131382 Commits

Author SHA1 Message Date
Stefan Hajnoczi
5ef0ecc594 Merge tag 'hw-misc-20260714' of https://github.com/philmd/qemu into staging
Misc HW patches

Various fixes mostly related to misc hardware devices.

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEE+qvnXhKRciHc/Wuy4+MsLN6twN4FAmpYiKcACgkQ4+MsLN6t
# wN75XhAAhaSICy5imrRLP39yCKHuw+YKblyzGOBE5v17io7BntQoBOrYERTETwcm
# R7SFUMFrvEJC21anOJ7kyc62jhrsnjWofmBp3sBV6eENboZXxuHxsIIr8mxJ+dgv
# 5u9UTfYQ6CMDWbM7keRpRFIKU2sogk1RUyH7Z3kedh3G6MEA4CrSkSf6B777G1lQ
# rm0rcJd5m6lDQ5rmrAd0jsJaI0UaOKLamcb43pm9w3KBDTHhOdJQNwqUX517R69p
# kjhZPAdIGRfyXsOd9S74jr+ZI+kzCi0fCcQGUwD5yges2oxAS+1N5TjYPzMz0E2v
# LDmuTrzRAqfl015QHbj5ayQHk/pAS/Mogoho29G4F6+nTKoo9HeIPX3bEEezJ1Nv
# TpQaD3fp3YBa7BubCSzij0zVZ3PFK1wTY1CrkFC8Je3gejZAafoWKWtZKGBD0nNz
# 2Qzwbef1g45v/GfQzdg3Fp3pgMeU7cHR60pAJsSI8ATbtXEZnWi/wc5VbhiJXXBB
# b8C2wefcbYP1wMKOL+cVZSG9wrwyj5/Yc9wW9nlFykOsBHVPYwvFhwA4dZlxCUXV
# MFWJHUdLdSOomhJqr/syH4V2EGuP9dXsz1zw9E0F06dwayjVOhX6Sd3rW6qj8+H7
# a8Nt7ZthWYpF/6e47HXOzS7VaXy4mvXz8kg4QGVlTBLbS3hGXpg=
# =Wjnj
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 16 Jul 2026 08:30:47 BST
# gpg:                using RSA key FAABE75E12917221DCFD6BB2E3E32C2CDEADC0DE
# gpg: Good signature from "Philippe Mathieu-Daudé (F4BUG) <f4bug@amsat.org>" [full]
# Primary key fingerprint: FAAB E75E 1291 7221 DCFD  6BB2 E3E3 2C2C DEAD C0DE

* tag 'hw-misc-20260714' of https://github.com/philmd/qemu:
  net: only advertise passt in netdev help when CONFIG_PASST
  hw/usb/hcd-xhci: Use qemu_log_mask() instead of fprintf() statement
  hw/usb/hcd-xhci: Remove the FIXME macro
  hw/usb/hcd-xhci: Turn guest-triggerable abort() into qemu_log_mask()
  hw/usb/hcd-ohci: Make sure that ohci_service_ed_list() cannot loop forever
  hw/display/virtio-gpu: fix dmabuf_fd leak on remap failure
  hw/sparc64/niagara: use int64_t for vdisk size to avoid truncation
  hw/display/qxl: fix TOCTOU in cursor chunk data_size handling
  hw/scsi/vmw_pvscsi: add a comment to explain the endianness
  hw/scsi/vmw_pvscsi: translate data endianness
  docs/devel: Document SSI dummy-cycle ownership
  hw/misc/ivshmem: clear chardev handlers before freeing peers
  hw/sparc64/sun4u: Mark unusable PCI busses as full to ease device plugging

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-17 10:01:52 +01:00
Stefan Hajnoczi
17ea1bfb9b Merge tag 'pull-misc-2026-07-14' of https://repo.or.cz/qemu/armbru into staging
Miscellaneous patches for 2026-07-14

# -----BEGIN PGP SIGNATURE-----
#
# iQJGBAABCgAwFiEENUvIs9frKmtoZ05fOHC0AOuRhlMFAmpV/gsSHGFybWJydUBy
# ZWRoYXQuY29tAAoJEDhwtADrkYZTi/oP/1B9i3crkWVFgzZ3YyvDFG5aAPtMZ4MU
# TFEh3xKtzOMIu/jvFvapSNAHG/4kPuiHTJXsi8VYtvzoKhhJggczSJI1K3JSxEtg
# 8j7RVKevIwEk3kBR4+L3yegGerNJd2cFfyJLK6DzljxqwRd1bo6/iigxwrg5WzG6
# YDyPqeOtrOBVDjjRXH5T1k+rL5HgmUp5JQWsc+gZSqdVSLWPnTEOtg1Xs1ipEIRm
# JRiKG/5ADwao8Ml6iGmmQQsFvNe6EYWbm6NGdavzuD7mp6Roxuq4CtxD+6jT3roK
# GxQKsig2Un2vBWgvI9ZokwULcpB4esiUAvz9pPYg9WZB/PXi24Fjivhjm2w69E8N
# QIU1TimQFkR0nIFkChYPAfQvBbzdTGv71dZ4/vxVI5ha7kAYw3xWMAGuMhX4FivW
# mEGu7j999IlRSWZYBLUsbsBCM4gXuxzPjs9Cp8xghLi9mnF+MITz0zCHKx2FQwE7
# 06yTeEvjPe8LWqx6mfeFq/k4c+Hpiib+D4cOyIBLqldGjFowbaaTmLP8W6VUGM07
# QsuPIE0Py9EOBwOXqYTYrv/SsBLPp03j3Om/P4Bo6E3Zhms0gF8+WXACyJX1t1H0
# V+GtgloccjgfP9hynHa5RaoFeDxOZwksV6cxbuWm38yhhcyaq0iZMXqGWjfO4h5f
# HgNAI8X660MA
# =fEwp
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 14 Jul 2026 10:14:51 BST
# gpg:                using RSA key 354BC8B3D7EB2A6B68674E5F3870B400EB918653
# gpg:                issuer "armbru@redhat.com"
# gpg: Good signature from "Markus Armbruster <armbru@redhat.com>" [full]
# gpg:                 aka "Markus Armbruster <armbru@pond.sub.org>" [full]
# Primary key fingerprint: 354B C8B3 D7EB 2A6B 6867  4E5F 3870 B400 EB91 8653

* tag 'pull-misc-2026-07-14' of https://repo.or.cz/qemu/armbru:
  json-parser: fix formatting of comment
  MAINTAINERS: Regularise the status fields (again)
  qom: Fix device-list-properties & friends to show legacy-FOO props
  qapi: Fix misspelled section tags in doc comments

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-17 10:00:20 +01:00
Rohitashv Kumar
504f2bad93 net: only advertise passt in netdev help when CONFIG_PASST
show_netdevs() lists each conditionally-compiled netdev backend behind
its CONFIG_* guard (CONFIG_SLIRP for "user", CONFIG_L2TPV3 for
"l2tpv3", CONFIG_NET_BRIDGE for "bridge", ...). The "passt" entry was
added unconditionally, so "-netdev help" advertises passt even in
builds configured with --disable-passt. Trying to use it then fails
with "Parameter 'type' does not accept value 'passt'", since the QAPI
NetClientDriver enum member "passt" is gated by 'if': 'CONFIG_PASST'.

