All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Marc-André Lureau" <marcandre.lureau@redhat.com>
To: qemu-devel@nongnu.org
Cc: richard.henderson@linaro.org
Subject: [GIT PULL 18/19] hw/input/ps2: answer unknown mouse commands with a resend
Date: Tue, 25 Aug 2026 15:21:08 +0400	[thread overview]
Message-ID: <20260825-fixes-v1-18-c59e8a620836@redhat.com> (raw)
In-Reply-To: <20260825-fixes-v1-0-c59e8a620836@redhat.com>

From: Christian Quante <christian@quante.one>

ps2_write_mouse() ends its command switch with a bare "default: break;",
so an unknown command draws no reply at all. A real PS/2 device answers
every byte it is given -- ACK (0xFA) when it understood one, resend
(0xFE) when it did not -- and a guest that gets nothing back is left
waiting out its reply timeout. The keyboard path in the same file has
answered unknown commands with KBD_REPLY_RESEND since commit
06b3611fc2a3 ("ps2: reject unknown commands, instead of blindly
accepting them").

Two guests were measured on this.

OS/2 probes the mouse with the vendor command 0xBB, which QEMU does not
implement, and then polls the status port until its own timeout runs
out. On a Warp 3 guest that wait costs about 25 ms of every boot under
TCG, and 2.1 s under KVM, where each of those polls leaves the guest.
With this patch the wait ends on the first read: the guest takes the
same error path an unexpected reply would, and does not retry.

Linux runs into two of them while probing the mouse: the ALPS probe
sends 0xEC (reset wrap mode), which ps2_write_mouse() only answers
while the mouse is in wrap mode, and the TrackPoint probe sends 0xE1.
Each costs libps2 a 200 ms reply timeout. Timing the psmouse detection
from a mark written to /dev/kmsg to the kernel's "input:" line, three
boots each of a 6.18.35 kernel under TCG: 426.7/428.8/441.6 ms without
this patch, 21.4/21.6/21.2 ms with it. The mouse is detected
identically either way; only the error the probe ends in changes, from
-EIO (nothing came back at all) to -EPROTO (libps2 gives up after its
second attempt).

The specification's second stage -- 0xFC (Error) when the byte after a
rejected one is invalid as well -- is deliberately left out. It would
need state that has to survive migration, no guest is known to test for
it, and the keyboard path does without it as well.

Cc: qemu-stable@nongnu.org
Signed-off-by: Christian Quante <christian@quante.one>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Message-ID: <20260825075127.34876-2-christian@quante.one>
---
 hw/input/ps2.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/hw/input/ps2.c b/hw/input/ps2.c
index 5516eb262d70..e8300d2d8308 100644
--- a/hw/input/ps2.c
+++ b/hw/input/ps2.c
@@ -73,6 +73,7 @@
 #define AUX_SET_DEFAULT     0xF6
 #define AUX_RESET           0xFF    /* Reset aux device */
 #define AUX_ACK             0xFA    /* Command byte ACK. */
+#define AUX_RESEND          0xFE    /* Command NACK, send the cmd again */
 
 #define MOUSE_STATUS_REMOTE     0x40
 #define MOUSE_STATUS_ENABLED    0x20
@@ -955,6 +956,11 @@ void ps2_write_mouse(PS2MouseState *s, int val)
                 s->mouse_type);
             break;
         default:
+            /*
+             * A PS/2 device answers every command it is given; an unknown
+             * one draws a resend.
+             */
+            ps2_queue(ps2, AUX_RESEND);
             break;
         }
         break;

-- 
2.55.0.543.g5ebe2ebe4ea8



  parent reply	other threads:[~2026-08-25 11:31 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-25 11:20 [GIT PULL 00/19] Various fixes Marc-André Lureau
2026-08-25 11:20 ` [GIT PULL 01/19] hw/misc: fix trace-events Marc-André Lureau
2026-08-25 11:20 ` [GIT PULL 02/19] migration/multifd: fix Error leak in multifd_recv_terminate_threads() Marc-André Lureau
2026-08-25 11:20 ` [GIT PULL 03/19] hw/core/machine: fix fdt memory leak Marc-André Lureau
2026-08-25 11:20 ` [GIT PULL 04/19] hw/display/qxl: validate primary surface stride against width Marc-André Lureau
2026-08-25 11:20 ` [GIT PULL 05/19] virtio-gpu: use g_try_malloc to avoid guest-triggered abort Marc-André Lureau
2026-09-03 19:36   ` Peter Maydell
2026-09-03 20:53     ` Marc-André Lureau
2026-09-10 11:19       ` Peter Maydell
2026-08-25 11:20 ` [GIT PULL 06/19] crypto: fix build against nettle >= 4 Marc-André Lureau
2026-08-25 11:54   ` Daniel P. Berrangé
2026-08-25 11:20 ` [GIT PULL 07/19] tests: tag slow tests with 'slow' suite for easy filtering Marc-André Lureau
2026-08-25 11:20 ` [GIT PULL 08/19] ui/egl: fix render node cleanup order Marc-André Lureau
2026-08-25 11:20 ` [GIT PULL 09/19] ui/egl: fix qemu_egl_display type Marc-André Lureau
2026-08-25 11:21 ` [GIT PULL 10/19] tests/functional: fix pylint false positives for cv2 module Marc-André Lureau
2026-08-25 11:21 ` [GIT PULL 11/19] chardev: Don't unregister yank upon async path connection failure Marc-André Lureau
2026-08-25 11:21 ` [GIT PULL 12/19] hw/display/vga: fix text-mode OOB write after a graphics surface switch Marc-André Lureau
2026-08-25 11:21 ` [GIT PULL 13/19] hw/display/virtio-gpu: Avoid creating empty udmabuf Marc-André Lureau
2026-08-25 11:21 ` [GIT PULL 14/19] hw/display/virtio-gpu: Avoid mmap() for empty blob Marc-André Lureau
2026-08-25 11:21 ` [GIT PULL 15/19] hw/display/virtio-gpu: Propagate udmabuf errors Marc-André Lureau
2026-08-25 11:21 ` [GIT PULL 16/19] hw/display/virtio-gpu: Check cursor data presence Marc-André Lureau
2026-08-25 11:21 ` [GIT PULL 17/19] hw/display/virtio-gpu: Validate resource per command Marc-André Lureau
2026-08-25 11:21 ` Marc-André Lureau [this message]
2026-08-25 11:21 ` [GIT PULL 19/19] hw/input/ps2: say why unknown keyboard commands draw a resend Marc-André Lureau
2026-08-25 18:40 ` [GIT PULL 00/19] Various fixes Richard Henderson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260825-fixes-v1-18-c59e8a620836@redhat.com \
    --to=marcandre.lureau@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=richard.henderson@linaro.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.