mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: sayo <rg32@ciallo.tech>
To: Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
	Borislav Petkov <bp@alien8.de>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	"H . Peter Anvin" <hpa@zytor.com>
Cc: x86@kernel.org, linux-kernel@vger.kernel.org,
	m.younesbadr@gmail.com, nir@lichtman.org
Subject: [PATCH v3 1/2] init: claim parameters consumed before the main kernel
Date: Mon,  5 Oct 2026 13:13:45 -0400	[thread overview]
Message-ID: <20261005171815.49494-2-rg32@ciallo.tech> (raw)
In-Reply-To: <20261005171815.49494-1-rg32@ciallo.tech>

Some kernel parameters are consumed before the main kernel is running: the
boot stub, the decompressor and the EFI stub all read the command line
directly (cmdline_find_option*()) and act on options that the main kernel
never registers, because they describe things that are already decided by
then - the kernel's load address, 5-level paging setup, the memory
encryption mode, and so on.

Such parameters are not in any __setup()/early_param() table in the main
kernel, so parse_args() cannot know that they were eaten and
unknown_bootoption() classifies them as unknown: valueless ones end up in
init's argv, "key=value" ones end up in init's environment. On x86 that
list currently contains nokaslr, no5lvl, mem_encrypt= and edd=, all of them
documented parameter names in
Documentation/admin-guide/kernel-parameters.txt.

Inits that look at their arguments are affected: openrc-init takes the
runlevel from argv[1] and therefore reports "nokaslr is an invalid
runlevel", while a shell used as init treats the argument as a script name
and exits, which panics the kernel.

Adding a stub handler for each such parameter on each architecture does not
scale: arm64, loongarch and s390 each carry one for "nokaslr" alone. Let
architectures list the parameters their boot code consumed instead, and
have unknown_bootoption() drop those before they are classified: they are
then neither reported as unknown nor handed to init, while genuinely
unknown parameters keep reaching init exactly as before.

Signed-off-by: sayo <rg32@ciallo.tech>
---
 include/linux/init.h | 12 ++++++++++++
 init/main.c          | 16 ++++++++++++++++
 2 files changed, 28 insertions(+)

diff --git a/include/linux/init.h b/include/linux/init.h
index 6326c61e2332..90c77d6d8cb7 100644
--- a/include/linux/init.h
+++ b/include/linux/init.h
@@ -375,6 +375,18 @@ extern const struct obs_kernel_param __setup_start[], __setup_end[];
 /* Relies on boot_command_line being set */
 void __init parse_early_param(void);
 void __init parse_early_options(char *cmdline);
+
+/*
+ * Parameters consumed before the main kernel started - by the boot stub, the
+ * decompressor or the EFI stub. They cannot be matched against the
+ * __setup()/early_param() tables in the main kernel, so architectures list
+ * them in an override of boot_param_consumed() to keep them from being
+ * reported as unknown and handed to init.
+ *
+ * @param is the parameter as it appeared on the command line, including
+ * "=value" for parameters that had one.
+ */
+bool boot_param_consumed(const char *param);
 #endif /* __ASSEMBLY__ */
 
 #else /* MODULE */
diff --git a/init/main.c b/init/main.c
index 31f2bf54976a..1230ac77029d 100644
--- a/init/main.c
+++ b/init/main.c
@@ -506,6 +506,18 @@ static int __init set_init_arg(char *param, char *val,
 	return 0;
 }
 
+/*
+ * Did the boot stub, the decompressor or the EFI stub consume this parameter
+ * before the main kernel started? Such parameters are not in any parameter
+ * table here, so nothing else can tell that they were eaten - without this
+ * they are reported as unknown and handed to init. Architectures override
+ * this to list them; see also boot_param_consumed().
+ */
+bool __init __weak boot_param_consumed(const char *param)
+{
+	return false;
+}
+
 /*
  * Unknown boot options get handed to init, unless they look like
  * unused parameters (modprobe will find them in /proc/cmdline).
@@ -527,6 +539,10 @@ static int __init unknown_bootoption(char *param, char *val,
 
 	repair_env_string(param, val);
 
+	/* Eaten by the boot stub/decompressor before the main kernel ran? */
+	if (boot_param_consumed(param))
+		return 0;
+
 	/* Handle bootloader identifier */
 	for (int i = 0; bootloader[i]; i++) {
 		if (strstarts(param, bootloader[i]))

  reply	other threads:[~2026-10-05 17:19 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 17:13 [PATCH v3 0/2] x86: stop handing boot-stage parameters to init sayo
2026-10-05 17:13 ` sayo [this message]
2026-10-05 17:13 ` [PATCH v3 2/2] x86: claim the parameters consumed by the boot stub and decompressor sayo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261005171815.49494-2-rg32@ciallo.tech \
    --to=rg32@ciallo.tech \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=m.younesbadr@gmail.com \
    --cc=mingo@redhat.com \
    --cc=nir@lichtman.org \
    --cc=tglx@kernel.org \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®