From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308095; cv=none; d=zohomail.com; s=zohoarc; b=ULyYo+uzh5LswDXbw3Qw2I85bozELW/ZjNMjNHJmGsGLDPMJQaaL/IQclO4g8UmPx9EiBLvtkCLMPKr7ZTYgQudSLODRbLmD5ZW1jXkaXaOFPJu5Eg807sOkpDrPyKSmaAvcw9799rlVRAMyb5FpW1Pq+4X39Sn43PAJUAnDPxc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308095; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yHRf+bmo/i+DJ2Gq684jxsdIlfgq4gkPQEZA+Pp1OO4=; b=KDZnN6BAFLU/75KBXf6nlzAVn5CwZRZYqTiw9GaXRTGfgGSNcbIsYph49uMlCADl5sk7kVBc/5Nfak1XO+IVbxo8QtsoHELBn4jTg7ufOOqj/cjLGtr+vR+pn4jWaACC9ArXQ6Hzaxa5qjROqzBZLBG2sOAmuoNHXq0ZysEJuJY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308095982821.1514248273846; Wed, 24 Jun 2026 06:34:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNjU-000746-Iv; Wed, 24 Jun 2026 09:33:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjJ-00070R-P2; Wed, 24 Jun 2026 09:33:28 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjG-0000Nx-V6; Wed, 24 Jun 2026 09:33:24 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 3EA081BA9B3; Wed, 24 Jun 2026 16:33:15 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id CDBE23DEA02; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307995; bh=sIl/tdh7IsN9ArdeDKreQuQNxHNbY82eRu4BG+AwbgQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=C1f/GyDDdRn1rb7dGQqeWN1jgZYwH2u7V2c3IQj87tLe/cqIaId0XjWITUrir3v+U RR269IovBj5sVBouB91IkIQpF2OeUZKUxmoFCRnxiXPeIbwm+5YjqSK2mMT+o9rF4O 9XT0z1I34INdkmGGQgl0pIANfsdFmd8f4ph3MjoH/N4OrqOd1rt2qAihMTYwrYk5c+ NDp4y1spQnUTeKdJkozQy1EUO/RkrmLA9eCwtyko5TvNmj3ji1DaNlqhfHWYD8fpQy 5oT1tD3pXu+FfBFTZeKbFF03Uai7g3J1IiG8+To9uLk/0v2isskdsM0zDeXbd7FBPk kUynYDp9YpBvg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , "Maciej S. Szmigiero" , Michael Tokarev Subject: [Stable-11.0.2 001/107] crypto: fix client side anonymous TLS credentials Date: Wed, 24 Jun 2026 16:30:06 +0300 Message-ID: <20260624133301.403266-1-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308096404158500 From: Daniel P. Berrang=C3=A9 The previous refactoring of credential creation failed to allocate storage fo the anonymous TLS credentials on the client endpoint. Fixes: 70f9fd8dbf7233bee497055a9b7825e3729ce853 Reported-by: Maciej S. Szmigiero Signed-off-by: Daniel P. Berrang=C3=A9 (cherry picked from commit 27b127d7348a922ef91ce607776407407f9c2a3e) Signed-off-by: Michael Tokarev diff --git a/crypto/tlscredsanon.c b/crypto/tlscredsanon.c index 1551382e1f..190c9833a7 100644 --- a/crypto/tlscredsanon.c +++ b/crypto/tlscredsanon.c @@ -73,6 +73,8 @@ qcrypto_tls_creds_anon_load(QCryptoTLSCredsAnon *creds, box->dh_params); } } else { + box =3D qcrypto_tls_creds_box_new_client(GNUTLS_CRD_ANON); + ret =3D gnutls_anon_allocate_client_credentials(&box->data.anoncli= ent); if (ret < 0) { error_setg(errp, "Cannot allocate credentials: %s", diff --git a/tests/unit/test-crypto-tlssession.c b/tests/unit/test-crypto-t= lssession.c index 0d06a6892e..dc7a01bb06 100644 --- a/tests/unit/test-crypto-tlssession.c +++ b/tests/unit/test-crypto-tlssession.c @@ -24,6 +24,7 @@ #include "crypto-tls-psk-helpers.h" #include "crypto/tlscredsx509.h" #include "crypto/tlscredspsk.h" +#include "crypto/tlscredsanon.h" #include "crypto/tlssession.h" #include "qom/object_interfaces.h" #include "qapi/error.h" @@ -190,6 +191,121 @@ static void test_crypto_tls_session_psk(void) } =20 =20 +static QCryptoTLSCreds *test_tls_creds_anon_create( + QCryptoTLSCredsEndpoint endpoint) +{ + Object *parent =3D object_get_objects_root(); + Object *creds =3D object_new_with_props( + TYPE_QCRYPTO_TLS_CREDS_ANON, + parent, + (endpoint =3D=3D QCRYPTO_TLS_CREDS_ENDPOINT_SERVER ? + "testtlscredsserver" : "testtlscredsclient"), + &error_abort, + "endpoint", (endpoint =3D=3D QCRYPTO_TLS_CREDS_ENDPOINT_SERVER ? + "server" : "client"), + "priority", "NORMAL", + NULL + ); + return QCRYPTO_TLS_CREDS(creds); +} + + +static void test_crypto_tls_session_anon(void) +{ + QCryptoTLSCreds *clientCreds; + QCryptoTLSCreds *serverCreds; + QCryptoTLSSession *clientSess =3D NULL; + QCryptoTLSSession *serverSess =3D NULL; + int channel[2]; + bool clientShake =3D false; + bool serverShake =3D false; + int ret; + + /* We'll use this for our fake client-server connection */ + ret =3D qemu_socketpair(AF_UNIX, SOCK_STREAM, 0, channel); + g_assert(ret =3D=3D 0); + + /* + * We have an evil loop to do the handshake in a single + * thread, so we need these non-blocking to avoid deadlock + * of ourselves + */ + qemu_set_blocking(channel[0], false, &error_abort); + qemu_set_blocking(channel[1], false, &error_abort); + + clientCreds =3D test_tls_creds_anon_create( + QCRYPTO_TLS_CREDS_ENDPOINT_CLIENT); + g_assert(clientCreds !=3D NULL); + + serverCreds =3D test_tls_creds_anon_create( + QCRYPTO_TLS_CREDS_ENDPOINT_SERVER); + g_assert(serverCreds !=3D NULL); + + /* Now the real part of the test, setup the sessions */ + clientSess =3D qcrypto_tls_session_new( + clientCreds, NULL, NULL, + QCRYPTO_TLS_CREDS_ENDPOINT_CLIENT, &error_abort); + g_assert(clientSess !=3D NULL); + + serverSess =3D qcrypto_tls_session_new( + serverCreds, NULL, NULL, + QCRYPTO_TLS_CREDS_ENDPOINT_SERVER, &error_abort); + g_assert(serverSess !=3D NULL); + + /* For handshake to work, we need to set the I/O callbacks + * to read/write over the socketpair + */ + qcrypto_tls_session_set_callbacks(serverSess, + testWrite, testRead, + &channel[0]); + qcrypto_tls_session_set_callbacks(clientSess, + testWrite, testRead, + &channel[1]); + + /* + * Finally we loop around & around doing handshake on each + * session until we get an error, or the handshake completes. + * This relies on the socketpair being nonblocking to avoid + * deadlocking ourselves upon handshake + */ + do { + int rv; + if (!serverShake) { + rv =3D qcrypto_tls_session_handshake(serverSess, + &error_abort); + g_assert(rv >=3D 0); + if (rv =3D=3D QCRYPTO_TLS_HANDSHAKE_COMPLETE) { + serverShake =3D true; + } + } + if (!clientShake) { + rv =3D qcrypto_tls_session_handshake(clientSess, + &error_abort); + g_assert(rv >=3D 0); + if (rv =3D=3D QCRYPTO_TLS_HANDSHAKE_COMPLETE) { + clientShake =3D true; + } + } + } while (!clientShake || !serverShake); + + + /* Finally make sure the server & client validation is successful. */ + g_assert(qcrypto_tls_session_check_credentials(serverSess, + &error_abort) =3D=3D 0); + g_assert(qcrypto_tls_session_check_credentials(clientSess, + &error_abort) =3D=3D 0); + + object_unparent(OBJECT(serverCreds)); + object_unparent(OBJECT(clientCreds)); + + qcrypto_tls_session_free(serverSess); + qcrypto_tls_session_free(clientSess); + + close(channel[0]); + close(channel[1]); +} + + struct QCryptoTLSSessionTestData { const char *servercacrt; const char *clientcacrt; @@ -421,9 +537,11 @@ int main(int argc, char **argv) test_tls_init(KEYFILE); test_tls_psk_init(PSKFILE); =20 - /* Simple initial test using Pre-Shared Keys. */ + /* Simple initial tests using Pre-Shared Keys & anon creds */ g_test_add_func("/qcrypto/tlssession/psk", test_crypto_tls_session_psk); + g_test_add_func("/qcrypto/tlssession/anon", + test_crypto_tls_session_anon); =20 /* More complex tests using X.509 certificates. */ # define TEST_SESS_REG(name, caCrt, \ --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308086; cv=none; d=zohomail.com; s=zohoarc; b=KPtQpfupiUwNSyPPswpi+elvkArGBHuSzHFKuyWno9bwqNuwlkGUkbaMZXRku+WdTuIdSIIgA9EjK+vHX/Ad1niIoyi6bE69+y1iKzwns6No7sJsaSrpAchuOGIxPNXVnVGfN+Pxa0B7LowKBCnPid6nOfzOKgEOYxAGBYe9Yn0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308086; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ewAhXTeSCf5dYK5UwmxQgVBXYrxBDhyrOyifKt+Stl4=; b=nmg85aMCrVpoIt9w4uF56puimLiT6aJEIs+KZKbbedzPgbRp7rCfH/H8Nxjrb7nrRHwbpRpSsM6nxjUSnbcmOBcwjx1D0PE3s3jRidOaHkyGv6eyWO1fxpzfkm0rXt22Z8zBbmMiMUeOf8ToqAKM6TFnAFkP3JelffYnAhxkbPY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308083427747.6434176526535; Wed, 24 Jun 2026 06:34:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNjZ-00076j-F3; Wed, 24 Jun 2026 09:33:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjJ-00070Q-OI; Wed, 24 Jun 2026 09:33:28 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjG-0000Nz-Vr; Wed, 24 Jun 2026 09:33:24 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 50C7E1BA9B4; Wed, 24 Jun 2026 16:33:15 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id DF4953DEA03; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307995; bh=ruH2hkT0kSahVJDVkJVWgjKgRpyoHENjlyJWh/U7KsQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=q4QerLIaJfJMpxRnzPn8MYl4nxrweDQ2NwJBsrgdrwaGhIUmGfrJ2Xqkd1ir4nR9r dyRYvYLpszazvZtQq5Giykgmg+cCtLUHrwP6x0AC89nJKyUFv0tTr/8SJJoAfBqjPY eT7dul2si2B607J/Meu+xZ3IUa8UGOwWpLwQw23aoL8/voH96eHxc0lLdJc0Hh5a42 RFsP6G3uQjtuhQ191Xzz4YuJ71r1wZkoWBsNUroyPgRqHuiJ+eVp7DeYSmYgHro6dA 7dfhu+fnWDHFzEywbMNq8qO14AY517qC+Dm0cHAv9E0v+Tm1cGyOwaF0VS4GTGc2Xj fn0exebCRLdFg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Max Chou , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 002/107] target/riscv: Update MISA.C for Zc* extensions Date: Wed, 24 Jun 2026 16:30:07 +0300 Message-ID: <20260624133301.403266-2-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308091292158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang MISA.C is set if the following extensions are selected: * Zca and not F. * Zca, Zcf and F (but not D) is specified (RV32 only). * Zca, Zcf and Zcd if D is specified (RV32 only). * Zca, Zcd if D is specified (RV64 only). Therefore, MISA.C must be set according to the Zc* extension rules. Warn the user if RVC is explicitly disabled but MISA.C is required by the rules above. Signed-off-by: Frank Chang Reviewed-by: Max Chou Reviewed-by: Alistair Francis Message-ID: <20260424050509.3935180-2-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit f0433a8bc4ac5626499ff09ba5d165dbf7a4a980) Signed-off-by: Michael Tokarev diff --git a/target/riscv/tcg/tcg-cpu.c b/target/riscv/tcg/tcg-cpu.c index 988b2d905f..800b7dce5d 100644 --- a/target/riscv/tcg/tcg-cpu.c +++ b/target/riscv/tcg/tcg-cpu.c @@ -1150,6 +1150,44 @@ static void riscv_cpu_enable_implied_rules(RISCVCPU = *cpu) } } =20 +/* + * MISA.C is set if the following extensions are selected: + * - Zca and not F. + * - Zca, Zcf and F (but not D) is specified on RV32. + * - Zca, Zcf and Zcd if D is specified on RV32. + * - Zca, Zcd if D is specified on RV64. + */ +static void riscv_cpu_update_misa_c(RISCVCPU *cpu) +{ + CPURISCVState *env =3D &cpu->env; + bool set_misa_c =3D false; + + if (riscv_has_ext(env, RVC)) { + return; + } + + if (cpu->cfg.ext_zca && !riscv_has_ext(env, RVF)) { + set_misa_c =3D true; + } else if (riscv_cpu_mxl(env) =3D=3D MXL_RV32 && + cpu->cfg.ext_zca && cpu->cfg.ext_zcf && + (riscv_has_ext(env, RVD) ? cpu->cfg.ext_zcd : + riscv_has_ext(env, RVF))) { + set_misa_c =3D true; + } else if (riscv_cpu_mxl(env) =3D=3D MXL_RV64 && + cpu->cfg.ext_zca && cpu->cfg.ext_zcd) { + set_misa_c =3D true; + } + + if (set_misa_c) { + if (cpu_misa_ext_is_user_set(RVC)) { + warn_report("RVC mandated by Zca/Zcf/Zcd extensions"); + return; + } + + riscv_cpu_set_misa_ext(env, env->misa_ext | RVC); + } +} + void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, Error **errp) { CPURISCVState *env =3D &cpu->env; @@ -1157,6 +1195,7 @@ void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, E= rror **errp) =20 riscv_cpu_init_implied_exts_rules(); riscv_cpu_enable_implied_rules(cpu); + riscv_cpu_update_misa_c(cpu); =20 riscv_cpu_validate_misa_priv(env, &local_err); if (local_err !=3D NULL) { --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308190; cv=none; d=zohomail.com; s=zohoarc; b=D8S+Pz0vxi5gRZBYAFh9Isnn+53j7gsRdGHn9D6YU959QHSW59yXbLkFY3KbfZTwlgLyQNfh1wFT0OXGq+d5xV3Lp8DnNxlGBsszXzXOyff5rUjWGMs9eGZEfGseJgbizzSIlwgsK18KzEaYjs/ziruDUqbFaGA3naZ2gJxMMG8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308190; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=TjaHev/Y+EfoaRW7QetxRsXNnbz8zRhbGITqt/bYlKc=; b=RY1y6AOjS4Ksl+9JUrT9ZbmoDFq4XV2mSb1TJnTn2nW6boP1CC18ROoDc21SaSsNgN0/GrAv4pCLDxTnm5imk9oJp+e7BWTXaqIm5rVapsLwAixTTFX7PZrV/a7D/X3wUw4XioeQgUiGXFR0jhVZFaL9ZBwuG+VnJoDHTbbMIMI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308190972590.2254401406232; Wed, 24 Jun 2026 06:36:30 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNja-00078f-UQ; Wed, 24 Jun 2026 09:33:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjP-00072v-Nf; Wed, 24 Jun 2026 09:33:34 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjM-0000Ob-Fl; Wed, 24 Jun 2026 09:33:30 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 642CD1BA9B5; Wed, 24 Jun 2026 16:33:15 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id F19873DEA04; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307995; bh=rsMHcXMYMMN7Tj2tvLEWxPX3ekn7XpT0o/qUhhvEK6Q=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=SjzFemGqKo1t4/ncJo5j3CjcYvAvZL0rxiX9kvEWgARK7epb8rt7AW9DMMqHlfaLX TzFwuNR3tTGg7mYSmbwJJ5nOAfATTwRtjUl/+vsNO86XAWjtuwBNS66K8sq5Od4Hds CGd1Wr60yfJ+/0dQWpYOXIP8vsNRctBJFvVWvczZR4jcPD3hx8YtmhyV3mBVqDxShD mUeXXwb4/CILxArlTEZqwH+GyqpWKyeGogEEt+QmA0TexHzf5HLt7qPeGPEWJNEOTK YkN5Vlly6fiTY9/khdreK8ZtRV3fiQiBB50A7Vnm5+2fNTWQoA4yW1q8sEnwWsPf8H wGS0D/H9CULgQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Max Chou , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 003/107] target/riscv: Update MISA.X for non-standard extensions Date: Wed, 24 Jun 2026 16:30:08 +0300 Message-ID: <20260624133301.403266-3-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308192936158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang MISA.X is set if there are any non-standard extensions. We should set MISA.X when any of the vendor extensions is enabled. Signed-off-by: Frank Chang Reviewed-by: Max Chou Reviewed-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260424050509.3935180-3-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit 613bb1949fffc4aeb9e554e35fecc7d6f7ddd27b) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu.h b/target/riscv/cpu.h index 35d1f6362c..a6adf6efc6 100644 --- a/target/riscv/cpu.h +++ b/target/riscv/cpu.h @@ -69,6 +69,7 @@ typedef struct CPUArchState CPURISCVState; #define RVH RV('H') #define RVG RV('G') #define RVB RV('B') +#define RVX RV('X') =20 extern const uint32_t misa_bits[]; const char *riscv_get_misa_ext_name(uint32_t bit); diff --git a/target/riscv/tcg/tcg-cpu.c b/target/riscv/tcg/tcg-cpu.c index 800b7dce5d..c5505414ae 100644 --- a/target/riscv/tcg/tcg-cpu.c +++ b/target/riscv/tcg/tcg-cpu.c @@ -1188,6 +1188,20 @@ static void riscv_cpu_update_misa_c(RISCVCPU *cpu) } } =20 +/* MISA.X is set when any of the non-standard extensions is enabled. */ +static void riscv_cpu_update_misa_x(RISCVCPU *cpu) +{ + CPURISCVState *env =3D &cpu->env; + const RISCVCPUMultiExtConfig *arr =3D riscv_cpu_vendor_exts; + + for (int i =3D 0; arr[i].name !=3D NULL; i++) { + if (isa_ext_is_enabled(cpu, arr[i].offset)) { + riscv_cpu_set_misa_ext(env, env->misa_ext | RVX); + break; + } + } +} + void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, Error **errp) { CPURISCVState *env =3D &cpu->env; @@ -1196,6 +1210,7 @@ void riscv_tcg_cpu_finalize_features(RISCVCPU *cpu, E= rror **errp) riscv_cpu_init_implied_exts_rules(); riscv_cpu_enable_implied_rules(cpu); riscv_cpu_update_misa_c(cpu); + riscv_cpu_update_misa_x(cpu); =20 riscv_cpu_validate_misa_priv(env, &local_err); if (local_err !=3D NULL) { --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308168; cv=none; d=zohomail.com; s=zohoarc; b=UTA0kKuhujwQDXgsZr3xKvScmmaEJIqQB3fy+/PAgtRw+xisSoUOHU4JBCRcc36mDdTUA/O36pNvtREj34neMe4qT//KjULSHrUsLKTdLnvWnMHYEicWLPGihJjQRFKqwg8AUPktNX2GCQkKDK+riOY3r1kV/kNQgGRn5eRmTI8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308168; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=zVGoTtCWroKBy0DiSa/4XhoQIjB6LurM5lWqN1tUVGw=; b=SHNGl37q2H4uUaq1sVF5HmQK8IvtisO2nR+PJjRMP6Y05mEBTxsmgTks0EFnzC7wWpqIOfTSrrkKGFluEJRKG/QLDL9OSJqXb68jiVYsJwIA9+KOQEL69X3OKzUfs9lit1L2we9gx4OYgNTnRRfoIhobmTC9X60QwlH0XoUUfWk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308168800791.0227230473641; Wed, 24 Jun 2026 06:36:08 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNjU-000748-JK; Wed, 24 Jun 2026 09:33:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjN-00070d-L3; Wed, 24 Jun 2026 09:33:30 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjL-0000Oc-A2; Wed, 24 Jun 2026 09:33:28 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 79BC01BA9B6; Wed, 24 Jun 2026 16:33:15 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1110C3DEA05; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307995; bh=qLusf94cp14bL3s613kWiuKwXIw/4+Fsc+S5U4dxtmA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=SxCYA5g0Z0s8ScTUZux8wGrE7z43aOtpNEUK/ZuVsB+kk8gewMQGjY/wOOBd4h7xn fJEbWlICo2zhW+gSNysmTM+ACvKK4iJf3Mt7O0VhDL94MTaKtPJre27Ysvz+HdVpPI nlYC1VvZjccihDeizGXnC7+TFMayOlE+h2JilHCfhxvCI30Phw3u6Wj9buItgK/KqH dFklk7THNy59taLvqgAJWzuwUARA97dfro9IcajRt7O4tJfrDV847ForIqHoxQgwoN hcyavXsqzjKHdJMXuX0nTgNYWlcuqtmJXaHWKCUsPSqFwbTpirmP4reNMDtas+Y8WH QMUbuV6iny7IA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Andrew Jones , Daniel Henrique Barboza , Nutty Liu , Tomasz Jeznach , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 004/107] hw/riscv/riscv-iommu: Fix Svnapot 64KB pages Date: Wed, 24 Jun 2026 16:30:09 +0300 Message-ID: <20260624133301.403266-4-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308170897158500 Content-Type: text/plain; charset="utf-8" From: Andrew Jones The Svnapot extension encodes a 64KB leaf PTE by setting PTE_N and storing bits [3:0] of the PPN as a NAPOT size indicator. The IOMMU model wasn't checking PTE_N and therefore was using the raw (NAPOT- encoded) PPN directly in the physical address, yielding an address 32 KB above the correct base. Fix both riscv_iommu_spa_fetch() and pdt_memory_read() by mirroring the Svnapot handling already present in target/riscv/cpu_helper.c: napot_bits =3D ctz64(ppn) + 1 /* 4 for 64KB */ napot_mask =3D (1 << napot_bits) - 1 /* 0xF */ phys_base =3D PPN_PHYS(ppn & ~napot_mask) page_offset =3D addr & (PPN_PHYS(napot_mask) | (TARGET_PAGE_SIZE - 1)) The spec only defines napot_bits =3D=3D 4 (64KB); any other value is treated as a reserved encoding. This is a fix, rather than new feature support, because the spec says "IOMMU implementations must support the Svnapot standard extension for NAPOT Translation Contiguity." Fixes: 0c54acb8243d ("hw/riscv: add RISC-V IOMMU base emulation") Cc: qemu-stable@nongnu.org Signed-off-by: Andrew Jones Reviewed-by: Daniel Henrique Barboza Reviewed-by: Nutty Liu Reviewed-by: Tomasz Jeznach Message-ID: <20260508205129.377032-1-andrew.jones@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit fcbd93e96be2ed0e5139542f54be31efa6d2b1dc) Signed-off-by: Michael Tokarev diff --git a/hw/riscv/riscv-iommu.c b/hw/riscv/riscv-iommu.c index c3c9ed6469..917a969081 100644 --- a/hw/riscv/riscv-iommu.c +++ b/hw/riscv/riscv-iommu.c @@ -237,6 +237,25 @@ static bool riscv_iommu_msi_check(RISCVIOMMUState *s, = RISCVIOMMUContext *ctx, return true; } =20 +/* Returns the NAPOT page mask, or 0 for reserved encodings. */ +static hwaddr riscv_iommu_napot_page_mask(hwaddr ppn, hwaddr addr, hwaddr = *out) +{ + int napot_bits =3D ctz64(ppn) + 1; + hwaddr napot_mask, page_mask; + + /* The spec only defines 64KB (napot_bits =3D=3D 4) */ + if (napot_bits !=3D 4) { + return 0; + } + + napot_mask =3D (1ULL << napot_bits) - 1; + page_mask =3D PPN_PHYS(napot_mask) | (TARGET_PAGE_SIZE - 1); + + *out =3D PPN_PHYS(ppn & ~napot_mask) | (addr & page_mask); + + return page_mask; +} + /* * RISCV IOMMU Address Translation Lookup - Page Table Walk * @@ -458,9 +477,20 @@ static int riscv_iommu_spa_fetch(RISCVIOMMUState *s, R= ISCVIOMMUContext *ctx, } else { /* Leaf PTE, translation completed. */ sc[pass].step =3D sc[pass].levels; - base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); - /* Update address mask based on smallest translation granulari= ty */ - iotlb->addr_mask &=3D (1ULL << va_skip) - 1; + + if (pte & PTE_N) { + hwaddr mask =3D riscv_iommu_napot_page_mask(ppn, addr, &ba= se); + + if (!mask) { + break; + } + iotlb->addr_mask &=3D mask; + } else { + base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + /* Update address mask based on smallest translation granu= larity */ + iotlb->addr_mask &=3D (1ULL << va_skip) - 1; + } + /* Continue with S-Stage translation? */ if (pass && sc[0].step !=3D sc[0].levels) { pass =3D S_STAGE; @@ -997,7 +1027,13 @@ static MemTxResult pdt_memory_read(RISCVIOMMUState *s, return MEMTX_ACCESS_ERROR; /* Misaligned PPN */ } else { /* Leaf PTE, translation completed. */ - base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + if (pte & PTE_N) { + if (!riscv_iommu_napot_page_mask(ppn, addr, &base)) { + return MEMTX_ACCESS_ERROR; + } + } else { + base =3D PPN_PHYS(ppn) | (addr & ((1ULL << va_skip) - 1)); + } break; } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308069; cv=none; d=zohomail.com; s=zohoarc; b=hwzJawCjPFQq4hAfliSPG6wKz+os7o3+KfM1JNiemZD1xbI0X2zrzzunn0G5oVyhNRKHxuUEMPPR+I7QmxQ+StJdXnuD1WPGvJhCcJnoj+RmqQqLgvmWXCCDe/SkpA9IvMG37lZ5xig05VWZZgt+KN4x06wkiFq3v/uXJruKE7U= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308069; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=2b+g9SLUsxSVaeE8lDIdekpOIZT2llZuUAvsDin+GUM=; b=f732e+xbKr3pTWUfjFeLdgPuGoyX0r7Tbl0ngJWBj0CKxl291xTNmRiM4unOnV++OH92yCM3zkf2w1nK4AvGfBECW/FHvTlxaD6vKpxDUWNAL4lmkaAHqDjH9CaaqxwdBwt9wKN+S9P2FLt2T7o1L9mh38Zogp1j/GHxzxjo2FI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308069982523.3658768003959; Wed, 24 Jun 2026 06:34:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNjc-0007A6-0H; Wed, 24 Jun 2026 09:33:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjR-00072x-ED; Wed, 24 Jun 2026 09:33:34 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjP-0000Ox-P9; Wed, 24 Jun 2026 09:33:33 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 8CC531BA9B7; Wed, 24 Jun 2026 16:33:15 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 264933DEA06; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307995; bh=RRilm8J/FA34uAbj7pNEW/b/xFYBDEIAPFSEmcy+wOg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Ciz2Iw80ce8FY6ha1dy27q0JjP1nkUU+dOjioGOEixIk2BMo/wZviouE19Bo4KYs4 BlKF82QfDEMSu1NBG6cXf8F5eaMkwmv7Q91ebVRL/N9q/cMt4mb8uPbRy79VIovBly aFJ8MnVKnbD94tPwc3SqPq8eVj7AdXDJTBF6sgtZZbYdbRpMgsjttmiH//rMGGpoz+ yGouK7DnHqA4oLz1eSVypSgk1jrRTQuSdyA5wUwAaGXjdNXTVsK/6Q75NZHK9n3BJm /GOPIu3pz1qpc57kiEVrGoObjoq8/o++/+4WctqJpR7g+koSxhF8M7mepF5wZjFCCb xVoJDMQG4GTPg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Chao Liu , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 005/107] target/riscv: Allow mseccfg access based on ext_zicfilp Date: Wed, 24 Jun 2026 16:30:10 +0300 Message-ID: <20260624133301.403266-5-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308072968158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi The Zicfilp extension adds the MLPE field to the mseccfg CSR. According to the RISC-V Privileged Specification, mseccfg exists if any extension that adds a field to it is implemented. Currently, the `have_mseccfg()` predicate function checks for Smepmp, Zkr, and Smmpm, but misses Zicfilp. As a result, if a CPU is configured with `zicfilp=3Dtrue` but without the other extensions, accessing the mseccfg CSR will incorrectly raise an illegal instruction exception. This patch adds the missing check for `ext_zicfilp` to ensure the CSR is properly accessible when the Zicfilp extension is enabled. This issue was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-isa-m= anual/pr-2561/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Chao Liu Reviewed-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260511072705.3015986-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 249483623242c1b9ad4a1600083bea534620917a) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 29dd596ae4..51e668b46d 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -770,6 +770,9 @@ static RISCVException have_mseccfg(CPURISCVState *env, = int csrno) if (riscv_cpu_cfg(env)->ext_smmpm) { return RISCV_EXCP_NONE; } + if (riscv_cpu_cfg(env)->ext_zicfilp) { + return RISCV_EXCP_NONE; + } =20 return RISCV_EXCP_ILLEGAL_INST; } --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308113; cv=none; d=zohomail.com; s=zohoarc; b=P7se3LctrcXoDWJMqHBw2ZTD2dZZtB7DPyzVPlYJ4DrRbdi9pmhAkf9FlFYTBU8hskmpNE8uWQFjcwfhfVvh2H1T/4mwEheSRSmrIxWzt1hzS+eJh3i0Tv5BUcbel8vz1JxJksDDmm9bluoITlWxOMiu8o6g4HrHNwocBmrpF74= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308113; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VFa35nHRyANSJ/jW5W6xpj1HGEbyCNXlX90bNbDtFZI=; b=RZNnaqxc/ipOcD6b+R3ru6AuYPy5bjkmbOQU99g1Kd16jXHlaATDwZjnbvu0Im8W+xrV0orgqiwDqtwRdIIwVg1+cf8TxTySkGeWbGr/TZEPC8xrWPWquM7g7FSHUpDHn/dHsGjNWjHHa/ULDNeA0e9cZLJSI7X1c0MMPC1DwhQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178230811281319.007414483829393; Wed, 24 Jun 2026 06:35:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNjb-00079i-Om; Wed, 24 Jun 2026 09:33:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjU-00074A-9V; Wed, 24 Jun 2026 09:33:36 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjR-0000PK-4d; Wed, 24 Jun 2026 09:33:34 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9C3B31BA9B8; Wed, 24 Jun 2026 16:33:15 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 396583DEA07; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307995; bh=nmmnp3npEHERyKVMs7WdQEpW4jB59+5sjKmOfypT4CE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=p6E1lrsrMZxoMJPlJwmGmXbJPvaJrePrtKITdnV45ov/xgQcWWh62w+ua20MApBJF EDKJetEWXd+2l5xmZTXSVW7jg0Lxp2OLeIUTSweRCbOztTUVyYFWKz0AEGn008nhin m+rs5/RkP5lnzSgfDEuGj2MSfUYD8JXRg3tmLW8wu2PNzXjBMaiTAdPJfOhbmbmQc4 idK5TUEp/Ft//15KAIn+nJKbkB4r3k6gwiSwTNowGkWEW1RMfZ3Mi0kjUUey9Fb1zm yVXCcAfw7gejJ1iIfQlF50XRa2ez3G588rCRTw3iCwLugTR3ZqZy7wiHRMrr9hNgXY AHTj7wESzeHnw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Anton Blanchard , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 006/107] target/riscv: rvv: Handle source overlap of vector widening reduction instructions Date: Wed, 24 Jun 2026 16:30:11 +0300 Message-ID: <20260624133301.403266-6-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308116337158500 Content-Type: text/plain; charset="utf-8" From: Anton Blanchard Widening reductions read vs2 as a vector of SEW elements and vs1[0] as a scalar of 2*SEW. The ISA does not allow the same vector register to be read with different EEWs, so they must not overlap. vs1 is read as a scalar from element 0, so it is treated as a single vector register (independent of LMUL) when checking overlap. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3208 Signed-off-by: Anton Blanchard Acked-by: Alistair Francis Message-ID: <20260417080328.31918-1-antonb@tenstorrent.com> Signed-off-by: Alistair Francis (cherry picked from commit caf3bef5f01e85b8bbd24e1851b50616fa03a5bb) Signed-off-by: Michael Tokarev diff --git a/target/riscv/insn_trans/trans_rvv.c.inc b/target/riscv/insn_tr= ans/trans_rvv.c.inc index 4df9a40b44..d9a0027e0b 100644 --- a/target/riscv/insn_trans/trans_rvv.c.inc +++ b/target/riscv/insn_trans/trans_rvv.c.inc @@ -3062,6 +3062,7 @@ GEN_OPIVV_TRANS(vredxor_vs, reduction_check) static bool reduction_widen_check(DisasContext *s, arg_rmrr *a) { return reduction_check(s, a) && (s->sew < MO_64) && + !is_overlapped(a->rs1, 1, a->rs2, 1 << MAX(s->lmul, 0)) && ((s->sew + 1) <=3D (s->cfg_ptr->elen >> 4)); } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308179; cv=none; d=zohomail.com; s=zohoarc; b=F/xFXz7Nl0/bkgHMdH8ro2p62Oha5pcQnl1n48kH7BMlrXOvEScWBHHwQXJyfUfNOAV5LwgIQ+4sI3rcmOPKWtuFtPbEjtuesWKehl867poqrqHo4PcyMnXhuJu7tcWLXq7BU+bnNKu4m0ZrfTN3HNqDCMsTXjrttkoDX/cgfbI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308179; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yLPBWjyAAPA5p9AnKtORONEjaqs5zrJJxLmnbbschaA=; b=DJNEzGiV28WuoedUa5Jd+W92e7JiqIN9LyXiqOjdU4xkfxr0YGFUF+ZXexAQNb/wia8KOJzbxxMShgOc8kI1kd/QEBffS/GT2+NcwToeRaOoOY0WGNs6oEJPfuHtcLNmeHeNygPVHD8LSj0NYQnbAU033Gv0IF85CojI10w7M24= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308179042929.925438374725; Wed, 24 Jun 2026 06:36:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNjd-0007Bd-Eo; Wed, 24 Jun 2026 09:33:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjW-00074b-Sv; Wed, 24 Jun 2026 09:33:40 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjU-0000Pa-Bd; Wed, 24 Jun 2026 09:33:37 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B02261BA9B9; Wed, 24 Jun 2026 16:33:15 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 491883DEA08; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307995; bh=LTAxSberyWeoDcQ5ZuEoxEhrXnHV2K4/3Fs3fFdtb8o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=hrVXpyNPFi4QowzU/AtoXTPAZzsuN6dhBkk/zELO1cljw5bTyC6Z6duKEvMnYabiX VUL9oENrPJ1abnpIU/rTX5wfJ9dwFRd+wSHb2svopF5nym+GuDQ1evSzg4S1eZl6Nj qsv6s2RCd4dYz44nn635uHPNsVXB/NMzOu2WvNLvY9v8wveFFkuzcqx7NsJK8I3GfV YaFVPpa8DPprDPvhC/DAJkScJE0TxMrDKHhxiF32OrvsCLj3RxIlnQPT6/NPBhrMkM 5b8q2j/+JlStpACTad5oEbdU9gtpi78wtQnvCpLT4aDerubmXb+eOO1vc1tz1jdn+W B9+LuDx1/71jA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Frank Chang , Chao Liu , Jim Shu , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 007/107] hw/char: Check interrupt after txctrl register is written Date: Wed, 24 Jun 2026 16:30:12 +0300 Message-ID: <20260624133301.403266-7-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308180885158500 Content-Type: text/plain; charset="utf-8" From: Frank Chang It's possible that the transmit watermark level (txctrl.txcnt) is updated when the user writes to txctrl register, which may decrease the transmit watermark level to less than the number of entries in the transmit FIFO. In such a case, the interrupt should be raised so we need to call sifive_uart_update_irq() to check and update interrupt when txctrl register is written. Otherwise, the interrupt will have to be delayed until next TX FIFO transmission is processed. Suggested-by: Chao Liu Signed-off-by: Frank Chang Reviewed-by: Jim Shu Reviewed-by: Alistair Francis Message-ID: <20260513030503.3665414-1-frank.chang@sifive.com> Signed-off-by: Alistair Francis (cherry picked from commit e07077a766071418e76d1c7db7e51e344776eaf2) Signed-off-by: Michael Tokarev diff --git a/hw/char/sifive_uart.c b/hw/char/sifive_uart.c index b4de662d61..b9bbaaef59 100644 --- a/hw/char/sifive_uart.c +++ b/hw/char/sifive_uart.c @@ -213,6 +213,7 @@ sifive_uart_write(void *opaque, hwaddr addr, if (SIFIVE_UART_TXEN(s->txctrl) && !fifo8_is_empty(&s->tx_fifo)) { sifive_uart_trigger_tx_fifo(s); } + sifive_uart_update_irq(s); return; case SIFIVE_UART_RXCTRL: s->rxctrl =3D val64; --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308078; cv=none; d=zohomail.com; s=zohoarc; b=nOm/0onNkqMsphbwg6+qfdf3JA+IAkk6/WFpQA4lz4anSvtUfpz5lMAluGfnqCW+Nk6egxhMx4H4g+ccQEUU4MGe+N6UmwHWl2oix4Z2jbR2NJsRNkGIzOWxrTlH5UbYkk5TJ+92aoL+GzM4xdc9jvm81E0/F/PleSEsKNjfBiI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308078; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fHh1yD5B9Bp9c7LkGde5elhFscJ8YshIrJjC+/dxn4A=; b=PPM2ngu8NCOTObXPyuYQveiOrzWSn45Wexy2uY9elKB216vyUb4yJZHZGHWkdWX5NBYECmpAU4KIe7D4tHO40R2/LjtLqfplnqFm250p0+IVVGGPTiKV9zGxKsuLKOgTxw54ns1DfEwB7MbeqOJhNw2XacGQmp3ep0GDhYuWKoU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178230807892293.60199341598809; Wed, 24 Jun 2026 06:34:38 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNjc-0007BB-U6; Wed, 24 Jun 2026 09:33:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjY-00074d-3p; Wed, 24 Jun 2026 09:33:40 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjV-0000Py-M9; Wed, 24 Jun 2026 09:33:39 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BF1B21BA9BA; Wed, 24 Jun 2026 16:33:15 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 5C6813DEA09; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307995; bh=x8Obbye/RcP9958V3Ik52SIuaNnuyPM0y+vpzi01500=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=qdjI3CEpO+S69CGcNqc63BUiVVuzCE7nzmljUWn41+dbHmNC6OdKQCjyt9X2yZCJS +TG4cBECjc0Fhh7vWpP6LtXA9uApFMrDNZDKa5N33yWkKW4TqjaNcuxlo6wSalOonA VQCPN5JsKiYe3NRPqwStuUNkfDMQgF34i/keFxHHzhwBGaRThtOPcSBTdlt7p8ysp8 9bDhehvy2sRcX08aSXqvhQnapfJ3mwSWuWCxza0aEfJTMT3XpE1P0VjhhXxwk5mbeu CFca+45buvc8OIvOSYV1GCfqAz6wf0Fb/JWerikIxSC6A2cI2pJMo3vzVv6iCtaAzW E9uai7QKFEsKQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Abhigyan Kumar <314abh@gmail.com>, Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 008/107] target/riscv: Fix medeleg[11] read-only zero bit for M-mode ECALL Date: Wed, 24 Jun 2026 16:30:13 +0300 Message-ID: <20260624133301.403266-8-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308080230158500 Content-Type: text/plain; charset="utf-8" From: Abhigyan Kumar <314abh@gmail.com> RISC-V Privileged Specification 3.1.8 (Machine Trap Delegation Registers (medeleg and mideleg)) mentions: "For exceptions that cannot occur in less privileged modes, the corresponding medeleg bits should be read-only zero. In particular, medeleg[11] is read-only zero." QEMU incorrectly included RISCV_EXCP_M_ECALL in DELEGABLE_EXCPS. It allowed the 11th bit to be written and read as set. Fixed by removing it from the DELEGABLE_EXCPS mask, adhering to the specification. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3438 Signed-off-by: Abhigyan Kumar <314abh@gmail.com> Reviewed-by: Alistair Francis Message-ID: <20260427060849.749179-2-314abh@gmail.com> [ Changes by AF: - Remove comment ] Signed-off-by: Alistair Francis (cherry picked from commit a0946caf1d9ec21446ebdcb5eab2400baa4323ae) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 51e668b46d..35e98df420 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -1789,7 +1789,6 @@ static const uint64_t all_ints =3D M_MODE_INTERRUPTS = | S_MODE_INTERRUPTS | (1ULL << (RISCV_EXCP_U_ECALL)) | \ (1ULL << (RISCV_EXCP_S_ECALL)) | \ (1ULL << (RISCV_EXCP_VS_ECALL)) | \ - (1ULL << (RISCV_EXCP_M_ECALL)) | \ (1ULL << (RISCV_EXCP_INST_PAGE_FAULT)) | \ (1ULL << (RISCV_EXCP_LOAD_PAGE_FAULT)) | \ (1ULL << (RISCV_EXCP_STORE_PAGE_FAULT)) | \ --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308137; cv=none; d=zohomail.com; s=zohoarc; b=IwrJoDVC09rsPTlbddGrytJnQG6kiOH5DGbOhTICFs01GQfc8VQlGkfnVNHCaL07qf3CJWGjdX0N7c09mnG/91dVrw/M6Tg1/+YxH8m616cL1OZ1aAAlhBED0l98uIz5sBWP1fUTTHUsNMe1eeYsmn10GXf2DYhFeyaGIjwShEc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308137; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=oeaq1lTffkqBhPb3OhXHSiRXMAlPQFw3Fhc0gUZ9ZlM=; b=JzpTv9QaqT88trhrC8IKNSIli1/PUKJPw7ttcs2NpDb4InRsR8YAmWTxxhk3KICOWrySDxtq1OusKQSw2L/2wtvzCKn71R3XMRL0nO0RqBM7yOTFyrYgbBgT282dhBqhyBEcuDZ9RdQzD2bQykQlAlZw1OMNDf7DjLxDIGLafr4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308137161354.06651529384453; Wed, 24 Jun 2026 06:35:37 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNjg-0007F4-0j; Wed, 24 Jun 2026 09:33:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNja-00078N-1s; Wed, 24 Jun 2026 09:33:42 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjY-0000QH-Fm; Wed, 24 Jun 2026 09:33:41 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id CE0A01BA9BB; Wed, 24 Jun 2026 16:33:15 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6B3863DEA0A; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307995; bh=UQO7+vmvaDWY9veMsChhE+30MJhvcboOLnQu6QDtjGI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=sNXW24PqSvlJLpltQA4L2Nm910uBZzmtpje7FS6FxSjlyqcLhNUZh58oEnutHtOd1 AcyJkqD7N3fQmlZRwMY7aQQk0BwXk8slxFY6uALxE0Isy6DTYOXFYf4oSV517vU6Rr 3jTJvVUPw7GweOtFqXIh+hfG6a/PnDKw7qDRVoU0f6cGRN10acfZ4uMVA9jImct52o +NbHp9vpsvYmDR/yx7YF57ZNl3pP7WJTVeubk0GjjmDDcqdzVf+6wo+djZVy2EaMB9 D4rN1vUIQIerIm7SsRAmNUosw6TasCuDUY4aWi5Wxmap68Mn4ybz6OG7CdGKSOp4eD OqGPOzbQPD7yw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Alistair Francis , Daniel Henrique Barboza , Michael Tokarev Subject: [Stable-11.0.2 009/107] target/riscv/pmp: Fix integer overflow in TOR and NA4 address computation Date: Wed, 24 Jun 2026 16:30:14 +0300 Message-ID: <20260624133301.403266-9-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308138506158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi According to the RISC-V Privileged Manual: "The Sv32 page-based virtual-memory scheme described in sv32 supports 34-bit physical addresses for RV32, so the PMP scheme must support addresses wider than XLEN for RV32." However, the current QEMU implementation uses `target_ulong` (which resolves to `uint32_t` on RV32) for PMP address variables. When shifting these addresses left (e.g., `this_addr << 2`), an integer overflow occurs, truncating the high bits of the 34-bit physical address. Fix this issue by changing the types of PMP address variables (`this_addr` and `prev_addr`) to `hwaddr`. This issue was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-isa-m= anual/pr-2472/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Alistair Francis Reviewed-by: Daniel Henrique Barboza Message-ID: <20260511102627.3120140-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 612f22c19db8adbe9b155f199ede01e86cc1546c) Signed-off-by: Michael Tokarev diff --git a/target/riscv/pmp.c b/target/riscv/pmp.c index 5391caa59c..a71091a316 100644 --- a/target/riscv/pmp.c +++ b/target/riscv/pmp.c @@ -227,8 +227,8 @@ static void pmp_decode_napot(hwaddr a, hwaddr *sa, hwad= dr *ea) void pmp_update_rule_addr(CPURISCVState *env, uint32_t pmp_index) { uint8_t this_cfg =3D env->pmp_state.pmp[pmp_index].cfg_reg; - target_ulong this_addr =3D env->pmp_state.pmp[pmp_index].addr_reg; - target_ulong prev_addr =3D 0u; + hwaddr this_addr =3D env->pmp_state.pmp[pmp_index].addr_reg; + hwaddr prev_addr =3D 0u; hwaddr sa =3D 0u; hwaddr ea =3D 0u; int g =3D pmp_get_granularity_g(env); --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308066; cv=none; d=zohomail.com; s=zohoarc; b=Tcpug4DIjnSA+ks0VIe0dMjI4cwKVeBn46hsfxRYe03A8G6yqgFJ9eDoIGOd8C6fPyl3NOhbhJy3qhJy9yokomeLoc8fQwuo6yZd6cibeN0oJ6N2PiIfb+zAV1eSAHeu3KIowpE2YaCI5jr0zLOerX3/sYX7o3n86+vFPNe+M2k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308066; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9PLPBbNgAsG6FZGp1Ie6s5X4g7r4k274JqGJRoEYywQ=; b=C5kzZyMoj3v229othb1o1pZe1pPUq7yswM1wKaL2rhPtpUgGM15AI4spG15fg1NDxMzccIioh8/efFQ6n4K6ZvifHdkbCj6TecqLX4k/LWphlgyp2i+x00o057/9XCra7HVPGqXr8Q5G32++BGeNBZs53/aLUig39usm+IydesA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308064085690.3701494734269; Wed, 24 Jun 2026 06:34:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNje-0007Db-Dd; Wed, 24 Jun 2026 09:33:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjb-00079F-BS; Wed, 24 Jun 2026 09:33:43 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjZ-0000QQ-Hz; Wed, 24 Jun 2026 09:33:43 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id DC89B1BA9BC; Wed, 24 Jun 2026 16:33:15 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 795FA3DEA0B; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307995; bh=UHMqgPHGlj8+eniKPa2ZlWyJsrrz5RAQJ32gOb+/r4w=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=buloH730QPRkG1dxaQR8ZbcCip54Oxhf3ojP+3qRliYsO0tUk3x29qAEB21j+stm3 E5cXoUhFcry/YVRKs6JwZa97eC62I21TyzMJPnrPSSFM3gDugGl2yTtmCP5RTdRuOw rlWP3fZw3xG5QsHlvam/REuI7nMmNjAkHk298zD8QuTW9OQ3Ku2mDI0iNN0+f/lGhO E+BdQaAdoC+LfGBnlzuKM/4hA02oZ5PB7LNyskl6wzJqfbydq2YdSKFGVxEqzp9Xrg Fs3oWuwuOYsuphyv9SmnTlmbJUHRFNpeP68YAdMlwLH8EwqhUoTwpft8lMygwljtN2 CXG0VhWTXS+0g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 010/107] target/riscv: Add mseccfg to VMStateDescription Date: Wed, 24 Jun 2026 16:30:15 +0300 Message-ID: <20260624133301.403266-10-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308071284158500 Content-Type: text/plain; charset="utf-8" From: Zishun Yi Currently, the Machine Security Configuration Register (mseccfg) was missing from the live migration state. This omission causes the register to be reset to zero on the destination host after migration. Fixed by adding vmstate_mseccfg subsection This vulnerability was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/a22e4459cd026ae970791dfbd= 9cfe5d110fbd46b/output/riscv-isa-manual/pr-1879/qemu.txt#L121 Signed-off-by: Zishun Yi Reviewed-by: Alistair Francis Message-ID: <20260511124828.3210477-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit eccb1d6940256668109dc6dc42450ced9f324134) Signed-off-by: Michael Tokarev diff --git a/target/riscv/machine.c b/target/riscv/machine.c index 09c032a879..6776e7bf5a 100644 --- a/target/riscv/machine.c +++ b/target/riscv/machine.c @@ -423,6 +423,25 @@ static const VMStateDescription vmstate_sstc =3D { } }; =20 +static bool mseccfg_needed(void *opaque) +{ + RISCVCPU *cpu =3D opaque; + + return cpu->cfg.ext_smepmp || cpu->cfg.ext_zkr + || cpu->cfg.ext_smmpm || cpu->cfg.ext_zicfilp; +} + +static const VMStateDescription vmstate_mseccfg =3D { + .name =3D "cpu/mseccfg", + .version_id =3D 1, + .minimum_version_id =3D 1, + .needed =3D mseccfg_needed, + .fields =3D (const VMStateField[]) { + VMSTATE_UINTTL(env.mseccfg, RISCVCPU), + VMSTATE_END_OF_LIST() + } +}; + const VMStateDescription vmstate_riscv_cpu =3D { .name =3D "cpu", .version_id =3D 11, @@ -499,6 +518,7 @@ const VMStateDescription vmstate_riscv_cpu =3D { &vmstate_ssp, &vmstate_ctr, &vmstate_sstc, + &vmstate_mseccfg, NULL } }; --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308151; cv=none; d=zohomail.com; s=zohoarc; b=kuMTNWsmTFPFLMy7tARyODn1mSsu2TwYOGNjCOZzO6rseYyMXxducSKXJXvhk4iPNyao6S7YTHwN8AmOvRfRUWa1MSuAn8Th9qzs0eHqtXr/uxEmv2chMrC8FLkhj206vF2Jdpn7QpzH0iCNtH1SjDVhwcTAA+3Q/ZeHwar7Azs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308151; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=w8Hon4VGlvEsDUAAFagjoNEBiWAMe45DDhoCB4gjyCc=; b=MM9dVqaNeUKIsGOe4hFK3Aoy52H+HVYS15Ewfhu6cBXRfMenSoaGy1Hk+/pwvPE02ygAIUAR0SXqrgP7i5jublO8hGmR0a9YVJgXaSLu0bDb4tsOJCL5LhZfDgkPWYRrQ/Uh5rZPRHmZShFgqsBLH/XRwSFjBKeYZmowC3wWYmE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178230815199064.46397801817011; Wed, 24 Jun 2026 06:35:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNjg-0007F9-N0; Wed, 24 Jun 2026 09:33:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjd-0007Bf-Av; Wed, 24 Jun 2026 09:33:45 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjb-0000Qp-Go; Wed, 24 Jun 2026 09:33:45 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id EA3A21BA9BD; Wed, 24 Jun 2026 16:33:15 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 87E783DEA0C; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307995; bh=y4R+0lv/Ip/IJfxR+IGI+lwzpO9fm3pE+KIrDmMRibo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=KWMg44RaIRjxfCo+Ie82ntNnjpm5vA1Th5x5HoLR3apgxnfutM3BHYhpRLVJOZoGa Q7ejVuypbqan2XeiVObeTtgcfb99EMLB9v92wM6zkphlOxALPlppamsTkoIG6pTcDD rsqsOzZAN6zmzIDkTbhBm/fJ48ufRKUZqpU+7JX/AoOWPJVJ3dulCEJ3z6Lqda57KV vPGeKMJvwCNXwgjbxjpYUaRpIMbZ3yQnr4srgwi2XWjFiEH/eV7YyINvbkznRAd12r ZUPcq4Bxj6w5GQeKx2FHxgrnceraa8knIjHUrkFFTxJWRqPETK6eKImFlLcnuevS4P tqoKkVbRJ9paA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alistair Francis , Daniel Henrique Barboza , Michael Tokarev Subject: [Stable-11.0.2 011/107] target/riscv: Update the local interrupt mask Date: Wed, 24 Jun 2026 16:30:16 +0300 Message-ID: <20260624133301.403266-11-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308153628158500 Content-Type: text/plain; charset="utf-8" From: Alistair Francis The RISC-V spec describes bits 0-15 as standard fixed interrupts. The AIA spec on the other hand describes bits 0-12 as standard fixed interrupts. This conflict causes issues for us as we don't dynamically determine if AIA is enabled when setting the *delegable_ints consts. This means currently we incorrectly treat the LCOFIP bit as delegable, even if AIA is disabled, which is incorrect (see the issues mentioned below). The AIA spec indicates that implementations can determine which bits of 13-63 in mvien are writable, so let's just make it bits 15-63 to match the main spec. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3133 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3134 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3135 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3138 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3140 Signed-off-by: Alistair Francis Reviewed-by: Daniel Henrique Barboza Message-ID: <20260513051841.1671987-1-alistair.francis@wdc.com> Signed-off-by: Alistair Francis (cherry picked from commit 27f9566dcd98bdde045ef5ae7b8199456c8a51c1) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 35e98df420..d65d176fe8 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -1764,13 +1764,13 @@ static RISCVException write_stimecmph(CPURISCVState= *env, int csrno, #define VSTOPI_NUM_SRCS 5 =20 /* - * All core local interrupts except the fixed ones 0:12. This macro is for + * All core local interrupts except the fixed ones 0:15. This macro is for * virtual interrupts logic so please don't change this to avoid messing up * the whole support, For reference see AIA spec: `5.3 Interrupt filtering= and * virtual interrupts for supervisor level` and `6.3.2 Virtual interrupts = for * VS level`. */ -#define LOCAL_INTERRUPTS (~0x1FFFULL) +#define LOCAL_INTERRUPTS (~0xFFFFULL) =20 static const uint64_t delegable_ints =3D S_MODE_INTERRUPTS | VS_MODE_INTERRUPTS | MIP_LCOFIP; --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308077; cv=none; d=zohomail.com; s=zohoarc; b=TnegXeoH9/FcSltQjOzWFtQcCwP5LN7wtC9Qw1oLeX3wcPEwHqG45PMxpXfxvm6TIBLlCWQHm7nazkKZU/l+jge2/iWG93D4kfrghbFg/pfHjFBimRQPqwSMkLBaTuEnY9Av9IohX7mNR+IRPqzFrA3+Sc2lJ5pNONuL+SCl6Wk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308077; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=PmpxywzMWm5RBruQeJasC/yyvzMZ1TMb83FOQ6YwXdg=; b=XzlkD/lL44fCc7b0tIQAw3hhhQv5TfnzPPULI8dR67zstoUXrYINrphl8DHOYau/0CJZsmePP0H1fGkIguCIBgTTcYE07Hq0HmNRVYDN1xeLfbr7N6WM7AsS7qnEZ3ceAdUzylFhKNCB/fB86ZuWX2tQ17kZyaCLGkXViIBgEyc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308076860703.6772609565598; Wed, 24 Jun 2026 06:34:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNk1-0007Qd-7t; Wed, 24 Jun 2026 09:34:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjy-0007Od-GQ; Wed, 24 Jun 2026 09:34:06 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjw-0000RH-Sh; Wed, 24 Jun 2026 09:34:06 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 06E901BA9BE; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 965953DEA0D; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=nBTl9hK8MG28XPQTMfA9qQqImj/KPixRdgkMHL6YTeQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=WrjggXBGDZ0mhp1P5/jIveGMNfjIjZjPKexjYoTHO2z0ESn9q9IiSsMfjna3oX12k Mp5xNUWbT92R4Ih9GcPz9CJYREngrHXjgFmvJu3wphHFAw94j9TMQfA4Ys+tBbUg+m EGMlrMmY1tFEBqkVZaVt20lE8ECE67qV9wU49TEYTFGWjIih8KCPLsBlZHrMOYhYjo YOfHnYr0P/cLKKtquhTVPmenBsILaIMhQUTgXXBJbTv6MS6CkDqNp58Kb+SM+fP8Bw +2Jnf0oLkp9rLK15OAJXPYDW6+VA6cYjKhTC35lx36Aph5avZomfSH+3/mujVcyyLa rJYj3Xjl9ODNw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Zishun Yi , Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 012/107] target/riscv: clear mseccfg on reset for all dependent extensions Date: Wed, 24 Jun 2026 16:30:17 +0300 Message-ID: <20260624133301.403266-12-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308080247158501 Content-Type: text/plain; charset="utf-8" From: Zishun Yi Currently, the `mseccfg` CSR is only cleared to 0 during reset if the `ext_smepmp` is enabled. However, this register is now shared by several other extensions such as `zkr`, `smmpm`, and `zicfilp`. Fix by clearing `mseccfg` if any dependent extension is present, and adjusting the relevant comments. This vulnerability was discovered and reported by SpecHunter, an AI-driven architecture specification analysis tool. Link: https://github.com/yizishun/rv-isa-sec/blob/master/output/riscv-svvpt= c/pr-134/qemu.txt Signed-off-by: Zishun Yi Reviewed-by: Daniel Henrique Barboza Message-ID: <20260512052240.330815-1-vulab@iscas.ac.cn> Signed-off-by: Alistair Francis (cherry picked from commit 8158a74f0a0db8626d7836eb03eca7aba46c18b5) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu.c b/target/riscv/cpu.c index 8ac935ac06..269ea35f6d 100644 --- a/target/riscv/cpu.c +++ b/target/riscv/cpu.c @@ -754,10 +754,14 @@ static void riscv_cpu_reset_hold(Object *obj, ResetTy= pe type) =20 /* * Clear mseccfg and unlock all the PMP entries upon reset. - * This is allowed as per the priv and smepmp specifications - * and is needed to clear stale entries across reboots. + * This is required as per the priv, smepmp, and other security + * extension specifications that share this CSR, and is needed + * to clear stale entries across reboots. */ - if (riscv_cpu_cfg(env)->ext_smepmp) { + if (riscv_cpu_cfg(env)->ext_smepmp || + riscv_cpu_cfg(env)->ext_zkr || + riscv_cpu_cfg(env)->ext_smmpm || + riscv_cpu_cfg(env)->ext_zicfilp) { env->mseccfg =3D 0; } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308243; cv=none; d=zohomail.com; s=zohoarc; b=oGxBSSLn9SQmZtqzJJU09TrhDAUJPPC7MWjO0KBc6N/nQNCkJEpLiIjSrq56H/3Z62N/IZVuvezo/g0me6IL3FnH6o7bxW2Kq8haaKOTpuAXnotV+My22ru4scdo7YZFHs3T/PLgkGJ2ytYHkSyZ8vE4gO3tSnTVxy2V03+001g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308243; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=uElaEYieXH0EcLg4ndfptWyUv+5+T5degTt/qcpdfxA=; b=nkNTGqY5IN6tJ5tTjj42EaqoYS6aAIpgfJfAStBDhgO8Atu7v2UIbjs1QOyuoIQmdtwEcsDxu7L88WMRWGVMv8AqsRe0hRGzF3NG9MSvplBSMrDiQ0imWUXOEtN90bFggXAUToDS3krsJ0rVVS+H8M3ZD1zo6bXDpAD9fFdLDDQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308243819615.5170329287797; Wed, 24 Jun 2026 06:37:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNk1-0007SP-VS; Wed, 24 Jun 2026 09:34:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNk0-0007QC-9z; Wed, 24 Jun 2026 09:34:08 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjy-0000Sg-OE; Wed, 24 Jun 2026 09:34:08 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 163981BA9BF; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id A71423DEA0E; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=Buh3wzvyJ5YPdIEyfbrsL/XcS/pQ3fOnyg/b6Lqqf10=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=duZUL1ywpnlujHQXzYK6YY/msfBSePxtgcDXaTifwOVDPF5EOHxcjtmF4p8KxRmw4 qpJF28YW670bd7v+iBcaoSLpoceBNCxZnspuJqAy7dPFK5lXVxpEfuCDguP7VWCX9l smn4/11rp+LjxKBwyTEqeVEjUXCIGJ4nouCB10+1SuuDJ8UK+e2Rq1oN1jVEeyUE/R 9McdkZWM+oTwFwLKeNC1e7LWk9cNLms3EcE+VAxceV636o/5Fs2BzcNy6+UjEpumv1 zyhW/i6eARY5ml8mbksp9SB5HU4EI9NynEqsazHhdEJVyvCBX19p9L85TTVcN9ouce x9kcZ1MmGlrXg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 013/107] target/riscv/csr.c: fix read of pmpaddr(0-63) CSRs Date: Wed, 24 Jun 2026 16:30:18 +0300 Message-ID: <20260624133301.403266-13-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308245356158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza The priv spec defines, for RV64, that the upper 10 bits of pmpaddr0-pmpaddr63 are WARL and are supposed to be cleared. After this patch, using the bug reproducer in [1], writing ffffffffffffffff in pmpaddr0 and reading it back now results in 003fffffffffffff. Here's the 'diff -cp' dump before and after this change: *************** IN: *** 5272,5278 **** pmpcfg10 0000000000000000 pmpcfg12 0000000000000000 pmpcfg14 0000000000000000 ! pmpaddr0 ffffffffffffffff pmpaddr1 0000000000000000 pmpaddr2 0000000000000000 pmpaddr3 0000000000000000 Reviewed-by: Alistair Francis Message-ID: <20260514123342.2139464-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 53cc9747ed7c9b95ba084d614976dd48c9a57a97) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index d65d176fe8..cf1fe6041c 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -5304,6 +5304,23 @@ static RISCVException read_pmpaddr(CPURISCVState *en= v, int csrno, target_ulong *val) { *val =3D pmpaddr_csr_read(env, csrno - CSR_PMPADDR0); + + /* + * For RV64, bits 54-63 of the address registers + * PMPAADDR(0-63) is a WARL zero field (priv spec, + * section "Physical Memory Protection CSRs"). + * + * We'll have to add an annoying TARGET_RISCV64 gate + * here to avoid complaints about masking bits 0-53 + * of a potential 32 bit target_ulong '*var'. + */ +#ifdef TARGET_RISCV64 + if (env->misa_mxl =3D=3D MXL_RV64 + && csrno >=3D CSR_PMPADDR0 && csrno <=3D CSR_PMPADDR63) { + target_ulong read_mask =3D MAKE_64BIT_MASK(0, 54); + *val &=3D read_mask; + } +#endif return RISCV_EXCP_NONE; } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308638; cv=none; d=zohomail.com; s=zohoarc; b=h8F8BU4ed9jaiPOPTHYljc5+hxRQFoL9n94GZbz5JOtK22qJXVMFRsh1Ksl+hzrA/yaRzgdanVidueiyAdgTUjOSTLvR+U8TY8tPcEcG2BMy2JKB4ksdWydQfAbcyk3JD9C6D7I9Liv2VZ12S+sUXrkOkeqUu1ruRcGs5z21b4c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308638; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fvJWXPv5E60JZC/gtStCwcqftPG2fmvhKsFmUu+T5jA=; b=G+EWyHY2ML0Wsus2YvyRbB44+b0YxA28za4vTdiW9+JzbUByaXh3FtNJH2TqOoUh+CRRjaGMCwNVMygFtMPPZJOeJ4oFTWqVT+Tmx4zYVrk02FUzAna4zGI8IRy5NJXN/rGiJC/qb+V6bIqRURnnm8UIVo8Wm0IDmJxqrOFk55Q= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308638239302.9823332500031; Wed, 24 Jun 2026 06:43:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNk3-0007Ty-Al; Wed, 24 Jun 2026 09:34:11 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNk1-0007Qw-HA; Wed, 24 Jun 2026 09:34:09 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNjz-0000UO-SY; Wed, 24 Jun 2026 09:34:09 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 251881BA9C0; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B657E3DEA0F; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=EQ1/T6K5U0ItJX7O+kcFKps+jhA1+1znygudWJ+5mdI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=OuNhG8JjIHnWXUGEImY78GQ++zHweAbOQBVoyxwpx+S1rsy4MqyO48XDY54AhQphA 8SvtFZak4gBtMIoBs5+yOPZvR04YbgsjnbToxd+8JyJN+WlR0HsVAH8d/DNPT2XZmq W8PfZdeqMYtqXeESTya0Sn0o7Ed65cxNHHxWKnPwyED9bS7NZEmnK9PuGvvEGmOOTl QFckbFbyr8aKlajPWNs94Qp2yPDgauPSGgrtKvSZZzyzcRnvtvd5KELsdJFnvB9JWs AqYo9b++4P8SAfKt8bvPlnGFUpTaihq+ueAXbuTj/E7kcTuti4s0gSxXcneJs1O8xT xcIiS4cxVPDWg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Portia Stephens , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 014/107] target/riscv: Make hpmcounterh return the upper 32-bits Date: Wed, 24 Jun 2026 16:30:19 +0300 Message-ID: <20260624133301.403266-14-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308639539158500 Content-Type: text/plain; charset="utf-8" From: Portia Stephens The counter value was not being bitshifted for a hpmcounterh read resulting in hpmcounterh returning the bottom 32-bits. Fixes: cfc96df65e01 ("target/riscv: Remove upper_half from riscv_pmu_ctr_g= et_fixed_counters_val") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3498 Cc: qemu-stable@nongnu.org Signed-off-by: Portia Stephens Reviewed-by: Alistair Francis Message-ID: <20260519043352.3685866-1-stephensportia@gmail.com> Signed-off-by: Alistair Francis (cherry picked from commit 02284108376a6bcfdd56a11de1c6e0bcc3d0e53b) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index cf1fe6041c..0f14ea4689 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -1392,8 +1392,9 @@ RISCVException riscv_pmu_read_ctr(CPURISCVState *env,= target_ulong *val, */ if (riscv_pmu_ctr_monitor_cycles(env, ctr_idx) || riscv_pmu_ctr_monitor_instructions(env, ctr_idx)) { - *val =3D riscv_pmu_ctr_get_fixed_counters_val(env, ctr_idx) - - ctr_prev + ctr_val; + uint64_t cntr =3D riscv_pmu_ctr_get_fixed_counters_val(env, ctr_id= x) - + ctr_prev + ct= r_val; + *val =3D extract64(cntr, start, length); } else { *val =3D ctr_val; } --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308233; cv=none; d=zohomail.com; s=zohoarc; b=YRQs1vnuHpvmhcXp9yp0vdhESjPLu9Jmf4tVIZoGOPje7GG90Bf8eOWjFcp+DH0D8eOx0OcasfMHTboz3dDWABu/Y6aDUCeZ2c2AOHgd1aQmxJ0tm+siTMojp1OWaMet132YeEdnNelAMxkCuHPo41it3ZIwFBZJY3XwNm6U3Eo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308233; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=pby/DNkEDKLCWfWpY4ntSB6WG9nu650GoJXazxzGKDk=; b=QK2BHU8q22IKZaKVyocuJRDhHc+aQUzGnjOqNHgtPsnEqDucuE5CWH4tji2hYw4MV+2OxQjFR3hUOz/+t8PSl83zYaYdib7rvKo8o5IkiPB5uqr7PCYlvc6m/NkkcM/5hG+zOpdsTQvBf7dHoxUWF7HGQEmTcCMfVV27PVvVOHI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308233648738.3147182589718; Wed, 24 Jun 2026 06:37:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNk5-0007Uw-1g; Wed, 24 Jun 2026 09:34:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNk3-0007U1-Br; Wed, 24 Jun 2026 09:34:11 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNk1-0000Uf-Nk; Wed, 24 Jun 2026 09:34:11 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 340491BA9C1; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C56F53DEA10; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=VpUXHEeZq4VCjeyy0rgRt2Of/KA2IN5KTxh0zZi1P0I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=YJBZ6tAFE0bKwB2iPABZHN/3XcV8SANDGm6Nw1CbK1W7FcH6nXCcvv2DUBl6Mj1QL 4GlyvRdx0jXR7gbeNNCeoyASo3eb43pbNA8paRAHCmWMr9KuZh+Llo9pwVy+NoPOB0 FvgqJvs1M0T31mdCFkhwNBTVDQc+ltgo+r7WcUBQUF/r7qbxAk3kcVVfpYKtfCFp7l k/T72XEBc5ch8CmciabuXFLWMePDXWl6anlabu0//zu8fRXGgUBY6KMB/gd+lPPRIE D5oAAuI54JkUjbWCK3jbptLmtP+hgfF34877+oqo7oaxLsgnjeLoAB7+C7uDO+Rs+w QCAEdrklNWNgg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 015/107] linux-user/mips64: fix elf_core_copy_regs register layout in core files Date: Wed, 24 Jun 2026 16:30:20 +0300 Message-ID: <20260624133301.403266-15-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308235296158503 From: Matt Turner mips64/elfload.c uses #include "../mips/elfload.c" to share code. When the compiler processes mips/elfload.c the quoted #include "target_elf.h" resolves relative to the including file's directory, so it picks up mips/target_elf.h instead of mips64/target_elf.h. mips/target_elf.h pulls in mips/target_ptrace.h, whose target_pt_regs has a pad0[6] field before regs[]. As a result elf_core_copy_regs writes: r->pt.regs[i] -> reserved[6+i] (shifted by 6 from the correct index) r->pt.cp0_epc -> reserved[40] (correct mips64 N64 index is 34) The Linux kernel and glibc both use the mips64 N64 layout (no pad0): EPC at reserved[34]. Debuggers and libunwind reading the core with N64 constants therefore see a completely wrong register set =E2=80=94 EPC point= s to GP, RA holds the branch target instead of the link address, etc. Fix by: - Guarding the mips32 elf_core_copy_regs in mips/elfload.c with #ifndef TARGET_MIPS64 so it is not compiled for mips64/mipsn32 targets. - Providing a mips64-specific elf_core_copy_regs in mips64/elfload.c that writes directly to r->reserved[i] with the correct N64 indices, bypassing the struct field names that are tainted by the wrong header include. The mipsn32 (TARGET_ABI_MIPSN32) and mips64el targets are covered by the same mips64/elfload.c and benefit from the same fix. Signed-off-by: Matt Turner Cc: qemu-stable@nongnu.org Signed-off-by: Helge Deller (cherry picked from commit dd3a906d3505561d9cb3367b82c5475acca50b6b) Signed-off-by: Michael Tokarev diff --git a/linux-user/mips/elfload.c b/linux-user/mips/elfload.c index cc5bbf05ab..1a46e180cf 100644 --- a/linux-user/mips/elfload.c +++ b/linux-user/mips/elfload.c @@ -131,6 +131,7 @@ const char *get_elf_base_platform(CPUState *cs) #undef MATCH_PLATFORM_INSN =20 /* See linux kernel: arch/mips/kernel/process.c:elf_dump_regs. */ +#ifndef TARGET_MIPS64 void elf_core_copy_regs(target_elf_gregset_t *r, const CPUMIPSState *env) { for (int i =3D 1; i < ARRAY_SIZE(env->active_tc.gpr); i++) { @@ -146,3 +147,4 @@ void elf_core_copy_regs(target_elf_gregset_t *r, const = CPUMIPSState *env) r->pt.cp0_status =3D tswapl(env->CP0_Status); r->pt.cp0_cause =3D tswapl(env->CP0_Cause); } +#endif diff --git a/linux-user/mips64/elfload.c b/linux-user/mips64/elfload.c index b719555e65..9081ae8111 100644 --- a/linux-user/mips64/elfload.c +++ b/linux-user/mips64/elfload.c @@ -1 +1,30 @@ #include "../mips/elfload.c" + +/* + * mips/elfload.c defines elf_core_copy_regs guarded by #ifndef TARGET_MIP= S64. + * + * We must provide the mips64 version here. We cannot use r->pt.regs[] be= cause + * when mips/elfload.c is #include'd above its "#include "target_elf.h"" r= esolves + * to mips/target_elf.h (compiler searches the including file's directory = first), + * which pulls in mips/target_ptrace.h. That struct has pad0[6] before re= gs[], + * so r->pt.regs[i] writes to reserved[6+i] =E2=80=94 offset by 6 from wha= t the kernel + * and glibc expect for the N64 ABI (EPC at reserved[34], not reserved[40]= ). + * + * Write directly to reserved[] using the mips64 N64 index layout: + * R0-R31 at reserved[0..31], LO at [32], HI at [33], EPC at [34]. + */ +void elf_core_copy_regs(target_elf_gregset_t *r, const CPUMIPSState *env) +{ + /* R0 is always 0; r->reserved is zero-initialised by the caller */ + for (int i =3D 1; i < 32; i++) { + r->reserved[i] =3D tswap64(env->active_tc.gpr[i]); + } + r->reserved[26] =3D 0; /* k0 */ + r->reserved[27] =3D 0; /* k1 */ + r->reserved[32] =3D tswap64(env->active_tc.LO[0]); + r->reserved[33] =3D tswap64(env->active_tc.HI[0]); + r->reserved[34] =3D tswap64(env->active_tc.PC); + r->reserved[35] =3D tswap64(env->CP0_BadVAddr); + r->reserved[36] =3D tswap64(env->CP0_Status); + r->reserved[37] =3D tswap64(env->CP0_Cause); +} --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308081; cv=none; d=zohomail.com; s=zohoarc; b=DJfv5/4JprbgcriXTaIcLIzbCWta6vlyve6p1o/wdo9bFg0q63S3MZFxMg5x4W4DX/FOCdPDwuF3mPmOF61RR0Qzn3qn9o41XYf0+wDhpP4lue+aW2/k8xvoB+dpi1Sf7brwzyzvojzWvZx4wXAh28La8U9oE+tZofqVRKIh/5o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308081; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rRd80eVCDzT4CYprjOUGBtpOF7UOLQaMHwId3i53lek=; b=nAo6oEbB5ZPWq3qg/Ww+osO1cWY8W7E4GbMpZ8DM51QrDgVPayAFQYPHSkpOUOsHeJJS4Z6ORhsf27MsD0SpssQT8gd/OSTB38J9PGbFZ56GSbncRB1uNoMMMpbSWUUlG9Y9zZwH9XBPNls6tCuR15c81p3Y+Aoe3XnHUVtkXXE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308081607349.84619738728077; Wed, 24 Jun 2026 06:34:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNkS-0008U0-2M; Wed, 24 Jun 2026 09:34:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkO-0008RE-PD; Wed, 24 Jun 2026 09:34:33 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkN-0000Ut-14; Wed, 24 Jun 2026 09:34:32 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 432691BA9C2; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D456A3DEA11; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=5LTbrdiZZKvPaIrNvB8ScBmmfWMVGkV6wGymiQXW1SQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Yb+7MnkFSy14CNzg0GRVsQZsC/Jm7SBkkk9VqJKlkwpPaMK08b3qUN9dI+4OWnETE KMT/jy0WH7P5VYyvCgKR4koW2oi7krpjzZpxtRL+JD9b4yN92kg7rU3sGsv3NXA0t7 ku2T7RjeDkePTOavQ0YrPrtsIRuvTd57gGpT9dNpV2d4toMQU0/eXDCocr+wYx6a+2 K9vOD5D2p6b6VmG0VbcLFhE3P5MgpLQ4YkFVGDBZlES4Kkp+AJwXLfUbFVVsqe4Ibi SAUWf83TyC1Ena3tXN7wn1fweep4I1iQrlpB8mNlOhEGeV0KJWIS5usog/yQeKEM2Y mBWsMzTPvhUcA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 016/107] linux-user/mips64: fix mipsn32 elf_core_copy_regs entry width Date: Wed, 24 Jun 2026 16:30:21 +0300 Message-ID: <20260624133301.403266-16-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308084586158500 From: Matt Turner For mipsn32 (TARGET_ABI32=3Dy, TARGET_LONG_BITS=3D64): abi_ulong =3D uint32_t (4 bytes) =E2=80=94 for pointers and ABI-sized fie= lds target_ulong =3D uint64_t (8 bytes) =E2=80=94 for general-purpose registe= rs linux-user/elfload.c allocates target_elf_prstatus using the mips64/target_elf.h definition where target_elf_gregset_t has target_ulong reserved[45] (8 bytes each, 360 bytes total). However, in linux-user/mips64/elfload.c, #include "target_elf.h" inside the included mips/elfload.c resolves to mips/target_elf.h (compiler searches the file's own directory first), where the union uses abi_ulong reserved[45]. For mipsn32 this gives 4-byte entries (180 bytes), not the 8-byte entries (360 bytes) that elfload.c actually allocated. Writing via r->reserved[34] therefore lands at byte offset 34*4=3D136 instead of the correct 34*8=3D272, silently zeroing the EPC in the core file. Fix by casting the pointer to target_ulong * so writes always use 8-byte slots and land at the offsets matching the allocated layout. This does not change behavior for mips64 (N64) where abi_ulong already equals target_ulong (both 8 bytes). Signed-off-by: Matt Turner Cc: qemu-stable@nongnu.org Signed-off-by: Helge Deller (cherry picked from commit 6033df08e93df313771b6637230de2d66bdc09cb) Signed-off-by: Michael Tokarev diff --git a/linux-user/mips64/elfload.c b/linux-user/mips64/elfload.c index 9081ae8111..e4d84a7bd6 100644 --- a/linux-user/mips64/elfload.c +++ b/linux-user/mips64/elfload.c @@ -15,16 +15,31 @@ */ void elf_core_copy_regs(target_elf_gregset_t *r, const CPUMIPSState *env) { - /* R0 is always 0; r->reserved is zero-initialised by the caller */ + /* + * linux-user/elfload.c allocates target_elf_prstatus using the + * definition from mips64/target_elf.h, where target_elf_gregset_t + * has target_ulong reserved[45] (8 bytes each =3D 360 bytes total). + * + * But in this compilation unit, "#include target_elf.h" resolved to + * mips/target_elf.h (wrong directory), so our local target_elf_gregse= t_t + * has abi_ulong reserved[45] which is only 4 bytes each for mipsn32. + * Using r->reserved[i] would write to the wrong offsets for mipsn32. + * + * Cast to target_ulong * to always write 8-byte entries at the correct + * positions, matching the layout that elfload.c allocated. + */ + target_ulong *regs =3D (target_ulong *)r; + + /* R0 is always 0; buffer is zero-initialised by the caller */ for (int i =3D 1; i < 32; i++) { - r->reserved[i] =3D tswap64(env->active_tc.gpr[i]); + regs[i] =3D tswap64(env->active_tc.gpr[i]); } - r->reserved[26] =3D 0; /* k0 */ - r->reserved[27] =3D 0; /* k1 */ - r->reserved[32] =3D tswap64(env->active_tc.LO[0]); - r->reserved[33] =3D tswap64(env->active_tc.HI[0]); - r->reserved[34] =3D tswap64(env->active_tc.PC); - r->reserved[35] =3D tswap64(env->CP0_BadVAddr); - r->reserved[36] =3D tswap64(env->CP0_Status); - r->reserved[37] =3D tswap64(env->CP0_Cause); + regs[26] =3D 0; /* k0 */ + regs[27] =3D 0; /* k1 */ + regs[32] =3D tswap64(env->active_tc.LO[0]); + regs[33] =3D tswap64(env->active_tc.HI[0]); + regs[34] =3D tswap64(env->active_tc.PC); + regs[35] =3D tswap64(env->CP0_BadVAddr); + regs[36] =3D tswap64(env->CP0_Status); + regs[37] =3D tswap64(env->CP0_Cause); } --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308353; cv=none; d=zohomail.com; s=zohoarc; b=do9Jm4WDSHozHCSMTFwnhMFyvS5a2F6/x7vI4/469bVhDyvER5S00Apy79T1tXliUUXNBSfFXZyV4Ml++aF0HYgbWxowJ7SXVVnyf6Tmw6HJb1PBGAt/8qlC8CuYoRiIppAcYdlmwuatij1xQaBq26BKblRKkbNd3Zb+uWcVcQ8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308353; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=klO2C5fuiH+pcM9N8CegDHYpQsR7G1+1pGiLzLuAgTU=; b=ifyylNXA10PIfs90XQ62XdIZPgZ2j6PtyPBRVzYNyxJSvTVHLRxbt6e0w/I95q4ladtbigCEQOEuuFAT2WscjLaG345N/NE1+YGeqV0XlOJ9QK0e9eJD48SMalbBRPuPJZulMUVHQFYGGm6Bb+j7nTs5aZirpTAK4bskNg0qU+Q= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308353818163.27174536880398; Wed, 24 Jun 2026 06:39:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNkV-0000Ah-N8; Wed, 24 Jun 2026 09:34:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkQ-0008Sf-Fx; Wed, 24 Jun 2026 09:34:34 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkO-0000V7-Pp; Wed, 24 Jun 2026 09:34:34 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 52EA51BA9C3; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E350D3DEA12; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=oeWCQUoPxo3Y5KEpbVvM3clq9pSKvlzk66CPh2w8/2o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=hdrvNs/ehvb0V2sEci1gVGVs4FCRmjpM1BeFKcl0u9v1RrCCvWcl4e+xddBjlBzgy zROXFw6TF+LrESe7yxiGJ/8CTrp8lNWijfoyB5CEgZU6SPAFQCIbzyR4UmJu6tq7l4 2pn7xBlbvfVy45WfMl9sa6WF+TWxUq+61C0cmlRjQa0hWN1iqnKDe94NvquxMm+IGc nTyXqx6VGKLRcdkj/6UDNLUc2ol1SmWvHvf8HUcowj9MMVIMTL4VKDebhG5/D3fOaQ yuMXhhywKwgcinDA0hjk3cp8lpkXpffzbdEdyO33gVTCIdW6iLCEiIZiiDGr1qlflj BN3e6XgYoFzoA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 017/107] ui/vnc: fix OOB read access in VNC SASL mechname array Date: Wed, 24 Jun 2026 16:30:22 +0300 Message-ID: <20260624133301.403266-17-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308354386158500 From: Daniel P. Berrang=C3=A9 When reading the SASL mechname array off the VNC connection, if malicious, the received data may contain embedded NULs. If this happens the memory buffer returned by g_strndup may be shorter than the original data. Unfortunately the code continued to index into this buffer with an offset equal to the original length. This is a potential OOB read of the array. Fixes: 5847d9e1 (ui/vnc: simplify and avoid strncpy) Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-2-berrange@redhat.com> (cherry picked from commit ae18df638fb4285c7b645f98c43f5ebc2e123a55) Signed-off-by: Michael Tokarev diff --git a/ui/vnc-auth-sasl.c b/ui/vnc-auth-sasl.c index 3f4cfc471d..9f15980fca 100644 --- a/ui/vnc-auth-sasl.c +++ b/ui/vnc-auth-sasl.c @@ -490,6 +490,8 @@ static int protocol_client_auth_sasl_mechname(VncState = *vs, uint8_t *data, size_ char *mechname =3D g_strndup((const char *) data, len); trace_vnc_auth_sasl_mech_choose(vs, mechname); =20 + /* If 'data' had embedded NUL the dup'd string might now be shorter */ + len =3D strlen(mechname); if (strncmp(vs->sasl.mechlist, mechname, len) =3D=3D 0) { if (vs->sasl.mechlist[len] !