)]}'
{
  "log": [
    {
      "commit": "539bc315538afe036a4b99088659aa82e3b489f2",
      "tree": "086533de9fabc4225b24c79f3ffddcd04cbc1fed",
      "parents": [
        "42f81189265fdb965755f61294de9463cc22c10f",
        "77b91aca6148fafcade41516f12a3309f1e1f552"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Thu Aug 13 07:16:25 2026 -0700"
      },
      "committer": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Thu Aug 13 07:16:25 2026 -0700"
      },
      "message": "Merge tag \u0027pull-loongarch-20260813\u0027 of https://github.com/bibo-mao/qemu into staging\n\nloongarch queue\n\n# -----BEGIN PGP SIGNATURE-----\n#\n# iHUEABYKAB0WIQQNhkKjomWfgLCz0aQfewwSUazn0QUCan07bAAKCRAfewwSUazn\n# 0ZduAP9gFsFWHI9HgdeS+y48rLpqDMTK2y8P+WTGTj61nG5UngEA0HlDV+wQGkcA\n# WVqq1qafvTFDi/DSYErFmLlvFhUQCA4\u003d\n# \u003dAi1s\n# -----END PGP SIGNATURE-----\n# gpg: Signature made Wed 12 Aug 2026 08:35:08 PM PDT\n# gpg:                using EDDSA key 0D8642A3A2659F80B0B3D1A41F7B0C1251ACE7D1\n# gpg: Good signature from \"bibo mao \u003cmaobibo@loongson.cn\u003e\" [unknown]\n# gpg: WARNING: This key is not certified with a trusted signature!\n# gpg:          There is no indication that the signature belongs to the owner.\n# Primary key fingerprint: 7044 3A00 19C0 E97A 31C7  13C4 8E86 8FB7 A176 9D4C\n#      Subkey fingerprint: 0D86 42A3 A265 9F80 B0B3  D1A4 1F7B 0C12 51AC E7D1\n\n* tag \u0027pull-loongarch-20260813\u0027 of https://github.com/bibo-mao/qemu:\n  target/loongarch: Set timer tick value even if disabled\n  tests/acpi: Update LoongArch virt MADT\n  hw/loongarch/virt: Set MADT revision to 6\n  tests/acpi: Allow LoongArch virt MADT changes\n  hw/intc/loongarch_pch_pic: Validate htmsi_vector before indexing parent_irq\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\n"
    },
    {
      "commit": "42f81189265fdb965755f61294de9463cc22c10f",
      "tree": "1951cb230fcdd930cd5d292a2a92e560b38e0181",
      "parents": [
        "8402bdd56e37d0d2da1a2013b7ad74832256be50",
        "89f15c1362970150bf5711cdb84b9742c0db0cd8"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Thu Aug 13 07:14:33 2026 -0700"
      },
      "committer": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Thu Aug 13 07:14:33 2026 -0700"
      },
      "message": "Merge tag \u0027next-pull-request\u0027 of https://gitlab.com/peterx/qemu into staging\n\nmigration/mem pull for 11.2\n\nv2: fixes macos build error\n\n- Dongli\u0027s patch to add cpr-transfer support for HMP\n- Fabiano\u0027s doc update for migration on security issues\n- Gavin\u0027s fix for MMIO access support for memory APIs, reverting ram_device ops\n- Sam\u0027s migration test build fix for !ASN1\n- Peter\u0027s a few migration hardening fixes\n\n# -----BEGIN PGP SIGNATURE-----\n#\n# iIgEABYKADAWIQS5GE3CDMRX2s990ak7X8zN86vXBgUCan3KARIccGV0ZXJ4QHJl\n# ZGhhdC5jb20ACgkQO1/MzfOr1wa76QD/eBLnPtDvmpNHNH3+bm/3XC3zwyy7v69U\n# bGK3ocwI3sQA/j9o5FCc7xDCA0QaW6RMeerlLXvXR0uwH46UESKKDloF\n# \u003d/Jbs\n# -----END PGP SIGNATURE-----\n# gpg: Signature made Thu 13 Aug 2026 06:43:29 AM PDT\n# gpg:                using EDDSA key B9184DC20CC457DACF7DD1A93B5FCCCDF3ABD706\n# gpg:                issuer \"peterx@redhat.com\"\n# gpg: Good signature from \"Peter Xu \u003cxzpeter@gmail.com\u003e\" [unknown]\n# gpg:                 aka \"Peter Xu \u003cpeterx@redhat.com\u003e\" [unknown]\n# gpg: WARNING: The key\u0027s User ID is not certified with a trusted signature!\n# gpg:          There is no indication that the signature belongs to the owner.\n# Primary key fingerprint: B918 4DC2 0CC4 57DA CF7D  D1A9 3B5F CCCD F3AB D706\n\n* tag \u0027next-pull-request\u0027 of https://gitlab.com/peterx/qemu:\n  migration: Fix rare hang of migration_channel_read_peek()\n  migration/ram: Check for RAMBlock size mismatch when parsing\n  migration/multifd: Replace assert() with error_setg() in recv paths\n  migration/multifd: Validate next_packet_size in zlib/zstd recv\n  tests/qtest/migration: Only build tls_no_hostname test with TASN1\n  system/memory: Make ram device region directly accessible\n  system/memory: Use qemu_ram_move() for directly accessible regions\n  system/memory: Use memmove() for directly accessible regions\n  migration/cpr: Add HMP support for cpr-transfer\n  docs: Add security considerations for migration\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\n"
    },
    {
      "commit": "89f15c1362970150bf5711cdb84b9742c0db0cd8",
      "tree": "98a1cf37479de0deabec53c06c16069f7bdedef1",
      "parents": [
        "10dd206e92e0f688b7aa411e57533448c56ab6b8"
      ],
      "author": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Wed Aug 12 08:43:27 2026 -0400"
      },
      "committer": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Thu Aug 13 09:41:40 2026 -0400"
      },
      "message": "migration: Fix rare hang of migration_channel_read_peek()\n\nIn an unlikely case, when a migration stream is attached to the destination\nQEMU and only send \u003c4 bytes to the channel as magic, it\u0027s possible that\nmigration_channel_read_peek() may spin forever.\n\nFix it by adding a manual sleep for partial read.\n\nSince the path isn\u0027t attached to a coroutine, it means when partial read\nhappens, there\u0027s yet not much we can do but hang the main thread, it will\nhappen even for len\u003d\u003d0 case.  It means monitors can hang due to this,\neither partial read or no data arrived (but connection established).\n\nLeave this for later, the hope is this is extremely rare in production.\n\nResolves: https://gitlab.com/qemu-project/qemu/-/work_items/3889\nReported-by: Feifan Qian \u003cbea1e@proton.me\u003e\nCc: Daniel P. Berrangé \u003cberrange@redhat.com\u003e\nReviewed-by: Daniel P. Berrangé \u003cberrange@redhat.com\u003e\nLink: https://lore.kernel.org/r/20260812124327.2572363-1-peterx@redhat.com\nSigned-off-by: Peter Xu \u003cpeterx@redhat.com\u003e\n"
    },
    {
      "commit": "10dd206e92e0f688b7aa411e57533448c56ab6b8",
      "tree": "7c208e500c4b9460854d96fe94d1ccd549db6d32",
      "parents": [
        "cf45083edc2b760a952836187aba7ec4139418c0"
      ],
      "author": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Tue Jul 28 17:04:17 2026 -0400"
      },
      "committer": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Thu Aug 13 09:41:40 2026 -0400"
      },
      "message": "migration/ram: Check for RAMBlock size mismatch when parsing\n\nAdd an underflow check for the subtract of total RAMBlock size to make sure\nit won\u0027t underflow.  It should not happen in production systems but only if\nthe migration stream was hijacked, which is not a real concern since\nmigration channel is trusted.  Still protect against it.\n\nResolves: https://gitlab.com/qemu-project/qemu/-/work_items/4013\nReported-by: Tristan Madani \u003ctristan@talencesecurity.com\u003e\nReviewed-by: Fabiano Rosas \u003cfarosas@suse.de\u003e\nLink: https://lore.kernel.org/r/20260728210417.1925078-6-peterx@redhat.com\nSigned-off-by: Peter Xu \u003cpeterx@redhat.com\u003e\n"
    },
    {
      "commit": "77b91aca6148fafcade41516f12a3309f1e1f552",
      "tree": "84430ef39856d0e472bfb75fc3c81b272589d726",
      "parents": [
        "c94267793c10ef111663d8c2e85e0331ff8a6800"
      ],
      "author": {
        "name": "Bibo Mao",
        "email": "maobibo@loongson.cn",
        "time": "Tue Jul 14 10:55:16 2026 +0800"
      },
      "committer": {
        "name": "Bibo Mao",
        "email": "maobibo@loongson.cn",
        "time": "Thu Aug 13 11:34:48 2026 +0800"
      },
      "message": "target/loongarch: Set timer tick value even if disabled\n\nIf constant timer is enabled, its tick value is remained value from\nthe next expired time. However if timer is not enabled, its value\nshould be CONSTANT_TIMER_TICK_MASK or zero.\n\nSigned-off-by: Bibo Mao \u003cmaobibo@loongson.cn\u003e\nReviewed-by: Xianglai Li \u003clixianglai@loongson.cn\u003e\n"
    },
    {
      "commit": "c94267793c10ef111663d8c2e85e0331ff8a6800",
      "tree": "fe9d200a00c7ef7071ed1a53322c6444cb326785",
      "parents": [
        "9583a9c07d9d91439e5921ae7fb69bd7f69a94f3"
      ],
      "author": {
        "name": "Dongyan Qian",
        "email": "qiandongyan@loongson.cn",
        "time": "Tue Aug 04 11:30:36 2026 +0800"
      },
      "committer": {
        "name": "Bibo Mao",
        "email": "maobibo@loongson.cn",
        "time": "Thu Aug 13 11:34:48 2026 +0800"
      },
      "message": "tests/acpi: Update LoongArch virt MADT\n\nRegenerate the APIC and APIC.topology test data after correcting the\nLoongArch virt MADT revision.\n\nThe generated tables change only Header.Revision from 1 to 6 and the\ncorresponding checksum. Their lengths and interrupt controller\nsubtables remain unchanged.\n\nSigned-off-by: Dongyan Qian \u003cqiandongyan@loongson.cn\u003e\nSigned-off-by: Bibo Mao \u003cmaobibo@loongson.cn\u003e\nReviewed-by: Bibo Mao \u003cmaobibo@loongson.cn\u003e\n"
    },
    {
      "commit": "9583a9c07d9d91439e5921ae7fb69bd7f69a94f3",
      "tree": "27ba619af426e8b4f7c1ffbd90c39eba5d1c28fd",
      "parents": [
        "181b584b7765fac97a3caac3fe0121fc379d779a"
      ],
      "author": {
        "name": "Dongyan Qian",
        "email": "qiandongyan@loongson.cn",
        "time": "Tue Aug 04 11:30:35 2026 +0800"
      },
      "committer": {
        "name": "Bibo Mao",
        "email": "maobibo@loongson.cn",
        "time": "Thu Aug 13 11:34:48 2026 +0800"
      },
      "message": "hw/loongarch/virt: Set MADT revision to 6\n\nThe LoongArch virt machine emits Core PIC, EIO PIC, MSI PIC and BIO PIC\nsubtables, but advertises MADT revision 1. Revision 1 predates these\nLoongArch interrupt controller structures.\n\nACPI 6.5 introduced the LoongArch interrupt controller structures and\ndefined MADT revision 6. ACPI 6.6 raises the MADT revision to 7 for the\nadditional RISC-V interrupt controller structures, while leaving the\nLoongArch structures unchanged.\n\nSince the virt machine emits only the LoongArch structures defined by\nACPI 6.5, set the MADT header revision to 6, the minimum revision that\ndescribes the table contents.\n\nFixes: 735143f10d3 (\"hw/loongarch: Add acpi ged support\")\nSigned-off-by: Dongyan Qian \u003cqiandongyan@loongson.cn\u003e\nSigned-off-by: Bibo Mao \u003cmaobibo@loongson.cn\u003e\nReviewed-by: Bibo Mao \u003cmaobibo@loongson.cn\u003e\n"
    },
    {
      "commit": "181b584b7765fac97a3caac3fe0121fc379d779a",
      "tree": "551d853e427b7664736d61d51b01298814d92133",
      "parents": [
        "80776c4df92c3d58f89608b61e355092a7d524ed"
      ],
      "author": {
        "name": "Dongyan Qian",
        "email": "qiandongyan@loongson.cn",
        "time": "Tue Aug 04 11:30:34 2026 +0800"
      },
      "committer": {
        "name": "Bibo Mao",
        "email": "maobibo@loongson.cn",
        "time": "Thu Aug 13 11:34:47 2026 +0800"
      },
      "message": "tests/acpi: Allow LoongArch virt MADT changes\n\nThe LoongArch virt MADT revision will be corrected to match the\ninterrupt controller structures it contains.\n\nAllow the APIC and APIC.topology test data to change so that the source\nchange can be reviewed separately from the regenerated binary tables.\n\nSigned-off-by: Dongyan Qian \u003cqiandongyan@loongson.cn\u003e\nSigned-off-by: Bibo Mao \u003cmaobibo@loongson.cn\u003e\nReviewed-by: Bibo Mao \u003cmaobibo@loongson.cn\u003e\n"
    },
    {
      "commit": "80776c4df92c3d58f89608b61e355092a7d524ed",
      "tree": "6e81a898ed50a37ffbd2e6a97a058dfbf3220292",
      "parents": [
        "d49f87606ac1a6e15701b26c1b16c5d7e948ffcb"
      ],
      "author": {
        "name": "Bin Guo",
        "email": "guobin@linux.alibaba.com",
        "time": "Tue Aug 04 15:34:45 2026 +0800"
      },
      "committer": {
        "name": "Bibo Mao",
        "email": "maobibo@loongson.cn",
        "time": "Thu Aug 13 11:34:47 2026 +0800"
      },
      "message": "hw/intc/loongarch_pch_pic: Validate htmsi_vector before indexing parent_irq\n\npch_pic_update_irq() used the guest-writable htmsi_vector[irq] value as an\nindex into parent_irq[] without checking bounds.  A value \u003e\u003d irq_num (64 in\nthe array, but only 32 are used by the virt machine) causes an out-of-bounds\nread and a guest-triggerable QEMU crash.\n\nValidate the vector before calling qemu_set_irq() in both the raise and lower\npaths and log a guest error if it is out of range.\n\nResolves: https://gitlab.com/qemu-project/qemu/-/work_items/4114\nCc: qemu-stable@nongnu.org\nSigned-off-by: Bin Guo \u003cguobin@linux.alibaba.com\u003e\nSigned-off-by: Bibo Mao \u003cmaobibo@loongson.cn\u003e\nReviewed-by: Bibo Mao \u003cmaobibo@loongson.cn\u003e\n"
    },
    {
      "commit": "8402bdd56e37d0d2da1a2013b7ad74832256be50",
      "tree": "e603253b1a83d551f4b502cbd992efface4ae604",
      "parents": [
        "d49f87606ac1a6e15701b26c1b16c5d7e948ffcb",
        "9b3d68edb24d4e04f49822c6e11641e4eb23dfd5"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Wed Aug 12 18:48:06 2026 -0700"
      },
      "committer": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Wed Aug 12 18:48:06 2026 -0700"
      },
