Only unmap HVF sections that were mapped - #277
Merged
Merged
Conversation
hvf_set_phys_mem() unmaps every removed section, and turns an add it cannot map into an unmap too. When pflash leaves romd_mode on a write command, the flat view deletes its mapped ROMD section and adds an I/O section for the same range; that add became a second hv_vm_unmap() of the range, and deleting the I/O section on the way back was a third. An unaligned section is unmapped without ever being mapped in the same way. The ROM device's romd_mode already holds its new value when the old section is deleted, so the region cannot tell a mapped section from one that never was. Add a QEMU patch that records mapped sections, as KVM does with its slot lookup, and only unmaps what it recorded. omacom#151 is an M4 on macOS 26.3 killed with EXC_GUARD (DEALLOC_GAP) in hv_vm_unmap, called from pflash_mem_write_with_attrs. The test compiles the patched function against a fake HVF that refuses to unmap what it does not hold, and checks the mapping after every step of a pflash write/read cycle, device removal and an unaligned section: the original makes four bad unmaps, the patched one none, and the flash traps while out of romd_mode. QEMU was not rebuilt and the crash was not reproduced here; an HVF trace from an affected Mac would confirm it. Refs omacom#151
stevederico
force-pushed
the
fix/hvf-romd-double-unmap
branch
from
September 28, 2026 05:04
aa049d1 to
e1a35c2
Compare
stevederico
marked this pull request as ready for review
September 28, 2026 05:05
This was referenced Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed and why
Refs #151.
hvf_set_phys_mem()unmaps every removed section, and turns an add it cannot map into an unmap as well. When pflash leaves romd_mode on a write command, the flat view deletes its mapped ROMD section and adds an I/O section for the same range; that add becomes a secondhv_vm_unmap()of the range, and deleting the I/O section on the way back to romd_mode is a third. #151's crash isEXC_GUARD (DEALLOC_GAP)inhv_vm_unmap, called frompflash_mem_write_with_attrs.The ROM device's
romd_modealready holds its new value when the old section is deleted, so the region cannot tell a mapped section from one that never was. The new QEMU patchmacos/patches/qemu-hvf-mapped-sections.patchrecords the sections it maps (keyed by start address, since a section is removed with the range it was added with) and only unmaps what it recorded, like KVM's slot lookup. It applies after the free-page reclaim patch.Testing
python3 macos/Tests/test-hvf-mapped-sections.py: compiles the patched function against a fake HVF that refuses to unmap what it does not hold, and checks the mapping after every step of a pflash write/read cycle, device removal and an unaligned section. The original function makes four bad unmaps; the patched one makes none, and the flash traps while out of romd_modec3d48b7after all existing project patchesmake testpasses on this branch on macOS 15.6 (MacBook Air, Apple Silicon)make runtimebuilds QEMU with this patch on macOS 15.6