Guard the help entry with CONFIG_PASST so the advertised backends match
those actually compiled into the binary.

Signed-off-by: Rohitashv Kumar <roohiit@amazon.de>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Puranjay Mohan <puranjay@kernel.org>
Message-ID: <20260713194511.1058450-1-rohit.kuma1313@gmail.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:29:09 +02:00
Thomas Huth
ebe66684a5 hw/usb/hcd-xhci: Use qemu_log_mask() instead of fprintf() statement
We've got a proper way for logging unimplemented hardware features,
so use qemu_log_mask() instead of the fprintf() here now.

Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260713161406.361197-4-thuth@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:29:09 +02:00
Thomas Huth
96c9f9709d hw/usb/hcd-xhci: Remove the FIXME macro
The FIXME macro is only used in one case, which should hopefully
never trigger: The containing function handles all the USB_RET_*
values except for USB_RET_ADD_TO_QUEUE and USB_RET_REMOVE_FROM_QUEUE,
which are both internal return values for when an async packet needs
to be queued or dequeued, and which shouldn't still be the status by
the time we get to this function. Thus let's simplify this spot
and use a g_assert_not_reached() instead (and remove the DPRINT()
in front of it to avoid that code analyzers trip over unreachable
code here).

Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260713161406.361197-3-thuth@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:29:09 +02:00
Thomas Huth
5257259428 hw/usb/hcd-xhci: Turn guest-triggerable abort() into qemu_log_mask()
The FIXME macros in xhci_alloc_device_streams() can be triggered
by a (malicious) guest. Since the macro also contains an abort()
statement, this terminates QEMU. Turn the FIXME statements into
a qemu_log_mask() instead to avoid that a guest can shoot itself
this way.

Reported-by: Feifan Qian <bea1e@proton.me>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3784
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260713161406.361197-2-thuth@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:29:09 +02:00
Thomas Huth
98e5a8eb4f hw/usb/hcd-ohci: Make sure that ohci_service_ed_list() cannot loop forever
The inner while loop in ohci_service_ed_list() could theoretically
loop forever if a malicious guest prepares a set of bad descriptors.
Add a check to the loop to avoid this situation.

Reported-by: Feifan Qian <bea1e@proton.me>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3781
Signed-off-by: Thomas Huth <thuth@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Message-ID: <20260713160458.343323-1-thuth@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:29:09 +02:00
Marc-André Lureau
564c4d7e99 hw/display/virtio-gpu: fix dmabuf_fd leak on remap failure
When virtio_gpu_create_udmabuf() succeeds but virtio_gpu_remap_udmabuf()
fails (mmap returns MAP_FAILED), virtio_gpu_init_udmabuf() returns early
without closing the dmabuf fd. Since res->blob is never set in this
path, later cleanup via virtio_gpu_cleanup_mapping() skips
virtio_gpu_fini_udmabuf() entirely, leaking the file descriptor.

Call virtio_gpu_destroy_udmabuf() before the early return to close
the fd. This function already handles partial state correctly: it
skips the munmap when res->remapped is NULL and closes the fd when
res->dmabuf_fd >= 0.

Fixes: 9b60cdf987 ("virtio-gpu: Add udmabuf helpers")
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Message-ID: <20260713125622.111513-1-marcandre.lureau@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-16 09:28:54 +02:00
Dmitry Pimenov
76dbe26fd6 hw/sparc64/niagara: use int64_t for vdisk size to avoid truncation
blk_getlength() returns int64_t, but niagara_init() stored it in an int,
truncating the if=pflash virtual-ramdisk size for images >= 2 GiB. A ~4 GiB
image truncated to 0/negative, failed the `size > 0` check, and exit(1)'d
before the CPU ran, ending with:

  qemu-system-sparc64: could not load ram disk

Signed-off-by: Dmitry Pimenov <sun4qemu@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260710222350.9185-1-sun4qemu@gmail.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Marc-André Lureau
a3cc0069e1 hw/display/qxl: fix TOCTOU in cursor chunk data_size handling
Snapshot chunk.data_size into a host-local variable before passing it to
qxl_phys2virt() for validation, and pass it through qxl_cursor() and
qxl_unpack_chunks() so that no subsequent code re-reads the field.

Without this, a racing vCPU can inflate data_size between the
qxl_phys2virt() validation and the memcpy in qxl_unpack_chunks(),
causing a source read past the validated region. In practice the read
stays within the guest's own VRAM mmap, so the impact is limited.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3757
Reported-by: Feifan Qian <bea1e@proton.me>
Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260710134352.2313675-1-marcandre.lureau@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Miao Wang
ecc569639a hw/scsi/vmw_pvscsi: add a comment to explain the endianness
Add a comment to explain the endianness of the pvscsi device. We have
no information about the endianness should be little-endian or CPU
native endian because the current driver code is designed to work only
on x86 and is not endianness aware. We assume that the pvscsi device is
implicitly little-endian.

Signed-off-by: Miao Wang <shankerwangmiao@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260710-pvscsi-endianness-v3-2-27fe1c4d1f6e@gmail.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Miao Wang
5a811329bd hw/scsi/vmw_pvscsi: translate data endianness
This patch improves the implementation of the pvscsi device by
translating the endianness of the data sent or received from the guest.
This ensures pvscsi can work on big-endian hosts with little-endian
guests.

This patch assumes, although not having found any specifications, that
the pvscsi device is little-endian, since pvscsi seems to be used only
on x86 platforms, which are little-endian.

