]> git.ipfire.org Git - thirdparty/qemu.git/log
thirdparty/qemu.git
3 months agohw/core/cpu: Expose CPUState::start_powered_off docstring
Philippe Mathieu-Daudé [Tue, 26 Aug 2025 14:29:12 +0000 (16:29 +0200)] 
hw/core/cpu: Expose CPUState::start_powered_off docstring

The comment about @start_powered_off is buried within the
CPUState structure. Hoist it to the structure docstring
comment.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-Id: <20260423170229.64655-6-philmd@linaro.org>

3 months agohw/avr: Build as common unit files
Philippe Mathieu-Daudé [Fri, 13 Mar 2026 04:52:01 +0000 (05:52 +0100)] 
hw/avr: Build as common unit files

Nothing there is target-specific anymore.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@linaro.org>
Message-Id: <20260313062055.2188-38-philmd@linaro.org>

3 months agoMerge tag 'pull-11.1-virtio-gpu-hotfixes-230426-1' of https://gitlab.com/stsquad...
Stefan Hajnoczi [Fri, 24 Apr 2026 00:51:57 +0000 (20:51 -0400)] 
Merge tag 'pull-11.1-virtio-gpu-hotfixes-230426-1' of https://gitlab.com/stsquad/qemu into staging

virtio-gpu fixes:

  - fix build on Windows due to EGL assumption
  - fix use-after-free on virgl resource

# -----BEGIN PGP SIGNATURE-----
#
# iQEzBAABCgAdFiEEZoWumedRZ7yvyN81+9DbCVqeKkQFAmnqN/sACgkQ+9DbCVqe
# KkR+cAf+INMexc1Wzc81XUs3UamDOPQmIKTu/36P7K3PrVwvwtb/KhIjlgsiUDjy
# thP9wZcMVJNA8heCFOp3kMzydEBbZ3Ywiz5TWulrvGrwBwPDf93+bTlgr1cDzDwI
# bi2CjR4NUHtICGC/6Smh9UbRLMh5FkGB/XpyXr+Gkl+THT4s+evQXP8xYuvbfKZj
# qKsxz2oaCZNqYJRfUPBxNLaiS7VRGVJBaOLSuhLUegQZ4T0CzcyprOfreOfjolwC
# hmGcC1w/Sb1EJZkgE9ZKi30AMXS4NuHfMXHNCI76xIMYd/c9/B19AVUv3ZVIbuNs
# vAdamiBnIRffPLGhttOqhLCndNHGHA==
# =uXFe
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 23 Apr 2026 11:17:15 EDT
# gpg:                using RSA key 6685AE99E75167BCAFC8DF35FBD0DB095A9E2A44
# gpg: Good signature from "Alex Bennée (Master Work Key) <alex.bennee@linaro.org>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 6685 AE99 E751 67BC AFC8  DF35 FBD0 DB09 5A9E 2A44

* tag 'pull-11.1-virtio-gpu-hotfixes-230426-1' of https://gitlab.com/stsquad/qemu:
  hw/display: don't accidentally autofree existing virgl resources
  ui/sdl2: Fix assumption of EGL presence at runtime

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
3 months agoMerge tag 'for-upstream' of https://gitlab.com/bonzini/qemu into staging
Stefan Hajnoczi [Fri, 24 Apr 2026 00:51:46 +0000 (20:51 -0400)] 
Merge tag 'for-upstream' of https://gitlab.com/bonzini/qemu into staging

* accel/mshv: ioeventfd fixes
* memory: avoid memmove in flatview_simplify()
* first batch of clang-cl support patches for qemu-ga
* target/i386: fix emulator issue
* target/i386: fix strList leak
* target/i386: emulate: include name of unhandled instruction
* target/i386/tcg: fix decoding of MOVBE and CRC32 in 16-bit mode
* thread-win32: replace CRITICAL_SECTION with SRWLOCK
* target/i386: fix missing PF_INSTR in SIGSEGV context
* util: actually use in pthread_condattr_setclock
* vapic: restore IRQ polling for non-kernel irqchip backends

# -----BEGIN PGP SIGNATURE-----
#
# iQFIBAABCgAyFiEE8TM4V0tmI4mGbHaCv/vSX3jHroMFAmnp9BYUHHBib256aW5p
# QHJlZGhhdC5jb20ACgkQv/vSX3jHroN0Vwf/SCepaTVfA+XXU9ZQLKBch2uPusxM
# iphUdCFyKytydITrIuTQlAQ4EyfnlTouj1qn7SE/cKuRpl9J1Z/eFUGjg0wsDIYM
# J++3wZfGP0foUDYep2bdRQnTiKqgTC93DQUk2mxahdKLqWTo6lSijM0o9NvBvRT1
# ntItGt0KPH1D0eK/cr7+yA4LoMpVzyx+OUHIP+2egJ2el3eRbcI2z6yRPBIAKcSa
# 7xFHcUmHB8gkLdgKX0Lsn80zL69w/au5cwDnjS1k24iZbl3pFsnVVKkgPMSs0Ekm
# Z81nW7s74Woo7VAhrn8A3sYZmJY6wVWNhM1uI3S3Tkg03yGumRrLVAm7tw==
# =hjOY
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 23 Apr 2026 06:27:34 EDT
# gpg:                using RSA key F13338574B662389866C7682BFFBD25F78C7AE83
# gpg:                issuer "pbonzini@redhat.com"
# gpg: Good signature from "Paolo Bonzini <bonzini@gnu.org>" [full]
# gpg:                 aka "Paolo Bonzini <pbonzini@redhat.com>" [full]
# Primary key fingerprint: 46F5 9FBD 57D6 12E7 BFD4  E2F7 7E15 100C CD36 69B1
#      Subkey fingerprint: F133 3857 4B66 2389 866C  7682 BFFB D25F 78C7 AE83

* tag 'for-upstream' of https://gitlab.com/bonzini/qemu: (25 commits)
  target/i386: emulate: include name of unhandled instruction
  memory: Optimize flatview_simplify() to eliminate redundant memmove calls
  meson: add missing semicolon in pthread_condattr_setclock test
  thread-win32: replace CRITICAL_SECTION with SRWLOCK
  target/i386/tcg: fix decoding of MOVBE and CRC32 in 16-bit mode
  accel/mshv: return correct errno value from ioeventfd failure
  accel/mshv: fix ioeventfd deassignment to forward correct datamatch value
  target/i386/mshv: Fix segment regression in MMIO emu
  meson: Don't require nm for non-modular builds
  storage-daemon: use same link arguments as other tools
  util: Remove unused sys/param.h
  util: Remove unused dirent.h
  osdep: Remove unused strings.h
  hw/ppc: Use glib2 instead of strcasecmp/strncasecmp
  target/xtensa: Use glib2 instead of strcasecmp/strncasecmp
  target/ppc: Use glib2 instead of strcasecmp/strncasecmp
  target/riscv: Use glib2 instead of strcasecmp/strncasecmp
  target/sparc: Use glib2 instead of strcasecmp/strncasecmp
  io: Use glib2 instead of strcasecmp/strncasecmp
  block: Use glib2 instead of strcasecmp/strncasecmp
  ...

