xref: /linux/init/main.c (revision 15a1fbdcfb519c2bd291ed01c6c94e0b89537a77)
1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3  *  linux/init/main.c
4  *
5  *  Copyright (C) 1991, 1992  Linus Torvalds
6  *
7  *  GK 2/5/95  -  Changed to support mounting root fs via NFS
8  *  Added initrd & change_root: Werner Almesberger & Hans Lermen, Feb '96
9  *  Moan early if gcc is old, avoiding bogus kernels - Paul Gortmaker, May '96
10  *  Simplified starting of init:  Michael A. Griffith <grif@acm.org>
11  */
12 
13 #define DEBUG		/* Enable initcall_debug */
14 
15 #include <linux/types.h>
16 #include <linux/extable.h>
17 #include <linux/module.h>
18 #include <linux/proc_fs.h>
19 #include <linux/binfmts.h>
20 #include <linux/kernel.h>
21 #include <linux/syscalls.h>
22 #include <linux/stackprotector.h>
23 #include <linux/string.h>
24 #include <linux/ctype.h>
25 #include <linux/delay.h>
26 #include <linux/ioport.h>
27 #include <linux/init.h>
28 #include <linux/initrd.h>
29 #include <linux/memblock.h>
30 #include <linux/acpi.h>
31 #include <linux/bootconfig.h>
32 #include <linux/console.h>
33 #include <linux/nmi.h>
34 #include <linux/percpu.h>
35 #include <linux/kmod.h>
36 #include <linux/vmalloc.h>
37 #include <linux/kernel_stat.h>
38 #include <linux/start_kernel.h>
39 #include <linux/security.h>
40 #include <linux/smp.h>
41 #include <linux/profile.h>
42 #include <linux/rcupdate.h>
43 #include <linux/moduleparam.h>
44 #include <linux/kallsyms.h>
45 #include <linux/writeback.h>
46 #include <linux/cpu.h>
47 #include <linux/cpuset.h>
48 #include <linux/cgroup.h>
49 #include <linux/efi.h>
50 #include <linux/tick.h>
51 #include <linux/sched/isolation.h>
52 #include <linux/interrupt.h>
53 #include <linux/taskstats_kern.h>
54 #include <linux/delayacct.h>
55 #include <linux/unistd.h>
56 #include <linux/utsname.h>
57 #include <linux/rmap.h>
58 #include <linux/mempolicy.h>
59 #include <linux/key.h>
60 #include <linux/buffer_head.h>
61 #include <linux/page_ext.h>
62 #include <linux/debug_locks.h>
63 #include <linux/debugobjects.h>
64 #include <linux/lockdep.h>
65 #include <linux/kmemleak.h>
66 #include <linux/pid_namespace.h>
67 #include <linux/device/driver.h>
68 #include <linux/kthread.h>
69 #include <linux/sched.h>
70 #include <linux/sched/init.h>
71 #include <linux/signal.h>
72 #include <linux/idr.h>
73 #include <linux/kgdb.h>
74 #include <linux/ftrace.h>
75 #include <linux/async.h>
76 #include <linux/sfi.h>
77 #include <linux/shmem_fs.h>
78 #include <linux/slab.h>
79 #include <linux/perf_event.h>
80 #include <linux/ptrace.h>
81 #include <linux/pti.h>
82 #include <linux/blkdev.h>
83 #include <linux/elevator.h>
84 #include <linux/sched/clock.h>
85 #include <linux/sched/task.h>
86 #include <linux/sched/task_stack.h>
87 #include <linux/context_tracking.h>
88 #include <linux/random.h>
89 #include <linux/list.h>
90 #include <linux/integrity.h>
91 #include <linux/proc_ns.h>
92 #include <linux/io.h>
93 #include <linux/cache.h>
94 #include <linux/rodata_test.h>
95 #include <linux/jump_label.h>
96 #include <linux/mem_encrypt.h>
97 
98 #include <asm/io.h>
99 #include <asm/bugs.h>
100 #include <asm/setup.h>
101 #include <asm/sections.h>
102 #include <asm/cacheflush.h>
103 
104 #define CREATE_TRACE_POINTS
105 #include <trace/events/initcall.h>
106 
107 static int kernel_init(void *);
108 
109 extern void init_IRQ(void);
110 extern void radix_tree_init(void);
111 
112 /*
113  * Debug helper: via this flag we know that we are in 'early bootup code'
114  * where only the boot processor is running with IRQ disabled.  This means
115  * two things - IRQ must not be enabled before the flag is cleared and some
116  * operations which are not allowed with IRQ disabled are allowed while the
117  * flag is set.
118  */
119 bool early_boot_irqs_disabled __read_mostly;
120 
121 enum system_states system_state __read_mostly;
122 EXPORT_SYMBOL(system_state);
123 
124 /*
125  * Boot command-line arguments
126  */
127 #define MAX_INIT_ARGS CONFIG_INIT_ENV_ARG_LIMIT
128 #define MAX_INIT_ENVS CONFIG_INIT_ENV_ARG_LIMIT
129 
130 extern void time_init(void);
131 /* Default late time init is NULL. archs can override this later. */
132 void (*__initdata late_time_init)(void);
133 
134 /* Untouched command line saved by arch-specific code. */
135 char __initdata boot_command_line[COMMAND_LINE_SIZE];
136 /* Untouched saved command line (eg. for /proc) */
137 char *saved_command_line;
138 /* Command line for parameter parsing */
139 static char *static_command_line;
140 /* Untouched extra command line */
141 static char *extra_command_line;
142 /* Extra init arguments */
143 static char *extra_init_args;
144 
145 #ifdef CONFIG_BOOT_CONFIG
146 /* Is bootconfig on command line? */
147 static bool bootconfig_found;
148 static bool initargs_found;
149 #else
150 # define bootconfig_found false
151 # define initargs_found false
152 #endif
153 
154 static char *execute_command;
155 static char *ramdisk_execute_command;
156 
157 /*
158  * Used to generate warnings if static_key manipulation functions are used
159  * before jump_label_init is called.
160  */
161 bool static_key_initialized __read_mostly;
162 EXPORT_SYMBOL_GPL(static_key_initialized);
163 
164 /*
165  * If set, this is an indication to the drivers that reset the underlying
166  * device before going ahead with the initialization otherwise driver might
167  * rely on the BIOS and skip the reset operation.
168  *
169  * This is useful if kernel is booting in an unreliable environment.