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Miao Wang <shankerwangmiao@gmail.com>
Message-ID: <20260710-pvscsi-endianness-v3-1-27fe1c4d1f6e@gmail.com>
[PMD: Rebased on top of commit cb30b8758d physmem API conversion]
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Bin Meng
6387fbad45 docs/devel: Document SSI dummy-cycle ownership
Document the boundary between SPI/SSI controller models and SPI flash
models when representing fast-read dummy cycles. It explains that
flash models own command semantics, while controllers own
hardware-generated dummy transfers and cycle-to-byte conversion.

Signed-off-by: Bin Meng <bin.meng@processmission.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260707083431.219671-11-bin.meng@processmission.com>
[PMD: Update MAINTAINERS]
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Haotian Jiang
5157ceb10c hw/misc/ivshmem: clear chardev handlers before freeing peers
ivshmem_exit() frees s->peers and s->msi_vectors but does not clear
the chardev handlers registered in ivshmem_common_realize(). Those
handlers are only removed later in object_finalize() via release_chr,
which runs after ivshmem_exit().

Between exit and finalize, ivshmem_read() can fire on pending chardev
data and process_msg_connect() dereferences the freed s->peers.
Additionally, s->peers, s->nb_peers, and s->msi_vectors are not
zeroed after free, leaving dangling pointers that make the UAF code
paths reachable.

Fix by clearing chardev handlers at the beginning of ivshmem_exit(),
before any resources they access are freed, and nullifying freed
pointers.

Cc: qemu-stable@nongnu.org
Fixes: f64a078d45 ("ivshmem: fix pci_ivshmem_exit()")
Link: https://gitlab.com/qemu-project/qemu/-/work_items/3594
Reported-by: Haotian Jiang <sundayjiang@tencent.com>
Signed-off-by: Haotian Jiang <sundayjiang@tencent.com>
Message-ID: <tencent_3105EC28797360A155078F53@qq.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Thomas Huth
506fa577db hw/sparc64/sun4u: Mark unusable PCI busses as full to ease device plugging
When trying to plug a PCI device to a Sparc64 machine, you currently
have to specify the right bus ("bus=pciB"), otherwise you get this error:

 $ qemu-system-sparc64 -device virtio-scsi-pci
 qemu-system-sparc64: -device virtio-scsi-pci: PCI: no slot/function
 available for virtio-scsi-pci, all in use or reserved

This is quite annoying for the unexperienced users, and it also breaks
e.g. the iotests ("make check-block") when running with qemu-system-sparc64.

Mark the non-usable PCI busses as full now, so that QEMU can automatically
plug new PCI devices to the right "pciB" bus.

Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260309181452.83702-1-thuth@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-15 15:50:22 +02:00
Stefan Hajnoczi
eca2c16212 Update version for v11.1.0-rc0 release
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-14 20:36:23 +01:00
Stefan Hajnoczi
a3c1ad55ba Merge tag 's390x-20260714' of https://gitlab.com/cohuck/qemu into staging
more s390x guest->host interface hardening (sclp, css)

# -----BEGIN PGP SIGNATURE-----
#
# iIgEABYKADAWIQRpo7U29cv8ZSCAJsHeiLtWQd5mwQUCalYBQxIcY29odWNrQHJl
# ZGhhdC5jb20ACgkQ3oi7VkHeZsEg8gEA2leqR6LLqQFqacysYj7uu2NK7NqWbShY
# k3wvWVq6h7IBAMzLs/pnrNdJM8VjlPnAdD1UUCXme4MbzDFPv9tFElII
# =+khB
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 14 Jul 2026 10:28:35 BST
# gpg:                using EDDSA key 69A3B536F5CBFC65208026C1DE88BB5641DE66C1
# gpg:                issuer "cohuck@redhat.com"
# gpg: Good signature from "Cornelia Huck <conny@cornelia-huck.de>" [unknown]
# gpg:                 aka "Cornelia Huck <cohuck@kernel.org>" [unknown]
# gpg:                 aka "Cornelia Huck <cornelia.huck@de.ibm.com>" [full]
# gpg:                 aka "Cornelia Huck <huckc@linux.vnet.ibm.com>" [full]
# gpg:                 aka "Cornelia Huck <cohuck@redhat.com>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: C3D0 D66D C362 4FF6 A8C0  18CE DECF 6B93 C6F0 2FAF
#      Subkey fingerprint: 69A3 B536 F5CB FC65 2080  26C1 DE88 BB56 41DE 66C1

* tag 's390x-20260714' of https://gitlab.com/cohuck/qemu:
  s390x/css: firm up handling of chained TIC CCWs
  s390x/sclpcpi: check event length field before reading from buffer
  s390x/sclp: prevent re-reading the sclp header

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-14 20:33:35 +01:00
Eric Farman
33bece0fa1 s390x/css: firm up handling of chained TIC CCWs
The logic in css_interpret_ccw() correctly returns -EINVAL if a
Transfer-In-Channel (TIC) CCW is command chained to another TIC CCW.
The same routine also correctly returns -EINVAL if 256 CCWs do not
perform a data transfer as part of the I/O operation [0].

What is missing, however, is a combination of these two, where a loop
can be generated that will continue processing CCWs but without
providing an opportunity to catch a breath. Fix this by capping
the number of TIC CCWs in a channel program at the same limit as
the CCWs without data transfer.

[0] See "Invalid Sequence" in z/Architecture Principles of Operation
    (SA22-7832-14), p16-27

Cc: qemu-stable@nongnu.org
Signed-off-by: Eric Farman <farman@linux.ibm.com>
Acked-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Farhan Ali <alifm@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Message-ID: <20260713074708.884282-1-borntraeger@linux.ibm.com>
Signed-off-by: Cornelia Huck <cohuck@redhat.com>
2026-07-14 11:19:34 +02:00
Paolo Bonzini
87f608e3c2 json-parser: fix formatting of comment
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Message-ID: <20260713114622.1950506-1-pbonzini@redhat.com>
Reviewed-by: Markus Armbruster <armbru@redhat.com>
[Mea culpa]
Signed-off-by: Markus Armbruster <armbru@redhat.com>
2026-07-14 10:59:58 +02:00
Markus Armbruster
f87693a841 MAINTAINERS: Regularise the status fields (again)
Orphaned isn't a state, Orphan is.

Fixes: fb7001e458 (MAINTAINERS: Remove PhilMD from firmware sections, 2026-04-17)
Signed-off-by: Markus Armbruster <armbru@redhat.com>
Message-ID: <20260710111403.2953873-1-armbru@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-14 10:58:17 +02:00
Markus Armbruster
9dbce799e7 qom: Fix device-list-properties & friends to show legacy-FOO props
qmp_device_list_properties() skips properties whose name starts with
"legacy-".  This is a flawed test for "is a legacy property".

