Commit Graph

1803 Commits

Author SHA1 Message Date
Peter Maydell
3fb456e9a0 Merge tag 'pull-request-2026-03-02' of https://gitlab.com/thuth/qemu into staging
* Remove qemu-system-microblazeel (qemu-system-microblaze can be used instead)
* Improve detection of the docker/podman binary
* Prevent a null pointer dereference during zpci hot unplug

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEEJ7iIR+7gJQEY8+q5LtnXdP5wLbUFAmmlgwQACgkQLtnXdP5w
# LbW4jw//VMx6pHEu5L3Rzr3FZdgMJUhJ3UQKoV5PAImHz96QjIZi3kR311/D7Xjr
# nPf9VVgVZUEKzwyCfv7V06M9S79Jbw2cJesEIcu5LqbvGxKcevXVPMdVPpDG7P7T
# zuNW7eyIMpHYHRnMnxRNY/Hl8S1P9spEWJeQpNxfe9AKoWh2i4vEC8KLMAf59DAw
# MX0CZjonMeCBSWBqRqP0zOeUqiq9n49Lz1LQnCZb1R2TF+RGmwfe6+NaBeEZ9BSg
# FWGVIIq09OFxvtUuuut5X47DOrxk69q0RmiLy+wyrpH3VMxWM41n3oensoaNm0Xj
# dg0Eq1GzQwnLalaVgdqriGnymQWtvKXmlXHsIAwedLscOO6F5L+T12WZUSUjDZ92
# SGGKyi2TSkgEZO1naLxi+J0dMWSO51wOOln9GAgFHkT/PuF/12r0sVweXXiovucr
# 4CWKP8VGU5MVpGlZ9flLwXiq8uS1GOsMQbBj/eoVOxEuFnL0crX9dME8vlpoGYAg
# THmuLKOxtcVtC9BxBZQkMFj6IKdRYEfFnNuCl2gk33Ksdb9QYCyL54XSZ9vtvhhG
# +5ajjl+w+O8HgnQKdWSQy1PYrvQ6EXtY0ZOf0q0yPfz4oq4Ib81oLhfvK0AywM17
# DALYymGpGgOgGYIkKQKcn3id7OnaIiRe7ai4GeJ9AbFVgxR4l+w=
# =Sdy4
# -----END PGP SIGNATURE-----
# gpg: Signature made Mon Mar  2 12:31:00 2026 GMT
# gpg:                using RSA key 27B88847EEE0250118F3EAB92ED9D774FE702DB5
# gpg: Good signature from "Thomas Huth <th.huth@gmx.de>" [full]
# gpg:                 aka "Thomas Huth <thuth@redhat.com>" [full]
# gpg:                 aka "Thomas Huth <huth@tuxfamily.org>" [full]
# gpg:                 aka "Thomas Huth <th.huth@posteo.de>" [undefined]
# Primary key fingerprint: 27B8 8847 EEE0 2501 18F3  EAB9 2ED9 D774 FE70 2DB5

* tag 'pull-request-2026-03-02' of https://gitlab.com/thuth/qemu:
  gitlab: ensure docker output is always displayed in CI
  tests/docker: allow display of docker output
  tests/docker: add support for podman remote access
  tests/docker: improve handling of docker probes
  Remove the qemu-system-microblazeel target from the build
  gitlab-ci: Remove the microblazeel target from the CI jobs
  tests/qtest: Remove the microblazeel target from the qtests
  tests/functional: Remove the microblazeel test
  tests/functional: Make sure test case .py files are executable
  s390x/pci: prevent null pointer dereference during zpci hot unplug

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-03-02 14:01:46 +00:00
Thomas Huth
b63b340430 tests/qtest: Remove the microblazeel target from the qtests
The "petalogix-ml605" boot-serial-test can be run with the
"microblaze" target. The remaining tests can simply be dropped
now that we are going to remove the "microblazeel" target.

Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-ID: <20260226084608.11251-3-thuth@redhat.com>
2026-03-02 08:28:24 +01:00
Alexander Graf
0e7f6f6359 hw/nitro: Add nitro machine
Add a machine model to spawn a Nitro Enclave. Unlike the existing -M
nitro-enclave, this machine model works exclusively with the -accel
nitro accelerator to drive real Nitro Enclave creation. It supports
memory allocation, number of CPU selection, both x86_64 as well as
aarch64, implements the Enclave heartbeat logic and debug serial
console.

To use it, create an EIF file and run

  $ qemu-system-x86_64 -accel nitro,debug-mode=on -M nitro -nographic \
                       -kernel test.eif

or

  $ qemu-system-aarch64 -accel nitro,debug-mode=on -M nitro -nographic \
                        -kernel test.eif

Signed-off-by: Alexander Graf <graf@amazon.com>

Link: https://lore.kernel.org/r/20260225220807.33092-9-graf@amazon.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-02-27 14:22:07 +01:00
Peter Maydell
314f2d7fe6 Merge tag 'qtest-20260217-pull-request' of https://gitlab.com/farosas/qemu into staging
QTest pull request

- RISCV IOMMU test

# -----BEGIN PGP SIGNATURE-----
#
# iQJEBAABCAAuFiEEqhtIsKIjJqWkw2TPx5jcdBvsMZ0FAmmUlLMQHGZhcm9zYXNA
# c3VzZS5kZQAKCRDHmNx0G+wxnW3eEACAR/RJWKbxQM2O0M4QS5BKtryaI5y7CMb5
# VwovTOVwzs1WsV3eve5Q6y6vcGIjgp7Q53I5l9pvzLB4IcXG+RG5l9lP8AcEctvn
# KyY6dPD8FmXLmhYOrnyXDNkfS72g9ELfsccm8prJi3Xeo7yXVJf7e+sPE3YVPBPa
# 8YfIlgkVWDy2OfrM7kd4SaCoNevs2jMlhqdzXxg6KZNBx51wX2knDYGSenWFyL//
# 0YgRGnMSprLJgWHrddU4dQe+knpOZWHPqZuq9eSoAVO+k6i0+znwEoCqQNRssYhI
# Hgu5/A/NdAbOQiktEKGjjgMX8XDo5fq4BklLaGeziGwjgsflK9M1VSttgJUHgCOr
# aR216kclzi+dDxqNNS7hWack0OjhnHYErDcbAyYdTkm5kCE1h6Co2t0rZIVZZBW6
# sGiF1rMLjJvSC34v29hJCEmbDcW1w2fEAb14ntrbov+XKhsgwtE74H7sj81hLJzQ
# rfIqwn3cjTtGfMXuc0fK4vqSjmPfkZse4/b68fJAaduV9A7bof1HId+k82tMO69v
# ZtLhWsk8dSJmRNDM1gzeOPB2TDunX+i54AJboa7G0DMpPA8VGxvoVygdhC9GSfu0
# rXpPkywjcvX6sUIkoUi7KGAREjH+vH8pUbVVisbLI9kt3ovaj60R8S+dySQCEhBl
# ZKmy8EAeEg==
# =jkva
# -----END PGP SIGNATURE-----
# gpg: Signature made Tue Feb 17 16:17:55 2026 GMT
# gpg:                using RSA key AA1B48B0A22326A5A4C364CFC798DC741BEC319D
# gpg:                issuer "farosas@suse.de"
# gpg: Good signature from "Fabiano Rosas <farosas@suse.de>" [unknown]
# gpg:                 aka "Fabiano Almeida Rosas <fabiano.rosas@suse.com>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: AA1B 48B0 A223 26A5 A4C3  64CF C798 DC74 1BEC 319D

* tag 'qtest-20260217-pull-request' of https://gitlab.com/farosas/qemu:
  tests/qtest: Add RISC-V IOMMU bare-metal test
  tests/qtest/libqos: Add RISC-V IOMMU helper library

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-02-17 16:46:05 +00:00
Peter Maydell
fd5ecd187b tests/qtest/migration/tls-tests.c: Don't use tls_psk end hook for no_tls tests
If you run the TLS tests under a clang undefined-behaviour sanitizer build
it will fall over like this:

../../tests/unit/crypto-tls-psk-helpers.c:53:12: runtime error: null pointer passed as argument 1, which is declared to never be null
/usr/include/unistd.h:858:48: note: nonnull attribute specified here
    #0 0x62bd810762ee in test_tls_psk_cleanup /home/pm215/qemu/build/clang/../../tests/unit/crypto-tls-psk-helpers.c:53:5
    #1 0x62bd81073f89 in migrate_hook_end_tls_psk /home/pm215/qemu/build/clang/../../tests/qtest/migration/tls-tests.c:101:5
    #2 0x62bd81062ef0 in test_precopy_common /home/pm215/qemu/build/clang/../../tests/qtest/migration/framework.c:947:9

This happens because test_precopy_tcp_no_tls() uses a custom start_hook
that only sets a couple of parameters, but reuses the tsk_psk end_hook.
However, the end_hook runs cleanup that assumes that the data was set
up by migrate_hook_start_tls_psk_common(). In particular, it will
unconditionally call test_tls_psk_cleanup(data->pskfile), and
test_tls_psk_cleanup() will unconditionally unlink() the filename it
is passed, which is undefined behaviour if you pass it a NULL pointer.

Instead of creating a TestMigrateTLSPSKData struct which we never set
any fields in and requiring the migrate_hook_end_tls_psk() hook to
cope with that, don't allocate the struct in the start_hook. Then
there is nothing we need to clean up, and we can set the end_hook
to NULL (which the test framework will interpret as "don't call
any end_hook").

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260212114747.1103466-1-peter.maydell@linaro.org
[no need to copy stable]
Signed-off-by: Fabiano Rosas <farosas@suse.de>
2026-02-17 10:06:03 -03:00
Chao Liu
a8f98ffd7b tests/qtest: Add RISC-V IOMMU bare-metal test
Add a qtest suite for the RISC-V IOMMU PCI device on the virt machine.
The test exercises bare, S-stage, G-stage, and nested translation paths
using iommu-testdev and the qos-riscv-iommu helpers.

The test validates:
- Device context (DC) configuration
- SV39 page table walks for S-stage translation
- SV39x4 page table walks for G-stage translation
- Nested translation combining both stages
- FCTL register constraints

This provides regression coverage for the RISC-V IOMMU implementation
without requiring a full guest OS boot.

Signed-off-by: Chao Liu <chao.liu.zevorn@gmail.com>
Reviewed-by: Tao Tang <tangtao1634@phytium.com.cn>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/35f046c8d21aa6d5f9a531258762e01be198d8cf.1770127918.git.chao.liu.zevorn@gmail.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
2026-02-17 09:37:40 -03:00
Chao Liu
9d8ffbfc1d tests/qtest/libqos: Add RISC-V IOMMU helper library
Introduce a libqos helper module for RISC-V IOMMU testing with
iommu-testdev. The helper provides routines to:

- Build device contexts (DC) and 3-level page tables for SV39/SV39x4
- Program command queue (CQ), fault queue (FQ), and DDTP registers
  following the RISC-V IOMMU specification
- Execute DMA translations and verify results

The current implementation supports SV39 for S-stage and SV39x4 for
G-stage translation. Support for SV48/SV48x4/SV57/SV57x4 can be added
in future patches.

