From nobody Mon Jun 8 06:36:26 2026 Received: from mail-wm1-f74.google.com (mail-wm1-f74.google.com [209.85.128.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 74FAE4D9908 for ; Fri, 5 Jun 2026 12:10:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.74 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780661451; cv=none; b=W46Lya55exerf2Jla/9Ka62belh8hpE+O5ik3VEqytKGPlYnF1zr6NPI5KbVtZ+kNCYa6dVECOpjhPc9AqPjDX8WX7obDyzK4p6sHFEmBNJij3hNhWq0oliwliyo50RxJreLuUcVZy8FBbj1ThrWfL1qB8Jl1y+h5GdifYvkH5k= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780661451; c=relaxed/simple; bh=xKcoYrnZSLRtuvDg+jInKO3MwVcx9i0MV0mwLRQ9qW4=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=Yl1T1MO0t2Fo20tVpOi51SVuyomg4dbabKen7/0RsC3TXdOrcN4FKJDRIhXGNOda54M/Z39gjCyieSI4jAzxvEHjXJb6DIcSa9Wms9VwQNoA+ZjfLInIyFIZhT6Wx4CTvwruct8VquEZF69PEU2ShZony9w2jxdL4yJ6BOI//XU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--mclapinski.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=l4FZKk3j; arc=none smtp.client-ip=209.85.128.74 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--mclapinski.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="l4FZKk3j" Received: by mail-wm1-f74.google.com with SMTP id 5b1f17b1804b1-490bde3d239so14689125e9.1 for ; Fri, 05 Jun 2026 05:10:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1780661447; x=1781266247; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:from:to:cc:subject :date:message-id:reply-to; bh=58P1q1XUXWtvX8VsXYXNzBZuVvbe3GtJn7syrrjTljc=; b=l4FZKk3jpWWB+WaMOixA34N9H/uXaTIfMshx/iSvMKNQhguPwKci6LQs2z5qFYltKH Pi8Xd2X6jCQW52/nGmzUMc7z8hQF2BQEhpgjOhgRt7ulLuvOl7kYa6T+awRtdNdKFDsn kUv0nP5UpnMnDiL2DGp30j7b4TQRZQWKaVasLIjLSrDK7O7b1XEf+9lfkHw/ohH5qMG2 DKCXxUeYexED6938ys9rDJf5MoOztijS1EpvAA3Nbmmn2PaD6Nk7QwQv8vBch5lCzAN9 4XqsnjmTYI98dacRr4kg35J8XpuPFLksdk655pTr3gFgj5XLsCTTk/QmoEqOy9yNEBkK PYQg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780661447; x=1781266247; h=cc:to:from:subject:message-id:mime-version:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=58P1q1XUXWtvX8VsXYXNzBZuVvbe3GtJn7syrrjTljc=; b=Xx06Qaw/WdoapDBwvH75wlgy+kr5CPDbj5/NJ3Sr7rJxbaNjYBbCzLbeTMn47rKm6p EGTzSypcz8Q1uoS2CONeH14gLu2GOAv1/zcfdgKsVCOA2ynbw8qcRusCIFDeXF44eoqX jXj0kJn7lsseBq3BSqMadQMe7X3vqvVr6vGaqSSjsTk/Px0n09RP7+t4aKMe7eF+ZbC2 jGyIXuKHbOCTyi8j0n/5DXe5dPwxPnnArkdua6nZsliJYe6+XxxRD9d2JQmwQTdnzukr +tYqIh1Q43EwhB5tMHxGngh4HtZqUT3QF2febctRSDs/sDqK8e4g596JdHhiiDw0MdjG rTvw== X-Forwarded-Encrypted: i=1; AFNElJ8FcYoH2rVhD60ONC6bGyxwY27riRaAs+nC/Dyr1E0dZxNuau6XAfQI4Wc3OrZXdEMVYJiwoBZdyW9o+hU=@vger.kernel.org X-Gm-Message-State: AOJu0YwM7siG4j39Kq04r3tK/bQFh7CPdEk8eA7VLkXeq/0gu+c+//Su 6q/oDvO77SWGYZ6F5IkEwhobJp6wlopEKEZ20ciQ5FNlpfNfTqMzTp3kJVA58ld0pkhBb+ZE8kf JBtS0M04U4mtIIx20dDxL5A== X-Received: from wmoq17.prod.google.com ([2002:a05:600c:46d1:b0:490:beee:59ba]) (user=mclapinski job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:81c9:b0:490:b724:507d with SMTP id 5b1f17b1804b1-490c259f6e2mr43633315e9.11.1780661447497; Fri, 05 Jun 2026 05:10:47 -0700 (PDT) Date: Fri, 5 Jun 2026 14:10:40 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.54.0.1032.g2f8565e1d1-goog