From nobody Mon Sep 28 04:53:54 2026 Received: from canpmsgout12.his.huawei.com (canpmsgout12.his.huawei.com [113.46.200.227]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2E6173BE631; Wed, 26 Aug 2026 09:25:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.227 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736322; cv=none; b=NSm9ND0KiTne4+Q0sCTYxTOcZsprqsOJV9o7ODv+PRNiW8MWnpzOFsJ8d3cwmRtq6aE2TEeOdS6veVu1SbYsKuw+et/7OdZqa00GNegFwvlgbABfdyCXYB3cG29/cTRZwy8fX6QNE/cUAZdLXJqB5X68G0DJ92DltXgZAakk5yw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736322; c=relaxed/simple; bh=5q8QFLZL7ojRckmmkDzVlKdwpjd/K8NBVs2A7WTGeYM=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=OdZdnTwxOrt1SvIin2X3f0OTQTmUq315awRLeUrjY/Yg+FVSuBaSiUZ1TXIqcMI7+xxXOU3bUIMV0qFLHRapKgqauJLMZ2TnWdnmjQD/j0Ej1VUL2C7/ABI2jdg4chL++wL+20KBq4DzqdP3V1lf1YQIPUfNOMtEkBQNnhHgCbE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=PPmdK3kJ; arc=none smtp.client-ip=113.46.200.227 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="PPmdK3kJ" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=6U6CPPAT7oq2s1cbcD6b76t+xbaZUc0osrokVU5xyX0=; b=PPmdK3kJEMBO9dLIkD+9RHj9K6ETQ7E3tZgwSwg33u+8Apv5S6QInyvdcPqW0uOeefZfFNifs avI2H1N0SMkKMKxRlaBr3B6rKK1J201kwoZ5XBWxgys2j83mYzT2hMzLuCu5ieeFkde+xyuGeWc 2zoCN5E9bV1d+v7S1XueOJc= Received: from mail.maildlp.com (unknown [172.19.163.15]) by canpmsgout12.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrd1dDrznTVd; Wed, 26 Aug 2026 17:14:57 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id A4F4340586; Wed, 26 Aug 2026 17:25:11 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:09 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 01/17] kexec: Record allocated CMA pages to fix release size mismatch Date: Wed, 26 Aug 2026 17:25:25 +0800 Message-ID: <20260826092541.3905933-2-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" The CMA pages allocated for a kexec segment are released using the segment's memsz to calculate the number of pages. However, some architecture loaders modify the segment's memsz after allocation (e.g. arm64 subtracts text_offset), causing the release function to free fewer pages than were originally allocated, leaking the remaining CMA pages. Add a per-segment `segment_cma_pages` array to store the number of pages actually allocated from CMA. Populate it during kexec_add_buffer() using the aligned memsz, and use it in kimage_free_cma() to accurately release all allocated pages. This avoids relying on the potentially modified segment->memsz and prevents silent CMA memory leaks. Cc: Andrew Morton Cc: Baoquan He Cc: Mike Rapoport Cc: Pasha Tatashin Cc: Pratyush Yadav Cc: Brian Mak Cc: Pingfan Liu Cc: Sourabh Jain Cc: Justinien Bouron Cc: Li Chen Cc: stable@vger.kernel.org Link: https://sashiko.dev/#/patchset/20260729031235.2840255-1-ruanjinjie%40= huawei.com Fixes: 07d24902977e ("kexec: enable CMA based contiguous allocation") Signed-off-by: Jinjie Ruan --- include/linux/kexec.h | 1 + kernel/kexec_core.c | 3 ++- kernel/kexec_file.c | 16 ++++++++++++---- 3 files changed, 15 insertions(+), 5 deletions(-) diff --git a/include/linux/kexec.h b/include/linux/kexec.h index 0af8ae4fdd08..83c296c0eb6c 100644 --- a/include/linux/kexec.h +++ b/include/linux/kexec.h @@ -349,6 +349,7 @@ struct kimage { unsigned long nr_segments; struct kexec_segment segment[KEXEC_SEGMENT_MAX]; struct page *segment_cma[KEXEC_SEGMENT_MAX]; + unsigned int segment_cma_pages[KEXEC_SEGMENT_MAX]; =20 struct list_head control_pages; struct list_head dest_pages; diff --git a/kernel/kexec_core.c b/kernel/kexec_core.c index dc770b9a6d05..611b15bb1369 100644 --- a/kernel/kexec_core.c +++ b/kernel/kexec_core.c @@ -560,7 +560,7 @@ static void kimage_free_cma(struct kimage *image) =20 for (i =3D 0; i < image->nr_segments; i++) { struct page *cma =3D image->segment_cma[i]; - u32 nr_pages =3D image->segment[i].memsz >> PAGE_SHIFT; + unsigned int nr_pages =3D image->segment_cma_pages[i]; =20 if (!cma) continue; @@ -568,6 +568,7 @@ static void kimage_free_cma(struct kimage *image) arch_kexec_pre_free_pages(page_address(cma), nr_pages); dma_release_from_contiguous(NULL, cma, nr_pages); image->segment_cma[i] =3D NULL; + image->segment_cma_pages[i] =3D 0; } =20 } diff --git a/kernel/kexec_file.c b/kernel/kexec_file.c index 59fb9d71e9d8..bfae3fee7f2f 100644 --- a/kernel/kexec_file.c +++ b/kernel/kexec_file.c @@ -670,7 +670,7 @@ static int kexec_walk_resources(struct kexec_buf *kbuf, =20 static int kexec_alloc_contig(struct kexec_buf *kbuf) { - size_t nr_pages =3D kbuf->memsz >> PAGE_SHIFT; + size_t nr_pages =3D PFN_DOWN(kbuf->memsz); unsigned long mem; struct page *p; =20 @@ -756,6 +756,8 @@ int kexec_locate_mem_hole(struct kexec_buf *kbuf) */ int kexec_add_buffer(struct kexec_buf *kbuf) { + unsigned long nr_segments =3D kbuf->image->nr_segments; + size_t nr_pages; struct kexec_segment *ksegment; int ret; =20 @@ -763,7 +765,7 @@ int kexec_add_buffer(struct kexec_buf *kbuf) if (!kbuf->image->file_mode) return -EINVAL; =20 - if (kbuf->image->nr_segments >=3D KEXEC_SEGMENT_MAX) + if (nr_segments >=3D KEXEC_SEGMENT_MAX) return -EINVAL; =20 /* @@ -789,12 +791,18 @@ int kexec_add_buffer(struct kexec_buf *kbuf) return ret; =20 /* Found a suitable memory range */ - ksegment =3D &kbuf->image->segment[kbuf->image->nr_segments]; + ksegment =3D &kbuf->image->segment[nr_segments]; ksegment->kbuf =3D kbuf->buffer; ksegment->bufsz =3D kbuf->bufsz; ksegment->mem =3D kbuf->mem; ksegment->memsz =3D kbuf->memsz; - kbuf->image->segment_cma[kbuf->image->nr_segments] =3D kbuf->cma; + kbuf->image->segment_cma[nr_segments] =3D kbuf->cma; + if (kbuf->cma) { + nr_pages =3D (unsigned int)(PFN_DOWN(kbuf->memsz)); + kbuf->image->segment_cma_pages[nr_segments] =3D nr_pages; + } else { + kbuf->image->segment_cma_pages[nr_segments] =3D 0; + } kbuf->image->nr_segments++; return 0; } --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout06.his.huawei.com (canpmsgout06.his.huawei.com [113.46.200.221]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B59E53BD638; Wed, 26 Aug 2026 09:25:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.221 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736319; cv=none; b=FzQx6sxkegEHu8mR0OXoNp1c6vJXMXp6bVKXwSWghxuYGcAViB1fpickuj4E29zyh7KNzGhZELYWwlfSLL/pw5QVb+QQqAExvnUvGe5pW8zXTYr0iSsk1TPZItcbgN4oYeXPgcs7ZhYjtROMxVIdmw6NQLKKSwMU/9NTBOzk+Fc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736319; c=relaxed/simple; bh=c2P02/Z0pLH4Qawm+g8g6MB8uoXZotW191R5m/+28Cg=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=iPgz7B18LvctdZDWDdoihVbtieTGJJElNwgYLwdTprXDNcGUjTiku2azpC5F7lO3tdp4Qg1iRoAJ2OtEFJvz+CBJesqATQX4C3nP+c5Ux2wXcUvHVky39bFAfgMq/46M9GlVSboz43LkVZRJaniCCPEOUQekaf/ZOHNOEaxPFMk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=T8c8+n0h; arc=none smtp.client-ip=113.46.200.221 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="T8c8+n0h" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=sbSk8OJq/l2XFTPb3OtwS42B6HB337pYFx+UhYhprQM=; b=T8c8+n0h22Tq1zVVtz7DjXb5w6+R1aGD/V9ecKTeM2uRCAgFmOcuoeWtKKBKTJhTcoEYufilU nHB7WJmb9Tl9N5EMS7H+1vNtHc3odCNbsM4CaphmYV0tEmTGQs3nEvlZcBkVf3LqODgbGw8yImD nGFusQhKqhqcQ5RieTuHGsg= Received: from mail.maildlp.com (unknown [172.19.162.223]) by canpmsgout06.his.huawei.com (SkyGuard) with ESMTPS id 4hVJr62H8VzRhR0; Wed, 26 Aug 2026 17:14:30 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id ECA5540561; Wed, 26 Aug 2026 17:25:13 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:11 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 02/17] kexec: Extract kexec_free_segment_cma() from kimage_free_cma() Date: Wed, 26 Aug 2026 17:25:26 +0800 Message-ID: <20260826092541.3905933-3-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" kimage_free_cma() relies on image->nr_segments to iterate over segments. When an architecture loader (e.g., arm64) truncates nr_segments on a mid-way failure, CMA pages allocated beyond the new boundary become unreachable, causing silent memory leaks. Extract the per-segment freeing logic into the exported helper kexec_free_segment_cma(), so that architecture loaders can release individual segments before nr_segments is truncated. Refactor kimage_free_cma() to loop over the new helper, preserving existing behavior. Cc: Andrew Morton Cc: Baoquan He Cc: Mike Rapoport Cc: Pasha Tatashin Cc: Pratyush Yadav Signed-off-by: Jinjie Ruan --- include/linux/kexec.h | 2 ++ kernel/kexec_core.c | 27 +++++++++++++++------------ 2 files changed, 17 insertions(+), 12 deletions(-) diff --git a/include/linux/kexec.h b/include/linux/kexec.h index 83c296c0eb6c..d7c83938dfd3 100644 --- a/include/linux/kexec.h +++ b/include/linux/kexec.h @@ -533,6 +533,7 @@ extern bool kexec_file_dbg_print; =20 extern void *kimage_map_segment(struct kimage *image, int idx); extern void kimage_unmap_segment(void *buffer); +extern void kexec_free_segment_cma(struct kimage *image, unsigned long idx= ); #else /* !CONFIG_KEXEC_CORE */ struct pt_regs; struct task_struct; @@ -544,6 +545,7 @@ static inline int kexec_crash_loaded(void) { return 0; } static inline void *kimage_map_segment(struct kimage *image, int idx) { return NULL; } static inline void kimage_unmap_segment(void *buffer) { } +static inline void kexec_free_segment_cma(struct kimage *image, unsigned l= ong idx) { } #define kexec_in_progress false #endif /* CONFIG_KEXEC_CORE */ =20 diff --git a/kernel/kexec_core.c b/kernel/kexec_core.c index 611b15bb1369..ee66e8ffd358 100644 --- a/kernel/kexec_core.c +++ b/kernel/kexec_core.c @@ -554,23 +554,26 @@ static void kimage_free_entry(kimage_entry_t entry) kimage_free_pages(page); } =20 -static void kimage_free_cma(struct kimage *image) +void kexec_free_segment_cma(struct kimage *image, unsigned long idx) { - unsigned long i; + unsigned int nr_pages =3D image->segment_cma_pages[idx]; + struct page *cma =3D image->segment_cma[idx]; =20 - for (i =3D 0; i < image->nr_segments; i++) { - struct page *cma =3D image->segment_cma[i]; - unsigned int nr_pages =3D image->segment_cma_pages[i]; + if (!cma) + return; =20 - if (!cma) - continue; + arch_kexec_pre_free_pages(page_address(cma), nr_pages); + dma_release_from_contiguous(NULL, cma, nr_pages); + image->segment_cma[idx] =3D NULL; + image->segment_cma_pages[idx] =3D 0; +} =20 - arch_kexec_pre_free_pages(page_address(cma), nr_pages); - dma_release_from_contiguous(NULL, cma, nr_pages); - image->segment_cma[i] =3D NULL; - image->segment_cma_pages[i] =3D 0; - } +static void kimage_free_cma(struct kimage *image) +{ + unsigned long i; =20 + for (i =3D 0; i < image->nr_segments; i++) + kexec_free_segment_cma(image, i); } =20 void kimage_free(struct kimage *image) --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout10.his.huawei.com (canpmsgout10.his.huawei.com [113.46.200.225]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 984C63C1097; Wed, 26 Aug 2026 09:25:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.225 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736321; cv=none; b=tClUjYrpVkuUfKpfS1lyLLaTAX3ItkwLwHcPmlnym6+GI3ZGWt7VX5qLWk4WTCpFAwhwELCt3vKVv2/FwLU4GLD5BldiCck2aMmCQyZXDbdoQds4V/j0lIZ5cLUM8maBPOBiabBMwfE35dzdsw8YDleEMGil7ADN2TtTmyX7tqA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736321; c=relaxed/simple; bh=dwgncQqVyzPFNessPOGKN2UeVG9vVedPe+OsTFQgmXU=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=dTRmgnCnUKUCVlNeyxgQBaQathz0iiem27n5ZLofZn9xg9l4xUbNyrURA/Nso3kZSlj6PVc032qwX9o5FRYSt45lW8OffwSOaWSgfDQTllX7fZQSWOig8TbSZKiQaC+AkUIDcNv9ML/aOI41g621cLe4QepL2vuJAxU0xivzt7c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=CtxVcq19; arc=none smtp.client-ip=113.46.200.225 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="CtxVcq19" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=igqtNYMEL8oKIpnu2DrMNvEYzwwJSEovzlP+FnYUOCA=; b=CtxVcq19s4/+nlwp4cUNXfDx1nZiyIWFU4uWCub+//6KtP7pZWS9arcnPlF2LC/ogoKXyeVeP TCuE1W141iovkLTXAPEBXvujBx6CaVYA0od9WENgqjGwUbcGu+QPm1w6sqo05U8KePvOSjI314O 40wUQWbWiVj05nmSEjphxXc= Received: from mail.maildlp.com (unknown [172.19.162.92]) by canpmsgout10.his.huawei.com (SkyGuard) with ESMTPS id 4hVJr63K6dz1K96b; Wed, 26 Aug 2026 17:14:30 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id 3E84140565; Wed, 26 Aug 2026 17:25:16 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:13 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 03/17] arm64: kexec_file: Fix CMA page leaks in segment placement retry loops Date: Wed, 26 Aug 2026 17:25:27 +0800 Message-ID: <20260826092541.3905933-4-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" During kexec image placement retry loops, any midway failure causes the loader to truncate `image->nr_segments` back to its initial state to purge the failed segments. However, this truncation introduces a memory leak. The CMA pages allocated via kexec_add_buffer() during the failed attempt are tracked in the `image->segment_cma` array. Because the subsequent cleanup paths only iterate up to the truncated `nr_segments` boundary, these allocated CMA pages outside the new boundary are permanently leaked. Fix this by explicitly releasing the associated CMA buffers in the failure paths before `image->nr_segments` is reduced. Cc: Catalin Marinas Cc: Will Deacon Cc: Breno Leitao Cc: Pratyush Yadav Cc: Andrew Morton Cc: Yeoreum Yun Cc: Baoquan He Cc: stable@vger.kernel.org Fixes: 07d24902977e4 ("kexec: enable CMA based contiguous allocation") Signed-off-by: Jinjie Ruan --- arch/arm64/kernel/kexec_image.c | 1 + arch/arm64/kernel/machine_kexec_file.c | 5 ++++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/arch/arm64/kernel/kexec_image.c b/arch/arm64/kernel/kexec_imag= e.c index b70f4df15a1a..ffcb7f9075e6 100644 --- a/arch/arm64/kernel/kexec_image.c +++ b/arch/arm64/kernel/kexec_image.c @@ -107,6 +107,7 @@ static void *image_load(struct kimage *image, * We couldn't find space for the other segments; erase the * kernel segment and try the next available hole. */ + kexec_free_segment_cma(image, kernel_segment_number); image->nr_segments -=3D 1; kbuf.buf_min =3D kernel_segment->mem + kernel_segment->memsz; kbuf.mem =3D KEXEC_BUF_MEM_UNKNOWN; diff --git a/arch/arm64/kernel/machine_kexec_file.c b/arch/arm64/kernel/mac= hine_kexec_file.c index 854d872dfd0f..e48f29167b38 100644 --- a/arch/arm64/kernel/machine_kexec_file.c +++ b/arch/arm64/kernel/machine_kexec_file.c @@ -179,7 +179,10 @@ int load_other_segments(struct kimage *image, return 0; =20 out_err: - image->nr_segments =3D orig_segments; + while (image->nr_segments > orig_segments) { + kexec_free_segment_cma(image, image->nr_segments - 1); + image->nr_segments--; + } kvfree(dtb); return ret; } --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout05.his.huawei.com (canpmsgout05.his.huawei.com [113.46.200.220]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D06433D79E2; Wed, 26 Aug 2026 09:25:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.220 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736324; cv=none; b=KuUxiOdI4POyOH5SS1PV/dsUFoxFxEpEHD5eQjdqAqfMnn3m5/02bZ41o8CVNldmuhbK3iPt9MIAYV4i0WKt0WRZS3+Ze7OghOzfcMrqhq49U5nII9YtP8CsChRzgvEQn9zOGkkg1rM9YTLLERuDevUFtp631mcMiwcXCMhWS7o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736324; c=relaxed/simple; bh=yiGxQ7QIQdwQ3p4Fr0ygdVNI7N08QTdXriOuGM/62Gk=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=rB7fFHcHf1Z2uHgBr80OTia1WKYGi518m79A9LCn4xlmcET/pUDN9xXU6hbWKntrcscROfM9gZbZYg/VqBQSjNyEXdF4eKSNSuQeZmwbd0Bj4tFiOQ7y1lAiZvyuhRmAmAGwf3EQLWUAaFnrmH0K4lVftXMZ+o4S8D/kzNNZ5rk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=cXqqzSbx; arc=none smtp.client-ip=113.46.200.220 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="cXqqzSbx" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=RK4VHRefALxjC8rB7K7w3VAwG6W6KlTC58IWMIYwUgI=; b=cXqqzSbxz3lvEuOS9efT6kFVnZWykzECj9tiFIF8xUH5zySw0l0wtrrPJavS5/6c0ugtHU44w TQx608nHzqqoqjifoGQQm3bSkj4dVZdXvljaZRoir8tVoNs8JWQj9Dkf8ZWXUzNH3gtlFlTVTbj f2PJ9QOpTcwTuI1J8MwWSoI= Received: from mail.maildlp.com (unknown [172.19.162.144]) by canpmsgout05.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrj5Vvrz12LDt; Wed, 26 Aug 2026 17:15:01 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id D4F9D4056D; Wed, 26 Aug 2026 17:25:18 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:16 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 04/17] arm64: kexec_file: Fix elf_headers memory leak in retry loop Date: Wed, 26 Aug 2026 17:25:28 +0800 Message-ID: <20260826092541.3905933-5-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" If load_other_segments() fails after image->elf_headers is assigned, the memory lifecycle is safely managed by the global kimage object and will be freed in arch_kimage_file_post_load_cleanup(). However, during a retry loop in image_load(), a subsequent iteration will allocate a new buffer and overwrite image->elf_headers. This permanently leaks the stale memory from the previous iteration before the global cleanup can track it. Fix this by explicitly freeing the stale `image->elf_headers` buffer before assigning the newly allocated headers. Cc: Catalin Marinas Cc: Will Deacon Cc: Thomas Huth Cc: Breno Leitao Cc: Andrew Morton Cc: Yeoreum Yun Cc: Baoquan He Cc: stable@vger.kernel.org Fixes: 108aa503657e ("arm64: kexec_file: try more regions if loading segmen= ts fails") Signed-off-by: Jinjie Ruan --- arch/arm64/kernel/machine_kexec_file.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/arch/arm64/kernel/machine_kexec_file.c b/arch/arm64/kernel/mac= hine_kexec_file.c index e48f29167b38..2f750e5f4fcc 100644 --- a/arch/arm64/kernel/machine_kexec_file.c +++ b/arch/arm64/kernel/machine_kexec_file.c @@ -112,6 +112,10 @@ int load_other_segments(struct kimage *image, vfree(headers); goto out_err; } + + if (unlikely(image->elf_headers)) + vfree(image->elf_headers); + image->elf_headers =3D headers; image->elf_load_addr =3D kbuf.mem; image->elf_headers_sz =3D headers_sz; --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout02.his.huawei.com (canpmsgout02.his.huawei.com [113.46.200.217]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C8C0A3DB62F; Wed, 26 Aug 2026 09:25:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.217 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736334; cv=none; b=CdENcj1CaVZmSt7vSyMZmx9vBCsgRnN6KefWMWxabGCzij+AcVJKvHmRhNbReuHhth3RlL8e/6ni1geNIjX8LAiWCvQKchOmZZ8KNMMph/bzALIx8nJTwQrsi61QNQZ1aFTXsv08hQPXVr6kKBwkMzQDBP2VspmxlTWNzae+qdA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736334; c=relaxed/simple; bh=pqwmROV2ldLwW0tL4b4mcAsvlFNFi2XdYsiPH9Ty7ls=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=JhuplIirqe1UXbdNpheXDRY3MAa8yoglvPWoH3vTXP4HraVk3dQo8SzMBph8/P6JTJftWLfvEWrGT4f/kWki7F4baFt+W7L1wjngEIo9s4AaPnnZ2wG1rpiYioRC801vyS3ejf6w6dwvHNiv/mbPdK6JznvZF9Um2IQmjCPLCgU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=xq1YbTvD; arc=none smtp.client-ip=113.46.200.217 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="xq1YbTvD" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=C/N27OffVwB9HknmerMZN+vGpNQOngX4+yhYYxhlpgs=; b=xq1YbTvD3XNNnXqFEYm+rNDxG6EdsqcQH0HTMN1s5TayGIm1XkNSyQvmkbCWJmLw2RC3Hg9MW 03OTT0taTlXRmwul+dn+StNpv/it+wBQ3leQZDkbShT3eaE7XAglReIYtuKqLTKOKW4s7jvAaSh i66n7enwbsFGUXQhFmGkLKQ= Received: from mail.maildlp.com (unknown [172.19.163.104]) by canpmsgout02.