Commit e27a401d2e for qemu.org

commit e27a401d2e5a78a303f2c393a289638824e8c0a7
Author: Nguyen Dinh Phi <phind.uet@gmail.com>
Date:   Mon Aug 3 01:03:45 2026 +0800

    rust/bits: Use checked_ilog2() in Binary::format to avoid panic

    ilog2() panics when VALID__ is 0 on empty bits. Switch to checked_ilog2()
    to handle zero safely.

    Signed-off-by: Nguyen Dinh Phi <phind.uet@gmail.com>
    Link: https://lore.kernel.org/r/20260802170346.3493821-3-phind.uet@gmail.com
    Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>

diff --git a/rust/bits/src/lib.rs b/rust/bits/src/lib.rs
index 60b63f969d..5769bc761a 100644
--- a/rust/bits/src/lib.rs
+++ b/rust/bits/src/lib.rs
@@ -215,7 +215,9 @@ pub const fn invert(self) -> Self {
         impl ::std::fmt::Binary for $struct_name {
             fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
                 // If no width, use the highest valid bit
-                let width = f.width().unwrap_or((Self::VALID__.ilog2() + 1) as usize);
+                let width = f
+                    .width()
+                    .unwrap_or(Self::VALID__.checked_ilog2().map_or(1, |bit| (bit + 1) as usize));
                 write!(f, "{:0>width$.precision$b}", self.0,
                        width = width,
                        precision = f.precision().unwrap_or(width))
@@ -412,6 +414,12 @@ pub struct InterruptMask(u32) {
         }
     }

+    bits! {
+        pub struct EmptyMask(u32) {
+            NONE = 0,
+        }
+    }
+
     #[test]
     pub fn test_not() {
         assert_eq!(
@@ -450,4 +458,9 @@ pub fn test_sub_assign() {
         op1 -= InterruptMask::RI;
         assert_eq!(op1, InterruptMask::E - InterruptMask::RI);
     }
+
+    #[test]
+    pub fn test_bit_display_empty() {
+        assert_eq!(format!("{:b}", EmptyMask::NONE), "0");
+    }
 }