUsMrOxnMYpJ2G+3k+V/nYWAb7ksQVMyLwLDLayJvRRkfWzXeJYVqsu3vnsLeDJlhdhZZu93/SWOEbpHg7gPPy2IwBYu6FccBwK4A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383452973900.79284797451; Sat, 13 Jun 2026 13:44:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7a-0004eZ-6T; Sat, 13 Jun 2026 16:38:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV73-0004GP-La; Sat, 13 Jun 2026 16:37:55 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV70-0003XG-Ar; Sat, 13 Jun 2026 16:37:52 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A8C7F1B6EEF; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1AB783CE941; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=DJZuAd6uoTybgvHP17Px/QZ+fzo7XTUkf9sXHlZo+24=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=cEDPit4UFCUGJ7ffIA6cUEYbDcjI/nzcn4feFeukykriqNCgFukzm4qzEFUZiyb7W 4eZGkt2A+DKmI84isUskaqs9V0QEAaDdF6OVDF7qL8Nk+0m1brBEC9EO4JOojDUt9+ Tu74heTNBaAJzH07CA34gv86PNHj6R9qMd0HhN4Jh4/q4X3E2+8VlZ0c17WH7TNidS KuAzx72zkE+oymGxbh3IvY6fY91eHTi3sgecv4UVGNOd/ZrGaOz+ynKySfu0nSraPe R2Xzfhy+2Jzk0HGf1kQEx84bGEEamr47PW6saaqjyppmJ8HTdkL333xiWgWodMdnDA /CTySI7PNPUog== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Heechan Kang , Feifan Qian , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 21/72] ui: fix validation of VNC extended clipboard data length Date: Sat, 13 Jun 2026 23:34:47 +0300 Message-ID: <20260613203542.1809153-21-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383454319158500 From: Heechan Kang QEMU's VNC extended clipboard handler inflates a client-controlled compressed clipboard payload. The code checks the declared text size against the total inflated buffer size: if (tsize < size) but then copies from: tbuf =3D buf + 4; qemu_clipboard_set_data(..., tsize, tbuf, true); The correct bound is the remaining data length after the 4-byte length field, not the total inflated buffer length. As a result, a VNC client can make QEMU copy up to 3 bytes past the end of the inflated heap buffer. With a second VNC client, those copied bytes are observable through the normal VNC extended clipboard PROVIDE path. Fixes: CVE-2026-8343 Reported-by: Heechan Kang Reported-by: Feifan Qian Reviewed-by: Daniel P. Berrang=C3=A9 Signed-off-by: Heechan Kang [DB: added #include and 'return' statements] Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260512095543.459949-1-berrange@redhat.com> (cherry picked from commit e56b4bbff1df260487b80abe1f967f687fa115d3) Signed-off-by: Michael Tokarev diff --git a/ui/vnc-clipboard.c b/ui/vnc-clipboard.c index 124b6fbd9c..fa05d86f42 100644 --- a/ui/vnc-clipboard.c +++ b/ui/vnc-clipboard.c @@ -23,6 +23,7 @@ */ =20 #include "qemu/osdep.h" +#include "qemu/error-report.h" #include "vnc.h" #include "vnc-jobs.h" =20 @@ -282,10 +283,16 @@ void vnc_client_cut_text_ext(VncState *vs, int32_t le= n, uint32_t flags, uint8_t buf && size >=3D 4) { uint32_t tsize =3D read_u32(buf, 0); uint8_t *tbuf =3D buf + 4; - if (tsize < size) { + if (tsize <=3D size - 4) { qemu_clipboard_set_data(&vs->cbpeer, vs->cbinfo, QEMU_CLIPBOARD_TYPE_TEXT, tsize, tbuf, true); + } else { + error_report("vnc: malformed extended clipboard payload " + "with text length %u exceeding available %u", + tsize, size - 4); + vnc_client_error(vs); + return; } } } --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383174; cv=none; d=zohomail.com; s=zohoarc; b=klWU9A+OuJpLe25uJ0DkvKbrTRocBmO8YN0sx1BnoPX/FROaJeM+OFMhVAHhaN7MaUQ24Nte8oQksZg+UGus/9jeVlKj8c+cRimXTwbdm/Sack57IZUG0+PJ70ZcwK33wsjkWp7HJ0V/ZaRqBVp57VDQQpcyhj+g/vgHyCQPtUg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383174; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=w+/gWzAvjdmKAbs8WgpM0WUQBmp7xUrGd+EE9pvpEyU=; b=X3CMSt4u8PaiA4zrsPx1SiJPNAxbV5Rd5yN/ZUQ80V6cSGNTE7aXKhWV405F0Uu9/olR0G9L3WO3l07pRhhTfnN8MJ2R3Rcur7n8hZzhfL6OcncDKta4Rn6oDZPu2GOpZASN7uLI8S68mMHsNF5nk4LKx8ARKIMXsgmyFrirZTA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383174679888.5240225067582; Sat, 13 Jun 2026 13:39:34 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7q-0005D5-Sd; Sat, 13 Jun 2026 16:38:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7R-0004XH-7A; Sat, 13 Jun 2026 16:38:21 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7P-0003Yn-7I; Sat, 13 Jun 2026 16:38:16 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B6E481B6EF1; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 2BCC03CE942; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=JhsN/767JFqhwqO2AGJRt0GzEC5CwLXGBheFiPVcamw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=wov8GeXecoFRrsEEejqLIm8UzGgbOiWvhyUZ4wU+ZC8XINyu7cvq4t4KT/Awwsr2Y erH3i0gW3N5c2ZcgkF2vsODYXNofaS8ghyOmV7+qfTwL5GgOnNV850Y2KJTJzsBiR2 IvSQRJb8PXiE+xN2rhnMcVuAhcwkskdWOAbomMjN+GI91Rq+Ao4zye28SdTQx3wFNt 2Bbn+gcPLqecXcC3GTZ8nRZiGIPpaIaJf3+iOI44HsDSR/LDgOE0K+NbKe7g4o67kX aGmY5KS3E+hpcTlke1Z6nzwT9Vz1kCzbXs66UxiUiVw00QBAqFAPIBEp4Bx3GuXt7c q4Co4znA5dAVw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Wei Che Kao , Michael Tokarev Subject: [Stable-11.0.2 22/72] lsi53c895a: fix use-after-free of cancelled request Date: Sat, 13 Jun 2026 23:34:48 +0300 Message-ID: <20260613203542.1809153-22-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383175358158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini When processing the Message Out phase, the lsi53c895a controller can cancel a request and the continue by processing more messages. When this happens, it is important that a cancelled request is not processed further, because scsi_req_cancel can cause the request to be freed. Right now this is happening in two cases, but not when cancelling the entire queue of requests after an ABORT, CLEAR QUEUE or BUS DEVICE RESET message. In that case, a subsequent ABORT TAG message can use a dangling current_req. There are three possible fixes: - add a missing check inside the loop, clearing current_req if p->req =3D=3D current_req. This is obvious but complicates the code inside the foreach loop. - change the conditional prior to the loop from "if (s->current)" to "if (current_req)". This would work, because s->current !=3D NULL implies current_req !=3D NULL, and would clear current_req correctly. However it is less obvious because the point of the code is to clear the entire queue, which consists of s->current and s->queue; current_req is not special here. - delay the retrieval of current_req until an ABORT TAG message is seen. This is the most correct option, because the SCSI protocol only deals with tags; requests are a QEMU concept that only makes sense for the purpose of calling into the SCSI layer. Reported-by: Wei Che Kao Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 5297a0fc65317ba7f79ef44ce7a44e41d15fdb27) Signed-off-by: Michael Tokarev diff --git a/hw/scsi/lsi53c895a.c b/hw/scsi/lsi53c895a.c index 54123f7757..0843d325ab 100644 --- a/hw/scsi/lsi53c895a.c +++ b/hw/scsi/lsi53c895a.c @@ -1000,10 +1000,8 @@ static void lsi_do_msgout(LSIState *s) =20 if (s->current) { current_tag =3D s->current->tag; - current_req =3D s->current; } else { current_tag =3D s->select_tag; - current_req =3D lsi_find_by_tag(s, current_tag); } =20 trace_lsi_do_msgout(s->dbc); @@ -1058,9 +1056,13 @@ static void lsi_do_msgout(LSIState *s) case 0x0d: /* The ABORT TAG message clears the current I/O process only. = */ trace_lsi_do_msgout_abort(current_tag); + if (s->current) { + current_req =3D s->current; + } else { + current_req =3D lsi_find_by_tag(s, current_tag); + } if (current_req && current_req->req) { scsi_req_cancel(current_req->req); - current_req =3D NULL; } lsi_disconnect(s); break; @@ -1086,7 +1088,6 @@ static void lsi_do_msgout(LSIState *s) /* clear the current I/O process */ if (s->current) { scsi_req_cancel(s->current->req); - current_req =3D NULL; } =20 /* As the current implemented devices scsi_disk and scsi_gener= ic --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383131; cv=none; d=zohomail.com; s=zohoarc; b=OHuoHabrKwNzzBpnSc+58npjjb0hUgTcEB9UttMjSitURgARcPDd6gi/QqT/dySdS7ilxt1CEyC8WIBmD36eSODdouy8HIy3jEAf8fNvKtS7S7SMM1du9uN9IgCdd+beveW4FcFYjF4WiNBzSa3Puv55tqkUAUBnoIrOuqdrvOY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383131; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ANOXZm6dcj30NfIvaUKISNxJr1+sXM45YqnSN7lXA2s=; b=kFuWp3AXMdD8HDPU5OoBpUUCAnsKbRMNczk+w+ZOnNLt6L9vie+AkazYj0s7JrXLGk5lw2rNyYoBBKhyYOD2T6eRPaWhs7Tzv8kelGBf06y9s3oYz/h5tRphI4AOicH6z2/4aiFoDVwArH6pIaAhaS5xcLg/hasrBvdES/sb8UU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383131394147.99057023961905; Sat, 13 Jun 2026 13:38:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7p-000549-BM; Sat, 13 Jun 2026 16:38:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7R-0004XG-75; Sat, 13 Jun 2026 16:38:21 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7P-0003Yo-7m; Sat, 13 Jun 2026 16:38:16 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C3E601B6EF2; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 39F2F3CE943; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=iBMovGSeLWV0hOg/lRXOTm8xcdar8YmPiwUV+GGbnlA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=vdAPdGmJKXf9KvfixFeF2i0nnCiWHtExtsCwql1p3RG7uTkW4KkT0Rk6K6L4UvBpv dOduBTofadyNNx31Eizfcn4Y6uTLbmkYPi2k5jFfcwBmm/Ja9NzC2hvzKK9r7WPU3H tyJdwGsYBoyRE8VWt3LaSeQu95Xq9x/nAL1wORC916EeGHYhwWeU/k5VBa/32nUfZW Uej6f9wqa3JdE3Y+owa+oS7y5YjWYCsqReUI7gDLzO1YzuDVkkzfiSiA1kSx87tm8n ZllMzUQpFz5d+Sldb4iFmMOGR3C6IgE6dL5wL7OB8nP9FZ+sPxcN3Yb1PMWGSzhClj zeNUBsMOQPehQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 23/72] lsi53c895a: clear tag byte when processing messages Date: Sat, 13 Jun 2026 23:34:49 +0300 Message-ID: <20260613203542.1809153-23-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383133182158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini Instead of simply ORing the message byte, clear what was there before. Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 4494dec8c2bfd8a5d9b1eabe4a26ab850a4f6700) Signed-off-by: Michael Tokarev diff --git a/hw/scsi/lsi53c895a.c b/hw/scsi/lsi53c895a.c index 0843d325ab..1b7f02fc7c 100644 --- a/hw/scsi/lsi53c895a.c +++ b/hw/scsi/lsi53c895a.c @@ -1041,16 +1041,19 @@ static void lsi_do_msgout(LSIState *s) } break; case 0x20: /* SIMPLE queue */ + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; trace_lsi_do_msgout_simplequeue(s->select_tag & 0xff); break; case 0x21: /* HEAD of queue */ qemu_log_mask(LOG_UNIMP, "lsi_scsi: HEAD queue not implemented= \n"); + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; break; case 0x22: /* ORDERED queue */ qemu_log_mask(LOG_UNIMP, "lsi_scsi: ORDERED queue not implemented\n"); + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; break; case 0x0d: --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383129; cv=none; d=zohomail.com; s=zohoarc; b=RCzKzqC4ZuCbv8buwtTipnfdvMb/aTppiTgz3Vik8ulbe6yYchOoOPXZT5NlVRN+2+/hdMz6Wu7vYbR3einejM0Ygt/ICZNAU1HGcXkNQvTt5Jh6RcH5Qdz1HKlhncNXzqO0puz+62O0m9naKobKnFyjr833FdsLuBPFsOvUT+Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383129; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ZAdl/QfKeg5j6Y7Dyo0ZcDCXuPYv2JEGheYi+zNctdg=; b=eF/P8M7iL+NWVV84LnWIwftACipRFLN4jtwhNK16jllqJZlHITos9bsIeixqccAcXcNSUvMAApurPISJKhZtD6lHx3GViE2A+jHQaXDyLYP3HRg3NzXgjyqIqLak+Jk5hJbgl2QhjDtnii/3pc6FMDMncAxBVlMw5C0Z+ggUB1A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383129392470.5545054080502; Sat, 13 Jun 2026 13:38:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7q-0005C3-Ie; Sat, 13 Jun 2026 16:38:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7U-0004YH-7M; Sat, 13 Jun 2026 16:38:22 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7S-0003hc-LK; Sat, 13 Jun 2026 16:38:19 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D13B31B6EF3; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 46BB83CE944; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=WG1eqqDRC0XESaMjrceBdpmpNaVRXVi8x92Ta+mAlxQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ljsxOOPweHSiNCrMU/r2D9K7CkImQeAXrN1pDwTMRb2e202e+fwhmiLxTRWMilSat dhgJokMoK7crtwkfQIG/zQaVFhecRExGhDCYdoHY7HUvMWGV2XLWTr/C5Q/gkWUAnC qBLqtM0MqjWzQnUTPz7ud+SDLLyve0qmRh7UFWs1WcefqQBOn8dOoHnnFWCKGQqZTe 2K59Ny60n/IWAXMzLfnwk2AF9Bt29XoW/+6PXxDhPYojZ/07PzGm0nwNaGNwrZ5pTO kVjCjayzJAwYT1plzuQmYw84TTybZtfXGYZ7GTjmWoI7Pchv8M1jPezHKkw6xoU7VO w+BcHac8oQFYg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Wei Che Kao , Michael Tokarev Subject: [Stable-11.0.2 24/72] apic: fix delivery bitmask with modified xAPIC ids Date: Sat, 13 Jun 2026 23:34:50 +0300 Message-ID: <20260613203542.1809153-24-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383131369158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini Self-IPIs (or all-but-self IPIs) in QEMU can cause a out-of-bounds access to deliver_bitmask, because the access uses the APIC ID register which is writable by the guest. However, foreach_apic uses the delivery bitmask indexes to look up the local_apics[] array, which is indexed by *initial* APIC id. Using the right id fixes both a possible heap write overflow if the modified APIC id is too large for max_apic_words, and a mis-delivery of both self and all-but-self IPIs. Reported-by: Wei Che Kao Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 153dc2fa7bbe0491290d22c4bbb6807074f24260) Signed-off-by: Michael Tokarev diff --git a/hw/intc/apic.c b/hw/intc/apic.c index 8766ed00b9..ced7df49bd 100644 --- a/hw/intc/apic.c +++ b/hw/intc/apic.c @@ -648,13 +648,6 @@ static void apic_deliver(APICCommonState *s, uint32_t = dest, uint8_t dest_mode, APICCommonState *apic_iter; uint32_t deliver_bitmask_size =3D max_apic_words * sizeof(uint32_t); g_autofree uint32_t *deliver_bitmask =3D g_new(uint32_t, max_apic_word= s); - uint32_t current_apic_id; - - if (is_x2apic_mode(s)) { - current_apic_id =3D s->initial_apic_id; - } else { - current_apic_id =3D s->id; - } =20 switch (dest_shorthand) { case 0: @@ -662,14 +655,20 @@ static void apic_deliver(APICCommonState *s, uint32_t= dest, uint8_t dest_mode, break; case 1: memset(deliver_bitmask, 0x00, deliver_bitmask_size); - apic_set_bit(deliver_bitmask, current_apic_id); + /* + * The self and all-but-self cases do not use apic_match_dest() and + * directly fill in deliver_bitmask; the bitmask's indexes in turn + * map to local_apics[] slots which are never changed even if the + * xAPIC id is modified. So use s->initial_apic_id instead of s->= id. + */ + apic_set_bit(deliver_bitmask, s->initial_apic_id); break; case 2: memset(deliver_bitmask, 0xff, deliver_bitmask_size); break; case 3: memset(deliver_bitmask, 0xff, deliver_bitmask_size); - apic_reset_bit(deliver_bitmask, current_apic_id); + apic_reset_bit(deliver_bitmask, s->initial_apic_id); break; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383281; cv=none; d=zohomail.com; s=zohoarc; b=O5PcbDTW4+rajsMQMpGlV4SMUtVZSloIFhAkYyZ/AHXbQ7yla0xwTE5kwdqWOrNE4fr6Ed+m98bRba8d4OXHWzB2CdIZOlMs9JurGTvXikRHqsqCLWYf/cF2JwI9w6HaJLvjhdtpv5KQirfU4RUSATaw9/hNwV44DyQceHFOaJ4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383281; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=iE/rb4A2p1obU9jOkJvmuimN87umjPB5QwmSmlR5AfY=; b=XD3jxOBc7n4wf0xyjeGrh8d94GyWU7lYl6q6P1kgDSW7fwUeelk6uL1aiTogWr29tphA/2INCq3ZqXWuwAT7pjkRzGvBqB1i4sCSjZngBmKD5slpxVC9q5cI3TUf2yf2WFN4Z/ggv7+PehAGpu00o/BFoCfuJnEyl2t9y1LDU1E= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383281595237.1615640907761; Sat, 13 Jun 2026 13:41:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7r-0005Hk-MI; Sat, 13 Jun 2026 16:38:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7U-0004YI-Db; Sat, 13 Jun 2026 16:38:22 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7S-0003hd-LE; Sat, 13 Jun 2026 16:38:20 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id DE3DF1B6EF4; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 53E503CE945; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=qo7CUVoBJT6J/Xn9BS8biH/2dl+pou5Ie/pG+aXu1z8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=kZSjIoLn0rTyuRh/NM/Ugzrx3XEgoRMZyNEDVBk0C1naDoqJhn0ZJnWRbkm6PpGCR 8QXhof8aVhn7I90xHy7hLMPmMSAQX16+Qt5SnReNBOV/ZNZM2f5pA2X8+ejUIl5wDo 7hQqBVJh/iCKGlhsDXv36IUEwnIlz7QEriRt15y2UNCjox57dgaFNtImErCQR20GTQ KEn2qp4cmo+oOKPdk81H3Fm4E3wRY/Odd7+iH9NEd8Nho/MosccWK7K6eUjzCIH8ke Nu0govmikao6+b+4RhHKfNjM3TItcbyca9bxkXpufEPs+hYeAv8Kh9JnoecDM1C0gi A0QfUr7zF8Ewg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Jinjie Ruan , Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 25/72] mc146818rtc: Fix get_guest_rtc_ns() overflow bug Date: Sat, 13 Jun 2026 23:34:51 +0300 Message-ID: <20260613203542.1809153-25-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383281738158500 Content-Type: text/plain; charset="utf-8" From: Jinjie Ruan In get_guest_rtc_ns(), "s->base_rtc" is uint64_t, which multiplied by "NANOSECONDS_PER_SECOND" may overflow the uint64_t type, which will cause the QEMU Linux Virtual Machine's RTC time to jump and in turn triggers a kernel Soft Lockup and ultimately leads to a crash. Fix it by avoiding adding s->base_rtc in get_guest_rtc_ns_offset(), because get_guest_rtc_ns() is used either take the remainder of NANOSECONDS_PER_SECOND or take the quotient of NANOSECONDS_PER_SECOND. Fixes: 56038ef6234e ("RTC: Update the RTC clock only when reading it") Signed-off-by: Jinjie Ruan Link: https://lore.kernel.org/r/20260114013257.3500578-1-ruanjinjie@huawei.= com Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 4b6c088c88ccc9e7cafc72759c99742b3993f9f7) Signed-off-by: Michael Tokarev diff --git a/hw/rtc/mc146818rtc.c b/hw/rtc/mc146818rtc.c index ccbb279716..bcab018c7c 100644 --- a/hw/rtc/mc146818rtc.c +++ b/hw/rtc/mc146818rtc.c @@ -77,12 +77,13 @@ static inline bool rtc_running(MC146818RtcState *s) (s->cmos_data[RTC_REG_A] & 0x70) <=3D 0x20); } =20 -static uint64_t get_guest_rtc_ns(MC146818RtcState *s) +/* + * Note: get_rtc_ns_since_last_update() does not include the base_rtc seco= nds + * value. This does not matter if the caller only needs the nanoseconds p= art. + */ +static uint64_t get_rtc_ns_since_last_update(MC146818RtcState *s) { - uint64_t guest_clock =3D qemu_clock_get_ns(rtc_clock); - - return s->base_rtc * NANOSECONDS_PER_SECOND + - guest_clock - s->last_update + s->offset; + return qemu_clock_get_ns(rtc_clock) - s->last_update + s->offset; } =20 static void rtc_coalesced_timer_update(MC146818RtcState *s) @@ -258,7 +259,7 @@ static void check_update_timer(MC146818RtcState *s) return; } =20 - guest_nsec =3D get_guest_rtc_ns(s) % NANOSECONDS_PER_SECOND; + guest_nsec =3D get_rtc_ns_since_last_update(s) % NANOSECONDS_PER_SECON= D; next_update_time =3D qemu_clock_get_ns(rtc_clock) + NANOSECONDS_PER_SECOND - guest_nsec; =20 @@ -510,7 +511,7 @@ static void cmos_ioport_write(void *opaque, hwaddr addr, /* if disabling set mode, update the time */ if ((s->cmos_data[RTC_REG_B] & REG_B_SET) && (s->cmos_data[RTC_REG_A] & 0x70) <=3D 0x20) { - s->offset =3D get_guest_rtc_ns(s) % NANOSECONDS_PER_SE= COND; + s->offset =3D get_rtc_ns_since_last_update(s) % NANOSE= CONDS_PER_SECOND; rtc_set_time(s); } } @@ -623,10 +624,8 @@ static void rtc_update_time(MC146818RtcState *s) { struct tm ret; time_t guest_sec; - int64_t guest_nsec; =20 - guest_nsec =3D get_guest_rtc_ns(s); - guest_sec =3D guest_nsec / NANOSECONDS_PER_SECOND; + guest_sec =3D s->base_rtc + get_rtc_ns_since_last_update(s) / NANOSECO= NDS_PER_SECOND; gmtime_r(&guest_sec, &ret); =20 /* Is SET flag of Register B disabled? */ @@ -637,7 +636,7 @@ static void rtc_update_time(MC146818RtcState *s) =20 static int update_in_progress(MC146818RtcState *s) { - int64_t guest_nsec; + uint64_t guest_nsec; =20 if (!rtc_running(s)) { return 0; @@ -652,7 +651,7 @@ static int update_in_progress(MC146818RtcState *s) } } =20 - guest_nsec =3D get_guest_rtc_ns(s); + guest_nsec =3D get_rtc_ns_since_last_update(s); /* UIP bit will be set at last 244us of every second. */ if ((guest_nsec % NANOSECONDS_PER_SECOND) >=3D (NANOSECONDS_PER_SECOND - UIP_HOLD_LENGTH)) { --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383374; cv=none; d=zohomail.com; s=zohoarc; b=ax7szcuV/7zhfbHgmBIVs1wB90aZP+S6F/i/vPOq/YDl0yJAr2/bh88w2+PfIK/Ud/oz3Dw9COh8XMXJxjnlAlxlAj3xUZb5Xd5+KTwzwX0U9jG3zRyrV+HUHzfv8rHKCucluVwTM7KATa53uOT0XY+4iOlFVTtStK7fb9dETMw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383374; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tucsnmonG+4p1u7XFQ0gQ/y4jJpFlnWJXSkr/KOwnPI=; b=SqJbCqT96qxa1tbceWPGf09dTpPN50AwsDotPVkrNpFUdRr2BNVoQqyb3uKcGWHr5ttA/KSyIlhvHrrWVYGS3jKqQ+s0seKIMmLjAmPc3gnPVWCRmbhxQR1Kyq0VlX6b9IQ1wJh3OWJPITZEfYxm9MXRtcnKg5q5T9ePEztGc6U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138337467062.73623068171901; Sat, 13 Jun 2026 13:42:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7s-0005NF-Us; Sat, 13 Jun 2026 16:38:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7X-0004cM-HE; Sat, 13 Jun 2026 16:38:24 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7V-0003lU-L3; Sat, 13 Jun 2026 16:38:23 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id F1F2A1B6EF5; Sat, 13 Jun 2026 23:36:03 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 61C1E3CE946; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382963; bh=Y5IXrWGf9fd6lqmrWDpBY6sNZwdv47Q9g5caZWHM55s=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=IhNZeBskryMQhvt/LwVlwj9AqCTNWNEBPdhZYj7yoz0oAwMAaSQO/MiEqGGCWpTlA FX/NSjI/2cbkDbnjNuF6OfU4ieMszug2wBT0UKjeNnUNZOnjHLJMAmKYMZ6VPhC4EA 8Uv+jwoPyMebKhQFMv0rsTNgUSgzlh/1N7T6FEs5nIM9yj3mV/y0MOqNx7wnJWbdVY NlXswyqkhAX9q/9+FzZfBqerwAg/Ygm0XRii4GDJEahOxL09LDSNw5k5pIuowP1LNl wNvOpF5oofg4m3s9L+dgphi1qDSTOtgFsls3ZOZfn1lwQb7OAQHNeEtO0jouBDPPQP CigqFBEbQwv+A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Kevin Wolf , Hanna Reitz , Stefan Hajnoczi , Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 26/72] block/linux-aio: bound ioq_submit() recursion depth Date: Sat, 13 Jun 2026 23:34:52 +0300 Message-ID: <20260613203542.1809153-26-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383376108158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" qemu_laio_process_completions() wraps its body in defer_call_begin / defer_call_end. Inside the section, completion callbacks wake coroutines that queue new aiocbs; laio_do_submit() defers laio_deferred_fn. At the bottom of qemu_laio_process_completions() the defer_call_end() fires laio_deferred_fn, which calls ioq_submit(), closing the cycle: ioq_submit -> io_submit(2) // some sync completions -> qemu_laio_process_completions // defer_call_begin -> aio_co_wake // resumes coroutine -> laio_do_submit -> defer_call(laio_deferred_fn, s) // enqueued -> defer_call_end // nesting drops to 0 -> laio_deferred_fn -> ioq_submit // +1 stack frame, loop When io_submit(2) returns asynchronously (O_DIRECT) the cycle terminates in one extra frame: the fresh aiocb is still in flight, no completion is drained, no coroutine wakes, no new submission queues. When submissions complete synchronously (non-O_DIRECT, or per-descriptor drivers such as vmdk) each level enqueues more work for the next defer_call_end() to drain, so recursion grows without bound and QEMU crashes with SIGSEGV on the thread guard page. The cycle was closed by two performance commits, each correct in isolation: 076682885d ("block/linux-aio: convert to blk_io_plug_call() API") -- introduced laio_deferred_fn and wired laio_do_submit -> defer_call(laio_deferred_fn, s). 84d61e5f36 ("virtio: use defer_call() in virtio_irqfd_notify()") -- added defer_call_begin/end around qemu_laio_process_completions so virtio-irqfd notifications batch across a completion pass. The supported aio=3Dnative + cache=3Dnone pairing keeps submissions asynchronous, so the cycle stays bounded; nothing in the code enforces that contract. Observed in production as a SIGSEGV during a backup job configured with --cached + aio=3Dnative; reproducible on upstream with qemu-io against vmdk. Cap ioq_submit() recursion with a counter on LaioQueue, which is only accessed from the AioContext home thread. On overflow, return without submitting. The pending work is drained by s->completion_bh, which qemu_laio_process_completions() has already scheduled on entry -- no work is lost; one event-loop round-trip of latency is paid only when the bound is hit, which cannot happen on a supported configuration. Signed-off-by: Denis V. Lunev CC: Kevin Wolf CC: Hanna Reitz CC: Stefan Hajnoczi CC: Paolo Bonzini Message-ID: <20260520142503.251959-2-den@openvz.org> Signed-off-by: Stefan Hajnoczi (cherry picked from commit 6864bec553b2e37699739615e604fc3c7bae0e1d) Signed-off-by: Michael Tokarev diff --git a/block/linux-aio.c b/block/linux-aio.c index 0a7424fbb3..5aaf2e8514 100644 --- a/block/linux-aio.c +++ b/block/linux-aio.c @@ -36,6 +36,19 @@ /* Maximum number of requests in a batch. (default value) */ #define DEFAULT_MAX_BATCH 32 =20 +/* + * Bound on how deep ioq_submit() may recurse on a single LaioQueue via the + * ioq_submit -> qemu_laio_process_completions -> defer_call_end -> + * laio_deferred_fn -> ioq_submit cycle. The cycle terminates naturally + * when io_submit(2) returns asynchronously (O_DIRECT), but can grow + * without bound when submissions complete synchronously. On overflow + * the caller returns without submitting; the outermost + * qemu_laio_process_completions() has already scheduled s->completion_bh + * (via qemu_bh_schedule() at the top of that function), which resumes + * submission from the next event-loop dispatch. + */ +#define IOQ_SUBMIT_MAX_DEPTH 8 + struct qemu_laiocb { Coroutine *co; LinuxAioState *ctx; @@ -61,6 +74,7 @@ typedef struct { unsigned int in_queue; unsigned int in_flight; bool blocked; + unsigned int submit_depth; QSIMPLEQ_HEAD(, qemu_laiocb) pending; } LaioQueue; =20 @@ -331,6 +345,7 @@ static void ioq_init(LaioQueue *io_q) io_q->in_queue =3D 0; io_q->in_flight =3D 0; io_q->blocked =3D false; + io_q->submit_depth =3D 0; } =20 static void ioq_submit(LinuxAioState *s) @@ -340,6 +355,11 @@ static void ioq_submit(LinuxAioState *s) QEMU_UNINITIALIZED struct iocb *iocbs[MAX_EVENTS]; QSIMPLEQ_HEAD(, qemu_laiocb) completed; =20 + if (s->io_q.submit_depth >=3D IOQ_SUBMIT_MAX_DEPTH) { + return; + } + s->io_q.submit_depth++; + do { if (s->io_q.in_flight >=3D MAX_EVENTS) { break; @@ -385,6 +405,8 @@ static void ioq_submit(LinuxAioState *s) * pended requests will be submitted from there. */ } + + s->io_q.submit_depth--; } =20 static uint64_t laio_max_batch(LinuxAioState *s, uint64_t dev_max_batch) --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383345; cv=none; d=zohomail.com; s=zohoarc; b=M9ubOVGWuqy+i/Cy/gt23GHoOFybKJub/CBKVRd2G+2905y8u4Lwx7ELFG040GDu33Egvxqytec0dHSrtI52zFZOLlGW+264Bhz0h/vpkCzh5LEaI6rA3vViGbUPHNK01z+84jzcEV2p97J9CA3Tx3aJxlKqI1MCD5XWZ82cplU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383345; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=I20BjNk0as2dvmlR7BaHdkTzikRUg0imDQdmZn7Dnts=; b=IyYoC0MBR8cbOVtUITDefNzcdO8rZyNeHm5zA5Ie6FGDMyrhKwKfFrQFTGM3VJomirCQhRlTU724DLYgpEOVPidBEhkiXuDX4QIy7efvxNRlemx+zl5dWpT1N3EEhD/TZSoQs30UjRgkGiB7VmDVfGFs9+sOUDdvDDyQDwK0MuA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383345975304.47707797906503; Sat, 13 Jun 2026 13:42:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7u-0005RA-2H; Sat, 13 Jun 2026 16:38:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7r-0005JG-O9; Sat, 13 Jun 2026 16:38:43 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7p-0003mJ-Rs; Sat, 13 Jun 2026 16:38:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 0C0BD1B6EF6; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 756353CE947; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=WoDzbd+bsFS1hjb4l+NXgUrDQ81yYUUXj+/8Gg3rZ10=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=oQkV7kHEKKnssx0rVTwnWKay3rkAQuGsa8DoStteL701rDRsbGAH3h5ZmpqpIDqL6 D7qI4ncEXHwrQfPTHUnh8pNLIRoCYByc8HiLv7tmkiWB9VcljslOywKAf6niwci83Y DUX123fDfnct9u0yhcWSKmyBpPD73f0xzOOsSBQPKaG7OAiZGn6F6Aq4ruAPQkTiA2 hQPgHR7mN3BZWT102y4q1r5SKJ5AAq3wpYUU1/+I91acenzYZvIixHcvryR60APn3i HnzNg7XKHbGe/S5AO+jIZ5iTBX7U8RQ89Oc3VeCjD2TIp9IbwVQ1oMDtBYuhx0qAXW Wobv9Y9wplPlQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Michael Tokarev Subject: [Stable-11.0.2 27/72] target/arm: SVE2 FMAXP, FMINP must honour AH=1 Date: Sat, 13 Jun 2026 23:34:53 +0300 Message-ID: <20260613203542.1809153-27-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383347926158500 From: Peter Maydell The behaviour of floating-point maximum and minimum insns has some odd special cases when FPCR.AH=3D1. We get this right in most places (for instance, the ASIMD FMAXP, FMINP) but forgot about it for the SVE2 versions of FMAXP and FMINP. Cc: qemu-stable@nongnu.org Fixes: 384433e70983 ("target/arm: Implement FPCR.AH semantics for FMINP and= FMAXP") Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Message-id: 20260521122913.1565011-2-peter.maydell@linaro.org (cherry picked from commit 446050c4dfe4566ae3fcba9c6588c89a66ed4b33) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/helper-sve-defs.h b/target/arm/tcg/helper-sve-d= efs.h index c3541a8ca8..cd05dd0fb4 100644 --- a/target/arm/tcg/helper-sve-defs.h +++ b/target/arm/tcg/helper-sve-defs.h @@ -2914,6 +2914,20 @@ DEF_HELPER_FLAGS_6(sve2_fminp_zpzz_s, TCG_CALL_NO_RW= G, DEF_HELPER_FLAGS_6(sve2_fminp_zpzz_d, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, fpst, i32) =20 +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_h, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_s, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_d, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) + +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_h, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_s, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_d, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) + DEF_HELPER_FLAGS_5(sve2_eor3, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, i= 32) DEF_HELPER_FLAGS_5(sve2_bcax, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, i= 32) DEF_HELPER_FLAGS_5(sve2_bsl1n, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, = i32) diff --git a/target/arm/tcg/sve_helper.c b/target/arm/tcg/sve_helper.c index 062d8881bd..179cbd74fb 100644 --- a/target/arm/tcg/sve_helper.c +++ b/target/arm/tcg/sve_helper.c @@ -778,6 +778,14 @@ DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_h, float16, H1_2, floa= t16_min) DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_s, float32, H1_4, float32_min) DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_d, float64, H1_8, float64_min) =20 +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_h, float16, H1_2, helper_vfp_ah_maxh) +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_s, float32, H1_4, helper_vfp_ah_maxs) +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_d, float64, H1_8, helper_vfp_ah_maxd) + +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_h, float16, H1_2, helper_vfp_ah_minh) +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_s, float32, H1_4, helper_vfp_ah_mins) +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_d, float64, H1_8, helper_vfp_ah_mind) + #undef DO_ZPZZ_PAIR_FP =20 /* Three-operand expander, controlled by a predicate, in which the diff --git a/target/arm/tcg/translate-sve.c b/target/arm/tcg/translate-sve.c index 5bace3fda1..6a5c508743 100644 --- a/target/arm/tcg/translate-sve.c +++ b/target/arm/tcg/translate-sve.c @@ -7666,8 +7666,8 @@ TRANS_FEAT_NONSTREAMING(HISTSEG, aa64_sve2, gen_gvec_= ool_arg_zzz, DO_ZPZZ_FP(FADDP, aa64_sme_or_sve2, sve2_faddp_zpzz) DO_ZPZZ_FP(FMAXNMP, aa64_sme_or_sve2, sve2_fmaxnmp_zpzz) DO_ZPZZ_FP(FMINNMP, aa64_sme_or_sve2, sve2_fminnmp_zpzz) -DO_ZPZZ_FP(FMAXP, aa64_sme_or_sve2, sve2_fmaxp_zpzz) -DO_ZPZZ_FP(FMINP, aa64_sme_or_sve2, sve2_fminp_zpzz) +DO_ZPZZ_AH_FP(FMAXP, aa64_sme_or_sve2, sve2_fmaxp_zpzz, sve2_ah_fmaxp_zpzz) +DO_ZPZZ_AH_FP(FMINP, aa64_sme_or_sve2, sve2_fminp_zpzz, sve2_ah_fminp_zpzz) =20 