170  * For ex. kdump situation where previous kernel has crashed, BIOS has been
171  * skipped and devices will be in unknown state.
172  */
173 unsigned int reset_devices;
174 EXPORT_SYMBOL(reset_devices);
175 
176 static int __init set_reset_devices(char *str)
177 {
178 	reset_devices = 1;
179 	return 1;
180 }
181 
182 __setup("reset_devices", set_reset_devices);
183 
184 static const char *argv_init[MAX_INIT_ARGS+2] = { "init", NULL, };
185 const char *envp_init[MAX_INIT_ENVS+2] = { "HOME=/", "TERM=linux", NULL, };
186 static const char *panic_later, *panic_param;
187 
188 extern const struct obs_kernel_param __setup_start[], __setup_end[];
189 
190 static bool __init obsolete_checksetup(char *line)
191 {
192 	const struct obs_kernel_param *p;
193 	bool had_early_param = false;
194 
195 	p = __setup_start;
196 	do {
197 		int n = strlen(p->str);
198 		if (parameqn(line, p->str, n)) {
199 			if (p->early) {
200 				/* Already done in parse_early_param?
201 				 * (Needs exact match on param part).
202 				 * Keep iterating, as we can have early
203 				 * params and __setups of same names 8( */
204 				if (line[n] == '\0' || line[n] == '=')
205 					had_early_param = true;
206 			} else if (!p->setup_func) {
207 				pr_warn("Parameter %s is obsolete, ignored\n",
208 					p->str);
209 				return true;
210 			} else if (p->setup_func(line + n))
211 				return true;
212 		}
213 		p++;
214 	} while (p < __setup_end);
215 
216 	return had_early_param;
217 }
218 
219 /*
220  * This should be approx 2 Bo*oMips to start (note initial shift), and will
221  * still work even if initially too large, it will just take slightly longer
222  */
223 unsigned long loops_per_jiffy = (1<<12);
224 EXPORT_SYMBOL(loops_per_jiffy);
225 
226 static int __init debug_kernel(char *str)
227 {
228 	console_loglevel = CONSOLE_LOGLEVEL_DEBUG;
229 	return 0;
230 }
231 
232 static int __init quiet_kernel(char *str)
233 {
234 	console_loglevel = CONSOLE_LOGLEVEL_QUIET;
235 	return 0;
236 }
237 
238 early_param("debug", debug_kernel);
239 early_param("quiet", quiet_kernel);
240 
241 static int __init loglevel(char *str)
242 {
243 	int newlevel;
244 
245 	/*
246 	 * Only update loglevel value when a correct setting was passed,
247 	 * to prevent blind crashes (when loglevel being set to 0) that
248 	 * are quite hard to debug
249 	 */
250 	if (get_option(&str, &newlevel)) {
251 		console_loglevel = newlevel;
252 		return 0;
253 	}
254 
255 	return -EINVAL;
256 }
257 
258 early_param("loglevel", loglevel);
259 
260 #ifdef CONFIG_BOOT_CONFIG
261 
262 char xbc_namebuf[XBC_KEYLEN_MAX] __initdata;
263 
264 #define rest(dst, end) ((end) > (dst) ? (end) - (dst) : 0)
265 
266 static int __init xbc_snprint_cmdline(char *buf, size_t size,
267 				      struct xbc_node *root)
268 {
269 	struct xbc_node *knode, *vnode;
270 	char *end = buf + size;
271 	char c = '\"';
272 	const char *val;
273 	int ret;
274 
275 	xbc_node_for_each_key_value(root, knode, val) {
276 		ret = xbc_node_compose_key_after(root, knode,
277 					xbc_namebuf, XBC_KEYLEN_MAX);
278 		if (ret < 0)
279 			return ret;
280 
281 		vnode = xbc_node_get_child(knode);
282 		ret = snprintf(buf, rest(buf, end), "%s%c", xbc_namebuf,
283 				vnode ? '=' : ' ');
284 		if (ret < 0)
285 			return ret;
286 		buf += ret;
287 		if (!vnode)
288 			continue;
289 
290 		c = '\"';
291 		xbc_array_for_each_value(vnode, val) {
292 			ret = snprintf(buf, rest(buf, end), "%c%s", c, val);
293 			if (ret < 0)
294 				return ret;
295 			buf += ret;
296 			c = ',';
297 		}
298 		if (rest(buf, end) > 2)
299 			strcpy(buf, "\" ");
300 		buf += 2;
301 	}
302 
303 	return buf - (end - size);
304 }
305 #undef rest
306 
307 /* Make an extra command line under given key word */
308 static char * __init xbc_make_cmdline(const char *key)
309 {
310 	struct xbc_node *root;
311 	char *new_cmdline;
312 	int ret, len = 0;
313 
314 	root = xbc_find_node(key);
315 	if (!root)
316 		return NULL;
317 
318 	/* Count required buffer size */
319 	len = xbc_snprint_cmdline(NULL, 0, root);
320 	if (len <= 0)
321 		return NULL;
322 
323 	new_cmdline = memblock_alloc(len + 1, SMP_CACHE_BYTES);
324 	if (!new_cmdline) {
325 		pr_err("Failed to allocate memory for extra kernel cmdline.\n");
326 		return NULL;
327 	}
328 
329 	ret = xbc_snprint_cmdline(new_cmdline, len + 1, root);
330 	if (ret < 0 || ret > len) {
331 		pr_err("Failed to print extra kernel cmdline.\n");
332 		return NULL;
333 	}
334 
335 	return new_cmdline;
336 }
337 
338 u32 boot_config_checksum(unsigned char *p, u32 size)
339 {
340 	u32 ret = 0;
341 
342 	while (size--)
343 		ret += *p++;
344 
345 	return ret;
346 }
347 
348 static int __init bootconfig_params(char *param, char *val,
349 				    const char *unused, void *arg)
350 {
351 	if (strcmp(param, "bootconfig") == 0) {
352 		bootconfig_found = true;
353 	} else if (strcmp(param, "--") == 0) {
354 		initargs_found = true;
355 	}
356 	return 0;
357 }
358 
359 static void __init setup_boot_config(const char *cmdline)
360 {
361 	static char tmp_cmdline[COMMAND_LINE_SIZE] __initdata;
362 	u32 size, csum;
363 	char *data, *copy;
364 	u32 *hdr;
365 	int ret;
366 
367 	strlcpy(tmp_cmdline, boot_command_line, COMMAND_LINE_SIZE);
368 	parse_args("bootconfig", tmp_cmdline, NULL, 0, 0, 0, NULL,
369 		   bootconfig_params);
370 
371 	if (!bootconfig_found)
372 		return;
373 
374 	if (!initrd_end)
375 		goto not_found;
376 
377 	hdr = (u32 *)(initrd_end - 8);
378 	size = hdr[0];
379 	csum = hdr[1];