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrS2MbVzcbMk; Wed, 26 Aug 2026 17:14:48 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id 2935A4058C; Wed, 26 Aug 2026 17:25:21 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:18 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 05/17] LoongArch: kexec: Fix CMA page leaks in segment placement retry loops Date: Wed, 26 Aug 2026 17:25:29 +0800 Message-ID: <20260826092541.3905933-6-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" During kexec image placement retry loops, any midway failure causes the loader to truncate `image->nr_segments` back to its initial state to purge the failed segments. However, this truncation introduces a memory leak. The CMA pages allocated via kexec_add_buffer() during the failed attempt are tracked in the `image->segment_cma` array. Because the subsequent cleanup paths only iterate up to the truncated `nr_segments` boundary, these allocated CMA pages outside the new boundary are permanently leaked. Fix this by explicitly releasing the associated CMA buffers in the failure paths before `image->nr_segments` is reduced. Cc: Huacai Chen Cc: WANG Xuerui Cc: Youling Tang Cc: "Mike Rapoport (Microsoft)" Cc: Sourabh Jain Cc: Kees Cook Cc: stable@vger.kernel.org Link: https://sashiko.dev/#/patchset/20260729031235.2840255-1-ruanjinjie%40= huawei.com Fixes: 55d990f0084c ("LoongArch: Add EFI binary support for kexec_file") Signed-off-by: Jinjie Ruan --- arch/loongarch/kernel/kexec_efi.c | 1 + arch/loongarch/kernel/machine_kexec_file.c | 6 +++++- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/arch/loongarch/kernel/kexec_efi.c b/arch/loongarch/kernel/kexe= c_efi.c index 5ee78ebb1546..15fd797ff3de 100644 --- a/arch/loongarch/kernel/kexec_efi.c +++ b/arch/loongarch/kernel/kexec_efi.c @@ -86,6 +86,7 @@ static void *efi_kexec_load(struct kimage *image, * We couldn't find space for the other segments; erase the * kernel segment and try the next available hole. */ + kexec_free_segment_cma(image, kernel_segment_number); image->nr_segments -=3D 1; kbuf.buf_min =3D kernel_segment->mem + kernel_segment->memsz; kbuf.mem =3D KEXEC_BUF_MEM_UNKNOWN; diff --git a/arch/loongarch/kernel/machine_kexec_file.c b/arch/loongarch/ke= rnel/machine_kexec_file.c index 5412aa9f3568..62a5be102065 100644 --- a/arch/loongarch/kernel/machine_kexec_file.c +++ b/arch/loongarch/kernel/machine_kexec_file.c @@ -217,7 +217,11 @@ int load_other_segments(struct kimage *image, return 0; =20 out_err: - image->nr_segments =3D orig_segments; + while (image->nr_segments > orig_segments) { + kexec_free_segment_cma(image, image->nr_segments - 1); + image->nr_segments--; + } + kfree(modified_cmdline); return ret; } --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout04.his.huawei.com (canpmsgout04.his.huawei.com [113.46.200.219]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E27F93DAAD8; Wed, 26 Aug 2026 09:25:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.219 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736329; cv=none; b=BRZk1ZxEDeQhAx+GUsdetssr7no9OKj6o2pMqR08+lEdPdg7Sqq4s9m7QKikQxmrFgLTw6wP+3fb6kw+SyETPVnHvMqgEYuVEaT6t1kmF9oM/L6vcA+HeXbcrGFVpUCv0M//JZHV17zpQOR96kn6UbmyuUsNGwmYYcwUrkjrI7k= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736329; c=relaxed/simple; bh=LUUN6hor9kB1vGW9ORLacT7hasUnGUVa0oXa/BtcYiM=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=DaopaWaV4quiK0Ir5DVj/qxbn6tT1h2jPznDZdRkJlL59Uu7P2MWvOtAtEM8CQzO2Bnshu5MsaBP94SAPvYRwwjefaVilFpiY3uzEvJXyjtk1qD4OVKfqDAxFZm7wylYks+ag3R9ikmABiI8A/fC0lLw9skvzrlWoCvgm63tD0A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=WJsU5ZLP; arc=none smtp.client-ip=113.46.200.219 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="WJsU5ZLP" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=up4/oktyfAdON3km3wdZWwjp1/r+vQu8s3QiiQB06UU=; b=WJsU5ZLPqqnObamEl+eDb1OQLn8fzTm2lS+jqZvsjkBOcZoPNvOCq137VskBlGKfkXIRHLxz0 r3TIwLJgnYKX+hhXcyhYsMrcfZw4l3uKg5x5sTenzOpFogQlp8Dx4ywI3SARgUR1LDQ5r9Wjz1F GJzxQD5oYk6LTh2w3OIGcw8= Received: from mail.maildlp.com (unknown [172.19.162.223]) by canpmsgout04.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrC6g9Pz1prNF; Wed, 26 Aug 2026 17:14:35 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id 6EC4740561; Wed, 26 Aug 2026 17:25:23 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:21 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 06/17] LoongArch: kexec_file: Fix elf_headers memory leak in retry loop Date: Wed, 26 Aug 2026 17:25:30 +0800 Message-ID: <20260826092541.3905933-7-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" If load_other_segments() fails after image->elf_headers is assigned, the memory lifecycle is safely managed by the global kimage object and will be freed in arch_kimage_file_post_load_cleanup(). However, during a retry loop in efi_kexec_load(), a subsequent iteration will allocate a new buffer and overwrite image->elf_headers. This permanently leaks the stale memory from the previous iteration before the global cleanup can track it. Fix this by explicitly freeing the stale `image->elf_headers` buffer before assigning the newly allocated headers. Cc: Huacai Chen Cc: WANG Xuerui Cc: Youling Tang Cc: "Mike Rapoport (Microsoft)" Cc: Sourabh Jain Cc: Kees Cook Cc: stable@vger.kernel.org Link: https://sashiko.dev/#/patchset/20260729031235.2840255-1-ruanjinjie%40= huawei.com Fixes: 55d990f0084c ("LoongArch: Add EFI binary support for kexec_file") Signed-off-by: Jinjie Ruan --- arch/loongarch/kernel/machine_kexec_file.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/arch/loongarch/kernel/machine_kexec_file.c b/arch/loongarch/ke= rnel/machine_kexec_file.c index 62a5be102065..3beb6977ecc6 100644 --- a/arch/loongarch/kernel/machine_kexec_file.c +++ b/arch/loongarch/kernel/machine_kexec_file.c @@ -166,6 +166,10 @@ int load_other_segments(struct kimage *image, vfree(headers); goto out_err; } + + if (unlikely(image->elf_headers)) + vfree(image->elf_headers); + image->elf_headers =3D headers; image->elf_load_addr =3D kbuf.mem; image->elf_headers_sz =3D headers_sz; --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout07.his.huawei.com (canpmsgout07.his.huawei.com [113.46.200.222]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5094630F958; Wed, 26 Aug 2026 09:25:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.222 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736330; cv=none; b=i3BoorBQH8MQzklpoC5BHMDLRaG9ahu/OcdDqwwFj56qF8bS0WIbXt8TlYoYPuu/+Yp6Fb96Q8eo6wsN/aOlZGNDcQM3YpNHK10b37slELJMaGW3i2i/AEro4Mf+QuFhpST0clW5hC1YrOn08w2KNUuahOoX5PRhaH0J15yrFWU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736330; c=relaxed/simple; bh=Gux6e2rOWG5ce6XalVJRUELCND74gCjevVy+uRKnBfo=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=XC5TQsJSUZwDjEeA3rqPhTzMEsigAbtBTpY40MK1U20ttCuhgxENkXXRGdI2Pa0C7KgVFp1oqfABgzrERdG8iMgFExI5uuzSOpcsxshzv2+fN9TbGKcYMpNo8LAhcq3VOYditEOfZMoUHYeoDXGIvGTEnautvgbDfPJpEPOGD1g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=i/qQKHNz; arc=none smtp.client-ip=113.46.200.222 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="i/qQKHNz" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=y759v80hfcLGexoE6U+P0qCW895e0rqrtykfndhs3p4=; b=i/qQKHNz8OxKmJLSE6ETOW3Vyzml5TlfhhQAVfoBCgLl3ppxbzz6ZfYvrUMLwW7wzTAHquxJ5 7xkkPqtSSJUuN3dgmG4MYGSJZEltvqtaf1bLmuJ2Nfz2lINRwFVWYySZIoIptnPTMwZvuSdXvB9 ZX7arRtCRna8ymHdQexhtqQ= Received: from mail.maildlp.com (unknown [172.19.162.92]) by canpmsgout07.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrJ0mhvzLlXB; Wed, 26 Aug 2026 17:14:40 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id B445D4058A; Wed, 26 Aug 2026 17:25:25 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:23 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 07/17] crash_dump: Fix potential double-free of keys_header Date: Wed, 26 Aug 2026 17:25:31 +0800 Message-ID: <20260826092541.3905933-8-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" `keys_header` was freed in `build_keys_header()` without being reset to NULL, and the error path in `crash_load_dm_crypt_keys()` freed it unconditionally even when reused, leading to double-free or use-after-free. Add `free_keys_header()` to centralize freeing and NULL-setting. Use it in `build_keys_header()` and only free in the error path when the header was newly built (`!is_dm_key_reused`). Cc: Andrew Morton Cc: Baoquan He Cc: Mike Rapoport Cc: Pasha Tatashin Cc: Pratyush Yadav Cc: Dave Young Cc: stable@vger.kernel.org Fixes: e3a84be1ec2f ("arm64,ppc64le/kdump: pass dm-crypt keys to kdump kern= el") Signed-off-by: Jinjie Ruan --- kernel/crash_dump_dm_crypt.c | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) diff --git a/kernel/crash_dump_dm_crypt.c b/kernel/crash_dump_dm_crypt.c index c685497cd470..ed0960ff0987 100644 --- a/kernel/crash_dump_dm_crypt.c +++ b/kernel/crash_dump_dm_crypt.c @@ -363,15 +363,21 @@ static struct configfs_subsystem config_keys_subsys = =3D { }, }; =20 +static void free_keys_header(void) +{ + if (keys_header) { + kvfree(keys_header); + keys_header =3D NULL; + } +} + static int build_keys_header(void) { struct config_item *item =3D NULL; struct config_key *key; int i, r; =20 - if (keys_header !=3D NULL) - kvfree(keys_header); - + free_keys_header(); keys_header =3D kzalloc(get_keys_header_size(key_count), GFP_KERNEL); if (!keys_header) return -ENOMEM; @@ -441,7 +447,8 @@ int crash_load_dm_crypt_keys(struct kimage *image) r =3D kexec_add_buffer(&kbuf); if (r) { pr_err("Failed to call kexec_add_buffer, ret=3D%d\n", r); - kvfree((void *)kbuf.buffer); + if (!is_dm_key_reused) + free_keys_header(); return r; } image->dm_crypt_keys_addr =3D kbuf.mem; --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout06.his.huawei.com (canpmsgout06.his.huawei.com [113.46.200.221]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 34DFB3E022C; Wed, 26 Aug 2026 09:25:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.221 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736335; cv=none; b=JgZu6YrLHc0HHCQ2hpEoLDzZFTYBNicxLaq/dvybaLz6FGwqxB4fc1cWP1sQ2eYgK/RPPCLPNlJX/dt3mTrZ5c+WNNLnDRzqdDcBt3/HGUuVUUy/9E0XFqQfqt346mDNPTOwtO/ZwCEuwWmNH1DDiansSM0xt2phuMln9QxuZ/Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736335; c=relaxed/simple; bh=4dgOcWsb0wUMNxIrA2b9vrtUC420NG02zpCd7pGO7o8=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=smhNymL8zfOkaLxvL/7NPZNwgpAkolJVFPAedYBS7J+urn2xMwqKMIrViSA8epj8nY9hHz6HXBaF9OqFxtG423zrP+Cw2AftmfKaP2te/3Z9Zu1b1ILlwCNRyhBA+0Y+F2JFWdI9Qi0FlXcUY1drqRxjh+VMB6uZixjEsTrHG14= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=JX+hJB4h; arc=none smtp.client-ip=113.46.200.221 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="JX+hJB4h" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=0gF1CX+SLowxFh9fJKRvX/sCOgXb1E06TJatahYgRnw=; b=JX+hJB4hTDDgkqA1/sg50c8MkVgqGYd5+tQwQD3uhUYhWr5tSyj9b7DiiSZk+6f6uc8AIE9K+ ir0Lyq63+jQ7c35zwdyKfSwDnYHnSJCkKIb5GmhVr88An2gsqRKmbRDNYbe4sIKFnFBQ50Jwe6I os3GmFKja6Un1xAaUllqd0w= Received: from mail.maildlp.com (unknown [172.19.163.104]) by canpmsgout06.