      "message": "Merge tag \u0027s390x-20260812\u0027 of https://gitlab.com/efarman/qemu into staging\n\nFirst batch of s390x updates for 11.2:\n - compat machines for 11.2\n - allow guest backing with 2G hugepages\n - fixes to TCG (and a couple tests on them)\n - hardening fixes in boot/sclp code\n - regenerate s390-ccw.img\n\n# -----BEGIN PGP SIGNATURE-----\n#\n# iIsEABYKADMWIQQB3Dhbwk4ZE3uUN6KmTx4R4Fx3tAUCanygMxUcZmFybWFuQGxp\n# bnV4LmlibS5jb20ACgkQpk8eEeBcd7RMqwEAzBhcnvUDHowDalVgBJ4QTWcbUx2D\n# dZgoMvFpFYB2aEsA/32H81TzvrwX4xAkJlqdGIrQbPGmtdvAOKfjketAjGMC\n# \u003dlFhB\n# -----END PGP SIGNATURE-----\n# gpg: Signature made Wed 12 Aug 2026 09:32:51 AM PDT\n# gpg:                using EDDSA key 01DC385BC24E19137B9437A2A64F1E11E05C77B4\n# gpg:                issuer \"farman@linux.ibm.com\"\n# gpg: Good signature from \"Eric Farman \u003cfarman@linux.ibm.com\u003e\" [unknown]\n# gpg: WARNING: The key\u0027s User ID is not certified with a trusted signature!\n# gpg:          There is no indication that the signature belongs to the owner.\n# Primary key fingerprint: D2C6 0504 C9E8 F568 CFE5  87B5 3827 B212 71BF 9562\n#      Subkey fingerprint: 01DC 385B C24E 1913 7B94  37A2 A64F 1E11 E05C 77B4\n\n* tag \u0027s390x-20260812\u0027 of https://gitlab.com/efarman/qemu:\n  pc-bios/s390-ccw.img: update s390x bios\n  hw: add compat machines for 11.2\n  target/s390x: Allow 2G hugepages guest backing\n  tests/tcg/s390x: Test STCKF condition code on a faulting store\n  target/s390x/tcg: Set STCK/STCKF condition code after the store\n  pc-bios/s390-ccw: Fix off-by-one errors with loadparm and boot entries\n  pc-bios/s390-ccw: bound zipl menu strlen and replace VLA in zipl_print_entry\n  pc-bios/s390-ccw: bounds-check zipl menu entry index before array write\n  pc-bios/s390-ccw: fix out-of-bounds read in iso_get_file_size()\n  s390x/ipl: validate num_comp against iplb length before iterating\n  hw/char/sclpconsole-lm: avoid guest triggerable assert\n  tests/tcg/s390x: Test DR overflow (INT64_MIN / -1)\n  target/s390x: Fix DR/D INT64_MIN / -1 host crash\n  tests/tcg/s390x: Test PRNO TRNG interruptibility\n  target/s390x: Make PRNO TRNG interruptible\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\n"
    },
    {
      "commit": "d49f87606ac1a6e15701b26c1b16c5d7e948ffcb",
      "tree": "baa431cb9629c77c45f9096dd2449b21c9830f5d",
      "parents": [
        "055952c0aa91ea7a00d135b73f78fc0b13442d6c",
        "ce276ab1a92cad460930fada1bc2e2e4a96f7595"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Wed Aug 12 15:21:53 2026 -0700"
      },
      "committer": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Wed Aug 12 15:21:53 2026 -0700"
      },
      "message": "Merge tag \u0027linux-user-pull-request\u0027 of https://github.com/hdeller/qemu-hppa into staging\n\nlinux-user patches\n\nPatches from Mat Turner to support the mount_setattr() syscall and to add\nfloating-point registers to core dumps on alpha, mips, hppa, riscv and sh4.\n\n# -----BEGIN PGP SIGNATURE-----\n#\n# iHUEABYKAB0WIQS86RI+GtKfB8BJu973ErUQojoPXwUCanzZYQAKCRD3ErUQojoP\n# X+x4AP9UqX4OuUUZy+HA33eW+54JIT9xfF88VnU6VhZdQpPhlQEA3cYz393TjIpT\n# uXlgPvwCVa6C3/qUSq//00v3KQsF+Q0\u003d\n# \u003d4lE3\n# -----END PGP SIGNATURE-----\n# gpg: Signature made Wed 12 Aug 2026 01:36:49 PM PDT\n# gpg:                using EDDSA key BCE9123E1AD29F07C049BBDEF712B510A23A0F5F\n# gpg: Good signature from \"Helge Deller \u003cdeller@gmx.de\u003e\" [unknown]\n# gpg:                 aka \"Helge Deller \u003cdeller@kernel.org\u003e\" [unknown]\n# gpg: WARNING: This key is not certified with a trusted signature!\n# gpg:          There is no indication that the signature belongs to the owner.\n# Primary key fingerprint: 4544 8228 2CD9 10DB EF3D  25F8 3E5F 3D04 A7A2 4603\n#      Subkey fingerprint: BCE9 123E 1AD2 9F07 C049  BBDE F712 B510 A23A 0F5F\n\n* tag \u0027linux-user-pull-request\u0027 of https://github.com/hdeller/qemu-hppa:\n  linux-user/sh4: write the floating-point registers to a core dump\n  linux-user/riscv: write the floating-point registers to a core dump\n  linux-user/hppa: write the floating-point registers to a core dump\n  linux-user/mips: write the floating-point registers to a core dump\n  linux-user/alpha: write the floating-point registers to a core dump\n  linux-user: support writing floating-point registers to a core dump\n  linux-user: implement mount_setattr(2)\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\n"
    },
    {
      "commit": "055952c0aa91ea7a00d135b73f78fc0b13442d6c",
      "tree": "a8149337c37cdf02a91f8b4182150bf09053e569",
      "parents": [
        "c0b6d0ca16c3ac946ff65f9d5dce7429707c6b10",
        "2e555f5b44d1586517e44d47f73afa6062f48b93"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Wed Aug 12 09:20:11 2026 -0700"
      },
      "committer": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Wed Aug 12 09:20:11 2026 -0700"
      },
      "message": "Merge tag \u0027pull-hex-20260812v2-1\u0027 of https://github.com/qualcomm/qemu into staging\n\nHexagon queue\n\nFixes:\n* ssub32_saturate, ssub64_saturate fixes\n\nFeatures:\n\n* l2vic device\n* qtimer device\n* HVX-IEEE instructions (v68+)\n* HVX GVec overrides for v{avg*,absdiff,sadd,*}\n\n# -----BEGIN PGP SIGNATURE-----\n#\n# iQIzBAABCgAdFiEEPWaq5HRZSCTIjOD4GlSvuOVkbDIFAmp8k4UACgkQGlSvuOVk\n# bDJBHg//SKfafuoDX/BLl46aRKD3ESOohRPrMypSdmKxAsPrjKnawVzEtQW7LZha\n# U/Ch5wKCpuLZk+ZXXXzVDxaz4rgrbbXtc/jLiJ4EibquFpCRwcIZnQy7+uLXf+DI\n# A9tNoCBhWsw8RA/CFPei6tGZjZKLF4eXImf8n9028RwGyX7wGbVP26C1VoVfbegl\n# +HOjy2y1Oqmw0DmljFGESSFTyJDEM2Y9SdhyBSrS1fmof24ad0cRiTeoMwNfk1iX\n# JoW8+bYteTJ8vLui7RBvDIuk4rHYg5SLk8yqDA3SwzoFuL/jjI612SXM3TIT2ySe\n# dgUK4B8XtiqGSYNuQed8TXoTicq3qaKv/zlxDMhpFLl7SV6v+sfhNBxP++gjM8YY\n# yuTlNJDppPkorETzvPsVEbS8+Z3xr3EzsqDwYRSMT48XEk26iAyWRLy7EfKsGnUY\n# RGe122Hy8oDNXomFTQxWpQ0Nr3fkfh/X+B7ydYGFZbb0Z1shY+7f2Zu9Xefjy7bv\n# sdf+bH4bTCSy1/bfG81dPhvYh4JefPEvLOUF6l3ssYeY54asx0yrFy1oipc2Ancw\n# sRjD2/10QkDNEnSfwf6v7uUmpvAm4rtY/m8s0fzevst1PxvVOREo2AckK2CYaH6T\n# viYpyY881FlyA6zVJTt89ktozzsU9yJmm8zYbE74KPNUs7KV4cU\u003d\n# \u003d5k5b\n# -----END PGP SIGNATURE-----\n# gpg: Signature made Wed 12 Aug 2026 08:38:45 AM PDT\n# gpg:                using RSA key 3D66AAE474594824C88CE0F81A54AFB8E5646C32\n# gpg: Good signature from \"Brian Cain (QUIC) \u003cquic_bcain@quicinc.com\u003e\" [unknown]\n# gpg:                 aka \"Brian Cain \u003cbcain@kernel.org\u003e\" [unknown]\n# gpg:                 aka \"Brian Cain (QuIC) \u003cbcain@quicinc.com\u003e\" [unknown]\n# gpg:                 aka \"Brian Cain (CAF) \u003cbcain@codeaurora.org\u003e\" [unknown]\n# gpg:                 aka \"bcain\" [unknown]\n# gpg: WARNING: This key is not certified with a trusted signature!\n# gpg:          There is no indication that the signature belongs to the owner.\n# Primary key fingerprint: 6350 20F9 67A7 7164 79EF  49E0 175C 464E 541B 6D47\n#      Subkey fingerprint: 3D66 AAE4 7459 4824 C88C  E0F8 1A54 AFB8 E564 6C32\n\n* tag \u0027pull-hex-20260812v2-1\u0027 of https://github.com/qualcomm/qemu: (41 commits)\n  tests/hexagon: add tests for HVX bfloat\n  tests/hexagon: add tests for v68 HVX IEEE float comparisons\n  tests/hexagon: add tests for v68 HVX IEEE float conversions\n  tests/hexagon: add tests for v68 HVX IEEE float min/max\n  tests/hexagon: add tests for v68 HVX IEEE float arithmetics\n  target/hexagon: add v73 HVX IEEE bfloat16 insns\n  target/hexagon: add v68 HVX IEEE float compare insns\n  target/hexagon: add v68 HVX IEEE float conversion insns\n  target/hexagon: add v68 HVX IEEE float misc insns\n  target/hexagon: add v68 HVX IEEE float min/max insns\n  target/hexagon: add v68 HVX IEEE float arithmetic insns\n  hexagon: print info on \"-d in_asm\" for disabled IEEE FP instructions\n  hexagon: group cpu configurations in their own struct\n  target/hexagon/cpu: add HVX IEEE FP extension\n  target/hexagon: fix incorrect/too-permissive HVX encodings\n  Hexagon (target/hexagon) Clean up disassembly of control and system regs\n  tests/tcg/hexagon: add HVX tests for vabsdiff\n  tests/tcg/hexagon: add HVX test for V6_vsubwsat saturation\n  target/hexagon: add GVec overrides for HVX vector average\n  target/hexagon: add GVec overrides for HVX absolute difference\n  ...\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\n"
    },
    {
      "commit": "c0b6d0ca16c3ac946ff65f9d5dce7429707c6b10",
      "tree": "a812343780aadc51f9578e7694aa96a04fcd55d4",
      "parents": [
        "d5393e5a03103ba964ae5753a7ace3a65f6d77eb",
        "49aecf39008ebeb86127b5055cefa17d68370b20"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Wed Aug 12 09:19:55 2026 -0700"
      },
      "committer": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Wed Aug 12 09:19:55 2026 -0700"
      },
      "message": "Merge tag \u0027pull-target-arm-20260812\u0027 of https://gitlab.com/pm215/qemu into staging\n\ntarget-arm queue:\n * Implement emulation of FEAT_SME_TMOP\n * New board model: Axiado EVK SCM3003\n * Fix various minor bugs in mps3-an547 model\n * hw/i2c/bcm2835_i2c: Correct iomem size\n * hw/misc/bcm2835_powermgt: implement a real watchdog timer\n * hw/arm/raspi4b: fix guest never seeing more than ~1 GiB of RAM\n\n# -----BEGIN PGP SIGNATURE-----\n#\n# iQJNBAABCAA3FiEE4aXFk81BneKOgxXPPCUl7RQ2DN4FAmp8Y+kZHHBldGVyLm1h\n# eWRlbGxAbGluYXJvLm9yZwAKCRA8JSXtFDYM3iwKEACaH/Ztj8k5NiH9AVF7+2ii\n# SkM2oJoLLyFw2LXgXMnQgzdmMhwW7odsd8xp76prfDIrOZE5uFXAX+7F8I5Vnmcn\n# nyHVhqvJlxx+JEVSGLhjmHhJCaqxisbtaFVEdhvBn2r7b5YCcmB9pOaUnMpZI2Mt\n# ahXtqiExHZ04Y57JIoOuMOs+JSLn2QoMlUy3aP0BetyVfDyfxjU/8XnVQnDWec1J\n# Df+QWgFdHhOlb8vy6lurrdDC8Q5F0nEKTHfq5aCl4DjpOg4uMzqHQ4GFdxHDlhGi\n# 2z+Toyq/I2dBKebv0tWdLjcDMkLrmfNZcIs5VPsm+vvQyt2wN5rFnJKAMYcmN4BS\n# 7Z8C1RBPnsSZaYCeh97oCipce1WeGPpPjKlfBqMwdF95jBnn/zMGULmxB/W2Ays/\n# gKD9RpKmvfUZNQ9JRFr/u+vNvvY2xki1u3yB0F0j+f8ggp8PxpHli7gxlA3x9PyZ\n# AhmDj6JK0+zciPlC6FnSVTipNE8ZGU8XN8DCp4LNU5zye3aDtoCCmJwVVryYeRBT\n# bq7kj2En13pP66OZUAb1MRu2gnwIuq0GZwQ3aYtWqe8DxcVa7r2fGxaRR0GDjY+r\n# l1SzSd5CCExpaLi4c3FO6sz12jHfzRLjKtULEyv/37kVNbI+SpOj6UwCQAgAYTz8\n# Gq/mTm1heDXTDjcwEp6lQQ\u003d\u003d\n# \u003dILzl\n# -----END PGP SIGNATURE-----\n# gpg: Signature made Wed 12 Aug 2026 05:15:37 AM PDT\n# gpg:                using RSA key E1A5C593CD419DE28E8315CF3C2525ED14360CDE\n# gpg:                issuer \"peter.maydell@linaro.org\"\n# gpg: Good signature from \"Peter Maydell \u003cpeter.maydell@linaro.org\u003e\" [unknown]\n# gpg:                 aka \"Peter Maydell \u003cpmaydell@gmail.com\u003e\" [unknown]\n# gpg:                 aka \"Peter Maydell \u003cpmaydell@chiark.greenend.org.uk\u003e\" [unknown]\n# gpg:                 aka \"Peter Maydell \u003cpeter@archaic.org.uk\u003e\" [unknown]\n# gpg: WARNING: The key\u0027s User ID is not certified with a trusted signature!\n# gpg:          There is no indication that the signature belongs to the owner.\n# Primary key fingerprint: E1A5 C593 CD41 9DE2 8E83  15CF 3C25 25ED 1436 0CDE\n\n* tag \u0027pull-target-arm-20260812\u0027 of https://gitlab.com/pm215/qemu: (26 commits)\n  tests/functional/aarch64: add raspi4b full-RAM regression test\n  hw/arm/raspi4b: fix guest never seeing more than ~1 GiB of RAM\n  hw/misc/bcm2835_powermgt: implement a real watchdog timer\n  hw/i2c/bcm2835_i2c: Correct iomem size\n  hw/arm/mps2-tz.c: add AN547 AHB PPC EXP1 DMA ports\n  hw/arm/mps2-tz.c: fix AN547 APB PPC EXP0 MPC ports\n  hw/arm/armsse.c: fix SSE-300 PPU addresses\n  hw/arm/armsse.c: fix SSE-300 s32kwatchdog address\n  hw/arm: ax3000-soc: Enable Cadence GPIO controllers\n  hw/gpio: Add Cadence GPIO controller\n  hw/arm: Add Axiado EVK SCM3003\n  hw/arm: ax3000-soc: Enable Axiado SD host controller\n  hw/sd: Add Axiado SD host controller with eMMC PHY\n  hw/arm: ax3000-soc: Enable Ax3000 clock control\n  hw/misc: Add AX3000 clock control\n  hw/arm: Add Axiado SoC AX3000\n  target/arm: Enable FEAT_SME_TMOP for -cpu max\n  target/arm: Implement {S,SU,US,U}TMOPA (4-way)\n  target/arm: Implement [SU]TMOPA (2-way)\n  target/arm: Implement FTMOPA (widening, 4-way, FP8 to FP32)\n  ...\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\n"
    },
    {
      "commit": "9b3d68edb24d4e04f49822c6e11641e4eb23dfd5",
      "tree": "e234ecf4212639edd7af74efa3897e3a400556d3",
      "parents": [
        "93676b24721135ae965169dd5797d37a5e022939"
      ],
      "author": {
        "name": "Eric Farman",
        "email": "farman@linux.ibm.com",
        "time": "Wed Aug 12 11:13:28 2026 -0400"
      },
      "committer": {
        "name": "Eric Farman",
        "email": "farman@linux.ibm.com",
        "time": "Wed Aug 12 11:13:28 2026 -0400"
      },
      "message": "pc-bios/s390-ccw.img: update s390x bios\n\nUpdate the s390 bios with recent fixes for out-of-bounds accesses.\n\nSigned-off-by: Eric Farman \u003cfarman@linux.ibm.com\u003e\n"
    },
    {
      "commit": "93676b24721135ae965169dd5797d37a5e022939",
      "tree": "09a3ebeedaaab3539844916896963ea191a7105c",
      "parents": [
        "6126cbe2e59d7a9df1128f6072e3480267451187"
      ],
      "author": {
        "name": "Cornelia Huck",
        "email": "cohuck@redhat.com",
        "time": "Thu Jul 23 18:38:06 2026 +0200"
      },
      "committer": {
        "name": "Eric Farman",
        "email": "farman@linux.ibm.com",
        "time": "Wed Aug 12 10:21:15 2026 -0400"
      },
      "message": "hw: add compat machines for 11.2\n\nAdd 11.2 machine types for arm/i440fx/loongarch/m68k/q35/s390x/spapr.\n\nSigned-off-by: Cornelia Huck \u003ccohuck@redhat.com\u003e\nReviewed-by: Eric Farman \u003cfarman@linux.ibm.com\u003e\nReviewed-by: Bibo Mao \u003cmaobibo@loongson.cn\u003e\nLink: https://lore.kernel.org/qemu-devel/20260723163806.368127-1-cohuck@redhat.com\n[farman@linux.ibm.com: fixup hw/core/machine.c hunk]\nSigned-off-by: Eric Farman \u003cfarman@linux.ibm.com\u003e\n"
    },
    {
