Update Linux to 6.18 - #4191
Update Linux to 6.18#4191sayanchowdhury wants to merge 10 commits into
Conversation
There was a problem hiding this comment.
Pull request overview
This PR updates the Flatcar/CoreOS kernel stack to Linux 6.18.26, including new kernel sources/modules/kernel ebuilds, updated kernel configuration for amd64/arm64, and compatibility fixes for the legacy NVIDIA 550.163.01 driver against newer kernel APIs.
Changes:
- Bump kernel sources to 6.18.26 (new
coreos-sources,coreos-modules,coreos-kernelebuilds + updated Manifest). - Add/refresh downstream kernel patch set under
coreos-sources/files/6.18/(secure-boot/lockdown-related, build tooling tweaks). - Extend
old-nvidia-drivers-550.163.01to support kernels up to 6.18 via additional patching andsrc_prepareadjustments.
Reviewed changes
Copilot reviewed 23 out of 23 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/old-nvidia-drivers-550.163.01-r2.ebuild | Bump supported kernel max to 6.18 and add NVIDIA 550 build-fix patches + in-tree sed adjustments. |
| sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0001-mm-use-vm_flags_reset-to-avoid-GPL-only-vma_start_wr.patch | Adapts NVIDIA mm/VMA flag helpers for Linux 6.15+ GPL/export changes. |
| sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0002-nvidia-drm-550.163.01-pass-drm_format_info-to-nv_drm.patch | Updates NVIDIA DRM fb_create plumbing for Linux 6.17+ API change (format info param). |
| sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0003-nvidia-use-hrtimer_setup-for-Linux-6.15.patch | Switches to hrtimer_setup() for Linux 6.15+ in the open kernel module path. |
| sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0004-nvidia-uvm-guard-iommu_dev_enable_disable_feature-fo.patch | Guards removed IOMMU SVA enable/disable calls for Linux 6.16+. |
| sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0005-nvidia-uvm-guard-SMMU-WAR-code-with-UVM_ATS_SMMU_WA.patch | Makes ARM64 SMMU WAR code conditional to avoid non-ARM build issues. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/Manifest | Adds distfiles entries for linux-6.18 + patch-6.18.26. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/coreos-sources-6.18.26.ebuild | New kernel sources ebuild for 6.18.26 with patch list for Flatcar deltas. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0001-pahole-support-reproducible-builds.patch | Enables reproducible-build support in pahole flags. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0002-Revert-x86-boot-Remove-the-bugger-off-message.patch | Reverts upstream removal needed for dm-verity hash storage per commit message. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0003-efi-Add-an-EFI_SECURE_BOOT-flag-to-indicate-secure-b.patch | Adds EFI secure boot flag plumbing and secureboot.c addition. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0003-efi-add-an-efi_secure_boot-flag-to-indicate-secure-b.patch | Duplicate alternate-form patch file for EFI secure boot flag plumbing. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0004-efi-Lock-down-the-kernel-if-booted-in-secure-boot-mo.patch | Adds lockdown-on-secure-boot behavior and related Kconfig/API changes. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0004-efi-lock-down-the-kernel-if-booted-in-secure-boot-mo.patch | Duplicate alternate-form patch file for secure-boot lockdown. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0005-mtd-phram-slram-Disable-when-the-kernel-is-locked-do.patch | Disables phram/slram mappings under kernel lockdown (security hardening). |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0005-mtd-disable-slram-and-phram-when-locked-do.patch | Duplicate alternate-form patch file for phram/slram lockdown behavior. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0006-arm64-add-kernel-config-option-to-lock-down-when-in-.patch | Adds arm64 secure-boot lockdown config/plumbing via FDT params. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/files/6.18/z0007-tools-hv-fix-cross-compilation-for-ARM64.patch | Fixes Hyper-V tools Makefile logic for ARM64 cross builds. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/coreos-modules-6.18.26.ebuild | New modules ebuild for 6.18.26: builds vmlinux+modules and installs minimal build tree. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/commonconfig-6.18 | New shared kernel config fragment for 6.18 (common options). |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/amd64_defconfig-6.18 | New amd64-specific config fragment for 6.18. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-modules/files/arm64_defconfig-6.18 | New arm64-specific config fragment for 6.18. |
| sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-kernel/coreos-kernel-6.18.26.ebuild | New kernel build/install ebuild for 6.18.26 (dracut/bootengine integration). |
Suppressed comments (1)
sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/old-nvidia-drivers-550.163.01-r2.ebuild:167
- Same issue as above:
\bis not a portable/working word-boundary in sed. If this substitution doesn't match,del_timer_sync()won't be renamed and the build will still fail on kernels where it was renamed/removed. Prefer\</\>for word boundaries.
find "${S}" \( -name '*.c' -o -name '*.h' \) \
-exec sed -i 's/\bdel_timer_sync\b/timer_delete_sync/g' {} + || die
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
dongsupark
left a comment
There was a problem hiding this comment.