static bool do_fmmla(DisasContext *s, arg_rrrr_esz *a, gen_helper_gvec_4_ptr *fn) --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383267; cv=none; d=zohomail.com; s=zohoarc; b=jqfXbIZ68maIxfYYLRIMEDzcFC2XCQNElvsq1HNiO/bdZhtg8iiPf6BC8sSEiRc6Qkc/t6ZnYNYHJumv9m54WtgoafsGvgFeTkB2dvSA7fw9uFc6eHb/wfdCjzdWwBOdwK5tkFLGsyfhGJhnRwNqMcX3/Dc39bwJWDxwL0PGoKo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383267; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=viX3VZjmyK2dGm+2YqBvE8L+Q3aCxw0L4v8u38lPCBg=; b=RUJXI9PQ/0PonrvPjAf1TtNXlQHilCDEDJDW4OqywSQmSrkIG6HIj7UqugqlmjuSGQnTdYqa3nZP8j/M5cNPIIYUEBYgZJ+T68LpmOVwPVVU3ufKw2BL8jAiFme8oYbkObA+BM0J1OG8yTmUMWAmsWsCqKlMYx1/op/icHfRh50= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383267802835.6649132162636; Sat, 13 Jun 2026 13:41:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7w-0005jd-Eb; Sat, 13 Jun 2026 16:38:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7u-0005Xe-NW; Sat, 13 Jun 2026 16:38:46 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7t-0003rM-2e; Sat, 13 Jun 2026 16:38:46 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 1B8881B6EF7; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 839053CE948; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=6xlNGyXQ+fCOU4K82Yr9pLl9TrVrEkNSH6c86ZKUM2U=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=fm0bYMOGeP4LdhTt6nmfrWaWfHU9PTMi6Zv5kOU7zw1KGa5noTgMPtzkv2qKmSpms OVGzpYkEFYSKyay5j+UCd17Wq/8TCTK7EqXCsvMdGMLGpiJ4ho5syiY69WRFqW2HU0 3mQCeLEQUyLz3RNEfHK8sebbpjZiS4bXEUNYemm9VqIub4k8qcDnbXHIopLd0Dyke1 Vktq5GZGovqhLKXg+Kwr9rl2CebHfO8aB45+oQWJero0pDs8HZXgd9wXuJXKB6FKk/ tTgt/Q+vvwaKdrOIsw1crbXeLFm6j+dCi6m2uuMz7BW9Sbp20fVfz5ZqsWV2eorRI7 56NraMxrJVMyg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Richard Henderson , Michael Tokarev Subject: [Stable-11.0.2 28/72] target/arm: Use FPST_A64_F16 for SVE FCVTLT_hs Date: Sat, 13 Jun 2026 23:34:54 +0300 Message-ID: <20260613203542.1809153-28-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383269672158500 From: Peter Maydell We should be using the F16-specific float_status for conversions from half-precision, because halfprec inputs never set Input Denormal. If we use the FPST_A64 fpstatus then we will incorrectly set FPCR.IDC for input-denormals when FPCR.AH=3D1. In commit e07b48995aaa we updated most of the halfprec-to-other conversion insns to use FPST_A64_F16 as part of implementing FEAT_AHP. However we missed the SVE FCVTLT instruction, which has a halfprec-to-single encoding. Correct the FPST we use for the hs variant of FCVTLT. Cc: qemu-stable@nongnu.org Fixes: e07b48995aaa ("target/arm: Use FPST_A64_F16 for halfprec-to-other co= nversions")a Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Reviewed-by: Richard Henderson Message-id: 20260521122913.1565011-3-peter.maydell@linaro.org (cherry picked from commit aa42300f86d172d7252f0cb95c2efd7570ad6b8f) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/translate-sve.c b/target/arm/tcg/translate-sve.c index 6a5c508743..f9dfda4a7a 100644 --- a/target/arm/tcg/translate-sve.c +++ b/target/arm/tcg/translate-sve.c @@ -7826,7 +7826,7 @@ TRANS_FEAT(BFCVTNT, aa64_sme_sve_bf16, gen_gvec_fpst_= arg_zpz, s->fpcr_ah ? FPST_AH : FPST_A64) =20 TRANS_FEAT(FCVTLT_hs, aa64_sme_or_sve2, gen_gvec_fpst_arg_zpz, - gen_helper_sve2_fcvtlt_hs, a, 0, FPST_A64) + gen_helper_sve2_fcvtlt_hs, a, 0, FPST_A64_F16) TRANS_FEAT(FCVTLT_sd, aa64_sme_or_sve2, gen_gvec_fpst_arg_zpz, gen_helper_sve2_fcvtlt_sd, a, 0, FPST_A64) =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383402; cv=none; d=zohomail.com; s=zohoarc; b=D3AJossCt3skLORreyyAHGYspneUE7JjUNBrR57aM+dyfrNeDuoE+8atK7rUCriY1kibQhDQ+mtjXJk0CiGIau4H7VcYMyv4nevuYt5b90jI3uQJkNaP8NLLPSx5gfugY+v8JO5zM3I/zHuCWqQ2QiDgy2sjuSxe+6IaqUMadXU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383402; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=DjfV00XFRXfJt/kXP0vZG960O91CPxE3rgMrmDhS2VQ=; b=MCg8LJxDygKPnAy0UTum+Gzud/3kYDLLX27QFAOXGmVtx4aeo28aj3QWt5dUc7HgFTpW6FgMq3aR+uTE1hfTPGzUDPmwf8lFXHgYlnBOXpQFFRDX/zSysY19psXABOpXQV9DPMHO3egIW2tnwx4EJrOY8PEHv67LgU2xmfMWvyI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383402459928.0414733747211; Sat, 13 Jun 2026 13:43:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV7y-0005un-31; Sat, 13 Jun 2026 16:38:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7v-0005b2-8A; Sat, 13 Jun 2026 16:38:47 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7t-0003tP-Ho; Sat, 13 Jun 2026 16:38:46 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 2B7961B6EF8; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 936E33CE949; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=avXEFBMXyDcCefkdmfwuGAjiUyl870djlo++1qvZzJI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=U+q5A3Oo0eBprxbIeEpL0s5/W6Y5GPbyKwECcm1cnbz8LHXvilLc0K+ZL2/H18jia zaAkg+5cr+5E4XtqQm92is1qNyecYpgQ3uZWIG/s7a427oSzEoTFgwY9StVoXExg+5 r0NdKw5XbCyeZtndwGsvkjWIqk28xXRe/bbqCTAvgc3/s6AKbVL28a0ojpmlPhUtxr oJpWiMUBSdFIz6ZQwcmT6mP2QuIo9bBUH726+DB+DqH9C2PmmoCpUiwCpSq1/g3qH3 gkanh3lRZq4XGza+FbRthYrK2G2nKwAqIEoDad9tGMsXbnCsj7oo5dTihi5licRHT3 yUUKV9Mr4okFw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Richard Henderson , Michael Tokarev Subject: [Stable-11.0.2 29/72] target/arm: Set correct fp flags for FLOGB when FPCR.AH = 1 Date: Sat, 13 Jun 2026 23:34:55 +0300 Message-ID: <20260613203542.1809153-29-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383404130158500 From: Peter Maydell Our implementation of the FLOGB insn does the operations entirely in the helper function, without needing to use fpu functions. This means it needs to handle all the fp status flags itself. We aren't setting float_flag_input_denormal_used when we use (i.e. do not flush to zero) an input denormal, which means that FPCR.IDC isn't set when it should be for FPCR.AH=3D1. We missed this when we added float_flag_input_denormal_used and made the fpu/ code set it. Add the missing float_raise(). Cc: qemu-stable@nongnu.org Fixes: d38a57a3f ("target/arm: Enable FEAT_AFP for '-cpu max'") Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Reviewed-by: Richard Henderson Message-id: 20260521122913.1565011-4-peter.maydell@linaro.org (cherry picked from commit 23ece2805f9a3f90f317aac1b49ee45783b57636) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/sve_helper.c b/target/arm/tcg/sve_helper.c index 179cbd74fb..d884ba474f 100644 --- a/target/arm/tcg/sve_helper.c +++ b/target/arm/tcg/sve_helper.c @@ -5036,6 +5036,7 @@ static int16_t do_float16_logb_as_int(float16 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -15 - clz32(frac); } /* flush to zero */ @@ -5064,6 +5065,7 @@ static int32_t do_float32_logb_as_int(float32 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -127 - clz32(frac); } /* flush to zero */ @@ -5092,6 +5094,7 @@ static int64_t do_float64_logb_as_int(float64 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -1023 - clz64(frac); } /* flush to zero */ --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383163; cv=none; d=zohomail.com; s=zohoarc; b=Jc+/BzY1kBQBtzjVbjxOLpBo11/BlOrw89H0DQe4afuits8+bjeZKGBjNyIdKTgPcl9/ZrQTX0YeE9FMFcN3DgRn56x87Imk+ph+NFrdAaJpJJbIl/LeUGyMZ5GeKY7238VzHKzdundysnSba/Rf3OmmgIaiatiVLLHoaQEUnNw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383163; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=uapO9DdXwnSiugjn6O/aiMQq7i0kYYrNusBjgwHE83M=; b=OGJbgVK7oZ8RI86t2TM7dJ7V9uhbOroCBIOX7jiu3eHHbKWqQPZO1gtGvdyAE+/Dr6EJC4EIbRI8xb/tDY9o6iShslfm0W3Z0yjYAe7AqUQ370aZfDhQfnDHv4I4m0sql/HafABYwThr1EMW/ovISWK+XZuAUfdUO2umzOZm9sI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138316317454.80920144830702; Sat, 13 Jun 2026 13:39:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV80-0006DK-14; Sat, 13 Jun 2026 16:38:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7y-0005zS-3M; Sat, 13 Jun 2026 16:38:50 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV7w-0003uE-Ba; Sat, 13 Jun 2026 16:38:49 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 3B8A21B6EF9; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id A33163CE94A; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=rWeJQo1BZj3/v/6iAk7Qi6eblFf1sDgGtXlKWB4QA7Y=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=aRbG9l5p4U/g3BQs9lHK1ckadYMBha8Phtd1vBi5KxrlfZl5PBw1gQcNumOFMW6XR zhc9oOEPZb708bRuJnr00KDFnjmvCWHdvFDANHAHJt5p0uLWaeKoFpQA8lGPfNoDdV gQEY6NS+fW2xMXfuJSe/D1d2xkpcVEBAj498hSH9lGjfW087rmFN7mbJgZ2NtmVe2u U7w6BwPoxCOXe+Lht8mKk0q33+FxtDkCz0bvqDzHahxPU3LwDRzIbUzPAmeFk7kCAv eRsWCFuY1Ei9/nYhQzPlNMk2uYDv6Z5nk1K7WAXQgrVOkptGl2b9ozCM5wRPRY0sJ6 z+Yyd/zY2xhEQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, GuoHan Zhao , John Levon , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Michael Tokarev Subject: [Stable-11.0.2 30/72] vfio-user: reject zero DMA page size capability Date: Sat, 13 Jun 2026 23:34:56 +0300 Message-ID: <20260613203542.1809153-30-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383163702158500 From: GuoHan Zhao check_pgsizes() validates that no page-size bits smaller than VFIO_USER_DEF_PGSIZE are set, but it still accepts pgsizes=3D0. This lets a malformed server overwrite the default page-size mask with zero. Later vfio_user_setup() asserts that proxy->dma_pgsizes is non-zero, so dev= ice realization aborts instead of reporting a version capability error. Reject a zero DMA page-size mask during version capability parsing. Fixes: 36227628d824 (vfio-user: implement message send infrastructure) Signed-off-by: GuoHan Zhao Reviewed-by: John Levon Link: https://lore.kernel.org/qemu-devel/20260522081306.4186242-1-zhaoguoha= n@kylinos.cn Signed-off-by: C=C3=A9dric Le Goater (cherry picked from commit ab89d02dac6f0f53e35a689f01099602aa2de816) Signed-off-by: Michael Tokarev diff --git a/hw/vfio-user/proxy.c b/hw/vfio-user/proxy.c index 314dfd23d8..3fe5b0138b 100644 --- a/hw/vfio-user/proxy.c +++ b/hw/vfio-user/proxy.c @@ -1155,9 +1155,11 @@ static bool check_pgsizes(VFIOUserProxy *proxy, QObj= ect *qobj, Error **errp) return false; } =20 - /* must be larger than default */ - if (pgsizes & (VFIO_USER_DEF_PGSIZE - 1)) { - error_setg(errp, "pgsize 0x%"PRIx64" too small", pgsizes); + /* must not be zero or smaller than default */ + if (pgsizes < VFIO_USER_DEF_PGSIZE || + (pgsizes & (VFIO_USER_DEF_PGSIZE - 1))) { + error_setg(errp, "%s 0x%"PRIx64" too small", + VFIO_USER_CAP_PGSIZES, pgsizes); return false; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383327; cv=none; d=zohomail.com; s=zohoarc; b=mZaj6lwDdj207CUnlI1hLVukKAd5VnlCbYNdj5l2JGGFLEpSIKTUjMR2OQXUq+HC1PTV/3U2Lk4LJdX2uv5WL/aB/Z+UnwCsCoM5bytx6xliANmbarEdUfIcJ+R9CV3zrIG688+VSiXi+RzXKDdN0RnwYvwikU1I9jTrGCnLOBM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383327; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=C8OltfmBdjqemAjbnbPuXVPEhCeqj/TByYPdohd8IDA=; b=FP7QO6F22RfI1bkSsnfXkcWXo10VLBWkQQITb3GCHFMm4uhBQVxDREh0Sh6446aYVL8alr/0AmboL4gO1LKgtRASJ26QWyBAhgi3oNa0QCLG8osqLJGUtf93GxcQYrr7yhM++WGDSKrMV0U1CIV8sO80Wg5J+VXE5S4yBpPgv58= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383327581968.3131634546311; Sat, 13 Jun 2026 13:42:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV8K-0007ht-O7; Sat, 13 Jun 2026 16:39:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8I-0007Zq-Al; Sat, 13 Jun 2026 16:39:10 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8G-0003uM-Ob; Sat, 13 Jun 2026 16:39:10 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 493ED1B6EFA; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B2BC33CE94B; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=wW//6R9DcVQincR5nU8HAvA6a7TrUpycElpGLnaC2BU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=MSHSfYMQWQ9LL3SCtWKbQ1SWHZ05DOzrMuTbjLwxdiP++sIptDzaKGppytn7x7Ohs H7ICkLYVyDZduq4MHWgHxboEveuXbd22sVGDHFZBgY1fs9nIGRc89oIjg0erY4qfJg WK6Rp5sAvt6UkVEG6bM/SkRLcwRblSm/QIH44MjQbmG7v656O3CrGWZpnd5+jRHUJD LUr0mNH5e8SxBTBqK6sTvIU2fYws/boaPRxXpTaohwNXwwJT6ObTYDF3+GJMFLz48I OrSqECbgfzNjNzJbRlUqBLH2IsYaUStX45CEk65BUFXIcJkqpDibf3jHOwd190ux9H QGUY1Ab0BV4sg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, GuoHan Zhao , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Michael Tokarev Subject: [Stable-11.0.2 31/72] vfio-user: reject zero migration page size capability Date: Sat, 13 Jun 2026 23:34:57 +0300 Message-ID: <20260613203542.1809153-31-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383328088158500 From: GuoHan Zhao check_migr_pgsize() validates that no page-size bits smaller than VFIO_USER_DEF_PGSIZE are set, but it still accepts pgsize=3D0. This can rep= lace the default migration page size with an unusable value. Reject a zero migration page size during version capability parsing, matchi= ng the lower-bound check used for the DMA page-size capability. Fixes: 36227628d824 (vfio-user: implement message send infrastructure) Signed-off-by: GuoHan Zhao Link: https://lore.kernel.org/qemu-devel/20260522081306.4186242-2-zhaoguoha= n@kylinos.cn Signed-off-by: C=C3=A9dric Le Goater (cherry picked from commit 497b5c5b05ac2be00ae16c723e2445ebbc486cb2) Signed-off-by: Michael Tokarev diff --git a/hw/vfio-user/proxy.c b/hw/vfio-user/proxy.c index 3fe5b0138b..3167d27b03 100644 --- a/hw/vfio-user/proxy.c +++ b/hw/vfio-user/proxy.c @@ -1081,9 +1081,11 @@ static bool check_migr_pgsize(VFIOUserProxy *proxy, = QObject *qobj, Error **errp) return false; } =20 - /* must be larger than default */ - if (pgsize & (VFIO_USER_DEF_PGSIZE - 1)) { - error_setg(errp, "pgsize 0x%"PRIx64" too small", pgsize); + /* must not be zero or smaller than default */ + if (pgsize < VFIO_USER_DEF_PGSIZE || + (pgsize & (VFIO_USER_DEF_PGSIZE - 1))) { + error_setg(errp, "%s 0x%"PRIx64" too small", + VFIO_USER_CAP_PGSIZE, pgsize); return false; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383293; cv=none; d=zohomail.com; s=zohoarc; b=F9FmCIzqvQhGETB6ny4Je2bq6rC2K/RyTuJfkX5tCm7BHyd0/WW2PFEYjOlcNefDAP5nM8UGqtc4QdftwrQRou9YFajAZFjNC/LTp2ayJ8SxYjmZBMlJiTgdoxRviSxH1+FcBWU/KdSeDdKuP8Du68e/hukdL0jc0YLfvX5AiSk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383293; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=76mFz2nrpEmAbRw3BjDdsH+LUUeOu5Pi+FGqlQzJiZM=; b=fLuN+4gIxxlGAPJRiBc9LZiUh4tiClvjGqU0aA5wo3jmAYmfaD9foteWE2AcOf1uHYRHT7CGB9GIOKdkZjaJwp9Fw2uL93UU1cAhEbg247YbiWfQeX/eMMfKqdBukSXqYY5wHygRy2FfXkp9s9bjFT35CAymntPtDjed0y4wPPA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383293798244.15383090987996; Sat, 13 Jun 2026 13:41:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV8N-0007lA-Ls; Sat, 13 Jun 2026 16:39:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8L-0007jK-Bg; Sat, 13 Jun 2026 16:39:13 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8J-0003un-L8; Sat, 13 Jun 2026 16:39:13 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 5A70A1B6EFB; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C0FCC3CE94C; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=jdO06w1bx/0mcHC/4q+Ne5w93oHOj/sR1DdBi8Mfk7I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=KWCBLAPbWwUnUTEbwTetVuWthx1y6HLF+wn6hapvyj4Ad52JFcVlhIWAcAYqXLYWm FQQDlgWZ1W/+35U121GUrmvkqZ234Lpn7ajy6pW4lcr7MR2Gr/N0cSj/bYerCBnKcW 1SSpd35xbBV+JhGK2XWj9HcAkJ7ri/4wNBX3SYlAaeedtWt9PlXAAYBvLOvId3IC+r jVbpwx9bwldWV3rpuULph8ADI1dmN/WHD+mK+retEuIkcpjziZ/xudDD08zm3vqdTc MccE0Z7Q16Y590MS/VCddJJzSLv5h+OJpJ3EpR89JDHecB/kjvIw28TzYFd+q1E5Ry q28Pptp1+yocw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Chenyi Qiang , Farrah Chen , Zhenzhong Duan , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Michael Tokarev Subject: [Stable-11.0.2 32/72] vfio/container: Restrict dma_map_file() to shared RAM or RAM devices Date: Sat, 13 Jun 2026 23:34:58 +0300 Message-ID: <20260613203542.1809153-32-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383295791158500 From: Chenyi Qiang vfio_container_dma_map() uses dma_map_file() whenever a RAMBlock has an fd and the VFIO IOMMU backend supports file-based DMA mapping. That is not correct for private file-backed guest RAM. dma_map_file() resolves PFNs from the backing file, but private guest RAM mappings (MAP_PRIVATE) can run on different PFNs than the file because they are subject to copy-on-write (COW) anomalies. As a result, using dma_map_file() on a privately mapped RAMBlock can program DMA against pages that do not back QEMU's actual guest memory. Fix this by using dma_map_file() only for shared mapped RAMBlocks (MAP_SHARED) or RAM device regions. Fixes: fb32965b6dd8 ("vfio/iommufd: use IOMMU_IOAS_MAP_FILE") Reported-by: Farrah Chen Closes: https://bugzilla.kernel.org/show_bug.cgi?id=3D220776 Reviewed-by: Zhenzhong Duan Suggested-by: C=C3=A9dric Le Goater Signed-off-by: Chenyi Qiang Link: https://lore.kernel.org/qemu-devel/20260527101109.71781-1-chenyi.qian= g@intel.com Reviewed-by: C=C3=A9dric Le Goater Signed-off-by: C=C3=A9dric Le Goater (cherry picked from commit e6c47bebdf8628e635e1ba970919ca96d572dbbe) Signed-off-by: Michael Tokarev diff --git a/hw/vfio/container.c b/hw/vfio/container.c index 4c2816b574..56bd9ac009 100644 --- a/hw/vfio/container.c +++ b/hw/vfio/container.c @@ -74,15 +74,43 @@ void vfio_address_space_insert(VFIOAddressSpace *space, bcontainer->space =3D space; } =20 +static bool vfio_container_can_dma_map_file(VFIOContainer *bcontainer, + MemoryRegion *mr, int *fd) +{ + VFIOIOMMUClass *vioc =3D VFIO_IOMMU_GET_CLASS(bcontainer); + RAMBlock *rb =3D mr->ram_block; + + if (!vioc->dma_map_file || !rb) { + return false; + } + + *fd =3D qemu_ram_get_fd(rb); + if (*fd < 0) { + return false; + } + + /* + * We can use IOMMU DMA mapping (IOMMU_IOAS_MAP_FILE) for : + * + * 1) Guest RAM blocks explicitly configured as shared (MAP_SHARED) + * 2) RAM device sub-regions (MMIO BARs) + * + * Private RAM mappings (MAP_PRIVATE) are strictly excluded. Because + * they are subject to copy-on-write (COW) anomalies, their underlying + * PFNs can permanently diverge from the backing file + */ + return qemu_ram_is_shared(rb) || memory_region_is_ram_device(mr); +} + int vfio_container_dma_map(VFIOContainer *bcontainer, hwaddr iova, uint64_t size, void *vaddr, bool readonly, MemoryRegion *mr) { VFIOIOMMUClass *vioc =3D VFIO_IOMMU_GET_CLASS(bcontainer); - RAMBlock *rb =3D mr->ram_block; - int mfd =3D rb ? qemu_ram_get_fd(rb) : -1; + int mfd; =20 - if (mfd >=3D 0 && vioc->dma_map_file) { + if (vfio_container_can_dma_map_file(bcontainer, mr, &mfd)) { + RAMBlock *rb =3D mr->ram_block; unsigned long start =3D vaddr - qemu_ram_get_host_addr(rb); unsigned long offset =3D qemu_ram_get_fd_offset(rb); =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383283; cv=none; d=zohomail.com; s=zohoarc; b=n9WauAv2lLwOaZSkplk3XAgx5enwI2H4TaeV4WBZWWkIXYJkoczUcyAj522y6n8xpLp+yaXePbaXis0BREm+0VD+9l9JoZM/SvAEHXZolG+GCr8XZMNYCHgbVa4yMeyB0h5EB21x100EoasSCfeqXKsgIcvBRK9LeJSzkvEPKZw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383283; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=u+jTOkhb1UDG8TNjel9copBgPTJwijNiMhmUR5wgzyk=; b=TUWYyHC6Tz6nA3fEyPPw7wAmDsHr+MGrtTAElCncqt6j/aWQH8MhoOJpHKT/b4CSPMAlnyxsb0LTHp+dSybGkotfJDrTRj1INSyvW40e9/FIHuxG6TRn/ulSAVoqSDEUT/n0L6CMaVy9HXyASiceGYm5VggRPgnney1WuCsfxLo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383283306538.6697133068623; Sat, 13 Jun 2026 13:41:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV8N-0007lF-Ld; Sat, 13 Jun 2026 16:39:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8L-0007j8-8k; Sat, 13 Jun 2026 16:39:13 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8J-00044e-PO; Sat, 13 Jun 2026 16:39:13 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 725B11B6EFC; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D19213CE94D; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=OQcZflaaAdCO1CU6lugVRJpFmRJmYwX7C3Bxhwi4Fi0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=eC3rgOTFvoKRJEc4LDxlKWCpCucVcyh2/xbE1CbudGdZNIccT2SfR/RcRxWiyuRju PuweZ0auWPCs+dapjHrOlQqFVYHPAq9WnkDHwJjHuDeHMno+IpFUi4YE2skVaJUTNw BGLEt39T/EgqwVM4dfE/Djstftl6PZCtRrwxCYjZY3Ff5nO1jl4BMI55QWmizSfBk0 eyiZbI903JJjv/PqBUOPQwSfk6B05EHQ9u9PjOMMQy9YjAayckDUSrUVLud+B8SFSg F0Xj9qtujfOnsncUWekM58a3kNq4pBpXVBVAourvFWDh3gFXxEx8e+ByCvGtkbGOTx G5TOMUf0yHdiQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richard Henderson , Peter Maydell , Michael Tokarev Subject: [Stable-11.0.2 33/72] target/arm: Enable REVD for SVE2.1 Date: Sat, 13 Jun 2026 23:34:59 +0300 Message-ID: <20260613203542.1809153-33-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383283682158500 Content-Type: text/plain; charset="utf-8" From: Richard Henderson Cc: qemu-stable@nongnu.org Signed-off-by: Richard Henderson Message-id: 20260522220408.235438-1-richard.henderson@linaro.org Reviewed-by: Peter Maydell Signed-off-by: Peter Maydell (cherry picked from commit f12e7ba6f43803ec73c92b4ebeee6187113ba1fc) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/translate-sve.c b/target/arm/tcg/translate-sve.c index f9dfda4a7a..a05967f4fb 100644 --- a/target/arm/tcg/translate-sve.c +++ b/target/arm/tcg/translate-sve.c @@ -2992,7 +2992,8 @@ TRANS_FEAT(REVH, aa64_sme_or_sve, gen_gvec_ool_arg_zp= z, revh_fns[a->esz], a, 0) TRANS_FEAT(REVW, aa64_sme_or_sve, gen_gvec_ool_arg_zpz, a->esz =3D=3D 3 ? gen_helper_sve_revw_d : NULL, a, 0) =20 -TRANS_FEAT(REVD, aa64_sme, gen_gvec_ool_arg_zpz, gen_helper_sme_revd_q, a,= 0) +TRANS_FEAT(REVD, aa64_sme_or_sve2p1, gen_gvec_ool_arg_zpz, + gen_helper_sme_revd_q, a, 0) =20 TRANS_FEAT(SPLICE, aa64_sme_or_sve, gen_gvec_ool_arg_zpzz, gen_helper_sve_splice, a, a->esz) --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383454; cv=none; d=zohomail.com; s=zohoarc; b=G6PAheEF+s/XyJivO5/2KB45mG9BqqZ3sE3+0JgTx5ahKWKMtOgTZx8UbufMpLVFmT+UAv4ap67yYsPUaQQs4GSmIv5HcI/GsxH6ARve7PPabosnxZnAThlBVwcR0H0tJ0mRgddlNV/Kk88IHKEYGmLzvTE7U0S6C1gr7+HH1Oo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383454; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=KtCW87gIb8OLBbMPaIMP1X1sjFnnTeJxkvQ/8tmmREY=; b=Zct+XF1IsJBJx1886fk33HVKb5ZriAbY9TepcTmKou5QlU1sZdjq6fpbglRXHMhFQvvBZyl/vdN9fycMyqq5u5ncDe4RZWHfh7+xjdG36RYbQNXnh+uVNZI4rO6qPT3gF6iGSpv+1SiPh0O8zV2VgaRGmXphuR0NvPtraAo05V8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383454388727.4010632650189; Sat, 13 Jun 2026 13:44:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV8Q-0007ox-3V; Sat, 13 Jun 2026 16:39:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8O-0007nG-DG; Sat, 13 Jun 2026 16:39:16 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8M-00045K-MH; Sat, 13 Jun 2026 16:39:16 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 8028A1B6EFD; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E9EAA3CE94E; Sat, 13 Jun 2026 23:36:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=1SLei3wOec+IuksXol0hfWzvxEzayfmod70lDXMUvdU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ZjnZPfi1QlClTEHU/rsYyri80UyMh5l0RhyD5XBGgqDLGyUUwiZRd4Dq63H0X+uDh NPRHVVGxUWY67q/dYtmjnx44xqnB8bDnYxKhobu9sdIb3Nr67SUpcz4r9y2ZnnOE0L x51iIy90AkLjVqo5yozKuBcq9+yOK3CmqDd7Wl6lP9y8hHHP9C8ayT0Pk5Aa49Jajm OBf1Q9QRXKspOQq3bZxfc85fdVqUdqjyyk4x068k6CWXdfyv1z+b7fKoa3Jvv3liwG oEGsYWSlmjNgSo47XudtGOFvgTEQ7V/R3NGHWypmGn4kPT4Nq6f8KHPSPPuOeFLVp/ gdbGJ+P7SO3nA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Richard Henderson , Michael Tokarev Subject: [Stable-11.0.2 34/72] target/arm: Don't assert if 64-bit EL2 AT insn sees a Domain fault Date: Sat, 13 Jun 2026 23:35:00 +0300 Message-ID: <20260613203542.1809153-34-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383456331158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell The Domain fault type can only happen for 32-bit short-format descriptors. This means that it almost never needs to be encoded in a long-format fault status code. However, there is one corner case where we do need to report it as a long-format FSC: if a 64-bit EL2 does an AT insn on an AArch32 EL1&0 translation regime that is using short-descriptors and that translation operation hits a Domain fault, then this is reported in the PAR_EL1 in long-format. The PAR_EL1 register description defines that this should be reported as 0b111101 for a level 1 Domain fault or 0b111110 for a level 2 Domain fault. The Arm ARM pseudocode special cases this in the function AArch64_PARFaultStatus() (because no other "fault to LFSC" code path can be a Domain fault). For QEMU, implement it in arm_fi_to_lfsc(). Cc: qemu-stable@nongnu.org Fixes: 1fa498fe0de97 ("target/arm: Provide fault type enum and FSR conversi= on functions") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3512 Signed-off-by: Peter Maydell Reviewed-by: Richard Henderson Message-id: 20260526174155.2491217-1-peter.maydell@linaro.org (cherry picked from commit bb957530471c792a9a51e822a6c2fa8398cc48f6) Signed-off-by: Michael Tokarev diff --git a/target/arm/internals.h b/target/arm/internals.h index 85980f0e69..556c0729c7 100644 --- a/target/arm/internals.h +++ b/target/arm/internals.h @@ -872,6 +872,16 @@ static inline uint32_t arm_fi_to_lfsc(ARMMMUFaultInfo = *fi) assert(fi->level >=3D 0 && fi->level <=3D 3); fsc =3D 0b001100 | fi->level; break; + case ARMFault_Domain: + /* + * This can only happen when doing an AT insn at EL2 for an AArch32 + * stage 1 EL1&0 translation regime using short-descriptors, and + * the translation hits a Domain fault. This needs to be reported = in + * the long-format PAR. Compare pseudocode AArch64_PARFaultStatus(= ). + */ + assert(fi->level =3D=3D 1 || fi->level =3D=3D 2); + fsc =3D 0b111100 | fi->level; + break; case ARMFault_Translation: assert(fi->level >=3D -1 && fi->level <=3D 3); if (fi->level < 0) { --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383226; cv=none; d=zohomail.com; s=zohoarc; b=GXF+YxlM83BPcsCS0IgVhQGdYuDegpHHYRI5sQdfrxe8ZqzcejO2S/hN7oyiNli3NLmGyqOiV15EUo6H9sjzh/P1VLML7mWZiCZ4EXPimS1a021SRxu7QuxcREOvG+LPwt/bGaJTdK1pUgFFz04MEinwMsNQrjjsNsT0HIUrUJo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383226; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=OVHbi+TOkb8S0F8WCrKVPCe+ssQGpdSUVdagSU5Oh/E=; b=Ae1d776MhID7QlqtQTLljVoFhz5rFe83u5oOol1Uv2H3Mzu1TkZDsxgwihVKhdJyb99YKXDtZxY2JZnrWRdNQ8OmD+9nCEmkTr1nIGfazJjrbcf2yTRqcTSr+ZpHhMLR1IjdJ6uaKPYBXvgNNvo0GIXRlRMFx4oVGlFpfaeo0EU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138322696589.58828584159903; Sat, 13 Jun 2026 13:40:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV8j-0008Kn-Ux; Sat, 13 Jun 2026 16:39:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8i-0008F2-A4; Sat, 13 Jun 2026 16:39:36 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8g-00045O-RN; Sat, 13 Jun 2026 16:39:36 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 8E6611B6EFE; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0359A3CE94F; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=i+yfxhU/CaItktIbTAcONgxmHDsA/PtMAephYUbH82s=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=FerTlXiIzofy4Ah2uhackInaFGIgVi8XTavVgYf/860v5Bi5fJxEhMGqrCnwvYCcH BkX5LjT3LclHhMi8qnt77GfUDlAQe3ptcEEwIre6Abr7uXN5XdKphP14+LP6hQmZ5x DmM8B2qcua3QGIcasn126DkXl2FT5k61VrsIBL8vaTy3Lo8TNv5YnkIqARkozmaCNz ETBgJW6QvxtnlxfVK7NAufqU1uODOe6gh8uPi3Y/m4aK03I1Rof4Jyavz/AdiXQw9k oFRYYZE+zTtKAJXUMlTybVl5k6At6tmZEnPg0D6/72ccvWiqsEtJN/5hjY4lI8sxNa LI4wUZw4imKOA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Richard Henderson , Michael Tokarev Subject: [Stable-11.0.2 35/72] target/arm: SME BFCVT, BFCVTN have "Alternate BFloat16 behaviors" Date: Sat, 13 Jun 2026 23:35:01 +0300 Message-ID: <20260613203542.1809153-35-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383227740158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell The Arm ARM A1.5.10 notes that some instructions have "Alternate Bfloat16 behaviors" when FPCR.AH =3D=3D 1. We implement these using the FPST_AH and FPST_AH_F16 fp_status words. The list includes the SME BFVCT (single-precision to BFloat16) and BFCVTN, but we forgot to make those use FPST_AH_F16 when we implemented them. (We get the ASIMD and SVE insns on the list right.) Add the missing logic to select the right FPST. Cc: qemu-stable@nongnu.org Fixes: 465d36db0e1 ("target/arm: Implement SME2 BFCVT, BFCVTN, FCVT, FCVTN") Reviewed-by: Richard Henderson Signed-off-by: Peter Maydell Message-id: 20260521180854.1744788-1-peter.maydell@linaro.org (cherry picked from commit ca33de98447c2c2825c1af73cfacf4f65a9bc6c6) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/translate-sme.c b/target/arm/tcg/translate-sme.c index 7d25ac5a51..6064ed8697 100644 --- a/target/arm/tcg/translate-sme.c +++ b/target/arm/tcg/translate-sme.c @@ -1418,9 +1418,9 @@ static bool do_zz_fpst(DisasContext *s, arg_zz_n *a, = int data, } =20 TRANS_FEAT(BFCVT, aa64_sme2, do_zz_fpst, a, 0, - FPST_A64, gen_helper_sme2_bfcvt) + s->fpcr_ah ? FPST_AH : FPST_A64, gen_helper_sme2_bfcvt) TRANS_FEAT(BFCVTN, aa64_sme2, do_zz_fpst, a, 0, - FPST_A64, gen_helper_sme2_bfcvtn) + s->fpcr_ah ? FPST_AH : FPST_A64, gen_helper_sme2_bfcvtn) TRANS_FEAT(FCVT_n, aa64_sme2, do_zz_fpst, a, 0, FPST_A64, gen_helper_sme2_fcvt_n) TRANS_FEAT(FCVTN, aa64_sme2, do_zz_fpst, a, 0, --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383294; cv=none; d=zohomail.com; s=zohoarc; b=CIM5+aFZsuYF6xNTCVQzjCmsFG1mVqiSLS/LfDUOTqrAZ0Koh5omQ4Uio+ZWP/dt7+uAbGl3DP8JMeJ6Rs8jNbey4sZ8/gnnM1/gxalV2gr0wuUzs1AjiJpObporgB6WV+fxrSdvWQriNQmU2N2bbSvHrcQsDeGv7Q5/hlxeseE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383294; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=TfTuvLqnheBnOqPHqrM8UbLagLKfQlvFbihS/EIscr0=; b=cEXYbTrxX38Ngy/9Bu+o3937B7APi+80ZHRWf/8oAcq8IAMGXMDZb2oW27uRSTLHmJNOGsVMDJkc9KSfznYifMgm0E1it6N8pxvsX4fugA6lE7HVat9WMujQLQNkk3jRGuoVS9k24Yl9xQNCHc42rZ1dMPxEfQv+yYDwr29eE4U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383294746684.1850275278023; Sat, 13 Jun 2026 13:41:34 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV8u-00004z-PY; Sat, 13 Jun 2026 16:39:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8n-0008Ri-0T; Sat, 13 Jun 2026 16:39:41 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8j-000486-TU; Sat, 13 Jun 2026 16:39:40 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9D09A1B6EFF; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 11CB83CE950; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=y3EvD+HGZtAGlIf1KZvi3tGEQakW/9VhWWOSw41RWQc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ki6s+sf4RswAsKCBUIRW4Q+qJgRFw1Uje2+IjAxEt5DAszcrsSTBZiYDPdIsy7MkC zyZzZ8Gvnq1v5uaAQ5COpwYNrb+nsUY2M3lKqxZqyYZnp1zF6/VnpWqrkton7ovHiL lWhjIWMVuDqGZ6Iu4tQ8QKlksnMX3PsvWyNJN+xQgWxvGn9cb7zkK16vHDeBzhZEfT y74eljn+bVjsGuoKn3dx6YOHZXxdjXWRxEEfaxlQaIF8/MoPWOEG/yv/GX5n8owE8o wAXUZu7P40hLx/I+qTaHmSGPQXlDRiQFHbxiaNYN16BvwNYS/NNn8N0d1SW9SeIYxM 7YHn4RwKFTo7Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Jason Wang , Michael Tokarev Subject: [Stable-11.0.2 36/72] hw/net/rocker_of_dpa: Check group ID pointers are not NULL Date: Sat, 13 Jun 2026 23:35:02 +0300 Message-ID: <20260613203542.1809153-36-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383295792158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell In of_dpa_cmd_add_l2_flood(), we use rocker_tlv_parse_nested() to fill in a tlvs[] array. If the guest command is valid then the entries should be pointers to TLV data items with group IDs. However, if the guest gives us bogus data then rocker_tlv_parse_nested() indicates this by leaving the tlvs[] entries NULL. In the other places that use this function, we check for this before using the value, but here we forgot, and the result is that QEMU can crash: #0 __memcpy_avx_unaligned_erms () at ../sysdeps/x86_64/multiarch/memmove-v= ec-unaligned-erms.S:331 #1 0x00005555574f7137 in __asan_memcpy () #2 0x0000555558106792 in ldl_he_p (ptr=3D0x8) at /home/pm215/qemu/include/= qemu/bswap.h:278 #3 0x0000555558106755 in ldl_le_p (ptr=3D0x8) at /home/pm215/qemu/include/= qemu/bswap.h:311 #4 0x00005555580f85ed in rocker_tlv_get_le32 (tlv=3D0x0) at ../../hw/net/r= ocker/rocker_tlv.h:114 #5 0x000055555810a8ad in of_dpa_cmd_add_l2_flood (of_dpa=3D0x506000082e38,= group=3D0x503000b4e440, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2032 #6 0x0000555558108a74 in of_dpa_cmd_group_do (of_dpa=3D0x506000082e38, gro= up_id=3D1073741824, group=3D0x503000b4e440, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2115 #7 0x0000555558108730 in of_dpa_cmd_group_add (of_dpa=3D0x506000082e38, gr= oup_id=3D1073741824, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2135 #8 0x00005555580f66ec in of_dpa_group_cmd (of_dpa=3D0x506000082e38, info=3D0x514000072e40, buf=3D0x5070002356c0 "= \001", cmd=3D7, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2194 Check for NULL values and return an error. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/1851 Signed-off-by: Peter Maydell Signed-off-by: Jason Wang (cherry picked from commit 8526b7d6b67beda0c83e4a8aec1449475fe5dd65) Signed-off-by: Michael Tokarev diff --git a/hw/net/rocker/rocker_of_dpa.c b/hw/net/rocker/rocker_of_dpa.c index 3190a0e75c..958f3006c1 100644 --- a/hw/net/rocker/rocker_of_dpa.c +++ b/hw/net/rocker/rocker_of_dpa.c @@ -2029,6 +2029,10 @@ static int of_dpa_cmd_add_l2_flood(OfDpa *of_dpa, Of= DpaGroup *group, group_tlvs[ROCKER_TLV_OF_DPA_GROUP_IDS]); =20 for (i =3D 0; i < group->l2_flood.group_count; i++) { + if (!tlvs[i + 1]) { + err =3D -ROCKER_EINVAL; + goto err_out; + } group->l2_flood.group_ids[i] =3D rocker_tlv_get_le32(tlvs[i + 1]); } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383454; cv=none; d=zohomail.com; s=zohoarc; b=Gey4idZeB9UoGvR4kcqIKejqPN9kl8OF7GpzpIdR3Sup5HKESMxBdH+Owat2RQTzjZWMZB0b2ACBLLtSYCNPXzG/RYuLsL9D1FMEWaLP+VjsHX6WzP/j1T7JVueg1p8R5H5wl1o5yLehTMsysgU6baA0E1sl8faLgZb1JxaIgOs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383454; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=iuxSRBWTkgfSk8L5/YiR9Jlu2z2RuFjoYyWwfzawbvw=; b=DAq7fnGVCKb+hNrVSzmsZGidZGe8cqiX6IL4vjCqN8hiXHaY5BVFCwYr+TGBJAUIbamsOxzImzz+Wto93XkoENxYVIxcHR1I9uKfv4vvk0Z7zM3Fw67xhDJMQtTg7Sc5Lu4OlNbvWuOYh2pTptMfKmDbaRVy0yC6I17TfrRywFI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383454398700.5557297139668; Sat, 13 Jun 2026 13:44:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV8s-0008Ve-BZ; Sat, 13 Jun 2026 16:39:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8m-0008Rh-W3; Sat, 13 Jun 2026 16:39:41 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8j-0004D9-TP; Sat, 13 Jun 2026 16:39:39 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id AB9AC1B6F00; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 20C1B3CE951; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=u9MhEfJFgVBl71EK5UreCe/1IDcR0M1fW4f5yCNMfJM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=kCs4pd0EtMD7opNWPNFt2RZFEAQHyJpeotMh/mLAE7EdcEaBpRrsGPDBqlcltVbjg kbrU6ch4itkiz3cbsLkXhveyJ6sLRX8z4ayHffKbsHo1kOsmedZrwk+nDD5jc4kbzE 33MwK07kbpIPpu1cw3N2J1ln7Af+V8ovEkPMyJxMYoE3ZgJCSgNyuZGUb/9eIqauE6 bgEOzogd+31ifnZXpxx1lQWJCxtqPDVz4QOuIawaDrXDRLubQ1WPfKevlV+kLS4vhX YqJEjgkd49fGwg2JaPvoQpyuXT3dgKJtzPJtUwyKXBsLJHpHsVLHn92/yaZ9tLVTId FVxGfurL5wMlQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Jason Wang , Michael Tokarev Subject: [Stable-11.0.2 37/72] hw/net/rocker_of_dpa: Avoid unaligned accesses in _of_dpa_flow_match() Date: Sat, 13 Jun 2026 23:35:03 +0300 Message-ID: <20260613203542.1809153-37-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383456328158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell _of_dpa_flow_match() tries to do masked comparisons of OfDpaFlowkey structs by casting pointers to them to uint64_t* and then doing the memory accesses as 64-bit. This is undefined behaviour because the pointers might not be 64-bit aligned, and the UB sanitizer spots this: ../../hw/net/rocker/rocker_of_dpa.c:321:20: runtime error: load of misalign= ed address 0x512000164044 for type 'uint64_t' (aka 'unsigned long'), which = requires 8 byte alignment 0x512000164044: note: pointer points here 02 00 00 00 00 00 ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00= 00 00 00 00 00 00 00 00 ^ We do know that OfDpaFlowKey structs must be at least aligned enough for uint32_t accesses, because that's the type of the first field. Switch to using uint32_t accesses in the loop. Because the "width" field is always set via the FLOW_KEY_WIDTH macro and not exposed to the guest, we can adjust the macro to store the number of uint32_t to be checked rather than needing to change the loop boundary in the match function. Cc: qemu-stable@nongnu.org Signed-off-by: Peter Maydell Signed-off-by: Jason Wang (cherry picked from commit 71d027cfee8553e2ec28efa1ddd7fd0ecbadcc86) Signed-off-by: Michael Tokarev diff --git a/hw/net/rocker/rocker_of_dpa.c b/hw/net/rocker/rocker_of_dpa.c index 958f3006c1..3d6f55b512 100644 --- a/hw/net/rocker/rocker_of_dpa.c +++ b/hw/net/rocker/rocker_of_dpa.c @@ -99,13 +99,13 @@ typedef struct of_dpa_flow_key { } nd; } ipv6; }; - int width; /* how many uint64_t's in key? */ + int width; /* how many uint32_t's in key? */ } OfDpaFlowKey; =20 -/* Width of key which includes field 'f' in u64s, rounded up */ +/* Width of key which includes field 'f' in u32s, rounded up */ #define FLOW_KEY_WIDTH(f) \ DIV_ROUND_UP(offsetof(OfDpaFlowKey, f) + sizeof_field(OfDpaFlowKey, f)= , \ - sizeof(uint64_t)) + sizeof(uint32_t)) =20 typedef struct of_dpa_flow_action { uint32_t goto_tbl; @@ -304,9 +304,9 @@ static void _of_dpa_flow_match(void *key, void *value, = void *user_data) { OfDpaFlow *flow =3D value; OfDpaFlowMatch *match =3D user_data; - uint64_t *k =3D (uint64_t *)&flow->key; - uint64_t *m =3D (uint64_t *)&flow->mask; - uint64_t *v =3D (uint64_t *)&match->value; + uint32_t *k =3D (uint32_t *)&flow->key; + uint32_t *m =3D (uint32_t *)&flow->mask; + uint32_t *v =3D (uint32_t *)&match->value; int i; =20 if (flow->key.tbl_id =3D=3D match->value.tbl_id) { --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383367; cv=none; d=zohomail.com; s=zohoarc; b=SMGeuNbDf8vV7p32wsB+ZYyTh3/knBjGWb/30hHNyNKOqoAqwA5S0ev5ylNSiid0yopuNxkSOg2yMph/ZnJIqvgbXdMTlyP5RyRZgBbCe8UhudTnPzaTLJqGOW8IrzIUDclCoBnzOVynvWWW5d7c7F0ZXtvjiK04hHbBPbf+Hes= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383367; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=HGxfuZJKsLe8+60uPCQZxke+PsDM5TGk+j/oBE/o73A=; b=BLgp5E8ct6R175nsUTaiPdkAN1+EbgZH5HbRGmfr4mQRFLRS97uTraJi7Ms7KvA8szWSNmRU7YgUMmKPS4Lkj537IO+TfcCSmNQzpSnh9rCcN9uH3AulqgQSc3Jd3OVhNF//jAtQN0oo+W4s0tO/8prbqdAYn0S82FhskdDLVkE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383367799198.46160324119194; Sat, 13 Jun 2026 13:42:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV9E-0000Sg-Ur; Sat, 13 Jun 2026 16:40:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8q-0008Vf-72; Sat, 13 Jun 2026 16:39:44 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8o-0004EI-JJ; Sat, 13 Jun 2026 16:39:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BAE6C1B6F01; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 2F0523CE952; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=LlFJ5MNrrFqn2jreYasQuWyv+SrH/nQ9Zgl3Dd/fIBM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=oiulHuJG+q+stsRi/jEB/lrVygzkZImVou2lRENMWGwU0pghw2Klf7KTANMFaMwTp D/kYMUW8kcmoNHZLBPik05BGntBeCKSaq2DhSzMOTKyBgH6NX36cRszRkqVQrtRrXw T23hkfeVfgB5pv0QmbZfJm2GnfORmeGVZREl/W8998wyT6I7siXMT+3kWKmkGIk5Qv Rucgg4wY/2l1ZWwddwbKvU18J0lauy3/jR841hSFVJDQ6nMnFvaw7Y+29oFB+6IUMv 9KbkRjavlxGjMVEB/nJedLzuDfjFW6jj9xNRbggPJf8GhAwl2tuFIWXaQHJBCiYI0N QrqQkeljtwq7A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 38/72] linux-user/ppc: restore fp_status from FPSCR on sigreturn Date: Sat, 13 Jun 2026 23:35:04 +0300 Message-ID: <20260613203542.1809153-38-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383368003158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner restore_user_regs() restores the PPC FPSCR with a direct assignment: env->fpscr =3D (uint32_t) fpscr; ppc_store_fpscr() exists precisely to write FPSCR and keep the derived env->fp_status in sync: it calls fpscr_set_rounding_mode() to update the softfloat rounding mode, and set_float_rebias_overflow/underflow() to reflect the FP_OE/FP_UE enable bits. The direct assignment bypasses all of this. On sigreturn, interrupted code resumes with whatever rounding mode and overflow/underflow-rebias state the signal handler last installed in fp_status, rather than the state that was saved at signal delivery. Replace the direct assign with ppc_store_fpscr(). The FPSCR_MTFS_MASK applied inside ppc_store_fpscr() only excludes the computed FP_FEX and FP_VX bits, which it re-derives correctly from the exception and enable bits in the restored value. Fixes: bcd4933a23 ("linux-user: ppc signal handling") Cc: qemu-stable@nongnu.org Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 3f50dd46664bdf94f10aca8b76dc4dcb9182a5ae) Signed-off-by: Michael Tokarev diff --git a/linux-user/ppc/signal.c b/linux-user/ppc/signal.c index a9c10e0987..ab1afea30a 100644 --- a/linux-user/ppc/signal.c +++ b/linux-user/ppc/signal.c @@ -420,7 +420,7 @@ static void restore_user_regs(CPUPPCState *env, __get_user(*fpr, &frame->mc_fregs[i]); } __get_user(fpscr, &frame->mc_fregs[32]); - env->fpscr =3D (uint32_t) fpscr; + ppc_store_fpscr(env, (uint32_t) fpscr); } =20 #if !defined(TARGET_PPC64) --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383490; cv=none; d=zohomail.com; s=zohoarc; b=T0v+4Yvq5xrxW2vYY6R2eqOgP6vQR7EMczC2OnemFJ4SeJG3ykx4U6bxpGf7gLdBZ63sRkFtWRvu9eoOuLrGAvUPYv/bcCU/4j/LF/umFlcA21nHtRsgIoyaJShKkQx5X8DN8+myOhlvMK8fG7T8FVXG2B/QSNAm9RLFoGkHtgg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383490; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=mH6yRBZ/PDbfJvNZ//Mq+d1prFsF088AMQ9/HmMVqsg=; b=HROoI439WJqYibhDhilZEYS12UMaoyud2IYkjc9235h9fL5AQvWOkfJ674YqHWFUwiH9els4t/ob4Onj5HC7lk0qQdnxC3wTNqiLkGeNQyAnNqFky7/nVIkKcvDeIJTq7078GxA+nvxpnpwSYC8vJ5zI6u6gMWp/qrkhOTUCn9U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383490174308.5505748340273; Sat, 13 Jun 2026 13:44:50 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV96-0000GK-Gd; Sat, 13 Jun 2026 16:40:02 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8q-0008Vg-84; Sat, 13 Jun 2026 16:39:44 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV8o-0004EJ-Fq; Sat, 13 Jun 2026 16:39:44 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C94241B6F02; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 3E9E43CE953; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=qPeqdKxBJoa6vMIIrWN4BZr+z637BJiDM9Ba4X2UnAY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=SZJxBp5o2ecadobl2ALLVl3+9+aCscj9zuNR+L/bPcbpwglPv1AxqEE3v3Ka0/fZB u7+WkGCWdQqyW2KBHAFJ9/f69kNzU7vUmlF5qkc/56KyFkHWn0dNLopfXO4IA5Jmst 2akntZj4WIEllnZe2WrdtqXA2hrYQwwhMavY4V7AuP9DIwD4rqXPk1fivj+rQHZCML y5kPfZ/ZuVRD078rpHOLPmNQ4RqBLT4/PCdDfh0fb4sojGWUuv9KuR+c85htnpkF5E +0/d8JCyeQ5V6YE9TVlaEN/uYmpaV9lD30XwpXTsMdNZQqsfkB5ciOyLoTgTe3t2+W 81lsn2xV9vt2g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 39/72] linux-user/mips: save/restore FCSR across signal delivery Date: Sat, 13 Jun 2026 23:35:05 +0300 Message-ID: <20260613203542.1809153-39-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383490491158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the MIPS FPU control/status register (FCSR, fcr31) in env->active_fpu.fcr31. The rounding mode, flush-to-zero (FS), and NaN-2008 mode bits in fcr31 are reflected into the derived env->active_fpu.fp_status via set_float_rounding_mode() and friends; every architectural write to FCSR goes through helper_ctc1() which calls restore_fp_status() to keep the two in sync. Both target_sigcontext variants (O32 and N32/N64) have an sc_fpc_csr field that holds FCSR, but setup_sigcontext() never wrote it and restore_sigcontext() never read it. As a result: - The signal frame always delivered sc_fpc_csr =3D=3D 0 to the handler, so sigaction(SA_SIGINFO) handlers that inspect the interrupted context see the wrong FCSR. - On sigreturn, active_fpu.fcr31 retained whatever value the signal handler last installed (if any), and active_fpu.fp_status was never resynced. Interrupted code resumed with the wrong rounding mode, FS flag, and NaN-2008 semantics. Fix setup_sigcontext() to save fcr31 into sc_fpc_csr. Fix restore_sigcontext() to read it back (masked to fcr31_rw_bitmask as the kernel does) and call cpu_mips_restore_fp_status() to resync fp_status from the restored fcr31. Add cpu_mips_restore_fp_status() in target/mips/fpu.c (which already defines ieee_rm and includes fpu_helper.h), and declare it in cpu.h. Fixes: 084d0497a0 ("mips-linux-user: Save and restore fpu and dsp from sigc= ontext") Cc: qemu-stable@nongnu.org Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 84b920ccb5ee5287747af2d36d1ece6367b6a40e) Signed-off-by: Michael Tokarev diff --git a/linux-user/mips/signal.c b/linux-user/mips/signal.c index d69a5d73dd..1b10012726 100644 --- a/linux-user/mips/signal.c +++ b/linux-user/mips/signal.c @@ -134,6 +134,7 @@ static inline void setup_sigcontext(CPUMIPSState *regs, for (i =3D 0; i < 32; ++i) { __put_user(regs->active_fpu.fpr[i].d, &sc->sc_fpregs[i]); } + __put_user(regs->active_fpu.fcr31, &sc->sc_fpc_csr); } =20 static inline void @@ -165,6 +166,12 @@ restore_sigcontext(CPUMIPSState *regs, struct target_s= igcontext *sc) for (i =3D 0; i < 32; ++i) { __get_user(regs->active_fpu.fpr[i].d, &sc->sc_fpregs[i]); } + { + uint32_t fcr31; + __get_user(fcr31, &sc->sc_fpc_csr); + regs->active_fpu.fcr31 =3D fcr31 & regs->active_fpu.fcr31_rw_bitma= sk; + cpu_mips_restore_fp_status(regs); + } } =20 /* diff --git a/target/mips/cpu.h b/target/mips/cpu.h index ed662135cb..3b4da9887b 100644 --- a/target/mips/cpu.h +++ b/target/mips/cpu.h @@ -1366,6 +1366,9 @@ void cpu_mips_clock_init(MIPSCPU *cpu); /* helper.c */ target_ulong exception_resume_pc(CPUMIPSState *env); =20 +/* fpu.c */ +void cpu_mips_restore_fp_status(CPUMIPSState *env); + /** * mips_cpu_create_with_clock: * @typename: a MIPS CPU type. diff --git a/target/mips/fpu.c b/target/mips/fpu.c index c7c487c1f9..8b661865ca 100644 --- a/target/mips/fpu.c +++ b/target/mips/fpu.c @@ -17,6 +17,11 @@ const FloatRoundMode ieee_rm[4] =3D { float_round_down }; =20 +void cpu_mips_restore_fp_status(CPUMIPSState *env) +{ + restore_fp_status(env); +} + const char fregnames[32][4] =3D { "f0", "f1", "f2", "f3", "f4", "f5", "f6", "f7", "f8", "f9", "f10", "f11", "f12", "f13", "f14", "f15", --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383244; cv=none; d=zohomail.com; s=zohoarc; b=CG79B9/CGH2hhzIy+Nhw2/1LbqcgIE+jSVUeA62xjW9cZr7M/1oiSmivfUQaDY3WSUvR7Kn9yYXkRE3JdQmwcWAQpj4JQZDBU7wKtF80tRcck92d7hwc2BOfA3lTMxheGtjzBKsRfuFwBxrUAcV+Uss5GNTgXPjCw7RQDNDiq0c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383244; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LPhyYccvzczMUvS1xg6EDqVdVvYUg9RiFt2CCvF1NVI=; b=g3UJBZ5TPbH2xXor3jj77t4FdgEu8HyF6+M4HCy+h/HOdwsUoypFk6vF0s2k5Ac+s9TaDRVHOowpVfuStNsazbCi3E1emruQCKm9MXgLtK3b/gQIUdjRiv+UJYQQ7zS/bn8rl4KdI1wEVHuoRID8tUxDKCP1TwW/uJocm0g08Jo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383244728314.48585223186626; Sat, 13 Jun 2026 13:40:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV9H-0000at-FU; Sat, 13 Jun 2026 16:40:11 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9D-0000Th-Jl; Sat, 13 Jun 2026 16:40:08 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9B-0004F4-OX; Sat, 13 Jun 2026 16:40:07 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id DBD991B6F03; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 4D3203CE954; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=Wqggm+YI9CGOXrC37tB98c0M6KNUDE9ZIppSxjX+MCI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=dH+m4u6rmw7CoCPKhAJvOOLteb6BOFXkWhXU2l3elwBaLsACLzgq3zeb+VexL8Fmb q9CsKJ3SeSVpWGQItDp4MobIUUENsHjbPFW8C19xI/I9ptDtXQy0EBzZ0eA3ecKkv0 c4sy2NjgYtvs0aE++PXBKVrs9AnR9HTu1OvEL6g5PYYFiRx2YPyGMtWh8a/fx0TwlQ TZSTNwKarPk3lHlLQd0FLUxnHCzHlXhHNhJC5GUh7W9l3QPbXnFcMBHKmIyanCRnoc bAZDYdt+RDquo8Uchm47oNo2EbBufWoX4EBi3XOfqtEO9Bhpu+wjklW5TGzytuQmju tDdsMtIrHZvUA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Yoshinori Sato , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 40/72] linux-user/sh4: preserve T/M/Q bits across signal delivery Date: Sat, 13 Jun 2026 23:35:06 +0300 Message-ID: <20260613203542.1809153-40-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383245630158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the SH4 T, M and Q status-register bits outside env->sr, in the dedicated env->sr_t, env->sr_m and env->sr_q fields; cpu_read_sr() folds them back into the architectural SR value and cpu_write_sr() splits them back out. setup_sigcontext() saved the bare env->sr (so the T/M/Q bits were always zero in the signal frame) and restore_sigcontext() wrote the value straight back into env->sr without updating sr_t/sr_m/sr_q. As a result the T bit was never preserved across signal delivery: on sigreturn the interrupted code resumed with whatever T value the signal handler last left behind. Any conditional branch (or addc/subc/rotcl/div1, etc.) immediately following the interrupted instruction could then take the wrong path. This is the cause of the long-standing intermittent failures of the tests/tcg/multiarch/signals.c test on sh4, which was marked BROKEN. With a SIGRTMIN timer firing every millisecond across many threads, the race was hit a few percent of the time and corrupted the guest heap, surfacing as a SIGSEGV in memset, a malloc assertion, or an rseq registration abort. Traced on a deterministic rr recording: a cmp/hi set T=3D0, the timer signal interrupted the very next instruction (a bf), the handler left T=3D1, and the resumed bf took glibc calloc's MORECORE_CLEARS branch, using the old top-chunk size as the clear length for a freshly split small chunk and running memset off the end of the heap. Fix setup_sigcontext()/restore_sigcontext() to use cpu_read_sr() and cpu_write_sr() so the T, M and Q bits round-trip correctly, and drop the BROKEN annotation on the sh4 signals test. Fixes: c3b5bc8ab3 ("SH4: Signal handling for the user space emulator, by Ma= gnus Damm.") Cc: qemu-stable@nongnu.org Reviewed-by: Yoshinori Sato Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 6bf4c0295cccf74f3c5c0b674328b97d6fd1505c) Signed-off-by: Michael Tokarev diff --git a/linux-user/sh4/signal.c b/linux-user/sh4/signal.c index d70be24c38..cc36425c49 100644 --- a/linux-user/sh4/signal.c +++ b/linux-user/sh4/signal.c @@ -131,8 +131,10 @@ static void setup_sigcontext(struct target_sigcontext = *sc, COPY(gregs[14]); COPY(gregs[15]); COPY(gbr); COPY(mach); COPY(macl); COPY(pr); - COPY(sr); COPY(pc); + COPY(pc); #undef COPY + /* The T, M and Q bits live outside env->sr; fold them back in. */ + __put_user(cpu_read_sr(regs), &sc->sc_sr); =20 for (i=3D0; i<16; i++) { __put_user(regs->fregs[i], &sc->sc_fpregs[i]); @@ -159,8 +161,14 @@ static void restore_sigcontext(CPUSH4State *regs, stru= ct target_sigcontext *sc) COPY(gregs[14]); COPY(gregs[15]); COPY(gbr); COPY(mach); COPY(macl); COPY(pr); - COPY(sr); COPY(pc); + COPY(pc); #undef COPY + /* The T, M and Q bits live outside env->sr; unfold them. */ + { + uint32_t sr; + __get_user(sr, &sc->sc_sr); + cpu_write_sr(regs, sr); + } =20 for (i=3D0; i<16; i++) { __get_user(regs->fregs[i], &sc->sc_fpregs[i]); diff --git a/tests/tcg/sh4/Makefile.target b/tests/tcg/sh4/Makefile.target index 7852fa62d8..b7a8737be0 100644 --- a/tests/tcg/sh4/Makefile.target +++ b/tests/tcg/sh4/Makefile.target @@ -3,13 +3,6 @@ # SuperH specific tweaks # =20 -# This triggers failures for sh4-linux about 10% of the time. -# Random SIGSEGV at unpredictable guest address, cause unknown. -run-signals: signals - $(call skip-test, $<, "BROKEN") -run-plugin-signals-with-%: - $(call skip-test, $<, "BROKEN") - VPATH +=3D $(SRC_PATH)/tests/tcg/sh4 =20 test-macl: CFLAGS +=3D -O -g --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383303; cv=none; d=zohomail.com; s=zohoarc; b=n4WP9Miq4KhnONrXaOz1RQyVFXi/7ap9ijkYTg9roLUXJlGFndBqucut3KGb8VQEooec89wI+saBwqYC20g6pkOsYMNYjB3HE5U7kuo5VwhuBuArqHaPX8raK9Rqh4hIBvll+pb7/PV3s9LUxnX91KNfc0TKXDdrQpK0UTo8zWo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383303; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hyg8vU45DM+g+du69jrlEz81Wrm+PtwUiPNfGOYab3o=; b=UsEnmVHu/oWwKRuMERfDUXrLiMN0dOq53cnQkhKkyAH87MfeVeN6FukV6K7ipjHMDGZVDaA30qbvkgJW7TdLoR9Zh4y4Z1FWlbYuXBeWIedNd5DyVeCX5KEYE0PYtSJT5AWRdL5JMEakqtg5ndUgj/VXT6symGumCv+cf3l6NbE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383303439978.9809754130692; Sat, 13 Jun 2026 13:41:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV9J-0000ks-5w; Sat, 13 Jun 2026 16:40:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9D-0000Ti-R5; Sat, 13 Jun 2026 16:40:08 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9C-0004F6-1n; Sat, 13 Jun 2026 16:40:07 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id EDB231B6F04; Sat, 13 Jun 2026 23:36:04 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 5FB073CE955; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382964; bh=LnNZu/aRjpZZFrq6QaE6GVF8IP/wzZvL7ML5ZltIi0U=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ggZIgV8+K5VzhSm118twoWAoZcP+4V1PEoFS8K+tGRlqu6/jHjKnesYW5GU8GU0fg 2LoXOgVB3AhUarFIRbBBQdGW/pVyg9LnwRhVBe0ZmpbdEnLCH5/4aospuzay03vjyk JHDhMYK8HVnUH8+CsQHPjAELTdQ7LflONrB+KNx36TwLFLA4sVn7sdwTwukXaSi2f9 VkYTHI/UuXu8mNiyG0csDf5BZamaBdT/jf+pM1VL1Uys21Z5QqaZAzEs3YVMBVySpm LW6eftZvdjtcAK6zsPVTgtgG3jOH26AcvxtRDphjEkOdNS6eiRBQq06RdCGMh04xKD ZOybZPyC0T3pQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Yoshinori Sato , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 41/72] linux-user/sh4: restore FP rounding mode on sigreturn Date: Sat, 13 Jun 2026 23:35:07 +0300 Message-ID: <20260613203542.1809153-41-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383303884158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner The SH4 FPSCR rounding-mode (RM) and denormal (DN) bits are not held only in env->fpscr: they are also reflected into the derived env->fp_status via set_float_rounding_mode()/set_flush_to_zero(). The guest keeps the two in sync by routing every write to FPSCR through helper_ld_fpscr(). restore_sigcontext() wrote the saved value straight into env->fpscr and never touched env->fp_status, so on sigreturn the interrupted code resumed with whatever FP rounding mode and flush-to-zero setting the signal handler last installed. (regs->flags =3D 0 forces the FR/SZ/PR TB flags to be recomputed, but fp_status is runtime float state, not a TB flag, so it was left stale.) This is the FP analogue of the T/M/Q bit problem just fixed for the integer status register. Factor the FPSCR -> fp_status synchronisation out of helper_ld_fpscr() into cpu_load_fpscr() and use it from restore_sigcontext() so the rounding mode round-trips correctly across signal delivery. Fixes: c3b5bc8ab3 ("SH4: Signal handling for the user space emulator, by Ma= gnus Damm.") Cc: qemu-stable@nongnu.org Reviewed-by: Yoshinori Sato Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit a740f17ed0fbc5cd38e3cb12136c58d38aba098d) Signed-off-by: Michael Tokarev diff --git a/linux-user/sh4/signal.c b/linux-user/sh4/signal.c index cc36425c49..00290d6e40 100644 --- a/linux-user/sh4/signal.c +++ b/linux-user/sh4/signal.c @@ -173,7 +173,12 @@ static void restore_sigcontext(CPUSH4State *regs, stru= ct target_sigcontext *sc) for (i=3D0; i<16; i++) { __get_user(regs->fregs[i], &sc->sc_fpregs[i]); } - __get_user(regs->fpscr, &sc->sc_fpscr); + /* Resync the derived float_status state, not just env->fpscr. */ + { + uint32_t fpscr; + __get_user(fpscr, &sc->sc_fpscr); + cpu_load_fpscr(regs, fpscr); + } __get_user(regs->fpul, &sc->sc_fpul); =20 regs->tra =3D -1; /* disable syscall checks */ diff --git a/target/sh4/cpu.h b/target/sh4/cpu.h index b0759010c4..fbecde13a9 100644 --- a/target/sh4/cpu.h +++ b/target/sh4/cpu.h @@ -380,4 +380,7 @@ static inline void cpu_write_sr(CPUSH4State *env, uint3= 2_t sr) env->sr =3D sr & ~((1u << SR_M) | (1u << SR_Q) | (1u << SR_T)); } =20 +/* Set FPSCR and the derived float_status rounding/flush-to-zero state. */ +void cpu_load_fpscr(CPUSH4State *env, uint32_t val); + #endif /* SH4_CPU_H */ diff --git a/target/sh4/op_helper.c b/target/sh4/op_helper.c index 669bc84cb6..cf0f80e4a5 100644 --- a/target/sh4/op_helper.c +++ b/target/sh4/op_helper.c @@ -204,7 +204,7 @@ void helper_macw(CPUSH4State *env, int32_t arg0, int32_= t arg1) } } =20 -void helper_ld_fpscr(CPUSH4State *env, uint32_t val) +void cpu_load_fpscr(CPUSH4State *env, uint32_t val) { env->fpscr =3D val & FPSCR_MASK; if ((val & FPSCR_RM_MASK) =3D=3D FPSCR_RM_ZERO) { @@ -215,6 +215,11 @@ void helper_ld_fpscr(CPUSH4State *env, uint32_t val) set_flush_to_zero((val & FPSCR_DN) !=3D 0, &env->fp_status); } =20 +void helper_ld_fpscr(CPUSH4State *env, uint32_t val) +{ + cpu_load_fpscr(env, val); +} + static void update_fpscr(CPUSH4State *env, uintptr_t retaddr) { int xcpt, cause, enable; --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383526; cv=none; d=zohomail.com; s=zohoarc; b=aEm8MGQDau9I75NMKyOCrF+4XFV4Fv4YU258KKhYc4X9Xl7OPHfitiPDA2QgtGn9IVHcphGm7yQlMVAS4juy6E13GtzkC2IzO56uL5OedO/9lnszoEYZJ2xeLuoXR0gOeZPNRYMgqUPh+c0luTGRKUPuy5VLSqLHc3b+2lFtDV8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383526; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=5OkeV3lYkdiZ3J8R3h6L+/wbU+nY7AmeOBMy1hA792w=; b=A1p6YMWRazDsjlk5JQRhTmOFAV7PxoC6sNBEnC6Kx4W3axNgFT64uokK0Kfii8uBSjMfpo9HbacU/klJ0DK6H3HrJp9vEdkHmonzOjCxcEX8fTet7wQAmpBknQGuzPbERjBkUKbaB+3rHnFGj1wsLotIyrb0cDMIy5NdF63Py8c= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383526100238.14818893659435; Sat, 13 Jun 2026 13:45:26 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV9M-00010b-En; Sat, 13 Jun 2026 16:40:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9H-0000aY-CD; Sat, 13 Jun 2026 16:40:11 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9F-0004TJ-6e; Sat, 13 Jun 2026 16:40:10 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 088F01B6F05; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 717443CE956; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=Ghl0ZtyIs4gKQ1+JEGboppp/jddtSue3ilOs0f6SYAE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=EQ+I4tRRn+o61kPH38flIq0SYENNpkEnMUJfo91Qiy/tWCAZXQb2nr2lvOFNp83Cq WgUmstwV8CzSKUgt6EI/OcArFZ5SK8vTrXomAov6mSyXtn/4rWwSCC70aLenIFokZJ M5S7Y5e+6v4TasubGJO3GggYjFx+xfim/1SB2jvml16bumi5B9expT+b01wiDVjGQc RqREW9KXxvJ4M1BjSXe+56o8QKHFaenqvZhjd77mAIzocdF3mHhCcr10Wo6Y2fIK/m r1rCFjUkwXZh2Ydp6suIIknfGVQgDibPEPEii+XBy24AJMnuCfj0I6/yUsjkzKHxEN l+/Us2miZoo3Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 42/72] linux-user/s390x: restore fpu_status rounding mode from FPC on sigreturn Date: Sat, 13 Jun 2026 23:35:08 +0300 Message-ID: <20260613203542.1809153-42-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383526672158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the s390x floating-point control register (FPC) in env->fpc. The rounding mode bits [2:0] of FPC are reflected into the derived env->fpu_status via set_float_rounding_mode(); every architectural write to FPC goes through HELPER(sfpc) which keeps the two in sync. restore_sigregs() restored FPC with a direct assignment: __get_user(env->fpc, &sc->fpregs.fpc); This wrote env->fpc correctly but never updated env->fpu_status, so on sigreturn the interrupted code resumed with whatever rounding mode the signal handler last installed in fpu_status. Factor the two-step "write fpc + sync fpu_status" logic out of HELPER(sfpc) into cpu_s390x_load_fpc(), declare it in cpu.h, and call it from restore_sigregs() in place of the direct assignment. cpu_s390x_load_fpc() partially reuses the sanity check from HELPER(sfpc): if the FPC value has an invalid rounding mode or reserved bits set, it falls back to 0, matching the kernel's fpu_lfpc_safe() behavior where a corrupt signal frame value causes a specification exception and 0 is used instead. HELPER(sfpc) now calls cpu_s390x_load_fpc() after its full specification-exception check, including the FEAT_FLOATING_POINT_EXT test that is not needed for the signal restore path. Fixes: 2941e0fa05 ("linux-user/s390x: Save/restore fpc when handling a sign= al") Cc: qemu-stable@nongnu.org Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 2762cd51ee033dccb3167110376dd125244cc819) Signed-off-by: Michael Tokarev diff --git a/linux-user/s390x/signal.c b/linux-user/s390x/signal.c index 96d1c8d11c..28ad80bde4 100644 --- a/linux-user/s390x/signal.c +++ b/linux-user/s390x/signal.c @@ -332,7 +332,11 @@ static void restore_sigregs(CPUS390XState *env, target= _sigregs *sc) for (i =3D 0; i < 16; i++) { __get_user(env->aregs[i], &sc->regs.acrs[i]); } - __get_user(env->fpc, &sc->fpregs.fpc); + { + uint32_t fpc; + __get_user(fpc, &sc->fpregs.fpc); + cpu_s390x_load_fpc(env, fpc); + } for (i =3D 0; i < 16; i++) { __get_user(*get_freg(env, i), &sc->fpregs.fprs[i]); } diff --git a/target/s390x/cpu.h b/target/s390x/cpu.h index 40bc1f0741..6826cda1c0 100644 --- a/target/s390x/cpu.h +++ b/target/s390x/cpu.h @@ -896,6 +896,7 @@ void s390_init_sigp(void); /* helper.c */ void s390_cpu_set_psw(CPUS390XState *env, uint64_t mask, uint64_t addr); uint64_t s390_cpu_get_psw_mask(CPUS390XState *env); +void cpu_s390x_load_fpc(CPUS390XState *env, uint32_t fpc); =20 /* outside of target/s390x/ */ S390CPU *s390_cpu_addr2state(uint16_t cpu_addr); diff --git a/target/s390x/tcg/fpu_helper.c b/target/s390x/tcg/fpu_helper.c index 122994960a..6152d14aa9 100644 --- a/target/s390x/tcg/fpu_helper.c +++ b/target/s390x/tcg/fpu_helper.c @@ -952,6 +952,19 @@ static const int fpc_to_rnd[8] =3D { float_round_to_odd, }; =20 +void cpu_s390x_load_fpc(CPUS390XState *env, uint32_t fpc) +{ + /* + * Mimic kernel fpu_lfpc_safe(): a corrupt signal frame value that wou= ld + * trigger a specification exception instead results in FPC being set = to 0. + */ + if (fpc_to_rnd[fpc & 0x7] =3D=3D -1 || fpc & 0x03030088u) { + fpc =3D 0; + } + env->fpc =3D fpc; + set_float_rounding_mode(fpc_to_rnd[fpc & 0x7], &env->fpu_status); +} + /* set fpc */ void HELPER(sfpc)(CPUS390XState *env, uint64_t fpc) { @@ -959,12 +972,7 @@ void HELPER(sfpc)(CPUS390XState *env, uint64_t fpc) (!s390_has_feat(S390_FEAT_FLOATING_POINT_EXT) && fpc & 0x4)) { tcg_s390_program_interrupt(env, PGM_SPECIFICATION, GETPC()); } - - /* Install everything in the main FPC. */ - env->fpc =3D fpc; - - /* Install the rounding mode in the shadow fpu_status. */ - set_float_rounding_mode(fpc_to_rnd[fpc & 0x7], &env->fpu_status); + cpu_s390x_load_fpc(env, fpc); } =20 /* set fpc and signal */ --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383314; cv=none; d=zohomail.com; s=zohoarc; b=BVOgLH87ryMNrdCRFusqh92h72OkQzvrESqc++1XSix5gS4nC0uNG7qQUqNtFgjUiYktN28igppT3GF3nmMvoQeeRlcyGdLB2cT5nIir9p3FzvUcZZkM4k31japBxtePJSJgymh+EDTqrAyybU28eWG1P9Buiyd/nP0lQ+PCIaI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383314; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Vx6YLiojGLoOIis9elYM0zKzJHAICjR+3Ciim4gXpH8=; b=Z3r/eli8HTSLSiXDtLb6Wn1WSWRlzYf0nOxTgilflmcECbONvY9CgEOINcRWhE8PAcZMOnRaUo/WgBCkqOfUNVn/ovDbrdzzsZWmSSf+NIY0BgtsBCALvs17pPYK7fH2m3HBALStY9JQMXvUd7pZL5iU/SUJWuAoJ+ijDFn7deE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383314581217.8936832799384; Sat, 13 Jun 2026 13:41:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV9K-0000t2-WF; Sat, 13 Jun 2026 16:40:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9H-0000bX-A9; Sat, 13 Jun 2026 16:40:11 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9F-0004TR-C1; Sat, 13 Jun 2026 16:40:10 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 20CAD1B6F06; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 802943CE957; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=lRK4NhiR2fBV89rabH41NE98LJMgN+fdDW4JciwJ5Yk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=JSBnMafgnCFyDo4xz3HxzhLHTBPIicfTnmoyTQBlImFCPG/bkq9riI4bBfygjKWlP E8wkiGuAyMjACOQhTl2TGvByyW8cIzQ0xpMdhtSheBByMgiOq4R3GtnsTXs1tXdMA1 MwdGuM2VUquw1AQU4os2ZXCjKqDnmAWXJWPkAedgPSQrGjFQRI+WcFLKoczoO0TzfF qK8Dp/QmV5Q9hbn3ZRSO9MqKvb3V2kmtT6whOB5PNvZJVbL+Ek5N++xyLY80W7esmz h7OhWEJPYjKX1MVg0veLdFob/9jRFkIz36fUiCdv7p5GQeB4ntE0Owl1Rgvcbdj1TW IRDYsDmZXSFOQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-11.0.2 43/72] hw/9pfs: add NULL check in v9fs_path_is_ancestor() Date: Sat, 13 Jun 2026 23:35:09 +0300 Message-ID: <20260613203542.1809153-43-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383315906158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add NULL check for s1->data and s2->data before using them in string operations. This prevents potential crashes when dealing with uninitialized paths. This is just a defensive measure. We are currently never passing NULL to this function. Link: https://lore.kernel.org/qemu-devel/3348c4d683f061c23083bd45994d527be4= fb7cbc.