The other downside I see is that it rules out booting other operating systems (at least right now). Other than linux itself (and maybe freebsd?) you can't kexec from a running linux kernel to another OS.
Not sure if this is current, but apparently you can kexec to grub4dos, an on to windows (i assume this won't work for W10 with secure boot enabled, though):
I don't know the details but I recall that using linux as a bootloader was a potential threat the ChromeOS people wanted to block with some patches to the Linux kernel that tied it somehow to secure boot that the kernel maintainers (Linus himself commented on the issue as it was controversial) rejected at the form the patches had at the time.
- the "lockdown" patches you refer to. The goal of those is to maintain the attestation that the running kernel code is the code that was loaded through a signature chain. If you can modify the kernel at runtime, obviously the attestation has to be invalid.
I don't think it's impossible to boot Windows from Linux, but doing so should result in Windows detecting that it's in insecure/unsigned mode.