I think we should run Jenkins CI for all providers, especially for such a big Kernel bump.
| CONFIG_CPU_FREQ_STAT=y | ||
| # CONFIG_CROSS_MEMORY_ATTACH is not set | ||
| CONFIG_CRYPTO_AES=m | ||
| CONFIG_CRYPTO_CRC32C=y |
There was a problem hiding this comment.
Why is the kernel config CRYPTO_CRC32C is needed for building old nvidia drivers?
There was a problem hiding this comment.
Nothing in the kernel depends on this, and nothing enables it by default, as far as I can see. It has something to do with iSCSI.
8c7ac50 to
04c95aa
Compare
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 22 out of 25 changed files in this pull request and generated 3 comments.
Suppressed comments (4)
sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/old-nvidia-drivers-550.163.01-r2.ebuild:162
- The
sedexpression uses\bas a word-boundary, but in GNUsedregex\bis a backspace escape, not a word-boundary. This means the replacement likely never happens and the EXTRA_CFLAGS→ccflags-y migration won’t take effect on 6.15+ builds.
find "${S}" \( -name 'Kbuild' -o -name 'Makefile' \) \
-exec sed -i 's/\bEXTRA_CFLAGS\b/ccflags-y/g' {} + || die
sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/old-nvidia-drivers-550.163.01-r2.ebuild:167
- Same issue here:
\bdel_timer_sync\bwon’t match as a word-boundary in GNUsed(\b is backspace). The rename totimer_delete_synclikely won’t be applied, defeating the intended compatibility fix.
find "${S}" \( -name '*.c' -o -name '*.h' \) \
-exec sed -i 's/\bdel_timer_sync\b/timer_delete_sync/g' {} + || die
sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0002-nvidia-drm-550.163.01-pass-drm_format_info-to-nv_drm.patch:143
- This patch claims to use the conftest symbol (NV_DRM_FB_CREATE_TAKES_FORMAT_INFO) instead of a hardcoded kernel version check, but the function prototype in nvidia-drm-fb.h is guarded by
LINUX_VERSION_CODE >= 6.17. That can desync the prototype from the call sites guarded bydefined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO)(e.g. with backports), causing build failures.
+#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 17, 0)
+ const struct drm_format_info *info,
+#endif
sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0002-nvidia-drm-550.163.01-pass-drm_format_info-to-nv_drm.patch:263
- Same conftest-vs-version mismatch in the non-open
kernel/nvidia-drm/nvidia-drm-fb.hhunk: the prototype is guarded byLINUX_VERSION_CODE >= 6.17, while the rest of the patch usesdefined(NV_DRM_FB_CREATE_TAKES_FORMAT_INFO). These need to use the same condition to avoid signature mismatches on backports/custom kernels.
+#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 17, 0)
+ const struct drm_format_info *info,
+#endif
04c95aa to
431311e
Compare
431311e to
919f146
Compare
919f146 to
c8c1a8b
Compare
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 23 out of 26 changed files in this pull request and generated no new comments.
Suppressed comments (4)
sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/old-nvidia-drivers-550.163.01-r2.ebuild:167
- The del_timer_sync -> timer_delete_sync rewrite is applied unconditionally. That will break builds against kernels where timer_delete_sync() doesn't exist (older than the rename), even though this ebuild doesn't set a minimum supported kernel. Gate the rewrite on the target kernel version so older kernels keep del_timer_sync().
# Linux 6.15 renamed del_timer_sync() to timer_delete_sync() (commit
# d4b4c87). NVIDIA 550 calls del_timer_sync in nv.c and nv-nano-timer.c.
find "${S}" \( -name '*.c' -o -name '*.h' \) \
-exec sed -i 's/\bdel_timer_sync\b/timer_delete_sync/g' {} + || die
sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0002-nvidia-drm-550.163.01-pass-drm_format_info-to-nv_drm.patch:143
- This patch introduces NV_DRM_FB_CREATE_TAKES_FORMAT_INFO as a conftest-based feature probe, but the nvidia-drm-fb.h prototype is guarded by a hardcoded LINUX_VERSION_CODE check. That can cause prototype/definition mismatches on backported kernels where the conftest macro is defined but the version check is false. Guard the prototype with the same conftest macro used everywhere else in this patch.
