Statistics
| Branch: | Revision:

root / qemu-doc.texi @ b756921a

History | View | Annotate | Download (34.5 kB)

1 386405f7 bellard
\input texinfo @c -*- texinfo -*-
2 386405f7 bellard
3 0806e3f6 bellard
@iftex
4 1f673135 bellard
@settitle QEMU CPU Emulator User Documentation
5 386405f7 bellard
@titlepage
6 386405f7 bellard
@sp 7
7 1f673135 bellard
@center @titlefont{QEMU CPU Emulator User Documentation}
8 386405f7 bellard
@sp 3
9 386405f7 bellard
@end titlepage
10 0806e3f6 bellard
@end iftex
11 386405f7 bellard
12 386405f7 bellard
@chapter Introduction
13 386405f7 bellard
14 322d0c66 bellard
@section Features
15 386405f7 bellard
16 1f673135 bellard
QEMU is a FAST! processor emulator using dynamic translation to
17 1f673135 bellard
achieve good emulation speed.
18 1eb20527 bellard
19 1eb20527 bellard
QEMU has two operating modes:
20 0806e3f6 bellard
21 0806e3f6 bellard
@itemize @minus
22 0806e3f6 bellard
23 0806e3f6 bellard
@item 
24 1f673135 bellard
Full system emulation. In this mode, QEMU emulates a full system (for
25 1f673135 bellard
example a PC), including a processor and various peripherials. It can
26 1f673135 bellard
be used to launch different Operating Systems without rebooting the
27 1f673135 bellard
PC or to debug system code.
28 1eb20527 bellard
29 0806e3f6 bellard
@item 
30 1f673135 bellard
User mode emulation (Linux host only). In this mode, QEMU can launch
31 1f673135 bellard
Linux processes compiled for one CPU on another CPU. It can be used to
32 1f673135 bellard
launch the Wine Windows API emulator (@url{http://www.winehq.org}) or
33 1f673135 bellard
to ease cross-compilation and cross-debugging.
34 1eb20527 bellard
35 1eb20527 bellard
@end itemize
36 1eb20527 bellard
37 7c3fc84d bellard
QEMU can run without an host kernel driver and yet gives acceptable
38 6f2f2b24 bellard
performance. 
39 322d0c66 bellard
40 52c00a5f bellard
For system emulation, the following hardware targets are supported:
41 52c00a5f bellard
@itemize
42 52c00a5f bellard
@item PC (x86 processor)
43 52c00a5f bellard
@item PREP (PowerPC processor)
44 15a34c63 bellard
@item PowerMac (PowerPC processor, in progress)
45 b756921a bellard
@item Sun4m (Sparc processor, in progress)
46 52c00a5f bellard
@end itemize
47 386405f7 bellard
48 1f673135 bellard
For user emulation, x86, PowerPC, ARM, and SPARC CPUs are supported.
49 0806e3f6 bellard
50 5b9f457a bellard
@chapter Installation
51 5b9f457a bellard
52 15a34c63 bellard
If you want to compile QEMU yourself, see @ref{compilation}.
53 15a34c63 bellard
54 1f673135 bellard
@section Linux
55 1f673135 bellard
56 7c3fc84d bellard
If a precompiled package is available for your distribution - you just
57 7c3fc84d bellard
have to install it. Otherwise, see @ref{compilation}.
58 5b9f457a bellard
59 1f673135 bellard
@section Windows
60 8cd0ac2f bellard
61 15a34c63 bellard
Download the experimental binary installer at
62 15a34c63 bellard
@url{http://www.freeoszoo.org/download.php}.
63 d691f669 bellard
64 1f673135 bellard
@section Mac OS X
65 d691f669 bellard
66 15a34c63 bellard
Download the experimental binary installer at
67 15a34c63 bellard
@url{http://www.freeoszoo.org/download.php}.
68 df0f11a0 bellard
69 52c00a5f bellard
@chapter QEMU PC System emulator invocation
70 1eb20527 bellard
71 0806e3f6 bellard
@section Introduction
72 0806e3f6 bellard
73 0806e3f6 bellard
@c man begin DESCRIPTION
74 0806e3f6 bellard
75 7c3fc84d bellard
The QEMU System emulator simulates the
76 7c3fc84d bellard
following PC peripherials:
77 0806e3f6 bellard
78 0806e3f6 bellard
@itemize @minus
79 15a34c63 bellard
@item 
80 15a34c63 bellard
i440FX host PCI bridge and PIIX3 PCI to ISA bridge
81 0806e3f6 bellard
@item
82 15a34c63 bellard
Cirrus CLGD 5446 PCI VGA card or dummy VGA card with Bochs VESA
83 15a34c63 bellard
extensions (hardware level, including all non standard modes).
84 0806e3f6 bellard
@item
85 0806e3f6 bellard
PS/2 mouse and keyboard
86 0806e3f6 bellard
@item 
87 15a34c63 bellard
2 PCI IDE interfaces with hard disk and CD-ROM support
88 1f673135 bellard
@item
89 1f673135 bellard
Floppy disk
90 0806e3f6 bellard
@item 
91 15a34c63 bellard
NE2000 PCI network adapters
92 0806e3f6 bellard
@item
93 05d5818c bellard
Serial ports
94 05d5818c bellard
@item
95 181f1558 bellard
Soundblaster 16 card
96 0806e3f6 bellard
@end itemize
97 0806e3f6 bellard
98 15a34c63 bellard
QEMU uses the PC BIOS from the Bochs project and the Plex86/Bochs LGPL
99 15a34c63 bellard
VGA BIOS.
100 15a34c63 bellard
101 0806e3f6 bellard
@c man end
102 0806e3f6 bellard
103 1eb20527 bellard
@section Quick Start
104 1eb20527 bellard
105 285dc330 bellard
Download and uncompress the linux image (@file{linux.img}) and type:
106 0806e3f6 bellard
107 0806e3f6 bellard
@example
108 285dc330 bellard
qemu linux.img
109 0806e3f6 bellard
@end example
110 0806e3f6 bellard
111 0806e3f6 bellard
Linux should boot and give you a prompt.
112 0806e3f6 bellard
113 ec410fc9 bellard
@section Invocation
114 ec410fc9 bellard
115 ec410fc9 bellard
@example
116 0806e3f6 bellard
@c man begin SYNOPSIS
117 0806e3f6 bellard
usage: qemu [options] [disk_image]
118 0806e3f6 bellard
@c man end
119 ec410fc9 bellard
@end example
120 ec410fc9 bellard
121 0806e3f6 bellard
@c man begin OPTIONS
122 9d4520d0 bellard
@var{disk_image} is a raw hard disk image for IDE hard disk 0.
123 ec410fc9 bellard
124 ec410fc9 bellard
General options:
125 ec410fc9 bellard
@table @option
126 2be3bc02 bellard
@item -fda file
127 2be3bc02 bellard
@item -fdb file
128 be3edd95 bellard
Use @var{file} as floppy disk 0/1 image (@xref{disk_images}). You can
129 be3edd95 bellard
use the host floppy by using @file{/dev/fd0} as filename.
130 2be3bc02 bellard
131 ec410fc9 bellard
@item -hda file
132 ec410fc9 bellard
@item -hdb file
133 181f1558 bellard
@item -hdc file
134 181f1558 bellard
@item -hdd file
135 2be3bc02 bellard
Use @var{file} as hard disk 0, 1, 2 or 3 image (@xref{disk_images}).
136 1f47a922 bellard
137 181f1558 bellard
@item -cdrom file
138 181f1558 bellard
Use @var{file} as CD-ROM image (you cannot use @option{-hdc} and and
139 be3edd95 bellard
@option{-cdrom} at the same time). You can use the host CD-ROM by
140 be3edd95 bellard
using @file{/dev/cdrom} as filename.
141 181f1558 bellard
142 1f673135 bellard
@item -boot [a|c|d]
143 1f673135 bellard
Boot on floppy (a), hard disk (c) or CD-ROM (d). Hard disk boot is
144 2be3bc02 bellard
the default.
145 1f47a922 bellard
146 181f1558 bellard
@item -snapshot
147 1f47a922 bellard
Write to temporary files instead of disk image files. In this case,
148 1f47a922 bellard
the raw disk image you use is not written back. You can however force
149 1f47a922 bellard
the write back by pressing @key{C-a s} (@xref{disk_images}). 
150 ec410fc9 bellard
151 ec410fc9 bellard
@item -m megs
152 15a34c63 bellard
Set virtual RAM size to @var{megs} megabytes. Default is 128 MB.
153 ec410fc9 bellard
154 0806e3f6 bellard
@item -nographic
155 0806e3f6 bellard
156 0806e3f6 bellard
Normally, QEMU uses SDL to display the VGA output. With this option,
157 0806e3f6 bellard
you can totally disable graphical output so that QEMU is a simple
158 0806e3f6 bellard
command line application. The emulated serial port is redirected on
159 0806e3f6 bellard
the console. Therefore, you can still use QEMU to debug a Linux kernel
160 0806e3f6 bellard
with a serial console.