380 
381 	if (size >= XBC_DATA_MAX) {
382 		pr_err("bootconfig size %d greater than max size %d\n",
383 			size, XBC_DATA_MAX);
384 		return;
385 	}
386 
387 	data = ((void *)hdr) - size;
388 	if ((unsigned long)data < initrd_start)
389 		goto not_found;
390 
391 	if (boot_config_checksum((unsigned char *)data, size) != csum) {
392 		pr_err("bootconfig checksum failed\n");
393 		return;
394 	}
395 
396 	copy = memblock_alloc(size + 1, SMP_CACHE_BYTES);
397 	if (!copy) {
398 		pr_err("Failed to allocate memory for bootconfig\n");
399 		return;
400 	}
401 
402 	memcpy(copy, data, size);
403 	copy[size] = '\0';
404 
405 	ret = xbc_init(copy);
406 	if (ret < 0)
407 		pr_err("Failed to parse bootconfig\n");
408 	else {
409 		pr_info("Load bootconfig: %d bytes %d nodes\n", size, ret);
410 		/* keys starting with "kernel." are passed via cmdline */
411 		extra_command_line = xbc_make_cmdline("kernel");
412 		/* Also, "init." keys are init arguments */
413 		extra_init_args = xbc_make_cmdline("init");
414 	}
415 	return;
416 not_found:
417 	pr_err("'bootconfig' found on command line, but no bootconfig found\n");
418 }
419 #else
420 #define setup_boot_config(cmdline)	do { } while (0)
421 #endif
422 
423 /* Change NUL term back to "=", to make "param" the whole string. */
424 static void __init repair_env_string(char *param, char *val)
425 {
426 	if (val) {
427 		/* param=val or param="val"? */
428 		if (val == param+strlen(param)+1)
429 			val[-1] = '=';
430 		else if (val == param+strlen(param)+2) {
431 			val[-2] = '=';
432 			memmove(val-1, val, strlen(val)+1);
433 		} else
434 			BUG();
435 	}
436 }
437 
438 /* Anything after -- gets handed straight to init. */
439 static int __init set_init_arg(char *param, char *val,
440 			       const char *unused, void *arg)
441 {
442 	unsigned int i;
443 
444 	if (panic_later)
445 		return 0;
446 
447 	repair_env_string(param, val);
448 
449 	for (i = 0; argv_init[i]; i++) {
450 		if (i == MAX_INIT_ARGS) {
451 			panic_later = "init";
452 			panic_param = param;
453 			return 0;
454 		}
455 	}
456 	argv_init[i] = param;
457 	return 0;
458 }
459 
460 /*
461  * Unknown boot options get handed to init, unless they look like
462  * unused parameters (modprobe will find them in /proc/cmdline).
463  */
464 static int __init unknown_bootoption(char *param, char *val,
465 				     const char *unused, void *arg)
466 {
467 	size_t len = strlen(param);
468 
469 	repair_env_string(param, val);
470 
471 	/* Handle obsolete-style parameters */
472 	if (obsolete_checksetup(param))
473 		return 0;
474 
475 	/* Unused module parameter. */
476 	if (strnchr(param, len, '.'))
477 		return 0;
478 
479 	if (panic_later)
480 		return 0;
481 
482 	if (val) {
483 		/* Environment option */
484 		unsigned int i;
485 		for (i = 0; envp_init[i]; i++) {
486 			if (i == MAX_INIT_ENVS) {
487 				panic_later = "env";
488 				panic_param = param;
489 			}
490 			if (!strncmp(param, envp_init[i], len+1))
491 				break;
492 		}
493 		envp_init[i] = param;
494 	} else {
495 		/* Command line option */
496 		unsigned int i;
497 		for (i = 0; argv_init[i]; i++) {
498 			if (i == MAX_INIT_ARGS) {
499 				panic_later = "init";
500 				panic_param = param;
501 			}
502 		}
503 		argv_init[i] = param;
504 	}
505 	return 0;
506 }
507 
508 static int __init init_setup(char *str)
509 {
510 	unsigned int i;
511 
512 	execute_command = str;
513 	/*
514 	 * In case LILO is going to boot us with default command line,
515 	 * it prepends "auto" before the whole cmdline which makes
516 	 * the shell think it should execute a script with such name.
517 	 * So we ignore all arguments entered _before_ init=... [MJ]
518 	 */
519 	for (i = 1; i < MAX_INIT_ARGS; i++)
520 		argv_init[i] = NULL;
521 	return 1;
522 }
523 __setup("init=", init_setup);
524 
525 static int __init rdinit_setup(char *str)
526 {
527 	unsigned int i;
528 
529 	ramdisk_execute_command = str;
530 	/* See "auto" comment in init_setup */
531 	for (i = 1; i < MAX_INIT_ARGS; i++)
532 		argv_init[i] = NULL;
533 	return 1;
534 }
535 __setup("rdinit=", rdinit_setup);
536 
537 #ifndef CONFIG_SMP
538 static const unsigned int setup_max_cpus = NR_CPUS;
539 static inline void setup_nr_cpu_ids(void) { }
540 static inline void smp_prepare_cpus(unsigned int maxcpus) { }
541 #endif
542 
543 /*
544  * We need to store the untouched command line for future reference.
545  * We also need to store the touched command line since the parameter
546  * parsing is performed in place, and we should allow a component to
547  * store reference of name/value for future reference.
548  */
549 static void __init setup_command_line(char *command_line)
550 {
551 	size_t len, xlen = 0, ilen = 0;
552 
553 	if (extra_command_line)
554 		xlen = strlen(extra_command_line);
555 	if (extra_init_args)
556 		ilen = strlen(extra_init_args) + 4; /* for " -- " */
557 
558 	len = xlen + strlen(boot_command_line) + 1;
559 
560 	saved_command_line = memblock_alloc(len + ilen, SMP_CACHE_BYTES);
561 	if (!saved_command_line)
562 		panic("%s: Failed to allocate %zu bytes\n", __func__, len + ilen);
563 
564 	static_command_line = memblock_alloc(len, SMP_CACHE_BYTES);
565 	if (!static_command_line)
566 		panic("%s: Failed to allocate %zu bytes\n", __func__, len);
567 
568 	if (xlen) {
569 		/*
570 		 * We have to put extra_command_line before boot command
571 		 * lines because there could be dashes (separator of init
572 		 * command line) in the command lines.