      "commit": "d5393e5a03103ba964ae5753a7ace3a65f6d77eb",
      "tree": "2a32a025069b070bb277566c53b37beffa6bdf5f",
      "parents": [
        "e8d693e12af9cbb89d724baadfcc08559669e279",
        "0375f6498eee6188089924bb766c653492ff8857"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Wed Aug 12 07:16:57 2026 -0700"
      },
      "committer": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Wed Aug 12 07:16:57 2026 -0700"
      },
      "message": "Merge tag \u0027pull-aspeed-20260811\u0027 of https://github.com/legoater/qemu into staging\n\naspeed queue:\n\n* Fixes missing Kconfig dependencies for Aspeed boards\n* Adds 64-bit addressing support to the EHCI USB controller model.\n  Enable it on the AST2700\n* Extends Aspeed SMC qtest coverage with fast-read, DOR and QOR\n  read modes\n* Introduces a separate Aspeed2700SCUState type and shares the SCUIO,\n  FMC and SCU instances across the AST2700 PSP, SSP and TSP\n  coprocessors\n* Adds Data FIFO-based flash access for the AST2700 FMC controller\n* Adds the ADC128D818 12-bit 8-channel ADC sensor device with tests,\n  wired up on the Anacapa board\n* Reworks the PCA9552/PCA9555 GPIO/LED driver: polarity inversion,\n  datasheet-conformant command handling, GPIO QOM properties, reset\n  via the Resettable interface, and extensive qtest coverage\n* Reworks the PCA9554 GPIO driver: output-to-input reflection,\n  PCA9536 support, pin direction property, and qtest coverage\n* Adds PCA9555 IO expanders and temperature sensors to the Catalina\n  board\n* Adds AST2700 I2C master buffer mode support\n* Updates ASPEED functional tests to SDK v11.03 and Zephyr SDK v03.08\n* Adds AES-GCM support to the QEMU crypto cipher layer (gcrypt,\n  nettle, gnutls backends) with unit tests\n* Adds crypto (AES) command emulation to the Aspeed HACE model:\n  direct access, scatter-gather, CTR, GCM modes, 64-bit DMA, with\n  qtest coverage on AST2500, AST2600, AST1030 and AST2700\n\n# -----BEGIN PGP SIGNATURE-----\n#\n# iQIzBAABCAAdFiEEoPZlSPBIlev+awtgUaNDx8/77KEFAmp7TbQACgkQUaNDx8/7\n# 7KGqiBAAuiozhStgwzhV1ywfStIVL1wUQsg4UiODmihJEd1eRS7KH6q37enXuydI\n# zKycSTjg1gJUglRbq0OUk+WNeMCwusLVZm2u6GCIF4B9m8n7Qn09vpGY9egAfTdv\n# XTm1/GStxLLlYp6WaXyXXbm6D5F2KjkaNyqjy2UEQwzsiOfkDcABqnH5CFNT6d3U\n# q2rcRZ/8exv1bWDD9PI5ip3Si/Uf1p8X8Kcrij5aQRMaJJMZnQZcccryZFz6waxe\n# xTeQEEE6whS0MwTfKqH6uIm1D2NlekYe3FXDjP4agePhTG/RN3leMxCL3QIwJfk4\n# sMKf+Mapac1rVE/EY5KHYwKbCGR2t8uRbVTXMhywiZeV8WyBGiq+tabklw8hsFvA\n# 56Q3ez7oTT6vTaIRMSC7PrXXLEZKywhA4jICd2HWq2Dt+XEiAcT6nvM4pDp2ktXq\n# PtpxLKhlelZ2P7GJUAvOa8rtaeif9RiPELN8cliVqT5MrC0iodMmh+eCponYKwZl\n# tThzUBatZVn/BP3EFGT7GHicfr3owCblxfuHPVMZiWlX3n4ymixa/3sGk73zb+jo\n# foSCpi8YEAYxzhcwBfOrNE1UqQuwhOvQWugmEgFfSbjvqL7sFOeivWraYv46fcwE\n# EQ9+Ah35VE2rq6fNvfUHiTZqWFGDYSvMVHKGCGR0CCu8PJOwdFM\u003d\n# \u003dSS88\n# -----END PGP SIGNATURE-----\n# gpg: Signature made Tue 11 Aug 2026 09:28:36 AM PDT\n# gpg:                using RSA key A0F66548F04895EBFE6B0B6051A343C7CFFBECA1\n# gpg: Good signature from \"Cédric Le Goater \u003cclg@redhat.com\u003e\" [full]\n# gpg:                 aka \"Cédric Le Goater \u003cclg@kaod.org\u003e\" [full]\n\n* tag \u0027pull-aspeed-20260811\u0027 of https://github.com/legoater/qemu: (83 commits)\n  tests/qtest/aspeed-hace: Test the crypto command on the AST2700\n  hw/misc/aspeed_hace: Enable the crypto command on the AST2700\n  hw/misc/aspeed_hace: Support the AES-GCM mode for the crypto command\n  hw/misc/aspeed_hace: Support 64-bit DMA for the crypto command\n  tests/unit/test-crypto-cipher: Test AES-GCM mode\n  crypto/cipher-gnutls: Implement AES-GCM\n  crypto/cipher-nettle: Implement AES-GCM\n  crypto/cipher-gcrypt: Implement AES-GCM\n  crypto/cipher: Add setaad/gettag for AEAD modes\n  crypto/cipher: Add GCM to QCryptoCipherMode\n  tests/qtest/aspeed-hace: Test the crypto command on the AST1030\n  tests/qtest/aspeed-hace: Test the crypto command on the AST2600\n  hw/misc/aspeed_hace: Support the CTR mode for the crypto command\n  hw/misc/aspeed_hace: Support scatter-gather mode for the crypto command\n  tests/qtest/aspeed-hace: Test the crypto command on the AST2500\n  hw/misc/aspeed_hace: Support the crypto command in direct access mode\n  hw/arm/aspeed: avoid sign mismatch on sscanf for uart property\n  tests/functional/arm/test_aspeed_ast1060: Update ASPEED ZEPHYR PROJECT v03.07\n  tests/functional/arm/test_aspeed_ast1030: Update ASPEED Zephyr SDK v03.08\n  tests/functional/arm/test_aspeed_ast2500_sdk: Update ASPEED SDK v11.03\n  ...\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\n"
    },
    {
      "commit": "cf45083edc2b760a952836187aba7ec4139418c0",
      "tree": "5551fcdd1f961df0c442c9dff6e18d4b1b737433",
      "parents": [
        "ac7fa2e9d457ff9c777be32617f3c46548c4cadf"
      ],
      "author": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Tue Jul 28 17:04:15 2026 -0400"
      },
      "committer": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Wed Aug 12 08:39:39 2026 -0400"
      },
      "message": "migration/multifd: Replace assert() with error_setg() in recv paths\n\nQPL and UADK multifd backends use assert() to validate wire-controlled\nfields like per-page compressed lengths and packet size consistency.  These\nasserts will stop working with -DNDEBUG builds, so may stop working.\n\nReplace all assert() calls in the receive path with proper error_setg() so\nvalidation failures are reported gracefully rather than crashing or\nsilently ignored.\n\nWhile at it, touch up an assert() in qatzip recv path too.\n\nCc: qemu-stable \u003cqemu-stable@nongnu.org\u003e\nCc: Yuan Liu \u003cyuan1.liu@intel.com\u003e\nCc: Yichen Wang \u003cyichen.wang@bytedance.com\u003e\nReviewed-by: Fabiano Rosas \u003cfarosas@suse.de\u003e\nLink: https://lore.kernel.org/r/20260728210417.1925078-4-peterx@redhat.com\nSigned-off-by: Peter Xu \u003cpeterx@redhat.com\u003e\n"
    },
    {
      "commit": "ac7fa2e9d457ff9c777be32617f3c46548c4cadf",
      "tree": "a0d0dae6bdd775a468bb2ceedcbb9a5df333ae83",
      "parents": [
        "bdfe26faca7b7c8daa7895783d55ec6d05164880"
      ],
      "author": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Tue Jul 28 17:04:14 2026 -0400"
      },
      "committer": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Wed Aug 12 08:39:39 2026 -0400"
      },
      "message": "migration/multifd: Validate next_packet_size in zlib/zstd recv\n\nThe zlib and zstd multifd compression backends read next_packet_size from\nthe incoming migration stream and use it directly as the read length into a\nfixed-size buffer (MULTIFD_PACKET_SIZE * 2 \u003d 1MB).  A malicious migration\nsource can set next_packet_size bigger than allocated, causing a heap\nbuffer overflow write on the destination.\n\nAdd a check against zbuff_len before reading, matching what the qatzip\nbackend already does.  Also replace the assert(in_size \u003d\u003d 0) for empty\npackets with proper error reporting, since the value is wire-controlled,\nmeanwhile assert() stops working with -DNDEBUG builds.\n\nResolves: https://gitlab.com/qemu-project/qemu/-/work_items/3737\nReported-by: xlabai \u003cxlabai@tencent.com\u003e\nReported-by: Jules Denardou \u003cjules.denardou@datadoghq.com\u003e\nReported-by: Tristan Madani \u003ctristan@talencesecurity.com\u003e\nReported-by: david korczynski (@david1766)\nReported-by: huntr bubble (@bubblehuntr)\nCc: qemu-stable \u003cqemu-stable@nongnu.org\u003e\nReviewed-by: Fabiano Rosas \u003cfarosas@suse.de\u003e\nLink: https://lore.kernel.org/r/20260728210417.1925078-3-peterx@redhat.com\nSigned-off-by: Peter Xu \u003cpeterx@redhat.com\u003e\n"
    },
    {
      "commit": "49aecf39008ebeb86127b5055cefa17d68370b20",
      "tree": "7d6bd6fad6513a5cf50203445e3943933bbe8694",
      "parents": [
        "c59b6916269d8d813399bfc02c75207b0bef91c6"
      ],
      "author": {
        "name": "Marcelo Manzo",
        "email": "marcelomanzo@gmail.com",
        "time": "Tue Aug 11 10:35:39 2026 -0400"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:56 2026 +0100"
      },
      "message": "tests/functional/aarch64: add raspi4b full-RAM regression test\n\nGuards against the bug fixed in the previous commit: boots raspi4b\u0027s\ndefault 2 GiB configuration and checks that the guest actually sees\nclose to that (\u003e1.9M kB), not the ~921 MiB the bug left it capped at.\nDeliberately checks a threshold rather than the exact byte count of\neither figure, since the precise number depends on how this specific\npinned kernel accounts for its own early reservations; the threshold\nis comfortably between the two (943524 kB broken, 1905824 kB fixed,\nconfirmed by hand against this exact kernel/initrd).\n\nFolded into the existing test_arm_raspi4_initrd test rather than a\nnew standalone boot, since it needs no machine state that test isn\u0027t\nalready setting up, and the functional-test suite is already slow\nenough from how many separate guest boots it runs.\n\nSigned-off-by: Marcelo Manzo \u003cmarcelomanzo@gmail.com\u003e\nMessage-id: 20260811143539.7835-3-marcelomanzo@gmail.com\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "c59b6916269d8d813399bfc02c75207b0bef91c6",
      "tree": "ada04840236363ae412ce23393714b3fb23ab66e",
      "parents": [
        "21fcfb6046082a06b82c17688634a1b769ee63a0"
      ],
      "author": {
        "name": "Marcelo Manzo",
        "email": "marcelomanzo@gmail.com",
        "time": "Tue Aug 11 10:35:38 2026 -0400"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:56 2026 +0100"
      },
      "message": "hw/arm/raspi4b: fix guest never seeing more than ~1 GiB of RAM\n\nraspi4_modify_dtb() decides whether to add a second memory node above\nthe 1 GiB peripheral hole by checking info-\u003eram_size -- but that field\nis the boot loader\u0027s RAM budget for loading the kernel/initrd/dtb\nimage, itself always capped to at most UPPER_RAM_BASE - vcram_size by\nraspi_base_machine_init(). Since that capped value can never exceed\nUPPER_RAM_BASE by construction, the condition was never true for any\nraspi4b configuration, and the second node was never added: the guest\nnever saw more than ~1 GiB of its nominal RAM, regardless of the\nmachine\u0027s actual size.\n\nboard_ram_size(info-\u003eboard_id), computed one line above in the same\nfunction, is the value that was actually needed -- the board\u0027s real\ntotal RAM, not the boot loader\u0027s own budget for where it\u0027s allowed to\nplace the kernel image.\n\nConfirmed via direct measurement inside the guest (\"free -h\" /\n/proc/meminfo) on raspi4b\u0027s default 2 GiB configuration, before and\nafter:\n\n    before: MemTotal:  943524 kB (~921 MiB)\n    after:  MemTotal: 1905824 kB (~1861 MiB)\n\nAlso verified against two real, unmodified Raspberry Pi OS releases\n(Debian 11/Bullseye and Debian 13/Trixie): both now report ~1.8 GiB of\nusable RAM instead of ~900 MiB, with clean boots, working SSH, and no\nkernel errors on either.\n\nSigned-off-by: Marcelo Manzo \u003cmarcelomanzo@gmail.com\u003e\nReviewed-by: Philippe Mathieu-Daudé \u003cphilmd@oss.qualcomm.com\u003e\nMessage-id: 20260811143539.7835-2-marcelomanzo@gmail.com\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "21fcfb6046082a06b82c17688634a1b769ee63a0",
      "tree": "71266f506d3c8b7a9c62650100de9fbc1bae80ec",
      "parents": [
        "20bf099da7c0dff3494cc36ae43add1ff376be52"
      ],
      "author": {
        "name": "Marcelo Manzo",
        "email": "marcelomanzo@gmail.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:56 2026 +0100"
      },
      "message": "hw/misc/bcm2835_powermgt: implement a real watchdog timer\n\nThe RSTC register\u0027s write-config bits (0x30) being set to the\n\"full reset\" value (0x20) does not mean \"reset now\" -- it arms the\nhardware watchdog so that a reset happens if the WDOG countdown\nregister is not refreshed before it expires. The previous\nimplementation treated any such RSTC write as an immediate reset,\nregardless of the WDOG value.\n\nThis is dormant on older/lighter userspace (nothing in Bullseye\u0027s\ndefault boot touches these registers this way), but modern systemd\n(observed with Debian 13/Trixie\u0027s systemd 257) writes to RSTC as part\nof routine early-boot watchdog probing. With the old code, this fires\nan immediate reset a few seconds into boot; combined with -no-reboot\nthis looks exactly like a QEMU crash (clean exit, no panic, no guest\nreboot message) with the last log line being the RSTC/WDOG write.\n\nFix this by actually implementing the watchdog as a QEMUTimer: writes\nto RSTC/WDOG (re)compute the timeout from the WDOG register (in units\nof 1/65536 s, per the real hardware) and arm a timer for that many\nnanoseconds out; only when the timer actually fires do we request a\nsystem reset or shutdown, matching real hardware behavior. Clearing\nthe write-config bits or the WDOG value disarms the timer, and reset\ndisarms it too.\n\nVerified against real Raspberry Pi OS images under the patched\nraspi4b machine: Bullseye (5.15) and Bookworm (6.12) never exercised\nthis path either way; Trixie (6.18, systemd 257) no longer crashes at\nboot and reaches a working login/SSH state.\n\nThis is a migration compatibility break for the raspi boards.\n\nSigned-off-by: Marcelo Manzo \u003cmarcelomanzo@gmail.com\u003e\n[PMM: bump vmstate version IDs, note migration break in commit msg]\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "20bf099da7c0dff3494cc36ae43add1ff376be52",
      "tree": "13fdc6da5d67da20ae091fac942177053b86d9a0",