Signed-off-by: Chao Liu <chao.liu.zevorn@gmail.com>
Reviewed-by: Tao Tang <tangtao1634@phytium.com.cn>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
Link: https://lore.kernel.org/qemu-devel/a2edf8c44f0bce26dccb91a7d13edb58be50c1a3.1770127918.git.chao.liu.zevorn@gmail.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
2026-02-17 09:37:40 -03:00
Peter Maydell
ece408818d Merge tag 'for-upstream' of https://gitlab.com/bonzini/qemu into staging
* hw/i386: Remove deprecated PC 2.6 and 2.7 machines
* i386/cpu: Fix incorrect initializer in Diamond Rapids definition
* qom: Clean up property release
* target/i386/kvm: set KVM_PMU_CAP_DISABLE if "-pmu" is configured
* target/i386/kvm: reset AMD and perfmon-v2 PMU registers during VM reset
* mshv: Cleanup
* target/i386: convert SEV-ES termination requests to guest panic events

# -----BEGIN PGP SIGNATURE-----
#
# iQFIBAABCgAyFiEE8TM4V0tmI4mGbHaCv/vSX3jHroMFAmmO+kYUHHBib256aW5p
# QHJlZGhhdC5jb20ACgkQv/vSX3jHroPwIQf/XL4HXB7bYQH7LtTgsjmmxPpEqGuM
# 2QWvv1HurGf4pBCkBB7iFdzngSbJSzvtIM4D2KRuXVc99Ml8Do4kKGwDdtVfaM+I
# x+nsJfnSGA7tuNVQUUDEM1XWrnk3+O9oQxlk3elBWy8IBIjHFY1rv3FBdO9WkDpu
# AlaMITrX4R7u5gadCrxvAprbngNGlK220HZ+nxdxvf6mWkYMPqy1xtNzHIioG61V
# A94tdv/OZnUoQMd98c/yUvfST4/Gx6FeoEYfmyXGrnLM+Tc9es/xpN/mCYLdP3wA
# MDS170D2Z0zoZScLcpMfeqSn5cDYBMOSHBzqFpw2/FNVTO3td2qlSMLjzw==
# =AqB6
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri Feb 13 10:17:42 2026 GMT
# gpg:                using RSA key F13338574B662389866C7682BFFBD25F78C7AE83
# gpg:                issuer "pbonzini@redhat.com"
# gpg: Good signature from "Paolo Bonzini <bonzini@gnu.org>" [full]
# gpg:                 aka "Paolo Bonzini <pbonzini@redhat.com>" [full]
# Primary key fingerprint: 46F5 9FBD 57D6 12E7 BFD4  E2F7 7E15 100C CD36 69B1
#      Subkey fingerprint: F133 3857 4B66 2389 866C  7682 BFFB D25F 78C7 AE83

* tag 'for-upstream' of https://gitlab.com/bonzini/qemu: (41 commits)
  target/i386/mshv: remove unused optimization of gva=>gpa translation
  accel/mshv: Remove remap overlapping mappings code
  tests: add /qdev/free-properties test
  qdev: make release_tpm() idempotent
  qdev: make release_drive() idempotent
  qdev: make release_string() idempotent
  qdev: Free property array on release
  target/i386/kvm: support perfmon-v2 for reset
  target/i386/kvm: reset AMD PMU registers during VM reset
  target/i386/kvm: rename architectural PMU variables
  target/i386/kvm: extract unrelated code out of kvm_x86_build_cpuid()
  target/i386/kvm: set KVM_PMU_CAP_DISABLE if "-pmu" is configured
  i386/cpu: Fix incorrect initializer in Diamond Rapids definition
  hw/char/virtio-serial: Do not expose the 'emergency-write' property
  hw/virtio/virtio-pci: Remove VirtIOPCIProxy::ignore_backend_features field
  hw/i386/intel_iommu: Remove IntelIOMMUState::buggy_eim field
  hw/core/machine: Remove hw_compat_2_7[] array
  hw/audio/pcspk: Remove PCSpkState::migrate field
  target/i386/cpu: Remove CPUX86State::full_cpuid_auto_level field
  hw/i386/pc: Remove pc_compat_2_7[] array
  ...

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-02-13 10:30:08 +00:00
Peter Maydell
91eb10be2e Merge tag 'pull-aspeed-20260212' of https://github.com/legoater/qemu into staging
aspeed-next queue:

* Adds support for the AST2700 A2 SoC, including a new machine and
  a functional test
* Enhances AST2600 OTP functional test
* Restructures Aspeed ARM tests into separate files for better
  parallelism.
* Includes new SDK tests with Linux 5.15.
* Fixes Aspeed I2C models

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCAAdFiEEoPZlSPBIlev+awtgUaNDx8/77KEFAmmOSFgACgkQUaNDx8/7
# 7KEq0RAAyhY6FCrwU3hyeA0WPCWAIhoXjqVkuPIqbLEKpazuRK2A0XeN1QH38VUu
# rotcWx5O/eTqwDXm4uTPcHGjiFjL9YRkj3opBE33pfbnMWllezUrK6Soa3q4A9uk
# FnV2YN0sucaueUdXaKe4dJr12uxUWWTQ53Lr+yt0wmXJsjvBsUWaXBTJj+aGPWuS
# u46yxJFxKUK/3GkA8nnEOm91EEQYkETX5LeWZm8aqN/BHuvJNqWuhx19rj1kaa1K
# VXgv3lvvfTpKCpqz2BwFa03ZL4PNCRlS+fN1A9idcnh4yQzngw07jc/9r3Kx/8PS
# zYFgko7EU6Ja4WojToFU4yZK5NZN6BfCd6HAjIBN86EsysDWcNS9DXmqvPnMaPGl
# l+580YsGFO2F7sd8iSPAYT1Tl17jOLVMNIW4khNVOTUnJKIJWlfyA2u4J/1iYKcF
# UiASnvmtryNru9TahlCfTK1SLsFywKN3q6lgVFMba9GX2fzrtZCCDHrQYqHWnnGj
# IzpiUAX/GU8ST1p3RjA0hR2TdBHcA6QByOFhJYQoSmHw5gcuuVxXKNl+y1y9zj07
# YPJFm2V/29m/XcpV0NkAhpX+Gcg9ASrMEQplis2v0nvzSMd/Lcr7YNJLtX9/zkth
# wP8dRnSqisWrUDEUSYap8rxPdguRlUv/tAoxcJVlryN2fB8sOOc=
# =78p2
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu Feb 12 21:38:32 2026 GMT
# gpg:                using RSA key A0F66548F04895EBFE6B0B6051A343C7CFFBECA1
# gpg: Good signature from "Cédric Le Goater <clg@redhat.com>" [full]
# gpg:                 aka "Cédric Le Goater <clg@kaod.org>" [full]
# Primary key fingerprint: A0F6 6548 F048 95EB FE6B  0B60 51A3 43C7 CFFB ECA1

* tag 'pull-aspeed-20260212' of https://github.com/legoater/qemu:
  tests/functional/aarch64/test_aspeed_ast2700fc: Use AST2700 A2 SDK image for FC tests
  hw/arm/aspeed_ast27x0-fc: Increase BMC DRAM size to 2GB for AST2700 A2
  hw/arm/aspeed_ast27x0-fc: Switch AST2700 FC machine to A2 SoC
  tests/functional/aarch64/test_aspeed_ast2700a2: Add AST2700 A2 EVB functional tests
  tests/functional/aarch64/test_aspeed_ast2700: Rename AST2700 A1 test to reduce test runtime
  tests/qtest/ast2700-hace-test: Use ast2700-evb alias for AST2700 HACE tests
  hw/arm/aspeed_ast27x0_evb: Move ast2700-evb alias to AST2700 A2 EVB
  hw/arm/aspeed_ast27x0_evb: Add AST2700 A2 EVB machine
  hw/arm/aspeed_ast27x0: Add AST2700 A2 SoC support
  hw/misc/aspeed_scu: Add AST2700 A2 silicon revisions
  hw/misc/aspeed_scu: Remove unused SoC silicon revision definitions
  tests/functional/arm/aspeed_ast2600: Enhance OTP test with functional validation
  hw/i2c/aspeed_i2c: Increase I2C device register size to 0xA0
  hw/i2c/aspeed_i2c: Fix out-of-bounds read in I2C MMIO handlers
  tests/functional: Add SDK tests with Linux 5.15
  tests/functional: Split Aspeed ARM tests into separate files

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-02-13 09:33:35 +00:00
Peter Maydell
05167ea35a Merge tag 'ipmi-add-fake-lan-config' of https://github.com/cminyard/qemu into staging
Add a fake LAN config operation for testing

Just add the commands, the proper data that can be set, and some tests.

Submitter ran migration test.

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEE/Q1c5nzg9ZpmiCaGYfOMkJGb/4EFAmmODfcACgkQYfOMkJGb
# /4EGEg/+NAygBBmU3gyBwrbSwS6Zch1Csq9M8sBGexEmbi/T9ICHI8Sfb3aX7JSr
# 3hZS/pPXn9Bb1vNQ5fQ2KCfDY0CjXtNBiSOvttgtYHiYu+Dz7+0WicusGKUoUywp
# jYwzsFaa8Nf//rhNGdXLXOOhNtMHD5ia3awhg5lPBgFTTrfGiKaz9CzTQCaFZtub
# Tt4nWjN+qBXPTBOsLTEZiIJ7qh9LhM56qT6e85wLwLjNSPgmctCTR+j1gg4nWSq2
# SOUQ6KeIY+DGk4G21i2HnHpjZK9BrUoISBElrSUECxRMokOAgPapMzAFZvErDI5n
# SiIuLjJqsOsPqjw60zrGhM81lawqJxSViQtVdHZ2vM4XABMOUs5msgE7doJMPGIH
# Hmnchv7WGZuWIwAsvF1T3fTyLvGES/8pv6UMKLjscdEIO7JMveUAvQHjUN1j06Ny
# p1VEB2EgkPz6YnvxZ2WN693SuWGhAuixRmjBHABwp+l43QvCYen+XMEnaBzcAnKl
# qrNMrU44OXDqofUrb5zaqj5o5Lmv8vjApGa3ouhKmYCinluboEEvPtP8szGVGat3
# k6cRPtz6FkngM1jtAUBCxH2pb0Rol3gFqfkoZRjqO3hyOl8q1ky5nSWcZqiJ5DPE
# fPIZW22ZF3yJPdVtSzwaiJ8klk9z3hgOoFlyZQkojaGuSeu2UOE=
# =QbzC
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu Feb 12 17:29:27 2026 GMT
# gpg:                using RSA key FD0D5CE67CE0F59A6688268661F38C90919BFF81
# gpg: Good signature from "Corey Minyard <cminyard@mvista.com>" [unknown]
# gpg:                 aka "Corey Minyard <minyard@acm.org>" [unknown]
# gpg:                 aka "Corey Minyard <corey@minyard.net>" [unknown]
# gpg:                 aka "Corey Minyard <minyard@mvista.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: FD0D 5CE6 7CE0 F59A 6688  2686 61F3 8C90 919B FF81

* tag 'ipmi-add-fake-lan-config' of https://github.com/cminyard/qemu:
  hw/ipmi/ipmi_bmc_sim: Support setting fake LAN channel config
  hw/ipmi/ipmi_bmc_sim: Support getting fake LAN channel config

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-02-13 09:33:24 +00:00
Jamin Lin
7c79c954aa tests/qtest/ast2700-hace-test: Use ast2700-evb alias for AST2700 HACE tests
Update AST2700 HACE qtests to use the "ast2700-evb" machine alias
instead of a specific silicon revision.