The test is flawed because non-legacy properties can and do start with
"legacy-".  Back when it was added, no such properties existed.  Right
now, three such properties do: property "legacy-cmb" of device "nvme",
and properties "legacy-cache" and "legacy-multi-node" of devices
"x86_64-cpu", "i386-cpu", and its children.

This affects QMP command "device-list-properties", HMP command
"device_add T,help", and command line option "-device T,help".

Legacy properties are gone since commit a61383f7ab (qdev: Legacy
properties are now unused internally, drop, 2025-10-22).  This makes
the fix easy: delete the code that skips them.

Reproducer: -device nvme,help doesn't show legacy-cmb before the
patch, and does after.

Fixes: f4eb32b590 (qmp: show QOM properties in device-list-properties, 2014-05-20)
Signed-off-by: Markus Armbruster <armbru@redhat.com>
Message-ID: <20260708140948.2622814-1-armbru@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
2026-07-14 10:58:15 +02:00
Markus Armbruster
8b61adae4e qapi: Fix misspelled section tags in doc comments
Section tags are case sensitive and end with a colon.  Screwing up
either gets them interpreted as ordinary paragraph.  Fix a few.

Fixes: 4e88e7e340 (qapi/qom: Define cache enumeration and properties for machine, 2024-11-01)
Fixes: 8eb6d39e22 (qom: qom-list-get, 2025-07-11)
Signed-off-by: Markus Armbruster <armbru@redhat.com>
Message-ID: <20260701061136.798815-1-armbru@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
2026-07-14 10:53:03 +02:00
Stefan Hajnoczi
191489ba75 Merge tag 'pull-riscv-to-apply-20260714' of https://github.com/alistair23/qemu into staging
RISC-V PR for 11.1

* Mark Microchip PolarFire SoC as Odd Fixes in MAINTAINERS
* Fix RISC-V privilege level in uftrace plugin
* Add K230 Linux boot tests
* Fix kernel command line for sifive_u test

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEaukCtqfKh31tZZKWr3yVEwxTgBMFAmpVteUACgkQr3yVEwxT
# gBOPmxAAmPrfbQUTe2Zs0jZGYc3joPHWLIjBwx1p/623WtjXYwXYXbkgKw3BVNOf
# qtu8O2dkNeUK7V8Udmi2tPiANHrV0bbvhFWPgLOINtQQyQV79mpwZGO9id1eU2Xj
# rRLxB190rA2IKFN4Stum1SCuVQpO3DiDtf6B+VppgpShH08TIFeaDtCySOv5UfHS
# WoYlpCFyp99dkkOD+fBNojILiJSLfquhw5tmMgKeFUJXAvVJxDKhAtIHKziCbTUx
# VozVx7blAUEMsf4z+ZUq1Buu/6p8kDD6f+eEQ4eCqHh2HfB6V0BV1uvQFaaxMMF2
# h4mOGuZV1L1d1h5cGtSg1aMJNgAUEUKo+ykiXsGGiaYvUnt3eNZh2xAYwJImliVA
# U9Y6MizID3DaECP27wETTLmrbayuJ8GzSlkoI7jwm9QDmxYFp+TvneTuz9xSlIEy
# lRz/l3mUMJ0RCpvrEbBX56RPbCGIuXgOTdCyAd1hxvCMjwzqtsmQ0vftuFTbWliO
# t5/4EPDJuZVseIKFMSE2RHM2kWWcIOUs5Op42tNxP0Yp/UjBdhNy8KaNWpWmn8vF
# PPSBsFr2dsVSaQz0kSiYTSTg2TcOlGug6mvZJeTdXDNRY0uWIPPrMFpHwk/Fa5G5
# VQC6s/BX9dFAiJDqDwwN9CZR3TzYOHmQfiSWY71+lfb6AI4CuLg=
# =mUxx
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue 14 Jul 2026 05:07:01 BST
# gpg:                using RSA key 6AE902B6A7CA877D6D659296AF7C95130C538013
# gpg: Good signature from "Alistair Francis <alistair@alistair23.me>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 6AE9 02B6 A7CA 877D 6D65  9296 AF7C 9513 0C53 8013

* tag 'pull-riscv-to-apply-20260714' of https://github.com/alistair23/qemu:
  tests/functional/riscv64: sifive_u: Fix kernel command line
  tests/functional/riscv64: Add K230 Linux boot tests
  uftrace: riscv privilege level
  MAINTAINERS: Mark Microchip PolarFire SoC as Odd Fixes

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-14 07:26:45 +01:00
Stefan Hajnoczi
c149f7b367 Merge tag 'pbouvier/pr/plugins-20260713' of https://gitlab.com/p-b-o/qemu into staging
Changes:
- [PATCH v1] uftrace: riscv privilege level (Yanfeng Liu <yfliu2008@qq.com>)
  Link: https://lore.kernel.org/qemu-devel/tencent_E17E8F6494EE130F71527C6BCE481AF33E08@qq.com
- [PATCH v12 0/2] contrib/plugins: add dlcall to call host functions (Ziyang Zhang <functioner@sjtu.edu.cn>)
  Link: https://lore.kernel.org/qemu-devel/20260711094523.622997-1-functioner@sjtu.edu.cn

# -----BEGIN PGP SIGNATURE-----
#
# iQGzBAABCgAdFiEEN8FWlNi6l2Sxlz/btEQ30ZwoYt8FAmpVKSgACgkQtEQ30Zwo
# Yt9wYgv8D3Uh6ebumK4SlHAmMm41gF5wjZsfmA5YXstcPlmxt2sZEbVaTnyLyhZd
# Q8F34HVJ5vaClPoFiQKz+arCLFvLZ4MAgqMy/pxedIhJVhW2b/dt0Z10HkJc8kDx
# baJyv36GmUwnXrTWGZAuLZq7CbQ1xSH4BN6qHAY6mpHogdISABhG6hArz9leHZO/
# NlnxFpfkr29Hd1XLu5u7de35SWRtQbAJYCqtELmR/ZxhKOJU6kr63VR4zr5jVVNX
# px6JQxPkeSFypHV1+klbxCQiXkflwBrYpIKRXrAVNZ7HwMXK6iDw4D/L5TzyxdJn
# 7yMVZ05+xI0o+yS46A0btGoinrnNyjeZjKh1VV7A4DuZ7mfbIII+fvE3JdAzvhzO
# xvrTwwYksiztEK86r8yq7DT9FIx5LLF+B93NgdUtUvvOQP1z1BvvCdePN1KwUrpo
# UgO45akAv8QBVD5uNS4Lh/fG3HarYgdrwt87P3vgynEhuGIE+7QZfOmooNwlwu8v
# SSngbr/5
# =9JyL
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 13 Jul 2026 19:06:32 BST
# gpg:                using RSA key 37C15694D8BA9764B1973FDBB44437D19C2862DF
# gpg: Good signature from "Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 37C1 5694 D8BA 9764 B197  3FDB B444 37D1 9C28 62DF