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
3 months agoMerge tag 'pull-target-arm-20260423' of https://gitlab.com/pm215/qemu into staging
Stefan Hajnoczi [Fri, 24 Apr 2026 00:51:23 +0000 (20:51 -0400)] 
Merge tag 'pull-target-arm-20260423' of https://gitlab.com/pm215/qemu into staging

target-arm queue:
 * virt: Allow user to specify cache topology
 * target/arm: Move OMAP CP15 register definitions to cpregs-omap.c
 * target/arm: cleanups for single-binary work
 * MAINTAINERS: remove people who are no longer active in the project

# -----BEGIN PGP SIGNATURE-----
#
# iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmnp7eQZHHBldGVyLm1h
# eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3uxPD/9LdXmnEt8UokGKk8sU5cT9
# +zgUC3tMRrKDF3bBtOWe07OwnLtccgdsf6+fnSh0Jzlac7xMRCU9OxGon6mAq+bh
# Pj9Nie/DI7bGDXN7Q0MKOyI9wxDJl3wTekurDID3Enafebdp1xOB/BF0G72LSn0d
# b9ID7PYXJQafd5AIJ52nXaewPlqyd2iYn1YvcS8IK2Ht2qVt2qAVRkpt+fAGWfD5
# XlC1pNF2Mpfezu1Gj2BNJqZTNdDdFgMG7nuhdjqnPENHrN4+7lHFUtwBmsDslkWU
# pDhOx7P9GaRlN4TVwnY6WKJyp3J5Uo9l8m+2P9XXqba+e0yJ9jUyA2J1HXKBaQZY
# JTNqfuNgfQN+cMg9Iiad98btzOAJfsgO9ndvTGNrKxEbIMwRreSnKrgzUobAp+6j
# 62Sik2tAsdtzis3/zdq/sIbblx93CLfUka5vqP9c1SEcRU/cvhT8JigEZcXDjT0T
# bJtCF5UKA9GcP6Uq24xcDjMCmnUruGSTjnN1Af/gCD9RU5+Y+bLP7c+8IboaEM97
# yCfdrUEdy1j5tZ0UQlxMTH9Pe+6WwjigN4OqA+vHZDJI83+5XnRSqqXEWC1g5E2T
# XWcckVYldpKqGR6TOgEUP1aWMsLjbxwu9zeBEhRR5LbwOMfi7K1uIXRQvYvfGfEJ
# ak6nBgfFxyK4A7S8OHFstQ==
# =BDx3
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu 23 Apr 2026 06:01:08 EDT
# gpg:                using RSA key E1A5C593CD419DE28E8315CF3C2525ED14360CDE
# gpg:                issuer "peter.maydell@linaro.org"
# gpg: Good signature from "Peter Maydell <peter.maydell@linaro.org>" [full]
# gpg:                 aka "Peter Maydell <pmaydell@gmail.com>" [full]
# gpg:                 aka "Peter Maydell <pmaydell@chiark.greenend.org.uk>" [full]
# gpg:                 aka "Peter Maydell <peter@archaic.org.uk>" [unknown]
# Primary key fingerprint: E1A5 C593 CD41 9DE2 8E83  15CF 3C25 25ED 1436 0CDE

* tag 'pull-target-arm-20260423' of https://gitlab.com/pm215/qemu: (59 commits)
  MAINTAINERS: Remove Xie Changlong
  MAINTAINERS: Remove Xiao Guangrong
  MAINTAINERS: Remove Wen Congyang
  MAINTAINERS: Remove Yanan Wang
  MAINTAINERS: Remove Vijai Kumar K
  MAINTAINERS: Remove Su Hang
  MAINTAINERS: Remove Shannon Zhao
  MAINTAINERS: Remove Ryo ONODERA
  MAINTAINERS: Remove Ronnie Sahlberg
  MAINTAINERS: Remove Luigi Rizzo
  MAINTAINERS: Remove Qiuhao Li
  MAINTAINERS: Remove Jia Liu
  MAINTAINERS: Remove Paul Burton
  MAINTAINERS: Remove Aarushi Mehta
  MAINTAINERS: Remove Marcel Apfelbaum
  MAINTAINERS: Remove Magnus Damm
  MAINTAINERS: Remove Mahmoud Mandour
  MAINTAINERS: Remove Bastian Koppelmann
  MAINTAINERS: Remove Huai-Cheng Kuo
  MAINTAINERS: Remove Dongjiu Geng
  ...

Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
3 months agotarget/hexagon: Change DisasContext packet type
Marco Liebel [Thu, 22 Jan 2026 22:34:23 +0000 (14:34 -0800)] 
target/hexagon: Change DisasContext packet type

The pkt variable inside DisasContext is of type Packet * and gets
assigned to a local variable in decode_and_translate_packet. Right now
there seems to be no problem with it but future changes to e.g.
hexagon_tr_transalte_packet are potentially dangerous if pkt is accessed
after the local variable goes out of scope.

Since packets are being translated one at a time, the type of pkt can be
changed to just Packet to avoid risk of having a dangling pointer.

Signed-off-by: Marco Liebel <marco.liebel@oss.qualcomm.com>
Reviewed-by: Brian Cain <brian.cain@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
3 months agoHexagon (target/hexagon) Remove snprint_a_pkt_debug
Taylor Simpson [Tue, 17 Feb 2026 21:22:45 +0000 (14:22 -0700)] 
Hexagon (target/hexagon) Remove snprint_a_pkt_debug

Function is not used

Signed-off-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Reviewed-by: Anton Johansson <anjo@rev.ng>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
3 months agotests/tcg/hexagon: Add test for revision-gated instruction decoding
Brian Cain [Tue, 17 Feb 2026 21:22:44 +0000 (14:22 -0700)] 
tests/tcg/hexagon: Add test for revision-gated instruction decoding

Add check_rev_gating, a linux-user test that verifies the decoder
rejects instructions from a newer CPU revision than the one selected
by the ELF binary's e_flags.

Co-authored-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Co-authored-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Reviewed-by: Marco Liebel <marco.liebel@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
3 months agoHexagon (target/hexagon) Disassembly of invalid packets
Taylor Simpson [Tue, 17 Feb 2026 21:22:43 +0000 (14:22 -0700)] 
Hexagon (target/hexagon) Disassembly of invalid packets

We pass the Hexagon CPU definition to disassemble_hexagon.  This allows
decode_packet to know if the opcodes are supported.

Note that we print valid instructions in a packet when one or more is
invalid.  Rather than this
0x0002128c:  0x1eae4fec { <invalid>
0x00021290:  0x1c434c04 <invalid>
0x00021294:  0x1e03edf0 <invalid> }

We print this
0x0002128c:  0x1eae4fec { <invalid>
0x00021290:  0x1c434c04 V4.w = vadd(V12.w,V3.w)
0x00021294:  0x1e03edf0 V16 = V13 }

Co-authored-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Co-authored-by: Brian Cain <brian.cain@oss.qualcomm.com>
Signed-off-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Reviewed-by: Anton Johansson <anjo@rev.ng>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
3 months agoHexagon (target/hexagon) Check each opcode against current CPU definition
Taylor Simpson [Tue, 17 Feb 2026 21:22:42 +0000 (14:22 -0700)] 
Hexagon (target/hexagon) Check each opcode against current CPU definition

During decoding, check that the opcode is supported in the current
Hexagon CPU definition

Co-authored-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Co-authored-by: Brian Cain <brian.cain@oss.qualcomm.com>
Signed-off-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Reviewed-by: Anton Johansson <anjo@rev.ng>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
3 months agoHexagon (target/hexagon) Introduce tag_rev_info.c.inc
Matheus Tavares Bernardino [Tue, 17 Feb 2026 21:22:41 +0000 (14:22 -0700)] 
Hexagon (target/hexagon) Introduce tag_rev_info.c.inc

Table that records which CPU revision introduced or removed
for each opcode

Co-authored-by: Brian Cain <brian.cain@oss.qualcomm.com>
Co-authored-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Signed-off-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Reviewed-by: Anton Johansson <anjo@rev.ng>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
3 months agoHexagon (target/hexagon) Add Hexagon definition field to DisasContext
Taylor Simpson [Tue, 17 Feb 2026 21:22:40 +0000 (14:22 -0700)] 
Hexagon (target/hexagon) Add Hexagon definition field to DisasContext

Initialize the field in hexagon_tr_init_disas_context

Co-authored-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Co-authored-by: Brian Cain <brian.cain@oss.qualcomm.com>
Signed-off-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Reviewed-by: Anton Johansson <anjo@rev.ng>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
3 months agoHexagon (linux-user/hexagon) Identify Hexagon version in ELF file
Taylor Simpson [Tue, 17 Feb 2026 21:22:39 +0000 (14:22 -0700)] 
Hexagon (linux-user/hexagon) Identify Hexagon version in ELF file