      "parents": [
        "f43d9507194c81e76ef2828ef90a3b2102890c20"
      ],
      "author": {
        "name": "botszhuang",
        "email": "huang.botsz@gmail.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:56 2026 +0100"
      },
      "message": "hw/i2c/bcm2835_i2c: Correct iomem size\n\nThe last valid register is the Clock Stretch Timeout (CLKT) at\noffset 0x1c. Since it is a 32-bit register, the total memory\nregion size should be 0x1c + 4 \u003d 0x20.\n\nUpdate the size parameter in memory_region_init_io() from 0x24\nto 0x20 to accurately reflect the hardware specification.\n\n\nSuggested-by: Philippe Mathieu-Daudé \u003cphilmd@oss.qualcomm.com\u003e\nSigned-off-by: botszhuang \u003chuang.botsz@gmail.com\u003e\nReviewed-by: Philippe Mathieu-Daudé \u003cphilmd@oss.qualcomm.com\u003e\nMessage-id: 20260804144611.31735-1-huang.botsz@gmail.com\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "f43d9507194c81e76ef2828ef90a3b2102890c20",
      "tree": "5110a4a5e827ce1e3093e2595d9926416277b4ae",
      "parents": [
        "230edd14d5554bd35fe5ffee37a34437973ed9c2"
      ],
      "author": {
        "name": "Simon Xu",
        "email": "simonxhy0404@gmail.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:56 2026 +0100"
      },
      "message": "hw/arm/mps2-tz.c: add AN547 AHB PPC EXP1 DMA ports\n\nPage 42 of the AN547 TRM defines the AHB PPC EXP1 ports with DMA 1-3\n\nAN547 TRM: https://developer.arm.com/documentation/dai0547/latest/\n\nSuggested-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Simon Xu \u003csimonxhy0404@gmail.com\u003e\nMessage-id: 20260805191257.11303-5-simonxhy0404@gmail.com\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "230edd14d5554bd35fe5ffee37a34437973ed9c2",
      "tree": "14f2a42bb055229a69e2963efe2965b2c91a2d19",
      "parents": [
        "024c539a625c4cb15bc5e2f50b4a91672eef3f77"
      ],
      "author": {
        "name": "Simon Xu",
        "email": "simonxhy0404@gmail.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:56 2026 +0100"
      },
      "message": "hw/arm/mps2-tz.c: fix AN547 APB PPC EXP0 MPC ports\n\nThe AN547 TRM defines them to be on ports [15:13], not [2:0].\n\nAN547 TRM: https://developer.arm.com/documentation/dai0547/latest/\n\nFixes: eb09d533d87f (\"hw/arm/mps2-tz: Add new mps3-an547 board\")\nSuggested-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Simon Xu \u003csimonxhy0404@gmail.com\u003e\nMessage-id: 20260805191257.11303-4-simonxhy0404@gmail.com\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "024c539a625c4cb15bc5e2f50b4a91672eef3f77",
      "tree": "a070b93315efbca600991f2b436bc6dae15a04ef",
      "parents": [
        "000ef0d13b4fb82a0e4279d6409df805fc28815b"
      ],
      "author": {
        "name": "Simon Xu",
        "email": "simonxhy0404@gmail.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:56 2026 +0100"
      },
      "message": "hw/arm/armsse.c: fix SSE-300 PPU addresses\n\nThe SSE-300 CPU0_PPU, MGMT_PPU, DEBUG_PPU had the wrong addresses\nthat were the same as the SSE-200 addresses.\nPage 146 of the SSE-300 TRM defines the addresses of the PPUs.\n\nSSE-300 TRM: https://support.arm.com/documentation/101773/latest/\n\nFixes: 8901bb414a24 (\"hw/arm/armsse: Add SSE-300 support\")\nSigned-off-by: Simon Xu \u003csimonxhy0404@gmail.com\u003e\nMessage-id: 20260805191257.11303-3-simonxhy0404@gmail.com\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "000ef0d13b4fb82a0e4279d6409df805fc28815b",
      "tree": "ac31c1df5499c8ca76385b293093efd14acd5668",
      "parents": [
        "a4256760c0e0a123569be2e99d8749f00b812c1d"
      ],
      "author": {
        "name": "Simon Xu",
        "email": "simonxhy0404@gmail.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:56 2026 +0100"
      },
      "message": "hw/arm/armsse.c: fix SSE-300 s32kwatchdog address\n\nThe SSE-300 SLOWCLK Secure Watchdog Timer is only defined at address\n0x5802e000 in the secure region.\nPage 45 of the SSE-300 TRM specifies that \"the watchdog is Secure\naccess only\".\n\nSSE-300 TRM: https://support.arm.com/documentation/101773/latest/\n\nFixes: 8901bb414a24 (\"hw/arm/armsse: Add SSE-300 support\")\nSuggested-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Simon Xu \u003csimonxhy0404@gmail.com\u003e\nMessage-id: 20260805191257.11303-2-simonxhy0404@gmail.com\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "a4256760c0e0a123569be2e99d8749f00b812c1d",
      "tree": "88fdad41c070f51d0e0da0d4cf6e3bb660393380",
      "parents": [
        "cc57a945feb0906af6b56591c790f60bfd65945c"
      ],
      "author": {
        "name": "Kuan-Jui Chiu",
        "email": "kchiu@axiado.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:56 2026 +0100"
      },
      "message": "hw/arm: ax3000-soc: Enable Cadence GPIO controllers\n\nEnable 8 Cadence GPIO controllers into Axiado AX3000 SoC\n\nSigned-off-by: Kuan-Jui Chiu \u003ckchiu@axiado.com\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nReviewed-by: Philippe Mathieu-Daudé \u003cphilmd@oss.qualcomm.com\u003e\nMessage-id: 20260713073033.3883619-9-kchiu@axiado.com\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "cc57a945feb0906af6b56591c790f60bfd65945c",
      "tree": "55abeeeb73e41e8e09acc24ceed09ccd4b8e1b06",
      "parents": [
        "4e5205339fc4b5e56ed4d97d4a504bdee779fb8f"
      ],
      "author": {
        "name": "Kuan-Jui Chiu",
        "email": "kchiu@axiado.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:56 2026 +0100"
      },
      "message": "hw/gpio: Add Cadence GPIO controller\n\nThis patch add a new model for Cadence GPIO controller which\nsupports 32 pins and interrupts for level-triggered/edge-triggered type on\ninput pins.\n\nAlso define new trace functions for analysis purpose and new configuration to\nenable this model.\n\nSigned-off-by: Kuan-Jui Chiu \u003ckchiu@axiado.com\u003e\nMessage-id: 20260713073033.3883619-8-kchiu@axiado.com\n[PMM: drop unnecessary \u003cprivate\u003e and \u003cpublic\u003e marker comments]\n\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "4e5205339fc4b5e56ed4d97d4a504bdee779fb8f",
      "tree": "0da689ea130af2a867fcd1ec2c309da00bcdb355",
      "parents": [
        "2019f4e0ddb3f7c0d3246042ee7535b7348792ce"
      ],
      "author": {
        "name": "Kuan-Jui Chiu",
        "email": "kchiu@axiado.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:40 2026 +0100"
      },
      "message": "hw/arm: Add Axiado EVK SCM3003\n\nAdd EVK axiado-scm3003 built with AX3000 SoC\n\nSigned-off-by: Kuan-Jui Chiu \u003ckchiu@axiado.com\u003e\nMessage-id: 20260713073033.3883619-7-kchiu@axiado.com\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n[PMM: KConfig for the board has to depend on TCG \u0026\u0026 ARM]\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "2019f4e0ddb3f7c0d3246042ee7535b7348792ce",
      "tree": "2bbb1a5a7c023534745831625c172260a83eb924",
      "parents": [
        "8c55a630c5b91fd7292fb11ee0e69a5914b66487"
      ],
      "author": {
        "name": "Kuan-Jui Chiu",
        "email": "kchiu@axiado.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:40 2026 +0100"
      },
      "message": "hw/arm: ax3000-soc: Enable Axiado SD host controller\n\nEnable SD host controller into Axiado AX3000 SoC to load kernel and rootfs\nfrom eMMC.\n\nSigned-off-by: Kuan-Jui Chiu \u003ckchiu@axiado.com\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713073033.3883619-6-kchiu@axiado.com\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "8c55a630c5b91fd7292fb11ee0e69a5914b66487",
      "tree": "797b4d96279db19f8cbef8609d6cca2e302f9dff",
      "parents": [
        "406738e50861b2deb19414a73b8a9079565523d8"
      ],
      "author": {
        "name": "Kuan-Jui Chiu",
        "email": "kchiu@axiado.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:40 2026 +0100"
      },
      "message": "hw/sd: Add Axiado SD host controller with eMMC PHY\n\nThis patch add a new model for Axiado SD host controller which is compatible\nwith SDHCI 3.0 spec\n\nThis device model also includes a eMMC PHY which helps to control SD/eMMC\n\nSigned-off-by: Kuan-Jui Chiu \u003ckchiu@axiado.com\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713073033.3883619-5-kchiu@axiado.com\n[PMM: Use HWADDR_PRIx]\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "406738e50861b2deb19414a73b8a9079565523d8",
      "tree": "892a4e372969eef70bc7b4a4abaf1d599583f3db",
      "parents": [
        "38b52563758ec3fe5df2ba8efa86b155ad79649d"
      ],
      "author": {
        "name": "Kuan-Jui Chiu",
        "email": "kchiu@axiado.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:40 2026 +0100"
      },
      "message": "hw/arm: ax3000-soc: Enable Ax3000 clock control\n\nSigned-off-by: Kuan-Jui Chiu \u003ckchiu@axiado.com\u003e\nMessage-id: 20260713073033.3883619-4-kchiu@axiado.com\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "38b52563758ec3fe5df2ba8efa86b155ad79649d",
      "tree": "0916959919ff7563a790a9d9b061e755915d186a",
      "parents": [
        "33a71a68c6e137c80c9f6a7370d546404ed38513"
      ],
      "author": {
        "name": "Kuan-Jui Chiu",
        "email": "kchiu@axiado.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:41:40 2026 +0100"
      },
      "message": "hw/misc: Add AX3000 clock control\n\nThis patch adds a new model for Axiado AX3000 clock control which supports\nto read ID and status\n\nSigned-off-by: Kuan-Jui Chiu \u003ckchiu@axiado.com\u003e\nMessage-id: 20260713073033.3883619-3-kchiu@axiado.com\n[PMM: use HWADDR_PRIx]\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "33a71a68c6e137c80c9f6a7370d546404ed38513",
      "tree": "6539a278575beb5839ff01c62484019b7a467f2e",
      "parents": [
        "8ae365bdc8395e54fe0e137143858b505409d82a"
      ],
      "author": {
        "name": "Kuan-Jui Chiu",
        "email": "kchiu@axiado.com",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:20:34 2026 +0100"
      },
      "message": "hw/arm: Add Axiado SoC AX3000\n\nThis patch adds new model for Axiado SoC AX3000 which supports\n    4 Cortex-A53 ARM64 CPUs\n    Arm Generic Interrupt Controller v3\n    4 Cadence UARTs\n\nSigned-off-by: Kuan-Jui Chiu \u003ckchiu@axiado.com\u003e\nMessage-id: 20260713073033.3883619-2-kchiu@axiado.com\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n[PMM: Kconfig for the SoC shouldn\u0027t depend on ARM]\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "8ae365bdc8395e54fe0e137143858b505409d82a",
      "tree": "fe0f7cf94cc70fc1b47544a445c89116a41805d4",
      "parents": [
        "e56b670ea130b05c6abd3218357996a14c88338d"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:20:34 2026 +0100"
      },
      "message": "target/arm: Enable FEAT_SME_TMOP for -cpu max\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713230244.70174-11-richard.henderson@linaro.org\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "e56b670ea130b05c6abd3218357996a14c88338d",
      "tree": "f48d645bcc461d36eba3fdd49d70384a6d35f976",
      "parents": [
        "695e4e87a437e1d2d50755b0ed906cc54898813c"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:20:34 2026 +0100"
      },
      "message": "target/arm: Implement {S,SU,US,U}TMOPA (4-way)\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713230244.70174-10-richard.henderson@linaro.org\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "695e4e87a437e1d2d50755b0ed906cc54898813c",
      "tree": "32a0529aa34aa91d05c73ab024b2f532abe2c41d",
      "parents": [
        "1c7b4f9db3ed05a09431e3e1363b4af47c28df2b"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:20:34 2026 +0100"
      },
      "message": "target/arm: Implement [SU]TMOPA (2-way)\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713230244.70174-9-richard.henderson@linaro.org\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "1c7b4f9db3ed05a09431e3e1363b4af47c28df2b",
      "tree": "f74383ca34b8019d95f3d9bed97072aa1dada487",
      "parents": [
        "e921da8b98f0be99edf973e3d623d79ac2cd3705"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:20:34 2026 +0100"
      },
      "message": "target/arm: Implement FTMOPA (widening, 4-way, FP8 to FP32)\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713230244.70174-8-richard.henderson@linaro.org\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "e921da8b98f0be99edf973e3d623d79ac2cd3705",
      "tree": "951518373b35a635d0021af7cddecbdceb487445",
      "parents": [
        "f6a2d780f1489de6f3453e0c0ef70ae9813a412c"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:20:34 2026 +0100"
      },
      "message": "target/arm: Implement FTMOPA (widening, 2-way, FP8 to FP16)\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713230244.70174-7-richard.henderson@linaro.org\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "f6a2d780f1489de6f3453e0c0ef70ae9813a412c",
      "tree": "f88ee615ea980ab821803bfe946ffc5202bb81a5",
      "parents": [
        "cfe1e6503a0b828b7237d5c16c3b7f59f5bd7449"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:20:34 2026 +0100"
      },
      "message": "target/arm: Implement FTMOPA (widening, 2-way, FP16 to FP32)\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713230244.70174-6-richard.henderson@linaro.org\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "cfe1e6503a0b828b7237d5c16c3b7f59f5bd7449",
      "tree": "1564b20bc33c05c9e6e581a8a9d52d8e62afba44",
      "parents": [
        "aa8965de49e66cc4c04dbd99274d108418687a8e"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:20:34 2026 +0100"