* tag 'pbouvier/pr/plugins-20260713' of https://gitlab.com/p-b-o/qemu:
  docs/about/emulation: document the dlcall plugin
  contrib/plugins: add a minimal dlcall plugin
  uftrace: riscv privilege level

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-14 07:25:54 +01:00
Stefan Hajnoczi
d7860aec47 Merge tag 'pull-11.1-gitdm-updates-130726-1' of https://gitlab.com/stsquad/qemu into staging
gitdm updates

  - various mailmap fixes
  - update IBM gitdm map
  - add more individual contributors to gitdm
  - update Qualcomm entries
  - migrate gitdm to scripts/

# -----BEGIN PGP SIGNATURE-----
#
# iQEzBAABCgAdFiEEZoWumedRZ7yvyN81+9DbCVqeKkQFAmpVD1oACgkQ+9DbCVqe
# KkQlVQf/W7AyRksRaBM9JdfJwq3po5iDrUqBCU1VInz1fviltSOVD0qluInqzcnH
# ZbBA9l9B0Luq9RLFUSHfaX3kvyF2Ti+/6kmdFLkuAxKdyEuzY5k4yGhPmNUyPm6r
# gWQds6dMKcEzChmfzKloDUVkWbnlDrtUCLrjFXIA/32qODMNG/hUEAGO5xR6XojF
# 2sCJhBgeuEbBPEqghv6oCv4YAPLipmk2TgAAia7CPMX9pDlEBH9bs5T5O6QMoepF
# ZsYG+QALVEIEJAwAgQcHwzPEzSajb47BEPGskiXyL9oFZ0jUwyMAI1iQqzBhJvbB
# i7w+4CTMgAXgrjnmg1HoB2R0o1rgTg==
# =+6U6
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 13 Jul 2026 17:16:26 BST
# gpg:                using RSA key 6685AE99E75167BCAFC8DF35FBD0DB095A9E2A44
# gpg: Good signature from "Alex Bennée (Master Work Key) <alex.bennee@linaro.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 6685 AE99 E751 67BC AFC8  DF35 FBD0 DB09 5A9E 2A44

* tag 'pull-11.1-gitdm-updates-130726-1' of https://gitlab.com/stsquad/qemu:
  scripts/gitdm: migrate from contrib
  contrib/gitdm: Update Qualcomm entries
  contrib/gitdm: add more individual contributors
  contrib/gitdm: Update IBM map
  mailmap: add fix for Zhongyao Chen
  mailmap: add email mapping for Alexander Mikhalitsyn
  mailmap: Fix Ryan Zhang email address

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-14 07:25:42 +01:00
Stefan Hajnoczi
357220ce32 Merge tag 'pull-target-arm-20260713' of https://gitlab.com/pm215/qemu into staging
target-arm queue:
 * hw/misc/zynq_slcr.c: drop duplicate reset value for DDRIOB_DCI_CTRL
 * hw/arm/tegra241-cmdqv: Do not sync GERRORN on VCMDQ allocation
 * hw/arm/smmuv3: Sanitize fields provided by guest
 * hw/i2c: pmbus: clear output buffer on write
 * docs/system/arm: Add some missing FEAT_FOO we already implement
 * arm/virt: fix smmuv3_devices leak
 * target/arm: Be more defensive for invalid tlbi_aa64_get_range
 * hw/dma: don't allow weird transfer lengths for bcm2835
 * hw/net/vmxnet3: Correct bounds check on tx queue index
 * hw/usb/dev-wacom: Don't write off end of buffer
 * hw/display/sm501: Don't let guest write off end of buffer
 * hw/misc/allwinner-r40-ccu.c: Correct handling of out of range accesses
 * hw/misc/stm32_rcc: Correct offset-to-irq calculation

# -----BEGIN PGP SIGNATURE-----
#
# iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmpU09QZHHBldGVyLm1h
# eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3ksND/9RYq9Ki0OneG6XDcjWRRz9
# 9j6fEBFZlDTD9UsK+ypjD/gLkPqmYdBm9eAk5BBKXy1nAGOYrIQQKZcUOrpdVjey
# 4HWUc2fUWqijSnyhHMrswgI/HarxZAZEBX6TcrVYyuuVwm/LIIlqfGg4R5M3JGgY
# uEmexaCt4c/fIBLAbTmhzwQ4xDUKFceoB4GiI66gdNZQ6889xAu5JPYwmqK+ljnX
# u98Y0UatBgTF3ya7TMHL1D5KkF9S7yzNQwYoh+WT654PfjUlAlsCQfdeqZ3rWAxZ
# IFvpOjljAbrohXqeKGqf5+ShX6Tmb2Xd9sHBiWwbZhQ4NMOGfoAhTdtmYAUNOS+T
# aolThLAliOf5cvXM3yrXCfYrJiDTbvlkWxOInFYk61iKCzDMm7Yb/jcrS0xr6l50
# rhrOh/ydJtJIa31Dz2wvk+22Q84ZqyBy+1RTJ1thlAxycQ8o3a35mSiAUGwzcI98
# 6VTw4gOWaKiOqpbaPvv1ofEkhDWcIUGJK6k9JdVNuCppL7BGfbJXqkKSBqxjExqn
# G3A3QdWF6Ko/7US23gaMk4GO5k9ELSDZKiysnQUs4zs1r+nr21e8hsFfKyOYJ/nq
# l+0TSzCHkpYEGRyO1AsCWDrw7b8mIvF6ty5RmE7e6B/W+WmsectLDnnlX6rTxYSU
# BGQivwgrfdDWRsVGXTr1Lw==
# =E6wg
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 13 Jul 2026 13:02:28 BST
# gpg:                using RSA key E1A5C593CD419DE28E8315CF3C2525ED14360CDE
# gpg:                issuer "peter.maydell@linaro.org"
# gpg: Good signature from "Peter Maydell <peter.maydell@linaro.org>" [full]
# gpg:                 aka "Peter Maydell <pmaydell@gmail.com>" [full]
# gpg:                 aka "Peter Maydell <pmaydell@chiark.greenend.org.uk>" [full]
# gpg:                 aka "Peter Maydell <peter@archaic.org.uk>" [unknown]
# Primary key fingerprint: E1A5 C593 CD41 9DE2 8E83  15CF 3C25 25ED 1436 0CDE