Return proper Hexagon CPU version from get_elf_cpu_model

Co-authored-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Co-authored-by: Brian Cain <brian.cain@oss.qualcomm.com>
Signed-off-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Reviewed-by: Anton Johansson <anjo@rev.ng>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
3 months agoHexagon (target/hexagon) Properly handle Hexagon CPU version
Taylor Simpson [Tue, 17 Feb 2026 21:22:38 +0000 (14:22 -0700)] 
Hexagon (target/hexagon) Properly handle Hexagon CPU version

Add the following CPU versions that were previously missing
    v5
    v55
    v60
    v61
    v62
    v65

Create a CPUHexagonDef struct to represent the definition of a core
    Currently contains an enum with the known Hexagon CPU versions
Add a field to HexagonCPUClass to note the Hexagon definition

Co-authored-by: Matheus Tavares Bernardino <matheus.bernardino@oss.qualcomm.com>
Co-authored-by: Brian Cain <brian.cain@oss.qualcomm.com>
Signed-off-by: Taylor Simpson <ltaylorsimpson@gmail.com>
Reviewed-by: Anton Johansson <anjo@rev.ng>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
3 months agomigration/qemu-file: drop incorrect const from qemu_get_buffer_at buf
Junjie Cao [Mon, 20 Apr 2026 20:13:17 +0000 (04:13 +0800)] 
migration/qemu-file: drop incorrect const from qemu_get_buffer_at buf

qemu_get_buffer_at() reads data *into* buf -- it should not be const.
Drop the qualifier and remove the now-unnecessary cast.

Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260420201317.30199-4-junjie.cao@intel.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration/file: switch file_write_ramblock_iov to pwritev_all
Junjie Cao [Mon, 20 Apr 2026 20:13:16 +0000 (04:13 +0800)] 
migration/file: switch file_write_ramblock_iov to pwritev_all

file_write_ramblock_iov() uses single-shot qio_channel_pwritev() and
only checks for ret < 0.  A short write (0 <= ret < requested) would be
treated as success.

Switch to qio_channel_pwritev_all() which retries until all bytes are
written or an error occurs.

Fixes: f427d90b98 ("migration/multifd: Support outgoing mapped-ram stream format")
Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260420201317.30199-3-junjie.cao@intel.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration/qemu-file: switch buffer_at functions to positioned I/O _all helpers
Junjie Cao [Mon, 20 Apr 2026 20:13:15 +0000 (04:13 +0800)] 
migration/qemu-file: switch buffer_at functions to positioned I/O _all helpers

qemu_put_buffer_at() and qemu_get_buffer_at() have the same pattern as
the bug fixed in multifd_file_recv_data(): the ssize_t return value from
the channel layer is stored in a size_t variable, and a short transfer
would be mishandled rather than retried.

Switch to qio_channel_pwrite_all() / qio_channel_pread_all() which
handle short transfers internally and make the code more robust and
consistent with the rest of the positioned I/O call sites.

Fixes: 7f5b50a401 ("migration/qemu-file: add utility methods for working with seekable channels")
Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260420201317.30199-2-junjie.cao@intel.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agotests/qtest/migration: fix fd leak in ufd_version_check
Trieu Huynh [Sun, 19 Apr 2026 11:03:04 +0000 (18:03 +0700)] 
tests/qtest/migration: fix fd leak in ufd_version_check

ufd_version_check() opens a userfaultfd via uffd_open() but never closes
it on any path where the open succeeded: the UFFDIO_API failure path,
the missing-ioctls path, and the success path all returned without
calling close(ufd).

Convert to a goto-out pattern consistent with uffd_open() used in
util/userfaultfd.c and migration/postcopy-ram.c, ensuring the fd is
always closed before returning.

Signed-off-by: Trieu Huynh <vikingtc4@gmail.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260419110304.8661-1-viking4@gmail.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agotests/unit: add pread/pwrite _all tests for io channel file
Junjie Cao [Mon, 13 Apr 2026 21:45:49 +0000 (05:45 +0800)] 
tests/unit: add pread/pwrite _all tests for io channel file

Add unit tests for the new qio_channel_pread{v,}_all{,_eof}() and
qio_channel_pwrite{v,}_all() APIs.

The basic tests write data to a file channel, then read it back at
various offsets using both the single-buffer and iovec variants to
make sure the round-trip produces identical content.  The _eof tests
verify all three return cases -- full read (1), clean EOF (0), and
partial-then-EOF (-1 with error set) -- and check that the strict
wrappers (preadv_all / pread_all) treat a clean EOF as an error.

All tests are guarded by CONFIG_PREADV since the underlying channel
methods require preadv(2).

Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Acked-by: Daniel P. Berrangé <berrange@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260413214549.926435-5-junjie.cao@intel.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration/file: fix type mismatch and NULL deref in multifd_file_recv_data
Junjie Cao [Mon, 13 Apr 2026 21:45:48 +0000 (05:45 +0800)] 
migration/file: fix type mismatch and NULL deref in multifd_file_recv_data

multifd_file_recv_data() stores the return value of qio_channel_pread()
(ssize_t) in a size_t variable.  On I/O error the -1 return value wraps
to SIZE_MAX, producing a nonsensical read size in the error message.

More critically, a short read (0 <= ret < data->size) is possible when
the migration file is truncated.  In that case qio_channel_pread()
returns a non-negative value without setting *errp.  The function then
calls error_prepend(errp, ...) which dereferences *errp -- a NULL
pointer -- crashing QEMU.

Fix both issues by switching to qio_channel_pread_all() introduced in
a previous patch, which retries on short reads and treats end-of-file
as an error, so the caller no longer needs to check the byte count
manually.  Add ERRP_GUARD() so that error_prepend() works correctly
even when errp is &error_fatal or NULL.

Fixes: a49d15a38d3d ("migration/multifd: Support incoming mapped-ram stream format")
Suggested-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Link: https://lore.kernel.org/qemu-devel/20260413214549.926435-4-junjie.cao@intel.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agoio/channel: introduce qio_channel_pwrite{v,}_all()
Junjie Cao [Mon, 13 Apr 2026 21:45:47 +0000 (05:45 +0800)] 
io/channel: introduce qio_channel_pwrite{v,}_all()

Add positioned write helpers that retry on short writes, matching
the pread_all family from the previous patch.

  qio_channel_pwritev_all()  -- retry loop; returns 0 on success,
                                 -1 on error.
  qio_channel_pwrite_all()   -- single-buffer convenience wrapper.

Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Link: https://lore.kernel.org/qemu-devel/20260413214549.926435-3-junjie.cao@intel.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agoio/channel: introduce qio_channel_pread{v, }_all{, _eof}()
Junjie Cao [Mon, 13 Apr 2026 21:45:46 +0000 (05:45 +0800)] 
io/channel: introduce qio_channel_pread{v, }_all{, _eof}()

qio_channel_pread() and qio_channel_preadv() perform a single
positioned read and may return a short result.  Callers that need all
bytes currently have to open-code a retry loop or simply treat a short
read as an error.

Introduce four new helpers following the existing read_all / readv_all
pattern:

  qio_channel_preadv_all_eof()  -- retry loop; returns 1 on success,
                                    0 on clean EOF, -1 on error.
  qio_channel_preadv_all()      -- wraps _eof; treats early EOF as
                                    error; returns 0 / -1.
  qio_channel_pread_all_eof()   -- single-buffer convenience wrapper
                                    around preadv_all_eof().
  qio_channel_pread_all()       -- single-buffer convenience wrapper
                                    around preadv_all().

These advance the file offset internally after each partial read.
All four are marked coroutine_mixed_fn, consistent with the existing
_all helpers.

Suggested-by: Peter Xu <peterx@redhat.com>
Signed-off-by: Junjie Cao <junjie.cao@intel.com>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Acked-by: Daniel P. Berrangé <berrange@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260413214549.926435-2-junjie.cao@intel.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: validate page_size in mapped-ram header before use
Trieu Huynh [Sun, 5 Apr 2026 09:44:47 +0000 (16:44 +0700)] 
migration: validate page_size in mapped-ram header before use

mapped_ram_read_header() reads page_size from the migration stream and
stores it in MappedRamHeader, but does not validate that the value is
non-zero before it is later used in parse_ramblock_mapped_ram():

num_pages = length / header.page_size;

If a corrupted or malformed migration stream provides invalid, guest
resumes either with corrupted memory or crashes unexpectedly (eg.
page_size = 0)

Add validation in mapped_ram_read_header() to reject invalid page_size
values early and return an error instead of continuing with an invalid
header.