161 0806e3f6 bellard
162 3d11d0eb bellard
@item -k language
163 3d11d0eb bellard
164 3d11d0eb bellard
Use keyboard layout @var{language} (for example @code{fr} for
165 3d11d0eb bellard
French). This option is only needed where it is not easy to get raw PC
166 3d11d0eb bellard
keycodes (e.g. on Macs or with some X11 servers). You don't need to
167 3d11d0eb bellard
use it on PC/Linux or PC/Windows hosts.
168 3d11d0eb bellard
169 3d11d0eb bellard
The available layouts are:
170 3d11d0eb bellard
@example
171 3d11d0eb bellard
ar  de-ch  es  fo     fr-ca  hu  ja  mk     no  pt-br  sv
172 3d11d0eb bellard
da  en-gb  et  fr     fr-ch  is  lt  nl     pl  ru     th
173 3d11d0eb bellard
de  en-us  fi  fr-be  hr     it  lv  nl-be  pt  sl     tr
174 3d11d0eb bellard
@end example
175 3d11d0eb bellard
176 3d11d0eb bellard
The default is @code{en-us}.
177 3d11d0eb bellard
178 a8c490cd bellard
@item -enable-audio
179 a8c490cd bellard
180 a8c490cd bellard
The SB16 emulation is disabled by default as it may give problems with
181 a8c490cd bellard
Windows. You can enable it manually with this option.
182 a8c490cd bellard
183 15a34c63 bellard
@item -localtime
184 15a34c63 bellard
Set the real time clock to local time (the default is to UTC
185 15a34c63 bellard
time). This option is needed to have correct date in MS-DOS or
186 15a34c63 bellard
Windows.
187 15a34c63 bellard
188 d63d307f bellard
@item -full-screen
189 d63d307f bellard
Start in full screen.
190 d63d307f bellard
191 f7cce898 bellard
@item -pidfile file
192 f7cce898 bellard
Store the QEMU process PID in @var{file}. It is useful if you launch QEMU
193 f7cce898 bellard
from a script.
194 f7cce898 bellard
195 0806e3f6 bellard
@end table
196 0806e3f6 bellard
197 1f673135 bellard
Network options:
198 1f673135 bellard
199 1f673135 bellard
@table @option
200 1f673135 bellard
201 1f673135 bellard
@item -n script      
202 52c00a5f bellard
Set TUN/TAP network init script [default=/etc/qemu-ifup]. This script
203 52c00a5f bellard
is launched to configure the host network interface (usually tun0)
204 1f673135 bellard
corresponding to the virtual NE2000 card.
205 1f673135 bellard
206 1f673135 bellard
@item -macaddr addr   
207 1f673135 bellard
208 1f673135 bellard
Set the mac address of the first interface (the format is
209 1f673135 bellard
aa:bb:cc:dd:ee:ff in hexa). The mac address is incremented for each
210 1f673135 bellard
new network interface.
211 1f673135 bellard
212 52c00a5f bellard
@item -tun-fd fd
213 52c00a5f bellard
Assumes @var{fd} talks to a tap/tun host network interface and use
214 52c00a5f bellard
it. Read @url{http://bellard.org/qemu/tetrinet.html} to have an
215 52c00a5f bellard
example of its use.
216 52c00a5f bellard
217 52c00a5f bellard
@item -user-net 
218 15a34c63 bellard
Use the user mode network stack. This is the default if no tun/tap
219 15a34c63 bellard
network init script is found.
220 52c00a5f bellard
221 9bf05444 bellard
@item -tftp prefix
222 9bf05444 bellard
When using the user mode network stack, activate a built-in TFTP
223 9bf05444 bellard
server. All filenames beginning with @var{prefix} can be downloaded
224 9bf05444 bellard
from the host to the guest using a TFTP client. The TFTP client on the
225 9bf05444 bellard
guest must be configured in binary mode (use the command @code{bin} of
226 9bf05444 bellard
the Unix TFTP client). The host IP address on the guest is as usual
227 9bf05444 bellard
10.0.2.2.
228 9bf05444 bellard
229 2518bd0d bellard
@item -smb dir
230 2518bd0d bellard
When using the user mode network stack, activate a built-in SMB
231 2518bd0d bellard
server so that Windows OSes can access to the host files in @file{dir}
232 2518bd0d bellard
transparently.
233 2518bd0d bellard
234 2518bd0d bellard
In the guest Windows OS, the line:
235 2518bd0d bellard
@example
236 2518bd0d bellard
10.0.2.4 smbserver
237 2518bd0d bellard
@end example
238 2518bd0d bellard
must be added in the file @file{C:\WINDOWS\LMHOSTS} (for windows 9x/Me)
239 2518bd0d bellard
or @file{C:\WINNT\SYSTEM32\DRIVERS\ETC\LMHOSTS} (Windows NT/2000).
240 2518bd0d bellard
241 2518bd0d bellard
Then @file{dir} can be accessed in @file{\\smbserver\qemu}.
242 2518bd0d bellard
243 2518bd0d bellard
Note that a SAMBA server must be installed on the host OS in
244 2518bd0d bellard
@file{/usr/sbin/smbd}. QEMU was tested succesfully with smbd version
245 2518bd0d bellard
2.2.7a from the Red Hat 9.
246 2518bd0d bellard
247 9bf05444 bellard
@item -redir [tcp|udp]:host-port:[guest-host]:guest-port
248 9bf05444 bellard
249 9bf05444 bellard
When using the user mode network stack, redirect incoming TCP or UDP
250 9bf05444 bellard
connections to the host port @var{host-port} to the guest
251 9bf05444 bellard
@var{guest-host} on guest port @var{guest-port}. If @var{guest-host}
252 9bf05444 bellard
is not specified, its value is 10.0.2.15 (default address given by the
253 9bf05444 bellard
built-in DHCP server).
254 9bf05444 bellard
255 9bf05444 bellard
For example, to redirect host X11 connection from screen 1 to guest
256 9bf05444 bellard
screen 0, use the following:
257 9bf05444 bellard
258 9bf05444 bellard
@example
259 9bf05444 bellard
# on the host
260 9bf05444 bellard
qemu -redir tcp:6001::6000 [...]
261 9bf05444 bellard
# this host xterm should open in the guest X11 server
262 9bf05444 bellard
xterm -display :1
263 9bf05444 bellard
@end example
264 9bf05444 bellard
265 9bf05444 bellard
To redirect telnet connections from host port 5555 to telnet port on
266 9bf05444 bellard
the guest, use the following:
267 9bf05444 bellard
268 9bf05444 bellard
@example
269 9bf05444 bellard
# on the host
270 9bf05444 bellard
qemu -redir tcp:5555::23 [...]
271 9bf05444 bellard
telnet localhost 5555
272 9bf05444 bellard
@end example
273 9bf05444 bellard
274 9bf05444 bellard
Then when you use on the host @code{telnet localhost 5555}, you
275 9bf05444 bellard
connect to the guest telnet server.
276 9bf05444 bellard
277 52c00a5f bellard
@item -dummy-net 
278 15a34c63 bellard
Use the dummy network stack: no packet will be received by the network
279 52c00a5f bellard
cards.
280 1f673135 bellard
281 1f673135 bellard
@end table
282 1f673135 bellard
283 1f673135 bellard
Linux boot specific. When using this options, you can use a given
284 1f673135 bellard
Linux kernel without installing it in the disk image. It can be useful
285 1f673135 bellard
for easier testing of various kernels.
286 1f673135 bellard
287 0806e3f6 bellard
@table @option
288 0806e3f6 bellard
289 0806e3f6 bellard
@item -kernel bzImage 
290 0806e3f6 bellard
Use @var{bzImage} as kernel image.
291 0806e3f6 bellard
292 0806e3f6 bellard
@item -append cmdline 
293 0806e3f6 bellard
Use @var{cmdline} as kernel command line
294 0806e3f6 bellard
295 0806e3f6 bellard
@item -initrd file
296 0806e3f6 bellard
Use @var{file} as initial ram disk.
297 0806e3f6 bellard
298 ec410fc9 bellard
@end table
299 ec410fc9 bellard
300 15a34c63 bellard
Debug/Expert options:
301 ec410fc9 bellard
@table @option
302 a0a821a4 bellard
303 a0a821a4 bellard
@item -serial dev
304 a0a821a4 bellard
Redirect the virtual serial port to host device @var{dev}. Available
305 a0a821a4 bellard
devices are:
306 a0a821a4 bellard
@table @code
307 a0a821a4 bellard
@item vc
308 a0a821a4 bellard
Virtual console
309 a0a821a4 bellard
@item pty
310 a0a821a4 bellard
[Linux only] Pseudo TTY (a new PTY is automatically allocated)
311 a0a821a4 bellard
@item null
312 a0a821a4 bellard
void device
313 a0a821a4 bellard
@item stdio
314 a0a821a4 bellard
[Unix only] standard input/output
315 a0a821a4 bellard
@end table
316 a0a821a4 bellard
The default device is @code{vc} in graphical mode and @code{stdio} in
317 a0a821a4 bellard
non graphical mode.
318 a0a821a4 bellard
319 05d5818c bellard
This option can be used several times to simulate up to 4 serials
320 05d5818c bellard
ports.
321 05d5818c bellard
322 a0a821a4 bellard
@item -monitor dev
323 a0a821a4 bellard
Redirect the monitor to host device @var{dev} (same devices as the
324 a0a821a4 bellard
serial port).