The AST2700 A1 and A2 revisions are compatible for the HACE model, so
the tests do not depend on a particular EVB revision. Using the
"ast2700-evb" alias ensures the tests always run the latest
supported AST2700 silicon revision.

Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260211021527.119674-7-jamin_lin@aspeedtech.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-02-12 16:06:55 +01:00
Mohamed Mediouni
72a231af4c qtest: hw/arm: virt: add new test case for GICv3 + GICv2m
Signed-off-by: Mohamed Mediouni <mohamed@unpredictable.fr>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-02-10 11:34:48 +00:00
Mohamed Mediouni
2e1bb23b44 tests: data: update AArch64 ACPI tables
After the previous commit introducing GICv3 + GICv2m configurations,
update the AArch64 ACPI tables for the GICv2 case.

Changes to the ACPI tables:

tests/data/acpi/aarch64/virt/IORT.dsl:

@@ -11,68 +11,49 @@
  */

 [000h 0000 004h]                   Signature : "IORT"    [IO Remapping Table]
-[004h 0004 004h]                Table Length : 00000080
+[004h 0004 004h]                Table Length : 00000054
 [008h 0008 001h]                    Revision : 05
-[009h 0009 001h]                    Checksum : B1
+[009h 0009 001h]                    Checksum : 3C
 [00Ah 0010 006h]                      Oem ID : "BOCHS "
 [010h 0016 008h]                Oem Table ID : "BXPC    "
 [018h 0024 004h]                Oem Revision : 00000001
 [01Ch 0028 004h]             Asl Compiler ID : "BXPC"
 [020h 0032 004h]       Asl Compiler Revision : 00000001

-[024h 0036 004h]                  Node Count : 00000002
+[024h 0036 004h]                  Node Count : 00000001
 [028h 0040 004h]                 Node Offset : 00000030
 [02Ch 0044 004h]                    Reserved : 00000000

-[030h 0048 001h]                        Type : 00
-[031h 0049 002h]                      Length : 0018
-[033h 0051 001h]                    Revision : 01
+[030h 0048 001h]                        Type : 02
+[031h 0049 002h]                      Length : 0024
+[033h 0051 001h]                    Revision : 03
 [034h 0052 004h]                  Identifier : 00000000
 [038h 0056 004h]               Mapping Count : 00000000
-[03Ch 0060 004h]              Mapping Offset : 00000000
+[03Ch 0060 004h]              Mapping Offset : 00000024

-[040h 0064 004h]                    ItsCount : 00000001
-[044h 0068 004h]                 Identifiers : 00000000
-
-[048h 0072 001h]                        Type : 02
-[049h 0073 002h]                      Length : 0038
-[04Bh 0075 001h]                    Revision : 03
-[04Ch 0076 004h]                  Identifier : 00000001
-[050h 0080 004h]               Mapping Count : 00000001
-[054h 0084 004h]              Mapping Offset : 00000024
-
-[058h 0088 008h]           Memory Properties : [IORT Memory Access Properties]
-[058h 0088 004h]             Cache Coherency : 00000001
-[05Ch 0092 001h]       Hints (decoded below) : 00
+[040h 0064 008h]           Memory Properties : [IORT Memory Access Properties]
+[040h 0064 004h]             Cache Coherency : 00000001
+[044h 0068 001h]       Hints (decoded below) : 00
                                    Transient : 0
                               Write Allocate : 0
                                Read Allocate : 0
                                     Override : 0
-[05Dh 0093 002h]                    Reserved : 0000
-[05Fh 0095 001h] Memory Flags (decoded below) : 03
+[045h 0069 002h]                    Reserved : 0000
+[047h 0071 001h] Memory Flags (decoded below) : 03
                                    Coherency : 1
                             Device Attribute : 1
                Ensured Coherency of Accesses : 0
-[060h 0096 004h]               ATS Attribute : 00000000
-[064h 0100 004h]          PCI Segment Number : 00000000
-[068h 0104 001h]           Memory Size Limit : 40
-[069h 0105 002h]          PASID Capabilities : 0000
-[06Bh 0107 001h]                    Reserved : 00
+[048h 0072 004h]               ATS Attribute : 00000000
+[04Ch 0076 004h]          PCI Segment Number : 00000000
+[050h 0080 001h]           Memory Size Limit : 40
+[051h 0081 002h]          PASID Capabilities : 0000
+[053h 0083 001h]                    Reserved : 00

-[06Ch 0108 004h]                  Input base : 00000000
-[070h 0112 004h]                    ID Count : 0000FFFF
-[074h 0116 004h]                 Output Base : 00000000
-[078h 0120 004h]            Output Reference : 00000030
-[07Ch 0124 004h]       Flags (decoded below) : 00000000
-                              Single Mapping : 0
+Raw Table Data: Length 84 (0x54)

-Raw Table Data: Length 128 (0x80)
-
-    0000: 49 4F 52 54 80 00 00 00 05 B1 42 4F 43 48 53 20  // IORT......BOCHS
+    0000: 49 4F 52 54 54 00 00 00 05 3C 42 4F 43 48 53 20  // IORTT....<BOCHS
     0010: 42 58 50 43 20 20 20 20 01 00 00 00 42 58 50 43  // BXPC    ....BXPC
-    0020: 01 00 00 00 02 00 00 00 30 00 00 00 00 00 00 00  // ........0.......
-    0030: 00 18 00 01 00 00 00 00 00 00 00 00 00 00 00 00  // ................
-    0040: 01 00 00 00 00 00 00 00 02 38 00 03 01 00 00 00  // .........8......
-    0050: 01 00 00 00 24 00 00 00 01 00 00 00 00 00 00 03  // ....$...........
-    0060: 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00  // ........@.......
-    0070: FF FF 00 00 00 00 00 00 30 00 00 00 00 00 00 00  // ........0.......
+    0020: 01 00 00 00 01 00 00 00 30 00 00 00 00 00 00 00  // ........0.......
+    0030: 02 24 00 03 00 00 00 00 00 00 00 00 24 00 00 00  // .$..........$...
+    0040: 01 00 00 00 00 00 00 03 00 00 00 00 00 00 00 00  // ................
+    0050: 40 00 00 00                                      // @...

tests/data/acpi/aarch64/virt/IORT.smmuv3-dev.dsl:

@@ -11,164 +11,120 @@
  */

 [000h 0000 004h]                   Signature : "IORT"    [IO Remapping Table]
-[004h 0004 004h]                Table Length : 0000016C
+[004h 0004 004h]                Table Length : 00000104
 [008h 0008 001h]                    Revision : 05
-[009h 0009 001h]                    Checksum : C8
+[009h 0009 001h]                    Checksum : 49
 [00Ah 0010 006h]                      Oem ID : "BOCHS "
 [010h 0016 008h]                Oem Table ID : "BXPC    "
 [018h 0024 004h]                Oem Revision : 00000001
 [01Ch 0028 004h]             Asl Compiler ID : "BXPC"
 [020h 0032 004h]       Asl Compiler Revision : 00000001

-[024h 0036 004h]                  Node Count : 00000004
+[024h 0036 004h]                  Node Count : 00000003
 [028h 0040 004h]                 Node Offset : 00000030
 [02Ch 0044 004h]                    Reserved : 00000000

-[030h 0048 001h]                        Type : 00
-[031h 0049 002h]                      Length : 0018
-[033h 0051 001h]                    Revision : 01
+[030h 0048 001h]                        Type : 04
+[031h 0049 002h]                      Length : 0044
+[033h 0051 001h]                    Revision : 04
 [034h 0052 004h]                  Identifier : 00000000
 [038h 0056 004h]               Mapping Count : 00000000
 [03Ch 0060 004h]              Mapping Offset : 00000000

-[040h 0064 004h]                    ItsCount : 00000001
-[044h 0068 004h]                 Identifiers : 00000000
-
-[048h 0072 001h]                        Type : 04
-[049h 0073 002h]                      Length : 0058
-[04Bh 0075 001h]                    Revision : 04
-[04Ch 0076 004h]                  Identifier : 00000001
-[050h 0080 004h]               Mapping Count : 00000001
-[054h 0084 004h]              Mapping Offset : 00000044
-
-[058h 0088 008h]                Base Address : 000000000C000000
-[060h 0096 004h]       Flags (decoded below) : 00000001
+[040h 0064 008h]                Base Address : 000000000C000000
+[048h 0072 004h]       Flags (decoded below) : 00000001
                              COHACC Override : 1
                                HTTU Override : 0
                       Proximity Domain Valid : 0
                               DeviceID Valid : 0
-[064h 0100 004h]                    Reserved : 00000000
-[068h 0104 008h]               VATOS Address : 0000000000000000
-[070h 0112 004h]                       Model : 00000000
-[074h 0116 004h]                  Event GSIV : 00000090
-[078h 0120 004h]                    PRI GSIV : 00000091
-[07Ch 0124 004h]                   GERR GSIV : 00000093
-[080h 0128 004h]                   Sync GSIV : 00000092
-[084h 0132 004h]            Proximity Domain : 00000000
-[088h 0136 004h]     Device ID Mapping Index : 00000000
+[04Ch 0076 004h]                    Reserved : 00000000
+[050h 0080 008h]               VATOS Address : 0000000000000000
+[058h 0088 004h]                       Model : 00000000
+[05Ch 0092 004h]                  Event GSIV : 00000090
+[060h 0096 004h]                    PRI GSIV : 00000091
+[064h 0100 004h]                   GERR GSIV : 00000093
+[068h 0104 004h]                   Sync GSIV : 00000092
+[06Ch 0108 004h]            Proximity Domain : 00000000
+[070h 0112 004h]     Device ID Mapping Index : 00000000

-[08Ch 0140 004h]                  Input base : 00000000
-[090h 0144 004h]                    ID Count : 0000FFFF
-[094h 0148 004h]                 Output Base : 00000000
-[098h 0152 004h]            Output Reference : 00000030
-[09Ch 0156 004h]       Flags (decoded below) : 00000000
-                              Single Mapping : 0
+[074h 0116 001h]                        Type : 04
+[075h 0117 002h]                      Length : 0044
+[077h 0119 001h]                    Revision : 04
+[078h 0120 004h]                  Identifier : 00000001
+[07Ch 0124 004h]               Mapping Count : 00000000
+[080h 0128 004h]              Mapping Offset : 00000000