Steps to reproduce:

Create a migration snapshot with mapped-ram enabled:
(qemu) migrate_set_capability mapped-ram on
(qemu) migrate file:/tmp/qemu-snapshots/snapshot.bin
Modify the snapshot so that MappedRamHeader.page_size becomes diff with
target psize. (0/512/8192/1GB).
Restore the snapshot:
(qemu) migrate_set_capability mapped-ram on
(qemu) migrate_incoming file:/tmp/qemu-snapshots/snapshot.bin

As-is:
* [0]: Floating point exception (core dumped)
* [512/8192]: Silent corruption
* [1GB]: "post load hook failed for: kvm-tpr-opt" (EPERM)
To-be:
* All: qemu-system-x86_64: Migration mapped-ram header has invalid
  page_size [val] (expected 4096)

Signed-off-by: Trieu Huynh <vikingtc4@gmail.com>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260405094447.11347-1-viking4@gmail.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agotests/unit/test-vmstate: add tests for VMS_ARRAY_OF_POINTER_AUTO_ALLOC
Alexander Mikhalitsyn [Wed, 1 Apr 2026 20:28:44 +0000 (16:28 -0400)] 
tests/unit/test-vmstate: add tests for VMS_ARRAY_OF_POINTER_AUTO_ALLOC

Add tests for VMSTATE_VARRAY_OF_POINTER_TO_STRUCT_UINT32_ALLOC.

Signed-off-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
[peterx: Removed two tests due to macro not used, rebase, fix warning]
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Juraj Marcin <jmarcin@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260401202844.673494-12-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agovmstate: Stop checking size for nullptr compression
Fabiano Rosas [Wed, 1 Apr 2026 20:28:43 +0000 (16:28 -0400)] 
vmstate: Stop checking size for nullptr compression

The NULL pointer marker code applies only to VMS_ARRAY_OF_POINTER,
where the size is never NULL. Move the setting of is_null under
VMS_ARRAY_OF_POINTER, so we can stop checking the size.

Reviewed-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Juraj Marcin <jmarcin@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260401202844.673494-11-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agovmstate: Implement VMS_ARRAY_OF_POINTER_AUTO_ALLOC
Peter Xu [Wed, 1 Apr 2026 20:28:42 +0000 (16:28 -0400)] 
vmstate: Implement VMS_ARRAY_OF_POINTER_AUTO_ALLOC

Introduce a new flag, VMS_ARRAY_OF_POINTER_AUTO_ALLOC, for VMSD field.  It
must be used together with VMS_ARRAY_OF_POINTER.

It can be used to allow migration of an array of pointers where the
pointers may point to NULLs.

Note that we used to allow migration of a NULL pointer within an array that
is being migrated. That corresponds to the code around vmstate_info_nullptr
where we may get/put one byte showing that the element of an array is NULL.

That usage is fine but very limited, it's because even if it will migrate a
NULL pointer with a marker, it still works in a way that both src and dest
QEMUs must know exactly which elements of the array are non-NULL, so
instead of dynamically loading an array (which can have NULL pointers), it
actually only verifies the known NULL pointers are still NULL pointers
after migration.

Also, in that case since dest QEMU knows exactly which element is NULL,
which is not NULL, dest QEMU's device code will manage all allocations for
the elements before invoking vmstate_load_vmsd().

That's not enough per evolving needs of new device states that may want to
provide real dynamic array of pointers, like what Alexander proposed here
with the NVMe device migration:

https://lore.kernel.org/r/20260317102708.126725-1-alexander@mihalicyn.com

This patch is an alternative approach to address the problem.

Along with the flag, introduce two new macros:

  VMSTATE_VARRAY_OF_POINTER_TO_STRUCT_UINT{8|32}_ALLOC()

Which will be used very soon in the NVMe series.

Reviewed-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Tested-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Juraj Marcin <jmarcin@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260401202844.673494-10-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agovmstate: Implement load of ptr marker in vmstate core
Peter Xu [Wed, 1 Apr 2026 20:28:41 +0000 (16:28 -0400)] 
vmstate: Implement load of ptr marker in vmstate core

The loader side of ptr marker is pretty straightforward, instead of playing
the inner_field trick, just do the load manually assuming the marker layout
is a stable ABI (which it is true already).

This will remove some logic while loading VMSD, and hopefully it makes it
slightly easier to read.  Unfortunately, we still need to keep the sender
side because of the JSON blob we're maintaining..

This paves way for future processing of non-NULL markers as well.

When at it, not check "size" anymore for existing NULL markers, and move it
under the same VMS_ARRAY_OF_POINTER section because that's the only place
that NULL marker can happen (which guarantess size==host ptr size, which is
non-zero).

Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Juraj Marcin <jmarcin@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260401202844.673494-9-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agovmstate: Allow vmstate_info_nullptr to emit non-NULL markers
Peter Xu [Wed, 1 Apr 2026 20:28:40 +0000 (16:28 -0400)] 
vmstate: Allow vmstate_info_nullptr to emit non-NULL markers

We used to have one vmstate called "nullptr" which is only used to generate
one-byte hint to say one pointer is NULL.

Let's extend its use so that it will generate another byte to say the
pointer is non-NULL.

With that, the name of the info struct (or functions) do not apply anymore.
Update correspondingly.

Update analyze-migration.py to work with the new layout.

No functional change intended yet.

Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Juraj Marcin <jmarcin@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260401202844.673494-8-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agovmstate: Introduce vmstate_save_field_with_vmdesc()
Peter Xu [Wed, 1 Apr 2026 20:28:39 +0000 (16:28 -0400)] 
vmstate: Introduce vmstate_save_field_with_vmdesc()

Introduce a helper to do both the JSON blob generations and save vmstate.
This further shrinks the function a bit.  More importantly, we'll need to
save two fields in one loop very soon in the future with the JSON blob.

Reviewed-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Juraj Marcin <jmarcin@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260401202844.673494-7-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agovmstate: Rename VMS_NULLPTR_MARKER to VMS_MARKER_PTR_NULL
Peter Xu [Wed, 1 Apr 2026 20:28:38 +0000 (16:28 -0400)] 
vmstate: Rename VMS_NULLPTR_MARKER to VMS_MARKER_PTR_NULL

Prepare for a new MARKER for non-NULL pointer.

Reviewed-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Juraj Marcin <jmarcin@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260401202844.673494-6-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agovmstate: Update max_elems early and check field compressable once
Peter Xu [Wed, 1 Apr 2026 20:28:37 +0000 (16:28 -0400)] 
vmstate: Update max_elems early and check field compressable once

QEMU has a trick in vmstate_save_vmsd_v(), where it will try to compress
multiple JSON entries into one with a count to avoid duplicated entries.

That only applies to the cases where vmsd_can_compress() should return
true.  For example, vmsd_desc_field_start() later (who will take the
updated max_elems as the last parameter) will ignore the value passed in
when vmsd_can_compress() returns false.

Do that check once at the start of loop, and use it to update max_elems, so
that max_elems keeps 1 for uncompressable VMSD fields, which is more
straightforward.

This also paves way to make this counter work for ptr marker VMSD fields
too.

No functional change intended in this patch alone.

Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Juraj Marcin <jmarcin@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260401202844.673494-5-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agovmstate: Do not set size for VMS_ARRAY_OF_POINTER
Peter Xu [Wed, 1 Apr 2026 20:28:36 +0000 (16:28 -0400)] 
vmstate: Do not set size for VMS_ARRAY_OF_POINTER

When VMS_ARRAY_OF_POINTER is specified, it means the vmstate field is an
array of pointers.

The size of the element is not relevant to whatever it is stored inside: it
is always the host pointer size.

Let's reserve the "size" field in this case for future use, update
vmstate_size() so as to make it still work for array of pointers properly.