573 		 */
574 		strcpy(saved_command_line, extra_command_line);
575 		strcpy(static_command_line, extra_command_line);
576 	}
577 	strcpy(saved_command_line + xlen, boot_command_line);
578 	strcpy(static_command_line + xlen, command_line);
579 
580 	if (ilen) {
581 		/*
582 		 * Append supplemental init boot args to saved_command_line
583 		 * so that user can check what command line options passed
584 		 * to init.
585 		 */
586 		len = strlen(saved_command_line);
587 		if (initargs_found) {
588 			saved_command_line[len++] = ' ';
589 		} else {
590 			strcpy(saved_command_line + len, " -- ");
591 			len += 4;
592 		}
593 
594 		strcpy(saved_command_line + len, extra_init_args);
595 	}
596 }
597 
598 /*
599  * We need to finalize in a non-__init function or else race conditions
600  * between the root thread and the init thread may cause start_kernel to
601  * be reaped by free_initmem before the root thread has proceeded to
602  * cpu_idle.
603  *
604  * gcc-3.4 accidentally inlines this function, so use noinline.
605  */
606 
607 static __initdata DECLARE_COMPLETION(kthreadd_done);
608 
609 noinline void __ref rest_init(void)
610 {
611 	struct task_struct *tsk;
612 	int pid;
613 
614 	rcu_scheduler_starting();
615 	/*
616 	 * We need to spawn init first so that it obtains pid 1, however
617 	 * the init task will end up wanting to create kthreads, which, if
618 	 * we schedule it before we create kthreadd, will OOPS.
619 	 */
620 	pid = kernel_thread(kernel_init, NULL, CLONE_FS);
621 	/*
622 	 * Pin init on the boot CPU. Task migration is not properly working
623 	 * until sched_init_smp() has been run. It will set the allowed
624 	 * CPUs for init to the non isolated CPUs.
625 	 */
626 	rcu_read_lock();
627 	tsk = find_task_by_pid_ns(pid, &init_pid_ns);
628 	set_cpus_allowed_ptr(tsk, cpumask_of(smp_processor_id()));
629 	rcu_read_unlock();
630 
631 	numa_default_policy();
632 	pid = kernel_thread(kthreadd, NULL, CLONE_FS | CLONE_FILES);
633 	rcu_read_lock();
634 	kthreadd_task = find_task_by_pid_ns(pid, &init_pid_ns);
635 	rcu_read_unlock();
636 
637 	/*
638 	 * Enable might_sleep() and smp_processor_id() checks.
639 	 * They cannot be enabled earlier because with CONFIG_PREEMPTION=y
640 	 * kernel_thread() would trigger might_sleep() splats. With
641 	 * CONFIG_PREEMPT_VOLUNTARY=y the init task might have scheduled
642 	 * already, but it's stuck on the kthreadd_done completion.
643 	 */
644 	system_state = SYSTEM_SCHEDULING;
645 
646 	complete(&kthreadd_done);
647 
648 	/*
649 	 * The boot idle thread must execute schedule()
650 	 * at least once to get things moving:
651 	 */
652 	schedule_preempt_disabled();
653 	/* Call into cpu_idle with preempt disabled */
654 	cpu_startup_entry(CPUHP_ONLINE);
655 }
656 
657 /* Check for early params. */
658 static int __init do_early_param(char *param, char *val,
659 				 const char *unused, void *arg)
660 {
661 	const struct obs_kernel_param *p;
662 
663 	for (p = __setup_start; p < __setup_end; p++) {
664 		if ((p->early && parameq(param, p->str)) ||
665 		    (strcmp(param, "console") == 0 &&
666 		     strcmp(p->str, "earlycon") == 0)
667 		) {
668 			if (p->setup_func(val) != 0)
669 				pr_warn("Malformed early option '%s'\n", param);
670 		}
671 	}
672 	/* We accept everything at this stage. */
673 	return 0;
674 }
675 
676 void __init parse_early_options(char *cmdline)
677 {
678 	parse_args("early options", cmdline, NULL, 0, 0, 0, NULL,
679 		   do_early_param);
680 }
681 
682 /* Arch code calls this early on, or if not, just before other parsing. */
683 void __init parse_early_param(void)
684 {
685 	static int done __initdata;
686 	static char tmp_cmdline[COMMAND_LINE_SIZE] __initdata;
687 
688 	if (done)
689 		return;
690 
691 	/* All fall through to do_early_param. */
692 	strlcpy(tmp_cmdline, boot_command_line, COMMAND_LINE_SIZE);
693 	parse_early_options(tmp_cmdline);
694 	done = 1;
695 }
696 
697 void __init __weak arch_post_acpi_subsys_init(void) { }
698 
699 void __init __weak smp_setup_processor_id(void)
700 {
701 }
702 
703 # if THREAD_SIZE >= PAGE_SIZE
704 void __init __weak thread_stack_cache_init(void)
705 {
706 }
707 #endif
708 
709 void __init __weak mem_encrypt_init(void) { }
710 
711 void __init __weak poking_init(void) { }
712 
713 void __init __weak pgtable_cache_init(void) { }
714 
715 bool initcall_debug;
716 core_param(initcall_debug, initcall_debug, bool, 0644);
717 
718 #ifdef TRACEPOINTS_ENABLED
719 static void __init initcall_debug_enable(void);
720 #else
721 static inline void initcall_debug_enable(void)
722 {
723 }
724 #endif
725 
726 /* Report memory auto-initialization states for this boot. */
727 static void __init report_meminit(void)
728 {
729 	const char *stack;
730 
731 	if (IS_ENABLED(CONFIG_INIT_STACK_ALL))
732 		stack = "all";
733 	else if (IS_ENABLED(CONFIG_GCC_PLUGIN_STRUCTLEAK_BYREF_ALL))
734 		stack = "byref_all";
735 	else if (IS_ENABLED(CONFIG_GCC_PLUGIN_STRUCTLEAK_BYREF))
736 		stack = "byref";
737 	else if (IS_ENABLED(CONFIG_GCC_PLUGIN_STRUCTLEAK_USER))
738 		stack = "__user";
739 	else
740 		stack = "off";
741 
742 	pr_info("mem auto-init: stack:%s, heap alloc:%s, heap free:%s\n",
743 		stack, want_init_on_alloc(GFP_KERNEL) ? "on" : "off",
744 		want_init_on_free() ? "on" : "off");
745 	if (want_init_on_free())
746 		pr_info("mem auto-init: clearing system memory may take some time...\n");
747 }
748 
749 /*
750  * Set up kernel memory allocators
751  */
752 static void __init mm_init(void)
753 {
754 	/*
755 	 * page_ext requires contiguous pages,
756 	 * bigger than MAX_ORDER unless SPARSEMEM.
