Commit 10a81449a2 for qemu.org
commit 10a81449a279be0d5b46c3422b445ca3f42d3393
Author: Matthew Rosato <mjrosato@linux.ibm.com>
Date: Tue Sep 29 11:30:11 2026 -0400
s390x/pci: Use qemu_log_mask() for guest-triggered errors in reg_ioat()
The error paths in reg_ioat() that are triggered by a guest providing
invalid MPCIFC arguments use error_report(), which writes unconditionally
to stderr. A misbehaving guest can exploit this to flood the host log
by repeatedly issuing the instruction with bad arguments.
Replace these with qemu_log_mask(LOG_GUEST_ERROR, ...) so that the
messages are suppressible.
Fixes: 863f6f52b713 ("s390: implement pci instructions")
Fixes: dfcee1ea4c52 ("s390x/pci: add support for guests that request direct mapping")
Cc: qemu-stable@nongnu.org
Signed-off-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Farhan Ali <alifm@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Link: https://lore.kernel.org/qemu-devel/20260929153012.774530-3-mjrosato@linux.ibm.com
Signed-off-by: Eric Farman <farman@linux.ibm.com>
diff --git a/hw/s390x/s390-pci-inst.c b/hw/s390x/s390-pci-inst.c
index bac813fb6a..73417edade 100644
--- a/hw/s390x/s390-pci-inst.c
+++ b/hw/s390x/s390-pci-inst.c
@@ -15,8 +15,8 @@
#include "exec/memop.h"
#include "exec/target_page.h"
#include "system/memory.h"
-#include "qemu/error-report.h"
#include "qemu/bswap.h"
+#include "qemu/log.h"
#include "system/hw_accel.h"
#include "hw/core/boards.h"
#include "hw/pci/pci_device.h"
@@ -1044,11 +1044,12 @@ static int reg_ioat(CPUS390XState *env, S390PCIBusDevice *pbdev, ZpciFib fib,
/* currently we only support designation type 1 with translation */
if (t && dt != ZPCI_IOTA_RTTO) {
- error_report("unsupported ioat dt %d t %d", dt, t);
+ qemu_log_mask(LOG_GUEST_ERROR,
+ "unsupported ioat dt %d t %d\n", dt, t);
s390_program_interrupt(env, PGM_OPERAND, ra);
return -EINVAL;
} else if (!t && !pbdev->rtr_avail) {
- error_report("relaxed translation not allowed");
+ qemu_log_mask(LOG_GUEST_ERROR, "relaxed translation not allowed\n");
s390_program_interrupt(env, PGM_OPERAND, ra);
return -EINVAL;
}