[PATCH v5 0/9] Bug fixes and enhancements for kdump LUKS support

Coiby Xu coiby.xu at gmail.com
Tue Sep 8 17:36:42 PDT 2026


Hi all,

This patch set brings some stability fixes and improvements to the
recently introduced CONFIG_CRASH_DM_CRYPT feature [1][2] (which is to
support LUKS-encrypted device dump target),
  1. address several memory management issues
  2. fix race conditions like configfs writing happens concurrently with
     kexec_file_load syscall
  3. improve configfs handling
  4. update documentation 

v5
- Changes suggested/inspired by Sourabh
  - Fix mistake of unlocking a not-acquired kexec lock
  - Only acquire mutex lock when is_dm_key_reused=False
    - Patch "crash_dump: Read the number of dm-crypt keys from reserved memory" 
      is now a prerequisite patch for 
      "crash_dump: Disallow writing to dm-crypt configfs during kexec_file_load syscall"
    - Release the configfs mutex lock early in crash_load_dm_crypt_keys
      (previous released at the end of kexec_file_load syscall)
- Address the memory leak issue reported by Jinjie when ARM64 repeatedly
  calls crash_load_dm_crypt_keys and also rename
  kexec_file_post_load_cleanup_dm_crypt to crash_dm_crypt_cleanup for
  readability


v4
- Changes suggested by Sourabh
  - Add missing newlines and show the return code in logs
  - Return return code instead of count in config_keys_reuse_store
  - use kexec_lock instead of mutex lock to ensure serial access to is_dm_key_reused
  - drop helper function crash_hotplug_support
- Add Reviewed-by tags from Sourabh

v3
- Changes suggested by Sourabh
   - more robust check on crash hotplug support
   - use configfs mutex when writing to crash_dm_crypt_keys/restore
   - warn the user when keys have been restored
- Drop patch "crash_dump: Release reference to a keyring at correct
  time" since Guangshuo's version [3] is a more complete fix
- Adjust layout of documentation for crash hotplug support
- Check return codes of the function that
  restore_dm_crypt_keys_to_thread_keyring calls 

v2
 - A different way to address potential double and UAF issues
 - Address several issues [5] scrutinized by Sourabh based on
   Sashiko's review feedback [6] on v1 patch
 - Other improvements like logging fix and doc updates

[1] http://lists.infradead.org/pipermail/kexec/2025-February/031850.html
[2] https://lore.kernel.org/all/20260225060347.718905-1-coxu@redhat.com/
[3] https://lore.kernel.org/all/20260704112509.3717884-1-lgs201920130244@gmail.com
[4] https://git.kernel.org/pub/scm/linux/kernel/git/liveupdate/linux.git/log/?h=kexec-fixes
[5] https://lore.kernel.org/all/972b9a73-d066-4a38-8a4b-fe7d1ba2944b@linux.ibm.com/
[6] https://sashiko.dev/#/patchset/20260403100126.1468200-1-coxu%40redhat.com


Coiby Xu (9):
  crash_dump: Fix potential double free and UAF of keys_header
  crash_dump: Read the number of dm-crypt keys from reserved memory
  crash_dump: Disallow writing to dm-crypt configfs during
    kexec_file_load syscall
  crash_dump: Free temporary dm-crypt keys_header buffer in kdump kernel
  crash_dump: Only use kexec_dprintk during the kexec_file_load syscall
  crash_dump: Improve readability of config_keys_restore_store
  crash_dump: Check the function return codes in
    restore_dm_crypt_keys_to_thread_keyring
  crash_dump: Disallow configfs/crash_dm_crypt_key/reuse if crash
    hotplug supported
  Documentation: kdump: Add arm64 and ppc64le to encrypted dump target
    support list

 Documentation/admin-guide/kdump/kdump.rst |  20 ++-
 arch/arm64/kernel/kexec_image.c           |   1 +
 include/linux/kexec.h                     |   6 +
 kernel/crash_dump_dm_crypt.c              | 171 ++++++++++++++++------
 kernel/kexec_file.c                       |   2 +
 5 files changed, 148 insertions(+), 52 deletions(-)


base-commit: 28924df2a08f440c73991b83028032c901de2ae4
-- 
2.55.0




More information about the linux-arm-kernel mailing list