Message-ID: <20260605121040.1177072-1-mclapinski@google.com> Subject: [PATCH v2] pstore: add a KHO backend From: Michal Clapinski To: Kees Cook , Tony Luck , "Guilherme G. Piccoli" , Pasha Tatashin , Mike Rapoport , Pratyush Yadav , Alexander Graf , linux-kernel@vger.kernel.org, kexec@lists.infradead.org Cc: Michal Clapinski Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Up to this point to preserve late shutdown logs in memory, users had to predefine a memory region using ramoops. This commit changes this by preserving a buffer using kexec-handover. pstore_kho supports preserving only 1 dmesg buffer. It gets replaced with the new buffer on every kexec, so the user has to copy the file out of pstore after every kexec. There is no erase() support. Signed-off-by: Michal Clapinski --- v2: - Added a comment explaining the benefits of pstore_kho. - Created include/linux/kho/abi/pstore.h. - Got rid of the KHO subtree. - Made sure never to free incoming kho data. This way the module can be safely reloaded. - Sashiko complained that I trust the data coming from the old kernel. I ignored it. LMK if I shouldn't trust the old kernel. --- fs/pstore/Kconfig | 10 ++ fs/pstore/Makefile | 2 + fs/pstore/pstore_kho.c | 230 +++++++++++++++++++++++++++++++++ include/linux/kho/abi/pstore.h | 27 ++++ 4 files changed, 269 insertions(+) create mode 100644 fs/pstore/pstore_kho.c create mode 100644 include/linux/kho/abi/pstore.h diff --git a/fs/pstore/Kconfig b/fs/pstore/Kconfig index 3acc38600cd1..455790fec955 100644 --- a/fs/pstore/Kconfig +++ b/fs/pstore/Kconfig @@ -81,6 +81,16 @@ config PSTORE_RAM =20 For more information, see Documentation/admin-guide/ramoops.rst. =20 +config PSTORE_KHO + tristate "Preserve logs over kexec" + depends on PSTORE + depends on KEXEC_HANDOVER + help + A pstore backend for preserving dmesg over KHO (kexec handover). + It does not require any additional cmdline params to work. + + It supports preservation of only 1 dmesg file. + config PSTORE_ZONE tristate depends on PSTORE diff --git a/fs/pstore/Makefile b/fs/pstore/Makefile index c270467aeece..518cd408bf8e 100644 --- a/fs/pstore/Makefile +++ b/fs/pstore/Makefile @@ -13,6 +13,8 @@ pstore-$(CONFIG_PSTORE_PMSG) +=3D pmsg.o ramoops-objs +=3D ram.o ram_core.o obj-$(CONFIG_PSTORE_RAM) +=3D ramoops.o =20 +obj-$(CONFIG_PSTORE_KHO) +=3D pstore_kho.o + pstore_zone-objs +=3D zone.o obj-$(CONFIG_PSTORE_ZONE) +=3D pstore_zone.o =20 diff --git a/fs/pstore/pstore_kho.c b/fs/pstore/pstore_kho.c new file mode 100644 index 000000000000..6d4187d91642 --- /dev/null +++ b/fs/pstore/pstore_kho.c @@ -0,0 +1,230 @@ +// SPDX-License-Identifier: GPL-2.0 +/* + * KHO (Kexec Handover) backend for pstore. + * + * KHO-based pstore provides a mechanism to hand over pstore data (specifi= cally + * dmesg logs) from one kernel to another across a kexec reboot using the + * Kexec Handover (KHO) framework. + * + * Key advantages of KHO-based pstore include: + * - No hardcoded memmap: Unlike ramoops, it does not require reserving a = static + * memory region in the bootloader or device tree. Memory is