757 	 */
758 	page_ext_init_flatmem();
759 	init_debug_pagealloc();
760 	report_meminit();
761 	mem_init();
762 	kmem_cache_init();
763 	kmemleak_init();
764 	pgtable_init();
765 	debug_objects_mem_init();
766 	vmalloc_init();
767 	ioremap_huge_init();
768 	/* Should be run before the first non-init thread is created */
769 	init_espfix_bsp();
770 	/* Should be run after espfix64 is set up. */
771 	pti_init();
772 }
773 
774 void __init __weak arch_call_rest_init(void)
775 {
776 	rest_init();
777 }
778 
779 asmlinkage __visible void __init start_kernel(void)
780 {
781 	char *command_line;
782 	char *after_dashes;
783 
784 	set_task_stack_end_magic(&init_task);
785 	smp_setup_processor_id();
786 	debug_objects_early_init();
787 
788 	cgroup_init_early();
789 
790 	local_irq_disable();
791 	early_boot_irqs_disabled = true;
792 
793 	/*
794 	 * Interrupts are still disabled. Do necessary setups, then
795 	 * enable them.
796 	 */
797 	boot_cpu_init();
798 	page_address_init();
799 	pr_notice("%s", linux_banner);
800 	early_security_init();
801 	setup_arch(&command_line);
802 	setup_boot_config(command_line);
803 	setup_command_line(command_line);
804 	setup_nr_cpu_ids();
805 	setup_per_cpu_areas();
806 	smp_prepare_boot_cpu();	/* arch-specific boot-cpu hooks */
807 	boot_cpu_hotplug_init();
808 
809 	build_all_zonelists(NULL);
810 	page_alloc_init();
811 
812 	pr_notice("Kernel command line: %s\n", saved_command_line);
813 	/* parameters may set static keys */
814 	jump_label_init();
815 	parse_early_param();
816 	after_dashes = parse_args("Booting kernel",
817 				  static_command_line, __start___param,
818 				  __stop___param - __start___param,
819 				  -1, -1, NULL, &unknown_bootoption);
820 	if (!IS_ERR_OR_NULL(after_dashes))
821 		parse_args("Setting init args", after_dashes, NULL, 0, -1, -1,
822 			   NULL, set_init_arg);
823 	if (extra_init_args)
824 		parse_args("Setting extra init args", extra_init_args,
825 			   NULL, 0, -1, -1, NULL, set_init_arg);
826 
827 	/*
828 	 * These use large bootmem allocations and must precede
829 	 * kmem_cache_init()
830 	 */
831 	setup_log_buf(0);
832 	vfs_caches_init_early();
833 	sort_main_extable();
834 	trap_init();
835 	mm_init();
836 
837 	ftrace_init();
838 
839 	/* trace_printk can be enabled here */
840 	early_trace_init();
841 
842 	/*
843 	 * Set up the scheduler prior starting any interrupts (such as the
844 	 * timer interrupt). Full topology setup happens at smp_init()
845 	 * time - but meanwhile we still have a functioning scheduler.
846 	 */
847 	sched_init();
848 	/*
849 	 * Disable preemption - early bootup scheduling is extremely
850 	 * fragile until we cpu_idle() for the first time.
851 	 */
852 	preempt_disable();
853 	if (WARN(!irqs_disabled(),
854 		 "Interrupts were enabled *very* early, fixing it\n"))
855 		local_irq_disable();
856 	radix_tree_init();
857 
858 	/*
859 	 * Set up housekeeping before setting up workqueues to allow the unbound
860 	 * workqueue to take non-housekeeping into account.
861 	 */
862 	housekeeping_init();
863 
864 	/*
865 	 * Allow workqueue creation and work item queueing/cancelling
866 	 * early.  Work item execution depends on kthreads and starts after
867 	 * workqueue_init().
868 	 */
869 	workqueue_init_early();
870 
871 	rcu_init();
872 
873 	/* Trace events are available after this */
874 	trace_init();
875 
876 	if (initcall_debug)
877 		initcall_debug_enable();
878 
879 	context_tracking_init();
880 	/* init some links before init_ISA_irqs() */
881 	early_irq_init();
882 	init_IRQ();
883 	tick_init();
884 	rcu_init_nohz();
885 	init_timers();
886 	hrtimers_init();
887 	softirq_init();
888 	timekeeping_init();
889 
890 	/*
891 	 * For best initial stack canary entropy, prepare it after:
892 	 * - setup_arch() for any UEFI RNG entropy and boot cmdline access
893 	 * - timekeeping_init() for ktime entropy used in rand_initialize()
894 	 * - rand_initialize() to get any arch-specific entropy like RDRAND
895 	 * - add_latent_entropy() to get any latent entropy
896 	 * - adding command line entropy
897 	 */
898 	rand_initialize();
899 	add_latent_entropy();
900 	add_device_randomness(command_line, strlen(command_line));
901 	boot_init_stack_canary();
902 
903 	time_init();
904 	printk_safe_init();
905 	perf_event_init();
906 	profile_init();
907 	call_function_init();
908 	WARN(!irqs_disabled(), "Interrupts were enabled early\n");
909 
910 	early_boot_irqs_disabled = false;
911 	local_irq_enable();
912 
913 	kmem_cache_init_late();
914 
915 	/*
916 	 * HACK ALERT! This is early. We're enabling the console before
917 	 * we've done PCI setups etc, and console_init() must be aware of
918 	 * this. But we do want output early, in case something goes wrong.
