Re: [PATCH v3 1/2] kexec: return -ENOEXEC from image probe functions on mismatch
From: Mukesh Pilaniya <hidden>
Date: 2026-08-26 15:51:23
Also in:
kexec, linux-riscv, lkml, loongarch
Hi Will, On 25/08/26 8:44 pm, Will Deacon wrote:
On Tue, Aug 25, 2026 at 10:43:48AM +0530, Mukesh Pilaniya wrote:quoted
On 24/08/26 7:37 pm, Will Deacon wrote:quoted
On Fri, Aug 21, 2026 at 07:19:57PM +0530, Mukesh Pilaniya wrote:quoted
Several kexec_file_load() image probe functions return -EINVAL when they do not recognize the image format. A probe function that rejects an image should return -ENOEXEC to indicate that the image is not a recognized executable format. -EINVAL implies a problem with the syscall parameters, not with image recognition. kexec_image_probe_default() iterates through registered loaders and returns the last probe's error code to the caller. That error propagates as the kexec_file_load() return value to userspace. Returning -EINVAL from a probe when no loader matches is semantically incorrect and misleads userspace about the nature of the failure. Return -ENOEXEC from all probe functions and their helpers when the image format is not recognized. Signed-off-by: Mukesh Pilaniya <redacted> Reviewed-by: Philipp Rudo <redacted> Reviewed-by: Pratyush Yadav <pratyush@kernel.org> Reviewed-by: Bradley Morgan <redacted> --- arch/arm64/kernel/kexec_image.c | 4 ++-- arch/loongarch/kernel/kexec_efi.c | 4 ++-- arch/riscv/kernel/kexec_image.c | 4 ++-- kernel/kexec_elf.c | 4 ++-- 4 files changed, 8 insertions(+), 8 deletions(-)Hmm, so after this patch, are there actually any implementations of .probe() that return anything other than 0 or -ENOEXEC? I couldn't spot any after a quick look. Willkexec_elf_probe() can return -ENOMEM if memory allocation (kzalloc())fails inside elf_read_phdrs(). This behavior was previously discussed in the first patch of this series [1].Fair enough, but I'd have thought it would be easier to special-case the one -ENOMEM path instead of changing all the backends to return -ENOEXEC all over the place (and hoping people don't start returning -EINVAL again in future). Will
Returning -EINVAL from a probe on format mismatch is semantically wrong on its own — independent of how kexec_image_probe_default() handles the return value. x86 bzImage64_probe() and s390 s390_elf_probe() already return -ENOEXEC correctly; this patch just brings the remaining backends in line. Also IMHO, checking for err != -ENOEXEC in kexec_image_probe_default() is more robust than special-casing err == -ENOMEM. -- Regards, Mukesh Pilaniya