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrN2SFjzRhrs; Wed, 26 Aug 2026 17:14:44 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id 0BF314058C; Wed, 26 Aug 2026 17:25:28 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:25 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 08/17] crash: Extract crash_get_memory_ranges() helper Date: Wed, 26 Aug 2026 17:25:32 +0800 Message-ID: <20260826092541.3905933-9-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" Factor out the crash memory range collection logic from crash_prepare_headers() into a separate function. This allows the memory hotplug path to obtain and modify the range list (e.g. remove offlined memory) before generating the elfcorehdr. Cc: Andrew Morton Cc: Baoquan He Cc: Mike Rapoport Cc: Pasha Tatashin Cc: Pratyush Yadav Cc: Dave Young Signed-off-by: Jinjie Ruan --- include/linux/crash_core.h | 1 + kernel/crash_core.c | 22 +++++++++++++++++++--- 2 files changed, 20 insertions(+), 3 deletions(-) diff --git a/include/linux/crash_core.h b/include/linux/crash_core.h index bc087124cd78..619af312bd9a 100644 --- a/include/linux/crash_core.h +++ b/include/linux/crash_core.h @@ -62,6 +62,7 @@ extern int crash_prepare_elf64_headers(struct crash_mem *= mem, int need_kernel_ma extern int crash_prepare_headers(int need_kernel_map, void **addr, unsigned long *sz, unsigned long *nr_mem_ranges); extern int crash_exclude_core_ranges(struct crash_mem **cmem); +extern int crash_get_memory_ranges(struct crash_mem **mem_ranges); =20 struct kimage; struct kexec_segment; diff --git a/kernel/crash_core.c b/kernel/crash_core.c index d0bd2d0cf899..991d1599cf9a 100644 --- a/kernel/crash_core.c +++ b/kernel/crash_core.c @@ -317,8 +317,7 @@ int crash_exclude_core_ranges(struct crash_mem **cmem) return 0; } =20 -int crash_prepare_headers(int need_kernel_map, void **addr, unsigned long = *sz, - unsigned long *nr_mem_ranges) +int crash_get_memory_ranges(struct crash_mem **mem_ranges) { unsigned int max_nr_ranges; struct crash_mem *cmem; @@ -344,13 +343,30 @@ int crash_prepare_headers(int need_kernel_map, void *= *addr, unsigned long *sz, if (ret) goto out; =20 + *mem_ranges =3D cmem; + return 0; + +out: + kvfree(cmem); + return ret; +} + +int crash_prepare_headers(int need_kernel_map, void **addr, unsigned long = *sz, + unsigned long *nr_mem_ranges) +{ + struct crash_mem *cmem =3D NULL; + int ret; + + ret =3D crash_get_memory_ranges(&cmem); + if (ret) + return ret; + /* Return the computed number of memory ranges, for hotplug usage */ if (nr_mem_ranges) *nr_mem_ranges =3D cmem->nr_ranges; =20 ret =3D crash_prepare_elf64_headers(cmem, need_kernel_map, addr, sz); =20 -out: kvfree(cmem); return ret; } --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout08.his.huawei.com (canpmsgout08.his.huawei.com [113.46.200.223]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7CBA43E1688; Wed, 26 Aug 2026 09:25:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.223 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736338; cv=none; b=oontvuyIY8jDGznjFxW4PvWsFl5wZqFoOayuwlV2WWIHb15f5ewyTRSxBSfE2Nqys6o0mKGbbtBjkXeC3YIl/obE2ssRbeGYLT6CaMbEVkvmLfp1dvMY9Q/znYEoKB6ApgM+rVF47xYeEn7By0l5b3M2k+hZxnQoFbzU8oqDuQg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736338; c=relaxed/simple; bh=mzfFYRFfS9u5sI5K8D5V0nfIRv40HqZCJHBJb7ryyNg=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Ws9IBPVxD/e69t0FiN4j/ofd0t/05Qs7jAYUoui1seTgMm/F+28jU2PWOI0WibXD4nX+c0k6cDkxIYDxBrdYPEk7IlSaY/9AP9aAi9g0oQuXZpdVnyJMo/ljOgsojbi8UM9cs/7cCqSUm7UhCLMvvjGRYvglmyN/j6QThTFcpb4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=3MdARlzQ; arc=none smtp.client-ip=113.46.200.223 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="3MdARlzQ" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=Cgw5ZyBI8tRtEDh7EDDRec6LYICayfmN/Ij1j/3X5fQ=; b=3MdARlzQun+xzAHOJhU4sO7o1K3lj0gTWdnFc55tBXyFjPHnWZTqiO3DmfdrhM0KvbpYg+PLQ Gm2jGZjDNIHD7qJ+XMi6WDQTtzAxhZwAd0rjnzFXn/r+AS2pkKxpOgdhXBJBi3/8JVnX+40fxH7 PhonXjGR1KQyVYU0TBpsG08= Received: from mail.maildlp.com (unknown [172.19.163.15]) by canpmsgout08.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrN45zdzmVb6; Wed, 26 Aug 2026 17:14:44 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id 5C57740586; Wed, 26 Aug 2026 17:25:30 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:27 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 09/17] crash: Fix TOCTOU race in crash memory range collection Date: Wed, 26 Aug 2026 17:25:33 +0800 Message-ID: <20260826092541.3905933-10-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" The crash kernel ELF core header construction counts system memory ranges via `arch_get_system_nr_ranges()`, allocates the crash_mem buffer, and then populates it via `arch_crash_populate_cmem()`. This sequence has a time-of-check-to-time-of-use (TOCTOU) race with memory hotplug: a concurrent hotplug event between the count and populate steps can increase the number of ranges beyond the allocated capacity, causing an out-of-bounds write. If the event triggers memblock_double_array(), the memblock array can be freed and reallocated during iteration, leading to a use-after-free. Protect the entire range collection with device_hotplug_lock. Since the hotplug notification path already holds that lock, add a lockless helper, crash_get_memory_ranges_nolock(), for use there. The regular crash_get_memory_ranges() acquires the lock and calls the helper. Cc: stable@vger.kernel.org Cc: Andrew Morton Cc: Baoquan He Cc: Mike Rapoport Cc: Pasha Tatashin Cc: Pratyush Yadav Cc: Dave Young Cc: AKASHI Takahiro Cc: Will Deacon Cc: James Morse Cc: Palmer Dabbelt Cc: Youling Tang Cc: Huacai Chen Fixes: 8d5f894a3108 ("x86: kexec_file: lift CRASH_MAX_RANGES limit on crash= _mem buffer") Fixes: 3751e728cef2 ("arm64: kexec_file: add crash dump support") Fixes: 8acea455fafa ("RISC-V: Support for kexec_file on panic") Fixes: 1bcca8620a91 ("LoongArch: Add crash dump support for kexec_file") Link: https://sashiko.dev/#/patchset/20260729031235.2840255-1-ruanjinjie%40= huawei.com Signed-off-by: Jinjie Ruan --- arch/x86/kernel/crash.c | 9 ++++++++- include/linux/crash_core.h | 2 +- kernel/crash_core.c | 28 +++++++++++++++++++++++++++- 3 files changed, 36 insertions(+), 3 deletions(-) diff --git a/arch/x86/kernel/crash.c b/arch/x86/kernel/crash.c index e6f23933a6df..8f8c0e592849 100644 --- a/arch/x86/kernel/crash.c +++ b/arch/x86/kernel/crash.c @@ -448,6 +448,7 @@ unsigned int arch_crash_get_elfcorehdr_size(void) void arch_crash_handle_hotplug_event(struct kimage *image, void *arg) { void *elfbuf =3D NULL, *old_elfcorehdr; + struct crash_mem *cmem =3D NULL; unsigned long mem, memsz; unsigned long elfsz =3D 0; =20 @@ -461,11 +462,16 @@ void arch_crash_handle_hotplug_event(struct kimage *i= mage, void *arg) (image->hp_action =3D=3D KEXEC_CRASH_HP_REMOVE_CPU))) return; =20 + if (crash_get_memory_ranges_nolock(&cmem)) { + pr_err("Failed to get crash mem range\n"); + goto out; + } + /* * Create the new elfcorehdr reflecting the changes to CPU and/or * memory resources. */ - if (crash_prepare_headers(IS_ENABLED(CONFIG_X86_64), &elfbuf, &elfsz, NUL= L)) { + if (crash_prepare_elf64_headers(cmem, IS_ENABLED(CONFIG_X86_64), &elfbuf,= &elfsz)) { pr_err("unable to create new elfcorehdr"); goto out; } @@ -502,6 +508,7 @@ void arch_crash_handle_hotplug_event(struct kimage *ima= ge, void *arg) pr_debug("updated elfcorehdr\n"); =20 out: + kvfree(cmem); vfree(elfbuf); } #endif diff --git a/include/linux/crash_core.h b/include/linux/crash_core.h index 619af312bd9a..6789ff0af39e 100644 --- a/include/linux/crash_core.h +++ b/include/linux/crash_core.h @@ -62,7 +62,7 @@ extern int crash_prepare_elf64_headers(struct crash_mem *= mem, int need_kernel_ma extern int crash_prepare_headers(int need_kernel_map, void **addr, unsigned long *sz, unsigned long *nr_mem_ranges); extern int crash_exclude_core_ranges(struct crash_mem **cmem); -extern int crash_get_memory_ranges(struct crash_mem **mem_ranges); +extern int crash_get_memory_ranges_nolock(struct crash_mem **mem_ranges); =20 struct kimage; struct kexec_segment; diff --git a/kernel/crash_core.c b/kernel/crash_core.c index 991d1599cf9a..05a2a8be083d 100644 --- a/kernel/crash_core.c +++ b/kernel/crash_core.c @@ -7,6 +7,7 @@ #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt =20 #include +#include #include #include #include @@ -317,7 +318,21 @@ int crash_exclude_core_ranges(struct crash_mem **cmem) return 0; } =20 -int crash_get_memory_ranges(struct crash_mem **mem_ranges) +/** + * crash_get_memory_ranges_nolock - Collect crash kernel memory ranges + * @mem_ranges: Output parameter for the allocated crash_mem structure + * + * Gathers the system memory ranges to be included in the crash kernel's + * ELF core header, excluding the crashkernel reserved region and other + * architecture-specific areas. + * + * Context: Caller must hold device_hotplug_lock. + * + * Return: 0 on success, in which case *@mem_ranges points to a newly + * allocated struct crash_mem that the caller must free with kvfree(). + * Returns a negative error code on failure. + */ +int crash_get_memory_ranges_nolock(struct crash_mem **mem_ranges) { unsigned int max_nr_ranges; struct crash_mem *cmem; @@ -351,6 +366,17 @@ int crash_get_memory_ranges(struct crash_mem **mem_ran= ges) return ret; } =20 +static int crash_get_memory_ranges(struct crash_mem **mem_ranges) +{ + int ret; + + lock_device_hotplug(); + ret =3D crash_get_memory_ranges_nolock(mem_ranges); + unlock_device_hotplug(); + + return ret; +} + int crash_prepare_headers(int need_kernel_map, void **addr, unsigned long = *sz, unsigned long *nr_mem_ranges) { --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout10.his.huawei.com (canpmsgout10.his.huawei.com [113.46.200.225]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 874E53E49C3; Wed, 26 Aug 2026 09:25:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.225 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736340; cv=none; b=QmN3nSi6rA42I7F67iVFMZF/LcZbQTtFUpOHIJOMygUuf7BVc/WO2gr1KsjRli+Ecs2150K+hG3K/biem4irbmyAu7x8d7CQtcJ603idYfllQnWpFCeoGrXjvztgBSIgLodJmoF0M/hOf3Snn7OaTtZYmE5mG9OR12X1wvcRwGo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736340; c=relaxed/simple; bh=hj7O0mc+N7oLs2vHmLb6D4Xl+JoGYOjT34wtqVr/QSI=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Y+7J1Tx/t7B18E34Hq8TrurfSxgA7bIkQfkw5q6prfDCBW/TXoEGTT0xmimylbB8K/oorKKOZyqncEWWt9xaJ6i+4nNzSm1+FMerIgWvraw/ObLwwjApq8Acn0EBAKQdyNsxHhsAoeJivChxod7RXRoeUZC36GIiqmC8QCIxME8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=ZJrMcXmw; arc=none smtp.client-ip=113.46.200.225 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="ZJrMcXmw" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=KafofVQEPWxjkKkXavgX1N/QAvKy21rncyT7kiECYKY=; b=ZJrMcXmwPlgzadHtphWXfa6syHPyy8XhgReWZ7UmfF+ftCT3E/BT8h8jt/WPwO9Gl7FX0Gdce FpBge1xJOiNT4y51fY4AFonznIyQJqB8mR//FJpoYo4ihkvBHHjsaciISJu+jrSzckYhIAuxH6G okgGEcDZkqcaw6iUFcDeVKY= Received: from mail.maildlp.com (unknown [172.19.163.214]) by canpmsgout10.