325 a0a821a4 bellard
The default device is @code{vc} in graphical mode and @code{stdio} in
326 a0a821a4 bellard
non graphical mode.
327 a0a821a4 bellard
328 ec410fc9 bellard
@item -s
329 0806e3f6 bellard
Wait gdb connection to port 1234 (@xref{gdb_usage}). 
330 ec410fc9 bellard
@item -p port
331 ec410fc9 bellard
Change gdb connection port.
332 52c00a5f bellard
@item -S
333 52c00a5f bellard
Do not start CPU at startup (you must type 'c' in the monitor).
334 ec410fc9 bellard
@item -d             
335 9d4520d0 bellard
Output log in /tmp/qemu.log
336 46d4767d bellard
@item -hdachs c,h,s,[,t]
337 46d4767d bellard
Force hard disk 0 physical geometry (1 <= @var{c} <= 16383, 1 <=
338 46d4767d bellard
@var{h} <= 16, 1 <= @var{s} <= 63) and optionally force the BIOS
339 46d4767d bellard
translation mode (@var{t}=none, lba or auto). Usually QEMU can guess
340 46d4767d bellard
all thoses parameters. This option is useful for old MS-DOS disk
341 46d4767d bellard
images.
342 7c3fc84d bellard
343 15a34c63 bellard
@item -isa
344 15a34c63 bellard
Simulate an ISA-only system (default is PCI system).
345 15a34c63 bellard
@item -std-vga
346 15a34c63 bellard
Simulate a standard VGA card with Bochs VBE extensions (default is
347 15a34c63 bellard
Cirrus Logic GD5446 PCI VGA)
348 d63d307f bellard
@item -loadvm file
349 d63d307f bellard
Start right away with a saved state (@code{loadvm} in monitor)
350 ec410fc9 bellard
@end table
351 ec410fc9 bellard
352 3e11db9a bellard
@c man end
353 3e11db9a bellard
354 3e11db9a bellard
@section Keys
355 3e11db9a bellard
356 3e11db9a bellard
@c man begin OPTIONS
357 3e11db9a bellard
358 a1b74fe8 bellard
During the graphical emulation, you can use the following keys:
359 a1b74fe8 bellard
@table @key
360 f9859310 bellard
@item Ctrl-Alt-f
361 a1b74fe8 bellard
Toggle full screen
362 a0a821a4 bellard
363 f9859310 bellard
@item Ctrl-Alt-n
364 a0a821a4 bellard
Switch to virtual console 'n'. Standard console mappings are:
365 a0a821a4 bellard
@table @emph
366 a0a821a4 bellard
@item 1
367 a0a821a4 bellard
Target system display
368 a0a821a4 bellard
@item 2
369 a0a821a4 bellard
Monitor
370 a0a821a4 bellard
@item 3
371 a0a821a4 bellard
Serial port
372 a1b74fe8 bellard
@end table
373 a1b74fe8 bellard
374 f9859310 bellard
@item Ctrl-Alt
375 a0a821a4 bellard
Toggle mouse and keyboard grab.
376 a0a821a4 bellard
@end table
377 a0a821a4 bellard
378 3e11db9a bellard
In the virtual consoles, you can use @key{Ctrl-Up}, @key{Ctrl-Down},
379 3e11db9a bellard
@key{Ctrl-PageUp} and @key{Ctrl-PageDown} to move in the back log.
380 3e11db9a bellard
381 a0a821a4 bellard
During emulation, if you are using the @option{-nographic} option, use
382 a0a821a4 bellard
@key{Ctrl-a h} to get terminal commands:
383 ec410fc9 bellard
384 ec410fc9 bellard
@table @key
385 a1b74fe8 bellard
@item Ctrl-a h
386 ec410fc9 bellard
Print this help
387 a1b74fe8 bellard
@item Ctrl-a x    
388 ec410fc9 bellard
Exit emulatior
389 a1b74fe8 bellard
@item Ctrl-a s    
390 1f47a922 bellard
Save disk data back to file (if -snapshot)
391 a1b74fe8 bellard
@item Ctrl-a b
392 1f673135 bellard
Send break (magic sysrq in Linux)
393 a1b74fe8 bellard
@item Ctrl-a c
394 1f673135 bellard
Switch between console and monitor
395 a1b74fe8 bellard
@item Ctrl-a Ctrl-a
396 a1b74fe8 bellard
Send Ctrl-a
397 ec410fc9 bellard
@end table
398 0806e3f6 bellard
@c man end
399 0806e3f6 bellard
400 0806e3f6 bellard
@ignore
401 0806e3f6 bellard
402 0806e3f6 bellard
@setfilename qemu 
403 0806e3f6 bellard
@settitle QEMU System Emulator
404 0806e3f6 bellard
405 1f673135 bellard
@c man begin SEEALSO
406 1f673135 bellard
The HTML documentation of QEMU for more precise information and Linux
407 1f673135 bellard
user mode emulator invocation.
408 1f673135 bellard
@c man end
409 1f673135 bellard
410 1f673135 bellard
@c man begin AUTHOR
411 1f673135 bellard
Fabrice Bellard
412 1f673135 bellard
@c man end
413 1f673135 bellard
414 1f673135 bellard
@end ignore
415 1f673135 bellard
416 1f673135 bellard
@end ignore
417 1f673135 bellard
418 1f673135 bellard
@section QEMU Monitor
419 1f673135 bellard
420 1f673135 bellard
The QEMU monitor is used to give complex commands to the QEMU
421 1f673135 bellard
emulator. You can use it to:
422 1f673135 bellard
423 1f673135 bellard
@itemize @minus
424 1f673135 bellard
425 1f673135 bellard
@item
426 1f673135 bellard
Remove or insert removable medias images
427 1f673135 bellard
(such as CD-ROM or floppies)
428 1f673135 bellard
429 1f673135 bellard
@item 
430 1f673135 bellard
Freeze/unfreeze the Virtual Machine (VM) and save or restore its state
431 1f673135 bellard
from a disk file.
432 1f673135 bellard
433 1f673135 bellard
@item Inspect the VM state without an external debugger.
434 1f673135 bellard
435 1f673135 bellard
@end itemize
436 1f673135 bellard
437 1f673135 bellard
@subsection Commands
438 1f673135 bellard
439 1f673135 bellard
The following commands are available:
440 1f673135 bellard
441 1f673135 bellard
@table @option
442 1f673135 bellard
443 1f673135 bellard
@item help or ? [cmd]
444 1f673135 bellard
Show the help for all commands or just for command @var{cmd}.
445 1f673135 bellard
446 1f673135 bellard
@item commit  
447 1f673135 bellard
Commit changes to the disk images (if -snapshot is used)
448 1f673135 bellard
449 1f673135 bellard
@item info subcommand 
450 1f673135 bellard
show various information about the system state
451 1f673135 bellard
452 1f673135 bellard
@table @option
453 1f673135 bellard
@item info network
454 1f673135 bellard
show the network state
455 1f673135 bellard
@item info block
456 1f673135 bellard
show the block devices
457 1f673135 bellard
@item info registers
458 1f673135 bellard
show the cpu registers
459 1f673135 bellard
@item info history
460 1f673135 bellard
show the command line history
461 1f673135 bellard
@end table
462 1f673135 bellard
463 1f673135 bellard
@item q or quit
464 1f673135 bellard
Quit the emulator.
465 1f673135 bellard
466 1f673135 bellard
@item eject [-f] device
467 1f673135 bellard
Eject a removable media (use -f to force it).
468 1f673135 bellard
469 1f673135 bellard
@item change device filename
470 1f673135 bellard
Change a removable media.
471 1f673135 bellard
472 1f673135 bellard
@item screendump filename
473 1f673135 bellard
Save screen into PPM image @var{filename}.
474 1f673135 bellard
475 1f673135 bellard
@item log item1[,...]
476 1f673135 bellard
Activate logging of the specified items to @file{/tmp/qemu.log}.
477 1f673135 bellard
478 1f673135 bellard
@item savevm filename
479 1f673135 bellard
Save the whole virtual machine state to @var{filename}.
480 1f673135 bellard
481 1f673135 bellard
@item loadvm filename
482 1f673135 bellard
Restore the whole virtual machine state from @var{filename}.
483 1f673135 bellard
484 1f673135 bellard
@item stop
485 1f673135 bellard
Stop emulation.
486 1f673135 bellard
487 1f673135 bellard
@item c or cont
488 1f673135 bellard
Resume emulation.
489 1f673135 bellard
490 1f673135 bellard
@item gdbserver [port]
491 1f673135 bellard
Start gdbserver session (default port=1234)
492 1f673135 bellard
493 1f673135 bellard
@item x/fmt addr
494 1f673135 bellard
Virtual memory dump starting at @var{addr}.
495 1f673135 bellard
496 1f673135 bellard
@item xp /fmt addr
497 1f673135 bellard
Physical memory dump starting at @var{addr}.
498 1f673135 bellard
499 1f673135 bellard
@var{fmt} is a format which tells the command how to format the
500 1f673135 bellard
data. Its syntax is: @option{/@{count@}@{format@}@{size@}}
501 1f673135 bellard
502 1f673135 bellard
@table @var
503 1f673135 bellard
@item count 
504 1f673135 bellard
is the number of items to be dumped.
