ChangeLog/11.1

From QEMU

Release schedule: Planning/11.1.

System emulation

Removed features and incompatible changes

New deprecated options and features

  • The low level `-mon` argument is obsoleted by the new `-object` support with 'monitor-qmp' and 'monitor-hmp' types.

Guest CPUs

68k

Alpha

Arm

  • The virt board now allows users to specify the cache topology for virtual machines.
  • New machine type: imx8mp-evk models the i.MX 8MM EVK(Evaluation Kit) board
  • qemu-system-aarch64 now allows you to boot a 32-bit guest on a 64-bit TCG CPU with "-cpu <type>,aarch64=off"
  • fsl-imx6ul: The LCDIF display device is now implemented
  • hvf: now supports the platform vGIC for the virt board
  • hvf: support nested virtualization for the virt board
  • There is now an experimental emulation of the GICv5 interrupt controller. Consult the documentation of the "gic-version=x-5" option in docs/system/arm/virt.rst for more information and details of what its experimental status means.
  • On NVIDIA Tegra241 hardware, Command Queue Virtualisation (CMDQV) support is now available via "-device arm-smmuv3,accel=on,cmdqv=on", giving each VM dedicated hardware SMMUv3 command queues, improving performance.
  • The sabrelite board now supports FlexCAN emulation
  • Arm boards now support loading the UEFI shim via the standard '-shim' argument
  • WFE and WFET are now implemented to no longer be mere no-ops, including honouring trap conditions
  • WFIT/WFET properly report syndrome and register information
  • New CPU architectural features emulated:
    • FEAT_FAMINMAX
    • FEAT_FPMR
    • FEAT_CMPBR
    • FEAT_RNG_TRAP
    • FEAT_F8F16MM
    • FEAT_F8F32MM
    • FEAT_FP8DOT2
    • FEAT_SSVE_FP8DOT2
    • FEAT_FP8DOT4
    • FEAT_SSVE_FP8DOT4,
    • FEAT_FP8FMA
    • FEAT_SSVE_FP8FMA
    • FEAT_SME_LUTv2
    • FEAT_SME_F8F32
    • FEAT_SME_F8F16
    • FEAT_SSVE_AES
    • FEAT_FP8
    • FEAT_LUT
    • FEAT_MTE_CANONICAL_TAGS,
    • FEAT_MTE_NO_ADDRESS_TAGS
    • FEAT_MTE_PERM
    • FEAT_MTE_STORE_ONLY
    • FEAT_MTE_TAGGED_FAR
    • FEAT_MTE4
    • FEAT_RME_GPC3
    • FEAT_SME_MOP4
    • FEAT_FPRCVT
    • FEAT_SSVE_FEXPA
    • FEAT_WxFT

AVR

Hexagon

  • The initial system emulation support is now present. But until semihosting and interrupt controller features arrive, the uses for hexagon system emulation are very limited in 11.1. Consider using a subsequent release when available.
  • Fixed unaligned accesses for linux-user emulation. Note well: this means that defective programs which appeared to behave normally will now start to (correctly) generate a bus error when performing an unaligned scalar access.

HPPA

  • New firmware SeaBIOS-hppa v25
  • Fast TLB insert fix for HP-UX 9

LoongArch

Microblaze

MIPS

OpenRISC

PowerPC

  • MPIPL support for PowerNV
  • ppc/spapr: Make Power11 as default cpu for pseries
  • ppc/pnv: Make PowerNV11 as the default powernv machine
  • SLOF FW update to 20260627
  • Testcase improvements for PowerNV
  • Removal of deprecated Power8E and 8NVL CPUs
  • ppc/pnv: Add a nest MMU model
  • hw/ssi/pnv_spi: Fix fifo8 memory leak on unrealize
  • hw/intc/xics: Add a check for an invalid server id
  • ppc/spapr: skip system reset for quiesced CPUs
  • ppc/pnv: Fix uninitialized MpiplProcDumpArea struct
  • target/ppc/kvm: Fix const violation when trimming CPU alias suffix
  • ppc/pnv: external dtb fix and test addition
  • PHB code refactor for better maintainability
  • Revert deprecation of 405 CPUs
  • target/ppc: Expose TB offset of guest in Qemu monitor

Renesas RX

Renesas SH (sh4)

  • Signal handler and libunwind fixes for linux-user
  • decode_gusa: recognize add#imm with prior mov Rm, Rn

