> Well, the proper solution for the future would be for the kernel to save and restore a random seed using UEFI variables, a similar firmware mechanism or free space in a boot sector or swap partition.
This needs to be invalidated before numbers dependent on the seed are used, else you risk attacks where you get someone to generate the same random numbers on consecutive boots.
In turn, if you crash during bootup at the wrong time, you're left without a seed.
Yes, you need to update the seed immediately after reading it and before using it.
There is no problem with a crash assuming that the seed write mechanism is crash-safe (which is achievable with block storage, but indeed I'm not sure whether firmware is properly designed and implemented).
This needs to be invalidated before numbers dependent on the seed are used, else you risk attacks where you get someone to generate the same random numbers on consecutive boots.
In turn, if you crash during bootup at the wrong time, you're left without a seed.