505 1f673135 bellard
506 1f673135 bellard
@item format
507 1f673135 bellard
can be x (hexa), d (signed decimal), u (unsigned decimal), o (octal),
508 1f673135 bellard
c (char) or i (asm instruction).
509 1f673135 bellard
510 1f673135 bellard
@item size
511 52c00a5f bellard
can be b (8 bits), h (16 bits), w (32 bits) or g (64 bits). On x86,
512 52c00a5f bellard
@code{h} or @code{w} can be specified with the @code{i} format to
513 52c00a5f bellard
respectively select 16 or 32 bit code instruction size.
514 1f673135 bellard
515 1f673135 bellard
@end table
516 1f673135 bellard
517 1f673135 bellard
Examples: 
518 1f673135 bellard
@itemize
519 1f673135 bellard
@item
520 1f673135 bellard
Dump 10 instructions at the current instruction pointer:
521 1f673135 bellard
@example 
522 1f673135 bellard
(qemu) x/10i $eip
523 1f673135 bellard
0x90107063:  ret
524 1f673135 bellard
0x90107064:  sti
525 1f673135 bellard
0x90107065:  lea    0x0(%esi,1),%esi
526 1f673135 bellard
0x90107069:  lea    0x0(%edi,1),%edi
527 1f673135 bellard
0x90107070:  ret
528 1f673135 bellard
0x90107071:  jmp    0x90107080
529 1f673135 bellard
0x90107073:  nop
530 1f673135 bellard
0x90107074:  nop
531 1f673135 bellard
0x90107075:  nop
532 1f673135 bellard
0x90107076:  nop
533 1f673135 bellard
@end example
534 1f673135 bellard
535 1f673135 bellard
@item
536 1f673135 bellard
Dump 80 16 bit values at the start of the video memory.
537 1f673135 bellard
@example 
538 1f673135 bellard
(qemu) xp/80hx 0xb8000
539 1f673135 bellard
0x000b8000: 0x0b50 0x0b6c 0x0b65 0x0b78 0x0b38 0x0b36 0x0b2f 0x0b42
540 1f673135 bellard
0x000b8010: 0x0b6f 0x0b63 0x0b68 0x0b73 0x0b20 0x0b56 0x0b47 0x0b41
541 1f673135 bellard
0x000b8020: 0x0b42 0x0b69 0x0b6f 0x0b73 0x0b20 0x0b63 0x0b75 0x0b72
542 1f673135 bellard
0x000b8030: 0x0b72 0x0b65 0x0b6e 0x0b74 0x0b2d 0x0b63 0x0b76 0x0b73
543 1f673135 bellard
0x000b8040: 0x0b20 0x0b30 0x0b35 0x0b20 0x0b4e 0x0b6f 0x0b76 0x0b20
544 1f673135 bellard
0x000b8050: 0x0b32 0x0b30 0x0b30 0x0b33 0x0720 0x0720 0x0720 0x0720
545 1f673135 bellard
0x000b8060: 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720
546 1f673135 bellard
0x000b8070: 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720
547 1f673135 bellard
0x000b8080: 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720
548 1f673135 bellard
0x000b8090: 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720 0x0720
549 1f673135 bellard
@end example
550 1f673135 bellard
@end itemize
551 1f673135 bellard
552 1f673135 bellard
@item p or print/fmt expr
553 1f673135 bellard
554 1f673135 bellard
Print expression value. Only the @var{format} part of @var{fmt} is
555 1f673135 bellard
used.
556 0806e3f6 bellard
557 a3a91a35 bellard
@item sendkey keys
558 a3a91a35 bellard
559 a3a91a35 bellard
Send @var{keys} to the emulator. Use @code{-} to press several keys
560 a3a91a35 bellard
simultaneously. Example:
561 a3a91a35 bellard
@example
562 a3a91a35 bellard
sendkey ctrl-alt-f1
563 a3a91a35 bellard
@end example
564 a3a91a35 bellard
565 a3a91a35 bellard
This command is useful to send keys that your graphical user interface
566 a3a91a35 bellard
intercepts at low level, such as @code{ctrl-alt-f1} in X Window.
567 a3a91a35 bellard
568 15a34c63 bellard
@item system_reset
569 15a34c63 bellard
570 15a34c63 bellard
Reset the system.
571 15a34c63 bellard
572 1f673135 bellard
@end table
573 0806e3f6 bellard
574 1f673135 bellard
@subsection Integer expressions
575 1f673135 bellard
576 1f673135 bellard
The monitor understands integers expressions for every integer
577 1f673135 bellard
argument. You can use register names to get the value of specifics
578 1f673135 bellard
CPU registers by prefixing them with @emph{$}.
579 ec410fc9 bellard
580 1f47a922 bellard
@node disk_images
581 1f47a922 bellard
@section Disk Images
582 1f47a922 bellard
583 acd935ef bellard
Since version 0.6.1, QEMU supports many disk image formats, including
584 acd935ef bellard
growable disk images (their size increase as non empty sectors are
585 acd935ef bellard
written), compressed and encrypted disk images.
586 1f47a922 bellard
587 acd935ef bellard
@subsection Quick start for disk image creation
588 acd935ef bellard
589 acd935ef bellard
You can create a disk image with the command:
590 1f47a922 bellard
@example
591 acd935ef bellard
qemu-img create myimage.img mysize
592 1f47a922 bellard
@end example
593 acd935ef bellard
where @var{myimage.img} is the disk image filename and @var{mysize} is its
594 acd935ef bellard
size in kilobytes. You can add an @code{M} suffix to give the size in
595 acd935ef bellard
megabytes and a @code{G} suffix for gigabytes.
596 acd935ef bellard
597 acd935ef bellard
@xref{qemu_img_invocation} for more information.
598 1f47a922 bellard
599 1f47a922 bellard
@subsection Snapshot mode
600 1f47a922 bellard
601 1f47a922 bellard
If you use the option @option{-snapshot}, all disk images are
602 1f47a922 bellard
considered as read only. When sectors in written, they are written in
603 1f47a922 bellard
a temporary file created in @file{/tmp}. You can however force the
604 acd935ef bellard
write back to the raw disk images by using the @code{commit} monitor
605 acd935ef bellard
command (or @key{C-a s} in the serial console).
606 1f47a922 bellard
607 acd935ef bellard
@node qemu_img_invocation
608 acd935ef bellard
@subsection @code{qemu-img} Invocation
609 1f47a922 bellard
610 acd935ef bellard
@include qemu-img.texi
611 05efe46e bellard
612 9d4fb82e bellard
@section Network emulation
613 9d4fb82e bellard
614 9d4fb82e bellard
QEMU simulates up to 6 networks cards (NE2000 boards). Each card can
615 9d4fb82e bellard
be connected to a specific host network interface.
616 9d4fb82e bellard
617 9d4fb82e bellard
@subsection Using tun/tap network interface
618 9d4fb82e bellard
619 9d4fb82e bellard
This is the standard way to emulate network. QEMU adds a virtual
620 9d4fb82e bellard
network device on your host (called @code{tun0}), and you can then
621 9d4fb82e bellard
configure it as if it was a real ethernet card.
622 9d4fb82e bellard
623 9d4fb82e bellard
As an example, you can download the @file{linux-test-xxx.tar.gz}
624 9d4fb82e bellard
archive and copy the script @file{qemu-ifup} in @file{/etc} and
625 9d4fb82e bellard
configure properly @code{sudo} so that the command @code{ifconfig}
626 9d4fb82e bellard
contained in @file{qemu-ifup} can be executed as root. You must verify
627 9d4fb82e bellard
that your host kernel supports the TUN/TAP network interfaces: the
628 9d4fb82e bellard
device @file{/dev/net/tun} must be present.
629 9d4fb82e bellard
630 9d4fb82e bellard
See @ref{direct_linux_boot} to have an example of network use with a
631 9d4fb82e bellard
Linux distribution.
632 9d4fb82e bellard
633 9d4fb82e bellard
@subsection Using the user mode network stack
634 9d4fb82e bellard
635 443f1376 bellard
By using the option @option{-user-net} or if you have no tun/tap init
636 443f1376 bellard
script, QEMU uses a completely user mode network stack (you don't need
637 443f1376 bellard
root priviledge to use the virtual network). The virtual network
638 443f1376 bellard
configuration is the following:
639 9d4fb82e bellard
640 9d4fb82e bellard
@example
641 9d4fb82e bellard
642 9d4fb82e bellard
QEMU Virtual Machine    <------>  Firewall/DHCP server <-----> Internet
643 9d4fb82e bellard
     (10.0.2.x)            |          (10.0.2.2)
644 9d4fb82e bellard
                           |
645 2518bd0d bellard
                           ---->  DNS server (10.0.2.3)
646 2518bd0d bellard
                           |     
647 2518bd0d bellard
                           ---->  SMB server (10.0.2.4)
648 9d4fb82e bellard
@end example
649 9d4fb82e bellard
650 9d4fb82e bellard
The QEMU VM behaves as if it was behind a firewall which blocks all
651 9d4fb82e bellard
incoming connections. You can use a DHCP client to automatically
652 9d4fb82e bellard
configure the network in the QEMU VM.
653 9d4fb82e bellard
654 9d4fb82e bellard
In order to check that the user mode network is working, you can ping
655 9d4fb82e bellard
the address 10.0.2.2 and verify that you got an address in the range
656 9d4fb82e bellard
10.0.2.x from the QEMU virtual DHCP server.
