From: Stanley Jhu <stanleyjhu@google.com>
To: Jeuk Kim <jeuk20.kim@samsung.com>, qemu-devel@nongnu.org
Cc: Brian Kao <powenkao@google.com>, Stanley Jhu <stanleyjhu@google.com>
Subject: [PATCH v2 0/3] hw/ufs: Support Task Management Request (TMR) and MCQ status registers
Date: Wed, 9 Sep 2026 11:11:43 +0800 [thread overview]
Message-ID: <20260909031146.1646684-1-stanleyjhu@google.com> (raw)
This patch series implements JEDEC UFSHCI specification compliance for
Task Management Requests (TMR) and Multi-Circular Queue (MCQ) runtime
status and interrupt registers in the QEMU UFS emulator.
Why:
In QEMU UFS emulation, Linux guest error recovery paths (such as SCSI
abort during command timeout) issue Task Management Requests (TMR) via
the UTP Task Management Request List (UTMRL). Furthermore, when MCQ
is enabled, the Linux driver initializes and accesses per-queue runtime
registers (SQnRTC, SQnRTS, SQnIS, CQnIS, etc.). Currently, QEMU treats
UTMRLDBR and MCQ operational registers as unsupported, triggering
"invalid register offset" warnings and causing SCSI EH aborts to time out
and escalate unnecessarily to full controller resets. Additionally,
pending SCSI requests in the block layer were not cancelled when requests
were cleared or aborted in ufs_clear_req(), posing Use-After-Free
hazards upon asynchronous AIO callbacks.
What:
- Patch 1: Tracks SCSIRequest in UfsRequest and cancels pending requests
via scsi_req_cancel() in ufs_clear_req(), ensuring clean Block AIO
teardown.
- Patch 2: Implements MCQ runtime operational registers (queue lifecycle
control, per-queue interrupt status/enable, global CQES sync) and HCE=0
MMIO read protection.
- Patch 3: Implements Task Management Request handling for UTMRLDBR
(supporting UFS_QUERY_TASK and UFS_ABORT_TASK for both legacy UTRL
and MCQ queues).
Differences from v1:
- Split into two independent series: this series contains production
specification compliance and memory safety fixes; experimental fault
injection properties (x-hold-tag, x-hold-mode) have been moved to a
separate follow-up patch based on this series.
- Separated scsi_req_cancel() into Patch 1 to isolate the block layer
memory safety fix.
- Added HCE=0 operational register read guard (returning 0xffffffff) in
Patch 2 per JEDEC UFSHCI specification.
- Cleaned up TMR completion handling and trace events in Patch 3.
Tested:
- Verified on ARM64 Linux guest (linux-next) running on QEMU.
- Verified ufshcd_mcq_make_queues_operational() succeeds without invalid
register offset warnings.
- Verified SCSI command aborts and Task Management Requests via Linux
SCSI error handling escalation.
- Verified 100% data integrity (cmp) on /dev/sda after abort and reset
recovery.
- Passes ./scripts/checkpatch.pl with 0 errors and 0 warnings.
Stanley Jhu (3):
hw/ufs: Track SCSIRequest and cancel pending requests in ufs_clear_req
hw/ufs: Support MCQ runtime interrupt and queue status registers
hw/ufs: Implement Task Management Request (TMR) handling
hw/ufs/lu.c | 12 +++
hw/ufs/trace-events | 2 +
hw/ufs/ufs.c | 196 +++++++++++++++++++++++++++++++++++++++++++-
hw/ufs/ufs.h | 1 +
include/block/ufs.h | 9 ++
5 files changed, 217 insertions(+), 3 deletions(-)
--
2.55.0.1007.g17ff1f9808-goog
next reply other threads:[~2026-09-09 3:12 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 3:11 Stanley Jhu [this message]
2026-09-09 3:11 ` [PATCH v2 1/3] hw/ufs: Track SCSIRequest and cancel pending requests in ufs_clear_req Stanley Jhu
2026-09-23 2:03 ` Jeuk Kim
2026-09-23 14:45 ` Stanley Jhu
2026-09-09 3:11 ` [PATCH v2 2/3] hw/ufs: Support MCQ runtime interrupt and queue status registers Stanley Jhu
2026-09-23 2:03 ` Jeuk Kim
2026-09-23 14:45 ` Stanley Jhu
2026-09-09 3:11 ` [PATCH v2 3/3] hw/ufs: Implement Task Management Request (TMR) handling Stanley Jhu
2026-09-23 2:03 ` Jeuk Kim
2026-09-23 14:45 ` Stanley Jhu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909031146.1646684-1-stanleyjhu@google.com \
--to=stanleyjhu@google.com \
--cc=jeuk20.kim@samsung.com \
--cc=powenkao@google.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.