allocated + * dynamically and handed over to the next kernel. + * - Firmware independence: It does not rely on platform firmware support = (like + * ACPI ERST or UEFI variable storage) to preserve logs across reboots. + * - High throughput: It avoids the performance bottlenecks of serial cons= oles, + * not being limited by console baud rates. + * - Complete log preservation: It preserves all dmesg logs, including tho= se + * generated late in the reboot cycle after filesystems have been unmoun= ted, + * up to the point of the kexec jump. + */ + +#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt + +#include +#include +#include +#include +#include +#include +#include +#include + +/* + * The in and out buffers are separate and they need not be the same size. + * Therefore, this is not part of ABI. + */ +#define RECORD_MAX_SIZE (1 << CONFIG_LOG_BUF_SHIFT) + +struct pstore_kho_context { + struct pstore_info pstore; + bool read_done; +}; + +static struct pstore_ser *kho_ser_in; +static struct pstore_ser *kho_ser_out; + +static int pstore_kho_open(struct pstore_info *psi) +{ + struct pstore_kho_context *cxt =3D psi->data; + + cxt->read_done =3D false; + return 0; +} + +static ssize_t pstore_kho_read(struct pstore_record *record) +{ + struct pstore_kho_context *cxt =3D record->psi->data; + struct pstore_kho_record *kho_data_in; + + if (cxt->read_done || !kho_ser_in) + return 0; + + cxt->read_done =3D true; + kho_data_in =3D &kho_ser_in->record; + + record->buf =3D kmemdup(kho_data_in->buf, kho_data_in->size, GFP_KERNEL); + if (!record->buf) + return -ENOMEM; + + record->type =3D PSTORE_TYPE_DMESG; + record->id =3D 0; + record->size =3D kho_data_in->size; + record->time.tv_sec =3D kho_data_in->time_sec; + record->time.tv_nsec =3D kho_data_in->time_nsec; + record->count =3D kho_data_in->count; + record->reason =3D kho_data_in->reason; + record->part =3D kho_data_in->part; + record->compressed =3D kho_data_in->compressed; + + return record->size; +} + +static int pstore_kho_write(struct pstore_record *record) +{ + struct pstore_kho_record *kho_data_out =3D &kho_ser_out->record; + + if (record->type !=3D PSTORE_TYPE_DMESG) + return -EINVAL; + + if (kho_data_out->size !=3D 0) { + pr_err("pstore kho already contains a record\n"); + return -ENOSPC; + } + + if (record->size > RECORD_MAX_SIZE) { + pr_err("dmesg record too big, record size: %lu, available space: %d\n", + record->size, RECORD_MAX_SIZE); + return -ENOSPC; + } + + memcpy(kho_data_out->buf, record->buf, record->size); + kho_data_out->size =3D record->size; + kho_data_out->time_sec =3D record->time.tv_sec; + kho_data_out->time_nsec =3D record->time.tv_nsec; + kho_data_out->count =3D record->count; + kho_data_out->reason =3D record->reason; + kho_data_out->part =3D record->part; + kho_data_out->compressed =3D record->compressed; + + return 0; +} + +static struct pstore_kho_context pstore_kho_cxt =3D { + .pstore =3D { + .owner =3D THIS_MODULE, + .name =3D "kho", + .bufsize =3D RECORD_MAX_SIZE, + .flags =3D PSTORE_FLAGS_DMESG, + .max_reason =3D KMSG_DUMP_SHUTDOWN, + .open =3D pstore_kho_open, + .read =3D pstore_kho_read, + .write =3D pstore_kho_write, + }, +}; + +static void __init kho_setup_incoming(void) +{ + phys_addr_t kho_ser_phys; + int err; + + err =3D kho_retrieve_subtree(KHO_PSTORE_FDT_NAME, &kho_ser_phys); + if (err) { + if (err !