* tag 'pull-target-arm-20260713' of https://gitlab.com/pm215/qemu: (26 commits)
  hw/misc/stm32_rcc: Correct offset-to-irq calculation
  hw/misc/allwinner-r40-ccu.c: Correct handling of out of range accesses
  hw/display/sm501: Don't allow guest to set ram size larger than it is
  hw/display/sm501: Avoid overflow problems in bounds check calculations
  hw/display/sm501: Catch bad coordinates for RTL operations
  hw/usb/dev-wacom: Don't write off end of buffer
  hw/net/vmxnet3: Correct bounds check on tx queue index
  hw/dma: don't allow weird transfer lengths for bcm2835
  target/arm: Be more defensive for invalid tlbi_aa64_get_range
  arm/virt: fix smmuv3_devices leak
  docs/system: add FEAT_HAF
  docs/system: add FEAT_S2TGran[4|16|64]K features
  docs/system: fix sorting of FEAT_S2[PIE|FWB]
  docs/system: document FEAT_IVIPT
  docs/system: document FEAT_MTE4
  docs/system: document FEAT_Secure
  docs/system: add big and little endian features names
  docs/system: declare support for FEAT_EVT2
  hw/i2c: pmbus: clear output buffer on write
  hw/arm/smmuv3: Enforce alignment of L2Ptr according to the span
  ...

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-14 07:25:30 +01:00
Stefan Hajnoczi
4eac8b40f2 Merge tag 'linux-user-for-v11.1-pull-request' of https://github.com/hdeller/qemu-hppa into staging
linux-user-for-v11.1 pull request

Please pull two fixes for linux-user for v11.1:
- Validate guest-passed dm_ioctl data_size
- Alpha: Fix programs using getauxval(AT_HWCAP) to detect BWX/FIX/CIX

# -----BEGIN PGP SIGNATURE-----
#
# iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCalT3fwAKCRD3ErUQojoP
# X7twAPsH/PcMbDMiwKluAOE+/r1rZ95Qp9YXuKfZhUypoizivwEAs5IdB5PKwI5s
# lGaJdOpkm7HWAEbjiYgr25d+dPBcagg=
# =zCLL
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon 13 Jul 2026 15:34:39 BST
# gpg:                using EDDSA key BCE9123E1AD29F07C049BBDEF712B510A23A0F5F
# gpg: Good signature from "Helge Deller <deller@gmx.de>" [unknown]
# gpg:                 aka "Helge Deller <deller@kernel.org>" [unknown]
# gpg:                 aka "Helge Deller <deller@debian.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 4544 8228 2CD9 10DB EF3D  25F8 3E5F 3D04 A7A2 4603
#      Subkey fingerprint: BCE9 123E 1AD2 9F07 C049  BBDE F712 B510 A23A 0F5F

* tag 'linux-user-for-v11.1-pull-request' of https://github.com/hdeller/qemu-hppa:
  linux-user/alpha: populate AT_HWCAP from env->amask
  linux-user: Validate guest-passed dm_ioctl data_size

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
2026-07-14 07:25:06 +01:00
Bin Meng
8fb3075916 tests/functional/riscv64: sifive_u: Fix kernel command line
Build the complete kernel command line before adding it to the QEMU
arguments. This ensures the panic, noreboot and rootwait options are
passed to the guest.

Fixes: 7db162fa01 ("tests/functional: Test SPI-SD adapter without SD card connected")
Signed-off-by: Bin Meng <bin.meng@processmission.com>

Reviewed-by: Chao Liu <chao.liu@processmission.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260713120245.781959-1-bin.meng@processmission.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-07-14 11:56:14 +10:00
Junze Cao
a539bb911e tests/functional/riscv64: Add K230 Linux boot tests
The K230 machine supports direct Linux boot and firmware boot through
the SDK U-Boot, but neither path has functional test coverage.

Add one test for each boot path. Both tests use the Yocto initramfs
assets and wait for the shell prompt to confirm a successful boot.

Fetch the boot assets from the k230-boot-assets repository maintained
by Chao Liu. Pin the URLs to a repository commit and verify each asset
with its SHA-256 digest.

Signed-off-by: Junze Cao <caojunze424@gmail.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260711125320.72319-1-caojunze424@gmail.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-07-14 11:32:51 +10:00
Yanfeng Liu
ae06586a02 uftrace: riscv privilege level
This adds RiscV virtual user and supervisor privilege levels to
uftrace plugin to avoid crashing with H extension guests.

Signed-off-by: Yanfeng Liu <yfliu2008@qq.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <tencent_E17E8F6494EE130F71527C6BCE481AF33E08@qq.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-07-14 11:30:44 +10:00
Alistair Francis
1d642d39cf MAINTAINERS: Mark Microchip PolarFire SoC as Odd Fixes
Mark the "Microchip PolarFire SoC Icicle Kit" as Odd Fixes and enlist
Conor and Sebastian as people to help deal with the fixes.

Acked-by: Conor Dooley <conor.dooley@microchip.com>
Acked-by: Sebastian Huber <sebastian.huber@embedded-brains.de>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260513023859.518484-1-alistair.francis@wdc.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
2026-07-14 11:23:29 +10:00
Ziyang Zhang
eee8e58eed docs/about/emulation: document the dlcall plugin
Document the dlcall plugin under Example Plugins: what it does, the trusted-
guests and guest_base == 0 constraints, how to load it, and a pointer to
Lorelei, one end-to-end userspace implementation, for the toolchain and a
runnable example.

Co-authored-by: Kailiang Xu <xukl2019@sjtu.edu.cn>
Co-authored-by: Mingyuan Xia <xiamy@ultrarisc.com>
Signed-off-by: Ziyang Zhang <functioner@sjtu.edu.cn>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260711094523.622997-3-functioner@sjtu.edu.cn
Signed-off-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
2026-07-13 11:04:51 -07:00
Ziyang Zhang
09b7a409a7 contrib/plugins: add a minimal dlcall plugin
Add a minimal dlcall plugin that lets the guest invoke host functions
through magic system calls. The plugin registers a vCPU syscall filter
callback that intercepts a reserved syscall number and dispatches a set
of pass-through operations: querying host attributes, loading and freeing
shared libraries, resolving symbols, retrieving the last library error,
and invoking a host function through a common interface.