657 9d4fb82e bellard
658 b415a407 bellard
Note that @code{ping} is not supported reliably to the internet as it
659 b415a407 bellard
would require root priviledges. It means you can only ping the local
660 b415a407 bellard
router (10.0.2.2).
661 b415a407 bellard
662 9bf05444 bellard
When using the built-in TFTP server, the router is also the TFTP
663 9bf05444 bellard
server.
664 9bf05444 bellard
665 9bf05444 bellard
When using the @option{-redir} option, TCP or UDP connections can be
666 9bf05444 bellard
redirected from the host to the guest. It allows for example to
667 9bf05444 bellard
redirect X11, telnet or SSH connections.
668 443f1376 bellard
669 9d4fb82e bellard
@node direct_linux_boot
670 9d4fb82e bellard
@section Direct Linux Boot
671 1f673135 bellard
672 1f673135 bellard
This section explains how to launch a Linux kernel inside QEMU without
673 1f673135 bellard
having to make a full bootable image. It is very useful for fast Linux
674 1f673135 bellard
kernel testing. The QEMU network configuration is also explained.
675 1f673135 bellard
676 1f673135 bellard
@enumerate
677 1f673135 bellard
@item
678 1f673135 bellard
Download the archive @file{linux-test-xxx.tar.gz} containing a Linux
679 1f673135 bellard
kernel and a disk image. 
680 1f673135 bellard
681 1f673135 bellard
@item Optional: If you want network support (for example to launch X11 examples), you
682 1f673135 bellard
must copy the script @file{qemu-ifup} in @file{/etc} and configure
683 1f673135 bellard
properly @code{sudo} so that the command @code{ifconfig} contained in
684 1f673135 bellard
@file{qemu-ifup} can be executed as root. You must verify that your host
685 1f673135 bellard
kernel supports the TUN/TAP network interfaces: the device
686 1f673135 bellard
@file{/dev/net/tun} must be present.
687 1f673135 bellard
688 1f673135 bellard
When network is enabled, there is a virtual network connection between
689 1f673135 bellard
the host kernel and the emulated kernel. The emulated kernel is seen
690 1f673135 bellard
from the host kernel at IP address 172.20.0.2 and the host kernel is
691 1f673135 bellard
seen from the emulated kernel at IP address 172.20.0.1.
692 1f673135 bellard
693 1f673135 bellard
@item Launch @code{qemu.sh}. You should have the following output:
694 1f673135 bellard
695 1f673135 bellard
@example
696 1f673135 bellard
> ./qemu.sh 
697 1f673135 bellard
Connected to host network interface: tun0
698 1f673135 bellard
Linux version 2.4.21 (bellard@voyager.localdomain) (gcc version 3.2.2 20030222 (Red Hat Linux 3.2.2-5)) #5 Tue Nov 11 18:18:53 CET 2003
699 1f673135 bellard
BIOS-provided physical RAM map:
700 1f673135 bellard
 BIOS-e801: 0000000000000000 - 000000000009f000 (usable)
701 1f673135 bellard
 BIOS-e801: 0000000000100000 - 0000000002000000 (usable)
702 1f673135 bellard
32MB LOWMEM available.
703 1f673135 bellard
On node 0 totalpages: 8192
704 1f673135 bellard
zone(0): 4096 pages.
705 1f673135 bellard
zone(1): 4096 pages.
706 1f673135 bellard
zone(2): 0 pages.
707 1f673135 bellard
Kernel command line: root=/dev/hda sb=0x220,5,1,5 ide2=noprobe ide3=noprobe ide4=noprobe ide5=noprobe console=ttyS0
708 1f673135 bellard
ide_setup: ide2=noprobe
709 1f673135 bellard
ide_setup: ide3=noprobe
710 1f673135 bellard
ide_setup: ide4=noprobe
711 1f673135 bellard
ide_setup: ide5=noprobe
712 1f673135 bellard
Initializing CPU#0
713 1f673135 bellard
Detected 2399.621 MHz processor.
714 1f673135 bellard
Console: colour EGA 80x25
715 1f673135 bellard
Calibrating delay loop... 4744.80 BogoMIPS
716 1f673135 bellard
Memory: 28872k/32768k available (1210k kernel code, 3508k reserved, 266k data, 64k init, 0k highmem)
717 1f673135 bellard
Dentry cache hash table entries: 4096 (order: 3, 32768 bytes)
718 1f673135 bellard
Inode cache hash table entries: 2048 (order: 2, 16384 bytes)
719 1f673135 bellard
Mount cache hash table entries: 512 (order: 0, 4096 bytes)
720 1f673135 bellard
Buffer-cache hash table entries: 1024 (order: 0, 4096 bytes)
721 1f673135 bellard
Page-cache hash table entries: 8192 (order: 3, 32768 bytes)
722 1f673135 bellard
CPU: Intel Pentium Pro stepping 03
723 1f673135 bellard
Checking 'hlt' instruction... OK.
724 1f673135 bellard
POSIX conformance testing by UNIFIX
725 1f673135 bellard
Linux NET4.0 for Linux 2.4
726 1f673135 bellard
Based upon Swansea University Computer Society NET3.039
727 1f673135 bellard
Initializing RT netlink socket
728 1f673135 bellard
apm: BIOS not found.
729 1f673135 bellard
Starting kswapd
730 1f673135 bellard
Journalled Block Device driver loaded
731 1f673135 bellard
Detected PS/2 Mouse Port.
732 1f673135 bellard
pty: 256 Unix98 ptys configured
733 1f673135 bellard
Serial driver version 5.05c (2001-07-08) with no serial options enabled
734 1f673135 bellard
ttyS00 at 0x03f8 (irq = 4) is a 16450
735 1f673135 bellard
ne.c:v1.10 9/23/94 Donald Becker (becker@scyld.com)
736 1f673135 bellard
Last modified Nov 1, 2000 by Paul Gortmaker
737 1f673135 bellard
NE*000 ethercard probe at 0x300: 52 54 00 12 34 56
738 1f673135 bellard
eth0: NE2000 found at 0x300, using IRQ 9.
739 1f673135 bellard
RAMDISK driver initialized: 16 RAM disks of 4096K size 1024 blocksize
740 1f673135 bellard
Uniform Multi-Platform E-IDE driver Revision: 7.00beta4-2.4
741 1f673135 bellard
ide: Assuming 50MHz system bus speed for PIO modes; override with idebus=xx
742 1f673135 bellard
hda: QEMU HARDDISK, ATA DISK drive
743 1f673135 bellard
ide0 at 0x1f0-0x1f7,0x3f6 on irq 14
744 1f673135 bellard
hda: attached ide-disk driver.
745 1f673135 bellard
hda: 20480 sectors (10 MB) w/256KiB Cache, CHS=20/16/63
746 1f673135 bellard
Partition check:
747 1f673135 bellard
 hda:
748 1f673135 bellard
Soundblaster audio driver Copyright (C) by Hannu Savolainen 1993-1996
749 1f673135 bellard
NET4: Linux TCP/IP 1.0 for NET4.0
750 1f673135 bellard
IP Protocols: ICMP, UDP, TCP, IGMP
751 1f673135 bellard
IP: routing cache hash table of 512 buckets, 4Kbytes
752 1f673135 bellard
TCP: Hash tables configured (established 2048 bind 4096)
753 1f673135 bellard
NET4: Unix domain sockets 1.0/SMP for Linux NET4.0.
754 1f673135 bellard
EXT2-fs warning: mounting unchecked fs, running e2fsck is recommended
755 1f673135 bellard
VFS: Mounted root (ext2 filesystem).
756 1f673135 bellard
Freeing unused kernel memory: 64k freed
757 1f673135 bellard
 
758 1f673135 bellard
Linux version 2.4.21 (bellard@voyager.localdomain) (gcc version 3.2.2 20030222 (Red Hat Linux 3.2.2-5)) #5 Tue Nov 11 18:18:53 CET 2003
759 1f673135 bellard
 
760 1f673135 bellard
QEMU Linux test distribution (based on Redhat 9)
761 1f673135 bellard
 
762 1f673135 bellard
Type 'exit' to halt the system
763 1f673135 bellard
 
764 1f673135 bellard
sh-2.05b# 
765 1f673135 bellard
@end example
766 1f673135 bellard
767 1f673135 bellard
@item
768 1f673135 bellard
Then you can play with the kernel inside the virtual serial console. You
769 1f673135 bellard
can launch @code{ls} for example. Type @key{Ctrl-a h} to have an help
770 1f673135 bellard
about the keys you can type inside the virtual serial console. In
771 1f673135 bellard
particular, use @key{Ctrl-a x} to exit QEMU and use @key{Ctrl-a b} as
772 1f673135 bellard
the Magic SysRq key.
773 1f673135 bellard
774 1f673135 bellard
@item 
775 1f673135 bellard
If the network is enabled, launch the script @file{/etc/linuxrc} in the
776 1f673135 bellard
emulator (don't forget the leading dot):
777 1f673135 bellard
@example
778 1f673135 bellard
. /etc/linuxrc
779 1f673135 bellard
@end example
780 1f673135 bellard
781 1f673135 bellard
Then enable X11 connections on your PC from the emulated Linux: 
782 1f673135 bellard
@example
783 1f673135 bellard
xhost +172.20.0.2
784 1f673135 bellard
@end example
785 1f673135 bellard
786 1f673135 bellard
You can now launch @file{xterm} or @file{xlogo} and verify that you have
787 1f673135 bellard
a real Virtual Linux system !
