Skip to content

Live Patching and kexec

Updating a running kernel without rebooting

Pages in this section

Page What it covers
Kernel Live Patching KLP, struct klp_patch, ftrace redirection, consistency model
KLP Consistency Model Per-task patch state, stack checking, transition workqueue, forced transitions
Cumulative Patches and Atomic Replace Patch stacking, .replace=true, struct klp_ops, disabling and removing patches
KLP State: Custom Consistency Checks klp_state API, transition callbacks, pre/post patch hooks, cumulative state inheritance
kGraft vs. kpatch History How SUSE's kGraft and Red Hat's kpatch converged into upstream livepatch, and why the consistency model took years to land
kexec kexec_load, machine_kexec, kdump integration, fast reboot
War Stories Stuck transitions, shadow variable leaks, compat syscall misses, old_sympos ambiguity, missing .replace

Quick reference

# Check if live patching is supported
grep CONFIG_LIVEPATCH /boot/config-$(uname -r)
# CONFIG_LIVEPATCH=y

# List active live patches
cat /sys/kernel/livepatch/*/enabled

# Apply a live patch (kernel module)
insmod mypatch.ko
cat /sys/kernel/livepatch/mypatch/enabled
# 1 = enabled (check transition=0 for fully consistent)

# Disable a live patch
echo 0 > /sys/kernel/livepatch/mypatch/enabled

# kexec: load a new kernel
kexec -l /boot/vmlinuz --initrd=/boot/initrd.img --reuse-cmdline

# Execute the loaded kernel (immediate, no POST)
kexec -e