When at this, provide rich documentation on how size / size_offset works in
vmstate.

Reviewed-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Juraj Marcin <jmarcin@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260401202844.673494-4-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agovmstate: Pass in struct itself for VMSTATE_VARRAY_OF_POINTER_UINT32
Peter Xu [Wed, 1 Apr 2026 20:28:35 +0000 (16:28 -0400)] 
vmstate: Pass in struct itself for VMSTATE_VARRAY_OF_POINTER_UINT32

Passing in a pointer almost never helps.  Convert it to pass in struct for
further refactoring on VMS_ARRAY_OF_POINTER.

Reviewed-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Juraj Marcin <jmarcin@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260401202844.673494-3-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agovmstate: Pass in struct itself for VMSTATE_ARRAY_OF_POINTER
Peter Xu [Wed, 1 Apr 2026 20:28:34 +0000 (16:28 -0400)] 
vmstate: Pass in struct itself for VMSTATE_ARRAY_OF_POINTER

Passing in a pointer almost never helps.  Convert it to pass in struct for
further refactoring on VMS_ARRAY_OF_POINTER.

Reviewed-by: Alexander Mikhalitsyn <aleksandr.mikhalitsyn@futurfusion.io>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Signed-off-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Juraj Marcin <jmarcin@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260401202844.673494-2-peterx@redhat.com
[delete spurious hunk touching roms/seabios]
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: fix QIOChannelFile leak on error in file_connect_outgoing
Trieu Huynh [Sat, 28 Mar 2026 12:12:14 +0000 (21:12 +0900)] 
migration: fix QIOChannelFile leak on error in file_connect_outgoing

Commit 03a680c978 changed g_autoptr(QIOChannelFile) to a plain pointer
but failed to restore the necessary object_unref() calls on error paths.
Previously, these were handled implicitly by the g_autoptr cleanup
mechanism.

Two error paths currently leak the QIOChannelFile object and its
underlying file descriptor:

  1. When ftruncate() fails (e.g., on character or block devices).
  2. When qio_channel_io_seek() fails after the channel is created.

In environments that retry migration automatically (e.g., libvirt),
these FDs accumulate until QEMU hits RLIMIT_NOFILE and fails with
EMFILE (Too many open files).

Add the missing object_unref() calls to both error paths to ensure
resources are properly released.

Signed-off-by: Trieu Huynh <vikingtc4@gmail.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260328121215.159532-1-vikingtc4@gmail.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agotests/qtest/migration: Add mapped-ram/postcopy validation test
Takeru Hayasaka [Fri, 27 Mar 2026 16:46:58 +0000 (16:46 +0000)] 
tests/qtest/migration: Add mapped-ram/postcopy validation test

The migration capability checks reject enabling postcopy-ram together
with mapped-ram, but there is no qtest covering this incompatibility.

Add a validation test that verifies QMP rejects the combination in
both capability ordering cases and returns the expected error.

This keeps the existing capability boundary covered without changing
migration behavior.

Signed-off-by: Takeru Hayasaka <hayatake396@gmail.com>
Link: https://lore.kernel.org/qemu-devel/20260327164705.1990226-1-hayatake396@gmail.com
[unlink src_serial]
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: Tweak description of migration property multifd-compression
Markus Armbruster [Thu, 26 Mar 2026 07:42:47 +0000 (08:42 +0100)] 
migration: Tweak description of migration property multifd-compression

Help for the migration pseudo-device shows property
"multifd-compression" like this:

  multifd-compression=<MultiFDCompression> - multifd_compression values (none/zlib/zstd/qpl/uadk/qatzip) (default: none)

Change it to

  multifd-compression=<MultiFDCompression> - multifd compression method (none/zlib/zstd/qpl/uadk/qatzip) (default: none)

Signed-off-by: Markus Armbruster <armbru@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260326074247.188674-4-armbru@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration/vmstate-types: move to new migration APIs
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:23:02 +0000 (00:23 +0300)] 
migration/vmstate-types: move to new migration APIs

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-19-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: drop VMStateField.err_hint
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:23:01 +0000 (00:23 +0300)] 
migration: drop VMStateField.err_hint

The field is unused, all users of VMSTATE_*_EQUAL pass _err_hint=NULL.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Acked-by: Eric Farman <farman@linux.ibm.com> # s390
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-18-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agohw/s390x/css: drop use of .err_hint for vmstate
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:23:00 +0000 (00:23 +0300)] 
hw/s390x/css: drop use of .err_hint for vmstate

That's the only usage through the whole base. Doesn't
worth keeping the whole complexity. And 2.7 machines were
long ago.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-17-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration/savevm: move to new migration APIs
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:59 +0000 (00:22 +0300)] 
migration/savevm: move to new migration APIs

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-16-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration/cpr: move to new migration APIs
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:58 +0000 (00:22 +0300)] 
migration/cpr: move to new migration APIs

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-15-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: introduce vmstate_load_vmsd() and vmstate_save_vmsd()
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:57 +0000 (00:22 +0300)] 
migration: introduce vmstate_load_vmsd() and vmstate_save_vmsd()

Introduce new APIs, returning bool.
The analysis
https://lore.kernel.org/qemu-devel/aQDdRn8t0B8oE3gf@x1.local/
shows, that vmstate_load_state() return value actually only
used to check for success, specific errno values doesn't make
sense.

With this commit we introduce new functions with modern bool
interface, and in following commits we'll update the
code base to use them, starting from migration/ code, and
finally we will remove old vmstate_load_state() and
vmstate_save_state().

This patch reworks existing functions to new one, so that
old interfaces are simple wrappers, which will be easy to
remove later.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-14-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: VMStateInfo: introduce new handlers with errp
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:56 +0000 (00:22 +0300)] 
migration: VMStateInfo: introduce new handlers with errp

Add new APIs with errp, to allow handlers report good
error messages. We'll convert existing handlers soon.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-13-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: convert vmstate_subsection_save/load functions to bool
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:55 +0000 (00:22 +0300)] 
migration: convert vmstate_subsection_save/load functions to bool

Convert them to bool return value, as preparation to further
convertion of vmstate_save/load_state().

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-12-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: factor out vmstate_post_load() from vmstate_load_state()
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:54 +0000 (00:22 +0300)] 
migration: factor out vmstate_post_load() from vmstate_load_state()

Simplify vmstate_load_state() which is rather big, and simplify further
refactoring.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-11-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: factor out vmstate_load_field() from vmstate_load_state()
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:53 +0000 (00:22 +0300)] 
migration: factor out vmstate_load_field() from vmstate_load_state()

Simplify vmstate_load_state() which is rather big, and simplify further
refactoring.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-10-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: factor out vmstate_pre_load() from vmstate_load_state()
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:52 +0000 (00:22 +0300)] 
migration: factor out vmstate_pre_load() from vmstate_load_state()

Simplify vmstate_load_state() which is rather big, and simplify further
refactoring.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-9-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: factor out vmstate_save_field() from vmstate_save_state()
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:51 +0000 (00:22 +0300)] 
migration: factor out vmstate_save_field() from vmstate_save_state()

Simplify vmstate_save_state() which is rather big, and simplify further
refactoring.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-8-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: factor out vmstate_pre_save() from vmstate_save_state()
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:50 +0000 (00:22 +0300)] 
migration: factor out vmstate_pre_save() from vmstate_save_state()

Simplify vmstate_save_state() which is rather big, and simplify further
refactoring.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-7-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: vmstate_save/load_state(): refactor tracing errors
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:49 +0000 (00:22 +0300)] 
migration: vmstate_save/load_state(): refactor tracing errors

To simplify further changes (convertion to bool+errp APIs),
let's rework some error paths:

- get rid of int ret in traces, as we are moving to bool+errp APIs
- split traces to _fail / _success (seems better than add boolean
  result to the message).
- prefer short error paths (return immediately on error)
- around trace_vmstate_load_field_error(), do not call
  qemu_file_set_error(), if the erroc comes from qemu_file_get_error()

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-6-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: vmstate_load_state(): add some newlines
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:48 +0000 (00:22 +0300)] 
migration: vmstate_load_state(): add some newlines

Split logical blocks by newlines, that simplify reading the code.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-5-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: make .post_save() a void function
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:47 +0000 (00:22 +0300)] 
migration: make .post_save() a void function

All other handlers now have _errp() variants. Should we go this way
for .post_save()? Actually it's rather strange, when the vmstate do
successful preparations in .pre_save(), then successfully save all
sections and subsections, end then fail when all the state is
successfully transferred to the target.