788 1f673135 bellard
789 1f673135 bellard
@end enumerate
790 1f673135 bellard
791 1f673135 bellard
NOTES:
792 1f673135 bellard
@enumerate
793 1f673135 bellard
@item 
794 1f673135 bellard
A 2.5.74 kernel is also included in the archive. Just
795 1f673135 bellard
replace the bzImage in qemu.sh to try it.
796 1f673135 bellard
797 1f673135 bellard
@item 
798 1f673135 bellard
In order to exit cleanly from qemu, you can do a @emph{shutdown} inside
799 1f673135 bellard
qemu. qemu will automatically exit when the Linux shutdown is done.
800 1f673135 bellard
801 1f673135 bellard
@item 
802 1f673135 bellard
You can boot slightly faster by disabling the probe of non present IDE
803 1f673135 bellard
interfaces. To do so, add the following options on the kernel command
804 1f673135 bellard
line:
805 1f673135 bellard
@example
806 1f673135 bellard
ide1=noprobe ide2=noprobe ide3=noprobe ide4=noprobe ide5=noprobe
807 1f673135 bellard
@end example
808 1f673135 bellard
809 1f673135 bellard
@item 
810 1f673135 bellard
The example disk image is a modified version of the one made by Kevin
811 1f673135 bellard
Lawton for the plex86 Project (@url{www.plex86.org}).
812 1f673135 bellard
813 1f673135 bellard
@end enumerate
814 1f673135 bellard
815 0806e3f6 bellard
@node gdb_usage
816 da415d54 bellard
@section GDB usage
817 da415d54 bellard
818 da415d54 bellard
QEMU has a primitive support to work with gdb, so that you can do
819 0806e3f6 bellard
'Ctrl-C' while the virtual machine is running and inspect its state.
820 da415d54 bellard
821 9d4520d0 bellard
In order to use gdb, launch qemu with the '-s' option. It will wait for a
822 da415d54 bellard
gdb connection:
823 da415d54 bellard
@example
824 6c9bf893 bellard
> qemu -s -kernel arch/i386/boot/bzImage -hda root-2.4.20.img -append "root=/dev/hda"
825 da415d54 bellard
Connected to host network interface: tun0
826 da415d54 bellard
Waiting gdb connection on port 1234
827 da415d54 bellard
@end example
828 da415d54 bellard
829 da415d54 bellard
Then launch gdb on the 'vmlinux' executable:
830 da415d54 bellard
@example
831 da415d54 bellard
> gdb vmlinux
832 da415d54 bellard
@end example
833 da415d54 bellard
834 da415d54 bellard
In gdb, connect to QEMU:
835 da415d54 bellard
@example
836 6c9bf893 bellard
(gdb) target remote localhost:1234
837 da415d54 bellard
@end example
838 da415d54 bellard
839 da415d54 bellard
Then you can use gdb normally. For example, type 'c' to launch the kernel:
840 da415d54 bellard
@example
841 da415d54 bellard
(gdb) c
842 da415d54 bellard
@end example
843 da415d54 bellard
844 0806e3f6 bellard
Here are some useful tips in order to use gdb on system code:
845 0806e3f6 bellard
846 0806e3f6 bellard
@enumerate
847 0806e3f6 bellard
@item
848 0806e3f6 bellard
Use @code{info reg} to display all the CPU registers.
849 0806e3f6 bellard
@item
850 0806e3f6 bellard
Use @code{x/10i $eip} to display the code at the PC position.
851 0806e3f6 bellard
@item
852 0806e3f6 bellard
Use @code{set architecture i8086} to dump 16 bit code. Then use
853 0806e3f6 bellard
@code{x/10i $cs*16+*eip} to dump the code at the PC position.
854 0806e3f6 bellard
@end enumerate
855 0806e3f6 bellard
856 1a084f3d bellard
@section Target OS specific information
857 1a084f3d bellard
858 1a084f3d bellard
@subsection Linux
859 1a084f3d bellard
860 15a34c63 bellard
To have access to SVGA graphic modes under X11, use the @code{vesa} or
861 15a34c63 bellard
the @code{cirrus} X11 driver. For optimal performances, use 16 bit
862 15a34c63 bellard
color depth in the guest and the host OS.
863 1a084f3d bellard
864 e3371e62 bellard
When using a 2.6 guest Linux kernel, you should add the option
865 e3371e62 bellard
@code{clock=pit} on the kernel command line because the 2.6 Linux
866 e3371e62 bellard
kernels make very strict real time clock checks by default that QEMU
867 e3371e62 bellard
cannot simulate exactly.
868 e3371e62 bellard
869 7c3fc84d bellard
When using a 2.6 guest Linux kernel, verify that the 4G/4G patch is
870 7c3fc84d bellard
not activated because QEMU is slower with this patch. The QEMU
871 7c3fc84d bellard
Accelerator Module is also much slower in this case. Earlier Fedora
872 7c3fc84d bellard
Core 3 Linux kernel (< 2.6.9-1.724_FC3) were known to incorporte this
873 7c3fc84d bellard
patch by default. Newer kernels don't have it.
874 7c3fc84d bellard
875 1a084f3d bellard
@subsection Windows
876 1a084f3d bellard
877 1a084f3d bellard
If you have a slow host, using Windows 95 is better as it gives the
878 1a084f3d bellard
best speed. Windows 2000 is also a good choice.
879 1a084f3d bellard
880 e3371e62 bellard
@subsubsection SVGA graphic modes support
881 e3371e62 bellard
882 e3371e62 bellard
QEMU emulates a Cirrus Logic GD5446 Video
883 15a34c63 bellard
card. All Windows versions starting from Windows 95 should recognize
884 15a34c63 bellard
and use this graphic card. For optimal performances, use 16 bit color
885 15a34c63 bellard
depth in the guest and the host OS.
886 1a084f3d bellard
887 e3371e62 bellard
@subsubsection CPU usage reduction
888 e3371e62 bellard
889 e3371e62 bellard
Windows 9x does not correctly use the CPU HLT
890 15a34c63 bellard
instruction. The result is that it takes host CPU cycles even when
891 15a34c63 bellard
idle. You can install the utility from
892 15a34c63 bellard
@url{http://www.user.cityline.ru/~maxamn/amnhltm.zip} to solve this
893 15a34c63 bellard
problem. Note that no such tool is needed for NT, 2000 or XP.
894 1a084f3d bellard
895 e3371e62 bellard
@subsubsection Windows 2000 disk full problems
896 e3371e62 bellard
897 e3371e62 bellard
Currently (release 0.6.0) QEMU has a bug which gives a @code{disk
898 e3371e62 bellard
full} error during installation of some releases of Windows 2000. The
899 e3371e62 bellard
workaround is to stop QEMU as soon as you notice that your disk image
900 e3371e62 bellard
size is growing too fast (monitor it with @code{ls -ls}). Then
901 e3371e62 bellard
relaunch QEMU to continue the installation. If you still experience
902 e3371e62 bellard
the problem, relaunch QEMU again.
903 e3371e62 bellard
904 e3371e62 bellard
Future QEMU releases are likely to correct this bug.
905 e3371e62 bellard
906 e3371e62 bellard
@subsubsection Windows XP security problems
907 e3371e62 bellard
908 e3371e62 bellard
Some releases of Windows XP install correctly but give a security
909 e3371e62 bellard
error when booting:
910 e3371e62 bellard
@example
911 e3371e62 bellard
A problem is preventing Windows from accurately checking the
912 e3371e62 bellard
license for this computer. Error code: 0x800703e6.
913 e3371e62 bellard
@end example
914 e3371e62 bellard
The only known workaround is to boot in Safe mode
915 e3371e62 bellard
without networking support. 
916 e3371e62 bellard
917 e3371e62 bellard
Future QEMU releases are likely to correct this bug.
918 e3371e62 bellard
919 a0a821a4 bellard
@subsection MS-DOS and FreeDOS
920 a0a821a4 bellard
921 a0a821a4 bellard
@subsubsection CPU usage reduction
922 a0a821a4 bellard
923 a0a821a4 bellard
DOS does not correctly use the CPU HLT instruction. The result is that
924 a0a821a4 bellard
it takes host CPU cycles even when idle. You can install the utility
925 a0a821a4 bellard
from @url{http://www.vmware.com/software/dosidle210.zip} to solve this
926 a0a821a4 bellard
problem.
927 a0a821a4 bellard
928 15a34c63 bellard
@chapter QEMU PowerPC System emulator invocation
929 1a084f3d bellard
930 15a34c63 bellard
Use the executable @file{qemu-system-ppc} to simulate a complete PREP
931 15a34c63 bellard
or PowerMac PowerPC system.