919 	 */
920 	console_init();
921 	if (panic_later)
922 		panic("Too many boot %s vars at `%s'", panic_later,
923 		      panic_param);
924 
925 	lockdep_init();
926 
927 	/*
928 	 * Need to run this when irqs are enabled, because it wants
929 	 * to self-test [hard/soft]-irqs on/off lock inversion bugs
930 	 * too:
931 	 */
932 	locking_selftest();
933 
934 	/*
935 	 * This needs to be called before any devices perform DMA
936 	 * operations that might use the SWIOTLB bounce buffers. It will
937 	 * mark the bounce buffers as decrypted so that their usage will
938 	 * not cause "plain-text" data to be decrypted when accessed.
939 	 */
940 	mem_encrypt_init();
941 
942 #ifdef CONFIG_BLK_DEV_INITRD
943 	if (initrd_start && !initrd_below_start_ok &&
944 	    page_to_pfn(virt_to_page((void *)initrd_start)) < min_low_pfn) {
945 		pr_crit("initrd overwritten (0x%08lx < 0x%08lx) - disabling it.\n",
946 		    page_to_pfn(virt_to_page((void *)initrd_start)),
947 		    min_low_pfn);
948 		initrd_start = 0;
949 	}
950 #endif
951 	setup_per_cpu_pageset();
952 	numa_policy_init();
953 	acpi_early_init();
954 	if (late_time_init)
955 		late_time_init();
956 	sched_clock_init();
957 	calibrate_delay();
958 	pid_idr_init();
959 	anon_vma_init();
960 #ifdef CONFIG_X86
961 	if (efi_enabled(EFI_RUNTIME_SERVICES))
962 		efi_enter_virtual_mode();
963 #endif
964 	thread_stack_cache_init();
965 	cred_init();
966 	fork_init();
967 	proc_caches_init();
968 	uts_ns_init();
969 	buffer_init();
970 	key_init();
971 	security_init();
972 	dbg_late_init();
973 	vfs_caches_init();
974 	pagecache_init();
975 	signals_init();
976 	seq_file_init();
977 	proc_root_init();
978 	nsfs_init();
979 	cpuset_init();
980 	cgroup_init();
981 	taskstats_init_early();
982 	delayacct_init();
983 
984 	poking_init();
985 	check_bugs();
986 
987 	acpi_subsystem_init();
988 	arch_post_acpi_subsys_init();
989 	sfi_init_late();
990 
991 	/* Do the rest non-__init'ed, we're now alive */
992 	arch_call_rest_init();
993 }
994 
995 /* Call all constructor functions linked into the kernel. */
996 static void __init do_ctors(void)
997 {
998 #ifdef CONFIG_CONSTRUCTORS
999 	ctor_fn_t *fn = (ctor_fn_t *) __ctors_start;
1000 
1001 	for (; fn < (ctor_fn_t *) __ctors_end; fn++)
1002 		(*fn)();
1003 #endif
1004 }
1005 
1006 #ifdef CONFIG_KALLSYMS
1007 struct blacklist_entry {
1008 	struct list_head next;
1009 	char *buf;
1010 };
1011 
1012 static __initdata_or_module LIST_HEAD(blacklisted_initcalls);
1013 
1014 static int __init initcall_blacklist(char *str)
1015 {
1016 	char *str_entry;
1017 	struct blacklist_entry *entry;
1018 
1019 	/* str argument is a comma-separated list of functions */
1020 	do {
1021 		str_entry = strsep(&str, ",");
1022 		if (str_entry) {
1023 			pr_debug("blacklisting initcall %s\n", str_entry);
1024 			entry = memblock_alloc(sizeof(*entry),
1025 					       SMP_CACHE_BYTES);
1026 			if (!entry)
1027 				panic("%s: Failed to allocate %zu bytes\n",
1028 				      __func__, sizeof(*entry));
1029 			entry->buf = memblock_alloc(strlen(str_entry) + 1,
1030 						    SMP_CACHE_BYTES);
1031 			if (!entry->buf)
1032 				panic("%s: Failed to allocate %zu bytes\n",
1033 				      __func__, strlen(str_entry) + 1);
1034 			strcpy(entry->buf, str_entry);
1035 			list_add(&entry->next, &blacklisted_initcalls);
1036 		}
1037 	} while (str_entry);
1038 
1039 	return 0;
1040 }
1041 
1042 static bool __init_or_module initcall_blacklisted(initcall_t fn)
1043 {
1044 	struct blacklist_entry *entry;
1045 	char fn_name[KSYM_SYMBOL_LEN];
1046 	unsigned long addr;
1047 
1048 	if (list_empty(&blacklisted_initcalls))
1049 		return false;
1050 
1051 	addr = (unsigned long) dereference_function_descriptor(fn);
1052 	sprint_symbol_no_offset(fn_name, addr);
1053 
1054 	/*
1055 	 * fn will be "function_name [module_name]" where [module_name] is not
1056 	 * displayed for built-in init functions.  Strip off the [module_name].
