The monitor
QEMU's human monitor: every command and info subcommand, answered in QEMU's words, at the (wemu) prompt.
The human monitor (HMP) is QEMU's text console for a running machine. Every command and info subcommand of QEMU 11.1 is known; this page lists what each does here.
Opening the monitor
- In a terminal: with
-nographic, press Ctrl+A then c to switch between the guest's console and the monitor.-monitor stdioputs the monitor on the terminal from the start. The prompt is(wemu). - From JavaScript:
vm.hmp(line)runs one command and resolves with its output. - Over QMP:
human-monitor-commandwith{"command-line": "info status"}.
(wemu) info status
VM status: running
(wemu) savevm clean
(wemu) x /4xg $sphelp (or ?) lists every command with a one-line description; info alone lists the subcommands.
Note Leave a space between a command and its format: x /8xg $sp, not x/8xg $sp.
Run control
| Command | Description |
|---|---|
stop, s | Pause the machine. |
cont, c | Resume it. |
system_reset | Reset it. |
system_powerdown | Press the power button. |
quit, q | Stop and release the machine. |
Snapshots and migration
| Command | Description |
|---|---|
savevm TAG | Save the whole machine under TAG. |
loadvm TAG | Restore it. |
delvm TAG | Delete it. |
info snapshots | List the snapshots. |
migrate [-d] file:PATH | Save the machine's state to a file. -d is accepted; the command returns when the file is written either way. |
migrate_incoming file:PATH | Load a state into a machine started with -incoming defer. |
migrate_set_capability CAP on|off, migrate_set_parameter NAME VALUE | Accepted and stored. |
See Snapshots.
Memory and registers
x and xp
x /FMT ADDRESS guest virtual memory, as core 0 sees it now
xp /FMT ADDRESS guest physical memory (RAM)FMT is /[count][format][size]:
| Part | Values | Default |
|---|---|---|
| count | how many units | 1 |
| format | x hex, d signed decimal, u unsigned decimal, o octal, c character, i instruction words | x |
| size | b 1 byte, h 2, w 4, g 8 | w |
The last format used is remembered. Rows hold 8 bytes for byte units and 16 bytes otherwise; a row that can't be read prints Cannot access memory and ends the dump.
(wemu) xp /4xw 0x40000000 # four 32-bit words at the start of RAM, in hex
(wemu) x /8xb $pc # eight bytes at the current instruction
(wemu) x /2dg $sp # two 64-bit signed values on the stackNote There is no disassembler: /i prints each instruction as its 32-bit word.
print and p
print /FMT EXPRESSIONEvaluates an expression and prints it in hex (or the given format). Expressions take numbers (0x… hex, a leading 0 for octal, decimal), the registers $pc, $sp, $x0 to $x30 and $el, parentheses, and C's operators + - * / % & | ^ ~ << >>.
(wemu) p $sp + 0x10 # an address, in hex
(wemu) p /d $x0 # a register, in decimalOther memory commands
| Command | Description |
|---|---|
info registers | Core 0's X0 to X30. |
gva2gpa ADDRESS | Translate a virtual address to a physical one. |
sum ADDRESS SIZE | A checksum of physical memory. |
memsave ADDRESS SIZE FILE | Save virtual memory to a file. |
pmemsave ADDRESS SIZE FILE | Save physical memory to a file. |
dump-guest-memory FILE | An ELF core of the guest's RAM. -p (a paging dump) is refused: paging dumps are not available here. |
dumpdtb FILE | The device tree the guest booted with. |
info mem, info mtree | The RAM's address range. |
Input and display
| Command | Description |
|---|---|
sendkey KEYS [HOLD_MS] | Press keys together, joined by -: sendkey ctrl-alt-delete. |
mouse_move DX DY [DZ] | Move the pointer; DZ turns the wheel. |
mouse_button STATE | Set the buttons: 1 left, 2 middle, 4 right. |
screendump FILE [-f png] | Save the screen as PPM, or PNG. |
info mice | The pointing devices. |
Devices
| Command | Description |
|---|---|
info block | The disks. |
info blockstats | Disk counters. |
info network | The network cards and their backends. |
set_link NAME on|off | A network card's link. |
info usb | The USB devices. |
info pci | The PCI functions. |
info chardev | The character devices. |
ringbuf_write DEVICE DATA, ringbuf_read DEVICE SIZE | A ring-buffer console. |
info qtree, info qom-tree, qom-list, qom-get | The device tree. |
info virtio | The virtio devices. |
Sound
| Command | Description |
|---|---|
wavcapture PATH [FREQUENCY [BITS [CHANNELS]]] | Record what the guest plays to a WAV file. |
stopcapture | Stop recording and write the file. |
info capture | The recording in progress. |
Information
| Subcommand | Shows |
|---|---|
info status | The run state. |
info version | 11.1.50 (warm64 0.1.0) |
info name, info uuid | The -name and -uuid. |
info cpus | The cores. |
info kvm | kvm support: disabled |
info accel | tcg |
info jit | The JIT's counters. |
info irq, info pic | The interrupt controller. |
info roms | The kernel image loaded. |
info migrate | The last migration. |
info memory_size_summary | The RAM size. |