The magic syscall number defaults to 4096 and can be overridden at load
time with the "syscall_num=N" argument; values low enough to clash with a
real syscall are rejected.

Co-authored-by: Kailiang Xu <xukl2019@sjtu.edu.cn>
Co-authored-by: Mingyuan Xia <xiamy@ultrarisc.com>
Signed-off-by: Ziyang Zhang <functioner@sjtu.edu.cn>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/20260711094523.622997-2-functioner@sjtu.edu.cn
Signed-off-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
2026-07-13 11:04:51 -07:00
Yanfeng Liu
9550219649 uftrace: riscv privilege level
This adds RiscV virtual user and supervisor privilege levels to
uftrace plugin to avoid crashing with H extension guests.

Signed-off-by: Yanfeng Liu <yfliu2008@qq.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/tencent_E17E8F6494EE130F71527C6BCE481AF33E08@qq.com
Signed-off-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
2026-07-13 11:04:50 -07:00
Alex Bennée
651c451c8e scripts/gitdm: migrate from contrib
As discussed previously it was suggested scripts might be a better
location for this meta data.

Link: https://lore.kernel.org/all/CAFEAcA_5HvGriDsWnb1ALuA_dgG320eKv7yuM2kThv=rfOSZQA@mail.gmail.com/
Suggested-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260709080040.4157324-10-alex.bennee@linaro.org>
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
2026-07-13 17:13:11 +01:00
Philippe Mathieu-Daudé
9542cacf90 contrib/gitdm: Update Qualcomm entries
Add an entry for Qualcomm Technologies, Inc.,
include previous quicinc.com contributions.

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Leif Lindholm <leif.lindholm@oss.qualcomm.com>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Message-ID: <20260707153003.58914-1-philmd@oss.qualcomm.com>
Message-ID: <20260709080040.4157324-9-alex.bennee@linaro.org>
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
2026-07-13 17:12:02 +01:00
Alex Bennée
03ff36f201 contrib/gitdm: add more individual contributors
Acked-by: Tomita Moeko <tomitamoeko@gmail.com>
Acked-by: Julian Ganz <neither@nut.email>
Message-ID: <20260709080040.4157324-8-alex.bennee@linaro.org>
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
2026-07-13 17:11:57 +01:00
Joel Stanley
5c6422ce95 contrib/gitdm: Update IBM map
A number of us have moved on from IBM.

 * Alexey moved to AMD in 2022.
 * Andrew moved to Code Construct in 2023.
 * Ben moved to Amazon in 2019.
 * Cedric moved to Redhat.
 * Daniel moved to Ventana in 2024.
 * Greg moved to Redhat.
 * Joel moved to Tenstorrent in 2025.
 * Suraj moved to Amazon in 2019

Most have either stopped working on QEMU or swtiched to corp addresses.

Signed-off-by: Joel Stanley <joel@jms.id.au>
Acked-by: Greg Kurz <groug@kaod.org>
Message-ID: <20260709080040.4157324-5-alex.bennee@linaro.org>
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
2026-07-13 17:08:23 +01:00
Alex Bennée
545f85b8e7 mailmap: add fix for Zhongyao Chen
Fixes: c24f58d532 (target/riscv: Fix tail handling for vmv.s.x and vfmv.s.f)
Cc: chen.zhongyao@zte.com.cn
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-ID: <20260709080040.4157324-4-alex.bennee@linaro.org>
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
2026-07-13 17:08:23 +01:00
Alexander Mikhalitsyn
784022730f mailmap: add email mapping for Alexander Mikhalitsyn
I use my company's email to sign-off patches, but send them from my
personal email cause it's Gmail hosted and works much better than Outlook.

It causes some misunderstanding and inconvenience for maintainers sometimes [1].
So I would like to add this email mapping to clear out all possible confusion here.

Link: https://lore.kernel.org/qemu-devel/CAAjaMXabXNmh1UZ5wnpX4wucnC+yWvMo2-jr2XBTby4zqf6CTA@mail.gmail.com/ [1]
Signed-off-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Message-ID: <20260708134744.169452-1-alexander@mihalicyn.com>
Message-ID: <20260709080040.4157324-3-alex.bennee@linaro.org>
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
2026-07-13 17:08:23 +01:00
Philippe Mathieu-Daudé
f89a4247c9 mailmap: Fix Ryan Zhang email address
Add a .mailmap entry to fix the invalid email introduced
in commit 490a3e1867 ("ui/sdl2: Set GL ES profile before
creating initial GL context").

Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org>
Message-ID: <20260619071422.99061-1-philmd@oss.qualcomm.com>
Message-ID: <20260709080040.4157324-2-alex.bennee@linaro.org>
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
2026-07-13 17:08:23 +01:00
Matt Turner
7a2e863f9d linux-user/alpha: populate AT_HWCAP from env->amask
Alpha has never set AT_HWCAP in linux-user emulation, so getauxval(AT_HWCAP)
always returned 0 regardless of the emulated CPU model.

The Linux kernel computes ELF_HWCAP as ~amask(-1), i.e. the set of ISA
extension bits that the amask instruction reports as supported (cleared in
its output).  env->amask stores exactly those bits with the same layout
(BWX=0x1, FIX=0x2, CIX=0x4, MVI=0x100, TRAP=0x200, PREFETCH=0x1000), so
returning it directly from get_elf_hwcap matches the kernel convention.

Add HAVE_ELF_HWCAP to target_elf.h and implement get_elf_hwcap() in
elfload.c to expose the emulated CPU's capability mask to user-space
programs via the auxiliary vector.

Without this fix, programs using getauxval(AT_HWCAP) to detect BWX/FIX/CIX
(such as glibc's memcpy or JIT compilers targeting Alpha) incorrectly
concluded that no extensions were available even when emulating ev56+.

Signed-off-by: Matt Turner <mattst88@gmail.com>
Cc: qemu-stable@nongnu.org
Reviewed-by: Helge Deller <deller@gmx.de>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-07-13 16:16:31 +02:00
Christian Borntraeger
8a116a2853 s390x/sclpcpi: check event length field before reading from buffer
A guest might send a too short SCCB with SCLP_EVENT_CTRL_PGM_ID. QEMU
would fill its data structures with garbage data. Check for the precise
length of the CBI data structure and reject otherwise.