      },
      "message": "target/arm: Implement BFTMOPA (widening)\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713230244.70174-5-richard.henderson@linaro.org\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "aa8965de49e66cc4c04dbd99274d108418687a8e",
      "tree": "42ae628888ee3c5ce4d18bf72b088198bda69755",
      "parents": [
        "76bc7dc82d2c37295aca07757e7623d3bfc650a8"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:20:34 2026 +0100"
      },
      "message": "target/arm: Implement BFTMOPA (non-widening)\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713230244.70174-4-richard.henderson@linaro.org\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "76bc7dc82d2c37295aca07757e7623d3bfc650a8",
      "tree": "b0305939d7daf6a8e1fe4b9f5ff6565b703cfba3",
      "parents": [
        "21e726d226e53896a0e6dcbb732b93bcea89115e"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:20:34 2026 +0100"
      },
      "message": "target/arm: Implement FTMOPA (non-widening, FP16)\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713230244.70174-3-richard.henderson@linaro.org\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "21e726d226e53896a0e6dcbb732b93bcea89115e",
      "tree": "fd4fb2b950074689acc12e61890a6ee919de348d",
      "parents": [
        "e8d693e12af9cbb89d724baadfcc08559669e279"
      ],
      "author": {
        "name": "Richard Henderson",
        "email": "richard.henderson@linaro.org",
        "time": "Tue Aug 11 20:14:11 2026 +0100"
      },
      "committer": {
        "name": "Peter Maydell",
        "email": "peter.maydell@linaro.org",
        "time": "Wed Aug 12 11:20:34 2026 +0100"
      },
      "message": "target/arm: Implement FTMOPA (non-widening, FP32)\n\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-id: 20260713230244.70174-2-richard.henderson@linaro.org\nSigned-off-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\n"
    },
    {
      "commit": "2e555f5b44d1586517e44d47f73afa6062f48b93",
      "tree": "d8a5ed0a4ef16e0ab26b460746446abd8c046548",
      "parents": [
        "6bebed5a4771eb8149a9560c762e7dd326f35429"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:39:05 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:45:45 2026 -0700"
      },
      "message": "tests/hexagon: add tests for HVX bfloat\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/392114c4c16e6f7f2835a6513987aafea82b565c.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "6bebed5a4771eb8149a9560c762e7dd326f35429",
      "tree": "79deeb89a7e619d0376d028780560dc047ce144a",
      "parents": [
        "57da1eb994e4fe7073e9079864ba6d94a7a55ee7"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:39:04 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:45:44 2026 -0700"
      },
      "message": "tests/hexagon: add tests for v68 HVX IEEE float comparisons\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/53e73707092d31bcde6ed8189c5496b00345f8fa.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "57da1eb994e4fe7073e9079864ba6d94a7a55ee7",
      "tree": "96067b5e076de5500eddd846856a8a6943b69974",
      "parents": [
        "7f3a641101f683549e60de55d30c5006ee97d996"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:39:03 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:45:44 2026 -0700"
      },
      "message": "tests/hexagon: add tests for v68 HVX IEEE float conversions\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/ec6af07a285c47e5f6df343860bfedce5bed9421.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "7f3a641101f683549e60de55d30c5006ee97d996",
      "tree": "dc6b384724cdcb5cfc1b2c5e7548418056ec273b",
      "parents": [
        "449e485814ddadb1ae6f50ca9c9e01a248985eae"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:39:02 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:45:44 2026 -0700"
      },
      "message": "tests/hexagon: add tests for v68 HVX IEEE float min/max\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/7fdbc12ed4c62a16068c380a85ee2356051e61ea.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "449e485814ddadb1ae6f50ca9c9e01a248985eae",
      "tree": "6d09eadb87a6171dc97a34f3ee37bd8dd3b66eff",
      "parents": [
        "9d70629fa0e03ee2341f1aab4928d43ed1718d93"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:39:01 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:45:44 2026 -0700"
      },
      "message": "tests/hexagon: add tests for v68 HVX IEEE float arithmetics\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/791f122bfd744a77177608b524d852fe826cd595.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "9d70629fa0e03ee2341f1aab4928d43ed1718d93",
      "tree": "5a5cdbe29cb276bd35f0db00eca194a009d8d79f",
      "parents": [
        "7646bc0b72a78960d497371036d5841dc590412b"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:39:00 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:45:44 2026 -0700"
      },
      "message": "target/hexagon: add v73 HVX IEEE bfloat16 insns\n\nAdd HVX IEEE bfloat16 (bf16) instructions:\n\nArithmetic operations:\n- V6_vadd_sf_bf, V6_vsub_sf_bf: add/sub bf16 widening to sf output\n- V6_vmpy_sf_bf: multiply bf16 widening to sf output\n- V6_vmpy_sf_bf_acc: multiply-accumulate bf16 widening to sf output\n\nMin/Max operations:\n- V6_vmin_bf, V6_vmax_bf: bf16 min/max\n\nComparison operations:\n- V6_vgtbf: greater-than compare\n- V6_vgtbf_and, V6_vgtbf_or, V6_vgtbf_xor: predicate variants\n\nConversion operations:\n- V6_vcvt_bf_sf: convert sf to bf16\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/1a253373567781e0e141c34b41eaffad4789a493.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "7646bc0b72a78960d497371036d5841dc590412b",
      "tree": "74d38fe3277673600f3225a9691098b0f1320e96",
      "parents": [
        "011b2512f9551b9c91d760fc38d65e5eb7bc2b3b"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:38:59 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:45:44 2026 -0700"
      },
      "message": "target/hexagon: add v68 HVX IEEE float compare insns\n\nAdd HVX IEEE floating-point compare instructions:\n- V6_vgthf, V6_vgtsf: greater-than compare\n- V6_vgthf_and, V6_vgtsf_and: greater-than with predicate-and\n- V6_vgthf_or, V6_vgtsf_or: greater-than with predicate-or\n- V6_vgthf_xor, V6_vgtsf_xor: greater-than with predicate-xor\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/96e27588ad5a7d47ba9f56f1d547729a19b691c5.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "011b2512f9551b9c91d760fc38d65e5eb7bc2b3b",
      "tree": "0c017be82f36105abaaf9b015ff43a9b2080751f",
      "parents": [
        "60f11988ebd6a2a44fff8230aa41ad384aac1f97"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:38:58 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "target/hexagon: add v68 HVX IEEE float conversion insns\n\nAdd HVX IEEE floating-point conversion instructions:\n- vconv_hf_h, vconv_h_hf, vconv_sf_w, vconv_w_sf: vconv operations\n- vcvt_hf_sf, vcvt_sf_hf: float \u003c-\u003e half float conversions\n- vcvt_hf_b, vcvt_hf_h, vcvt_hf_ub, vcvt_hf_uh: int to half float\n- vcvt_b_hf, vcvt_h_hf, vcvt_ub_hf, vcvt_uh_hf: half float to int\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/beca620d2e5e0bc15886bf967ab3961a49eca5f7.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "60f11988ebd6a2a44fff8230aa41ad384aac1f97",
      "tree": "4b81573c7d923a2b28c7c337a6de3ed628070ba1",
      "parents": [
        "2843fc5feb5336a313b906d898037ef6dab94578"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:38:57 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "target/hexagon: add v68 HVX IEEE float misc insns\n\nAdd HVX IEEE floating-point miscellaneous instructions:\n- vassign_fp (vfmv): vector move\n- vfneg_hf, vfneg_sf: vector floating-point negate\n- vabs_hf, vabs_sf: vector absolute value\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/0bd3279ca0bbf7c01548e3b4e7a9c8fdbdbe4ee1.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "2843fc5feb5336a313b906d898037ef6dab94578",
      "tree": "557b5dc0cbc4b9d73ad1b86cdb898827b90ecab1",
      "parents": [
        "69e46b28228441c5d064fb3b84691cbb23e71296"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:38:56 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "target/hexagon: add v68 HVX IEEE float min/max insns\n\nAdd HVX IEEE floating-point min/max instructions:\n- vfmin_hf, vfmin_sf: IEEE floating-point minimum\n- vfmax_hf, vfmax_sf: IEEE floating-point maximum\n- vmax_hf, vmax_sf: qfloat IEEE maximum\n- vmin_hf, vmin_sf: qfloat IEEE minimum\n\nThe Hexagon qfloat variants are similar to the IEEE-754 ones, but they\nhandle NaN slightly differently. See comment on hvx_ieee_fp.h\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/8e274a7a10a5aae23eb1250db0b4f4250c81f3ef.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "69e46b28228441c5d064fb3b84691cbb23e71296",
      "tree": "424c55617e67f4da7f5d07f5e13f48a11032bed0",
      "parents": [
        "97a75a12d6875b0b86211ea5699d1f7a4825e131"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:38:55 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "target/hexagon: add v68 HVX IEEE float arithmetic insns\n\nAdd HVX IEEE floating-point arithmetic instructions:\n- vmpy_sf_sf, vmpy_sf_hf, vmpy_hf_hf: multiply operations\n- vdmpy_sf_hf: dot-product multiply\n- vmpy_sf_hf_acc, vmpy_hf_hf_acc, vdmpy_sf_hf_acc: multiply-accumulate\n- vadd_sf_sf, vsub_sf_sf, vadd_sf_hf, vsub_sf_hf: add/sub with sf output\n- vadd_hf_hf, vsub_hf_hf: add/sub with hf output\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/8923b6c6bc4fe750c07a07bcd490761f8bab52fe.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "97a75a12d6875b0b86211ea5699d1f7a4825e131",
      "tree": "0413beb5e9ca38d801ee4fb6bd4aaa1922cfa5be",
      "parents": [
        "5995de98c4699b3246f1dffa86b90f677b6e7684"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:38:54 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hexagon: print info on \"-d in_asm\" for disabled IEEE FP instructions\n\nWhen cpu-\u003ecfg.ieee_fp_extension is off, IEEE FP instructions don\u0027t get\nexecuted. Let\u0027s print that info on the \"-d in_asm\" output to help users.\nThis will generate an output like the following:\n\n0x00020e30:  0x1f82e1c0 {       V0.sf \u003d vadd(V1.sf,V2.sf) (disabled: no ieee_fp) }\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Philippe Mathieu-Daudé \u003cphilmd@linaro.org\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/1bdc772e4a795ecd9f5bf2b7e7143cc4b297318c.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "5995de98c4699b3246f1dffa86b90f677b6e7684",
      "tree": "e8eb222123c570555f127ef740761128883f897b",
      "parents": [
        "e1245d0ea4552895429a10e6eb51f148cea4d4c0"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:38:53 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hexagon: group cpu configurations in their own struct\n\nThis will be used in a follow up commit.\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Philippe Mathieu-Daudé \u003cphilmd@linaro.org\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/8f9a2e2ccfd2eeda73a63d1a6abbfd6e5458b44c.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "e1245d0ea4552895429a10e6eb51f148cea4d4c0",
      "tree": "46b77023100dd2afe3a29177d31a347dbf5f8eed",
      "parents": [
        "770e282e50e6f6bafe76c3e6b41f9cc8acef7ad9"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:38:52 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "target/hexagon/cpu: add HVX IEEE FP extension\n\nThis flag will be used to control the HVX IEEE float instructions, which\nare only available at some Hexagon cores. When unavailable, the\ninstruction effectively only set the destination registers to 0.\n\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/10fb5b86db60a465e51db2cf73185307a1ec0895.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "770e282e50e6f6bafe76c3e6b41f9cc8acef7ad9",
      "tree": "f2a3a7a24ace482fda89e6ffa5ea71dd7bfa01a9",
      "parents": [
        "19148de4986f9e93392849a0e4fa75244e780e9f"
      ],
      "author": {
        "name": "Matheus Tavares Bernardino",
        "email": "matheus.bernardino@oss.qualcomm.com",
        "time": "Thu Apr 16 04:38:51 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "target/hexagon: fix incorrect/too-permissive HVX encodings\n\nThe following encodings have become stricter since v68:\n\n    - V6_vunpackob, V6_vunpackoh: ---00 -\u003e --000\n    - V6_vaddbq/hq/wq, V6_vaddbnq/hnq/wnq: ---01 -\u003e --001\n    - V6_vsubbq/hq, V6_vsubwq/bnq/hnq/wnq: ---01/---10 -\u003e --001/--010\n    - V6_vhist, V6_vwhist128/256, V6_vwhist128/256_sat: ---00 -\u003e --000\n    - V6_vhistq, V6_vwhist128/256q, V6_vwhist128/256q_sat: ---10 -\u003e --010\n\nPre v68 compilers, by default, already use \"0\" for the non-specified bit\nthat changed in v68, so unless someone is manually writing the binary\nencoding, this should not cause any backwards incompatibility with\npre-v68 binaries.\n\nReviewed-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nSigned-off-by: Matheus Tavares Bernardino \u003cmatheus.bernardino@oss.qualcomm.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/1fe4b8a0fcae6705a591b1b5131e28f6d8062eed.1776339451.git.matheus.bernardino@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "19148de4986f9e93392849a0e4fa75244e780e9f",
      "tree": "7ee3e88eab8704628dac3951a78888e928a0670d",
      "parents": [
        "dde6dc062adbae1c1a1928a87cc425c310339c2b"