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrQ6Fxpz1K96b; Wed, 26 Aug 2026 17:14:46 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id A22634057C; Wed, 26 Aug 2026 17:25:32 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:30 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 10/17] elf: Introduce elf64_phdr_size() helper Date: Wed, 26 Aug 2026 17:25:34 +0800 Message-ID: <20260826092541.3905933-11-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" Add a common helper to compute the total size of an ELF64 header (Ehdr + program headers) from the number of program headers. Replace open-coded calculations in powerpc, x86, vmcore, and crash_core. On ppc64, struct elfhdr maps to elf64_hdr, so the powerpc change is a pure cleanup. No functional change intended. Cc: Madhavan Srinivasan Cc: Michael Ellerman Cc: Nicholas Piggin Cc: "Christophe Leroy (CS GROUP)" Cc: Thomas Gleixner Cc: Ingo Molnar Cc: Borislav Petkov Cc: Dave Hansen Cc: "H. Peter Anvin" Cc: Andrew Morton Cc: Baoquan He Cc: Mike Rapoport Cc: Pasha Tatashin Cc: Pratyush Yadav Cc: Dave Young Cc: Kees Cook Cc: Sourabh Jain Signed-off-by: Jinjie Ruan --- arch/powerpc/kexec/crash.c | 2 +- arch/powerpc/platforms/powernv/opal-core.c | 3 +-- arch/x86/kernel/crash.c | 3 +-- fs/proc/vmcore.c | 6 ++---- include/linux/elf.h | 4 ++++ kernel/crash_core.c | 2 +- 6 files changed, 10 insertions(+), 10 deletions(-) diff --git a/arch/powerpc/kexec/crash.c b/arch/powerpc/kexec/crash.c index 775895f31037..fc0105c7af4c 100644 --- a/arch/powerpc/kexec/crash.c +++ b/arch/powerpc/kexec/crash.c @@ -478,7 +478,7 @@ unsigned int arch_crash_get_elfcorehdr_size(void) if (IS_ENABLED(CONFIG_MEMORY_HOTPLUG)) phdr_cnt +=3D CONFIG_CRASH_MAX_MEMORY_RANGES; =20 - return sizeof(struct elfhdr) + (phdr_cnt * sizeof(Elf64_Phdr)); + return elf64_phdr_size(phdr_cnt); } =20 /** diff --git a/arch/powerpc/platforms/powernv/opal-core.c b/arch/powerpc/plat= forms/powernv/opal-core.c index 32662d30d70f..fc0aad61504b 100644 --- a/arch/powerpc/platforms/powernv/opal-core.c +++ b/arch/powerpc/platforms/powernv/opal-core.c @@ -309,8 +309,7 @@ static int __init create_opalcore(void) char *bufp; =20 /* Get size of header & CPU notes for OPAL core */ - hdr_size =3D (sizeof(Elf64_Ehdr) + - ((oc_conf->ptload_cnt + 1) * sizeof(Elf64_Phdr))); + hdr_size =3D elf64_phdr_size(oc_conf->ptload_cnt + 1); cpu_notes_size =3D ((oc_conf->num_cpus * (CRASH_CORE_NOTE_HEAD_BYTES + CRASH_CORE_NOTE_NAME_BYTES + CRASH_CORE_NOTE_DESC_BYTES)) + diff --git a/arch/x86/kernel/crash.c b/arch/x86/kernel/crash.c index 8f8c0e592849..a3bf786286d4 100644 --- a/arch/x86/kernel/crash.c +++ b/arch/x86/kernel/crash.c @@ -374,8 +374,7 @@ int crash_load_segments(struct kimage *image) pnum +=3D 2 + CONFIG_NR_CPUS; =20 if (pnum < (unsigned long)PN_XNUM) { - kbuf.memsz =3D pnum * sizeof(Elf64_Phdr); - kbuf.memsz +=3D sizeof(Elf64_Ehdr); + kbuf.memsz =3D elf64_phdr_size(pnum); =20 image->elfcorehdr_index =3D image->nr_segments; =20 diff --git a/fs/proc/vmcore.c b/fs/proc/vmcore.c index 44d15436439f..ff324969d798 100644 --- a/fs/proc/vmcore.c +++ b/fs/proc/vmcore.c @@ -1238,8 +1238,7 @@ static int __init parse_crash_elf64_headers(void) } =20 /* Read in all elf headers. */ - elfcorebuf_sz_orig =3D sizeof(Elf64_Ehdr) + - ehdr.e_phnum * sizeof(Elf64_Phdr); + elfcorebuf_sz_orig =3D elf64_phdr_size(ehdr.e_phnum); elfcorebuf_sz =3D elfcorebuf_sz_orig; elfcorebuf =3D (void *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, get_order(elfcorebuf_sz_orig)); @@ -1605,8 +1604,7 @@ static int vmcore_add_device_ram_elf64(struct list_he= ad *list, size_t count) } =20 /* elfcorebuf_sz must always cover full pages. */ - new_size =3D sizeof(Elf64_Ehdr) + - (ehdr->e_phnum + count) * sizeof(Elf64_Phdr); + new_size =3D elf64_phdr_size(ehdr->e_phnum + count); new_size =3D roundup(new_size, PAGE_SIZE); =20 /* diff --git a/include/linux/elf.h b/include/linux/elf.h index 5c402788da19..400f58a13d92 100644 --- a/include/linux/elf.h +++ b/include/linux/elf.h @@ -109,4 +109,8 @@ static inline int arch_elf_adjust_prot(int prot, } #endif =20 +static inline unsigned long elf64_phdr_size(unsigned long phdr_cnt) +{ + return phdr_cnt * sizeof(Elf64_Phdr) + sizeof(Elf64_Ehdr); +} #endif /* _LINUX_ELF_H */ diff --git a/kernel/crash_core.c b/kernel/crash_core.c index 05a2a8be083d..bd3f82b62751 100644 --- a/kernel/crash_core.c +++ b/kernel/crash_core.c @@ -193,7 +193,7 @@ int crash_prepare_elf64_headers(struct crash_mem *mem, = int need_kernel_map, */ =20 nr_phdr++; - elf_sz =3D sizeof(Elf64_Ehdr) + nr_phdr * sizeof(Elf64_Phdr); + elf_sz =3D elf64_phdr_size(nr_phdr); elf_sz =3D ALIGN(elf_sz, ELF_CORE_HEADER_ALIGN); =20 buf =3D vzalloc(elf_sz); --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout03.his.huawei.com (canpmsgout03.his.huawei.com [113.46.200.218]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 79F973E1232; Wed, 26 Aug 2026 09:25:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.218 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736341; cv=none; b=inWDjVON68H+NhFVwXY3aoEI57qh06e8E61gH4QAnnSag5AgfUMv4XfVPM2CIUhOxtVU5qXh1C9BQjT+v7ZuVtUjcdaJD4wPhSkVN4ZLlEITCehb+M1zV5EsAjFRupvhTRrjPZxdifWyBvePc8UoAOerjVpczWHsN7mZr9n9IOU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736341; c=relaxed/simple; bh=KIduKjWG/Jw+fuabu45aCN9A79gkp85fMH3esbGjIv4=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=oRULZ+1hGA4nnT7Ygh7BfQO5SoGO7aGhp9UM5BBtFRyOA6PO5Gv2LTjwvVaE6jcXfwbuZIwXOQVa4s40sQP938BcrD6S7Q39sA+CDVVeneV0jp4DLMJ1Bxm2mrnjwfjVy1aIgYVn6UenoPvRQoc6fp9iF3pFNooS/1zppUO93Uk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=GB6QEE65; arc=none smtp.client-ip=113.46.200.218 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="GB6QEE65" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=AjFAkRrhVUTBFTsQMyUNsvLp/GHcd37S7PEMXZOcAZ4=; b=GB6QEE65ILKvCbQpXecQEb/ua/x3iezR7nE2mn7WyYvYlY4SUXxQ83iR38qyJiKIbAgDODNlH MU8cWojiXPCrCQ5dhsBQrS1ENBNRxVIcl10fi/R92xWzffLm8zRiqYcpNm7ebeVpN3c6nk/FktV hqwqWG9q2cn4HV8W9tiTxUc= Received: from mail.maildlp.com (unknown [172.19.162.144]) by canpmsgout03.his.huawei.com (SkyGuard) with ESMTPS id 4hVJr24p4czpTHV; Wed, 26 Aug 2026 17:14:26 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id 0D1434056D; Wed, 26 Aug 2026 17:25:35 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:32 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 11/17] crash: Introduce crash_extra_elfcorehdr_size() helper Date: Wed, 26 Aug 2026 17:25:35 +0800 Message-ID: <20260826092541.3905933-12-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" Extract the elfcorehdr extra space calculation from powerpc into a generic helper crash_extra_elfcorehdr_size() for use by other architectures. The helper includes compile-time and runtime checks, it also checks whether the total number of program headers (including fixed headers for kernel_map, VMCOREINFO, and CPU notes) exceeds PN_XNUM, and provides a stub when crash/memory hotplug is disabled. Cc: Madhavan Srinivasan Cc: Michael Ellerman Cc: Nicholas Piggin Cc: "Christophe Leroy (CS GROUP)" Cc: Andrew Morton Cc: Baoquan He Cc: Mike Rapoport Cc: Pasha Tatashin Cc: Pratyush Yadav Cc: Dave Young Cc: Sourabh Jain Signed-off-by: Jinjie Ruan --- arch/powerpc/kexec/file_load_64.c | 19 +------------------ include/linux/crash_core.h | 26 ++++++++++++++++++++++++++ 2 files changed, 27 insertions(+), 18 deletions(-) diff --git a/arch/powerpc/kexec/file_load_64.c b/arch/powerpc/kexec/file_lo= ad_64.c index 6075b1c88511..2b0325e4a628 100644 --- a/arch/powerpc/kexec/file_load_64.c +++ b/arch/powerpc/kexec/file_load_64.c @@ -374,23 +374,6 @@ static int load_backup_segment(struct kimage *image, s= truct kexec_buf *kbuf) return 0; } =20 -static unsigned int kdump_extra_elfcorehdr_size(struct crash_mem *cmem) -{ -#if defined(CONFIG_CRASH_HOTPLUG) && defined(CONFIG_MEMORY_HOTPLUG) - unsigned int extra_sz =3D 0; - - if (CONFIG_CRASH_MAX_MEMORY_RANGES > (unsigned int)PN_XNUM) - pr_warn("Number of Phdrs %u exceeds max\n", CONFIG_CRASH_MAX_MEMORY_RANG= ES); - else if (cmem->nr_ranges >=3D CONFIG_CRASH_MAX_MEMORY_RANGES) - pr_warn("Configured crash mem ranges may not be enough\n"); - else - extra_sz =3D (CONFIG_CRASH_MAX_MEMORY_RANGES - cmem->nr_ranges) * sizeof= (Elf64_Phdr); - - return extra_sz; -#endif - return 0; -} - /** * load_elfcorehdr_segment - Setup crash memory ranges and initialize elfc= orehdr * segment needed to load kdump kernel. @@ -428,7 +411,7 @@ static int load_elfcorehdr_segment(struct kimage *image= , struct kexec_buf *kbuf) * Account for extra space required to accommodate additional memory * ranges in elfcorehdr due to memory hotplug events. */ - kbuf->memsz =3D headers_sz + kdump_extra_elfcorehdr_size(cmem); + kbuf->memsz =3D headers_sz + crash_extra_elfcorehdr_size(cmem->nr_ranges); kbuf->top_down =3D false; =20 ret =3D kexec_add_buffer(kbuf); diff --git a/include/linux/crash_core.h b/include/linux/crash_core.h index 6789ff0af39e..d5981008a812 100644 --- a/include/linux/crash_core.h +++ b/include/linux/crash_core.h @@ -106,4 +106,30 @@ ssize_t dm_crypt_keys_read(char *buf, size_t count, u6= 4 *ppos); static inline int crash_load_dm_crypt_keys(struct kimage *image) {return 0= ; } #endif =20 +#if defined(CONFIG_CRASH_HOTPLUG) && defined(CONFIG_MEMORY_HOTPLUG) +static inline unsigned int crash_extra_elfcorehdr_size(unsigned int nr_mem= _ranges) +{ + unsigned int total_phdrs =3D 2 + num_possible_cpus() + CONFIG_CRASH_MAX_M= EMORY_RANGES; + + BUILD_BUG_ON(CONFIG_CRASH_MAX_MEMORY_RANGES > (unsigned int)PN_XNUM); + + if (nr_mem_ranges >=3D CONFIG_CRASH_MAX_MEMORY_RANGES) { + pr_warn_once("Configured crash mem ranges may not be enough\n"); + return 0; + } + + if (total_phdrs >=3D (unsigned int)PN_XNUM) { + pr_warn_once("number of Phdrs %u exceeds max\n", total_phdrs); + return 0; + } + + return (CONFIG_CRASH_MAX_MEMORY_RANGES - nr_mem_ranges) * sizeof(Elf64_Ph= dr); +} +#else +static inline unsigned int crash_extra_elfcorehdr_size(unsigned