Fixes: f345978f24 ("hw/s390x: add Control-Program Identification to QOM")
Cc: qemu-stable@nongnu.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Janosch Frank <frankja@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Message-ID: <20260709142906.197474-3-borntraeger@linux.ibm.com>
Signed-off-by: Cornelia Huck <cohuck@redhat.com>
2026-07-13 15:44:14 +02:00
Christian Borntraeger
20701190e0 s390x/sclp: prevent re-reading the sclp header
We verify the sccb length and then allocate based on that length. The
following access re-reads the sccb again. This can race against other
vCPUs overwriting the length field.

sclp_service_call_protected does not need a change as the ultravisor
provides a consistent snapshot.

Fixes: c1db53a591 ("s390/sclp: read sccb from mem based on provided length")
Cc: qemu-stable@nongnu.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Reviewed-by: Collin Walling <walling@linux.ibm.com>
Message-ID: <20260709142906.197474-2-borntraeger@linux.ibm.com>
Signed-off-by: Cornelia Huck <cohuck@redhat.com>
2026-07-13 15:44:14 +02:00
Peter Maydell
3c27494434 hw/misc/stm32_rcc: Correct offset-to-irq calculation
In the STM32 RCC, there is a block of 5 "enable" registers, each of
which has 32 bits; each bit determines the level of one of the 5 * 32
= 160 enable_irq output lines.  The code calculates the irq to be
worked on using
  irq_offset = ((addr - STM32_RCC_AHB1_ENR) / 4) * 32;

This assumes that the registers are all consecutive; however, there
is a gap between the AHB1/2/3 registers and the APB1/2 registers, so
for the APB1/2 registers we calculate a number that is 32 too high
and can index off the end of the enable_irq[] array.

The handling of the reset registers has an identical bug.

Adjust the calculation of irq_offset to cope with the gap, and fix
the case labels so accesses to the gap fall into the default
LOG_UNIMP rather than being treated as if they were an actual
register.

Coverity CID: 1663683, 1663686
Cc: qemu-stable@nongnu.org
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Message-id: 20260709104832.1989240-1-peter.maydell@linaro.org
2026-07-13 12:34:17 +01:00
Peter Maydell
f0a2786f7e hw/misc/allwinner-r40-ccu.c: Correct handling of out of range accesses
In allwinner_r40_ccu_write() we handle writes to a MemoryRegion of
size AW_R40_CCU_IOSIZE, and the register array is sized accordingly
at (AW_R40_CCU_IOSIZE / sizeof(uint32_t)).  However, one of the cases
in the switch is a range up to AW_R40_CCU_IOSIZE, which makes
Coverity think we might index off the end of the array. We also
have a similar case in the read function, but since that returns
early it doesn't have the same issue.

Adjust the handling of out of range accesses:
 - use AW_R40_CCU_IOSIZE - 4 as the upper bound, as this is the
   largest value we will actually see
 - return early in the write case, as we do in the read case

Coverity CID: 1663687
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Reviewed-by: Strahinja Jankovic <strahinja.p.jankovic@gmail.com>
Message-id: 20260709104802.1989086-1-peter.maydell@linaro.org
2026-07-13 12:34:17 +01:00
Peter Maydell
2ac2cf0483 hw/display/sm501: Don't allow guest to set ram size larger than it is
The SM501 DRAM_CONTROL register has a 7 bit Size field which allows
the guest to change the local memory size.  We use the local memory
size in bounds checks calculations for 2D operations. Currently we
have no check on the validity of the value the guest programs to
this field, which means that the guest can:
 - set it to a reserved value (6 or 7) which will cause
   get_local_mem_size() to read outside sm501_mem_local_size[]
 - set it to a value corresponding to more RAM than the card
   was created with, so that the 2D bounds check will let 2D
   operations access off the end of the memory region

Fix this by decoupling the value the guest reads and writes to this
field from the internal size we consider the local memory to have.
We validate changes and ignore them except for readback if they would
be reserved values or values for more memory than the card has.

Cc: qemu-stable@nongnu.org
Reported-by: Heechan Kang
Tested-by: BALATON Zoltan <balaton@eik.bme.hu>
Reviewed-by: BALATON Zoltan <balaton@eik.bme.hu>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260707150933.1410507-4-peter.maydell@linaro.org
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3811
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-13 12:34:17 +01:00
Peter Maydell
422734d5fc hw/display/sm501: Avoid overflow problems in bounds check calculations
When we check that a 2D rectangle operation isn't going to run off
the end of video RAM, we do the calculations as 32 bit arithmetic.
This means that carefully chosen guest register values can cause an
overflow so we don't detect that the operation is going to go outside
video memory.

Abstract the check out into a function, do the calculations as
64-bit arithmetic, and add assertions about the ranges of the
inputs.

Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3584
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Tested-by: BALATON Zoltan <balaton@eik.bme.hu>
Reviewed-by: BALATON Zoltan <balaton@eik.bme.hu>
Message-id: 20260707150933.1410507-3-peter.maydell@linaro.org
2026-07-13 12:34:17 +01:00
Peter Maydell
b378a1bd86 hw/display/sm501: Catch bad coordinates for RTL operations
The sm501 code doesn't check whether a right-to-left operation has
specified a width greater than the x-coordinate (which would make it
extend off the left edge of the screen), or similarly a height
greater than the y-coordinate.  This means the guest can misprogram
the device so that we underflow when calculating the address of the
top left pixel, which might result in accessing out of bounds
memory.  Catch this as a guest error and ignore the operation.

Reported-by: Yannick Wang
Tested-by: BALATON Zoltan <balaton@eik.bme.hu>
Reviewed-by: BALATON Zoltan <balaton@eik.bme.hu>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260707150933.1410507-2-peter.maydell@linaro.org
Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3920
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-07-13 12:34:17 +01:00
Peter Maydell
2c6fae7d7d hw/usb/dev-wacom: Don't write off end of buffer
In usb_wacom_handle_data() we allocate a buffer with a size
determined by the transfer size requested by the guest.  We then fill
it in by calling either usb_mouse_poll() or usb_wacom_poll(), both of
which functions take a length and return an actual length, which we
pass to usb_packet_copy().  However, usb_mouse_poll() doesn't check
the buffer size as it fills in the buffer, so if the guest passes an
overly short transfer size then it will write off the end of the
allocated buffer.

Check the length is at least big enough for the minimum 3 byte
packet and return nothing if it is not, as usb_wacom_poll() does.

Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3672
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-id: 20260706182034.1003176-1-peter.maydell@linaro.org
2026-07-13 12:34:17 +01:00