      ],
      "author": {
        "name": "Taylor Simpson",
        "email": "ltaylorsimpson@gmail.com",
        "time": "Mon Aug 10 21:22:06 2026 -0600"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "Hexagon (target/hexagon) Clean up disassembly of control and system regs\n\nChange disassembly of control regs from C{num}/{name} to {name}\nChange disassembly of system regs from S{num}/r{num} to {name}\n\nSigned-off-by: Taylor Simpson \u003cltaylorsimpson@gmail.com\u003e\nReviewed-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\nReviewed-by: Philippe Mathieu-Daudé \u003cphilmd@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260811032206.58501-1-ltaylorsimpson@gmail.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "dde6dc062adbae1c1a1928a87cc425c310339c2b",
      "tree": "6f1b8b67ed64dfd30d1645a24ef734d1f725b65d",
      "parents": [
        "ead4d3a8d874f7f59fec909ea17a66b056b39ea5"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Fri Aug 07 08:22:41 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "tests/tcg/hexagon: add HVX tests for vabsdiff\n\nCover the four vabsdiff variants.\n\nThe expected value is computed in int64_t to avoid overflowing the\nsource element type.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260807152241.1576334-8-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "ead4d3a8d874f7f59fec909ea17a66b056b39ea5",
      "tree": "c40ba70ecad36675744c64dc2cba712c6c62dc2f",
      "parents": [
        "ffbb6bbca5d0b74fb24ece36356963267f8b34ab"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Fri Aug 07 08:22:40 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "tests/tcg/hexagon: add HVX test for V6_vsubwsat saturation\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260807152241.1576334-7-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "ffbb6bbca5d0b74fb24ece36356963267f8b34ab",
      "tree": "f595c8021f9b5ff3b462066bc75f625064190926",
      "parents": [
        "234d8cb6f2e95cc5078b232943e47bc4f56170c3"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Fri Aug 07 08:22:39 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "target/hexagon: add GVec overrides for HVX vector average\n\nReviewed-by: Marco Liebel \u003cmarco.liebel@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260807152241.1576334-6-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "234d8cb6f2e95cc5078b232943e47bc4f56170c3",
      "tree": "0478976cd34f23875108a9a6333af71725367a40",
      "parents": [
        "d47d794ea2c7b3f5baa8d57fbe496c755119e0da"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Fri Aug 07 08:22:38 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "target/hexagon: add GVec overrides for HVX absolute difference\n\nReviewed-by: Marco Liebel \u003cmarco.liebel@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260807152241.1576334-5-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "d47d794ea2c7b3f5baa8d57fbe496c755119e0da",
      "tree": "df3ee448aee1a1e26e79f9450d784a1ece5efe0b",
      "parents": [
        "8c53023a26ec397fadaf3fd10404df1be57d2816"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Fri Aug 07 08:22:37 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "target/hexagon: add GVec override for HVX vmpyih multiply\n\nReviewed-by: Marco Liebel \u003cmarco.liebel@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260807152241.1576334-4-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "8c53023a26ec397fadaf3fd10404df1be57d2816",
      "tree": "0512810974e5ddfc326ad49004766f56423b2138",
      "parents": [
        "9e96b5953e2fb619a5ad6274ebba3baee0b933c4"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Fri Aug 07 08:22:36 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "target/hexagon: add GVec overrides for HVX saturating add/sub\n\nReviewed-by: Marco Liebel \u003cmarco.liebel@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260807152241.1576334-3-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "9e96b5953e2fb619a5ad6274ebba3baee0b933c4",
      "tree": "33ff2cbd475e875ca8efa7caa73b4fe57131071f",
      "parents": [
        "701eb2ac98ba543a3a458a7fcaf8cc0f5e469ed4"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Fri Aug 07 08:22:35 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "host-utils: fix ssub32/64_saturate return type and clamp direction\n\nssub32_saturate() and ssub64_saturate() were declared to return bool\ninstead of int32_t/int64_t, and clamped to the wrong bound on overflow.\n\nReviewed-by: Philippe Mathieu-Daudé \u003cphilmd@oss.qualcomm.com\u003e\nCc: qemu-stable@nongnu.org\nFixes: 16495533131 (\"host-utils: Introduce signed saturation primitives\")\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260807152241.1576334-2-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "701eb2ac98ba543a3a458a7fcaf8cc0f5e469ed4",
      "tree": "3e7eb532756811612699ff7de592975419c44bb5",
      "parents": [
        "71d618d3aa64bd7a33d8fc14fff6f3051ad633c2"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:23 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "tests/functional/hexagon: enable more arch_tests cases\n\nAdd more tests from hexagon-arch-tests, enabled by QTimer device.\n\nThese exercise cache maintenance ops, l2vic, thread start/stop, tlb/mmu\noperations, and user-mode transitions.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-19-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "71d618d3aa64bd7a33d8fc14fff6f3051ad633c2",
      "tree": "595045ba5c20ecbc874ad1602372339d2567bd78",
      "parents": [
        "57eaab1e8c8d7c1624591b1aeb668f14c3a8131d"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:22 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "tests/qtest: add qct-qtimer qtest\n\nAdd a qtest exercising the QCT QTimer\u0027s register access, view-region\nframe addressing, and one-shot timer firing behavior.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-18-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "57eaab1e8c8d7c1624591b1aeb668f14c3a8131d",
      "tree": "254c023e490406daaa49a78e31a2015bcc5d5b1f",
      "parents": [
        "954f0cec387e78fcbb6847f42bdd0c6794a5ed6e"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:21 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/hexagon: connect qtimer device\n\nAdd the QTimer to the shared hex-subsys so both machine models pick it\nup.  Map its view region, wire its interrupt lines into l2vic, and link\nit to the globalreg device backing HEX_SREG_TIMERLO/TIMERHI.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-17-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "954f0cec387e78fcbb6847f42bdd0c6794a5ed6e",
      "tree": "2618e6e17c1e689a46c869e5e8cc8f93be355fcb",
      "parents": [
        "240f3620af7048fea14e0e7daf4ffeab8f6bc820"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:20 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/timer: Add QCT QTimer device model\n\nImplement the QCT QTimer generic timer device used by Hexagon DSP\nsystems.\n\nCo-authored-by: Damien Hedde \u003cdamien.hedde@greensocs.com\u003e\nCo-authored-by: Tobias Röhmel \u003cquic_trohmel@quicinc.com\u003e\nCo-authored-by: Sid Manning \u003csidneym@quicinc.com\u003e\nCo-authored-by: Thomas Marceron \u003ctmarcero@qti.qualcomm.com\u003e\nCo-authored-by: Mahmoud Kamel \u003cmkamel@qti.qualcomm.com\u003e\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-16-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "240f3620af7048fea14e0e7daf4ffeab8f6bc820",
      "tree": "58f9eb83e3a2d5d3ac656cfc832e2d6c302c4687",
      "parents": [
        "8ff5b8d403483f76e36ffb30087aacaf1a41fe07"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:19 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "tests/functional/hexagon: add arch_tests functional test\n\nAdd the test_int_steering case from hexagon-arch-tests.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-15-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "8ff5b8d403483f76e36ffb30087aacaf1a41fe07",
      "tree": "f627e2fb58cb8d9d48e5f483e29b8e2cde253ec9",
      "parents": [
        "5f8e903c02404a8c880b4bfcfbe1589d0a36e911"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:18 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "tests/qtest: add L2VIC qtest\n\nAdd a qtest exercising L2VIC register access and interrupt\nenable/disable.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-14-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "5f8e903c02404a8c880b4bfcfbe1589d0a36e911",
      "tree": "39db8529da0b7c224c29b57988f0fc1a84b82f9f",
      "parents": [
        "abd9e918e79bc3ed860745890c35355b4ed85cc6"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:17 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/hexagon/virt: connect pl011 UART interrupt\n\nWire pl011\u0027s sysbus IRQ into l2vic at IRQ 15.\n\nReviewed-by: Philippe Mathieu-Daudé \u003cphilmd@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-13-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "abd9e918e79bc3ed860745890c35355b4ed85cc6",
      "tree": "080944321c768be00a9da708dab394c925cf2008",
      "parents": [
        "76f40eb3f19311d2f83ba3bd2e1a778681359902"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:16 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/hexagon/virt: add l2vic interrupt-controller and virtio-mmio FDT nodes\n\nExpose l2vic as a device-tree interrupt-controller node and reference\nit via interrupt-parent, so guest kernels can discover the virtio-mmio\ntransports.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-12-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "76f40eb3f19311d2f83ba3bd2e1a778681359902",
      "tree": "1a4a7cee35055bcd2b5fc889ba3c481a3e776521",
      "parents": [
        "03f38eecc93b66520bd22b07d25c88e03db0ff41"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:15 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/hexagon/virt: instantiate virtio-mmio transports\n\nAdd a VIRT_MMIO region and virtio-mmio transports, wired into l2vic.\n\nReviewed-by: Philippe Mathieu-Daudé \u003cphilmd@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-11-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "03f38eecc93b66520bd22b07d25c88e03db0ff41",
      "tree": "24c7e8f85ca9fa8536af28677c6fa7ab88d6bb94",
      "parents": [
        "df9c6d6396d08204674da2a81dfdc03b28bfda19"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:14 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/hexagon: connect l2vic device\n\nAdd the l2vic to the shared hex-subsys so both machine models pick it\nup.  Map its register banks, wire the interrupt lines to CPU[0]\nand link each vCPU, globalregs.\n\nReviewed-by: Philippe Mathieu-Daudé \u003cphilmd@oss.qualcomm.com\u003e\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-10-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "df9c6d6396d08204674da2a81dfdc03b28bfda19",
      "tree": "19cc96c551073083e7ef73b918684c127f3d2042",
      "parents": [
        "04f398b2a25d0b16339da4d0683ff505e2613ddf"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:13 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/hexagon: extract get_reg_value/set_reg_value stubs in globalreg\n\nRoute the globalreg read/write accessors through new\nget_reg_value()/set_reg_value() helpers instead of touching\ns-\u003eregs[reg] directly.\n\nThis will be exploited by a subsequent patch that redirects VID/VID1\naccesses to the L2VIC.\n\nReviewed-by: Philippe Mathieu-Daudé \u003cphilmd@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-9-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "04f398b2a25d0b16339da4d0683ff505e2613ddf",
      "tree": "c0c9a0dd45b81f8a67e255d77340da986735ed86",
      "parents": [
        "d922df10b27aa9f492638a22b62a43e873246c40"
      ],
      "author": {
        "name": "Sid Manning",
        "email": "sidneym@quicinc.com",
        "time": "Wed Aug 05 21:27:12 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/intc: Add l2vic interrupt controller\n\nThe Hexagon DSP requires an L2VIC to route up to 1024 external\ninterrupt sources through 4 VID output groups into the core\u0027s 8\ninterrupt inputs.  Add a device model for it.\n\nCo-authored-by: Matheus Tavares Bernardino \u003cquic_mathbern@quicinc.com\u003e\nCo-authored-by: Damien Hedde \u003cdamien.hedde@dahe.fr\u003e\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-8-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "d922df10b27aa9f492638a22b62a43e873246c40",
      "tree": "6aa768360135e041827e4cc42814f4ea1155b1f4",
      "parents": [
        "d33ec047c30d28c883cac0eaa4a7c9168cd81a5f"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:11 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "bitops.h: Add find_first_bit32()\n\nset_bit32()/test_bit32()/etc already let devices operate on\nguest-visible uint32_t register arrays without depending on the host\u0027s\n\u0027unsigned long\u0027 size.  Add find_first_bit32() so callers need not cast\na uint32_t array to \u0027unsigned long *\u0027.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-7-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "d33ec047c30d28c883cac0eaa4a7c9168cd81a5f",
      "tree": "c2b75e76078e9432eb61c5bd1484abd3039be022",
      "parents": [
        "d24f9c80f62f95cb8f6c2b8666d3efd1e021fb99"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:10 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/hexagon: group the CPUs in a cluster\n\nThe CPUs are now grouped in a TYPE_CPU_CLUSTER.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-6-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "d24f9c80f62f95cb8f6c2b8666d3efd1e021fb99",