int nr_mem= _ranges) +{ + return 0; +} +#endif + #endif /* LINUX_CRASH_CORE_H */ --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout01.his.huawei.com (canpmsgout01.his.huawei.com [113.46.200.216]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0E3873ED109; Wed, 26 Aug 2026 09:25:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.216 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736348; cv=none; b=pK/SMJeq8sdpw7MYLuJckFMLLhWz23Iwwqcx/sWmRRs3uuY9PykdGv5QLJxwBXJkqwLSnJ0OdF9I7VSUOrPfyOWm/C/+eOncFbPIeWE0x3xEQ/k60g0OJfy3U4qY6sC9CQo2MftDYkFLocJ9WOF+RL9nrkd9Y3LFE2tEUh119/o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736348; c=relaxed/simple; bh=B3MRvGj1XNfWcX6eTthp4R6Wtw5XRumXQaZYp7mj+ns=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=JOrWNM0+Bpy5n6G+C8iRmEYusZym/YespEBSPsxmxU6+tVDDkGuqPVuMR2j6LRGoB8xm3E9j0/zr6nQcrAgLkePUIdZjaY4BZLQcDot+Y6r6BN7u7icA9DTT67gb0zJRY05uTIQ278u1dAkHahNo663bNC7D+4vqTw566NubiDI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=a4FvfvUu; arc=none smtp.client-ip=113.46.200.216 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="a4FvfvUu" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=KzYnNWc+0aB4Y51Iy+zQKodek72TzHHBhe+K3gEl70Y=; b=a4FvfvUuiPTNABc2iMv3KAutqTC9WA6DvBebvxBhfcer3DCSOZtOe8dnu5/s6ElI+Hz6bAesu k9ZrFJCpO2/U2n4yp9si+ZX4XbqFPVdaqbXWYPHgTDZXPRlwV7Noj7RLHuPe1f5ibu5kf737x31 Mw6bPQPLfS53XujdFwjx/Bk= Received: from mail.maildlp.com (unknown [172.19.163.0]) by canpmsgout01.his.huawei.com (SkyGuard) with ESMTPS id 4hVJsB6sKyz1T4gh; Wed, 26 Aug 2026 17:15:26 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id 3EF8940537; Wed, 26 Aug 2026 17:25:37 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:34 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 12/17] x86/crash: Use num_possible_cpus() for elfcorehdr size Date: Wed, 26 Aug 2026 17:25:36 +0800 Message-ID: <20260826092541.3905933-13-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" Use num_possible_cpus() instead of CONFIG_NR_CPUS to calculate the elfcorehdr buffer size, matching what crash_prepare_elf64_headers() already uses for the actual header content. This avoids over-allocation when the system has fewer possible CPUs than the compile-time limit, and aligns x86 with PowerPC. Signed-off-by: Jinjie Ruan --- arch/x86/kernel/crash.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/arch/x86/kernel/crash.c b/arch/x86/kernel/crash.c index a3bf786286d4..afe2aea19f47 100644 --- a/arch/x86/kernel/crash.c +++ b/arch/x86/kernel/crash.c @@ -369,9 +369,9 @@ int crash_load_segments(struct kimage *image) * maximum CPUs and maximum memory ranges. */ if (IS_ENABLED(CONFIG_MEMORY_HOTPLUG)) - pnum =3D 2 + CONFIG_NR_CPUS + CONFIG_CRASH_MAX_MEMORY_RANGES; + pnum =3D 2 + num_possible_cpus() + CONFIG_CRASH_MAX_MEMORY_RANGES; else - pnum +=3D 2 + CONFIG_NR_CPUS; + pnum +=3D 2 + num_possible_cpus(); =20 if (pnum < (unsigned long)PN_XNUM) { kbuf.memsz =3D elf64_phdr_size(pnum); @@ -429,7 +429,7 @@ unsigned int arch_crash_get_elfcorehdr_size(void) unsigned int sz; =20 /* kernel_map, VMCOREINFO and maximum CPUs */ - sz =3D 2 + CONFIG_NR_CPUS; + sz =3D 2 + num_possible_cpus(); if (IS_ENABLED(CONFIG_MEMORY_HOTPLUG)) sz +=3D CONFIG_CRASH_MAX_MEMORY_RANGES; sz *=3D sizeof(Elf64_Phdr); --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout04.his.huawei.com (canpmsgout04.his.huawei.com [113.46.200.219]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F29413E8C65; Wed, 26 Aug 2026 09:25:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.219 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736344; cv=none; b=DORpn6V1KnQKqTdpt5GFU1Op9mCO4Sm7ckCUgX+OP2g2+/t/wxwx0rpDoUOyPwNOTXwCw5HFfTM6Rr4A3a0KoXtsMsCAInJ10/O3HY4PpPXvl6BAld7tacwTosAOG+YA0ohDPoldY6gqO4FdBTOb85lqvlEI73kLxN1/K8G7SUA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736344; c=relaxed/simple; bh=0mAik/i9N56JtyuHFVuPGWREFimlRQb3aDwMWBlPxeI=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=hAHOw5n2BbnvHpH2hq/qb6rUdy3g4p81pv8vbqXmP3yaMzHY3OleL4pECs/E2OUe0CXnJN2Hy+yEE9nNWtiOYxjT9CjCFKUvaYvgQql+37rKhfAQ87e7p6UqGJQcItSOYEqdvuC4PdQGxQBbQGJh5hNbU+qCZfScygUGSiVxgyA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=4/tAT6Kh; arc=none smtp.client-ip=113.46.200.219 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="4/tAT6Kh" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=OsSkMIhsameVeQcyubflsAKjqyDPzlK/Dltq516R/Cc=; b=4/tAT6KhStANNCVtYQC+DB5wYYXDiC3tT34fBpKlCqPTh2I1YSkgN/f/nRnKQCczgulZrLa5x SMtVukw+4IMcbUBzz4us12yj4rcnLybfHqc3ah2t+jgK2r5itK8c4c82rj9Gk9VcSKgK+3/ji5n r0Yl4uQkkWaI+TBCQprUFWY= Received: from mail.maildlp.com (unknown [172.19.162.144]) by canpmsgout04.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrX05jqz1prQB; Wed, 26 Aug 2026 17:14:52 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id 8733E4056D; Wed, 26 Aug 2026 17:25:39 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:37 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 13/17] crash: Improve elfcorehdr segment identification Date: Wed, 26 Aug 2026 17:25:37 +0800 Message-ID: <20260826092541.3905933-14-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" Only checking ELFMAG is insufficient, as other segments like the kernel image or an ELF initrd may also start with \x7fELF, leading to misidentification. This is especially problematic when elfcorehdr is not the last segment, such as: kexec -d --t bzImage -p bzImage --initrd=3D/bin/true Add an "e_type =3D=3D ET_CORE" check to ensure the correct segment is identified, and break early after finding it. Signed-off-by: Jinjie Ruan --- kernel/crash_core.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/kernel/crash_core.c b/kernel/crash_core.c index bd3f82b62751..0730c4ea8054 100644 --- a/kernel/crash_core.c +++ b/kernel/crash_core.c @@ -737,9 +737,14 @@ static void crash_handle_hotplug_event(unsigned int hp= _action, unsigned int cpu, mem =3D image->segment[n].mem; ptr =3D kmap_local_page(pfn_to_page(mem >> PAGE_SHIFT)); if (ptr) { + Elf64_Ehdr *ehdr =3D (Elf64_Ehdr *)ptr; + /* The segment containing elfcorehdr */ - if (memcmp(ptr, ELFMAG, SELFMAG) =3D=3D 0) + if (memcmp(ptr, ELFMAG, SELFMAG) =3D=3D 0 && ehdr->e_type =3D=3D ET_CO= RE) { image->elfcorehdr_index =3D (int)n; + kunmap_local(ptr); + break; + } kunmap_local(ptr); } } --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout06.his.huawei.com (canpmsgout06.his.huawei.com [113.46.200.221]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 22F693EB810; Wed, 26 Aug 2026 09:25:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.221 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736345; cv=none; b=YDmD4yTSWb0aiG6l4Yl0bSUsWmk8MN1xl2Jpg0ELf0Bu7CVidKi3tzB7810nxRuefWtlsiMKLrmVzrwZkWLYzUugXuGGXZQ/FBNPqRKT7bu8quh2yvWaeJ++hmF87EfJ5CgRgaF6jTOuhTf7znb3uQH38hjpMClSYzhg5jtUPjQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736345; c=relaxed/simple; bh=XXABn8LX+AttazHlskJELh9lXcJYjzLdcTZW63MrCNo=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=XFSEbRhBU9G3x4BQmFPNBg/r+9CaGr99RauqY+Ssh6LhhsJRcCuERllQqOq+ov0SILJc1f07UHScfCxlQwajcyA5aZ2Nx66CsxPgJMayWN4LChnsnR0Z/B4pvbuwlUGrTW/q6L+MlHIiToBsYwLiXIDHjQEnM42HMaOLcpK6G6E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=M2WCjUV3; arc=none smtp.client-ip=113.46.200.221 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="M2WCjUV3" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=oXgq3/Gz7CGC/Wi4k6l57KKkgsMLlKANbfKYe/2S3+8=; b=M2WCjUV36RnHb5fNe4vvLb2ECdr0SMY463sjrUv623cM5rtnEGxtrh7Jm17vAKP9UZkTNrCdo 4xEpxcC38LZJXMGdX94QIQPU5uBerz/eQFv4Hc6UV3ZlxTKy/gxQTre5I4ALJj/5VKN0N7CO2JZ Dri1ZnSNgYAZMZLggRJdoJE= Received: from mail.maildlp.com (unknown [172.19.163.0]) by canpmsgout06.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrf11brzRhR0; Wed, 26 Aug 2026 17:14:58 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id CE3AC40537; Wed, 26 Aug 2026 17:25:41 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:39 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 14/17] x86/crash: Simplify crash_load_segments() using crash_extra_elfcorehdr_size() Date: Wed, 26 Aug 2026 17:25:38 +0800 Message-ID: <20260826092541.3905933-15-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" Replace the open-coded elfcorehdr reservation logic in crash_load_segments() with the generic crash_extra_elfcorehdr_size() helper. The helper centralizes all PN_XNUM and memory range checks, reducing code duplication. The elfcorehdr_index is handled separately in crash_handle_hotplug_event() during the first hotplug event, so it does not need to be set in crash_load_segments(). Cc: Thomas Gleixner Cc: Ingo Molnar Cc: Borislav Petkov Cc: Dave Hansen Cc: "H. Peter Anvin" Cc: Andrew Morton Cc: Baoquan He Cc: "Mike Rapoport (Microsoft)" Signed-off-by: Jinjie Ruan --- arch/x86/kernel/crash.c | 32 +++++--------------------------- 1 file changed, 5 insertions(+), 27 deletions(-) diff --git a/arch/x86/kernel/crash.c b/arch/x86/kernel/crash.c index afe2aea19f47..99eb8583d932 100644 --- a/arch/x86/kernel/crash.c +++ b/arch/x86/kernel/crash.c @@ -348,42 +348,20 @@ int crash_setup_memmap_entries(struct kimage *image, = struct boot_params *params) =20 int crash_load_segments(struct kimage *image) { - int ret; - unsigned long pnum =3D 0; struct kexec_buf kbuf =3D { .image =3D image, .buf_min =3D 0, .buf_max =3D ULONG_MAX, .top_down =3D false }; + unsigned long nr_ranges =3D 0; + int ret; =20 /* Prepare elf headers and add a segment */ ret =3D crash_prepare_headers(IS_ENABLED(CONFIG_X86_64), &kbuf.buffer, - &kbuf.bufsz, &pnum); + &kbuf.bufsz, &nr_ranges); if (ret) return ret; =20 image->elf_headers =3D kbuf.buffer; - image->elf_headers_sz =3D kbuf.bufsz; - kbuf.memsz =3D kbuf.bufsz; - -#ifdef CONFIG_CRASH_HOTPLUG - /* - * The elfcorehdr segment size accounts for VMCOREINFO, kernel_map, - * maximum CPUs and maximum memory ranges. - */ - if (IS_ENABLED(CONFIG_MEMORY_HOTPLUG)) - pnum =3D 2 + num_possible_cpus() + CONFIG_CRASH_MAX_MEMORY_RANGES; - else - pnum +=3D 2 + num_possible_cpus(); - - if (pnum < (unsigned long)PN_XNUM) { - kbuf.memsz =3D elf64_phdr_size(pnum); - - image->elfcorehdr_index =3D image->nr_segments; - - /* Mark as usable to crash kernel, else crash kernel fails on boot */ - image->elf_headers_sz =3D kbuf.memsz; - } else { - pr_err("number of