-[0A0h 0160 001h]                        Type : 04
-[0A1h 0161 002h]                      Length : 0058
-[0A3h 0163 001h]                    Revision : 04
-[0A4h 0164 004h]                  Identifier : 00000002
-[0A8h 0168 004h]               Mapping Count : 00000001
-[0ACh 0172 004h]              Mapping Offset : 00000044
-
-[0B0h 0176 008h]                Base Address : 000000000C020000
-[0B8h 0184 004h]       Flags (decoded below) : 00000001
+[084h 0132 008h]                Base Address : 000000000C020000
+[08Ch 0140 004h]       Flags (decoded below) : 00000001
                              COHACC Override : 1
                                HTTU Override : 0
                       Proximity Domain Valid : 0
                               DeviceID Valid : 0
-[0BCh 0188 004h]                    Reserved : 00000000
-[0C0h 0192 008h]               VATOS Address : 0000000000000000
-[0C8h 0200 004h]                       Model : 00000000
-[0CCh 0204 004h]                  Event GSIV : 00000094
-[0D0h 0208 004h]                    PRI GSIV : 00000095
-[0D4h 0212 004h]                   GERR GSIV : 00000097
-[0D8h 0216 004h]                   Sync GSIV : 00000096
-[0DCh 0220 004h]            Proximity Domain : 00000000
-[0E0h 0224 004h]     Device ID Mapping Index : 00000000
+[090h 0144 004h]                    Reserved : 00000000
+[094h 0148 008h]               VATOS Address : 0000000000000000
+[09Ch 0156 004h]                       Model : 00000000
+[0A0h 0160 004h]                  Event GSIV : 00000094
+[0A4h 0164 004h]                    PRI GSIV : 00000095
+[0A8h 0168 004h]                   GERR GSIV : 00000097
+[0ACh 0172 004h]                   Sync GSIV : 00000096
+[0B0h 0176 004h]            Proximity Domain : 00000000
+[0B4h 0180 004h]     Device ID Mapping Index : 00000000

-[0E4h 0228 004h]                  Input base : 00000000
-[0E8h 0232 004h]                    ID Count : 0000FFFF
-[0ECh 0236 004h]                 Output Base : 00000000
-[0F0h 0240 004h]            Output Reference : 00000030
-[0F4h 0244 004h]       Flags (decoded below) : 00000000
-                              Single Mapping : 0
+[0B8h 0184 001h]                        Type : 02
+[0B9h 0185 002h]                      Length : 004C
+[0BBh 0187 001h]                    Revision : 03
+[0BCh 0188 004h]                  Identifier : 00000002
+[0C0h 0192 004h]               Mapping Count : 00000002
+[0C4h 0196 004h]              Mapping Offset : 00000024

-[0F8h 0248 001h]                        Type : 02
-[0F9h 0249 002h]                      Length : 0074
-[0FBh 0251 001h]                    Revision : 03
-[0FCh 0252 004h]                  Identifier : 00000003
-[100h 0256 004h]               Mapping Count : 00000004
-[104h 0260 004h]              Mapping Offset : 00000024
-
-[108h 0264 008h]           Memory Properties : [IORT Memory Access Properties]
-[108h 0264 004h]             Cache Coherency : 00000001
-[10Ch 0268 001h]       Hints (decoded below) : 00
+[0C8h 0200 008h]           Memory Properties : [IORT Memory Access Properties]
+[0C8h 0200 004h]             Cache Coherency : 00000001
+[0CCh 0204 001h]       Hints (decoded below) : 00
                                    Transient : 0
                               Write Allocate : 0
                                Read Allocate : 0
                                     Override : 0
-[10Dh 0269 002h]                    Reserved : 0000
-[10Fh 0271 001h] Memory Flags (decoded below) : 03
+[0CDh 0205 002h]                    Reserved : 0000
+[0CFh 0207 001h] Memory Flags (decoded below) : 03
                                    Coherency : 1
                             Device Attribute : 1
                Ensured Coherency of Accesses : 0
-[110h 0272 004h]               ATS Attribute : 00000000
-[114h 0276 004h]          PCI Segment Number : 00000000
-[118h 0280 001h]           Memory Size Limit : 40
-[119h 0281 002h]          PASID Capabilities : 0000
-[11Bh 0283 001h]                    Reserved : 00
+[0D0h 0208 004h]               ATS Attribute : 00000000
+[0D4h 0212 004h]          PCI Segment Number : 00000000
+[0D8h 0216 001h]           Memory Size Limit : 40
+[0D9h 0217 002h]          PASID Capabilities : 0000
+[0DBh 0219 001h]                    Reserved : 00

-[11Ch 0284 004h]                  Input base : 00000000
-[120h 0288 004h]                    ID Count : 000001FF
-[124h 0292 004h]                 Output Base : 00000000
-[128h 0296 004h]            Output Reference : 00000048
-[12Ch 0300 004h]       Flags (decoded below) : 00000000
+[0DCh 0220 004h]                  Input base : 00000000
+[0E0h 0224 004h]                    ID Count : 000001FF
+[0E4h 0228 004h]                 Output Base : 00000000
+[0E8h 0232 004h]            Output Reference : 00000030
+[0ECh 0236 004h]       Flags (decoded below) : 00000000
                               Single Mapping : 0

-[130h 0304 004h]                  Input base : 00001000
-[134h 0308 004h]                    ID Count : 000000FF
-[138h 0312 004h]                 Output Base : 00001000
-[13Ch 0316 004h]            Output Reference : 000000A0
-[140h 0320 004h]       Flags (decoded below) : 00000000
+[0F0h 0240 004h]                  Input base : 00001000
+[0F4h 0244 004h]                    ID Count : 000000FF
+[0F8h 0248 004h]                 Output Base : 00001000
+[0FCh 0252 004h]            Output Reference : 00000074
+[100h 0256 004h]       Flags (decoded below) : 00000000
                               Single Mapping : 0

-[144h 0324 004h]                  Input base : 00000200
-[148h 0328 004h]                    ID Count : 00000DFF
-[14Ch 0332 004h]                 Output Base : 00000200
-[150h 0336 004h]            Output Reference : 00000030
-[154h 0340 004h]       Flags (decoded below) : 00000000
-                              Single Mapping : 0
+Raw Table Data: Length 260 (0x104)

-[158h 0344 004h]                  Input base : 00001100
-[15Ch 0348 004h]                    ID Count : 0000EEFF
-[160h 0352 004h]                 Output Base : 00001100
-[164h 0356 004h]            Output Reference : 00000030
-[168h 0360 004h]       Flags (decoded below) : 00000000
-                              Single Mapping : 0
-
-Raw Table Data: Length 364 (0x16C)
-
-    0000: 49 4F 52 54 6C 01 00 00 05 C8 42 4F 43 48 53 20  // IORTl.....BOCHS
+    0000: 49 4F 52 54 04 01 00 00 05 49 42 4F 43 48 53 20  // IORT.....IBOCHS
     0010: 42 58 50 43 20 20 20 20 01 00 00 00 42 58 50 43  // BXPC    ....BXPC
-    0020: 01 00 00 00 04 00 00 00 30 00 00 00 00 00 00 00  // ........0.......
-    0030: 00 18 00 01 00 00 00 00 00 00 00 00 00 00 00 00  // ................
-    0040: 01 00 00 00 00 00 00 00 04 58 00 04 01 00 00 00  // .........X......
-    0050: 01 00 00 00 44 00 00 00 00 00 00 0C 00 00 00 00  // ....D...........
-    0060: 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  // ................
-    0070: 00 00 00 00 90 00 00 00 91 00 00 00 93 00 00 00  // ................
-    0080: 92 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  // ................
-    0090: FF FF 00 00 00 00 00 00 30 00 00 00 00 00 00 00  // ........0.......
-    00A0: 04 58 00 04 02 00 00 00 01 00 00 00 44 00 00 00  // .X..........D...
-    00B0: 00 00 02 0C 00 00 00 00 01 00 00 00 00 00 00 00  // ................
-    00C0: 00 00 00 00 00 00 00 00 00 00 00 00 94 00 00 00  // ................
-    00D0: 95 00 00 00 97 00 00 00 96 00 00 00 00 00 00 00  // ................
-    00E0: 00 00 00 00 00 00 00 00 FF FF 00 00 00 00 00 00  // ................
-    00F0: 30 00 00 00 00 00 00 00 02 74 00 03 03 00 00 00  // 0........t......
-    0100: 04 00 00 00 24 00 00 00 01 00 00 00 00 00 00 03  // ....$...........
-    0110: 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00  // ........@.......
-    0120: FF 01 00 00 00 00 00 00 48 00 00 00 00 00 00 00  // ........H.......
-    0130: 00 10 00 00 FF 00 00 00 00 10 00 00 A0 00 00 00  // ................
-    0140: 00 00 00 00 00 02 00 00 FF 0D 00 00 00 02 00 00  // ................
-    0150: 30 00 00 00 00 00 00 00 00 11 00 00 FF EE 00 00  // 0...............
-    0160: 00 11 00 00 30 00 00 00 00 00 00 00              // ....0.......
+    0020: 01 00 00 00 03 00 00 00 30 00 00 00 00 00 00 00  // ........0.......
+    0030: 04 44 00 04 00 00 00 00 00 00 00 00 00 00 00 00  // .D..............
+    0040: 00 00 00 0C 00 00 00 00 01 00 00 00 00 00 00 00  // ................
+    0050: 00 00 00 00 00 00 00 00 00 00 00 00 90 00 00 00  // ................
+    0060: 91 00 00 00 93 00 00 00 92 00 00 00 00 00 00 00  // ................
+    0070: 00 00 00 00 04 44 00 04 01 00 00 00 00 00 00 00  // .....D..........
+    0080: 00 00 00 00 00 00 02 0C 00 00 00 00 01 00 00 00  // ................
+    0090: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  // ................
+    00A0: 94 00 00 00 95 00 00 00 97 00 00 00 96 00 00 00  // ................
+    00B0: 00 00 00 00 00 00 00 00 02 4C 00 03 02 00 00 00  // .........L......
+    00C0: 02 00 00 00 24 00 00 00 01 00 00 00 00 00 00 03  // ....$...........
+    00D0: 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00  // ........@.......
+    00E0: FF 01 00 00 00 00 00 00 30 00 00 00 00 00 00 00  // ........0.......
+    00F0: 00 10 00 00 FF 00 00 00 00 10 00 00 74 00 00 00  // ............t...
+    0100: 00 00 00 00                                      // ....

tests/data/acpi/aarch64/virt/IORT.smmuv3-legacy.dsl:

@@ -11,129 +11,92 @@
  */

 [000h 0000 004h]                   Signature : "IORT"    [IO Remapping Table]
-[004h 0004 004h]                Table Length : 00000114
+[004h 0004 004h]                Table Length : 000000C0
 [008h 0008 001h]                    Revision : 05
-[009h 0009 001h]                    Checksum : 4A
+[009h 0009 001h]                    Checksum : 1C
 [00Ah 0010 006h]                      Oem ID : "BOCHS "
 [010h 0016 008h]                Oem Table ID : "BXPC    "
 [018h 0024 004h]                Oem Revision : 00000001
 [01Ch 0028 004h]             Asl Compiler ID : "BXPC"
 [020h 0032 004h]       Asl Compiler Revision : 00000001

-[024h 0036 004h]                  Node Count : 00000003
+[024h 0036 004h]                  Node Count : 00000002
 [028h 0040 004h]                 Node Offset : 00000030
 [02Ch 0044 004h]                    Reserved : 00000000