Every command
Every command and alias of QEMU 11.1's monitor is known. Those not described above:
More commands that work
| Command | Description |
|---|---|
help [COMMAND], ? | List the commands. |
cpu INDEX | Choose the CPU the memory commands use. Accepted; they use core 0. |
gpa2hva ADDRESS | Where a physical address lies in the machine's RAM. |
i /FMT PORT, o /FMT PORT VALUE | Read and write an I/O port. The board has no I/O port space, so reads return all ones. |
mouse_set INDEX | Choose the pointing device. There is one. |
chardev-send-break ID | Send a serial break. |
announce_self | Announce the network cards. |
migrate_cancel | Cancel a migration. |
log ITEMS, logfile FILE, trace-file, one-insn-per-tb, sync-profile | Accepted, with no effect. |
watchdog_action ACTION, migration_mode MODE, calc_dirty_rate, nbd_server_stop, clear | Accepted, with no effect. |
Commands refused
These answer as QEMU does on a machine without the feature:
| Commands | Why |
|---|---|
device_add, device_del, drive_add, drive_del, netdev_add, netdev_del, object_add, object_del, chardev-add, chardev-change, chardev-remove | No hot-plug: name devices on the command line. |
eject [-f] DEVICE, change | Disks aren't removable, with or without -f. |
block_resize, block_set_io_throttle | Disks are fixed while the machine runs. |
commit, block_stream, snapshot_blkdev, snapshot_blkdev_internal, snapshot_delete_blkdev_internal, drive_mirror, drive_backup | Raw images have no backing files, internal snapshots or jobs. |
block_job_set_speed, block_job_cancel, block_job_complete, block_job_pause, block_job_resume | No block jobs. |
nbd_server_start, nbd_server_add, nbd_server_remove | No NBD server. |
wemu-io, qemu-io | The disks are the host's images. |
migrate_continue, migrate_recover, migrate_pause, migrate_start_postcopy | No postcopy migration. |
system_wakeup | Guests can't suspend here. |
nmi | The machine has no NMIs. |
gpa2hpa | The host is WebAssembly: there's no host physical address. |
hostfwd_add, hostfwd_remove | The user network has no port forwarding. |
set_password, expire_password, client_migrate_info | No VNC or SPICE. |
gdbserver | No gdb stub. |
replay_break, replay_delete_break, replay_seek | Record and replay are off. |
set_vcpu_dirty_limit, cancel_vcpu_dirty_limit | Needs KVM. |
getfd, closefd | No file descriptors are passed to the monitor. |
trace-event NAME on|off | No trace events: No trace events found matching 'NAME'. |
qom-set | Properties are read-only. |
boot_set | The boot order can't change while running. |
balloon | No balloon device. |
exit_preconfig | Only in QEMU's preconfig state. |
pcie_aer_inject_error, mce, dump-skeys, x_colo_lost_heartbeat, xen-event-inject, xen-event-list | Other platforms' and features' commands. |
Every info subcommand
| Subcommand | Shows |
|---|---|
info status, info version, info name, info uuid | The run state, version, name and UUID. |
info cpus, info hotpluggable-cpus | The cores. |
info registers | Core 0's X0 to X30. |
info kvm, info accel, info accelerators | kvm support: disabled; tcg. |
info jit | The JIT's counters. |
info irq, info pic | The interrupt controller. |
info mem, info mtree, info ramblock, info memory_size_summary | The RAM. |
info numa | 0 nodes |
info roms | The kernel image loaded. |
info block, info blockstats, info block-jobs | The disks, their counters, and (none) block jobs. |
info network, info usernet | The network cards and the user network. |
info usb, info pci, info virtio, info mice | The devices. |
info chardev | The character devices. |
info qtree, info qdm, info qom-tree | The device tree, the device models, the object tree. |
info snapshots | The snapshots. |
info migrate, info migrate_capabilities, info migrate_parameters | The last migration and its settings. |
info dump | The last dump-guest-memory. |
info capture | The sound recording in progress. |
info vnc, info spice | Server: disabled |
info tpm | TPM device not supported |
info replay | Record/replay is not active |
info dirty_rate, info vcpu_dirty_limit | Not measured. |
info sync-profile | sync-profile is not enabled |
info history, info tlb, info lapic, info usbhost, info trace-events, info memdev, info memory-devices, info iothreads, info stats, info cryptodev, info rocker-ports | Empty: the machine has none. |
info sev, info sgx, info via | SEV is not available on this machine, and likewise. |
info balloon, info firmware-log | Refused: no balloon device, no firmware log. |
info vm-generation-id | Refused: VM Generation ID device not found. |
info rocker, info rocker-of-dpa-flows, info rocker-of-dpa-groups | Refused: rocker NAME not found. |
info virtio-status, info virtio-queue-status, info virtio-vhost-queue-status, info virtio-queue-element | Refused: Path PATH is not a VirtIODevice. |
info skeys, info cmma | Refused: this is only available on s390x guests. |