Phdrs %lu exceeds max\n", pnum); - } -#endif + kbuf.memsz =3D kbuf.bufsz + crash_extra_elfcorehdr_size(nr_ranges); + image->elf_headers_sz =3D kbuf.memsz; =20 kbuf.buf_align =3D ELF_CORE_HEADER_ALIGN; kbuf.mem =3D KEXEC_BUF_MEM_UNKNOWN; --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout07.his.huawei.com (canpmsgout07.his.huawei.com [113.46.200.222]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7E6383EDE42; Wed, 26 Aug 2026 09:25:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.222 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736348; cv=none; b=DZTXChJ9tdSFqIk1uh1uSBT1iepAHG80ZT+qVggEJFejSsuHlMQIgfoJtWhHwX2Ecgq/9xn+FEdyqv1SWykhbrBv9sJUhw3mnyYBPrtqHEapBixkk4+K/EmFC8h+N0KWeUnt387NETpQ2hYLTTHMmIqU7DAxV6mg1wKeXv5G9Ok= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736348; c=relaxed/simple; bh=sFgvpqXBFjB0DXF/Xo6Q5XaYIo/m7UqgznW5dkzn1TQ=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=HcBiYPoQqz5z3i8YDuoQNNKRMV/b4j+UD+cvvawlfFhzs1iAuXm9QYLHvargTHsGJKVhnurKhM9cHbbhS/jHMasainxi9+W5/wIjHbu9P0en4u+zoF/4NNOcr/j6QQrLHdFgFzB/+T9QPXk8+pK03EJrKHujg2vHX1urXKl0CKs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=sd/H+UNC; arc=none smtp.client-ip=113.46.200.222 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="sd/H+UNC" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=3yLl9In8Wv4o0ZdsQbHCo1Df/gDSHHkfLMajcmTmIOU=; b=sd/H+UNCaNAatBnZBdwzX8iqrWgk9CvZKeHro8YXwCBizriBg8j/ic2nCnNuWmYjOd30NiN+s o0gHA+GVWfBZxWfQc5kddUQtVkrxsFSTSz7Qz2UeV8XoAt1UtBiJcSp4/Oy1mZg78qh4xUuqL3O bguC9nDFMKh9jB1NsetGV8w= Received: from mail.maildlp.com (unknown [172.19.163.214]) by canpmsgout07.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrf3mV2zLlXB; Wed, 26 Aug 2026 17:14:58 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id 298AF4057C; Wed, 26 Aug 2026 17:25:44 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:41 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 15/17] crash: Simplify CRASH_MAX_MEMORY_RANGES handling Date: Wed, 26 Aug 2026 17:25:39 +0800 Message-ID: <20260826092541.3905933-16-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" Set CRASH_MAX_MEMORY_RANGES to 0 when MEMORY_HOTPLUG is disabled, then remove the now unnecessary IS_ENABLED(CONFIG_MEMORY_HOTPLUG) checks in powerpc and x86 arch_crash_get_elfcorehdr_size(). No functional change intended. Signed-off-by: Jinjie Ruan --- arch/powerpc/kexec/crash.c | 4 +--- arch/x86/kernel/crash.c | 4 +--- kernel/Kconfig.kexec | 3 ++- 3 files changed, 4 insertions(+), 7 deletions(-) diff --git a/arch/powerpc/kexec/crash.c b/arch/powerpc/kexec/crash.c index fc0105c7af4c..c47e3f867ea1 100644 --- a/arch/powerpc/kexec/crash.c +++ b/arch/powerpc/kexec/crash.c @@ -474,9 +474,7 @@ unsigned int arch_crash_get_elfcorehdr_size(void) unsigned long phdr_cnt; =20 /* A program header for possible CPUs + vmcoreinfo */ - phdr_cnt =3D num_possible_cpus() + 1; - if (IS_ENABLED(CONFIG_MEMORY_HOTPLUG)) - phdr_cnt +=3D CONFIG_CRASH_MAX_MEMORY_RANGES; + phdr_cnt =3D num_possible_cpus() + 1 + CONFIG_CRASH_MAX_MEMORY_RANGES; =20 return elf64_phdr_size(phdr_cnt); } diff --git a/arch/x86/kernel/crash.c b/arch/x86/kernel/crash.c index 99eb8583d932..116410ac90fb 100644 --- a/arch/x86/kernel/crash.c +++ b/arch/x86/kernel/crash.c @@ -407,9 +407,7 @@ unsigned int arch_crash_get_elfcorehdr_size(void) unsigned int sz; =20 /* kernel_map, VMCOREINFO and maximum CPUs */ - sz =3D 2 + num_possible_cpus(); - if (IS_ENABLED(CONFIG_MEMORY_HOTPLUG)) - sz +=3D CONFIG_CRASH_MAX_MEMORY_RANGES; + sz =3D 2 + num_possible_cpus() + CONFIG_CRASH_MAX_MEMORY_RANGES; sz *=3D sizeof(Elf64_Phdr); return sz; } diff --git a/kernel/Kconfig.kexec b/kernel/Kconfig.kexec index a97ed9605602..e6251dfe451a 100644 --- a/kernel/Kconfig.kexec +++ b/kernel/Kconfig.kexec @@ -160,7 +160,8 @@ config CRASH_HOTPLUG =20 config CRASH_MAX_MEMORY_RANGES int "Specify the maximum number of memory regions for the elfcorehdr" - default 8192 + default 8192 if MEMORY_HOTPLUG + default 0 if !MEMORY_HOTPLUG depends on CRASH_HOTPLUG help For the kexec_file_load() syscall path, specify the maximum number of --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout04.his.huawei.com (canpmsgout04.his.huawei.com [113.46.200.219]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A027A3EFFD7; Wed, 26 Aug 2026 09:25:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.219 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736350; cv=none; b=gDxSbIyuZTwiaJtfg0m5CM/QetubVsvMgPXefIwXwshA1YlzOK8ZFPMYl2G85RDbKTdNfuG0sPhof5Zh22ET3wF2yb6P33MZtxbbtOFjOb8BpcCbOCGUyOtfDvmpyhnt0nr1l4PJLeqAMTTwTdLe+0KHuj+nkzGl47eaJueWuAc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736350; c=relaxed/simple; bh=kp+6I708DzV79AoDBZFUXSGVAlkZ158GWQXxLRdCt18=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=ap7XU3WsO2NwSMaQf8XRCJBjhqIkNbZEutZnlxVwuJZH4SiPZxXP1IeXkEg6YtUyllUJpjMmQZxc1y/Dj5XfQ7KRn9Vk1GuF1yKeXNyXGi7XPrATVRSnipo9Tr/q4nqZbsA3gGMlHvHNtSe2ZYAojQIk37td/u4orxWw6UyDTVY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=PHmoGMGZ; arc=none smtp.client-ip=113.46.200.219 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="PHmoGMGZ" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=9eBN1xy3LsTspM2cXc9iihQZgxEMtvQyI2J8OiqZLKg=; b=PHmoGMGZCpSK83cFfL1l+GZjf/pY9I+6IoZqg3WJ4VLG4xW6NHlRLdZlpXZs7q+S1hU6FgzSG rPNsboboV+FxPnNuPRJvY6Ww7D51z6C62ISbmu/FflpvRh5Xiy1KVbEeTFJW1U4tML5IiSjG8eN PcED3zgeHCZOJt4Rn7qsZuQ= Received: from mail.maildlp.com (unknown [172.19.162.223]) by canpmsgout04.his.huawei.com (SkyGuard) with ESMTPS id 4hVJrf6YSLz1prN4; Wed, 26 Aug 2026 17:14:58 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id 6A56D40561; Wed, 26 Aug 2026 17:25:46 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:44 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 16/17] arm64: kexec_file: Simplify load_other_segments() Date: Wed, 26 Aug 2026 17:25:40 +0800 Message-ID: <20260826092541.3905933-17-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" Use `kbuf` fields directly in crash_prepare_headers() to eliminate the local variables "headers" and "headers_sz".. Advance the assignment to image->elf_headers before calling kexec_add_buffer(). If kexec_add_buffer() fails, the explicit vfree() in the error path can be removed, as the global infrastructure in arch_kimage_file_post_load_cleanup() will handle the cleanup. Cc: Catalin Marinas Cc: Will Deacon Cc: Baoquan He Cc: Breno Leitao Signed-off-by: Jinjie Ruan --- arch/arm64/kernel/machine_kexec_file.c | 24 +++++++++--------------- 1 file changed, 9 insertions(+), 15 deletions(-) diff --git a/arch/arm64/kernel/machine_kexec_file.c b/arch/arm64/kernel/mac= hine_kexec_file.c index 2f750e5f4fcc..3d907f8ee594 100644 --- a/arch/arm64/kernel/machine_kexec_file.c +++ b/arch/arm64/kernel/machine_kexec_file.c @@ -89,36 +89,30 @@ int load_other_segments(struct kimage *image, kbuf.buf_min =3D kernel_load_addr + kernel_size; =20 #ifdef CONFIG_CRASH_DUMP - /* load elf core header */ - void *headers; - unsigned long headers_sz; if (image->type =3D=3D KEXEC_TYPE_CRASH) { - ret =3D crash_prepare_headers(true, &headers, &headers_sz, NULL); + ret =3D crash_prepare_headers(true, &kbuf.buffer, &kbuf.bufsz, NULL); if (ret) { pr_err("Preparing elf core header failed\n"); goto out_err; } =20 - kbuf.buffer =3D headers; - kbuf.bufsz =3D headers_sz; + if (unlikely(image->elf_headers)) + vfree(image->elf_headers); + + image->elf_headers =3D kbuf.buffer; + image->elf_headers_sz =3D kbuf.bufsz; + kbuf.mem =3D KEXEC_BUF_MEM_UNKNOWN; - kbuf.memsz =3D headers_sz; + kbuf.memsz =3D kbuf.bufsz; kbuf.buf_align =3D SZ_64K; /* largest supported page size */ kbuf.buf_max =3D ULONG_MAX; kbuf.top_down =3D true; =20 ret =3D kexec_add_buffer(&kbuf); - if (ret) { - vfree(headers); + if (ret) goto out_err; - } - - if (unlikely(image->elf_headers)) - vfree(image->elf_headers); =20 - image->elf_headers =3D headers; image->elf_load_addr =3D kbuf.mem; - image->elf_headers_sz =3D headers_sz; =20 kexec_dprintk("Loaded elf core header at 0x%lx bufsz=3D0x%lx memsz=3D0x%= lx\n", image->elf_load_addr, kbuf.bufsz, kbuf.memsz); --=20 2.34.1 From nobody Mon Sep 28 04:53:55 2026 Received: from canpmsgout05.his.huawei.com (canpmsgout05.his.huawei.com [113.46.200.220]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2CE503F413E; Wed, 26 Aug 2026 09:25:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.220 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736353; cv=none; b=n4UO+RC7h/yE09zA/POZeGxF+DLahcra5n4ITuR/Lfb4x5wJLtsnDG9XUNEMZADR1aRO+mbeiEH6mXuCCeoxlUjm0wTxdBkcOk7fgr+1bNnFJyQB/Fcy1KTpUoxNJaHTGsS1RG6I8J8AVc/Exj0IOo4x0gYl9gsN9KaPj+K7mZg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787736353; c=relaxed/simple; bh=eQCXV3z3aNLdvq/SFmSdeAgeoDMbMX7gb2hYDjEVnZ8=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=mVZSFCLUDpGdEL4B7+ANC18Uhqv38AbuP2RAb00ox9tXc0Pe0MlSH5nca1rlGGbWIToB/kLj4oRFpt/ZVZq1tPGZY2s+8uLh7L6XOwEsM+TUJTgANaU2yFaCp2IJJY4mF60/HN24X8klyeJ+cIN/7PFn/R6pTb8ELTcxnlO8FI4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=1LNL5mVC; arc=none smtp.client-ip=113.46.200.220 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="1LNL5mVC" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=fFAgomx6mCnvCLtDv+rkVQ5LTZ6jKJXYGpd9rmPNNE8=; b=1LNL5mVCelb85PN9fuNceaoD72o8fCN0n9slnJpLPRXvNMoCM0ey58jciL1xalSTzmOGIlIZt QzwhzeumxoPtPnpkWa53lh7mcQOpffypdPA7T9QpcG02Et76WZVHm8Ut1q5RAjOtW3UhqZEIj3d sRmKY9R7dvYnIIPD8CQYKTI= Received: from mail.maildlp.com (unknown [172.19.163.0]) by canpmsgout05.his.huawei.com (SkyGuard) with ESMTPS id 4hVJsH4bLtz12LF9; Wed, 26 Aug 2026 17:15:31 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id B7F6640537; Wed, 26 Aug 2026 17:25:48 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Wed, 26 Aug 2026 17:25:46 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v3 17/17] arm64: crash: Add crash hotplug support Date: Wed, 26 Aug 2026 17:25:41 +0800 Message-ID: <20260826092541.3905933-18-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260826092541.3905933-1-ruanjinjie@huawei.com> References: <20260826092541.3905933-1-ruanjinjie@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To dggpemf500011.china.huawei.com (7.185.36.131) Content-Type: text/plain; charset="utf-8" When CPU or memory hotplug events occur, the elfcorehdr in the kdump