RISC-V

ISA and Extensions

  • Add RISC-V big-endian target support
  • Add draft RISC-V Zbr ext as xbr0p93
  • Add Zvfbfa extension support
  • Allow fractional LMUL on vector SHA instructions
  • Add KVM support for Zicbop and BFloat16 extensions
  • Add 'cbo' insns to disassembler
  • Enable `mnret` disassembly
  • Do not hide Sstc CSRs from gdbstub
  • Reject Svinval instructions in U-mode
  • Fault with reserved PTE.PBMT val
  • Allow LOAD_ADDR_MIS promotion to AMO fault
  • Add PMA access fault

Machines

  • Remove spike as default machine
  • Deprecate the shakti_c machine
  • Add Tenstorrent mvendorid
  • Update OpenSBI to v1.8.1
  • Implement Microchip mpfs ioscb PLLs and sysreg clock dividers
  • Add support for K230 board
  • Fix --disable-tcg builds

Fixes and Misc

  • Fix irq_overflow_left residual value bug in IOMMU
  • Add IPSR.PMIP RW1C support to IOMMU
  • Use kvm timer frequency when kvm enabled
  • Fix stale ptshift and base on page walk restart
  • Fix heap OOB in ACLINT MTIMER multi-socket
  • Reject RISC-V HTIF invalid signature ranges
  • Fix RV32 henvcfg/stateen CSR handling
  • Mask xepc[0] only when Zc* extension is enabled
  • Generate access fault if sc comparison fails
  • Don't OR mip.SEIP when mvien is one
  • Use ELEN for Fractional LMUL check
  • Fix Zjpm implementation
  • Handle mask/source overlap of vector reduction instructions
  • Fix Svnapot 64KB pages
  • Set MISA.[C|X] based on the selected extensions
  • Handle source overlap of vector widening reduction instructions
  • Check interrupt in SiFive UART after txctrl register is written
  • Fix medeleg[11] read-only zero bit for M-mode ECALL
  • Fix tail handling for vmv.s.x and vfmv.s.f
  • Update the local AIA interrupt mask
  • Fix the IOMMU FSC SV32 capability check
  • Fix the read of pmpaddr(0-63) CSRs
  • Make hpmcounterh return the upper 32-bits
  • Re-process IOMMU command queue after clearing CMD_ILL
  • Disable svpbmt if satp_mode is less then sv39
  • Disable svnapot if satp_mode is less then sv39
  • Numerous IOMMU fixes and compliance updates
  • Check PCIe DOE mailbox length for overflows
  • Add extensions after v7.1-rc4 update
  • Correct ACPI field sequence in SPCR table
  • Fix RISC-V privilege level in uftrace plugin

s390x

  • kvm: add support for the ASTFLE facility 2 (for nested)
  • enable boot menu for virtio-pci devices
  • disable legacy virtio-pci devices, which had never worked in the first place
  • Fixes:
    • assorted hardening fixes for the guest->host interface
    • fix some intermittent errors when booting from virtio-pci devices
    • various other fixes all over the place

SPARC

Tricore

x86

Xtensa

Accelerators

KVM

TCG

  • Fixed an issue with TB invalidation on MacOS [1]

Xen

Other accelerators

Device emulation and assignment

9pfs

ACPI / SMBIOS

Audio

Block devices

Graphics

  • vga: implement blinking in text mode

I2C

Input devices

IPMI

Network devices

NVDIMM

NVMe

PCI/PCIe

SCSI

SD card

SMBIOS

TPM

UFS

  • Added support for UFS Write Booster emulation based on the UFS 4.1 specification.
  • Added support for Host Initiated Defragmentation (HID) emulation based on the UFS 4.1 specification.

USB

  • Fixed possible use-after-free problem in "usb-redir" device (CVE-2026-15705)
  • Fixed possible infinite loop or crash in "usb-redir" device (CVE-2026-63319)
  • Fixed possible out-of-bounds heap access in XHCI sysbus device, e.g. used on the "microvm" machine (CVE-2026-16043)

VFIO

virtio

  • use-after-free fix for virtio-gpu (CVE-2026-6502)
  • fix crash when now EGL available on Windows
  • add vhost-user-rtc device to connect to vhost-user daemons offering a virtio-rtc implementation

vDPA

Other QEMU sub-systems

Audio

Authorization subsystem

Block subsystem

Character devices

Crypto subsystem

  • Fix creation of anonymous TLS credentials (tls-creds-anon object)
  • The --enable-nettle / --enable-gcrypt configure flags are now correctly honoured again.