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit abb0cc02fb56e2432837e34b80fe68768f95e774) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index e2713b9eee..e590c414ab 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -241,6 +241,9 @@ int v9fs_name_to_path(V9fsState *s, V9fsPath *dirpath, */ static int v9fs_path_is_ancestor(V9fsPath *s1, V9fsPath *s2) { + if (!s1->data || !s2->data) { + return 0; + } if (!strncmp(s1->data, s2->data, s1->size - 1)) { if (s2->data[s1->size - 1] =3D=3D '\0' || s2->data[s1->size - 1] = =3D=3D '/') { return 1; --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383410; cv=none; d=zohomail.com; s=zohoarc; b=grwdZ4z/ViF06+q18tXH9wDxeWYI//Z6U9IiinC31TfJUMuJ+/pgYipn5Uiwd8LuOkkDLn2nwS1j+A4Rq/rFDzwzp1LADaK3dpS7YgVrLxiVnMxbSeXFOWMlDiRzXTrcc2fQH7nAa+gw3ASNiiyQ7X28IGtRSr2DWiQKKm9orf8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383410; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RQ2t152RvX53cD46ZfAgHZnWnNxDD+SPXKW2xZdz2t8=; b=SDWpOd3rd/5lUiYizn7f1ponwJ5cFahi1EZcLZmklqnAirCJTzgkrd2K1z632cGg7aQcLlWF7e2piwJ0iLvDZYBMmhrSyMJ7WgvJFZGeFGrSq+SG60hf2O65VqyxXb1sbKd4rb4TBT+XfdWkKsj6Fu32K+c8syf3wP/2ApwuP28= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383410435243.0819027204211; Sat, 13 Jun 2026 13:43:30 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV9Q-000140-A7; Sat, 13 Jun 2026 16:40:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9K-0000t5-Kv; Sat, 13 Jun 2026 16:40:14 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9I-0004VE-S5; Sat, 13 Jun 2026 16:40:14 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 2D6201B6F08; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9856B3CE958; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=hruUjaXdQAdvaQCyFc5bpqH3UnncxRCYx7iu6J++zHc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Y5YW5ldHpqSeEQOe+ZJ7iHwYHBIMWamDxy37xHqCFBmReB2Y//O6pq5/oJxnGV7Cc 0NUYzKIE2JXYsZ77YFTq3GHuMd7ujwqa50W1ae3N5mIAx1R4BVXQnXYZSM/yerQGHJ Vxxsg1Yfs5sARtQ8xI0MexeqXOtZiSF8nlw02jRwswJ54+8IWWrIDqM4O8x2RJyFFR ZZde7v3aptbzAUk2VnYNN60E+FMjRzJxduTy8L/Am8qGteCf5TxDPEDk8gwZdKQaUf UCQIUAtnOq7rVmr61i0N97ekk8t38cholkllTBeya8NS84QucIW0TCHmrud4P2rO4X wNnpIhOFINFzg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-11.0.2 44/72] hw/9pfs: change V9fsPath.size to size_t and v9fs_path_sprintf() return type Date: Sat, 13 Jun 2026 23:35:10 +0300 Message-ID: <20260613203542.1809153-44-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383412176158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck - Change V9fsPath.size from uint16_t to size_t to support paths larger than 65536 bytes. - Change v9fs_path_sprintf() return type from void to int to allow error reporting. Link: https://lore.kernel.org/qemu-devel/2d2348d94ff43fbe4cc0aea24fb312c5c1= 5ee809.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit dbaf84e148b0c8b66dcb47788a6bb13806e401e4) Signed-off-by: Michael Tokarev diff --git a/fsdev/file-op-9p.h b/fsdev/file-op-9p.h index b85c9934de..e8d0661c4b 100644 --- a/fsdev/file-op-9p.h +++ b/fsdev/file-op-9p.h @@ -112,7 +112,7 @@ struct FsContext { }; =20 struct V9fsPath { - uint16_t size; + size_t size; char *data; }; P9ARRAY_DECLARE_TYPE(V9fsPath); diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index e590c414ab..88894ec9d2 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -203,16 +203,24 @@ void v9fs_path_free(V9fsPath *path) } =20 =20 -void v9fs_path_sprintf(V9fsPath *path, const char *fmt, ...) +int v9fs_path_sprintf(V9fsPath *path, const char *fmt, ...) { va_list ap; + int ret; =20 v9fs_path_free(path); =20 va_start(ap, fmt); - /* Bump the size for including terminating NULL */ - path->size =3D g_vasprintf(&path->data, fmt, ap) + 1; + ret =3D g_vasprintf(&path->data, fmt, ap); va_end(ap); + if (ret < 0) { + error_report_once("9pfs: unusual path formatting failure; " + "invalidating associated FID"); + return -1; + } + /* Bump the size for including terminating NULL */ + path->size =3D ret + 1; + return 0; } =20 void v9fs_path_copy(V9fsPath *dst, const V9fsPath *src) diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index 65cc45e344..b2df659b0e 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -456,8 +456,8 @@ static inline uint8_t v9fs_request_cancelled(V9fsPDU *p= du) void coroutine_fn v9fs_reclaim_fd(V9fsPDU *pdu); void v9fs_path_init(V9fsPath *path); void v9fs_path_free(V9fsPath *path); -void G_GNUC_PRINTF(2, 3) v9fs_path_sprintf(V9fsPath *path, const char *fmt, - ...); +int G_GNUC_PRINTF(2, 3) v9fs_path_sprintf(V9fsPath *path, const char *fmt, + ...); void v9fs_path_copy(V9fsPath *dst, const V9fsPath *src); size_t v9fs_readdir_response_size(V9fsString *name); int v9fs_name_to_path(V9fsState *s, V9fsPath *dirpath, --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383522; cv=none; d=zohomail.com; s=zohoarc; b=oDxTgJs2D5Akm8TslugvoNXgqoCSLh1RvLajn6ibOcs7ECkPOjzE9syxMWlIDr6GfuJibzDdNwlJ9FMSh9KMvggWoBrRuyoeAphvFfFNMDoQ8JGjHPhyglzupnzqWScIqgsDOEgpxU0+vV/SP1/kVzMz4Fz2eyCCIYTJ3bzwz+o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383522; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fZQxguZqXp0TiYFi/itdiD0OelZwID66/nHex9iRQjY=; b=P66f0KmTLOr0mnQVKP3YwxRd8c4FjvkdS20TJPExNYpjDBIt7F2mSKju1u37b4GXG59X+9G9Raeuz4Rrbay2KgrsM/J0Y7lIJzSzPuervWhLRD83JhOnvrUH/mHCOIL0D0FkTP1dMnjQyq5gi7ug/Oxhpmp58rMOTmOhzSFg8LI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17813835222142.8659064883117935; Sat, 13 Jun 2026 13:45:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV9h-0002XD-2M; Sat, 13 Jun 2026 16:40:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9f-0002Ox-Es; Sat, 13 Jun 2026 16:40:35 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9c-0004VU-Uz; Sat, 13 Jun 2026 16:40:35 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 44D101B6F0A; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id A48793CE959; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=O/VAYKtFT/ySzeCdN9vtq7zt1BEiR6EfG4DYJe0VKwM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=DnKrche/6bxqNXmYjQ8d6ywybzIfr0fu+hy+aLWdraJoTJppdRkuejTo9xkRLwLyn xU7/wcNGPbrQl3UMcZVqvanmFieGehdZKzVESCxfQfOcwFdO4ziFz8KHgtWe30tLSA ElOY2g4VY0k3ITnoTBEbvwAOrUBrv/EiSY9M4QWm5wgmfY+XvCUj8/pdExRoEIWxWe j455GUK+oT5JdBlYoZttaWmk5aX3M+QeRWu1YABaKHhqU5BNaaliuXpfC9GO8+qBPP kq8TqV+QfOwN5WV7IDKkDE4clLJvacmNZeFt6e8kRB7O/Pk8lZl9cEVQ850GzUO/iL NsUjmWDfp5hpw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-11.0.2 45/72] hw/9pfs: add error handling to v9fs_fix_path() Date: Sat, 13 Jun 2026 23:35:11 +0300 Message-ID: <20260613203542.1809153-45-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383522568158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Update v9fs_fix_path() to return int and propagate errors from v9fs_path_sprintf(). This allows callers to detect and handle path formatting failures. Link: https://lore.kernel.org/qemu-devel/a0592741a918b7cbe751980ec7ec0c03f5= 05924c.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 54dd352c59269fdb5241e7b6dbcecaff107e7f5a) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 88894ec9d2..d704de644f 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -1417,13 +1417,15 @@ static void print_sg(struct iovec *sg, int cnt) } =20 /* Will call this only for path name based fid */ -static void v9fs_fix_path(V9fsPath *dst, V9fsPath *src, int len) +static int v9fs_fix_path(V9fsPath *dst, V9fsPath *src, int len) { V9fsPath str; + int ret; v9fs_path_init(&str); v9fs_path_copy(&str, dst); - v9fs_path_sprintf(dst, "%s%s", src->data, str.data + len); + ret =3D v9fs_path_sprintf(dst, "%s%s", src->data, str.data + len); v9fs_path_free(&str); + return ret; } =20 static inline bool is_ro_export(FsContext *ctx) --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383463; cv=none; d=zohomail.com; s=zohoarc; b=lRmPS4W/7C9DpMROgoeN6zli6522OcwTUTUSvElL2O1z1nZIwaVlwGTtV3ZOBRzRXtFdVH4v95eZGbRDap1Be7T9WCYAdxaFvdt9hmQS2VgGZBK/QcgwPRR53WKuJTmfG86QzNPqUootwgurxV5e6QWbq+2iu5kZW6x5OSXMthA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383463; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=nsPlrAg5wdyHceESmd6nzkhsgrb+/rHodmlTH0nzrjU=; b=iwYB4hXVeLhod06hnmlwBFpctAjid0sGDtmsxhPwjoeoVd1HlyZhkvkmf5MhbuRbnd5wfTtFzTnhT6k1DT7BHParNDzzAct7WCOr8gOSOkEKuLv9tgN3WIt88L1uDobqI/wEFxx0KFEVp0XmekAhZ6jnklXqQhACw+pEV40FrAY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383463828899.4193815230155; Sat, 13 Jun 2026 13:44:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV9j-0002dz-Ub; Sat, 13 Jun 2026 16:40:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9i-0002bv-Cd; Sat, 13 Jun 2026 16:40:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9g-0004YE-96; Sat, 13 Jun 2026 16:40:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 51A3E1B6F0C; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id BBB9C3CE95A; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=4tk3GUct0C8a+DpGA4Ou5oAjqkp+/dLPmbzo2Xr5o3Y=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=RtQhxS+cJwhYPKGzly2J/7jFZVtqeoxnvQbY5n4gQ38dyzeNCrozK76EK+viA6i0a jzS3nx1Re/h2mqw5NabxcW+qbpL/8UfqKgBJ9RHGgOwiyR/iLppL0sYouEChKEXuLV CTRx7CE4tk7Tjzw4X+3E+uJpbomjmP1woQbS+I7S8lu2jxW3sWUYgbYqdvFxhz7yVi ERtQbs4CUYxvBniyk5Nflv4gaiV4YkIchzDEG1qGaoKcaJqEJkVxydGaH+9dCcY0TS Mf1YT61PxV+TcZ3NVgmS5cHxkomkaispdBVjTaJPhhlViGhNUpWgZbKhIk+n+R8VN/ naAkypTTAoDng== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Wang Jihe , Michael Tokarev Subject: [Stable-11.0.2 46/72] hw/9pfs: let callers of v9fs_path_sprintf() and v9fs_fix_path() handle errors Date: Sat, 13 Jun 2026 23:35:12 +0300 Message-ID: <20260613203542.1809153-46-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383464410158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck This patch mitigates issues with very large absolute paths. - Add error handling to all v9fs_path_sprintf() calls in local_name_to_path() - Update callers of v9fs_fix_path() to check return values. - When path formatting fails, clunk the affected FIDs to prevent use of invalid paths. - Use g_autofree for temporary variables to simplify code. Even though paths are usually limited to PATH_MAX (typically 4k) on guest, this limitation can be circumvented by using *at() functions on guest and creating very deep directory structures. This was a problem for QEMU 9p server, as it currently tracks the absolute path for each FID internally that always requires assembly of a (potentially ver large) absolute path. A true long-term fix would be getting rid of storing an absolute path for each FID internally. However that would likely be a massive change with uncertain implications. This patch therefore just mitigates the problem by immediately clunking (i.e. closing) all FIDs whose path exceed a limit that we could handle. As this only accounts to very unusual large absolute paths not ever been reported on (sane) production machines, this is currently considered an acceptable mitigation that should only (counter)affect malicious attempts. Fixes: 2f008a8c97e2 ("hw/9pfs: Use the correct signed type ...") Reported-by: Wang Jihe Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3358 Link: https://lore.kernel.org/qemu-devel/1d11dcbfc95b811dcdb48c6d7f3894d0eb= d073a2.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 3802c0e755a53b126e717415b54226a468bf7ddf) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p-local.c b/hw/9pfs/9p-local.c index 24cb1da90a..aa48306b0e 100644 --- a/hw/9pfs/9p-local.c +++ b/hw/9pfs/9p-local.c @@ -1261,26 +1261,35 @@ static int local_name_to_path(FsContext *ctx, V9fsP= ath *dir_path, } else if (!strcmp(name, "..")) { if (!strcmp(dir_path->data, ".")) { /* ".." relative to the root is "." */ - v9fs_path_sprintf(target, "."); + if (v9fs_path_sprintf(target, ".") < 0) { + return -1; + } } else { - char *tmp =3D g_path_get_dirname(dir_path->data); + g_autofree char *tmp =3D g_path_get_dirname(dir_path->data= ); /* Symbolic links are resolved by the client. We can assume * that ".." relative to "foo/bar" is equivalent to "foo" */ - v9fs_path_sprintf(target, "%s", tmp); - g_free(tmp); + if (v9fs_path_sprintf(target, "%s", tmp) < 0) { + return -1; + } } } else { assert(!strchr(name, '/')); - v9fs_path_sprintf(target, "%s/%s", dir_path->data, name); + if (v9fs_path_sprintf(target, "%s/%s", dir_path->data, name) <= 0) { + return -1; + } } } else if (!strcmp(name, "/") || !strcmp(name, ".") || !strcmp(name, "..")) { /* This is the root fid */ - v9fs_path_sprintf(target, "."); + if (v9fs_path_sprintf(target, ".") < 0) { + return -1; + } } else { assert(!strchr(name, '/')); - v9fs_path_sprintf(target, "./%s", name); + if (v9fs_path_sprintf(target, "./%s", name) < 0) { + return -1; + } } return 0; } diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index d704de644f..b4314d2549 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -3325,12 +3325,14 @@ static int coroutine_fn v9fs_complete_rename(V9fsPD= U *pdu, V9fsFidState *fidp, goto out; } } else { - char *dir_name =3D g_path_get_dirname(fidp->path.data); + g_autofree char *dir_name =3D g_path_get_dirname(fidp->path.data); V9fsPath dir_path; =20 v9fs_path_init(&dir_path); - v9fs_path_sprintf(&dir_path, "%s", dir_name); - g_free(dir_name); + err =3D v9fs_path_sprintf(&dir_path, "%s", dir_name); + if (err < 0) { + goto out; + } =20 err =3D v9fs_co_name_to_path(pdu, &dir_path, name->data, &new_path= ); v9fs_path_free(&dir_path); @@ -3351,7 +3353,10 @@ static int coroutine_fn v9fs_complete_rename(V9fsPDU= *pdu, V9fsFidState *fidp, while (g_hash_table_iter_next(&iter, &fid, (gpointer *) &tfidp)) { if (v9fs_path_is_ancestor(&fidp->path, &tfidp->path)) { /* replace the name */ - v9fs_fix_path(&tfidp->path, &new_path, strlen(fidp->path.data)= ); + if (v9fs_fix_path(&tfidp->path, &new_path, + strlen(fidp->path.data)) < 0) { + clunk_fid(s, tfidp->fid); + } } } out: @@ -3448,7 +3453,10 @@ static int coroutine_fn v9fs_fix_fid_paths(V9fsPDU *= pdu, V9fsPath *olddir, while (g_hash_table_iter_next(&iter, &fid, (gpointer *) &tfidp)) { if (v9fs_path_is_ancestor(&oldpath, &tfidp->path)) { /* replace the name */ - v9fs_fix_path(&tfidp->path, &newpath, strlen(oldpath.data)); + if (v9fs_fix_path(&tfidp->path, &newpath, + strlen(oldpath.data)) < 0) { + clunk_fid(s, tfidp->fid); + } } } out: --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383271; cv=none; d=zohomail.com; s=zohoarc; b=m3lG7YMZDy3SgNgtfczR9RELxIA5c260cef56imQVXE5b98LahUyOWt/C7ESW6tMTMqDumYyaQDiF5SAVK0xzkaFRq3YKYkFPNzxHKrywdPXgnH1nm5dHZYAqCyERZqX4U2xTK/ZWnWY7F+Q/LSEuSaD+nyey0UTJI+V84CQe5I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383271; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=deZHwNN5WIR4JTV2uTez3iP2bU6EN9kjhA9tphGZpPs=; b=PPPSgi2cc2djiXDXEvnWaDu4ZNygCMGK6uJMI0kS+QAEu8mIH+S8hfXoBLXgVy5Qpp0LTI+WSVRip5pg7S8Wh0QuRsjIpitsIqqhoRJJtO/SksaVRn5n8rHXvDAsSGubX2XY4mkQoNDg9bFKyX9bNindo+3ZLr4r3dF19sja4EA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383271615599.8064567222272; Sat, 13 Jun 2026 13:41:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV9l-0002gR-Ap; Sat, 13 Jun 2026 16:40:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9i-0002cx-Pq; Sat, 13 Jun 2026 16:40:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9g-0004mi-WC; Sat, 13 Jun 2026 16:40:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 5F7871B6F0E; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C8CF63CE95B; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=y7G/QIRnRsuPk7/oRZJGZMI9BKG1yQA33e2zndC2EKs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=vbyCxAh3Naz/9uO+igaDddSjyZIt5qYYWiwQOz7DVDFgJip81mSl0jR+bZJV/Mv1p 6AFcI5CC8wIacIqFMHzybiI26zQkOYbo2qgCSibswDwuhjPFoBjIUw+M2TtM3jLjUJ FnFZAyeQGEAg5gJmNOUDCoLPDsbPwsXHXWHrVFIEZk3IFSNzH7UNA5mbtfWDYZcqjk Rs9+w8AxJVbfD55OejaVJn3y3a1WkkxPrK+4IX8IX/Sa8KnALKAEfb2mOX4YkM3ytV WcfyyyXEPIPD9EpfcBRphDqCjiqYhOakoreZxF7hGnovDbCiUrMWuHGzcsnq7raIoM 0/uS4I2ajWlmQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Fabiano Rosas , Michael Tokarev Subject: [Stable-11.0.2 47/72] tests/qtest/libqos: add qvirtqueue_reset_pool() for descriptor pool reset Date: Sat, 13 Jun 2026 23:35:13 +0300 Message-ID: <20260613203542.1809153-47-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383273815158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add a function to reset the virtqueue descriptor pool state without reinitializing the device. This is useful for tests that issue a high number of requests and are limited by the simplified virtio test driver's descriptor tracking, which decrements num_free but never increments it back. The function is safe for synchronous test code where requests are sent and completed before the next request is issued. Acked-by: Fabiano Rosas Link: https://lore.kernel.org/qemu-devel/96cf23eea1204b34443218fe76bd4a5eaf= 9163e8.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit be33c56898f8b18617cff91525f0b68abee8de07) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/libqos/virtio.c b/tests/qtest/libqos/virtio.c index 010ff40834..ccbb325222 100644 --- a/tests/qtest/libqos/virtio.c +++ b/tests/qtest/libqos/virtio.c @@ -464,6 +464,29 @@ bool qvirtqueue_get_buf(QTestState *qts, QVirtQueue *v= q, uint32_t *desc_idx, return true; } =20 +/* + * qvirtqueue_reset_pool: + * @vq: The virtqueue to reset + * + * Reset the descriptor pool state without reinitializing the device. + * This is useful for tests that issue a high number of requests and + * are limited by the simplified virtio test driver's descriptor tracking, + * which decrements num_free but never increments it back. + * + * This is only safe for synchronous test code where requests are + * sent and completed before the next request is issued. Do not use + * with asynchronous code where multiple requests may be in-flight. + * + * Note: This only resets the available descriptor pool (free_head, + * num_free). The used ring position (last_used_idx) is NOT reset + * and should continue to track consumed responses across iterations. + */ +void qvirtqueue_reset_pool(QVirtQueue *vq) +{ + vq->free_head =3D 0; + vq->num_free =3D vq->size; +} + void qvirtqueue_set_used_event(QTestState *qts, QVirtQueue *vq, uint16_t i= dx) { g_assert(vq->event); diff --git a/tests/qtest/libqos/virtio.h b/tests/qtest/libqos/virtio.h index e238f1726f..f17be0b9b6 100644 --- a/tests/qtest/libqos/virtio.h +++ b/tests/qtest/libqos/virtio.h @@ -150,6 +150,8 @@ void qvirtqueue_kick(QTestState *qts, QVirtioDevice *d,= QVirtQueue *vq, bool qvirtqueue_get_buf(QTestState *qts, QVirtQueue *vq, uint32_t *desc_id= x, uint32_t *len); =20 +void qvirtqueue_reset_pool(QVirtQueue *vq); + void qvirtqueue_set_used_event(QTestState *qts, QVirtQueue *vq, uint16_t i= dx); =20 void qvirtio_start_device(QVirtioDevice *vdev); --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383339; cv=none; d=zohomail.com; s=zohoarc; b=ASAfURPJ6vTOoLoolbvV6GVSjhx2qw082wpwm38Sx3rYPLSoKZXQe0tDZ3JYJ0Y/in5H2LJMytS0p6fI1/vR+tj7dEvgstvtnymk/vnp8chMgQoZS7af7AVe+o0xtnoZN/MKYlmxG19LAmraNrSXBQBc3YQK8tQ5zKrhTL7Ghoo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383339; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=nFx5ll5IjzEhD464BUHRMl4++7Dr6szIvCcYB7TYdsA=; b=HM8+IxuW/aQRh9SOl0k8BiQlAVgmkVkCxBs4Xlmvm7T2l+//IFQObzR+522NMXkmDQ5ESRuiRb1GDBiKcnvYmGVAwonC1uYIvvaS3XaAD1kwYqcgEutSceLBpvsM0xM+eH2fIMzpKw7RrVeS03CurKCygjW3gpJPk3Pc5tfCjE8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383339962214.49314990619655; Sat, 13 Jun 2026 13:42:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYV9m-0002jZ-UK; Sat, 13 Jun 2026 16:40:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9l-0002hb-NV; Sat, 13 Jun 2026 16:40:41 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYV9j-0004nI-Qu; Sat, 13 Jun 2026 16:40:41 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 6D2321B6F10; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D6EAF3CE95C; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=sq3wfnIuv+1QgSiiJ3QDn+46DBYkyT99RJCkygeD7uc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=jtW4MGuSUo9ncyHe78zxUmCtDcQNvUuQGsVtBzdVpRminDk3jQ897adi8EEKYt5PO u5THKG8tJ11DRRm6ZOSQnZdCh1scgIPiTvHlHDSWmDig/yBxSXkPfiwOARS7Ky7iqW 5W74ZW9yOfovzCNA+ZfzumtnLOZ+8+CZRvZYhY+GUzRs6IEwaoHMd+vBKZutD80gW+ Gr8xlqyP0NO8iuKfd0B1xqiu8NR0Df378DUB9kI2WPHL1woj5nxR+CpslNqSSLD1Dt oIyNn4v40Tkfj/rUghcmWO2LFEHgS2p5Mo27tm/4UarvRJH3K4okQF8kd1bbFH8Miz bw/+DTz25647Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-11.0.2 48/72] tests/9pfs: add deep absolute path test Date: Sat, 13 Jun 2026 23:35:14 +0300 Message-ID: <20260613203542.1809153-48-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383341946158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add fs_deep_absolute_path test that creates a deep directory structure with an absolute path length exceeding 16-bit range (i.e. >65536) to verify the previous buffer overflow fix. This is a slow test (may take several seconds) and therefore registered as "slow" test and not running by default. Use -m slow to run this test. Link: https://gitlab.com/qemu-project/qemu/-/issues/3358 Link: https://lore.kernel.org/qemu-devel/933552b2cfc2c442fac7f4e68c777dce20= ee8d7e.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 198627807a6b94e2aab157cf345f98edb1ac1a7a) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index ac38ccf595..1c69d41e33 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -14,6 +14,7 @@ =20 #include "qemu/osdep.h" #include "qemu/module.h" +#include "libqos/virtio.h" #include "libqos/virtio-9p-client.h" =20 #define twalk(...) v9fs_twalk((TWalkOpt) __VA_ARGS__) @@ -752,6 +753,72 @@ static void fs_use_after_unlink(void *obj, void *data, g_assert_cmpint(attr.size, =3D=3D, 2001); } =20 +/* https://gitlab.com/qemu-project/qemu/-/issues/3358 */ +static void fs_deep_absolute_path(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + QVirtio9P *v9p =3D obj; + v9fs_set_allocator(t_alloc); + + if (!g_test_slow()) { + g_test_skip("This is a slow test, run with -m slow"); + return; + } + + GString *path =3D g_string_new("/"); + char name[256]; + uint32_t current_fid =3D 0; + + tattach({ .client =3D v9p }); + + /* Create deep directory structure until absolute path length + * exceeds 16-bit range. + */ + while (path->len <=3D 65536) { + /* use 255-byte name (NAME_MAX) to reduce iterations to ~257 */ + memset(name, 'A', 255); + name[255] =3D '\0'; + + /* create the directory relative to current FID */ + tmkdir({ + .client =3D v9p, + .dfid =3D current_fid, + .name =3D name + }); + + /* just for locally tracking the current path length */ + g_string_append(path, name); + g_string_append(path, "/"); + + /* acquire new FID for the newly created directory */ + char *wnames[] =3D { name }; + current_fid =3D twalk({ + .client =3D v9p, + .fid =3D current_fid, + .nwname =3D 1, + .wnames =3D wnames + }).newfid; + + /* Reset descriptor pool to avoid exhaustion. The simplified + * virtio test driver does never free descriptors back to the pool + * after use, so we must manually reset it for the required high + * amount of 9p requests here. + */ + qvirtqueue_reset_pool(v9p->vq); + } + + /* check if the deepest directory is accessible */ + v9fs_attr attr =3D {}; + tgetattr({ + .client =3D v9p, + .fid =3D current_fid, + .request_mask =3D P9_GETATTR_BASIC, + .rgetattr.attr =3D &attr + }); + + g_string_free(path, TRUE); +} + static void cleanup_9p_local_driver(void *data) { /* remove previously created test dir when test is completed */ @@ -819,6 +886,8 @@ static void register_virtio_9p_test(void) &opts); qos_add_test("local/use_after_unlink", "virtio-9p", fs_use_after_unlin= k, &opts); + qos_add_test("local/deep_absolute_path", "virtio-9p", + fs_deep_absolute_path, &opts); } =20 libqos_init(register_virtio_9p_test); --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383513; cv=none; d=zohomail.com; s=zohoarc; b=Dk5XDW665XFegxPFk9y7tJLF+FVq4pg0pNHKxGKqsdzqrpvoCe09A63Lw4ss2/ZrccfyYawy8SpQ7YwZPG+1M2FTQ4/rsOyvNoBIwg7DBBY71DZG+tT6d54ZgpFgX6UtO5vl73p1kRr4yM3lBsKGgjat5lIKdMUVqlpCCek91lI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383513; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=QexvaD/MiGmJTC9cP/EjJxH5JoDHVk3sdWXGWFlh3Lk=; b=Voxpx+HmtbQFb4w0j0pp5JbCBXzB+p2fnKAGDz9KDMmG++dv2O/QMmjB3pyZcXjtnpkb/gR6sTP3UA7arx8TUF1eoaA1GkDr+3/ajIIBr5AD0z1fs6QjYnR6uWPOsIMP9fXmL8Fgkdp2v4DOPd51PFkrpRijNM0WuYusjkeC3kM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383513665776.2925402017601; Sat, 13 Jun 2026 13:45:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVA7-000358-Ix; Sat, 13 Jun 2026 16:41:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVA5-000323-Uh; Sat, 13 Jun 2026 16:41:01 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVA4-0004ng-9I; Sat, 13 Jun 2026 16:41:01 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 7E2D51B6F12; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E40DB3CE95D; Sat, 13 Jun 2026 23:36:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=ubdO+zpxQThsSC68lkwISaMv3bI5tKubzpj/X8KopDg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=gs2CH7z/wMSUT3Jol1LvY5Es8xf35jYd5Kk3SGviw4bxY7Ho0NANnvMcEpgndAE4U C87kTRdkBcVYCjBdkFb8IscHK6O95QfEKFCm/yb0peXEC8rWa7m/a1iAMZriyAUmfY 1gGZYUjh2DMSshLNAKZZN5ManNzBEK2OYli3t+lk2FNipFQx2wS7k3Hdm2Eocg3etd JH2jABmIWoTJi3Ussld4aqs8J/z/xrOUP82JTwB3GWPYtNg6oVAiKlrOCaCatOxxv1 d/sNSGt4RtrCeM6bbZs1ACp1BhQUJLttmM7S54tlw01o2Vle45roVumy5uutvrwkgx l8RWv1DokP9PA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, sin99xx , Christian Schoenebeck , Michael Tokarev Subject: [Stable-11.0.2 49/72] 9pfs: fix missing rename lock in v9fs_co_readdir_many (CVE-2026-48004) Date: Sat, 13 Jun 2026 23:35:15 +0300 Message-ID: <20260613203542.1809153-49-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383514539158500 Content-Type: text/plain; charset="utf-8" From: sin99xx v9fs_co_readdir_many() dispatches do_readdir_many() to a worker thread that reads V9fsFidState's path.data without holding a rename lock. A concurrent rename request, e.g. of its parent dir, causes the FID's absolute path to be altered by freeing the old path string and assigning a new one. This causes a heap-use-after-free race condition while do_readdir_many() is still accessing the old object. This allows a DoS by an unprivileged guest user. Fix this by wrapping the worker thread dispatch block within a pair of v9fs_path_read_lock() and v9fs_path_unlock() calls, like it's done at other places. Fixes: 2149675b195f ("9pfs: add new function v9fs_co_readdir_many()") Fixes: CVE-2026-48004 Reported-by: sin99xx Signed-off-by: sin99xx [Christian Schoenebeck: add commit log message] Link: https://lore.kernel.org/qemu-devel/E1wPkYi-000adH-4E@kylie.crudebyte.= com Signed-off-by: Christian Schoenebeck (cherry picked from commit 5a8da7e979f1f56b1cab82c2354833f309f1a78f) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/codir.c b/hw/9pfs/codir.c index bce7dd96e9..5568399343 100644 --- a/hw/9pfs/codir.c +++ b/hw/9pfs/codir.c @@ -220,13 +220,16 @@ int coroutine_fn v9fs_co_readdir_many(V9fsPDU *pdu, V= 9fsFidState *fidp, bool dostat) { int err =3D 0; + V9fsState *s =3D pdu->s; =20 if (v9fs_request_cancelled(pdu)) { return -EINTR; } + v9fs_path_read_lock(s); v9fs_co_run_in_worker({ err =3D do_readdir_many(pdu, fidp, entries, offset, maxsize, dosta= t); }); + v9fs_path_unlock(s); return err; } =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383538; cv=none; d=zohomail.com; s=zohoarc; b=lgnXQaJNJHNjnj7V6LT83jTqqSEVy+GSfv+Z3KiLMOlJ09CFGCaMiHJaJjjdDIVO82eaBDbyglcJIFe0anhQ6CCl4poX1LCvuB7nSd14PYLYirh/ss3yAZSq5wQlIHmk/UV27Fg2k3u6PgO7w0jej0GBZSP3ktYaKhR6OLDw9cs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383538; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lEIED/Wc9tzJFjCP7matfedwXpt/sEA5sQFT6daDr6M=; b=dJyranz89c8nmhaQtzvmXc+uclYiqEpW2Rql48vsO1YOYEA+kt7+VNV1KPzdIhXTS/Rr/+42vueD2b9QER49r601YKNtSTtW+89r9Hd2yq2Kgo+LDyVgsiWdVuMnUdDODTsyijvyJN7RTHgz3eh9MbvQ5gyCsFs7HPE0BpllJVA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383538568416.78010302592895; Sat, 13 Jun 2026 13:45:38 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVAB-0003Cx-4P; Sat, 13 Jun 2026 16:41:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVA8-00037p-Uh; Sat, 13 Jun 2026 16:41:04 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVA7-0004uW-7m; Sat, 13 Jun 2026 16:41:04 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 907E21B6F14; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 02D393CE95E; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=L7RCWWMvQS+EFrMDUd1cQg3OODBBHJtF30sWO9d+Tds=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=u1Gh0hEAJ/aOrQR0k8Fd8qIYGVZdFXT9QtTpP9o9LHtdwR+oh140qLxhwNgjAxiRw mOoWmd3GC2n2dWYUbQyeZ20Gq5dA+d+2esXFFg2R+i9lNW8wX8iO7QkD9DaBnbWa/C ZSUXCFYEn+BfOdSEnruy/EZov4DVS+jIaLp+4mdGC9Mg5lERddRLsX8FO5LMQ5YwFU y6eVxZovr0JaxXmCzCS/PjXapmVL3/bh5O5yWXraRa1EQovHP7UMletnQhktulI+Rv KKhBg5aptBHCRQ8/xNiWc3UnPzMBdkfHjoxMOQR0wo46n31ao+TzKst9v3LWywBmov vYkMD5MAjofjg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Markus Armbruster , Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 50/72] util/envlist: fix prefix-match in envlist_unsetenv() name lookup Date: Sat, 13 Jun 2026 23:35:16 +0300 Message-ID: <20260613203542.1809153-50-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383540684158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" envlist_unsetenv() looked up the entry to remove with strncmp(entry->ev_var, env, strlen(env)). The comparison length is the requested name's length, so any stored entry whose name *starts* with that name compares equal. envlist_setenv() inserts at the head of the list, so the first hit wins: with FOO=3D... stored first and FOOBAR=3D... stored afterward, envlist_unsetenv("FOO") iterates from the head, matches FOOBAR=3D... on the prefix, and drops it instead of FOO=3D... linux-user and bsd-user reach this code via the -U command-line switch, so the bug is reachable from a normal qemu-user invocation. envlist_setenv() used the same strncmp pattern but with envname_len =3D (eq_sign - env + 1), so the '=3D' byte sat inside the compared window and acted as an implicit boundary. setenv was therefore not buggy -- but the safety lived in the byte layout of ev_var rather than in the entry, so a future edit could easily drift the two sites apart again. Store the name length on each entry at insertion time and compare with explicit length equality plus memcmp via a small helper. Use the helper at both lookup sites so the boundary becomes a structural property of the entry: envlist_unsetenv() stops prefix-matching, and envlist_setenv()'s self-search no longer depends on the '=3D' byte serving as a sentinel. Fixes: 04a6dfebb6b5 ("linux-user: Add generic env variable handling") Signed-off-by: Denis V. Lunev Reviewed-by: Stefan Hajnoczi Message-id: 20260520212628.479772-2-den@openvz.org Cc: Stefan Hajnoczi Cc: Markus Armbruster Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi (cherry picked from commit c131ae56c13ffe6bd7089cf0d9bd00a7c2dbc71f) Signed-off-by: Michael Tokarev diff --git a/util/envlist.c b/util/envlist.c index 15fdbb109d..196c92c190 100644 --- a/util/envlist.c +++ b/util/envlist.c @@ -3,7 +3,8 @@ #include "qemu/envlist.h" =20 struct envlist_entry { - const char *ev_var; /* actual env value */ + const char *ev_var; /* actual env value: "NAME=3DVALUE" */ + size_t ev_name_len; /* length of NAME (offset of '=3D') */ QLIST_ENTRY(envlist_entry) ev_link; }; =20 @@ -12,6 +13,13 @@ struct envlist { size_t el_count; /* number of entries */ }; =20 +static inline bool envlist_name_eq(const struct envlist_entry *entry, + const char *name, size_t name_len) +{ + return entry->ev_name_len =3D=3D name_len && + memcmp(entry->ev_var, name, name_len) =3D=3D 0; +} + /* * Allocates new envlist and returns pointer to it. */ @@ -67,7 +75,7 @@ envlist_setenv(envlist_t *envlist, const char *env) /* find out first equals sign in given env */ if ((eq_sign =3D strchr(env, '=3D')) =3D=3D NULL) return (EINVAL); - envname_len =3D eq_sign - env + 1; + envname_len =3D eq_sign - env; =20 /* * If there already exists variable with given name @@ -76,8 +84,9 @@ envlist_setenv(envlist_t *envlist, const char *env) */ for (entry =3D envlist->el_entries.lh_first; entry !