mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Sourabh Jain" <sourabhjain@linux.ibm.com>
Cc: "Hari Bathini" <hbathini@linux.ibm.com>,
	kexec@lists.infradead.org, "Pratyush Yadav" <pratyush@kernel.org>,
	"Michael Ellerman" <mpe@ellerman.id.au>,
	linux-kernel@vger.kernel.org, "Alexander Graf" <graf@amazon.com>,
	linuxppc-dev@lists.ozlabs.org,
	"Madhavan Srinivasan" <maddy@linux.ibm.com>,
	"Mahesh Salgaonkar" <mahesh@linux.ibm.com>,
	"Shivang Upadhyay" <shivangu@linux.ibm.com>,
	"Andrew Morton" <akpm@linux-foundation.org>,
	"Baoquan He" <baoquan.he@linux.dev>,
	"Ritesh Harjani (IBM)" <ritesh.list@gmail.com>,
	"Shrikanth Hegde" <sshegde@linux.ibm.com>,
	"Aditya Gupta" <adityag@linux.ibm.com>,
	"Mike Rapoport" <rppt@kernel.org>,
	"Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
	"Pasha Tatashin" <pasha.tatashin@soleen.com>,
	"Nicholas Piggin" <npiggin@gmail.com>
Subject: Re: [PATCH v1 2/2] powerpc: add support for Kexec HandOver (KHO)
Date: Mon, 28 Sep 2026 08:43:09 +0000	[thread overview]
Message-ID: <20260928084310.10CDB1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260928083226.107807-3-sourabhjain@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] boot: late KHO initialization allows memblock to clobber preserved memory
--

commit 2f581dec390379323e7a0b4e4badb03487eea55f
Author: Sourabh Jain <sourabhjain@linux.ibm.com>

powerpc: add support for Kexec HandOver (KHO)

Add architecture bits to enable CONFIG_KEXEC_HANDOVER on powerpc. This
patch checks for KHO information in the device tree before unflattening it,
allowing a kernel booted via KHO kexec to recover the FDT and scratch region.
It also moves early_init_dt_check_kho() to be called from setup_arch().

> diff --git a/arch/powerpc/kernel/setup-common.c b/arch/powerpc/kernel/setup-common.c
> index 4afaba19b5867..53c2f1897bfe1 100644
> --- a/arch/powerpc/kernel/setup-common.c
> +++ b/arch/powerpc/kernel/setup-common.c
> @@ -923,6 +923,8 @@ void __init setup_arch(char **cmdline_p)
>  	/* Set a half-reasonable default so udelay does something sensible */
>  	loops_per_jiffy = 500000000 / HZ;
>  
> +	early_init_dt_check_kho();
> +
>  	/* Unflatten the device-tree passed by prom_init or kexec */
>  	unflatten_device_tree();

[Severity: High]
Does calling early_init_dt_check_kho() in setup_arch() happen too late to
protect against early memblock allocations clobbering preserved KHO memory?

The Kexec HandOver (KHO) mechanism uses a scratch memory region to strictly
confine early boot memory allocations in the successor kernel. This prevents
them from overwriting memory pages preserved by the previous kernel, and is
enforced when kho_populate() invokes memblock_set_kho_scratch_only().

However, setup_arch() is invoked from start_kernel() long after early_setup()
completes. During early_setup(), substantial dynamic memblock allocations occur
before KHO scratch memory confinement is enforced.

For example, move_device_tree() allocates memory for the FDT:

arch/powerpc/kernel/prom.c:move_device_tree() {
	...
	p = memblock_alloc_raw(size, PAGE_SIZE);
	...
}

This is called via early_init_devtree() from early_setup():

arch/powerpc/kernel/setup_64.c:early_setup() {
	...
	early_init_devtree(__va(dt_ptr));

	allocate_paca_ptrs();
	allocate_paca(boot_cpuid);
	... 
	early_init_mmu();
	...
}

Because KHO scratch-only mode has not yet been enforced during these early
allocations, could they use standard memblock policies and overwrite preserved
KHO memory state, corrupting the handover?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260928083226.107807-1-sourabhjain@linux.ibm.com?part=2

      reply	other threads:[~2026-09-28  8:43 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28  8:32 [PATCH v1 0/2] powerpc: enable " Sourabh Jain
2026-09-28  8:32 ` [PATCH v1 1/2] kho: check scratch vs CMA alignment at runtime Sourabh Jain
2026-09-28  8:41   ` sashiko-bot
2026-09-28  8:32 ` [PATCH v1 2/2] powerpc: add support for Kexec HandOver (KHO) Sourabh Jain
2026-09-28  8:43   ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928084310.10CDB1F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=adityag@linux.ibm.com \
    --cc=akpm@linux-foundation.org \
    --cc=baoquan.he@linux.dev \
    --cc=chleroy@kernel.org \
    --cc=graf@amazon.com \
    --cc=hbathini@linux.ibm.com \
    --cc=kexec@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=maddy@linux.ibm.com \
    --cc=mahesh@linux.ibm.com \
    --cc=mpe@ellerman.id.au \
    --cc=npiggin@gmail.com \
    --cc=pasha.tatashin@soleen.com \
    --cc=pratyush@kernel.org \
    --cc=ritesh.list@gmail.com \
    --cc=rppt@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=shivangu@linux.ibm.com \
    --cc=sourabhjain@linux.ibm.com \
    --cc=sshegde@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®