+#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 17, 0)
+ const struct drm_format_info *info,
+#endif
sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0002-nvidia-drm-550.163.01-pass-drm_format_info-to-nv_drm.patch:263
- Same issue as above: the proprietary-tree nvidia-drm-fb.h prototype uses a LINUX_VERSION_CODE guard, but the rest of the patch uses the conftest macro. This can break on backports/non-standard versioning. Use NV_DRM_FB_CREATE_TAKES_FORMAT_INFO for the prototype guard.
+#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 17, 0)
+ const struct drm_format_info *info,
+#endif
sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/coreos-sources-6.18.45.ebuild:45
- There are duplicate 6.18 patch variants in files/6.18 (e.g. z0003-efi-add-..., z0004-efi-lock-down-..., z0005-mtd-disable-...) that are not listed in UNIPATCH_LIST, so they won't be applied by this ebuild. Keeping unused duplicate patches is confusing and makes it harder to tell what actually ships; either delete the unused variants or switch UNIPATCH_LIST to reference them.
UNIPATCH_LIST="
${PATCH_DIR}/z0001-pahole-support-reproducible-builds.patch \
${PATCH_DIR}/z0002-Revert-x86-boot-Remove-the-bugger-off-message.patch \
${PATCH_DIR}/z0003-efi-Add-an-EFI_SECURE_BOOT-flag-to-indicate-secure-b.patch \
${PATCH_DIR}/z0004-efi-Lock-down-the-kernel-if-booted-in-secure-boot-mo.patch \
${PATCH_DIR}/z0005-mtd-phram-slram-Disable-when-the-kernel-is-locked-do.patch \
${PATCH_DIR}/z0006-arm64-add-kernel-config-option-to-lock-down-when-in-.patch \
${PATCH_DIR}/z0007-tools-hv-fix-cross-compilation.patch \
"
| CONFIG_HW_RANDOM_TIMERIOMEM=m | ||
| CONFIG_HW_RANDOM_VIRTIO=y | ||
| CONFIG_HYPERV=m | ||
| CONFIG_HYPERV=y |
There was a problem hiding this comment.
Does this have a reason to be enabled? asking as a curiosity - if this is enabled, why not enable (Y) all of the Hyper-V modules?
We can get rid of this line as well https://github.com/flatcar/bootengine/blob/7727ec78da72e700e8fa1ce2144cb2476448d186/dracut/53ignition/module-setup.sh#L173.
There was a problem hiding this comment.
This is probably a miss from the HyperV debugging I was doing
There was a problem hiding this comment.
Unresolving the converstation.
CONFIG_HYPERV has been changed from tristate to bool - so would require to be enabled
There was a problem hiding this comment.
Fair enough if it has to be y. That doesn't mean the rest has to be built-in though. We shouldn't bloat the core image for one platform unnecessarily.
There was a problem hiding this comment.
🔵 Needs a closer look
There is a confirmed error-handling bug in the new NVIDIA UVM 6.18 compatibility patch (lost PTR_ERR value during unwind) that can return an incorrect error code.
Review details
Suppressed comments (2)
sdk_container/src/third_party/coreos-overlay/x11-drivers/old-nvidia-drivers/files/0006-nvidia-uvm-adapt-to-page_pgmap-and-make_device_excl.patch:159
- In hmm_make_device_exclusive_range(), the error code from make_device_exclusive() is lost: inside the IS_ERR(page) path, the unwind loop overwrites
pagewith previously-acquired pages, soPTR_ERR(page)no longer returns the original error. This will return garbage (and can hide the real failure). Save the error before unwinding and return it.
+ page = make_device_exclusive(mm, addr, &g_uvm_global, &folio);
+ if (IS_ERR(page)) {
+ while (npages) {
+ page = pages[--npages];
+ unlock_page(page);
+ put_page(page);
+ }
+ npages = PTR_ERR(page);
+ break;
sdk_container/src/third_party/coreos-overlay/sys-kernel/coreos-sources/coreos-sources-6.18.45.ebuild:45
- files/6.18 currently contains duplicate patch variants (e.g. both z0003-efi-Add-… and z0003-efi-add-…, similarly for z0004 and z0005), but UNIPATCH_LIST only references one variant of each. Please consider deleting the unused duplicates to avoid ambiguity about which patch set is intended to ship.
