Re: [PATCH v2 1/5] arm64: kexec_file: Forbid non-crash kernels

From: Marc Zyngier
Date: Tue Jun 01 2021 - 04:36:35 EST


On Mon, 31 May 2021 20:37:49 +0100,
Ard Biesheuvel <ardb@xxxxxxxxxx> wrote:
>
> On Mon, 31 May 2021 at 11:57, Marc Zyngier <maz@xxxxxxxxxx> wrote:
> >
> > It has been reported that kexec_file doesn't really work on arm64.
> > It completely ignores any of the existing reservations, which results
> > in the secondary kernel being loaded where the GICv3 LPI tables live,
> > or even corrupting the ACPI tables.
> >
> > Since only crash kernels are imune to this as they use a reserved
> > memory region, disable the non-crash kernel use case. Further
> > patches will try and restore the functionality.
> >
> > Reported-by: Moritz Fischer <mdf@xxxxxxxxxx>
> > Signed-off-by: Marc Zyngier <maz@xxxxxxxxxx>
> > Cc: stable@xxxxxxxxxxxxxxx # 5.10
>
> Acked-by: Ard Biesheuvel <ardb@xxxxxxxxxx>
>
> ... but do we really only need this in 5.10 and not earlier?

We *do* need something in earlier kernel (as mentioned in the cover
letter), but not this patch (arch_kexec_locate_mem_hole doesn't exist
there, so there is nothing to override).

I guess that completely disabling CONFIG_KEXEC_FILE on arm64 is the
way to go for 5.4 and earlier, as I don't think there is any crash
kernel support there.

Thanks,

M.

--
Without deviation from the norm, progress is not possible.