1057 	 */
1058 	strreplace(fn_name, ' ', '\0');
1059 
1060 	list_for_each_entry(entry, &blacklisted_initcalls, next) {
1061 		if (!strcmp(fn_name, entry->buf)) {
1062 			pr_debug("initcall %s blacklisted\n", fn_name);
1063 			return true;
1064 		}
1065 	}
1066 
1067 	return false;
1068 }
1069 #else
1070 static int __init initcall_blacklist(char *str)
1071 {
1072 	pr_warn("initcall_blacklist requires CONFIG_KALLSYMS\n");
1073 	return 0;
1074 }
1075 
1076 static bool __init_or_module initcall_blacklisted(initcall_t fn)
1077 {
1078 	return false;
1079 }
1080 #endif
1081 __setup("initcall_blacklist=", initcall_blacklist);
1082 
1083 static __init_or_module void
1084 trace_initcall_start_cb(void *data, initcall_t fn)
1085 {
1086 	ktime_t *calltime = (ktime_t *)data;
1087 
1088 	printk(KERN_DEBUG "calling  %pS @ %i\n", fn, task_pid_nr(current));
1089 	*calltime = ktime_get();
1090 }
1091 
1092 static __init_or_module void
1093 trace_initcall_finish_cb(void *data, initcall_t fn, int ret)
1094 {
1095 	ktime_t *calltime = (ktime_t *)data;
1096 	ktime_t delta, rettime;
1097 	unsigned long long duration;
1098 
1099 	rettime = ktime_get();
1100 	delta = ktime_sub(rettime, *calltime);
1101 	duration = (unsigned long long) ktime_to_ns(delta) >> 10;
1102 	printk(KERN_DEBUG "initcall %pS returned %d after %lld usecs\n",
1103 		 fn, ret, duration);
1104 }
1105 
1106 static ktime_t initcall_calltime;
1107 
1108 #ifdef TRACEPOINTS_ENABLED
1109 static void __init initcall_debug_enable(void)
1110 {
1111 	int ret;
1112 
1113 	ret = register_trace_initcall_start(trace_initcall_start_cb,
1114 					    &initcall_calltime);
1115 	ret |= register_trace_initcall_finish(trace_initcall_finish_cb,
1116 					      &initcall_calltime);
1117 	WARN(ret, "Failed to register initcall tracepoints\n");
1118 }
1119 # define do_trace_initcall_start	trace_initcall_start
1120 # define do_trace_initcall_finish	trace_initcall_finish
1121 #else
1122 static inline void do_trace_initcall_start(initcall_t fn)
1123 {
1124 	if (!initcall_debug)
1125 		return;
1126 	trace_initcall_start_cb(&initcall_calltime, fn);
1127 }
1128 static inline void do_trace_initcall_finish(initcall_t fn, int ret)
1129 {
1130 	if (!initcall_debug)
1131 		return;
1132 	trace_initcall_finish_cb(&initcall_calltime, fn, ret);
1133 }
1134 #endif /* !TRACEPOINTS_ENABLED */
1135 
1136 int __init_or_module do_one_initcall(initcall_t fn)
1137 {
1138 	int count = preempt_count();
1139 	char msgbuf[64];
1140 	int ret;
1141 
1142 	if (initcall_blacklisted(fn))
1143 		return -EPERM;
1144 
1145 	do_trace_initcall_start(fn);
1146 	ret = fn();
1147 	do_trace_initcall_finish(fn, ret);
1148 
1149 	msgbuf[0] = 0;
1150 
1151 	if (preempt_count() != count) {
1152 		sprintf(msgbuf, "preemption imbalance ");
1153 		preempt_count_set(count);
1154 	}
1155 	if (irqs_disabled()) {
1156 		strlcat(msgbuf, "disabled interrupts ", sizeof(msgbuf));
1157 		local_irq_enable();
1158 	}
1159 	WARN(msgbuf[0], "initcall %pS returned with %s\n", fn, msgbuf);
1160 
1161 	add_latent_entropy();
1162 	return ret;
1163 }
1164 
1165 
1166 extern initcall_entry_t __initcall_start[];
1167 extern initcall_entry_t __initcall0_start[];
1168 extern initcall_entry_t __initcall1_start[];
1169 extern initcall_entry_t __initcall2_start[];
1170 extern initcall_entry_t __initcall3_start[];
1171 extern initcall_entry_t __initcall4_start[];
1172 extern initcall_entry_t __initcall5_start[];
1173 extern initcall_entry_t __initcall6_start[];
1174 extern initcall_entry_t __initcall7_start[];
1175 extern initcall_entry_t __initcall_end[];
1176 
1177 static initcall_entry_t *initcall_levels[] __initdata = {
1178 	__initcall0_start,
1179 	__initcall1_start,
1180 	__initcall2_start,
1181 	__initcall3_start,
1182 	__initcall4_start,
1183 	__initcall5_start,
1184 	__initcall6_start,
1185 	__initcall7_start,
1186 	__initcall_end,
1187 };
1188 
1189 /* Keep these in sync with initcalls in include/linux/init.h */
1190 static const char *initcall_level_names[] __initdata = {
1191 	"pure",
1192 	"core",
1193 	"postcore",
1194 	"arch",
1195 	"subsys",
1196 	"fs",
1197 	"device",
1198 	"late",
1199 };
1200 
1201 static int __init ignore_unknown_bootoption(char *param, char *val,
1202 			       const char *unused, void *arg)
1203 {
1204 	return 0;
1205 }
1206 
1207 static void __init do_initcall_level(int level, char *command_line)
1208 {
1209 	initcall_entry_t *fn;
1210 
1211 	parse_args(initcall_level_names[level],
1212 		   command_line, __start___param,
1213 		   __stop___param - __start___param,
1214 		   level, level,
1215 		   NULL, ignore_unknown_bootoption);
1216 
1217 	trace_initcall_level(initcall_level_names[level]);
1218 	for (fn = initcall_levels[level]; fn < initcall_levels[level+1]; fn++)
1219 		do_one_initcall(initcall_from_entry(fn));
1220 }
1221 
1222 static void __init do_initcalls(void)
1223 {
1224 	int level;
1225 	size_t len = strlen(saved_command_line) + 1;
1226 	char *command_line;
1227 
1228 	command_line = kzalloc(len, GFP_KERNEL);
1229 	if (!command_line)
1230 		panic("%s: Failed to allocate %zu bytes\n", __func__, len);
1231 
1232 	for (level = 0; level < ARRAY_SIZE(initcall_levels) - 1; level++) {
1233 		/* Parser modifies command_line, restore it each time */
1234 		strcpy(command_line, saved_command_line);
1235 		do_initcall_level(level, command_line);
1236 	}
1237 
1238 	kfree(command_line);
1239 }
1240 
1241 /*
1242  * Ok, the machine is now initialized. None of the devices
1243  * have been touched yet, but the CPU subsystem is up and
1244  * running, and memory and process management works.
1245  *
1246  * Now we can finally start doing some real work..