image becomes stale, potentially leading to incomplete crash dumps. Currently, userspace udev rules reload the entire kdump image upon such events, which is inefficient and leaves kdump inactive for a long time. Commit 247262756121 ("crash: add generic infrastructure for crash hotplug support") introduced a kernel mechanism to update only the elfcorehdr. This patch enables that support for arm64. On arm64, only memory hotplug events require elfcorehdr updates: - Physical CPU hotplug is not supported. - For ACPI based vCPU hotplug [1], the elfcorehdr is built using for_each_possible_cpu(), so no update is needed. The patch: - Adds CONFIG_ARCH_SUPPORTS_CRASH_HOTPLUG (default y). - Implements following arch functions to handle memory hotplug: 1. arch_crash_hotplug_support() 2. arch_crash_get_elfcorehdr_size() 3. arch_crash_handle_hotplug_event() - Moves arch_get_system_nr_ranges() and arch_crash_populate_cmem() from machine_kexec_file.c to crash.c for crash hotplug reuse. Follows the approach of x86 commit ea53ad9cf73b ("x86/crash: add x86 crash hotplug support") and powerpc commit b741092d5976 ("powerpc/crash: add crash CPU hotplug support"). Cc: Catalin Marinas Cc: Will Deacon Cc: Baoquan He Cc: "Mike Rapoport (Microsoft)" Cc: Andrew Morton Cc: Breno Leitao Cc: Sourabh Jain Cc: Mark Rutland Cc: Ard Biesheuvel Cc: Thomas Huth [1]: https://lore.kernel.org/all/20240529133446.28446-1-Jonathan.Cameron@hu= awei.com/ Signed-off-by: Jinjie Ruan --- arch/arm64/Kconfig | 3 + arch/arm64/include/asm/kexec.h | 11 ++ arch/arm64/kernel/Makefile | 2 +- arch/arm64/kernel/crash.c | 165 +++++++++++++++++++++++++ arch/arm64/kernel/machine_kexec_file.c | 36 +----- 5 files changed, 184 insertions(+), 33 deletions(-) create mode 100644 arch/arm64/kernel/crash.c diff --git a/arch/arm64/Kconfig b/arch/arm64/Kconfig index b5a51b0ef944..96de2660b1cb 100644 --- a/arch/arm64/Kconfig +++ b/arch/arm64/Kconfig @@ -1720,6 +1720,9 @@ config ARCH_DEFAULT_CRASH_DUMP config ARCH_HAS_GENERIC_CRASHKERNEL_RESERVATION def_bool CRASH_RESERVE =20 +config ARCH_SUPPORTS_CRASH_HOTPLUG + def_bool y + config TRANS_TABLE def_bool y depends on HIBERNATION || KEXEC_CORE diff --git a/arch/arm64/include/asm/kexec.h b/arch/arm64/include/asm/kexec.h index 892e5bebda95..f165c094b32e 100644 --- a/arch/arm64/include/asm/kexec.h +++ b/arch/arm64/include/asm/kexec.h @@ -130,6 +130,17 @@ extern int load_other_segments(struct kimage *image, char *cmdline); #endif =20 +#ifdef CONFIG_CRASH_HOTPLUG +void arch_crash_handle_hotplug_event(struct kimage *image, void *arg); +#define arch_crash_handle_hotplug_event arch_crash_handle_hotplug_event + +int arch_crash_hotplug_support(struct kimage *image, unsigned long kexec_f= lags); +#define arch_crash_hotplug_support arch_crash_hotplug_support + +unsigned int arch_crash_get_elfcorehdr_size(void); +#define crash_get_elfcorehdr_size arch_crash_get_elfcorehdr_size +#endif + #endif /* __ASSEMBLER__ */ =20 #endif diff --git a/arch/arm64/kernel/Makefile b/arch/arm64/kernel/Makefile index d2690c3ec528..9bbac452994c 100644 --- a/arch/arm64/kernel/Makefile +++ b/arch/arm64/kernel/Makefile @@ -64,7 +64,7 @@ obj-$(CONFIG_KEXEC_CORE) +=3D machine_kexec.o relocate_k= ernel.o \ obj-$(CONFIG_KEXEC_FILE) +=3D machine_kexec_file.o kexec_image.o obj-$(CONFIG_ARM64_RELOC_TEST) +=3D arm64-reloc-test.o arm64-reloc-test-y :=3D reloc_test_core.o reloc_test_syms.o -obj-$(CONFIG_CRASH_DUMP) +=3D crash_dump.o +obj-$(CONFIG_CRASH_DUMP) +=3D crash_dump.o crash.o obj-$(CONFIG_VMCORE_INFO) +=3D vmcore_info.o obj-$(CONFIG_ARM_SDE_INTERFACE) +=3D sdei.o obj-$(CONFIG_ARM64_PTR_AUTH) +=3D pointer_auth.o diff --git a/arch/arm64/kernel/crash.c b/arch/arm64/kernel/crash.c new file mode 100644 index 000000000000..d97e9cea2fc9 --- /dev/null +++ b/arch/arm64/kernel/crash.c @@ -0,0 +1,165 @@ +// SPDX-License-Identifier: GPL-2.0-only +/* + * Architecture specific functions for kexec based crash dumps. + */ + +#define pr_fmt(fmt) "crash hp: " fmt + +#include +#include +#include +#include +#include +#include + +#include + +#if defined(CONFIG_KEXEC_FILE) || defined(CONFIG_CRASH_HOTPLUG) +unsigned int arch_get_system_nr_ranges(void) +{ + unsigned int nr_ranges =3D 2 + crashk_cma_cnt; /* for exclusion of crashk= ernel region */ + phys_addr_t start, end; + u64 i; + + for_each_mem_range(i, &start, &end) + nr_ranges++; + + return nr_ranges; +} + +int arch_crash_populate_cmem(struct crash_mem *cmem) +{ + phys_addr_t start, end; + u64 i; + + for_each_mem_range(i, &start, &end) { + cmem->ranges[cmem->nr_ranges].start =3D start; + cmem->ranges[cmem->nr_ranges].end =3D end - 1; + cmem->nr_ranges++; + } + + return 0; +} +#endif + +#ifdef CONFIG_CRASH_HOTPLUG +int arch_crash_hotplug_support(struct kimage *image, unsigned long kexec_f= lags) +{ +#ifdef CONFIG_KEXEC_FILE + if (image->file_mode) + return 1; +#endif + /* + * For kexec_load syscall, crash hotplug support requires + * KEXEC_CRASH_HOTPLUG_SUPPORT flag to be passed by userspace. + */ + return kexec_flags & KEXEC_CRASH_HOTPLUG_SUPPORT; +} + +unsigned int arch_crash_get_elfcorehdr_size(void) +{ + unsigned long phdr_cnt; + + /* A program header for possible CPUs, vmcoreinfo and kernel_map */ + phdr_cnt =3D 2 + num_possible_cpus() + CONFIG_CRASH_MAX_MEMORY_RANGES; + + return elf64_phdr_size(phdr_cnt); +} + +/** + * update_crash_elfcorehdr() - Recreate the elfcorehdr and replace it with= old + * elfcorehdr in the kexec segment array. + * @image: the active struct kimage + * @mn: struct memory_notify data handler + */ +static void update_crash_elfcorehdr(struct kimage *image, struct memory_no= tify *mn) +{ + void *elfbuf =3D NULL, *old_elfcorehdr; + unsigned long mem, memsz, elfsz =3D 0; + struct crash_mem *cmem =3D NULL; + u64 start, end; + int ret; + + ret =3D crash_get_memory_ranges_nolock(&cmem); + if (ret) { + pr_err("Failed to get crash memory ranges.\n"); + goto out; + } + + /* + * The hot unplugged memory is part of crash memory ranges, + * remove it here. + */ + if (image->hp_action =3D=3D KEXEC_CRASH_HP_REMOVE_MEMORY) { + start =3D PFN_PHYS(mn->start_pfn); + end =3D start + PFN_PHYS(mn->nr_pages) - 1; + + ret =3D crash_exclude_mem_range(cmem, start, end); + if (ret) { + pr_err("Failed to remove hot-unplugged memory from crash memory ranges.= \n"); + goto out; + } + } + + /* + * Create the new elfcorehdr reflecting the changes to CPU and/or + * memory resources. + */ + ret =3D crash_prepare_elf64_headers(cmem, true, &elfbuf, &elfsz); + if (ret) { + pr_err("Failed to create new elfcorehdr"); + goto out; + } + + /* + * Obtain address and size of the elfcorehdr segment, and + * check it against the new elfcorehdr buffer. + */ + mem =3D image->segment[image->elfcorehdr_index].mem; + memsz =3D image->segment[image->elfcorehdr_index].memsz; + if (elfsz > memsz) { + pr_err("update elfcorehdr elfsz %lu > memsz %lu", + elfsz, memsz); + goto out; + } + + /* Copy new elfcorehdr over the old elfcorehdr at destination. */ + old_elfcorehdr =3D phys_to_virt(mem); + + /* + * Temporarily invalidate the crash image while the + * elfcorehdr is updated. + */ + xchg(&kexec_crash_image, NULL); + memcpy(old_elfcorehdr, elfbuf, elfsz); + dcache_clean_inval_poc((unsigned long)old_elfcorehdr, + (unsigned long)(old_elfcorehdr + elfsz)); + xchg(&kexec_crash_image, image); + pr_debug("updated elfcorehdr\n"); + +out: + kvfree(cmem); + vfree(elfbuf); +} + +/** + * arch_crash_handle_hotplug_event() - Handle hotplug elfcorehdr changes + * @image: a pointer to kexec_crash_image + * @arg: struct memory_notify handler for memory hotplug case and + * NULL for CPU hotplug case. + * + * Update the kdump image based on the type of hotplug event: + * - CPU add and remove: No action is needed. + * - Memory add/remove: Update the elfcorehdr to reflect the current memor= y layout. + * + * Prepare the new elfcorehdr and replace the existing elfcorehdr. + */ +void arch_crash_handle_hotplug_event(struct kimage *image, void *arg) +{ + if (image->hp_action =3D=3D KEXEC_CRASH_HP_ADD_CPU || + image->hp_action =3D=3D KEXEC_CRASH_HP_REMOVE_CPU) + return; + + update_crash_elfcorehdr(image, (struct memory_notify *)arg); +} +#endif /* CONFIG_CRASH_HOTPLUG */ diff --git a/arch/arm64/kernel/machine_kexec_file.c b/arch/arm64/kernel/mac= hine_kexec_file.c index 3d907f8ee594..acba49b04ae1 100644 --- a/arch/arm64/kernel/machine_kexec_file.c +++ b/arch/arm64/kernel/machine_kexec_file.c @@ -14,7 +14,6 @@ #include #include #include -#include #include #include #include @@ -39,34 +38,6 @@ int arch_kimage_file_post_load_cleanup(struct kimage *im= age) return kexec_image_post_load_cleanup_default(image); } =20 -#ifdef CONFIG_CRASH_DUMP -unsigned int arch_get_system_nr_ranges(void) -{ - unsigned int nr_ranges =3D 2 + crashk_cma_cnt; /* for exclusion of crashk= ernel region */ - phys_addr_t start, end; - u64 i; - - for_each_mem_range(i, &start, &end) - nr_ranges++; - - return nr_ranges; -} - -int arch_crash_populate_cmem(struct crash_mem *cmem) -{ - phys_addr_t start, end; - u64 i; - - for_each_mem_range(i, &start, &end) { - cmem->ranges[cmem->nr_ranges].start =3D start; - cmem->ranges[cmem->nr_ranges].end =3D end - 1; - cmem->nr_ranges++; - } - - return 0; -} -#endif - /* * Tries to add the initrd and DTB to the image. If it is not possible to = find * valid locations, this function will undo changes to the image and retur= n non @@ -89,8 +60,9 @@ int load_other_segments(struct kimage *image, kbuf.buf_min =3D kernel_load_addr + kernel_size; =20 #ifdef CONFIG_CRASH_DUMP + unsigned long nr_ranges =3D 0; if (image->type =3D=3D KEXEC_TYPE_CRASH) { - ret =3D crash_prepare_headers(true, &kbuf.buffer, &kbuf.bufsz, NULL); + ret =3D crash_prepare_headers(true, &kbuf.buffer, &kbuf.bufsz, &nr_range= s); if (ret) { pr_err("Preparing elf core header failed\n"); goto out_err; @@ -100,10 +72,10 @@ int load_other_segments(struct kimage *image, vfree(image->elf_headers); =20 image->elf_headers =3D kbuf.buffer; - image->elf_headers_sz =3D kbuf.bufsz; =20 kbuf.mem =3D KEXEC_BUF_MEM_UNKNOWN; - kbuf.memsz =3D kbuf.bufsz; + kbuf.memsz =3D kbuf.bufsz + crash_extra_elfcorehdr_size(nr_ranges); + image->elf_headers_sz =3D kbuf.memsz; kbuf.buf_align =3D SZ_64K; /* largest supported page size */ kbuf.buf_max =3D ULONG_MAX; kbuf.top_down =3D true; --=20 2.34.1