Use when setting up comprehensive QEMU debugging for Breenix - investigating interrupt handling bugs, debugging memory management issues, analyzing boot sequence problems, tracing hardware...
This skill provides comprehensive QEMU debugging capabilities for Breenix kernel development, including live inspection, detailed logging, and monitor access.
Invoke this skill when:
For interrupt-related issues (context switches, timer behavior, IRQ handling):
BREENIX_QEMU_LOG_PATH=/tmp/breenix-debug.log \
BREENIX_QEMU_DEBUG_FLAGS="int,cpu_reset,guest_errors" \
BREENIX_QEMU_MONITOR=tcp \
cargo run --release --bin qemu-uefi -- -serial stdio -display none
This enables:
int: Log all interrupts (IRQ delivery, exceptions, traps)cpu_reset: Track CPU resets and initializationguest_errors: Capture guest OS errors (page faults, invalid ops, etc.)For memory allocation, paging, or MMU issues:
BREENIX_QEMU_LOG_PATH=/tmp/breenix-memory.log \
BREENIX_QEMU_DEBUG_FLAGS="mmu,guest_errors,page" \
BREENIX_QEMU_MONITOR=tcp \
cargo run --release --bin qemu-uefi -- -serial stdio -display none
This enables:
mmu: Memory Management Unit operationspage: Page table walks and TLB operationsguest_errors: Page faults and access violationsFor boot hangs, firmware issues, or early initialization problems:
BREENIX_QEMU_DEBUGCON_FILE=/tmp/ovmf-debug.log \
BREENIX_QEMU_LOG_PATH=/tmp/breenix-boot.log \
BREENIX_QEMU_DEBUG_FLAGS="guest_errors,cpu_reset" \
BREENIX_QEMU_MONITOR=tcp \
cargo run --release --bin qemu-uefi -- -serial stdio -display none
This captures:
For register corruption, flag issues, or instruction tracing:
BREENIX_QEMU_LOG_PATH=/tmp/breenix-cpu.log \
BREENIX_QEMU_DEBUG_FLAGS="cpu,in_asm,int,guest_errors" \
BREENIX_QEMU_MONITOR=tcp \
cargo run --release --bin qemu-uefi -- -serial stdio -display none
WARNING: This generates MASSIVE logs (100+ MB/second). Use only for targeted debugging:
cpu: Dump CPU state after each instructionin_asm: Show instruction disassemblyThe monitor allows live inspection of the running kernel without stopping execution.
BREENIX_QEMU_MONITOR=tcp cargo run --release --bin qemu-uefi
Then in another terminal:
telnet localhost 4444
BREENIX_QEMU_MONITOR=stdio cargo run --release --bin qemu-uefi
WARNING: Stdio monitor mixes with kernel output. Use TCP for cleaner separation.
Once connected to the monitor, useful commands:
info registers # Show all CPU registers
info registers -a # Show all registers including hidden state
info cpus # List all virtual CPUs
info fpu # Show FPU registers
info idt # Show Interrupt Descriptor Table
info gdt # Show Global Descriptor Table
info mem # Show virtual memory mappings
info tlb # Show TLB entries
x/10i $rip # Disassemble 10 instructions at current RIP
x/32xb 0xdeadbeef # Dump 32 bytes at address in hex
xp/10gx 0xdeadbeef # Dump 10 8-byte values (physical address)
info pic # Show PIC (legacy interrupt controller) state
info ioapic # Show I/O APIC state
info lapic # Show Local APIC state
info qtree # Show device tree (find timer devices)
stop # Pause execution
cont # Resume execution
system_reset # Reset the system
quit # Exit QEMU
Set via BREENIX_QEMU_DEBUG_FLAGS (comma-separated):
guest_errors: Guest OS errors (page faults, invalid ops) - Start hereunimp: Unimplemented device/feature accessint: Interrupt delivery and exceptionscpu_reset: CPU initialization and resetsmmu: MMU operations (PT walks, TLB fills)page: Page table operationspcall: Protected mode call gatescpu: Full CPU state after each instructionin_asm: Disassembly of executed instructionsexec: Basic execution tracenochain: Disable TB chainingioport: I/O port access (useful for timer/PIC debugging)pci: PCI configuration space accessgrep -A5 "exception\|interrupt\|IRQ" /tmp/breenix-debug.log
Look for:
grep -E "APIC|timer|IRQ 0|IRQ 32" /tmp/breenix-debug.log
Look for:
grep -E "page fault|#PF|CR3|MMU" /tmp/breenix-memory.log
Look for:
tail -f /tmp/ovmf-debug.log # Watch firmware output
grep "cpu_reset\|triple fault" /tmp/breenix-boot.log
Look for:
BREENIX_QEMU_LOG_PATH=/tmp/debug.log \
BREENIX_QEMU_DEBUG_FLAGS="int,guest_errors" \
BREENIX_QEMU_MONITOR=tcp \
cargo run --release --bin qemu-uefi -- -serial stdio
telnet localhost 4444
info lapic
Look for:
info pic
info ioapic
Verify IRQ 0 (PIT) or IRQ 32 (APIC timer) is not masked.
grep "IRQ.*timer\|exception 32" /tmp/debug.log | less
info idt
Verify entry 32 (or appropriate vector) has valid handler address.
| Variable | Values | Purpose |
|---|---|---|
BREENIX_QEMU_LOG_PATH |
File path | Destination for QEMU debug logs |
BREENIX_QEMU_DEBUG_FLAGS |
Comma-separated flags | Enable specific QEMU logging (see flags above) |
BREENIX_QEMU_MONITOR |
none/stdio/tcp |
Monitor interface (default: none) |
BREENIX_QEMU_DEBUGCON_FILE |
File path | Capture firmware debug console (0x402) |
BREENIX_QEMU_DEBUGCON |
1 |
Route debug console to stdio |
BREENIX_VISUAL_TEST |
1 |
Show QEMU window (for visual debugging) |
BREENIX_QEMU_STORAGE |
ide/virtio |
Storage controller type |
BREENIX_GDB |
1 |
Enable GDB server on localhost:1234 |
BREENIX_QEMU_MONITOR=tcpguest_errors,int, not cpu,in_asmcpu flag can fill GB in seconds# Start debugging session (interrupt focus)
BREENIX_QEMU_LOG_PATH=/tmp/debug.log \
BREENIX_QEMU_DEBUG_FLAGS="int,guest_errors" \
BREENIX_QEMU_MONITOR=tcp \
cargo run --release --bin qemu-uefi -- -serial stdio
# Connect to monitor
telnet localhost 4444
# Essential monitor commands
info registers # CPU state
info lapic # Timer and interrupts
x/10i $rip # Disassemble at current position
info mem # Virtual memory map
# Analyze logs
grep -A5 "exception\|IRQ" /tmp/debug.log
guest_errors,int loggingBREENIX_GDB=1) is complementary; use for source-level debugging