1247  */
1248 static void __init do_basic_setup(void)
1249 {
1250 	cpuset_init_smp();
1251 	driver_init();
1252 	init_irq_proc();
1253 	do_ctors();
1254 	usermodehelper_enable();
1255 	do_initcalls();
1256 }
1257 
1258 static void __init do_pre_smp_initcalls(void)
1259 {
1260 	initcall_entry_t *fn;
1261 
1262 	trace_initcall_level("early");
1263 	for (fn = __initcall_start; fn < __initcall0_start; fn++)
1264 		do_one_initcall(initcall_from_entry(fn));
1265 }
1266 
1267 static int run_init_process(const char *init_filename)
1268 {
1269 	const char *const *p;
1270 
1271 	argv_init[0] = init_filename;
1272 	pr_info("Run %s as init process\n", init_filename);
1273 	pr_debug("  with arguments:\n");
1274 	for (p = argv_init; *p; p++)
1275 		pr_debug("    %s\n", *p);
1276 	pr_debug("  with environment:\n");
1277 	for (p = envp_init; *p; p++)
1278 		pr_debug("    %s\n", *p);
1279 	return do_execve(getname_kernel(init_filename),
1280 		(const char __user *const __user *)argv_init,
1281 		(const char __user *const __user *)envp_init);
1282 }
1283 
1284 static int try_to_run_init_process(const char *init_filename)
1285 {
1286 	int ret;
1287 
1288 	ret = run_init_process(init_filename);
1289 
1290 	if (ret && ret != -ENOENT) {
1291 		pr_err("Starting init: %s exists but couldn't execute it (error %d)\n",
1292 		       init_filename, ret);
1293 	}
1294 
1295 	return ret;
1296 }
1297 
1298 static noinline void __init kernel_init_freeable(void);
1299 
1300 #if defined(CONFIG_STRICT_KERNEL_RWX) || defined(CONFIG_STRICT_MODULE_RWX)
1301 bool rodata_enabled __ro_after_init = true;
1302 static int __init set_debug_rodata(char *str)
1303 {
1304 	return strtobool(str, &rodata_enabled);
1305 }
1306 __setup("rodata=", set_debug_rodata);
1307 #endif
1308 
1309 #ifdef CONFIG_STRICT_KERNEL_RWX
1310 static void mark_readonly(void)
1311 {
1312 	if (rodata_enabled) {
1313 		/*
1314 		 * load_module() results in W+X mappings, which are cleaned
1315 		 * up with call_rcu().  Let's make sure that queued work is
1316 		 * flushed so that we don't hit false positives looking for
1317 		 * insecure pages which are W+X.
1318 		 */
1319 		rcu_barrier();
1320 		mark_rodata_ro();
1321 		rodata_test();
1322 	} else
1323 		pr_info("Kernel memory protection disabled.\n");
1324 }
1325 #elif defined(CONFIG_ARCH_HAS_STRICT_KERNEL_RWX)
1326 static inline void mark_readonly(void)
1327 {
1328 	pr_warn("Kernel memory protection not selected by kernel config.\n");
1329 }
1330 #else
1331 static inline void mark_readonly(void)
1332 {
1333 	pr_warn("This architecture does not have kernel memory protection.\n");
1334 }
1335 #endif
1336 
1337 void __weak free_initmem(void)
1338 {
1339 	free_initmem_default(POISON_FREE_INITMEM);
1340 }
1341 
1342 static int __ref kernel_init(void *unused)
1343 {
1344 	int ret;
1345 
1346 	kernel_init_freeable();
1347 	/* need to finish all async __init code before freeing the memory */
1348 	async_synchronize_full();
1349 	ftrace_free_init_mem();
1350 	free_initmem();
1351 	mark_readonly();
1352 
1353 	/*
1354 	 * Kernel mappings are now finalized - update the userspace page-table
1355 	 * to finalize PTI.
1356 	 */
1357 	pti_finalize();
1358 
1359 	system_state = SYSTEM_RUNNING;
1360 	numa_default_policy();
1361 
1362 	rcu_end_inkernel_boot();
1363 
1364 	if (ramdisk_execute_command) {
1365 		ret = run_init_process(ramdisk_execute_command);
1366 		if (!ret)
1367 			return 0;
1368 		pr_err("Failed to execute %s (error %d)\n",
1369 		       ramdisk_execute_command, ret);
1370 	}
1371 
1372 	/*
1373 	 * We try each of these until one succeeds.
1374 	 *
1375 	 * The Bourne shell can be used instead of init if we are
1376 	 * trying to recover a really broken machine.
1377 	 */
1378 	if (execute_command) {
1379 		ret = run_init_process(execute_command);
1380 		if (!ret)
1381 			return 0;
1382 		panic("Requested init %s failed (error %d).",
1383 		      execute_command, ret);
1384 	}
1385 	if (!try_to_run_init_process("/sbin/init") ||
1386 	    !try_to_run_init_process("/etc/init") ||
1387 	    !try_to_run_init_process("/bin/init") ||
1388 	    !try_to_run_init_process("/bin/sh"))
1389 		return 0;
1390 
1391 	panic("No working init found.  Try passing init= option to kernel. "
1392 	      "See Linux Documentation/admin-guide/init.rst for guidance.");
1393 }
1394 
1395 void console_on_rootfs(void)
1396 {
1397 	/* Open the /dev/console as stdin, this should never fail */
1398 	if (ksys_open((const char __user *) "/dev/console", O_RDWR, 0) < 0)
1399 		pr_err("Warning: unable to open an initial console.\n");
1400 
1401 	/* create stdout/stderr */
1402 	(void) ksys_dup(0);
1403 	(void) ksys_dup(0);
1404 }
1405 
1406 static noinline void __init kernel_init_freeable(void)
1407 {
1408 	/*
1409 	 * Wait until kthreadd is all set-up.
1410 	 */
1411 	wait_for_completion(&kthreadd_done);
1412 
1413 	/* Now the scheduler is fully set up and can do blocking allocations */
1414 	gfp_allowed_mask = __GFP_BITS_MASK;
1415 
1416 	/*
1417 	 * init can allocate pages on any node
1418 	 */
1419 	set_mems_allowed(node_states[N_MEMORY]);
1420 
1421 	cad_pid = task_pid(current);
1422 
1423 	smp_prepare_cpus(setup_max_cpus);
1424 
1425 	workqueue_init();
1426 
1427 	init_mm_internals();
1428 
1429 	do_pre_smp_initcalls();
1430 	lockup_detector_init();
1431 
1432 	smp_init();
1433 	sched_init_smp();
1434 
1435 	page_alloc_init_late();
1436 	/* Initialize page ext after all struct pages are initialized. */
1437 	page_ext_init();
1438 
1439 	do_basic_setup();
1440 
1441 	console_on_rootfs();
1442 
1443 	/*
1444 	 * check if there is an early userspace init.  If yes, let it do all
1445 	 * the work
1446 	 */
1447 
1448 	if (!ramdisk_execute_command)
1449 		ramdisk_execute_command = "/init";
1450 
1451 	if (ksys_access((const char __user *)
1452 			ramdisk_execute_command, 0) != 0) {
1453 		ramdisk_execute_command = NULL;
1454 		prepare_namespace();
1455 	}
1456 
1457 	/*
1458 	 * Ok, we have completed the initial bootup, and
1459 	 * we're essentially up and running. Get rid of the
1460 	 * initmem segments and start the user-mode stuff..
1461 	 *
1462 	 * rootfs is available now, try loading the public keys
1463 	 * and default modules
1464 	 */
1465 
1466 	integrity_load_keys();
1467 }
1468