Happily, we have only three .post_save() realizations, all always
successful. Let's make this a rule.

Also note, that we call .post_save() in two places, and handle
its (theoretical) failure inconsistently. Fix that too.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Zhao Liu <zhao1.liu@intel.com> #rust
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-4-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: make vmstate_save_state_v() static
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:46 +0000 (00:22 +0300)] 
migration: make vmstate_save_state_v() static

It's used only in vmstate.c.

Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-3-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agomigration: vmstate_save_state_v: fix double error_setg
Vladimir Sementsov-Ogievskiy [Wed, 4 Mar 2026 21:22:45 +0000 (00:22 +0300)] 
migration: vmstate_save_state_v: fix double error_setg

We may call error_setg twice on same errp if inner
vmstate_save_state_v() or vmstate_save_state() call fails. Next we will
crash on assertion in error_setv().

Fixes: 848a0503422d043 "migration: Update error description outside migration.c"
Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260304212303.667141-2-vsementsov@yandex-team.ru
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agotests/functional: Make socat wait longer in migration exec test
Fabiano Rosas [Wed, 22 Apr 2026 23:00:01 +0000 (20:00 -0300)] 
tests/functional: Make socat wait longer in migration exec test

The migration_with_exec test is failing sporadically for all
architectures due to a race when the destination socat process takes
too long to start listening while the source process is already
issuing connect().

The race is inherent because the exec: migration spawns the
to-be-exec'ed command asynchronously and returns from the
migrate-incoming command. The localhost-only testcase is not
representative of the majority of migrations. In a real scenario
between two different hosts that race wouldn't happen.

Fix the testcase by configuring the source socat command to wait
indefinitely while trying to connect.

Reviewed-by: Thomas Huth <thuth@redhat.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260422230001.3168-1-farosas@suse.de
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agohw/display: don't accidentally autofree existing virgl resources
Alex Bennée [Fri, 17 Apr 2026 12:27:03 +0000 (13:27 +0100)] 
hw/display: don't accidentally autofree existing virgl resources

While sanity checking a create blob operation the use of the auto
freed res variable could lead to inadvertently freeing an existing
blob.

Avoid this by in-lining the virtio_gpu_virgl_find_resource() check as
the value is not needed anyway.

While at it add a comment to the end and use g_steal_pointer to make
it clearer the object lifetime exceeds the function bounds if we pass
all the checks.

Fixes: CVE-2026-6502
Fixes: 7c092f17cce (virtio-gpu: Handle resource blob commands)
Message-ID: 20260417094443.785462-1-alex.bennee@linaro.org
Reviewed-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org>
Cc: qemu-stable@nongnu.org
Message-ID: <20260417122703.845442-1-alex.bennee@linaro.org>
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
Reviewed-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>
3 months agoui/sdl2: Fix assumption of EGL presence at runtime
Anthony Roberts [Thu, 9 Apr 2026 11:02:55 +0000 (12:02 +0100)] 
ui/sdl2: Fix assumption of EGL presence at runtime

The original commit had a section of code which worked on the assumption
that if OpenGL was enabled at build, it was present on the end user machine,
and calls could be made to it. This is not always the case (such as Windows
on Arm devices).

This line should have also included a runtime check.

This commit moves the relevant line to inside a runtime check for OpenGL.

Fixes: 52053b7e0a0e ("ui/sdl2: Implement dpy dmabuf functions")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3347
Cc: qemu-stable@nongnu.org
Signed-off-by: Anthony Roberts <anthony.roberts@linaro.org>
Reviewed-by: Alex Bennée <alex.bennee@linaro.org>
Message-ID: <20260409110256.684-1-anthony.roberts@linaro.org>
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
3 months agocheckpatch: Allow spaces after all coroutine annotations
Fabiano Rosas [Mon, 20 Apr 2026 19:13:56 +0000 (16:13 -0300)] 
checkpatch: Allow spaces after all coroutine annotations

The coroutine annotations may be used in the declaration of function
pointers, which triggers checkpatch due to the space before the
parentheses. E.g:

  int coroutine_fn (*run)(Job *job, Error **errp);
                  ^
The coroutine_fn annotation is already included in the list of terms
where spaces are allowed. Add the other coroutine annotations:
coroutine_mixed_fn and no_coroutine_fn.

Reviewed-by: Markus Armbruster <armbru@redhat.com>
Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260420191356.4439-1-farosas@suse.de
Signed-off-by: Fabiano Rosas <farosas@suse.de>
3 months agotarget/i386: emulate: include name of unhandled instruction
Mohamed Mediouni [Tue, 7 Apr 2026 14:17:57 +0000 (16:17 +0200)] 
target/i386: emulate: include name of unhandled instruction

Instead of just the command number, include the instruction name to make debugging easier.

Signed-off-by: Mohamed Mediouni <mohamed@unpredictable.fr>
Link: https://lore.kernel.org/r/20260407141809.16862-2-mohamed@unpredictable.fr
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agomemory: Optimize flatview_simplify() to eliminate redundant memmove calls
Bin Guo [Tue, 31 Mar 2026 06:07:31 +0000 (14:07 +0800)] 
memory: Optimize flatview_simplify() to eliminate redundant memmove calls

The original flatview_simplify() implementation uses memmove() to shift
array elements after each merge operation, resulting in O(n²) time
complexity in the worst case. This is inefficient for VMs with large
memory topologies containing hundreds of MemoryRegions.

Replace the memmove-based approach with a two-pointer in-place compression
algorithm that achieves O(n) time complexity. The new algorithm uses a
write pointer i and a read pointer j, where i ≤ j is always maintained.
This invariant ensures we never overwrite unprocessed data, making memmove
unnecessary.

Signed-off-by: Bin Guo <guobin@linux.alibaba.com>
Link: https://lore.kernel.org/r/20260331060731.82641-1-guobin@linux.alibaba.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agomeson: add missing semicolon in pthread_condattr_setclock test
Stepan Popov [Mon, 30 Mar 2026 13:14:06 +0000 (16:14 +0300)] 
meson: add missing semicolon in pthread_condattr_setclock test

The test code was missing a semicolon after the pthread_condattr_t
variable declaration.

Signed-off-by: Stepan Popov <Stepan.Popov@kaspersky.com>
Reviewed-by: Alex Bennée <alex.bennee@linaro.org>
Fixes: 657ac98b58c ("thread-posix: use monotonic clock for QemuCond and QemuSemaphore", 2022-02-22)
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Link: https://lore.kernel.org/r/20260330131406.87080-1-Stepan.Popov@kaspersky.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agothread-win32: replace CRITICAL_SECTION with SRWLOCK
Paolo Bonzini [Mon, 30 Mar 2026 14:17:15 +0000 (16:17 +0200)] 
thread-win32: replace CRITICAL_SECTION with SRWLOCK

SRWLOCK is a much cheaper primitive than CRITICAL_SECTION, which
basically exists only as a legacy API.  The SRWLOCK is a single word
in memory and it is cheaper to just initialize it always.

Reviewed-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agotarget/i386/tcg: fix decoding of MOVBE and CRC32 in 16-bit mode
Paolo Bonzini [Tue, 31 Mar 2026 06:32:23 +0000 (08:32 +0200)] 
target/i386/tcg: fix decoding of MOVBE and CRC32 in 16-bit mode

Table A-4 of the SDM shows

                    F0                     F1
--------------------------------------------------------
     NP           MOVBE Gy,My           MOVBE My,Gy
     66           MOVBE Gw,Mw           MOVBW Mw,Gw
     F2           CRC32 Gd,Eb           CRC32 Gd,Ey
  66+F2           CRC32 Gd,Eb           CRC32 Gd,Ew

However, this is incorrect.  Both MOVBE and (for 0xF1) CRC32
take Gv, Ev or Mv operands.  In 16-bit mode therefore the
operand is of 16-bit size without prefix and 32-bit mode
with 0x66 (the data size override).