Dump

  • prevent dumping from migrating VMs
  • make win-dmp available only when Windows has published vmcoreinfo dump header
  • new dump-guest-memory test

GDBStub

GUI

  • vc chardevs now have "encoding" option to specify the expected character set (cp437 or utf8)
  • -display dbus now exposes org.qemu.Display1.Chardev.VCEncoding
  • the vt100 emulator now supports utf8 encoding with CP437 rendering
  • new "qemu-vnc" standalone VNC server, to export -display dbus
  • -display gtk: better handling of console hotplugging
  • improve resource cleanups on exit

fw_cfg

I/O subsystem

Memory backends

  • Fixed virtio-mem behavior within CoCo VMs (still needs guest OS support)

Migration

  • CPR-transfer downtime optimization for FD lookups using hash table\
  • A new parameter x-rdma-chunk-size is added for RDMA migration to specify chunk size
  • Enhanced query-migrate results with both system-wide remaining bytes reporting and expected downtime calculations (to include VFIO device states)
  • Fixed a regression on migrate-set-parameters crashing QEMU when both multifd and zerocopy are enabled
  • Fixed a possible migration hang in POSTCOY_DEVICE state when dest QEMU failed to ACK
  • Fixed a possible crash on a second migration if the first migration got cancelled before channel establishment
  • Fixed a possible but rare crash in VFIO migration

Monitor

QMP

  • The QMP monitor can now be created with '-object monitor-qmp,id=NNN,chardev=MMM', with '-mon' deprecated. The high level '-qmp' syntactic sugar remains unchanged.
  • It is now possible to hot-add and hot-remove QMP monitor instances using the `object-add` command and new 'monitor-qmp' type
  • The QMP monitor can be set to automatically delete when the client closes the connection via the new "close-action=delete" parameter.

HMP

  • The HMP monitor can now be created with '-object monitor-hmp,id=NNN,chardev=MMM', with '-mon' deprecated. The high level '-monitor' syntactic sugar remains unchanged.
  • It is now possible to hot-add (but NOT hot-remove) HMP monitor instances using the `object-add` command and new 'monitor-hmp' type

Network

Record/Replay

Semihosting

TCG Plugins

  • Refactored API to ensure all callbacks can receive userdata. This removes the need to have global variables to maintain state.

Tracing

User-mode emulation

  • Add emulation for preadv2() and pwritev2() syscalls
  • Implement fsmount series of syscalls for systemd support
  • Add emulation of /proc/cpuinfo file for ppc, loongarch and m68k CPUs
  • Implement finer grained madivse() syscall
  • VDSO support for sh4 and sh4eb
  • Flush error messages at exit
  • Fix IP multicast groups with different endian between host & guest
  • Fix CLONE_PARENT_SETTID when using fork-style clone()
  • Fix getifaddrs() on big-endian targets
  • Fix strace addresses in read() and write() on riscv64
  • Fix getsockopt() for SO_RCVTIMEO_NEW & SO_SNDTIMEO_NEW
  • Fix signals/rt_sigframe stack offset for ppc32
  • Signal handler fixes for sparc and sparc64
  • Fix stat64 struct on loongarch64 guest
  • Fixes for Cavium Octeon userspace
  • Improved CDROM support (added ioctls)
  • Allow getsockopt() with NULL optval address
  • Translate errno in IP_RECVERR and IPV6_RECVERR
  • Fix AT_EXECFN in AUXV for symlinked programs
  • Fix AT_PHDR when program headers are relocated into their own segment
  • Added coredump support and related fixes for hppa, riscv, alpha, sparc, mips64 and mipsn32
  • Signal handler and libunwind fixes for sh4 target
  • Various fixes in handling of floating point registers during signal delivery for ppc, mips, sh4, xtensa and s390x
  • Fix unlock of uninitialized frame pointer on sigreturn on xtensa
  • Validate guest-passed dm_ioctl data_size
  • Alpha: Fix programs using getauxval(AT_HWCAP) to detect BWX/FIX/CIX
  • Allow full 32-bit address space for sh4 guest
  • Fix msgctl syscall by correcting time and pid entries of the msqid_ds struct
  • Fix token in map_shadow_stack syscall on aarch64

Tools and other binaries

Block tools

Guest agent

Project related changes

Documentation

Build Information

Dependencies

Host support

Rust usage

Testing and CI

  • MacOS tests have been migrated from Cirrus to GitLab

Known issues