=3D '\0' && vs->sasl.mechlist[len] !=3D ',') { --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308127; cv=none; d=zohomail.com; s=zohoarc; b=M86xLKDZNosEedGgXv5ODWiaQivhFSGle2kG+PfaMB+Nil2PA7Tj+QK6x9rUMyb6ZY3fEF+zUbdOsDCpf41n2kMu93WGpbaZ+yYB9Cfg5zZ6nbNDrPzHmrCNswW8rhb5WnzxvyoKReM/wVIr0RxXKeyl9pDpI10+KzENiUhg82Y= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308127; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EhY38HvDVXyHmu318ZV4NMF/jUScLxYr7FlRgTwkWRg=; b=UoK7SCHQXXztSxO8pvXMYFFbkqASfWMY1Njw7kpHVYQnWPriKGBs/S2GLkC/lcKdW655Y3XLuzg18GBGqtsfPYXUlToQ/tFX2Sq3QyeNu+xHazq44EWJmw+i8G2UmpLt5YBMapRMNJaphxxJlmXw1dpOfG5ulxHdOrbFprsEIqI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17823081270755.659756383583613; Wed, 24 Jun 2026 06:35:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNkW-0000Bc-RY; Wed, 24 Jun 2026 09:34:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkR-0008VW-Sp; Wed, 24 Jun 2026 09:34:36 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkQ-0000Wt-B5; Wed, 24 Jun 2026 09:34:35 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 633811BA9C4; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id F35383DEA13; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=ZO2V1hRxjxtkQY97w81DzNP/KhHOgRzafHWy3erJ3rg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=KLZk1VffDlcsTvOQHD+MBL7ol206CakXSs1EgNAZBnVQjBVtjOUHWh7Ls7PlQ7X3y VDLOriROyOvpqXKEy3qdChZM+1/pySVxSUuZpqaJY9cKGvPqxfKA8fhRrI01pxMrXk kJ4PMg8JZL9PiS9D3ngHzKrLsKA41TZbrtEgz/Bcb+Pel58IWGMGqp2++6RCv4/Dhz shEoDgx3DgbifcCnSZHpF1bw7+0maMEkWCsHzSkWCaT/ewx3g1bPc2IuRfONmp8mTt FQDMQuIR4uKZTwqdRjRJFWAHYZYGdWJXqZzEAmP18DpVyCtAvj5oGeA221aehnL6mR CF/5HA43B0opw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 018/107] ui/vnc: fix OOB write in VNC stats array Date: Wed, 24 Jun 2026 16:30:23 +0300 Message-ID: <20260624133301.403266-18-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308130460158500 From: Daniel P. Berrang=C3=A9 The VncSurface struct maintains update statistics in an array: VncRectStat stats[VNC_STAT_ROWS][VNC_STAT_COLS]; where the dimensions are defined as: #define VNC_STAT_RECT 64 #define VNC_STAT_COLS (VNC_MAX_WIDTH / VNC_STAT_RECT) #define VNC_STAT_ROWS (VNC_MAX_HEIGHT / VNC_STAT_RECT) If VNC_MAX_WIDTH / VNC_MAX_HEIGHT are not an exact multiple of VNC_STAT_REC, the COLS/ROWS will be undersized by 1. Unfortunately: #define VNC_MAX_HEIGHT 2160 is not a multiple of 64, so there is potential for OOB reads and writes in the 'stats' array, if the guest surface is over 2112 pixels in height. An array overflow occurs when vnc_update_stats() records new statistics, either scribbling over data later in the VncDisplay struct that 'stats' is embedded in, or performing an OOB write on the allocated struct memory. Fixes: CVE-2026-48002 Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-3-berrange@redhat.com> (cherry picked from commit c3c6226fa48180edf9d4646d4112fb1becbc149b) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.h b/ui/vnc.h index ec8d0c91b5..ad41b418b9 100644 --- a/ui/vnc.h +++ b/ui/vnc.h @@ -92,8 +92,8 @@ typedef void VncSendHextileTile(VncState *vs, #define VNC_DIRTY_BPL(x) (sizeof((x)->dirty) / VNC_MAX_HEIGHT * BITS_PER_B= YTE) =20 #define VNC_STAT_RECT 64 -#define VNC_STAT_COLS (VNC_MAX_WIDTH / VNC_STAT_RECT) -#define VNC_STAT_ROWS (VNC_MAX_HEIGHT / VNC_STAT_RECT) +#define VNC_STAT_COLS DIV_ROUND_UP(VNC_MAX_WIDTH, VNC_STAT_RECT) +#define VNC_STAT_ROWS DIV_ROUND_UP(VNC_MAX_HEIGHT, VNC_STAT_RECT) =20 #define VNC_AUTH_CHALLENGE_SIZE 16 =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308622; cv=none; d=zohomail.com; s=zohoarc; b=iv6xH1we0DznIseXPGoEISNGgDWljHk2Gp7fkba0gF+rvOA0Mkv+ymVznfvVj2u9eqOvGjTPMKxgX8cF+cMcpZnPDg5Ha0Og/Z9V9dCjVv0LVNH1ymaBN1+TwXZseb9dwvQfengELP3zHAfbeaXwEZjnXfgdCSNqkCOATPJKzAk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308622; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GtcTReYH0pPdZNhR+J5vgPecDCjDxEA2wIYQWB4rR1c=; b=akbkD+aWsO+LHKOpFoyVlxKNuRh0HLL/C4pIpx94VV+UdO5Ray9Doh6qeMk8mNem/l0WLneqj1ekRg4sTfLKK+H1qyf8Vwau3io1aYfOODK/Sc7/oGw/JNA1CF5qWWM5cNkma0QrVoFZb+rT5eDoSCwRunn3dmysrbZX/8kswo4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308622453530.1082573689519; Wed, 24 Jun 2026 06:43:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNkY-0000JT-9q; Wed, 24 Jun 2026 09:34:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkT-00005c-Eg; Wed, 24 Jun 2026 09:34:37 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkR-0000XV-Sa; Wed, 24 Jun 2026 09:34:37 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 733F01BA9C5; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0F4563DEA14; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=lGk/OGkifKx4LKSM9herBoN6ehFZjTS6Al80zJPhBAI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=MSA/Uy49bccgyvkyyXCOakwLLo9MohGKCIFlzOkhfSzCXEZPNR+JyaHrvd4H8Ssie Cyw8NGzKpDTCtKSNSYorAMS9slngIm8LCw8DBQazNuTE8LwzInvrGPXHahmMh428m7 ZxLLNmoxVeYlLujuVAXjodRMkrpxKImBo7QMwRjYV9k6OFz+4wgd0p/PFLVQ9RcyrI HG5qcyi+CMcZ7S+dSLWX0pVUtlWinr/J9HoP+JyQ/8bdWgLu+G089DDdUTFryNGZ3O yiKJASrD7jdHD8IO7737X4gbJPrNE9R5VRkybadyQXHU5pOG5CwBS4E+/YvngCQ330 dW4NeO2vxCm1A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 019/107] ui/vnc: fix OOB write in lossy rect worker code Date: Wed, 24 Jun 2026 16:30:24 +0300 Message-ID: <20260624133301.403266-19-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308623410158500 From: Daniel P. Berrang=C3=A9 Incorrect calculation of the boundary condition when tracking lossy rectangles in the worker thread will result in an OOB write which can corrupt further worker state, and/or trigger any guard pages that may lie beyond the VncWorker struct. This can be triggered through careful choice of the display resolution in the guest OS by an unprivileged user. Fixes: CVE-2026-48002 Reported-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-4-berrange@redhat.com> [Marc-Andr=C3=A9 - added assert() suggest by philmd@linaro.org] Signed-off-by: Marc-Andr=C3=A9 Lureau (cherry picked from commit 46ee49034d26d04d95ba8f3183d4fbfa9d2b89b4) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.c b/ui/vnc.c index ccc73bd7aa..8ab44c830c 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -2994,13 +2994,15 @@ void vnc_sent_lossy_rect(VncWorker *worker, int x, = int y, int w, int h) { int i, j; =20 - w =3D (x + w) / VNC_STAT_RECT; - h =3D (y + h) / VNC_STAT_RECT; + w =3D DIV_ROUND_UP((x + w), VNC_STAT_RECT); + h =3D DIV_ROUND_UP((y + h), VNC_STAT_RECT); + assert(h <=3D VNC_STAT_ROWS); + assert(w <=3D VNC_STAT_COLS); x /=3D VNC_STAT_RECT; y /=3D VNC_STAT_RECT; =20 - for (j =3D y; j <=3D h; j++) { - for (i =3D x; i <=3D w; i++) { + for (j =3D y; j < h; j++) { + for (i =3D x; i < w; i++) { worker->lossy_rect[j][i] =3D 1; } } --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308616; cv=none; d=zohomail.com; s=zohoarc; b=V7Keid9pfILhbak8qYpSu/RDW3MUXdHpvtL0O9NNf6lQDU1Qn9NJTJS+3YtetxcE6PifWsfq4YOdaDbqtEQl91J+PqLt6/WYYZ9ttlcFV9sn1c/oC2DiIhoKd1cpaAlEQX5YHLP3ggwqo979v2fqR1zyAqey3Y3EEhpL7UCIhI0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308616; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=FijibwZ9sddXPEJQ/3kJRJfBZ6n2UfWemTLlXpeDXBQ=; b=KKsqN7lhnknzfj9/NmpAHMCzfXeu8F8CYf/vR5MO4SIB0wHS5ham8H2LFK4Cd7YR/bh+PX/vzSNxxueSmFSmIksr3V13EliG296BDcSLqDjlvDuq7caOrzQACT/hG1vPtmfHiNeIdiIlaULD18DI7B6woUndJtiy8Ifb7+NWOKk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308616951680.7193130432238; Wed, 24 Jun 2026 06:43:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNkZ-0000O6-GM; Wed, 24 Jun 2026 09:34:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkU-0000Ai-RI; Wed, 24 Jun 2026 09:34:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkT-0000Xn-AE; Wed, 24 Jun 2026 09:34:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 841E41BA9C6; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1F6E33DEA15; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=OwdSBD4V2b4+B8glKB7Gyvjax4SKaYALuDPpDERSKxU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=w+VQdKdCqlAb6XwFQqNuSrhNTHYoPbPitSCXVb5G4RHKAJSiEJL0d7PdY9jdTMkfe iENEYpbPVy1sof4g6KHUp0mU/t9JL/i6uxmXuFjjZlh16Dg7U3pHjgv4sWDYbbl/KV bQqVEDcSa8dJM4jCjpo+4tiC8mlMs+FFc52+Zryf2iG2SEpcVDWF5ufjeOhSOZIKgk WVQ+ooVXtC7Pm6RzJrWJPVCW2rfqueYN5rf4IqhXfe2wAseCTqRfx7BDIPo20PAsRO 9dzVRY7ShFjTZ/IX90JnuvdxidkN9+8GFUAWMDb9lJD87/ypZVyLoXcVMgerKn16n5 YsP8tPFGu9ReQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , boy juju , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 020/107] ui/vnc: fix OOB read updating VNC update frequency stats Date: Wed, 24 Jun 2026 16:30:25 +0300 Message-ID: <20260624133301.403266-20-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308617378158500 From: Daniel P. Berrang=C3=A9 Incorrect loop bounds in vnc_update_freq result in iterating past the last row and past the last column in the VNC stats array. With suitably chosen dimensions this could be a OOB read that accesses memory beyond the VncDisplay struct that the stats array is embedded in. Should this hit a guard page, it could trigger a guest crash. If it does not, then the VNC frequency stats will be updated with garbage. Fixes: CVE-2026-48003 Reported-by: boy juju Reviewed-by: Marc-Andr=C3=A9 Lureau Signed-off-by: Daniel P. Berrang=C3=A9 Message-ID: <20260521103353.1645561-5-berrange@redhat.com> (cherry picked from commit d0c7b82d3a89dd9c863f8aa69b07360c648ca9fb) Signed-off-by: Michael Tokarev diff --git a/ui/vnc.c b/ui/vnc.c index 8ab44c830c..1b5fc8117a 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -3105,12 +3105,14 @@ double vnc_update_freq(VncState *vs, int x, int y, = int w, int h) int i, j; double total =3D 0; int num =3D 0; + int x_end =3D x + w; + int y_end =3D y + h; =20 x =3D QEMU_ALIGN_DOWN(x, VNC_STAT_RECT); y =3D QEMU_ALIGN_DOWN(y, VNC_STAT_RECT); =20 - for (j =3D y; j <=3D y + h; j +=3D VNC_STAT_RECT) { - for (i =3D x; i <=3D x + w; i +=3D VNC_STAT_RECT) { + for (j =3D y; j < y_end; j +=3D VNC_STAT_RECT) { + for (i =3D x; i < x_end; i +=3D VNC_STAT_RECT) { total +=3D vnc_stat_rect(vs->vd, i, j)->freq; num++; } --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308207; cv=none; d=zohomail.com; s=zohoarc; b=c+IDzIwMA0FqKidzEd+hDm3krmlT2YuJUPgbMYlf+uztRSLnJUv2DFRHoHX0mIkygYYsbpW91EsKnauTuZ+2ZZGrd1Jv0seP7PcM9i/0lnjRzKfFB9B0Zjj0X/lUOk9WE08NZRBDQiJv7hnIjALq6H8vOaF2uk9L0WQfbnTWS9A= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308207; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rRgLOsAbB8mV5Z02gJ9i58QdSd5GSpfsC9YvYb5PuSc=; b=AZdYBYSr6EHNaSNFBbvO/Od+xK25at+rOTEbHwvERpH0mIhlJQPp7UcTA/Cx8su8P5k2lo4WCpx3gBOAmnsj9aaTPtCp/YDhLPzthH0ME4F4ZbraccbGK+b99FYX9URAVPi5Roym4BjNGXSql2kcePpAPFcHGqTul5O8yXHyCEs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17823082076593.4993643839293327; Wed, 24 Jun 2026 06:36:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNl0-0001fa-4X; Wed, 24 Jun 2026 09:35:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkq-0001Vn-Sf; Wed, 24 Jun 2026 09:35:02 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNko-0000Y1-U7; Wed, 24 Jun 2026 09:35:00 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 969D71BA9C7; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 308FE3DEA16; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=DJZuAd6uoTybgvHP17Px/QZ+fzo7XTUkf9sXHlZo+24=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=KyNrr26TdOZa77ZfUgdH8cKxwijSKAZ6bIJ76smkLZ0X57Fftiq8Z/CJIutW5ZQnS dMS12qUoZ+s82F2QC88aIWkGqUVsSAaj54097XbD1MlCC8IO3s4kaJ/6bDXyG5LEqv G4tbtCFF41WpAqNoUqGIjNxHQUDjktEtjl9OYe0Z0x6afT5bbXceWGATvyfiTP9Zja wG8m5+RmwSPS5MtnR0XSMIsd0kMYvwS+4Z6u5gv6fBVIvB2H8poXCHhWqF+ADU3YLE 4Uu9+Pkg8mscC7J6pQiSIcZ/YNpE5lyrz68cGS+RTy10rYAjKG0MBprYYiGMvS0Olk z1FdyRd7+xL3Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Heechan Kang , Feifan Qian , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 021/107] ui: fix validation of VNC extended clipboard data length Date: Wed, 24 Jun 2026 16:30:26 +0300 Message-ID: <20260624133301.403266-21-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308209229158500 From: Heechan Kang QEMU's VNC extended clipboard handler inflates a client-controlled compressed clipboard payload. The code checks the declared text size against the total inflated buffer size: if (tsize < size) but then copies from: tbuf =3D buf + 4; qemu_clipboard_set_data(..., tsize, tbuf, true); The correct bound is the remaining data length after the 4-byte length field, not the total inflated buffer length. As a result, a VNC client can make QEMU copy up to 3 bytes past the end of the inflated heap buffer. With a second VNC client, those copied bytes are observable through the normal VNC extended clipboard PROVIDE path. Fixes: CVE-2026-8343 Reported-by: Heechan Kang Reported-by: Feifan Qian Reviewed-by: Daniel P. Berrang=C3=A9 Signed-off-by: Heechan Kang [DB: added #include and 'return' statements] Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260512095543.459949-1-berrange@redhat.com> (cherry picked from commit e56b4bbff1df260487b80abe1f967f687fa115d3) Signed-off-by: Michael Tokarev diff --git a/ui/vnc-clipboard.c b/ui/vnc-clipboard.c index 124b6fbd9c..fa05d86f42 100644 --- a/ui/vnc-clipboard.c +++ b/ui/vnc-clipboard.c @@ -23,6 +23,7 @@ */ =20 #include "qemu/osdep.h" +#include "qemu/error-report.h" #include "vnc.h" #include "vnc-jobs.h" =20 @@ -282,10 +283,16 @@ void vnc_client_cut_text_ext(VncState *vs, int32_t le= n, uint32_t flags, uint8_t buf && size >=3D 4) { uint32_t tsize =3D read_u32(buf, 0); uint8_t *tbuf =3D buf + 4; - if (tsize < size) { + if (tsize <=3D size - 4) { qemu_clipboard_set_data(&vs->cbpeer, vs->cbinfo, QEMU_CLIPBOARD_TYPE_TEXT, tsize, tbuf, true); + } else { + error_report("vnc: malformed extended clipboard payload " + "with text length %u exceeding available %u", + tsize, size - 4); + vnc_client_error(vs); + return; } } } --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308197; cv=none; d=zohomail.com; s=zohoarc; b=I1jUM/a4OFUZNaSsXcaqkExKXWAbVYt/NCuHr/iNhVRopGSnW8uCgZlwvvirak79CDjCFBsDeMG6qohACcbbihvWbIWaOiYsso4EU+MS1M1gbLYFPdzCmo7k1mx0+DuZfEJN7EMlOX1z1bDvFzgrKqeBwtp5LnGzwJU64eGp/BM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308197; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=w+/gWzAvjdmKAbs8WgpM0WUQBmp7xUrGd+EE9pvpEyU=; b=U338woJYFonAz52IAegbvX0GmHxAwc13hvuyayi8FHB0XrM02yfGyfL/ui/90RKja2CPD8xzixynA1u6ftcbvhJxmQ2sJ5+8Usj/gqLzOdUkADC05I/yMI6i/Vi1DYfixj0HNspVD8yZBXt/AJk6lc7SPeTmI0a+AJQ//CJuNXw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308197419132.82306030804898; Wed, 24 Jun 2026 06:36:37 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNl0-0001kj-Q8; Wed, 24 Jun 2026 09:35:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNks-0001WS-4y; Wed, 24 Jun 2026 09:35:02 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkq-0000YC-FR; Wed, 24 Jun 2026 09:35:01 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A608A1BA9C8; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 42D183DEA17; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=JhsN/767JFqhwqO2AGJRt0GzEC5CwLXGBheFiPVcamw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=L8Up2zQG79RaE45dcpseIU47mOguicN3UnWsRGQoJMzRRwwPALWMdKHssW07ugfPL r1c4c1sozsw+t2V2xKkWQryqomWb8PL2wyvIRtz37Bq8Sz5TEufSHERvPPTjXqucXt 9JoBPZoUCw8UAWW38mh7hVPmxNAqLoO+r1zcKspzcIJb5qA7WsrAb3+8GS1RQzr1qA UHi6UdvkPAdv0lp/aFi7+1Zw1ebqj/w69oW0La2qYLXJqNr6cH1hADxsMG6fGGxemP 3lULxvVGmO3u6jcHhxkg/Np5WjCS0a8YKeld6vOC/hoxjFhagyujs1XFuizO1owf6F mcoTU3XmEB0Og== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Wei Che Kao , Michael Tokarev Subject: [Stable-11.0.2 022/107] lsi53c895a: fix use-after-free of cancelled request Date: Wed, 24 Jun 2026 16:30:27 +0300 Message-ID: <20260624133301.403266-22-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308198963158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini When processing the Message Out phase, the lsi53c895a controller can cancel a request and the continue by processing more messages. When this happens, it is important that a cancelled request is not processed further, because scsi_req_cancel can cause the request to be freed. Right now this is happening in two cases, but not when cancelling the entire queue of requests after an ABORT, CLEAR QUEUE or BUS DEVICE RESET message. In that case, a subsequent ABORT TAG message can use a dangling current_req. There are three possible fixes: - add a missing check inside the loop, clearing current_req if p->req =3D=3D current_req. This is obvious but complicates the code inside the foreach loop. - change the conditional prior to the loop from "if (s->current)" to "if (current_req)". This would work, because s->current !=3D NULL implies current_req !=3D NULL, and would clear current_req correctly. However it is less obvious because the point of the code is to clear the entire queue, which consists of s->current and s->queue; current_req is not special here. - delay the retrieval of current_req until an ABORT TAG message is seen. This is the most correct option, because the SCSI protocol only deals with tags; requests are a QEMU concept that only makes sense for the purpose of calling into the SCSI layer. Reported-by: Wei Che Kao Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 5297a0fc65317ba7f79ef44ce7a44e41d15fdb27) Signed-off-by: Michael Tokarev diff --git a/hw/scsi/lsi53c895a.c b/hw/scsi/lsi53c895a.c index 54123f7757..0843d325ab 100644 --- a/hw/scsi/lsi53c895a.c +++ b/hw/scsi/lsi53c895a.c @@ -1000,10 +1000,8 @@ static void lsi_do_msgout(LSIState *s) =20 if (s->current) { current_tag =3D s->current->tag; - current_req =3D s->current; } else { current_tag =3D s->select_tag; - current_req =3D lsi_find_by_tag(s, current_tag); } =20 trace_lsi_do_msgout(s->dbc); @@ -1058,9 +1056,13 @@ static void lsi_do_msgout(LSIState *s) case 0x0d: /* The ABORT TAG message clears the current I/O process only. = */ trace_lsi_do_msgout_abort(current_tag); + if (s->current) { + current_req =3D s->current; + } else { + current_req =3D lsi_find_by_tag(s, current_tag); + } if (current_req && current_req->req) { scsi_req_cancel(current_req->req); - current_req =3D NULL; } lsi_disconnect(s); break; @@ -1086,7 +1088,6 @@ static void lsi_do_msgout(LSIState *s) /* clear the current I/O process */ if (s->current) { scsi_req_cancel(s->current->req); - current_req =3D NULL; } =20 /* As the current implemented devices scsi_disk and scsi_gener= ic --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308619; cv=none; d=zohomail.com; s=zohoarc; b=abspt72gK1X+bUDBU5WNHw92Ur9CbYfyejaxdn9GizhSAqGisS1LtBJCBvg+/q3X21yL9y2//7jCALVK+mnys6g4YGHazOG5rzegMhVFrNOC2Q0KbfOawjXzZp0Xkw55nBx4qLpp9O1oyA2fMaffHWfaf9i0mOZQHrub0pm7C8Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308619; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ANOXZm6dcj30NfIvaUKISNxJr1+sXM45YqnSN7lXA2s=; b=IMIVYHmTFpyn1onqnDdJwz9DWmQHFuHpI1vFhD93lZcm0HhuUz+aQu+VHv3n/qISWqs0SJhQYVMdCH66Uwiw2ZOYYWPpBKXH3FNNTy+32MOmKu8OPoNyUowvpaI7oOXy+Zi7fx40KOA0DFs/oMVSzzafHtfQHOO8ZU5b2pUVvlg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308619241590.6935123062214; Wed, 24 Jun 2026 06:43:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNl3-000294-JY; Wed, 24 Jun 2026 09:35:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNku-0001Xs-E2; Wed, 24 Jun 2026 09:35:06 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNks-0000aZ-C2; Wed, 24 Jun 2026 09:35:03 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B3A851BA9C9; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 523C13DEA18; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=iBMovGSeLWV0hOg/lRXOTm8xcdar8YmPiwUV+GGbnlA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=QNFs0VyjVJQm4m13E62dPM0giP0tuU2fVLrBEDQXYcS/R1HPH/UBUukMkFICKqpvH sJiJecgB1/B+16tKQmFevRSCygZ99GoQjvssyFx3tihrr7P6+Lm4lpY2kBNootu8JO wPBcs2vNhiNlRQ7Tt/qYS91F8LrRKMiTQlASqZujwB6DtO/BJkR0BhHcDDSBbfYF+d 96l84SFpgYLRFgksnfHJ/FD+d9qenG7aIrxPEaIaigskkLaJky8MKDXNc05M6Ie89K FLcY9Qj/2PEt642XNDtYNfb9qbFYyKySyVtK86lp0MnyywRE+wJvls5Ec70Tl9RZKw Ci6Edb/GacfIQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 023/107] lsi53c895a: clear tag byte when processing messages Date: Wed, 24 Jun 2026 16:30:28 +0300 Message-ID: <20260624133301.403266-23-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308621385158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini Instead of simply ORing the message byte, clear what was there before. Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 4494dec8c2bfd8a5d9b1eabe4a26ab850a4f6700) Signed-off-by: Michael Tokarev diff --git a/hw/scsi/lsi53c895a.c b/hw/scsi/lsi53c895a.c index 0843d325ab..1b7f02fc7c 100644 --- a/hw/scsi/lsi53c895a.c +++ b/hw/scsi/lsi53c895a.c @@ -1041,16 +1041,19 @@ static void lsi_do_msgout(LSIState *s) } break; case 0x20: /* SIMPLE queue */ + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; trace_lsi_do_msgout_simplequeue(s->select_tag & 0xff); break; case 0x21: /* HEAD of queue */ qemu_log_mask(LOG_UNIMP, "lsi_scsi: HEAD queue not implemented= \n"); + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; break; case 0x22: /* ORDERED queue */ qemu_log_mask(LOG_UNIMP, "lsi_scsi: ORDERED queue not implemented\n"); + s->select_tag &=3D ~0xff; s->select_tag |=3D lsi_get_msgbyte(s) | LSI_TAG_VALID; break; case 0x0d: --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308328; cv=none; d=zohomail.com; s=zohoarc; b=SY8Vi8DKcRQpyrkkW0PMFcIIVlqG3FsSJzxfxteqBvzbePRIVigo4be4nPkH5waJsiOZ4KW8YbVJHK8an/aSOyiAeGCIPgdZWfUXNZkyE2xG4raXpI46O8gMzBgT3xxp5hxBoM3H7lenzsI6WCdfqn1k+oJuzFTweLve1TQAspU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308328; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ZAdl/QfKeg5j6Y7Dyo0ZcDCXuPYv2JEGheYi+zNctdg=; b=Itq58cdE/DxBGwkGPTTrThhZUCcQTte7O0es8oKq6a0lQgxLFaw52h1Bdud+nj1mW5KlUVL+SpxL7NFLlpCulu//aAGq9+9C5KwTFFPdp4zsjcKJ3oPLUX1HG7triZORhbKGT5CVKoEXLK+fXYDZU6oSFzmJgTtCs3mk7mCJw5g= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308328393857.8707018984949; Wed, 24 Jun 2026 06:38:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNl5-0002JZ-19; Wed, 24 Jun 2026 09:35:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNkw-0001bE-3Z; Wed, 24 Jun 2026 09:35:06 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNku-0000b0-FQ; Wed, 24 Jun 2026 09:35:05 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C28E91BA9CA; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 600633DEA19; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=WG1eqqDRC0XESaMjrceBdpmpNaVRXVi8x92Ta+mAlxQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=EfGWzT3I+606jrNcx5IkjA5fX6Qhs/+T2gPLuhIcEd101t8NifcrgVSgIjx+BQd79 irCcJwOp/2bpcqSesjILxvl/EujH0vmPOtUwoIi47i2k/ayRgB3l1syuPgVz/LxOzF gsr7BZu8G5elc/wvBUWdmP0aVK/oPsOPoanDNSwd1EHJJ7Uv0bgQeYuqj4kMf8Gmp1 nxnftsJUpRc2+y/xNVLpIC7g6sNeTNkKbQe4tS2GZNBdVODFa2zGB59ml2aP6HiY+a I1sv75sS3DwWeyRw6oqSaVtJZiqh0VA8KsLXmlDkeq9rSRC475sLegCmIjg6kbjwRN M/REJFW4SvFPw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Wei Che Kao , Michael Tokarev Subject: [Stable-11.0.2 024/107] apic: fix delivery bitmask with modified xAPIC ids Date: Wed, 24 Jun 2026 16:30:29 +0300 Message-ID: <20260624133301.403266-24-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308330033158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini Self-IPIs (or all-but-self IPIs) in QEMU can cause a out-of-bounds access to deliver_bitmask, because the access uses the APIC ID register which is writable by the guest. However, foreach_apic uses the delivery bitmask indexes to look up the local_apics[] array, which is indexed by *initial* APIC id. Using the right id fixes both a possible heap write overflow if the modified APIC id is too large for max_apic_words, and a mis-delivery of both self and all-but-self IPIs. Reported-by: Wei Che Kao Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 153dc2fa7bbe0491290d22c4bbb6807074f24260) Signed-off-by: Michael Tokarev diff --git a/hw/intc/apic.c b/hw/intc/apic.c index 8766ed00b9..ced7df49bd 100644 --- a/hw/intc/apic.c +++ b/hw/intc/apic.c @@ -648,13 +648,6 @@ static void apic_deliver(APICCommonState *s, uint32_t = dest, uint8_t dest_mode, APICCommonState *apic_iter; uint32_t deliver_bitmask_size =3D max_apic_words * sizeof(uint32_t); g_autofree uint32_t *deliver_bitmask =3D g_new(uint32_t, max_apic_word= s); - uint32_t current_apic_id; - - if (is_x2apic_mode(s)) { - current_apic_id =3D s->initial_apic_id; - } else { - current_apic_id =3D s->id; - } =20 switch (dest_shorthand) { case 0: @@ -662,14 +655,20 @@ static void apic_deliver(APICCommonState *s, uint32_t= dest, uint8_t dest_mode, break; case 1: memset(deliver_bitmask, 0x00, deliver_bitmask_size); - apic_set_bit(deliver_bitmask, current_apic_id); + /* + * The self and all-but-self cases do not use apic_match_dest() and + * directly fill in deliver_bitmask; the bitmask's indexes in turn + * map to local_apics[] slots which are never changed even if the + * xAPIC id is modified. So use s->initial_apic_id instead of s->= id. + */ + apic_set_bit(deliver_bitmask, s->initial_apic_id); break; case 2: memset(deliver_bitmask, 0xff, deliver_bitmask_size); break; case 3: memset(deliver_bitmask, 0xff, deliver_bitmask_size); - apic_reset_bit(deliver_bitmask, current_apic_id); + apic_reset_bit(deliver_bitmask, s->initial_apic_id); break; } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308219; cv=none; d=zohomail.com; s=zohoarc; b=Xt8Q4MqK2Z+/83gw1TTDcGTrfwvFh3VqdqIWuu42/3F07Yq0qeQZpIyYZo2GrqyPTKqGnk5/llY3u/BQY7tGOyTMuepcl3vEWTWOS2uPsGdCHVeyyn3nQ9PYXhduH0MUNEbzZkZNIFsUboY1707QarFUei+Y4t+elxSRcqOQFjw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308219; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=iE/rb4A2p1obU9jOkJvmuimN87umjPB5QwmSmlR5AfY=; b=Q8+0gN7pAXAUq2ReU5giP8BEgXOJsA3IGgxwroQWUxQiK7eGXFzZXK1n4TJmdfxW2U8IAQ1CuORksNUP8rq0qwsUsJySd80pY5Ap6PQqG8hoVNfnowW2mOfirae6AvaKLxh1U4hUBeIq4tNw0zMGGbsp+IuDjx0UCCPx7WUVrQ4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308219855768.4045734887741; Wed, 24 Jun 2026 06:36:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNlJ-0003L1-4b; Wed, 24 Jun 2026 09:35:29 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlH-0003KO-R8; Wed, 24 Jun 2026 09:35:27 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlF-0000mD-V6; Wed, 24 Jun 2026 09:35:27 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D15FE1BA9CB; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6E6D93DEA1A; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=qo7CUVoBJT6J/Xn9BS8biH/2dl+pou5Ie/pG+aXu1z8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=W8b2VkbqLe75vnHqAhyIwUFo3DP7Fv4x20w5faKqrlf784gU6zTF1rSpkF6BE0sYF pGLhuFqynwoB6GLUSwQTHMeLz7dZ8YW5Xd4CxRH/UYz+1GLYd6zRo179AFPXAy/Oul AGiSxfYcw7Ts1+1C+9WTsziUnHsSqvupkIJIZqtnvWqGEUdoEQuQ9VB3JYFnbl2+gD 2yJvB3mR7Xx1D0aSAWEJV65/Sm/oiwng2rHJ3oxBbh7dqxUhJUatzq4RjZZa42zCK0 dVSnpiwoeSnHci41ZY+w8BuFc9AWU1flMV2SammflaAnX35xHDtIKMPciZvaLZvAUQ 1rr04crKIiXBw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Jinjie Ruan , Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 025/107] mc146818rtc: Fix get_guest_rtc_ns() overflow bug Date: Wed, 24 Jun 2026 16:30:30 +0300 Message-ID: <20260624133301.403266-25-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308221343158500 Content-Type: text/plain; charset="utf-8" From: Jinjie Ruan In get_guest_rtc_ns(), "s->base_rtc" is uint64_t, which multiplied by "NANOSECONDS_PER_SECOND" may overflow the uint64_t type, which will cause the QEMU Linux Virtual Machine's RTC time to jump and in turn triggers a kernel Soft Lockup and ultimately leads to a crash. Fix it by avoiding adding s->base_rtc in get_guest_rtc_ns_offset(), because get_guest_rtc_ns() is used either take the remainder of NANOSECONDS_PER_SECOND or take the quotient of NANOSECONDS_PER_SECOND. Fixes: 56038ef6234e ("RTC: Update the RTC clock only when reading it") Signed-off-by: Jinjie Ruan Link: https://lore.kernel.org/r/20260114013257.3500578-1-ruanjinjie@huawei.= com Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini (cherry picked from commit 4b6c088c88ccc9e7cafc72759c99742b3993f9f7) Signed-off-by: Michael Tokarev diff --git a/hw/rtc/mc146818rtc.c b/hw/rtc/mc146818rtc.c index ccbb279716..bcab018c7c 100644 --- a/hw/rtc/mc146818rtc.c +++ b/hw/rtc/mc146818rtc.c @@ -77,12 +77,13 @@ static inline bool rtc_running(MC146818RtcState *s) (s->cmos_data[RTC_REG_A] & 0x70) <=3D 0x20); } =20 -static uint64_t get_guest_rtc_ns(MC146818RtcState *s) +/* + * Note: get_rtc_ns_since_last_update() does not include the base_rtc seco= nds + * value. This does not matter if the caller only needs the nanoseconds p= art. + */ +static uint64_t get_rtc_ns_since_last_update(MC146818RtcState *s) { - uint64_t guest_clock =3D qemu_clock_get_ns(rtc_clock); - - return s->base_rtc * NANOSECONDS_PER_SECOND + - guest_clock - s->last_update + s->offset; + return qemu_clock_get_ns(rtc_clock) - s->last_update + s->offset; } =20 static void rtc_coalesced_timer_update(MC146818RtcState *s) @@ -258,7 +259,7 @@ static void check_update_timer(MC146818RtcState *s) return; } =20 - guest_nsec =3D get_guest_rtc_ns(s) % NANOSECONDS_PER_SECOND; + guest_nsec =3D get_rtc_ns_since_last_update(s) % NANOSECONDS_PER_SECON= D; next_update_time =3D qemu_clock_get_ns(rtc_clock) + NANOSECONDS_PER_SECOND - guest_nsec; =20 @@ -510,7 +511,7 @@ static void cmos_ioport_write(void *opaque, hwaddr addr, /* if disabling set mode, update the time */ if ((s->cmos_data[RTC_REG_B] & REG_B_SET) && (s->cmos_data[RTC_REG_A] & 0x70) <=3D 0x20) { - s->offset =3D get_guest_rtc_ns(s) % NANOSECONDS_PER_SE= COND; + s->offset =3D get_rtc_ns_since_last_update(s) % NANOSE= CONDS_PER_SECOND; rtc_set_time(s); } } @@ -623,10 +624,8 @@ static void rtc_update_time(MC146818RtcState *s) { struct tm ret; time_t guest_sec; - int64_t guest_nsec; =20 - guest_nsec =3D get_guest_rtc_ns(s); - guest_sec =3D guest_nsec / NANOSECONDS_PER_SECOND; + guest_sec =3D s->base_rtc + get_rtc_ns_since_last_update(s) / NANOSECO= NDS_PER_SECOND; gmtime_r(&guest_sec, &ret); =20 /* Is SET flag of Register B disabled? */ @@ -637,7 +636,7 @@ static void rtc_update_time(MC146818RtcState *s) =20 static int update_in_progress(MC146818RtcState *s) { - int64_t guest_nsec; + uint64_t guest_nsec; =20 if (!rtc_running(s)) { return 0; @@ -652,7 +651,7 @@ static int update_in_progress(MC146818RtcState *s) } } =20 - guest_nsec =3D get_guest_rtc_ns(s); + guest_nsec =3D get_rtc_ns_since_last_update(s); /* UIP bit will be set at last 244us of every second. */ if ((guest_nsec % NANOSECONDS_PER_SECOND) >=3D (NANOSECONDS_PER_SECOND - UIP_HOLD_LENGTH)) { --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308859; cv=none; d=zohomail.com; s=zohoarc; b=DHJLoBg7gPfuFvQkf4k0Pw+5jnhI1JmQ27XOv1MK5ZPQhGUqfnQV7vvmZE+IRT9AppIdE1HtSOv7Nnbj1A/noDVXAhkrjxtCxF+Hfe+c9NKmoecTInoT8sdplRhu385tqyb0VC7uq7jPYACMJporAUCgEjLX//XTAopd4eUyd2w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308859; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tucsnmonG+4p1u7XFQ0gQ/y4jJpFlnWJXSkr/KOwnPI=; b=NijKDst/lJsYjK/FMQFOjn2XWteTW4jTuy0pQEV7cukKTlBDwpYmPoQdkeu+1qGeCzmZJRUO9ri7wbFJ9hKrDSEmH7kf0b5W9Rye+M0Rn7gsc+APTvJ9ygj4O3aKlKBkjFP69p3dV0VH1wGR6GGEOmjrvUNs5E9ndzKf3I4Mzic= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308859222608.3145100466221; Wed, 24 Jun 2026 06:47:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNlL-0003Mz-30; Wed, 24 Jun 2026 09:35:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlJ-0003Lp-G2; Wed, 24 Jun 2026 09:35:29 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlH-0000n1-OA; Wed, 24 Jun 2026 09:35:29 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E5F101BA9CC; Wed, 24 Jun 2026 16:33:16 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7E1093DEA1B; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307996; bh=Y5IXrWGf9fd6lqmrWDpBY6sNZwdv47Q9g5caZWHM55s=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=UH9x9jN6YdejMFSpB3kVpl4R7FlI4fh8Rb+/OMWQYleK5oDtpXx+Nuwm5aDQY8r48 ZHFvQGCbRczcNyR5loT/mTzr/k5C+Y7/6c1wv5NtVHNRkXcVzByxeb8qlhlRA7OrUb fq4HJ5L3kGfjwErKBuEIqCOCtINeHHpkmtGeS4EuuoHgOri9a+uRi3hpFpw0ZyYrey 4el/XcHQl24bKCUMPguvf1WeAOQSejls0sMSj/VTCVKdGQSQF03ISEIctKCN9vZeVP uIeZaAQcpXDibfKbL93qUKAJ/VD8CCKAgqv37O60xi1l0hTTYS5nOPJTdfwqba8q4L tTbHn/gouPDHQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Kevin Wolf , Hanna Reitz , Stefan Hajnoczi , Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 026/107] block/linux-aio: bound ioq_submit() recursion depth Date: Wed, 24 Jun 2026 16:30:31 +0300 Message-ID: <20260624133301.403266-26-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308859396158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" qemu_laio_process_completions() wraps its body in defer_call_begin / defer_call_end. Inside the section, completion callbacks wake coroutines that queue new aiocbs; laio_do_submit() defers laio_deferred_fn. At the bottom of qemu_laio_process_completions() the defer_call_end() fires laio_deferred_fn, which calls ioq_submit(), closing the cycle: ioq_submit -> io_submit(2) // some sync completions -> qemu_laio_process_completions // defer_call_begin -> aio_co_wake // resumes coroutine -> laio_do_submit -> defer_call(laio_deferred_fn, s) // enqueued -> defer_call_end // nesting drops to 0 -> laio_deferred_fn -> ioq_submit // +1 stack frame, loop When io_submit(2) returns asynchronously (O_DIRECT) the cycle terminates in one extra frame: the fresh aiocb is still in flight, no completion is drained, no coroutine wakes, no new submission queues. When submissions complete synchronously (non-O_DIRECT, or per-descriptor drivers such as vmdk) each level enqueues more work for the next defer_call_end() to drain, so recursion grows without bound and QEMU crashes with SIGSEGV on the thread guard page. The cycle was closed by two performance commits, each correct in isolation: 076682885d ("block/linux-aio: convert to blk_io_plug_call() API") -- introduced laio_deferred_fn and wired laio_do_submit -> defer_call(laio_deferred_fn, s). 84d61e5f36 ("virtio: use defer_call() in virtio_irqfd_notify()") -- added defer_call_begin/end around qemu_laio_process_completions so virtio-irqfd notifications batch across a completion pass. The supported aio=3Dnative + cache=3Dnone pairing keeps submissions asynchronous, so the cycle stays bounded; nothing in the code enforces that contract. Observed in production as a SIGSEGV during a backup job configured with --cached + aio=3Dnative; reproducible on upstream with qemu-io against vmdk. Cap ioq_submit() recursion with a counter on LaioQueue, which is only accessed from the AioContext home thread. On overflow, return without submitting. The pending work is drained by s->completion_bh, which qemu_laio_process_completions() has already scheduled on entry -- no work is lost; one event-loop round-trip of latency is paid only when the bound is hit, which cannot happen on a supported configuration. Signed-off-by: Denis V. Lunev CC: Kevin Wolf CC: Hanna Reitz CC: Stefan Hajnoczi CC: Paolo Bonzini Message-ID: <20260520142503.251959-2-den@openvz.org> Signed-off-by: Stefan Hajnoczi (cherry picked from commit 6864bec553b2e37699739615e604fc3c7bae0e1d) Signed-off-by: Michael Tokarev diff --git a/block/linux-aio.c b/block/linux-aio.c index 0a7424fbb3..5aaf2e8514 100644 --- a/block/linux-aio.c +++ b/block/linux-aio.c @@ -36,6 +36,19 @@ /* Maximum number of requests in a batch. (default value) */ #define DEFAULT_MAX_BATCH 32 =20 +/* + * Bound on how deep ioq_submit() may recurse on a single LaioQueue via the + * ioq_submit -> qemu_laio_process_completions -> defer_call_end -> + * laio_deferred_fn -> ioq_submit cycle. The cycle terminates naturally + * when io_submit(2) returns asynchronously (O_DIRECT), but can grow + * without bound when submissions complete synchronously. On overflow + * the caller returns without submitting; the outermost + * qemu_laio_process_completions() has already scheduled s->completion_bh + * (via qemu_bh_schedule() at the top of that function), which resumes + * submission from the next event-loop dispatch. + */ +#define IOQ_SUBMIT_MAX_DEPTH 8 + struct qemu_laiocb { Coroutine *co; LinuxAioState *ctx; @@ -61,6 +74,7 @@ typedef struct { unsigned int in_queue; unsigned int in_flight; bool blocked; + unsigned int submit_depth; QSIMPLEQ_HEAD(, qemu_laiocb) pending; } LaioQueue; =20 @@ -331,6 +345,7 @@ static void ioq_init(LaioQueue *io_q) io_q->in_queue =3D 0; io_q->in_flight =3D 0; io_q->blocked =3D false; + io_q->submit_depth =3D 0; } =20 static void ioq_submit(LinuxAioState *s) @@ -340,6 +355,11 @@ static void ioq_submit(LinuxAioState *s) QEMU_UNINITIALIZED struct iocb *iocbs[MAX_EVENTS]; QSIMPLEQ_HEAD(, qemu_laiocb) completed; =20 + if (s->io_q.submit_depth >=3D IOQ_SUBMIT_MAX_DEPTH) { + return; + } + s->io_q.submit_depth++; + do { if (s->io_q.in_flight >=3D MAX_EVENTS) { break; @@ -385,6 +405,8 @@ static void ioq_submit(LinuxAioState *s) * pended requests will be submitted from there. */ } + + s->io_q.submit_depth--; } =20 static uint64_t laio_max_batch(LinuxAioState *s, uint64_t dev_max_batch) --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308234; cv=none; d=zohomail.com; s=zohoarc; b=ewtTPmpSVNECZpWf+9bfqLmD0iiZ/FGBgmoAzQ6dttzQbbMXEChUloJYclkZBN9wjUVXNkqwXyaxHfDpS7Dshwxle1CoJhGNMPoY60wx/2dpnbRsi6BNb8Bf4ifpKEvLUmz6ATWGJiS1Stn8JSNPWbrW8wksfOb+CllwrbQ96D8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308234; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=I20BjNk0as2dvmlR7BaHdkTzikRUg0imDQdmZn7Dnts=; b=mNNSkPYLpQRYv6wrln6+8aUsh/DQqmXLvpJpvbScskHSW2t4hrkaW3/STMaAJOSkrvKZ1kmjOGrMFzxRpxe2zQCGuUNoEBkb4+NvPvjZyK8LvHe8dV/Rw/7hNzlBfvvQQGBy3b6bec8NLcea8nrl0CUAR3CveHAThFAV4WO8GGk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308234374165.63839451529452; Wed, 24 Jun 2026 06:37:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNlM-0003SV-Fn; Wed, 24 Jun 2026 09:35:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlK-0003Mv-Sg; Wed, 24 Jun 2026 09:35:30 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlJ-0000p7-8q; Wed, 24 Jun 2026 09:35:30 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 014761BA9CD; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9275E3DEA1C; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=WoDzbd+bsFS1hjb4l+NXgUrDQ81yYUUXj+/8Gg3rZ10=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=c2BaL8V+d+UqCd5UHwMSfeEXaLs/8A3A91Vx6PZ41dYWkfhytGjCiqrk0KASN2sxO caRl0UOGZcDCbZUgtq3qH5J1yVK+ZfYPdw4Dfy158aMyYZJC8iJfW1YTKD2Nc1nKkn G68LGBIXhxUGrNImuWtWSTJhzKIti1aqnzxDs6Y+886Ut6t3RKWWwIKf2RYsc5VZ80 8/qlKFaMA4I83Q/Bg7RjP9n8N8eyE6/h97ZGqtUh2ffp0LklbRUjBYQLoa2ghfzR2D F0R20m8z+z5QAjjJxKRWpiUcBCbPoNaDwEngiN1fuTru/GGXH8EllliUF1iKSLifq4 DmtJdl/5hsQTg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Michael Tokarev Subject: [Stable-11.0.2 027/107] target/arm: SVE2 FMAXP, FMINP must honour AH=1 Date: Wed, 24 Jun 2026 16:30:32 +0300 Message-ID: <20260624133301.403266-27-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308235236158500 From: Peter Maydell The behaviour of floating-point maximum and minimum insns has some odd special cases when FPCR.AH=3D1. We get this right in most places (for instance, the ASIMD FMAXP, FMINP) but forgot about it for the SVE2 versions of FMAXP and FMINP. Cc: qemu-stable@nongnu.org Fixes: 384433e70983 ("target/arm: Implement FPCR.AH semantics for FMINP and= FMAXP") Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Message-id: 20260521122913.1565011-2-peter.maydell@linaro.org (cherry picked from commit 446050c4dfe4566ae3fcba9c6588c89a66ed4b33) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/helper-sve-defs.h b/target/arm/tcg/helper-sve-d= efs.h index c3541a8ca8..cd05dd0fb4 100644 --- a/target/arm/tcg/helper-sve-defs.h +++ b/target/arm/tcg/helper-sve-defs.h @@ -2914,6 +2914,20 @@ DEF_HELPER_FLAGS_6(sve2_fminp_zpzz_s, TCG_CALL_NO_RW= G, DEF_HELPER_FLAGS_6(sve2_fminp_zpzz_d, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, fpst, i32) =20 +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_h, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_s, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fmaxp_zpzz_d, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) + +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_h, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_s, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) +DEF_HELPER_FLAGS_6(sve2_ah_fminp_zpzz_d, TCG_CALL_NO_RWG, + void, ptr, ptr, ptr, ptr, fpst, i32) + DEF_HELPER_FLAGS_5(sve2_eor3, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, i= 32) DEF_HELPER_FLAGS_5(sve2_bcax, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, i= 32) DEF_HELPER_FLAGS_5(sve2_bsl1n, TCG_CALL_NO_RWG, void, ptr, ptr, ptr, ptr, = i32) diff --git a/target/arm/tcg/sve_helper.c b/target/arm/tcg/sve_helper.c index 062d8881bd..179cbd74fb 100644 --- a/target/arm/tcg/sve_helper.c +++ b/target/arm/tcg/sve_helper.c @@ -778,6 +778,14 @@ DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_h, float16, H1_2, floa= t16_min) DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_s, float32, H1_4, float32_min) DO_ZPZZ_PAIR_FP(sve2_fminp_zpzz_d, float64, H1_8, float64_min) =20 +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_h, float16, H1_2, helper_vfp_ah_maxh) +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_s, float32, H1_4, helper_vfp_ah_maxs) +DO_ZPZZ_PAIR_FP(sve2_ah_fmaxp_zpzz_d, float64, H1_8, helper_vfp_ah_maxd) + +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_h, float16, H1_2, helper_vfp_ah_minh) +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_s, float32, H1_4, helper_vfp_ah_mins) +DO_ZPZZ_PAIR_FP(sve2_ah_fminp_zpzz_d, float64, H1_8, helper_vfp_ah_mind) + #undef DO_ZPZZ_PAIR_FP =20 /* Three-operand expander, controlled by a predicate, in which the diff --git a/target/arm/tcg/translate-sve.c b/target/arm/tcg/translate-sve.c index 5bace3fda1..6a5c508743 100644 --- a/target/arm/tcg/translate-sve.c +++ b/target/arm/tcg/translate-sve.c @@ -7666,8 +7666,8 @@ TRANS_FEAT_NONSTREAMING(HISTSEG, aa64_sve2, gen_gvec_= ool_arg_zzz, DO_ZPZZ_FP(FADDP, aa64_sme_or_sve2, sve2_faddp_zpzz) DO_ZPZZ_FP(FMAXNMP, aa64_sme_or_sve2, sve2_fmaxnmp_zpzz) DO_ZPZZ_FP(FMINNMP, aa64_sme_or_sve2, sve2_fminnmp_zpzz) -DO_ZPZZ_FP(FMAXP, aa64_sme_or_sve2, sve2_fmaxp_zpzz) -DO_ZPZZ_FP(FMINP, aa64_sme_or_sve2, sve2_fminp_zpzz) +DO_ZPZZ_AH_FP(FMAXP, aa64_sme_or_sve2, sve2_fmaxp_zpzz, sve2_ah_fmaxp_zpzz) +DO_ZPZZ_AH_FP(FMINP, aa64_sme_or_sve2, sve2_fminp_zpzz, sve2_ah_fminp_zpzz) =20 static bool do_fmmla(DisasContext *s, arg_rrrr_esz *a, gen_helper_gvec_4_ptr *fn) --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308195; cv=none; d=zohomail.com; s=zohoarc; b=ZBgqREOQMBJ5guSckilu8fW4b/XcKGPh8I49ZvFYn0vkhasRPYXrL2HzIKRFPe9piRoRNZSMOwvPAddY3aD7I3mxedLZM9T0MZO1U7gb8uU9xflle/O7wpfz7fG0r4C5tQ8CgGsO/CQLUKovPcn44KrSP8lq0KqIw3KeNSvJ5wU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308195; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=viX3VZjmyK2dGm+2YqBvE8L+Q3aCxw0L4v8u38lPCBg=; b=Kr6YWEp5rzQBFijZABDtmm+D7+pz/3OdoMyHAUcnwfYstuG3dLtDXtE4xqTwVw/LMV2Q3quakmKofR+metZjPa2GMUQIxROyXRad4NeMafvDTrq0N9vf0ElF6VpDr10nQpSiTm8RXeywgFHA+l0NtD6zYAdwqQYZeclwal/0x+0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308195273598.4933095131491; Wed, 24 Jun 2026 06:36:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNlQ-0003bD-GW; Wed, 24 Jun 2026 09:35:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlM-0003TK-HM; Wed, 24 Jun 2026 09:35:32 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlK-0000pS-Tk; Wed, 24 Jun 2026 09:35:32 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 11DD91BA9CE; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id A136D3DEA1D; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=6xlNGyXQ+fCOU4K82Yr9pLl9TrVrEkNSH6c86ZKUM2U=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=YlM15+CLRoelmgiKLe4KVgKOlBa0TLegkOwIHuPk/cDED0TONcI6gtXCKu8IXIhL7 uklltNMIYTVnTl50t+oqnD4EnJ01BYj6jsXs/i/hrk3QF6BOJdYT67x8zKcWXKhZoi BTKpUJuj0Ccq6ywlQKDwjmJr2upnSbKtwFfM2866IomUMX+qRWkj9UhZwYXdW1teAt 0pxHH9b1nSsdNIUL7eTNWnNPj1YSbf160BPgaRQXPpfTmPq2VSjF5kpxBZ5gbiSk6M WRQxhobUyk4mlI+3vHrF+6k9Oc7STxI79LW3kCl1+xXY4c8qE76AmvQCthvj7zImB+ QmiO9aj89IxEg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Richard Henderson , Michael Tokarev Subject: [Stable-11.0.2 028/107] target/arm: Use FPST_A64_F16 for SVE FCVTLT_hs Date: Wed, 24 Jun 2026 16:30:33 +0300 Message-ID: <20260624133301.403266-28-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308196939158500 From: Peter Maydell We should be using the F16-specific float_status for conversions from half-precision, because halfprec inputs never set Input Denormal. If we use the FPST_A64 fpstatus then we will incorrectly set FPCR.IDC for input-denormals when FPCR.AH=3D1. In commit e07b48995aaa we updated most of the halfprec-to-other conversion insns to use FPST_A64_F16 as part of implementing FEAT_AHP. However we missed the SVE FCVTLT instruction, which has a halfprec-to-single encoding. Correct the FPST we use for the hs variant of FCVTLT. Cc: qemu-stable@nongnu.org Fixes: e07b48995aaa ("target/arm: Use FPST_A64_F16 for halfprec-to-other co= nversions")a Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Reviewed-by: Richard Henderson Message-id: 20260521122913.1565011-3-peter.maydell@linaro.org (cherry picked from commit aa42300f86d172d7252f0cb95c2efd7570ad6b8f) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/translate-sve.c b/target/arm/tcg/translate-sve.c index 6a5c508743..f9dfda4a7a 100644 --- a/target/arm/tcg/translate-sve.c +++ b/target/arm/tcg/translate-sve.c @@ -7826,7 +7826,7 @@ TRANS_FEAT(BFCVTNT, aa64_sme_sve_bf16, gen_gvec_fpst_= arg_zpz, s->fpcr_ah ? FPST_AH : FPST_A64) =20 TRANS_FEAT(FCVTLT_hs, aa64_sme_or_sve2, gen_gvec_fpst_arg_zpz, - gen_helper_sve2_fcvtlt_hs, a, 0, FPST_A64) + gen_helper_sve2_fcvtlt_hs, a, 0, FPST_A64_F16) TRANS_FEAT(FCVTLT_sd, aa64_sme_or_sve2, gen_gvec_fpst_arg_zpz, gen_helper_sve2_fcvtlt_sd, a, 0, FPST_A64) =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308349; cv=none; d=zohomail.com; s=zohoarc; b=A3hdS6usewMepYAM0AGEI3Q4UdV3u3UyxIBhBjzmdHR+Zsw4DB21LMs2gf3ZwEDgqEsFPojm5oTRKKOJuEPJdaCov91dWZnI1Rz+fwi15bF5VWzE/Fzq46rYU82I+Pi8Fe8JQYjMcEY6K8JNhsu/LWSj/6tqU0P7OpNyFTUwIb0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308349; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=DjfV00XFRXfJt/kXP0vZG960O91CPxE3rgMrmDhS2VQ=; b=k5LMTgVhuKAmxHf1EZfNtxCYuGys2zL04zKN3aJU1/HcXARfKrGbZ60+rGpe5dGkmdMwSC1KpAbWdhNudKU6KOS/41lhWBPXEu12AfAnTwvTatYIGtqjqa5kqR34dsu8K+qKTaYv9U7DKzxyJYiOt0f1mNzMO2Wmo/tbS/3f+Lw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308349784798.8129000012367; Wed, 24 Jun 2026 06:39:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNlT-0003oA-AR; Wed, 24 Jun 2026 09:35:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlN-0003Zk-Tr; Wed, 24 Jun 2026 09:35:34 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlM-0000pq-BY; Wed, 24 Jun 2026 09:35:33 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 230B51BA9CF; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B2C2E3DEA1E; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=avXEFBMXyDcCefkdmfwuGAjiUyl870djlo++1qvZzJI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=jztRKFimmbAYIJ5jP6OWiW4dF59pPTNN+GgS6Whv2897xYVA1k/qO+XK9T4FMefdh ZxO36ajUIYzdgyxfvcDxgJU2FiiRBa6fbJudb1eD6iyvHeDJpgrctqRSohJi5zUcHu 8gh0MW6c6c/jUYmUV0S8sID12pnu9wOS6oGwMZAAylfw2AUOEcIW1mlgHZR+TvOXFs forlIfx/jFD0ymW8DlxHYajDtc+E/q3vDB8QuMMdodhqEKxIiSWNOV4AamPVASZPNe G4LmQfBAtlO0I5gMKMpMjHIAdsZElVDCaPKpoAzLHovQX3pNtsv2oNECwT76K1dksR xSQf49/cg7mUA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Richard Henderson , Michael Tokarev Subject: [Stable-11.0.2 029/107] target/arm: Set correct fp flags for FLOGB when FPCR.AH = 1 Date: Wed, 24 Jun 2026 16:30:34 +0300 Message-ID: <20260624133301.403266-29-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308350177158500 From: Peter Maydell Our implementation of the FLOGB insn does the operations entirely in the helper function, without needing to use fpu functions. This means it needs to handle all the fp status flags itself. We aren't setting float_flag_input_denormal_used when we use (i.e. do not flush to zero) an input denormal, which means that FPCR.IDC isn't set when it should be for FPCR.AH=3D1. We missed this when we added float_flag_input_denormal_used and made the fpu/ code set it. Add the missing float_raise(). Cc: qemu-stable@nongnu.org Fixes: d38a57a3f ("target/arm: Enable FEAT_AFP for '-cpu max'") Signed-off-by: Peter Maydell Reviewed-by: Alex Benn=C3=A9e Reviewed-by: Richard Henderson Message-id: 20260521122913.1565011-4-peter.maydell@linaro.org (cherry picked from commit 23ece2805f9a3f90f317aac1b49ee45783b57636) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/sve_helper.c b/target/arm/tcg/sve_helper.c index 179cbd74fb..d884ba474f 100644 --- a/target/arm/tcg/sve_helper.c +++ b/target/arm/tcg/sve_helper.c @@ -5036,6 +5036,7 @@ static int16_t do_float16_logb_as_int(float16 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -15 - clz32(frac); } /* flush to zero */ @@ -5064,6 +5065,7 @@ static int32_t do_float32_logb_as_int(float32 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -127 - clz32(frac); } /* flush to zero */ @@ -5092,6 +5094,7 @@ static int64_t do_float64_logb_as_int(float64 a, floa= t_status *s) if (frac !