mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Pratyush Yadav <pratyush@kernel.org>
To: Chris Bainbridge <chris.bainbridge@canonical.com>
Cc: "Mike Rapoport" <rppt@kernel.org>,
	"Pasha Tatashin" <pasha.tatashin@soleen.com>,
	"Jason Miu" <jasonmiu@google.com>,
	"Pratyush Yadav" <pratyush@kernel.org>,
	"Alexander Graf" <graf@amazon.com>,
	"Ran Xiaokai" <ran.xiaokai@zte.com.cn>,
	regressions@lists.linux.dev, linux-kernel@vger.kernel.org,
	kexec@lists.infradead.org, linux-mm@kvack.org,
	"Michał Cłapiński" <mclapinski@google.com>
Subject: Re: [BUG] KHO handover hangs when memmap reserves PMEM
Date: Sun, 04 Oct 2026 15:39:25 +0200	[thread overview]
Message-ID: <2vxzcxtplh4i.fsf@kernel.org> (raw)
In-Reply-To: <asE0R_f2r2TL-3Sy@px13> (Chris Bainbridge's message of "Sat, 3 Oct 2026 18:02:27 +0100")

Hi,

On Sat, Oct 03 2026, Chris Bainbridge wrote:

> Hello,
>
> I am reporting a regression in KHO handover.
>
> In the most recent Ubuntu 26.10 beta mini-ISO releases (2026-09-18 onwards),
> the first kernel reserves RAM for the downloaded ISO with a memmap directive
> such as memmap=<size>!4G, then kexecs a second kernel. On affected kernels, the
> first kernel reaches "kexec_core: Starting new kernel", but the second kernel
> produces no further output and QEMU spins at 100% CPU. On unaffected kernels,
> the second kernel starts and finds /dev/pmem0 with the expected "Persistent
> Memory (legacy)" range in /proc/iomem.

Just to confirm, the first kernel boots without memmap= right?

If so, I have seen this before. Michal (+Cc) found this originally in
our downstream test suite.

I think the main problem is that the radix tree pages can be anywhere in
memory. So on the first kernel, they can land in an area that the second
kernel's memmap= reserves. So kho_memory_init() might end up using
memory that memmap= reserved. I'm not sure why exactly the next kernel
doesn't produce any output, but IIRC memmap= memory is not mapped to the
direct map, so accessing those pages likely causes a page fault.

It is not easy to fix. We would need to make memmap= aware of KHO and
skip the radix tree pages, but that is pretty complicated to do for
early boot code. And honestly, I don't think it is worth it either.

So I'd suggest you turn KHO off for the kexec that adds memmap= if you
can.

>
> A source bisect identified 3f2ad90060f6 ("kho: adopt radix tree for preserved
> memory tracking") as the first bad commit; reverting it at the bisected
> revision restored the handover. The regression appears related to KHO metadata
> being accessed after the receiving kernel's memmap directive changes how the
> metadata's physical range is mapped.
>
> #regzbot introduced: 3f2ad90060f6
>
> I have an AI-generated candidate fix that changes 22 files. I have not attached
> or published it: although the AI did extensive verification on both x64 and
> arm64, I cannot review or explain the complete change, so I am not submitting
> it as a fix. If one of you thinks an unreviewed candidate would be useful for
> further analysis, please let me know.

-- 
Regards,
Pratyush Yadav

  reply	other threads:[~2026-10-04 13:39 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-03 17:02 Chris Bainbridge
2026-10-04 13:39 ` Pratyush Yadav [this message]
2026-10-04 15:09   ` Chris Bainbridge
2026-10-04 17:53     ` Pratyush Yadav

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2vxzcxtplh4i.fsf@kernel.org \
    --to=pratyush@kernel.org \
    --cc=chris.bainbridge@canonical.com \
    --cc=graf@amazon.com \
    --cc=jasonmiu@google.com \
    --cc=kexec@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=mclapinski@google.com \
    --cc=pasha.tatashin@soleen.com \
    --cc=ran.xiaokai@zte.com.cn \
    --cc=regressions@lists.linux.dev \
    --cc=rppt@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®