-[030h 0048 001h]                        Type : 00
-[031h 0049 002h]                      Length : 0018
-[033h 0051 001h]                    Revision : 01
+[030h 0048 001h]                        Type : 04
+[031h 0049 002h]                      Length : 0044
+[033h 0051 001h]                    Revision : 04
 [034h 0052 004h]                  Identifier : 00000000
 [038h 0056 004h]               Mapping Count : 00000000
 [03Ch 0060 004h]              Mapping Offset : 00000000

-[040h 0064 004h]                    ItsCount : 00000001
-[044h 0068 004h]                 Identifiers : 00000000
-
-[048h 0072 001h]                        Type : 04
-[049h 0073 002h]                      Length : 0058
-[04Bh 0075 001h]                    Revision : 04
-[04Ch 0076 004h]                  Identifier : 00000001
-[050h 0080 004h]               Mapping Count : 00000001
-[054h 0084 004h]              Mapping Offset : 00000044
-
-[058h 0088 008h]                Base Address : 0000000009050000
-[060h 0096 004h]       Flags (decoded below) : 00000001
+[040h 0064 008h]                Base Address : 0000000009050000
+[048h 0072 004h]       Flags (decoded below) : 00000001
                              COHACC Override : 1
                                HTTU Override : 0
                       Proximity Domain Valid : 0
                               DeviceID Valid : 0
-[064h 0100 004h]                    Reserved : 00000000
-[068h 0104 008h]               VATOS Address : 0000000000000000
-[070h 0112 004h]                       Model : 00000000
-[074h 0116 004h]                  Event GSIV : 0000006A
-[078h 0120 004h]                    PRI GSIV : 0000006B
-[07Ch 0124 004h]                   GERR GSIV : 0000006D
-[080h 0128 004h]                   Sync GSIV : 0000006C
-[084h 0132 004h]            Proximity Domain : 00000000
-[088h 0136 004h]     Device ID Mapping Index : 00000000
+[04Ch 0076 004h]                    Reserved : 00000000
+[050h 0080 008h]               VATOS Address : 0000000000000000
+[058h 0088 004h]                       Model : 00000000
+[05Ch 0092 004h]                  Event GSIV : 0000006A
+[060h 0096 004h]                    PRI GSIV : 0000006B
+[064h 0100 004h]                   GERR GSIV : 0000006D
+[068h 0104 004h]                   Sync GSIV : 0000006C
+[06Ch 0108 004h]            Proximity Domain : 00000000
+[070h 0112 004h]     Device ID Mapping Index : 00000000

-[08Ch 0140 004h]                  Input base : 00000000
-[090h 0144 004h]                    ID Count : 0000FFFF
-[094h 0148 004h]                 Output Base : 00000000
-[098h 0152 004h]            Output Reference : 00000030
-[09Ch 0156 004h]       Flags (decoded below) : 00000000
-                              Single Mapping : 0
+[074h 0116 001h]                        Type : 02
+[075h 0117 002h]                      Length : 004C
+[077h 0119 001h]                    Revision : 03
+[078h 0120 004h]                  Identifier : 00000001
+[07Ch 0124 004h]               Mapping Count : 00000002
+[080h 0128 004h]              Mapping Offset : 00000024

-[0A0h 0160 001h]                        Type : 02
-[0A1h 0161 002h]                      Length : 0074
-[0A3h 0163 001h]                    Revision : 03
-[0A4h 0164 004h]                  Identifier : 00000002
-[0A8h 0168 004h]               Mapping Count : 00000004
-[0ACh 0172 004h]              Mapping Offset : 00000024
-
-[0B0h 0176 008h]           Memory Properties : [IORT Memory Access Properties]
-[0B0h 0176 004h]             Cache Coherency : 00000001
-[0B4h 0180 001h]       Hints (decoded below) : 00
+[084h 0132 008h]           Memory Properties : [IORT Memory Access Properties]
+[084h 0132 004h]             Cache Coherency : 00000001
+[088h 0136 001h]       Hints (decoded below) : 00
                                    Transient : 0
                               Write Allocate : 0
                                Read Allocate : 0
                                     Override : 0
-[0B5h 0181 002h]                    Reserved : 0000
-[0B7h 0183 001h] Memory Flags (decoded below) : 03
+[089h 0137 002h]                    Reserved : 0000
+[08Bh 0139 001h] Memory Flags (decoded below) : 03
                                    Coherency : 1
                             Device Attribute : 1
                Ensured Coherency of Accesses : 0
-[0B8h 0184 004h]               ATS Attribute : 00000000
-[0BCh 0188 004h]          PCI Segment Number : 00000000
-[0C0h 0192 001h]           Memory Size Limit : 40
-[0C1h 0193 002h]          PASID Capabilities : 0000
-[0C3h 0195 001h]                    Reserved : 00
+[08Ch 0140 004h]               ATS Attribute : 00000000
+[090h 0144 004h]          PCI Segment Number : 00000000
+[094h 0148 001h]           Memory Size Limit : 40
+[095h 0149 002h]          PASID Capabilities : 0000
+[097h 0151 001h]                    Reserved : 00

-[0C4h 0196 004h]                  Input base : 00000000
-[0C8h 0200 004h]                    ID Count : 000001FF
-[0CCh 0204 004h]                 Output Base : 00000000
-[0D0h 0208 004h]            Output Reference : 00000048
-[0D4h 0212 004h]       Flags (decoded below) : 00000000
+[098h 0152 004h]                  Input base : 00000000
+[09Ch 0156 004h]                    ID Count : 000001FF
+[0A0h 0160 004h]                 Output Base : 00000000
+[0A4h 0164 004h]            Output Reference : 00000030
+[0A8h 0168 004h]       Flags (decoded below) : 00000000
                               Single Mapping : 0

-[0D8h 0216 004h]                  Input base : 00001000
-[0DCh 0220 004h]                    ID Count : 000000FF
-[0E0h 0224 004h]                 Output Base : 00001000
-[0E4h 0228 004h]            Output Reference : 00000048
-[0E8h 0232 004h]       Flags (decoded below) : 00000000
+[0ACh 0172 004h]                  Input base : 00001000
+[0B0h 0176 004h]                    ID Count : 000000FF
+[0B4h 0180 004h]                 Output Base : 00001000
+[0B8h 0184 004h]            Output Reference : 00000030
+[0BCh 0188 004h]       Flags (decoded below) : 00000000
                               Single Mapping : 0

-[0ECh 0236 004h]                  Input base : 00000200
-[0F0h 0240 004h]                    ID Count : 00000DFF
-[0F4h 0244 004h]                 Output Base : 00000200
-[0F8h 0248 004h]            Output Reference : 00000030
-[0FCh 0252 004h]       Flags (decoded below) : 00000000
-                              Single Mapping : 0
+Raw Table Data: Length 192 (0xC0)

-[100h 0256 004h]                  Input base : 00001100
-[104h 0260 004h]                    ID Count : 0000EEFF
-[108h 0264 004h]                 Output Base : 00001100
-[10Ch 0268 004h]            Output Reference : 00000030
-[110h 0272 004h]       Flags (decoded below) : 00000000
-                              Single Mapping : 0
-
-Raw Table Data: Length 276 (0x114)
-
-    0000: 49 4F 52 54 14 01 00 00 05 4A 42 4F 43 48 53 20  // IORT.....JBOCHS
+    0000: 49 4F 52 54 C0 00 00 00 05 1C 42 4F 43 48 53 20  // IORT......BOCHS
     0010: 42 58 50 43 20 20 20 20 01 00 00 00 42 58 50 43  // BXPC    ....BXPC
-    0020: 01 00 00 00 03 00 00 00 30 00 00 00 00 00 00 00  // ........0.......
-    0030: 00 18 00 01 00 00 00 00 00 00 00 00 00 00 00 00  // ................
-    0040: 01 00 00 00 00 00 00 00 04 58 00 04 01 00 00 00  // .........X......
-    0050: 01 00 00 00 44 00 00 00 00 00 05 09 00 00 00 00  // ....D...........
-    0060: 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  // ................
-    0070: 00 00 00 00 6A 00 00 00 6B 00 00 00 6D 00 00 00  // ....j...k...m...
-    0080: 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  // l...............
-    0090: FF FF 00 00 00 00 00 00 30 00 00 00 00 00 00 00  // ........0.......
-    00A0: 02 74 00 03 02 00 00 00 04 00 00 00 24 00 00 00  // .t..........$...
-    00B0: 01 00 00 00 00 00 00 03 00 00 00 00 00 00 00 00  // ................
-    00C0: 40 00 00 00 00 00 00 00 FF 01 00 00 00 00 00 00  // @...............
-    00D0: 48 00 00 00 00 00 00 00 00 10 00 00 FF 00 00 00  // H...............
-    00E0: 00 10 00 00 48 00 00 00 00 00 00 00 00 02 00 00  // ....H...........
-    00F0: FF 0D 00 00 00 02 00 00 30 00 00 00 00 00 00 00  // ........0.......
-    0100: 00 11 00 00 FF EE 00 00 00 11 00 00 30 00 00 00  // ............0...
-    0110: 00 00 00 00                                      // ....
+    0020: 01 00 00 00 02 00 00 00 30 00 00 00 00 00 00 00  // ........0.......
+    0030: 04 44 00 04 00 00 00 00 00 00 00 00 00 00 00 00  // .D..............
+    0040: 00 00 05 09 00 00 00 00 01 00 00 00 00 00 00 00  // ................
+    0050: 00 00 00 00 00 00 00 00 00 00 00 00 6A 00 00 00  // ............j...
+    0060: 6B 00 00 00 6D 00 00 00 6C 00 00 00 00 00 00 00  // k...m...l.......
+    0070: 00 00 00 00 02 4C 00 03 01 00 00 00 02 00 00 00  // .....L..........
+    0080: 24 00 00 00 01 00 00 00 00 00 00 03 00 00 00 00  // $...............
+    0090: 00 00 00 00 40 00 00 00 00 00 00 00 FF 01 00 00  // ....@...........
+    00A0: 00 00 00 00 30 00 00 00 00 00 00 00 00 10 00 00  // ....0...........
+    00B0: FF 00 00 00 00 10 00 00 30 00 00 00 00 00 00 00  // ........0.......

Signed-off-by: Mohamed Mediouni <mohamed@unpredictable.fr>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-02-10 11:34:48 +00:00
Mohamed Mediouni
eb1c60997c qtest: hw/arm: virt: skip ACPI test for IORT with GICv2
Signed-off-by: Mohamed Mediouni <mohamed@unpredictable.fr>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2026-02-10 11:34:48 +00:00
Philippe Mathieu-Daudé
6fcfe360dc hw/i386/pc: Remove deprecated pc-q35-2.7 and pc-i440fx-2.7 machines
These machines has been supported for a period of more than 6 years.
According to our versioned machine support policy (see commit
ce80c4fa6f "docs: document special exception for machine type
deprecation & removal") they can now be removed.  Remove the qtest
in test-x86-cpuid-compat.c file.

