2022-11-14 13:35:06

by Ricardo Ribalda

[permalink] [raw]
Subject: [PATCH v1 1/2] Documentation: sysctl: Correct kexec_load_disabled

kexec_load_disabled affects both ``kexec_load`` and ``kexec_file_load``
syscalls. Make it explicit.

Signed-off-by: Ricardo Ribalda <[email protected]>

diff --git a/Documentation/admin-guide/sysctl/kernel.rst b/Documentation/admin-guide/sysctl/kernel.rst
index 98d1b198b2b4..97394bd9d065 100644
--- a/Documentation/admin-guide/sysctl/kernel.rst
+++ b/Documentation/admin-guide/sysctl/kernel.rst
@@ -450,9 +450,10 @@ this allows system administrators to override the
kexec_load_disabled
===================

-A toggle indicating if the ``kexec_load`` syscall has been disabled.
-This value defaults to 0 (false: ``kexec_load`` enabled), but can be
-set to 1 (true: ``kexec_load`` disabled).
+A toggle indicating if the syscalls ``kexec_load`` and
+``kexec_file_load`` have been disabled.
+This value defaults to 0 (false: ``kexec_*load`` enabled), but can be
+set to 1 (true: ``kexec_*load`` disabled).
Once true, kexec can no longer be used, and the toggle cannot be set
back to false.
This allows a kexec image to be loaded before disabling the syscall,

--
b4 0.11.0-dev-d93f8


2022-11-23 10:09:03

by Baoquan He

[permalink] [raw]
Subject: Re: [PATCH v1 1/2] Documentation: sysctl: Correct kexec_load_disabled

On 11/14/22 at 02:18pm, Ricardo Ribalda wrote:
> kexec_load_disabled affects both ``kexec_load`` and ``kexec_file_load``
> syscalls. Make it explicit.
>
> Signed-off-by: Ricardo Ribalda <[email protected]>
>
> diff --git a/Documentation/admin-guide/sysctl/kernel.rst b/Documentation/admin-guide/sysctl/kernel.rst
> index 98d1b198b2b4..97394bd9d065 100644
> --- a/Documentation/admin-guide/sysctl/kernel.rst
> +++ b/Documentation/admin-guide/sysctl/kernel.rst
> @@ -450,9 +450,10 @@ this allows system administrators to override the
> kexec_load_disabled
> ===================
>
> -A toggle indicating if the ``kexec_load`` syscall has been disabled.
> -This value defaults to 0 (false: ``kexec_load`` enabled), but can be
> -set to 1 (true: ``kexec_load`` disabled).
> +A toggle indicating if the syscalls ``kexec_load`` and
> +``kexec_file_load`` have been disabled.
> +This value defaults to 0 (false: ``kexec_*load`` enabled), but can be
> +set to 1 (true: ``kexec_*load`` disabled).
> Once true, kexec can no longer be used, and the toggle cannot be set
> back to false.
> This allows a kexec image to be loaded before disabling the syscall,

LGTM,

Acked-by: Baoquan He <[email protected]>

>
> --
> b4 0.11.0-dev-d93f8
>