=3D 0) { if (!get_flush_inputs_to_zero(s)) { /* denormal: bias - fractional_zeros */ + float_raise(float_flag_input_denormal_used, s); return -1023 - clz64(frac); } /* flush to zero */ --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308263; cv=none; d=zohomail.com; s=zohoarc; b=nUl3PWrMDALaNzs915OsOzHTCpTgvJz/CpYGTEiSkJXvO6sYhT6T+IV/7Iqto4cKiHDSIsGANw7sbwqHq7ofh/6/KFH2wym1UkO9WhCcPdNw/T1LIcccTS0mvaBfuk9qx8FHXi5zkcULSE2vuls8QE8iab11GqWAD5yh0YYtibA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308263; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=uapO9DdXwnSiugjn6O/aiMQq7i0kYYrNusBjgwHE83M=; b=eMEcloR76fWGslluS4gEyRQUAYRF1/iMCKSpMgQJKEh7wzlJLHG3Uea4iLJ4US2dO9VdwNdEak3Qpqn0KG3H0MwEruUwNrJr9w/XrTl3gZPGqdhNX47cGlXif6kP4TVriHlQ3ytArF0BDduY+cOnfFEXbXwVTBHdpis+YRHnlLU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308263522647.2072392837105; Wed, 24 Jun 2026 06:37:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNls-0004bs-KN; Wed, 24 Jun 2026 09:36:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNll-0004GO-5v; Wed, 24 Jun 2026 09:36:00 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlh-0000qB-Vz; Wed, 24 Jun 2026 09:35:56 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 3407E1BA9D0; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C36CA3DEA1F; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=rWeJQo1BZj3/v/6iAk7Qi6eblFf1sDgGtXlKWB4QA7Y=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=XVp1eMBxHZ9OnYCD/8H8hmnpA4MeWUrmW5kesGk5Ypp0tigjTPUBwXXsUa2tJzvKD IREvQKGXDOaBAW55dbEouybYMCC2Pdaz9ZUXEGJoq/+ZxjBt8ZbUhDT2T8nWeNpFIg R/iDcGlX6E2qJrAsItC7vIr5wIbph0jWtgxf2lc1l+R3stkIIjxx67Yk1eU9SQ3YWH hlQsqruVE5cT70cCAJQ8bA3ZoD9Se3QP4PRoT0X9zM5mdXBR7QNAiQn4q0f5SuNjhc oIstZVStWCcg6Smnlz0ZPIhQeilDxvBCoO8VEVJHlZ4Gadpv0wTVT4/pMd0Q+WAJs4 Jo/nxIZI1miSA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, GuoHan Zhao , John Levon , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Michael Tokarev Subject: [Stable-11.0.2 030/107] vfio-user: reject zero DMA page size capability Date: Wed, 24 Jun 2026 16:30:35 +0300 Message-ID: <20260624133301.403266-30-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308265689158500 From: GuoHan Zhao check_pgsizes() validates that no page-size bits smaller than VFIO_USER_DEF_PGSIZE are set, but it still accepts pgsizes=3D0. This lets a malformed server overwrite the default page-size mask with zero. Later vfio_user_setup() asserts that proxy->dma_pgsizes is non-zero, so dev= ice realization aborts instead of reporting a version capability error. Reject a zero DMA page-size mask during version capability parsing. Fixes: 36227628d824 (vfio-user: implement message send infrastructure) Signed-off-by: GuoHan Zhao Reviewed-by: John Levon Link: https://lore.kernel.org/qemu-devel/20260522081306.4186242-1-zhaoguoha= n@kylinos.cn Signed-off-by: C=C3=A9dric Le Goater (cherry picked from commit ab89d02dac6f0f53e35a689f01099602aa2de816) Signed-off-by: Michael Tokarev diff --git a/hw/vfio-user/proxy.c b/hw/vfio-user/proxy.c index 314dfd23d8..3fe5b0138b 100644 --- a/hw/vfio-user/proxy.c +++ b/hw/vfio-user/proxy.c @@ -1155,9 +1155,11 @@ static bool check_pgsizes(VFIOUserProxy *proxy, QObj= ect *qobj, Error **errp) return false; } =20 - /* must be larger than default */ - if (pgsizes & (VFIO_USER_DEF_PGSIZE - 1)) { - error_setg(errp, "pgsize 0x%"PRIx64" too small", pgsizes); + /* must not be zero or smaller than default */ + if (pgsizes < VFIO_USER_DEF_PGSIZE || + (pgsizes & (VFIO_USER_DEF_PGSIZE - 1))) { + error_setg(errp, "%s 0x%"PRIx64" too small", + VFIO_USER_CAP_PGSIZES, pgsizes); return false; } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308373; cv=none; d=zohomail.com; s=zohoarc; b=BMj5xixWLGabx3rI7clkfBJl8fk4nmzgioaVkx1xFfhW9Wk5r1DChL2U3w/UU9J4HmgLn6RqW81OLlNTqnyXWAIZJ0jBEasU8Y1IRvdSTo7FIbj5JyCBVM/aVV88i4VTiRi7ODej18sPVdMtu23ZLsOoTGdriB+IkPRJvC/EqXs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308373; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=C8OltfmBdjqemAjbnbPuXVPEhCeqj/TByYPdohd8IDA=; b=Px7k9TlEgF2njANLqpYBR3nQhjtSW/N4ZSdVcc/Yu8VCsxo0l56Yi3PyyaNCPEzHZTfk0o1fxxzIjMYOz3nJTlT67tQGuy9oi0d//hMvCJOYdoXxFH0QAvOkfP2qyOdFFtuSeda55RDT4/IWjTusZ6RcCLiU7zCmBkrJ44O/fPY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308373286715.3023356528157; Wed, 24 Jun 2026 06:39:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNlr-0004QT-Ax; Wed, 24 Jun 2026 09:36:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlm-0004IT-A9; Wed, 24 Jun 2026 09:36:00 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlk-0000qS-Pr; Wed, 24 Jun 2026 09:35:58 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 43CA71BA9D1; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D451B3DEA20; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=wW//6R9DcVQincR5nU8HAvA6a7TrUpycElpGLnaC2BU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=mt/JC7utKM/D/xUFjnCEwS4FI+J77eLsQ5lbYKtf0cJIbWk6Ik7t0lna77YEKl3fy rLje3O7tmEyetE2d1E94p4z7aiD5o9ZzwdngKcmNRuqdTTB2qJGxfdm17Na+2x3y7S cG8g506xZN4dfGsrTKCbiWtu84QQlb41cme6ENGU4UUfkQVDfuq0Z+AT4KbhCNHvI3 jZXQa9PpBmN+2xgFDcU7oBtqacpV4dbwusxmO4eHoXlwLWTVbZuiZl32ZoAvwN1BGP ELpIroEkRd4UGMOuBu5C2oR40uQSL7Woz2U//uUTDdlV7mMT3EdFgtObREZhFTyPiR 9z7sCNztNbTCw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, GuoHan Zhao , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Michael Tokarev Subject: [Stable-11.0.2 031/107] vfio-user: reject zero migration page size capability Date: Wed, 24 Jun 2026 16:30:36 +0300 Message-ID: <20260624133301.403266-31-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308374647158500 From: GuoHan Zhao check_migr_pgsize() validates that no page-size bits smaller than VFIO_USER_DEF_PGSIZE are set, but it still accepts pgsize=3D0. This can rep= lace the default migration page size with an unusable value. Reject a zero migration page size during version capability parsing, matchi= ng the lower-bound check used for the DMA page-size capability. Fixes: 36227628d824 (vfio-user: implement message send infrastructure) Signed-off-by: GuoHan Zhao Link: https://lore.kernel.org/qemu-devel/20260522081306.4186242-2-zhaoguoha= n@kylinos.cn Signed-off-by: C=C3=A9dric Le Goater (cherry picked from commit 497b5c5b05ac2be00ae16c723e2445ebbc486cb2) Signed-off-by: Michael Tokarev diff --git a/hw/vfio-user/proxy.c b/hw/vfio-user/proxy.c index 3fe5b0138b..3167d27b03 100644 --- a/hw/vfio-user/proxy.c +++ b/hw/vfio-user/proxy.c @@ -1081,9 +1081,11 @@ static bool check_migr_pgsize(VFIOUserProxy *proxy, = QObject *qobj, Error **errp) return false; } =20 - /* must be larger than default */ - if (pgsize & (VFIO_USER_DEF_PGSIZE - 1)) { - error_setg(errp, "pgsize 0x%"PRIx64" too small", pgsize); + /* must not be zero or smaller than default */ + if (pgsize < VFIO_USER_DEF_PGSIZE || + (pgsize & (VFIO_USER_DEF_PGSIZE - 1))) { + error_setg(errp, "%s 0x%"PRIx64" too small", + VFIO_USER_CAP_PGSIZE, pgsize); return false; } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308327; cv=none; d=zohomail.com; s=zohoarc; b=A47/U9pg5Yk91tL5eBGMUOX1bK1jgSnJZ82jdsD6s1q9XD/bXAR/RS1+Ztt5C7c3QGSHPMbE5a1iEIHgtSrudZz+zAle73/YPKBZOEzad8Jj2pk2/tovLKT9LQsI7d8LB8FTbVYVvFWpIOnMZ8sTLK4JFzMXGBwjmrhQANL+dlY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308327; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=76mFz2nrpEmAbRw3BjDdsH+LUUeOu5Pi+FGqlQzJiZM=; b=UOsuUCw5jwG6XF2a3wRToUzXdX++nJh42FItXUfeeg+5M/AW1FwqwvUX07W32BAn1CLVeI2VWLH5+0tP76ZU3EB1nwDWvL68D7RWO+gEfXuFMITm3k8iL8cCUlhTto6SAxDwSuPJ81J+niNeGOU/q/B7nT6gLQqSHEN6Z4IDcZc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308327269972.9475322755898; Wed, 24 Jun 2026 06:38:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNlt-0004jA-Dy; Wed, 24 Jun 2026 09:36:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlo-0004IX-Bi; Wed, 24 Jun 2026 09:36:00 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlm-0000sL-Jf; Wed, 24 Jun 2026 09:36:00 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 55F001BA9D2; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E4C103DEA21; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=jdO06w1bx/0mcHC/4q+Ne5w93oHOj/sR1DdBi8Mfk7I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=yI6sal8ldZis1gvWbZVrAaVXP7wBQOC7z0uer1yr+8HuPRcr/UVjha8h3hAh08NWg SN7NWoYqHtzWvTGV7Lv2cqOLlLm2kULgYfULgbTB4F0oeWLiH75e/mF0M99GZ/4zKA 60cdcBxfpEzfw80yh7hVtNNNNug4Ah22kEJsbCVr4ZPnv7vIrgVh2x9UkaXiJinPiC lvXWqlnSdEBWmklOiBnMfjSfc1d/mNDRekPoXzH2SQaxuESM/UvoZjDUWSl/Tjioxc wqKIzcNHHjBkxaapJiJIHVJCyqHCS0VOgiV8X7w6jCGOSOewbdmiuU9v0U9ysHyw1q mq6KnVebNe6yA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Chenyi Qiang , Farrah Chen , Zhenzhong Duan , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Michael Tokarev Subject: [Stable-11.0.2 032/107] vfio/container: Restrict dma_map_file() to shared RAM or RAM devices Date: Wed, 24 Jun 2026 16:30:37 +0300 Message-ID: <20260624133301.403266-32-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308328052158501 From: Chenyi Qiang vfio_container_dma_map() uses dma_map_file() whenever a RAMBlock has an fd and the VFIO IOMMU backend supports file-based DMA mapping. That is not correct for private file-backed guest RAM. dma_map_file() resolves PFNs from the backing file, but private guest RAM mappings (MAP_PRIVATE) can run on different PFNs than the file because they are subject to copy-on-write (COW) anomalies. As a result, using dma_map_file() on a privately mapped RAMBlock can program DMA against pages that do not back QEMU's actual guest memory. Fix this by using dma_map_file() only for shared mapped RAMBlocks (MAP_SHARED) or RAM device regions. Fixes: fb32965b6dd8 ("vfio/iommufd: use IOMMU_IOAS_MAP_FILE") Reported-by: Farrah Chen Closes: https://bugzilla.kernel.org/show_bug.cgi?id=3D220776 Reviewed-by: Zhenzhong Duan Suggested-by: C=C3=A9dric Le Goater Signed-off-by: Chenyi Qiang Link: https://lore.kernel.org/qemu-devel/20260527101109.71781-1-chenyi.qian= g@intel.com Reviewed-by: C=C3=A9dric Le Goater Signed-off-by: C=C3=A9dric Le Goater (cherry picked from commit e6c47bebdf8628e635e1ba970919ca96d572dbbe) Signed-off-by: Michael Tokarev diff --git a/hw/vfio/container.c b/hw/vfio/container.c index 4c2816b574..56bd9ac009 100644 --- a/hw/vfio/container.c +++ b/hw/vfio/container.c @@ -74,15 +74,43 @@ void vfio_address_space_insert(VFIOAddressSpace *space, bcontainer->space =3D space; } =20 +static bool vfio_container_can_dma_map_file(VFIOContainer *bcontainer, + MemoryRegion *mr, int *fd) +{ + VFIOIOMMUClass *vioc =3D VFIO_IOMMU_GET_CLASS(bcontainer); + RAMBlock *rb =3D mr->ram_block; + + if (!vioc->dma_map_file || !rb) { + return false; + } + + *fd =3D qemu_ram_get_fd(rb); + if (*fd < 0) { + return false; + } + + /* + * We can use IOMMU DMA mapping (IOMMU_IOAS_MAP_FILE) for : + * + * 1) Guest RAM blocks explicitly configured as shared (MAP_SHARED) + * 2) RAM device sub-regions (MMIO BARs) + * + * Private RAM mappings (MAP_PRIVATE) are strictly excluded. Because + * they are subject to copy-on-write (COW) anomalies, their underlying + * PFNs can permanently diverge from the backing file + */ + return qemu_ram_is_shared(rb) || memory_region_is_ram_device(mr); +} + int vfio_container_dma_map(VFIOContainer *bcontainer, hwaddr iova, uint64_t size, void *vaddr, bool readonly, MemoryRegion *mr) { VFIOIOMMUClass *vioc =3D VFIO_IOMMU_GET_CLASS(bcontainer); - RAMBlock *rb =3D mr->ram_block; - int mfd =3D rb ? qemu_ram_get_fd(rb) : -1; + int mfd; =20 - if (mfd >=3D 0 && vioc->dma_map_file) { + if (vfio_container_can_dma_map_file(bcontainer, mr, &mfd)) { + RAMBlock *rb =3D mr->ram_block; unsigned long start =3D vaddr - qemu_ram_get_host_addr(rb); unsigned long offset =3D qemu_ram_get_fd_offset(rb); =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308453; cv=none; d=zohomail.com; s=zohoarc; b=bmV6TEpbRVrgldRieTBYGVGv+ylPmBKDg98sasfb/M94fTgBIL/jbhYCg/ssTAjOPt5ZXydL9kFWhCMAUWCrKSWC7eCH2qVuhKMs4cRn8COFyjdyXZJwA97v9Q3akRfO4G42R/n+stC2bFRwLPyOxANlW/EW3Rrc8NhW0URLvzM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308453; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=u+jTOkhb1UDG8TNjel9copBgPTJwijNiMhmUR5wgzyk=; b=oF2uPMmMCGYgs17dpaZAk8AEjdGCfbdO3+I8lEBxsT/uSM2epmrs7odEx8G3nddDWA1p+N4aNW2WVMKTf5bHycYVWh8tIwQQITPfRwKxUfRC3ap7GB9rzp+Dr9NNJiHjt9bbU+O79HMieNYBRVzzSSTAYBqSUJGLuieB4M7OzbQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308453985361.41261836018316; Wed, 24 Jun 2026 06:40:53 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNlt-0004k6-L0; Wed, 24 Jun 2026 09:36:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNlp-0004Mj-7g; Wed, 24 Jun 2026 09:36:01 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNln-0000sV-MU; Wed, 24 Jun 2026 09:36:00 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 6F2CB1BA9D3; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0259C3DEA22; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=OQcZflaaAdCO1CU6lugVRJpFmRJmYwX7C3Bxhwi4Fi0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TFhkbAmqjJhoeV+as6oySZs/x72qm6GuC6Nb9VvgUtPiFwq/yOlUJpjaRGs49og1F gm3QNSHwc2J90KvTP3WmlVcm4i22PrjZ35qDlQebabjYA6nr80WguQMXRd8NbHVTyZ 1Pntvp9m+U76hzyIfvvujcIjXupeoTCNOi5G+SQHttAly8pmSTOg8s0ubmFZrKLKfQ +49XnPJHkg/J/1C32iEqlteo8aiF5zD34TWBKjdLAogV3L0oscN+oohQyQ5LPhANLE joWhmd/3iCBjA/xsGM9aL/tAP9mf8LP1wkFDLC2RVZpZwTyRUE1y/lTxy7bEh0uCTR QTU85UtOwTkmg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richard Henderson , Peter Maydell , Michael Tokarev Subject: [Stable-11.0.2 033/107] target/arm: Enable REVD for SVE2.1 Date: Wed, 24 Jun 2026 16:30:38 +0300 Message-ID: <20260624133301.403266-33-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308454990158500 Content-Type: text/plain; charset="utf-8" From: Richard Henderson Cc: qemu-stable@nongnu.org Signed-off-by: Richard Henderson Message-id: 20260522220408.235438-1-richard.henderson@linaro.org Reviewed-by: Peter Maydell Signed-off-by: Peter Maydell (cherry picked from commit f12e7ba6f43803ec73c92b4ebeee6187113ba1fc) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/translate-sve.c b/target/arm/tcg/translate-sve.c index f9dfda4a7a..a05967f4fb 100644 --- a/target/arm/tcg/translate-sve.c +++ b/target/arm/tcg/translate-sve.c @@ -2992,7 +2992,8 @@ TRANS_FEAT(REVH, aa64_sme_or_sve, gen_gvec_ool_arg_zp= z, revh_fns[a->esz], a, 0) TRANS_FEAT(REVW, aa64_sme_or_sve, gen_gvec_ool_arg_zpz, a->esz =3D=3D 3 ? gen_helper_sve_revw_d : NULL, a, 0) =20 -TRANS_FEAT(REVD, aa64_sme, gen_gvec_ool_arg_zpz, gen_helper_sme_revd_q, a,= 0) +TRANS_FEAT(REVD, aa64_sme_or_sve2p1, gen_gvec_ool_arg_zpz, + gen_helper_sme_revd_q, a, 0) =20 TRANS_FEAT(SPLICE, aa64_sme_or_sve, gen_gvec_ool_arg_zpzz, gen_helper_sve_splice, a, a->esz) --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308322; cv=none; d=zohomail.com; s=zohoarc; b=fvFbwaHqserNWzgYLiM5YTO5m+E+FTQMB3wlwTlQektAHt5qMpb7ZTC+L/Z+Xkqouvn7jsfPuS3VoKoAwjEUuV3ItxWQOn2AM4LsllewLxTU8LgYlPFCeRc1j4/3Di1uA/D7KnF/Ij0MyYOBymJXck4bx3MH1j7Jd30kwcWKotw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308322; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=KtCW87gIb8OLBbMPaIMP1X1sjFnnTeJxkvQ/8tmmREY=; b=IPNWcHUNkaUbCErYjwci8pSczPc5Ry+/PNrJXBUqIEJ6kT9aLm2LkvypNSTKCWTANzQMzvneJ22UKj1k6rNziz3mXuXYQUK4On9vGJDy1bvRNUo9Oyn3n9vZq5Ucpv+LkQWxmiDd4hBwCcVgkmR7yubF38NPVTDIwSN0MboCa1k= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308322547698.059342974621; Wed, 24 Jun 2026 06:38:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNmF-000626-8H; Wed, 24 Jun 2026 09:36:27 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmB-0005uM-Ij; Wed, 24 Jun 2026 09:36:23 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNm9-0000sm-Rk; Wed, 24 Jun 2026 09:36:23 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 7E8801BA9D4; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1B8A33DEA23; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=1SLei3wOec+IuksXol0hfWzvxEzayfmod70lDXMUvdU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=NTOSYzzBNIYHxE+0mNSdfTPVztLJbEFK9vuFmNp4N7QCt+jCmqpM+1VqNyPf1TJqb oc6UM6NLqonx3uqoRIKDO3wTdqf5HKVrX04r/eRE/9VS2mB7I10NnP1duDTNjtUy+M h9NAclPVD2a1dFC/4QSSSAhS+Cm5l0hXy9R1VtVYys6c2S8LiYUqfz5QczFUE9Rld6 EOR9IWqj8LpwZ9OwV+BzZ4EMnEg4diFJTbHES7djyYGBHlkKcaHUKlc8UGAg9PXqvo lIrpUebfilzoh60Z0L4NX9gdijx0+NXX799BwjHrAl/IzxUXl9+dAhorFIjlr8h5id 1bBlrmW0xwNsw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Richard Henderson , Michael Tokarev Subject: [Stable-11.0.2 034/107] target/arm: Don't assert if 64-bit EL2 AT insn sees a Domain fault Date: Wed, 24 Jun 2026 16:30:39 +0300 Message-ID: <20260624133301.403266-34-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308323997158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell The Domain fault type can only happen for 32-bit short-format descriptors. This means that it almost never needs to be encoded in a long-format fault status code. However, there is one corner case where we do need to report it as a long-format FSC: if a 64-bit EL2 does an AT insn on an AArch32 EL1&0 translation regime that is using short-descriptors and that translation operation hits a Domain fault, then this is reported in the PAR_EL1 in long-format. The PAR_EL1 register description defines that this should be reported as 0b111101 for a level 1 Domain fault or 0b111110 for a level 2 Domain fault. The Arm ARM pseudocode special cases this in the function AArch64_PARFaultStatus() (because no other "fault to LFSC" code path can be a Domain fault). For QEMU, implement it in arm_fi_to_lfsc(). Cc: qemu-stable@nongnu.org Fixes: 1fa498fe0de97 ("target/arm: Provide fault type enum and FSR conversi= on functions") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3512 Signed-off-by: Peter Maydell Reviewed-by: Richard Henderson Message-id: 20260526174155.2491217-1-peter.maydell@linaro.org (cherry picked from commit bb957530471c792a9a51e822a6c2fa8398cc48f6) Signed-off-by: Michael Tokarev diff --git a/target/arm/internals.h b/target/arm/internals.h index 85980f0e69..556c0729c7 100644 --- a/target/arm/internals.h +++ b/target/arm/internals.h @@ -872,6 +872,16 @@ static inline uint32_t arm_fi_to_lfsc(ARMMMUFaultInfo = *fi) assert(fi->level >=3D 0 && fi->level <=3D 3); fsc =3D 0b001100 | fi->level; break; + case ARMFault_Domain: + /* + * This can only happen when doing an AT insn at EL2 for an AArch32 + * stage 1 EL1&0 translation regime using short-descriptors, and + * the translation hits a Domain fault. This needs to be reported = in + * the long-format PAR. Compare pseudocode AArch64_PARFaultStatus(= ). + */ + assert(fi->level =3D=3D 1 || fi->level =3D=3D 2); + fsc =3D 0b111100 | fi->level; + break; case ARMFault_Translation: assert(fi->level >=3D -1 && fi->level <=3D 3); if (fi->level < 0) { --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308358; cv=none; d=zohomail.com; s=zohoarc; b=SMple1aKXlXkD+H4UB4A336HM/CcPbFiIrV7degaCsJkCqiIHk5nSNhy4+lRmcPeGoE/zLfd/tMsphB3aaQNaYAOIsbN/+r0xSYx0NlGHvAAZRX5Y01ZCrfuHSFWto76GyC9iqffyN5IXJfZinZYmnFyDyN01NNOuodduBHo+hY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308358; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=OVHbi+TOkb8S0F8WCrKVPCe+ssQGpdSUVdagSU5Oh/E=; b=GTVL9enh79P5MePWoZbSTDC+vJhs9MkiiqZubThA2hE09orytbhe8EhYfCAFUQ/UiRgAMKtZqei2sewc+ikCDyhn5n3uvSeIAFCy2stcimmz0OLN026AV5+69Vct+v3QRlILueO50Hsti/hu9Ref7GH2VmpcmVuQugPKdSvl1AQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308358758818.8842330195138; Wed, 24 Jun 2026 06:39:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNmD-0005yC-5F; Wed, 24 Jun 2026 09:36:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmC-0005wT-5d; Wed, 24 Jun 2026 09:36:24 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmA-0000t0-Jz; Wed, 24 Jun 2026 09:36:23 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 8D8D51BA9D5; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 2A9CA3DEA24; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=i+yfxhU/CaItktIbTAcONgxmHDsA/PtMAephYUbH82s=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=tfTVz6/PP4KR6YDUOI7QLWNyxoeABoKo0o0M/WiYPP/f4hRyeqaH6QwL5kEnblmF4 szNko3BLte9Pw2tvziG7G3skoZRAQRjTCZZxF0w+YZUun1M/bd0sc81/V6I8KIBK30 DgO6/7ma8ip1Hd3QcByP/9NCVtds7hUmXmjVDqYJnFolnivBoqs8w6fBtY3+plxilU cWqhcn/Pexkc5PQXlGRDDULjHB2HZZxwNWJLxotNV5f4TVEcHQBcKGu+jvbjL5YP+Z JEgr4wFFk0F2Zl06LNiCC/Jc3h39+umVDO6WWTyKHdc3c6DQlHwcgzzn4gJB64r6Kc ruwMQeXEaMSxw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Richard Henderson , Michael Tokarev Subject: [Stable-11.0.2 035/107] target/arm: SME BFCVT, BFCVTN have "Alternate BFloat16 behaviors" Date: Wed, 24 Jun 2026 16:30:40 +0300 Message-ID: <20260624133301.403266-35-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308360237158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell The Arm ARM A1.5.10 notes that some instructions have "Alternate Bfloat16 behaviors" when FPCR.AH =3D=3D 1. We implement these using the FPST_AH and FPST_AH_F16 fp_status words. The list includes the SME BFVCT (single-precision to BFloat16) and BFCVTN, but we forgot to make those use FPST_AH_F16 when we implemented them. (We get the ASIMD and SVE insns on the list right.) Add the missing logic to select the right FPST. Cc: qemu-stable@nongnu.org Fixes: 465d36db0e1 ("target/arm: Implement SME2 BFCVT, BFCVTN, FCVT, FCVTN") Reviewed-by: Richard Henderson Signed-off-by: Peter Maydell Message-id: 20260521180854.1744788-1-peter.maydell@linaro.org (cherry picked from commit ca33de98447c2c2825c1af73cfacf4f65a9bc6c6) Signed-off-by: Michael Tokarev diff --git a/target/arm/tcg/translate-sme.c b/target/arm/tcg/translate-sme.c index 7d25ac5a51..6064ed8697 100644 --- a/target/arm/tcg/translate-sme.c +++ b/target/arm/tcg/translate-sme.c @@ -1418,9 +1418,9 @@ static bool do_zz_fpst(DisasContext *s, arg_zz_n *a, = int data, } =20 TRANS_FEAT(BFCVT, aa64_sme2, do_zz_fpst, a, 0, - FPST_A64, gen_helper_sme2_bfcvt) + s->fpcr_ah ? FPST_AH : FPST_A64, gen_helper_sme2_bfcvt) TRANS_FEAT(BFCVTN, aa64_sme2, do_zz_fpst, a, 0, - FPST_A64, gen_helper_sme2_bfcvtn) + s->fpcr_ah ? FPST_AH : FPST_A64, gen_helper_sme2_bfcvtn) TRANS_FEAT(FCVT_n, aa64_sme2, do_zz_fpst, a, 0, FPST_A64, gen_helper_sme2_fcvt_n) TRANS_FEAT(FCVTN, aa64_sme2, do_zz_fpst, a, 0, --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308579; cv=none; d=zohomail.com; s=zohoarc; b=loUcKhjdbLjBbHhVjLQhpdLOvL6lwQOLr0BTV8C0evN2K1U9Fl9ZLzPznn27SxrCyTnPnxGBVyu+DIu02I6GeZ1m/6eN+BSba75fICw0vslAxH4cAaEGym5+ZK1owbPLv4vr9Ql1i04RHpl1sHfV3XYOLuAOKDXYI+i9IfUqO50= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308579; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=TfTuvLqnheBnOqPHqrM8UbLagLKfQlvFbihS/EIscr0=; b=IkV5wlSot9pdsD4EgcDa0IZxEsdjMU0F+TJnQtmQbRO9nt3th4UNDMIhpPFoi0ejgKKzT4MXpDxzJ8rkrV1uOvJo5ZcW9ZwSAUT0O7F8I7iSML5mP8f+MS9oVX0HbKpd1tMZz7gNFHCZHTgwx2s+w1i9XoYOBYMi0r8MXSObAEs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17823085780381013.1163596417949; Wed, 24 Jun 2026 06:42:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNmG-00062d-7I; Wed, 24 Jun 2026 09:36:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmE-00061r-VD; Wed, 24 Jun 2026 09:36:26 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmD-0000wI-1S; Wed, 24 Jun 2026 09:36:26 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9D3B41BA9D6; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 39A323DEA25; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=y3EvD+HGZtAGlIf1KZvi3tGEQakW/9VhWWOSw41RWQc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=otZSJrX39i0Xt4X0moSJ+hJ7i/BK14xxCIp5zS41Yhz+oVYDkQtbmc8Lf2fm6R7BO u69BjNjqmaYvNPnqkDYWIx8Fr1dwkDBX+usiuDf6019vXAtIzWQqql0Zp8xj2XMRWW r1B3GYUEKiYIWHYlMH/JoPE4yd2C7kHJ/7C1LRm82zKYXQ3Zq5HfpYBweQ1pg/uGTb ZD/iZLGekKfpAuZqGz8gGD9ufqN0NidrtXmlwyeRp9VFvcu47T+MtnxjoGvnwsuGTd dXnrylikEutltKpD/ep+Z9WUhXmljuWtMXSUBkmENZa3gFEvuwDkiZjC3kcbOBILkK gj2Ua4coIKkWw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Jason Wang , Michael Tokarev Subject: [Stable-11.0.2 036/107] hw/net/rocker_of_dpa: Check group ID pointers are not NULL Date: Wed, 24 Jun 2026 16:30:41 +0300 Message-ID: <20260624133301.403266-36-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308593191158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell In of_dpa_cmd_add_l2_flood(), we use rocker_tlv_parse_nested() to fill in a tlvs[] array. If the guest command is valid then the entries should be pointers to TLV data items with group IDs. However, if the guest gives us bogus data then rocker_tlv_parse_nested() indicates this by leaving the tlvs[] entries NULL. In the other places that use this function, we check for this before using the value, but here we forgot, and the result is that QEMU can crash: #0 __memcpy_avx_unaligned_erms () at ../sysdeps/x86_64/multiarch/memmove-v= ec-unaligned-erms.S:331 #1 0x00005555574f7137 in __asan_memcpy () #2 0x0000555558106792 in ldl_he_p (ptr=3D0x8) at /home/pm215/qemu/include/= qemu/bswap.h:278 #3 0x0000555558106755 in ldl_le_p (ptr=3D0x8) at /home/pm215/qemu/include/= qemu/bswap.h:311 #4 0x00005555580f85ed in rocker_tlv_get_le32 (tlv=3D0x0) at ../../hw/net/r= ocker/rocker_tlv.h:114 #5 0x000055555810a8ad in of_dpa_cmd_add_l2_flood (of_dpa=3D0x506000082e38,= group=3D0x503000b4e440, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2032 #6 0x0000555558108a74 in of_dpa_cmd_group_do (of_dpa=3D0x506000082e38, gro= up_id=3D1073741824, group=3D0x503000b4e440, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2115 #7 0x0000555558108730 in of_dpa_cmd_group_add (of_dpa=3D0x506000082e38, gr= oup_id=3D1073741824, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2135 #8 0x00005555580f66ec in of_dpa_group_cmd (of_dpa=3D0x506000082e38, info=3D0x514000072e40, buf=3D0x5070002356c0 "= \001", cmd=3D7, group_tlvs=3D0x7fff68702c20) at ../../hw/net/rocker/rocker_of_dpa.c:2194 Check for NULL values and return an error. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/1851 Signed-off-by: Peter Maydell Signed-off-by: Jason Wang (cherry picked from commit 8526b7d6b67beda0c83e4a8aec1449475fe5dd65) Signed-off-by: Michael Tokarev diff --git a/hw/net/rocker/rocker_of_dpa.c b/hw/net/rocker/rocker_of_dpa.c index 3190a0e75c..958f3006c1 100644 --- a/hw/net/rocker/rocker_of_dpa.c +++ b/hw/net/rocker/rocker_of_dpa.c @@ -2029,6 +2029,10 @@ static int of_dpa_cmd_add_l2_flood(OfDpa *of_dpa, Of= DpaGroup *group, group_tlvs[ROCKER_TLV_OF_DPA_GROUP_IDS]); =20 for (i =3D 0; i < group->l2_flood.group_count; i++) { + if (!tlvs[i + 1]) { + err =3D -ROCKER_EINVAL; + goto err_out; + } group->l2_flood.group_ids[i] =3D rocker_tlv_get_le32(tlvs[i + 1]); } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308601; cv=none; d=zohomail.com; s=zohoarc; b=nmlEZFgj2P/nJQGROPxl+2seYpw7p4GIznhvKWTizhunhQ0zPTa/G2CppOef8CfsMiCsucWlK6luMLjbsQa17XmxALEZuCml7R1t/docm7tergcOW0t7uHkR7wfwX9ZeXXFkWJFCjnogEAEX57WnJ3V/HLFCLOh+Jp+GHsNYrFM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308601; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=iuxSRBWTkgfSk8L5/YiR9Jlu2z2RuFjoYyWwfzawbvw=; b=QsFvSHmUdvP8ehN+d7LwJ8DA/AfAxNMokhv0sMNx3QjZqe6FRaMCXOWettW2zc1n++hAWiOkpoGlFAHh9AdhE16bUaV02msgTlxptcUnQf/gWqru/fmOisjSa5Wp7UiLhdX4yPH6rgqHf+vW0TFX4pvFq/1pMzijCCtqiRjfUL8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308601269609.3093222588266; Wed, 24 Jun 2026 06:43:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNmG-00062h-BU; Wed, 24 Jun 2026 09:36:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmF-00062E-9H; Wed, 24 Jun 2026 09:36:27 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmD-0000wS-Id; Wed, 24 Jun 2026 09:36:27 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id AC9441BA9D7; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 49BEE3DEA26; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=u9MhEfJFgVBl71EK5UreCe/1IDcR0M1fW4f5yCNMfJM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=IwU+cPsxZjhtXvSA0R0eJ767ztEk8qI03nnfBhkA5y3kU2rdmeEQOgsT33Mkh1v2U Oc+Ms38OommG1BoxwxIpOaLijdUPaLQWO+IHW2C+CZw/QVyEUxNUzMWwbqTLer69zh R5d5+/+ubELT2E5GT2Hwaz+1BUDZrC82b94G+kXDsISfR6fPgNSjsiCeQf1hJ3rPFU olmuK8uxW+/ttm2SPIxLRZYC4MN6LCpfeLFBY+WTnnW4wokgdrh7e9y9I1Fr3iJQgQ ZxrFTWzXtXVKCgTugtlyxMpkmuPZVd4BfA9z18Dm0yRQ5UtdcSRCc60q49nfV2+UE9 8bCWz4fPSRv6g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Jason Wang , Michael Tokarev Subject: [Stable-11.0.2 037/107] hw/net/rocker_of_dpa: Avoid unaligned accesses in _of_dpa_flow_match() Date: Wed, 24 Jun 2026 16:30:42 +0300 Message-ID: <20260624133301.403266-37-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308603288158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell _of_dpa_flow_match() tries to do masked comparisons of OfDpaFlowkey structs by casting pointers to them to uint64_t* and then doing the memory accesses as 64-bit. This is undefined behaviour because the pointers might not be 64-bit aligned, and the UB sanitizer spots this: ../../hw/net/rocker/rocker_of_dpa.c:321:20: runtime error: load of misalign= ed address 0x512000164044 for type 'uint64_t' (aka 'unsigned long'), which = requires 8 byte alignment 0x512000164044: note: pointer points here 02 00 00 00 00 00 ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00= 00 00 00 00 00 00 00 00 ^ We do know that OfDpaFlowKey structs must be at least aligned enough for uint32_t accesses, because that's the type of the first field. Switch to using uint32_t accesses in the loop. Because the "width" field is always set via the FLOW_KEY_WIDTH macro and not exposed to the guest, we can adjust the macro to store the number of uint32_t to be checked rather than needing to change the loop boundary in the match function. Cc: qemu-stable@nongnu.org Signed-off-by: Peter Maydell Signed-off-by: Jason Wang (cherry picked from commit 71d027cfee8553e2ec28efa1ddd7fd0ecbadcc86) Signed-off-by: Michael Tokarev diff --git a/hw/net/rocker/rocker_of_dpa.c b/hw/net/rocker/rocker_of_dpa.c index 958f3006c1..3d6f55b512 100644 --- a/hw/net/rocker/rocker_of_dpa.c +++ b/hw/net/rocker/rocker_of_dpa.c @@ -99,13 +99,13 @@ typedef struct of_dpa_flow_key { } nd; } ipv6; }; - int width; /* how many uint64_t's in key? */ + int width; /* how many uint32_t's in key? */ } OfDpaFlowKey; =20 -/* Width of key which includes field 'f' in u64s, rounded up */ +/* Width of key which includes field 'f' in u32s, rounded up */ #define FLOW_KEY_WIDTH(f) \ DIV_ROUND_UP(offsetof(OfDpaFlowKey, f) + sizeof_field(OfDpaFlowKey, f)= , \ - sizeof(uint64_t)) + sizeof(uint32_t)) =20 typedef struct of_dpa_flow_action { uint32_t goto_tbl; @@ -304,9 +304,9 @@ static void _of_dpa_flow_match(void *key, void *value, = void *user_data) { OfDpaFlow *flow =3D value; OfDpaFlowMatch *match =3D user_data; - uint64_t *k =3D (uint64_t *)&flow->key; - uint64_t *m =3D (uint64_t *)&flow->mask; - uint64_t *v =3D (uint64_t *)&match->value; + uint32_t *k =3D (uint32_t *)&flow->key; + uint32_t *m =3D (uint32_t *)&flow->mask; + uint32_t *v =3D (uint32_t *)&match->value; int i; =20 if (flow->key.tbl_id =3D=3D match->value.tbl_id) { --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308884; cv=none; d=zohomail.com; s=zohoarc; b=Wlun9ojUT0YImOOiNGumtfHTDvoBB/uoUTu6eEsOcaQO+bv090mD20B82YLjr5aKukc15o+Uks01xN7MyjhbX7iohG2UT4zW1quIYVKqsRNjbOQ/sifvQTQejjS5MbVqM2ln3ObYTStdYOqVWSsQbqglEkivcxebuNTDRyZAgYQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308884; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=HGxfuZJKsLe8+60uPCQZxke+PsDM5TGk+j/oBE/o73A=; b=mzVe8OBVTFC7mwDw1PKZou2OA3+dUj1zL9r42NFz3s7QJCgS2mdGsS9lXRj2C9ou4xTvsHsIlmDYVutdwTYbEAbo64DcqhreSy2Aqx3ptwsgSFBvNWjXjv6VOjmxH1+dSVCysOpFimxnOP9BY/uJaQwylxnI5pw1wNi2sF0W14A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308884897400.3089379204215; Wed, 24 Jun 2026 06:48:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNmL-00066w-1g; Wed, 24 Jun 2026 09:36:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmH-000646-T9; Wed, 24 Jun 2026 09:36:29 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmG-0000x0-Bg; Wed, 24 Jun 2026 09:36:29 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BDAB21BA9D8; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 58E6D3DEA27; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=LlFJ5MNrrFqn2jreYasQuWyv+SrH/nQ9Zgl3Dd/fIBM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=q9HZVhk7GgOufYFqQBurSTeJbv8lyZaMygO9ByCnQ9mIm/cmN50J8WC3f13/bcq5S TVOeJQz+8jQBpVOHbbd3QdxPohWrRCqchyxu5+OKxvffbaN6NCK1Q99+3lj/76ewHe ldk25r8ZpKdDcQwpN8xqSTdArfZ8GB3ngRbBBIhL1JkE7QDOvfqOwsn19AAwB9F+83 O5xt1Rx7Gxn+EJuKnWSiyCssFFEQt078VeWRVmmx3mqQO/M64qquwf1lmfQi9EiJ6w r2w1iWD9lwVnd74tFyPoYdEj3jKb2CcpIKsiPI6n0FTjrvl54lT0lE70pZwVm8nHQi j2yK2BpWsqCCg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 038/107] linux-user/ppc: restore fp_status from FPSCR on sigreturn Date: Wed, 24 Jun 2026 16:30:43 +0300 Message-ID: <20260624133301.403266-38-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308885606158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner restore_user_regs() restores the PPC FPSCR with a direct assignment: env->fpscr =3D (uint32_t) fpscr; ppc_store_fpscr() exists precisely to write FPSCR and keep the derived env->fp_status in sync: it calls fpscr_set_rounding_mode() to update the softfloat rounding mode, and set_float_rebias_overflow/underflow() to reflect the FP_OE/FP_UE enable bits. The direct assignment bypasses all of this. On sigreturn, interrupted code resumes with whatever rounding mode and overflow/underflow-rebias state the signal handler last installed in fp_status, rather than the state that was saved at signal delivery. Replace the direct assign with ppc_store_fpscr(). The FPSCR_MTFS_MASK applied inside ppc_store_fpscr() only excludes the computed FP_FEX and FP_VX bits, which it re-derives correctly from the exception and enable bits in the restored value. Fixes: bcd4933a23 ("linux-user: ppc signal handling") Cc: qemu-stable@nongnu.org Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 3f50dd46664bdf94f10aca8b76dc4dcb9182a5ae) Signed-off-by: Michael Tokarev diff --git a/linux-user/ppc/signal.c b/linux-user/ppc/signal.c index a9c10e0987..ab1afea30a 100644 --- a/linux-user/ppc/signal.c +++ b/linux-user/ppc/signal.c @@ -420,7 +420,7 @@ static void restore_user_regs(CPUPPCState *env, __get_user(*fpr, &frame->mc_fregs[i]); } __get_user(fpscr, &frame->mc_fregs[32]); - env->fpscr =3D (uint32_t) fpscr; + ppc_store_fpscr(env, (uint32_t) fpscr); } =20 #if !defined(TARGET_PPC64) --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308617; cv=none; d=zohomail.com; s=zohoarc; b=b82vYwgJ49l8URdN33wkMKTgyFCikztGOzrgSqGSj5OvdOzeWlMlzfQ5ddOBzKQo1Rj0jnE0RKpb1vHFcDbdGw4KOZByLNrbcAgeP5BSqvV9H/lHq7jqVJxGl8addjXFriJsoaxmcFDk1mPHBtt9a4qQwQfWfjVmAMAS9xqKseA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308617; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=mH6yRBZ/PDbfJvNZ//Mq+d1prFsF088AMQ9/HmMVqsg=; b=kAsYpKk8XgFIOaAgAyFToRWMrAwun5yVkBZ6wGFv1GsmtTA3Tu6x7j77lnPNiTV2OlaVVNixY5w5cpZiQI506P8P1jDmTLX+2sGFGZtfUW/HVc1JhHkR3a1k3oDfBW44z+a6ETzX9c9IQzHHrPnMjKSP0r9+DKI31r7nSq4J/G4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308617590725.9456787390766; Wed, 24 Jun 2026 06:43:37 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNmj-0006dt-AN; Wed, 24 Jun 2026 09:36:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmc-0006UG-AO; Wed, 24 Jun 2026 09:36:52 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNma-0000xA-N7; Wed, 24 Jun 2026 09:36:50 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id CD0951BA9D9; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 69F6A3DEA28; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=qPeqdKxBJoa6vMIIrWN4BZr+z637BJiDM9Ba4X2UnAY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=lHbxZ5t5kKDJroHHlNdJ+W24I/3dKBD1Q9hGzuQSxQA3lH0cq8CU48ILc6pHmXzWX ZL8TmeBeDmG7o+mwM32KIGDyjpNBbF26LvWQwJPdKXhcvtOvMY8tzHO6860VlxGDw3 WsvmFwgg2QiN3QLs0KNNyQyhERvuiOKxAwhqwLuv34KeoI3HCZspXMTUZn1Vjm1Idv iYEEJtIW42ElUXT7CIet2sABn5Fp9FqFAb/0z70G0FAVfmPA9jgJBxp7ri9zgf0RTe sMtIr87Epl51bsw6r6XsYOCokkArst/oLRLgrcKFFaLkYWr4SerCOTxBnQgw5x1vjZ OS5hrZDlH8Erg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 039/107] linux-user/mips: save/restore FCSR across signal delivery Date: Wed, 24 Jun 2026 16:30:44 +0300 Message-ID: <20260624133301.403266-39-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308619537158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the MIPS FPU control/status register (FCSR, fcr31) in env->active_fpu.fcr31. The rounding mode, flush-to-zero (FS), and NaN-2008 mode bits in fcr31 are reflected into the derived env->active_fpu.fp_status via set_float_rounding_mode() and friends; every architectural write to FCSR goes through helper_ctc1() which calls restore_fp_status() to keep the two in sync. Both target_sigcontext variants (O32 and N32/N64) have an sc_fpc_csr field that holds FCSR, but setup_sigcontext() never wrote it and restore_sigcontext() never read it. As a result: - The signal frame always delivered sc_fpc_csr =3D=3D 0 to the handler, so sigaction(SA_SIGINFO) handlers that inspect the interrupted context see the wrong FCSR. - On sigreturn, active_fpu.fcr31 retained whatever value the signal handler last installed (if any), and active_fpu.fp_status was never resynced. Interrupted code resumed with the wrong rounding mode, FS flag, and NaN-2008 semantics. Fix setup_sigcontext() to save fcr31 into sc_fpc_csr. Fix restore_sigcontext() to read it back (masked to fcr31_rw_bitmask as the kernel does) and call cpu_mips_restore_fp_status() to resync fp_status from the restored fcr31. Add cpu_mips_restore_fp_status() in target/mips/fpu.c (which already defines ieee_rm and includes fpu_helper.h), and declare it in cpu.h. Fixes: 084d0497a0 ("mips-linux-user: Save and restore fpu and dsp from sigc= ontext") Cc: qemu-stable@nongnu.org Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 84b920ccb5ee5287747af2d36d1ece6367b6a40e) Signed-off-by: Michael Tokarev diff --git a/linux-user/mips/signal.c b/linux-user/mips/signal.c index d69a5d73dd..1b10012726 100644 --- a/linux-user/mips/signal.c +++ b/linux-user/mips/signal.c @@ -134,6 +134,7 @@ static inline void setup_sigcontext(CPUMIPSState *regs, for (i =3D 0; i < 32; ++i) { __put_user(regs->active_fpu.fpr[i].d, &sc->sc_fpregs[i]); } + __put_user(regs->active_fpu.fcr31, &sc->sc_fpc_csr); } =20 static inline void @@ -165,6 +166,12 @@ restore_sigcontext(CPUMIPSState *regs, struct target_s= igcontext *sc) for (i =3D 0; i < 32; ++i) { __get_user(regs->active_fpu.fpr[i].d, &sc->sc_fpregs[i]); } + { + uint32_t fcr31; + __get_user(fcr31, &sc->sc_fpc_csr); + regs->active_fpu.fcr31 =3D fcr31 & regs->active_fpu.fcr31_rw_bitma= sk; + cpu_mips_restore_fp_status(regs); + } } =20 /* diff --git a/target/mips/cpu.h b/target/mips/cpu.h index ed662135cb..3b4da9887b 100644 --- a/target/mips/cpu.h +++ b/target/mips/cpu.h @@ -1366,6 +1366,9 @@ void cpu_mips_clock_init(MIPSCPU *cpu); /* helper.c */ target_ulong exception_resume_pc(CPUMIPSState *env); =20 +/* fpu.c */ +void cpu_mips_restore_fp_status(CPUMIPSState *env); + /** * mips_cpu_create_with_clock: * @typename: a MIPS CPU type. diff --git a/target/mips/fpu.c b/target/mips/fpu.c index c7c487c1f9..8b661865ca 100644 --- a/target/mips/fpu.c +++ b/target/mips/fpu.c @@ -17,6 +17,11 @@ const FloatRoundMode ieee_rm[4] =3D { float_round_down }; =20 +void cpu_mips_restore_fp_status(CPUMIPSState *env) +{ + restore_fp_status(env); +} + const char fregnames[32][4] =3D { "f0", "f1", "f2", "f3", "f4", "f5", "f6", "f7", "f8", "f9", "f10", "f11", "f12", "f13", "f14", "f15", --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308322; cv=none; d=zohomail.com; s=zohoarc; b=asTUitoK0BJkjjwzPfoTYb5+DxBD074XI8JMQFKWZ3Rb9O+N6RbTHf+nOsBO0+XDm0Xz897QoYkYhFg8AAVJyeCs4JLBAZvyTgHTxIsG0KBSWF5hjgM1LYDrFe5YAWSIPtgbUBa7q7vEOMSUOlzxhKByA/kLFxK14q8OvmSGVYE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308322; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LPhyYccvzczMUvS1xg6EDqVdVvYUg9RiFt2CCvF1NVI=; b=c7WkzxTL5m5coYOWMsmp94m+OetaHvEnmOoLnztV1V1XDcAezyho1rk0lJ8Irwa3hKPTKV/vBm7GaAypcCrB4IZXpEakASfYkeWTplGlMbWbAoMZY5FjBQ2yNE87BF/u+aGtAI9KPsK80iLHaYBGqTJCGt47KY9t/pjCVFOUnsM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308322680190.57156686548217; Wed, 24 Jun 2026 06:38:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNmk-0006l9-Lu; Wed, 24 Jun 2026 09:36:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmf-0006Yo-OD; Wed, 24 Jun 2026 09:36:53 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmd-0000xb-QY; Wed, 24 Jun 2026 09:36:53 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id DFCDD1BA9DA; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 796253DEA29; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=Wqggm+YI9CGOXrC37tB98c0M6KNUDE9ZIppSxjX+MCI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=S62EN56Jy92Usuy9FptzZ1Dot/ymDsY3W7lxtQW+rWz/kX/EZ37+1vh+4eFN31BRM yy1OL8mBTROwq3rDaWNEbwRBnLtA6Cks042gGLV1DjICaxlGJQc7MgD9V9sSxkGWYz omydD9gtdxQnMNaHJBnUMG3pNH7v7iT0XQ/Q22Wd/78M8PZXfaOG0IlXCWX8t1bLJC 3vT4VgkgMaNqSNJuS33KgN1bjlxx9f3A2J9Hjj7rYdP7NDpivkG0HrliJZiTwLn7dm 5Rzxr0+imAvyGBoCQZchXEyNwPuMCmuKnd/MWG9im2zOsYahaOBeFqyhFf/srqNAuP 3kMssNd/q8gsg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Yoshinori Sato , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 040/107] linux-user/sh4: preserve T/M/Q bits across signal delivery Date: Wed, 24 Jun 2026 16:30:45 +0300 Message-ID: <20260624133301.403266-40-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308324015158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the SH4 T, M and Q status-register bits outside env->sr, in the dedicated env->sr_t, env->sr_m and env->sr_q fields; cpu_read_sr() folds them back into the architectural SR value and cpu_write_sr() splits them back out. setup_sigcontext() saved the bare env->sr (so the T/M/Q bits were always zero in the signal frame) and restore_sigcontext() wrote the value straight back into env->sr without updating sr_t/sr_m/sr_q. As a result the T bit was never preserved across signal delivery: on sigreturn the interrupted code resumed with whatever T value the signal handler last left behind. Any conditional branch (or addc/subc/rotcl/div1, etc.) immediately following the interrupted instruction could then take the wrong path. This is the cause of the long-standing intermittent failures of the tests/tcg/multiarch/signals.c test on sh4, which was marked BROKEN. With a SIGRTMIN timer firing every millisecond across many threads, the race was hit a few percent of the time and corrupted the guest heap, surfacing as a SIGSEGV in memset, a malloc assertion, or an rseq registration abort. Traced on a deterministic rr recording: a cmp/hi set T=3D0, the timer signal interrupted the very next instruction (a bf), the handler left T=3D1, and the resumed bf took glibc calloc's MORECORE_CLEARS branch, using the old top-chunk size as the clear length for a freshly split small chunk and running memset off the end of the heap. Fix setup_sigcontext()/restore_sigcontext() to use cpu_read_sr() and cpu_write_sr() so the T, M and Q bits round-trip correctly, and drop the BROKEN annotation on the sh4 signals test. Fixes: c3b5bc8ab3 ("SH4: Signal handling for the user space emulator, by Ma= gnus Damm.") Cc: qemu-stable@nongnu.org Reviewed-by: Yoshinori Sato Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 6bf4c0295cccf74f3c5c0b674328b97d6fd1505c) Signed-off-by: Michael Tokarev diff --git a/linux-user/sh4/signal.c b/linux-user/sh4/signal.c index d70be24c38..cc36425c49 100644 --- a/linux-user/sh4/signal.c +++ b/linux-user/sh4/signal.c @@ -131,8 +131,10 @@ static void setup_sigcontext(struct target_sigcontext = *sc, COPY(gregs[14]); COPY(gregs[15]); COPY(gbr); COPY(mach); COPY(macl); COPY(pr); - COPY(sr); COPY(pc); + COPY(pc); #undef COPY + /* The T, M and Q bits live outside env->sr; fold them back in. */ + __put_user(cpu_read_sr(regs), &sc->sc_sr); =20 for (i=3D0; i<16; i++) { __put_user(regs->fregs[i], &sc->sc_fpregs[i]); @@ -159,8 +161,14 @@ static void restore_sigcontext(CPUSH4State *regs, stru= ct target_sigcontext *sc) COPY(gregs[14]); COPY(gregs[15]); COPY(gbr); COPY(mach); COPY(macl); COPY(pr); - COPY(sr); COPY(pc); + COPY(pc); #undef COPY + /* The T, M and Q bits live outside env->sr; unfold them. */ + { + uint32_t sr; + __get_user(sr, &sc->sc_sr); + cpu_write_sr(regs, sr); + } =20 for (i=3D0; i<16; i++) { __get_user(regs->fregs[i], &sc->sc_fpregs[i]); diff --git a/tests/tcg/sh4/Makefile.target b/tests/tcg/sh4/Makefile.target index 7852fa62d8..b7a8737be0 100644 --- a/tests/tcg/sh4/Makefile.target +++ b/tests/tcg/sh4/Makefile.target @@ -3,13 +3,6 @@ # SuperH specific tweaks # =20 -# This triggers failures for sh4-linux about 10% of the time. -# Random SIGSEGV at unpredictable guest address, cause unknown. -run-signals: signals - $(call skip-test, $<, "BROKEN") -run-plugin-signals-with-%: - $(call skip-test, $<, "BROKEN") - VPATH +=3D $(SRC_PATH)/tests/tcg/sh4 =20 test-macl: CFLAGS +=3D -O -g --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308658; cv=none; d=zohomail.com; s=zohoarc; b=K/V2cY8mp5cNitXGbnzx0sb/z/maA35vkNgjSgfwM5BbzDwbPiQcm1jFkdTOilv2YMgB9kctLrzkfgvw3tC15cvrLEMeXEFoArt74P4XllqlU2Bf5nJNjVApMCqwXz4FYd1gAJ9awljQDh/+Omk9bS/B3X5SfjNnJuhRf2Qy95k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308658; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hyg8vU45DM+g+du69jrlEz81Wrm+PtwUiPNfGOYab3o=; b=as/0W+5Mrf7FOkuoJ8F8azTS6L9XGv9GqLeoefn7sWVFEZM6/5LJexVfPsWg3DnlsE4OJzS0IB50/HSpCyMew6r35xHp4Or98kcgdD4lbmVNqoU2p00GJWUU5cfqnZwYwI1yC5M9DuFose33l3Gl+g8F8wgIAVJfMIYII1j3W0A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308658813115.93883321920566; Wed, 24 Jun 2026 06:44:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNmj-0006hG-Vs; Wed, 24 Jun 2026 09:36:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmf-0006Yn-OB; Wed, 24 Jun 2026 09:36:53 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmd-0000yt-O6; Wed, 24 Jun 2026 09:36:53 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id F2FE51BA9DB; Wed, 24 Jun 2026 16:33:17 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 8C3E13DEA2A; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307997; bh=LnNZu/aRjpZZFrq6QaE6GVF8IP/wzZvL7ML5ZltIi0U=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=aSDckxiI0FvoTuGgn27N+o7FwBgf921T6ppvAS74s7IjJvBI6Xr24ueVI9aLrFw7u BfOTk904HxDJhfeZBmFKw/Xy2teC+XwZceTuvx93WH5tbIr+miVdYlQsUwvAkAq/Is njf5CFNKGGw/voUvuhTvLFwcQYtSP62bWhq6DnhyaDfPd8ESJUqQI2JLno2v8YjM7/ AMBcN5kia3LFQRiZQ2RX0C4i7rh4/o9vm2p3EpN8dZCjCqwzdxCETMK2D2v5nt/e+z +f+jzqH/VW25xClCMQs7WOS4RlWwIRxY/dVPDpzNtnZRqgKCxidwBKLPNmrO83cbmK DpPJblUakpkkg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Yoshinori Sato , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 041/107] linux-user/sh4: restore FP rounding mode on sigreturn Date: Wed, 24 Jun 2026 16:30:46 +0300 Message-ID: <20260624133301.403266-41-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308659713158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner The SH4 FPSCR rounding-mode (RM) and denormal (DN) bits are not held only in env->fpscr: they are also reflected into the derived env->fp_status via set_float_rounding_mode()/set_flush_to_zero(). The guest keeps the two in sync by routing every write to FPSCR through helper_ld_fpscr(). restore_sigcontext() wrote the saved value straight into env->fpscr and never touched env->fp_status, so on sigreturn the interrupted code resumed with whatever FP rounding mode and flush-to-zero setting the signal handler last installed. (regs->flags =3D 0 forces the FR/SZ/PR TB flags to be recomputed, but fp_status is runtime float state, not a TB flag, so it was left stale.) This is the FP analogue of the T/M/Q bit problem just fixed for the integer status register. Factor the FPSCR -> fp_status synchronisation out of helper_ld_fpscr() into cpu_load_fpscr() and use it from restore_sigcontext() so the rounding mode round-trips correctly across signal delivery. Fixes: c3b5bc8ab3 ("SH4: Signal handling for the user space emulator, by Ma= gnus Damm.") Cc: qemu-stable@nongnu.org Reviewed-by: Yoshinori Sato Reviewed-by: Richard Henderson Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit a740f17ed0fbc5cd38e3cb12136c58d38aba098d) Signed-off-by: Michael Tokarev diff --git a/linux-user/sh4/signal.c b/linux-user/sh4/signal.c index cc36425c49..00290d6e40 100644 --- a/linux-user/sh4/signal.c +++ b/linux-user/sh4/signal.c @@ -173,7 +173,12 @@ static void restore_sigcontext(CPUSH4State *regs, stru= ct target_sigcontext *sc) for (i=3D0; i<16; i++) { __get_user(regs->fregs[i], &sc->sc_fpregs[i]); } - __get_user(regs->fpscr, &sc->sc_fpscr); + /* Resync the derived float_status state, not just env->fpscr. */ + { + uint32_t fpscr; + __get_user(fpscr, &sc->sc_fpscr); + cpu_load_fpscr(regs, fpscr); + } __get_user(regs->fpul, &sc->sc_fpul); =20 regs->tra =3D -1; /* disable syscall checks */ diff --git a/target/sh4/cpu.h b/target/sh4/cpu.h index b0759010c4..fbecde13a9 100644 --- a/target/sh4/cpu.h +++ b/target/sh4/cpu.h @@ -380,4 +380,7 @@ static inline void cpu_write_sr(CPUSH4State *env, uint3= 2_t sr) env->sr =3D sr & ~((1u << SR_M) | (1u << SR_Q) | (1u << SR_T)); } =20 +/* Set FPSCR and the derived float_status rounding/flush-to-zero state. */ +void cpu_load_fpscr(CPUSH4State *env, uint32_t val); + #endif /* SH4_CPU_H */ diff --git a/target/sh4/op_helper.c b/target/sh4/op_helper.c index 669bc84cb6..cf0f80e4a5 100644 --- a/target/sh4/op_helper.c +++ b/target/sh4/op_helper.c @@ -204,7 +204,7 @@ void helper_macw(CPUSH4State *env, int32_t arg0, int32_= t arg1) } } =20 -void helper_ld_fpscr(CPUSH4State *env, uint32_t val) +void cpu_load_fpscr(CPUSH4State *env, uint32_t val) { env->fpscr =3D val & FPSCR_MASK; if ((val & FPSCR_RM_MASK) =3D=3D FPSCR_RM_ZERO) { @@ -215,6 +215,11 @@ void helper_ld_fpscr(CPUSH4State *env, uint32_t val) set_flush_to_zero((val & FPSCR_DN) !=3D 0, &env->fp_status); } =20 +void helper_ld_fpscr(CPUSH4State *env, uint32_t val) +{ + cpu_load_fpscr(env, val); +} + static void update_fpscr(CPUSH4State *env, uintptr_t retaddr) { int xcpt, cause, enable; --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308822; cv=none; d=zohomail.com; s=zohoarc; b=Qg7t+LZKr39m4GVbxL+8mY12KsXElMgNvsmpETxWookzubVzC/uNi7Pcsi5Emz5FGle9xZ7FtOTa1u1VsZ2XytDoW+4taZAYM+dpiwmGl+i2o+dVoUCTGeI1+IqeAFvbouLdvXlN0Hktz5UEZh5XZFCEIRHIfzwmXDKn29ERqgA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308822; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=5OkeV3lYkdiZ3J8R3h6L+/wbU+nY7AmeOBMy1hA792w=; b=O6MiolK3VbP+frFZQJzkENPw5b6ylZk/56ZEi2dEDPAxAnpccAqBgAkY455xnRz3hVjty1PX8PC+RvxU4CF3v5HLRF59bZIgkJ6Quu8LAZ9st0UflngHCieNIGeiDj5QUEtv1eJG9nnsn3ZnOJ59pgAVB2DBg+RtETVIaxWWlxo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308822199467.43916811990573; Wed, 24 Jun 2026 06:47:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNn6-0008Nc-GG; Wed, 24 Jun 2026 09:37:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNn4-0008LN-1S; Wed, 24 Jun 2026 09:37:18 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNn2-0000zM-BJ; Wed, 24 Jun 2026 09:37:17 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 0E2781BA9DC; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9F1F23DEA2B; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=Ghl0ZtyIs4gKQ1+JEGboppp/jddtSue3ilOs0f6SYAE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=IdHk4oJW9X0fljcUazYqMLvTDzPUQ/d0448/k8cEp6/AJTtgqc+SOXg+7RShQiSct VOLMF0NqfsnFX+1QNsnLjJXz1/sTpb6mpKxnZkZiVstYyueZFPlQyNlcav5mYUZ/2b UXWhavP0GzMM89iwBfq97OUXqYSb1MhndL+Y2nKdSbkT/YKC9Mv+NRyyf/QcXOTbdv JIWdlhpw2UK42S11hMsVR5bYDtPItJkywihmJY6D+xcMOj783dEM0DCbzS89YlgY0Q ZEtSN/e7o1yN+s3PJqqrImDXeEmlWOXG/SDz7cURdQEU1gOrPPWpLsbWr3JXcmWlAT OZpHFUJXw0RhQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 042/107] linux-user/s390x: restore fpu_status rounding mode from FPC on sigreturn Date: Wed, 24 Jun 2026 16:30:47 +0300 Message-ID: <20260624133301.403266-42-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308823115158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner QEMU keeps the s390x floating-point control register (FPC) in env->fpc. The rounding mode bits [2:0] of FPC are reflected into the derived env->fpu_status via set_float_rounding_mode(); every architectural write to FPC goes through HELPER(sfpc) which keeps the two in sync. restore_sigregs() restored FPC with a direct assignment: __get_user(env->fpc, &sc->fpregs.fpc); This wrote env->fpc correctly but never updated env->fpu_status, so on sigreturn the interrupted code resumed with whatever rounding mode the signal handler last installed in fpu_status. Factor the two-step "write fpc + sync fpu_status" logic out of HELPER(sfpc) into cpu_s390x_load_fpc(), declare it in cpu.h, and call it from restore_sigregs() in place of the direct assignment. cpu_s390x_load_fpc() partially reuses the sanity check from HELPER(sfpc): if the FPC value has an invalid rounding mode or reserved bits set, it falls back to 0, matching the kernel's fpu_lfpc_safe() behavior where a corrupt signal frame value causes a specification exception and 0 is used instead. HELPER(sfpc) now calls cpu_s390x_load_fpc() after its full specification-exception check, including the FEAT_FLOATING_POINT_EXT test that is not needed for the signal restore path. Fixes: 2941e0fa05 ("linux-user/s390x: Save/restore fpc when handling a sign= al") Cc: qemu-stable@nongnu.org Signed-off-by: Matt Turner Signed-off-by: Helge Deller (cherry picked from commit 2762cd51ee033dccb3167110376dd125244cc819) Signed-off-by: Michael Tokarev diff --git a/linux-user/s390x/signal.c b/linux-user/s390x/signal.c index 96d1c8d11c..28ad80bde4 100644 --- a/linux-user/s390x/signal.c +++ b/linux-user/s390x/signal.c @@ -332,7 +332,11 @@ static void restore_sigregs(CPUS390XState *env, target= _sigregs *sc) for (i =3D 0; i < 16; i++) { __get_user(env->aregs[i], &sc->regs.acrs[i]); } - __get_user(env->fpc, &sc->fpregs.fpc); + { + uint32_t fpc; + __get_user(fpc, &sc->fpregs.fpc); + cpu_s390x_load_fpc(env, fpc); + } for (i =3D 0; i < 16; i++) { __get_user(*get_freg(env, i), &sc->fpregs.fprs[i]); } diff --git a/target/s390x/cpu.h b/target/s390x/cpu.h index 40bc1f0741..6826cda1c0 100644 --- a/target/s390x/cpu.h +++ b/target/s390x/cpu.h @@ -896,6 +896,7 @@ void s390_init_sigp(void); /* helper.c */ void s390_cpu_set_psw(CPUS390XState *env, uint64_t mask, uint64_t addr); uint64_t s390_cpu_get_psw_mask(CPUS390XState *env); +void cpu_s390x_load_fpc(CPUS390XState *env, uint32_t fpc); =20 /* outside of target/s390x/ */ S390CPU *s390_cpu_addr2state(uint16_t cpu_addr); diff --git a/target/s390x/tcg/fpu_helper.c b/target/s390x/tcg/fpu_helper.c index 122994960a..6152d14aa9 100644 --- a/target/s390x/tcg/fpu_helper.c +++ b/target/s390x/tcg/fpu_helper.c @@ -952,6 +952,19 @@ static const int fpc_to_rnd[8] =3D { float_round_to_odd, }; =20 +void cpu_s390x_load_fpc(CPUS390XState *env, uint32_t fpc) +{ + /* + * Mimic kernel fpu_lfpc_safe(): a corrupt signal frame value that wou= ld + * trigger a specification exception instead results in FPC being set = to 0. + */ + if (fpc_to_rnd[fpc & 0x7] =3D=3D -1 || fpc & 0x03030088u) { + fpc =3D 0; + } + env->fpc =3D fpc; + set_float_rounding_mode(fpc_to_rnd[fpc & 0x7], &env->fpu_status); +} + /* set fpc */ void HELPER(sfpc)(CPUS390XState *env, uint64_t fpc) { @@ -959,12 +972,7 @@ void HELPER(sfpc)(CPUS390XState *env, uint64_t fpc) (!s390_has_feat(S390_FEAT_FLOATING_POINT_EXT) && fpc & 0x4)) { tcg_s390_program_interrupt(env, PGM_SPECIFICATION, GETPC()); } - - /* Install everything in the main FPC. */ - env->fpc =3D fpc; - - /* Install the rounding mode in the shadow fpu_status. */ - set_float_rounding_mode(fpc_to_rnd[fpc & 0x7], &env->fpu_status); + cpu_s390x_load_fpc(env, fpc); } =20 /* set fpc and signal */ --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308609; cv=none; d=zohomail.com; s=zohoarc; b=NWx4va9J58rNg/XXSPPjN8Xl0SjWuxCsdypsLOa8MKESmMxLvhU4uaFHmgVjUJ/f7zJhTYDmczUeBrnK8bXDeBiNa96X4CNcNYEbmZIEEGFUSm49aC7xsdxg2LKkkZVVQFZQWVffCqvIpGN7Gt8aTkOeFPqvruCWj/lXd8KVXRE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308609; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Vx6YLiojGLoOIis9elYM0zKzJHAICjR+3Ciim4gXpH8=; b=MtaF67mB4xYnagofpc0IhE3yH4z8O+1sjyi0VXygme2GguhAYMgJMX24afxuDHKPbhLZ5Oy1fk3C0mR967ZJVqjkuTlLRdtjkP2wsHP1AZffcjNPycoHTE0ZVi4DLnDYCNbMayTs1wyYhpYHiVqaVYl0uDs/kGc/43zMBfytvpc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308609772131.98726254707606; Wed, 24 Jun 2026 06:43:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNml-0006n5-4I; Wed, 24 Jun 2026 09:37:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmj-0006iT-Qh; Wed, 24 Jun 2026 09:36:57 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNmi-0000zN-7P; Wed, 24 Jun 2026 09:36:57 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 24F791BA9DD; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id AE11E3DEA2C; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=lRK4NhiR2fBV89rabH41NE98LJMgN+fdDW4JciwJ5Yk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=oS9KId8yfsmU5O9YAZo6lX8Ksgi7cJstGoG3aTWS8Fn6ORXyZIUPRAUsguAePl6ti VzT39qsqmJjg9AQMESdLRQDxuYIhnzy7qjV1Xv4A/YTFBKEKAbCGjffnVq3+IFjhVv P01g8iehj99J2EkLzIIdlLc5IGnHu1v1gJSxztcHP6Y1AGH8/cr2IlfL4Zl1kQbOsn +9TKc63mFD8u0kfky9H3GPCrL1dZqSu7UepYKVvabyEU9zWE2wxXQVNdKuDYVXZpqU J33K3TCNfqXT7wGdHsCjp9tand86QzPHh30U1B1WIo80awCZ6vo1i0J1bUx+C29LpE HKFNYOaxAx4bw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-11.0.2 043/107] hw/9pfs: add NULL check in v9fs_path_is_ancestor() Date: Wed, 24 Jun 2026 16:30:48 +0300 Message-ID: <20260624133301.403266-43-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308611335158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add NULL check for s1->data and s2->data before using them in string operations. This prevents potential crashes when dealing with uninitialized paths. This is just a defensive measure. We are currently never passing NULL to this function. Link: https://lore.kernel.org/qemu-devel/3348c4d683f061c23083bd45994d527be4= fb7cbc.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit abb0cc02fb56e2432837e34b80fe68768f95e774) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index e2713b9eee..e590c414ab 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -241,6 +241,9 @@ int v9fs_name_to_path(V9fsState *s, V9fsPath *dirpath, */ static int v9fs_path_is_ancestor(V9fsPath *s1, V9fsPath *s2) { + if (!s1->data || !s2->data) { + return 0; + } if (!strncmp(s1->data, s2->data, s1->size - 1)) { if (s2->data[s1->size - 1] =3D=3D '\0' || s2->data[s1->size - 1] = =3D=3D '/') { return 1; --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782309072; cv=none; d=zohomail.com; s=zohoarc; b=aAQ9IkNhdKnbLVVhZsx61azRt/jJVtkSf2MWE1xuqxawiaBEdO7oQ0HYk3XLk85AgaB5FFbtoGmNETAbCsi74D9NC4O6FroTV9EbyhQ8vCyQ74TQnqpSe9KLd3QhYULedEL300xzqAJFrU+vSP8e5FC2qKiEBLcn++Mi2dj1rz4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782309072; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RQ2t152RvX53cD46ZfAgHZnWnNxDD+SPXKW2xZdz2t8=; b=mLliWU0NbgPsi8oycCK69NY3m8XCIfkzQZi3++o6JNvhqyfkqlib/dw/g+h6Od/Vt6SFRBbO2xxRPF+K6uMK8TDGT8R0RdNqi093eIShHIiZF6393tKqU68WGPJybQLKS5ebzXK/+gRuxcqDAGjUJVMVq0h/0KklrD0Wg7xAwOM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782309072583682.831026187681; Wed, 24 Jun 2026 06:51:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNn9-0008W8-Qk; Wed, 24 Jun 2026 09:37:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNn6-0008PF-Rc; Wed, 24 Jun 2026 09:37:20 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNn5-0000zy-4l; Wed, 24 Jun 2026 09:37:20 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 30A2B1BA9DE; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C444E3DEA2D; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=hruUjaXdQAdvaQCyFc5bpqH3UnncxRCYx7iu6J++zHc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=SsAjep88y2nQJwOCVS1vUQCa8N7rJIMKaxWcenV2REY4GeGply2U1K3SJ5RKfjvco yQGg62lK085IkmRTM4G3p/pjL0UdVh9GXRUNsruZPOf52vjSm2RbZd2GM/Nyg37kWj L9YX5sTARYLvZVbaKAQWn056efIVrLjFvrOncdSqzDUOr3YXzZ6CIbQYNpoBtnlZ48 w2t55i4xktfIlFAVGOJik6/PvY2GswRZbEp+qhw9SE05fhfRKSC9dw9Vovegrz38Rg myywrNQ/cLBeEKORW4zUOnxSeXj7fO0YnzgwMhBpxxslAY4JvsKo40MwXe4U4V6tV0 ObFlhG8y25D5Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-11.0.2 044/107] hw/9pfs: change V9fsPath.size to size_t and v9fs_path_sprintf() return type Date: Wed, 24 Jun 2026 16:30:49 +0300 Message-ID: <20260624133301.403266-44-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782309072966158501 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck - Change V9fsPath.size from uint16_t to size_t to support paths larger than 65536 bytes. - Change v9fs_path_sprintf() return type from void to int to allow error reporting. Link: https://lore.kernel.org/qemu-devel/2d2348d94ff43fbe4cc0aea24fb312c5c1= 5ee809.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit dbaf84e148b0c8b66dcb47788a6bb13806e401e4) Signed-off-by: Michael Tokarev diff --git a/fsdev/file-op-9p.h b/fsdev/file-op-9p.h index b85c9934de..e8d0661c4b 100644 --- a/fsdev/file-op-9p.h +++ b/fsdev/file-op-9p.h @@ -112,7 +112,7 @@ struct FsContext { }; =20 struct V9fsPath { - uint16_t size; + size_t size; char *data; }; P9ARRAY_DECLARE_TYPE(V9fsPath); diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index e590c414ab..88894ec9d2 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -203,16 +203,24 @@ void v9fs_path_free(V9fsPath *path) } =20 =20 -void v9fs_path_sprintf(V9fsPath *path, const char *fmt, ...) +int v9fs_path_sprintf(V9fsPath *path, const char *fmt, ...) { va_list ap; + int ret; =20 v9fs_path_free(path); =20 va_start(ap, fmt); - /* Bump the size for including terminating NULL */ - path->size =3D g_vasprintf(&path->data, fmt, ap) + 1; + ret =3D g_vasprintf(&path->data, fmt, ap); va_end(ap); + if (ret < 0) { + error_report_once("9pfs: unusual path formatting failure; " + "invalidating associated FID"); + return -1; + } + /* Bump the size for including terminating NULL */ + path->size =3D ret + 1; + return 0; } =20 void v9fs_path_copy(V9fsPath *dst, const V9fsPath *src) diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index 65cc45e344..b2df659b0e 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -456,8 +456,8 @@ static inline uint8_t v9fs_request_cancelled(V9fsPDU *p= du) void coroutine_fn v9fs_reclaim_fd(V9fsPDU *pdu); void v9fs_path_init(V9fsPath *path); void v9fs_path_free(V9fsPath *path); -void G_GNUC_PRINTF(2, 3) v9fs_path_sprintf(V9fsPath *path, const char *fmt, - ...); +int G_GNUC_PRINTF(2, 3) v9fs_path_sprintf(V9fsPath *path, const char *fmt, + ...); void v9fs_path_copy(V9fsPath *dst, const V9fsPath *src); size_t v9fs_readdir_response_size(V9fsString *name); int v9fs_name_to_path(V9fsState *s, V9fsPath *dirpath, --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308564; cv=none; d=zohomail.com; s=zohoarc; b=V05y3kePBci8wj40CFmath33ApxPoUFgEy0fe1QSFFrRK20jYtGmdrUdzI8IHgvGbbQc8lU3SrZdGTIEcnqMuJ+Gv0nf15yJbfmVP/Nk4oKZL49FNUl0lKnKRxHDwgugnXn/TYbWA81PsoNLqAKz/QFTSz//dOMySFWf6Zqsjus= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308564; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fZQxguZqXp0TiYFi/itdiD0OelZwID66/nHex9iRQjY=; b=FAnYf5KrzI9mQwbbmU4b2/9Mzsw7bwgBl2SyV0Mc7cHeG4SQP/cnFKHtc1q9MxYR/NVtY1CRZlvetEDwyPC3EjE8RkgSNLXTIc+x6/em4tZJ5dZQhkuVbkwt6+P7dKjHvH1SG5cQJ4xQSfHPICHCynJ2SEcB5bq2Gq5bspe+fFk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308564040895.7939718337692; Wed, 24 Jun 2026 06:42:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNnA-000065-17; Wed, 24 Jun 2026 09:37:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNn7-0008Pu-OS; Wed, 24 Jun 2026 09:37:21 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNn5-000138-HK; Wed, 24 Jun 2026 09:37:20 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 490001BA9DF; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D0B933DEA2E; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=O/VAYKtFT/ySzeCdN9vtq7zt1BEiR6EfG4DYJe0VKwM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=GAxO5eluqsTOoFUFgMZP2lil8xsbGruFfYaToLFqhqXXJfbJQM3KK+9lDCm7IM1Rg D/JlIKjq1ydok054k9FF/5uk4X0Vf2SYbJ2Cp8+EAYe5zxXLXQ9kmX/Nkfaak21/pB 8LO4kLPwtUx+TiFxd7wwkp9uVYkylXakv+QlMhUNfLAqVgjzoRWnhTwULsUGEwxsvt 0sjgp+8Fufd1EwX3cGB9JaBrCLif2E4afxaN3J8LwWkdptfAEOqfg0bVPzqcJdO9dQ MsZKcl8YUE478n4PJ8hOhDpFzK0mokQeNTAXzK9wkmTFR/Zx0yqY2b5vhR2pIoHb5d PgtdsU5wHZWyQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-11.0.2 045/107] hw/9pfs: add error handling to v9fs_fix_path() Date: Wed, 24 Jun 2026 16:30:50 +0300 Message-ID: <20260624133301.403266-45-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308565335158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Update v9fs_fix_path() to return int and propagate errors from v9fs_path_sprintf(). This allows callers to detect and handle path formatting failures. Link: https://lore.kernel.org/qemu-devel/a0592741a918b7cbe751980ec7ec0c03f5= 05924c.