932 1a084f3d bellard
933 15a34c63 bellard
QEMU emulates the following PowerMac peripherials:
934 1a084f3d bellard
935 15a34c63 bellard
@itemize @minus
936 15a34c63 bellard
@item 
937 15a34c63 bellard
UniNorth PCI Bridge 
938 15a34c63 bellard
@item
939 15a34c63 bellard
PCI VGA compatible card with VESA Bochs Extensions
940 15a34c63 bellard
@item 
941 15a34c63 bellard
2 PMAC IDE interfaces with hard disk and CD-ROM support
942 15a34c63 bellard
@item 
943 15a34c63 bellard
NE2000 PCI adapters
944 15a34c63 bellard
@item
945 15a34c63 bellard
Non Volatile RAM
946 15a34c63 bellard
@item
947 15a34c63 bellard
VIA-CUDA with ADB keyboard and mouse.
948 1a084f3d bellard
@end itemize
949 1a084f3d bellard
950 52c00a5f bellard
QEMU emulates the following PREP peripherials:
951 52c00a5f bellard
952 52c00a5f bellard
@itemize @minus
953 52c00a5f bellard
@item 
954 15a34c63 bellard
PCI Bridge
955 15a34c63 bellard
@item
956 15a34c63 bellard
PCI VGA compatible card with VESA Bochs Extensions
957 15a34c63 bellard
@item 
958 52c00a5f bellard
2 IDE interfaces with hard disk and CD-ROM support
959 52c00a5f bellard
@item
960 52c00a5f bellard
Floppy disk
961 52c00a5f bellard
@item 
962 15a34c63 bellard
NE2000 network adapters
963 52c00a5f bellard
@item
964 52c00a5f bellard
Serial port
965 52c00a5f bellard
@item
966 52c00a5f bellard
PREP Non Volatile RAM
967 15a34c63 bellard
@item
968 15a34c63 bellard
PC compatible keyboard and mouse.
969 52c00a5f bellard
@end itemize
970 52c00a5f bellard
971 15a34c63 bellard
QEMU uses the Open Hack'Ware Open Firmware Compatible BIOS available at
972 15a34c63 bellard
@url{http://site.voila.fr/jmayer/OpenHackWare/index.htm}.
973 15a34c63 bellard
974 52c00a5f bellard
You can read the qemu PC system emulation chapter to have more
975 52c00a5f bellard
informations about QEMU usage.
976 52c00a5f bellard
977 15a34c63 bellard
@c man begin OPTIONS
978 15a34c63 bellard
979 15a34c63 bellard
The following options are specific to the PowerPC emulation:
980 15a34c63 bellard
981 15a34c63 bellard
@table @option
982 15a34c63 bellard
983 15a34c63 bellard
@item -prep
984 15a34c63 bellard
Simulate a PREP system (default is PowerMAC)
985 15a34c63 bellard
986 15a34c63 bellard
@item -g WxH[xDEPTH]  
987 15a34c63 bellard
988 15a34c63 bellard
Set the initial VGA graphic mode. The default is 800x600x15.
989 15a34c63 bellard
990 15a34c63 bellard
@end table
991 15a34c63 bellard
992 15a34c63 bellard
@c man end 
993 15a34c63 bellard
994 15a34c63 bellard
995 52c00a5f bellard
More information is available at
996 52c00a5f bellard
@url{http://jocelyn.mayer.free.fr/qemu-ppc/}.
997 52c00a5f bellard
998 e80cfcfc bellard
@chapter Sparc System emulator invocation
999 e80cfcfc bellard
1000 e80cfcfc bellard
Use the executable @file{qemu-system-sparc} to simulate a JavaStation
1001 e80cfcfc bellard
(sun4m architecture). The emulation is far from complete.
1002 e80cfcfc bellard
1003 e80cfcfc bellard
QEMU emulates the following sun4m peripherials:
1004 e80cfcfc bellard
1005 e80cfcfc bellard
@itemize @minus
1006 e80cfcfc bellard
@item 
1007 e80cfcfc bellard
IOMMU
1008 e80cfcfc bellard
@item
1009 e80cfcfc bellard
TCX Frame buffer
1010 e80cfcfc bellard
@item 
1011 e80cfcfc bellard
Lance (Am7990) Ethernet
1012 e80cfcfc bellard
@item
1013 e80cfcfc bellard
Non Volatile RAM M48T08
1014 e80cfcfc bellard
@item
1015 e80cfcfc bellard
Slave I/O: timers, interrupt controllers, Zilog serial ports
1016 e80cfcfc bellard
@end itemize
1017 e80cfcfc bellard
1018 e80cfcfc bellard
QEMU uses the Proll, a PROM replacement available at
1019 e80cfcfc bellard
@url{http://people.redhat.com/zaitcev/linux/}.
1020 e80cfcfc bellard
1021 b756921a bellard
A sample Linux kernel and ram disk image are available on the QEMU web
1022 b756921a bellard
site.
1023 b756921a bellard
1024 1f673135 bellard
@chapter QEMU User space emulator invocation
1025 386405f7 bellard
1026 1f673135 bellard
@section Quick Start
1027 df0f11a0 bellard
1028 1f673135 bellard
In order to launch a Linux process, QEMU needs the process executable
1029 1f673135 bellard
itself and all the target (x86) dynamic libraries used by it. 
1030 386405f7 bellard
1031 1f673135 bellard
@itemize
1032 386405f7 bellard
1033 1f673135 bellard
@item On x86, you can just try to launch any process by using the native
1034 1f673135 bellard
libraries:
1035 386405f7 bellard
1036 1f673135 bellard
@example 
1037 1f673135 bellard
qemu-i386 -L / /bin/ls
1038 1f673135 bellard
@end example
1039 386405f7 bellard
1040 1f673135 bellard
@code{-L /} tells that the x86 dynamic linker must be searched with a
1041 1f673135 bellard
@file{/} prefix.
1042 386405f7 bellard
1043 1f673135 bellard
@item Since QEMU is also a linux process, you can launch qemu with qemu (NOTE: you can only do that if you compiled QEMU from the sources):
1044 386405f7 bellard
1045 1f673135 bellard
@example 
1046 1f673135 bellard
qemu-i386 -L / qemu-i386 -L / /bin/ls
1047 1f673135 bellard
@end example
1048 386405f7 bellard
1049 1f673135 bellard
@item On non x86 CPUs, you need first to download at least an x86 glibc
1050 1f673135 bellard
(@file{qemu-runtime-i386-XXX-.tar.gz} on the QEMU web page). Ensure that
1051 1f673135 bellard
@code{LD_LIBRARY_PATH} is not set:
1052 df0f11a0 bellard
1053 1f673135 bellard
@example
1054 1f673135 bellard
unset LD_LIBRARY_PATH 
1055 1f673135 bellard
@end example
1056 1eb87257 bellard
1057 1f673135 bellard
Then you can launch the precompiled @file{ls} x86 executable:
1058 1eb87257 bellard
1059 1f673135 bellard
@example
1060 1f673135 bellard
qemu-i386 tests/i386/ls
1061 1f673135 bellard
@end example
1062 1f673135 bellard
You can look at @file{qemu-binfmt-conf.sh} so that
1063 1f673135 bellard
QEMU is automatically launched by the Linux kernel when you try to
1064 1f673135 bellard
launch x86 executables. It requires the @code{binfmt_misc} module in the
1065 1f673135 bellard
Linux kernel.
1066 1eb87257 bellard
1067 1f673135 bellard
@item The x86 version of QEMU is also included. You can try weird things such as:
1068 1f673135 bellard
@example
1069 1f673135 bellard
qemu-i386 /usr/local/qemu-i386/bin/qemu-i386 /usr/local/qemu-i386/bin/ls-i386
1070 1f673135 bellard
@end example
1071 1eb20527 bellard
1072 1f673135 bellard
@end itemize
1073 1eb20527 bellard
1074 1f673135 bellard
@section Wine launch
1075 1eb20527 bellard
1076 1f673135 bellard
@itemize
1077 386405f7 bellard
1078 1f673135 bellard
@item Ensure that you have a working QEMU with the x86 glibc
1079 1f673135 bellard
distribution (see previous section). In order to verify it, you must be
1080 1f673135 bellard
able to do:
1081 386405f7 bellard
1082 1f673135 bellard
@example
1083 1f673135 bellard
qemu-i386 /usr/local/qemu-i386/bin/ls-i386
1084 1f673135 bellard
@end example
1085 386405f7 bellard
1086 1f673135 bellard
@item Download the binary x86 Wine install
1087 1f673135 bellard
(@file{qemu-XXX-i386-wine.tar.gz} on the QEMU web page). 
1088 386405f7 bellard
1089 1f673135 bellard
@item Configure Wine on your account. Look at the provided script
1090 1f673135 bellard
@file{/usr/local/qemu-i386/bin/wine-conf.sh}. Your previous
1091 1f673135 bellard
@code{$@{HOME@}/.wine} directory is saved to @code{$@{HOME@}/.wine.org}.
1092 386405f7 bellard
1093 1f673135 bellard
@item Then you can try the example @file{putty.exe}:
1094 386405f7 bellard
1095 1f673135 bellard
@example
1096 1f673135 bellard
qemu-i386 /usr/local/qemu-i386/wine/bin/wine /usr/local/qemu-i386/wine/c/Program\ Files/putty.exe
1097 1f673135 bellard
@end example
1098 386405f7 bellard
1099 1f673135 bellard
@end itemize
1100 fd429f2f bellard
1101 1f673135 bellard
@section Command line options
1102 1eb20527 bellard
1103 1f673135 bellard
@example
1104 1f673135 bellard
usage: qemu-i386 [-h] [-d] [-L path] [-s size] program [arguments...]