UNIPATCH_LIST="
${PATCH_DIR}/z0001-pahole-support-reproducible-builds.patch \
${PATCH_DIR}/z0002-Revert-x86-boot-Remove-the-bugger-off-message.patch \
${PATCH_DIR}/z0003-efi-Add-an-EFI_SECURE_BOOT-flag-to-indicate-secure-b.patch \
${PATCH_DIR}/z0004-efi-Lock-down-the-kernel-if-booted-in-secure-boot-mo.patch \
${PATCH_DIR}/z0005-mtd-phram-slram-Disable-when-the-kernel-is-locked-do.patch \
${PATCH_DIR}/z0006-arm64-add-kernel-config-option-to-lock-down-when-in-.patch \
${PATCH_DIR}/z0007-tools-hv-fix-cross-compilation.patch \
"
- Files reviewed: 24/28 changed files
- Comments generated: 0 new
- Review effort level: Lite
9cbd702 to
c23e4d7
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical NVIDIA proprietary-module compatibility issues and additional cleanup remain unresolved.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 2
Open (8)
Apply UVM fixes to the proprietary module tree · New Add Linux 6.18 fixes to the proprietary module tree · New Retain SVA feature enablement for pre-6.16 kernels · New In the IS_ERR(page) path, the cleanup loop overwritespagewith previously-acquired pages before… The conftest snippet returns the result of page_pgmap(NULL) from a function typed as int.… coreos-modules-6.12.105 installed a/usr/lib/modules/${KV_FULL}/sourcesymlink (tobuild) for… Add changelog entry for Linux 6.18.45 update · New The 6.18 patch directory includes both git-format and quilt-style duplicates of the same patches…
c23e4d7 to
279eb27
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved critical and moderate findings remain in Hyper-V packaging, kernel sources/configuration, and NVIDIA compatibility.
Review effort: Lite
Findings: 2
Open (3)
Resolved since last review (8)
Add Linux 6.18 fixes to the proprietary module tree Apply UVM fixes to the proprietary module tree Retain SVA feature enablement for pre-6.16 kernels In the IS_ERR(page) path, the cleanup loop overwritespagewith previously-acquired pages before… The conftest snippet returns the result of page_pgmap(NULL) from a function typed as int.… coreos-modules-6.12.105 installed a/usr/lib/modules/${KV_FULL}/sourcesymlink (tobuild) for… Add changelog entry for Linux 6.18.45 update The 6.18 patch directory includes both git-format and quilt-style duplicates of the same patches…
| NV_CONFTEST_SYMBOL_COMPILE_TESTS += is_export_symbol_present_follow_pfnmap_start | ||
| NV_CONFTEST_SYMBOL_COMPILE_TESTS += is_export_symbol_gpl_pci_ats_supported | ||
| NV_CONFTEST_SYMBOL_COMPILE_TESTS += ecc_digits_from_bytes | ||
| +NV_CONFTEST_SYMBOL_COMPILE_TESTS += is_export_symbol_present_hrtimer_setup |
| detect_version | ||
| EXTRAVERSION="-flatcar" | ||
|
|
||
| DESCRIPTION="Full sources for the CoreOS Linux kernel" |
There was a problem hiding this comment.
I suspect that guidance is outdated.
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
279eb27 to
d92d33a
Compare
|
LGTM. Historically, this kind of change sometimes had the effect of breaking the hyper-v image by not building all the LIS drivers - need to verify that all drivers are built. |
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
…6.18 Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
…ions CONFIG_CRYPTO_SHA1_SSSE3 and CONFIG_CRYPTO_SHA256_SSSE3 no longer exist in the 6.18 Kconfig tree Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
The 6.18 defconfig was created without CONFIG_FPROBE, which had been enabled on 6.12 (scripts#4281). Some eBPF-based networking tools need it. Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>
Signed-off-by: Sayan Chowdhury <sayan.chowdhury2012@gmail.com>



Testing done
CI: https://jenkins.flatcar.org/job/container/job/packages_all_arches/490/
changelog/directory (user-facing change, bug fix, security fix, update)/bootand/usrsize, packages, list files for any missing binaries, kernel modules, config files, kernel modules, etc.This might help: flatcar/Flatcar#2424