=3D NULL; entry =3D entry->ev_link.le_next) { - if (strncmp(entry->ev_var, env, envname_len) =3D=3D 0) + if (envlist_name_eq(entry, env, envname_len)) { break; + } } =20 if (entry !=3D NULL) { @@ -90,6 +99,7 @@ envlist_setenv(envlist_t *envlist, const char *env) =20 entry =3D g_malloc(sizeof(*entry)); entry->ev_var =3D g_strdup(env); + entry->ev_name_len =3D envname_len; QLIST_INSERT_HEAD(&envlist->el_entries, entry, ev_link); =20 return (0); @@ -119,8 +129,9 @@ envlist_unsetenv(envlist_t *envlist, const char *env) envname_len =3D strlen(env); for (entry =3D envlist->el_entries.lh_first; entry !=3D NULL; entry =3D entry->ev_link.le_next) { - if (strncmp(entry->ev_var, env, envname_len) =3D=3D 0) + if (envlist_name_eq(entry, env, envname_len)) { break; + } } if (entry !=3D NULL) { QLIST_REMOVE(entry, ev_link); --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383538; cv=none; d=zohomail.com; s=zohoarc; b=fHwTku/mARYn6YBgGUlM7wnH7S7qi/r7tXPloKk+2A5qi+Xbm39goD6C9/mX7wLKNne0huYYa1ghmFici+Hg/oA43ibcsvRou0NsOy2PsObc0U94YvkUlqnfzTFItS+PSBHXvLExGZ1F5VUPqqL+FN/GdfDWGPGwqB/SeKYtDVc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383538; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GSEA0amuO7bgV7vcEO7hagscvXL1YsSeiPv4CgA7SiA=; b=gIWiTlK+OJy/18hKs/f/pnfFrX0g+nG1PkNBk13sXOZxf4yk+rGTngEhJbxzcVZqFtDoDVOFh877luMQNYiZqO39yne/HL42f3c+Mk/o2wPzXgkuE69N3DmnEkYs2RTxFmaexDe3F4BCB/Yw2kC476+z7XKSlImwjd6ObZn/QiQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383538593307.0567821280089; Sat, 13 Jun 2026 13:45:38 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVAB-0003Ed-Ew; Sat, 13 Jun 2026 16:41:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVA9-0003Be-Mr; Sat, 13 Jun 2026 16:41:05 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVA7-00054Z-Ho; Sat, 13 Jun 2026 16:41:05 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A10581B6F15; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 136D13CE95F; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=JXs/WU3mOiJFzXrfD96WT7o1RIgEL0n70leqESDJyxU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=qceZJI4Ru7PxAvs43W07CQt9n/bEYcM1FNnlN5pUrUeOkQI2ujysrnxfa1Ow+eLrN Y75TF7XrzhKbOVGPZFn07pj/iGD4zAIncyQmc8wfByum78wv2j517Wn5CIX4jWjrvr q2ikSFDWYwd6siuBQG9TrX3YUTjGiXL6pVV+dcDN0gmbkK+MDKguuhSHfcrGOdry+5 T9LVcUFQEWxMMPYKXRhweipbxq63/JaAGfyZ9qAynfqHoLCf3PSFujAaiA1WshTEc6 Y5b5y/fQnA5PvOFmrKtyuXg8YROVrMc0lXay06j7qoIscfYqrIKNEoH4UKYio5uZtJ 4gt19KhYPINKQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Markus Armbruster , Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 51/72] tests/unit: add test-envlist covering setenv/unsetenv name matching Date: Sat, 13 Jun 2026 23:35:17 +0300 Message-ID: <20260613203542.1809153-51-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383540739158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" util/envlist had no test coverage. Add tests/unit/test-envlist exercising the public envlist API and pinning down the prefix-match hazard fixed in the previous commit: - envlist_unsetenv("FOO") must not remove an entry named "FOOBAR"; - envlist_setenv("FOO=3D...") must not replace an existing "FOOBAR=3D..." entry placed earlier in the list (envlist_setenv() inserts at the head, so the first prefix match wins under the old strncmp rule). Also cover the rest of the contract: head-insertion order observed through envlist_to_environ(), replacement of an existing variable, the count argument of envlist_to_environ(), and the documented EINVAL paths (NULL inputs, setenv without '=3D', unsetenv with '=3D'). Signed-off-by: Denis V. Lunev Reviewed-by: Stefan Hajnoczi Message-id: 20260520212628.479772-3-den@openvz.org Cc: Stefan Hajnoczi Cc: Markus Armbruster Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi (cherry picked from commit 05221c600a5f3ef657d71aeaea632c5f1bab3a2d) Signed-off-by: Michael Tokarev diff --git a/tests/unit/meson.build b/tests/unit/meson.build index 41e8b06c33..f768e882a4 100644 --- a/tests/unit/meson.build +++ b/tests/unit/meson.build @@ -48,6 +48,7 @@ tests =3D { 'test-qapi-util': [], 'test-interval-tree': [], 'test-fifo': [], + 'test-envlist': [], } =20 if have_system or have_tools diff --git a/tests/unit/test-envlist.c b/tests/unit/test-envlist.c new file mode 100644 index 0000000000..53813dd4de --- /dev/null +++ b/tests/unit/test-envlist.c @@ -0,0 +1,196 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +/* + * envlist tests + * + * Copyright 2026 Virtuozzo International GmbH + * + * Authors: + * Denis V. Lunev + */ + +#include "qemu/osdep.h" +#include "qemu/envlist.h" + +static void free_environ(char **env) +{ + char **p; + + for (p =3D env; *p !=3D NULL; p++) { + g_free(*p); + } + g_free(env); +} + +static const char *find_env(char **env, const char *name) +{ + size_t name_len =3D strlen(name); + char **p; + + for (p =3D env; *p !=3D NULL; p++) { + if (strncmp(*p, name, name_len) =3D=3D 0 && (*p)[name_len] =3D=3D = '=3D') { + return *p + name_len + 1; + } + } + return NULL; +} + +static void test_envlist_basic(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + /* empty list */ + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 0); + g_assert_null(env[0]); + free_environ(env); + + /* add */ + g_assert_cmpint(envlist_setenv(el, "A=3D1"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "B=3D2"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "A"), =3D=3D, "1"); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* replace */ + g_assert_cmpint(envlist_setenv(el, "A=3D42"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "A"), =3D=3D, "42"); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* unset existing */ + g_assert_cmpint(envlist_unsetenv(el, "A"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + g_assert_null(find_env(env, "A")); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* unset non-existing is a no-op success */ + g_assert_cmpint(envlist_unsetenv(el, "NOPE"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + free_environ(env); + + envlist_free(el); +} + +/* + * envlist_setenv() inserts at the head; envlist_to_environ() walks + * head-to-tail, so the last setenv comes out first. + */ +static void test_envlist_head_insertion_order(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "A=3D1"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "B=3D2"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "C=3D3"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 3); + g_assert_cmpstr(env[0], =3D=3D, "C=3D3"); + g_assert_cmpstr(env[1], =3D=3D, "B=3D2"); + g_assert_cmpstr(env[2], =3D=3D, "A=3D1"); + g_assert_null(env[3]); + + free_environ(env); + envlist_free(el); +} + +static void test_envlist_einval(void) +{ + envlist_t *el =3D envlist_create(); + + /* NULL list */ + g_assert_cmpint(envlist_setenv(NULL, "A=3D1"), =3D=3D, EINVAL); + g_assert_cmpint(envlist_unsetenv(NULL, "A"), =3D=3D, EINVAL); + + /* NULL string */ + g_assert_cmpint(envlist_setenv(el, NULL), =3D=3D, EINVAL); + g_assert_cmpint(envlist_unsetenv(el, NULL), =3D=3D, EINVAL); + + /* setenv: missing '=3D' */ + g_assert_cmpint(envlist_setenv(el, "NOEQ"), =3D=3D, EINVAL); + + /* unsetenv: name must not contain '=3D' */ + g_assert_cmpint(envlist_unsetenv(el, "A=3DB"), =3D=3D, EINVAL); + + envlist_free(el); +} + +/* + * Regression: envlist_unsetenv("FOO") must not remove an entry named + * "FOOBAR" -- the previous strncmp(entry, name, strlen(name)) lookup + * prefix-matched. To trigger the bug, the longer-named entry has to + * be ahead of the target in the list: envlist_setenv() inserts at + * the head, so we add FOO first and FOOBAR last. + */ +static void test_envlist_unsetenv_no_prefix_match(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "FOO=3Dy"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "FOOBAR=3Dx"), =3D=3D, 0); + + g_assert_cmpint(envlist_unsetenv(el, "FOO"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + g_assert_cmpstr(find_env(env, "FOOBAR"), =3D=3D, "x"); + g_assert_null(find_env(env, "FOO")); + + free_environ(env); + envlist_free(el); +} + +/* + * envlist_setenv() must not replace a prior FOOBAR=3D... entry when + * setting FOO=3D... The pre-fix code happened to be safe here only + * because it included the trailing '=3D' byte in its strncmp length; + * this test pins down the post-fix contract that the name boundary + * is a property of the entry, not of the encoded form. + */ +static void test_envlist_setenv_no_prefix_match(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "FOOBAR=3Dx"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "FOO=3Dy"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "FOOBAR"), =3D=3D, "x"); + g_assert_cmpstr(find_env(env, "FOO"), =3D=3D, "y"); + + free_environ(env); + envlist_free(el); +} + +int main(int argc, char *argv[]) +{ + g_test_init(&argc, &argv, NULL); + + g_test_add_func("/envlist/basic", test_envlist_basic); + g_test_add_func("/envlist/head_insertion_order", + test_envlist_head_insertion_order); + g_test_add_func("/envlist/einval", test_envlist_einval); + g_test_add_func("/envlist/unsetenv_no_prefix_match", + test_envlist_unsetenv_no_prefix_match); + g_test_add_func("/envlist/setenv_no_prefix_match", + test_envlist_setenv_no_prefix_match); + + return g_test_run(); +} --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383365; cv=none; d=zohomail.com; s=zohoarc; b=MzaQWd45MLrbHzKtDIdebkY3stFuUx0CCM8jT444IjErPHLmr2EOpGkzih40Yg9z1hKDbLcpaq+FchAbQRO4M0g3wsFKNEiu1MDqemnV6Y7yjgROm4/CcOeBJJk2OrhCV+gVKzlfEXB3vYaxkfNm3fff1MC6j2bdh0GLVc/6bT8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383365; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=FfDXbBIvb5Fhy5ZyiCl3vfoqkFlFtMxYuICP36qSqq0=; b=ndIZG0MHDN81UoXOgJ4lCg/TokykURj7hlkHaQHjbJGRjoGRN33DbDzr1snJTHYvtAGBfpgsIUST7NkeTNVT9XnY4Y/LoauZzpeT2Yor4gqZkTYW1y0hVfAGRCIHs5n78RIBd/nLF69/r5tNM/K1cUBp2Tutc3O8WNGjO0q+gDM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383365377899.3274673567679; Sat, 13 Jun 2026 13:42:45 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVAE-0003JL-8C; Sat, 13 Jun 2026 16:41:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAC-0003Hi-Cl; Sat, 13 Jun 2026 16:41:08 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAA-00055G-ED; Sat, 13 Jun 2026 16:41:08 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B1D371B6F16; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 241C23CE960; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=VEkwjzgqpOMRnj24Pf/csY6+NNWUGNA5MVFit704Ems=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=uOWD3HaFf+ZpNzDyni5Jj5jUU4ah5S00KRUdaqoYt3gsUk4IbQORX7AkjzhQw2u/O pJ82xzjabhV1xIcEXhUzoo15C67foVpDDBl16AeRgjQGTnYUV+95yrQquOU0itcrd9 miopFihtuLiKxmCevDDHuKnWaWukDFd4lROoV0sfJQTXtPBstlRqWh5C2USUGZ4z4i HzhUyanwPUxMvf2/hUiTC5c0wIPMXIR0XxDnLvesb9G5XLDpyRD5jJ4n9DloEj2q69 ChICw72TMlY6He4R+SgD23aD/MgZzSBItQLhmjX8a/QXXPwYe5H8wEh4Mijs5hn8Pi zV5Xja5/Cl6RA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Alex=20Benn=C3=A9e?= , Pierrick Bouvier , Thomas Huth , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-11.0.2 52/72] ci: drop cirrus MacOS build Date: Sat, 13 Jun 2026 23:35:18 +0300 Message-ID: <20260613203542.1809153-52-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383366111158500 From: Alex Benn=C3=A9e CirrusCI is closing down soon so time to migrate. Reviewed-by: Pierrick Bouvier Reviewed-by: Thomas Huth Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-ID: <20260526110243.470002-6-alex.bennee@linaro.org> Signed-off-by: Alex Benn=C3=A9e (cherry picked from commit 984b192bdf371e275fb4226ca5047c1fff1de972) Signed-off-by: Michael Tokarev diff --git a/.gitlab-ci.d/cirrus.yml b/.gitlab-ci.d/cirrus.yml index f2a9a64b76..b71ab090b6 100644 --- a/.gitlab-ci.d/cirrus.yml +++ b/.gitlab-ci.d/cirrus.yml @@ -44,17 +44,3 @@ x64-freebsd-14-build: INSTALL_COMMAND: pkg install -y CONFIGURE_ARGS: --target-list-exclude=3Darm-softmmu,i386-softmmu,mips6= 4el-softmmu,mipsel-softmmu,mips-softmmu,ppc-softmmu,sh4eb-softmmu,xtensa-so= ftmmu --enable-rust TEST_TARGETS: check - -aarch64-macos-build: - extends: .cirrus_build_job - variables: - NAME: macos-14 - CIRRUS_VM_INSTANCE_TYPE: macos_instance - CIRRUS_VM_IMAGE_SELECTOR: image - CIRRUS_VM_IMAGE_NAME: ghcr.io/cirruslabs/macos-runner:sonoma - UPDATE_COMMAND: brew update - INSTALL_COMMAND: brew install - PATH_EXTRA: /opt/homebrew/ccache/libexec:/opt/homebrew/gettext/bin - PKG_CONFIG_PATH: /opt/homebrew/curl/lib/pkgconfig:/opt/homebrew/ncurse= s/lib/pkgconfig:/opt/homebrew/readline/lib/pkgconfig - CONFIGURE_ARGS: --target-list-exclude=3Darm-softmmu,i386-softmmu,mips6= 4-softmmu,mipsel-softmmu,mips-softmmu,ppc-softmmu,sh4-softmmu,xtensaeb-soft= mmu --enable-rust - TEST_TARGETS: check-unit check-block check-qapi-schema check-softfloat= check-qtest-x86_64 diff --git a/.gitlab-ci.d/cirrus/macos-14.vars b/.gitlab-ci.d/cirrus/macos-= 14.vars deleted file mode 100644 index def77cfdea..0000000000 --- a/.gitlab-ci.d/cirrus/macos-14.vars +++ /dev/null @@ -1,16 +0,0 @@ -# THIS FILE WAS AUTO-GENERATED -# -# $ lcitool variables macos-14 qemu -# -# https://gitlab.com/libvirt/libvirt-ci - -CCACHE=3D'/opt/homebrew/bin/ccache' -CPAN_PKGS=3D'' -CROSS_PKGS=3D'' -MAKE=3D'/opt/homebrew/bin/gmake' -NINJA=3D'/opt/homebrew/bin/ninja' -PACKAGING_COMMAND=3D'brew' -PIP3=3D'/opt/homebrew/bin/pip3' -PKGS=3D'bash bc bindgen bison bzip2 capstone ccache cmocka coreutils ctags= curl dbus diffutils dtc flex gcovr gettext git glib gnu-sed gnutls gtk+3 g= tk-vnc jemalloc jpeg-turbo json-c libcbor libepoxy libffi libgcrypt libiscs= i libnfs libpng libslirp libssh libtasn1 libusb llvm lzo make meson mtools = ncurses nettle ninja pixman pkg-config python-setuptools python3 rpm2cpio r= ust sdl2 sdl2_image snappy socat sparse spice-protocol swtpm tesseract usbr= edir vde vte3 vulkan-tools xorriso zlib zstd' -PYPI_PKGS=3D'PyYAML numpy pillow sphinx sphinx-rtd-theme tomli' -PYTHON=3D'/opt/homebrew/bin/python3' diff --git a/tests/lcitool/refresh b/tests/lcitool/refresh index e4d01d792b..fa4a16e358 100755 --- a/tests/lcitool/refresh +++ b/tests/lcitool/refresh @@ -311,7 +311,6 @@ try: # Cirrus packages lists for GitLab # generate_cirrus("freebsd-14") - generate_cirrus("macos-14") =20 # # VM packages lists --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383438; cv=none; d=zohomail.com; s=zohoarc; b=UO61l+FcYpyVaT6s2fgZJ5BGnoBOoOGXmcR+CIb7l8c9F0rhwq2kJvGNNCmfHKuUAHsuT6m/e/yErPyIt+s9babekeMpTIAcCqYvVP34xkEbNJWj8w3i1lPgTVDLMP4mtsu4uWdJ08di7WkFiz0eLoSZE1HNkYqQ14T9qgTOZeE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383438; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=5Ha0+t9PJjPX0GI1Oz+XYE2dURAy0ScL88zAlXAzdSc=; b=AJtc4KPIprdTlxrVzZikIHXDNWJMl72vjOHGbMdEU5ZLV/v3mN1wK/Ec4mhYQu+VsuY2jQvEg1gb9QHSL7p5e+3YVf0ECpp08zSS8LxV6tYpbAe2v1irFWDVIOoHGzxNrnm65NgVrlbo1lIPlMaX7yp1uupGJLFdXO/EGBQ6y0s= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383438045493.43262604844074; Sat, 13 Jun 2026 13:43:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVAF-0003Lf-6Y; Sat, 13 Jun 2026 16:41:11 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAD-0003IX-27; Sat, 13 Jun 2026 16:41:09 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAB-00055U-48; Sat, 13 Jun 2026 16:41:08 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BEF1D1B6F17; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 349483CE961; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=FCs91j2jahY7iqlzgzBO1t4k/xo/nVlyyBYkVbrJbIo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=dwaRPorhx5eBTKPer44cSDA9aYbZyybkl9a41xjeFObAzI11OLoU7SL7UIMufPiT2 tAIkLKXOqpodp4a2YeZZ+Ik8VKTgwOjQYOn3hV6V0+w/EsCTwxtuYaY/vSmEkfpCkn ORZadSynEW94STINzkr9K1nBtSsrYNf5VW3jfH2mJmTX4k9/7gte59TuNb7VpeCmRI 4Gd1xc2K82bwS7U0tJ/8vdY/WlignHB5IgZkzbFD6FxEC+khD9o1UuEcdb24qujdpH i4MOZHVrGNRe1PwYQuvqEWJqhpYML//Wvf2qV3qU+tHtvnW4sGQ65kNX/MPJzbbnKX MUlxQqhHOhKoQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Alex=20Benn=C3=A9e?= , Pierrick Bouvier , Michael Tokarev Subject: [Stable-11.0.2 53/72] gitlab: add initial MacOS 15 on gitlab runner Date: Sat, 13 Jun 2026 23:35:19 +0300 Message-ID: <20260613203542.1809153-53-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383438407158500 From: Alex Benn=C3=A9e The gitlab runners are currently in beta but available to projects on the Premium and Ultimate plans (which QEMU is via the Open Source program). We install some compilers via brew so we can run some of the check-tcg softmmu test cases. We disable rust as the version is too old. We disable plugins because we haven't taught the test harness about .dynlib vs .so yet. There is a discrepancy between the vars and version of MacOS because lcitool needs teaching about other versions (although I don't think it matters as brew is shared across versions). Reviewed-by: Pierrick Bouvier Message-ID: <20260526110243.470002-7-alex.bennee@linaro.org> Signed-off-by: Alex Benn=C3=A9e (cherry picked from commit 7684e78132905393e604014dce3185def4114108) Signed-off-by: Michael Tokarev diff --git a/.gitlab-ci.d/macos-14.vars b/.gitlab-ci.d/macos-14.vars new file mode 100644 index 0000000000..def77cfdea --- /dev/null +++ b/.gitlab-ci.d/macos-14.vars @@ -0,0 +1,16 @@ +# THIS FILE WAS AUTO-GENERATED +# +# $ lcitool variables macos-14 qemu +# +# https://gitlab.com/libvirt/libvirt-ci + +CCACHE=3D'/opt/homebrew/bin/ccache' +CPAN_PKGS=3D'' +CROSS_PKGS=3D'' +MAKE=3D'/opt/homebrew/bin/gmake' +NINJA=3D'/opt/homebrew/bin/ninja' +PACKAGING_COMMAND=3D'brew' +PIP3=3D'/opt/homebrew/bin/pip3' +PKGS=3D'bash bc bindgen bison bzip2 capstone ccache cmocka coreutils ctags= curl dbus diffutils dtc flex gcovr gettext git glib gnu-sed gnutls gtk+3 g= tk-vnc jemalloc jpeg-turbo json-c libcbor libepoxy libffi libgcrypt libiscs= i libnfs libpng libslirp libssh libtasn1 libusb llvm lzo make meson mtools = ncurses nettle ninja pixman pkg-config python-setuptools python3 rpm2cpio r= ust sdl2 sdl2_image snappy socat sparse spice-protocol swtpm tesseract usbr= edir vde vte3 vulkan-tools xorriso zlib zstd' +PYPI_PKGS=3D'PyYAML numpy pillow sphinx sphinx-rtd-theme tomli' +PYTHON=3D'/opt/homebrew/bin/python3' diff --git a/.gitlab-ci.d/macos.yml b/.gitlab-ci.d/macos.yml new file mode 100644 index 0000000000..c93bf12a29 --- /dev/null +++ b/.gitlab-ci.d/macos.yml @@ -0,0 +1,47 @@ +.macos_job_template: + extends: .base_job_template + stage: build + tags: + - saas-macos-large-m2pro + needs: [] + timeout: 80m + artifacts: + name: "$CI_JOB_NAME-$CI_COMMIT_REF_SLUG" + expire_in: 7 days + paths: + - build/meson-logs/ + - build/tests/tcg/ + reports: + junit: build/meson-logs/*.junit.xml + when: always + before_script: + - set -o allexport + - source .gitlab-ci.d/macos-14.vars + - set +o allexport + - export PATH=3D"$PATH_EXTRA:$PATH" + - export PKG_CONFIG_PATH=3D"$PKG_CONFIG_PATH" + - brew update + - brew install $PKGS + - brew install gdb aarch64-elf-gcc i686-elf-gcc x86_64-elf-gcc + - if test -n "$PYPI_PKGS" ; then PYLIB=3D$($PYTHON -c 'import sysconfi= g; print(sysconfig.get_path("stdlib"))'); rm -f $PYLIB/EXTERNALLY-MANAGED; = $PIP3 install --break-system-packages $PYPI_PKGS ; fi + script: + - mkdir build + - cd build + - ../configure --enable-werror $CONFIGURE_ARGS || { cat config.log mes= on-logs/meson-log.txt; exit 1; } + - $MAKE -j$(sysctl -n hw.ncpu) + - for TARGET in $TEST_TARGETS ; do $MAKE $TARGET ; done + +aarch64-macos-15-build: + extends: .macos_job_template + image: macos-15-xcode-16 + variables: + NAME: macos-15 + PATH_EXTRA: /opt/homebrew/gettext/bin + PKG_CONFIG_PATH: /opt/homebrew/curl/lib/pkgconfig:/opt/homebrew/ncurse= s/lib/pkgconfig:/opt/homebrew/readline/lib/pkgconfig + CONFIGURE_ARGS: + --target-list=3Daarch64-softmmu,i386-softmmu,x86_64-softmmu + --cross-prefix-aarch64=3Daarch64-elf- + --cross-prefix-i386=3Di686-elf- + --cross-prefix-x86_64=3Dx86_64-elf- + --disable-plugins + TEST_TARGETS: check-unit run-tcg-tests-aarch64-softmmu run-tcg-tests-i= 386-softmmu run-tcg-tests-x86_64-softmmu diff --git a/.gitlab-ci.d/qemu-project.yml b/.gitlab-ci.d/qemu-project.yml index 4d914c4897..9cbb5fe787 100644 --- a/.gitlab-ci.d/qemu-project.yml +++ b/.gitlab-ci.d/qemu-project.yml @@ -19,3 +19,4 @@ include: - local: '/.gitlab-ci.d/custom-runners.yml' - local: '/.gitlab-ci.d/cirrus.yml' - local: '/.gitlab-ci.d/windows.yml' + - local: '/.gitlab-ci.d/macos.yml' diff --git a/tests/lcitool/refresh b/tests/lcitool/refresh index fa4a16e358..4289cc381a 100755 --- a/tests/lcitool/refresh +++ b/tests/lcitool/refresh @@ -87,6 +87,12 @@ def generate_cirrus(target, trailer=3DNone): generate(filename, cmd, trailer) =20 =20 +def generate_vars(target, trailer=3DNone): + filename =3D Path(src_dir, ".gitlab-ci.d", target + ".vars") + cmd =3D lcitool_cmd + ["variables", "--format", "shell", target, "qemu= "] + generate(filename, cmd, trailer) + + def generate_pkglist(vm, target, project=3D"qemu"): filename =3D Path(src_dir, "tests", "vm", "generated", vm + ".json") cmd =3D lcitool_cmd + ["variables", "--format", "json", target, projec= t] @@ -312,6 +318,11 @@ try: # generate_cirrus("freebsd-14") =20 + # + # GitLab packages lists + # + generate_vars("macos-14") + # # VM packages lists # --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383398; cv=none; d=zohomail.com; s=zohoarc; b=DyjabRXZR4OsuZw3sFc3srwU1mUUJP8ysIWVftccoA3wDskaiq7wVfTHnd1BUPSdudXVnCwBAT67oitBcILP3qu3e++0NY4Yza9m+BfVIitYSOHIga8jX/Zz6U55C/24OtzitP3ssRdbvs2I3R8FlrjEy3w4JgR0FqvGPcJAb0s= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383398; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=dMTIrIn1jqYuyB0/of62QLSfjVYqAAyLy1iczuIDEV8=; b=ZYoTCqKfA+IcwEINF/CZPVi74CO8BpKvXXNnf3UT87d5qO17B8cwbxokpaym9WKhlnOTBPact5PH1unY2o3Geraev6rs/Wpbgik9pE6NLJmgQD5wCk7JS1ZN07utcs97qLC77Qg9pqE+B29ZhisPOtwCXfrE068yv1HEuPzBe6k= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383398732759.0329152109751; Sat, 13 Jun 2026 13:43:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVAb-0004aL-2s; Sat, 13 Jun 2026 16:41:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAZ-0004UC-RW; Sat, 13 Jun 2026 16:41:31 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAX-00056E-RY; Sat, 13 Jun 2026 16:41:31 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D0B001B6F18; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 428903CE962; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=zb56gFXKrBxhm7F3CspMLidaMJreYiHvIKwE6YJdNk8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=f+L+H20sAxbteDh9UTW/Z2CdvKlpV1vLJA+Wc1nv4bD4iJuaf/tcY1/bQ40JvaX+K oLH9q5KM5UlFgiUu9T7RBooCGRly1aUZrDu4Y9wYHEEJjb735kNWm/0SK4mZHVTb2U /5g0CXwGFTaYddzFXcrxwKzMjPgkfTPOnJnAX7r32ogo2xpEYIaxmglzqcz37bZ0Zt a7F7/iIS1JftiwP7gM1gMesHkJl+Y6wSWAx9qK9hnUGsj67w4G/3/8Ooy7Ax/0vbOq IWEYhJtvf+PDg4d3WdM1f3j72lYzb6qmc+uCRwXB1KvfjIHa8C1HysjvVZfvYeSRsr PRTH3o9vyueUA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Stefan Hajnoczi , Pierrick Bouvier , Warner Losh , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-11.0.2 54/72] gitlab: remove x64-freebsd-14-build Cirrus job Date: Sat, 13 Jun 2026 23:35:20 +0300 Message-ID: <20260613203542.1809153-54-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383400202158500 From: Stefan Hajnoczi Cirrus has shut down and the x64-freebsd-14-build is failing: https://gitlab.com/qemu-project/qemu/-/jobs/14656732122 Remove the x64-freebsd-14-build job to get the CI pipeline passing again. The next commit will be to remove Cirrus integration from the GitLab YAML and lcitool since it is no longer used. Signed-off-by: Stefan Hajnoczi Reviewed-by: Pierrick Bouvier Reviewed-by: Warner Losh Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-id: 20260602162457.828969-2-stefanha@redhat.com Signed-off-by: Stefan Hajnoczi (cherry picked from commit 4023f38b50a42a9a936ee3c1c3a9642110e42916) Signed-off-by: Michael Tokarev diff --git a/.gitlab-ci.d/cirrus.yml b/.gitlab-ci.d/cirrus.yml index b71ab090b6..4769d00c67 100644 --- a/.gitlab-ci.d/cirrus.yml +++ b/.gitlab-ci.d/cirrus.yml @@ -30,17 +30,3 @@ - cirrus-run -v --show-build-log always .gitlab-ci.d/cirrus/$NAME.yml variables: QEMU_JOB_CIRRUS: 1 - -x64-freebsd-14-build: - extends: .cirrus_build_job - variables: - NAME: freebsd-14 - CIRRUS_VM_INSTANCE_TYPE: freebsd_instance - CIRRUS_VM_IMAGE_SELECTOR: image_family - CIRRUS_VM_IMAGE_NAME: freebsd-14-3 - CIRRUS_VM_CPUS: 8 - CIRRUS_VM_RAM: 8G - UPDATE_COMMAND: pkg update; pkg upgrade -y - INSTALL_COMMAND: pkg install -y - CONFIGURE_ARGS: --target-list-exclude=3Darm-softmmu,i386-softmmu,mips6= 4el-softmmu,mipsel-softmmu,mips-softmmu,ppc-softmmu,sh4eb-softmmu,xtensa-so= ftmmu --enable-rust - TEST_TARGETS: check diff --git a/.gitlab-ci.d/cirrus/freebsd-14.vars b/.gitlab-ci.d/cirrus/free= bsd-14.vars deleted file mode 100644 index 98fbde6cc6..0000000000 --- a/.gitlab-ci.d/cirrus/freebsd-14.vars +++ /dev/null @@ -1,16 +0,0 @@ -# THIS FILE WAS AUTO-GENERATED -# -# $ lcitool variables freebsd-14 qemu -# -# https://gitlab.com/libvirt/libvirt-ci - -CCACHE=3D'/usr/local/bin/ccache' -CPAN_PKGS=3D'' -CROSS_PKGS=3D'' -MAKE=3D'/usr/local/bin/gmake' -NINJA=3D'/usr/local/bin/ninja' -PACKAGING_COMMAND=3D'pkg' -PIP3=3D'/usr/local/bin/pip' -PKGS=3D'alsa-lib bash bison bzip2 ca_root_nss capstone4 ccache4 cmocka cor= eutils ctags curl cyrus-sasl dbus diffutils dtc flex fusefs-libs3 gettext g= it glib gmake gnutls gsed gtk-vnc gtk3 json-c libepoxy libffi libgcrypt lib= jpeg-turbo libnfs libslirp libspice-server libssh libtasn1 llvm lzo2 meson = mtools ncurses nettle ninja opencv pixman pkgconf png py311-numpy py311-pil= low py311-pip py311-pyyaml py311-setuptools py311-sphinx py311-sphinx_rtd_t= heme py311-tomli py311-wheel python3 rpm2cpio rust rust-bindgen-cli sdl2 sd= l2_image snappy sndio socat spice-protocol tesseract usbredir virglrenderer= vte3 vulkan-tools xorriso zstd' -PYPI_PKGS=3D'' -PYTHON=3D'/usr/local/bin/python3' diff --git a/MAINTAINERS b/MAINTAINERS index ad215eced8..8cc89d4feb 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -4502,9 +4502,7 @@ FreeBSD Hosted Continuous Integration M: Ed Maste M: Li-Wen Hsu S: Maintained -F: .gitlab-ci.d/cirrus/freebsd* F: tests/vm/freebsd -W: https://cirrus-ci.com/github/qemu/qemu =20 Functional testing framework M: Thomas Huth diff --git a/tests/lcitool/refresh b/tests/lcitool/refresh index 4289cc381a..ad6a1e6fe8 100755 --- a/tests/lcitool/refresh +++ b/tests/lcitool/refresh @@ -313,11 +313,6 @@ try: enable_rust=3DFalse, trailer=3D"".join(debian_all_test_cross_compilers)) =20 - # - # Cirrus packages lists for GitLab - # - generate_cirrus("freebsd-14") - # # GitLab packages lists # --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383517; cv=none; d=zohomail.com; s=zohoarc; b=b4zXoIf90l8GbR0aBu+xo4mxCTkMHwThKWuzLX5KWyJ1sZtyneIaykY3auGHrZXIBsiQlEnyrhFFHbvaQTFm4Wio6TGyH4NhTv6Gm8l3dGifuX7pEWCLTWk+f5/+f1NN7zo9AEllP+OldNMFEnEum4P+LL/edc960yirMxcBmWU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383517; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RyY+DTEeM53gBbQV1iWDO5UtwnqvL2Ir8PDKrJIJ9A0=; b=ITkFnscuuZei2dBeLUfgkqNP+7ElOssxpsGMQellDY78sYR8VgRu0yMtw226oNxOqbGrZrTYmygP9UAfNgX7X4Gzrv+v81qCm6Da3jUxwddXH1bveQsWQE9SE0E3iwvdx4PVEfvEw/o/8Vo3DuGpe3K7cylHjVbZGp4zMwXNqGE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383517676768.6715348718128; Sat, 13 Jun 2026 13:45:17 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVAd-0004oJ-FT; Sat, 13 Jun 2026 16:41:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAb-0004bc-1n; Sat, 13 Jun 2026 16:41:33 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAY-00056X-Ge; Sat, 13 Jun 2026 16:41:32 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E237B1B6F19; Sat, 13 Jun 2026 23:36:05 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 546813CE963; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382965; bh=WpsrbVsZQk8gvShA9vq/22yy5WfUAbdU37e8V5+3KFo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=PRiOWR/PGSZSwtR8Cbe1lM74JpB8FJnmCy2k7rdeawmTBu2+ZuktkiRiqQyOd8/Vc b9Z6MP0mw55Yn+D41P4fgvmIoqa6yVIiUKF2GkrMPhDDUSqmxR8i9oohIKiU9jg6go hMhmGf0vE7lxMkIU6+UlvaSCgzDzlur5IltBvIZOqw57axjYVVsOwwASDXIJ/hWpia DtQllKhUnaY+C/p72GJXPbr+TDiPAnGwiIVgi1MrFCe2DVEgaCbfPdrPX2iz5qrtI+ wtW8hS1KgrK/yEqxLKcLww14YULhy9od8Fgpz5f7WzPb/IsTtFdvsDRY4FszxeHxqO JE0U3vq1+ecZA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Stefan Hajnoczi , Pierrick Bouvier , Warner Losh , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Michael Tokarev Subject: [Stable-11.0.2 55/72] lcitool: remove Cirrus CI support Date: Sat, 13 Jun 2026 23:35:21 +0300 Message-ID: <20260613203542.1809153-55-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383518680158500 From: Stefan Hajnoczi Remove GitLab CI integration for Cirrus CI now that nothing uses it anymore. Signed-off-by: Stefan Hajnoczi Reviewed-by: Pierrick Bouvier Reviewed-by: Warner Losh Reviewed-by: Alex Benn=C3=A9e Message-id: 20260602162457.828969-3-stefanha@redhat.com Signed-off-by: Stefan Hajnoczi (cherry picked from commit 29c042c6e9d4a09d4a0ac3fa54aeb7ee08ce0bdc) Signed-off-by: Michael Tokarev diff --git a/.gitlab-ci.d/base.yml b/.gitlab-ci.d/base.yml index 7640a1d52c..72eadc8073 100644 --- a/.gitlab-ci.d/base.yml +++ b/.gitlab-ci.d/base.yml @@ -52,10 +52,6 @@ variables: - if: '$CI_PIPELINE_SOURCE =3D=3D "schedule"' when: never =20 - # Cirrus jobs can't run unless the creds / target repo are set - - if: '$QEMU_JOB_CIRRUS && ($CIRRUS_GITHUB_REPO =3D=3D null || $CIRRUS= _API_TOKEN =3D=3D null)' - when: never - # Publishing jobs should only run on the default branch in upstream - if: '$QEMU_JOB_PUBLISH =3D=3D "1" && $CI_PROJECT_NAMESPACE =3D=3D $Q= EMU_CI_UPSTREAM && $CI_COMMIT_BRANCH !