Reviewed-by: Mark Cave-Ayland <mark.caveayland@nutanix.com>
Reviewed-by: Thomas Huth <thuth@redhat.com>
Reviewed-by: Zhao Liu <zhao1.liu@intel.com>
Reviewed-by: Igor Mammedov <imammedo@redhat.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Signed-off-by: Zhao Liu <zhao1.liu@intel.com>
Link: https://lore.kernel.org/r/20260108033051.777361-21-zhao1.liu@intel.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-02-07 14:37:52 +01:00
Zhao Liu
9b65a1dbc1 tests/acpi: Update DSDT tables for pc & q35 machines
Now the legacy cpu hotplug way has gone away, and there's no _INIT
method in DSDT table for modern cpu hotplug support.

Update DSDT tables for pc machine, and_INIT methods are removed from
DSDT tables:

  -            Method (_INI, 0, Serialized)  // _INI: Initialize
  -            {
  -                CSEL = Zero
  -            }

Signed-off-by: Zhao Liu <zhao1.liu@intel.com>
Acked-by: Igor Mammedov <imammedo@redhat.com>
Link: https://lore.kernel.org/r/20260108033051.777361-8-zhao1.liu@intel.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-02-07 14:37:52 +01:00
Igor Mammedov
0a07b71f20 tests/acpi: Allow DSDT table change for x86 machines
Before dropping legacy CPU hotplug code, mark and allow the affected
ACPI tables, to avoid breaking ACPI table testing.

Signed-off-by: Igor Mammedov <imammedo@redhat.com>
Signed-off-by: Zhao Liu <zhao1.liu@intel.com>
Link: https://lore.kernel.org/r/20260108033051.777361-3-zhao1.liu@intel.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2026-02-07 14:37:52 +01:00
Igor Mammedov
66cf169e29 q35: Fix migration of SMRAM state
When migrating, dst QEMU by default has SMRAM unlocked,
and since wmask is not migrated, the migrated value of
MCH_HOST_BRIDGE_F_SMBASE in config space fall to prey of

  mch_update_smbase_smram()
    ...
    if (pd->wmask[MCH_HOST_BRIDGE_F_SMBASE] == 0xff) {
        *reg = 0x00;

and is getting cleared and leads to unlocked smram
on dst even if on source it's been locked.

As Andrey has pointed out [1], we should derive wmask
from config and not other way around.

Drop offending chunk and resync wmask based on MCH_HOST_BRIDGE_F_SMBASE
register value. That would preserve the register during
migration and set smram regions into corresponding state.

What that changes is:
that it would let guest write junk values in register
(with no apparent effect) until it's stumbles upon
reserved 0x1 [|] 0x2 values, at which point it
would be only possible to lock register and trigger
switch to SMRAM blackhole in CPU AS.

While at it, fix up test by removing junk discard before negotiation hunk.

PS2:
Instead of adding a dedicated post_load handler for it,
reuse mch_update->mch_update_smbase_smram call chain
that is called on write/reset/post_load to be consistent
with how we handle mch registers.

PS3:
for prosterity here is erro message Andrey got due to this bug:
    qemu: vfio_container_dma_map(0x..., 0x0, 0xa0000, 0x....) = -22 (Invalid argument)
    qemu: hardware error: vfio: DMA mapping failed, unable to continue

1) https://patchew.org/QEMU/20251203180851.6390-1-arbn@yandex-team.com/

Fixes: f404220e27 ("q35: implement 128K SMRAM at default SMBASE address")
Reported-by: Andrey Ryabinin <arbn@yandex-team.com>
Signed-off-by: Igor Mammedov <imammedo@redhat.com>
Reviewed-by: Andrey Ryabinin <arbn@yandex-team.com>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-Id: <20251211165454.288476-1-imammedo@redhat.com>
2026-02-05 05:06:46 -05:00
Ilia Levi
94e72135d4 tests/qtest/ufs-test: Add test for mcq completion queue wraparound
Added a test that sends 32 NOP Out commands asynchronously. Since the CQ
has 31 entries by default, this tests the scenario where CQ processing
needs to wait for space to become available.

Additionally, added two minor fixes to existing tests:
* advance CQ head after reading from CQ
* initialize command descriptor slots bitmap in ufs_init()

Signed-off-by: Ilia Levi <ilia.levi@intel.com>
Acked-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Jeuk Kim <jeuk20.kim@samsung.com>
Signed-off-by: Jeuk Kim <jeuk20.kim@samsung.com>
2026-02-02 14:33:46 +09:00
Richard Henderson
363a069b31 Merge tag 'migration-20260123-pull-request' of https://gitlab.com/farosas/qemu into staging
Migration pull request

- Removal of deprecated query-migrationthreads command
- Removal of deprecated QMP migrate argument 'detach'
- Removal of deprecated zero-blocks capability
- Removal of deprecated migration to file using fd: URI
- Improvements to fd handling in QEMUFile
- Cleanups to postcopy tests
- Cleanup of migration channel connection code

# -----BEGIN PGP SIGNATURE-----
#
# iQJEBAABCAAuFiEEqhtIsKIjJqWkw2TPx5jcdBvsMZ0FAmlz0PIQHGZhcm9zYXNA
# c3VzZS5kZQAKCRDHmNx0G+wxnS1hEADSUFCynktz0MwmPbun9rHI/DSTmkk2SFIj
# 4WI66Wgez805uD/Xa/r7qpqpjkTTFd+mgbfUlkcmiatrrPMFsYFP4cyrtFfLOl16
# ODmYZO+VQ+cFpzgXDsS1IrHSwaJ1zU7sFkYLXGJdwwhkDWDDxHpO/1OADG7HotkH
# GFaZaMFim4fAHuDp688uzbUsljNjaKNlqbZQFVeg2S+ewEFtp1/tTY2oRTuKA0Es
# BPeENU6xQxR26YPn8lZub61D12ZNw4BCKTNANGvnDGjTmC9Ijw3iAjEo5O4TWhca
# q7UPkFS9uuxIxtAeRul92XzAclASnZ52Lk1oTfP083GcXIepsFwNKKmZtulOjGm2
# bz8exu46WUSO0wxlWcM/DGfmkapKbXteP/nIBjpeRrYxxz4dBJ4MHHCNv487Si3Y
# Um8dar3wUNP6UZEt/ZGidJRvcigMwM01aDVXyn05qqHQ8Qfj93ozi9hz1ttHBeDP
# QuX6LlJ4wiU4z9QZqNaDe7pwSi/VdROkp3U0/0SVySudqE/vTC0YtUxq2miH7RLl
# VJsYPF9nZOEgKXCqMdzM4G9kr/jJ0Ou7z8hm/J6l19joBn79pf7FrRG935LCM7at
# 0xkF1D+D/O4+C/mnYemVXNwY35MhQR9OihS6DjVxYeySf4QIwUtuzBQ6W1pz9vJt
# EyLedtJXpg==
# =7sEk
# -----END PGP SIGNATURE-----
# gpg: Signature made Sat 24 Jan 2026 06:50:10 AM AEDT
# gpg:                using RSA key AA1B48B0A22326A5A4C364CFC798DC741BEC319D
# gpg:                issuer "farosas@suse.de"
# gpg: Good signature from "Fabiano Rosas <farosas@suse.de>" [unknown]
# gpg:                 aka "Fabiano Almeida Rosas <fabiano.rosas@suse.com>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: AA1B 48B0 A223 26A5 A4C3  64CF C798 DC74 1BEC 319D

* tag 'migration-20260123-pull-request' of https://gitlab.com/farosas/qemu: (36 commits)
  migration/channel: Centralize calling migration_channel_connect_outgoing
  migration: Remove qmp_migrate_finish
  migration: Move CPR HUP watch to cpr-transfer.c
  migration: Free cpr-transfer MigrationAddress along with gsource
  migration: Move URI parsing to channel.c
  migration: Move channel parsing to channel.c
  migration: Move transport connection code into channel.c
  migration: Move channel code to channel.c
  migration: Rename instances of start
  migration/channel: Rename migration_channel_connect
  migration: Start incoming from channel.c
  migration/rdma: Use common connection paths
  migration: Move setting of QEMUFile into migration_outgoing|incoming_setup
  migration: Handle error in the early async paths
  migration: Fold migration_cleanup() into migration_connect_error_propagate()
  migration: yank: Move register instance earlier
  migration: Expand migration_connect_error_propagate to cover cancelling
  migration: Move error reporting out of migration_cleanup
  migration: Free the error earlier in the resume case
  migration: Use migrate_mode() to query for cpr-transfer
  ...

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-01-24 10:08:23 +11:00
Richard Henderson
092009a55c Merge tag 'net-pull-request' of https://github.com/jasowang/qemu into staging
# -----BEGIN PGP SIGNATURE-----
#
# iQEzBAABCAAdFiEEIV1G9IJGaJ7HfzVi7wSWWzmNYhEFAmlzZqsACgkQ7wSWWzmN
# YhGITAf+I46cGYha4dE7Gepbqnk+/eHxURNhToX2yZwWsRBkn4LEWHxavWzYGhTk
# acaVL7zPiHG7S33xSUT7Ie3yrLvbpATAlBsa5xbEKS26KAVIzVtsmMJA6jHyKXUX
# RKBoX2zUkveMZCDtU0XSPjf/wzf7LyeFEDk/o9Agl5zzqfU3mfe58Zk+9MkpFJ9Y
# HEGgocbW4Kuu65RJzesejbrBw0f3PMq8cfktUJ8rj0o5v5MX58hrijBAbE5JLrxG
# Z2u1GvMFR4ZA3e+Mmgu5zg2/AZ4/ZrN9c8moxB9DWLVX8Psz4fJwyYm2Hx0ldhf4
# 4ETQ326nrAZ5REiUTea1FPACBSK7dw==
# =TV7k
# -----END PGP SIGNATURE-----
# gpg: Signature made Fri 23 Jan 2026 11:16:43 PM AEDT
# gpg:                using RSA key 215D46F48246689EC77F3562EF04965B398D6211
# gpg: Good signature from "Jason Wang (Jason Wang on RedHat) <jasowang@redhat.com>" [unknown]
# gpg: WARNING: This key is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 215D 46F4 8246 689E C77F  3562 EF04 965B 398D 6211

* tag 'net-pull-request' of https://github.com/jasowang/qemu:
  tests/qtest: Add test for filter-redirector rx event opened
  qtest: add a test to test redirector status change
  net/filter-redirector: add support for dynamic status on/off switching
  tests/qtest: add test for filter-buffer interval change
  net/filter-buffer: make interval change take effect immediately
  net/tap: rework tap_set_sndbuf()
  net/tap: tap_set_sndbuf(): add return value
  net/tap: setup exit notifier only when needed
  net/tap: rework scripts handling
  net/tap: pass NULL to net_init_tap_one() in cases when scripts are NULL
  net/tap: net_init_tap_one(): move parameter checking earlier
  net/tap: net_init_tap_one(): drop extra error propagation
  net/tap-linux.c: avoid abort when setting invalid fd

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2026-01-24 07:58:52 +11:00
Peter Xu
f1fcc1c101 migration: Remove fd: support on files
This feature was deprecated in 9.1.  Remove it in this release (11.0).

We also need to remove one unit test (/migration/precopy/fd/file) that
covers the fd: file migration, because it'll stop working now.

