The monitor

QEMU's human monitor: every command and info subcommand, answered in QEMU's words, at the (wemu) prompt.

The human monitor (HMP) is QEMU's text console for a running machine. Every command and info subcommand of QEMU 11.1 is known; this page lists what each does here.

Opening the monitor

  • In a terminal: with -nographic, press Ctrl+A then c to switch between the guest's console and the monitor. -monitor stdio puts the monitor on the terminal from the start. The prompt is (wemu).
  • From JavaScript: vm.hmp(line) runs one command and resolves with its output.
  • Over QMP: human-monitor-command with {"command-line": "info status"}.
(wemu) info status
VM status: running
(wemu) savevm clean
(wemu) x /4xg $sp

help (or ?) lists every command with a one-line description; info alone lists the subcommands.

Note Leave a space between a command and its format: x /8xg $sp, not x/8xg $sp.

Run control

CommandDescription
stop, sPause the machine.
cont, cResume it.
system_resetReset it.
system_powerdownPress the power button.
quit, qStop and release the machine.

Snapshots and migration

CommandDescription
savevm TAGSave the whole machine under TAG.
loadvm TAGRestore it.
delvm TAGDelete it.
info snapshotsList the snapshots.
migrate [-d] file:PATHSave the machine's state to a file. -d is accepted; the command returns when the file is written either way.
migrate_incoming file:PATHLoad a state into a machine started with -incoming defer.
migrate_set_capability CAP on|off, migrate_set_parameter NAME VALUEAccepted and stored.

See Snapshots.

Memory and registers

x and xp

x /FMT ADDRESS      guest virtual memory, as core 0 sees it now
xp /FMT ADDRESS     guest physical memory (RAM)

FMT is /[count][format][size]:

PartValuesDefault
counthow many units1
formatx hex, d signed decimal, u unsigned decimal, o octal, c character, i instruction wordsx
sizeb 1 byte, h 2, w 4, g 8w

The last format used is remembered. Rows hold 8 bytes for byte units and 16 bytes otherwise; a row that can't be read prints Cannot access memory and ends the dump.

(wemu) xp /4xw 0x40000000     # four 32-bit words at the start of RAM, in hex
(wemu) x /8xb $pc             # eight bytes at the current instruction
(wemu) x /2dg $sp             # two 64-bit signed values on the stack

Note There is no disassembler: /i prints each instruction as its 32-bit word.

print /FMT EXPRESSION

Evaluates an expression and prints it in hex (or the given format). Expressions take numbers (0x… hex, a leading 0 for octal, decimal), the registers $pc, $sp, $x0 to $x30 and $el, parentheses, and C's operators + - * / % & | ^ ~ << >>.

(wemu) p $sp + 0x10           # an address, in hex
(wemu) p /d $x0               # a register, in decimal

Other memory commands

CommandDescription
info registersCore 0's X0 to X30.
gva2gpa ADDRESSTranslate a virtual address to a physical one.
sum ADDRESS SIZEA checksum of physical memory.
memsave ADDRESS SIZE FILESave virtual memory to a file.
pmemsave ADDRESS SIZE FILESave physical memory to a file.
dump-guest-memory FILEAn ELF core of the guest's RAM. -p (a paging dump) is refused: paging dumps are not available here.
dumpdtb FILEThe device tree the guest booted with.
info mem, info mtreeThe RAM's address range.

Input and display

CommandDescription
sendkey KEYS [HOLD_MS]Press keys together, joined by -: sendkey ctrl-alt-delete.
mouse_move DX DY [DZ]Move the pointer; DZ turns the wheel.
mouse_button STATESet the buttons: 1 left, 2 middle, 4 right.
screendump FILE [-f png]Save the screen as PPM, or PNG.
info miceThe pointing devices.

Devices

CommandDescription
info blockThe disks.
info blockstatsDisk counters.
info networkThe network cards and their backends.
set_link NAME on|offA network card's link.
info usbThe USB devices.
info pciThe PCI functions.
info chardevThe character devices.
ringbuf_write DEVICE DATA, ringbuf_read DEVICE SIZEA ring-buffer console.
info qtree, info qom-tree, qom-list, qom-getThe device tree.
info virtioThe virtio devices.

Sound

CommandDescription
wavcapture PATH [FREQUENCY [BITS [CHANNELS]]]Record what the guest plays to a WAV file.
stopcaptureStop recording and write the file.
info captureThe recording in progress.

Information

SubcommandShows
info statusThe run state.
info version11.1.50 (warm64 0.1.0)
info name, info uuidThe -name and -uuid.
info cpusThe cores.
info kvmkvm support: disabled
info acceltcg
info jitThe JIT's counters.
info irq, info picThe interrupt controller.
info romsThe kernel image loaded.
info migrateThe last migration.
info memory_size_summaryThe RAM size.