=3D $CI_DEFAULT_BRANCH' when: never diff --git a/.gitlab-ci.d/cirrus.yml b/.gitlab-ci.d/cirrus.yml deleted file mode 100644 index 4769d00c67..0000000000 --- a/.gitlab-ci.d/cirrus.yml +++ /dev/null @@ -1,32 +0,0 @@ -# Jobs that we delegate to Cirrus CI because they require an operating -# system other than Linux. These jobs will only run if the required -# setup has been performed on the GitLab account. -# -# The Cirrus CI configuration is generated by replacing target-specific -# variables in a generic template: some of these variables are provided -# when the GitLab CI job is defined, others are taken from a shell -# snippet generated using lcitool. -# -# Note that the $PATH environment variable has to be treated with -# special care, because we can't just override it at the GitLab CI job -# definition level or we risk breaking it completely. -.cirrus_build_job: - extends: .base_job_template - stage: build - image: registry.gitlab.com/libvirt/libvirt-ci/cirrus-run:latest - needs: [] - allow_failure: - exit_codes: 3 - # 20 mins larger than "timeout_in" in cirrus/build.yml - # as there's often a 5-10 minute delay before Cirrus CI - # actually starts the task - timeout: 80m - script: - - set -o allexport - - source .gitlab-ci.d/cirrus/$NAME.vars - - set +o allexport - - cirrus-vars <.gitlab-ci.d/cirrus/build.yml >.gitlab-ci.d/cirrus/$NAM= E.yml - - cat .gitlab-ci.d/cirrus/$NAME.yml - - cirrus-run -v --show-build-log always .gitlab-ci.d/cirrus/$NAME.yml - variables: - QEMU_JOB_CIRRUS: 1 diff --git a/.gitlab-ci.d/cirrus/README.rst b/.gitlab-ci.d/cirrus/README.rst deleted file mode 100644 index 657b0706d7..0000000000 --- a/.gitlab-ci.d/cirrus/README.rst +++ /dev/null @@ -1,54 +0,0 @@ -Cirrus CI integration -=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D - -GitLab CI shared runners only provide a docker environment running on Linu= x. -While it is possible to provide private runners for non-Linux platforms th= is -is not something most contributors/maintainers will wish to do. - -To work around this limitation, we take advantage of `Cirrus CI`_'s free -offering: more specifically, we use the `cirrus-run`_ script to trigger Ci= rrus -CI jobs from GitLab CI jobs so that Cirrus CI job output is integrated into -the main GitLab CI pipeline dashboard. - -There is, however, some one-time setup required. If you want FreeBSD and m= acOS -builds to happen when you push to your GitLab repository, you need to - -* set up a GitHub repository for the project, eg. ``yourusername/qemu``. - This repository needs to exist for cirrus-run to work, but it doesn't ne= ed to - be kept up to date, so you can create it and then forget about it; - -* enable the `Cirrus CI GitHub app`_ for your GitHub account; - -* sign up for Cirrus CI. It's enough to log into the website using your Gi= tHub - account; - -* grab an API token from the `Cirrus CI settings`_ page; - -* it may be necessary to push an empty ``.cirrus.yml`` file to your github= fork - for Cirrus CI to properly recognize the project. You can check whether - Cirrus CI knows about your project by navigating to: - - ``https://cirrus-ci.com/yourusername/qemu`` - -* in the *CI/CD / Variables* section of the settings page for your GitLab - repository, create two new variables: - - * ``CIRRUS_GITHUB_REPO``, containing the name of the GitHub repository - created earlier, eg. ``yourusername/qemu``; - - * ``CIRRUS_API_TOKEN``, containing the Cirrus CI API token generated ear= lier. - This variable **must** be marked as *Masked*, because anyone with know= ledge - of it can impersonate you as far as Cirrus CI is concerned. - - Neither of these variables should be marked as *Protected*, because in - general you'll want to be able to trigger Cirrus CI builds from non-prot= ected - branches. - -Once this one-time setup is complete, you can just keep pushing to your Gi= tLab -repository as usual and you'll automatically get the additional CI coverag= e. - - -.. _Cirrus CI GitHub app: https://github.com/marketplace/cirrus-ci -.. _Cirrus CI settings: https://cirrus-ci.com/settings/profile/ -.. _Cirrus CI: https://cirrus-ci.com/ -.. _cirrus-run: https://github.com/sio/cirrus-run/ diff --git a/.gitlab-ci.d/cirrus/build.yml b/.gitlab-ci.d/cirrus/build.yml deleted file mode 100644 index 41abd0b31a..0000000000 --- a/.gitlab-ci.d/cirrus/build.yml +++ /dev/null @@ -1,42 +0,0 @@ -@CIRRUS_VM_INSTANCE_TYPE@: - @CIRRUS_VM_IMAGE_SELECTOR@: @CIRRUS_VM_IMAGE_NAME@ - cpu: @CIRRUS_VM_CPUS@ - memory: @CIRRUS_VM_RAM@ - -env: - CIRRUS_CLONE_DEPTH: 1 - CI_REPOSITORY_URL: "@CI_REPOSITORY_URL@" - CI_COMMIT_REF_NAME: "@CI_COMMIT_REF_NAME@" - CI_COMMIT_SHA: "@CI_COMMIT_SHA@" - PATH: "@PATH_EXTRA@:$PATH" - PKG_CONFIG_PATH: "@PKG_CONFIG_PATH@" - PYTHON: "@PYTHON@" - MAKE: "@MAKE@" - CONFIGURE_ARGS: "@CONFIGURE_ARGS@" - TEST_TARGETS: "@TEST_TARGETS@" - -build_task: - # A little shorter than GitLab timeout in ../cirrus.yml - timeout_in: 60m - install_script: - - @UPDATE_COMMAND@ - - @INSTALL_COMMAND@ @PKGS@ - - if test -n "@PYPI_PKGS@" ; then PYLIB=3D$(@PYTHON@ -c 'import syscon= fig; print(sysconfig.get_path("stdlib"))'); rm -f $PYLIB/EXTERNALLY-MANAGED= ; @PIP3@ install @PYPI_PKGS@ ; fi - clone_script: - - git clone --depth 100 "$CI_REPOSITORY_URL" . - - git fetch origin "$CI_COMMIT_REF_NAME" - - git reset --hard "$CI_COMMIT_SHA" - step_script: - - mkdir build - - cd build - - ../configure --enable-werror $CONFIGURE_ARGS - || { cat config.log meson-logs/meson-log.txt; exit 1; } - - $MAKE -j$(sysctl -n hw.ncpu) - - for TARGET in $TEST_TARGETS ; - do - $MAKE -j$(sysctl -n hw.ncpu) $TARGET V=3D1 ; - done - always: - build_result_artifacts: - path: build/meson-logs/*log.txt - type: text/plain diff --git a/.gitlab-ci.d/qemu-project.yml b/.gitlab-ci.d/qemu-project.yml index 9cbb5fe787..104a147b2d 100644 --- a/.gitlab-ci.d/qemu-project.yml +++ b/.gitlab-ci.d/qemu-project.yml @@ -17,6 +17,5 @@ include: - local: '/.gitlab-ci.d/buildtest.yml' - local: '/.gitlab-ci.d/static_checks.yml' - local: '/.gitlab-ci.d/custom-runners.yml' - - local: '/.gitlab-ci.d/cirrus.yml' - local: '/.gitlab-ci.d/windows.yml' - local: '/.gitlab-ci.d/macos.yml' diff --git a/docs/devel/testing/ci-jobs.rst.inc b/docs/devel/testing/ci-job= s.rst.inc index f1c70344ec..d5b081978a 100644 --- a/docs/devel/testing/ci-jobs.rst.inc +++ b/docs/devel/testing/ci-jobs.rst.inc @@ -91,12 +91,6 @@ Maintainer controlled job variables The following variables may be set when defining a job in the CI configuration file. =20 -QEMU_JOB_CIRRUS -~~~~~~~~~~~~~~~ - -The job makes use of Cirrus CI infrastructure, requiring the -configuration setup for cirrus-run to be present in the repository - QEMU_JOB_OPTIONAL ~~~~~~~~~~~~~~~~~ =20 diff --git a/docs/devel/testing/main.rst b/docs/devel/testing/main.rst index 0662766b5c..e929ab3ec9 100644 --- a/docs/devel/testing/main.rst +++ b/docs/devel/testing/main.rst @@ -516,8 +516,8 @@ mappings to distribution package names for a wide varie= ty of third party projects. ``lcitool`` applies the mappings to a list of build pre-requisites in ``tests/lcitool/projects/qemu.yml``, determines the list of native packages to install on each distribution, and uses them -to generate build environments (dockerfiles and Cirrus CI variable files) -that are consistent across OS distribution. +to generate build environments (dockerfiles) that are consistent across OS +distribution. =20 =20 Adding new build pre-requisites diff --git a/tests/lcitool/refresh b/tests/lcitool/refresh index ad6a1e6fe8..0ccce6d5be 100755 --- a/tests/lcitool/refresh +++ b/tests/lcitool/refresh @@ -81,12 +81,6 @@ def generate_dockerfile(host, target, project=3D"qemu", = cross=3DNone, trailer=3DNone, generate(filename, cmd, trailer) =20 =20 -def generate_cirrus(target, trailer=3DNone): - filename =3D Path(src_dir, ".gitlab-ci.d", "cirrus", target + ".vars") - cmd =3D lcitool_cmd + ["variables", "--format", "shell", target, "qemu= "] - generate(filename, cmd, trailer) - - def generate_vars(target, trailer=3DNone): filename =3D Path(src_dir, ".gitlab-ci.d", target + ".vars") cmd =3D lcitool_cmd + ["variables", "--format", "shell", target, "qemu= "] --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383498; cv=none; d=zohomail.com; s=zohoarc; b=DznsNE3jGXlPAfF14czjp0D/dfAmY6O9quSaYA3dfTRyk4YdrA9nDgrO/JforeJ3eAFHMse0XRsiOOqtup5LYYytK/v6ONZv6oi633/Vsnups3LQCVxTpN+FUjsJ/IoSslvO7ZR3WgIuZ2oHeEbp6lLIGlyu9XoGNALTaguQxKA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383498; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8yarpF3uFCTgUZucjlrToJ5iK4crFWl2kfvhEgnIJMY=; b=dQE2dWBWxDsdNSV2zlT8LQATJ1kBDyjqmuv9DMzILqnja82YHu4FAM8H683wYbg3XRPdzi86GQq6ADhTT0f4+7MG1qtJCJ86fstXp1mXKw0X4w/c/jxUIuqeBZZR++VLRxqJPN4FRAiFyQ2XhLx8ljvkmpXkXgAVbPRDbJ1N2dY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383498700648.3983624860889; Sat, 13 Jun 2026 13:44:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVAf-0004uJ-2n; Sat, 13 Jun 2026 16:41:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAd-0004nH-3J; Sat, 13 Jun 2026 16:41:35 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAb-0005JR-CV; Sat, 13 Jun 2026 16:41:34 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 013EA1B6F1A; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 65DB73CE964; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=/yCG3jEExQpedxSgTR2/aw27BcSv2Xz3e8r7g1a46fI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=nmcUeUPhwgZfgLnqqQp58fnvLLf8Pk5Zgn0S0OGRoJRvaI1IgfvK91uyX/fn7R730 rJ0X/bqEtcHHlrwFWssK5VjrG53aSpSsutwpffeCQXM9lQP1oFRou5Rmk165DJiSEl l4CsLi4Rg5G0hkIczar5GPM8+ekMsrl3zEAqwbnB0dWagmr5dPq8tj3ez3TyI1GclK QXUsJtw8HDBmWe6N8ZlA+/IGopc7sFMX6fICmwCFeFs2D2DghghzhpmdWLwa6/aNwa CIIK35ovMy7//4kHBhotp+BUwpBv/99LuZnS998pURP0kK7qb6vO0no3GAqsXpHMso qM/asjKiw4kDg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alexandra Winter , Hendrik Brueckner , Christian Borntraeger , Gautam Gala , Cornelia Huck , Michael Tokarev Subject: [Stable-11.0.2 56/72] target/s390x: Make container ids in SysIB_15x 1-based Date: Sat, 13 Jun 2026 23:35:22 +0300 Message-ID: <20260613203542.1809153-56-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383500499158500 Content-Type: text/plain; charset="utf-8" From: Alexandra Winter The Container Id in a container-type TLE of SysIB_15x is defined as 8-bit unsigned nonzero integer. Make stsi fc 15 emulation architecture compliant, by starting the container ids at 1 for the lowest numbered container. The qemu misbehaviour without this patch becomes obvious due to a recently proposed kernel fix. Older linux kernels pass the container ids from stsi fc15 unchanged to sysfs, i.e. starting at 1 on s390 hardware. This resulted in off-by-one values when compared to the values from HMC. A Linux kernel fix is being proposed to correct the sysfs topology ids by -1, so they start at 0, e.g. when displayed by 'lscpu -ye'. In case a KVM guest with a fixed kernel runs on a host with a qemu without this fix, this can result in container ids erroneously being shown as 255. Example (Fixed guest on unfixed qemu): $ lscpu -ye CPU NODE DRAWER BOOK SOCKET CORE L1d:L1i:L2 ONLINE CONFIGURED POLARIZATION = ADDRESS 0 0 255 255 255 0 0:0:0 yes yes vert-medium 0 1 0 255 255 0 1 1:1:1 yes yes vert-medium 1 After this fix: $ lscpu -ye CPU NODE DRAWER BOOK SOCKET CORE L1d:L1i:L2 ONLINE CONFIGURED POLARIZATION = ADDRESS 0 0 0 0 0 0 0:0:0 yes yes vert-medium 0 1 0 0 0 1 1 1:1:1 yes yes vert-medium 1 Fixes: f4f54b582f ("target/s390x/cpu topology: handle STSI(15) and build th= e SYSIB") Signed-off-by: Alexandra Winter Acked-by: Hendrik Brueckner Acked-by: Christian Borntraeger Reviewed-by: Gautam Gala Message-ID: <20260511134909.43802-1-wintera@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit 1f1ccb6f3c48a2cd80e874d66afeef2dc28a65f3) Signed-off-by: Michael Tokarev diff --git a/target/s390x/kvm/stsi-topology.c b/target/s390x/kvm/stsi-topol= ogy.c index c8d6389cd8..af3fd8ad1b 100644 --- a/target/s390x/kvm/stsi-topology.c +++ b/target/s390x/kvm/stsi-topology.c @@ -90,9 +90,9 @@ static int stsi_topology_fill_sysib(S390TopologyList *top= ology_list, int last_drawer =3D -1; int last_book =3D -1; int last_socket =3D -1; - int drawer_id =3D 0; - int book_id =3D 0; - int socket_id =3D 0; + int drawer_id =3D 1; + int book_id =3D 1; + int socket_id =3D 1; int n =3D sizeof(SysIB_151x); =20 QTAILQ_FOREACH(entry, topology_list, next) { @@ -103,12 +103,12 @@ static int stsi_topology_fill_sysib(S390TopologyList = *topology_list, if (level > 3 && drawer_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); p =3D fill_container(p, 3, drawer_id++); - book_id =3D 0; + book_id =3D 1; } if (level > 2 && book_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); p =3D fill_container(p, 2, book_id++); - socket_id =3D 0; + socket_id =3D 1; } if (socket_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383508; cv=none; d=zohomail.com; s=zohoarc; b=keegyeqyt5XZujAZZWeviM1PbqSkLFw2rkO8kHFwEaZ/VkSXsSKjKEkYYpLaTNWB/pHNDvxZWHUtYcCkjWM40sK/QEbgKL7+CsBYHfxDlzu8+mIybnJTLN3CQTcSGAMXOHs7nc89ZOs6MQMxHlkA9xQL8qDH1Xw3f6+UKzsAMmg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383508; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8RFYwqIo8C3mEDUpEM8NRuAfkAUDfjqnS70zVKw66+Y=; b=HW4JDcsMSBwW/RMRdhU3UI5/ZOL/omAi5SMyfxVI7eIdis7g8FE+FnRszdya5K/tpseFy/IdU82FO164RmEr2EJ+bIg4VKmrOY+juP+N2obBldjnUdxbzrzLCzr3F1sFIaRHf+hLdp3pamrCJYFxPo6fp5MAaQfd8m3zNPlDuCE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383508762811.2006696340446; Sat, 13 Jun 2026 13:45:08 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVAg-0004wP-2d; Sat, 13 Jun 2026 16:41:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAe-0004rI-5C; Sat, 13 Jun 2026 16:41:36 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAc-0005Jg-IA; Sat, 13 Jun 2026 16:41:35 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 1E6711B6F1B; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7883D3CE965; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=7nNrOIUeTfp+RJapRBAV6b2JLZ6fd4BEihLhXZZY+hs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=wV+XK7hDEynQqzaEnNwQMvpwKbB+PK6Cdy38UIETxa7DcID3LxuXlZ0SyMN1SEe52 5VZPF907AmlB+n8GiiY2u7hMITeMrtDy3s1mALyw031d7zA1gjXq8s47rt7CH/Unvv md2Q+pzgldw1G99gywQXWaR5U5qcl4v6z5vt3NRx5wR6XR8mbFDRWBc6cOk5fXOJKt cp9gem7fsCPqL78ECC5SoMBpGBSxOZxXNPi+z4pI8kw3O56rEo0RKnMJzCD4+I45T2 0GW+qJYs7+rjmKXI5wgMwudr3ik3TgTK8VEaRC8laenx3QyACaSLhXhyFqMN+R8yrO DolYM5qhQ1RFw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Farhan Ali , Niklas Schnelle , Matthew Rosato , Omar Elghoul , Cornelia Huck , Michael Tokarev Subject: [Stable-11.0.2 57/72] s390x/pci: Fix interrupt forwarding disable for interpreted devices Date: Sat, 13 Jun 2026 23:35:23 +0300 Message-ID: <20260613203542.1809153-57-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383510521158500 Content-Type: text/plain; charset="utf-8" From: Farhan Ali Remove the FH_MASK_ENABLE check when disabling interrupt forwarding during device reset. This check was broken for the default case in the switch statement above, preventing proper cleanup of interrupt forwarding. The pbdev->aif check in s390_pci_kvm_aif_disable() already guards against double-disabling of interrupt forwarding. Cc: qemu-stable@nongnu.org Reported-by: Niklas Schnelle Signed-off-by: Farhan Ali Reviewed-by: Matthew Rosato Tested-by: Omar Elghoul Message-ID: <20260521182946.1607-1-alifm@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit 442f727b8bebabf20a4f6a7536a4ff2885402030) Signed-off-by: Michael Tokarev diff --git a/hw/s390x/s390-pci-bus.c b/hw/s390x/s390-pci-bus.c index 4de7b587e8..eb2b6185db 100644 --- a/hw/s390x/s390-pci-bus.c +++ b/hw/s390x/s390-pci-bus.c @@ -1504,7 +1504,7 @@ static void s390_pci_device_reset(DeviceState *dev) break; } =20 - if (pbdev->interp && (pbdev->fh & FH_MASK_ENABLE)) { + if (pbdev->interp) { /* Interpreted devices were using interrupt forwarding */ s390_pci_kvm_aif_disable(pbdev); } else if (pbdev->summary_ind) { --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383439; cv=none; d=zohomail.com; s=zohoarc; b=LSeYvIsI78AsIINo+3rTQ9etYEczdj0SOdh7IyRfZsd0QC2qcvNngrHnJgUC/6pLrQO0eAr+C8+rwN7aui+UlM8xzS9nT5iZhQ9c3ekGW7170oXZm74uDu2xNG29qyS+f74QTZFLQgIvYZK+zx4ku7xMNptLXQHa5LwL001VLDw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383439; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=DcNAXHvfGJ6Pyr63IODMb7d7UkCuhncOYyTvWSoluos=; b=nIk1AGFy65zngLz0TV9lCRQqaY52wVSK8LkDAE9BlTX8QGVHCzqlOsV0riJ6FtMTo0M5YWQcGg8SaJoi+G95fee2MEWE3FQ0hqZ99XQSHusdxXYysyesjtfhlIue6aATTEQAwxMd5g+OZ/bBn3Z59inyYTaJ2nIhYWoylPBfl64= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383439860103.88426303959807; Sat, 13 Jun 2026 13:43:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVBA-0005jB-9A; Sat, 13 Jun 2026 16:42:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVB1-0005ei-43; Sat, 13 Jun 2026 16:42:00 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAy-0005K2-IO; Sat, 13 Jun 2026 16:41:58 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 2F5861B6F1C; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9637B3CE966; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=tJ4gE78HIFs63Hs5+QVQwFGrGNIdLjjoMVKTIA667Hs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=MYWLkvnV8FMfElM+o9CB/d9m3UHzybv2vGd91cKx9LRJStwmn767Sbb7manMGLq+E 9qKf7Oj0O+6m4HPa1f/5f7YTQjBqFg/dXVdCeurdIseQKw8/2cgabk5H+7nBkr+8Fv pa3YAQzqRUOIMjJfsB6nPO7QCr3VabBwjBaBqmjyt8ZBHcvG/CyVHw/6JBXgtq6Sf4 aec2ZSGh6rFG/c+Q6LqNcsUFHPTjSPiV//7Eu8KUBXppNXQBMfKs3kxQqgGrVtlcwn +6VNUHqf4LfGIHoUMNC/S9YaFLzb2GZiNsw3UOuJDCy+kJ8zkfkuPmqrXDDvmcjtHK A3/bzczOajY3w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Jithu Joseph , Jamin Lin , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Michael Tokarev Subject: [Stable-11.0.2 58/72] hw/i3c: fix CMD/data FIFO depth reset values to match real silicon Date: Sat, 13 Jun 2026 23:35:24 +0300 Message-ID: <20260613203542.1809153-58-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383440487158500 From: Jithu Joseph The Linux DW-I3C master driver infers controller queue depths at probe by reading two status registers that report free queue slots, which at probe (queues empty) equals the full depth. It then uses those values to gate every I3C transfer -- any batch whose word count exceeds the advertised depth is rejected with -EOPNOTSUPP. QUEUE_STATUS_LEVEL (0x4c) [7:0] -> cmdfifodepth (cmd slots) DATA_BUFFER_STATUS_LEVEL (0x50) [7:0] -> datafifodepth (32-bit words) Per the AST2600 datasheet the reset values are 0x10 and 0x40 (16 cmd slots, 64 words =3D 256 B). QEMU was advertising 0x02 and 0x10, making the kernel believe the controller can only do 64-byte transfers. The visible symptom was -EOPNOTSUPP on any I3C transfer whose payload exceeded 64 B (datafifodepth =3D 0x10 =3D 16 words =3D 64 B). The underlying FIFOs in QEMU were already allocated at the right size (fifo32_create takes word counts; the existing defaults give 16 cmd slots and 64 data words). Only the advertised reset values were wrong. Correct the reset values in dw_i3c_resets[], and additionally drive the advertised depths from the queue-capacity configs in the reset handlers (as is already done for the device/char table pointers), so a configured override is reflected in what the guest reads instead of being silently ignored. The advertised fields are 8-bit, so the depth saturates at 255 regardless of the wider capacity configs. With this fix the guest sees datafifodepth=3D64 words and accepts transfers up to 256 B. Fixes: e974c6957576 ("hw/i3c/dw-i3c: Add more reset values") Cc: qemu-stable@nongnu.org Signed-off-by: Jithu Joseph Reviewed-by: Jamin Lin Link: https://lore.kernel.org/qemu-devel/20260604142207.2118098-2-jithu.jos= eph@oss.qualcomm.com Signed-off-by: C=C3=A9dric Le Goater (cherry picked from commit 2d3dc20d9d716729e06093311f678dc739affe5b) Signed-off-by: Michael Tokarev diff --git a/hw/i3c/dw-i3c.c b/hw/i3c/dw-i3c.c index d87d42be89..402c8f1922 100644 --- a/hw/i3c/dw-i3c.c +++ b/hw/i3c/dw-i3c.c @@ -282,8 +282,8 @@ static const uint32_t dw_i3c_resets[DW_I3C_NR_REGS] =3D= { [R_QUEUE_THLD_CTRL] =3D 0x01000101, [R_DATA_BUFFER_THLD_CTRL] =3D 0x01010100, [R_SLV_EVENT_CTRL] =3D 0x0000000b, - [R_QUEUE_STATUS_LEVEL] =3D 0x00000002, - [R_DATA_BUFFER_STATUS_LEVEL] =3D 0x00000010, + [R_QUEUE_STATUS_LEVEL] =3D 0x00000010, + [R_DATA_BUFFER_STATUS_LEVEL] =3D 0x00000040, [R_PRESENT_STATE] =3D 0x00000003, [R_I3C_VER_ID] =3D 0x3130302a, [R_I3C_VER_TYPE] =3D 0x6c633033, @@ -947,6 +947,10 @@ static void dw_i3c_reset(DeviceState *dev) s->cfg.dev_char_table_pointer); ARRAY_FIELD_DP32(s->regs, DEV_CHAR_TABLE_POINTER, DEV_CHAR_TABLE_DEPTH, s->cfg.dev_char_table_depth); + ARRAY_FIELD_DP32(s->regs, QUEUE_STATUS_LEVEL, CMD_QUEUE_EMPTY_LOC, + s->cfg.cmd_resp_queue_capacity_bytes); + ARRAY_FIELD_DP32(s->regs, DATA_BUFFER_STATUS_LEVEL, TX_BUF_EMPTY_LOC, + s->cfg.tx_rx_queue_capacity_bytes); =20 dw_i3c_cmd_queue_reset(s); dw_i3c_resp_queue_reset(s); @@ -1795,6 +1799,10 @@ static void dw_i3c_reset_enter(Object *obj, ResetTyp= e type) s->cfg.dev_char_table_pointer); ARRAY_FIELD_DP32(s->regs, DEV_CHAR_TABLE_POINTER, DEV_CHAR_TABLE_DEPTH, s->cfg.dev_char_table_depth); + ARRAY_FIELD_DP32(s->regs, QUEUE_STATUS_LEVEL, CMD_QUEUE_EMPTY_LOC, + s->cfg.cmd_resp_queue_capacity_bytes); + ARRAY_FIELD_DP32(s->regs, DATA_BUFFER_STATUS_LEVEL, TX_BUF_EMPTY_LOC, + s->cfg.tx_rx_queue_capacity_bytes); } =20 static void dw_i3c_realize(DeviceState *dev, Error **errp) --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383367; cv=none; d=zohomail.com; s=zohoarc; b=EbMiNkjaugEnFdRde1npNlsu5r6nqSgYneDOpdlLtqyzYi9f8lGaRT8YjwUxHYtij6FxYYBTfXEhHu2kXekSCD9bWazVGDDmHSoh0AicU6P8MmoVim0qzPYsEyoa3yuHO2k7DnkuXIUQwgKC7n+u7g3Agl+LPwD+Thmi7xvnA/4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383367; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Yu2JZD7aFZEDXW7vvAhrcDe/6zfsHhhsGcD/e20vqpM=; b=ZnHWT1JBsZO/owC0OdZvv1uIMxHKhH9nJqHgdz07UDWZD9xmfkzOvHQE+RAuS1bGqn1F6qcsLSthpiMVQQO/rBqUmWE8NEY3FmU6lUsaVMyN7u8F+pyuQUhMkBfVly/7ux9p1i8N40BIAMfLaoWejfVM2AMN9n3smQFoezYlJJc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383367419365.7083422096989; Sat, 13 Jun 2026 13:42:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVBF-0005pU-Ed; Sat, 13 Jun 2026 16:42:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVB3-0005hN-0Q; Sat, 13 Jun 2026 16:42:02 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVAz-0005KL-NB; Sat, 13 Jun 2026 16:42:00 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 413EA1B6F1D; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id A6E893CE967; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=BQUHibctTg0uqXwENGdkj0Gc78GOHcR3uWy9Znp2coE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=kKyOgocZX9gZQ6OfbJQl6bYqW0HdHPTb+oO1f/YYYGIhrU0TtzYtlrox+Yxmchjg8 lJSUhaptzINFvhv1mfCifQVZGFlPxZhJZ4j3ibcsUVXVf4nQoAteA+TXaud3sWmnGf ATjLA4e2OM1KYVcboGsDCcqa9dbdHPtWxcI+YPuvlBf2uCloN4o3upLnmxrDzGgCdk 8HUt/MIEpOUNI2hHVu2DmuMHUgF3J4iNCATZiZ4p3c9vGJf3z8eK7ck0XwX63e780p Jkt3Vm8+7NPCFrTPFpo28EPHqFLejF4AcfDV/QWvwYtSkLmE09gAf7uPOM5Y+1oU8u bzF/+ab1voS7w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fiona Ebner , Stefan Hajnoczi , Michael Tokarev Subject: [Stable-11.0.2 59/72] block/io: fallback to bounce buffer if BLKZEROOUT is not supported because of alignment Date: Sat, 13 Jun 2026 23:35:25 +0300 Message-ID: <20260613203542.1809153-59-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383368392158500 Content-Type: text/plain; charset="utf-8" From: Fiona Ebner Commit 5634622bcb ("file-posix: allow BLKZEROOUT with -t writeback") enables the BLKZEROOUT ioctl when using 'writeback' cache, regressing certain 'qemu-img convert' invocations, because of a pre-existing issue. Namely, the BLKZEROOUT ioctl might fail with errno EINVAL when the request is shorter than the block size of the block device. Fallback to the bounce buffer, similar to when the ioctl is not supported at all, rather than treating such an error as fatal. Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3257 Resolves: https://bugzilla.proxmox.com/show_bug.cgi?id=3D7197 Cc: qemu-stable@nongnu.org Signed-off-by: Fiona Ebner Message-ID: <20260105143416.737482-1-f.ebner@proxmox.com> [Added TODO comment describing a larger fix that could be implemented in the future. --Stefan] Signed-off-by: Stefan Hajnoczi (cherry picked from commit b4e28c304bc58325f8f712cb25e5d700826caa25) Signed-off-by: Michael Tokarev diff --git a/block/io.c b/block/io.c index e8fb4ede4d..6c0bbdcf1e 100644 --- a/block/io.c +++ b/block/io.c @@ -1918,7 +1918,18 @@ bdrv_co_do_pwrite_zeroes(BlockDriverState *bs, int64= _t offset, int64_t bytes, assert(!bs->supported_zero_flags); } =20 - if (ret =3D=3D -ENOTSUP && !(flags & BDRV_REQ_NO_FALLBACK)) { + /* + * TODO The ret =3D=3D -EINVAL && num < alignment case is a workar= ound for + * when request_alignment is 1 on files with cache=3Dwriteback. Th= e Linux + * ioctl(BLKZEROOUT) requires block alignment and will fail with + * EINVAL. The block layer should align the request to + * write_zeroes_alignment instead of trying the syscall, failing, = and + * falling back to a bounce buffer. Doing that is not easy so for = now + * we use a bounce buffer: + * https://lore.kernel.org/qemu-devel/20260109120837.2772961-1-f.e= bner@proxmox.com/ + */ + if ((ret =3D=3D -ENOTSUP || (ret =3D=3D -EINVAL && num < alignment= )) && + !(flags & BDRV_REQ_NO_FALLBACK)) { /* Fall back to bounce buffer if write zeroes is unsupported */ BdrvRequestFlags write_flags =3D flags & ~BDRV_REQ_ZERO_WRITE; =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383489; cv=none; d=zohomail.com; s=zohoarc; b=DpZH8JDh57oT16qgLtvpxi7qfgQIfEeueUJboB693v7s1Fgf51a1yMbEOzaDyKolsBWK7A+IzU6LXgukTwrpiGehR8Qqc2K1ozmLfV5ogNK6rzUBgSr7PERoA1/xC+Zs3sIuXL86KY+z4688yp4wZf+hLMullVUg4suSRfL0hFA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383489; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=DRN0LPP1ZJqzaRaUQpxjAd/crDAQ3VrdxZ50fQm53Wc=; b=fljfQrmOQwh0SMmceObtiLTLlC55dsWT6rti27ljqtIDW6T2EE1LawGMCYGJaZHszY1OPjxE1rrdYgkUtb2Gpi/ELuBypRMpDd/PN8bOZ26Pz745yxYDufuwwO82Xxd/Wls6ZwMV5gK3Xw4Algnmj4UhXpKqVC4A/EhgBDKP6eo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383489657368.489209188583; Sat, 13 Jun 2026 13:44:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVBL-0006AG-6T; Sat, 13 Jun 2026 16:42:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVB8-0005kh-KS; Sat, 13 Jun 2026 16:42:08 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVB3-0005RM-2V; Sat, 13 Jun 2026 16:42:03 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 528501B6F1E; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B87103CE968; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=8HHM1w7x1VDQswcT8xzFVme9fABgIN0/85/hbVFQpwc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=n0ldSWnTxDB8csS5p2Rrjsgedb4UjlFJ5798D6FgN2I2wFFpQiQYhEdt584/c5f0j gcu95sIpKTugqenLDvImWG/Gqr1qLc5qlPQTkFUOSqrCB8d8aoGHYYhQ04xg+HA+jk S3icv6zyCPb4fyy+nyTluAccYCj2dt5+zaqGZwQjiKUY7OS790pwQMs419GSZDWPtk wOQ7+FzV3SrKBFonTLAoOwWahOjW6vxJP3vdD8IoEaeFsABujreWv1A1xcARdIbzcg T0YIbIzUL/uORuTPZjjQ+wejKMyF2tx0JL5JDZAAHkrmPJz5DSD67l7nwZOtW+ecFo U+VzJQ2dh7HFw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Stefan Hajnoczi , Feifan Qian , Paolo Bonzini , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 60/72] virtio-blk: add missing VIRTIO_BLK_T_SCSI_CMD size check (CVE-2026-48914) Date: Sat, 13 Jun 2026 23:35:26 +0300 Message-ID: <20260613203542.1809153-60-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383490459158500 Content-Type: text/plain; charset="utf-8" From: Stefan Hajnoczi Check that the iovec containing struct virtio_scsi_inhdr is large enough before storing an error value there. Feifan Qian pointed out that this can be used to corrupt heap memory when the descriptor uses an MMIO address and a length of 1, forcing QEMU to allocate a 1-byte heap bounce buffer. virtio_stl_p() stores 4 bytes and therefore corrupts whatever is beyond the bounce buffer. Fixes: CVE-2026-48914 Fixes: f34e73cd69bd ("virtio-blk: report non-zero status when failing SG_IO= requests") Reported-by: Feifan Qian Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi Message-ID: <20260526154957.1741622-1-stefanha@redhat.com> Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit aeea0c2804c42f24915467a1e4c70e649e39b8e0) Signed-off-by: Michael Tokarev diff --git a/hw/block/virtio-blk.c b/hw/block/virtio-blk.c index 9cb9f1fb2b..6b92066aff 100644 --- a/hw/block/virtio-blk.c +++ b/hw/block/virtio-blk.c @@ -199,10 +199,16 @@ static void virtio_blk_handle_scsi(VirtIOBlockReq *re= q) =20 /* * The scsi inhdr is placed in the second-to-last input segment, just - * before the regular inhdr. + * before the regular inhdr. VIRTIO implementations normally do not re= ly on + * the precise message framing, but legacy implementations did and so = we do + * too for the legacy virtio-blk SCSI request type. * * Just put anything nonzero so that the ioctl fails in the guest. */ + if (elem->in_sg[elem->in_num - 2].iov_len !=3D sizeof(*scsi)) { + status =3D VIRTIO_BLK_S_IOERR; + goto fail; + } scsi =3D (void *)elem->in_sg[elem->in_num - 2].iov_base; virtio_stl_p(vdev, &scsi->errors, 255); status =3D VIRTIO_BLK_S_UNSUPP; --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383501; cv=none; d=zohomail.com; s=zohoarc; b=dmcDZm/q4I/pAWcEAzNo7BVtj3S/pMp4pH+YdveqnfsYrHempsr8nOu5yg4KNV4hPpnaKRsaMIo4us0p1sREbCq2yNMrLGRqWjLYRiblkNmawU5lVrnntj79vYN9Bj1WIEwkAM5SBF61Seawj5lkFfOtlZ6PdTApREsVxOdta2A= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383501; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=kPRoR6Y4vKY65iZQNM4x0/upq0V5iiOWNlAtuLI6rO8=; b=X4JAQrQadPjg/jJdHTbnD44Q/7mqQYUmTF69DM2zq0De/qMgO59z4uIuDHtc9++K4XRUcnPs9b74bWqqBBwL2oSNj1VDXTFSoV3eWByQpBqTADwkkcNZB6wQTFuAYY4//xvUPYFDDCDZrSLNfLNEuenux/TwZvmWJ6f592I9DSI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383501727286.46780554750353; Sat, 13 Jun 2026 13:45:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVBI-00060o-CP; Sat, 13 Jun 2026 16:42:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVB8-0005ms-ST; Sat, 13 Jun 2026 16:42:08 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVB4-0005Rl-V9; Sat, 13 Jun 2026 16:42:05 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 617DE1B6F20; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id CAB413CE969; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=yBluAs/gE8DSO3TfUiji3YFG4b/s0M7RfG8jpYCyV4I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=h7mOqQqLyQaIL3AGWruYQy0LREPhGj1IsgWD7IXvSsEgd6UjE9gHkWoGg80Z4BTng 2KrG3/POR51SYD/9U8FueCMvWi2eRpLODRKfHnkgd2tOYU65dO2P4QqOTunWjIT7ua M8ZJyMZ4MGPkIRb8XJYdafDt8YD2uJ29NGI8rS9z/h2MGK/3vcnluJ9X+WQaC+i9Hq HPAITxymCN2TRqtMbHojaaAMJ2mvy6IDvsVkNASM7HnA9hzk4zEO2OLqXzzCOGzdQZ vHCbTnNSnEX0Q4TpXtCgedXtfvDb9h/wlKMfOwmN2c6d6+Mck9xgPNuaLCL0vJpWb/ KYQSsxA9JWYVw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-11.0.2 61/72] qemu-io: Add 'aio_discard' command Date: Sat, 13 Jun 2026 23:35:27 +0300 Message-ID: <20260613203542.1809153-61-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383502536158500 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf Testing interactions between multiple requests that include discard requests require that qemu-io can do the discard asynchronously, like it already does for reads and writes. To this effect, add an 'aio_discard' command. Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-3-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit 7f8466e2ce620e3c6a6e2f32d616367174d4dbe9) Signed-off-by: Michael Tokarev diff --git a/qemu-io-cmds.c b/qemu-io-cmds.c index f6d077908f..de4c1966fe 100644 --- a/qemu-io-cmds.c +++ b/qemu-io-cmds.c @@ -2218,6 +2218,120 @@ static int discard_f(BlockBackend *blk, int argc, c= har **argv) return 0; } =20 +static void aio_discard_help(void) +{ + printf( +"\n" +" asynchronously discards a range of bytes from the given offset\n" +"\n" +" Example:\n" +" 'aio_discard 512 1k' - discards 1 kilobyte from 512 bytes into the file\= n" +"\n" +" Discards a segment of the currently open file.