For example, with NASM you get:

                                 bits 16
   67 0F 38 F0 02                movbe ax, [edx]
   66 67 0F 38 F0 02             movbe eax, [edx]

   67 F2 0F 38 F1 02             crc32 ax, word [edx]
   66 67 F2 0F 38 F1 02          crc32 eax, dword [edx]

versus

                                 bits 32
   66 0F 38 F0 02                movbe ax, [edx]
   0F 38 F0 02                   movbe eax, [edx]

   66 F2 0F 38 F1 02             crc32 eax, word [edx]
   F2 0F 38 F1 02                crc32 eax, dword [edx]

The instruction is listed correctly in the APX documentation
as "SCALABLE" (which means it has v-size operands).

Cc: qemu-stable@nongnu.org
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agoaccel/mshv: return correct errno value from ioeventfd failure
Aastha Rawat [Thu, 9 Apr 2026 11:53:07 +0000 (11:53 +0000)] 
accel/mshv: return correct errno value from ioeventfd failure

Returning the raw ioctl return value results in misleading error
message. Ensure that actual failure reason is propagated by returning
-errno for ioeventfd failure.

Signed-off-by: Aastha Rawat <aastharawat@linux.microsoft.com>
Reviewed-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260409-fix_ioevent-v1-2-053b810ae6fb@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agoaccel/mshv: fix ioeventfd deassignment to forward correct datamatch value
Aastha Rawat [Thu, 9 Apr 2026 11:53:06 +0000 (11:53 +0000)] 
accel/mshv: fix ioeventfd deassignment to forward correct datamatch value

unregister_ioevent() is not forwarding the datamatch (queue index) to
the mshv driver, causing only the first VirtIO-MMIO queue to be
deassigned correctly. Subsequent queues fail with `-ENOENT`, triggering
a fatal abort().

This failure was discovered while booting arm64 EDK2 firmware with mshv
accel.

Signed-off-by: Aastha Rawat <aastharawat@linux.microsoft.com>
Reviewed-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Link: https://lore.kernel.org/r/20260409-fix_ioevent-v1-1-053b810ae6fb@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agotarget/i386/mshv: Fix segment regression in MMIO emu
Magnus Kulke [Fri, 10 Apr 2026 14:26:52 +0000 (16:26 +0200)] 
target/i386/mshv: Fix segment regression in MMIO emu

When the segmentation code has been reworked, there is now an
unconditional call to emul_ops->read_segment_descriptor(). The MSHV impl
was delegating this to x86_read_segement_descriptor(), which read from
the GDT in guest memory. This fails for selector.idx == 0 and when no
GDT is set up (which is the case in real mode).

In the fix we change the MSHV impl to fill segment descriptor from
SegmentCache, that was populated from the hypervisor by mshv_load_regs()
before instruction emulation.

Fixes: 09442d98ab (target/i386: emulate: segmentation rework)
Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
Reviewed-by: Mohamed Mediouni <mohamed@unpredictable.fr>
Link: https://lore.kernel.org/r/20260410142652.367541-1-magnuskulke@linux.microsoft.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agomeson: Don't require nm for non-modular builds
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:44:01 +0000 (15:44 +0200)] 
meson: Don't require nm for non-modular builds

In the MSVC build environment, nm is missing; at the same time,
scripts/undefsym.py exits with code 0 at the beginning
for non-modular builds.

So, this change is harmless because it already didn't do anything
in non-modular builds, but remove the additional tool requirements.

Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Link: https://lore.kernel.org/r/20260327134401.270186-16-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agostorage-daemon: use same link arguments as other tools
Paolo Bonzini [Fri, 27 Mar 2026 13:44:00 +0000 (15:44 +0200)] 
storage-daemon: use same link arguments as other tools

Reviewed-by: Kevin Wolf <kwolf@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Link: https://lore.kernel.org/r/20260327134401.270186-15-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agoutil: Remove unused sys/param.h
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:59 +0000 (15:43 +0200)] 
util: Remove unused sys/param.h

We dropped the use of PATH_MAX in commit f3a8bdc1d5b26 (which
basically completely rewrote the path handling).
Now we don't need any sys/param.h defines.

Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Link: https://lore.kernel.org/r/20260327134401.270186-14-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agoutil: Remove unused dirent.h
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:58 +0000 (15:43 +0200)] 
util: Remove unused dirent.h

This one is OK to drop, because the rewrite of path.c in
commit f3a8bdc1d5b26 removed the uses of the dirent.h functions.

Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260327134401.270186-13-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agoosdep: Remove unused strings.h
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:57 +0000 (15:43 +0200)] 
osdep: Remove unused strings.h

We don't use strcasecmp/strncasecmp anymore. Also, we don't
use any other strings.h function. So this include is no more
needed.

Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260327134401.270186-12-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agohw/ppc: Use glib2 instead of strcasecmp/strncasecmp
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:56 +0000 (15:43 +0200)] 
hw/ppc: Use glib2 instead of strcasecmp/strncasecmp

This is a change in semantics. g_ascii_strcasecmp() doesn't honour
locale but strcasecmp() does. But this is OK for at least one reason:
 (1) QEMU always runs with the C locale so there's not an actual
     behaviour change here

Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260327134401.270186-11-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agotarget/xtensa: Use glib2 instead of strcasecmp/strncasecmp
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:55 +0000 (15:43 +0200)] 
target/xtensa: Use glib2 instead of strcasecmp/strncasecmp

This is a change in semantics. g_ascii_strcasecmp() doesn't honour
locale but strcasecmp() does. But this is OK for at least one reason:
 (1) QEMU always runs with the C locale so there's not an actual
     behaviour change here

Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260327134401.270186-10-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agotarget/ppc: Use glib2 instead of strcasecmp/strncasecmp
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:54 +0000 (15:43 +0200)] 
target/ppc: Use glib2 instead of strcasecmp/strncasecmp

This is a change in semantics. g_ascii_strcasecmp() doesn't honour
locale but strcasecmp() does. But this is OK for at least one reason:
 (1) QEMU always runs with the C locale so there's not an actual
     behaviour change here

Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260327134401.270186-9-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agotarget/riscv: Use glib2 instead of strcasecmp/strncasecmp
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:53 +0000 (15:43 +0200)] 
target/riscv: Use glib2 instead of strcasecmp/strncasecmp

This is a change in semantics. g_ascii_strcasecmp() doesn't honour
locale but strcasecmp() does. But this is OK for at least one reason:
 (1) QEMU always runs with the C locale so there's not an actual
     behaviour change here

Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Reviewed-by: Chao Liu <chao.liu.zevorn@gmail.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260327134401.270186-8-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agotarget/sparc: Use glib2 instead of strcasecmp/strncasecmp
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:52 +0000 (15:43 +0200)] 
target/sparc: Use glib2 instead of strcasecmp/strncasecmp

This is a change in semantics. g_ascii_strcasecmp() doesn't honour
locale but strcasecmp() does. But this is OK for at least one reason:
 (1) QEMU always runs with the C locale so there's not an actual
     behaviour change here
 (2) we want the comparison on boolean property value to be a plain
     ASCII one, not to do weird things with "I" in Turkish locales,
     so g_ascii_strcasecmp() is better as it's explicit about that

Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260327134401.270186-7-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agoio: Use glib2 instead of strcasecmp/strncasecmp
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:50 +0000 (15:43 +0200)] 
io: Use glib2 instead of strcasecmp/strncasecmp

This is a change in semantics. g_ascii_strcasecmp() doesn't honour
locale but strcasecmp() does. But this is OK for at least one reason:
 (1) QEMU always runs with the C locale so there's not an actual
     behaviour change here
 (2) we want the comparison data in HTTP header and it should be a plain
     ASCII one, not to do weird things with "I" in Turkish locales,
     so g_ascii_strcasecmp() is better as it's explicit about that

Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260327134401.270186-5-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agoblock: Use glib2 instead of strcasecmp/strncasecmp
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:49 +0000 (15:43 +0200)] 
block: Use glib2 instead of strcasecmp/strncasecmp

This is a change in semantics. g_ascii_strcasecmp() doesn't honour
locale but strcasecmp() does. But this is OK for at least one reason:
 (1) QEMU always runs with the C locale so there's not an actual
     behaviour change here
 (2) we want the comparison on url prefix and it should be a plain ASCII
     one, not to do weird things with "I" in Turkish locales,
     so g_ascii_strcasecmp() is better as it's explicit about that

Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260327134401.270186-4-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agoqom: Use g_ascii_strcasecmp instead of strcasecmp
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:48 +0000 (15:43 +0200)] 
qom: Use g_ascii_strcasecmp instead of strcasecmp

This is a change in semantics. g_ascii_strcasecmp() doesn't honour
locale but strcasecmp() does. But this is OK for at least one reason:
 (1) QEMU always runs with the C locale so there's not an actual
     behaviour change here
 (2) we want the comparison on class names to be a plain ASCII
     one, not to do weird things with "I" in Turkish locales,
     so g_ascii_strcasecmp() is better as it's explicit about that

Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Link: https://lore.kernel.org/r/20260327134401.270186-3-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agomeson: Use stddef.h instead of unistd.h
Kostiantyn Kostiuk [Fri, 27 Mar 2026 13:43:47 +0000 (15:43 +0200)] 
meson: Use stddef.h instead of unistd.h

POSIX says stddef.h provides size_t, which is the only thing
we care about here. unistd.h can be missing in non-POSIX runtimes,
so include stddef.h instead.

Signed-off-by: Kostiantyn Kostiuk <kkostiuk@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Link: https://lore.kernel.org/r/20260327134401.270186-2-kkostiuk@redhat.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agohw: i386: vapic: restore IRQ polling for non-kernel irqchip backends
rickgcn [Sat, 18 Apr 2026 06:14:29 +0000 (14:14 +0800)] 
hw: i386: vapic: restore IRQ polling for non-kernel irqchip backends

69dfc078 extended vAPIC handling for WHPX with user-mode irqchip, but it
also changed vapic_write() case 4 in a way that excludes TCG from
apic_poll_irq().

Before that change, IRQ polling happened whenever no in-kernel irqchip
was active. After the change, it only happened for KVM or WHPX with a
user-mode irqchip. Under TCG, both kvm_enabled() and whpx_enabled() are
false, so the poll never happens.

This regresses 32-bit Windows XP guests on a Windows host with
-machine pc-i440fx-10.0,accel=tcg, causing a STOP 0x0000000A during boot.

Fix it by making the decision depend on whether KVM or WHPX is using an
in-kernel irqchip, instead of whether either accelerator is enabled.

Fixes: 69dfc078a6f0 ("hw: i386: vapic: enable on WHPX with user-mode irqchip")
Signed-off-by: rickgcn <rickgcn@gmail.com>
Link: https://lore.kernel.org/r/20260418061429.16898-1-rickgcn@gmail.com
Cc: qemu-stable@nongnu.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agotarget/i386: fix missing PF_INSTR in SIGSEGV context
Simon Scherer [Mon, 13 Apr 2026 11:56:22 +0000 (13:56 +0200)] 
target/i386: fix missing PF_INSTR in SIGSEGV context

When running linux-user emulation, the SIGSEGV handler does not
correctly set the 4th bit (PF_INSTR) in the error_code variable of
the context argument (context->uc_mcontext.gregs[REG_ERR]).

Because this bit is never set, guest applications cannot distinguish
if a fault was due to missing executable permissions. This patch
ensures that when a page fault occurs during an instruction fetch,
the PF_INSTR flag is properly populated in the signal context.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3384
Signed-off-by: Simon Scherer <scherer.simon89@gmail.com>
Link: https://lore.kernel.org/r/20260413115622.160212-1-scherer.simon89@gmail.com
Cc: qemu-stable@nongnu.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agotarget/i386: fix strList leak in x86_cpu_get_unavailable_features
Marc-André Lureau [Mon, 13 Apr 2026 12:50:40 +0000 (16:50 +0400)] 
target/i386: fix strList leak in x86_cpu_get_unavailable_features

The result list built by x86_cpu_list_feature_names() was never freed
after being visited, causing a memory leak detected by ASan.
(the getter visitor is VISITOR_OUTPUT kind and doesn't own data)

Fixes: 506174bf8219 ("i386: "unavailable-features" QOM property")
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Link: https://lore.kernel.org/r/20260413125040.3842686-1-marcandre.lureau@redhat.com
Cc: qemu-stable@nongnu.org
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
3 months agoMAINTAINERS: Remove Xie Changlong
Peter Maydell [Thu, 16 Apr 2026 09:16:54 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Xie Changlong

Xie Changlong has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

This makes the "Replication" block filter orphan.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Lukas Straub <lukasstraub2@web.de>
Message-id: 20260416091654.316158-29-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Xiao Guangrong
Peter Maydell [Thu, 16 Apr 2026 09:16:53 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Xiao Guangrong

Xiao Guangrong has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-28-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Wen Congyang
Peter Maydell [Thu, 16 Apr 2026 09:16:52 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Wen Congyang

Wen Congyang has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Lukas Straub <lukasstraub2@web.de>
Message-id: 20260416091654.316158-27-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Yanan Wang
Peter Maydell [Thu, 16 Apr 2026 09:16:51 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Yanan Wang

Yanan Wang has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Thomas Huth <thuth@redhat.com>
Message-id: 20260416091654.316158-26-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Vijai Kumar K
Peter Maydell [Thu, 16 Apr 2026 09:16:50 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Vijai Kumar K

Vijai Kumar K has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

This makes the Shakti C class RISC-V SoC orphan.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-25-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Su Hang
Peter Maydell [Thu, 16 Apr 2026 09:16:49 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Su Hang

Su Hang has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

This makes the Intel Hexadecimal Object File Loader orphan.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-24-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Shannon Zhao
Peter Maydell [Thu, 16 Apr 2026 09:16:48 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Shannon Zhao

Shannon Zhao has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

This makes the "ARM ACPI Subsystem" orphan.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-23-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Ryo ONODERA
Peter Maydell [Thu, 16 Apr 2026 09:16:47 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Ryo ONODERA

Ryo ONODERA has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-22-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Ronnie Sahlberg
Peter Maydell [Thu, 16 Apr 2026 09:16:46 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Ronnie Sahlberg

Ronnie Sahlberg has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-21-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Luigi Rizzo
Peter Maydell [Thu, 16 Apr 2026 09:16:45 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Luigi Rizzo

Luigi Rizzo has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-20-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Qiuhao Li
Peter Maydell [Thu, 16 Apr 2026 09:16:44 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Qiuhao Li

Qiuhao Li has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-19-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Jia Liu
Peter Maydell [Thu, 16 Apr 2026 09:16:43 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Jia Liu

Jia Liu has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

This makes the or1k-sim OpenRISC machine orphan.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-18-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Paul Burton
Peter Maydell [Thu, 16 Apr 2026 09:16:42 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Paul Burton

Paul Burton has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-17-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Aarushi Mehta
Peter Maydell [Thu, 16 Apr 2026 09:16:41 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Aarushi Mehta

Aarushi Mehta has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-16-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Marcel Apfelbaum
Peter Maydell [Thu, 16 Apr 2026 09:16:40 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Marcel Apfelbaum

Marcel Apfelbaum has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-15-peter.maydell@linaro.org

3 months agoMAINTAINERS: Remove Magnus Damm
Peter Maydell [Thu, 16 Apr 2026 09:16:39 +0000 (10:16 +0100)] 
MAINTAINERS: Remove Magnus Damm

Magnus Damm has not posted to qemu-devel in some years and did not
respond to a query about whether they still wished to be listed in
our MAINTAINERS file.  Remove them, on the assumption that they are
no longer active in QEMU.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260416091654.316158-14-peter.maydell@linaro.org