=3D -ENOENT) + pr_err("failed to retrieve KHO data %s: %d\n", + KHO_PSTORE_FDT_NAME, err); + return; + } + + kho_ser_in =3D phys_to_virt(kho_ser_phys); + + if (kho_ser_in->version !=3D KHO_PSTORE_VERSION) { + pr_err("unsupported KHO pstore version: %d\n", kho_ser_in->version); + kho_ser_in =3D NULL; + return; + } + + pr_info("successfully restored preserved data\n"); +} + +static int __init kho_setup_outgoing(void) +{ + int err; + size_t total_size =3D sizeof(struct pstore_ser) + RECORD_MAX_SIZE; + + kho_ser_out =3D kho_alloc_preserve(total_size); + if (IS_ERR(kho_ser_out)) { + pr_err("failed to allocate pstore kho ser anchor\n"); + return PTR_ERR(kho_ser_out); + } + memset(kho_ser_out, 0, total_size); + kho_ser_out->version =3D KHO_PSTORE_VERSION; + + err =3D kho_add_subtree(KHO_PSTORE_FDT_NAME, kho_ser_out); + if (err) { + pr_err("failed to add KHO data\n"); + goto err_free_ser; + } + + return 0; + +err_free_ser: + kho_unpreserve_free(kho_ser_out); + return err; +} + +static int __init pstore_kho_init(void) +{ + int err; + struct pstore_kho_context *cxt =3D &pstore_kho_cxt; + + if (!kho_is_enabled()) { + pr_info("KHO is disabled, pstore_kho cannot start\n"); + return -ENODEV; + } + + kho_setup_incoming(); + err =3D kho_setup_outgoing(); + if (err) { + pr_err("failed to setup outgoing KHO\n"); + return err; + } + + cxt->pstore.data =3D cxt; + cxt->pstore.buf =3D kmalloc(cxt->pstore.bufsize, GFP_KERNEL); + if (!cxt->pstore.buf) { + err =3D -ENOMEM; + goto err_free_outgoing; + } + + err =3D pstore_register(&cxt->pstore); + if (err) { + pr_err("failed to register with pstore\n"); + goto err_free_pstore_buf; + } + + return 0; + +err_free_pstore_buf: + kfree(cxt->pstore.buf); + +err_free_outgoing: + kho_remove_subtree(kho_ser_out); + kho_unpreserve_free(kho_ser_out); + + return err; +} +module_init(pstore_kho_init); + +static void __exit pstore_kho_exit(void) +{ + pstore_unregister(&pstore_kho_cxt.pstore); + kfree(pstore_kho_cxt.pstore.buf); + + kho_remove_subtree(kho_ser_out); + kho_unpreserve_free(kho_ser_out); +} +module_exit(pstore_kho_exit); + +MODULE_LICENSE("GPL"); +MODULE_DESCRIPTION("Pstore backend for dmesg preservation over kexec"); diff --git a/include/linux/kho/abi/pstore.h b/include/linux/kho/abi/pstore.h new file mode 100644 index 000000000000..743ec64d67fc --- /dev/null +++ b/include/linux/kho/abi/pstore.h @@ -0,0 +1,27 @@ +/* SPDX-License-Identifier: GPL-2.0 */ + +#ifndef _LINUX_KHO_ABI_PSTORE_H +#define _LINUX_KHO_ABI_PSTORE_H + +#include + +#define KHO_PSTORE_FDT_NAME "pstore-kho" +#define KHO_PSTORE_VERSION 1 + +struct pstore_kho_record { + s64 size; + s64 time_sec; + u32 time_nsec; + s32 count; + u32 reason; + u32 part; + u32 compressed; + char buf[]; +}; + +struct pstore_ser { + u32 version; + struct pstore_kho_record record; +}; + +#endif /* _LINUX_KHO_ABI_PSTORE_H */ --=20 2.54.0.1032.g2f8565e1d1-goog