      "tree": "0285fc79d7de02af08b8c4b66aca7050436200ff",
      "parents": [
        "26088c1e7b39e05a724618518594383665b74069"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:09 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/hexagon: move the TLB to hex-subsys\n\nThe TLB device is sized from the config table, so both machines create\nit identically.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-5-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "26088c1e7b39e05a724618518594383665b74069",
      "tree": "2091d86194834483b0e6d47b58730eadcca5f6a5",
      "parents": [
        "024fff8b8160e20621731502213e1a077567b839"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:08 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/hexagon: move global registers to hex-subsys\n\nBoth machines create the global register device the same way, so let\nhex-subsys own it and link it to each CPU as it is realized.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-4-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "024fff8b8160e20621731502213e1a077567b839",
      "tree": "2d0f8a21e2264f276e775854e7f73fe13298f7a7",
      "parents": [
        "197870349f2b6e5bb3ed89bf1a949ecaca09cd78"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:07 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/hexagon: move VTCM to the common machine state\n\nThe VTCM is described by the config table, so every machine can set it\nup the same way.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-3-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "197870349f2b6e5bb3ed89bf1a949ecaca09cd78",
      "tree": "5b6a0b547ab231edb24724d08924bc9ce3255a7c",
      "parents": [
        "e8d693e12af9cbb89d724baadfcc08559669e279"
      ],
      "author": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Wed Aug 05 21:27:06 2026 -0700"
      },
      "committer": {
        "name": "Brian Cain",
        "email": "brian.cain@oss.qualcomm.com",
        "time": "Tue Aug 11 23:20:45 2026 -0700"
      },
      "message": "hw/hexagon: add hex-subsys\n\nThe virt and DSP machine models build the same core subsystem, let\u0027s\nabstract out that part.  Start with the DDR and config table ROM setup.\n\nReviewed-by: Pierrick Bouvier \u003cpierrick.bouvier@oss.qualcomm.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260806042723.3785369-2-brian.cain@oss.qualcomm.com\nSigned-off-by: Brian Cain \u003cbrian.cain@oss.qualcomm.com\u003e\n"
    },
    {
      "commit": "e8d693e12af9cbb89d724baadfcc08559669e279",
      "tree": "0f1ac03995a4f54bb4645dd3ca9f1d86dba16186",
      "parents": [
        "0573b1e11a2d746b290c76328b15bf06bf0e36a1"
      ],
      "author": {
        "name": "Stefan Hajnoczi",
        "email": "stefanha@redhat.com",
        "time": "Tue Aug 11 14:31:44 2026 -0400"
      },
      "committer": {
        "name": "Stefan Hajnoczi",
        "email": "stefanha@redhat.com",
        "time": "Tue Aug 11 16:12:34 2026 -0400"
      },
      "message": "tests/qtest: Do not use versioned pc-q35-5.2 machine anymore\n\nAs of QEMU v11.1.0, the v5.2.0 machines are not usable anymore.\n\nUse the latest x86 q35 machine instead, otherwise we get:\n\n  $ qemu-system-x86_64 -M pc-q35-5.2\n  qemu-system-x86_64: unsupported machine type: \"pc-q35-5.2\"\n  Use -machine help to list supported machines\n\nSee commit a35f8577a07 (\"include/hw: add macros for deprecation\n\u0026 removal of versioned machines\") and f59ee044067 (\"include/hw/boards:\ncope with dev/rc versions in deprecation checks\") for explanation\non automatically removed versioned machines.\n\nThis commit message is taken from commit 9eef3854d309 (\"tests/qtest: Do\nnot use versioned pc-q35-5.0 machine anymore\") by Philippe Mathieu-Daudé\n\u003cphilmd@linaro.org\u003e.\n\nCc: Philippe Mathieu-Daudé \u003cphilmd@linaro.org\u003e\nReviewed-by: Daniel P. Berrangé \u003cberrange@redhat.com\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nMessage-ID: \u003c20260811183144.190135-1-stefanha@redhat.com\u003e\nSigned-off-by: Stefan Hajnoczi \u003cstefanha@redhat.com\u003e\n"
    },
    {
      "commit": "bdfe26faca7b7c8daa7895783d55ec6d05164880",
      "tree": "83acd6c29d4bd0cc09e8b0e89522c6f781d49047",
      "parents": [
        "ff77a515113f052cc5fc571b6a328142fdfcf220"
      ],
      "author": {
        "name": "Sam Heney",
        "email": "github@me.samiser.xyz",
        "time": "Thu Jul 30 23:59:44 2026 +0100"
      },
      "committer": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Tue Aug 11 15:34:38 2026 -0400"
      },
      "message": "tests/qtest/migration: Only build tls_no_hostname test with TASN1\n\nThe test_precopy_tcp_tls_no_hostname test and its start hook use\nTestMigrateTLSX509 and migrate_hook_start_tls_x509_common(), which\nare only defined when CONFIG_TASN1 is set. This means building with\ngnutls enabled but libtasn1 unavailable fails:\n\n  ../tests/qtest/migration/tls-tests.c: In function \u0027migrate_hook_start_tls_x509_no_host\u0027:\n  ../tests/qtest/migration/tls-tests.c:510:5: error: unknown type name \u0027TestMigrateTLSX509\u0027\n\nGuard the test with CONFIG_TASN1 like the other x509 tests.\n\nFixes: df9c38b19af8 (\"tests/qtest/migration: Add a NULL parameters test for TLS\")\nSigned-off-by: Sam Heney \u003cgithub@me.samiser.xyz\u003e\nLink: https://lore.kernel.org/r/5f24de0e-49af-45a7-927f-f79b203bb335@app.fastmail.com\nSigned-off-by: Peter Xu \u003cpeterx@redhat.com\u003e\n"
    },
    {
      "commit": "ff77a515113f052cc5fc571b6a328142fdfcf220",
      "tree": "268d19b376b1b6274a78d8dcca95a3950547a8b9",
      "parents": [
        "bec5e7c71cc9770a900dac6930d076fe7ee9e57b"
      ],
      "author": {
        "name": "Gavin Shan",
        "email": "gshan@redhat.com",
        "time": "Tue Jul 28 13:17:31 2026 +1000"
      },
      "committer": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Tue Aug 11 15:34:38 2026 -0400"
      },
      "message": "system/memory: Make ram device region directly accessible\n\nThis basically reverts 4a2e242bbb30 (\"memory: Don\u0027t use memcpy for\nram_device regions\") to make ram device region directly accessible\nagain. With this, the bounce buffer is bypassed in address_space_map()\nwhen a ram device region is involved, potentially avoid to overrun\nthe (small) bounce buffer.\n\nReported-by: Julia Graham \u003cjugraham@redhat.com\u003e\nSuggested-by: Michael S. Tsirkin \u003cmst@redhat.com\u003e\nSuggested-by: Peter Xu \u003cpeterx@redhat.com\u003e\nSuggested-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nSuggested-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Gavin Shan \u003cgshan@redhat.com\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nLink: https://lore.kernel.org/r/20260728031731.286666-4-gshan@redhat.com\nSigned-off-by: Peter Xu \u003cpeterx@redhat.com\u003e\n"
    },
    {
      "commit": "bec5e7c71cc9770a900dac6930d076fe7ee9e57b",
      "tree": "21d58881f8aacdac626629aee24e92cff25947a0",
      "parents": [
        "d2d7e63da8e9a6ac4bb23e3ecc1de468530c9437"
      ],
      "author": {
        "name": "Gavin Shan",
        "email": "gshan@redhat.com",
        "time": "Tue Jul 28 13:17:30 2026 +1000"
      },
      "committer": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Tue Aug 11 15:34:38 2026 -0400"
      },
      "message": "system/memory: Use qemu_ram_move() for directly accessible regions\n\nAll ram device regions were turned to be indirectly accessible by commit\n4a2e242bbb (\"memory: Don\u0027t use memcpy for ram_device regions\"). This leads\nto guest hang on attempt to build \u0027cuda-samples\u0027 as reported by Julia. The\nguest is started by the following command lines, with GH100 GPU card passed\nfrom the host.\n\n   host$ lspci | grep GH100\n   0009:01:00.0 3D controller: NVIDIA Corporation GH100 [GH200 120GB / 480GB] (rev a1)\n   host$ /home/sandbox/gavin/qemu.main/build/qemu-system-aarch64            \\\n         -machine virt,gic-version\u003dhost,ras\u003don,highmem-mmio-size\u003d4T         \\\n         -accel kvm -cpu host -smp cpus\u003d48 -m size\u003d8G                       \\\n         -drive file\u003d/home/gavin/sandbox/images/disk.qcow2,if\u003dnone,id\u003dd0    \\\n         -device virtio-blk-pci,id\u003dvb0,bus\u003dpcie.0,drive\u003dd0,num-queues\u003d4     \\\n         -device vfio-pci-nohotplug,host\u003d0009:01:00.0,bus\u003dpcie.1.0\n           :\n   guest$ cd cuda-samples/build\n   guest$ make -j 20 clean\n   guest$ make -j 20\n           :\n   [ 54%] Linking CUDA executable graphMemoryNodes\n   [ 54%] Built target graphMemoryNodes\n   \u003cno more output afterwards, guest becomes frozen here\u003e\n\n   guest$ qemu-system-aarch64: virtio: bogus descriptor or out of resources\n   [  555.814025] virtio_blk virtio0: [vda] new size: 268435456 512-byte logical blocks (137 GB/128 GiB)\n\nWhen the GPU\u0027s driver (NVidia open driver) is loaded on guest bootup,\nthe memory blocks residing in the PCI BAR#4 of the GH100 GPU card can\nbe presented to the guest through memory hot-add. The page cache can\nthen be allocated from the hot added memory blocks when cuda-samples\nis being built. Afterwards, the page cache is sent to QEMU\u0027s virtio-blk\ndevice as part of the DMA request, the bounce buffer has to be used to\naccomodate the request as the corresponding memory region (MemoryRegion)\nis an indirectly accessible ram device region in qemu. However, the max\nbounce bufer size is only 4096 bytes by default and that is exhausted\nquickly, leading to a reset on the virtio-blk device and frozen guest\neventually.\n\n  QEMU\n  \u003d\u003d\u003d\u003d\n  virtio_blk_handle_output\n    virtio_blk_handle_vq\n      virtio_blk_get_request\n        virtqueue_pop\n          virtqueue_split_pop\n            virtqueue_map_desc\n              address_space_map\n                memory_access_is_direct         # Return false\n                  memory_region_supports_direct_access\n\n  (qemu) info mtree\n  memory-region: pci_bridge_pci\n    0000000000000000-ffffffffffffffff (prio 0, container): pci_bridge_pci\n      0000042000000000-0000043fffffffff (prio 1, i/o): 0009:01:00.0 base BAR 4\n        0000042000000000-0000043fffffffff (prio 0, i/o): 0009:01:00.0 BAR 4\n          0000042000000000-000004379fffffff (prio 0, ramd): 0009:01:00.0 BAR 4 mmaps[0]\n\nThis adds qemu_ram_move() where the aligned and small-sized accesses are\nhandled by qatomics, and fall back to memmove() otherwise. The memove()\nfor the directly accessible regions is replaced by qemu_ram_move() so that\nthe issue covered by commit 4a2e242bbb (MMIO access instructions were\noptimized to SSE instructions) is fixed. This makes \u0027ram_device_mem_ops\u0027\nredundant, paving the way to revert that commit to make the ram device\nregion directly accessible again in the next patch.\n\nBesides, this also fixes the issue of the unexpected frozen reception on\ne1000 NIC in the scenario of DPDK due to the wrong Rx queue full indication\ncaused by the following memcpy(), which is turned to 3 consective \u0027strb\u0027\ninstructions to the same location by glibc-2.24+ for aarch64. With this\napplied, the syntax of one-byte store is strictly ensured by a one-byte\nqatomic set.\n\n  QEMU\n  \u003d\u003d\u003d\u003d\n  e1000_receive_iov\n    pci_dma_write\n      pci_dma_rw\n        dma_memory_rw\n          dma_memory_rw_relaxed\n            address_space_rw\n              address_space_write\n                flatview_write\n                  flatview_write_continue\n                    flatview_write_continue_step\n                      memcpy    # 3 consective \u0027strb\u0027 instructions\n\nReported-by: Julia Graham \u003cjugraham@redhat.com\u003e\nReported-by: Liu Gang \u003cliugang24219@sangfor.com.cn\u003e\nReported-by: Ding Hui \u003cdinghui@sangfor.com.cn\u003e\nSuggested-by: Michael S. Tsirkin \u003cmst@redhat.com\u003e\nSuggested-by: Peter Xu \u003cpeterx@redhat.com\u003e\nSuggested-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nSuggested-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nSigned-off-by: Gavin Shan \u003cgshan@redhat.com\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nLink: https://lore.kernel.org/r/20260728031731.286666-3-gshan@redhat.com\n[peterx: remove src\u003d\u003ddst check, fix doc, enhance comments, per PeterM, add R-b]\nSigned-off-by: Peter Xu \u003cpeterx@redhat.com\u003e\n"
    },
    {
      "commit": "d2d7e63da8e9a6ac4bb23e3ecc1de468530c9437",
      "tree": "859af06ecb3afc2ccaf7b3a60e684941a1ccc799",
      "parents": [
        "403ccbc55d7bfdef41998fbe26967b017663c3eb"
      ],
      "author": {
        "name": "Gavin Shan",
        "email": "gshan@redhat.com",
        "time": "Tue Jul 28 13:17:29 2026 +1000"
      },
      "committer": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Tue Aug 11 15:34:38 2026 -0400"
      },
      "message": "system/memory: Use memmove() for directly accessible regions\n\nSimilar to what\u0027s done in commit 4a73aee88140 (\"softmmu: Use memmove in\nflatview_write_continue\"), there are more sites where the overlapping\nsource and destination buffer are allowed for the directly accessible\nregions. Use memmove() in those sites, listed as below.\n\n  hw/remote/vfio-user-obj.c::vfu_object_mr_rw\n  include/system/memory.h::address_space_read\n  system/physmem.c::flatview_read_continue_step\n\nSigned-off-by: Gavin Shan \u003cgshan@redhat.com\u003e\nReviewed-by: Peter Maydell \u003cpeter.maydell@linaro.org\u003e\nReviewed-by: Peter Xu \u003cpeterx@redhat.com\u003e\nLink: https://lore.kernel.org/r/20260728031731.286666-2-gshan@redhat.com\nSigned-off-by: Peter Xu \u003cpeterx@redhat.com\u003e\n"