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 54dd352c59269fdb5241e7b6dbcecaff107e7f5a) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 88894ec9d2..d704de644f 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -1417,13 +1417,15 @@ static void print_sg(struct iovec *sg, int cnt) } =20 /* Will call this only for path name based fid */ -static void v9fs_fix_path(V9fsPath *dst, V9fsPath *src, int len) +static int v9fs_fix_path(V9fsPath *dst, V9fsPath *src, int len) { V9fsPath str; + int ret; v9fs_path_init(&str); v9fs_path_copy(&str, dst); - v9fs_path_sprintf(dst, "%s%s", src->data, str.data + len); + ret =3D v9fs_path_sprintf(dst, "%s%s", src->data, str.data + len); v9fs_path_free(&str); + return ret; } =20 static inline bool is_ro_export(FsContext *ctx) --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308824; cv=none; d=zohomail.com; s=zohoarc; b=X0wZT/MhqzwVdM250CNgrqX1qbBQ8ArWwtIxQOhzJxX6C/ZEcBi8NosSSpH8WtEmM4/IGBAtCFCbrG/O8g1pw+LYECr5tH5l1irbF2lTO9fx4/n2sjaU/g27BGUCf172xydI2uqB3OGyA6lQOQa8onDYJL8wmr8WnHDGgS35xmM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308824; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=nsPlrAg5wdyHceESmd6nzkhsgrb+/rHodmlTH0nzrjU=; b=gTZUz2HS8VAsK16iXmvqQGAq8Izgj0XJDYorRbcWwx8cRD4EbBn9ivxHjYxXpCKBKB4BjrcQwQ6a0isdkDs8j1I7eKMnxUkRXIjC3eXEotUEOzT1DqpFgmQc5bG25Wgjjf03M956VBvIhpmlPdsB168btDMiE+Uxi4kBksaoapk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308824840695.2425022444432; Wed, 24 Jun 2026 06:47:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNnG-0000cT-3L; Wed, 24 Jun 2026 09:37:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNnA-0000A3-8b; Wed, 24 Jun 2026 09:37:24 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNn8-00013l-9R; Wed, 24 Jun 2026 09:37:23 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 57F9E1BA9E0; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E87B43DEA2F; Wed, 24 Jun 2026 16:33:23 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=4tk3GUct0C8a+DpGA4Ou5oAjqkp+/dLPmbzo2Xr5o3Y=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=X6zsxKGPn2wQB1+bw29DzIaTQMuSL2Z+vp3wt0Hk0Vkmi46MlUp+uCP1nLca+kiHr vY1Vchc0PfiSa+wPxyAaiSjAQ8Wxf2IJ3JVbBs31EWoDf63nxKUUskxDtx0ewxAr2/ 6Men0jujbzqXyqmEjlROt0E69+NaE82qajV8Jz6ckk6ASnlo7izY2y+L0D/tEGb4w7 Tyu0M0KzRvJ2iZjSJIvqYXczaIGXg0ei2YPIBoXy5oxMEpg8z8A/GbvSD6q4NtJk/w cZe/TA7snvJ0+FSDjXUFIjdX0+XqqXCMhp6ubZLQksL5nZOYsFTk5chvM5XU2mhvhy h35lW64yXr9rQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Wang Jihe , Michael Tokarev Subject: [Stable-11.0.2 046/107] hw/9pfs: let callers of v9fs_path_sprintf() and v9fs_fix_path() handle errors Date: Wed, 24 Jun 2026 16:30:51 +0300 Message-ID: <20260624133301.403266-46-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308825396158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck This patch mitigates issues with very large absolute paths. - Add error handling to all v9fs_path_sprintf() calls in local_name_to_path() - Update callers of v9fs_fix_path() to check return values. - When path formatting fails, clunk the affected FIDs to prevent use of invalid paths. - Use g_autofree for temporary variables to simplify code. Even though paths are usually limited to PATH_MAX (typically 4k) on guest, this limitation can be circumvented by using *at() functions on guest and creating very deep directory structures. This was a problem for QEMU 9p server, as it currently tracks the absolute path for each FID internally that always requires assembly of a (potentially ver large) absolute path. A true long-term fix would be getting rid of storing an absolute path for each FID internally. However that would likely be a massive change with uncertain implications. This patch therefore just mitigates the problem by immediately clunking (i.e. closing) all FIDs whose path exceed a limit that we could handle. As this only accounts to very unusual large absolute paths not ever been reported on (sane) production machines, this is currently considered an acceptable mitigation that should only (counter)affect malicious attempts. Fixes: 2f008a8c97e2 ("hw/9pfs: Use the correct signed type ...") Reported-by: Wang Jihe Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3358 Link: https://lore.kernel.org/qemu-devel/1d11dcbfc95b811dcdb48c6d7f3894d0eb= d073a2.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 3802c0e755a53b126e717415b54226a468bf7ddf) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p-local.c b/hw/9pfs/9p-local.c index 24cb1da90a..aa48306b0e 100644 --- a/hw/9pfs/9p-local.c +++ b/hw/9pfs/9p-local.c @@ -1261,26 +1261,35 @@ static int local_name_to_path(FsContext *ctx, V9fsP= ath *dir_path, } else if (!strcmp(name, "..")) { if (!strcmp(dir_path->data, ".")) { /* ".." relative to the root is "." */ - v9fs_path_sprintf(target, "."); + if (v9fs_path_sprintf(target, ".") < 0) { + return -1; + } } else { - char *tmp =3D g_path_get_dirname(dir_path->data); + g_autofree char *tmp =3D g_path_get_dirname(dir_path->data= ); /* Symbolic links are resolved by the client. We can assume * that ".." relative to "foo/bar" is equivalent to "foo" */ - v9fs_path_sprintf(target, "%s", tmp); - g_free(tmp); + if (v9fs_path_sprintf(target, "%s", tmp) < 0) { + return -1; + } } } else { assert(!strchr(name, '/')); - v9fs_path_sprintf(target, "%s/%s", dir_path->data, name); + if (v9fs_path_sprintf(target, "%s/%s", dir_path->data, name) <= 0) { + return -1; + } } } else if (!strcmp(name, "/") || !strcmp(name, ".") || !strcmp(name, "..")) { /* This is the root fid */ - v9fs_path_sprintf(target, "."); + if (v9fs_path_sprintf(target, ".") < 0) { + return -1; + } } else { assert(!strchr(name, '/')); - v9fs_path_sprintf(target, "./%s", name); + if (v9fs_path_sprintf(target, "./%s", name) < 0) { + return -1; + } } return 0; } diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index d704de644f..b4314d2549 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -3325,12 +3325,14 @@ static int coroutine_fn v9fs_complete_rename(V9fsPD= U *pdu, V9fsFidState *fidp, goto out; } } else { - char *dir_name =3D g_path_get_dirname(fidp->path.data); + g_autofree char *dir_name =3D g_path_get_dirname(fidp->path.data); V9fsPath dir_path; =20 v9fs_path_init(&dir_path); - v9fs_path_sprintf(&dir_path, "%s", dir_name); - g_free(dir_name); + err =3D v9fs_path_sprintf(&dir_path, "%s", dir_name); + if (err < 0) { + goto out; + } =20 err =3D v9fs_co_name_to_path(pdu, &dir_path, name->data, &new_path= ); v9fs_path_free(&dir_path); @@ -3351,7 +3353,10 @@ static int coroutine_fn v9fs_complete_rename(V9fsPDU= *pdu, V9fsFidState *fidp, while (g_hash_table_iter_next(&iter, &fid, (gpointer *) &tfidp)) { if (v9fs_path_is_ancestor(&fidp->path, &tfidp->path)) { /* replace the name */ - v9fs_fix_path(&tfidp->path, &new_path, strlen(fidp->path.data)= ); + if (v9fs_fix_path(&tfidp->path, &new_path, + strlen(fidp->path.data)) < 0) { + clunk_fid(s, tfidp->fid); + } } } out: @@ -3448,7 +3453,10 @@ static int coroutine_fn v9fs_fix_fid_paths(V9fsPDU *= pdu, V9fsPath *olddir, while (g_hash_table_iter_next(&iter, &fid, (gpointer *) &tfidp)) { if (v9fs_path_is_ancestor(&oldpath, &tfidp->path)) { /* replace the name */ - v9fs_fix_path(&tfidp->path, &newpath, strlen(oldpath.data)); + if (v9fs_fix_path(&tfidp->path, &newpath, + strlen(oldpath.data)) < 0) { + clunk_fid(s, tfidp->fid); + } } } out: --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782309071; cv=none; d=zohomail.com; s=zohoarc; b=nZ7O9XAlzzH4RIhKtdyqi8vcCG/hhvqapaG4z4qIzR3NC4OnaAEExq1/kvrtDtpD5o16VNHsPzn4U7q9KNLlBLO1XdCCyg0RlYVEADHvB+M/P4EjNVWxA1EmwsmZKJaFg7iy/s2uK8ZbWDaOnCBbBCbsyBaXl6aJmrWd1uy75i4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782309071; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=deZHwNN5WIR4JTV2uTez3iP2bU6EN9kjhA9tphGZpPs=; b=VKOVdaLEvfUf5RQGur34W9piHxC8Y/YKdsfDzFmizYumUvX9JcnnRFHOtrCrOtyWjfO1F1jWDPBEUgKgcCyhSRm+h/ti9kJKkUCGU1nEcbgs702JpIdMCU9kNArTfCcBq2/AqCfX2blrsnsCgoQAp2KeuVG6jxzKsewLY71PATA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782309071619557.8444401881883; Wed, 24 Jun 2026 06:51:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNnH-0000qb-QG; Wed, 24 Jun 2026 09:37:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNnB-0000GH-2E; Wed, 24 Jun 2026 09:37:25 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNn9-000140-9K; Wed, 24 Jun 2026 09:37:24 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 67B4F1BA9E1; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 03DA43DEA30; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=y7G/QIRnRsuPk7/oRZJGZMI9BKG1yQA33e2zndC2EKs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=OyptgZ5iN8x7H0nbd4iR0eONsVzMjfLVrEQf1U1ZY2Mepxxyg3ec7ROQTVYJK6rfg AVSB3o04RBNsoxvHH3Lnfkml/B9GfY9zzC6fR68uFMbFLSJKeA6l1obn76iI4Ncuwn KhMowH9rVppESLwFlfp+czF6k3Rvlgu+7gjnQyXY2E8/v9DOlEX2Cdoh/Uy6d1zRZs 3cYaGYKjFef64VJqrh1YxIpGeLNGLd6WpoZtX56loUi7LnuqiRgQJIqXuJKMrFZSSV k7yJx1LtCzHp3vx3MurvCz91Obv5uMqLzUbIT2MbKvpZEuCVrbjklBBp0mchu4fU1K cObkANDnXqK+Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Fabiano Rosas , Michael Tokarev Subject: [Stable-11.0.2 047/107] tests/qtest/libqos: add qvirtqueue_reset_pool() for descriptor pool reset Date: Wed, 24 Jun 2026 16:30:52 +0300 Message-ID: <20260624133301.403266-47-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782309072970158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add a function to reset the virtqueue descriptor pool state without reinitializing the device. This is useful for tests that issue a high number of requests and are limited by the simplified virtio test driver's descriptor tracking, which decrements num_free but never increments it back. The function is safe for synchronous test code where requests are sent and completed before the next request is issued. Acked-by: Fabiano Rosas Link: https://lore.kernel.org/qemu-devel/96cf23eea1204b34443218fe76bd4a5eaf= 9163e8.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit be33c56898f8b18617cff91525f0b68abee8de07) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/libqos/virtio.c b/tests/qtest/libqos/virtio.c index 010ff40834..ccbb325222 100644 --- a/tests/qtest/libqos/virtio.c +++ b/tests/qtest/libqos/virtio.c @@ -464,6 +464,29 @@ bool qvirtqueue_get_buf(QTestState *qts, QVirtQueue *v= q, uint32_t *desc_idx, return true; } =20 +/* + * qvirtqueue_reset_pool: + * @vq: The virtqueue to reset + * + * Reset the descriptor pool state without reinitializing the device. + * This is useful for tests that issue a high number of requests and + * are limited by the simplified virtio test driver's descriptor tracking, + * which decrements num_free but never increments it back. + * + * This is only safe for synchronous test code where requests are + * sent and completed before the next request is issued. Do not use + * with asynchronous code where multiple requests may be in-flight. + * + * Note: This only resets the available descriptor pool (free_head, + * num_free). The used ring position (last_used_idx) is NOT reset + * and should continue to track consumed responses across iterations. + */ +void qvirtqueue_reset_pool(QVirtQueue *vq) +{ + vq->free_head =3D 0; + vq->num_free =3D vq->size; +} + void qvirtqueue_set_used_event(QTestState *qts, QVirtQueue *vq, uint16_t i= dx) { g_assert(vq->event); diff --git a/tests/qtest/libqos/virtio.h b/tests/qtest/libqos/virtio.h index e238f1726f..f17be0b9b6 100644 --- a/tests/qtest/libqos/virtio.h +++ b/tests/qtest/libqos/virtio.h @@ -150,6 +150,8 @@ void qvirtqueue_kick(QTestState *qts, QVirtioDevice *d,= QVirtQueue *vq, bool qvirtqueue_get_buf(QTestState *qts, QVirtQueue *vq, uint32_t *desc_id= x, uint32_t *len); =20 +void qvirtqueue_reset_pool(QVirtQueue *vq); + void qvirtqueue_set_used_event(QTestState *qts, QVirtQueue *vq, uint16_t i= dx); =20 void qvirtio_start_device(QVirtioDevice *vdev); --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308715; cv=none; d=zohomail.com; s=zohoarc; b=iAA/LzRrQVAHETysrBldLBXQi2cpdv8JciWCJQDM/bM61WNqBjJ10JbZJZ9z3C209Q6VRlR7QhfGdBoL5BMAD4xtOybyuy8Jh4dtPqXfJuhC7ljDb81HZB0i/tw0Nu+516QX+GjTKAxSrY0mphdZXZKWJ4O1m2QONg9QQ3RyoZA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308715; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=nFx5ll5IjzEhD464BUHRMl4++7Dr6szIvCcYB7TYdsA=; b=FdzmjxUNA4aHWA+uD2kCHseL9F34xs238VrIt/YixgJOPQTnVSckDRiuZ+XS3y3kQitr42JqROAtn4CgQlyEABFtk/Fktn/dnTJ/GgU1Gimw/IgUEE7wq5GMWuxy8JJGG55ix+KK+bbeEpAjWFI3sBDyCtfWLHXIS5hqrz9zpLY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308715033850.7754284670607; Wed, 24 Jun 2026 06:45:15 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNoZ-0002tE-Lw; Wed, 24 Jun 2026 09:38:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNnX-0001hG-Hf; Wed, 24 Jun 2026 09:37:48 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNnV-00014P-Ni; Wed, 24 Jun 2026 09:37:47 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 753A51BA9E2; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 13FB83DEA31; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=sq3wfnIuv+1QgSiiJ3QDn+46DBYkyT99RJCkygeD7uc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=rF0w6fTK8K5oHlg30iGchV1f2lcSM6DJ7qROJ+sligU4xvTJkcSspCiphH/tyAFkx B2zCuOwkdlHDcX0Pek+ISYcApG/6bUBYXN1qLKo0wWaocNRgYDemLQDpbOPiFnBLHq ItSKiDPlMPi1SJCjc3zQIi5fML70u/loxexYiBNquAFa1SXVVayBgHzzaJbgLE4ay5 QkaqDPqPdR9eZ+mAxjTuH9vR+yQVq84pjkWVDzzoaNf6uSdF42UjN1aQfsD8Wh8qC2 h+OlHfR3LaNBdsLv51N8EOVeWa6828RoNGGYgnf133Q9tbz4RRKOKHzgyJhx9lAq5P 8eWlzNSDg+aUg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-11.0.2 048/107] tests/9pfs: add deep absolute path test Date: Wed, 24 Jun 2026 16:30:53 +0300 Message-ID: <20260624133301.403266-48-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308716331158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck Add fs_deep_absolute_path test that creates a deep directory structure with an absolute path length exceeding 16-bit range (i.e. >65536) to verify the previous buffer overflow fix. This is a slow test (may take several seconds) and therefore registered as "slow" test and not running by default. Use -m slow to run this test. Link: https://gitlab.com/qemu-project/qemu/-/issues/3358 Link: https://lore.kernel.org/qemu-devel/933552b2cfc2c442fac7f4e68c777dce20= ee8d7e.1779126034.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 198627807a6b94e2aab157cf345f98edb1ac1a7a) Signed-off-by: Michael Tokarev diff --git a/tests/qtest/virtio-9p-test.c b/tests/qtest/virtio-9p-test.c index ac38ccf595..1c69d41e33 100644 --- a/tests/qtest/virtio-9p-test.c +++ b/tests/qtest/virtio-9p-test.c @@ -14,6 +14,7 @@ =20 #include "qemu/osdep.h" #include "qemu/module.h" +#include "libqos/virtio.h" #include "libqos/virtio-9p-client.h" =20 #define twalk(...) v9fs_twalk((TWalkOpt) __VA_ARGS__) @@ -752,6 +753,72 @@ static void fs_use_after_unlink(void *obj, void *data, g_assert_cmpint(attr.size, =3D=3D, 2001); } =20 +/* https://gitlab.com/qemu-project/qemu/-/issues/3358 */ +static void fs_deep_absolute_path(void *obj, void *data, + QGuestAllocator *t_alloc) +{ + QVirtio9P *v9p =3D obj; + v9fs_set_allocator(t_alloc); + + if (!g_test_slow()) { + g_test_skip("This is a slow test, run with -m slow"); + return; + } + + GString *path =3D g_string_new("/"); + char name[256]; + uint32_t current_fid =3D 0; + + tattach({ .client =3D v9p }); + + /* Create deep directory structure until absolute path length + * exceeds 16-bit range. + */ + while (path->len <=3D 65536) { + /* use 255-byte name (NAME_MAX) to reduce iterations to ~257 */ + memset(name, 'A', 255); + name[255] =3D '\0'; + + /* create the directory relative to current FID */ + tmkdir({ + .client =3D v9p, + .dfid =3D current_fid, + .name =3D name + }); + + /* just for locally tracking the current path length */ + g_string_append(path, name); + g_string_append(path, "/"); + + /* acquire new FID for the newly created directory */ + char *wnames[] =3D { name }; + current_fid =3D twalk({ + .client =3D v9p, + .fid =3D current_fid, + .nwname =3D 1, + .wnames =3D wnames + }).newfid; + + /* Reset descriptor pool to avoid exhaustion. The simplified + * virtio test driver does never free descriptors back to the pool + * after use, so we must manually reset it for the required high + * amount of 9p requests here. + */ + qvirtqueue_reset_pool(v9p->vq); + } + + /* check if the deepest directory is accessible */ + v9fs_attr attr =3D {}; + tgetattr({ + .client =3D v9p, + .fid =3D current_fid, + .request_mask =3D P9_GETATTR_BASIC, + .rgetattr.attr =3D &attr + }); + + g_string_free(path, TRUE); +} + static void cleanup_9p_local_driver(void *data) { /* remove previously created test dir when test is completed */ @@ -819,6 +886,8 @@ static void register_virtio_9p_test(void) &opts); qos_add_test("local/use_after_unlink", "virtio-9p", fs_use_after_unlin= k, &opts); + qos_add_test("local/deep_absolute_path", "virtio-9p", + fs_deep_absolute_path, &opts); } =20 libqos_init(register_virtio_9p_test); --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308414; cv=none; d=zohomail.com; s=zohoarc; b=kOHXTJFzUZMEwRq3icK8dG5/UxkU5KOliXHSIF/kl9w0rIRJuSRG0CuwW/s4hIywBck/4w0wClTAxsC4kmgxZ+3MHdVY73MPDW/o3PDLglCx/bUml6+r4x7q2o0ish3Rqw+zucrIRFuPCRJ0RbVLtJ/bNd6sn4Ck6AWuZCpJGO4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308414; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=QexvaD/MiGmJTC9cP/EjJxH5JoDHVk3sdWXGWFlh3Lk=; b=SjE1e2tkMOjQVgmqt34t9hPxSA/aXoWJWXz7AMi434JSmWoDGIcCxmrKQQIUGsdnNXtm7Y+TGOt388Ru4huYBiyxLpwCxY3Ym94QOAlh0Wzt1UY3VyAHFzeub9/qDitkA5jZSPqPvlZ14RZfA9ByubT+el6e+HW0ISGAS/TEiog= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308414502986.3415256602161; Wed, 24 Jun 2026 06:40:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNoV-0002JB-9a; Wed, 24 Jun 2026 09:38:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNnY-0001hh-IC; Wed, 24 Jun 2026 09:37:49 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNnW-00014d-No; Wed, 24 Jun 2026 09:37:48 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 857801BA9E3; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 2192F3DEA32; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=ubdO+zpxQThsSC68lkwISaMv3bI5tKubzpj/X8KopDg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=s+Ww2xFa100XL0+wNRd0dV5pYHumIwwXLYhYsnKvpekXU4SWBpaoIJKXIgKz5vZKE WtnS8kys35bOFW9Vi+KoQw+g375ZQpefds2GtameUx4R3hmXyXq9py+t6kZA0YJQj6 p9g657++rIJIqMm3P8MhI6A1IdueM36YYf2nWIg/m4FUOhOCsEgdXcl4SJUmQstNd3 7kEfd11lL/fZgptjROkvwt+/Of57lbOU8x1bfRX5iNBBJbdbZosZkwuYDla9qOvq4T A2PrjUnkliiNmOLpLzHuCU90jUSZ13GnzZ1FHV1UQTiiRl14oWVr2rjSGi94hysqSv WXJTouxfp9BJw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, sin99xx , Christian Schoenebeck , Michael Tokarev Subject: [Stable-11.0.2 049/107] 9pfs: fix missing rename lock in v9fs_co_readdir_many (CVE-2026-48004) Date: Wed, 24 Jun 2026 16:30:54 +0300 Message-ID: <20260624133301.403266-49-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308414642158500 Content-Type: text/plain; charset="utf-8" From: sin99xx v9fs_co_readdir_many() dispatches do_readdir_many() to a worker thread that reads V9fsFidState's path.data without holding a rename lock. A concurrent rename request, e.g. of its parent dir, causes the FID's absolute path to be altered by freeing the old path string and assigning a new one. This causes a heap-use-after-free race condition while do_readdir_many() is still accessing the old object. This allows a DoS by an unprivileged guest user. Fix this by wrapping the worker thread dispatch block within a pair of v9fs_path_read_lock() and v9fs_path_unlock() calls, like it's done at other places. Fixes: 2149675b195f ("9pfs: add new function v9fs_co_readdir_many()") Fixes: CVE-2026-48004 Reported-by: sin99xx Signed-off-by: sin99xx [Christian Schoenebeck: add commit log message] Link: https://lore.kernel.org/qemu-devel/E1wPkYi-000adH-4E@kylie.crudebyte.= com Signed-off-by: Christian Schoenebeck (cherry picked from commit 5a8da7e979f1f56b1cab82c2354833f309f1a78f) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/codir.c b/hw/9pfs/codir.c index bce7dd96e9..5568399343 100644 --- a/hw/9pfs/codir.c +++ b/hw/9pfs/codir.c @@ -220,13 +220,16 @@ int coroutine_fn v9fs_co_readdir_many(V9fsPDU *pdu, V= 9fsFidState *fidp, bool dostat) { int err =3D 0; + V9fsState *s =3D pdu->s; =20 if (v9fs_request_cancelled(pdu)) { return -EINTR; } + v9fs_path_read_lock(s); v9fs_co_run_in_worker({ err =3D do_readdir_many(pdu, fidp, entries, offset, maxsize, dosta= t); }); + v9fs_path_unlock(s); return err; } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308456; cv=none; d=zohomail.com; s=zohoarc; b=a2wTOoREmpsGfEyuQ9LTV19cp+vE0XIPP82mUidxRTJP+9kwNWOOVxOdvWu9qfoj6ZgJoDa/ShXAwzWDLUJidn5ZgevXsW5MXoUZ/ASt4L5ZNuIPmVZ2z+f+2Kk5KbS/XLn/wwLrV/qV9nrHszvUAdwfHCGgFBHL/e3d3TVYBis= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308456; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lEIED/Wc9tzJFjCP7matfedwXpt/sEA5sQFT6daDr6M=; b=T2/LhMwfJRFMsXCs3V2xoxJJRYPODxTfE9iDaRpHj4kVNZALlMxqmB4PAWFcpLbGc5IXS2N9dQIcTDCynevJp4laREqVJWGRX5pz09rSPDSgHnkJPEtpyHoljjnxl7bnrzscRCqK3B7VQUb1yrgX4H0wlgUB8hH9gwXCiUIMTa8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308456947688.7179450794537; Wed, 24 Jun 2026 06:40:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNoX-0002YK-2R; Wed, 24 Jun 2026 09:38:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNne-0001jQ-Mr; Wed, 24 Jun 2026 09:38:00 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNnY-000187-V7; Wed, 24 Jun 2026 09:37:50 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 985401BA9E4; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 320DF3DEA33; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=L7RCWWMvQS+EFrMDUd1cQg3OODBBHJtF30sWO9d+Tds=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=lCNCAKaQXMY3Ngn5Tv8RSMf0ZLYnt2Bx5U9V3qxWSqtrvupOvP3/jUO5k82+Vs9ei 6GgZ7Ntgtl6nVcPRq3dt0LJZStZ0aeFobA5BLu2KKaiIUpuJE+cK85DeL7wlldgosH VW1E9AzCZCgA2yGvga57cZ3LvxVzeL8tSpGfeuO/ByEOBP8ecFvbdgHUM5GgRvE+UP vnOyNIVpAW2uI6TE+CLXQBYfcjTBWboAfNIKqYpM1rhVxoBa6dvTlN+0q7gxdCZlSL twskqPzayE1XiqibjNxTrXJFhgE5EiJw0JEMBBjt0gPcnnakVT62w1JaLFmzR8Vi8U PaanL1kWTijyw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Markus Armbruster , Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 050/107] util/envlist: fix prefix-match in envlist_unsetenv() name lookup Date: Wed, 24 Jun 2026 16:30:55 +0300 Message-ID: <20260624133301.403266-50-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308459035158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" envlist_unsetenv() looked up the entry to remove with strncmp(entry->ev_var, env, strlen(env)). The comparison length is the requested name's length, so any stored entry whose name *starts* with that name compares equal. envlist_setenv() inserts at the head of the list, so the first hit wins: with FOO=3D... stored first and FOOBAR=3D... stored afterward, envlist_unsetenv("FOO") iterates from the head, matches FOOBAR=3D... on the prefix, and drops it instead of FOO=3D... linux-user and bsd-user reach this code via the -U command-line switch, so the bug is reachable from a normal qemu-user invocation. envlist_setenv() used the same strncmp pattern but with envname_len =3D (eq_sign - env + 1), so the '=3D' byte sat inside the compared window and acted as an implicit boundary. setenv was therefore not buggy -- but the safety lived in the byte layout of ev_var rather than in the entry, so a future edit could easily drift the two sites apart again. Store the name length on each entry at insertion time and compare with explicit length equality plus memcmp via a small helper. Use the helper at both lookup sites so the boundary becomes a structural property of the entry: envlist_unsetenv() stops prefix-matching, and envlist_setenv()'s self-search no longer depends on the '=3D' byte serving as a sentinel. Fixes: 04a6dfebb6b5 ("linux-user: Add generic env variable handling") Signed-off-by: Denis V. Lunev Reviewed-by: Stefan Hajnoczi Message-id: 20260520212628.479772-2-den@openvz.org Cc: Stefan Hajnoczi Cc: Markus Armbruster Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi (cherry picked from commit c131ae56c13ffe6bd7089cf0d9bd00a7c2dbc71f) Signed-off-by: Michael Tokarev diff --git a/util/envlist.c b/util/envlist.c index 15fdbb109d..196c92c190 100644 --- a/util/envlist.c +++ b/util/envlist.c @@ -3,7 +3,8 @@ #include "qemu/envlist.h" =20 struct envlist_entry { - const char *ev_var; /* actual env value */ + const char *ev_var; /* actual env value: "NAME=3DVALUE" */ + size_t ev_name_len; /* length of NAME (offset of '=3D') */ QLIST_ENTRY(envlist_entry) ev_link; }; =20 @@ -12,6 +13,13 @@ struct envlist { size_t el_count; /* number of entries */ }; =20 +static inline bool envlist_name_eq(const struct envlist_entry *entry, + const char *name, size_t name_len) +{ + return entry->ev_name_len =3D=3D name_len && + memcmp(entry->ev_var, name, name_len) =3D=3D 0; +} + /* * Allocates new envlist and returns pointer to it. */ @@ -67,7 +75,7 @@ envlist_setenv(envlist_t *envlist, const char *env) /* find out first equals sign in given env */ if ((eq_sign =3D strchr(env, '=3D')) =3D=3D NULL) return (EINVAL); - envname_len =3D eq_sign - env + 1; + envname_len =3D eq_sign - env; =20 /* * If there already exists variable with given name @@ -76,8 +84,9 @@ envlist_setenv(envlist_t *envlist, const char *env) */ for (entry =3D envlist->el_entries.lh_first; entry !=3D NULL; entry =3D entry->ev_link.le_next) { - if (strncmp(entry->ev_var, env, envname_len) =3D=3D 0) + if (envlist_name_eq(entry, env, envname_len)) { break; + } } =20 if (entry !=3D NULL) { @@ -90,6 +99,7 @@ envlist_setenv(envlist_t *envlist, const char *env) =20 entry =3D g_malloc(sizeof(*entry)); entry->ev_var =3D g_strdup(env); + entry->ev_name_len =3D envname_len; QLIST_INSERT_HEAD(&envlist->el_entries, entry, ev_link); =20 return (0); @@ -119,8 +129,9 @@ envlist_unsetenv(envlist_t *envlist, const char *env) envname_len =3D strlen(env); for (entry =3D envlist->el_entries.lh_first; entry !=3D NULL; entry =3D entry->ev_link.le_next) { - if (strncmp(entry->ev_var, env, envname_len) =3D=3D 0) + if (envlist_name_eq(entry, env, envname_len)) { break; + } } if (entry !=3D NULL) { QLIST_REMOVE(entry, ev_link); --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308932; cv=none; d=zohomail.com; s=zohoarc; b=MoM2O7mMt96YJJAXeRJo2Mp8iPz3qwDMPtYwdl4XYNRFcKzqHCYz00CuO9WbbUPEfKm5em20TAjeqMVlQ70UYmWpxxbvTTj3hVRczD2ar1u8Bdo8VB0Tcs5LIt/ZG1O0p5vKtg0Hr+6UwQQurgjo8lRsRoZLUoY9CCXpJ3ki+Mc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308932; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GSEA0amuO7bgV7vcEO7hagscvXL1YsSeiPv4CgA7SiA=; b=HSJOk8sm8vQ0qWVAHMpFGHMg7yNkhUgIe7VjiUIFa5aX17c2NrU3is469/57XcccG3iBZI+fRA++OykdoRfARIbNWGESEMa8/hZznxXyw2LmwQu4cVe6EoVlwl2mWcVuqQKLL9ZoRLfoROQ5dIpqYbgHD/7jBZ/s0hTQieNjKkg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308932635771.9671397672624; Wed, 24 Jun 2026 06:48:52 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNoU-0002EC-AO; Wed, 24 Jun 2026 09:38:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNne-0001jR-Ob; Wed, 24 Jun 2026 09:38:00 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNnZ-00018L-VY; Wed, 24 Jun 2026 09:37:52 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id AD1521BA9E5; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 4532A3DEA34; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=JXs/WU3mOiJFzXrfD96WT7o1RIgEL0n70leqESDJyxU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=N9P0oOgXJw+ulwGCOhwQY+7h3FS8+QPJ6C8jl340ZKmctXrJHu1MbhnIBHuECf2b5 uPuTL3eH6tAhI6qdyxXBXSzzUSI835q+/G6Cm3lpyoWURkABTDk/4cbmQP9q2vAwI1 0EI0oSHjeJh1iZ3lrZcmprZpVETqaPiapC/ZSctFlXeCDugWsrfFW5/uCCW4nx1exi asP5loavLNZvXMIgRHtE7mUWW4o/E79rnxZbu6mi/MIqken5ZnLPK/W6GDdmhaVYiq GgAzr9TUYZhof8TcBW2lk+a2P2bid5qa2fWWSJhYQeH16GX/Nnj9gfcACvLjyvVpMt brPRIQK5MnOKA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Denis V. Lunev" , Stefan Hajnoczi , Markus Armbruster , Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 051/107] tests/unit: add test-envlist covering setenv/unsetenv name matching Date: Wed, 24 Jun 2026 16:30:56 +0300 Message-ID: <20260624133301.403266-51-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308933985158500 Content-Type: text/plain; charset="utf-8" From: "Denis V. Lunev" util/envlist had no test coverage. Add tests/unit/test-envlist exercising the public envlist API and pinning down the prefix-match hazard fixed in the previous commit: - envlist_unsetenv("FOO") must not remove an entry named "FOOBAR"; - envlist_setenv("FOO=3D...") must not replace an existing "FOOBAR=3D..." entry placed earlier in the list (envlist_setenv() inserts at the head, so the first prefix match wins under the old strncmp rule). Also cover the rest of the contract: head-insertion order observed through envlist_to_environ(), replacement of an existing variable, the count argument of envlist_to_environ(), and the documented EINVAL paths (NULL inputs, setenv without '=3D', unsetenv with '=3D'). Signed-off-by: Denis V. Lunev Reviewed-by: Stefan Hajnoczi Message-id: 20260520212628.479772-3-den@openvz.org Cc: Stefan Hajnoczi Cc: Markus Armbruster Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi (cherry picked from commit 05221c600a5f3ef657d71aeaea632c5f1bab3a2d) Signed-off-by: Michael Tokarev diff --git a/tests/unit/meson.build b/tests/unit/meson.build index 41e8b06c33..f768e882a4 100644 --- a/tests/unit/meson.build +++ b/tests/unit/meson.build @@ -48,6 +48,7 @@ tests =3D { 'test-qapi-util': [], 'test-interval-tree': [], 'test-fifo': [], + 'test-envlist': [], } =20 if have_system or have_tools diff --git a/tests/unit/test-envlist.c b/tests/unit/test-envlist.c new file mode 100644 index 0000000000..53813dd4de --- /dev/null +++ b/tests/unit/test-envlist.c @@ -0,0 +1,196 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +/* + * envlist tests + * + * Copyright 2026 Virtuozzo International GmbH + * + * Authors: + * Denis V. Lunev + */ + +#include "qemu/osdep.h" +#include "qemu/envlist.h" + +static void free_environ(char **env) +{ + char **p; + + for (p =3D env; *p !=3D NULL; p++) { + g_free(*p); + } + g_free(env); +} + +static const char *find_env(char **env, const char *name) +{ + size_t name_len =3D strlen(name); + char **p; + + for (p =3D env; *p !=3D NULL; p++) { + if (strncmp(*p, name, name_len) =3D=3D 0 && (*p)[name_len] =3D=3D = '=3D') { + return *p + name_len + 1; + } + } + return NULL; +} + +static void test_envlist_basic(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + /* empty list */ + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 0); + g_assert_null(env[0]); + free_environ(env); + + /* add */ + g_assert_cmpint(envlist_setenv(el, "A=3D1"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "B=3D2"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "A"), =3D=3D, "1"); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* replace */ + g_assert_cmpint(envlist_setenv(el, "A=3D42"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "A"), =3D=3D, "42"); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* unset existing */ + g_assert_cmpint(envlist_unsetenv(el, "A"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + g_assert_null(find_env(env, "A")); + g_assert_cmpstr(find_env(env, "B"), =3D=3D, "2"); + free_environ(env); + + /* unset non-existing is a no-op success */ + g_assert_cmpint(envlist_unsetenv(el, "NOPE"), =3D=3D, 0); + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + free_environ(env); + + envlist_free(el); +} + +/* + * envlist_setenv() inserts at the head; envlist_to_environ() walks + * head-to-tail, so the last setenv comes out first. + */ +static void test_envlist_head_insertion_order(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "A=3D1"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "B=3D2"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "C=3D3"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 3); + g_assert_cmpstr(env[0], =3D=3D, "C=3D3"); + g_assert_cmpstr(env[1], =3D=3D, "B=3D2"); + g_assert_cmpstr(env[2], =3D=3D, "A=3D1"); + g_assert_null(env[3]); + + free_environ(env); + envlist_free(el); +} + +static void test_envlist_einval(void) +{ + envlist_t *el =3D envlist_create(); + + /* NULL list */ + g_assert_cmpint(envlist_setenv(NULL, "A=3D1"), =3D=3D, EINVAL); + g_assert_cmpint(envlist_unsetenv(NULL, "A"), =3D=3D, EINVAL); + + /* NULL string */ + g_assert_cmpint(envlist_setenv(el, NULL), =3D=3D, EINVAL); + g_assert_cmpint(envlist_unsetenv(el, NULL), =3D=3D, EINVAL); + + /* setenv: missing '=3D' */ + g_assert_cmpint(envlist_setenv(el, "NOEQ"), =3D=3D, EINVAL); + + /* unsetenv: name must not contain '=3D' */ + g_assert_cmpint(envlist_unsetenv(el, "A=3DB"), =3D=3D, EINVAL); + + envlist_free(el); +} + +/* + * Regression: envlist_unsetenv("FOO") must not remove an entry named + * "FOOBAR" -- the previous strncmp(entry, name, strlen(name)) lookup + * prefix-matched. To trigger the bug, the longer-named entry has to + * be ahead of the target in the list: envlist_setenv() inserts at + * the head, so we add FOO first and FOOBAR last. + */ +static void test_envlist_unsetenv_no_prefix_match(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "FOO=3Dy"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "FOOBAR=3Dx"), =3D=3D, 0); + + g_assert_cmpint(envlist_unsetenv(el, "FOO"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 1); + g_assert_cmpstr(find_env(env, "FOOBAR"), =3D=3D, "x"); + g_assert_null(find_env(env, "FOO")); + + free_environ(env); + envlist_free(el); +} + +/* + * envlist_setenv() must not replace a prior FOOBAR=3D... entry when + * setting FOO=3D... The pre-fix code happened to be safe here only + * because it included the trailing '=3D' byte in its strncmp length; + * this test pins down the post-fix contract that the name boundary + * is a property of the entry, not of the encoded form. + */ +static void test_envlist_setenv_no_prefix_match(void) +{ + envlist_t *el =3D envlist_create(); + char **env; + size_t count; + + g_assert_cmpint(envlist_setenv(el, "FOOBAR=3Dx"), =3D=3D, 0); + g_assert_cmpint(envlist_setenv(el, "FOO=3Dy"), =3D=3D, 0); + + env =3D envlist_to_environ(el, &count); + g_assert_cmpuint(count, =3D=3D, 2); + g_assert_cmpstr(find_env(env, "FOOBAR"), =3D=3D, "x"); + g_assert_cmpstr(find_env(env, "FOO"), =3D=3D, "y"); + + free_environ(env); + envlist_free(el); +} + +int main(int argc, char *argv[]) +{ + g_test_init(&argc, &argv, NULL); + + g_test_add_func("/envlist/basic", test_envlist_basic); + g_test_add_func("/envlist/head_insertion_order", + test_envlist_head_insertion_order); + g_test_add_func("/envlist/einval", test_envlist_einval); + g_test_add_func("/envlist/unsetenv_no_prefix_match", + test_envlist_unsetenv_no_prefix_match); + g_test_add_func("/envlist/setenv_no_prefix_match", + test_envlist_setenv_no_prefix_match); + + return g_test_run(); +} --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308632; cv=none; d=zohomail.com; s=zohoarc; b=aKum7A5l+eb9OB9idxafbtRXflsB/dwEuKx3eiZ9V1NWU4yWv1ogJiAKvzLjfyatQCz3qPShse2XyVJN88WyQF+3bz57v3Tja9oeV3SybKM4TX3fsgGtbUMyW1DiWqZ4x4U95NJ6WBPXZAujWC+kVY7Op9KQI6nc6orsCzY23bI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308632; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=FfDXbBIvb5Fhy5ZyiCl3vfoqkFlFtMxYuICP36qSqq0=; b=c3eBxKb13M+zne1Mq5/IoZpW1CrRPZ/jK+KIrrfW2lTwui1l3cOH+NV20bQLJl3aUtxqBmVHIn5IXA7iFIqmHcca8+s3J0PLHvbKDCyQyw4xQKndrEa5KOcDQmzNGmTuZWSwZxeIroXwjw9tBGEMOQfV2ZmF2Oo8/86S+XmDGU0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17823086321461016.3799930430689; Wed, 24 Jun 2026 06:43:52 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNoY-0002iE-6d; Wed, 24 Jun 2026 09:38:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNnk-0001kh-JE; Wed, 24 Jun 2026 09:38:02 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNng-00019H-45; Wed, 24 Jun 2026 09:37:58 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BFD781BA9E6; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 595D23DEA35; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=VEkwjzgqpOMRnj24Pf/csY6+NNWUGNA5MVFit704Ems=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=lOJSQqjNprXMsMOdWktS3UcuLaXvSPb16FSUsaVID9iunZCf5ai+aLJqOHEpiaXnf 72aAbcu9hpKdzCVF+/W5+RxEK0VnrLnZsB7qwO+ad93W4V3fX8M28ORCuRE/2kcJEY 9+gWwhD4wFEDu8sOU7XUW3EVy8uMi0Rz18wHPC9Ykimqxdx3Brfdgmqx62ILRmA0KG 6qyXG6McmxuwSZbRPz0KLYzm8FF5d66zcGWq4SRqWgiZBrvSTj/SxXWtfAPhX6PON1 zYlq5XtmScACou6LJT+75Q+2YS5xataWbtXNurr6fzNUnJVOVbrtgfwgFh/YVdwCrR HXnL3QsfVwj0w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Alex=20Benn=C3=A9e?= , Pierrick Bouvier , Thomas Huth , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-11.0.2 052/107] ci: drop cirrus MacOS build Date: Wed, 24 Jun 2026 16:30:57 +0300 Message-ID: <20260624133301.403266-52-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308633550158500 From: Alex Benn=C3=A9e CirrusCI is closing down soon so time to migrate. Reviewed-by: Pierrick Bouvier Reviewed-by: Thomas Huth Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-ID: <20260526110243.470002-6-alex.bennee@linaro.org> Signed-off-by: Alex Benn=C3=A9e (cherry picked from commit 984b192bdf371e275fb4226ca5047c1fff1de972) Signed-off-by: Michael Tokarev diff --git a/.gitlab-ci.d/cirrus.yml b/.gitlab-ci.d/cirrus.yml index f2a9a64b76..b71ab090b6 100644 --- a/.gitlab-ci.d/cirrus.yml +++ b/.gitlab-ci.d/cirrus.yml @@ -44,17 +44,3 @@ x64-freebsd-14-build: INSTALL_COMMAND: pkg install -y CONFIGURE_ARGS: --target-list-exclude=3Darm-softmmu,i386-softmmu,mips6= 4el-softmmu,mipsel-softmmu,mips-softmmu,ppc-softmmu,sh4eb-softmmu,xtensa-so= ftmmu --enable-rust TEST_TARGETS: check - -aarch64-macos-build: - extends: .cirrus_build_job - variables: - NAME: macos-14 - CIRRUS_VM_INSTANCE_TYPE: macos_instance - CIRRUS_VM_IMAGE_SELECTOR: image - CIRRUS_VM_IMAGE_NAME: ghcr.io/cirruslabs/macos-runner:sonoma - UPDATE_COMMAND: brew update - INSTALL_COMMAND: brew install - PATH_EXTRA: /opt/homebrew/ccache/libexec:/opt/homebrew/gettext/bin - PKG_CONFIG_PATH: /opt/homebrew/curl/lib/pkgconfig:/opt/homebrew/ncurse= s/lib/pkgconfig:/opt/homebrew/readline/lib/pkgconfig - CONFIGURE_ARGS: --target-list-exclude=3Darm-softmmu,i386-softmmu,mips6= 4-softmmu,mipsel-softmmu,mips-softmmu,ppc-softmmu,sh4-softmmu,xtensaeb-soft= mmu --enable-rust - TEST_TARGETS: check-unit check-block check-qapi-schema check-softfloat= check-qtest-x86_64 diff --git a/.gitlab-ci.d/cirrus/macos-14.vars b/.gitlab-ci.d/cirrus/macos-= 14.vars deleted file mode 100644 index def77cfdea..0000000000 --- a/.gitlab-ci.d/cirrus/macos-14.vars +++ /dev/null @@ -1,16 +0,0 @@ -# THIS FILE WAS AUTO-GENERATED -# -# $ lcitool variables macos-14 qemu -# -# https://gitlab.com/libvirt/libvirt-ci - -CCACHE=3D'/opt/homebrew/bin/ccache' -CPAN_PKGS=3D'' -CROSS_PKGS=3D'' -MAKE=3D'/opt/homebrew/bin/gmake' -NINJA=3D'/opt/homebrew/bin/ninja' -PACKAGING_COMMAND=3D'brew' -PIP3=3D'/opt/homebrew/bin/pip3' -PKGS=3D'bash bc bindgen bison bzip2 capstone ccache cmocka coreutils ctags= curl dbus diffutils dtc flex gcovr gettext git glib gnu-sed gnutls gtk+3 g= tk-vnc jemalloc jpeg-turbo json-c libcbor libepoxy libffi libgcrypt libiscs= i libnfs libpng libslirp libssh libtasn1 libusb llvm lzo make meson mtools = ncurses nettle ninja pixman pkg-config python-setuptools python3 rpm2cpio r= ust sdl2 sdl2_image snappy socat sparse spice-protocol swtpm tesseract usbr= edir vde vte3 vulkan-tools xorriso zlib zstd' -PYPI_PKGS=3D'PyYAML numpy pillow sphinx sphinx-rtd-theme tomli' -PYTHON=3D'/opt/homebrew/bin/python3' diff --git a/tests/lcitool/refresh b/tests/lcitool/refresh index e4d01d792b..fa4a16e358 100755 --- a/tests/lcitool/refresh +++ b/tests/lcitool/refresh @@ -311,7 +311,6 @@ try: # Cirrus packages lists for GitLab # generate_cirrus("freebsd-14") - generate_cirrus("macos-14") =20 # # VM packages lists --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308976; cv=none; d=zohomail.com; s=zohoarc; b=TQpYOUx4Dhcp5AqJTyFxtfcmWU1AU5ATTe5Gv3HpeXaTAzsK3lHWM7SNs5K6qiW8x54x1OjBTHzBzfpNnK+jQLPJ3Og9viVi32TDFnpPcO28WAuTT0tPcMBjKgj4XYzHRVrK18/RR9aWSRY6ctZ73Ji6brq4aA9IRhagLhQC0zc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308976; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=5Ha0+t9PJjPX0GI1Oz+XYE2dURAy0ScL88zAlXAzdSc=; b=H+BcA1V4FvC+vAv+agPWlBxmr40QK71peCBecKSzdFENAKlHjm17mDsAkAfvCHdYo/c3lO0bQ9Xb4koaI+C5Z8NkKOHSKKqXoJQR+joWynbkaFUIPBbcvlDqodRPXrcIjSMi975/C5c/w3m+wcDDo13i8ZpAG/rvwSCzJhkWYU8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308976003630.9648778069748; Wed, 24 Jun 2026 06:49:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNoa-00033A-QD; Wed, 24 Jun 2026 09:38:53 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNo4-0001ux-7U; Wed, 24 Jun 2026 09:38:24 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNo0-00019J-6Z; Wed, 24 Jun 2026 09:38:19 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id CFD961BA9E7; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6BE073DEA36; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=FCs91j2jahY7iqlzgzBO1t4k/xo/nVlyyBYkVbrJbIo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=AfaBqjQbZXiQvD/7JYpNLbNBUMdPtbX5I0YV22ZnOO7zn9ipW2Ku7NtX7liyRzx9s cKSc4oxgw20MM27JuzW0fafUmbHUO3Q8LAD0T8HZxdCv+iNNuIsrSJnR9tc+GqZ5tL 37QoXIoaYanYXa+IKC/mTSSq5HMrI2xoAj7Uqu7068xU+cT6pAVSyFpoVouFNr4Kn0 /litUqhWomPM8Mp5J4I1uuvXxYHjd6MHnj7nSi1+lywS4uogi9ac9QsErtzAE2qkHZ +OzhvpujFZVPtnQQXs+npLnX7nJScLNQzbdQ1pbR9BDrMdlWzXBxanjVP39KEFgTno jfG5RrZbn0y0Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Alex=20Benn=C3=A9e?= , Pierrick Bouvier , Michael Tokarev Subject: [Stable-11.0.2 053/107] gitlab: add initial MacOS 15 on gitlab runner Date: Wed, 24 Jun 2026 16:30:58 +0300 Message-ID: <20260624133301.403266-53-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308976240158500 From: Alex Benn=C3=A9e The gitlab runners are currently in beta but available to projects on the Premium and Ultimate plans (which QEMU is via the Open Source program). We install some compilers via brew so we can run some of the check-tcg softmmu test cases. We disable rust as the version is too old. We disable plugins because we haven't taught the test harness about .dynlib vs .so yet. There is a discrepancy between the vars and version of MacOS because lcitool needs teaching about other versions (although I don't think it matters as brew is shared across versions). Reviewed-by: Pierrick Bouvier Message-ID: <20260526110243.470002-7-alex.bennee@linaro.org> Signed-off-by: Alex Benn=C3=A9e (cherry picked from commit 7684e78132905393e604014dce3185def4114108) Signed-off-by: Michael Tokarev diff --git a/.gitlab-ci.d/macos-14.vars b/.gitlab-ci.d/macos-14.vars new file mode 100644 index 0000000000..def77cfdea --- /dev/null +++ b/.gitlab-ci.d/macos-14.vars @@ -0,0 +1,16 @@ +# THIS FILE WAS AUTO-GENERATED +# +# $ lcitool variables macos-14 qemu +# +# https://gitlab.com/libvirt/libvirt-ci + +CCACHE=3D'/opt/homebrew/bin/ccache' +CPAN_PKGS=3D'' +CROSS_PKGS=3D'' +MAKE=3D'/opt/homebrew/bin/gmake' +NINJA=3D'/opt/homebrew/bin/ninja' +PACKAGING_COMMAND=3D'brew' +PIP3=3D'/opt/homebrew/bin/pip3' +PKGS=3D'bash bc bindgen bison bzip2 capstone ccache cmocka coreutils ctags= curl dbus diffutils dtc flex gcovr gettext git glib gnu-sed gnutls gtk+3 g= tk-vnc jemalloc jpeg-turbo json-c libcbor libepoxy libffi libgcrypt libiscs= i libnfs libpng libslirp libssh libtasn1 libusb llvm lzo make meson mtools = ncurses nettle ninja pixman pkg-config python-setuptools python3 rpm2cpio r= ust sdl2 sdl2_image snappy socat sparse spice-protocol swtpm tesseract usbr= edir vde vte3 vulkan-tools xorriso zlib zstd' +PYPI_PKGS=3D'PyYAML numpy pillow sphinx sphinx-rtd-theme tomli' +PYTHON=3D'/opt/homebrew/bin/python3' diff --git a/.gitlab-ci.d/macos.yml b/.gitlab-ci.d/macos.yml new file mode 100644 index 0000000000..c93bf12a29 --- /dev/null +++ b/.gitlab-ci.d/macos.yml @@ -0,0 +1,47 @@ +.macos_job_template: + extends: .base_job_template + stage: build + tags: + - saas-macos-large-m2pro + needs: [] + timeout: 80m + artifacts: + name: "$CI_JOB_NAME-$CI_COMMIT_REF_SLUG" + expire_in: 7 days + paths: + - build/meson-logs/ + - build/tests/tcg/ + reports: + junit: build/meson-logs/*.junit.xml + when: always + before_script: + - set -o allexport + - source .gitlab-ci.d/macos-14.vars + - set +o allexport + - export PATH=3D"$PATH_EXTRA:$PATH" + - export PKG_CONFIG_PATH=3D"$PKG_CONFIG_PATH" + - brew update + - brew install $PKGS + - brew install gdb aarch64-elf-gcc i686-elf-gcc x86_64-elf-gcc + - if test -n "$PYPI_PKGS" ; then PYLIB=3D$($PYTHON -c 'import sysconfi= g; print(sysconfig.get_path("stdlib"))'); rm -f $PYLIB/EXTERNALLY-MANAGED; = $PIP3 install --break-system-packages $PYPI_PKGS ; fi + script: + - mkdir build + - cd build + - ../configure --enable-werror $CONFIGURE_ARGS || { cat config.log mes= on-logs/meson-log.txt; exit 1; } + - $MAKE -j$(sysctl -n hw.ncpu) + - for TARGET in $TEST_TARGETS ; do $MAKE $TARGET ; done + +aarch64-macos-15-build: + extends: .macos_job_template + image: macos-15-xcode-16 + variables: + NAME: macos-15 + PATH_EXTRA: /opt/homebrew/gettext/bin + PKG_CONFIG_PATH: /opt/homebrew/curl/lib/pkgconfig:/opt/homebrew/ncurse= s/lib/pkgconfig:/opt/homebrew/readline/lib/pkgconfig + CONFIGURE_ARGS: + --target-list=3Daarch64-softmmu,i386-softmmu,x86_64-softmmu + --cross-prefix-aarch64=3Daarch64-elf- + --cross-prefix-i386=3Di686-elf- + --cross-prefix-x86_64=3Dx86_64-elf- + --disable-plugins + TEST_TARGETS: check-unit run-tcg-tests-aarch64-softmmu run-tcg-tests-i= 386-softmmu run-tcg-tests-x86_64-softmmu diff --git a/.gitlab-ci.d/qemu-project.yml b/.gitlab-ci.d/qemu-project.yml index 4d914c4897..9cbb5fe787 100644 --- a/.gitlab-ci.d/qemu-project.yml +++ b/.gitlab-ci.d/qemu-project.yml @@ -19,3 +19,4 @@ include: - local: '/.gitlab-ci.d/custom-runners.yml' - local: '/.gitlab-ci.d/cirrus.yml' - local: '/.gitlab-ci.d/windows.yml' + - local: '/.gitlab-ci.d/macos.yml' diff --git a/tests/lcitool/refresh b/tests/lcitool/refresh index fa4a16e358..4289cc381a 100755 --- a/tests/lcitool/refresh +++ b/tests/lcitool/refresh @@ -87,6 +87,12 @@ def generate_cirrus(target, trailer=3DNone): generate(filename, cmd, trailer) =20 =20 +def generate_vars(target, trailer=3DNone): + filename =3D Path(src_dir, ".gitlab-ci.d", target + ".vars") + cmd =3D lcitool_cmd + ["variables", "--format", "shell", target, "qemu= "] + generate(filename, cmd, trailer) + + def generate_pkglist(vm, target, project=3D"qemu"): filename =3D Path(src_dir, "tests", "vm", "generated", vm + ".json") cmd =3D lcitool_cmd + ["variables", "--format", "json", target, projec= t] @@ -312,6 +318,11 @@ try: # generate_cirrus("freebsd-14") =20 + # + # GitLab packages lists + # + generate_vars("macos-14") + # # VM packages lists # --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308936; cv=none; d=zohomail.com; s=zohoarc; b=S8UWTeAl5wUX7GeEvbfPM4GNvbyBtfz8Bd/QN7MevQeJvTAwu2ulX3cKkgYpYhwIm8nxUZ7W3W1zkz1WlrsSiGS+QriAWZvi7IUSJu8bkMmh8Hn9IRCamaH/zsiD37zLchEtQxWUIwvx7+Rd3TPYVVgsnQC7rbdT5rVWv/DOXXQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308936; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=dMTIrIn1jqYuyB0/of62QLSfjVYqAAyLy1iczuIDEV8=; b=aErGECWRtIScwye9ThroYwsAhvAVMuB9xXXsmxhJhyJXOUPM9skdBboFga/fawYejKMsh83Y684s9XFUjVCoRfjU2P5FeRzGSXsmpONK6kjEUBwYy6xtuDbAcBTx0FlvwvNAcyOfj08kShxiCJxJ+3XHLnEvWcuIaWXkXt4mq9k= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308936479164.7454399715357; Wed, 24 Jun 2026 06:48:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNoa-0002v3-1a; Wed, 24 Jun 2026 09:38:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNoF-00020c-AW; Wed, 24 Jun 2026 09:38:34 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNo5-00019x-Vu; Wed, 24 Jun 2026 09:38:25 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E35A21BA9E8; Wed, 24 Jun 2026 16:33:18 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7C8533DEA37; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307998; bh=zb56gFXKrBxhm7F3CspMLidaMJreYiHvIKwE6YJdNk8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=q7/hbEFEfi0hsohtRI9rVWCWqmBGF55NtPGwFCjFlhIiJRz1hRfKGoAAIb81NE1VD Lc+OkxuEN6eWmmiHfJHOAgOM7BGkAcJzYbMjyzJH/PqFeNwKuRkbf0YsxBe9KFUx3T st7O7tqWdGSQU1ET4lR1eD8Bo/9Py9fX9Sjf35Dfa9u8Y9ySFpBWYiu7/MfHZYNSVx DNBO/4aE0KndkRIr2rh5zszITfi3nRi56uBPq8EGG3pUb3pUNIg/kjTAkl1xw1+F0z uJhEMUvfgXZ7gD+RFD4Y+PuaO4KdN8XfGabfdR2BkzMS8G22khago/r1drEv8OgLs4 KeElObOt/JeJw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Stefan Hajnoczi , Pierrick Bouvier , Warner Losh , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-11.0.2 054/107] gitlab: remove x64-freebsd-14-build Cirrus job Date: Wed, 24 Jun 2026 16:30:59 +0300 Message-ID: <20260624133301.403266-54-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308938347158500 From: Stefan Hajnoczi Cirrus has shut down and the x64-freebsd-14-build is failing: https://gitlab.com/qemu-project/qemu/-/jobs/14656732122 Remove the x64-freebsd-14-build job to get the CI pipeline passing again. The next commit will be to remove Cirrus integration from the GitLab YAML and lcitool since it is no longer used. Signed-off-by: Stefan Hajnoczi Reviewed-by: Pierrick Bouvier Reviewed-by: Warner Losh Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-id: 20260602162457.828969-2-stefanha@redhat.com Signed-off-by: Stefan Hajnoczi (cherry picked from commit 4023f38b50a42a9a936ee3c1c3a9642110e42916) Signed-off-by: Michael Tokarev diff --git a/.gitlab-ci.d/cirrus.yml b/.gitlab-ci.d/cirrus.yml index b71ab090b6..4769d00c67 100644 --- a/.gitlab-ci.d/cirrus.yml +++ b/.gitlab-ci.d/cirrus.yml @@ -30,17 +30,3 @@ - cirrus-run -v --show-build-log always .gitlab-ci.d/cirrus/$NAME.yml variables: QEMU_JOB_CIRRUS: 1 - -x64-freebsd-14-build: - extends: .cirrus_build_job - variables: - NAME: freebsd-14 - CIRRUS_VM_INSTANCE_TYPE: freebsd_instance - CIRRUS_VM_IMAGE_SELECTOR: image_family - CIRRUS_VM_IMAGE_NAME: freebsd-14-3 - CIRRUS_VM_CPUS: 8 - CIRRUS_VM_RAM: 8G - UPDATE_COMMAND: pkg update; pkg upgrade -y - INSTALL_COMMAND: pkg install -y - CONFIGURE_ARGS: --target-list-exclude=3Darm-softmmu,i386-softmmu,mips6= 4el-softmmu,mipsel-softmmu,mips-softmmu,ppc-softmmu,sh4eb-softmmu,xtensa-so= ftmmu --enable-rust - TEST_TARGETS: check diff --git a/.gitlab-ci.d/cirrus/freebsd-14.vars b/.gitlab-ci.d/cirrus/free= bsd-14.vars deleted file mode 100644 index 98fbde6cc6..0000000000 --- a/.gitlab-ci.d/cirrus/freebsd-14.vars +++ /dev/null @@ -1,16 +0,0 @@ -# THIS FILE WAS AUTO-GENERATED -# -# $ lcitool variables freebsd-14 qemu -# -# https://gitlab.com/libvirt/libvirt-ci - -CCACHE=3D'/usr/local/bin/ccache' -CPAN_PKGS=3D'' -CROSS_PKGS=3D'' -MAKE=3D'/usr/local/bin/gmake' -NINJA=3D'/usr/local/bin/ninja' -PACKAGING_COMMAND=3D'pkg' -PIP3=3D'/usr/local/bin/pip' -PKGS=3D'alsa-lib bash bison bzip2 ca_root_nss capstone4 ccache4 cmocka cor= eutils ctags curl cyrus-sasl dbus diffutils dtc flex fusefs-libs3 gettext g= it glib gmake gnutls gsed gtk-vnc gtk3 json-c libepoxy libffi libgcrypt lib= jpeg-turbo libnfs libslirp libspice-server libssh libtasn1 llvm lzo2 meson = mtools ncurses nettle ninja opencv pixman pkgconf png py311-numpy py311-pil= low py311-pip py311-pyyaml py311-setuptools py311-sphinx py311-sphinx_rtd_t= heme py311-tomli py311-wheel python3 rpm2cpio rust rust-bindgen-cli sdl2 sd= l2_image snappy sndio socat spice-protocol tesseract usbredir virglrenderer= vte3 vulkan-tools xorriso zstd' -PYPI_PKGS=3D'' -PYTHON=3D'/usr/local/bin/python3' diff --git a/MAINTAINERS b/MAINTAINERS index ad215eced8..8cc89d4feb 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -4502,9 +4502,7 @@ FreeBSD Hosted Continuous Integration M: Ed Maste M: Li-Wen Hsu S: Maintained -F: .gitlab-ci.d/cirrus/freebsd* F: tests/vm/freebsd -W: https://cirrus-ci.com/github/qemu/qemu =20 Functional testing framework M: Thomas Huth diff --git a/tests/lcitool/refresh b/tests/lcitool/refresh index 4289cc381a..ad6a1e6fe8 100755 --- a/tests/lcitool/refresh +++ b/tests/lcitool/refresh @@ -313,11 +313,6 @@ try: enable_rust=3DFalse, trailer=3D"".join(debian_all_test_cross_compilers)) =20 - # - # Cirrus packages lists for GitLab - # - generate_cirrus("freebsd-14") - # # GitLab packages lists # --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308353; cv=none; d=zohomail.com; s=zohoarc; b=D/zAmm9ELGcLXc9bOi7DbIIVc4evysIxFahhn+pNARC8X0+PBwHSdnhsFj83yhDn9CpDAkgkPGIRPfnRXx8mpZO/cSVDZ8pdyAFMIWcH+GOJZb+hFP0TqrYjBEJjYzlrfSqA55SFeqowXwmCUmPEu1fdXAanhjSImL83FIHquQ4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308353; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RyY+DTEeM53gBbQV1iWDO5UtwnqvL2Ir8PDKrJIJ9A0=; b=CKOQEvAsQ9GLjz4jQbz7hWCOcgWMIzfKq0V6XUo0ueb02vCE35jOlE7+GrkA2ku3rAFsPNkdScA65Wg3Gf7UlklWgWANQthedrTiBzxzq0tey7/CbKodn0YZ+r78nm+NK/U5vh5x3vf2qlnzhHMsY2PVpghqAB9s7/8+uHwwuDs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308353517542.6423960686835; Wed, 24 Jun 2026 06:39:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNoi-0003IA-Bp; Wed, 24 Jun 2026 09:39:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNoF-00020e-AU; Wed, 24 Jun 2026 09:38:34 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNo6-0001BV-4Q; Wed, 24 Jun 2026 09:38:27 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 01A3F1BA9E9; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 8FA703DEA38; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=WpsrbVsZQk8gvShA9vq/22yy5WfUAbdU37e8V5+3KFo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=GcnQ8Wfrjz96EaAAvuBKRkzIjk1bmNLyJmNRKtR8dzs4bOBumPe4Hs96oEd2dCZKN /3bdz60iiJCfEpzAJnd9f43f/JcLEATj9afyyD0t79TSIVqqacqKH62oD7e4yHt9gT iegqTq2vAORH2xmDm5GlJL0J5TBztGXZ9FU7GCFdqEh8BR6faK/wpsTdv4qnqOeppS +rHm+CgJc4McslEuq6973TMojObtTVMB8B+svKUO4QSVzAj0x49Kq3GjY4JBYB7Hvj zhhxkToG4O7RyfbN9y6JCO1h35RmFrt0+97I+6/SOBJZavZFWOWkzfF/b3CxEuIrs/ HsmDRNMhbzGhw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Stefan Hajnoczi , Pierrick Bouvier , Warner Losh , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Michael Tokarev Subject: [Stable-11.0.2 055/107] lcitool: remove Cirrus CI support Date: Wed, 24 Jun 2026 16:31:00 +0300 Message-ID: <20260624133301.403266-55-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308354501158500 From: Stefan Hajnoczi Remove GitLab CI integration for Cirrus CI now that nothing uses it anymore. Signed-off-by: Stefan Hajnoczi Reviewed-by: Pierrick Bouvier Reviewed-by: Warner Losh Reviewed-by: Alex Benn=C3=A9e Message-id: 20260602162457.828969-3-stefanha@redhat.com Signed-off-by: Stefan Hajnoczi (cherry picked from commit 29c042c6e9d4a09d4a0ac3fa54aeb7ee08ce0bdc) Signed-off-by: Michael Tokarev diff --git a/.gitlab-ci.d/base.yml b/.gitlab-ci.d/base.yml index 7640a1d52c..72eadc8073 100644 --- a/.gitlab-ci.d/base.yml +++ b/.gitlab-ci.d/base.yml @@ -52,10 +52,6 @@ variables: - if: '$CI_PIPELINE_SOURCE =3D=3D "schedule"' when: never =20 - # Cirrus jobs can't run unless the creds / target repo are set - - if: '$QEMU_JOB_CIRRUS && ($CIRRUS_GITHUB_REPO =3D=3D null || $CIRRUS= _API_TOKEN =3D=3D null)' - when: never - # Publishing jobs should only run on the default branch in upstream - if: '$QEMU_JOB_PUBLISH =3D=3D "1" && $CI_PROJECT_NAMESPACE =3D=3D $Q= EMU_CI_UPSTREAM && $CI_COMMIT_BRANCH !