\n" +" -C, -- report statistics in a machine parsable format\n" +" -q, -- quiet mode, do not show I/O statistics\n" +" The discard is performed asynchronously and the aio_flush command must b= e\n" +" used to ensure all outstanding aio requests have been completed.\n" +" Note that due to its asynchronous nature, this command will be\n" +" considered successful once the request is submitted, independently\n" +" of potential I/O errors.\n" +"\n"); +} + +static int aio_discard_f(BlockBackend *blk, int argc, char **argv); + +static const cmdinfo_t aio_discard_cmd =3D { + .name =3D "aio_discard", + .cfunc =3D aio_discard_f, + .perm =3D BLK_PERM_WRITE, + .argmin =3D 2, + .argmax =3D -1, + .args =3D "[-Cq] off len", + .oneline =3D "asynchronously discards a number of bytes", + .help =3D aio_discard_help, +}; + +static void aio_discard_done(void *opaque, int ret) +{ + struct aio_ctx *ctx =3D opaque; + struct timespec t2; + + clock_gettime(CLOCK_MONOTONIC, &t2); + + if (ret < 0) { + printf("aio_discard failed: %s\n", strerror(-ret)); + block_acct_failed(blk_get_stats(ctx->blk), &ctx->acct); + goto out; + } + + block_acct_done(blk_get_stats(ctx->blk), &ctx->acct); + + if (ctx->qflag) { + goto out; + } + + /* Finally, report back -- -C gives a parsable format */ + t2 =3D tsub(t2, ctx->t1); + print_report("discarded ", &t2, ctx->offset, ctx->qiov.size, + ctx->qiov.size, 1, ctx->Cflag); +out: + g_free(ctx); +} + +static int aio_discard_f(BlockBackend *blk, int argc, char **argv) +{ + int c, ret; + int64_t count; + struct aio_ctx *ctx =3D g_new0(struct aio_ctx, 1); + + ctx->blk =3D blk; + + while ((c =3D getopt(argc, argv, "Cq")) !=3D -1) { + switch (c) { + case 'C': + ctx->Cflag =3D true; + break; + case 'q': + ctx->qflag =3D true; + break; + default: + g_free(ctx); + qemuio_command_usage(&aio_discard_cmd); + return -EINVAL; + } + } + + if (optind !=3D argc - 2) { + g_free(ctx); + qemuio_command_usage(&aio_discard_cmd); + return -EINVAL; + } + + ctx->offset =3D cvtnum(argv[optind]); + if (ctx->offset < 0) { + ret =3D ctx->offset; + print_cvtnum_err(ret, argv[optind]); + g_free(ctx); + return ret; + } + optind++; + + count =3D cvtnum(argv[optind]); + if (count < 0) { + print_cvtnum_err(count, argv[optind]); + g_free(ctx); + return count; + } + + clock_gettime(CLOCK_MONOTONIC, &ctx->t1); + ctx->qiov.size =3D count; + block_acct_start(blk_get_stats(blk), &ctx->acct, ctx->qiov.size, + BLOCK_ACCT_UNMAP); + blk_aio_pdiscard(blk, ctx->offset, count, aio_discard_done, ctx); + + return 0; +} + static int alloc_f(BlockBackend *blk, int argc, char **argv) { BlockDriverState *bs =3D blk_bs(blk); @@ -2800,6 +2914,7 @@ static void __attribute((constructor)) init_qemuio_co= mmands(void) qemuio_add_command(&length_cmd); qemuio_add_command(&info_cmd); qemuio_add_command(&discard_cmd); + qemuio_add_command(&aio_discard_cmd); qemuio_add_command(&alloc_cmd); qemuio_add_command(&map_cmd); qemuio_add_command(&reopen_cmd); --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383412; cv=none; d=zohomail.com; s=zohoarc; b=O42EcWWCwOsw736EbtIfPPCWFe2b29h5Q+wdwml8YtD+Sk6CSa85kDjiwHCfHXQQfcxZsj3IPb6o95lgOV3XQpJ90eTPNMwBXRNXlxXQ7eCj2FX/qLyyBikY0q7/nyP7yhC4YQRGNx3dsPTgZ+xoQhOWT0thDxIPiBtU3TJldSw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383412; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=XG/QBUMXO+x5S9OgxaerXGYMSJsNzM/EDXUGasQPzHg=; b=Dqb9S17XCw51o1e6aVC30gxivg1Sp8sBQE0SRy3a6VREFPzFpsC+Ud8v+llEwTlHZgV3O0eBnHDLceVHhUdh4k2UIcKwnMtJ/Rsb/DQS7XuO18Xn0ch4GT1DogVJsed/Ahh2iClY+JJ+2+AzI4lZTLdnS2Ia977hWDLfiZxWjeQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138341210429.510446739772192; Sat, 13 Jun 2026 13:43:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVBO-0006Ea-DV; Sat, 13 Jun 2026 16:42:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBC-0005pN-H0; Sat, 13 Jun 2026 16:42:12 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBA-0005Sw-3Y; Sat, 13 Jun 2026 16:42:09 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 713241B6F21; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D9D553CE96A; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=8146qO6KFVKscfnp7ME4DCWZ2VVfJ/m5ZGh/Be/5xEg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TuP4nU6uDBgIvvpUNoU2OsRVNymTIXBXBRyZmZ5ib3ifjxGECu8zR9yI4LP6lytjX FGE7uAvGQ9TAjd088qIjhw7ESJ2Dd6cd/LA8BVEdh2vnNPHgzDFkIDTSnIX/TmF1K8 GNSWjz/ZvbphRXB6jOmGoRC3+qOAUwuKyjjs9UguZ6OTfa9ar5WVFdRs6G4Sl3L6DA dWGxcyQ1fUxpq2DAz4xkqBk5AU//tt9z5iEe3Oz3iL876tAgfYcgyVPWWjIrvHObQi lk0wiavI8EljrVUMKS0xwpthcOwyNMu3rY02xr9kgnEIV+zaocrDXh91vikaw+WWLH clRGFExTNNLtg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-11.0.2 62/72] qcow2: Fix corruption on discard during write with COW Date: Sat, 13 Jun 2026 23:35:28 +0300 Message-ID: <20260613203542.1809153-62-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383414240158500 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf Most code in qcow2 that accesses (and potentially modifies) L2 tables does so while holding s->lock. There is one exception, which is allocating writes. They hold the lock initially while allocating clusters, but drop it for writing the guest payload before taking the lock again for updating the L2 tables. This allows concurrent requests that touch other parts of the image file to continue in parallel and is an important performance optimisation. However, this means that other requests that run while the lock is dropped for writing guest data must synchronise with the list of allocating requests in s->cluster_allocs and wait if they would overlap. For writes, this is done in handle_dependencies(), but discard and write zeros operations neglect to synchronise with s->cluster_allocs. This means that discard can free a cluster whose L2 entry will already be modified in qcow2_alloc_cluster_link_l2() by a previously started write. In the case of a pre-allocated zero cluster that is in the process of being overwritten, this means that discard can lead to a situation where the cluster is still mapped (because the write will restore the L2 entry just without the zero flag), but its refcount has been decreased, resulting in a corrupted image. Add the missing synchronisation to qcow2_cluster_discard() and qcow2_subcluster_zeroize() to fix the problem. Cc: qemu-stable@nongnu.org Reported-by: Denis V. Lunev Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-4-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit b8bfb1478d61512f851badd0d912c6661a2efee7) Signed-off-by: Michael Tokarev diff --git a/block/qcow2-cluster.c b/block/qcow2-cluster.c index c655bf6df4..8b1e80bd0b 100644 --- a/block/qcow2-cluster.c +++ b/block/qcow2-cluster.c @@ -1392,6 +1392,9 @@ count_single_write_clusters(BlockDriverState *bs, int= nb_clusters, * the same cluster. In this case we need to wait until the previous * request has completed and updated the L2 table accordingly. * + * If allow_shortening =3D=3D true, instead of waiting for a dependency, *= cur_bytes + * can be shortened so that the cluster allocations don't overlap. + * * Returns: * 0 if there was no dependency. *cur_bytes indicates the number of * bytes from guest_offset that can be read before the next @@ -1403,7 +1406,9 @@ count_single_write_clusters(BlockDriverState *bs, int= nb_clusters, */ static int coroutine_fn handle_dependencies(BlockDriverState *bs, uint64_t guest_offset, - uint64_t *cur_bytes, QCowL2Met= a **m) + uint64_t *cur_bytes, + bool allow_shortening, + QCowL2Meta **m) { BDRVQcow2State *s =3D bs->opaque; QCowL2Meta *old_alloc; @@ -1434,7 +1439,7 @@ static int coroutine_fn handle_dependencies(BlockDriv= erState *bs, =20 /* Conflict */ =20 - if (start < old_start) { + if (start < old_start && allow_shortening) { /* Stop at the start of a running allocation */ bytes =3D old_start - start; } else { @@ -1469,6 +1474,29 @@ static int coroutine_fn handle_dependencies(BlockDri= verState *bs, return 0; } =20 +static void coroutine_mixed_fn wait_for_dependencies(BlockDriverState *bs, + uint64_t guest_offset, + uint64_t bytes) +{ + BDRVQcow2State *s =3D bs->opaque; + QCowL2Meta *m =3D NULL; + int ret; + + /* + * Discard has some non-coroutine callers (creating internal snapshots= and + * make empty). They are calling from qemu-img or in a drained section= , so + * we know that no writes can be in progress. + */ + if (!qemu_in_coroutine()) { + assert(QLIST_EMPTY(&s->cluster_allocs)); + return; + } + + do { + ret =3D handle_dependencies(bs, guest_offset, &bytes, false, &m); + } while (ret =3D=3D -EAGAIN); +} + /* * Checks how many already allocated clusters that don't require a new * allocation there are at the given guest_offset (up to *bytes). @@ -1840,7 +1868,7 @@ again: * the right synchronisation between the in-flight request= and * the new one. */ - ret =3D handle_dependencies(bs, start, &cur_bytes, m); + ret =3D handle_dependencies(bs, start, &cur_bytes, true, m); if (ret =3D=3D -EAGAIN) { /* Currently handle_dependencies() doesn't yield if we already= had * an allocation. If it did, we would have to clean up the L2M= eta @@ -2000,6 +2028,15 @@ int qcow2_cluster_discard(BlockDriverState *bs, uint= 64_t offset, int64_t cleared; int ret; =20 + /* + * If we're touching a cluster for which allocating writes are in flig= ht, + * wait for them to complete to avoid conflicting metadata updates. + * + * We don't need to allocate a QCowL2Meta for the discard operation be= cause + * s->lock is held for the duration of the whole operation. + */ + wait_for_dependencies(bs, offset, bytes); + /* Caller must pass aligned values, except at image end */ assert(QEMU_IS_ALIGNED(offset, s->cluster_size)); assert(QEMU_IS_ALIGNED(end_offset, s->cluster_size) || @@ -2160,6 +2197,15 @@ int coroutine_fn qcow2_subcluster_zeroize(BlockDrive= rState *bs, uint64_t offset, int64_t cleared; int ret; =20 + /* + * If we're touching a cluster for which allocating writes are in flig= ht, + * wait for them to complete to avoid conflicting metadata updates. + * + * We don't need to allocate a QCowL2Meta for the zeroize operation be= cause + * s->lock is held for the duration of the whole operation. + */ + wait_for_dependencies(bs, offset, bytes); + /* If we have to stay in sync with an external data file, zero out * s->data_file first. */ if (data_file_is_raw(bs)) { --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383531; cv=none; d=zohomail.com; s=zohoarc; b=l/7Bs0xiSA7ilb48Oe4kz2ZbEI28Ez036IPA0tx26kv1/hinbl29j4l4bHeeO42dCJLFd+Zqjv5NUP1kzQAYKqMS23kaSD6MrGYsdvgS7vm4hLOG6e976gvi390rS1cbuKsbe0ZMjL53nWSqlU5PAj3V1kJ8psa4f2nzMiCjR5M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383531; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=t3bebmnC8aHOfy8MMBLbDFnLegLK3bhqmi9Ry6uHOB4=; b=N73VAYSamu/J18c0T6p7yJUv97+6D6zBY/d13DP0IBxYNyQmNg3XoqNdkY38xVvjZ8x/jzf2fpMid9iAn7tRIm84AfEtuAIN9VS237aJjukpB6a9kqGDsgiffmLB8FOEIfygAbfZMjDmukAHHmvGhPCfI6a2WJP0hzic4Ik8zsQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383531389803.1147178645464; Sat, 13 Jun 2026 13:45:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVBj-0006ZV-53; Sat, 13 Jun 2026 16:42:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBW-0006S3-38; Sat, 13 Jun 2026 16:42:30 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBU-0005T3-Bv; Sat, 13 Jun 2026 16:42:29 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 8067B1B6F22; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E95283CE96B; Sat, 13 Jun 2026 23:36:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=NeizuiU9CNw1ZzTV6M1T2A/yYQYGEMCvWTUWZVtOwzs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=h9PWq3kFe0AjiKNgF5Xa1gh5Cm/cw45RD/kS8MT+2EbVGAuEs2cyaructeJIPpxiX fdIdOEQs2y5pziJ5hySO+w5pGrCDWHKo7Xia1ZbawdOxfZ5KZDeiYGa/VQqnIfhN9S WFYgAFa2Lw13yC0hxuCjSvJJzuyNejMxwhK3IhXz8gTEo0AYHytWImpDw7tZ7dY/Sn 0L1YYJwRDqodFLLV6kD42lDcG7yKtLMb6E5BljEPdiuVR1ZiGcCLR4GQzJ699cFQnC qs1ZDoZHQFsTvtaW/+m8dJg5fSOLq1waglGOyay3SFRR0YchcNqk0F3IGyMvzJoKBu N75+wvQk2sNDw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-11.0.2 63/72] iotests/046: Test that discard/write_zeroes wait for dependencies Date: Sat, 13 Jun 2026 23:35:29 +0300 Message-ID: <20260613203542.1809153-63-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383532657158500 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf This is a regression test for the bug fixed in the previous commit where discard and write_zeroes operations wouldn't consider their dependencies in s->cluster_allocs. Without the fix, this results in a corrupted image. Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-5-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit 389f5bcc744d3ddc127d550a57261aed9bbba1f3) Signed-off-by: Michael Tokarev diff --git a/tests/qemu-iotests/046 b/tests/qemu-iotests/046 index 4c9ed4d26e..e03dd40147 100755 --- a/tests/qemu-iotests/046 +++ b/tests/qemu-iotests/046 @@ -184,6 +184,48 @@ aio_write -P 160 0x104000 0x18000 resume A aio_flush EOF + +# Create a pre-allocated zero cluster, then start a write on it and discar= d it +# before the L2 update is made +cat < Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383520829915.857356894961; Sat, 13 Jun 2026 13:45:20 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVBl-0006pr-HY; Sat, 13 Jun 2026 16:42:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBa-0006Ty-UZ; Sat, 13 Jun 2026 16:42:36 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBY-0005Tn-Ix; Sat, 13 Jun 2026 16:42:34 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9088E1B6F23; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 046CB3CE96C; Sat, 13 Jun 2026 23:36:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=effkG/M7ewMd9+pWv2wvWsr68cl3JK9vqRmhBkgxO6k=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Qu3lnlfoyGwPefPQhFWY8CGSGhYgSiCc5cfhK8ml1GWXbeX5X4ccEK4jIWEW7vECT wKAkegFN6tC1BZ/IiTyoplzw4iQFipMejX+2ES94QXqZ2YokqlumbiAWehfnlMyFVe EsJcCIYtamvBcPn0ExyNaSB9VWvooFC6m3IegOY9CmIVEIhorVXK/dnzO4kNOqZr79 td29TC2iuB9i65fqm0Nz7PGIk9/DcyTEvEq9QUqdzjA/MsyfEfTfVuhmrjIDm78IDu Xqx3oGgFIuKDLgYpZR9+f3C6MATPmcW2fq7UcXHhhfRFXWph4KQ+SVzmJrRnO1qkhF 32u32FQLhGbjA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Thomas Lamprecht , Fiona Ebner , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 64/72] qcow2: Fix data loss on zero write with detect-zeroes=unmap Date: Sat, 13 Jun 2026 23:35:30 +0300 Message-ID: <20260613203542.1809153-64-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383522680158500 Content-Type: text/plain; charset="utf-8" From: Thomas Lamprecht Commit b8bfb1478d ("qcow2: Fix corruption on discard during write with COW") added a wait_for_dependencies() at the start of qcow2_subcluster_zeroize(). That fixes the inconsistency it set out to fix, but turns the lock-protected pre-check in the caller, qcow2_co_pwrite_zeroes(), into a stale one: the wait yields s->lock, so an in-flight allocating write whose QCowL2Meta is already on s->cluster_allocs (but whose L2 entry is not yet linked) gets to link its entry during the yield. When the zeroize wakes, the cluster is now NORMAL, and with BDRV_REQ_MAY_UNMAP the free path in zero_in_l2_slice() unmaps the just-written cluster, silently dropping the data write's payload. This is reachable with detect-zeroes=3Dunmap (the default for VirtIO disks with discard on in Proxmox VE), under which the block layer auto-promotes all-zero buffers to BDRV_REQ_ZERO_WRITE | BDRV_REQ_MAY_UNMAP. A memory-constrained Debian guest running 'apt full-upgrade' on such a disk reproduces it as random SIGSEGVs: swapped-out code pages come back as zero. Wait for in-flight dependencies before the lock-protected check in qcow2_co_pwrite_zeroes(). If a write linked its L2 entry during the wait, the type check now fails and the block layer falls back to a bounce-buffered zero write that only touches the requested subrange, preserving the racing write's data. Promote wait_for_dependencies() to qcow2_wait_for_dependencies() so qcow2.c can call it. Fixes: b8bfb1478d ("qcow2: Fix corruption on discard during write with COW") Fixes: 7534bb105b ("qcow2: Fix corruption on discard during write with COW"= ) in 11.0.x series Cc: qemu-stable@nongnu.org Tested-by: Fiona Ebner Reviewed-by: Fiona Ebner Signed-off-by: Thomas Lamprecht Message-ID: <20260522151318.238064-1-t.lamprecht@proxmox.com> [kwolf: Reverted unnecessary change to 'nr' assignment] Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit 1d47eb68983577a4e06fe1c165d90e128b191b86) Signed-off-by: Michael Tokarev diff --git a/block/qcow2-cluster.c b/block/qcow2-cluster.c index 8b1e80bd0b..e02fae6a0c 100644 --- a/block/qcow2-cluster.c +++ b/block/qcow2-cluster.c @@ -1474,9 +1474,9 @@ static int coroutine_fn handle_dependencies(BlockDriv= erState *bs, return 0; } =20 -static void coroutine_mixed_fn wait_for_dependencies(BlockDriverState *bs, - uint64_t guest_offset, - uint64_t bytes) +void coroutine_mixed_fn qcow2_wait_for_dependencies(BlockDriverState *bs, + uint64_t guest_offset, + uint64_t bytes) { BDRVQcow2State *s =3D bs->opaque; QCowL2Meta *m =3D NULL; @@ -2035,7 +2035,7 @@ int qcow2_cluster_discard(BlockDriverState *bs, uint6= 4_t offset, * We don't need to allocate a QCowL2Meta for the discard operation be= cause * s->lock is held for the duration of the whole operation. */ - wait_for_dependencies(bs, offset, bytes); + qcow2_wait_for_dependencies(bs, offset, bytes); =20 /* Caller must pass aligned values, except at image end */ assert(QEMU_IS_ALIGNED(offset, s->cluster_size)); @@ -2204,7 +2204,7 @@ int coroutine_fn qcow2_subcluster_zeroize(BlockDriver= State *bs, uint64_t offset, * We don't need to allocate a QCowL2Meta for the zeroize operation be= cause * s->lock is held for the duration of the whole operation. */ - wait_for_dependencies(bs, offset, bytes); + qcow2_wait_for_dependencies(bs, offset, bytes); =20 /* If we have to stay in sync with an external data file, zero out * s->data_file first. */ diff --git a/block/qcow2.c b/block/qcow2.c index 81fd299b4c..19271b10a4 100644 --- a/block/qcow2.c +++ b/block/qcow2.c @@ -4234,10 +4234,16 @@ qcow2_co_pwrite_zeroes(BlockDriverState *bs, int64_= t offset, int64_t bytes, } =20 qemu_co_mutex_lock(&s->lock); - /* We can have new write after previous check */ offset -=3D head; bytes =3D s->subcluster_size; nr =3D s->subcluster_size; + /* + * Wait for in-flight allocating writes first: otherwise the type + * check below could pass on UNALLOCATED while a yet-to-link_l2 wr= ite + * completes during qcow2_subcluster_zeroize()'s own wait, letting= the + * resumed MAY_UNMAP discard the just-written data. + */ + qcow2_wait_for_dependencies(bs, offset, bytes); ret =3D qcow2_get_host_offset(bs, offset, &nr, &off, &type); if (ret < 0 || (type !=3D QCOW2_SUBCLUSTER_UNALLOCATED_PLAIN && diff --git a/block/qcow2.h b/block/qcow2.h index 192a45d596..ce517040c4 100644 --- a/block/qcow2.h +++ b/block/qcow2.h @@ -966,6 +966,10 @@ int coroutine_fn GRAPH_RDLOCK qcow2_subcluster_zeroize(BlockDriverState *bs, uint64_t offset, uint64_t b= ytes, int flags); =20 +void coroutine_mixed_fn +qcow2_wait_for_dependencies(BlockDriverState *bs, uint64_t guest_offset, + uint64_t bytes); + int GRAPH_RDLOCK qcow2_expand_zero_clusters(BlockDriverState *bs, BlockDriverAmendStatusCB *status_cb, diff --git a/tests/qemu-iotests/046 b/tests/qemu-iotests/046 index e03dd40147..0d84b5c1c7 100755 --- a/tests/qemu-iotests/046 +++ b/tests/qemu-iotests/046 @@ -226,6 +226,26 @@ aio_write -z 0x140000 0x10000 resume A aio_flush EOF + +# Start an allocating write to a previously unallocated cluster and, before +# its L2 update is linked, issue a concurrent sub-cluster zero write with +# MAY_UNMAP that targets a disjoint range within the same cluster. The zero +# write's head/tail are zero (cluster is unallocated), so qcow2_co_pwrite_= zeroes +# would expand it to the full subcluster. Without waiting for dependencies +# before the zero write's "unallocated" type check, that check passes, +# qcow2_subcluster_zeroize then yields in wait_for_dependencies, the alloc= ating +# write links its L2 entry, and the resumed zeroize unmaps the cluster - +# silently discarding the just-written data. Waiting first makes the zero = write +# fall back to a bounce-buffered real write, which only touches its own +# subrange. +cat < Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383501592963.6694694707397; Sat, 13 Jun 2026 13:45:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVBn-00076i-Uq; Sat, 13 Jun 2026 16:42:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBa-0006Tx-US; Sat, 13 Jun 2026 16:42:36 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBX-0005Yg-TI; Sat, 13 Jun 2026 16:42:33 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9E4381B6F24; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 13D393CE96D; Sat, 13 Jun 2026 23:36:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=sDVad7yR6XfEtdjJL/uZdWVwB7wdrZAt4MA6KLhxk0o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=If0ohev5Lu0Qn2sDL18eAk5zO6wtk+Qz9vqn/DlbocglcWkxSr1jv+IUuSv4U9Ype SZWW1ADRCYafxcg9mKIKjwc/CJpbCNKeP4hREChw6nn3JpdxmvhAfkfav4lnsSFhrc 51K6jo4p1F1K/Q1CiXP9jWp0LFHGvPr2gg4Ul690Wg/rIFsGbTv1qO5fHoxO0knoAO 9dR68GXfs2ckpA2Vk3pJiPzQoaSF/v94Xo3FXRQ6gTNBBdKCn6JhHVZNIyE2xnfjm6 W/J9/KspOL+PJGcO2QqkmJHp5bg3f6d5+pUYjtZYLLN73UCk7xwH17wBfdYyBwlFUf 11dUsyx6ezOow== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fiona Ebner , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 65/72] block/export/fuse: use struct fuse_init_in Date: Sat, 13 Jun 2026 23:35:31 +0300 Message-ID: <20260613203542.1809153-65-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383502722158500 Content-Type: text/plain; charset="utf-8" From: Fiona Ebner The code is switched to use the current 'struct fuse_init_in' in preparation to use the FUSE_DIRECT_IO_ALLOW_MMAP feature, which is part of the flags2 member that got added in protocol version 5.36. To not break compatibility with older kernels, the check for whether the full header of an operation was read in co_read_from_fuse_fd() needs to be adapted. In particular, for a FUSE_INIT operation, the protocol version must be considered, because the length of the header changed with protocol version 7.36. Always using the length of the old, shorter struct was inaccurate, since for newer protocol versions this might mean accepting a truncated read for FUSE_INIT. Users of the init header that want to use parts of the extended structure must check with the using_old_fuse_init_in() helper function if they may do so. Cc: qemu-stable@nongnu.org Fixes: a94a1d7699 ("fuse: Manually process requests (without libfuse)") Signed-off-by: Fiona Ebner Message-ID: <20260506145424.10249-2-f.ebner@proxmox.com> Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit 817cc2d045d25c980f20c2377d4a301f68d3e3e2) Signed-off-by: Michael Tokarev diff --git a/block/export/fuse.c b/block/export/fuse.c index a2a478d293..35218e3197 100644 --- a/block/export/fuse.c +++ b/block/export/fuse.c @@ -51,23 +51,16 @@ #define FUSE_MAX_READ_BYTES (MIN(BDRV_REQUEST_MAX_BYTES, 1 * 1024 * 1024)) #define FUSE_MAX_WRITE_BYTES (64 * 1024) =20 -/* - * fuse_init_in structure before 7.36. We don't need the flags2 field add= ed - * there, so we can work with the smaller older structure to stay compatib= le - * with older kernels. - */ -struct fuse_init_in_compat { - uint32_t major; - uint32_t minor; - uint32_t max_readahead; - uint32_t flags; -}; - typedef struct FuseRequestInHeader { struct fuse_in_header common; /* All supported requests */ union { - struct fuse_init_in_compat init; + /* + * When using_old_fuse_init_in() is true, then the smaller older s= truct + * is used by the kernel. The flags2 member and other new members = must + * be treated as absent then. + */ + struct fuse_init_in init; struct fuse_open_in open; struct fuse_setattr_in setattr; struct fuse_read_in read; @@ -629,6 +622,16 @@ static int clone_fuse_fd(int fd, Error **errp) return new_fd; } =20 +/** + * Check whether the smaller older fuse_init_in structure from before prot= ocol + * version 7.36 is used. The flags2 member and other new members must be t= reated + * as absent then. + */ +static bool using_old_fuse_init_in(const struct fuse_init_in *in) +{ + return in->major < 7 || (in->major =3D=3D 7 && in->minor < 36); +} + /** * Try to read a single request from the FUSE FD. * Takes a FuseQueue pointer in `opaque`. @@ -693,6 +696,31 @@ static void coroutine_fn co_read_from_fuse_fd(void *op= aque) goto no_request; } =20 + /* + * If the request is of type FUSE_INIT, need to check the version to + * actually determine the length of the fuse_init_in structure used by= the + * kernel. In protocol version 7.36, the structure was extended. + */ + if (in_hdr->common.opcode =3D=3D FUSE_INIT) { + /* Length of the fuse_init_in structure before 7.36. */ + size_t old_init_hdr_len =3D 16; + + /* + * Expect at least the size of the smaller older structure to ensu= re the + * version can be checked. + */ + if (unlikely(ret < sizeof(in_hdr->common) + old_init_hdr_len)) { + error_report("FUSE_INIT request truncated, read only %zi bytes= ", + ret); + fuse_write_err(fuse_fd, &in_hdr->common, -EINVAL); + goto no_request; + } + + if (using_old_fuse_init_in(&in_hdr->init)) { + op_hdr_len =3D old_init_hdr_len; + } + } + if (unlikely(ret < sizeof(in_hdr->common) + op_hdr_len)) { error_report("FUSE request truncated, expected %zu bytes, read %zi= " "bytes", @@ -826,7 +854,7 @@ static bool is_regular_file(const char *path, Error **e= rrp) */ static ssize_t coroutine_fn GRAPH_RDLOCK fuse_co_init(FuseExport *exp, struct fuse_init_out *out, - const struct fuse_init_in_compat *in) + const struct fuse_init_in *in) { const uint32_t supported_flags =3D FUSE_ASYNC_READ | FUSE_ASYNC_DIO; =20 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383555; cv=none; d=zohomail.com; s=zohoarc; b=nkRXMhwHZmmMRfPlGZZ+Pqbh097wI0IUcRcaOgrq8YIpUsE8YblvuOAlyo68xwl3z0AscHafL1NpFBoj73GS2cD21z9mvNZRy1I8hruyY+lsid5ul9nLJMogtjdqVpEZfTPeBzwPx8Txy9i4KvNKthVikLx/OVcx1uQJAbBcyhI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383555; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ZBLgF+W5SjUqZJQXToW7R0E3F/mPFd4kMce0TaDdles=; b=bzO1UD1yPHERjam9pSZyj68LD+UCMHegi93iGTbvFtTxxWCQBoQcLOkDQgUq22E/Cl1/yo9qv6mWIfbd2PdKkPFLqCCgsfHb2G+toHP53NbEC8juYHhUMjmaIxuUtoE45KI0AZAYAHK0hcMDXZGWIHK916ciHNUI8SuX6/TVYAw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383555094153.80778164132903; Sat, 13 Jun 2026 13:45:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVBl-0006pS-Ex; Sat, 13 Jun 2026 16:42:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBe-0006XG-Uy; Sat, 13 Jun 2026 16:42:40 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBd-0005ad-1J; Sat, 13 Jun 2026 16:42:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id AC78F1B6F25; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 217023CE96E; Sat, 13 Jun 2026 23:36:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=Qa5RM/R3DMq9VLRLiufaoNNUf9HV7xjAG3zxZJj488Y=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=nxr76iDsmNDP87fj58y9pa2BwViBb27e/3AvWV11wgffQouWmSInWX6bvJCw+LOhp rcZRnyNDfd2LubcAyrdQ6oFhO/lW3vXfocKRqHPI3x1dqpDUjflJfvcwUQ+aR+QWCu D5kM6mMTgO6xxRAYRr1v08osd+JEg12f9El4eifR4nPRINBR/6xTCwOOfIOLBuzQEt 09pITDg9BtGXSV3kQNm6nBh7wY1pgsnCFP5wxkocIbUw+xgnO0M46PrYkTJJQVbzGe IkaSKCI/KkR3yUSEI/w/O/4IzGlAIuDqXULKcZdVERKq7FRGSH4iAyldFq/uVLmYNr ZxhjJHO5o9ptw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fiona Ebner , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 66/72] block/export/fuse: set FUSE_DIRECT_IO_ALLOW_MMAP flag to fix regression Date: Sat, 13 Jun 2026 23:35:32 +0300 Message-ID: <20260613203542.1809153-66-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383556711158500 Content-Type: text/plain; charset="utf-8" From: Fiona Ebner Commit 8599559580 ("fuse: Set direct_io and parallel_direct_writes") broke use cases that require mmap() with MAP_SHARED on the export. In particular, swtpm_setup using its 'file://' protocol requires this. From the kernel documentation [0]: > To allow shared mmap, the FUSE_DIRECT_IO_ALLOW_MMAP flag may be > enabled in the FUSE_INIT reply. Set the FUSE_DIRECT_IO_ALLOW_MMAP flag to restore compatibility with users requiring shared mmap. The FUSE_INIT_EXT flag needs to be set for the flags2 member to have an effect. [0]: https://www.kernel.org/doc/html/next/filesystems/fuse/fuse-io.html Cc: qemu-stable@nongnu.org Fixes: 8599559580 ("fuse: Set direct_io and parallel_direct_writes") Signed-off-by: Fiona Ebner Message-ID: <20260506145424.10249-3-f.ebner@proxmox.com> Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit d1664a4058b2b4285d281d32c81ef646f78e7d9a) Signed-off-by: Michael Tokarev diff --git a/block/export/fuse.c b/block/export/fuse.c index 35218e3197..c0e8dfb643 100644 --- a/block/export/fuse.c +++ b/block/export/fuse.c @@ -856,7 +856,8 @@ static ssize_t coroutine_fn GRAPH_RDLOCK fuse_co_init(FuseExport *exp, struct fuse_init_out *out, const struct fuse_init_in *in) { - const uint32_t supported_flags =3D FUSE_ASYNC_READ | FUSE_ASYNC_DIO; + uint32_t supported_flags =3D FUSE_ASYNC_READ | FUSE_ASYNC_DIO; + uint32_t flags2 =3D 0; =20 if (in->major !=3D 7) { error_report("FUSE major version mismatch: We have 7, but kernel h= as %" @@ -871,13 +872,21 @@ fuse_co_init(FuseExport *exp, struct fuse_init_out *o= ut, return -EINVAL; } =20 + if (!using_old_fuse_init_in(in)) { + /* The flags2 flags must be shifted down by 32 bits. */ + const uint32_t supported_flags2 =3D FUSE_DIRECT_IO_ALLOW_MMAP >> 3= 2; + /* flags2 is only considered if FUSE_INIT_EXT is set. */ + supported_flags =3D supported_flags | FUSE_INIT_EXT; + flags2 =3D in->flags2 & supported_flags2; + } + *out =3D (struct fuse_init_out) { .major =3D 7, .minor =3D MIN(FUSE_KERNEL_MINOR_VERSION, in->minor), .max_readahead =3D in->max_readahead, .max_write =3D FUSE_MAX_WRITE_BYTES, .flags =3D in->flags & supported_flags, - .flags2 =3D 0, + .flags2 =3D flags2, =20 /* libfuse maximum: 2^16 - 1 */ .max_background =3D UINT16_MAX, --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383523; cv=none; d=zohomail.com; s=zohoarc; b=hZvobis9HK56HlHS4Gp6AWc/G4EPToSqs9DJsSGK3fe7Lk+fq4BRMOvR6eaiVr3Vvl0peHgWV7kgOZLN67o/3jFBcyuv/OOxVqym6J2dIaJRcDxQkskI2IdUmIcbZFG7+vMNdq/vfrfTtlabvkSOul4ehnPri2IQ6Hw6KKdH6ks= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383523; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=cXf9T8Brb7cwvMNXE1TyuRSqm5AirRBN/76LbIfisV8=; b=PdXgnJI1xfMVOBdSOlvhAaMvV+blokoTJcgi3nTvURdMFYovRhb7RzBJ1c+XWpH04TMAoixWlYZDde/Bx+VmurCuyx1oL9z83loQ2CvMzXkbjN8vkV2dtFUpQH0EBR3NdvqDJsbOJFKbsCMGh5FqhKq9dCDVokvFkHjK0c+wnro= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383523531583.831872646146; Sat, 13 Jun 2026 13:45:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVBj-0006eu-Sc; Sat, 13 Jun 2026 16:42:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBe-0006XJ-V6; Sat, 13 Jun 2026 16:42:40 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBd-0005af-0s; Sat, 13 Jun 2026 16:42:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BAE5E1B6F26; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 304573CE96F; Sat, 13 Jun 2026 23:36:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=DvcG+/emGldtmPeJDW0d3whJBKyCeFHS8szQ3LhN0e0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=EqsNVy4BavVn3aMvoNi01X7ddB4D1807tIIv9LSOT0XqRE1OpdNt4YWB1ortG+fqn vW+YloId7FPDDrn5kR/HSqK/tVjMPyU8cBCLE8fCHDusBvkR0IKQpzt7kUTQbdSI9j 1KnOZ2cfVO0H3/phpnY2gNdQ7aLekZ1fC1El9ZijPl8nPKXNtnb9xiwlY6wLRcc6s+ owQ4Pc30HOfnWYbymIHf2mIab7qDeJ/MWytdREGEeP+WrR2pz1RejVwowCreTpsBTW k8uwCyPkiOMcdPmXqrt8LY12OgukOJNKA8343nKSu8BOPz6m1puzTxl0fBvXb511zL eHXkdzPHJUDXA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fiona Ebner , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 67/72] iotests: test shared mmap for fuse export Date: Sat, 13 Jun 2026 23:35:33 +0300 Message-ID: <20260613203542.1809153-67-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383524622158500 Content-Type: text/plain; charset="utf-8" From: Fiona Ebner This test would have worked before commit 8599559580 ("fuse: Set direct_io and parallel_direct_writes") and is working again since commit HEAD~1 ("block/export/fuse: set FUSE_DIRECT_IO_ALLOW_MMAP flag to fix regression"). Signed-off-by: Fiona Ebner Message-ID: <20260506145424.10249-4-f.ebner@proxmox.com> Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit ba20257d9b45c28f23a66b3f79bebffd6322ff76) Signed-off-by: Michael Tokarev diff --git a/tests/qemu-iotests/tests/fuse-mmap-shared b/tests/qemu-iotests= /tests/fuse-mmap-shared new file mode 100755 index 0000000000..52941a3bb6 --- /dev/null +++ b/tests/qemu-iotests/tests/fuse-mmap-shared @@ -0,0 +1,105 @@ +#!