    },
    {
      "commit": "403ccbc55d7bfdef41998fbe26967b017663c3eb",
      "tree": "409ec9f7e6a22a13ac141777fde82f3a4c356487",
      "parents": [
        "8b6405a493a2106eaa3893237595afb4759ca498"
      ],
      "author": {
        "name": "Dongli Zhang",
        "email": "dongli.zhang@oracle.com",
        "time": "Tue Jul 28 01:59:03 2026 -0700"
      },
      "committer": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Tue Aug 11 15:34:38 2026 -0400"
      },
      "message": "migration/cpr: Add HMP support for cpr-transfer\n\nCurrently the cpr-transfer source QEMU instance cannot be driven entirely\nvia HMP.  The source must use QMP in order to specify both the\nmain migration channel and the CPR channel.\n\nExtend the HMP migrate command with an optional CPR channel URI. When the\nmigration mode is cpr-transfer, HMP uses this URI to build a\nCPR MigrationChannel in addition to the main migration channel. The new\noption is rejected unless the migration mode is cpr-transfer, so existing\nHMP migrate usage is unchanged.\n\nFor example, source QEMU HMP commands can be something like below. The\n\"-c unix:/tmp/cpr.sock\" is for CPR URI.\n\n(qemu) migrate_set_parameter mode cpr-transfer\n(qemu) migrate -c unix:/tmp/cpr.sock tcp:0:50002\n\nSigned-off-by: Dongli Zhang \u003cdongli.zhang@oracle.com\u003e\nReviewed-by: Dr. David Alan Gilbert \u003cdave@treblig.org\u003e\nAcked-by: Maciej S. Szmigiero \u003cmaciej.szmigiero@oracle.com\u003e\nLink: https://lore.kernel.org/r/20260728085903.173265-1-dongli.zhang@oracle.com\nSigned-off-by: Peter Xu \u003cpeterx@redhat.com\u003e\n"
    },
    {
      "commit": "8b6405a493a2106eaa3893237595afb4759ca498",
      "tree": "533454a8d3e1da3b1913a7677d793b4ebb699a81",
      "parents": [
        "84f07211cc5b4fc6a371559bf8a5de4fb068e648"
      ],
      "author": {
        "name": "Fabiano Rosas",
        "email": "farosas@suse.de",
        "time": "Tue Jul 21 10:14:57 2026 -0300"
      },
      "committer": {
        "name": "Peter Xu",
        "email": "peterx@redhat.com",
        "time": "Tue Aug 11 15:34:38 2026 -0400"
      },
      "message": "docs: Add security considerations for migration\n\nAdd the security considerations that are unique to migration and that\ndo not already fall into one of the other categories. Some aspects are\nbetter framed as security architecture considerations, so extend that\nsection to mention TLS and clarify that disk images and guest network\nalso need to be isolated from other processes, not just other guests.\n\nReviewed-by: Peter Xu \u003cpeterx@redhat.com\u003e\nReviewed-by: Daniel P. Berrangé \u003cberrange@redhat.com\u003e\nSigned-off-by: Fabiano Rosas \u003cfarosas@suse.de\u003e\nLink: https://lore.kernel.org/r/20260721131457.3062767-1-farosas@suse.de\nSigned-off-by: Peter Xu \u003cpeterx@redhat.com\u003e\n"
    },
    {
      "commit": "0375f6498eee6188089924bb766c653492ff8857",
      "tree": "f87e684057da53199c23d755380875707ed9cfd7",
      "parents": [
        "baf15a2cf21c75ec9c3f068991cf28844887bf74"
      ],
      "author": {
        "name": "Jamin Lin",
        "email": "jamin_lin@aspeedtech.com",
        "time": "Tue Aug 11 06:01:37 2026 +0000"
      },
      "committer": {
        "name": "Cédric Le Goater",
        "email": "clg@redhat.com",
        "time": "Tue Aug 11 18:25:58 2026 +0200"
      },
      "message": "tests/qtest/aspeed-hace: Test the crypto command on the AST2700\n\nCover the AST2700 crypto engine, which drives 64-bit scatter-gather DMA\nand adds AES-GCM on top of the ECB/CBC/CTR modes shared with the AST2600.\nAdd AES-128 and AES-256 GCM known-answer vectors (GCM specification /\nNIST SP 800-38D, no associated data) and a dedicated GCM runner that\nprograms the tag buffer and reads the tag back, checking it after both\nencryption and decryption. Register the AST2700 with all four modes.\n\nSigned-off-by: Jamin Lin \u003cjamin_lin@aspeedtech.com\u003e\nReviewed-by: Kane Chen \u003ckane_chen@aspeedtech.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260811060115.1849266-17-jamin_lin@aspeedtech.com\nSigned-off-by: Cédric Le Goater \u003cclg@redhat.com\u003e\n"
    },
    {
      "commit": "baf15a2cf21c75ec9c3f068991cf28844887bf74",
      "tree": "1c4b025ca26214608362288bb491015add6b59fd",
      "parents": [
        "7a1a61b7ace9a4f7dad5cc3d4d69459029360961"
      ],
      "author": {
        "name": "Jamin Lin",
        "email": "jamin_lin@aspeedtech.com",
        "time": "Tue Aug 11 06:01:36 2026 +0000"
      },
      "committer": {
        "name": "Cédric Le Goater",
        "email": "clg@redhat.com",
        "time": "Tue Aug 11 18:25:58 2026 +0200"
      },
      "message": "hw/misc/aspeed_hace: Enable the crypto command on the AST2700\n\nWith direct/scatter-gather access, 64-bit DMA and AES-GCM all in place,\nthe AST2700 crypto engine is now fully modelled. Drop its temporary\ninterrupt-only workaround so the crypto command runs for real, like the\nother HACE variants.\n\nSigned-off-by: Jamin Lin \u003cjamin_lin@aspeedtech.com\u003e\nReviewed-by: Kane Chen \u003ckane_chen@aspeedtech.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260811060115.1849266-16-jamin_lin@aspeedtech.com\nSigned-off-by: Cédric Le Goater \u003cclg@redhat.com\u003e\n"
    },
    {
      "commit": "7a1a61b7ace9a4f7dad5cc3d4d69459029360961",
      "tree": "3919b4e6722dbbd69fda1092a68ca9a3907c13ed",
      "parents": [
        "c98058bb3d3464be0923ffd5f88937ecc57a0cac"
      ],
      "author": {
        "name": "Jamin Lin",
        "email": "jamin_lin@aspeedtech.com",
        "time": "Tue Aug 11 06:01:35 2026 +0000"
      },
      "committer": {
        "name": "Cédric Le Goater",
        "email": "clg@redhat.com",
        "time": "Tue Aug 11 18:25:58 2026 +0200"
      },
      "message": "hw/misc/aspeed_hace: Support the AES-GCM mode for the crypto command\n\nImplement the AES-GCM mode (HACE10[6:4] \u003d 0b101) used by the AST2700\ncrypto engine: decode the GCM selection, read the 96-bit IV from the\ncontext buffer, operate on the exact data length (GCM handles a partial\nfinal block itself), and write the 128-bit authentication tag to the tag\nbuffer (HACE18/HACE8C). The hardware GCM path is only used without\nassociated data (the driver falls back to software otherwise), so AAD is\nnot modelled and a non-zero HACE14 is reported as unimplemented.\n\nSigned-off-by: Jamin Lin \u003cjamin_lin@aspeedtech.com\u003e\nReviewed-by: Kane Chen \u003ckane_chen@aspeedtech.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260811060115.1849266-15-jamin_lin@aspeedtech.com\nSigned-off-by: Cédric Le Goater \u003cclg@redhat.com\u003e\n"
    },
    {
      "commit": "c98058bb3d3464be0923ffd5f88937ecc57a0cac",
      "tree": "5aa77712c80a3ee2576e2815b011c45892004a6b",
      "parents": [
        "69ddeb2fac7454daa6b5cd896cc91df96566ee25"
      ],
      "author": {
        "name": "Jamin Lin",
        "email": "jamin_lin@aspeedtech.com",
        "time": "Tue Aug 11 06:01:34 2026 +0000"
      },
      "committer": {
        "name": "Cédric Le Goater",
        "email": "clg@redhat.com",
        "time": "Tue Aug 11 18:25:58 2026 +0200"
      },
      "message": "hw/misc/aspeed_hace: Support 64-bit DMA for the crypto command\n\nThe AST2700 crypto engine addresses DRAM with 64 bits, supplying the high\nhalf of the source, destination and context addresses through HACE80,\nHACE84 and HACE88. Add those registers and a crypt_get_addr() helper that\ncombines the low and high halves when the SoC has 64-bit DMA, mirroring\nthe hash engine. SoCs without 64-bit DMA (AST2500/AST2600/AST1030) ignore\nthe high registers, so their behaviour is unchanged.\n\nSigned-off-by: Jamin Lin \u003cjamin_lin@aspeedtech.com\u003e\nReviewed-by: Kane Chen \u003ckane_chen@aspeedtech.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260811060115.1849266-14-jamin_lin@aspeedtech.com\nSigned-off-by: Cédric Le Goater \u003cclg@redhat.com\u003e\n"
    },
    {
      "commit": "69ddeb2fac7454daa6b5cd896cc91df96566ee25",
      "tree": "4c945022a23d6500d1b818652c68274b25e5fe5b",
      "parents": [
        "66c320fd5d492cc5287e4f5bde52def3efbd149e"
      ],
      "author": {
        "name": "Jamin Lin",
        "email": "jamin_lin@aspeedtech.com",
        "time": "Tue Aug 11 06:01:32 2026 +0000"
      },
      "committer": {
        "name": "Cédric Le Goater",
        "email": "clg@redhat.com",
        "time": "Tue Aug 11 18:25:58 2026 +0200"
      },
      "message": "tests/unit/test-crypto-cipher: Test AES-GCM mode\n\nExercise the new GCM mode and the setaad/gettag helpers with the\ncanonical AES-GCM test vectors from the GCM specification (McGrew \u0026\nViega, also NIST SP 800-38D): AES-128 and AES-256, with and without\nassociated data. Each vector is run through encrypt (checking the\nciphertext and the generated tag) and decrypt (checking the recovered\nplaintext and the recomputed tag).\n\nSigned-off-by: Jamin Lin \u003cjamin_lin@aspeedtech.com\u003e\nReviewed-by: Daniel P. Berrangé \u003cberrange@redhat.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260811060115.1849266-13-jamin_lin@aspeedtech.com\nSigned-off-by: Cédric Le Goater \u003cclg@redhat.com\u003e\n"
    },
    {
      "commit": "66c320fd5d492cc5287e4f5bde52def3efbd149e",
      "tree": "6b492cf2590353751b48781ea0f6f570fbaaf6fd",
      "parents": [
        "b0f7e8cc97d16133bfd7ce344b525188d68e30f1"
      ],
      "author": {
        "name": "Jamin Lin",
        "email": "jamin_lin@aspeedtech.com",
        "time": "Tue Aug 11 06:01:31 2026 +0000"
      },
      "committer": {
        "name": "Cédric Le Goater",
        "email": "clg@redhat.com",
        "time": "Tue Aug 11 18:25:58 2026 +0200"
      },
      "message": "crypto/cipher-gnutls: Implement AES-GCM\n\nAdd the AES-GCM AEAD mode to the gnutls backend so it is available when\nQEMU is built with gnutls (neither gcrypt nor nettle). GCM uses the\nincremental gnutls_cipher_* API with the GNUTLS_CIPHER_AES_*_GCM\nalgorithms: gnutls_cipher_set_iv() sets the nonce, gnutls_cipher_add_auth()\nfeeds the associated data, gnutls_cipher_encrypt2()/decrypt2() process the\nmessage, and gnutls_cipher_tag() reads back the authentication tag.\n\nSigned-off-by: Jamin Lin \u003cjamin_lin@aspeedtech.com\u003e\nReviewed-by: Daniel P. Berrangé \u003cberrange@redhat.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260811060115.1849266-12-jamin_lin@aspeedtech.com\nSigned-off-by: Cédric Le Goater \u003cclg@redhat.com\u003e\n"
    },
    {
      "commit": "b0f7e8cc97d16133bfd7ce344b525188d68e30f1",
      "tree": "ab175bdfafedfd75d20622dbda23fa25b3edf5b2",
      "parents": [
        "1429ef61c89672ef8c8eb3241c22ba46390b9003"
      ],
      "author": {
        "name": "Jamin Lin",
        "email": "jamin_lin@aspeedtech.com",
        "time": "Tue Aug 11 06:01:30 2026 +0000"
      },
      "committer": {
        "name": "Cédric Le Goater",
        "email": "clg@redhat.com",
        "time": "Tue Aug 11 18:25:58 2026 +0200"
      },
      "message": "crypto/cipher-nettle: Implement AES-GCM\n\nAdd the AES-GCM AEAD mode to the nettle backend so it is available when\nQEMU is built with nettle instead of gcrypt. GCM is driven through\nnettle\u0027s generic gcm_* interface, using the AES encrypt function for both\ndirections: gcm_set_iv() sets the (typically 96-bit) nonce, gcm_update()\nfeeds the associated data, gcm_encrypt()/gcm_decrypt() need not be block\naligned, and gcm_digest() produces the authentication tag.\n\nSigned-off-by: Jamin Lin \u003cjamin_lin@aspeedtech.com\u003e\nReviewed-by: Daniel P. Berrangé \u003cberrange@redhat.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260811060115.1849266-11-jamin_lin@aspeedtech.com\nSigned-off-by: Cédric Le Goater \u003cclg@redhat.com\u003e\n"
    },
    {
      "commit": "1429ef61c89672ef8c8eb3241c22ba46390b9003",
      "tree": "3d1554516cd40fcb64918071ac14bc69de59e566",
      "parents": [
        "a4383c086228f8626f2318b7f4b984002ce820df"
      ],
      "author": {
        "name": "Jamin Lin",
        "email": "jamin_lin@aspeedtech.com",
        "time": "Tue Aug 11 06:01:28 2026 +0000"
      },
      "committer": {
        "name": "Cédric Le Goater",
        "email": "clg@redhat.com",
        "time": "Tue Aug 11 18:25:58 2026 +0200"
      },
      "message": "crypto/cipher-gcrypt: Implement AES-GCM\n\nMap QCRYPTO_CIPHER_MODE_GCM to GCRY_CIPHER_MODE_GCM and advertise it in\nqcrypto_cipher_supports() for 128-bit block ciphers. Add a GCM driver\nwhose setiv accepts the (typically 96-bit) nonce, whose encrypt/decrypt\ndo not require block-aligned lengths, and which implements setaad via\ngcry_cipher_authenticate() and gettag via gcry_cipher_gettag().\n\nSigned-off-by: Jamin Lin \u003cjamin_lin@aspeedtech.com\u003e\nReviewed-by: Daniel P. Berrangé \u003cberrange@redhat.com\u003e\nAcked-by: Daniel P. Berrangé \u003cberrange@redhat.com\u003e\nLink: https://lore.kernel.org/qemu-devel/20260811060115.1849266-10-jamin_lin@aspeedtech.com\nSigned-off-by: Cédric Le Goater \u003cclg@redhat.com\u003e\n"
    }
  ],
  "next": "a4383c086228f8626f2318b7f4b984002ce820df"
}