1105 1f673135 bellard
@end example
1106 1eb20527 bellard
1107 1f673135 bellard
@table @option
1108 1f673135 bellard
@item -h
1109 1f673135 bellard
Print the help
1110 1f673135 bellard
@item -L path   
1111 1f673135 bellard
Set the x86 elf interpreter prefix (default=/usr/local/qemu-i386)
1112 1f673135 bellard
@item -s size
1113 1f673135 bellard
Set the x86 stack size in bytes (default=524288)
1114 386405f7 bellard
@end table
1115 386405f7 bellard
1116 1f673135 bellard
Debug options:
1117 386405f7 bellard
1118 1f673135 bellard
@table @option
1119 1f673135 bellard
@item -d
1120 1f673135 bellard
Activate log (logfile=/tmp/qemu.log)
1121 1f673135 bellard
@item -p pagesize
1122 1f673135 bellard
Act as if the host page size was 'pagesize' bytes
1123 1f673135 bellard
@end table
1124 386405f7 bellard
1125 15a34c63 bellard
@node compilation
1126 15a34c63 bellard
@chapter Compilation from the sources
1127 15a34c63 bellard
1128 7c3fc84d bellard
@section Linux/Unix
1129 7c3fc84d bellard
1130 7c3fc84d bellard
@subsection Compilation
1131 7c3fc84d bellard
1132 7c3fc84d bellard
First you must decompress the sources:
1133 7c3fc84d bellard
@example
1134 7c3fc84d bellard
cd /tmp
1135 7c3fc84d bellard
tar zxvf qemu-x.y.z.tar.gz
1136 7c3fc84d bellard
cd qemu-x.y.z
1137 7c3fc84d bellard
@end example
1138 7c3fc84d bellard
1139 7c3fc84d bellard
Then you configure QEMU and build it (usually no options are needed):
1140 7c3fc84d bellard
@example
1141 7c3fc84d bellard
./configure
1142 7c3fc84d bellard
make
1143 7c3fc84d bellard
@end example
1144 7c3fc84d bellard
1145 7c3fc84d bellard
Then type as root user:
1146 7c3fc84d bellard
@example
1147 7c3fc84d bellard
make install
1148 7c3fc84d bellard
@end example
1149 7c3fc84d bellard
to install QEMU in @file{/usr/local}.
1150 7c3fc84d bellard
1151 7c3fc84d bellard
@subsection Tested tool versions
1152 7c3fc84d bellard
1153 7c3fc84d bellard
In order to compile QEMU succesfully, it is very important that you
1154 7c3fc84d bellard
have the right tools. The most important one is gcc. I cannot guaranty
1155 7c3fc84d bellard
that QEMU works if you do not use a tested gcc version. Look at
1156 7c3fc84d bellard
'configure' and 'Makefile' if you want to make a different gcc
1157 7c3fc84d bellard
version work.
1158 7c3fc84d bellard
1159 7c3fc84d bellard
@example
1160 7c3fc84d bellard
host      gcc      binutils      glibc    linux       distribution
1161 7c3fc84d bellard
----------------------------------------------------------------------
1162 7c3fc84d bellard
x86       3.2      2.13.2        2.1.3    2.4.18
1163 7c3fc84d bellard
          2.96     2.11.93.0.2   2.2.5    2.4.18      Red Hat 7.3
1164 7c3fc84d bellard
          3.2.2    2.13.90.0.18  2.3.2    2.4.20      Red Hat 9
1165 7c3fc84d bellard
1166 7c3fc84d bellard
PowerPC   3.3 [4]  2.13.90.0.18  2.3.1    2.4.20briq
1167 7c3fc84d bellard
          3.2
1168 7c3fc84d bellard
1169 7c3fc84d bellard
Alpha     3.3 [1]  2.14.90.0.4   2.2.5    2.2.20 [2]  Debian 3.0
1170 7c3fc84d bellard
1171 7c3fc84d bellard
Sparc32   2.95.4   2.12.90.0.1   2.2.5    2.4.18      Debian 3.0
1172 7c3fc84d bellard
1173 7c3fc84d bellard
ARM       2.95.4   2.12.90.0.1   2.2.5    2.4.9 [3]   Debian 3.0
1174 7c3fc84d bellard
1175 7c3fc84d bellard
[1] On Alpha, QEMU needs the gcc 'visibility' attribute only available
1176 7c3fc84d bellard
    for gcc version >= 3.3.
1177 7c3fc84d bellard
[2] Linux >= 2.4.20 is necessary for precise exception support
1178 7c3fc84d bellard
    (untested).
1179 7c3fc84d bellard
[3] 2.4.9-ac10-rmk2-np1-cerf2
1180 7c3fc84d bellard
1181 7c3fc84d bellard
[4] gcc 2.95.x generates invalid code when using too many register
1182 7c3fc84d bellard
variables. You must use gcc 3.x on PowerPC.
1183 7c3fc84d bellard
@end example
1184 15a34c63 bellard
1185 15a34c63 bellard
@section Windows
1186 15a34c63 bellard
1187 15a34c63 bellard
@itemize
1188 15a34c63 bellard
@item Install the current versions of MSYS and MinGW from
1189 15a34c63 bellard
@url{http://www.mingw.org/}. You can find detailed installation
1190 15a34c63 bellard
instructions in the download section and the FAQ.
1191 15a34c63 bellard
1192 15a34c63 bellard
@item Download 
1193 15a34c63 bellard
the MinGW development library of SDL 1.2.x
1194 15a34c63 bellard
(@file{SDL-devel-1.2.x-mingw32.tar.gz}) from
1195 15a34c63 bellard
@url{http://www.libsdl.org}. Unpack it in a temporary place, and
1196 15a34c63 bellard
unpack the archive @file{i386-mingw32msvc.tar.gz} in the MinGW tool
1197 15a34c63 bellard
directory. Edit the @file{sdl-config} script so that it gives the
1198 15a34c63 bellard
correct SDL directory when invoked.
1199 15a34c63 bellard
1200 15a34c63 bellard
@item Extract the current version of QEMU.
1201 15a34c63 bellard
 
1202 15a34c63 bellard
@item Start the MSYS shell (file @file{msys.bat}).
1203 15a34c63 bellard
1204 15a34c63 bellard
@item Change to the QEMU directory. Launch @file{./configure} and 
1205 15a34c63 bellard
@file{make}.  If you have problems using SDL, verify that
1206 15a34c63 bellard
@file{sdl-config} can be launched from the MSYS command line.
1207 15a34c63 bellard
1208 15a34c63 bellard
@item You can install QEMU in @file{Program Files/Qemu} by typing 
1209 15a34c63 bellard
@file{make install}. Don't forget to copy @file{SDL.dll} in
1210 15a34c63 bellard
@file{Program Files/Qemu}.
1211 15a34c63 bellard
1212 15a34c63 bellard
@end itemize
1213 15a34c63 bellard
1214 15a34c63 bellard
@section Cross compilation for Windows with Linux
1215 15a34c63 bellard
1216 15a34c63 bellard
@itemize
1217 15a34c63 bellard
@item
1218 15a34c63 bellard
Install the MinGW cross compilation tools available at
1219 15a34c63 bellard
@url{http://www.mingw.org/}.
1220 15a34c63 bellard
1221 15a34c63 bellard
@item 
1222 15a34c63 bellard
Install the Win32 version of SDL (@url{http://www.libsdl.org}) by
1223 15a34c63 bellard
unpacking @file{i386-mingw32msvc.tar.gz}. Set up the PATH environment
1224 15a34c63 bellard
variable so that @file{i386-mingw32msvc-sdl-config} can be launched by
1225 15a34c63 bellard
the QEMU configuration script.
1226 15a34c63 bellard
1227 15a34c63 bellard
@item 
1228 15a34c63 bellard
Configure QEMU for Windows cross compilation:
1229 15a34c63 bellard
@example
1230 15a34c63 bellard
./configure --enable-mingw32
1231 15a34c63 bellard
@end example
1232 15a34c63 bellard
If necessary, you can change the cross-prefix according to the prefix
1233 15a34c63 bellard
choosen for the MinGW tools with --cross-prefix. You can also use
1234 15a34c63 bellard
--prefix to set the Win32 install path.
1235 15a34c63 bellard
1236 15a34c63 bellard
@item You can install QEMU in the installation directory by typing 
1237 15a34c63 bellard
@file{make install}. Don't forget to copy @file{SDL.dll} in the
1238 15a34c63 bellard
installation directory. 
1239 15a34c63 bellard
1240 15a34c63 bellard
@end itemize
1241 15a34c63 bellard
1242 15a34c63 bellard
Note: Currently, Wine does not seem able to launch
1243 15a34c63 bellard
QEMU for Win32.
1244 15a34c63 bellard
1245 15a34c63 bellard
@section Mac OS X
1246 15a34c63 bellard
1247 15a34c63 bellard
The Mac OS X patches are not fully merged in QEMU, so you should look
1248 15a34c63 bellard
at the QEMU mailing list archive to have all the necessary
1249 15a34c63 bellard
information.