On Fri, Sep 04 2026, George Guo wrote: > From: George Guo <[email protected]> > > The EFI KHO configuration table is a global channel. Updating it while > a candidate kexec image is still being loaded can leave the channel > pointing at the failed candidate even though the previous image remains > installed. Synchronize it instead from the image selected for execution.
Huh? Sorry, I don't understand this is supposed to mean at all. What failed candidate? > > Use the actual scratch payload size rather than its page-aligned segment > size, and propagate update failures before live-update serialization. > Keep clearing the channel for cold and crash images best-effort. Huh? This is word soup and I don't understand what any of this is supposed to mean. If you are using a LLM to generate this, please _read_ what the output is and see if it even is readable to someone else. And if you are writing this by hand, then take a step back, and consider if patch reviews can even understand what you are saying. > > Signed-off-by: George Guo <[email protected]> > --- > kernel/crash_core.c | 7 +++++++ > kernel/kexec_core.c | 5 +++++ > kernel/kexec_internal.h | 3 +++ > kernel/liveupdate/kexec_handover.c | 33 ++++++++++++++++++++++++++++++ > 4 files changed, 48 insertions(+) > > diff --git a/kernel/crash_core.c b/kernel/crash_core.c > index 2b36aa9fade0..6166ce4203d3 100644 > --- a/kernel/crash_core.c > +++ b/kernel/crash_core.c > @@ -138,6 +138,13 @@ void __noclone __crash_kexec(struct pt_regs *regs) > if (kexec_crash_image) { > struct pt_regs fixed_regs; > > + /* > + * A crash image carries no KHO state: clear the > + * transport so the crash kernel boots cold instead > + * of reviving from stale state. > + */ > + (void)kho_sync_channel(kexec_crash_image); > + > crash_setup_regs(&fixed_regs, regs); > crash_save_vmcoreinfo(); > machine_crash_shutdown(&fixed_regs); > diff --git a/kernel/kexec_core.c b/kernel/kexec_core.c > index dc770b9a6d05..147f5b5b23d4 100644 > --- a/kernel/kexec_core.c > +++ b/kernel/kexec_core.c > @@ -1146,6 +1146,11 @@ int kernel_kexec(void) > goto Unlock; > } > > + /* Synchronize the handover transport with the image being executed. */ > + error = kho_sync_channel(kexec_image); > + if (error) > + goto Unlock; > + Why are you setting this at kexec time? Why not set it at load time like every other architecture? Also what's this "sync channel"? Use simpler words that _actually describe_ what they do. > if (!kexec_image->preserve_context) { > error = liveupdate_reboot(); > if (error) > diff --git a/kernel/kexec_internal.h b/kernel/kexec_internal.h > index 228bb88c018b..4d4c2290e85c 100644 > --- a/kernel/kexec_internal.h > +++ b/kernel/kexec_internal.h > @@ -46,6 +46,7 @@ struct kexec_buf; > int kho_locate_mem_hole(struct kexec_buf *kbuf, > int (*func)(struct resource *, void *)); > int kho_fill_kimage(struct kimage *image); > +int kho_sync_channel(struct kimage *image); > #else > static inline int kho_locate_mem_hole(struct kexec_buf *kbuf, > int (*func)(struct resource *, void *)) > @@ -54,5 +55,7 @@ static inline int kho_locate_mem_hole(struct kexec_buf > *kbuf, > } > > static inline int kho_fill_kimage(struct kimage *image) { return 0; } > + > +static inline int kho_sync_channel(struct kimage *image) { return 0; } > #endif /* CONFIG_KEXEC_HANDOVER */ > #endif /* LINUX_KEXEC_INTERNAL_H */ > diff --git a/kernel/liveupdate/kexec_handover.c > b/kernel/liveupdate/kexec_handover.c > index 39f489a258d9..3aa5c66dfc6d 100644 > --- a/kernel/liveupdate/kexec_handover.c > +++ b/kernel/liveupdate/kexec_handover.c > @@ -14,6 +14,7 @@ > #include <linux/cma.h> > #include <linux/kmemleak.h> > #include <linux/count_zeros.h> > +#include <linux/efi.h> > #include <linux/kasan.h> > #include <linux/kexec.h> > #include <linux/kexec_handover.h> > @@ -2074,6 +2075,38 @@ int kho_fill_kimage(struct kimage *image) > return 0; > } > > +/* > + * Synchronize the handover transport with the image that is about to be > + * executed. The EFI config table channel is global, while kexec keeps > + * separate images for a normal reboot and for crash. Write the state of the > + * selected image immediately before it is executed, rather than while a > + * candidate image is being loaded, so a failed replacement cannot leave the > + * channel pointing at that failed image. > + * > + * An image loaded through the legacy kexec_load() syscall, a crash image, or > + * an image loaded while KHO is disabled carries no handover state. Clear > the > + * channel for those images so the next kernel boots cold instead of reviving > + * from stale state. Clearing is best-effort because an absent channel > cannot > + * affect a cold boot. > + */ > +int kho_sync_channel(struct kimage *image) > +{ > + int err; > + > + if (!image->kho.fdt || !image->kho.scratch) { > + efi_kho_update(0, 0, 0, 0); > + return 0; > + } > + > + err = efi_kho_update(image->kho.fdt, PAGE_SIZE, > + image->kho.scratch->mem, > + image->kho.scratch->bufsz); > + if (err) > + pr_warn("failed to update EFI config table: %d\n", err); > + > + return err; > +} > + > static int kho_walk_scratch(struct kexec_buf *kbuf, > int (*func)(struct resource *, void *)) > { -- Regards, Pratyush Yadav