Reviewed-by: Prasad Pandit <ppandit@redhat.com>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Signed-off-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260115225503.3083355-3-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
2026-01-23 11:24:19 -03:00
Peter Xu
3346b16aa2 tests/migration-test: Remove postcopy_recovery_fail_stage from MigrateCommon
The parameter can be instead passed into the function to avoid polluting
the global address space of MigrateCommon.

Reviewed-by: Prasad Pandit <ppandit@redhat.com>
Signed-off-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260114153751.2427172-3-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
2026-01-23 11:24:19 -03:00
Peter Xu
86571f5121 tests/migration-test: Remove postcopy_data from MigrateCommon
Now postcopy is not the only user of start_hook / end_hook that will pass
in a opaque pointer.  It doesn't need to be defined in MigrateCommon as
part of the framework, as all other hook users can pass hook_data around.
Do it too for postcopy.

Reviewed-by: Prasad Pandit <ppandit@redhat.com>
Signed-off-by: Peter Xu <peterx@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260114153751.2427172-2-peterx@redhat.com
Signed-off-by: Fabiano Rosas <farosas@suse.de>
2026-01-23 11:24:18 -03:00
Jason Wang
014c06435f tests/qtest: Add test for filter-redirector rx event opened
Add a new test case 'test_redirector_rx_event_opened' to verify the
handling of the CHR_EVENT_OPENED event in filter-redirector.

The test simulates a scenario where the backend character device (socket)
is disconnected and then reconnected. It works by:
1. Connecting to the redirector's socket (triggers CHR_EVENT_OPENED).
2. Sending a packet to verify initial connectivity.
3. Disconnecting (triggers CHR_EVENT_CLOSED).
4. Reconnecting (triggers CHR_EVENT_OPENED again).
5. Sending another packet to verify that the redirector correctly
   re-registers its handlers and resumes passing traffic.

This ensures that the filter-redirector can recover and function correctly
after a backend reconnection.

Reviewed-by: Zhang Chen <zhangckid@gmail.com>
Signed-off-by: Jason Wang <jasowang@redhat.com>
2026-01-23 14:47:24 +08:00
Jason Wang
414af49791 qtest: add a test to test redirector status change
This patch adds a qtest to test the status change of
filter-redirector. Two subtests were added:

- test_redirector_status: tests dynamic on/off switching at runtime
  using qom-set QMP command

- test_redirector_init_status_off: tests creating filter-redirector
  with status=off from the start via command line

Both tests verify that:

1. When status is off, data from indev chardev is not received
2. When status is switched to on, data is received correctly

Reviewed-by: Zhang Chen <zhangckid@gmail.com>
Signed-off-by: Jason Wang <jasowang@redhat.com>
2026-01-23 14:46:47 +08:00
Jason Wang
50f6d44850 tests/qtest: add test for filter-buffer interval change
Add test_change_interval_timer to verify that modifying the 'interval'
property of filter-buffer at runtime takes effect immediately.

The test uses socket backend and filter-redirector to verify timer behavior:
- Creates filter-buffer with a very long interval (1000 seconds)
- Sends a packet which gets buffered
- Advances virtual clock by 1 second, verifies packet is still buffered
- Changes interval to 1ms via qom-set (timer should be rescheduled)
- Advances virtual clock by 2ms, verifies packet is now released
- This proves the timer was rescheduled immediately when interval changed

The test uses filter-redirector to observe when packets are released
by filter-buffer, providing end-to-end verification of the timer
rescheduling behavior.

Reviewed-by: Zhang Chen <zhangckid@gmail.com>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Signed-off-by: Jason Wang <jasowang@redhat.com>
2026-01-23 14:44:17 +08:00
Philippe Mathieu-Daudé
e44dc42f3a bswap: Use 'qemu/bswap.h' instead of 'qemu/host-utils.h'
These files only require "qemu/bswap.h", not "qemu/host-utils.h".

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260109163730.57087-2-philmd@linaro.org>
2026-01-22 10:48:45 +01:00
Philippe Mathieu-Daudé
3115691855 bswap: Include missing 'qemu/bswap.h' header
All these files indirectly include the "qemu/bswap.h" header.
Make this inclusion explicit to avoid build errors when
refactoring unrelated headers.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260109164742.58041-4-philmd@linaro.org>
2026-01-22 10:48:45 +01:00
Tao Tang
d8d19c31b2 tests/qtest: Add SMMUv3 bare-metal test using iommu-testdev
Add a qtest suite that validates ARM SMMUv3 translation without guest
firmware or OS. The tests leverage iommu-testdev to trigger DMA
operations and the qos-smmuv3 library to configure IOMMU translation
structures.

This test suite targets the virt machine and covers:
- Stage 1 only translation (VA -> PA via CD page tables)
- Stage 2 only translation (IPA -> PA via STE S2 tables)
- Nested translation (VA -> IPA -> PA, Stage 1 + Stage 2)
- Design to extended to support multiple security spaces
    (Non-Secure, Secure, Root, Realm)

Each test case follows this sequence:
1. Initialize SMMUv3 with appropriate command/event queues
2. Build translation tables (STE/CD/PTE) for the target scenario
3. Configure iommu-testdev with IOVA and DMA attributes via MMIO
4. Trigger DMA and validate successful translation
5. Verify data integrity through a deterministic write-read pattern

This bare-metal approach provides deterministic IOMMU testing with
minimal dependencies, making failures directly attributable to the SMMU
translation path.

Signed-off-by: Tao Tang <tangtao1634@phytium.com.cn>
Tested-by: Pierrick Bouvier <pierrick.bouvier@linaro.org>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@linaro.org>
Message-ID: <20260119161112.3841386-9-tangtao1634@phytium.com.cn>
[PMD: Cover tests/qtest/iommu-smmuv3-test.c in MAINTAINERS]
Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
2026-01-20 19:51:36 +01:00
Tao Tang
489812e32d tests/qtest/libqos: Add SMMUv3 helper library
Introduce qos-smmuv3, a reusable library for SMMUv3-related qtest
operations. This module encapsulates common tasks like:

- SMMUv3 initialization (enabling, configuring command/event queues)
- Stream Table Entry (STE) and Context Descriptor (CD) setup
- Multi-level page table construction (L0-L3 for 4KB granules)
- Support for Stage 1, Stage 2, and nested translation modes
- Could be easily extended to support multi-space testing infrastructure
    (Non-Secure, Secure, Root, Realm)

The library provides high-level abstractions that allow test code to
focus on IOMMU behavior validation rather than low-level register
manipulation and page table encoding. Key features include:

- Provide memory allocation for translation structures with proper
    alignment
- Helper functions to build valid STEs/CDs for different translation
    scenarios
- Page table walkers that handle address offset calculations per
    security space

This infrastructure is designed to be used by iommu-testdev-based tests
and future SMMUv3 test suites, reducing code duplication and improving
test maintainability.

Signed-off-by: Tao Tang <tangtao1634@phytium.com.cn>
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@linaro.org>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Message-ID: <20260119161112.3841386-8-tangtao1634@phytium.com.cn>
Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
2026-01-20 19:51:36 +01:00
Tao Tang
a68650098a tests/qtest: Add libqos iommu-testdev helpers
Introduce a libqos helper module for the iommu-testdev
device used by qtests. This module provides some common functions to
all IOMMU test cases using iommu-testdev.

Wire the new sources into tests/qtest/libqos/meson.build so
they are built as part of the qtest support library.

Signed-off-by: Tao Tang <tangtao1634@phytium.com.cn>
Message-ID: <20260119161112.3841386-7-tangtao1634@phytium.com.cn>
Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
2026-01-20 19:51:36 +01:00
Philippe Mathieu-Daudé
a49cb762eb tests/qtest/migration: Add MigrationTestEnv::has_hvf field
Allow tests to tune their parameters when running on HVF.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20250128135429.8500-6-philmd@linaro.org>
2026-01-16 07:05:09 +01:00
Philippe Mathieu-Daudé
851fc792d5 tests/qtest/migration: Make 'has_dirty_ring' generic
Keep accelerator knowledge limited within MigrationTestEnv,
expose a generic %has_dirty_ring value, only checking for
KVM when initializing it in migration_get_env().

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Message-ID: <20250128135429.8500-3-philmd@linaro.org>
2026-01-16 07:05:09 +01:00
Cédric Le Goater
aef386e0b1 tests/qtest: Fix build error
Newer gcc compiler (version 16.0.0 20260103 (Red Hat 16.0.0-0) (GCC))
detects an unused variable error:

  ../tests/qtest/libqtest.c: In function ‘qtest_qom_has_concrete_type’:
  ../tests/qtest/libqtest.c:1044:9: error: variable ‘idx’ set but not used [-Werror=unused-but-set-variable=]

Remove idx.

Cc: Fabiano Rosas <farosas@suse.de>
Cc: Laurent Vivier <lvivier@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Link: https://lore.kernel.org/qemu-devel/20260112123146.1010621-1-clg@redhat.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-01-13 08:29:59 +01:00
Zhenzhong Duan
4fda086f76 intel_iommu: Update terminology to match VTD spec
VTD spec revision 3.4 released in December 2021 renamed "First-level" to
"First-stage" and "Second-level" to "Second-stage".

Do the same in intel_iommu code to match spec, change all existing
"fl/sl/FL/SL/first level/second level/stage-1/stage-2" terminology to
"fs/ss/FS/SS/first stage/second stage".

Opportunistically fix a error print of "flts=on" with "x-flts=on".

No functional changes intended.

Suggested-by: Yi Liu <yi.l.liu@intel.com>
Suggested-by: Eric Auger <eric.auger@redhat.com>
Signed-off-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
Reviewed-by: Eric Auger <eric.auger@redhat.com>
Reviewed-by: Yi Liu <yi.l.liu@intel.com>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20260106061304.314546-4-zhenzhong.duan@intel.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-01-13 08:29:58 +01:00
Philippe Mathieu-Daudé
35ddb78b65 system/ioport: Declare x86-specific I/O port in little-endian order
X86 in/out port (related to ISA bus) uses little endianness:
- enforce little endianness in x86 cpu_in/out() accessors,
- serialize QTest in/out port accesses as little-endian.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260109165058.59144-22-philmd@linaro.org>
2026-01-12 23:47:56 +01:00
Philippe Mathieu-Daudé
8afde4364d tests/qtest: Remove unnecessary 'qemu/bswap.h' include
None of these files use API declared in "qemu/bswap.h",
remove the unnecessary inclusion.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Reviewed-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20260109164742.58041-2-philmd@linaro.org>
2026-01-12 23:47:56 +01:00
Yunpeng Yang
75c15651af hw/ipmi/ipmi_bmc_sim: Support setting fake LAN channel config
The "Set LAN Configuration Parameters" IPMI command is added to the
`ipmi_bmc_sim` device to support dynamically setting fake LAN channel
configurations. With the fake LAN channel enabled, inside the guest OS,
tools such as `ipmitool` can be used to modify the configurations.

Signed-off-by: Yunpeng Yang <yunpeng.yang@nutanix.com>
Message-ID: <20260105155648.1037077-3-yunpeng.yang@nutanix.com>
Signed-off-by: Corey Minyard <corey@minyard.net>
2026-01-05 13:07:23 -06:00
Yubin Zou
eb5f781add test/qtest: Add Unit test for Aspeed SGPIO
This commit introduces a new qtest for the Aspeed SGPIO controller
The test covers the following:
  - Setting and clearing SGPIO output pins and verifying the pin state.
  - Setting and clearing SGPIO input pins and verifying the pin state.
  - Verifying that level-high interrupts are correctly triggered and cleared.