=3D $CI_DEFAULT_BRANCH' when: never diff --git a/.gitlab-ci.d/cirrus.yml b/.gitlab-ci.d/cirrus.yml deleted file mode 100644 index 4769d00c67..0000000000 --- a/.gitlab-ci.d/cirrus.yml +++ /dev/null @@ -1,32 +0,0 @@ -# Jobs that we delegate to Cirrus CI because they require an operating -# system other than Linux. These jobs will only run if the required -# setup has been performed on the GitLab account. -# -# The Cirrus CI configuration is generated by replacing target-specific -# variables in a generic template: some of these variables are provided -# when the GitLab CI job is defined, others are taken from a shell -# snippet generated using lcitool. -# -# Note that the $PATH environment variable has to be treated with -# special care, because we can't just override it at the GitLab CI job -# definition level or we risk breaking it completely. -.cirrus_build_job: - extends: .base_job_template - stage: build - image: registry.gitlab.com/libvirt/libvirt-ci/cirrus-run:latest - needs: [] - allow_failure: - exit_codes: 3 - # 20 mins larger than "timeout_in" in cirrus/build.yml - # as there's often a 5-10 minute delay before Cirrus CI - # actually starts the task - timeout: 80m - script: - - set -o allexport - - source .gitlab-ci.d/cirrus/$NAME.vars - - set +o allexport - - cirrus-vars <.gitlab-ci.d/cirrus/build.yml >.gitlab-ci.d/cirrus/$NAM= E.yml - - cat .gitlab-ci.d/cirrus/$NAME.yml - - cirrus-run -v --show-build-log always .gitlab-ci.d/cirrus/$NAME.yml - variables: - QEMU_JOB_CIRRUS: 1 diff --git a/.gitlab-ci.d/cirrus/README.rst b/.gitlab-ci.d/cirrus/README.rst deleted file mode 100644 index 657b0706d7..0000000000 --- a/.gitlab-ci.d/cirrus/README.rst +++ /dev/null @@ -1,54 +0,0 @@ -Cirrus CI integration -=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D - -GitLab CI shared runners only provide a docker environment running on Linu= x. -While it is possible to provide private runners for non-Linux platforms th= is -is not something most contributors/maintainers will wish to do. - -To work around this limitation, we take advantage of `Cirrus CI`_'s free -offering: more specifically, we use the `cirrus-run`_ script to trigger Ci= rrus -CI jobs from GitLab CI jobs so that Cirrus CI job output is integrated into -the main GitLab CI pipeline dashboard. - -There is, however, some one-time setup required. If you want FreeBSD and m= acOS -builds to happen when you push to your GitLab repository, you need to - -* set up a GitHub repository for the project, eg. ``yourusername/qemu``. - This repository needs to exist for cirrus-run to work, but it doesn't ne= ed to - be kept up to date, so you can create it and then forget about it; - -* enable the `Cirrus CI GitHub app`_ for your GitHub account; - -* sign up for Cirrus CI. It's enough to log into the website using your Gi= tHub - account; - -* grab an API token from the `Cirrus CI settings`_ page; - -* it may be necessary to push an empty ``.cirrus.yml`` file to your github= fork - for Cirrus CI to properly recognize the project. You can check whether - Cirrus CI knows about your project by navigating to: - - ``https://cirrus-ci.com/yourusername/qemu`` - -* in the *CI/CD / Variables* section of the settings page for your GitLab - repository, create two new variables: - - * ``CIRRUS_GITHUB_REPO``, containing the name of the GitHub repository - created earlier, eg. ``yourusername/qemu``; - - * ``CIRRUS_API_TOKEN``, containing the Cirrus CI API token generated ear= lier. - This variable **must** be marked as *Masked*, because anyone with know= ledge - of it can impersonate you as far as Cirrus CI is concerned. - - Neither of these variables should be marked as *Protected*, because in - general you'll want to be able to trigger Cirrus CI builds from non-prot= ected - branches. - -Once this one-time setup is complete, you can just keep pushing to your Gi= tLab -repository as usual and you'll automatically get the additional CI coverag= e. - - -.. _Cirrus CI GitHub app: https://github.com/marketplace/cirrus-ci -.. _Cirrus CI settings: https://cirrus-ci.com/settings/profile/ -.. _Cirrus CI: https://cirrus-ci.com/ -.. _cirrus-run: https://github.com/sio/cirrus-run/ diff --git a/.gitlab-ci.d/cirrus/build.yml b/.gitlab-ci.d/cirrus/build.yml deleted file mode 100644 index 41abd0b31a..0000000000 --- a/.gitlab-ci.d/cirrus/build.yml +++ /dev/null @@ -1,42 +0,0 @@ -@CIRRUS_VM_INSTANCE_TYPE@: - @CIRRUS_VM_IMAGE_SELECTOR@: @CIRRUS_VM_IMAGE_NAME@ - cpu: @CIRRUS_VM_CPUS@ - memory: @CIRRUS_VM_RAM@ - -env: - CIRRUS_CLONE_DEPTH: 1 - CI_REPOSITORY_URL: "@CI_REPOSITORY_URL@" - CI_COMMIT_REF_NAME: "@CI_COMMIT_REF_NAME@" - CI_COMMIT_SHA: "@CI_COMMIT_SHA@" - PATH: "@PATH_EXTRA@:$PATH" - PKG_CONFIG_PATH: "@PKG_CONFIG_PATH@" - PYTHON: "@PYTHON@" - MAKE: "@MAKE@" - CONFIGURE_ARGS: "@CONFIGURE_ARGS@" - TEST_TARGETS: "@TEST_TARGETS@" - -build_task: - # A little shorter than GitLab timeout in ../cirrus.yml - timeout_in: 60m - install_script: - - @UPDATE_COMMAND@ - - @INSTALL_COMMAND@ @PKGS@ - - if test -n "@PYPI_PKGS@" ; then PYLIB=3D$(@PYTHON@ -c 'import syscon= fig; print(sysconfig.get_path("stdlib"))'); rm -f $PYLIB/EXTERNALLY-MANAGED= ; @PIP3@ install @PYPI_PKGS@ ; fi - clone_script: - - git clone --depth 100 "$CI_REPOSITORY_URL" . - - git fetch origin "$CI_COMMIT_REF_NAME" - - git reset --hard "$CI_COMMIT_SHA" - step_script: - - mkdir build - - cd build - - ../configure --enable-werror $CONFIGURE_ARGS - || { cat config.log meson-logs/meson-log.txt; exit 1; } - - $MAKE -j$(sysctl -n hw.ncpu) - - for TARGET in $TEST_TARGETS ; - do - $MAKE -j$(sysctl -n hw.ncpu) $TARGET V=3D1 ; - done - always: - build_result_artifacts: - path: build/meson-logs/*log.txt - type: text/plain diff --git a/.gitlab-ci.d/qemu-project.yml b/.gitlab-ci.d/qemu-project.yml index 9cbb5fe787..104a147b2d 100644 --- a/.gitlab-ci.d/qemu-project.yml +++ b/.gitlab-ci.d/qemu-project.yml @@ -17,6 +17,5 @@ include: - local: '/.gitlab-ci.d/buildtest.yml' - local: '/.gitlab-ci.d/static_checks.yml' - local: '/.gitlab-ci.d/custom-runners.yml' - - local: '/.gitlab-ci.d/cirrus.yml' - local: '/.gitlab-ci.d/windows.yml' - local: '/.gitlab-ci.d/macos.yml' diff --git a/docs/devel/testing/ci-jobs.rst.inc b/docs/devel/testing/ci-job= s.rst.inc index f1c70344ec..d5b081978a 100644 --- a/docs/devel/testing/ci-jobs.rst.inc +++ b/docs/devel/testing/ci-jobs.rst.inc @@ -91,12 +91,6 @@ Maintainer controlled job variables The following variables may be set when defining a job in the CI configuration file. =20 -QEMU_JOB_CIRRUS -~~~~~~~~~~~~~~~ - -The job makes use of Cirrus CI infrastructure, requiring the -configuration setup for cirrus-run to be present in the repository - QEMU_JOB_OPTIONAL ~~~~~~~~~~~~~~~~~ =20 diff --git a/docs/devel/testing/main.rst b/docs/devel/testing/main.rst index 0662766b5c..e929ab3ec9 100644 --- a/docs/devel/testing/main.rst +++ b/docs/devel/testing/main.rst @@ -516,8 +516,8 @@ mappings to distribution package names for a wide varie= ty of third party projects. ``lcitool`` applies the mappings to a list of build pre-requisites in ``tests/lcitool/projects/qemu.yml``, determines the list of native packages to install on each distribution, and uses them -to generate build environments (dockerfiles and Cirrus CI variable files) -that are consistent across OS distribution. +to generate build environments (dockerfiles) that are consistent across OS +distribution. =20 =20 Adding new build pre-requisites diff --git a/tests/lcitool/refresh b/tests/lcitool/refresh index ad6a1e6fe8..0ccce6d5be 100755 --- a/tests/lcitool/refresh +++ b/tests/lcitool/refresh @@ -81,12 +81,6 @@ def generate_dockerfile(host, target, project=3D"qemu", = cross=3DNone, trailer=3DNone, generate(filename, cmd, trailer) =20 =20 -def generate_cirrus(target, trailer=3DNone): - filename =3D Path(src_dir, ".gitlab-ci.d", "cirrus", target + ".vars") - cmd =3D lcitool_cmd + ["variables", "--format", "shell", target, "qemu= "] - generate(filename, cmd, trailer) - - def generate_vars(target, trailer=3DNone): filename =3D Path(src_dir, ".gitlab-ci.d", target + ".vars") cmd =3D lcitool_cmd + ["variables", "--format", "shell", target, "qemu= "] --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308667; cv=none; d=zohomail.com; s=zohoarc; b=Xxj2rTWR2tQm4Dgd2TNwgAQl4+Z5a0Dyn6YntIYVZ81ryAi6e5yVTdqFGocEaqNDJYAufK2iYxuK6/b0D4kpIvzL4BBzL7pJDFwTtP6w/v/L2GEXnM+z54vGbc8W6Vn8kEq95klrok1xj2V3qMsV/bBe/Fl7TetsdNLXuMuGpP8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308667; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8yarpF3uFCTgUZucjlrToJ5iK4crFWl2kfvhEgnIJMY=; b=TJq89gEo3Vez37J1IILuzaqRfGgcz0EGIxFmFwA5j7pbBDVYMojBAzh//8mmisJXFYhItpRBeJ9EbdXwASuP0kLVBhmrT7etZ1/P78zWoYPvBT/DzuqQ+RYo/y7BYCmge/UZgSicegKpxthhxXScUcGp2j2nvuE2S3AlujtO0dA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178230866737746.08907248352671; Wed, 24 Jun 2026 06:44:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNol-0003Qj-D7; Wed, 24 Jun 2026 09:39:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNoJ-00021b-1d; Wed, 24 Jun 2026 09:38:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNoG-0001CV-NI; Wed, 24 Jun 2026 09:38:34 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 154451BA9EA; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id A17EE3DEA39; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=/yCG3jEExQpedxSgTR2/aw27BcSv2Xz3e8r7g1a46fI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=gqdYMyc6kSjcYJiWDB7VDznPFOFMNz66iVwucHONf9V0bwsLm53XiZdc0IFkFD4Ic HE+1Em30pWCsUnN7WtZqQ9X62v78OGxTzShObWVf4ADADyhtQ+Dr/0d26oomZKqJJ6 AWnbex+KODYfMW1YCnQWmc5X0QUyKpJpzvMcKX//DdiBeifK7cZTJ0w0UuFINdRJHw qPVVmdF0O4woUAChG+jt5W9JQrMy8ZIrRfYdEhBSYlue58fINMQ09ArX58tMqujEc6 dcsIBs93iLW4o3rz4nl9s4mDzn3BmUI+WoJig7vt+sDF09yhac75tKVbNa4S0yUvlg rYIR2T6XbQUUQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alexandra Winter , Hendrik Brueckner , Christian Borntraeger , Gautam Gala , Cornelia Huck , Michael Tokarev Subject: [Stable-11.0.2 056/107] target/s390x: Make container ids in SysIB_15x 1-based Date: Wed, 24 Jun 2026 16:31:01 +0300 Message-ID: <20260624133301.403266-56-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308667749158501 Content-Type: text/plain; charset="utf-8" From: Alexandra Winter The Container Id in a container-type TLE of SysIB_15x is defined as 8-bit unsigned nonzero integer. Make stsi fc 15 emulation architecture compliant, by starting the container ids at 1 for the lowest numbered container. The qemu misbehaviour without this patch becomes obvious due to a recently proposed kernel fix. Older linux kernels pass the container ids from stsi fc15 unchanged to sysfs, i.e. starting at 1 on s390 hardware. This resulted in off-by-one values when compared to the values from HMC. A Linux kernel fix is being proposed to correct the sysfs topology ids by -1, so they start at 0, e.g. when displayed by 'lscpu -ye'. In case a KVM guest with a fixed kernel runs on a host with a qemu without this fix, this can result in container ids erroneously being shown as 255. Example (Fixed guest on unfixed qemu): $ lscpu -ye CPU NODE DRAWER BOOK SOCKET CORE L1d:L1i:L2 ONLINE CONFIGURED POLARIZATION = ADDRESS 0 0 255 255 255 0 0:0:0 yes yes vert-medium 0 1 0 255 255 0 1 1:1:1 yes yes vert-medium 1 After this fix: $ lscpu -ye CPU NODE DRAWER BOOK SOCKET CORE L1d:L1i:L2 ONLINE CONFIGURED POLARIZATION = ADDRESS 0 0 0 0 0 0 0:0:0 yes yes vert-medium 0 1 0 0 0 1 1 1:1:1 yes yes vert-medium 1 Fixes: f4f54b582f ("target/s390x/cpu topology: handle STSI(15) and build th= e SYSIB") Signed-off-by: Alexandra Winter Acked-by: Hendrik Brueckner Acked-by: Christian Borntraeger Reviewed-by: Gautam Gala Message-ID: <20260511134909.43802-1-wintera@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit 1f1ccb6f3c48a2cd80e874d66afeef2dc28a65f3) Signed-off-by: Michael Tokarev diff --git a/target/s390x/kvm/stsi-topology.c b/target/s390x/kvm/stsi-topol= ogy.c index c8d6389cd8..af3fd8ad1b 100644 --- a/target/s390x/kvm/stsi-topology.c +++ b/target/s390x/kvm/stsi-topology.c @@ -90,9 +90,9 @@ static int stsi_topology_fill_sysib(S390TopologyList *top= ology_list, int last_drawer =3D -1; int last_book =3D -1; int last_socket =3D -1; - int drawer_id =3D 0; - int book_id =3D 0; - int socket_id =3D 0; + int drawer_id =3D 1; + int book_id =3D 1; + int socket_id =3D 1; int n =3D sizeof(SysIB_151x); =20 QTAILQ_FOREACH(entry, topology_list, next) { @@ -103,12 +103,12 @@ static int stsi_topology_fill_sysib(S390TopologyList = *topology_list, if (level > 3 && drawer_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); p =3D fill_container(p, 3, drawer_id++); - book_id =3D 0; + book_id =3D 1; } if (level > 2 && book_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); p =3D fill_container(p, 2, book_id++); - socket_id =3D 0; + socket_id =3D 1; } if (socket_change) { SYSIB_GUARD(n, sizeof(SYSIBContainerListEntry)); --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308642; cv=none; d=zohomail.com; s=zohoarc; b=kZ+dix4bvMtb8gZvAT7D1fx0XXBa2g1dScQeYpXVyp5TfshgOL1dxHOXKb4YbgqGrByaj/ryggds5WESD0TGb+Hz4LYqE19q0ruBOErajA+Gjum4vUs00Dv45mhlex54e0d+xPBrARoXTDIvs7Hkt/RC2LE+zIxdN2RQhL3Y2e4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308642; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8RFYwqIo8C3mEDUpEM8NRuAfkAUDfjqnS70zVKw66+Y=; b=A7VwxDlDjnQPXDn8F8KRmd44tatcnpb6KTjUy/wPUr25+XVFoQkCuXLXQASm3e+ZvkciJJYxAMXIT7SqBbeT5KVfKzctSaPNQnH2ecBJB40F8a7LDccfxnVip7Xb/7ZmxI0lwxOT1T0qCGwwWJdK7873H4/aTwu+yp/aKU8TGz0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308642393398.6675933930718; Wed, 24 Jun 2026 06:44:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNoY-0002iV-CA; Wed, 24 Jun 2026 09:38:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNoJ-00021c-2V; Wed, 24 Jun 2026 09:38:38 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNoG-0001CX-Mt; Wed, 24 Jun 2026 09:38:34 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 33CC91BA9EB; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B5D983DEA3A; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=7nNrOIUeTfp+RJapRBAV6b2JLZ6fd4BEihLhXZZY+hs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=oEkhwqblEYahzIwjmr/3kwHuQ7KJw6Pixk/cSyqI0FTETo2AxcNcy4vOh6HFcPYkN JA7+dsdG+/qXzKfcY7uVMS1zXL/m03qFVfle64TpnE86lqIxvqHHwrZxRR495khPAI UluGQbg1NXbdw9LE+kEXP/lY0fumqSOjUR7HtTczZ0jMawy8EGUoz5GETvPRpyeGZE UR9Ll5y/KdIh2gWN6eLFwe5pBb+t/3XsvmjU7z4VG/InSDpOpWwwhBQBdwkZQouuAD HC7wqIPtFGldbxAO5BMnL7i4qdLYD8/REUf2j48P7m+KEElNQrc8t0o4Le8Hq6RbYG zMLO4vsCIRRKw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Farhan Ali , Niklas Schnelle , Matthew Rosato , Omar Elghoul , Cornelia Huck , Michael Tokarev Subject: [Stable-11.0.2 057/107] s390x/pci: Fix interrupt forwarding disable for interpreted devices Date: Wed, 24 Jun 2026 16:31:02 +0300 Message-ID: <20260624133301.403266-57-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308643558158500 Content-Type: text/plain; charset="utf-8" From: Farhan Ali Remove the FH_MASK_ENABLE check when disabling interrupt forwarding during device reset. This check was broken for the default case in the switch statement above, preventing proper cleanup of interrupt forwarding. The pbdev->aif check in s390_pci_kvm_aif_disable() already guards against double-disabling of interrupt forwarding. Cc: qemu-stable@nongnu.org Reported-by: Niklas Schnelle Signed-off-by: Farhan Ali Reviewed-by: Matthew Rosato Tested-by: Omar Elghoul Message-ID: <20260521182946.1607-1-alifm@linux.ibm.com> Signed-off-by: Cornelia Huck (cherry picked from commit 442f727b8bebabf20a4f6a7536a4ff2885402030) Signed-off-by: Michael Tokarev diff --git a/hw/s390x/s390-pci-bus.c b/hw/s390x/s390-pci-bus.c index 4de7b587e8..eb2b6185db 100644 --- a/hw/s390x/s390-pci-bus.c +++ b/hw/s390x/s390-pci-bus.c @@ -1504,7 +1504,7 @@ static void s390_pci_device_reset(DeviceState *dev) break; } =20 - if (pbdev->interp && (pbdev->fh & FH_MASK_ENABLE)) { + if (pbdev->interp) { /* Interpreted devices were using interrupt forwarding */ s390_pci_kvm_aif_disable(pbdev); } else if (pbdev->summary_ind) { --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308444; cv=none; d=zohomail.com; s=zohoarc; b=h6L9l42dSpiJNoGvLOrDbiGYCCLQkfTtJY1bLTJWO/3YLgskwp/JmYN/GMB44mdku1oNKBlV7crxcJQpWpME0CBrkPkt+MpwFoxGPS5zuf89nNXoRQqmCnkPoSDeu3ausofnYQf7CT0GBD0TUMF9pG1f0xWfGoAqne07QI3nMxw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308444; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=DcNAXHvfGJ6Pyr63IODMb7d7UkCuhncOYyTvWSoluos=; b=mnuG/qihyyneNOYaVwiA259cfeF0qSf0goY76eYiwR7kV9U2VdnmSHLdFngPfbNV4rttYqaYHNnkH7gSVjM9cxn+JT1R4stkbtNbrC8Q1anZAFOpC5JUj95J/0Jtl8iiJpbke9DdDqo8ILpiBYRwfRu0qDJfC7rvz4HkZKfqwmE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308444298769.8607608347621; Wed, 24 Jun 2026 06:40:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNom-0003d2-O1; Wed, 24 Jun 2026 09:39:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNoO-00022V-LR; Wed, 24 Jun 2026 09:38:42 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNoK-0001DL-Tx; Wed, 24 Jun 2026 09:38:39 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 45CB81BA9EC; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D4E563DEA3B; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=tJ4gE78HIFs63Hs5+QVQwFGrGNIdLjjoMVKTIA667Hs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ZccXV7MfpIc2A38/qtyZMOsfzOoy6BzA9cmaW/Spi84SwnaVhIjqOo/DnFYa3nDat TwdZNRLfYuLgRaHOzdhvWlzQbh1/dEBNWkctCu/ElqhOjHjxnro9kQ9Eje5liAQngs v+n3i96FpCvvmq65jAqCU5Zcv4X9yHQG+SMHDCZ13WOYbeQEd8AliJOrHr2XM2bXHk gxUD5jV/ULd0ZYhNRaE2ArVaGN3JiAuD/IYXeoNxa8G3Z8GkoS9XCZ1beYFfQJQEY8 fga0YEjgQ3QKm8QQLm3KAKA1IslWoKitXFV8P6VkMwQH32qJOcMZ6mQIyoRLQPqiA3 nNOz/hfilDCIA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Jithu Joseph , Jamin Lin , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Michael Tokarev Subject: [Stable-11.0.2 058/107] hw/i3c: fix CMD/data FIFO depth reset values to match real silicon Date: Wed, 24 Jun 2026 16:31:03 +0300 Message-ID: <20260624133301.403266-58-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308445092158500 From: Jithu Joseph The Linux DW-I3C master driver infers controller queue depths at probe by reading two status registers that report free queue slots, which at probe (queues empty) equals the full depth. It then uses those values to gate every I3C transfer -- any batch whose word count exceeds the advertised depth is rejected with -EOPNOTSUPP. QUEUE_STATUS_LEVEL (0x4c) [7:0] -> cmdfifodepth (cmd slots) DATA_BUFFER_STATUS_LEVEL (0x50) [7:0] -> datafifodepth (32-bit words) Per the AST2600 datasheet the reset values are 0x10 and 0x40 (16 cmd slots, 64 words =3D 256 B). QEMU was advertising 0x02 and 0x10, making the kernel believe the controller can only do 64-byte transfers. The visible symptom was -EOPNOTSUPP on any I3C transfer whose payload exceeded 64 B (datafifodepth =3D 0x10 =3D 16 words =3D 64 B). The underlying FIFOs in QEMU were already allocated at the right size (fifo32_create takes word counts; the existing defaults give 16 cmd slots and 64 data words). Only the advertised reset values were wrong. Correct the reset values in dw_i3c_resets[], and additionally drive the advertised depths from the queue-capacity configs in the reset handlers (as is already done for the device/char table pointers), so a configured override is reflected in what the guest reads instead of being silently ignored. The advertised fields are 8-bit, so the depth saturates at 255 regardless of the wider capacity configs. With this fix the guest sees datafifodepth=3D64 words and accepts transfers up to 256 B. Fixes: e974c6957576 ("hw/i3c/dw-i3c: Add more reset values") Cc: qemu-stable@nongnu.org Signed-off-by: Jithu Joseph Reviewed-by: Jamin Lin Link: https://lore.kernel.org/qemu-devel/20260604142207.2118098-2-jithu.jos= eph@oss.qualcomm.com Signed-off-by: C=C3=A9dric Le Goater (cherry picked from commit 2d3dc20d9d716729e06093311f678dc739affe5b) Signed-off-by: Michael Tokarev diff --git a/hw/i3c/dw-i3c.c b/hw/i3c/dw-i3c.c index d87d42be89..402c8f1922 100644 --- a/hw/i3c/dw-i3c.c +++ b/hw/i3c/dw-i3c.c @@ -282,8 +282,8 @@ static const uint32_t dw_i3c_resets[DW_I3C_NR_REGS] =3D= { [R_QUEUE_THLD_CTRL] =3D 0x01000101, [R_DATA_BUFFER_THLD_CTRL] =3D 0x01010100, [R_SLV_EVENT_CTRL] =3D 0x0000000b, - [R_QUEUE_STATUS_LEVEL] =3D 0x00000002, - [R_DATA_BUFFER_STATUS_LEVEL] =3D 0x00000010, + [R_QUEUE_STATUS_LEVEL] =3D 0x00000010, + [R_DATA_BUFFER_STATUS_LEVEL] =3D 0x00000040, [R_PRESENT_STATE] =3D 0x00000003, [R_I3C_VER_ID] =3D 0x3130302a, [R_I3C_VER_TYPE] =3D 0x6c633033, @@ -947,6 +947,10 @@ static void dw_i3c_reset(DeviceState *dev) s->cfg.dev_char_table_pointer); ARRAY_FIELD_DP32(s->regs, DEV_CHAR_TABLE_POINTER, DEV_CHAR_TABLE_DEPTH, s->cfg.dev_char_table_depth); + ARRAY_FIELD_DP32(s->regs, QUEUE_STATUS_LEVEL, CMD_QUEUE_EMPTY_LOC, + s->cfg.cmd_resp_queue_capacity_bytes); + ARRAY_FIELD_DP32(s->regs, DATA_BUFFER_STATUS_LEVEL, TX_BUF_EMPTY_LOC, + s->cfg.tx_rx_queue_capacity_bytes); =20 dw_i3c_cmd_queue_reset(s); dw_i3c_resp_queue_reset(s); @@ -1795,6 +1799,10 @@ static void dw_i3c_reset_enter(Object *obj, ResetTyp= e type) s->cfg.dev_char_table_pointer); ARRAY_FIELD_DP32(s->regs, DEV_CHAR_TABLE_POINTER, DEV_CHAR_TABLE_DEPTH, s->cfg.dev_char_table_depth); + ARRAY_FIELD_DP32(s->regs, QUEUE_STATUS_LEVEL, CMD_QUEUE_EMPTY_LOC, + s->cfg.cmd_resp_queue_capacity_bytes); + ARRAY_FIELD_DP32(s->regs, DATA_BUFFER_STATUS_LEVEL, TX_BUF_EMPTY_LOC, + s->cfg.tx_rx_queue_capacity_bytes); } =20 static void dw_i3c_realize(DeviceState *dev, Error **errp) --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308857; cv=none; d=zohomail.com; s=zohoarc; b=VR/JQe/cfOSVybcGd2KnZJeElqKb+qvH0wZwuZ/l69k8agvEsthcqhZfbxMKQ7bnf+5aYERM2QcKD3JCsSUUpvb0ZSjl1o7HU8hI/dsQv+DMYAuvFAaPNRzp7yvUWwH6/XSalVeu8FCAGh3R55/eLDEq49fklxWpeTjms54mymM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308857; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Yu2JZD7aFZEDXW7vvAhrcDe/6zfsHhhsGcD/e20vqpM=; b=JhqFjieHROkkZnBs6EhPCqlMcHWkWSgJfvY6Fwmg2nC3FNPTkVujxtlH/W7FFwb+0VClFbT3DmKBDtPLQBXdI1yjy2O9uHOJXdxvxa8fzdTVeB5r1pJFAdEHoDMkKMLo8hQQz4tX8HsokvpyVoNIEG3gCg/zRRXXCcU3fN1UhXo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308857135873.8580855772966; Wed, 24 Jun 2026 06:47:37 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNoq-000491-IW; Wed, 24 Jun 2026 09:39:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNom-0003a2-Af; Wed, 24 Jun 2026 09:39:04 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNof-0001DM-0u; Wed, 24 Jun 2026 09:39:03 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 54B151BA9ED; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E606C3DEA3C; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=BQUHibctTg0uqXwENGdkj0Gc78GOHcR3uWy9Znp2coE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ljEI0Dc0FerG7i8XfhELiLXN+pfVqG7k9lQegPXXvpp2IIYb/oKFCEolP74ydTdnd tTnO0J8Quz13EwrT33Z+4pJjI6atswDdE/eHGVEO/1EVgllB9Y0j77AciQP19/XPts AMOh00N0OFHingwXcO2uqgN34Y0g7L5f87zn9FdvYSZfGFdwuIWh+sCR4MUWF6vMhq TA2V+4gOKzVnrOx0tG2OdFMfQ8hdqPcePccIuElYGLXarvj5hCCMklo8zMu7jZoWPr U6qocWME5q2QwHKmgkFBrhc7sO8g65kdTllW2U4yNxZ41cdfMMknJbuKZP8Kt3YMWR dUJVEZNuYmE/w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fiona Ebner , Stefan Hajnoczi , Michael Tokarev Subject: [Stable-11.0.2 059/107] block/io: fallback to bounce buffer if BLKZEROOUT is not supported because of alignment Date: Wed, 24 Jun 2026 16:31:04 +0300 Message-ID: <20260624133301.403266-59-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308859500158501 Content-Type: text/plain; charset="utf-8" From: Fiona Ebner Commit 5634622bcb ("file-posix: allow BLKZEROOUT with -t writeback") enables the BLKZEROOUT ioctl when using 'writeback' cache, regressing certain 'qemu-img convert' invocations, because of a pre-existing issue. Namely, the BLKZEROOUT ioctl might fail with errno EINVAL when the request is shorter than the block size of the block device. Fallback to the bounce buffer, similar to when the ioctl is not supported at all, rather than treating such an error as fatal. Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3257 Resolves: https://bugzilla.proxmox.com/show_bug.cgi?id=3D7197 Cc: qemu-stable@nongnu.org Signed-off-by: Fiona Ebner Message-ID: <20260105143416.737482-1-f.ebner@proxmox.com> [Added TODO comment describing a larger fix that could be implemented in the future. --Stefan] Signed-off-by: Stefan Hajnoczi (cherry picked from commit b4e28c304bc58325f8f712cb25e5d700826caa25) Signed-off-by: Michael Tokarev diff --git a/block/io.c b/block/io.c index e8fb4ede4d..6c0bbdcf1e 100644 --- a/block/io.c +++ b/block/io.c @@ -1918,7 +1918,18 @@ bdrv_co_do_pwrite_zeroes(BlockDriverState *bs, int64= _t offset, int64_t bytes, assert(!bs->supported_zero_flags); } =20 - if (ret =3D=3D -ENOTSUP && !(flags & BDRV_REQ_NO_FALLBACK)) { + /* + * TODO The ret =3D=3D -EINVAL && num < alignment case is a workar= ound for + * when request_alignment is 1 on files with cache=3Dwriteback. Th= e Linux + * ioctl(BLKZEROOUT) requires block alignment and will fail with + * EINVAL. The block layer should align the request to + * write_zeroes_alignment instead of trying the syscall, failing, = and + * falling back to a bounce buffer. Doing that is not easy so for = now + * we use a bounce buffer: + * https://lore.kernel.org/qemu-devel/20260109120837.2772961-1-f.e= bner@proxmox.com/ + */ + if ((ret =3D=3D -ENOTSUP || (ret =3D=3D -EINVAL && num < alignment= )) && + !(flags & BDRV_REQ_NO_FALLBACK)) { /* Fall back to bounce buffer if write zeroes is unsupported */ BdrvRequestFlags write_flags =3D flags & ~BDRV_REQ_ZERO_WRITE; =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308856; cv=none; d=zohomail.com; s=zohoarc; b=TQsJZ/GaG+DlGZ1xMevCdVBakgOnhvAfW7BNS5iscnDYyKhbQfrI82dnk3BaYKHHxuq/IHzKTqzrAFiULKznxZpqO49aV/+g0hcWcQXd3bapby1i+UUMXg32Wxmrj0obkGtyoR4E9Rha/b7S00I6GG27bbtkXhaDCvduKHWJaOk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308856; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=DRN0LPP1ZJqzaRaUQpxjAd/crDAQ3VrdxZ50fQm53Wc=; b=cnpv3FywDtDdTw84EXOaI1Kx4vo5AuSc2d7YUnMIsWo+saWJWseCY5MbnJDdiDaGyA/pWwE2dax2wadszFIorQm4kr+uvz4QYBLX5mrA0n498uUpt9jxlDiZskUislsI+jtT7ZAsdByWnS4bqe/RXKowO46dvV47VtuYYfJbobE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308856936141.7794996811167; Wed, 24 Jun 2026 06:47:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNop-0003zO-Gs; Wed, 24 Jun 2026 09:39:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNom-0003Zk-77; Wed, 24 Jun 2026 09:39:04 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNok-0001Do-6H; Wed, 24 Jun 2026 09:39:03 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 66DB91BA9EE; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 011893DEA3D; Wed, 24 Jun 2026 16:33:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=8HHM1w7x1VDQswcT8xzFVme9fABgIN0/85/hbVFQpwc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=jdAae8yFgS+c1LanrI/lCCVucWIpZg5Ov4qisXKcXKNh7txLkK+fmjFAzG4xAOB6U Y7ThLptR1PYMXO1h9INAMxnC8w64QsJtipmAyd+5kVE3f7QydUvPhHH2Ie1IWoErdh F+hWJAUR9NU5u45kyXnRvifdf76IOrvQ+kOE9mtme7+JcSRDbxCw7Ae+E90+lSU6Qy 425WKkknxlkFt8mlvsZ0iyScI/CgqSP+/jM6WusJNjqXNfWs4vm/Nzbq4am/J2AAZd NRNRkCeyAwPlzTf/40qlY0RlLSCl8OxHWGg+OGXjWSJoQcp4jK6zU07DPdwM2AofDc Du5E3ab9e70/Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Stefan Hajnoczi , Feifan Qian , Paolo Bonzini , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 060/107] virtio-blk: add missing VIRTIO_BLK_T_SCSI_CMD size check (CVE-2026-48914) Date: Wed, 24 Jun 2026 16:31:05 +0300 Message-ID: <20260624133301.403266-60-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308857309158500 Content-Type: text/plain; charset="utf-8" From: Stefan Hajnoczi Check that the iovec containing struct virtio_scsi_inhdr is large enough before storing an error value there. Feifan Qian pointed out that this can be used to corrupt heap memory when the descriptor uses an MMIO address and a length of 1, forcing QEMU to allocate a 1-byte heap bounce buffer. virtio_stl_p() stores 4 bytes and therefore corrupts whatever is beyond the bounce buffer. Fixes: CVE-2026-48914 Fixes: f34e73cd69bd ("virtio-blk: report non-zero status when failing SG_IO= requests") Reported-by: Feifan Qian Cc: Paolo Bonzini Signed-off-by: Stefan Hajnoczi Message-ID: <20260526154957.1741622-1-stefanha@redhat.com> Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit aeea0c2804c42f24915467a1e4c70e649e39b8e0) Signed-off-by: Michael Tokarev diff --git a/hw/block/virtio-blk.c b/hw/block/virtio-blk.c index 9cb9f1fb2b..6b92066aff 100644 --- a/hw/block/virtio-blk.c +++ b/hw/block/virtio-blk.c @@ -199,10 +199,16 @@ static void virtio_blk_handle_scsi(VirtIOBlockReq *re= q) =20 /* * The scsi inhdr is placed in the second-to-last input segment, just - * before the regular inhdr. + * before the regular inhdr. VIRTIO implementations normally do not re= ly on + * the precise message framing, but legacy implementations did and so = we do + * too for the legacy virtio-blk SCSI request type. * * Just put anything nonzero so that the ioctl fails in the guest. */ + if (elem->in_sg[elem->in_num - 2].iov_len !=3D sizeof(*scsi)) { + status =3D VIRTIO_BLK_S_IOERR; + goto fail; + } scsi =3D (void *)elem->in_sg[elem->in_num - 2].iov_base; virtio_stl_p(vdev, &scsi->errors, 255); status =3D VIRTIO_BLK_S_UNSUPP; --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308353; cv=none; d=zohomail.com; s=zohoarc; b=XO04Vg94fz92r1kODXMwPMbP56l1Dp28WkwT9Bwy35TwketVR/pnSX8NUjhF/ZOpWbspPwBgvPij1ezMsLnIz1Jv2KUbN43lR4a5jolSNCx3JkGSMlPj8v49UhUmi2+5q8nUAWgNQLOf3+M2eFhrwICObFfSt6YPx9CvyOLhPn4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308353; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=kPRoR6Y4vKY65iZQNM4x0/upq0V5iiOWNlAtuLI6rO8=; b=HVVbMZTnPoT8ACKMRwPQfwtCUN5XElg9D/TfKU0b9Rhn3wSX2afZWE2Tj5zqZ8GD2A5YnjZKlWngNlfNxrT50RlqYT+jwfWpj15ewYLyQoYeyKM70esBCp1a0qLBXr9Sy0EDWhiGKGfCHFqsiNuRdXOYiZHWHlWBHGnNEjd4OME= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308353917887.5329529613282; Wed, 24 Jun 2026 06:39:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNor-0004JC-WC; Wed, 24 Jun 2026 09:39:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNop-00045V-IP; Wed, 24 Jun 2026 09:39:07 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNon-0001FS-J4; Wed, 24 Jun 2026 09:39:07 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 766701BA9EF; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1329A3DEA3E; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=yBluAs/gE8DSO3TfUiji3YFG4b/s0M7RfG8jpYCyV4I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=h2J+x+3mnizxuoibvR5sgJXUaRe0DpIlwhXcz0rly50tThvyg3IwFsS7T9EWwtNHw K9tWlteSIO8d6Zok4+bL62FfomXgY3RpsCI0C4RKo2ccG0Lep7zOJ3g4mcWjQG+s3Q KJoXtHQfAIYhIiarTAJmtyWuwYPVyrrNWR6t+8W9doMgSZfMgWfmpsto/Pm/9Xwy7K xQ2ExVVZ0sG6xkmV+QqJalUhXbBPmVvXPfnKVj2KE3lpFBD30+3xBexVmJPo9PXk5c KxnleM5xoANHlEMzTqZ7BAc7Bdy2IXP/TpxARWPEdtxzlST7H/PPWIf6cyHPXKIrxZ IRYO9KI+7acvw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-11.0.2 061/107] qemu-io: Add 'aio_discard' command Date: Wed, 24 Jun 2026 16:31:06 +0300 Message-ID: <20260624133301.403266-61-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308354420158501 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf Testing interactions between multiple requests that include discard requests require that qemu-io can do the discard asynchronously, like it already does for reads and writes. To this effect, add an 'aio_discard' command. Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-3-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit 7f8466e2ce620e3c6a6e2f32d616367174d4dbe9) Signed-off-by: Michael Tokarev diff --git a/qemu-io-cmds.c b/qemu-io-cmds.c index f6d077908f..de4c1966fe 100644 --- a/qemu-io-cmds.c +++ b/qemu-io-cmds.c @@ -2218,6 +2218,120 @@ static int discard_f(BlockBackend *blk, int argc, c= har **argv) return 0; } =20 +static void aio_discard_help(void) +{ + printf( +"\n" +" asynchronously discards a range of bytes from the given offset\n" +"\n" +" Example:\n" +" 'aio_discard 512 1k' - discards 1 kilobyte from 512 bytes into the file\= n" +"\n" +" Discards a segment of the currently open file.\n" +" -C, -- report statistics in a machine parsable format\n" +" -q, -- quiet mode, do not show I/O statistics\n" +" The discard is performed asynchronously and the aio_flush command must b= e\n" +" used to ensure all outstanding aio requests have been completed.\n" +" Note that due to its asynchronous nature, this command will be\n" +" considered successful once the request is submitted, independently\n" +" of potential I/O errors.\n" +"\n"); +} + +static int aio_discard_f(BlockBackend *blk, int argc, char **argv); + +static const cmdinfo_t aio_discard_cmd =3D { + .name =3D "aio_discard", + .cfunc =3D aio_discard_f, + .perm =3D BLK_PERM_WRITE, + .argmin =3D 2, + .argmax =3D -1, + .args =3D "[-Cq] off len", + .oneline =3D "asynchronously discards a number of bytes", + .help =3D aio_discard_help, +}; + +static void aio_discard_done(void *opaque, int ret) +{ + struct aio_ctx *ctx =3D opaque; + struct timespec t2; + + clock_gettime(CLOCK_MONOTONIC, &t2); + + if (ret < 0) { + printf("aio_discard failed: %s\n", strerror(-ret)); + block_acct_failed(blk_get_stats(ctx->blk), &ctx->acct); + goto out; + } + + block_acct_done(blk_get_stats(ctx->blk), &ctx->acct); + + if (ctx->qflag) { + goto out; + } + + /* Finally, report back -- -C gives a parsable format */ + t2 =3D tsub(t2, ctx->t1); + print_report("discarded ", &t2, ctx->offset, ctx->qiov.size, + ctx->qiov.size, 1, ctx->Cflag); +out: + g_free(ctx); +} + +static int aio_discard_f(BlockBackend *blk, int argc, char **argv) +{ + int c, ret; + int64_t count; + struct aio_ctx *ctx =3D g_new0(struct aio_ctx, 1); + + ctx->blk =3D blk; + + while ((c =3D getopt(argc, argv, "Cq")) !=3D -1) { + switch (c) { + case 'C': + ctx->Cflag =3D true; + break; + case 'q': + ctx->qflag =3D true; + break; + default: + g_free(ctx); + qemuio_command_usage(&aio_discard_cmd); + return -EINVAL; + } + } + + if (optind !=3D argc - 2) { + g_free(ctx); + qemuio_command_usage(&aio_discard_cmd); + return -EINVAL; + } + + ctx->offset =3D cvtnum(argv[optind]); + if (ctx->offset < 0) { + ret =3D ctx->offset; + print_cvtnum_err(ret, argv[optind]); + g_free(ctx); + return ret; + } + optind++; + + count =3D cvtnum(argv[optind]); + if (count < 0) { + print_cvtnum_err(count, argv[optind]); + g_free(ctx); + return count; + } + + clock_gettime(CLOCK_MONOTONIC, &ctx->t1); + ctx->qiov.size =3D count; + block_acct_start(blk_get_stats(blk), &ctx->acct, ctx->qiov.size, + BLOCK_ACCT_UNMAP); + blk_aio_pdiscard(blk, ctx->offset, count, aio_discard_done, ctx); + + return 0; +} + static int alloc_f(BlockBackend *blk, int argc, char **argv) { BlockDriverState *bs =3D blk_bs(blk); @@ -2800,6 +2914,7 @@ static void __attribute((constructor)) init_qemuio_co= mmands(void) qemuio_add_command(&length_cmd); qemuio_add_command(&info_cmd); qemuio_add_command(&discard_cmd); + qemuio_add_command(&aio_discard_cmd); qemuio_add_command(&alloc_cmd); qemuio_add_command(&map_cmd); qemuio_add_command(&reopen_cmd); --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308919; cv=none; d=zohomail.com; s=zohoarc; b=QvWuRu2UnNCVaZBjxJI6y3OhNfz0XyqX12bfszxu789IRphwtmjyLKaw+9bL9mV6OzuaNMoujWQRxmEQm6kT+4QTdZIVejdMowy9khInfBCNh2olx0PEBtTLjwBZTTMljDKEJVTQwgWSztY2IcPrm+1knscZZPLmQdkGcEZjCck= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308919; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=XG/QBUMXO+x5S9OgxaerXGYMSJsNzM/EDXUGasQPzHg=; b=S7idydFuxuNoExeaWQdXEdZ0X8dYEXClBkgfdIQI5S+PSfbZcYMMUWvb9wA1A2WkW/6uSzUmrUsGjvOatFpwNh6YpFswx33DPCfYN1jFb7+wfsvSI781wi5tUykTPNnIhnnRPNfWeR3EQPFV2I1uVI4FZ/JMAVpPQ+GisNDsdY4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308919984622.4041929649884; Wed, 24 Jun 2026 06:48:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNos-0004P5-UK; Wed, 24 Jun 2026 09:39:11 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNop-00045t-Kf; Wed, 24 Jun 2026 09:39:07 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNon-0001FU-JN; Wed, 24 Jun 2026 09:39:07 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 863FD1BA9F0; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 22C813DEA3F; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=8146qO6KFVKscfnp7ME4DCWZ2VVfJ/m5ZGh/Be/5xEg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=KcTmG/yn6S+qpkSF8mG2hXT9ihfTdlnMYSaGLgZ8eYuNIVb33zNyPloFMtow/oNSE zRIFmlBD2784i+dLm7heDA/bzmz7Y//IofAPHwVTtuNtPhtL2TUg6OtmNIye/wiJrm SVWbeg4+3dSgIHsymVTTMi4Q/9y2U5/45P4Q1Ic4XFNDNzShyMNwL+QkPQPtyEsP8f MhAoaDmqutb9a8/qrBmo99croH9BqJFDGEHThjBtz5EVWRNqc9H4oab4V5/z1JDCTN 49H5Oh9uMiuyzo6D7GMlDEefBDSaQwAbAxdRdgLBUN9XBvdlVcoEhEHNRhFjHb5r3d CnkzED2keP73w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-11.0.2 062/107] qcow2: Fix corruption on discard during write with COW Date: Wed, 24 Jun 2026 16:31:07 +0300 Message-ID: <20260624133301.403266-62-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308922173158500 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf Most code in qcow2 that accesses (and potentially modifies) L2 tables does so while holding s->lock. There is one exception, which is allocating writes. They hold the lock initially while allocating clusters, but drop it for writing the guest payload before taking the lock again for updating the L2 tables. This allows concurrent requests that touch other parts of the image file to continue in parallel and is an important performance optimisation. However, this means that other requests that run while the lock is dropped for writing guest data must synchronise with the list of allocating requests in s->cluster_allocs and wait if they would overlap. For writes, this is done in handle_dependencies(), but discard and write zeros operations neglect to synchronise with s->cluster_allocs. This means that discard can free a cluster whose L2 entry will already be modified in qcow2_alloc_cluster_link_l2() by a previously started write. In the case of a pre-allocated zero cluster that is in the process of being overwritten, this means that discard can lead to a situation where the cluster is still mapped (because the write will restore the L2 entry just without the zero flag), but its refcount has been decreased, resulting in a corrupted image. Add the missing synchronisation to qcow2_cluster_discard() and qcow2_subcluster_zeroize() to fix the problem. Cc: qemu-stable@nongnu.org Reported-by: Denis V. Lunev Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-4-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit b8bfb1478d61512f851badd0d912c6661a2efee7) Signed-off-by: Michael Tokarev diff --git a/block/qcow2-cluster.c b/block/qcow2-cluster.c index c655bf6df4..8b1e80bd0b 100644 --- a/block/qcow2-cluster.c +++ b/block/qcow2-cluster.c @@ -1392,6 +1392,9 @@ count_single_write_clusters(BlockDriverState *bs, int= nb_clusters, * the same cluster. In this case we need to wait until the previous * request has completed and updated the L2 table accordingly. * + * If allow_shortening =3D=3D true, instead of waiting for a dependency, *= cur_bytes + * can be shortened so that the cluster allocations don't overlap. + * * Returns: * 0 if there was no dependency. *cur_bytes indicates the number of * bytes from guest_offset that can be read before the next @@ -1403,7 +1406,9 @@ count_single_write_clusters(BlockDriverState *bs, int= nb_clusters, */ static int coroutine_fn handle_dependencies(BlockDriverState *bs, uint64_t guest_offset, - uint64_t *cur_bytes, QCowL2Met= a **m) + uint64_t *cur_bytes, + bool allow_shortening, + QCowL2Meta **m) { BDRVQcow2State *s =3D bs->opaque; QCowL2Meta *old_alloc; @@ -1434,7 +1439,7 @@ static int coroutine_fn handle_dependencies(BlockDriv= erState *bs, =20 /* Conflict */ =20 - if (start < old_start) { + if (start < old_start && allow_shortening) { /* Stop at the start of a running allocation */ bytes =3D old_start - start; } else { @@ -1469,6 +1474,29 @@ static int coroutine_fn handle_dependencies(BlockDri= verState *bs, return 0; } =20 +static void coroutine_mixed_fn wait_for_dependencies(BlockDriverState *bs, + uint64_t guest_offset, + uint64_t bytes) +{ + BDRVQcow2State *s =3D bs->opaque; + QCowL2Meta *m =3D NULL; + int ret; + + /* + * Discard has some non-coroutine callers (creating internal snapshots= and + * make empty). They are calling from qemu-img or in a drained section= , so + * we know that no writes can be in progress. + */ + if (!qemu_in_coroutine()) { + assert(QLIST_EMPTY(&s->cluster_allocs)); + return; + } + + do { + ret =3D handle_dependencies(bs, guest_offset, &bytes, false, &m); + } while (ret =3D=3D -EAGAIN); +} + /* * Checks how many already allocated clusters that don't require a new * allocation there are at the given guest_offset (up to *bytes). @@ -1840,7 +1868,7 @@ again: * the right synchronisation between the in-flight request= and * the new one. */ - ret =3D handle_dependencies(bs, start, &cur_bytes, m); + ret =3D handle_dependencies(bs, start, &cur_bytes, true, m); if (ret =3D=3D -EAGAIN) { /* Currently handle_dependencies() doesn't yield if we already= had * an allocation. If it did, we would have to clean up the L2M= eta @@ -2000,6 +2028,15 @@ int qcow2_cluster_discard(BlockDriverState *bs, uint= 64_t offset, int64_t cleared; int ret; =20 + /* + * If we're touching a cluster for which allocating writes are in flig= ht, + * wait for them to complete to avoid conflicting metadata updates. + * + * We don't need to allocate a QCowL2Meta for the discard operation be= cause + * s->lock is held for the duration of the whole operation. + */ + wait_for_dependencies(bs, offset, bytes); + /* Caller must pass aligned values, except at image end */ assert(QEMU_IS_ALIGNED(offset, s->cluster_size)); assert(QEMU_IS_ALIGNED(end_offset, s->cluster_size) || @@ -2160,6 +2197,15 @@ int coroutine_fn qcow2_subcluster_zeroize(BlockDrive= rState *bs, uint64_t offset, int64_t cleared; int ret; =20 + /* + * If we're touching a cluster for which allocating writes are in flig= ht, + * wait for them to complete to avoid conflicting metadata updates. + * + * We don't need to allocate a QCowL2Meta for the zeroize operation be= cause + * s->lock is held for the duration of the whole operation. + */ + wait_for_dependencies(bs, offset, bytes); + /* If we have to stay in sync with an external data file, zero out * s->data_file first. */ if (data_file_is_raw(bs)) { --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782309083; cv=none; d=zohomail.com; s=zohoarc; b=Vmdd9PysYQ9rCC+KNs1zVGVWIUyydYmzFlgqCQbqrOMFjXQHURs/1rV4l9Sd974Pqs6xnfdHUq2L1bBy/rTl15QMSlppHq4YnWy2DrHyLsaOzfZN7AIJaPfM6oNG3r/RZo0Yg/UOxN8D7MgDZPKnzfHBg9G6LR4nAuhYkDPqvu8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782309083; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=t3bebmnC8aHOfy8MMBLbDFnLegLK3bhqmi9Ry6uHOB4=; b=Eg+5jYawlfG+SVLhu6iCpWXN/vxYZ4Rkk5W69sC6nWzLrrGhE7pssZorz6rsVZHiEGe96RYFh3iO9Oqd9BZlkVTZIGev9N5Hp4QC7herF90ODTHgqDerTF3NSLZJ7s2b23v+WIUZlI3pviwBnyVNNpAIRO7ddCYBlsSN0d7OZGQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782309083425781.584599419274; Wed, 24 Jun 2026 06:51:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNou-0004aQ-Se; Wed, 24 Jun 2026 09:39:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNot-0004Re-2W; Wed, 24 Jun 2026 09:39:11 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNor-0001Fz-2l; Wed, 24 Jun 2026 09:39:10 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 95F911BA9F1; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 329E03DEA40; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=NeizuiU9CNw1ZzTV6M1T2A/yYQYGEMCvWTUWZVtOwzs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=CYUvUy68FFgNUN53GnvmoXskDC/Ln6AHDdDWv9MF2zH/5e4APnD01aqUnxq9hhzz/ SWhzCMnEuZwrYtEfqLgzfMvClsi6H4tIWFnfxfueN13umY/DJxjptRrYUV54K9SnmB m8l0nNgREXVyRvQz/pyQYS7sjqwrcWXNKtwFJkQ9zZkEI+T/JYhJ3aDTTNNEf/uSz5 JPYRRTW2K+qoCQLzMUOEOLZ6iLGrRy02E8xINNW+KDauAJVjZcmIdwKUZmMLtwgoEG L8OHJm5is+Uh1lQWNtj8euPd2qNPzRzjgyrjeYyIWi9Oh81GXRnLg4WZF7yCbhg9d2 GZxz2LvYrMyAQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Kevin Wolf , "Denis V. Lunev" , Michael Tokarev Subject: [Stable-11.0.2 063/107] iotests/046: Test that discard/write_zeroes wait for dependencies Date: Wed, 24 Jun 2026 16:31:08 +0300 Message-ID: <20260624133301.403266-63-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782309085073158500 Content-Type: text/plain; charset="utf-8" From: Kevin Wolf This is a regression test for the bug fixed in the previous commit where discard and write_zeroes operations wouldn't consider their dependencies in s->cluster_allocs. Without the fix, this results in a corrupted image. Signed-off-by: Kevin Wolf Message-ID: <20260427170520.101242-5-kwolf@redhat.com> Reviewed-by: Denis V. Lunev Tested-by: Denis V. Lunev Signed-off-by: Kevin Wolf (cherry picked from commit 389f5bcc744d3ddc127d550a57261aed9bbba1f3) Signed-off-by: Michael Tokarev diff --git a/tests/qemu-iotests/046 b/tests/qemu-iotests/046 index 4c9ed4d26e..e03dd40147 100755 --- a/tests/qemu-iotests/046 +++ b/tests/qemu-iotests/046 @@ -184,6 +184,48 @@ aio_write -P 160 0x104000 0x18000 resume A aio_flush EOF + +# Create a pre-allocated zero cluster, then start a write on it and discar= d it +# before the L2 update is made +cat < Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308914835533.406897568912; Wed, 24 Jun 2026 06:48:34 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNpG-0005Og-AN; Wed, 24 Jun 2026 09:39:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpE-0005LC-4b; Wed, 24 Jun 2026 09:39:32 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpB-0001G2-5O; Wed, 24 Jun 2026 09:39:31 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A6C341BA9F2; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 42C393DEA41; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=effkG/M7ewMd9+pWv2wvWsr68cl3JK9vqRmhBkgxO6k=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=lnZpLHgiso3BCL+XppDu2RG+V6Il03XoAzTFa3cmEXs8OFkEv+hHXX0bV6IVtlp7a 0u0Pn2Mn/vxrDbyPVjITcqbwGkykjlYpk/WE96RChS8ftZr6IAIEzIczcE70VgChiO wQthYSNoXwUI5NBTiFDuOmGSy2lZGBJGOJZ8y3teK+V7JmvKUYpMYRHS/AB5+HVh9D ieTWXTdREzUGJL6wb0eCuOrc1cJm3C6y5ji22kbDZjViiP54iWd/AZLpGefyeyIs0q JbQjPZWS6i0JA90fGi0r5Wjd9fIdaBxxc52oKErDe2BD7KWxeJueCh7KZi6m3FcaWA 0DCw+UVC5NPLQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Thomas Lamprecht , Fiona Ebner , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 064/107] qcow2: Fix data loss on zero write with detect-zeroes=unmap Date: Wed, 24 Jun 2026 16:31:09 +0300 Message-ID: <20260624133301.403266-64-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308916201158500 Content-Type: text/plain; charset="utf-8" From: Thomas Lamprecht Commit b8bfb1478d ("qcow2: Fix corruption on discard during write with COW") added a wait_for_dependencies() at the start of qcow2_subcluster_zeroize(). That fixes the inconsistency it set out to fix, but turns the lock-protected pre-check in the caller, qcow2_co_pwrite_zeroes(), into a stale one: the wait yields s->lock, so an in-flight allocating write whose QCowL2Meta is already on s->cluster_allocs (but whose L2 entry is not yet linked) gets to link its entry during the yield. When the zeroize wakes, the cluster is now NORMAL, and with BDRV_REQ_MAY_UNMAP the free path in zero_in_l2_slice() unmaps the just-written cluster, silently dropping the data write's payload. This is reachable with detect-zeroes=3Dunmap (the default for VirtIO disks with discard on in Proxmox VE), under which the block layer auto-promotes all-zero buffers to BDRV_REQ_ZERO_WRITE | BDRV_REQ_MAY_UNMAP. A memory-constrained Debian guest running 'apt full-upgrade' on such a disk reproduces it as random SIGSEGVs: swapped-out code pages come back as zero. Wait for in-flight dependencies before the lock-protected check in qcow2_co_pwrite_zeroes(). If a write linked its L2 entry during the wait, the type check now fails and the block layer falls back to a bounce-buffered zero write that only touches the requested subrange, preserving the racing write's data. Promote wait_for_dependencies() to qcow2_wait_for_dependencies() so qcow2.c can call it. Fixes: b8bfb1478d ("qcow2: Fix corruption on discard during write with COW") Fixes: 7534bb105b ("qcow2: Fix corruption on discard during write with COW"= ) in 11.0.x series Cc: qemu-stable@nongnu.org Tested-by: Fiona Ebner Reviewed-by: Fiona Ebner Signed-off-by: Thomas Lamprecht Message-ID: <20260522151318.238064-1-t.lamprecht@proxmox.com> [kwolf: Reverted unnecessary change to 'nr' assignment] Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit 1d47eb68983577a4e06fe1c165d90e128b191b86) Signed-off-by: Michael Tokarev diff --git a/block/qcow2-cluster.c b/block/qcow2-cluster.c index 8b1e80bd0b..e02fae6a0c 100644 --- a/block/qcow2-cluster.c +++ b/block/qcow2-cluster.c @@ -1474,9 +1474,9 @@ static int coroutine_fn handle_dependencies(BlockDriv= erState *bs, return 0; } =20 -static void coroutine_mixed_fn wait_for_dependencies(BlockDriverState *bs, - uint64_t guest_offset, - uint64_t bytes) +void coroutine_mixed_fn qcow2_wait_for_dependencies(BlockDriverState *bs, + uint64_t guest_offset, + uint64_t bytes) { BDRVQcow2State *s =3D bs->opaque; QCowL2Meta *m =3D NULL; @@ -2035,7 +2035,7 @@ int qcow2_cluster_discard(BlockDriverState *bs, uint6= 4_t offset, * We don't need to allocate a QCowL2Meta for the discard operation be= cause * s->lock is held for the duration of the whole operation. */ - wait_for_dependencies(bs, offset, bytes); + qcow2_wait_for_dependencies(bs, offset, bytes); =20 /* Caller must pass aligned values, except at image end */ assert(QEMU_IS_ALIGNED(offset, s->cluster_size)); @@ -2204,7 +2204,7 @@ int coroutine_fn qcow2_subcluster_zeroize(BlockDriver= State *bs, uint64_t offset, * We don't need to allocate a QCowL2Meta for the zeroize operation be= cause * s->lock is held for the duration of the whole operation. */ - wait_for_dependencies(bs, offset, bytes); + qcow2_wait_for_dependencies(bs, offset, bytes); =20 /* If we have to stay in sync with an external data file, zero out * s->data_file first. */ diff --git a/block/qcow2.c b/block/qcow2.c index 81fd299b4c..19271b10a4 100644 --- a/block/qcow2.c +++ b/block/qcow2.c @@ -4234,10 +4234,16 @@ qcow2_co_pwrite_zeroes(BlockDriverState *bs, int64_= t offset, int64_t bytes, } =20 qemu_co_mutex_lock(&s->lock); - /* We can have new write after previous check */ offset -=3D head; bytes =3D s->subcluster_size; nr =3D s->subcluster_size; + /* + * Wait for in-flight allocating writes first: otherwise the type + * check below could pass on UNALLOCATED while a yet-to-link_l2 wr= ite + * completes during qcow2_subcluster_zeroize()'s own wait, letting= the + * resumed MAY_UNMAP discard the just-written data. + */ + qcow2_wait_for_dependencies(bs, offset, bytes); ret =3D qcow2_get_host_offset(bs, offset, &nr, &off, &type); if (ret < 0 || (type !=3D QCOW2_SUBCLUSTER_UNALLOCATED_PLAIN && diff --git a/block/qcow2.h b/block/qcow2.h index 192a45d596..ce517040c4 100644 --- a/block/qcow2.h +++ b/block/qcow2.h @@ -966,6 +966,10 @@ int coroutine_fn GRAPH_RDLOCK qcow2_subcluster_zeroize(BlockDriverState *bs, uint64_t offset, uint64_t b= ytes, int flags); =20 +void coroutine_mixed_fn +qcow2_wait_for_dependencies(BlockDriverState *bs, uint64_t guest_offset, + uint64_t bytes); + int GRAPH_RDLOCK qcow2_expand_zero_clusters(BlockDriverState *bs, BlockDriverAmendStatusCB *status_cb, diff --git a/tests/qemu-iotests/046 b/tests/qemu-iotests/046 index e03dd40147..0d84b5c1c7 100755 --- a/tests/qemu-iotests/046 +++ b/tests/qemu-iotests/046 @@ -226,6 +226,26 @@ aio_write -z 0x140000 0x10000 resume A aio_flush EOF + +# Start an allocating write to a previously unallocated cluster and, before +# its L2 update is linked, issue a concurrent sub-cluster zero write with +# MAY_UNMAP that targets a disjoint range within the same cluster. The zero +# write's head/tail are zero (cluster is unallocated), so qcow2_co_pwrite_= zeroes +# would expand it to the full subcluster. Without waiting for dependencies +# before the zero write's "unallocated" type check, that check passes, +# qcow2_subcluster_zeroize then yields in wait_for_dependencies, the alloc= ating +# write links its L2 entry, and the resumed zeroize unmaps the cluster - +# silently discarding the just-written data. Waiting first makes the zero = write +# fall back to a bounce-buffered real write, which only touches its own +# subrange. +cat < Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308633051430.1833192804811; Wed, 24 Jun 2026 06:43:53 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNpI-0005Ro-2D; Wed, 24 Jun 2026 09:39:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpG-0005Oy-7R; Wed, 24 Jun 2026 09:39:34 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpE-0001HD-FL; Wed, 24 Jun 2026 09:39:33 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B4BFA1BA9F3; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 528AC3DEA42; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=sDVad7yR6XfEtdjJL/uZdWVwB7wdrZAt4MA6KLhxk0o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=cUh3SfR4QhbNPdqf+iW8jgCPdmrRyJ0oyzHnGs4LWtZE7dQD8pC3jxsyBJ/yKO4id XFggH3pxhb85ByAxXeFBK/DqyoF/uf1+ozJPlaVu+8ZzNBcgoyeyiqTiCTF9D+nMwK UhQERLFDFj11WKzQ0hgg/scFomFUWUynH1qswFJhEDCyTRS3i5vVYzngRvB0MzjDGI IFfjIgzUzCLAsJOSTbKH8b1UMIFqJ3t8ZtWTKYUX/LdfeKo4adKRBh/hgrBoBTHfzn PTx+dCF3RTWRas6Xkm7+O0blAy9+vNt+cZuCsBhuHjzE+tdnrz2XxXDLCrQ7YX5oPu dPynmS5j9NQ/A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fiona Ebner , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 065/107] block/export/fuse: use struct fuse_init_in Date: Wed, 24 Jun 2026 16:31:10 +0300 Message-ID: <20260624133301.403266-65-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308633572158500 Content-Type: text/plain; charset="utf-8" From: Fiona Ebner The code is switched to use the current 'struct fuse_init_in' in preparation to use the FUSE_DIRECT_IO_ALLOW_MMAP feature, which is part of the flags2 member that got added in protocol version 5.36. To not break compatibility with older kernels, the check for whether the full header of an operation was read in co_read_from_fuse_fd() needs to be adapted. In particular, for a FUSE_INIT operation, the protocol version must be considered, because the length of the header changed with protocol version 7.36. Always using the length of the old, shorter struct was inaccurate, since for newer protocol versions this might mean accepting a truncated read for FUSE_INIT. Users of the init header that want to use parts of the extended structure must check with the using_old_fuse_init_in() helper function if they may do so. Cc: qemu-stable@nongnu.org Fixes: a94a1d7699 ("fuse: Manually process requests (without libfuse)") Signed-off-by: Fiona Ebner Message-ID: <20260506145424.10249-2-f.ebner@proxmox.com> Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit 817cc2d045d25c980f20c2377d4a301f68d3e3e2) Signed-off-by: Michael Tokarev diff --git a/block/export/fuse.c b/block/export/fuse.c index a2a478d293..35218e3197 100644 --- a/block/export/fuse.c +++ b/block/export/fuse.c @@ -51,23 +51,16 @@ #define FUSE_MAX_READ_BYTES (MIN(BDRV_REQUEST_MAX_BYTES, 1 * 1024 * 1024)) #define FUSE_MAX_WRITE_BYTES (64 * 1024) =20 -/* - * fuse_init_in structure before 7.36. We don't need the flags2 field add= ed - * there, so we can work with the smaller older structure to stay compatib= le - * with older kernels. - */ -struct fuse_init_in_compat { - uint32_t major; - uint32_t minor; - uint32_t max_readahead; - uint32_t flags; -}; - typedef struct FuseRequestInHeader { struct fuse_in_header common; /* All supported requests */ union { - struct fuse_init_in_compat init; + /* + * When using_old_fuse_init_in() is true, then the smaller older s= truct + * is used by the kernel. The flags2 member and other new members = must + * be treated as absent then. + */ + struct fuse_init_in init; struct fuse_open_in open; struct fuse_setattr_in setattr; struct fuse_read_in read; @@ -629,6 +622,16 @@ static int clone_fuse_fd(int fd, Error **errp) return new_fd; } =20 +/** + * Check whether the smaller older fuse_init_in structure from before prot= ocol + * version 7.36 is used. The flags2 member and other new members must be t= reated + * as absent then. + */ +static bool using_old_fuse_init_in(const struct fuse_init_in *in) +{ + return in->major < 7 || (in->major =3D=3D 7 && in->minor < 36); +} + /** * Try to read a single request from the FUSE FD. * Takes a FuseQueue pointer in `opaque`. @@ -693,6 +696,31 @@ static void coroutine_fn co_read_from_fuse_fd(void *op= aque) goto no_request; } =20 + /* + * If the request is of type FUSE_INIT, need to check the version to + * actually determine the length of the fuse_init_in structure used by= the + * kernel. In protocol version 7.36, the structure was extended. + */ + if (in_hdr->common.opcode =3D=3D FUSE_INIT) { + /* Length of the fuse_init_in structure before 7.36. */ + size_t old_init_hdr_len =3D 16; + + /* + * Expect at least the size of the smaller older structure to ensu= re the + * version can be checked. + */ + if (unlikely(ret < sizeof(in_hdr->common) + old_init_hdr_len)) { + error_report("FUSE_INIT request truncated, read only %zi bytes= ", + ret); + fuse_write_err(fuse_fd, &in_hdr->common, -EINVAL); + goto no_request; + } + + if (using_old_fuse_init_in(&in_hdr->init)) { + op_hdr_len =3D old_init_hdr_len; + } + } + if (unlikely(ret < sizeof(in_hdr->common) + op_hdr_len)) { error_report("FUSE request truncated, expected %zu bytes, read %zi= " "bytes", @@ -826,7 +854,7 @@ static bool is_regular_file(const char *path, Error **e= rrp) */ static ssize_t coroutine_fn GRAPH_RDLOCK fuse_co_init(FuseExport *exp, struct fuse_init_out *out, - const struct fuse_init_in_compat *in) + const struct fuse_init_in *in) { const uint32_t supported_flags =3D FUSE_ASYNC_READ | FUSE_ASYNC_DIO; =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:26 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308394; cv=none; d=zohomail.com; s=zohoarc; b=MMboDVx2e7elQzf2T34FbaHpsNz7mzX6hJz7SZP1LqJ/tUFVm1lqNPfVKZMfwsbQrgzbojPIAR2pKa9fYebVHWqeplUfBIvKvDb81bl0aQtD9y5HKgYgFuflY1qkA+PhSA5yz2UBQvhVCAdQM5GFUl/1gucWCn+/EAcM4iMgCNA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308394; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ZBLgF+W5SjUqZJQXToW7R0E3F/mPFd4kMce0TaDdles=; b=OXETONa4TDAa/BvXHidWN6vZ3abQVqTfitz6teGkeRY0jsnGvq9MYthhzsl8RTRK1INHBqVevUSD2c255m2KcePFENVh0m7vKEo1Sjs1ijgq7z0p6qCZumWrvDCeDoWSu/7nzk+kb07HV8aFVQAm25n85S9AydwpPztgR+dlLcQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308394761612.8803232939498; Wed, 24 Jun 2026 06:39:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNpJ-0005SY-9O; Wed, 24 Jun 2026 09:39:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpH-0005Ql-CB; Wed, 24 Jun 2026 09:39:35 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpF-0001IY-K3; Wed, 24 Jun 2026 09:39:35 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C44771BA9F4; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6126F3DEA43; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=Qa5RM/R3DMq9VLRLiufaoNNUf9HV7xjAG3zxZJj488Y=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=jUdAmoSFSUGgv7Itrb1lxVI8epLzNqyQqr6czl1cuUHZS+3nBcBP9xBxqMRgznCiu lJSbnLC2LVDX2f7QIw8GYuhX8zWN9QsS7EcxoFYq+/47wUjMeeMLU8DbBdPnMuZExB L6houGvYqNUJN+NrytieJIYm6srO5F03KJ6raK4Jq1haCpq956HOvqg0iKSU1BHEzg eifbrTzosYaLprebD3MWhFr1RrGpam6gyvYNfhYh50JbWKKdvmIAeAuuvdPzvvWuen ER94ISbLiBlQ0QivL2+bgLKhuFQ+AQVmJD8PPHVePzXuAXJHAlw1EQ2OQH07kkHVA/ jCB6KbUaZJUXw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fiona Ebner , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 066/107] block/export/fuse: set FUSE_DIRECT_IO_ALLOW_MMAP flag to fix regression Date: Wed, 24 Jun 2026 16:31:11 +0300 Message-ID: <20260624133301.403266-66-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308396577158500 Content-Type: text/plain; charset="utf-8" From: Fiona Ebner Commit 8599559580 ("fuse: Set direct_io and parallel_direct_writes") broke use cases that require mmap() with MAP_SHARED on the export. In particular, swtpm_setup using its 'file://' protocol requires this. From the kernel documentation [0]: > To allow shared mmap, the FUSE_DIRECT_IO_ALLOW_MMAP flag may be > enabled in the FUSE_INIT reply. Set the FUSE_DIRECT_IO_ALLOW_MMAP flag to restore compatibility with users requiring shared mmap. The FUSE_INIT_EXT flag needs to be set for the flags2 member to have an effect. [0]: https://www.kernel.org/doc/html/next/filesystems/fuse/fuse-io.html Cc: qemu-stable@nongnu.org Fixes: 8599559580 ("fuse: Set direct_io and parallel_direct_writes") Signed-off-by: Fiona Ebner Message-ID: <20260506145424.10249-3-f.ebner@proxmox.com> Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit d1664a4058b2b4285d281d32c81ef646f78e7d9a) Signed-off-by: Michael Tokarev diff --git a/block/export/fuse.c b/block/export/fuse.c index 35218e3197..c0e8dfb643 100644 --- a/block/export/fuse.c +++ b/block/export/fuse.c @@ -856,7 +856,8 @@ static ssize_t coroutine_fn GRAPH_RDLOCK fuse_co_init(FuseExport *exp, struct fuse_init_out *out, const struct fuse_init_in *in) { - const uint32_t supported_flags =3D FUSE_ASYNC_READ | FUSE_ASYNC_DIO; + uint32_t supported_flags =3D FUSE_ASYNC_READ | FUSE_ASYNC_DIO; + uint32_t flags2 =3D 0; =20 if (in->major !=3D 7) { error_report("FUSE major version mismatch: We have 7, but kernel h= as %" @@ -871,13 +872,21 @@ fuse_co_init(FuseExport *exp, struct fuse_init_out *o= ut, return -EINVAL; } =20 + if (!using_old_fuse_init_in(in)) { + /* The flags2 flags must be shifted down by 32 bits. */ + const uint32_t supported_flags2 =3D FUSE_DIRECT_IO_ALLOW_MMAP >> 3= 2; + /* flags2 is only considered if FUSE_INIT_EXT is set. */ + supported_flags =3D supported_flags | FUSE_INIT_EXT; + flags2 =3D in->flags2 & supported_flags2; + } + *out =3D (struct fuse_init_out) { .major =3D 7, .minor =3D MIN(FUSE_KERNEL_MINOR_VERSION, in->minor), .max_readahead =3D in->max_readahead, .max_write =3D FUSE_MAX_WRITE_BYTES, .flags =3D in->flags & supported_flags, - .flags2 =3D 0, + .flags2 =3D flags2, =20 /* libfuse maximum: 2^16 - 1 */ .max_background =3D UINT16_MAX, --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308886; cv=none; d=zohomail.com; s=zohoarc; b=ExgJbzs1WuMkx1x3gRBVV2NjU1o6VifxFQ1GFvx3PO4H6gbJk7Z6mEoyGVfE4j4QBrohx71t1mDU7yY4F8lQWPFqV4JMPr66IbbCPQeGOEiUcIeLs8lJH1yXg7aZBfV5zoMKfTKV2W+Q/UdzC13l//Te0tqTtdp9Me5Od8mie+Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308886; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=cXf9T8Brb7cwvMNXE1TyuRSqm5AirRBN/76LbIfisV8=; b=ESzASvTj+RyP79+H/pxTpX91HrXNTu8y7JvrdrCQl2Krf2E+p4VxJDhAkleWem26pzOfEP+ldPHA1muCIsiC+FFxVx9kTTCYVrOec5KaTJMvd7M7b02UcUV0zcItaghx1Ur5jtP94OqolYKYMBYVERahW3rszc7RcMW1O3oU/0c= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308886130559.5884092668722; Wed, 24 Jun 2026 06:48:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNpL-0005WG-4Q; Wed, 24 Jun 2026 09:39:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpJ-0005UL-Gb; Wed, 24 Jun 2026 09:39:37 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpH-0001Iy-Lw; Wed, 24 Jun 2026 09:39:37 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D37241BA9F5; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 70ED43DEA44; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=DvcG+/emGldtmPeJDW0d3whJBKyCeFHS8szQ3LhN0e0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=grknz3PeTe6QompirRChMVPhqBSv4oY7SnfYviNCXDDvK5QWMp3akcEZVT0V85ijN tQVLg41FouGfXZpQYLP+JVX8UBVmtUmK1omn/+ZP+r1aG0C9Cs9pCA1FB+gXe/BfVk ArlJxgEZJpOet7wUdD7QBWes0stgRYJMB2NirJfbIcVbya7aYczOABKZA+5dbkV1s9 ymKmUiA6+36j8n2qlZmiDTtpyM1TEZANuHAqQCPX94D5uXqo3ILsNo7zt9Kco7kbiB dHeqzKzKRfgU6ipOBmKFKZK4JR2XJ9hjIS2tBx4Ty3GR0qVAHv2onuPR1LDdlr/xSq 0PXq777a1hgIg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fiona Ebner , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 067/107] iotests: test shared mmap for fuse export Date: Wed, 24 Jun 2026 16:31:12 +0300 Message-ID: <20260624133301.403266-67-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308887760158500 Content-Type: text/plain; charset="utf-8" From: Fiona Ebner This test would have worked before commit 8599559580 ("fuse: Set direct_io and parallel_direct_writes") and is working again since commit HEAD~1 ("block/export/fuse: set FUSE_DIRECT_IO_ALLOW_MMAP flag to fix regression"). Signed-off-by: Fiona Ebner Message-ID: <20260506145424.10249-4-f.ebner@proxmox.com> Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit ba20257d9b45c28f23a66b3f79bebffd6322ff76) Signed-off-by: Michael Tokarev diff --git a/tests/qemu-iotests/tests/fuse-mmap-shared b/tests/qemu-iotests= /tests/fuse-mmap-shared new file mode 100755 index 0000000000..52941a3bb6 --- /dev/null +++ b/tests/qemu-iotests/tests/fuse-mmap-shared @@ -0,0 +1,105 @@ +#!/usr/bin/env python3 +# group: rw +# +# Test that a FUSE export can be mmap()-ed with MAP_SHARED +# +# Copyright (C) 2026 Proxmox Server Solutions GmbH +# +# SPDX-License-Identifier: GPL-2.0-or-later + +import os +import itertools +import mmap +from mmap import MAP_SHARED +from pathlib import Path + +import iotests +from iotests import qemu_img, qemu_io, QemuStorageDaemon + +def test_fuse_support(mount_point): + test_qsd =3D QemuStorageDaemon('--blockdev', 'null-co,node-name=3Dnode= 0', + qmp=3DTrue) + res =3D test_qsd.qmp('block-export-add', { + 'id': 'exp0', + 'type': 'fuse', + 'node-name': 'node0', + 'mountpoint': mount_point, + 'allow-other': 'off' + }) + test_qsd.stop() + if 'error' in res: + assert (res['error']['desc'] =3D=3D + "Parameter 'type' does not accept value 'fuse'") + iotests.notrun('No FUSE support') + +# Shared mmap when using direct IO is only supported for Linux kernels >= =3D 6.6 +# with commit e78662e818f94 ("fuse: add a new fuse init flag to relax +# estrictions in no cache mode"). +def test_linux_kernel_support(): + [major, minor] =3D map(int, os.uname().release.split('.')