Thread (8 messages) flat view 8 messages, 3 authors, 16d ago

Re: [PATCH v3 1/2] kexec: return -ENOEXEC from image probe functions on mismatch

From: Mukesh Pilaniya <hidden>
Date: 2026-08-26 15:51:23
Also in: kexec, linux-riscv, lkml, loongarch

Hi Will,

On 25/08/26 8:44 pm, Will Deacon wrote:
On Tue, Aug 25, 2026 at 10:43:48AM +0530, Mukesh Pilaniya wrote:
quoted
On 24/08/26 7:37 pm, Will Deacon wrote:
quoted
On Fri, Aug 21, 2026 at 07:19:57PM +0530, Mukesh Pilaniya wrote:
quoted
Several kexec_file_load() image probe functions return -EINVAL when
they do not recognize the image format.  A probe function that rejects
an image should return -ENOEXEC to indicate that the image is not a
recognized executable format.  -EINVAL implies a problem with the
syscall parameters, not with image recognition.

kexec_image_probe_default() iterates through registered loaders and
returns the last probe's error code to the caller.  That error
propagates as the kexec_file_load() return value to userspace.
Returning -EINVAL from a probe when no loader matches is semantically
incorrect and misleads userspace about the nature of the failure.

Return -ENOEXEC from all probe functions and their helpers when the
image format is not recognized.

Signed-off-by: Mukesh Pilaniya <redacted>
Reviewed-by: Philipp Rudo <redacted>
Reviewed-by: Pratyush Yadav <pratyush@kernel.org>
Reviewed-by: Bradley Morgan <redacted>
---
 arch/arm64/kernel/kexec_image.c   | 4 ++--
 arch/loongarch/kernel/kexec_efi.c | 4 ++--
 arch/riscv/kernel/kexec_image.c   | 4 ++--
 kernel/kexec_elf.c                | 4 ++--
 4 files changed, 8 insertions(+), 8 deletions(-)
Hmm, so after this patch, are there actually any implementations of .probe()
that return anything other than 0 or -ENOEXEC? I couldn't spot any after
a quick look.

Willkexec_elf_probe() can return -ENOMEM if memory allocation (kzalloc())
fails inside elf_read_phdrs(). This behavior was previously discussed in
the first patch of this series [1].
Fair enough, but I'd have thought it would be easier to special-case the
one -ENOMEM path instead of changing all the backends to return
-ENOEXEC all over the place (and hoping people don't start returning
-EINVAL again in future).

Will
Returning -EINVAL from a probe on format mismatch is semantically wrong
on its own — independent of how kexec_image_probe_default() handles
the return value.  x86 bzImage64_probe() and s390 s390_elf_probe()
already return -ENOEXEC correctly; this patch just brings the remaining
backends in line.

Also IMHO, checking for err != -ENOEXEC in kexec_image_probe_default()
is more robust than special-casing err == -ENOMEM.

-- 
Regards,
Mukesh Pilaniya

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help