/usr/bin/env python3 +# group: rw +# +# Test that a FUSE export can be mmap()-ed with MAP_SHARED +# +# Copyright (C) 2026 Proxmox Server Solutions GmbH +# +# SPDX-License-Identifier: GPL-2.0-or-later + +import os +import itertools +import mmap +from mmap import MAP_SHARED +from pathlib import Path + +import iotests +from iotests import qemu_img, qemu_io, QemuStorageDaemon + +def test_fuse_support(mount_point): + test_qsd =3D QemuStorageDaemon('--blockdev', 'null-co,node-name=3Dnode= 0', + qmp=3DTrue) + res =3D test_qsd.qmp('block-export-add', { + 'id': 'exp0', + 'type': 'fuse', + 'node-name': 'node0', + 'mountpoint': mount_point, + 'allow-other': 'off' + }) + test_qsd.stop() + if 'error' in res: + assert (res['error']['desc'] =3D=3D + "Parameter 'type' does not accept value 'fuse'") + iotests.notrun('No FUSE support') + +# Shared mmap when using direct IO is only supported for Linux kernels >= =3D 6.6 +# with commit e78662e818f94 ("fuse: add a new fuse init flag to relax +# estrictions in no cache mode"). +def test_linux_kernel_support(): + [major, minor] =3D map(int, os.uname().release.split('.')[:2]) + if major < 6 or (major =3D=3D 6 and minor < 6): + iotests.notrun('No kernel support for shared mmap with direct IO') + +image_size =3D 1 * 1024 * 1024 +image =3D os.path.join(iotests.test_dir, 'image.' + iotests.imgfmt) +fuse_mount_point =3D os.path.join(iotests.test_dir, 'export.fuse') +Path(fuse_mount_point).touch() + +test_fuse_support(fuse_mount_point) +test_linux_kernel_support() + +class TestMmapShared(iotests.QMPTestCase): + + def setUp(self): + qemu_img('create', '-f', iotests.imgfmt, image, str(image_size)) + qemu_io(image, '-c', f'write -P 23 0 {image_size}') + + self.qsd =3D QemuStorageDaemon(qmp=3DTrue) + + self.qsd.cmd('blockdev-add', { + 'node-name': 'node0', + 'driver': iotests.imgfmt, + 'file': { + 'driver': 'file', + 'filename': image + } + }) + + self.qsd.cmd('block-export-add', { + 'id': 'exp0', + 'type': 'fuse', + 'node-name': 'node0', + 'mountpoint': fuse_mount_point, + 'writable': True, + 'allow-other': 'off' + }) + + def tearDown(self): + self.stop_qsd() + os.remove(image) + os.remove(fuse_mount_point) + + def stop_qsd(self): + if self.qsd: + self.qsd.stop() + self.qsd =3D None + + def test_mmap_shared(self): + with open(fuse_mount_point, 'r+b') as file: + with mmap.mmap(file.fileno(), image_size, flags=3DMAP_SHARED) = as mm: + buf =3D bytearray(image_size) + buf[:] =3D itertools.repeat(23, image_size) + assert mm.read(image_size) =3D=3D buf + buf[:] =3D itertools.repeat(42, image_size) + mm.seek(0) + mm.write(buf) + mm.flush() + self.stop_qsd() + qemu_io(image, '-c', f'read -P 42 0 {image_size}') + +if __name__ =3D=3D '__main__': + # LUKS would require key-secret in blockdev-add + iotests.main(supported_fmts=3D['generic'], + unsupported_fmts=3D['luks'], + supported_protocols=3D['file'], + supported_platforms=3D['linux']) diff --git a/tests/qemu-iotests/tests/fuse-mmap-shared.out b/tests/qemu-iot= ests/tests/fuse-mmap-shared.out new file mode 100644 index 0000000000..ae1213e6f8 --- /dev/null +++ b/tests/qemu-iotests/tests/fuse-mmap-shared.out @@ -0,0 +1,5 @@ +. +---------------------------------------------------------------------- +Ran 1 tests + +OK --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383461; cv=none; d=zohomail.com; s=zohoarc; b=LgaYrwTrthqv69ANFV5DmNzJEoBcX/QsbLra4yagKaxr63i0Pj1T/0Vz5poXnsHjINVMykSovl43VpU861jLRCjslaIP5iterM2FqiJ0q1YxVOS5bEuwJX1BmODvHS/W8LKMA53ivE8ugWrAHnwo9BMp1RvemiDpH5yOqto4Cso= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383461; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YY0uwse6Hb5jrP1SVvHE0sspwTX5gxzDKwYLa5WCu7I=; b=Ds4AugPUYlIHc7rlDnHZL9lo/4C/U3qLyfbjk42y6ysbjDoCiyJNxsiZmvAmwjLSMdsa4U0Coz2XlaNVzaVl8LPDnLKt00eybSyBnKx3f1zCGbozZ9u7AF4PWLnKxwbWTbeLIDChrtnm+V+8LpUDZaSLKQoBuZZzhS4CxaNRuBw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178138346106498.8502401691876; Sat, 13 Jun 2026 13:44:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVC7-00005m-KW; Sat, 13 Jun 2026 16:43:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVC3-0008MM-SK; Sat, 13 Jun 2026 16:43:05 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVC1-0005bO-4R; Sat, 13 Jun 2026 16:43:03 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id CB9DF1B6F27; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 3E9923CE970; Sat, 13 Jun 2026 23:36:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=sfQCC5CgFR1Bz1gV5P/NZ8E4hv3um15ceX7Klvs2YNc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=lJqZ6w8jlo1qJUZvmbbk2GHb/pq+HVuKUbxb2zcSwPDO80gstlqeRt5DgIOFMnwnu mgAvt998JJW0GuK4e6xg5JnGds0q6fMvlUPB5dCJtMpely2GoZQpXq4Rbf2irn9VHH XtDPL7e5UH+AZhZs8NUv3cqwb5WSxNeANt1ouxfjhAos1bNC+m7pVzbf68KzMapGl4 LTIZlqPnVLx1Oy7vPynS/5yxNbHmU34O3wYJhr9Yo3jeOnAGcBlfWHDoVX/iWlR6OA TneDhmYFeLeRfslHa8HbA6+J6N8BzSkzD2qOq3mKRxQiNi/61zr2Op7AJx//OUqr6j 9rMsmjUnEUmSQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fabiano Rosas , Stefan Hajnoczi , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 68/72] qed: Don't try to flush during incoming migration Date: Sat, 13 Jun 2026 23:35:34 +0300 Message-ID: <20260613203542.1809153-68-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383462402158500 Content-Type: text/plain; charset="utf-8" From: Fabiano Rosas It's not possible to access the image file while there is an incoming migration in progress, the QEMU process doesn't hold any locks to the storage at this point so nodes are inactive. Attempting to flush leads to an assert at bdrv_co_write_req_prepare(): assert(!(bs->open_flags & BDRV_O_INACTIVE)) The issue is reproducible by running iotest 181 on a host under cpu load. The migration must coincide with the header already containing the QED_F_NEED_CHECK flag. The sequence of events is as follows, with the respective call stacks referenced below: During block device init, bdrv_qed_attach_aio_context() starts the 'need_check' timer. The timer will not fire during incoming migration as it uses QEMU_CLOCK_VIRTUAL (to avoid this very issue, as the code comment indicates). (0) However, there's still bdrv_qed_drain_begin() which uses the fact that the timer is live to decide whether to start the qed_need_check_timer_entry() directly. (1) The qed_need_check_timer_entry() eventually calls into qed_write_header() -> bdrv_co_pwrite() leading to the assert. (2) Skip creating the 'need_check' timer whenever the image is inactive. The stacks: (0) =3D=3D issues timer_mod =3D=3D #6 in qed_start_need_check_timer at ../block/qed.c:340 #7 in bdrv_qed_attach_aio_context at ../block/qed.c:373 #8 in bdrv_qed_do_open at ../block/qed.c:556 #9 in bdrv_qed_open_entry at ../block/qed.c:582 #10 in coroutine_trampoline at ../util/coroutine-ucontext.c:175 #0 in qemu_coroutine_switch<+120> at ../util/coroutine-ucontext.c:321 #1 in qemu_aio_coroutine_enter<+356> at ../util/qemu-coroutine.c:293 #2 in aio_co_enter<+179> at ../util/async.c:710 #3 in aio_co_wake<+53> at ../util/async.c:695 #4 in thread_pool_co_cb<+47> at ../util/thread-pool.c:283 #5 in thread_pool_completion_bh<+241> at ../util/thread-pool.c:202 #6 in aio_bh_call<+109> at ../util/async.c:173 #7 in aio_bh_poll<+299> at ../util/async.c:220 #8 in aio_poll<+690> at ../util/aio-posix.c:745 #9 in bdrv_qed_open<+392> at ../block/qed.c:607 #10 in bdrv_open_driver<+327> at ../block.c:1678 #11 in bdrv_open_common<+1619> at ../block.c:2008 #12 in bdrv_open_inherit<+2556> at ../block.c:4191 #13 in bdrv_open<+118> at ../block.c:4286 #14 in blk_new_open<+199> at ../block/block-backend.c:458 #15 in blockdev_init<+2011> at ../blockdev.c:612 #16 in drive_new<+3008> at ../blockdev.c:1008 #17 in drive_init_func<+51> at ../system/vl.c:662 #18 in qemu_opts_foreach<+227> at ../util/qemu-option.c:1148 #19 in configure_blockdev<+350> at ../system/vl.c:721 #20 in qemu_create_early_backends<+343> at ../system/vl.c:2076 #21 in qemu_init<+12483> at ../system/vl.c:3778 #22 in main<+46> at ../system/main.c:71 (1) =3D=3D sees timer_pending =3D=3D #6 in bdrv_qed_drain_begin at ../block/qed.c:391 #7 in bdrv_do_drained_begin at ../block/io.c:366 #8 in bdrv_do_drained_begin_quiesce at ../block/io.c:386 #9 in bdrv_child_cb_drained_begin at ../block.c:1207 #10 in bdrv_parent_drained_begin_single at ../block/io.c:133 #11 in bdrv_parent_drained_begin at ../block/io.c:64 #12 in bdrv_do_drained_begin at ../block/io.c:364 #13 in bdrv_drained_begin at ../block/io.c:393 #14 in blk_drain at ../block/block-backend.c:2101 #15 in blk_unref at ../block/block-backend.c:544 #16 in bdrv_open_inherit at ../block.c:4197 #17 in bdrv_open at ../block.c:4286 #18 in blk_new_open at ../block/block-backend.c:458 #19 in blockdev_init at ../blockdev.c:612 #20 in drive_new at ../blockdev.c:1008 #21 in drive_init_func at ../system/vl.c:662 #22 in qemu_opts_foreach at ../util/qemu-option.c:1148 #23 in configure_blockdev at ../system/vl.c:721 #24 in qemu_create_early_backends at ../system/vl.c:2076 #25 in qemu_init at ../system/vl.c:3778 #26 in main at ../system/main.c:71 (2) =3D=3D crashes =3D=3D #5 in __assert_fail (assertion=3D"!(bs->open_flags & BDRV_O_INACTIVE)", f= ile=3D"../block/io.c", line=3D1977 #6 in bdrv_co_write_req_prepare at ../block/io.c:1977 #7 in bdrv_aligned_pwritev at ../block/io.c:2099 #8 in bdrv_co_pwritev_part at ../block/io.c:2316 #9 in bdrv_co_pwritev at ../block/io.c:2233 #10 in bdrv_co_pwrite at ../include/block/block_int-io.h:77 #11 in qed_write_header at ../block/qed.c:128 #12 in qed_need_check_timer at ../block/qed.c:305 #13 in qed_need_check_timer_entry at ../block/qed.c:319 Note that this issue is not exactly the same as what's been reported in Gitlab, but given how easily this reproduces, I imagine it has to be happening in that setup as well. Link: https://gitlab.com/qemu-project/qemu/-/work_items/3515 Signed-off-by: Fabiano Rosas Message-ID: <20260603193813.2327596-1-farosas@suse.de> Reviewed-by: Stefan Hajnoczi Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit 7e573b660fefdebd21cb755d0d34bb5942fd3af3) Signed-off-by: Michael Tokarev diff --git a/block/qed.c b/block/qed.c index da23a83d62..0eccfa21c9 100644 --- a/block/qed.c +++ b/block/qed.c @@ -351,16 +351,22 @@ static void bdrv_qed_detach_aio_context(BlockDriverSt= ate *bs) { BDRVQEDState *s =3D bs->opaque; =20 - qed_cancel_need_check_timer(s); - timer_free(s->need_check_timer); - s->need_check_timer =3D NULL; + if (s->need_check_timer) { + qed_cancel_need_check_timer(s); + timer_free(s->need_check_timer); + s->need_check_timer =3D NULL; + } } =20 -static void bdrv_qed_attach_aio_context(BlockDriverState *bs, - AioContext *new_context) +static void GRAPH_RDLOCK bdrv_qed_attach_aio_context(BlockDriverState *bs, + AioContext *new_conte= xt) { BDRVQEDState *s =3D bs->opaque; =20 + if (bdrv_is_inactive(bs)) { + return; + } + s->need_check_timer =3D aio_timer_new(new_context, QEMU_CLOCK_VIRTUAL, SCALE_NS, qed_need_check_timer_cb, s); --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383539; cv=none; d=zohomail.com; s=zohoarc; b=maLhgBoNtBlg46eu5uT9vIbQGy2JJldQ9uTvlQiZlIbxds0Tmd3UtV/HSj2Y4AgW9m6vwrsr12qUjHYcfjF/SCgfupWCZA7DNTCYTGvG24F/i3A2qySUQet2hU7OycqxLRXT4hLb5pDRI1Ge/UjH1Bqz4K8AgCwkosr17TH5rVU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383539; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=W6JdPy4K4kJsSCs072IAMTesptt2rb0cvbse46zoUr4=; b=jtWzmTVTDpapqsgyh32BE2l+uHhda19OYgapFTHMa8vWxSyAAyE3htX6IgiZZsG9Z6uY3wRmtdC90xHFrI/rO8j4F3iBOIbOWp0l2kbyNWzZe/xHutXARxVeQEUHBvmdcz5FWwzXkSaWxYW6GVCEmaqRgQvXJHS988/8YGf2hwI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383539377423.12674258343054; Sat, 13 Jun 2026 13:45:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVBm-00070H-Oc; Sat, 13 Jun 2026 16:42:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBj-0006fE-O9; Sat, 13 Jun 2026 16:42:43 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVBh-0005bP-2f; Sat, 13 Jun 2026 16:42:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E992D1B6F28; Sat, 13 Jun 2026 23:36:06 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 4EE633CE971; Sat, 13 Jun 2026 23:36:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382966; bh=jbkwDL2RSoWTXG3cX/JQP8fdtVWxdulh+xyfSz/UVgk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=lDHxJ2UuttiF65KvmSRl1DEF9ld9VlrSm+rPXt998WoddMTSMgEsdwv2DIEQvtvvy AD4UbCmtO/deAn1JXWM4qYKtj1+F8B1DfBgQPCUEEKEXJzQIr8mFmGoRariB+WWuA2 qzvz0phkdhGZca95vkn+D1Fq0fQ3R93en2uLgmPI3J+tEV4+kYEVIULu4hWFok/w98 B+AL6YkBApI5jaI3nRyqCgHsytmCByk821hyHTMmGrtTmU5OrFlFC6/kX51/Mcgtpc y734DnaR4WRPXOtFyRB4CmHnthNZHEEQ5WjsHSryju0BefBEqusRAMKA9RJ4czh5RX B8gTYlWn3fw2Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Munkhbaatar Enkhbaatar , Peter Maydell , Michael Tokarev Subject: [Stable-11.0.2 69/72] hw/usb/hcd-ohci: Clean up USBPacket before freeing ISO TD packet Date: Sat, 13 Jun 2026 23:35:35 +0300 Message-ID: <20260613203542.1809153-69-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383540628158500 Content-Type: text/plain; charset="utf-8" From: Munkhbaatar Enkhbaatar ohci_service_iso_td() allocates a USBPacket and frees it after synchronous completion, but it does not call usb_packet_cleanup() first. Call usb_packet_cleanup() before g_free() so resources owned by USBPacket are released. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3463 Signed-off-by: Munkhbaatar Enkhbaatar Reviewed-by: Peter Maydell Signed-off-by: Peter Maydell (cherry picked from commit 163f9a4e0651b3b4a1438d919489a200d3646ba3) Signed-off-by: Michael Tokarev diff --git a/hw/usb/hcd-ohci.c b/hw/usb/hcd-ohci.c index 6ed8046fc2..37a11f0c94 100644 --- a/hw/usb/hcd-ohci.c +++ b/hw/usb/hcd-ohci.c @@ -756,6 +756,7 @@ static int ohci_service_iso_td(OHCIState *ohci, struct = ohci_ed *ed) } else { ret =3D pkt->status; } + usb_packet_cleanup(pkt); g_free(pkt); =20 trace_usb_ohci_iso_td_so(start_offset, end_offset, start_addr, end_add= r, --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383454; cv=none; d=zohomail.com; s=zohoarc; b=cPQwg0ukhbwRSmAMBB7781BLMYLNKb06t9SThDt8C6RwJ0twME2goKm9Im5wtTn0rbg7fa/NlAvDL/SkL/UEcTiDZFoxpYhrY09Vm2TOlLEiXlMwvWaXHm6QgMebt580qzMElTHqkUU56O+qqilxMOQOy1TOeKe2xRnzDGNXtwo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383454; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Tgn1MeSZ1Iaof+ci+OgIQdbVXJ7ncNHsbikfefpWW4g=; b=eUzlJFfozH1WH2h5LKVAu3h/u0kJWbx8UzI8xaVV6gj1TFYgRN4660tV4jVv0L8A38QxxMSSUkdSumtNbGEeYCbfyQYJa4xwSuutEx9MZBGaJ2Bj55dWmhvT5HNrxT7STOeDIWTsAnJb3+urfR3iuEFSdXpzNpxEGgTd6R5Yl2M= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383454368511.1216068714491; Sat, 13 Jun 2026 13:44:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVCJ-0000er-TK; Sat, 13 Jun 2026 16:43:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVC9-0000LB-If; Sat, 13 Jun 2026 16:43:10 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVC5-0005e7-8T; Sat, 13 Jun 2026 16:43:06 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 0FD781B6F29; Sat, 13 Jun 2026 23:36:07 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6CD3D3CE972; Sat, 13 Jun 2026 23:36:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382967; bh=OJlFeqPSPJI/9JHSpoI1kmMeeq87tuzghZZQuthmz0c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ZL3Z8903nsj+yIyTbtKI7RX0qYQwKDKynMUXLeZAgWdJ8Me6a5VT0ig1NSudmO94n u0rW0DVwOpjICFxzKJ/O7pCHmCtd1clXXbXPzY1uK0x62gnMISMBPM+9+8EyLFAfRp yz2/aHj5NaMr9NaD2Fbg5oErLySxKCJTCZ8FF9LgYhDyf4gAiXOO6xCnMo7Z7lmjhJ +3TEjzV5bJe6cQznLbjBUOyPSkv1iJOV4eO3DHchQsn7yXw7J4q/V6NCXQpMIsI7hm xC9LOMsDGmpLw/QEHKhyd8hvk9htACgfRC3D3n1ZiXtHJNJi/xFRkD/D8yrxRaL5U7 VekYOSRo6XD9g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richard Henderson , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-11.0.2 70/72] fpu: Handle all rounding modes in partsN_uncanon_normal Date: Sat, 13 Jun 2026 23:35:36 +0300 Message-ID: <20260613203542.1809153-70-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383456316158500 From: Richard Henderson Missed float_round_nearest_even_max when recomputing round. CC: qemu-stable@nongnu.org Fixes: 72330260cdb ("softfloat: Add float_round_nearest_even_max") Reported-by: Peter Maydell Signed-off-by: Richard Henderson Reviewed-by: Peter Maydell Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-id: 20260608190155.637067-2-richard.henderson@linaro.org Signed-off-by: Peter Maydell (cherry picked from commit a6a1f92d5a2368882e9b6851b6ab8b9a56d71a8c) Signed-off-by: Michael Tokarev diff --git a/fpu/softfloat-parts.c.inc b/fpu/softfloat-parts.c.inc index 3c323c0cec..edfcbeb80b 100644 --- a/fpu/softfloat-parts.c.inc +++ b/fpu/softfloat-parts.c.inc @@ -431,6 +431,7 @@ static void partsN(uncanon_normal)(FloatPartsN *p, floa= t_status *s, /* Need to recompute round-to-even/round-to-odd. */ switch (s->float_rounding_mode) { case float_round_nearest_even: + case float_round_nearest_even_max: if (N > 64 && frac_lsb =3D=3D 0) { inc =3D ((p->frac_hi & 1) || (p->frac_lo & round_mask) !=3D frac_lsbm1 --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383429; cv=none; d=zohomail.com; s=zohoarc; b=AiILZvdy5BoEwqQ91GDYqg/+BREmpz9tEdxnaNdwewNlnXZy5S7LbkCK6GQrwZR/SVT1p+LStXPhQ18khq1PCuKdr8za5gmw+9F14vOPtVn6IGL9JKDsRAGUxnlEHvQXlTJydR320xGso02Zn3sbImUE2HuWFB4VXZBhV3HUU4c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383429; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=H+lOVpHRBOLns2YdeRPT4ntj/ReDbGR+7tvR/1bGXFY=; b=LbyaC3o87Ajwscu6eeBgX1M3crqYHugKBFIRKRn+Oc5zoJGcZ1N7Y2bBvmspgYx2TC+KXfbBWX/YN1gt6KaYNC7A8nZjvXhz5svliwuMD5lJracfGBq5x5nSMyTYtC8qHuVcs0dyusQQweygXpx/v/FRpOirYJT5oiOfmIldbSc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383429152382.075787248667; Sat, 13 Jun 2026 13:43:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVCJ-0000bS-4G; Sat, 13 Jun 2026 16:43:19 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVC9-0000LK-J3; Sat, 13 Jun 2026 16:43:11 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVC5-0005jq-C7; Sat, 13 Jun 2026 16:43:06 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 20FB91B6F2A; Sat, 13 Jun 2026 23:36:07 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 877E63CE973; Sat, 13 Jun 2026 23:36:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382967; bh=u48ie73Wjnwd+AefzvtIOSouHz6g5JAEaBHx18K6fCM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=KHhdgJOyBJYS4eB38GcFXwviuexvAb5a200vKa5wGVHMsgf0OW9G9eyUyhatNyCmS cTomFFc+LwRn/xe7jNU3NEMJZKevxqRsfEjeqZbkyvyDPdpxpuzTnSBHeh9nkBVFuJ 1Ld3BwmMcePEOf1ve3YsgwrXTa85TWslbBqyX3q69EWYLYX7MsNPiUJAStuQDWxrZo CXziia0Kb6GhfiB1AU811cADjIftcaQdQJMGstO0q0crCS/43jdy3RHo3XXQBFeIHo tsQMeF5aPGHBoZZTVMFkCwgjPPDhU1pijxflYwW8C2qlV3+cvMSsLTopwUhP8+whm2 cRTPY6fGOAp7A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Xinhui Yang , Pierrick Bouvier , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 71/72] linux-user: implement fsmount(2) series of syscalls Date: Sat, 13 Jun 2026 23:35:37 +0300 Message-ID: <20260613203542.1809153-71-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383430420158500 Content-Type: text/plain; charset="utf-8" From: Xinhui Yang This series of syscalls replaces the old mount(2) syscall with a series of syscalls that operates around a filesystem context. This series of syscalls is available since Linux 5.2 and glibc 2.36+. Their users include systemd since v259 and libmount from util-linux, and possibly other widely used projects. Preliminary checks are implemented to ensure the validity of the interface. v2: Add syscall wrappers in case the build machine does not support the fsmount() syscalls. (added by Helge Deller) Signed-off-by: Xinhui Yang Reviewed-by: Pierrick Bouvier Signed-off-by: Helge Deller (cherry picked from commit 767c32fe69834344bf71f4071ff33292cd46f626) Signed-off-by: Michael Tokarev diff --git a/linux-user/syscall.c b/linux-user/syscall.c index 65bbeb8551..993718973a 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -9653,6 +9653,19 @@ _syscall5(int, sys_move_mount, int, __from_dfd, cons= t char *, __from_pathname, int, __to_dfd, const char *, __to_pathname, unsigned int, flag) #endif =20 +#if defined(TARGET_NR_fsopen) && defined(NR_fsopen) +#define __NR_sys_fsopen __NR_fsopen +_syscall2(int, sys_fsopen, const char *, fs_name, unsigned int, flags); +#define __NR_sys_fsconfig __NR_fsconfig +_syscall5(int, sys_fsconfig, int, fs_fd, unsigned int, cmd, const char *, = key, + const void *, value, int, aux) +#define __NR_sys_fsmount __NR_fsmount +_syscall3(int, sys_fsmount, int, fs_fd, unsigned int, flags, + unsigned int, ms_flags) +#define __NR_sys_fspick __NR_fspick +_syscall3(int, sys_fspick, int, dfd, const char *, path, unsigned int, fla= gs) +#endif + /* This is an internal helper for do_syscall so that it is easier * to have a single return point, so that actions, such as logging * of syscall results, can be performed. @@ -14348,6 +14361,97 @@ static abi_long do_syscall1(CPUArchState *cpu_env,= int num, abi_long arg1, return do_map_shadow_stack(cpu_env, arg1, arg2, arg3); #endif =20 +#if defined(TARGET_NR_fsopen) && defined(NR_fsopen) + case TARGET_NR_fsopen: + { + p =3D lock_user_string(arg1); + if (!p) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsopen(p, arg2)); + unlock_user(p, arg1, 0); + } + return ret; + case TARGET_NR_fsconfig: + { + /* + * fsconfig(int, int, char *, void *, int) + * NOTE: p4 is nullable and its type might not be a string. + */ + void *p3, *p4; + int cmd =3D (int) arg2; + switch (cmd) { + case FSCONFIG_SET_BINARY: + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + p3 =3D lock_user_string(arg3); + if (!p3) { + return -TARGET_EFAULT; + } + if (cmd !=3D FSCONFIG_SET_BINARY) { + /* key and value must be strings. */ + p4 =3D lock_user_string(arg4); + } else { + /* + * Otherwise the value must be a raw buffer with its + * length specified in arg5 (aux). + */ + p4 =3D lock_user(VERIFY_READ, arg4, arg5, 1); + } + if (!p4) { + unlock_user(p3, arg3, 0); + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, p3, p4, arg5)); + unlock_user(p3, arg3, 0); + unlock_user(p4, arg4, 0); + break; + + case FSCONFIG_SET_FLAG: + case FSCONFIG_SET_FD: + /* arg4 (value) must be NULL. */ + if (arg4) { + return -TARGET_EFAULT; + } + p3 =3D lock_user_string(arg3); + if (!p3) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, p3, NULL, arg5)= ); + unlock_user(p3, arg3, 0); + break; + case FSCONFIG_CMD_CREATE: + case FSCONFIG_CMD_RECONFIGURE: +#ifdef FSCONFIG_CMD_CREATE_EXCL + /* + * FSCONFIG_CMD_CREATE_EXCL is only available since Linux + * 6.6. Guarding it to allow building with pre-6.6 headers. + */ + case FSCONFIG_CMD_CREATE_EXCL: +#endif + /* key and value must be NULL, aux must be 0. */ + if (arg3 || arg4 || arg5) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, NULL, NULL, 0)); + break; + default: + return -TARGET_EFAULT; + } + } + return ret; + case TARGET_NR_fsmount: + ret =3D get_errno(sys_fsmount(arg1, arg2, arg3)); + return ret; + case TARGET_NR_fspick: + { + p =3D lock_user_string(arg2); + ret =3D get_errno(sys_fspick(arg1, p, arg3)); + unlock_user(p, arg2, 0); + } + return ret; +#endif default: qemu_log_mask(LOG_UNIMP, "Unsupported syscall: %d\n", num); return -TARGET_ENOSYS; --=20 2.47.3 From nobody Sun Jul 26 13:30:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1781383490; cv=none; d=zohomail.com; s=zohoarc; b=A33xFIfuI5SMv6xgioNgsTaBHK8lXKd6EIAXOVyueETjJuY5blqg37EdvjIGK/gSu6oxvaQwChj0iaAF+md05lekHqEIm0+QVk1MEuxhoU5t6lbiy+0BiF2V3OPZrIOYmIkBJoPJf3Bq8LORys+g2WstpcvC+rqbqo6N/XhwqsM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781383490; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=odhWAaLRFrm0d7iYphGajF4buVcnBaO8MCsEHE0Lpf4=; b=YWJS/SeH/W0Sso99xspE3e4P4FeY5y/pdWIEQtY2ygWB3sl6aknx6Saje5P4hWYUr22GU3P3KhJtOM/b0lmbicsX1htV4nN+nVUa8uN6P3KYLkIPmWPUQi9uHjpGnfpyJXkm6P3xF052zJkx5C+6iQwrElLnkU3F80+3F43wCSE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781383490252140.10641163121977; Sat, 13 Jun 2026 13:44:50 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYVCK-0000nY-Ri; Sat, 13 Jun 2026 16:43:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVCF-0000XC-Am; Sat, 13 Jun 2026 16:43:17 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYVCB-0005lN-9m; Sat, 13 Jun 2026 16:43:14 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 3258D1B6F2B; Sat, 13 Jun 2026 23:36:07 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 992213CE974; Sat, 13 Jun 2026 23:36:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1781382967; bh=m5IAU8IqElonT7fQAjsY3AIw/X/Ijl9y7o08uPY1MMQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=uIrN6UCdILxnjd/SiXYHcTSek6biXFlwVA2GULxSxBLWqrly1Y86Svc1HN1BYU9cD YjGX5FVLSDDgDFyYA+Qo9UbSgd46pn7XpvFUR1fKKf5f5XlDwXoDYV5ByVlwzN2Kj8 5Egg358bypv6J+SH39qMeSlSGbm/xBPYyPR2vtSmw+dc5hH7qx5ya/wh6OtFE+8d3A yyvrbajt1M3j3jUU4Qi5LcneFyLY2fzvCCSxyj1jBDw2BvTDUvLzGvNOSYq5wWANWL 7UFxkuoLYd/ZWMY2g2JSWnoePDNHq22gSmyemENq0jj7qRbZmCQIm11SLrrGMpam8N r9kPhOx2sqVmg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Xinhui Yang , Pierrick Bouvier , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 72/72] linux-user/strace: add fsmount series of syscalls Date: Sat, 13 Jun 2026 23:35:38 +0300 Message-ID: <20260613203542.1809153-72-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1781383490552158500 Content-Type: text/plain; charset="utf-8" From: Xinhui Yang Following the addition of fsmount(2) series of syscalls in the syscall handler, strace support is added, with a dedicated function to print the parameters of fsconfig(2), which contains parameters that can be interpreted as multiple types. Snippet of the strace dump when running `mount -t tmpfs tmpfs /media`: 18 fsopen(tmpfs,1) =3D 3 18 read(3,0x407fcf1c,8191) =3D -1 errno=3D61 (No data available) 18 fsconfig(3,FSCONFIG_SET_STRING,"source","tmpfs",0) =3D 0 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 fsconfig(3,FSCONFIG_CMD_CREATE,NULL,NULL,0) =3D 0 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 fsmount(3,1,0) =3D 4 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 statx(4,"",AT_EMPTY_PATH|AT_STATX_SYNC_AS_STAT,0x1000,0x407fee98) =3D 0 18 move_mount(4,,-100,/media,4) =3D 0 18 read(3,0x407fcfcc,8191) =3D -1 errno=3D61 (No data available) 18 close(3) =3D 0 18 close(4) =3D 0 v2: Fixed build on RHEL9 due to missing syscalls (Helge) Signed-off-by: Xinhui Yang Reviewed-by: Pierrick Bouvier Signed-off-by: Helge Deller (cherry picked from commit 6e0aa9f6c731df3f8d1071cfd5ec63fe7b923713) Signed-off-by: Michael Tokarev diff --git a/linux-user/strace.c b/linux-user/strace.c index 2cbaf94c89..3a81cc95f4 100644 --- a/linux-user/strace.c +++ b/linux-user/strace.c @@ -4344,6 +4344,111 @@ print_statx(CPUArchState *cpu_env, const struct sys= callname *name, } #endif =20 +#if defined(TARGET_NR_fsconfig) && defined(NR_fsconfig) +static void +print_fsconfig_cmd_name(int cmd) +{ + switch (cmd) { + case FSCONFIG_SET_FLAG: + qemu_log("%s%s", "FSCONFIG_SET_FLAG", get_comma(0)); + break; + case FSCONFIG_SET_STRING: + qemu_log("%s%s", "FSCONFIG_SET_STRING", get_comma(0)); + break; + case FSCONFIG_SET_BINARY: + qemu_log("%s%s", "FSCONFIG_SET_BINARY", get_comma(0)); + break; + case FSCONFIG_SET_PATH: + qemu_log("%s%s", "FSCONFIG_SET_PATH", get_comma(0)); + break; + case FSCONFIG_SET_PATH_EMPTY: + qemu_log("%s%s", "FSCONFIG_SET_PATH_EMPTY", get_comma(0)); + break; + case FSCONFIG_SET_FD: + qemu_log("%s%s", "FSCONFIG_SET_FD", get_comma(0)); + break; + case FSCONFIG_CMD_CREATE: + qemu_log("%s%s", "FSCONFIG_CMD_CREATE", get_comma(0)); + break; + case FSCONFIG_CMD_RECONFIGURE: + qemu_log("%s%s", "FSCONFIG_CMD_RECONFIGURE", get_comma(0)); + break; +#ifdef FSCONFIG_CMD_CREATE_EXCL + case FSCONFIG_CMD_CREATE_EXCL: + /* Only available since Linux 6.6. */ + qemu_log("%s%s", "FSCONFIG_CMD_CREATE_EXCL", get_comma(0)); + break; +#endif + default: + qemu_log("%s (%d)%s", "UNKNOWN_CMD", cmd, get_comma(0)); + break; + } +} + +static void +print_fsconfig(CPUArchState *cpu_env, const struct syscallname *name, + abi_long arg0, abi_long arg1, abi_long arg2, + abi_long arg3, abi_long arg4, abi_long arg5) +{ + /* + * fsconfig(int fd, int cmd, char* key, void* value, int aux) + * Where: + * fd: file descriptor returned by fsopen(). + * cmd: integer constant specifying a command. + * key: a string, can be NULL on certain commands. + * value: any data in a buffer, can be NULL, raw buffer or a string. + * aux: axillary values such as flags for FSCONFIG_SET_PATH. + */ + int cmd =3D (int) arg1; + print_syscall_prologue(name); + print_raw_param("%d", arg0, 0); + print_fsconfig_cmd_name(cmd); + /* Process arg2 (key). */ + switch (cmd) { + case FSCONFIG_SET_FLAG: + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_BINARY: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + case FSCONFIG_SET_FD: + print_string(arg2, 0); + break; + default: + print_pointer(arg2, 0); + break; + } + /* Process arg3 (value). */ + switch (cmd) { + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + print_string(arg3, 0); + break; + default: + print_pointer(arg3, 0); + break; + } + /* + * Process arg4 (aux). + * On FSCONFIG_SET_PATH and FSCONFIG_SET_PATH_EMPTY, aux can + * be either 0 or AT_FDCWD. + * On FSCONFIG_SET_BINARY, aux is an integer to state the length + * of the buffer pointed by arg3. + * Otherwise, it must be 0. + */ + switch (cmd) { + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + print_at_dirfd(arg4, 1); + break; + default: + print_raw_param("%d", arg4, 1); + break; + } + print_syscall_epilogue(name); +} +#endif + #ifdef TARGET_NR_ioctl static void print_ioctl(CPUArchState *cpu_env, const struct syscallname *name, diff --git a/linux-user/strace.list b/linux-user/strace.list index 6162a407f9..e363892e0a 100644 --- a/linux-user/strace.list +++ b/linux-user/strace.list @@ -1722,3 +1722,18 @@ #ifdef TARGET_NR_rseq { TARGET_NR_rseq, "rseq" , "%s(%p,%u,%d,%#x)", NULL, NULL }, #endif +#ifdef TARGET_NR_fsopen +{ TARGET_NR_fsopen, "fsopen", "%s(%s,%d)", NULL, NULL }, +#endif +#if defined(TARGET_NR_fsconfig) && defined(NR_fsconfig) +{ TARGET_NR_fsconfig, "fsconfig", NULL, print_fsconfig, NULL }, +#endif +#ifdef TARGET_NR_fsmount +{ TARGET_NR_fsmount, "fsmount", "%s(%d,%d,%d)", NULL, NULL }, +#endif +#ifdef TARGET_NR_move_mount +{ TARGET_NR_move_mount, "move_mount", "%s(%d,%s,%d,%s,%d)", NULL, NULL }, +#endif +#ifdef TARGET_NR_fspick +{ TARGET_NR_fspick, "fspick", "%s(%d,%s,%d)", NULL, NULL }, +#endif --=20 2.47.3