[:2]) + if major < 6 or (major =3D=3D 6 and minor < 6): + iotests.notrun('No kernel support for shared mmap with direct IO') + +image_size =3D 1 * 1024 * 1024 +image =3D os.path.join(iotests.test_dir, 'image.' + iotests.imgfmt) +fuse_mount_point =3D os.path.join(iotests.test_dir, 'export.fuse') +Path(fuse_mount_point).touch() + +test_fuse_support(fuse_mount_point) +test_linux_kernel_support() + +class TestMmapShared(iotests.QMPTestCase): + + def setUp(self): + qemu_img('create', '-f', iotests.imgfmt, image, str(image_size)) + qemu_io(image, '-c', f'write -P 23 0 {image_size}') + + self.qsd =3D QemuStorageDaemon(qmp=3DTrue) + + self.qsd.cmd('blockdev-add', { + 'node-name': 'node0', + 'driver': iotests.imgfmt, + 'file': { + 'driver': 'file', + 'filename': image + } + }) + + self.qsd.cmd('block-export-add', { + 'id': 'exp0', + 'type': 'fuse', + 'node-name': 'node0', + 'mountpoint': fuse_mount_point, + 'writable': True, + 'allow-other': 'off' + }) + + def tearDown(self): + self.stop_qsd() + os.remove(image) + os.remove(fuse_mount_point) + + def stop_qsd(self): + if self.qsd: + self.qsd.stop() + self.qsd =3D None + + def test_mmap_shared(self): + with open(fuse_mount_point, 'r+b') as file: + with mmap.mmap(file.fileno(), image_size, flags=3DMAP_SHARED) = as mm: + buf =3D bytearray(image_size) + buf[:] =3D itertools.repeat(23, image_size) + assert mm.read(image_size) =3D=3D buf + buf[:] =3D itertools.repeat(42, image_size) + mm.seek(0) + mm.write(buf) + mm.flush() + self.stop_qsd() + qemu_io(image, '-c', f'read -P 42 0 {image_size}') + +if __name__ =3D=3D '__main__': + # LUKS would require key-secret in blockdev-add + iotests.main(supported_fmts=3D['generic'], + unsupported_fmts=3D['luks'], + supported_protocols=3D['file'], + supported_platforms=3D['linux']) diff --git a/tests/qemu-iotests/tests/fuse-mmap-shared.out b/tests/qemu-iot= ests/tests/fuse-mmap-shared.out new file mode 100644 index 0000000000..ae1213e6f8 --- /dev/null +++ b/tests/qemu-iotests/tests/fuse-mmap-shared.out @@ -0,0 +1,5 @@ +. +---------------------------------------------------------------------- +Ran 1 tests + +OK --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308446; cv=none; d=zohomail.com; s=zohoarc; b=UGNJAra03N10Y+i4tXo/p+UCtJIxTP6woBiFbV5bx9Vf6Ns08U7xcSye6mtwIz8l2CrZDVrKvR13WFS7WkBjATzwKGavOqdbnHDcW9EEuHwLcL1XLqIvoKdQlYwop8Hr+z+8IFziUbJbG4rlDC0gXTumvotSGg5fIhL8q5hLuFI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308446; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YY0uwse6Hb5jrP1SVvHE0sspwTX5gxzDKwYLa5WCu7I=; b=Ar0pHl0Dxjwstea/zYncX9DKJmdfISE5QKti6KbDbei9larR09an3SYxeFATC+jgjti7FHnMvYp4tQm1EwBll7tZIpHdhlzZBrXcY+xYN4PBVCbdJnN0ul/KECngDnAOuj8iAhdrqK1yBXg1hRGbfB/pLLwW1TJpjTJqOn/7kQI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178230844648611.371928294734289; Wed, 24 Jun 2026 06:40:46 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNpM-0005XF-2G; Wed, 24 Jun 2026 09:39:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpL-0005Wc-69; Wed, 24 Jun 2026 09:39:39 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpI-0001JA-TP; Wed, 24 Jun 2026 09:39:38 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E44D21BA9F6; Wed, 24 Jun 2026 16:33:19 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 7FD863DEA45; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782307999; bh=sfQCC5CgFR1Bz1gV5P/NZ8E4hv3um15ceX7Klvs2YNc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=DycWhdsLytPhMXZDcqH0FLi7oruteSJbdXzLwGiWXEjUP3xa2K6t7LNcfjKx6t3w6 baJDO75DW8e0xMZIRcIG2FtmAVFGwRBtS3MtdO9nGUd74lZD10ws4acTrIFoveBZyu MFXXqoVEO0z+iNf1WQNUTLEW5F+jHU44cYqX1cPcPJAAl8dEzOiKPidTCQ+84xICYi M/BYJcI5BFu7/AcISn+eFbAB1yMYbfOCsFOFEGQgJRXRtJ/8U5J2fmfjzLQU1A1DFv HruesYeSopnu4IhzSwMEFXlH+HlmTkOq387IyUIqvKafVyeCANVF9wgSKdh1/3gxAA htlSUE0DNK42g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Fabiano Rosas , Stefan Hajnoczi , Kevin Wolf , Michael Tokarev Subject: [Stable-11.0.2 068/107] qed: Don't try to flush during incoming migration Date: Wed, 24 Jun 2026 16:31:13 +0300 Message-ID: <20260624133301.403266-68-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308448960158500 Content-Type: text/plain; charset="utf-8" From: Fabiano Rosas It's not possible to access the image file while there is an incoming migration in progress, the QEMU process doesn't hold any locks to the storage at this point so nodes are inactive. Attempting to flush leads to an assert at bdrv_co_write_req_prepare(): assert(!(bs->open_flags & BDRV_O_INACTIVE)) The issue is reproducible by running iotest 181 on a host under cpu load. The migration must coincide with the header already containing the QED_F_NEED_CHECK flag. The sequence of events is as follows, with the respective call stacks referenced below: During block device init, bdrv_qed_attach_aio_context() starts the 'need_check' timer. The timer will not fire during incoming migration as it uses QEMU_CLOCK_VIRTUAL (to avoid this very issue, as the code comment indicates). (0) However, there's still bdrv_qed_drain_begin() which uses the fact that the timer is live to decide whether to start the qed_need_check_timer_entry() directly. (1) The qed_need_check_timer_entry() eventually calls into qed_write_header() -> bdrv_co_pwrite() leading to the assert. (2) Skip creating the 'need_check' timer whenever the image is inactive. The stacks: (0) =3D=3D issues timer_mod =3D=3D #6 in qed_start_need_check_timer at ../block/qed.c:340 #7 in bdrv_qed_attach_aio_context at ../block/qed.c:373 #8 in bdrv_qed_do_open at ../block/qed.c:556 #9 in bdrv_qed_open_entry at ../block/qed.c:582 #10 in coroutine_trampoline at ../util/coroutine-ucontext.c:175 #0 in qemu_coroutine_switch<+120> at ../util/coroutine-ucontext.c:321 #1 in qemu_aio_coroutine_enter<+356> at ../util/qemu-coroutine.c:293 #2 in aio_co_enter<+179> at ../util/async.c:710 #3 in aio_co_wake<+53> at ../util/async.c:695 #4 in thread_pool_co_cb<+47> at ../util/thread-pool.c:283 #5 in thread_pool_completion_bh<+241> at ../util/thread-pool.c:202 #6 in aio_bh_call<+109> at ../util/async.c:173 #7 in aio_bh_poll<+299> at ../util/async.c:220 #8 in aio_poll<+690> at ../util/aio-posix.c:745 #9 in bdrv_qed_open<+392> at ../block/qed.c:607 #10 in bdrv_open_driver<+327> at ../block.c:1678 #11 in bdrv_open_common<+1619> at ../block.c:2008 #12 in bdrv_open_inherit<+2556> at ../block.c:4191 #13 in bdrv_open<+118> at ../block.c:4286 #14 in blk_new_open<+199> at ../block/block-backend.c:458 #15 in blockdev_init<+2011> at ../blockdev.c:612 #16 in drive_new<+3008> at ../blockdev.c:1008 #17 in drive_init_func<+51> at ../system/vl.c:662 #18 in qemu_opts_foreach<+227> at ../util/qemu-option.c:1148 #19 in configure_blockdev<+350> at ../system/vl.c:721 #20 in qemu_create_early_backends<+343> at ../system/vl.c:2076 #21 in qemu_init<+12483> at ../system/vl.c:3778 #22 in main<+46> at ../system/main.c:71 (1) =3D=3D sees timer_pending =3D=3D #6 in bdrv_qed_drain_begin at ../block/qed.c:391 #7 in bdrv_do_drained_begin at ../block/io.c:366 #8 in bdrv_do_drained_begin_quiesce at ../block/io.c:386 #9 in bdrv_child_cb_drained_begin at ../block.c:1207 #10 in bdrv_parent_drained_begin_single at ../block/io.c:133 #11 in bdrv_parent_drained_begin at ../block/io.c:64 #12 in bdrv_do_drained_begin at ../block/io.c:364 #13 in bdrv_drained_begin at ../block/io.c:393 #14 in blk_drain at ../block/block-backend.c:2101 #15 in blk_unref at ../block/block-backend.c:544 #16 in bdrv_open_inherit at ../block.c:4197 #17 in bdrv_open at ../block.c:4286 #18 in blk_new_open at ../block/block-backend.c:458 #19 in blockdev_init at ../blockdev.c:612 #20 in drive_new at ../blockdev.c:1008 #21 in drive_init_func at ../system/vl.c:662 #22 in qemu_opts_foreach at ../util/qemu-option.c:1148 #23 in configure_blockdev at ../system/vl.c:721 #24 in qemu_create_early_backends at ../system/vl.c:2076 #25 in qemu_init at ../system/vl.c:3778 #26 in main at ../system/main.c:71 (2) =3D=3D crashes =3D=3D #5 in __assert_fail (assertion=3D"!(bs->open_flags & BDRV_O_INACTIVE)", f= ile=3D"../block/io.c", line=3D1977 #6 in bdrv_co_write_req_prepare at ../block/io.c:1977 #7 in bdrv_aligned_pwritev at ../block/io.c:2099 #8 in bdrv_co_pwritev_part at ../block/io.c:2316 #9 in bdrv_co_pwritev at ../block/io.c:2233 #10 in bdrv_co_pwrite at ../include/block/block_int-io.h:77 #11 in qed_write_header at ../block/qed.c:128 #12 in qed_need_check_timer at ../block/qed.c:305 #13 in qed_need_check_timer_entry at ../block/qed.c:319 Note that this issue is not exactly the same as what's been reported in Gitlab, but given how easily this reproduces, I imagine it has to be happening in that setup as well. Link: https://gitlab.com/qemu-project/qemu/-/work_items/3515 Signed-off-by: Fabiano Rosas Message-ID: <20260603193813.2327596-1-farosas@suse.de> Reviewed-by: Stefan Hajnoczi Reviewed-by: Kevin Wolf Signed-off-by: Kevin Wolf (cherry picked from commit 7e573b660fefdebd21cb755d0d34bb5942fd3af3) Signed-off-by: Michael Tokarev diff --git a/block/qed.c b/block/qed.c index da23a83d62..0eccfa21c9 100644 --- a/block/qed.c +++ b/block/qed.c @@ -351,16 +351,22 @@ static void bdrv_qed_detach_aio_context(BlockDriverSt= ate *bs) { BDRVQEDState *s =3D bs->opaque; =20 - qed_cancel_need_check_timer(s); - timer_free(s->need_check_timer); - s->need_check_timer =3D NULL; + if (s->need_check_timer) { + qed_cancel_need_check_timer(s); + timer_free(s->need_check_timer); + s->need_check_timer =3D NULL; + } } =20 -static void bdrv_qed_attach_aio_context(BlockDriverState *bs, - AioContext *new_context) +static void GRAPH_RDLOCK bdrv_qed_attach_aio_context(BlockDriverState *bs, + AioContext *new_conte= xt) { BDRVQEDState *s =3D bs->opaque; =20 + if (bdrv_is_inactive(bs)) { + return; + } + s->need_check_timer =3D aio_timer_new(new_context, QEMU_CLOCK_VIRTUAL, SCALE_NS, qed_need_check_timer_cb, s); --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308705; cv=none; d=zohomail.com; s=zohoarc; b=OVTSEpZe/D+EWfra/RI76BVuRZ4VfCIUfj5oNlwTS08ThJdNbpa0pwMCxr4zQ/kgif9n4MGkXZoX0M9SEzBo3prKf2tj9TJtm1iAwwsg/Rsq2QP43fd9nssDErpUJ4hfsBn08n3zICkdq5H3i5H3ye6LmtPF8J9gmEWF9/2wrjI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308705; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=W6JdPy4K4kJsSCs072IAMTesptt2rb0cvbse46zoUr4=; b=KG/O/sjC8/F7nfK+uPShxXZHiyDmPYl2u7exBME2sc8Su8zziL0kmQprnHXVhxrF39eCGL6uooE9E1yfW9760IkvGenFK9f60oP0GYuaSx7LSQa2MaYO2Bga4Fe84fIdp1HK23v6Eyi8t4y7dqh8pehbMISlV1M0tnGmjAtX3RA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308705924612.7240165288742; Wed, 24 Jun 2026 06:45:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNpi-0006Py-9O; Wed, 24 Jun 2026 09:40:02 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpg-0006N4-L3; Wed, 24 Jun 2026 09:40:00 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpe-0001JV-V1; Wed, 24 Jun 2026 09:40:00 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 09E771BA9F7; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 90AD63DEA46; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=jbkwDL2RSoWTXG3cX/JQP8fdtVWxdulh+xyfSz/UVgk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=qcbtaRYU8n0ZfTnTwaZRb+7jDeYq5vDHY9biULK8zbNlQqmCMFIhzWvQT13cwU1oG Qx1EYf4eHjqOoPdlgKQFUrdkfPw77Nzobq3LcijDQeTPt3uyDj8DG+Vtx7V1uu/aXn ETz/x9/1MmhyvfnJ5OQb34CelHpNXUx9R3+7LP+jaE5JiPwmTY26i+BzJHuhv+xd+Z SOwqCl1y5ktDeT6IYQzWLRICB0ft0bQDpo18ChbWyJpdYb2jxX3F6PrWYQVkmk5wx6 tdf/X2clwJ3k6NLUqlBt1IJ3ejjDfTBL2HawpW5wLLoAXqEog/k0JbPC+mj5tnHEjz DjLZmFYP/UYPA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Munkhbaatar Enkhbaatar , Peter Maydell , Michael Tokarev Subject: [Stable-11.0.2 069/107] hw/usb/hcd-ohci: Clean up USBPacket before freeing ISO TD packet Date: Wed, 24 Jun 2026 16:31:14 +0300 Message-ID: <20260624133301.403266-69-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308708316158500 Content-Type: text/plain; charset="utf-8" From: Munkhbaatar Enkhbaatar ohci_service_iso_td() allocates a USBPacket and frees it after synchronous completion, but it does not call usb_packet_cleanup() first. Call usb_packet_cleanup() before g_free() so resources owned by USBPacket are released. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3463 Signed-off-by: Munkhbaatar Enkhbaatar Reviewed-by: Peter Maydell Signed-off-by: Peter Maydell (cherry picked from commit 163f9a4e0651b3b4a1438d919489a200d3646ba3) Signed-off-by: Michael Tokarev diff --git a/hw/usb/hcd-ohci.c b/hw/usb/hcd-ohci.c index 6ed8046fc2..37a11f0c94 100644 --- a/hw/usb/hcd-ohci.c +++ b/hw/usb/hcd-ohci.c @@ -756,6 +756,7 @@ static int ohci_service_iso_td(OHCIState *ohci, struct = ohci_ed *ed) } else { ret =3D pkt->status; } + usb_packet_cleanup(pkt); g_free(pkt); =20 trace_usb_ohci_iso_td_so(start_offset, end_offset, start_addr, end_add= r, --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308634; cv=none; d=zohomail.com; s=zohoarc; b=eBHgLiuvC1Hp4ctPCZcIjkX0r1BeUA/BlZUsZ5t3Wbv7llZ5qrH7WSCkPu+dq+TtUNMRXX80SaeenKfsIm44cSChMXhrhuySngppR9iuKgulNP1C0Y9RABNeNbX1qn1G+sQSVc+fChBauxIXGzLPVa5eM7J94f7T9T7yPcZVLxo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308634; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Tgn1MeSZ1Iaof+ci+OgIQdbVXJ7ncNHsbikfefpWW4g=; b=LvTlqBHF2LRigBF+akTt5B82ljkt0pPOqdkIJUmHcX/afHZ75mzSJs+mDKmLzTS5WGirui5Htkj6BuJKNEkWEizLp4lm4rFwiL7N+cptVKFAuu/dswlXqLwbAL+5BezHGtanx+dwvM3dBk/Ez3TnmVnz2rCGIWGjAjDzHTLtAUw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308634254378.30444801237593; Wed, 24 Jun 2026 06:43:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNpk-0006RN-H2; Wed, 24 Jun 2026 09:40:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpj-0006QW-DN; Wed, 24 Jun 2026 09:40:03 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNph-0001Jm-Np; Wed, 24 Jun 2026 09:40:03 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 25C461BA9F8; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id AAB043DEA47; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=OJlFeqPSPJI/9JHSpoI1kmMeeq87tuzghZZQuthmz0c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Wa7/2HXNa7OBRdAhJjA5pUo2iOGbu+/2zJXGwffhzf9eOmgezDmZ1AgKTNt/UqXz5 eJ3wm0pb5XeAQhnKqMDeV9Qx4KA0L5SPAKDWuxy5rq1LTaFFX15SA8tp6tcdO9hj+x fk8ncHoe0rfw9+XnO7kLwJ8ayMf9DoNZTcDwUVIu1/1rhbwSvxU/gcFPpiZY8S871U iU7z/2Ma8/XM9LPF2V0krqF2LUN0XDaDkhfdNolkpkw7ocWsju2lin65tSrTyceFoe R2nWajxg2HIOw5BGoseBm25YKT4xfoFErzmWbwfJzE1lBAND0L24IVeM61RAgR1TaM jsoTfsstQCMEg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Richard Henderson , Peter Maydell , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-11.0.2 070/107] fpu: Handle all rounding modes in partsN_uncanon_normal Date: Wed, 24 Jun 2026 16:31:15 +0300 Message-ID: <20260624133301.403266-70-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308635540158501 From: Richard Henderson Missed float_round_nearest_even_max when recomputing round. CC: qemu-stable@nongnu.org Fixes: 72330260cdb ("softfloat: Add float_round_nearest_even_max") Reported-by: Peter Maydell Signed-off-by: Richard Henderson Reviewed-by: Peter Maydell Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-id: 20260608190155.637067-2-richard.henderson@linaro.org Signed-off-by: Peter Maydell (cherry picked from commit a6a1f92d5a2368882e9b6851b6ab8b9a56d71a8c) Signed-off-by: Michael Tokarev diff --git a/fpu/softfloat-parts.c.inc b/fpu/softfloat-parts.c.inc index 3c323c0cec..edfcbeb80b 100644 --- a/fpu/softfloat-parts.c.inc +++ b/fpu/softfloat-parts.c.inc @@ -431,6 +431,7 @@ static void partsN(uncanon_normal)(FloatPartsN *p, floa= t_status *s, /* Need to recompute round-to-even/round-to-odd. */ switch (s->float_rounding_mode) { case float_round_nearest_even: + case float_round_nearest_even_max: if (N > 64 && frac_lsb =3D=3D 0) { inc =3D ((p->frac_hi & 1) || (p->frac_lo & round_mask) !=3D frac_lsbm1 --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308628; cv=none; d=zohomail.com; s=zohoarc; b=J/xVnzuY6uRzB+7cAeZJBzHFopFGlqfiWq9JYq8jfNMesPp16PjraLVeuIuAGt5iUjeA9V+GnDSrn+2kWnEc874nKOZM+7es/lzQc1CthZ4Gd5gsc6ep+6WycNj+jD3fq0VRaXED8vprMHI5ojZXzPnNKWi6MvACpXu7dPb0yCc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308628; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=H+lOVpHRBOLns2YdeRPT4ntj/ReDbGR+7tvR/1bGXFY=; b=ZIkAGKpG1tpf6JSW3Va6XNxtE2raYVaPB8ynhSF7O1aof/UDmjc+Kao9LRR5tfpBMftI339cBcnAWe/IqBiLgVCieJiM8j0Fv4BbW6mGbPlCYKivM87MteMIJimwVUsst73yWlAQ4ldW4eqXh1l0o2+SLNTCohuVu+/Ke5e3tYk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308628326559.191746019429; Wed, 24 Jun 2026 06:43:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNpl-0006Tb-Ar; Wed, 24 Jun 2026 09:40:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpk-0006Qv-0P; Wed, 24 Jun 2026 09:40:04 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpi-0001MN-3p; Wed, 24 Jun 2026 09:40:03 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 357CA1BA9F9; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C61453DEA48; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=u48ie73Wjnwd+AefzvtIOSouHz6g5JAEaBHx18K6fCM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VZR9KWXec2ghiH3qfNQz3BrLintJoHrN0qBf/L4fdwQmrJb1v9h+1mO/Yqah/9LwA /avdVPrMieMYie2uZjwKhPWqmtcc1snP55rmmZumHCi28PzfioyiE7EQM7rZrDSErN Py6WQp8dUASN9tf9QsuO4fyJ2Gs4eHcSAWLAB307mac54kZ2BZ1cBXhiKd9gWlTC5F KFYxZQ4gOmZFr2LQobpUe9RksVw5mo6MpA8AKiY8KAwY2FLHSuuGyTBa8hygFc064O 25+B/N+Ho4zcCrnKPbHuW9x6W5AGgaRhJVDcYISgVeZaoUqARiPkgg1TFvFQZ/HUAx 3dfaOJKi6ZPTQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Xinhui Yang , Pierrick Bouvier , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 071/107] linux-user: implement fsmount(2) series of syscalls Date: Wed, 24 Jun 2026 16:31:16 +0300 Message-ID: <20260624133301.403266-71-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308629553158500 Content-Type: text/plain; charset="utf-8" From: Xinhui Yang This series of syscalls replaces the old mount(2) syscall with a series of syscalls that operates around a filesystem context. This series of syscalls is available since Linux 5.2 and glibc 2.36+. Their users include systemd since v259 and libmount from util-linux, and possibly other widely used projects. Preliminary checks are implemented to ensure the validity of the interface. v2: Add syscall wrappers in case the build machine does not support the fsmount() syscalls. (added by Helge Deller) Signed-off-by: Xinhui Yang Reviewed-by: Pierrick Bouvier Signed-off-by: Helge Deller (cherry picked from commit 767c32fe69834344bf71f4071ff33292cd46f626) Signed-off-by: Michael Tokarev diff --git a/linux-user/syscall.c b/linux-user/syscall.c index 65bbeb8551..993718973a 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -9653,6 +9653,19 @@ _syscall5(int, sys_move_mount, int, __from_dfd, cons= t char *, __from_pathname, int, __to_dfd, const char *, __to_pathname, unsigned int, flag) #endif =20 +#if defined(TARGET_NR_fsopen) && defined(NR_fsopen) +#define __NR_sys_fsopen __NR_fsopen +_syscall2(int, sys_fsopen, const char *, fs_name, unsigned int, flags); +#define __NR_sys_fsconfig __NR_fsconfig +_syscall5(int, sys_fsconfig, int, fs_fd, unsigned int, cmd, const char *, = key, + const void *, value, int, aux) +#define __NR_sys_fsmount __NR_fsmount +_syscall3(int, sys_fsmount, int, fs_fd, unsigned int, flags, + unsigned int, ms_flags) +#define __NR_sys_fspick __NR_fspick +_syscall3(int, sys_fspick, int, dfd, const char *, path, unsigned int, fla= gs) +#endif + /* This is an internal helper for do_syscall so that it is easier * to have a single return point, so that actions, such as logging * of syscall results, can be performed. @@ -14348,6 +14361,97 @@ static abi_long do_syscall1(CPUArchState *cpu_env,= int num, abi_long arg1, return do_map_shadow_stack(cpu_env, arg1, arg2, arg3); #endif =20 +#if defined(TARGET_NR_fsopen) && defined(NR_fsopen) + case TARGET_NR_fsopen: + { + p =3D lock_user_string(arg1); + if (!p) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsopen(p, arg2)); + unlock_user(p, arg1, 0); + } + return ret; + case TARGET_NR_fsconfig: + { + /* + * fsconfig(int, int, char *, void *, int) + * NOTE: p4 is nullable and its type might not be a string. + */ + void *p3, *p4; + int cmd =3D (int) arg2; + switch (cmd) { + case FSCONFIG_SET_BINARY: + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + p3 =3D lock_user_string(arg3); + if (!p3) { + return -TARGET_EFAULT; + } + if (cmd !=3D FSCONFIG_SET_BINARY) { + /* key and value must be strings. */ + p4 =3D lock_user_string(arg4); + } else { + /* + * Otherwise the value must be a raw buffer with its + * length specified in arg5 (aux). + */ + p4 =3D lock_user(VERIFY_READ, arg4, arg5, 1); + } + if (!p4) { + unlock_user(p3, arg3, 0); + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, p3, p4, arg5)); + unlock_user(p3, arg3, 0); + unlock_user(p4, arg4, 0); + break; + + case FSCONFIG_SET_FLAG: + case FSCONFIG_SET_FD: + /* arg4 (value) must be NULL. */ + if (arg4) { + return -TARGET_EFAULT; + } + p3 =3D lock_user_string(arg3); + if (!p3) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, p3, NULL, arg5)= ); + unlock_user(p3, arg3, 0); + break; + case FSCONFIG_CMD_CREATE: + case FSCONFIG_CMD_RECONFIGURE: +#ifdef FSCONFIG_CMD_CREATE_EXCL + /* + * FSCONFIG_CMD_CREATE_EXCL is only available since Linux + * 6.6. Guarding it to allow building with pre-6.6 headers. + */ + case FSCONFIG_CMD_CREATE_EXCL: +#endif + /* key and value must be NULL, aux must be 0. */ + if (arg3 || arg4 || arg5) { + return -TARGET_EFAULT; + } + ret =3D get_errno(sys_fsconfig(arg1, arg2, NULL, NULL, 0)); + break; + default: + return -TARGET_EFAULT; + } + } + return ret; + case TARGET_NR_fsmount: + ret =3D get_errno(sys_fsmount(arg1, arg2, arg3)); + return ret; + case TARGET_NR_fspick: + { + p =3D lock_user_string(arg2); + ret =3D get_errno(sys_fspick(arg1, p, arg3)); + unlock_user(p, arg2, 0); + } + return ret; +#endif default: qemu_log_mask(LOG_UNIMP, "Unsupported syscall: %d\n", num); return -TARGET_ENOSYS; --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308669; cv=none; d=zohomail.com; s=zohoarc; b=TeMzmgDaLm4ExRm/pmLP9S0HeSxEri6tD4Hoot/EGrUKzp2/IFh+MZ2ZG8EIuNMIagk7yYLHkmZCbkBuqlRGjrBfE/nqRrl+ZZRHTaGXD2+8+RtGlU+dLLLrxS9RFOoqoK+fQz0O19iYQ3Nfj2NRVfhcF4VYfoSY+viznLq07kE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308669; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=odhWAaLRFrm0d7iYphGajF4buVcnBaO8MCsEHE0Lpf4=; b=Jvyqn/t1UgYIlxVIcBMS8966eRObJkNDkiBtxa6zt7Og/6cnjde3HKq8mowsSCbPNHqPGIS9ZOHSxbmQFgOod5dZWOdmlDh+Tz7kzIc1M6aC0A0m08ZoVdmcsyQp687lgKSYb6c7/pG/iCJDsfZVGZ0/nAGrmbm3kde+tEQnyNk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308669362736.4018149591861; Wed, 24 Jun 2026 06:44:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNpr-0006Zr-Tf; Wed, 24 Jun 2026 09:40:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpq-0006Yb-Du; Wed, 24 Jun 2026 09:40:10 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNpk-0001Nm-T0; Wed, 24 Jun 2026 09:40:10 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 444821BA9FA; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D52123DEA49; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=m5IAU8IqElonT7fQAjsY3AIw/X/Ijl9y7o08uPY1MMQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=DnP8R4BOiS66L0FC0MRycRrToA3G5BO6KYgsbPYUWlMPpEuDSgEP4dYz/9fvFT5o6 giZLNW1m/KWXIzZgkBWNiBV5kjTlYWevuEPCh/JNzs2bfPCzB/bOo21oEr50RPhUpx SWl7s4dEKvuYfzbOjtMCG1EwIiQyh8wpumUp5gBhMq4uB42z/OJrZ8WqVxsGkqzv4n 2ss5CTRBaObJzeyev+XSnLC2Sfj8IMJf3zpSQ9VwBAd9lqPHM+YuTtBl47RaIumpIs YeKIL+mbU0pKXNVY4oO+FevTEO50BidXgGhFwYSyE4yGRd7Dckv0W4QpE7VkPmG2Rl fQqfgt0qCSz9A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Xinhui Yang , Pierrick Bouvier , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 072/107] linux-user/strace: add fsmount series of syscalls Date: Wed, 24 Jun 2026 16:31:17 +0300 Message-ID: <20260624133301.403266-72-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308669815158500 Content-Type: text/plain; charset="utf-8" From: Xinhui Yang Following the addition of fsmount(2) series of syscalls in the syscall handler, strace support is added, with a dedicated function to print the parameters of fsconfig(2), which contains parameters that can be interpreted as multiple types. Snippet of the strace dump when running `mount -t tmpfs tmpfs /media`: 18 fsopen(tmpfs,1) =3D 3 18 read(3,0x407fcf1c,8191) =3D -1 errno=3D61 (No data available) 18 fsconfig(3,FSCONFIG_SET_STRING,"source","tmpfs",0) =3D 0 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 fsconfig(3,FSCONFIG_CMD_CREATE,NULL,NULL,0) =3D 0 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 fsmount(3,1,0) =3D 4 18 read(3,0x407fce3c,8191) =3D -1 errno=3D61 (No data available) 18 statx(4,"",AT_EMPTY_PATH|AT_STATX_SYNC_AS_STAT,0x1000,0x407fee98) =3D 0 18 move_mount(4,,-100,/media,4) =3D 0 18 read(3,0x407fcfcc,8191) =3D -1 errno=3D61 (No data available) 18 close(3) =3D 0 18 close(4) =3D 0 v2: Fixed build on RHEL9 due to missing syscalls (Helge) Signed-off-by: Xinhui Yang Reviewed-by: Pierrick Bouvier Signed-off-by: Helge Deller (cherry picked from commit 6e0aa9f6c731df3f8d1071cfd5ec63fe7b923713) Signed-off-by: Michael Tokarev diff --git a/linux-user/strace.c b/linux-user/strace.c index 2cbaf94c89..3a81cc95f4 100644 --- a/linux-user/strace.c +++ b/linux-user/strace.c @@ -4344,6 +4344,111 @@ print_statx(CPUArchState *cpu_env, const struct sys= callname *name, } #endif =20 +#if defined(TARGET_NR_fsconfig) && defined(NR_fsconfig) +static void +print_fsconfig_cmd_name(int cmd) +{ + switch (cmd) { + case FSCONFIG_SET_FLAG: + qemu_log("%s%s", "FSCONFIG_SET_FLAG", get_comma(0)); + break; + case FSCONFIG_SET_STRING: + qemu_log("%s%s", "FSCONFIG_SET_STRING", get_comma(0)); + break; + case FSCONFIG_SET_BINARY: + qemu_log("%s%s", "FSCONFIG_SET_BINARY", get_comma(0)); + break; + case FSCONFIG_SET_PATH: + qemu_log("%s%s", "FSCONFIG_SET_PATH", get_comma(0)); + break; + case FSCONFIG_SET_PATH_EMPTY: + qemu_log("%s%s", "FSCONFIG_SET_PATH_EMPTY", get_comma(0)); + break; + case FSCONFIG_SET_FD: + qemu_log("%s%s", "FSCONFIG_SET_FD", get_comma(0)); + break; + case FSCONFIG_CMD_CREATE: + qemu_log("%s%s", "FSCONFIG_CMD_CREATE", get_comma(0)); + break; + case FSCONFIG_CMD_RECONFIGURE: + qemu_log("%s%s", "FSCONFIG_CMD_RECONFIGURE", get_comma(0)); + break; +#ifdef FSCONFIG_CMD_CREATE_EXCL + case FSCONFIG_CMD_CREATE_EXCL: + /* Only available since Linux 6.6. */ + qemu_log("%s%s", "FSCONFIG_CMD_CREATE_EXCL", get_comma(0)); + break; +#endif + default: + qemu_log("%s (%d)%s", "UNKNOWN_CMD", cmd, get_comma(0)); + break; + } +} + +static void +print_fsconfig(CPUArchState *cpu_env, const struct syscallname *name, + abi_long arg0, abi_long arg1, abi_long arg2, + abi_long arg3, abi_long arg4, abi_long arg5) +{ + /* + * fsconfig(int fd, int cmd, char* key, void* value, int aux) + * Where: + * fd: file descriptor returned by fsopen(). + * cmd: integer constant specifying a command. + * key: a string, can be NULL on certain commands. + * value: any data in a buffer, can be NULL, raw buffer or a string. + * aux: axillary values such as flags for FSCONFIG_SET_PATH. + */ + int cmd =3D (int) arg1; + print_syscall_prologue(name); + print_raw_param("%d", arg0, 0); + print_fsconfig_cmd_name(cmd); + /* Process arg2 (key). */ + switch (cmd) { + case FSCONFIG_SET_FLAG: + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_BINARY: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + case FSCONFIG_SET_FD: + print_string(arg2, 0); + break; + default: + print_pointer(arg2, 0); + break; + } + /* Process arg3 (value). */ + switch (cmd) { + case FSCONFIG_SET_STRING: + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + print_string(arg3, 0); + break; + default: + print_pointer(arg3, 0); + break; + } + /* + * Process arg4 (aux). + * On FSCONFIG_SET_PATH and FSCONFIG_SET_PATH_EMPTY, aux can + * be either 0 or AT_FDCWD. + * On FSCONFIG_SET_BINARY, aux is an integer to state the length + * of the buffer pointed by arg3. + * Otherwise, it must be 0. + */ + switch (cmd) { + case FSCONFIG_SET_PATH: + case FSCONFIG_SET_PATH_EMPTY: + print_at_dirfd(arg4, 1); + break; + default: + print_raw_param("%d", arg4, 1); + break; + } + print_syscall_epilogue(name); +} +#endif + #ifdef TARGET_NR_ioctl static void print_ioctl(CPUArchState *cpu_env, const struct syscallname *name, diff --git a/linux-user/strace.list b/linux-user/strace.list index 6162a407f9..e363892e0a 100644 --- a/linux-user/strace.list +++ b/linux-user/strace.list @@ -1722,3 +1722,18 @@ #ifdef TARGET_NR_rseq { TARGET_NR_rseq, "rseq" , "%s(%p,%u,%d,%#x)", NULL, NULL }, #endif +#ifdef TARGET_NR_fsopen +{ TARGET_NR_fsopen, "fsopen", "%s(%s,%d)", NULL, NULL }, +#endif +#if defined(TARGET_NR_fsconfig) && defined(NR_fsconfig) +{ TARGET_NR_fsconfig, "fsconfig", NULL, print_fsconfig, NULL }, +#endif +#ifdef TARGET_NR_fsmount +{ TARGET_NR_fsmount, "fsmount", "%s(%d,%d,%d)", NULL, NULL }, +#endif +#ifdef TARGET_NR_move_mount +{ TARGET_NR_move_mount, "move_mount", "%s(%d,%s,%d,%s,%d)", NULL, NULL }, +#endif +#ifdef TARGET_NR_fspick +{ TARGET_NR_fspick, "fspick", "%s(%d,%s,%d)", NULL, NULL }, +#endif --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782309046; cv=none; d=zohomail.com; s=zohoarc; b=EPZrSNobhSegbhO4E5cRxVoobMWApup2bI22CdFZZyupbNBEq/MTbCI2OHRqnYRkZbfEYc9IVE/LMLubdXqAhOZCr/5vD9SZC8+DpG/6WLBCnaFOnwJ1HXgqMu+6Qg3xlBVslCpGD27KG1WOPbftNwdMsW7QJCYN2EY0ztpNXiQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782309046; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=s2VwVMO2zwYHcNnyeR1Tmm6Y9mo3o9/DPS67PfE9rVk=; b=itxCrVp904jVS8c53gLhJBwBpTzXIS3nVdPMkCZFQ1Izq15VAgTwCxj2aPaFtfZVDBZlQsKakPI74sN+Z9gA/ggbosb5D1YA3Hpm+nOM7skA7srVidp1h2KNoA1i9U+epE6da0vHHnSWJkf2EiTQEfocwzo0wlX4XLHKZVmpQy8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782309046189264.1908736560807; Wed, 24 Jun 2026 06:50:46 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNq8-00070M-TN; Wed, 24 Jun 2026 09:40:29 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNq7-0006zk-0L; Wed, 24 Jun 2026 09:40:27 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNq5-0001Sj-HG; Wed, 24 Jun 2026 09:40:26 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 53F3F1BA9FB; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E40813DEA4A; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=vAyKN8+M9jEln4kJ8vKcewQrLe0bjr8DlYPubHyvRMc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=YHfXlDQDb/VhuM4xaAt0TWOUymWOXgcu8jonIg+rUGbLSICJVmzLS6nUGiZSGRrSV xelU0R6m4q8Y7cTosK6H8XnbVxLg35tRNCuJH9ei049+u24FI0L3D4AsMP2uStdf1y QBX/5AzaiFFMPlraEqPpgNkqrHQUo/eYla0209ZK+/XNJuWqe6nZu4I4gO5jE4ttcA dRFT1KJs8/XCZbp8xkp3LPWbsJ4VzWf+KPpfFX8R+zkeAx4oArIkpvSA2HXLm+g0ol Q3Nm2Mac22KuoGcAyIW6XIWqJhaoQ1iQYzqae+rSrqMWaJIJ68C7mCqC1m6j6PlYL1 HEuT44Z7Y3HXA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Thomas Huth , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Laurent Vivier , Michael Tokarev Subject: [Stable-11.0.2 073/107] system/rtc: Fix a possible year-2038 integer overflow problem Date: Wed, 24 Jun 2026 16:31:18 +0300 Message-ID: <20260624133301.403266-73-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782309046821158500 From: Thomas Huth rtc_realtime_clock_offset is initialized with: rtc_realtime_clock_offset =3D qemu_clock_get_ms(QEMU_CLOCK_REALTIME) / 10= 00; And QEMU_CLOCK_REALTIME might be based on gettimeofday() in certain cases (see get_clock_realtime() in include/qemu/timer.h). So this counter will exceed 32 bits in the year 2038, thus we should not store this value in a normal integer variable. Change it to a time_t to fix the problem. And while we're at it, also adjust the nearby rtc_host_datetime_offset variable to be on the safe side in the related code. Signed-off-by: Thomas Huth Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Laurent Vivier Reviewed-by: Michael Tokarev Signed-off-by: Michael Tokarev (cherry picked from commit ae84c738e40339cc0f22773dd4692de529d88739) Signed-off-by: Michael Tokarev diff --git a/system/rtc.c b/system/rtc.c index 56951288c4..f7eca982b0 100644 --- a/system/rtc.c +++ b/system/rtc.c @@ -40,8 +40,8 @@ static enum { RTC_BASE_DATETIME, } rtc_base_type =3D RTC_BASE_UTC; static time_t rtc_ref_start_datetime; -static int rtc_realtime_clock_offset; /* used only with QEMU_CLOCK_REALTIM= E */ -static int rtc_host_datetime_offset =3D -1; /* valid & used only with +static time_t rtc_realtime_clock_offset; /* used only with QEMU_CLOCK_REAL= TIME */ +static time_t rtc_host_datetime_offset =3D -1; /* valid & used only with RTC_BASE_DATETIME */ QEMUClockType rtc_clock; /***********************************************************/ --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308935; cv=none; d=zohomail.com; s=zohoarc; b=IWjN7VlBkQidAjDl+ZUJKWCSXMTg6b2ZCSaCRmCL+6YUoS+z8sQaevzv14See9WlQE6a2NwgrZ2A8E94aDfuH/VFmzD9tuGxM5dPjFoWULqFj7cd5HahOOzJoCpgj4IDmSYTcTNKmtqSUEuAQCqyzvxOfsO0acMBtmrw5QMhPTs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308935; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=0Jx7V2qWO2MiW0Nz3gEyIvJg0kS33WvMZgR931dZYJc=; b=jX+hH0cgRepliM/Bvy5A0oAfGhWOukwEUbAdRszspXDh+TtZyf0AJKDXhWpXArF3x9/4ZGGdAydhfb9nSzIDLUwXV8zqI87QQdPhcTmiaAbWxS/QGPe+qSjKSPNxAmANZtOvt111U6NsTIKlhFMHJv5ULVFkvzR4wxCD9mI879M= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308935000552.8520072150216; Wed, 24 Jun 2026 06:48:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNqH-0007Kr-Bb; Wed, 24 Jun 2026 09:40:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqD-00079x-VV; Wed, 24 Jun 2026 09:40:34 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqB-0001Zs-SO; Wed, 24 Jun 2026 09:40:33 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 61D691BA9FC; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id F3C433DEA4B; Wed, 24 Jun 2026 16:33:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=IC8fy+lrNSCIA7DyirnI+qUtNnrwGtlcAjyFid+uikg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=qfur8RRKIpq/fffBhAg4xQCm4ubdqKxD1zQq3cXoZfNNvTqVVO6DTgeup9MkWDSeY J5GNODdoQ9q78dHi050icOr9g823Pp3tz4GZDdUQ2Kw9mFLYakYz2BvgnmkLCG28wW FWt0PD/yR1UfWfvK4tILeyc0RFmBIJJ/ATRo5n/4x0xsNUtFC9V5RRAakXtldRnn// usl2Y4EGpcHE2Tfn7UPJs78HB5tPm76L4ejxIj9dabOFWkeqq6oWeIHVBf/XiQlQrU Wf3jbtF6HtJi8aYRSMU8kUnpNSG5BPlJFYlNTaAyntIwn6RISDgGyOBw4U2/G/xoIk VuO1CaFZ56Ikw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Dominique Martinet , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 074/107] linux-user: add preadv2/preadv2 Date: Wed, 24 Jun 2026 16:31:19 +0300 Message-ID: <20260624133301.403266-74-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308935929158500 Content-Type: text/plain; charset="utf-8" From: Dominique Martinet Some programs apparently use these, like the python test suite. The flags argument (rwf_t) is an int, with values shared on all arches and does not need translating. This was tested manually with the following python script: ``` import os fd =3D os.open('test', os.O_RDWR|os.O_CREAT) os.pwritev(fd, [b'test', b'ok'], 0, os.RWF_HIPRI) buf =3D [bytearray(3), bytearray(10)] os.preadv(fd, buf, 0, os.RWF_HIPRI) print(buf[0]) print(buf[1]) ``` Signed-off-by: Dominique Martinet Reviewed-by: Helge Deller Signed-off-by: Helge Deller (cherry picked from commit fb4c08147ba79c552897427a42e3b24b38712786) Signed-off-by: Michael Tokarev diff --git a/linux-user/syscall.c b/linux-user/syscall.c index 993718973a..11d3b41dff 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -741,6 +741,11 @@ safe_syscall5(ssize_t, preadv, int, fd, const struct i= ovec *, iov, int, iovcnt, unsigned long, pos_l, unsigned long, pos_h) safe_syscall5(ssize_t, pwritev, int, fd, const struct iovec *, iov, int, i= ovcnt, unsigned long, pos_l, unsigned long, pos_h) +safe_syscall6(ssize_t, preadv2, int, fd, const struct iovec *, iov, int, i= ovcnt, + unsigned long, pos_l, unsigned long, pos_h, __kernel_rwf_t, = flags) +safe_syscall6(ssize_t, pwritev2, int, fd, const struct iovec *, iov, + int, iovcnt, unsigned long, pos_l, unsigned long, pos_h, + __kernel_rwf_t, flags) safe_syscall3(int, connect, int, fd, const struct sockaddr *, addr, socklen_t, addrlen) safe_syscall6(ssize_t, sendto, int, fd, const void *, buf, size_t, len, @@ -11847,6 +11852,39 @@ static abi_long do_syscall1(CPUArchState *cpu_env,= int num, abi_long arg1, } } return ret; +#endif +#if defined(TARGET_NR_preadv2) + case TARGET_NR_preadv2: + { + struct iovec *vec =3D lock_iovec(VERIFY_WRITE, arg2, arg3, 0); + if (vec !=3D NULL) { + unsigned long low, high; + + target_to_host_low_high(arg4, arg5, &low, &high); + ret =3D get_errno(safe_preadv2(arg1, vec, arg3, low, high,= arg6)); + unlock_iovec(vec, arg2, arg3, 1); + } else { + ret =3D -host_to_target_errno(errno); + } + } + return ret; +#endif +#if defined(TARGET_NR_pwritev2) + case TARGET_NR_pwritev2: + { + struct iovec *vec =3D lock_iovec(VERIFY_READ, arg2, arg3, 1); + if (vec !=3D NULL) { + unsigned long low, high; + + target_to_host_low_high(arg4, arg5, &low, &high); + ret =3D get_errno(safe_pwritev2(arg1, vec, arg3, low, high, + arg6)); + unlock_iovec(vec, arg2, arg3, 0); + } else { + ret =3D -host_to_target_errno(errno); + } + } + return ret; #endif case TARGET_NR_getsid: return get_errno(getsid(arg1)); --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308916; cv=none; d=zohomail.com; s=zohoarc; b=XFSaI1QeqhcEFvR21ksnXSmLbRL1xTwCV860PWBRXAl2QN5gZ/I3yJYBlOb6WCCVD9TeVm2yIYib/0mWiB8LxRy9k5KFwr3FN6HMuuFREXs8xTyFnfYGq8DuDBHCDQGpTc6Xzh+iD8Io3yiEN+hM011uEd8a5PidAAdjCa87ong= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308916; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=UD2+DPWi5PG9kWVYhulYrZhJ9gGl+gHPCPF+kDgoprE=; b=SsUXucXY5wL8KhKT7QNnaBzc86lLDCxDd/XYHEPegsP8GLPrMdXhtTLbGz9jn5VbyW5LCKDG2wZWOpJ/QUJ3fj18vZh1sLx+JD7xnCizyW9ptrjQGtuUffbqBEguKMa/ecElialY6tsnXAhn/gtBKqtseRSxklBolQilVP43kyk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308916771648.059959390924; Wed, 24 Jun 2026 06:48:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNqC-00073w-Gz; Wed, 24 Jun 2026 09:40:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqA-00071a-GJ; Wed, 24 Jun 2026 09:40:30 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNq8-0001ah-Rb; Wed, 24 Jun 2026 09:40:30 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 7319C1BA9FD; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0DBB43DEA4C; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=VSJWBkniMIQWTAxp3abpJo8buGy5iaM6qoVOrvgvcZI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=GTLid7UiaWpz2N/Tol2zatbs0C1Dg4Z+etZ+PmdLw7y4ITgjSJMcQLcISQfA1ngmU cxnk8V+fZHYrpH8wguNHYGKEGZfk2vkXzVzXXO1h2zY7hqHJyh23rw1vMWww/bW1qm UPe5CDnEMVwCO9gGy+JrpScg/KluhrXEGYnNiEqOttsK+on9c/0zWLE6um0P2AtzxO OCI2fTphbbKxvp+NwjRcdL3ubd1Ohgcx0ADscMQe/RicVZjyW9Ta7rqx2z9t6zQFEB xQfBFTIlGoR7B0bGsf8hiDI+fZ42B5ey46UGY5WkiGrk5KznuxxODcXqvPAhWXyMFg KtpRjHTnetlZw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Yunhe Wang , Alejandro Jimenez , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-11.0.2 075/107] amd_iommu: restrict command buffer head/tail ranges to ring size Date: Wed, 24 Jun 2026 16:31:20 +0300 Message-ID: <20260624133301.403266-75-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308917858158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini The AMD IOMMU command buffer is a ring buffer of cmdbuf_len (a power of two) entries. Each entry is 16 bytes and the head pointer cycles through the set: [0, 16, 32, ..., (cmdbuf_len - 1) * AMDVI_COMMAND_SIZE] The tail pointer is written by the guest through the COMMAND_TAIL MMIO register (offset 0x2008); the while loop in amdvi_cmdbuf_run() only terminates when head =3D=3D tail. If tail is set to a value higher than cmdbuf_len * 16, head will cycle through all the elements of the ring buffer indefinitely, without ever matching tail. Fix this by further masking tail (and head, for consistency) against the size of the ring buffer. Reported-by: Yunhe Wang Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini Reviewed-by: Alejandro Jimenez Reviewed-by: Michael S. Tsirkin Message-Id: <20260511113923.2478812-1-pbonzini@redhat.com> Signed-off-by: Michael S. Tsirkin (cherry picked from commit 3097d54016ea9f8f0436f0b20e1b4d78a02b6aeb) Signed-off-by: Michael Tokarev diff --git a/hw/i386/amd_iommu.c b/hw/i386/amd_iommu.c index 789e09d6f2..197e452e3c 100644 --- a/hw/i386/amd_iommu.c +++ b/hw/i386/amd_iommu.c @@ -1578,7 +1578,8 @@ static inline void amdvi_handle_devtab_write(AMDVISta= te *s) static inline void amdvi_handle_cmdhead_write(AMDVIState *s) { s->cmdbuf_head =3D amdvi_readq(s, AMDVI_MMIO_COMMAND_HEAD) - & AMDVI_MMIO_CMDBUF_HEAD_MASK; + & AMDVI_MMIO_CMDBUF_HEAD_MASK + & (s->cmdbuf_len * AMDVI_COMMAND_SIZE - 1); amdvi_cmdbuf_run(s); } =20 @@ -1594,7 +1595,8 @@ static inline void amdvi_handle_cmdbase_write(AMDVISt= ate *s) static inline void amdvi_handle_cmdtail_write(AMDVIState *s) { s->cmdbuf_tail =3D amdvi_readq(s, AMDVI_MMIO_COMMAND_TAIL) - & AMDVI_MMIO_CMDBUF_TAIL_MASK; + & AMDVI_MMIO_CMDBUF_TAIL_MASK + & (s->cmdbuf_len * AMDVI_COMMAND_SIZE - 1); amdvi_cmdbuf_run(s); } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308969; cv=none; d=zohomail.com; s=zohoarc; b=E+nhF7ROcYccmrUkvy8y769m8LMoNosciZEGYsoaFU/cSDYgRohZ1yPZ0hpFgKut/pkCbBenFlRLLUwJcZlR+ZPa7XZmq6LLNn7krP6y0JYX/S1DbvDO8kBVBb2gqHj5il0tWpUo/W647VuKkSq0MONgupsGXQyfivQFRRm3xgQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308969; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=2THzimZNzl2h8sAD1Ikwy+aVH9vVcnll/G5azt7lKnc=; b=flu6nluLcZhQWLElczyH9i+SQtdxm71BTGhUnuzoN8jFtwXAUD3oyOFQwpdgdSsSJS15CUGXWJDOS0Trf8Xgch+TA3mhQArKTyGEjzVGmEntb2VnrGlD7oRXBtLmNzH6pzthTIaeUnR3nQyWbJOw+rl2fHRqoLZDSk+83unvmGo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308969670691.1393865265812; Wed, 24 Jun 2026 06:49:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNqF-0007EP-K7; Wed, 24 Jun 2026 09:40:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqD-00079s-Ul; Wed, 24 Jun 2026 09:40:33 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqC-0001bA-0e; Wed, 24 Jun 2026 09:40:33 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 831A71BA9FE; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1F4033DEA4D; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=J49kia/tO7O8THwkyjKfcO3OkGNeHdw8KGvAjrobIlA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=tC/AworgqtD2K/wEdm/j4ccWU3QEnsYG3Uf5eIdJ56Abk93Z2/DH1ReHv13ZrUcSw keuhmdzglKexRntbBz/o7fnfL/Qjg4gMHClDYhsltxXrJk8K+kJSLTpZuGb6Dgj5id zLeXIaN9LzBIvwQHA8q/j8Bxpnmb7uh5RN5e/2pBHeH47zsvAKvC6UHXMN7pUswE2u F9TOrmUqLBNKP7W+Hsj9hHl1s2REApwqCWNuIUblOb03Zqi09Um6rwJClNMxbIzN5L XplfodA/sn3pBenWnifFqyj3Ji8gcxMgtalH9M+6GLB7l9+uCYKz2u5OL6IgTYX35U xg4YeMM8WEThQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alejandro Jimenez , Sairaj Kodilkar , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-11.0.2 076/107] amd_iommu: Update command buffer head ptr in MMIO region after wraparound Date: Wed, 24 Jun 2026 16:31:21 +0300 Message-ID: <20260624133301.403266-76-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308970509158500 Content-Type: text/plain; charset="utf-8" From: Alejandro Jimenez When processing a command, amdvi_cmdbuf_run() increments cmdbuf_head and writes it to the emulated MMIO register space before checking whether it has reached the end of the command buffer. If the incremented value reaches the end of the buffer and the tail pointer is zero, the loop exits and the COMMAND_HEAD offset still contains an unwrapped value. There are no errors in command processing since internal cmdbuf_head state is always correctly updated, but the spec defines the CmdHeadPtr field in MMIO Offset 2000h Command Buffer Head Pointer Register as RW i.e. guest-visible, so it should be kept consistent. Wrap cmdbuf_head before updating COMMAND_HEAD so the MMIO-visible register always matches the internal command buffer head pointer position. Cc: qemu-stable@nongnu.org Signed-off-by: Alejandro Jimenez Reviewed-by: Sairaj Kodilkar Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-Id: <20260512150044.334867-1-alejandro.j.jimenez@oracle.com> (cherry picked from commit 3c98e446af825b5806c1e5cd1244b2431b15e884) Signed-off-by: Michael Tokarev diff --git a/hw/i386/amd_iommu.c b/hw/i386/amd_iommu.c index 197e452e3c..5d6a405263 100644 --- a/hw/i386/amd_iommu.c +++ b/hw/i386/amd_iommu.c @@ -1475,12 +1475,12 @@ static void amdvi_cmdbuf_run(AMDVIState *s) trace_amdvi_command_exec(s->cmdbuf_head, s->cmdbuf_tail, s->cmdbuf= ); amdvi_cmdbuf_exec(s); s->cmdbuf_head +=3D AMDVI_COMMAND_SIZE; - amdvi_writeq_raw(s, AMDVI_MMIO_COMMAND_HEAD, s->cmdbuf_head); =20 /* wrap head pointer */ if (s->cmdbuf_head >=3D s->cmdbuf_len * AMDVI_COMMAND_SIZE) { s->cmdbuf_head =3D 0; } + amdvi_writeq_raw(s, AMDVI_MMIO_COMMAND_HEAD, s->cmdbuf_head); } } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308613; cv=none; d=zohomail.com; s=zohoarc; b=ILChpKFpy0vTizjgyFrRPW6lNBYFSXAhF2Ztm5j74LzipK5vSRC6ZHtn456vD3LioxtInUXtb/vfez3h8bBwTNh0CZ9aUGY5gcaA6PKJ6N6liP5gBqx1TqPZ7FcesmD+BhOpb9zcyuCc4MSbTyTcPaLpkTlxjAnPEBb4QEzfcOs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308613; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LxjQ2yzG7OKcohWN1EKaWcVIthKfJy32yzOpz6CkDMc=; b=K+7MExV6pWQef5EqCyPmDlXeeB0QphzMaaCZ2gp21H5v+xIFow3Ic17ilcyZFR7pWiy1CAXSg8l1oIk8b3VTp5QJ4g0XYHEIgL4SGkTqvjjawNyV3M2JanT6gxOBvUV6LRMWdcvRJaSZtKSFxWETWhEOOIB7lWvLBzRo5tDbo48= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308613585586.9330175806948; Wed, 24 Jun 2026 06:43:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNqJ-0007Pk-3t; Wed, 24 Jun 2026 09:40:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqH-0007LP-Cl; Wed, 24 Jun 2026 09:40:37 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqF-0001bj-Cj; Wed, 24 Jun 2026 09:40:37 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 91A191BA9FF; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 2F42E3DEA4E; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=R0i2RijjIZBMA8Q3VCOFqy0Ro6U7kZgq0oUgKZr5Kmc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=uhiq52eRrHAMk7Q0g6ygT5hi16HjgHFECAqTg2wN0qM3Htj/NlT68caUWzxuE++su 54heLREub+WzHvHAk5P7h4jY2MZE3RrCuioYAzJrV/pOPO2nxnYimbWH4v5ZgkJ9vd DUeKP+v7bmraNcPppLXcI7vLT4ICnBphu9bw2Rj0beHtmPpR6gVrp/mJi9Y2JpLM/W 0t7RXkBHW0ExxvK5r2n6nMQtFoXa/S/4jy5otSsmq+0+qgVjVf6JUJFkKM0dQUIJni TFKvdDObvcvUWJ/ekD6sHUUxaPrfnLnbW/Pl70gWhRa/8tZ9PC8S+ASdTGVmCi++2D cN2y7wiaHCTKA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Costas Argyris , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-11.0.2 077/107] tests/qtest: Add amd-iommu command buffer head wrap test Date: Wed, 24 Jun 2026 16:31:22 +0300 Message-ID: <20260624133301.403266-77-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308617417158500 Content-Type: text/plain; charset="utf-8" From: Costas Argyris Add a qtest for AMD IOMMU command buffer head pointer wraparound. The test programs a command buffer, fills it with COMPLETION_WAIT commands, advances the tail to consume all but the final entry, then wraps the tail to zero to force the final command to advance CmdHeadPtr past the end of the buffer. The guest-visible CmdHeadPtr register must then wrap back to ze= ro. This covers the case fixed by an earlier CmdHeadPtr wraparound patch. The Linux kernel AMD IOMMU driver is not affected by this bug because it uses COMPLETION_WAIT with a memory store doorbell to detect command progres= s. Signed-off-by: Costas Argyris Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-Id: <20260530183458.7778-1-costas.argyris@amd.com> (cherry picked from commit 8a1c09cbd3fe776a467398700c610cd126ee8a59) Signed-off-by: Michael Tokarev diff --git a/MAINTAINERS b/MAINTAINERS index 8cc89d4feb..296a9c7697 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -4026,6 +4026,7 @@ M: Alejandro Jimenez R: Sairaj Kodilkar S: Supported F: hw/i386/amd_iommu* +F: tests/qtest/amd-iommu-test.c =20 OpenSBI Firmware L: qemu-riscv@nongnu.org diff --git a/tests/qtest/amd-iommu-test.c b/tests/qtest/amd-iommu-test.c new file mode 100644 index 0000000000..fb28511588 --- /dev/null +++ b/tests/qtest/amd-iommu-test.c @@ -0,0 +1,76 @@ +/* + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#include "qemu/osdep.h" +#include "libqtest.h" +#include "hw/i386/amd_iommu.h" + +#define CMDBUF_ADDR 0x200000 +#define CMDBUF_LEN_FIELD 8 +#define CMDBUF_ENTRIES (1U << CMDBUF_LEN_FIELD) + +static inline uint64_t amdvi_reg_readq(QTestState *s, uint64_t offset) +{ + return qtest_readq(s, AMDVI_BASE_ADDR + offset); +} + +static inline void amdvi_reg_writeq(QTestState *s, uint64_t offset, + uint64_t val) +{ + qtest_writeq(s, AMDVI_BASE_ADDR + offset, val); +} + +static void test_cmdbuf_head_wrap(void) +{ + QTestState *s; + uint64_t head; + int i; + /* 16 bytes per command */ + struct { + uint64_t qw0; + uint64_t qw1; + } cmdbuf[CMDBUF_ENTRIES]; + + if (!qtest_has_machine("q35")) { + g_test_skip("q35 machine not available"); + return; + } + + s =3D qtest_init("-M q35 -device amd-iommu"); + + /* fill the command buffer with COMPLETION_WAIT (no-op) commands */ + for (i =3D 0; i < CMDBUF_ENTRIES; i++) { + cmdbuf[i].qw0 =3D (uint64_t)AMDVI_CMD_COMPLETION_WAIT << 60; + cmdbuf[i].qw1 =3D 0; + } + qtest_memwrite(s, CMDBUF_ADDR, cmdbuf, sizeof(cmdbuf)); + + /* point the IOMMU at the command buffer and set its length */ + amdvi_reg_writeq(s, AMDVI_MMIO_COMMAND_BASE, + CMDBUF_ADDR | ((uint64_t)CMDBUF_LEN_FIELD << 56)); + + /* enable the IOMMU and its command buffer processor */ + amdvi_reg_writeq(s, AMDVI_MMIO_CONTROL, + AMDVI_MMIO_CONTROL_AMDVIEN | AMDVI_MMIO_CONTROL_CMDBU= FLEN); + + /* advance tail to the last entry, consuming all but the final entry */ + amdvi_reg_writeq(s, AMDVI_MMIO_COMMAND_TAIL, + (CMDBUF_ENTRIES - 1) * AMDVI_COMMAND_SIZE); + + /* wrap tail to 0, consuming the final entry and completing the buffer= */ + amdvi_reg_writeq(s, AMDVI_MMIO_COMMAND_TAIL, 0); + + /* after consuming all entries the IOMMU must wrap CmdHeadPtr to 0 */ + head =3D amdvi_reg_readq(s, AMDVI_MMIO_COMMAND_HEAD); + g_assert((head & AMDVI_MMIO_CMDBUF_HEAD_MASK) =3D=3D 0); + + qtest_quit(s); +} + +int main(int argc, char **argv) +{ + g_test_init(&argc, &argv, NULL); + qtest_add_func("/q35/amd-iommu/cmdbuf-head-wrap", test_cmdbuf_head_wra= p); + return g_test_run(); +} diff --git a/tests/qtest/meson.build b/tests/qtest/meson.build index be4fa627b5..12ad4c0ad6 100644 --- a/tests/qtest/meson.build +++ b/tests/qtest/meson.build @@ -95,6 +95,7 @@ qtests_i386 =3D \ (config_all_devices.has_key('CONFIG_SB16') ? ['fuzz-sb16-test'] : []) + = \ (config_all_devices.has_key('CONFIG_SDHCI_PCI') ? ['fuzz-sdcard-test'] := []) + \ (config_all_devices.has_key('CONFIG_ESP_PCI') ? ['am53c974-test'] : []) = + \ + (config_all_devices.has_key('CONFIG_AMD_IOMMU') ? ['amd-iommu-test'] : [= ]) + \ (config_all_devices.has_key('CONFIG_VTD') ? ['intel-iommu-test'] : []) += \ (host_os !=3D 'windows' and = \ config_all_devices.has_key('CONFIG_ACPI_ERST') ? ['erst-test'] : []) + = \ --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308605; cv=none; d=zohomail.com; s=zohoarc; b=cXBEGxl9JYGkhUHfOczpwvknFQohWGKOX8CZpZxs4LHFXDOyp0LX5KfAH3EJcZAJk5OzrvXucg3BpC5M72MyAGcKDeT82J9x7c2JKCdBPJh48MnEWDAF6DY5lxyVRKEmmebGCNiKfdsSLTP33sRItXyMY4AvaUuaVs1YP3xC9ho= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308605; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=jragrNGIBZCMNaXcrBgFweyiHcZbkiL2YhwYqGbMWBU=; b=mffFWwuiNIPTCWcr7U0GZTY7elBz9JJ/2fHLbRttcZsGSL9YErcB+GyszjdZOkPd0Gb8Pcq5sP389xAfHfCfB3MBSqDBpjlDiu8/cyXHYPCLjL/hkjDJ1ItP+R0WZfmiZgcGr3zhK5IXr0uUUB+v13RKMVR8BLCTFoVijSB1iZ4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178230860564292.92641020017084; Wed, 24 Jun 2026 06:43:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNqd-0007o1-Rh; Wed, 24 Jun 2026 09:40:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqb-0007mU-Rp; Wed, 24 Jun 2026 09:40:57 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqZ-0001bl-DK; Wed, 24 Jun 2026 09:40:57 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id A40051BAA00; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 3D84F3DEA4F; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=d7opk2Xa97uV2FkuLbY8eu2qrVn55daJy9OwhsI0JY8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ne4VN4oFw92u6TbQxnk1wM7CfRf3IPfOHN3MK8FuqBdUGs71xFbVE+/eIfWg6nS0D aVeHS9l6asHUDAcQEW69fcTNGfwRotx34gpyoSEQz9svCXn2n57mt2penb3cZLXyTJ zDAF6DwvUqXizzdFdu6gIxKAdmiEmxML/F9nPeGofook4LkuSjWa+ws5ZigSd4cpN5 kHLdgaTcfsJW4fo7eiXUKe+loh0ycQJ8y2ir2REazC7oKqkwP9CPXE1AkCU7PsGPNC AoL9quiplvVq2iPHnaqjq1TwkWdwNw6TmkM3CPwchDrxbmLxH/nVfR0Yjhd8OsX/a5 IFQzs4Gm4scXQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Stefano Garzarella , DARKNAVY , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-11.0.2 078/107] libvhost-user: fix buffer overflow in virtqueue_read_indirect_desc() Date: Wed, 24 Jun 2026 16:31:23 +0300 Message-ID: <20260624133301.403266-78-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308607714158500 From: Stefano Garzarella virtqueue_read_indirect_desc() copies an indirect descriptor table into a buffer in chunks when the table crosses a memory region boundary. The destination is a struct vring_desc pointer but is advanced by a byte count, so each increment moves the pointer by read_len elements instead of read_len bytes, writing beyond the buffer. Use a char pointer for the destination so that the arithmetic advances correctly. While at it, change the source from a struct vring_desc pointer to a void pointer: when the table is split across regions, vu_gpa_to_va() can return a pointer into the middle of a descriptor, so casting it to a struct vring_desc pointer is wrong. The pointer is only used as a memcpy() source, so a void pointer is fine. Fixes: CVE-2026-6425 Fixes: 293084a719 ("libvhost-user: Support across-memory-boundary access") Cc: qemu-stable@nongnu.org Reported-by: DARKNAVY Signed-off-by: Stefano Garzarella Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-Id: <20260417132645.121192-2-sgarzare@redhat.com> (cherry picked from commit 85805ee887be4adddb1f1a34f526968adc95e582) Signed-off-by: Michael Tokarev diff --git a/subprojects/libvhost-user/libvhost-user.c b/subprojects/libvho= st-user/libvhost-user.c index 9c630c2170..014d210748 100644 --- a/subprojects/libvhost-user/libvhost-user.c +++ b/subprojects/libvhost-user/libvhost-user.c @@ -2391,8 +2391,9 @@ static int virtqueue_read_indirect_desc(VuDev *dev, struct vring_desc *desc, uint64_t addr, size_t len) { - struct vring_desc *ori_desc; + char *dst_desc =3D (char *)desc; uint64_t read_len; + void *ori_desc; =20 if (len > (VIRTQUEUE_MAX_SIZE * sizeof(struct vring_desc))) { return -1; @@ -2409,10 +2410,10 @@ virtqueue_read_indirect_desc(VuDev *dev, struct vri= ng_desc *desc, return -1; } =20 - memcpy(desc, ori_desc, read_len); + memcpy(dst_desc, ori_desc, read_len); len -=3D read_len; addr +=3D read_len; - desc +=3D read_len; + dst_desc +=3D read_len; } =20 return 0; --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308609; cv=none; d=zohomail.com; s=zohoarc; b=Nn32jggGCGPUOlduR6UOeDv0WdxfYfVi/8ySBvHs2+Hs2ic2TT4Jgbmq2lIpLppyAPT5KDg6JJxvwMmecwPQJ4PqAJDu/DPcLszbB3N0Cxoh6GE5YF+STt5x45aGHn6AMgEpyJQ4zMntYajA7Ndml9NhEqJvFLfNzPSha5EVEaU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308609; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gLWTe/vUxIlDgyeDSvz5XCN7j+IAHBszh6VVr400454=; b=iXz58niSuEo4kJz31UPx1Euguwf4wRyhdtcrz2V3fACleU+G71XepW/E4w2ihBP69rwJWSjfA42m/M0hGOqFUfWFSSqNX8PIlsZgbLcFJmmmo0PJoFJVQ0EBeHtmFZUMvPdGAFHDbO9SwpExQlaeK/8yqz78gPxxjSvzlGGUQG8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308609848540.2168478402375; Wed, 24 Jun 2026 06:43:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNqg-0007sl-8e; Wed, 24 Jun 2026 09:41:02 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqf-0007rN-77; Wed, 24 Jun 2026 09:41:01 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqc-0001cH-RY; Wed, 24 Jun 2026 09:41:00 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B7E921BAA01; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 506423DEA50; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=gHDs/HtfRmKLqu7Xc07ZeNMMhlhMCC/Q7xG8i/OcEfs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=t5ItgNfa9IbfTFJQgv/z+xe4xvTVFZajK5BSListlOVyvIljgspLfkoox9Gi+Q833 ffxh1usRiW7RmLDEpLbR9Bo0az+r3/RJG3Wwz3IpntpwrFCFN/99Et3w4OL8L3/R2v HDPziQPcLFXYk9UKWpcgTlK1DqpqA/c8JnX5/5ivhIq1SR516jul6Pz8oIjAZQ/sr7 HCJUZ6DcUWfqJp028QAbmnhORUSrj4luoxfB9EgIYdPWH7y6NpnpkVTG1M3rXNTNIo Vkq/XZMJjMyYEZn0NKcrIN5SMyYj45qFJE/e53mlMhtFSQ86iBZvRunsqtxIWy5nYt 6Fr3gwFllfN5A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Stefano Garzarella , DARKNAVY , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-11.0.2 079/107] libvduse: fix buffer overflow in vduse_queue_read_indirect_desc() Date: Wed, 24 Jun 2026 16:31:24 +0300 Message-ID: <20260624133301.403266-79-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308611760158500 From: Stefano Garzarella vduse_queue_read_indirect_desc() copies an indirect descriptor table into a buffer in chunks when the table crosses a memory region boundary. The destination is a struct vring_desc pointer but is advanced by a byte count, so each increment moves the pointer by read_len elements instead of read_len bytes, writing beyond the buffer. Use a char pointer for the destination so that the arithmetic advances correctly. While at it, change the source from a struct vring_desc pointer to a void pointer: when the table is split across regions, iova_to_va() can return a pointer into the middle of a descriptor, so casting it to a struct vring_desc pointer is wrong. The pointer is only used as a memcpy() source, so a void pointer is fine. Fixes: CVE-2026-6425 Fixes: a6caeee811 ("libvduse: Add VDUSE (vDPA Device in Userspace) library") Cc: qemu-stable@nongnu.org Reported-by: DARKNAVY Signed-off-by: Stefano Garzarella Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-Id: <20260417132645.121192-3-sgarzare@redhat.com> (cherry picked from commit 9f1b6d013d42b112680b435af9a9dff331b3fbaf) Signed-off-by: Michael Tokarev diff --git a/subprojects/libvduse/libvduse.c b/subprojects/libvduse/libvdus= e.c index 21ffbb5b8d..df9ca5e56f 100644 --- a/subprojects/libvduse/libvduse.c +++ b/subprojects/libvduse/libvduse.c @@ -465,8 +465,9 @@ static int vduse_queue_read_indirect_desc(VduseDev *dev, struct vring_desc *desc, uint64_t addr, size_t len) { - struct vring_desc *ori_desc; + char *dst_desc =3D (char *)desc; uint64_t read_len; + void *ori_desc; =20 if (len > (VIRTQUEUE_MAX_SIZE * sizeof(struct vring_desc))) { return -1; @@ -483,10 +484,10 @@ vduse_queue_read_indirect_desc(VduseDev *dev, struct = vring_desc *desc, return -1; } =20 - memcpy(desc, ori_desc, read_len); + memcpy(dst_desc, ori_desc, read_len); len -=3D read_len; addr +=3D read_len; - desc +=3D read_len; + dst_desc +=3D read_len; } =20 return 0; --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308763; cv=none; d=zohomail.com; s=zohoarc; b=fSjNfNFOGe9+1rb0a6RLcXYVqaUl9zajhO0FyzXcSPZHUES9B3sJrgKqU95x1QIB9jgDMozdNyWSq/k+Bfep168EHuzGa5xtPi2QLAV4sqw20Uzb+j2UgkblfSnw/Xwk9WqcdtXbp9X17pCkVVnlKL7vjaQYmgAP1uA6k3P0krw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308763; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3p9VDxq7liSp060Ohv/LQY9Him4gAeKG/0KxI9bV/+g=; b=gOrmliYPohEQAqHfADiL7C7rlJ0wCoXVSH87q2Y0oQ4iMaU2FqcKq7aB6LbpG9P1u8cJskANkqnFIjRQyTli0ep10A4IScgUAKbg5D/kFuJCVE7GakRdbvGhpUhPt1mqmwb6ad6XrnoPD2Q3otMqlyIEEtT/cg4Jz9xWZW+00xw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178230876354338.56646537161612; Wed, 24 Jun 2026 06:46:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNqj-0007uS-8E; Wed, 24 Jun 2026 09:41:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqf-0007sO-N8; Wed, 24 Jun 2026 09:41:01 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqd-0001nP-9Z; Wed, 24 Jun 2026 09:41:01 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id CA2521BAA02; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 64A523DEA51; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=ETGA5e2j1inKLrkrRC3C9TsrU/3uSvhIAGjtp79kSZ0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=k5zuY+qfoXg6GTC0sonO5a9E1y6r1YQNEtdxTHzkIkan//mFP+FOtgyK4LrIg1Rd8 toWaYw5vqfJxdpyEnpUTmmWTy8HbtwkAxroemkiBr1+s/ZDNm8IRz6X2PY1ZpZiOMO CxeTS3IdVGTwiyYzTPtSHCf75YfN5QO8lTmPhsf4/lo03zRkHgxZsdjWpBXZ6SAnbl NOPgTounQIzSOHsjWg7FT9qxHKYBH7lvXVMj5e8qyT5CH+mvklt0mbJruSze4nQoZj mpyLw6pg3dUOveIfbFbYb9Gh+BvAz1kO+jaEDmJbwuze1VRy0cYMOBXrVIsOdQRjDy VrpmFAE8suqOQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alejandro Jimenez , David Hoppenbrouwers , Sairaj Kodilkar , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-11.0.2 080/107] amd_iommu: Follow root pointer before page walk and use 1-based levels Date: Wed, 24 Jun 2026 16:31:25 +0300 Message-ID: <20260624133301.403266-80-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308765060158501 Content-Type: text/plain; charset="utf-8" From: Alejandro Jimenez DTE[Mode] and PTE NextLevel encode page table levels as 1-based values, but fetch_pte() currently uses a 0-based level counter, making the logic harder to follow and requiring conversions between DTE mode and level. Switch the page table walk logic to use 1-based level accounting in fetch_pte() and the relevant macro helpers. To further simplify the page walking loop, split the root page table access from the walk i.e. rework fetch_pte() to follow the DTE Page Table Root Pointer and retrieve the top level pagetable entry before entering the loop, then iterate only over the PDE/PTE entries. The reworked algorithm fixes a page walk bug where the page size was calculated for the next level before checking if the current PTE was already a leaf/hugepage. That caused hugepage mappings to be reported as 4K pages, leading to performance degradation and failures in some setups. Fixes: a74bb3110a5b ("amd_iommu: Add helpers to walk AMD v1 Page Table form= at") Cc: qemu-stable@nongnu.org Reported-by: David Hoppenbrouwers Reviewed-By: David Hoppenbrouwers Reviewed-by: Sairaj Kodilkar Signed-off-by: Alejandro Jimenez Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-Id: <20260330212817.992673-2-alejandro.j.jimenez@oracle.com> (cherry picked from commit 786550e2d38a92e90c13eb9d57e3a72d7ab38d51) Signed-off-by: Michael Tokarev diff --git a/hw/i386/amd_iommu.c b/hw/i386/amd_iommu.c index 5d6a405263..bc083d0073 100644 --- a/hw/i386/amd_iommu.c +++ b/hw/i386/amd_iommu.c @@ -648,6 +648,52 @@ static uint64_t large_pte_page_size(uint64_t pte) return PTE_LARGE_PAGE_SIZE(pte); } =20 +/* + * Validate DTE fields and extract permissions and top level data required= to + * initiate the page table walk. + * + * On success, returns 0 and stores: + * - top_level: highest page-table level encoded in DTE[Mode] + * - dte_perms: effective permissions from the DTE + * + * On failure, returns -AMDVI_FR_PT_ROOT_INV. This includes cases where: + * - DTE permissions disallow read AND write + * - DTE[Mode] is invalid for translation + * - IOVA exceeds the address width supported by DTE[Mode] + * In all such cases a page walk must be aborted. + */ +static uint64_t amdvi_get_top_pt_level_and_perms(hwaddr address, uint64_t = dte, + uint8_t *top_level, + IOMMUAccessFlags *dte_per= ms) +{ + *dte_perms =3D amdvi_get_perms(dte); + if (*dte_perms =3D=3D IOMMU_NONE) { + return -AMDVI_FR_PT_ROOT_INV; + } + + /* Verifying a valid mode is encoded in DTE */ + *top_level =3D get_pte_translation_mode(dte); + + /* + * Page Table Root pointer is only valid for GPA->SPA translation on + * supported modes. + */ + if (*top_level =3D=3D 0 || *top_level > 6) { + return -AMDVI_FR_PT_ROOT_INV; + } + + /* + * If IOVA is larger than the max supported by the highest pgtable lev= el, + * there is nothing to do. + */ + if (address > PT_LEVEL_MAX_ADDR(*top_level)) { + /* IOVA too large for the current DTE */ + return -AMDVI_FR_PT_ROOT_INV; + } + + return 0; +} + /* * Helper function to fetch a PTE using AMD v1 pgtable format. * On successful page walk, returns 0 and pte parameter points to a valid = PTE. @@ -662,40 +708,49 @@ static uint64_t large_pte_page_size(uint64_t pte) static uint64_t fetch_pte(AMDVIAddressSpace *as, hwaddr address, uint64_t = dte, uint64_t *pte, hwaddr *page_size) { - IOMMUAccessFlags perms =3D amdvi_get_perms(dte); - - uint8_t level, mode; uint64_t pte_addr; + uint8_t pt_level, next_pt_level; + IOMMUAccessFlags perms; + int ret; =20 - *pte =3D dte; *page_size =3D 0; =20 - if (perms =3D=3D IOMMU_NONE) { - return -AMDVI_FR_PT_ROOT_INV; - } - /* - * The Linux kernel driver initializes the default mode to 3, correspo= nding - * to a 39-bit GPA space, where each entry in the pagetable translates= to a - * 1GB (2^30) page size. + * Verify the DTE is properly configured before page walk, and extract + * top pagetable level and permissions. */ - level =3D mode =3D get_pte_translation_mode(dte); - assert(mode > 0 && mode < 7); + ret =3D amdvi_get_top_pt_level_and_perms(address, dte, &pt_level, &per= ms); + if (ret < 0) { + return ret; + } =20 /* - * If IOVA is larger than the max supported by the current pgtable lev= el, - * there is nothing to do. + * Retrieve the top pagetable entry by following the DTE Page Table Ro= ot + * Pointer and indexing the top level table using the IOVA from the re= quest. */ - if (address > PT_LEVEL_MAX_ADDR(mode - 1)) { - /* IOVA too large for the current DTE */ + pte_addr =3D NEXT_PTE_ADDR(dte, pt_level, address); + *pte =3D amdvi_get_pte_entry(as->iommu_state, pte_addr, as->devfn); + + if (*pte =3D=3D (uint64_t)-1) { + /* + * A returned PTE of -1 here indicates a failure to read the top l= evel + * page table from guest memory. A page walk is not possible and p= age + * size must be returned as 0. + */ return -AMDVI_FR_PT_ROOT_INV; } =20 - do { - level -=3D 1; + /* + * Calculate page size for the top level page table entry. + * This ensures correct results for a single level Page Table setup. + */ + *page_size =3D PTE_LEVEL_PAGE_SIZE(pt_level); =20 - /* Update the page_size */ - *page_size =3D PTE_LEVEL_PAGE_SIZE(level); + /* + * The root page table entry and its level have been determined. Begin= the + * page walk. + */ + while (pt_level > 0) { =20 /* Permission bits are ANDed at every level, including the DTE */ perms &=3D amdvi_get_perms(*pte); @@ -708,37 +763,34 @@ static uint64_t fetch_pte(AMDVIAddressSpace *as, hwad= dr address, uint64_t dte, return 0; } =20 + next_pt_level =3D PTE_NEXT_LEVEL(*pte); + /* Large or Leaf PTE found */ - if (PTE_NEXT_LEVEL(*pte) =3D=3D 7 || PTE_NEXT_LEVEL(*pte) =3D=3D 0= ) { + if (next_pt_level =3D=3D 0 || next_pt_level =3D=3D 7) { /* Leaf PTE found */ break; } =20 + pt_level =3D next_pt_level; + /* - * Index the pgtable using the IOVA bits corresponding to current = level - * and walk down to the lower level. + * The current entry is a Page Directory Entry. Descend to the low= er + * page table level encoded in current pte, and index the new table + * using the appropriate IOVA bits to retrieve the new entry. */ - pte_addr =3D NEXT_PTE_ADDR(*pte, level, address); + *page_size =3D PTE_LEVEL_PAGE_SIZE(pt_level); + + pte_addr =3D NEXT_PTE_ADDR(*pte, pt_level, address); *pte =3D amdvi_get_pte_entry(as->iommu_state, pte_addr, as->devfn); =20 if (*pte =3D=3D (uint64_t)-1) { - /* - * A returned PTE of -1 indicates a failure to read the page t= able - * entry from guest memory. - */ - if (level =3D=3D mode - 1) { - /* Failure to retrieve the Page Table from Root Pointer */ - *page_size =3D 0; - return -AMDVI_FR_PT_ROOT_INV; - } else { - /* Failure to read PTE. Page walk skips a page_size chunk = */ - return -AMDVI_FR_PT_ENTRY_INV; - } + /* Failure to read PTE. Page walk skips a page_size chunk */ + return -AMDVI_FR_PT_ENTRY_INV; } - } while (level > 0); + } + + assert(PTE_NEXT_LEVEL(*pte) =3D=3D 0 || PTE_NEXT_LEVEL(*pte) =3D=3D 7); =20 - assert(PTE_NEXT_LEVEL(*pte) =3D=3D 0 || PTE_NEXT_LEVEL(*pte) =3D=3D 7 = || - level =3D=3D 0); /* * Page walk ends when Next Level field on PTE shows that either a lea= f PTE * or a series of large PTEs have been reached. In the latter case, ev= en if diff --git a/hw/i386/amd_iommu.h b/hw/i386/amd_iommu.h index 302ccca512..7af3c742b7 100644 --- a/hw/i386/amd_iommu.h +++ b/hw/i386/amd_iommu.h @@ -186,17 +186,16 @@ =20 #define IOMMU_PTE_PRESENT(pte) ((pte) & AMDVI_PTE_PR) =20 -/* Using level=3D0 for leaf PTE at 4K page size */ -#define PT_LEVEL_SHIFT(level) (12 + ((level) * 9)) +/* Using level=3D1 for leaf PTE at 4K page size */ +#define PT_LEVEL_SHIFT(level) (12 + (((level) - 1) * 9)) =20 /* Return IOVA bit group used to index the Page Table at specific level */ #define PT_LEVEL_INDEX(level, iova) (((iova) >> PT_LEVEL_SHIFT(level))= & \ GENMASK64(8, 0)) =20 -/* Return the max address for a specified level i.e. max_oaddr */ -#define PT_LEVEL_MAX_ADDR(x) (((x) < 5) ? \ - ((1ULL << PT_LEVEL_SHIFT((x + 1))) - 1) : \ - (~(0ULL))) +/* Return the maximum output address for a specified page table level */ +#define PT_LEVEL_MAX_ADDR(level) (((level) > 5) ? (~(0ULL)) : \ + ((1ULL << PT_LEVEL_SHIFT((level) + 1))= - 1)) =20 /* Extract the NextLevel field from PTE/PDE */ #define PTE_NEXT_LEVEL(pte) (((pte) & AMDVI_PTE_NEXT_LEVEL_MASK) >> 9) --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308669; cv=none; d=zohomail.com; s=zohoarc; b=bTiqbpI98c15dZO4fBlPO62ORHGcFpIqEjAtfJ5N7tv+mphJgYVOdduMtkHKMYccXZktu6i4JXzXGZqgl0DLK9eHoZWiMV+//TetRCyD59PhPh49ufpfEc2XfWpfewj++cdsSJg2SPp/Kh3IK0RiGDlXdnCDTqxq6RO62/ACS0o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308669; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tHeUYys7R7W5v6ZgB+mPpwGoZwb9mV+cyL21EU9BwOI=; b=LHAgP+vc6vEk/jGC1OYThlVqU0M6EpbZx7RfzL/xaSY/2RFKwEiQxAYEXZvoQmYv37HlL5EjqPpfyp2XVnDNDuDdcduF4322JPRBLuLCwcNra1NkNO++XBaqJE9ZjlxcSR/FphMGztY56sFWpHT0qc7/DPgH9XzWa2iYd1mUcTs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308669389308.7063153729873; Wed, 24 Jun 2026 06:44:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNqy-0007vj-I1; Wed, 24 Jun 2026 09:41:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqi-0007u1-7k; Wed, 24 Jun 2026 09:41:04 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNqg-0001oY-ND; Wed, 24 Jun 2026 09:41:03 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D9F781BAA03; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 763653DEA52; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=A9nBOVBTnivWI/q3oet90xjGFoxMzLhbyetbfnEmpZs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=f8R0DcGKEm9EyXcEdX7gE9JoptpwrsoZZmzd8JpZ1WuAAHkAVNMWR10WvA3Qngl2o o4ClOqhfvvWgFjobVKXg1LX+90Uu4jTuxR3mPRJOfa2R8NAuoCSCgUCQ/1Z3aInf+n On7ozE9D3WYhjbpcdrrrLuU4eMSMYPA0tiuqgh062KHqvMeImf8HS1DrWgiaFyFijD Xgsl72t9achehqbWtCODgGDzKJkkJ540lDX+h/nDVKJ1MQnIX041pWPb+HoQLBsZBL u5BeEk56PFYn560j+a91DT41P3wNr+0s6IRSOdvhWTBkfW7QAWtF0wA45vuQjx5X5U Ug/+RnOcDlmtw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Alejandro Jimenez , Sairaj Kodilkar , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-11.0.2 081/107] amd_iommu: Reject non-decreasing NextLevel in fetch_pte() Date: Wed, 24 Jun 2026 16:31:26 +0300 Message-ID: <20260624133301.403266-81-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308669741158500 Content-Type: text/plain; charset="utf-8" From: Alejandro Jimenez The AMD-Vi specification requires that the NextLevel field for a page table entry must not be greater or equal to the current page table entry level. Enforce this to avoid infinite page walk loops on corrupted or buggy guest page tables. The initial implementation of fetch_pte() did not implement this check, but was not vulnerable since the page walk code explicitly decremented the level instead of retrieving it from the page table entry. Cc: qemu-stable@nongnu.org Reviewed-by: Sairaj Kodilkar Signed-off-by: Alejandro Jimenez Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-Id: <20260330212817.992673-3-alejandro.j.jimenez@oracle.com> (cherry picked from commit 291aa70ad254b6c48012dbfd16a4af0978ea1b84) Signed-off-by: Michael Tokarev diff --git a/hw/i386/amd_iommu.c b/hw/i386/amd_iommu.c index bc083d0073..99b05b2ab6 100644 --- a/hw/i386/amd_iommu.c +++ b/hw/i386/amd_iommu.c @@ -771,6 +771,10 @@ static uint64_t fetch_pte(AMDVIAddressSpace *as, hwadd= r address, uint64_t dte, break; } =20 + /* Next level must always be less than current level */ + if (pt_level <=3D next_pt_level) { + return -AMDVI_FR_PT_ENTRY_INV; + } pt_level =3D next_pt_level; =20 /* --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782309015; cv=none; d=zohomail.com; s=zohoarc; b=Dm6mW1Wkelu/n5SLwUeaAasOpyrhwPzjRa82exWf1LAO1LFdv9/yW7I4jy+41VAZfeJEAMF1xvJoaDKB41ibqHK2HNvuM90BoAto+cd1+7fPBYWuFnAKiPcWuqcWDmQEi7cgVp3VhZ/hnoLccluy1iDJAQDnuLqdYWEEyWCC9K8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782309015; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=JyfLHDIxyIMZM133xr+tQwGkRf4Vo3/dLMDEE3z1Htg=; b=IXYGPpuslfrlCYU+WTRTKXshRNi3WkCu5caW4BJvzdjgvFCWRQ6tOW0zCDEGlftDJd+gUCylHEbFdSC9JpDQxOSsXMIuh0Tbw4iQT/LlPP/jxZY3iyFKxSvidz2MDabBcMaXqaOB5rzbdHxIYryZgx5ktGnwt6xe9apHreubXzM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782309015833526.7603630696327; Wed, 24 Jun 2026 06:50:15 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNrM-0008KI-H2; Wed, 24 Jun 2026 09:41:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNr3-00080v-0d; Wed, 24 Jun 2026 09:41:25 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNr1-0001om-5M; Wed, 24 Jun 2026 09:41:24 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id F30851BAA04; Wed, 24 Jun 2026 16:33:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 861593DEA53; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308000; bh=CEWfNtl3ujQvy6+5b3hQDwhS9J6oM/M5tL9TtqaGx10=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=v04wyeFjXmqvu5F8gtSI0WXANV1U43dv3qtFeY1chhP7AneIKkMy6IzickNtqXR0f cCepAJBo2swUf1iQUFejCIqSf5179+ZW2zicb3j7P76Fi3tDeARqRdx5SeccX2Oaid tfAzWbJPvU3CQ0OJWkTse1rgb6F6xq/i+Tga+q5sTJKN7jQJicBUZYKmDCmIcxYmin DeCyuaRWPU5vHIC9XXoAcwpnrYvfb4Bzux/lW7g00kj63a78R0OFMPaabehVVOTVvf en9QbY7J6r6qvRH0XBisXZa/n9GW56NpJ1HrcT+Y/CidLdvWB8fKYfMVPGsROM8TN1 kLqN7FimDW2aA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?Eugenio=20P=C3=A9rez?= , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-11.0.2 082/107] virtio: Allow to fill a whole virtqueue in order Date: Wed, 24 Jun 2026 16:31:27 +0300 Message-ID: <20260624133301.403266-82-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782309016541158500 From: Eugenio P=C3=A9rez As the while steps < max_steps is already one less than the vq size, the right maximum max_steps variable is queue length, not the maximum possible remainder of % vq->vring.num. Fixes: b44135daa37 ("virtio: virtqueue_ordered_fill - VIRTIO_F_IN_ORDER sup= port") Signed-off-by: Eugenio P=C3=A9rez Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-Id: <20260304173535.2702587-2-eperezma@redhat.com> (cherry picked from commit eceff0982f97cc79a26883b93f8eac05cd126dd8) Signed-off-by: Michael Tokarev diff --git a/hw/virtio/virtio.c b/hw/virtio/virtio.c index 8fcf6cfd0b..b337c50c74 100644 --- a/hw/virtio/virtio.c +++ b/hw/virtio/virtio.c @@ -986,7 +986,7 @@ static void virtqueue_ordered_fill(VirtQueue *vq, const= VirtQueueElement *elem, * We shouldn't need to increase 'i' by more than or equal to * the distance between used_idx and last_avail_idx (max_steps). */ - max_steps =3D (vq->last_avail_idx - vq->used_idx) % vq->vring.num; + max_steps =3D MIN(vq->last_avail_idx - vq->used_idx, vq->vring.num); =20 /* Search for element in vq->used_elems */ while (steps < max_steps) { --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308573; cv=none; d=zohomail.com; s=zohoarc; b=UGRsDXXAeczjPn0IiLJZjokQ7meabTlTQ48rqA3cTT+jjjgGB//ZoSPi8E/PYJ/SvscX0xqzJONKQp+X2VkSQC3DRLOUupKixQiRuSuTZadCijIpzZPTPf3zXvLH/vEOvuwzOkVMHf881D2jlVFAuX8r4hpu4HyXDzTMloJKhGA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308573; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=WqJB6dine2V816IcmY/1WY3yajte6i+QUykHiMn+ew8=; b=Ef3MFk/mu0AOdflDkxZ2hJRQrBe7FAOSL4xKcXhHD3Kc7EAkqDvn5nvEdaxcMI9W9N4Nmgu4V52rXY9pB9tAVVdeCGVaYYVQhgM9KOHeAywRwz9/idv+nE9A4LC0dj9hX9AiHLPFUIxWTEEWbUU+aAVs/DJvBr8RyC13+vR+3Vg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308573768913.1095714322873; Wed, 24 Jun 2026 06:42:53 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNrP-0008VY-Va; Wed, 24 Jun 2026 09:41:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNr8-0008ET-QC; Wed, 24 Jun 2026 09:41:31 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNr4-0001p8-4H; Wed, 24 Jun 2026 09:41:28 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 107331BAA05; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9F7A73DEA54; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=mYIBBPM2w05ZoQ5erEn848OzcrIcDR1XfzXNWI3y9ow=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=gnLjWM0EKu63647scxGZkGoYtl1HTb/XQCvnrcQdgFDpFX/eiQ8xqsygh57Bn3Mwv oM8wGU8zJfw2PMIdAfe8SP6rUGS/kdXt587KinOv4Ma3MjpsQnkHBBDPw1yH7ldLMO aq9k92/hz5xkxrLxDWGO39Rxvak6NTyxaZWiltun+HOAtqITI6XoWoaRfE6vADr91q t/gX1qdzeRZfv/nsWJ49Bi+UpbW5b+AsQkVRLpVGdwpVtm+2LV6Y7ol2gGx+NmGyOr MLn3Ztk8vq1+KHd8ucJ/MGqwTUtE+VRZz+GHwSW4qWd2TUOpSyw24hohjGs/5C84QO UafKnkqNJJsiA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Chao Liu , Michael Tokarev Subject: [Stable-11.0.2 083/107] target/riscv/cpu_helper.c: allow LOAD_ADDR_MIS promotion to AMO fault Date: Wed, 24 Jun 2026 16:31:28 +0300 Message-ID: <20260624133301.403266-83-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308575084158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza promote_load_fault() is missing the promotion of misaligned AMO load addresses, i.e. RISCV_EXCP_LOAD_ADDR_MIS should be promoted to RISCV_EXCP_STORE_AMO_ADDR_MIS when RISCV_UW2_ALWAYS_STORE_AMO (i.e. always_storeamo is true). All other load AMO faults are already being covered. Cc: qemu-stable@nongnu.org Fixes: 98f21c30f5 ("target/riscv: AMO operations always raise store/AMO fau= lt") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3503 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Reviewed-by: Chao Liu Message-ID: <20260522181353.429782-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit d85a4ec06a65ccdd5c7d0f00b3e6695fc14a547a) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu_helper.c b/target/riscv/cpu_helper.c index 22bab45e68..f631d008bd 100644 --- a/target/riscv/cpu_helper.c +++ b/target/riscv/cpu_helper.c @@ -2124,6 +2124,9 @@ static target_ulong promote_load_fault(target_ulong o= rig_cause) =20 case RISCV_EXCP_LOAD_PAGE_FAULT: return RISCV_EXCP_STORE_PAGE_FAULT; + + case RISCV_EXCP_LOAD_ADDR_MIS: + return RISCV_EXCP_STORE_AMO_ADDR_MIS; } =20 /* if no promotion, return original cause */ --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308936; cv=none; d=zohomail.com; s=zohoarc; b=acpoy0fmT4ElaQcCcNHEpmzqph9k+65BB614MuFZg4HG6GUJBR0IZ47MRd1C8ogKz0Kl7d1QAgYwvmWC0TIjsgPqremYaI6RfYCDJdBv4xJu00Vw6A/cW8eEbZS38jMnLXkfVNnhYN7fUDmnMVkvjBvJptARdXuu4ZG0YqNXM3g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308936; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VGxV8oQVJ9MNvjH9Pl6LFfFUD+okDGRerq7M+C4v6G8=; b=Y05rGeoKlhIdWKpoPXNPbRg0FF3d0nqU7Sl7+fCEL+axxgBnAokrBqBiZcQWl3SfFhlUm5uJTfNoQZV2ZYdlOQ9aemK8tovlpFVqqmLuhRfjt9gwESq0mDvRmy3HOvBTstyuihh9LVE3EVyoRcNVmf96Y5pxAjKZrDWKUd8hT0s= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308936052371.9806266119846; Wed, 24 Jun 2026 06:48:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNrK-0008JQ-Fy; Wed, 24 Jun 2026 09:41:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNr8-0008EU-IQ; Wed, 24 Jun 2026 09:41:31 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNr4-0001ql-G6; Wed, 24 Jun 2026 09:41:29 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 214A51BAA06; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B106C3DEA55; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=eQvSMPmomQqwaPPkfKeVvtAg7zOdGaHkyz/lMko70sI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=MF7Msi5B2HkXKKK7pKEOLr6eYligD6VdOdVqW7Fwl5iCnv8a/w8w8DXkCSTnJInt8 aZ4gwfrzu5fiw63BCIi1fWdDUqOVVFGbc9FcwrMfxPaq7tF7Hra0SynJ2ptRgOI0Ap 6mboBs1Z4IqV2e6fSUdYrSUVuAqoBP7Nu7IQvXoaE2QUMV6L5fM0nFsHb+ZXEpFo5p TuMR6qdUNxcKF7EGINp6N0RExPHd5JNZSXiOtE7BqWizkmbg5wG5gOWkQrtUtaXflC 13j/aN8vlGE5WU9o3hxeDO9Y79PLkyRV49rfsfiCH7rBOgOUaedvNx3cVdtr+lVOpz GgNsW1kTRWTcA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Chao Liu , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 084/107] target/riscv/tcg: disable svpbmt if satp_mode < sv39 Date: Wed, 24 Jun 2026 16:31:29 +0300 Message-ID: <20260624133301.403266-84-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308937929158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza Priv spec chapter "Svpbmt Extension for Page-Based Memory Types, Version 1.0" mentions that "The Svpbmt extension depends on the Sv39 extension.". We're not doing any satp checks when enabling svpbmt. This causes problems with the riscv32 'max' CPU that happens to be enabling svpbmt even though it doesn't support the required satp mode. In fact all rv32 CPUs are allowing menvcfg.PBMTE writes, which doesn't make sense for them in any circunstance since svpbmt is not possible for rv32 at this moment [1]. This also impacts rv64 CPUs that are running in satp 'bare' mode and are reporting svpbmt in the riscv,isa. All these problems can be solved by disabling svpbmt if satp_mode is not at least sv39. The problem reported in [1] goes away because we'll never enable MENVCFG_PBMTE write mask in write_menvcfgh(). We're also become consistent with how svpbmt is enabled for rv64. In case the user enables svpbmt in the command line using an invalid setup, not just disable svpbmt but also throw a warning: $ ./build/qemu-system-riscv64 -M virt,dumpdtb=3Dfdt.dtb \ -cpu max,sv39=3Doff,sv48=3Doff,sv57=3Doff,sv64=3Doff,svpbmt=3Don qemu-system-riscv64: warning: svpbmt requires at least satp sv39, current s= atp mode: none [1] https://gitlab.com/qemu-project/qemu/-/work_items/3473 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3473 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Chao Liu Message-ID: <20260519114858.316532-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 109856754cbd4c98db49e67071b620945a4ee2a9) Signed-off-by: Michael Tokarev diff --git a/target/riscv/tcg/tcg-cpu.c b/target/riscv/tcg/tcg-cpu.c index c5505414ae..24496b0d8a 100644 --- a/target/riscv/tcg/tcg-cpu.c +++ b/target/riscv/tcg/tcg-cpu.c @@ -874,6 +874,17 @@ void riscv_cpu_validate_set_extensions(RISCVCPU *cpu, = Error **errp) return; } =20 +#ifndef CONFIG_USER_ONLY + if (cpu->cfg.ext_svpbmt && cpu->cfg.max_satp_mode < VM_1_10_SV39) { + cpu->cfg.ext_svpbmt =3D false; + if (cpu_cfg_ext_is_user_set(CPU_CFG_OFFSET(ext_svpbmt))) { + warn_report("svpbmt requires at least satp sv39, " + "current satp mode: %s", + satp_mode_str(cpu->cfg.max_satp_mode, + riscv_cpu_is_32bit(cpu))); + } + } +#endif /* * Disable isa extensions based on priv spec after we * validated and set everything we need. --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308719; cv=none; d=zohomail.com; s=zohoarc; b=fVvaJwZ4FcKT8mlvFUM1KsFcEpHVAUSZEv6v1E7r4bEgVHTEouwDJ/jb4EQUHBZRtFpUqjN9oI1ip6td8U7SF7F6/0u7/F7Voudzek+DifBA8GQKb41oHoce/6SbSy8T+5NoY+WPmayqKq4tkQA/vxXWxWxcutyfVq3nhDiPRGo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308719; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=QsDZHKVyD/2FIthVYDJzTSM8bxz5LOCS4rhQ8/vT4D8=; b=eZi3SuJn+xND5Zg1kx9b9ceK4qHQDNtvk/6YiQvXzB+m4oUUQeHZxzH5ygCT64yNBJcgb9rVzObgC9JM9zKzHE/1Bdk9rTyDjiaib/Ku+pNEaeTOcJEh3DmRyqcHFpgOOHEF0v0TsI4fxoR8OHOtRQ/VyU55NRNfCgkI3ZLVnE0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308719028884.9957661370585; Wed, 24 Jun 2026 06:45:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNrV-0000GT-Or; Wed, 24 Jun 2026 09:41:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrB-0008F7-Gy; Wed, 24 Jun 2026 09:41:35 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrA-0001rh-0t; Wed, 24 Jun 2026 09:41:33 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 318591BAA07; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C1C273DEA56; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=IKgs5bsnyOSKcYnwzV+SHFl/xquAUuTC6KqQdb72ZbU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=IRMFmP8ALpsMJWGUnmvuMcsdl1hl+nqkNzk7BI7je/a4vpFGKhncMApgKivFeML9j QBEpmOtA7rb6f8q0nQQ7mc8nGgCL5UTWMtrAjSoa+5RghVLBKrPOQkHxDMCvnZEbB7 zgScUqoVvefQxcqnyryKfU0pOc6zNKjCT5kgF5clxt7MQxe1u2a6yBHsyTTXw9PJec rw2hWhJwQZSV9Zwvhbvslq2FUh5W66ANdqKo+0i5tdWnMUWhRIsUL3moHJeUddYzVK ACAiQoBDwJ3CGOajc2S+JvCQQx4CknDC13p+BHeQY18CTC2kmUhBZhFH7vcm0K50jS oRnxNEEuUlBHw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 085/107] target/riscv/csr.c: do not allow mstatus MPV/GVA writes Date: Wed, 24 Jun 2026 16:31:30 +0300 Message-ID: <20260624133301.403266-85-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308720455158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza The priv spec states the following about mstatus.MPV: "The MPV bit (Machine Previous Virtualization Mode) is written by the implementation whenever a trap is taken into M-mode." And, about mstatus.GVA: "Field GVA (Guest Virtual Address) is written by the implementation whenever a trap is taken into M-mode." Both are written during riscv_cpu_do_interrupt(). They're not supposed to be written by userspace. As far as write_mstatus goes these fields are read only. The same applies for mstatush.MPV/mstatush.GVA. Fixes: 03dd405dd5 ("target/riscv: Support MSTATUS.MPV/GVA only when RVH is = enabled") Signed-off-by: Daniel Henrique Barboza Acked-by: Alistair Francis Message-ID: <20260514194537.2416243-2-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 18645f19578955ec5ff2c40cd2c8753d6bc460c2) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 0f14ea4689..ec4aa357b4 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -2027,9 +2027,6 @@ static RISCVException write_mstatus(CPURISCVState *en= v, int csrno, } =20 if (xl !=3D MXL_RV32 || env->debugger) { - if (riscv_has_ext(env, RVH)) { - mask |=3D MSTATUS_MPV | MSTATUS_GVA; - } if ((val & MSTATUS64_UXL) !=3D 0) { mask |=3D MSTATUS64_UXL; } @@ -2066,7 +2063,7 @@ static RISCVException write_mstatush(CPURISCVState *e= nv, int csrno, target_ulong val, uintptr_t ra) { uint64_t valh =3D (uint64_t)val << 32; - uint64_t mask =3D riscv_has_ext(env, RVH) ? MSTATUS_MPV | MSTATUS_GVA = : 0; + uint64_t mask =3D 0; =20 if (riscv_cpu_cfg(env)->ext_smdbltrp) { mask |=3D MSTATUS_MDT; --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308607; cv=none; d=zohomail.com; s=zohoarc; b=OCSVhkOD6nA47sezsqEgJLtjVG8U3alunY6M0i9snAsUDfeQs3invIl0K4j0cuLeKVlMTmRZOX1vW+YGPqG+Wr0Z0x6fgbVg+CUqyJ3Zg9mjOjMEM7s6u+vm/vJQq5HfPLwrW0hu0Xy2OaDCMI4Y7+pNFquAtWOieGtwaZm4zso= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308607; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=egqS9z5leNWUaQvpPPDNEBuSduYbNpK31hpoYCdWHv4=; b=K/gb8YHzY5geKjXe2a0dmsZSlmJqKAV9Ebl9GJDRIRvYM1Cbu7HPB6V1GdLXAjQFAwN0c2OXxkfLqJBKPdJS7/postwdJe0lRjFowsKiyejAUxM8Cspg3uASqdIfrFrif97SbaWZs1tqDaIBfT9+sMm5VssxfqwiVl8aDOJGqgc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308607732761.5691691326872; Wed, 24 Jun 2026 06:43:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNre-0000WJ-KJ; Wed, 24 Jun 2026 09:42:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrD-0008Fw-2j; Wed, 24 Jun 2026 09:41:36 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrA-0001rj-1E; Wed, 24 Jun 2026 09:41:33 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 3FD631BAA08; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D18B43DEA57; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=CEcTVxTkASjqes1EwI/5mD0EgcRl88KTc8Zuopa1EpY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=a04Dyajo3nAud5y4hhFS1S2maD059+uROPMnWscsNKc8niEuK8vYoDntRXFPYPP60 pnh42BoO3qNbfKJjZqHrx0nSBn+Q7xN3UjEF/biTZAW65MitgvvT8AC3YVxKas6Z8v oGeDnJjZXVfkFJBq8MVJYWPcGL6JaWVykaD8EBlDAw3c8a9DGosxEX4xQY2Lck1wfC PC0BcASFAJa3FWBIc8pvOzpaPohET/uvQCLViL45LlQZ18cTwRfjSkPp+rJmTgakX3 oP15hB9JVSueWLXm8caeHy4+7GlDB0vfZs11TTYknPE6+v8hFpDfWT2SNqGuQEDqwA 3pePP1GIJW1Fg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 086/107] target/riscv/csr.c: fix mstatus.UXL reserved value Date: Wed, 24 Jun 2026 16:31:31 +0300 Message-ID: <20260624133301.403266-86-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308609332158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza By the priv spec the value "3" is marked as 'Reserved' for mstatus.UXL. Handle a mstatus.UXL =3D 3 write by writing the current 'xl' instead. Fixes: https://gitlab.com/qemu-project/qemu/-/work_items/3367 Signed-off-by: Daniel Henrique Barboza Acked-by: Alistair Francis Message-ID: <20260514194537.2416243-3-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit ddfd33f1965804fc4a718d8d46bc150525c2f9db) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index ec4aa357b4..78dd4e0070 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -2028,7 +2028,17 @@ static RISCVException write_mstatus(CPURISCVState *e= nv, int csrno, =20 if (xl !=3D MXL_RV32 || env->debugger) { if ((val & MSTATUS64_UXL) !=3D 0) { + uint64_t uxl =3D val & MSTATUS64_UXL >> 32; mask |=3D MSTATUS64_UXL; + + /* + * uxl =3D 3 is reserved so write the current xl instead. + * In case xl =3D MXL_RV128 (3) write MXL_RV64. + */ + if (uxl =3D=3D 3) { + uxl =3D xl =3D=3D MXL_RV128 ? MXL_RV64 : xl; + val =3D deposit64(val, 32, 2, uxl); + } } } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308654; cv=none; d=zohomail.com; s=zohoarc; b=XBUm+TkfjIpxCnJuc3tt79wlgc2/SEfKuWSKkkP3J1sTnF4QBlxKZW6vOJVKSZRTJH6wWZIVgqSSNavEV5VGA4IRkHD3rd285zY20z7xGuemWlMqORezDd5Vnp6M+Z/AiJiVIVJza5xcF1yIF7J3r8zbBVklIKnFsUg5UbyRB/o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308654; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yfJIm8EcWk213xAHzXlHVgjmALBS65jEWR/ewCB8onk=; b=k5Cm2DC1exN6tkodqh3tBhit2zNlm5ysZWtamjp8hnU1S3KifQiZoc8Glj5NmD2jq2AKilYH0YxHNeyMa2O6pFGLQ4CHrUQlwsynaoNlfkTdBsf/VfebCAXhPUU043IaF7bbW+tWQgtp0DrPFAAndglqcUQUwdbtE+RGav8/x9g= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178230865470638.988717725070615; Wed, 24 Jun 2026 06:44:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNrk-0000jF-9l; Wed, 24 Jun 2026 09:42:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrZ-0000Nq-1X; Wed, 24 Jun 2026 09:41:57 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrX-0001sN-4r; Wed, 24 Jun 2026 09:41:56 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 5145D1BAA09; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E01633DEA58; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=NJu5fj1Zrg+RCUjSQsJZtEbF98yRPCsiDRVzepx5cNM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=hUrPEx0jKFbX1G389Xqh+JU67VaEViRHMQSl6xmpG4gc+a2Rol/TxRP5suyTimS2o EBy+OnZSYyeG9VayKarF9RM0XHce7gsIiVvXZIO2uEwhNIF/NfcBB87IvlFfrPb7Sc ZjOm23sUu7nG3OEMB2H7RrdPW21mlEK5t0s0fWqlW7IrHP+aJu1a0gaNyEXN8vDc+I SJTdLNLoHjvD0mGIOLKic59KIssgA6AvByRB4VwT2hSq9+7ZDsOqN66DtRB+az8huP MnQortfCGDINSrihgcLmhO5JUtNogjGrLiqUVj8Z2flwcra11GnZp98p4KYRHoYpDU uw4S/w1+flNzw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Chao Liu , Richard Henderson , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 087/107] disas/riscv.c: add 'cbo' insns to disassembler Date: Wed, 24 Jun 2026 16:31:32 +0300 Message-ID: <20260624133301.403266-87-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308655821158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza We forgot to add 'cbo' insns to disas/riscv.c. The result is that the disassembler recognizes all of them as 'lq', an insn that happens to share the same opcode space. While we're at it reorder cbo_* entries in insn32.decode using opcode order instead of insn name. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3480 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Chao Liu Reviewed-by: Richard Henderson Message-ID: <20260519204714.1376551-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 9273cda72293ed2f414a0f239c4ac78fb7838c0e) Signed-off-by: Michael Tokarev diff --git a/disas/riscv.c b/disas/riscv.c index 6f2667482d..0ed8a3b5ed 100644 --- a/disas/riscv.c +++ b/disas/riscv.c @@ -984,6 +984,10 @@ typedef enum { rv_op_ssamoswap_d =3D 953, rv_op_c_sspush =3D 954, rv_op_c_sspopchk =3D 955, + rv_op_cbo_inval =3D 956, + rv_op_cbo_clean =3D 957, + rv_op_cbo_flush =3D 958, + rv_op_cbo_zero =3D 959, } rv_op; =20 /* register names */ @@ -2254,6 +2258,10 @@ const rv_opcode_data rvi_opcode_data[] =3D { rv_op_sspush, 0 }, { "c.sspopchk", rv_codec_cmop_ss, rv_fmt_rs1, NULL, rv_op_sspopchk, rv_op_sspopchk, 0 }, + { "cbo.inval", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 }, + { "cbo.clean", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 }, + { "cbo.flush", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 }, + { "cbo.zero", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 }, }; =20 /* CSR names */ @@ -2875,7 +2883,26 @@ static void decode_inst_opcode(rv_decode *dec, rv_is= a isa) switch ((inst >> 12) & 0b111) { case 0: op =3D rv_op_fence; break; case 1: op =3D rv_op_fence_i; break; - case 2: op =3D rv_op_lq; break; + case 2: + /* + * 'lq' shares the "(...) 010 ..... 0001111" opcode space + * with 'cbo' insns. Check the next 5 bits to select + * what we want: + * + * cbo_inval 0000000 00000 ..... 010 00000 0001111 + * cbo_clean 0000000 00001 ..... 010 00000 0001111 + * cbo_flush 0000000 00010 ..... 010 00000 0001111 + * cbo_zero 0000000 00100 ..... 010 00000 0001111 + * + * Anything that doesn't match these will default to 'lq'. + */ + switch ((inst >> 17) & 0b11111) { + case 0: op =3D rv_op_cbo_inval; break; + case 1: op =3D rv_op_cbo_clean; break; + case 2: op =3D rv_op_cbo_flush; break; + case 4: op =3D rv_op_cbo_zero; break; + default: op =3D rv_op_lq; break; + } } break; case 4: diff --git a/target/riscv/insn32.decode b/target/riscv/insn32.decode index 6e35c4b1e6..21272fdb50 100644 --- a/target/riscv/insn32.decode +++ b/target/riscv/insn32.decode @@ -207,9 +207,9 @@ ldu ............ ..... 111 ..... 0000011 @i { [ # *** RV32 Zicbom Standard Extension *** + cbo_inval 0000000 00000 ..... 010 00000 0001111 @sfence_vm cbo_clean 0000000 00001 ..... 010 00000 0001111 @sfence_vm cbo_flush 0000000 00010 ..... 010 00000 0001111 @sfence_vm - cbo_inval 0000000 00000 ..... 010 00000 0001111 @sfence_vm =20 # *** RV32 Zicboz Standard Extension *** cbo_zero 0000000 00100 ..... 010 00000 0001111 @sfence_vm --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308663; cv=none; d=zohomail.com; s=zohoarc; b=ADpdH5u9JDnP+Gv80Orvoqo1hmz3RdrItqUJEXOWz1K98Q8fhzyRKFavTu4CVD+kcIPbaXf2YN6VpwxxsxmZNWjyuqgjd2jsPhDx+YFTWpddZZwXSq2BM6vhG8qx2VkLiWkyzxDt4TsYEASHuJquWHU3UteO1OylKyoXNYPly3s= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308663; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8MKZmDFF5GGhjr9ndEoU75TWncGPO4cM5SNZIfU0cvQ=; b=R2XJ2gHdXmPQT36Iz0ernryVgeuU1bPQ17h53bJg0mrOkDIoU9MdsUDHx8JaPjrdoCcVy+y0yT4/27kygP6URTVTxvKCrMPf42GNWZrmAduYby/e/DBPMx00XIMSkxsOPfJL0YN9GqMqnII+cwGUv9fNYKUMkm6WrpFt4PMRX1w= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308662996441.9840941350135; Wed, 24 Jun 2026 06:44:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNrk-0000fw-1Z; Wed, 24 Jun 2026 09:42:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrb-0000Wv-1K; Wed, 24 Jun 2026 09:41:59 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrY-0001sl-Ff; Wed, 24 Jun 2026 09:41:58 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 6074E1BAA0A; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id F15443DEA59; Wed, 24 Jun 2026 16:33:26 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=0qeQG38BzP/Bizi+dlJAjX3FnMzZTa7jiRiX9fH3TzQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=XpIIdxPu+nmac1Zf0rCf0hZwIoAduGJV2AHwdkjS3iZuPl7oWLh4i8NduJMVUuQvH rVFNu+YL2a6s5cvNy6HrHJ74UsF8nXWMdgJCNbCjsrSaXubFwo9K1/TLHZnWwd1WOp RurF+viLP5Smm6/fACNHnqbTwCCLuUzu/86v1bL0G+nuPaSzXulpPgktAX9W87ZuQy 97WAMmivJoYbaeoSke5qIj6izR7730G0fQUMXEV3jMDcyTGV3DVRirp/5majYY20LS mjIiDrRHnkOfcLx5lDvYRgVqPQvMl8NJ9CXLkvRDtiCye2ZZit/9qrXCZB5guhpfnJ 2BW6yw6ROSK0A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 088/107] target/riscv/insn_trans/trans_rvzicbo.c.inc: save opcode before helpers Date: Wed, 24 Jun 2026 16:31:33 +0300 Message-ID: <20260624133301.403266-88-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308663754158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza All helpers from this file can trigger ILLEGAL_INSN exceptions via check_zicbo_envcfg() directly, bypassing the usual exception code from translate.c. If we don't save the opcode before each helper, riscv_raise_exception() is triggered and env->bins won't be unwind during cpu_loop_exit_restore() (code path cpu_restore_state -> cpu_restore_state_from_tb() -> restore_state_to_opc()). And finally, in riscv_cpu_do_interrupt(), we will set (m)tval =3D 0 when we= can, instead, set it to the cbo opcode that generated the exception. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3380 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260520214704.1943652-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit d6c5855c76b2ea849adb0fb91379dbb1e5a94dca) Signed-off-by: Michael Tokarev diff --git a/target/riscv/insn_trans/trans_rvzicbo.c.inc b/target/riscv/ins= n_trans/trans_rvzicbo.c.inc index 15711c3140..096f7dde27 100644 --- a/target/riscv/insn_trans/trans_rvzicbo.c.inc +++ b/target/riscv/insn_trans/trans_rvzicbo.c.inc @@ -33,6 +33,8 @@ static bool trans_cbo_clean(DisasContext *ctx, arg_cbo_cl= ean *a) REQUIRE_ZICBOM(ctx); TCGv src =3D get_address(ctx, a->rs1, 0); =20 + /* The helper may raise ILLEGAL_INSN -- record binv for unwind. */ + decode_save_opc(ctx, 0); gen_helper_cbo_clean_flush(tcg_env, src); return true; } @@ -42,6 +44,8 @@ static bool trans_cbo_flush(DisasContext *ctx, arg_cbo_fl= ush *a) REQUIRE_ZICBOM(ctx); TCGv src =3D get_address(ctx, a->rs1, 0); =20 + /* The helper may raise ILLEGAL_INSN -- record binv for unwind. */ + decode_save_opc(ctx, 0); gen_helper_cbo_clean_flush(tcg_env, src); return true; } @@ -51,6 +55,8 @@ static bool trans_cbo_inval(DisasContext *ctx, arg_cbo_in= val *a) REQUIRE_ZICBOM(ctx); TCGv src =3D get_address(ctx, a->rs1, 0); =20 + /* The helper may raise ILLEGAL_INSN -- record binv for unwind. */ + decode_save_opc(ctx, 0); gen_helper_cbo_inval(tcg_env, src); return true; } @@ -60,6 +66,8 @@ static bool trans_cbo_zero(DisasContext *ctx, arg_cbo_zer= o *a) REQUIRE_ZICBOZ(ctx); TCGv src =3D get_address(ctx, a->rs1, 0); =20 + /* The helper may raise ILLEGAL_INSN -- record binv for unwind. */ + decode_save_opc(ctx, 0); gen_helper_cbo_zero(tcg_env, src); return true; } --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308702; cv=none; d=zohomail.com; s=zohoarc; b=eV05P438Dy4q4kqUe/QqAwiclU0aTwDMr7DXBq7WuS9B3OZf0MNn6Az1kHOmfrKcY6DizPN+IuVPWgWi7hFbowCfYkPX/uAr1+lJ7lUl4teaSyRH2OqdK+iOia5uTKSqG1raFfHInmh1zX05rM5mDf/bmbOQ90WwUA8XmGWKajM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308702; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RoEx2+CxN3U/bllTirja3oo4zUXv6saTYLK7B5KLrrI=; b=YHIenRGVfjusqD/lMO+54Jk33Wo09oM9Sft1GEOvZfd9sJ77u+P7i5zIs2h/xDBZEMcw/rCpfODn9+p4QjY3wRlAca6/h/echEm0I57gZlBassmGhNLntrqNSwK3qFqu9hOcf+edhQgScrpGTM4JcLotATaqF+BHwyRDkQVyMww= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308702287558.5058862643887; Wed, 24 Jun 2026 06:45:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNry-0000wR-Ah; Wed, 24 Jun 2026 09:42:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrc-0000ZO-WD; Wed, 24 Jun 2026 09:42:02 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrb-0001ux-4f; Wed, 24 Jun 2026 09:42:00 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 6EB1F1BAA0B; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0C4563DEA5A; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=uPPwjcq5ppvp1MZms9UGGsAC3WsimsfdOd6fgW4/rrI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=LXbTwhQxHaC2LeICA+3E108fwED0XJSBoKmNcLZlIJGS+bwNfcrsgZSEfOxb9Nlh7 1mzTJt9b+mXrJhdADTVUbEmM1Y9QLHmhc9ueVtohpAfsnWUt9FSygdTtwD6qH7nj0p Qvr1qZXKeV5Sfk2AkKOJOrN/foMT6g9cjNwQLv6hecD+le1TxDsmeP5BYFKZ1F6B62 6IeGm9GNnrACB03jOvCDUaKb7OZlRZ9McPHTeGIBEjsyATcUtV52HFxAxiORPw+zNP GWYRZK0mtZ7dI3/bL6EnHokRv6UKkWbbpoOJ8Gvc3x3qeYiWwAwjhAU4VUnRk+Zdl5 ifAtQzrYuBA3Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 089/107] target/riscv/cpu_helper.c: fault with reserved PTE.PBMT val Date: Wed, 24 Jun 2026 16:31:34 +0300 Message-ID: <20260624133301.403266-89-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308704080158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza We need to fault during any access done while PTE bits 62-61 are both set, according to the RISC-V priv spec. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3494 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260521130727.2311629-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 3e33da68f1db7ab586063b708aa571086e7400ce) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu_helper.c b/target/riscv/cpu_helper.c index f631d008bd..d64c4d2e80 100644 --- a/target/riscv/cpu_helper.c +++ b/target/riscv/cpu_helper.c @@ -1396,6 +1396,25 @@ static int get_physical_address(CPURISCVState *env, = hwaddr *physical, return TRANSLATE_FAIL; } =20 + /* + * priv spec, "Svpbmt" chapter: + * "For non-leaf PTEs, bits 62-61 are reserved for future + * standard use. Until their use is defined by a standard + * extension, they must be cleared by software for forward + * compatibility, or else a page-fault exception is raised." + * + * For leaf PTEs the same bits are also reserved but in that + * case the page-fault is mandatory. Make both cases consiste= nt + * by also page faulting here. + */ + if ((pte & PTE_PBMT) =3D=3D PTE_PBMT) { + qemu_log_mask(LOG_GUEST_ERROR, "%s: PBMT bits 62 and 61 ar= e " + "reserved but are set in PTE: " + "addr: 0x%" HWADDR_PRIx " pte: 0x" TARGET_FMT_lx "= \n", + __func__, pte_addr, pte); + return TRANSLATE_FAIL; + } + if (!riscv_cpu_cfg(env)->ext_svnapot && (pte & PTE_N)) { /* Reserved without Svnapot extension */ qemu_log_mask(LOG_GUEST_ERROR, "%s: N bit set in PTE, " @@ -1448,6 +1467,23 @@ static int get_physical_address(CPURISCVState *env, = hwaddr *physical, return TRANSLATE_FAIL; } =20 + /* + * priv spec, "Svpbmt" chapter: + * "For leaf PTEs, setting bits 62-61 to the value 3 is reserved + * for future standard use. Until this value is defined by a + * standard extension, using this reserved value in a leaf PTE + * raises a page-fault exception. " + * + * Raise a fault if 62-61 (i.e. PTE_PBMT) are set. + */ + if ((pte & PTE_PBMT) =3D=3D PTE_PBMT) { + qemu_log_mask(LOG_GUEST_ERROR, "%s: PBMT bits 62 and 61 are " + "reserved but are set in leaf PTE: " + "addr: 0x%" HWADDR_PRIx " pte: 0x" TARGET_FMT_lx "\n= ", + __func__, pte_addr, pte); + return TRANSLATE_FAIL; + } + target_ulong rwx =3D pte & (PTE_R | PTE_W | PTE_X); /* Check for reserved combinations of RWX flags. */ switch (rwx) { --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308970; cv=none; d=zohomail.com; s=zohoarc; b=cgcugFA5kCIWVwG+MqOAdZcwGTa0BkGadr8y7h/8hEs8gHwspkWs1BrQpqFhcqXnPdS283+0nXcmgDCexLsQuHAMCv2GVCQYP2S9sGlFX51Mn7IVnXhWYT627tG71UEWZVoq0z/TLcWCeeqgA9lvDt06l0alFCceqibsNG6prwI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308970; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=0AJrKBMvmMVVDo3IIIxtclVYK9nbJC1G2NBK19AjTUU=; b=nKa9UoJeaCIzPdq0yLJsPLQu+R5lQYzmqkN3mpkbbCxkYklimQtXTykvcdBt/0MaRUE5VrYf7I9lTQPzJNGCHuAtUp0PTzHblsf7/Cd4c4cVW1X1UetFjShLhAHIwaTaO+P52ER7RIFdWE60lxMwQh0TdwuEFF8YOi5kybCynCE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308970289722.4366227065807; Wed, 24 Jun 2026 06:49:30 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNsH-000189-Jv; Wed, 24 Jun 2026 09:42:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNre-0000ZY-LD; Wed, 24 Jun 2026 09:42:04 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrc-0001vF-Gm; Wed, 24 Jun 2026 09:42:02 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 7F46B1BAA0C; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1AD303DEA5B; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=xyeWbwDuQ+aowg9DTN9j7L2dMVeci73X2nXvAfRyHbI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=v309/pJwDcMAeqdbq0xt4nQeCv8MtPX9+TQ8lo1vS+3IFH1kfjo+UvRnWdYpwZ1Hw NTW9eR1EpUM1DHhryNOca4MkkAvTr/03sMhq8gj7OTIq1jbEwZI8hU//WS29dUpNbR dRaVKFabwJZ/l+JrmNyGILo1KmaUT/vzDoRqC45QLwE6a0CvZLYAVcdha9aZT7A+x4 +DjphKGhiKCrnrJqDgZY7PCOufRXJDnPQDtUoLhFA9CsEUGq1Ozp8SYWh5DlceZ+g4 JlkAohkGcvzPoNqDCo8YrT0aRQ/a5Hzvfhe9LGSMXwbGbIISXA6wQY32NOxZPM1/g6 llcNQG1vwPb/Q== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Chao Liu , Michael Tokarev Subject: [Stable-11.0.2 090/107] target/riscv/cpu_helper.c: add PMA access fault Date: Wed, 24 Jun 2026 16:31:35 +0300 Message-ID: <20260624133301.403266-90-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308972219158501 From: Daniel Henrique Barboza We're not doing anything special w.r.t PMA (Physical Memory Access) related faults, handling them like regular faults that will eventually turn to be regular page faults. Turns out we can't do that. Priv spec section "Virtual Address Translation Process" mentions: "If a store to the PTE at address a+va.vpn[i]=C3=97PTESIZE would violate a PMA or PMP check, raise an access-fault exception corresponding to the original access type." This means that we should handle PMA violations with access faults, like we're already doing with PMP. One clear code path where we should throw a PMA failure, exposed by [1], is the error return from address_space_ld* call. There's a separated issue with the error code being returned by them (it always return DECODE_ERROR even with 'rejected' reads) that we're going to work around it by assuming that we did a good job with the PTE address sanitization beforehand, and interpret that the error here is related to PMA. This is of course not ideal but fixing this QEMU API is out of scope for this work. All this said, we'll set the new pmp_pma_violation flag when we have either a PMP or a PMA fault, and everything else shall fall into place. [1] https://gitlab.com/qemu-project/qemu/-/work_items/3502 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3502 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Reviewed-by: Chao Liu Message-ID: <20260522172502.320529-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 8e090ecfa9e5d9c225a9f6aae1e39586c182afa7) Signed-off-by: Michael Tokarev diff --git a/target/riscv/cpu.h b/target/riscv/cpu.h index a6adf6efc6..8a77682627 100644 --- a/target/riscv/cpu.h +++ b/target/riscv/cpu.h @@ -131,7 +131,8 @@ enum { TRANSLATE_SUCCESS, TRANSLATE_FAIL, TRANSLATE_PMP_FAIL, - TRANSLATE_G_STAGE_FAIL + TRANSLATE_G_STAGE_FAIL, + TRANSLATE_PMA_FAIL, }; =20 /* Extension context status */ diff --git a/target/riscv/cpu_helper.c b/target/riscv/cpu_helper.c index d64c4d2e80..665d0f7181 100644 --- a/target/riscv/cpu_helper.c +++ b/target/riscv/cpu_helper.c @@ -1374,7 +1374,22 @@ static int get_physical_address(CPURISCVState *env, = hwaddr *physical, } =20 if (res !=3D MEMTX_OK) { - return TRANSLATE_FAIL; + /* + * The result of address_space_* APIs above does not take into + * consideration reject reads, putting all errors in the same + * cathegory (DECODE_ERROR), although there's a clear + * distinction between a rejected read versus other errors + * (see memory_region_dispatch_read() -> + * memory_region_access_valid()). This is something that + * we might have to deal with core QEMU logic some other + * day. + * + * For this particular error path, given that we made checks + * w.r.t legal PTE address before calling those APIs, we'll + * assume that anything !=3D MEMTX_OK means a rejected read, + * i.e. a PMA error. + */ + return TRANSLATE_PMA_FAIL; } =20 if (riscv_cpu_sxl(env) =3D=3D MXL_RV32) { @@ -1654,7 +1669,8 @@ static int get_physical_address(CPURISCVState *env, h= waddr *physical, } =20 static void raise_mmu_exception(CPURISCVState *env, target_ulong address, - MMUAccessType access_type, bool pmp_violat= ion, + MMUAccessType access_type, + bool pmp_pma_violation, bool first_stage, bool two_stage, bool two_stage_indirect) { @@ -1662,7 +1678,7 @@ static void raise_mmu_exception(CPURISCVState *env, t= arget_ulong address, =20 switch (access_type) { case MMU_INST_FETCH: - if (pmp_violation) { + if (pmp_pma_violation) { cs->exception_index =3D RISCV_EXCP_INST_ACCESS_FAULT; } else if (env->virt_enabled && !first_stage) { cs->exception_index =3D RISCV_EXCP_INST_GUEST_PAGE_FAULT; @@ -1671,7 +1687,7 @@ static void raise_mmu_exception(CPURISCVState *env, t= arget_ulong address, } break; case MMU_DATA_LOAD: - if (pmp_violation) { + if (pmp_pma_violation) { cs->exception_index =3D RISCV_EXCP_LOAD_ACCESS_FAULT; } else if (two_stage && !first_stage) { cs->exception_index =3D RISCV_EXCP_LOAD_GUEST_ACCESS_FAULT; @@ -1680,7 +1696,7 @@ static void raise_mmu_exception(CPURISCVState *env, t= arget_ulong address, } break; case MMU_DATA_STORE: - if (pmp_violation) { + if (pmp_pma_violation) { cs->exception_index =3D RISCV_EXCP_STORE_AMO_ACCESS_FAULT; } else if (two_stage && !first_stage) { cs->exception_index =3D RISCV_EXCP_STORE_GUEST_AMO_ACCESS_FAUL= T; @@ -1806,7 +1822,7 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address, = int size, vaddr im_address; hwaddr pa =3D 0; int prot, prot2, prot_pmp; - bool pmp_violation =3D false; + bool pmp_pma_violation =3D false; bool first_stage_error =3D true; bool two_stage_lookup =3D mmuidx_2stage(mmu_idx); bool two_stage_indirect_error =3D false; @@ -1907,8 +1923,8 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address, = int size, } } =20 - if (ret =3D=3D TRANSLATE_PMP_FAIL) { - pmp_violation =3D true; + if (ret =3D=3D TRANSLATE_PMP_FAIL || ret =3D=3D TRANSLATE_PMA_FAIL) { + pmp_pma_violation =3D true; } =20 if (ret =3D=3D TRANSLATE_SUCCESS) { @@ -1935,7 +1951,7 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address, = int size, cpu_check_watchpoint(cs, address, size, MEMTXATTRS_UNSPECIFIED, wp_access, retaddr); =20 - raise_mmu_exception(env, address, access_type, pmp_violation, + raise_mmu_exception(env, address, access_type, pmp_pma_violation, first_stage_error, two_stage_lookup, two_stage_indirect_error); cpu_loop_exit_restore(cs, retaddr); --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308656; cv=none; d=zohomail.com; s=zohoarc; b=abOW9tAZ09ZgHorV/2yWmhH4QHt2xyC4qATN6qAWwdDoxpJK6jx3oP/ZLtc79Uw+dPAULEn7PCs75P/0oFcEY0kHeR28hLl3nYVTeZhqw3zGyszo6BTL2A5mzKto+GcWKauY8FtYB2FoyeJ6jNH7y+9job07k1q/cRZ7+UjBjcQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308656; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EWjVF9HtcAArCJX/Vn5Im0ZdLaniZETW+LLwWeq8R3k=; b=nOy2CmMt1zyZE2Gd7Ik6w/CCj/q+luF4LPdY1I7v6pK3lqjXa+9tG6mhlMXPDAGpAFKIE733zocbMvD1kZIjrP/kM98gxaNEJgkkPci/JIIqxYYDRtAM8LFtBdGATeCptW0vzsGZ6ClnkM5mohqOSjoT92cmEt1wdWpYr418K88= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308656878570.5498937683024; Wed, 24 Jun 2026 06:44:16 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNry-0000wU-BD; Wed, 24 Jun 2026 09:42:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNrg-0000Zr-2e; Wed, 24 Jun 2026 09:42:04 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNre-0001vZ-Da; Wed, 24 Jun 2026 09:42:03 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 8F1E11BAA0D; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 2BBA13DEA5C; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=C1XT6cdd60teLzTCxyeH20aD9PBFHuswDFTF+CRRc2U=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=tbSof3oqeJtpZdlcx6EPrzyJalCkg8QdtGOZYiGfC2hhPe5IlH6C9mpfZ7+NFY3+F WAu6imvVciWE6t5BS4iq2hAjmd83ikLI8kM5vZ8iF/xXoxCXbURuT/f6CEw4Rm/27o h7TqWR1C+VSZRyhV5ZiXo/tzVsHwYgz1/Nzs2z+7olwLpqk3R5CBux6VmDPgIZ17sw OQDbP/e1Q/foBnoffJiTDctF3bgvTPhEJkoaWEVlcXdATbcXNSyI62mDB7M/Xu/N24 r3S+2wwwM1h9tucxHCpTfPLdUtyAn+XxIjI8hlT/X7Wkc7EbfQdHzyzLt3AcskMheX zzO+8UL/I5WKA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 091/107] target/riscv/tcg: disable svnapot if satp_mode < sv39 Date: Wed, 24 Jun 2026 16:31:36 +0300 Message-ID: <20260624133301.403266-91-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308657678158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza We did a recent change to disable svpbmt if satp_mode < sv39 that was discovered via a gitlab report. This time we don't have an opened bug but the problem is similar: RISC-V privileged ISA, chapter '"Svnapot" Extension for NAPOT Translation Contiguity, Version 1.0' states: "The Svnapot extension depends on the Sv39 extension." Do the same thing with svnapot, including the user warning in case we try to enable it without the required satp_mode: $ ./build/qemu-system-riscv64 -M virt,dumpdtb=3Dfdt.dtb \ -cpu max,sv39=3Doff,sv48=3Doff,sv57=3Doff,sv64=3Doff,svnapot=3Don qemu-system-riscv64: warning: svnapot requires at least satp sv39, current = satp mode: none Signed-off-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260527213034.2094103-1-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 601c8494c6c7e73f5b3f30b5823de2c13c003990) Signed-off-by: Michael Tokarev diff --git a/target/riscv/tcg/tcg-cpu.c b/target/riscv/tcg/tcg-cpu.c index 24496b0d8a..b810592daf 100644 --- a/target/riscv/tcg/tcg-cpu.c +++ b/target/riscv/tcg/tcg-cpu.c @@ -884,6 +884,16 @@ void riscv_cpu_validate_set_extensions(RISCVCPU *cpu, = Error **errp) riscv_cpu_is_32bit(cpu))); } } + + if (cpu->cfg.ext_svnapot && cpu->cfg.max_satp_mode < VM_1_10_SV39) { + cpu->cfg.ext_svnapot =3D false; + if (cpu_cfg_ext_is_user_set(CPU_CFG_OFFSET(ext_svnapot))) { + warn_report("svnapot requires at least satp sv39, " + "current satp mode: %s", + satp_mode_str(cpu->cfg.max_satp_mode, + riscv_cpu_is_32bit(cpu))); + } + } #endif /* * Disable isa extensions based on priv spec after we --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308683; cv=none; d=zohomail.com; s=zohoarc; b=FAYtmOqomol2od6sA0RMHveJ/rzY1B7N/K3fgbfpXFindgmxmVlK2U35TuMGBml7miVRsWbY2HTpyGgfJI4UFOdQbfOumJYdzeIL8K7GjlStHYKWN11qA88P6aXnSddQml+2TGpt5nOJrRDnw0z+ix+8fKEwHRFIuuY+wFH654k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308683; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=oaXoNXJGzqj0flMKNXc/EwSXy3NvsIrv7XZcyMnIJ3M=; b=MWxTbMQNqerodeGQZFmfqrT8NPJeF0hHyO6iQNgIKWiKMawwPvAwoajLkfwzT4xGm2CrwvrMNJTxNbMMb1Ev39IU2+ZEaqwZIk7bQkmRu11B3EgYj4J+6l0mmTfznxtXTpu9FIjRSyGW5pVzIfkm6W+QR4nRfIVymSNNNDkHKJA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308683262165.9759756317926; Wed, 24 Jun 2026 06:44:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNsJ-0001GN-Dc; Wed, 24 Jun 2026 09:42:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNs2-0000zx-Ju; Wed, 24 Jun 2026 09:42:30 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNs0-0001vn-5L; Wed, 24 Jun 2026 09:42:25 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 9DD571BAA0E; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 3B1603DEA5D; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=ry6mtzO4AFtcMZbYpxL6+brjFsNbamMA5dDuVzUFZB8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ESgq6gTe3h2eD2gG4dWZy0rh4Bq1+LSGfU23zIZ+L9cl7MvB/HfEBDlOTjVbn1BqX RIc2QTUGrkolTwlhTOgzYvErPlVlpGUv4H192gHsEbn6khkZg+ab08sRfULDZTe/mI tpzrb0OUCNeKHZpquDQ3pYgSX08JZ6XT1hoF7CPWvgDVLaCFWCfQ13iG0fWA5NuKGw MLvxtdjtTQeF8nllE7St/eA4GPSoyPwrtWC7WTzulTJGeaR9YOul6+/Qe7J2wWbRj8 zTGCoahYaGM+883pCxkc415aIqeBhgQ5KXYTpd2Tg5a4HHpxhZo+P0iXk27CuQozoM iGSuksX4zg4wQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Daniel Henrique Barboza , Alistair Francis , Michael Tokarev Subject: [Stable-11.0.2 092/107] disas/riscv.c: fix inst_length() Date: Wed, 24 Jun 2026 16:31:37 +0300 Message-ID: <20260624133301.403266-92-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308683939158500 Content-Type: text/plain; charset="utf-8" From: Daniel Henrique Barboza inst_length() can return 0 if 'inst' happens to not match any known encoding (like [1]). Returning 0 is not desirable, even for unknown encodings, given that it will cause a loop in target_disas() later on. The most recent version of the RISC-V unpriv spec ditched the sophisticated instruction-length encoding. We're now supporting only 16-bit and 32-bit length instructions, where: "All the 32-bit instructions in the base ISA have their lowest two bits set to 11. The optional compressed 16-bit instruction-set extensions have their lowest two bits equal to 00, 01, or 10." So the code is now simpler, never returning 0, and in fact it's the same thing we're already doing in insn_len() from target/riscv/internals.h. Due to include shenarigans we can't use that function in disas/riscv.c, but I believe we can cut ourselves some slack this time and not lose sleep over a 1 line of duplicated logic. We're documenting it though! [1] https://gitlab.com/qemu-project/qemu/-/work_items/3479 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3479 Signed-off-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Message-ID: <20260527200355.2068879-2-daniel.barboza@oss.qualcomm.com> Signed-off-by: Alistair Francis (cherry picked from commit 758dce9c98af4f3ef26eada48a484a7d60258636) Signed-off-by: Michael Tokarev diff --git a/disas/riscv.c b/disas/riscv.c index 0ed8a3b5ed..5a61d1bb80 100644 --- a/disas/riscv.c +++ b/disas/riscv.c @@ -5083,26 +5083,10 @@ static bool check_constraints(rv_decode *dec, const= rvc_constraint *c) return true; } =20 -/* instruction length */ - +/* Same as insn_len() from target/riscv/internals.h */ static size_t inst_length(rv_inst inst) { - /* NOTE: supports maximum instruction size of 64-bits */ - - /* - * instruction length coding - * - * aa - 16 bit aa !=3D 11 - * bbb11 - 32 bit bbb !=3D 111 - * 011111 - 48 bit - * 0111111 - 64 bit - */ - - return (inst & 0b11) !=3D 0b11 ? 2 - : (inst & 0b11100) !=3D 0b11100 ? 4 - : (inst & 0b111111) =3D=3D 0b011111 ? 6 - : (inst & 0b1111111) =3D=3D 0b0111111 ? 8 - : 0; + return (inst & 3) =3D=3D 3 ? 4 : 2; } =20 /* format instruction */ --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308675; cv=none; d=zohomail.com; s=zohoarc; b=ZWiImpB3oaOQRVp7zLp5jVJMkDAAx9LkjBdzfZFMXqofXd8A+3COg11NHWD4LRP7G/mQOTRED13SPgOBJAZHnBB93YBkrn7nZa6flvMd4nwbe7mmFXdnlUBAhobaInPyl4P9YAlucWajgm4pIWpDzz4/ZPztjJxAgwkz8D+DhsI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308675; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=7h38FkuHOdktq3/fA9YutSQItJo8vpPcjgzF3ptuMKo=; b=DTnBkVEv9B9lHGuoO+W7McGr48lv0e99+FgsTqY62CwAI1xLegS+5IJnce4RsgDBKiIJPyjYkCeeCo6nOUpSEnybKk+EyQ1mJjwyVtr0d40Ajlh9QoDNJsUTj1MFWUFq0aQhhZ29VvwRD4qDyNs9rN+VXK1E12uBgq66mYv93fE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308675973331.06831471406997; Wed, 24 Jun 2026 06:44:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNsI-0001Dx-G4; Wed, 24 Jun 2026 09:42:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNs3-000100-Nn; Wed, 24 Jun 2026 09:42:30 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNs1-0001w4-Ha; Wed, 24 Jun 2026 09:42:27 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B77661BAA0F; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 49EA83DEA5E; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=r8gg0U3DYFSvCPdz+8ffEzJTMnzSG3354csObtAj96I=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ld38ZUW9bYf06RICJOR+PXDTuw+BJrWmD3T6E067Yv3/8WDxJ3XfZVfXxgzBIff+z PWatCW4TFshAZ+QEUVfRGRtw/kY5jOcqqtRshewGIELx4X8pv1jnEcT8pXWKA1g2mR cvPoIulB9SXnr9AMlIu/L9uwzlj1wLVsUmG7/5TxLWMQK+OMeTiVRL/ls4Uo3rMeNg b4rcwis3Co2cPboLNvg91CK5At4cK9vNyQ/O//d7s0HygNn2McMlpe0Swp1fJzUlCN a6iJOzSzPeXQ4urxvR9k9XXGdxcb536jmPTxVVIwmMO7z1LuDhDveXmDm219bHxYb7 Pj0dvoG5En0ng== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Abhigyan Kumar <314abh@gmail.com>, Alistair Francis , Daniel Henrique Barboza , Michael Tokarev Subject: [Stable-11.0.2 093/107] target/riscv: mask vxrm csrw write to the low 2 bits Date: Wed, 24 Jun 2026 16:31:38 +0300 Message-ID: <20260624133301.403266-93-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308677781158500 Content-Type: text/plain; charset="utf-8" From: Abhigyan Kumar <314abh@gmail.com> Citing the RISC-V specification: "The vector fixed-point rounding-mode register holds a two-bit read-write rounding-mode field in the least-significant bits (vxrm[1:0]). The upper bits, vxrm[XLEN-1:2], should be written as zeros." QEMU wrote full value into env->vxrm causing read of upper bits too. Used existing macros for bit-masking. Previous had a hard-coded value. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3470 Signed-off-by: Abhigyan Kumar <314abh@gmail.com> Reviewed-by: Alistair Francis Reviewed-by: Daniel Henrique Barboza Message-ID: <20260530102100.78150-1-314abh@gmail.com> Signed-off-by: Alistair Francis (cherry picked from commit 9f550a0b630672f4831d9115e66d208ed71cf252) Signed-off-by: Michael Tokarev diff --git a/target/riscv/csr.c b/target/riscv/csr.c index 78dd4e0070..60dba08b99 100644 --- a/target/riscv/csr.c +++ b/target/riscv/csr.c @@ -960,7 +960,7 @@ static RISCVException write_vxrm(CPURISCVState *env, in= t csrno, #if !defined(CONFIG_USER_ONLY) env->mstatus |=3D MSTATUS_VS; #endif - env->vxrm =3D val; + env->vxrm =3D val & (VCSR_VXRM >> VCSR_VXRM_SHIFT); return RISCV_EXCP_NONE; } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308942; cv=none; d=zohomail.com; s=zohoarc; b=JFCAlMg5q0jeh+QOsLZpPi+DuZBCG2pBsAAZwRr/j7tfuV3f3kDAbeu3i6ytXoE8yvnqtvd1TDu+t1LofSSvt9PJt72zWqHVbhXFm3le5YtuZ9UpSNVzWGlHQbSOIMVveYb5LGJ5dOG5vsLDOO5EYzrkp0bn4QMeJ9P9TFRWavU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308942; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9kp9OsCRI4BgURyQulupZQenpS9tJEAwGTKiEDmupJ4=; b=OBlUXqp1B7/oFUghV0arUqBD+kQ0s70nfifgCyVs1PHVaG4kLIXj0p2GYwO4UXl79VUtT4i+6e05Vx4bynt/hb/OJ4QMe5EMjQVuauSn3wlYKYrWLFen/fcbyJeGYBlkVtYvgHaTGbQLgGADUJhSTcrfrkfhG1hWf1N1BoAY7tE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308942380768.267099298725; Wed, 24 Jun 2026 06:49:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNsK-0001QN-JE; Wed, 24 Jun 2026 09:42:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNs5-00010Z-Eh; Wed, 24 Jun 2026 09:42:31 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNs4-0001y1-15; Wed, 24 Jun 2026 09:42:29 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id D3E491BAA10; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 63BB23DEA5F; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=XToyEyO85k0wvOXd+H658vKKXC4nhak7e7vcR3tu/po=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=qKrOa6/JrbVpytpjrAU+vJONSs0K58S5KvKWv2no431pQfgVln3O+VQAl3shcTl1t DZYt1++zabdHFxgwVH9FG7awdipNyphec+cnEM7mBvWt7mI9ruhdtNnac+UKeyCKzC L85qzezM7ew7BdERZcu6sJw6/rwBIdplhyUZnopN1D4Agd3LNP1Gqqqd+Js968hjaB NAhCd4SyxWmnqdYgyTOQB0k+2PCWnMaALxOW7cK0XDtn307P05N1PRIvaz0kQln9L3 vut9Q6ZeJouzCQlOvHlsSXOr12R2cPBIEtrIUPa2jtUK3eOyCQ7cSWs8WU5Wq73yX2 9Gik2kEQkTgGw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Gerd Hoffmann , Feifan Qian , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-11.0.2 094/107] hw/uefi: fix parse_hexstr Date: Wed, 24 Jun 2026 16:31:39 +0300 Message-ID: <20260624133301.403266-94-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308943935158500 From: Gerd Hoffmann Make sure we actually have two input characters available before going to parse two hex digits. Fixes one byte buffer overflow of the output buffer in case the input string has an odd number of characters. Fixes: CVE-2026-48915 Fixes: 12058948abdf ("hw/uefi: add var-service-json.c + qapi for NV vars.") Reported-by: Feifan Qian Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Gerd Hoffmann Message-ID: <20260526135948.599148-1-kraxel@redhat.com> (cherry picked from commit d6601a7e1c2452100ed7e4b1d74a70b9acc0abe6) Signed-off-by: Michael Tokarev diff --git a/hw/uefi/var-service-json.c b/hw/uefi/var-service-json.c index f5f1556833..8621b86c5c 100644 --- a/hw/uefi/var-service-json.c +++ b/hw/uefi/var-service-json.c @@ -98,7 +98,7 @@ static void parse_hexstr(void *dest, char *src, int len) uint8_t *data =3D dest; size_t i; =20 - for (i =3D 0; i < len; i +=3D 2) { + for (i =3D 0; i + 1 < len; i +=3D 2) { *(data++) =3D parse_hexchar(src[i]) << 4 | parse_hexchar(src[i + 1]); --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308893; cv=none; d=zohomail.com; s=zohoarc; b=BnxVTw7H5jEy31eQ67F/8i5FyBtz0GQ3xjeP3M5jfhKuYodlDjl+ipJ53+Nb31WwB0nkklokgl4Lz0MLn1NQx1O3zMe6pyf4AdQZofsI0XKn9oP3nEr3SUQCS6whh64NX12guzOjoMv3R72YdnJqeMb+c2Jv8coXIDuqNK9M3uk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308893; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VTg1YXS+3Ho+oI8JTC0UYJCYLLfUO1YqHR5z2MfjNPQ=; b=mbkil80SjyOj6cYjEtZL/o9QyFMwX/07Y4qq9vhTiWD0ujpHe0LZrUag52pWpaMeO5/9ROQLEPazwjVoJgMAf5auslUk6cLViKai1b/HXQx20HN3H9hbwvHmO6xUOf32uvybReuE2/SUJT8nC8PVjnS1x3Otw2mNWCFCu91oWX8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308893781823.7778749748729; Wed, 24 Jun 2026 06:48:13 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNsM-0001du-A5; Wed, 24 Jun 2026 09:42:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNs7-00010w-1j; Wed, 24 Jun 2026 09:42:31 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNs5-0001yD-4p; Wed, 24 Jun 2026 09:42:30 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id E1FDC1BAA11; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 801933DEA60; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=h9zV7rUphTw7kX5AsxS5PvVvjPl4MDSruwhLFemulHs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=urgck4hbgjBY4pVZExFRn6nU3jU2/+31QhHpwtZBaI0v0aEKZGltcQVUvNxvf+TDa C9hfpv+7EfY+rrPsg+QhiDTUOng9b/argty/Mbt4OH5q950ZsoUzBh5GBib3em/ZSc yDO7Bqmlt6HRbOHTa8DwxNE53/RJvYY15haEJDraOqwCJyDxqmaSrNUnPSzE62J+fN 2PXZJZoxMTz/QlzIusWqY+Mpwq4U+W9YXHK1xprZhY1Tl8aeRkmycBVA7QwSgRwnqg biHbqnyaXUI2aZEtnut9OJofjaEo152JpQCJNbW1t3pswZIgAdsQz1AJDkjkDMU+dM GZRVBt/XMcvow== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 095/107] target/i386: apply mod to immediate count of an RCL/RCR operation Date: Wed, 24 Jun 2026 16:31:40 +0300 Message-ID: <20260624133301.403266-95-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308895678158500 Content-Type: text/plain; charset="utf-8" From: Paolo Bonzini RCR and RCL instructions with a count of 9 are the same as if the count was 0, but they generated incorrect code because the can_be_zero flag is false. This causes 0 to underflow into -1 at tcg_gen_subi_tl(count, count, 1). Fix by absorbing the modulo computation into gen_shift_count(), now renamed gen_shift_count_1(), so that it can handle both reductions. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3452 Signed-off-by: Paolo Bonzini (cherry picked from commit e38d0afade7c134cd4d675f54d26c394cc3cc31f) Signed-off-by: Michael Tokarev diff --git a/target/i386/tcg/emit.c.inc b/target/i386/tcg/emit.c.inc index ce636b6c56..8eca66b696 100644 --- a/target/i386/tcg/emit.c.inc +++ b/target/i386/tcg/emit.c.inc @@ -3244,8 +3244,9 @@ static void gen_PUSHF(DisasContext *s, X86DecodedInsn= *decode) assume_cc_op(s, CC_OP_EFLAGS); } =20 -static MemOp gen_shift_count(DisasContext *s, X86DecodedInsn *decode, - bool *can_be_zero, TCGv *count, int unit) +static MemOp gen_shift_count_1(DisasContext *s, X86DecodedInsn *decode, + bool *can_be_zero, TCGv *count, int unit, + int mod) { MemOp ot =3D decode->op[0].ot; int mask =3D (ot <=3D MO_32 ? 0x1f : 0x3f); @@ -3255,16 +3256,31 @@ static MemOp gen_shift_count(DisasContext *s, X86De= codedInsn *decode, case X86_OP_INT: *count =3D tcg_temp_new(); tcg_gen_andi_tl(*count, cpu_regs[R_ECX], mask); + + if (mod < mask) { + TCGv temp =3D tcg_temp_new(); + assert(mod * 4 >=3D mask); + if (mod * 2 < mask) { + tcg_gen_subi_tl(temp, *count, mod * 2); + tcg_gen_movcond_tl(TCG_COND_GE, *count, temp, tcg_constant= _tl(0), temp, *count); + } + tcg_gen_subi_tl(temp, *count, mod); + tcg_gen_movcond_tl(TCG_COND_GE, *count, temp, tcg_constant_tl(= 0), temp, *count); + } *can_be_zero =3D true; break; =20 case X86_OP_IMM: - if ((decode->immediate & mask) =3D=3D 0) { + decode->immediate &=3D mask; + if (mod < mask) { + decode->immediate %=3D mod; + } + if (decode->immediate =3D=3D 0) { *count =3D NULL; break; } *count =3D tcg_temp_new(); - tcg_gen_movi_tl(*count, decode->immediate & mask); + tcg_gen_movi_tl(*count, decode->immediate); break; =20 case X86_OP_SKIP: @@ -3279,6 +3295,13 @@ static MemOp gen_shift_count(DisasContext *s, X86Dec= odedInsn *decode, return ot; } =20 +static MemOp gen_shift_count(DisasContext *s, X86DecodedInsn *decode, + bool *can_be_zero, TCGv *count, int unit) +{ + return gen_shift_count_1(s, decode, can_be_zero, count, unit, + INT_MAX); +} + /* * Compute existing flags in decode->cc_src, for gen_* functions that wants * to set the cc_op set to CC_OP_ADCOX. In particular, this allows rotate @@ -3397,29 +3420,14 @@ static void gen_rot_overflow(X86DecodedInsn *decode= , TCGv result, TCGv old, /* * RCx operations are invariant modulo 8*operand_size+1. For 8 and 16-bit= operands, * this is less than 0x1f (the mask applied by gen_shift_count) so reduce = further. + * FIXME: are flags updated if the count is nonzero, but a multiple of (8 = << op) + 1? */ -static void gen_rotc_mod(MemOp ot, TCGv count) +static MemOp gen_rotc_count(DisasContext *s, X86DecodedInsn *decode, + bool *can_be_zero, TCGv *count, int unit) { - TCGv temp; - - switch (ot) { - case MO_8: - temp =3D tcg_temp_new(); - tcg_gen_subi_tl(temp, count, 18); - tcg_gen_movcond_tl(TCG_COND_GE, count, temp, tcg_constant_tl(0), t= emp, count); - tcg_gen_subi_tl(temp, count, 9); - tcg_gen_movcond_tl(TCG_COND_GE, count, temp, tcg_constant_tl(0), t= emp, count); - break; - - case MO_16: - temp =3D tcg_temp_new(); - tcg_gen_subi_tl(temp, count, 17); - tcg_gen_movcond_tl(TCG_COND_GE, count, temp, tcg_constant_tl(0), t= emp, count); - break; - - default: - break; - } + MemOp ot =3D decode->op[0].ot; + return gen_shift_count_1(s, decode, can_be_zero, count, unit, + (8 << ot) + 1); } =20 /* @@ -3440,7 +3448,7 @@ static void gen_RCL(DisasContext *s, X86DecodedInsn *= decode) bool have_1bit_cin, can_be_zero; TCGv count; TCGLabel *zero_label =3D NULL; - MemOp ot =3D gen_shift_count(s, decode, &can_be_zero, &count, decode->= op[2].unit); + MemOp ot =3D gen_rotc_count(s, decode, &can_be_zero, &count, decode->o= p[2].unit); TCGv low, high, low_count; =20 if (!count) { @@ -3451,7 +3459,6 @@ static void gen_RCL(DisasContext *s, X86DecodedInsn *= decode) high =3D tcg_temp_new(); low_count =3D tcg_temp_new(); =20 - gen_rotc_mod(ot, count); have_1bit_cin =3D gen_eflags_adcox(s, decode, true, can_be_zero); if (can_be_zero) { zero_label =3D gen_new_label(); @@ -3492,7 +3499,7 @@ static void gen_RCR(DisasContext *s, X86DecodedInsn *= decode) bool have_1bit_cin, can_be_zero; TCGv count; TCGLabel *zero_label =3D NULL; - MemOp ot =3D gen_shift_count(s, decode, &can_be_zero, &count, decode->= op[2].unit); + MemOp ot =3D gen_rotc_count(s, decode, &can_be_zero, &count, decode->o= p[2].unit); TCGv low, high, high_count; =20 if (!count) { @@ -3503,7 +3510,6 @@ static void gen_RCR(DisasContext *s, X86DecodedInsn *= decode) high =3D tcg_temp_new(); high_count =3D tcg_temp_new(); =20 - gen_rotc_mod(ot, count); have_1bit_cin =3D gen_eflags_adcox(s, decode, true, can_be_zero); if (can_be_zero) { zero_label =3D gen_new_label(); --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308615; cv=none; d=zohomail.com; s=zohoarc; b=ksA7X0KoqifvrSNvHo+vD6DsgOomAc+Uxoqm2erW24rEdZJBAfbOXKf+IPHObvhr5WLunvIv8wpfVC/Eh2q3S1l1edXxbp/GyU+Kp6bU3YamKu3O4Wiea0F8XycaC4aX858EV92BkGxCqwa7w+MaeptfhMWceR+7V3W6q+MAN7M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308615; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lLgRkNdvFfsKKBNBVLLYpfvSwIH6IwOUzTDLw/mq0X4=; b=KrSdLQUFf0zrIvK2W1yzO4UK7W7CLWA9SK3xX7h4UjUELKXkz8MvTGt5v5zlgFBEBiemfatdokLyAoaVX+uBzKHVg5DKzGoRSJ9lxtRrvIa7v2ny6SOEqBrg/Utv8nvbGpC4guLypP9XdTZrQMhTk5vrDI99kz9FrANCsfDK9m8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308615812746.6501813241172; Wed, 24 Jun 2026 06:43:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNsX-0002X3-2A; Wed, 24 Jun 2026 09:42:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsS-0002P0-Oh; Wed, 24 Jun 2026 09:42:53 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsQ-0001yT-S3; Wed, 24 Jun 2026 09:42:52 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id F19AC1BAA12; Wed, 24 Jun 2026 16:33:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 8E5B93DEA61; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308001; bh=BizYKPonuqh83YxKZA002CnSJeSjU0Wy/O3qLhenGNE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=m/0GJn5YTG+8aEheE2A2T2sgRJyFJG6ClEZn9TbEeAHKZvWh/9qX30n8PfNwSxXUQ BARDbC0CyEG/S6llBK/amqMHcYeP5+bIJr/gpjfAixp+PHBIRiLHPTAaaETeGpEn4o U5Ne3kqivObOAJ+ub6WvWT8Khwil7NmkXf9fUIw4wjT52BXcW6yESBOf4EhPaC61Av yAy771nMrS16w+HyVj7hyamCW9+bHPQQpj+NGVOIcUT/K+D3WP5s1m5Z62sBzovt2p kokFJlw4cECrdF2MEZkwvwWRdeD9O6aVWN9Rocx9csxtBuOnNJSpNdYOw+R5/QO5l7 dKEZHeiz9dN0g== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Mathias Krause , Paolo Bonzini , Michael Tokarev Subject: [Stable-11.0.2 096/107] gdbstub: Update x86 control register bits Date: Wed, 24 Jun 2026 16:31:41 +0300 Message-ID: <20260624133301.403266-96-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308617441158500 Content-Type: text/plain; charset="utf-8" From: Mathias Krause The control register bits haven't been updated in a few years, making them lack behind features QEMU ganied in these years. Update them to the current version of the SDM and sort the 32bit version to be in line with all the other definitions (descending order). This should remove confusion when debugging, for example, CET-enabled guests: - before the change: (gdb) info registers cr4 cr4 0x8000f0 [ PGE MCE PAE PSE ] - after the change: (gdb) info registers cr4 cr4 0x8000f0 [ CET PGE MCE PAE PSE ] Signed-off-by: Mathias Krause Link: https://lore.kernel.org/r/20260327143413.254227-1-minipli@grsecurity.= net Signed-off-by: Paolo Bonzini (cherry picked from commit 88d39a2937ebad64b8aed8247450e1a6ddf274be) Signed-off-by: Michael Tokarev diff --git a/gdbstub/gdb-xml/i386-32bit.xml b/gdbstub/gdb-xml/i386-32bit.xml index 7a66a02b67..1dec40e1d2 100644 --- a/gdbstub/gdb-xml/i386-32bit.xml +++ b/gdbstub/gdb-xml/i386-32bit.xml @@ -87,27 +87,34 @@ =20 - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + + + + + + + + + + =20 diff --git a/gdbstub/gdb-xml/i386-64bit.xml b/gdbstub/gdb-xml/i386-64bit.xml index 6d88969211..9ac9164e6a 100644 --- a/gdbstub/gdb-xml/i386-64bit.xml +++ b/gdbstub/gdb-xml/i386-64bit.xml @@ -102,9 +102,16 @@ =20 + + + + + + + --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308928; cv=none; d=zohomail.com; s=zohoarc; b=A4gIpZYerqIGp5T5tUNDlLUCGHfF+XB9VOY/3ERG2LqlNbFeZPWXK630UbIIGst+A8RFMNFh53H/AbZFf6/rAr9e4OoQEiEKXCcxNBLW+pRdBmRg4USFyQjkyluxWtHhrUIRlsLWZUE/w/PAjYYN9rC90SlXw05vxHockshZ2pg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308928; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=5xmzdGWKWdUjvmzezbRQ3rrUbhuMkDAzLlRtU4sVOe0=; b=ZjFoaoIdz0lNESJnNe/oDejemfq1vtxJ4eehrBgMqaupXOE1NUif3nDtcs1VYkfuH5Ke9g23+EsI/JJQXgY4ZyCsNM4EJjN2vxZ6HuJV5X6TXCHWunegGlKCFGup/Ae8GRgE1oYUZEIKP9iQFMFgtC6ptdr9PPprqwsP9DR0Xwo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308928181479.552057305786; Wed, 24 Jun 2026 06:48:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNsZ-0002hU-CA; Wed, 24 Jun 2026 09:42:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsU-0002Ur-3p; Wed, 24 Jun 2026 09:42:55 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsS-0001yi-Gx; Wed, 24 Jun 2026 09:42:53 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 0C6E71BAA13; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 9DD3C3DEA62; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308002; bh=p+RgyZqfzzH9Uz8MgHjT6tgAT1pxWyGGGjt9gn2iJzo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=krqdC1BEp7KD+VzpCKTB0l/8I80IC2vTaSKDaUqlETEkD2rvTmZvlutVdXtTZkbpB SquXIvCzQj0IRKMUhXCYjhRjZHiQuvvxQLu38nteQhFHSNyb27J1tMC6hC2WeCOokJ gi+z3Z9gDQb9RR9vku2FtBtyafwDXK4p6thP0S5hAtpkwXkgD8P52hRU1EAQHtQ3nP pN6yMDEVvv1IlfMmSbu6zxSMJBsC8TrPw5gaSeYUhc7puo596Gtb3Tv1PLOchZrxmI PAX386GpFbs4aNB8MtIrdDuh4XEpnRMDfn2zAyh0LAsqNPeEfYQ/pvfwDzPhbxmKZe 9rD91kIeH1kmA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Feifan Qian , Michael Tokarev Subject: [Stable-11.0.2 097/107] hw/9pfs: fix abort due to illegal name with Twstat rename Date: Wed, 24 Jun 2026 16:31:42 +0300 Message-ID: <20260624133301.403266-97-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308929865158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck The legacy Twstat 9p request can be used to rename files and directories. Unlike the other, more recent rename requests like Trename and Trenameat, Twstat does not validate the submitted new name before passing it to v9fs_complete_rename(). A priviliged guest user with direct communication access to 9p server could pass a string containing '/' as new name, which causes an assertion fault (DoS) in local_name_to_path(). Fix this by rejecting such strings by checking the client supplied new name with name_is_illegal(), similar to how Trename and Trenameat handlers do already. Reported-by: Feifan Qian Fixes: 8cf89e007a ("virtio-9p: Add P9_TWSTAT support") Link: https://lore.kernel.org/qemu-devel/ba09716828e82992f9d8cac7f00eee0bc1= c43c61.1780072238.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 7f5445e7e4050cc117ed4b137bb7dd1474e49d57) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index b4314d2549..f84698bfcc 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -3638,6 +3638,11 @@ static void coroutine_fn v9fs_wstat(void *opaque) err =3D -EOPNOTSUPP; goto out; } + if (name_is_illegal(v9stat.name.data)) { + err =3D -ENOENT; + goto out; + } + v9fs_path_write_lock(s); err =3D v9fs_complete_rename(pdu, fidp, -1, &v9stat.name); v9fs_path_unlock(s); --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308943; cv=none; d=zohomail.com; s=zohoarc; b=hG5Ky6Bkphz/Xz17ujKqnBHH73LKpvAL3bSv6n+EzvnnV4ePz8Db0/Z4I3RIoaYlIIuU4n00gRhydkRV75eKOzBstsDUHVEkQ/a2zDQKQnLk7WwxvX9UkgP9XgkSj4GIl1EvaF9l95NjlRQ+8e4Jsn1iunTzUkKccpzoBpylVNg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308943; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=PTB9rEjQ12JpFXDeY0qebHla/k6ny00VxPEspjAbIZk=; b=Ghkp2WQu2+I3Hc7xCbWTVwYwlVZVaAwLWghbniHuVokGWsd1rTh7QFf2jTrJHLBPuP61gSZNbhIO0gg1L8Y854WjyAYLRmRSuFnsoeZe7TQJgFWqJdHewG3dPbo7mOwfuB6FAcUWyvMGpRY0csd43IUwmA+kEXIx5icv4xTji4c= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308943339124.5014889456279; Wed, 24 Jun 2026 06:49:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNsb-0002mq-OI; Wed, 24 Jun 2026 09:43:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsV-0002Yk-OT; Wed, 24 Jun 2026 09:42:55 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsU-00021l-6P; Wed, 24 Jun 2026 09:42:55 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 19B2E1BAA14; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id AC9853DEA63; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308002; bh=J0rHM6wTNz+A/ze9gmNWyp+H/Vifrhgz0ISNPvz8rK8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=heOqvoPx2LM7KYkkgfuqSJi8Fw20cRZIbPIaxMNTfcp1/pB81FA9UD1ImklCJCnoX eVx/ic3pOOcAo9T5IKsoNoKNSxZh91/LMTBPFQw8/K3UnTaiJXKpFU++JGTB3+gali SZLHtWa6RH/idFEqa0LPz0JkVOrQ7Dcp02vne5PHI4a+zYRBcWDi4mpffP1MB0f4HB EmuyikTd1fyvaCDzIwDfiLm0lNxy+rirHbqfgt+BNOv4u9H/t0N0+PVUjjskbh3xH7 CK7k4wQmkzDIl6l5j5LDOK75p3bHkjGZpC/wD9gfmwrFgm1CNkpN/6KRvYsZFyypK7 W7N91JUTBOsTA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Christian Schoenebeck , Michael Tokarev Subject: [Stable-11.0.2 098/107] hw/9pfs: reject . and .. in Twstat rename Date: Wed, 24 Jun 2026 16:31:43 +0300 Message-ID: <20260624133301.403266-98-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308943940158500 Content-Type: text/plain; charset="utf-8" From: Christian Schoenebeck The other Trename and Trenameat handlers already reject "." and ".." as new name on rename requests by returning -EISDIR in this case. The legacy Twstat rename handler is missing this validation. While passing "." or ".." does not trigger a crash as fixed by the previous patch (since the fs backend driver's system calls handle these gracefully), it creates a behavioral inconsistency, as it is semantically meaningless to rename a file to a directory reference in the first place. Fix this by rejecting "." and ".." in Twstat rename handler with -EISDIR to match behavior of Trename and Trenameat handlers. Fixes: 8cf89e007a ("virtio-9p: Add P9_TWSTAT support") Link: https://lore.kernel.org/qemu-devel/662333331d371c6c343c8091161de8eaa1= 21880e.1780072238.git.qemu_oss@crudebyte.com Signed-off-by: Christian Schoenebeck (cherry picked from commit 08750e31fcdccf5352dc3b44475ed5ba6bc80221) Signed-off-by: Michael Tokarev diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index f84698bfcc..936e4e9349 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -3642,6 +3642,10 @@ static void coroutine_fn v9fs_wstat(void *opaque) err =3D -ENOENT; goto out; } + if (!strcmp(".", v9stat.name.data) || !strcmp("..", v9stat.name.da= ta)) { + err =3D -EISDIR; + goto out; + } =20 v9fs_path_write_lock(s); err =3D v9fs_complete_rename(pdu, fidp, -1, &v9stat.name); --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308884; cv=none; d=zohomail.com; s=zohoarc; b=G3WDkqhV6fJkRVfPPF8lhnViQIE6m3hM039NlcCSPPmMOmU/Zw/Bkm/gF/B/MBHxDr5DIjjDGiV1hDwMSIPhSGuPFCc9HRUMwhI8Q6nKCp8GOpD6V68RukNsb5F0WkYCxn3yVijPrn2JFgn1zi8wj3+a9LH+MliJbW3hSFEOhCc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308884; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4UTStD5prUpL+AWEBrzH+oxL5vZ+kB8F+6YgDfMDLGo=; b=TMyD4OVjZU1T0HbKwSqUF53IEi9RoXcuMMLlkFOReX2hwnpO9PxdYKTmwPF+mrblk841sKRIAhEkWUKQU8HnenqNZQLAo3rDryOcWxRzFizqtnEvxIhMS4y/z75+3T7OyjWo6sxWitkner++xEEUNimaNchEWu045lYYGJ51ECs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308884774699.2501179225593; Wed, 24 Jun 2026 06:48:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNsq-0002wc-7T; Wed, 24 Jun 2026 09:43:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsX-0002dM-8O; Wed, 24 Jun 2026 09:42:57 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsV-000221-Fd; Wed, 24 Jun 2026 09:42:56 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 290201BAA15; Wed, 24 Jun 2026 16:33:22 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id BA22F3DEA64; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308002; bh=UionjM9okuVr30pX3e19TeiANShrLy3DkF/YO9W4QMI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=DaFF0XkaT/qq4zb2Ie8MJV04OdrfQSKtAo2+jCILPlGUwOdr17O8mZkQXgRzklGjp MLqxJ7VaTHCVfYJ8dhS0pSqGHZ4h+kfRQjH6ET9WXagoYpMm/DmxHm032rBzs40mto /Q149K97NUhE+YFdIlbRViIKCA7ROpgYfuSaiIqAojPxwrcrnlWt9Rly1QkANo1Z+/ hDU4Mq5TRZeK1TUakg8xwya7NhMJZPYXG/tBjAY8rjlzFOp0kTRBu+Vx2WzZlKATdi Zul1lGQXqLluCYezq9kcHFuQ5gpy402xJEq35RUVrwy26jja+/WuxFdi8g5GskBwn5 Y41fjoRfAwLbA== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Akihiko Odaki , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 099/107] ui/sdl2: Explicitly specify EGL platform Date: Wed, 24 Jun 2026 16:31:44 +0300 Message-ID: <20260624133301.403266-99-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308885886158500 From: Akihiko Odaki Mesa's eglGetDisplay() chooses the native EGL platform from EGL_PLATFORM, limited autodetection, or the build-time default. If that selects Wayland while SDL is using the X11 video backend, Mesa can treat the X11 Display pointer as a wl_display and crash during eglInitialize(). Probe EGL with the X11 platform explicitly before enabling SDL_HINT_VIDEO_X11_FORCE_EGL. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3540 Signed-off-by: Akihiko Odaki Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260611-sdl-v1-1-93d4a51684bb@rsg.ci.i.u-tokyo.ac.jp> (cherry picked from commit 6157908503f9a5a14d17a8ecf8cc3308107e1458) Signed-off-by: Michael Tokarev diff --git a/include/ui/egl-helpers.h b/include/ui/egl-helpers.h index acf993fcf5..c97a0d5c24 100644 --- a/include/ui/egl-helpers.h +++ b/include/ui/egl-helpers.h @@ -61,6 +61,11 @@ void egl_dmabuf_create_fence(QemuDmaBuf *dmabuf); =20 EGLSurface qemu_egl_init_surface_x11(EGLContext ectx, EGLNativeWindowType = win); =20 +#if defined(CONFIG_X11) || defined(CONFIG_GBM) || defined(WIN32) +EGLDisplay qemu_egl_get_display(EGLNativeDisplayType native, + EGLenum platform); +#endif + #if defined(CONFIG_X11) || defined(CONFIG_GBM) =20 int qemu_egl_init_dpy_x11(EGLNativeDisplayType dpy, DisplayGLMode mode); diff --git a/ui/egl-helpers.c b/ui/egl-helpers.c index e3f2872cc1..069a524955 100644 --- a/ui/egl-helpers.c +++ b/ui/egl-helpers.c @@ -520,8 +520,8 @@ EGLSurface qemu_egl_init_surface_x11(EGLContext ectx, E= GLNativeWindowType win) * platform extensions (EGL_KHR_platform_gbm and friends) yet it doesn't s= eem * like mesa will be able to advertise these (even though it can do EGL 1.= 5). */ -static EGLDisplay qemu_egl_get_display(EGLNativeDisplayType native, - EGLenum platform) +EGLDisplay qemu_egl_get_display(EGLNativeDisplayType native, + EGLenum platform) { EGLDisplay dpy =3D EGL_NO_DISPLAY; =20 diff --git a/ui/sdl2.c b/ui/sdl2.c index 987ad334bb..9dd5e305e1 100644 --- a/ui/sdl2.c +++ b/ui/sdl2.c @@ -862,7 +862,8 @@ static void sdl2_set_hint_x11_force_egl(void) } =20 /* Prefer EGL over GLX to get dma-buf support. */ - egl_display =3D eglGetDisplay((EGLNativeDisplayType)x_disp); + egl_display =3D qemu_egl_get_display((EGLNativeDisplayType)x_disp, + EGL_PLATFORM_X11_KHR); =20 if (egl_display !=3D EGL_NO_DISPLAY) { /* --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308651; cv=none; d=zohomail.com; s=zohoarc; b=G6BHWrW1Po8vbhOmpz0xtMEEHQz9oYEXuijGlaAHFLZnvDOJdYBnJD3FTAZL9R7ehRJOQYz/FM3cyBv19nVsZ6dNk4W8fpkCVfTvZJllmB3X1sDZ1Hbq6Bd77rZdP1NiZWpuKyWmVGNMdmWB69ZOnE63Odbrfr8W6XvcsCxsm44= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308651; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=UMI2Yjih9nmXIOBtCZxXYd8rRnF3hmDfZiM5gVXrrNM=; b=S1CpjHCb630hfFnYMBdiouQYlbMKqj6seQcmdteVLN8Nlh4PJaneYd9PaZ9p1rwk/vBLexzW5eP1zAjjB3+C+ferUNqPJsljOfxnOIY6V+uCeKhJkLFnMdXSwxx1zAoWJKA86G+jOk3viY7W7lNANgpyVsBRgL34FNqMn+VSuuQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308651535868.3679962004926; Wed, 24 Jun 2026 06:44:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNsz-0003Fg-En; Wed, 24 Jun 2026 09:43:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsY-0002k7-VS; Wed, 24 Jun 2026 09:42:59 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsX-00022L-Ar; Wed, 24 Jun 2026 09:42:58 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 195261BAA16; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id A7F213DEA65; Wed, 24 Jun 2026 16:33:32 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308007; bh=iazvMrVmZE5ISJAL7v7sv9o2wPrqoCv21izsEMeF+OI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=bxNUFsQldQSRhp7H4ont1OUDg5eVnGTP4la5WTAqItvdNOrk8QN9jL1NPAE/vfEtd m/pUGVQVs6vlfAbg071F3nVMce2gqteu2UCuX6HljQ38Ls+QJNQ/jLKJ93bvhrk8dF uTZOLOTyudDUchF6wdGrivcsLueBdd/wIXP6K7zZn1kWhSetQNLLTvzyOrIc3vwqLn U0XK8Y96Y8glN8Sb+ag8QKGReg4hJ+M8+SjDBYGSqybHrBQYxNz8RkXZqdZcx4t0e8 nVva9FT4G6HyhQLvhVERC2hdo99CY+h9D/UzQFEenOCqn3rtIoBK+D1D5kULcWrB7F 0IC3W7pCXQsvg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Ryan Zhang , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Michael Tokarev Subject: [Stable-11.0.2 100/107] ui/sdl2: Set GL ES profile before creating initial GL context Date: Wed, 24 Jun 2026 16:31:45 +0300 Message-ID: <20260624133301.403266-100-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308653627158500 From: Ryan Zhang When the user selects GLES via '-display sdl,gl=3Des', we need to set SDL_GL_CONTEXT_PROFILE_MASK to SDL_GL_CONTEXT_PROFILE_ES before calling SDL_GL_CreateContext(). This ensures SDL_GL_LoadLibrary() loads the correct GLES driver instead of the desktop OpenGL driver. Fix the below issue: qemu-system-aarch64: /usr/src/debug/libepoxy /1.5.10/src/dispatch_common.c:872: epoxy_get_proc_address: Assertion `0 && "Couldn't find current GLX or EGL context.\n"' failed. sdl2_gl_create_context() already sets the profile mask correctly for ES mode, but the initial context created in sdl2_window_create() is missing the same treatment. Fixes:da3f7a3ab9ea0091955b58f8909dfcee01f4043e ("ui/sdl: try to instantiate= the matching opengl renderer") Signed-off-by: ryan.zhang@nxp.com Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: (cherry picked from commit 490a3e1867f025c68fa13db766b5c8da16c6eca4) Signed-off-by: Michael Tokarev diff --git a/ui/sdl2.c b/ui/sdl2.c index 9dd5e305e1..eccc5b0e90 100644 --- a/ui/sdl2.c +++ b/ui/sdl2.c @@ -113,6 +113,8 @@ void sdl2_window_create(struct sdl2_console *scon) =20 if (scon->opts->gl =3D=3D DISPLAY_GL_MODE_ES) { driver =3D "opengles2"; + SDL_GL_SetAttribute(SDL_GL_CONTEXT_PROFILE_MASK, + SDL_GL_CONTEXT_PROFILE_ES); } =20 SDL_SetHint(SDL_HINT_RENDER_DRIVER, driver); --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308659; cv=none; d=zohomail.com; s=zohoarc; b=Wi6hml5b+j73Di5pUfdBhYNhLQKiMCEseL0OECJQtsAB6wZm8T26M6j7tUffa1VIJnTeUFbY2/QQxeCFoEhf7lDL+RVIUo1ZHeDHG6aP4BwB+RMWBCyHDg8cayrInGFjaatwR24J8/UtaeweOuUegHNFdfHqXsyc7Ry7hnhY4eA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308659; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9N1rErj015lzuQPHviFbndfPTsQOiSanH+mvL+IdG60=; b=T7RxnNSyTrDedtqmVDi/6Hm8ih5ps2Sy4VfyAfzpEurug84kZZVPCkNlnVQ/r/wIXDvgB7wXRvT7IbbZWlGpUW7fCMqejlMImUShpM1LAjAzUfyvJ65l5NwC4+R16/JpQW2u5iM3gQuHe8uryrgZ8WbHzrO59llll1TJFVQpUGs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308659182913.7139871341291; Wed, 24 Jun 2026 06:44:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNt0-0003ZS-SS; Wed, 24 Jun 2026 09:43:27 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsu-00034E-5a; Wed, 24 Jun 2026 09:43:20 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNss-00022d-MQ; Wed, 24 Jun 2026 09:43:19 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 264F51BAA17; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id B63353DEA66; Wed, 24 Jun 2026 16:33:32 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308007; bh=PHq0ridNjf1XruU6OjfEWU58yBhDM9HHaSZ10WkIeSU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=RwxxOeRqym5nAqwj30S5eLZK6sn4PkEujDhi8iOEELbi0+y2Ev7F7KyyajAwouLE6 nknXV9fUxvKv90zUvXZZQ70wb3gAXcYHPGC3ngROkNrE1sdJB08MshiPQlqewrNJ7d EOmR/F42HK6+kGigw8LbH70R2G3Znmv+TPQ7Cqs6iynKAvf9wpEO3/6h0WWnI/YKS/ DXRnLR2lrxjRezhUUFKggzIm0nmTUhXFzT2qWrBj/jxsEaenOU1wHgrASlzjMKGzXF JU5X1vv012N8tYEDKAeSuDr5vG7BqA+0OnrjebaTlbAmlWVmLthEGTu1F4B2veVS7J AFUUtnTmHyQdw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, "Scott J. Goldman" , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Michael Tokarev Subject: [Stable-11.0.2 101/107] target/arm/hvf: Stop pre-allocating cpreg_vmstate arrays Date: Wed, 24 Jun 2026 16:31:46 +0300 Message-ID: <20260624133301.403266-101-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308659690158500 From: "Scott J. Goldman" Commit ab2ddc7b66 ("target/arm/machine: Use VMSTATE_VARRAY_INT32_ALLOC for cpreg arrays") moved cpreg_vmstate_indexes / cpreg_vmstate_values to be allocated by VMSTATE_VARRAY_INT32_ALLOC and added an assertion in cpu_pre_load() that they are NULL on entry. The same commit dropped the redundant g_renew()/array_len assignments from the kvm, whpx and helper.c cpu init paths, but the hvf cpu init path still pre-allocates them. The result is that loading a snapshot or migration stream into an HVF guest immediately aborts: ERROR:target/arm/machine.c:1043:cpu_pre_load: assertion failed: (!cpu->cpreg_vmstate_indexes) Drop the leftover cpreg_vmstate_indexes / cpreg_vmstate_values allocations and the cpreg_vmstate_array_len assignment from hvf_arch_init_vcpu(), matching what was already done for the other arm accelerators. Signed-off-by: Scott J. Goldman Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Peter Maydell (cherry picked from commit 06fd39e426bbd3a68e50fc847892e7448174ce2f) Signed-off-by: Michael Tokarev diff --git a/target/arm/hvf/hvf.c b/target/arm/hvf/hvf.c index 5016783062..d8bc85f279 100644 --- a/target/arm/hvf/hvf.c +++ b/target/arm/hvf/hvf.c @@ -1288,12 +1288,6 @@ int hvf_arch_init_vcpu(CPUState *cpu) sregs_match_len); arm_cpu->cpreg_values =3D g_renew(uint64_t, arm_cpu->cpreg_values, sregs_match_len); - arm_cpu->cpreg_vmstate_indexes =3D g_renew(uint64_t, - arm_cpu->cpreg_vmstate_indexe= s, - sregs_match_len); - arm_cpu->cpreg_vmstate_values =3D g_renew(uint64_t, - arm_cpu->cpreg_vmstate_values, - sregs_match_len); =20 memset(arm_cpu->cpreg_values, 0, sregs_match_len * sizeof(uint64_t)); =20 @@ -1330,7 +1324,6 @@ int hvf_arch_init_vcpu(CPUState *cpu) } } arm_cpu->cpreg_array_len =3D sregs_cnt; - arm_cpu->cpreg_vmstate_array_len =3D sregs_cnt; =20 /* cpreg tuples must be in strictly ascending order */ qsort(arm_cpu->cpreg_indexes, sregs_cnt, sizeof(uint64_t), compare_u64= ); --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308929; cv=none; d=zohomail.com; s=zohoarc; b=G6ZawLcD7ZrQA0//1qqKNqiC6oUnrRq/YOqpjdpd0MD0okgH9/5kiL6Xbcv0f6Mn7dDUNo17cUlsKfHmfMD01DXcuwLSAI9NPZVRZluY23VM+PZU7jvspD5uZxmbnzL67xN8JpWZlDpJgYOEsjImFoEblsLGT+kH71rxtW1j7Z0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308929; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=pMqcIqeETN6XStacinzrqxXhC7r22cqpvsN0GJBELNU=; b=Nq6x5/hHSD4P0NDg8UbNim6CSIQTrIeCAr6cpXVGRM+mntsmra09kfImixFvCwP2u77H/VF9+JSuJh7GDMCGXn8x2W1btBTLBO+OWX3aqWMdaYNbJAszdyEkqr32n4CTM6dd1CUjE42WXiBPooZ7CRgvtGGZcOv2cMtepweCvJc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308929558633.3798099514536; Wed, 24 Jun 2026 06:48:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNt2-0003jM-MS; Wed, 24 Jun 2026 09:43:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsw-00037I-KD; Wed, 24 Jun 2026 09:43:23 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsu-00022w-NW; Wed, 24 Jun 2026 09:43:22 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 35ECA1BAA18; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id C71473DEA67; Wed, 24 Jun 2026 16:33:32 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308007; bh=wjkwm/YElTmVmb2fMrsoqfIHt476Avlk2JWVfCZUdEQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Xg0Xgs1c89TJsoF+BCxuO26M2G8QHqCOI9tqyv2XBCZhjF/2H5MzMPh57P94uH8qA 3Ha4Y36xaSi5CDxy/wrSDV4sS2iE0TyniRJ9zaNxykoWoNJqClvtFUoDTnyE9v+QK6 BpgMo8clxPdjoLXyLK7jRKnpTdwmHP2aJonYQH268jN/TTR/SbqKgsu+0UPtwgDVpA ltmFCWpPxKhpfpSJi12wazH8GhaOzyqFzxr6eNb/xnQaG3Rhm1q2seWnxYb7AO1QkJ U+2rxLmXNxtP3LkbJ4bWBWnf1KZAo/DcwG+zeBgGAqCHdIYHm9P9lnNk64OvwONvG0 2+5XWaclsaxtw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 102/107] target/xtensa: add cpu_set_fcr/fsr helpers to sync fp_status Date: Wed, 24 Jun 2026 16:31:47 +0300 Message-ID: <20260624133301.403266-102-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308929833158500 From: Matt Turner Factor FCR=E2=86=92fp_status and FSR=E2=86=92fp_status synchronisation out = of the wur_fpu{2k,}_fcr/wur_fpu_fsr helpers into cpu_set_fcr(), cpu_set_fsr(), and cpu_get_fsr(). Signal delivery code needs to restore the FP rounding mode and exception flags without duplicating the flag-mapping tables. cpu_set_fcr() applies the union mask 0xfffff07f (superset of the wur_fpu_fcr mask 0x0000007f and the wur_fpu2k_fcr mask 0xfffff07f) so that FCR bits valid only on fpu2k configs are preserved while MBZ bits 7-11 are always cleared. Signed-off-by: Matt Turner Reviewed-by: Richard Henderson Signed-off-by: Helge Deller (cherry picked from commit 7e859bacea09a626c239f14ab9c01f13d5225723) Signed-off-by: Michael Tokarev diff --git a/target/xtensa/cpu.h b/target/xtensa/cpu.h index 2219292484..68effb44de 100644 --- a/target/xtensa/cpu.h +++ b/target/xtensa/cpu.h @@ -643,6 +643,10 @@ static inline void xtensa_select_static_vectors(CPUXte= nsaState *env, } void xtensa_runstall(CPUXtensaState *env, bool runstall); =20 +uint32_t cpu_get_fsr(CPUXtensaState *env); +void cpu_set_fcr(CPUXtensaState *env, uint32_t v); +void cpu_set_fsr(CPUXtensaState *env, uint32_t v); + #define XTENSA_OPTION_BIT(opt) (((uint64_t)1) << (opt)) #define XTENSA_OPTION_ALL (~(uint64_t)0) =20 diff --git a/target/xtensa/fpu_helper.c b/target/xtensa/fpu_helper.c index 5358060c50..2e51cabe3f 100644 --- a/target/xtensa/fpu_helper.c +++ b/target/xtensa/fpu_helper.c @@ -64,46 +64,39 @@ void xtensa_use_first_nan(CPUXtensaState *env, bool use= _first) &env->fp_status); } =20 -void HELPER(wur_fpu2k_fcr)(CPUXtensaState *env, uint32_t v) +uint32_t cpu_get_fsr(CPUXtensaState *env) { - static const int rounding_mode[] =3D { - float_round_nearest_even, - float_round_to_zero, - float_round_up, - float_round_down, - }; + uint32_t flags =3D 0; + int fef =3D get_float_exception_flags(&env->fp_status); + unsigned i; =20 - env->uregs[FCR] =3D v & 0xfffff07f; - set_float_rounding_mode(rounding_mode[v & 3], &env->fp_status); + for (i =3D 0; i < ARRAY_SIZE(xtensa_fp_flag_map); ++i) { + if (fef & xtensa_fp_flag_map[i].softfloat_fp_flag) { + flags |=3D xtensa_fp_flag_map[i].xtensa_fp_flag; + } + } + return flags << XTENSA_FSR_FLAGS_SHIFT; } =20 -void HELPER(wur_fpu_fcr)(CPUXtensaState *env, uint32_t v) +void cpu_set_fcr(CPUXtensaState *env, uint32_t v) { - static const int rounding_mode[] =3D { + static const FloatRoundMode rounding_mode[] =3D { float_round_nearest_even, float_round_to_zero, float_round_up, float_round_down, }; =20 - if (v & 0xfffff000) { - qemu_log_mask(LOG_GUEST_ERROR, - "MBZ field of FCR is written non-zero: %08x\n", v); - } - env->uregs[FCR] =3D v & 0x0000007f; + env->uregs[FCR] =3D v & 0xfffff07f; set_float_rounding_mode(rounding_mode[v & 3], &env->fp_status); } =20 -void HELPER(wur_fpu_fsr)(CPUXtensaState *env, uint32_t v) +void cpu_set_fsr(CPUXtensaState *env, uint32_t v) { uint32_t flags =3D v >> XTENSA_FSR_FLAGS_SHIFT; int fef =3D 0; unsigned i; =20 - if (v & 0xfffff000) { - qemu_log_mask(LOG_GUEST_ERROR, - "MBZ field of FSR is written non-zero: %08x\n", v); - } env->uregs[FSR] =3D v & 0x00000f80; for (i =3D 0; i < ARRAY_SIZE(xtensa_fp_flag_map); ++i) { if (flags & xtensa_fp_flag_map[i].xtensa_fp_flag) { @@ -113,19 +106,35 @@ void HELPER(wur_fpu_fsr)(CPUXtensaState *env, uint32_= t v) set_float_exception_flags(fef, &env->fp_status); } =20 -uint32_t HELPER(rur_fpu_fsr)(CPUXtensaState *env) +void HELPER(wur_fpu2k_fcr)(CPUXtensaState *env, uint32_t v) { - uint32_t flags =3D 0; - int fef =3D get_float_exception_flags(&env->fp_status); - unsigned i; + cpu_set_fcr(env, v); +} =20 - for (i =3D 0; i < ARRAY_SIZE(xtensa_fp_flag_map); ++i) { - if (fef & xtensa_fp_flag_map[i].softfloat_fp_flag) { - flags |=3D xtensa_fp_flag_map[i].xtensa_fp_flag; - } +void HELPER(wur_fpu_fcr)(CPUXtensaState *env, uint32_t v) +{ + if (v & 0xfffff000) { + qemu_log_mask(LOG_GUEST_ERROR, + "MBZ field of FCR is written non-zero: %08x\n", v); } - env->uregs[FSR] =3D flags << XTENSA_FSR_FLAGS_SHIFT; - return flags << XTENSA_FSR_FLAGS_SHIFT; + cpu_set_fcr(env, v & 0x0000007f); +} + +void HELPER(wur_fpu_fsr)(CPUXtensaState *env, uint32_t v) +{ + if (v & 0xfffff000) { + qemu_log_mask(LOG_GUEST_ERROR, + "MBZ field of FSR is written non-zero: %08x\n", v); + } + cpu_set_fsr(env, v); +} + +uint32_t HELPER(rur_fpu_fsr)(CPUXtensaState *env) +{ + uint32_t fsr =3D cpu_get_fsr(env); + + env->uregs[FSR] =3D fsr; + return fsr; } =20 float64 HELPER(abs_d)(float64 v) --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308821; cv=none; d=zohomail.com; s=zohoarc; b=UzYQMP5GxJFhd1wnsevxhWMdS95N11mn5MBWwTA1swRGJzcVVUQna7J9YaxBDV+LLNkyCfDX25369+9S/Kw9s6LtBpqT9LevMFJTn56aRwn4p63wRNRPoAOFPc7AoMqxx9ZWpvfjwmlFa252D46Oop+H8+KH0RX4ip+JB8G2PAc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308821; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=qPmQMFrf0ssnLo2/xT/Hpc0myGJNk7WG9bTev4P00eU=; b=asUuG7np8MT5iFbaZk0NTLYsvipnRQTJEcelp5waVdug0JeKQm2niXRCIoRps7+SzLhk8tGp3ouKLd1MsqZglPrCFpwb3+kBItXo5kUYVFkuB2fBEBvoBDpoLPPGAGod+h4uVm+mPUUcRY73I2TBOtxffb6UbnnX/EpN7tMrPvg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308821638588.3870707763211; Wed, 24 Jun 2026 06:47:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNt4-0003w1-2j; Wed, 24 Jun 2026 09:43:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsx-0003A6-CA; Wed, 24 Jun 2026 09:43:23 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsv-00024j-KY; Wed, 24 Jun 2026 09:43:23 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 460101BAA19; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id D5E173DEA68; Wed, 24 Jun 2026 16:33:32 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308007; bh=1SQrUs/J8qxQ0tTKePHRCk8HlcCtFT4tkMdG/+dWCeg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=fVnSMjlrF9sYpwbGZkxpW+r1A4uiyzSOnPhGGV9xWT1RmBBpT1ZLxD1pYACiYLGL8 wwvt4clhg8yo+OHtZ1J3hUvNccDTepIM7Aw2VjxAWcN95GyFpnQv8YulClYK2v2Lbv ll0zC48NkMZzujqssB/OSeNc3Q3GbqaiLqlMVQvJflQDe8AY2kZ8MVS7cklMsmqIoD 1cqE68Y8F/4m6b6m2lTyn8Jcc3lwf7/qe9MP/94pYfp4WeCI0ta/fQUmxW872spHw1 97ctunht1DuX0yv2p86zmJHB4SaFZyW7XWObn18PVjLS5Bi/UGJT749OsKGHf5uYnG LvRL4tueJVQPw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Richard Henderson , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 103/107] linux-user/xtensa: save/restore FP registers across signal delivery Date: Wed, 24 Jun 2026 16:31:48 +0300 Message-ID: <20260624133301.403266-103-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308823053158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner Add support for saving and restoring f0-f15 across signal delivery. The target_xtensa_xtregs_fp struct carries 32-bit f-regs for cores with XTENSA_OPTION_FP_COPROCESSOR; target_xtensa_xtregs_dfp carries 64-bit f-regs for cores with XTENSA_OPTION_DFP_COPROCESSOR. Lock the xtregs region via lock_user before reading on sigreturn, since sc_xtregs is a user-space pointer that may lie outside the locked sigframe. Signed-off-by: Matt Turner Reviewed-by: Richard Henderson Signed-off-by: Helge Deller (cherry picked from commit 6858e3a71cc41510937bec0950eb4e42e33ba5f2) Signed-off-by: Michael Tokarev diff --git a/linux-user/xtensa/signal.c b/linux-user/xtensa/signal.c index ef8b0c3a27..e3f9da322b 100644 --- a/linux-user/xtensa/signal.c +++ b/linux-user/xtensa/signal.c @@ -21,6 +21,7 @@ #include "user-internals.h" #include "signal-common.h" #include "linux-user/trace.h" +#include "target/xtensa/cpu.h" =20 struct target_sigcontext { abi_ulong sc_pc; @@ -43,10 +44,25 @@ struct target_ucontext { target_sigset_t tuc_sigmask; }; =20 +struct target_xtensa_xtregs_fp { + uint32_t f[16]; + uint32_t fcr; + uint32_t fsr; +}; + +struct target_xtensa_xtregs_dfp { + uint64_t f[16]; + uint32_t fcr; + uint32_t fsr; +}; + struct target_rt_sigframe { target_siginfo_t info; struct target_ucontext uc; - /* TODO: xtregs */ + union { + struct target_xtensa_xtregs_fp fp; + struct target_xtensa_xtregs_dfp dfp; + } xtregs; uint8_t retcode[6]; abi_ulong window[4]; }; @@ -107,6 +123,7 @@ static int flush_window_regs(CPUXtensaState *env) } =20 static int setup_sigcontext(struct target_rt_sigframe *frame, + abi_ulong frame_addr, CPUXtensaState *env) { struct target_sigcontext *sc =3D &frame->uc.tuc_mcontext; @@ -123,8 +140,25 @@ static int setup_sigcontext(struct target_rt_sigframe = *frame, for (i =3D 0; i < 16; ++i) { __put_user(env->regs[i], sc->sc_a + i); } - __put_user(0, &sc->sc_xtregs); - /* TODO: xtregs */ + if (xtensa_option_enabled(env->config, XTENSA_OPTION_DFP_COPROCESSOR))= { + for (i =3D 0; i < 16; ++i) { + __put_user(env->fregs[i].f64, &frame->xtregs.dfp.f[i]); + } + __put_user(env->uregs[FCR], &frame->xtregs.dfp.fcr); + __put_user(cpu_get_fsr(env), &frame->xtregs.dfp.fsr); + __put_user(frame_addr + offsetof(struct target_rt_sigframe, xtregs= ), + &sc->sc_xtregs); + } else if (xtensa_option_enabled(env->config, XTENSA_OPTION_FP_COPROCE= SSOR)) { + for (i =3D 0; i < 16; ++i) { + __put_user(env->fregs[i].f32[FP_F32_LOW], &frame->xtregs.fp.f[= i]); + } + __put_user(env->uregs[FCR], &frame->xtregs.fp.fcr); + __put_user(cpu_get_fsr(env), &frame->xtregs.fp.fsr); + __put_user(frame_addr + offsetof(struct target_rt_sigframe, xtregs= ), + &sc->sc_xtregs); + } else { + __put_user(0, &sc->sc_xtregs); + } return 1; } =20 @@ -190,7 +224,7 @@ void setup_rt_frame(int sig, struct target_sigaction *k= a, __put_user(0, &frame->uc.tuc_flags); __put_user(0, &frame->uc.tuc_link); target_save_altstack(&frame->uc.tuc_stack, env); - if (!setup_sigcontext(frame, env)) { + if (!setup_sigcontext(frame, frame_addr, env)) { unlock_user_struct(frame, frame_addr, 0); goto give_sigsegv; } @@ -243,8 +277,8 @@ give_sigsegv: force_sigsegv(sig); } =20 -static void restore_sigcontext(CPUXtensaState *env, - struct target_rt_sigframe *frame) +static int restore_sigcontext(CPUXtensaState *env, + struct target_rt_sigframe *frame) { struct target_sigcontext *sc =3D &frame->uc.tuc_mcontext; uint32_t ps; @@ -266,7 +300,51 @@ static void restore_sigcontext(CPUXtensaState *env, for (i =3D 0; i < 16; ++i) { __get_user(env->regs[i], sc->sc_a + i); } - /* TODO: xtregs */ + { + abi_ulong xtregs_addr; + + __get_user(xtregs_addr, &sc->sc_xtregs); + if (xtregs_addr) { + if (xtensa_option_enabled(env->config, + XTENSA_OPTION_DFP_COPROCESSOR)) { + struct target_xtensa_xtregs_dfp *xtregs; + uint32_t fcr, fsr; + + xtregs =3D lock_user(VERIFY_READ, xtregs_addr, + sizeof(*xtregs), 1); + if (!xtregs) { + return 0; + } + for (i =3D 0; i < 16; ++i) { + __get_user(env->fregs[i].f64, &xtregs->f[i]); + } + __get_user(fcr, &xtregs->fcr); + __get_user(fsr, &xtregs->fsr); + unlock_user(xtregs, xtregs_addr, 0); + cpu_set_fcr(env, fcr); + cpu_set_fsr(env, fsr); + } else if (xtensa_option_enabled(env->config, + XTENSA_OPTION_FP_COPROCESSOR)= ) { + struct target_xtensa_xtregs_fp *xtregs; + uint32_t fcr, fsr; + + xtregs =3D lock_user(VERIFY_READ, xtregs_addr, + sizeof(*xtregs), 1); + if (!xtregs) { + return 0; + } + for (i =3D 0; i < 16; ++i) { + __get_user(env->fregs[i].f32[FP_F32_LOW], &xtregs->f[i= ]); + } + __get_user(fcr, &xtregs->fcr); + __get_user(fsr, &xtregs->fsr); + unlock_user(xtregs, xtregs_addr, 0); + cpu_set_fcr(env, fcr); + cpu_set_fsr(env, fsr); + } + } + } + return 1; } =20 long do_rt_sigreturn(CPUXtensaState *env) @@ -282,7 +360,9 @@ long do_rt_sigreturn(CPUXtensaState *env) target_to_host_sigset(&set, &frame->uc.tuc_sigmask); set_sigmask(&set); =20 - restore_sigcontext(env, frame); + if (!restore_sigcontext(env, frame)) { + goto badframe; + } target_restore_altstack(&frame->uc.tuc_stack, env); =20 unlock_user_struct(frame, frame_addr, 0); --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308652; cv=none; d=zohomail.com; s=zohoarc; b=NbzcGZ+5kvL61GPy+IEFRRLcMa6nLObeD6e5ayRgvUHGgmuskQOkibYQAGNNaFCXmXO4i/5vxt+zluW9FcsetEeGn4dCct7gQYEZZusHcyWvGpoFnYIcO4PcZWTrcDRwbkl0PuKB48Xdf3qz1wi8Y+w+hytO+IJ1Lkj/v1XmaLg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308652; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=JsUyLfwqbemTc5OQoaeJAmQZmryBUGQDslnGPSxLhrE=; b=OdaluU+v1XT25bjYZrtLOsEeRhag00BTY51AGcLz5bsp+NYCgrJc9X+dOc9jdE4ahSv3avAX0XV6J+7EnXQc05KAA9AOO41k/SSICPvlP2egnKvJrCzmokGhI78+ETaU6Pte8nRDYFSYhNSb36JAt7qKencuvUBXHDON4uDjWEw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308652463762.6320304694668; Wed, 24 Jun 2026 06:44:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNt5-00049o-Ec; Wed, 24 Jun 2026 09:43:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsz-0003T3-SD; Wed, 24 Jun 2026 09:43:25 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNsy-00025B-8f; Wed, 24 Jun 2026 09:43:25 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 5E7D71BAA1A; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E5EF03DEA69; Wed, 24 Jun 2026 16:33:32 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308007; bh=OF7kv8ty/UyH3XtZD3bgYaY8b9DOoJzTV7jeCA7mvHw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=N6byTTWMUq5gMxkMFMiku2+HdHaC5NkJ9LKfWoKCUc5Enpe8a7hvMRdm3jeU1FjKJ nBr0Li6OoNZn1NOaDnTSSvxjWRzGZ5TTNv+1KSSNMQuOiAPIw3Ek3BFHyRjnwf7K7d q5A6y/pwQza7EY/nCGzJE6cmguRs7ssQ4AxNizpEwThEd1TtwqRWTCZTPY6nwE7eOi ZcwOihwdnsPnj9yjyA+R//EKv1RIr8CxitAe+AlEbLbY7BFCJuRaxtLD8L4OsYgTFG JKlVxo2wcInCkEZUSJ8NTagwi8f3mT29/sIW7mFj1YxCIufW8x5SECOE2D//v4cFij 0JbkwUcYBq1vw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Matt Turner , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 104/107] linux-user/xtensa: fix unlock of uninitialized frame pointer on sigreturn Date: Wed, 24 Jun 2026 16:31:49 +0300 Message-ID: <20260624133301.403266-104-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308653599158500 Content-Type: text/plain; charset="utf-8" From: Matt Turner If lock_user_struct fails, frame is uninitialized but the badframe label unconditionally calls unlock_user_struct on it. Handle the lock failure inline so badframe is only reached with a valid lock. Signed-off-by: Matt Turner Cc: qemu-stable@nongnu.org Reviewed-by: Helge Deller Signed-off-by: Helge Deller (cherry picked from commit 54e08dbe8f2aeca57e3b1a5eab09a9fec88c1c67) Signed-off-by: Michael Tokarev diff --git a/linux-user/xtensa/signal.c b/linux-user/xtensa/signal.c index e3f9da322b..4990c50045 100644 --- a/linux-user/xtensa/signal.c +++ b/linux-user/xtensa/signal.c @@ -355,7 +355,8 @@ long do_rt_sigreturn(CPUXtensaState *env) =20 trace_user_do_rt_sigreturn(env, frame_addr); if (!lock_user_struct(VERIFY_READ, frame, frame_addr, 1)) { - goto badframe; + force_sig(TARGET_SIGSEGV); + return -QEMU_ESIGRETURN; } target_to_host_sigset(&set, &frame->uc.tuc_sigmask); set_sigmask(&set); --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782309056; cv=none; d=zohomail.com; s=zohoarc; b=e4FVJ3G+oWBqjqdbwn7izUiqamxg3brq9VMHGNnJBRpe0gv7soEwcx17LEuq1bGq9vnSSC/ITL4LdAA3Tmo7bbpJnK2o0M6lqeJDcGMBQKVNzKGpwvcqPxhglYAx8+BRJn/6IazO4GKl5ew7QclLYqIjpFIGDzJuJOlpor7lyZc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782309056; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=vMKzoobV9Q0L9n+oEuDmozK6QvFzQoU4IHQIOrKfMRc=; b=GxXhSQ+J9yig7ugPFIPW0HdjTW5oHcP21UUYxVYVal54rYRO+oR8BxG7WX7qFUvdgfRDDwHsNHar5PWN6ZmsqcJP5pkXPlG/qoEeTgQ515fNJl8ZOoYXJ1BMpjGLv6tqkclSz+CQ7da3lCxtOm7nS2b8aHpTLpVtjYEJca2t2iA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782309056883778.0252807204874; Wed, 24 Jun 2026 06:50:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNtM-0006B2-Rt; Wed, 24 Jun 2026 09:43:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNtK-00061L-L0; Wed, 24 Jun 2026 09:43:46 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNtI-00025H-RX; Wed, 24 Jun 2026 09:43:46 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 709FA1BAA1B; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 0AD593DEA6A; Wed, 24 Jun 2026 16:33:33 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308007; bh=oSBt1no7uW7UsqIIUgO+H9H6J1W2PuuatD0PtVI1C58=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=K7e086MafkcD3IWb+kLr5CG8Whxa+L3F2l/ABKr9v8VH8hCG0haH8TOPD/RGpzzVO JBYycDG9AsWQZjuercAehmU3npEFJ6Oj+vojSCgcG2j36j/8vrJ9lhXza5h14kLAza 8Ze6gM+8azFCO9E8Jv+N3rVnUz771tMgBEijs5FnqIiHFpkEXVmmGfSH9Vwk2mjvcH KeEQW54+ZeSb56hW4UxUx61r0M2qFTsROUOavA7CRB7qons7BqPCl2z3f+r187ytXc +ThgDFx2TFFrOHKJHUnqkAGszmVbH3sZEFAzAEuDjnKsyWcUcUIpnzGkplOfnF4xeW ZXb0NT5IpiXdg== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Aditya Gupta , Zexiang Zhang , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-11.0.2 105/107] ppc/pnv_phb3: Error out on invalid config access Date: Wed, 24 Jun 2026 16:31:50 +0300 Message-ID: <20260624133301.403266-105-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782309058846158500 Content-Type: text/plain; charset="utf-8" From: Aditya Gupta PHB in Power8 supports 8 byte registers, and hence the ops structure allows accessing of 8 bytes in 'pnv_phb3_reg_ops' Both 'pnv_phb3_reg_read' & 'pnv_phb3_reg_write' pass the arguments as is to 'pnv_phb3_config_{read,write}', if offset is PHB_CONFIG_DATA. This when called with size as 8, causes following assert failure in 'pci_host_config_read_common' & 'pci_host_config_write_common': assert(len <=3D 4); Validate that size is <=3D4, before jumping to pci_host_config_{read,write}= _common Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3334 Reported-by: Zexiang Zhang Fixes: 9ae1329ee2fe ("ppc/pnv: Add models for POWER8 PHB3 PCIe Host bridge") Signed-off-by: Aditya Gupta Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-Id: <20260326190438.734239-2-adityag@linux.ibm.com> (cherry picked from commit 218109781209f9d77242b2cdf743acac8bc3b893) Signed-off-by: Michael Tokarev diff --git a/hw/pci-host/pnv_phb3.c b/hw/pci-host/pnv_phb3.c index d6ab515337..4ffdb4ce31 100644 --- a/hw/pci-host/pnv_phb3.c +++ b/hw/pci-host/pnv_phb3.c @@ -475,6 +475,11 @@ void pnv_phb3_reg_write(void *opaque, hwaddr off, uint= 64_t val, unsigned size) =20 /* Special case configuration data */ if ((off & 0xfffc) =3D=3D PHB_CONFIG_DATA) { + if (size > 4) { + phb3_error(phb, "Invalid config access, offset: 0x%"PRIx64" si= ze: %d", + off, size); + return; + } pnv_phb3_config_write(phb, off & 0x3, size, val); return; } @@ -597,6 +602,11 @@ uint64_t pnv_phb3_reg_read(void *opaque, hwaddr off, u= nsigned size) uint64_t val; =20 if ((off & 0xfffc) =3D=3D PHB_CONFIG_DATA) { + if (size > 4) { + phb3_error(phb, "Invalid config access, offset: 0x%"PRIx64" si= ze: %d", + off, size); + return ~0ull; + } return pnv_phb3_config_read(phb, off & 0x3, size); } =20 --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782309072; cv=none; d=zohomail.com; s=zohoarc; b=ih7vMxWxQz9eP0ykbfVqo9IAxvFqCWWp5grLzjg8bR2Xnach1sFH0Ag+Z7vLcGFiKMHP2ICiL0W1kB23teqPmhsu4biGovNMfZz9dqtY2IULSO0LT1wDeggnN9Ij3kwZh05zj/iLhiOUGZHYCd8UWaYoHYNBExv700ETnxz1vz4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782309072; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bi49JqxzkqO7dRpd3alzmjp8eAbYOvcuOITHRO/5vhg=; b=DZbqT+cflL9zas7nXIuUvUp5UQLM7LX2HKDsHacm6tiw1UZVNUr899Y+8RAFkqrAyOqUmk7yG9G84hmKIwPAwHmwAUnG2kes0JuKjrF29VQrP/ggum6o8mWe/MBctMKiXdop2jwAVGKFCFJnW9EXbLYvaO4rXlcyEH/gd+Xc9Qk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782309072768823.1501526811653; Wed, 24 Jun 2026 06:51:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNtP-0006J4-A9; Wed, 24 Jun 2026 09:43:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNtN-0006BU-1p; Wed, 24 Jun 2026 09:43:49 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNtL-00025k-CN; Wed, 24 Jun 2026 09:43:48 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id B679D1BAA1C; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1D0823DEA6B; Wed, 24 Jun 2026 16:33:33 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308007; bh=13Qb9Nx8cR17potvT3cEjjnap4gymQSQ/97ixQ0MK/M=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=CxFDJDANKgUZ159bR7sjWGeixXrVB+vE3Xr5/ajKw9mRGDDBPHpkyYYD79CYEAHrE IRSbJnO+sRATA7SWk2NSTh21okqB1N46peJFc5K/0GwrJGuzkHpz8FTpNgNkL/+IRR oq2VnTE3ec0PucfciqeYQeZBWdgzbg8ECG79cLUE+mG3B6rxql456zaayZe6wzZA74 fE+BJ8npmiiM2dV9Ulm0C32IgC4mPlfs4bh5jx/Fpo37q9i2CRmsXQT0+4x+q3Kr+V D2tqK9pHo6EwWBTv54Tn0h52L3slgE5+3oaiKzd6+mDk17nyG2slRLLRqgYQFiC5b+ qD/pdWbLhOW5A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Aditya Gupta , Zexiang Zhang , "Michael S. Tsirkin" , Michael Tokarev Subject: [Stable-11.0.2 106/107] hw/pci: Replace assert with bounds check and return Date: Wed, 24 Jun 2026 16:31:51 +0300 Message-ID: <20260624133301.403266-106-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782309072963158500 Content-Type: text/plain; charset="utf-8" From: Aditya Gupta As reported in https://gitlab.com/qemu-project/qemu/-/work_items/3334, callers of 'pci_host_config_{read,write}_common' can pass length as 8, causing an assert failure The original issue with pnv_phb3 triggering the assert was fixed in a previous commit Instead of asserting on invalid length, check if the length is valid (<=3D4), otherwise return (with the failure error code in read) Reported-by: Zexiang Zhang Signed-off-by: Aditya Gupta Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Message-Id: <20260326190438.734239-3-adityag@linux.ibm.com> (cherry picked from commit c7209c56718107fefd5deae140a450954d31ff2b) Signed-off-by: Michael Tokarev diff --git a/hw/pci/pci_host.c b/hw/pci/pci_host.c index 91e3885c7f..2a7fdfa563 100644 --- a/hw/pci/pci_host.c +++ b/hw/pci/pci_host.c @@ -81,7 +81,12 @@ void pci_host_config_write_common(PCIDevice *pci_dev, ui= nt32_t addr, return; } =20 - assert(len <=3D 4); + if (len > 4) { + PCI_DPRINTF("%s: invalid length access: addr " HWADDR_FMT_plx " \ + len %d val %"PRIx32"\n", __func__, addr, len, val); + return; + } + /* non-zero functions are only exposed when function 0 is present, * allowing direct removal of unexposed functions. */ @@ -106,7 +111,12 @@ uint32_t pci_host_config_read_common(PCIDevice *pci_de= v, uint32_t addr, return ~0x0; } =20 - assert(len <=3D 4); + if (len > 4) { + PCI_DPRINTF("%s: invalid length access: addr " HWADDR_FMT_plx " \ + len %d val %"PRIx32"\n", __func__, addr, len, val); + return ~0x0; + } + /* non-zero functions are only exposed when function 0 is present, * allowing direct removal of unexposed functions. */ --=20 2.47.3 From nobody Sun Jul 26 11:53:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1782308687; cv=none; d=zohomail.com; s=zohoarc; b=Aqiljcau6xmP/hGetSQaS3kLcvfKoyTTf0UK7nNaMnbVfAkTNxkDOzT99uPMvF8V2itkGwXgMrA3uc5qAEmReKkRC9G1gt8v3V1KJFPMcxeNN25XOFhiEe9i6OypelcWGLXGogl508AjqCmTL3JcjWJuQT04Kffusizh8GI+BsI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782308687; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=5beFfrJULvT7Mu6vvR8svbH8KtMp0+EgBdbEUpy2dcQ=; b=Ua8N10u/fU3rLb0QTmxGYsxq2Yg361FBovfHNkHgAr/YJRuLGw8LfT6On1hKIDuIeViD7L+Jf6Q9hJDxaXJVAE70BEsL84CrH1AfqXRTQU32TV5zncH45uF//6HOGkWQA+4hF6HifM2/fB2IhxasqaU5XQP1fVUgcM4mXOyPfVY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782308687183495.30712523109446; Wed, 24 Jun 2026 06:44:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wcNtQ-0006Ny-5F; Wed, 24 Jun 2026 09:43:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNtN-0006Ci-MF; Wed, 24 Jun 2026 09:43:49 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wcNtL-00028X-Vu; Wed, 24 Jun 2026 09:43:49 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id C62C21BAA1D; Wed, 24 Jun 2026 16:33:27 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 62CBE3DEA6C; Wed, 24 Jun 2026 16:33:33 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1782308007; bh=Keok8i8qUdh8lw5p9O3kG49/Lx9jiNE6zo1Es59rBbU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=AbudlXmcF5PXcVLIRkOT+McpjlhnnDsoPXEQ0EdI182T8kIcRYOuiEgP916soUNFf e/l9fYmeooRe5JOUD0fQh6u6FwQAO7LH05G6Jb2GWSFn2NF8kkspSu2eRMQOisyC1r yXKDkGFkUMwG/YQiXaI3b7ql6q8ZSKEsYGT7ozE7kDe/65COBXwZNf117omqILFA7w sD4k14BCv7zPJ2Cdd120FWfwZPtH4gGc4/X1jKWTL+qjvLf0t9x2WZOrZoavuf29fk Kq+4n/rjE2wio4nsk1PvhgfZKdF6OabhED5UFPHK01mXBDMVqb9gH1vUBwUEdzQ6Vp Z5uCFT7wTKWJQ== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Akshit Yadav , Helge Deller , Michael Tokarev Subject: [Stable-11.0.2 107/107] linux-user: Fix AT_PHDR when program headers are relocated into their own segment Date: Wed, 24 Jun 2026 16:31:52 +0300 Message-ID: <20260624133301.403266-107-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1782308687915158500 Content-Type: text/plain; charset="utf-8" From: Akshit Yadav When a binary is patched or relocated such that the program header table is moved into a separate PT_LOAD segment (rather than sitting at the start of = the first loadable segment), QEMU's AT_PHDR auxv entry becomes incorrect. The loader was computing AT_PHDR as load_addr + e_phoff, which assumes the head= ers are mapped 1:1 from file offset 0. This breaks when the headers are elsewhe= re. The Linux kernel instead locates the PT_LOAD segment that contains e_phoff, then computes the in-memory address as p_vaddr + (e_phoff - p_offset). This correctly handles relocated headers. Fix by: 1. Add phdr_addr field to image_info to cache the resolved address. 2. Initialize to load_addr + e_phoff (fallback for headers outside any PT_L= OAD). 3. In the PT_LOAD mapping loop, detect if the segment contains e_phoff and override with the segment-relative address. 4. Use info->phdr_addr for AT_PHDR instead of the incorrect formula. Signed-off-by: Akshit Yadav Reviewed-by: Helge Deller (cherry picked from commit 156e536a7b9700018aaa2437072c14e3376340a7) Signed-off-by: Michael Tokarev diff --git a/linux-user/elfload.c b/linux-user/elfload.c index 0e757787d2..b995a85eaf 100644 --- a/linux-user/elfload.c +++ b/linux-user/elfload.c @@ -699,7 +699,7 @@ static abi_ulong create_elf_tables(abi_ulong p, int arg= c, int envc, /* There must be exactly DLINFO_ITEMS entries here, or the assert * on info->auxv_len will trigger. */ - NEW_AUX_ENT(AT_PHDR, (abi_ulong)(info->load_addr + exec->e_phoff)); + NEW_AUX_ENT(AT_PHDR, (abi_ulong)(info->phdr_addr)); NEW_AUX_ENT(AT_PHENT, (abi_ulong)(sizeof (struct elf_phdr))); NEW_AUX_ENT(AT_PHNUM, (abi_ulong)(exec->e_phnum)); NEW_AUX_ENT(AT_PAGESZ, (abi_ulong)(TARGET_PAGE_SIZE)); @@ -1469,6 +1469,12 @@ static void load_elf_image(const char *image_name, c= onst ImageSource *src, info->data_offset =3D load_bias; info->load_addr =3D load_addr; info->entry =3D ehdr->e_entry + load_bias; + /* + * Fallback for AT_PHDR if the program headers do not fall within + * any PT_LOAD segment (see the loop below, which overrides this with + * the correct in-memory address when a containing segment is found). + */ + info->phdr_addr =3D load_addr + ehdr->e_phoff; info->start_code =3D -1; info->end_code =3D 0; info->start_data =3D -1; @@ -1523,6 +1529,19 @@ static void load_elf_image(const char *image_name, c= onst ImageSource *src, vaddr_ef =3D vaddr + eppnt->p_filesz; vaddr_em =3D vaddr + eppnt->p_memsz; =20 + /* + * If this segment contains the program headers, record their + * in-memory address for AT_PHDR. This matches the kernel, whi= ch + * locates the headers via the containing PT_LOAD rather than + * assuming load_addr + e_phoff (false when the phdrs are not + * mapped 1:1 from file offset 0, e.g. relocated into their own + * segment by a binary patcher). + */ + if (eppnt->p_offset <=3D ehdr->e_phoff && + ehdr->e_phoff < eppnt->p_offset + eppnt->p_filesz) { + info->phdr_addr =3D vaddr + (ehdr->e_phoff - eppnt->p_offs= et); + } + /* * Some segments may be completely empty, with a non-zero p_me= msz * but no backing file segment. diff --git a/linux-user/qemu.h b/linux-user/qemu.h index 7f98fb2607..a9dda4bbd7 100644 --- a/linux-user/qemu.h +++ b/linux-user/qemu.h @@ -26,6 +26,7 @@ struct image_info { abi_ulong load_bias; abi_ulong load_addr; + abi_ulong phdr_addr; abi_ulong start_code; abi_ulong end_code; abi_ulong start_data; --=20 2.47.3