)]}'
{
  "commit": "1c1e34cda5dbcf41bbbd33cdf592f32cbbbcd9d6",
  "tree": "5d1646c9abb244f451b59265ba38becce0d42045",
  "parents": [
    "0ad411258bb4586a50b93864d342668eb37be9e9"
  ],
  "author": {
    "name": "Junjie Cao",
    "email": "junjie.cao@intel.com",
    "time": "Mon Aug 31 10:23:02 2026 +0800"
  },
  "committer": {
    "name": "Michael Tokarev",
    "email": "mjt@tls.msk.ru",
    "time": "Wed Sep 16 09:36:16 2026 +0300"
  },
  "message": "hw/cxl: fix the CDAT DOE overlapping the Flex Bus DVSEC when sn\u003d is set\n\nct3_realize() adds the CDAT DOE at a fixed 0x190.  Since 8700ee15de the\nfour DVSECs take 0x90 bytes, which from 0x100 ends exactly at 0x190.\nWith sn\u003d the Device Serial Number capability pushes the block to\n0x10c..0x19c, and the DOE, added later, overwrites the last 12 bytes of\nthe Flex Bus Port DVSEC: Capability2, Control2 and Status2.  Nothing\ncatches this -- pcie_add_capability() checks bounds, not overlap, and\nthe chain still walks because the DVSEC\u0027s next pointer becomes 0x190,\ninside its own body.  Most cxl-type3 examples in\ndocs/system/devices/cxl.rst set sn\u003d.\n\nDerive the offset from the DVSEC block instead, as cxl_upstream.c\nalready does.  Without sn\u003d the layout is unchanged byte for byte; with\nsn\u003d the DOE moves to 0x19c, below the AER capability at 0x200.  The\ntype 3 device has no VMStateDescription, so its config space never\nreaches the migration stream.\n\nFixes: 8700ee15de (\"hw/cxl: Standardize all references on CXL r3.1 and minor updates\")\nSigned-off-by: Junjie Cao \u003cjunjie.cao@intel.com\u003e\nReviewed-by: Michael S. Tsirkin \u003cmst@redhat.com\u003e\nSigned-off-by: Michael S. Tsirkin \u003cmst@redhat.com\u003e\nMessage-ID: \u003c20260831022302.406740-1-junjie.cao@intel.com\u003e\n(cherry picked from commit 0ddbce88c45a7376a9fc948097d58195358ffec7)\nSigned-off-by: Michael Tokarev \u003cmjt@tls.msk.ru\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "91db48570d2b668d10a5a036537e3ae62f13a919",
      "old_mode": 33188,
      "old_path": "hw/mem/cxl_type3.c",
      "new_id": "f516ab203b20e45f5f8377752f9d4289c2cd21f0",
      "new_mode": 33188,
      "new_path": "hw/mem/cxl_type3.c"
    }
  ]
}