Signed-off-by: Yubin Zou <yubinz@google.com>
Reviewed-by: Kane Chen <kane_chen@aspeedtech.com>
Link: https://lore.kernel.org/qemu-devel/20251219-aspeed-sgpio-v5-6-fd5593178144@google.com
Signed-off-by: Cédric Le Goater <clg@redhat.com>
2026-01-05 10:38:02 +01:00
Richard Henderson
942b0d378a Merge tag 'for-upstream' of https://gitlab.com/bonzini/qemu into staging
* cleanup include/hw headers
* cleanup memory headers
* rust: preludes
* rust: support for dtrace
* rust/hpet: first part of reorganization
* meson: small cleanups
* target/i386: Diamond Rapids CPU model including CET, APX, AVX10.2

# -----BEGIN PGP SIGNATURE-----
#
# iQFIBAABCgAyFiEE8TM4V0tmI4mGbHaCv/vSX3jHroMFAmlPov8UHHBib256aW5p
# QHJlZGhhdC5jb20ACgkQv/vSX3jHroPN1wf9HCceQ1273g7HbNeamay2bSaqypyM
# sEUBk4ipwO0dp7AYaaX5MeJ8NxeYcK82oFgm35WLY1tMOv0BZG5ez02dLoh5C4fb
# Bmy3kV1aY9cxF0IwTyD4dIADlZoaMnGgMElUKFY2/EixjxOUMLe90b1MO2KczqFa
# jvC4gmjx5PC1r+BHycSEdKm2Rbunueb/5eSkKeyTX7rjxQ/Eij0uGjrWrZkMWtgs
# ERJ2xo+D6a38w/uJ88KuqUV1BqYxNNwKmvOwVBU2xFB9o9bm20TNOJZ3+D+Ki8Aj
# idv+rU0XY1bWseo4USuozsqxfkjLJ5lj2YYUkSVO/I1wJmuO7Bq6xzrCxg==
# =/nIt
# -----END PGP SIGNATURE-----
# gpg: Signature made Sat 27 Dec 2025 08:12:31 PM AEDT
# gpg:                using RSA key F13338574B662389866C7682BFFBD25F78C7AE83
# gpg:                issuer "pbonzini@redhat.com"
# gpg: Good signature from "Paolo Bonzini <bonzini@gnu.org>" [unknown]
# gpg:                 aka "Paolo Bonzini <pbonzini@redhat.com>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: 46F5 9FBD 57D6 12E7 BFD4  E2F7 7E15 100C CD36 69B1
#      Subkey fingerprint: F133 3857 4B66 2389 866C  7682 BFFB D25F 78C7 AE83

* tag 'for-upstream' of https://gitlab.com/bonzini/qemu: (152 commits)
  block: rename block/aio-wait.h to qemu/aio-wait.h
  block: rename block/aio.h to qemu/aio.h
  block: reduce files included by block/aio.h
  block: extract include/qemu/aiocb.h out of include/block/aio.h
  hw: add missing includes hidden by block/aio.h
  qmp: Fix thread race
  thread-pool: Fix thread race
  dosc/cpu-models-x86: Add documentation for DiamondRapids
  i386/cpu: Add CPU model for Diamond Rapids
  i386/cpu: Define dependency for VMX_VM_ENTRY_LOAD_IA32_FRED
  i386/cpu: Add an option in X86CPUDefinition to control CPUID 0x1f
  i386/cpu: Allow cache to be shared at thread level
  i386/cpu: Allow unsupported avx10_version with x-force-features
  i386/cpu: Add a helper to get host avx10 version
  i386/cpu: Support AVX10.2 with AVX10 feature models
  i386/cpu: Add support for AVX10_VNNI_INT in CPUID enumeration
  i386/cpu: Add CPUID.0x1E.0x1 subleaf for AMX instructions
  i386/cpu: Add support for MOVRS in CPUID enumeration
  run: introduce a script for running devel commands
  gitlab-ci: enable rust for msys2-64bit
  ...

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2025-12-29 09:10:40 +11:00
Paolo Bonzini
a7ab886b6e tests/meson: do not reuse migration_files variable
The variable is defined in migration/meson.build, reusing it is confusing.

Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2025-12-27 10:11:11 +01:00
Paolo Bonzini
7f548b8f23 include: reorganize memory API headers
Move RAMBlock functions out of ram_addr.h and cpu-common.h;
move memory API headers out of include/exec and into include/system.

Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2025-12-27 10:11:09 +01:00
Paolo Bonzini
3e7316044d include: move hw/registerfields.h to hw/core/
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2025-12-27 10:11:08 +01:00
Paolo Bonzini
d1000ecae2 include: move hw/qdev-core.h to hw/core/, rename
Call it hw/core/qdev.h to avoid the duplication in the name.

Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2025-12-27 10:11:07 +01:00
Paolo Bonzini
1942b61b74 include: move hw/boards.h to hw/core/
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2025-12-27 10:11:06 +01:00
Richard Henderson
5887cb3e2b Merge tag 'qtest-20251226-pull-request' of https://gitlab.com/farosas/qemu into staging
Qtest pull request

- Fix tests using deprecated machine versions

# -----BEGIN PGP SIGNATURE-----
#
# iQJEBAABCAAuFiEEqhtIsKIjJqWkw2TPx5jcdBvsMZ0FAmlOxGMQHGZhcm9zYXNA
# c3VzZS5kZQAKCRDHmNx0G+wxnQ8jEACKyE525JVTSBqa7UTVpU1WMmViHGYoQY1S
# bbGHTnWuMMXHFw0ptF1nMRQbKSZvtOJ7BDYDs/lYhNzKCJJ47/WkHyv9npUH1ttl
# jSbbZz0iN5RrIkRvVv3paiJ+uh3pCOSnThh86eUCf8W+7lwpulYVM5AUTg7cc7Lh
# sTCDbVp6im/tB5ePySUTp7edSc+tEXe1NufmKxOfw7znvn0Aqj+31F5KV39GvyQb
# CpaoPxVI6l6F489EcDiwzLXGoOTG6pmIx0fvDiHiC+u41lwLL/dDsWfXS03EdQmu
# GXD0SKSp7ta0QhxvhSlmasM/YqNIeXGGdNeAEVvoZdV9jm3KIFZViOqa7ObPxlGO
# h8ZBM3mwkDzLcszp1F1UF5a0HoBUv7F788W1Ocn3QEumFS2UmOG1xJ6vWhBCWOyC
# n6XrA9ollxuqpBL+wkZF1fKeFWQp0+umsaosQoC1l3+dw0MIgwf0wwncMD0XNMhO
# L3pRkH/kgNo0C6U4CwujpXtel3Q0C51+6kSzpKFUgpt/5Igd30jdDEszbrv1HKFB
# ZrTOuTFPOPIH9+BVZYbId4deyUUcs0zUNUO+xpizBuq4kNg1npxGLJO77kNYOSdJ
# TurJcyAkwQp9Wd0kcMzXOVA0qKJvmsWtX36GCBhrecaW+sWLq8b8uYv8LBdFvaRh
# 3Z5depSLQQ==
# =n+cs
# -----END PGP SIGNATURE-----
# gpg: Signature made Sat 27 Dec 2025 04:22:43 AM AEDT
# gpg:                using RSA key AA1B48B0A22326A5A4C364CFC798DC741BEC319D
# gpg:                issuer "farosas@suse.de"
# gpg: Good signature from "Fabiano Rosas <farosas@suse.de>" [unknown]
# gpg:                 aka "Fabiano Almeida Rosas <fabiano.rosas@suse.com>" [unknown]
# gpg: WARNING: The key's User ID is not certified with a trusted signature!
# gpg:          There is no indication that the signature belongs to the owner.
# Primary key fingerprint: AA1B 48B0 A223 26A5 A4C3  64CF C798 DC74 1BEC 319D

* tag 'qtest-20251226-pull-request' of https://gitlab.com/farosas/qemu:
  tests/qtest: Do not use versioned pc-q35-5.0 machine anymore

Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2025-12-27 08:44:15 +11:00
Philippe Mathieu-Daudé
9eef3854d3 tests/qtest: Do not use versioned pc-q35-5.0 machine anymore
As of QEMU v10.2.0, the v5.0.0 machines are not usable anymore.

Use the latest x86 q35 machine instead, otherwise we get:

  $ qemu-system-x86_64 -M pc-q35-5.0
  qemu-system-x86_64: unsupported machine type: "pc-q35-5.0"
  Use -machine help to list supported machines

See commit a35f8577a0 ("include/hw: add macros for deprecation
& removal of versioned machines") and f59ee04406 ("include/hw/boards:
cope with dev/rc versions in deprecation checks") for explanation
on automatically removed versioned machines.

Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Fabiano Rosas <farosas@suse.de>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Link: https://lore.kernel.org/qemu-devel/20251224085714.83169-1-philmd@linaro.org
Signed-off-by: Fabiano Rosas <farosas@suse.de>
2025-12-26 12:06:46 -03:00
Fabiano Rosas
11e06ae0b5 tests/qtest/migration: Pass MigrateStart into cancel tests
Pass the "args" parameter to the cancel tests so they can access the
config object which will be part of this struct.

Signed-off-by: Fabiano Rosas <farosas@suse.de>
Link: https://lore.kernel.org/r/20251215220041.12657-27-farosas@suse.de
Signed-off-by: Peter Xu <peterx@redhat.com>
2025-12-23 09:24:34 -05:00
Fabiano Rosas
6fea394aa6 tests/qtest/migration: Pass MigrateCommon into test functions
With the upcoming addition of the config QDict, the tests will need a
better way of managing the memory of the test data than putting the
test arguments on the stack of the test functions. The config QDict
will need to be merged into the arguments of migrate_qmp* functions,
which causes a refcount increment, so the test functions would need to
allocate and deref the config QDict themselves.

A better approach is to already pass the arguments into the test
functions and do the memory management in the existing wrapper. There
is already migration_test_destroy(), which is called for every test.

Do the following:

- merge the two existing wrappers, migration_test_wrapper() and
  migration_test_wrapper_full(). The latter was pioneer in passing
  data into the tests, but now all tests will receive data, so we
  don't need it anymore.

  The usage of migration_test_wrapper_full() was in passing a slightly
  different test name string into the cancel tests, so still keep the
  migration_test_add_suffix() function.

- add (char *name, MigrateCommon *args) to the signature of all test
  functions.

- alter any code to stop allocating args on the stack and instead use
  the object that came as parameter.

- pass args around as needed.

- while here, order args (MigrateCommon) before args->start
  (MigrateStart) and put a blank like in between.

No functional change.

Signed-off-by: Fabiano Rosas <farosas@suse.de>
Link: https://lore.kernel.org/r/20251215220041.12657-26-farosas@suse.de
[peterx: fix a conflict with newly added mapped-ram+ignore-share test]
Signed-off-by: Peter Xu <peterx@redhat.com>
2025-12-23 09:24:34 -05:00