Every command

Every command and alias of QEMU 11.1's monitor is known. Those not described above:

More commands that work

CommandDescription
help [COMMAND], ?List the commands.
cpu INDEXChoose the CPU the memory commands use. Accepted; they use core 0.
gpa2hva ADDRESSWhere a physical address lies in the machine's RAM.
i /FMT PORT, o /FMT PORT VALUERead and write an I/O port. The board has no I/O port space, so reads return all ones.
mouse_set INDEXChoose the pointing device. There is one.
chardev-send-break IDSend a serial break.
announce_selfAnnounce the network cards.
migrate_cancelCancel a migration.
log ITEMS, logfile FILE, trace-file, one-insn-per-tb, sync-profileAccepted, with no effect.
watchdog_action ACTION, migration_mode MODE, calc_dirty_rate, nbd_server_stop, clearAccepted, with no effect.

Commands refused

These answer as QEMU does on a machine without the feature:

CommandsWhy
device_add, device_del, drive_add, drive_del, netdev_add, netdev_del, object_add, object_del, chardev-add, chardev-change, chardev-removeNo hot-plug: name devices on the command line.
eject [-f] DEVICE, changeDisks aren't removable, with or without -f.
block_resize, block_set_io_throttleDisks are fixed while the machine runs.
commit, block_stream, snapshot_blkdev, snapshot_blkdev_internal, snapshot_delete_blkdev_internal, drive_mirror, drive_backupRaw images have no backing files, internal snapshots or jobs.
block_job_set_speed, block_job_cancel, block_job_complete, block_job_pause, block_job_resumeNo block jobs.
nbd_server_start, nbd_server_add, nbd_server_removeNo NBD server.
wemu-io, qemu-ioThe disks are the host's images.
migrate_continue, migrate_recover, migrate_pause, migrate_start_postcopyNo postcopy migration.
system_wakeupGuests can't suspend here.
nmiThe machine has no NMIs.
gpa2hpaThe host is WebAssembly: there's no host physical address.
hostfwd_add, hostfwd_removeThe user network has no port forwarding.
set_password, expire_password, client_migrate_infoNo VNC or SPICE.
gdbserverNo gdb stub.
replay_break, replay_delete_break, replay_seekRecord and replay are off.
set_vcpu_dirty_limit, cancel_vcpu_dirty_limitNeeds KVM.
getfd, closefdNo file descriptors are passed to the monitor.
trace-event NAME on|offNo trace events: No trace events found matching 'NAME'.
qom-setProperties are read-only.
boot_setThe boot order can't change while running.
balloonNo balloon device.
exit_preconfigOnly in QEMU's preconfig state.
pcie_aer_inject_error, mce, dump-skeys, x_colo_lost_heartbeat, xen-event-inject, xen-event-listOther platforms' and features' commands.

Every info subcommand

SubcommandShows
info status, info version, info name, info uuidThe run state, version, name and UUID.
info cpus, info hotpluggable-cpusThe cores.
info registersCore 0's X0 to X30.
info kvm, info accel, info acceleratorskvm support: disabled; tcg.
info jitThe JIT's counters.
info irq, info picThe interrupt controller.
info mem, info mtree, info ramblock, info memory_size_summaryThe RAM.
info numa0 nodes
info romsThe kernel image loaded.
info block, info blockstats, info block-jobsThe disks, their counters, and (none) block jobs.
info network, info usernetThe network cards and the user network.
info usb, info pci, info virtio, info miceThe devices.
info chardevThe character devices.
info qtree, info qdm, info qom-treeThe device tree, the device models, the object tree.
info snapshotsThe snapshots.
info migrate, info migrate_capabilities, info migrate_parametersThe last migration and its settings.
info dumpThe last dump-guest-memory.
info captureThe sound recording in progress.
info vnc, info spiceServer: disabled
info tpmTPM device not supported
info replayRecord/replay is not active
info dirty_rate, info vcpu_dirty_limitNot measured.
info sync-profilesync-profile is not enabled
info history, info tlb, info lapic, info usbhost, info trace-events, info memdev, info memory-devices, info iothreads, info stats, info cryptodev, info rocker-portsEmpty: the machine has none.
info sev, info sgx, info viaSEV is not available on this machine, and likewise.
info balloon, info firmware-logRefused: no balloon device, no firmware log.
info vm-generation-idRefused: VM Generation ID device not found.
info rocker, info rocker-of-dpa-flows, info rocker-of-dpa-groupsRefused: rocker NAME not found.
info virtio-status, info virtio-queue-status, info virtio-vhost-queue-status, info virtio-queue-elementRefused: Path PATH is not a VirtIODevice.
info skeys, info cmmaRefused: this is only available on s390x guests.

See also