[PATCH v5 0/9] Bug fixes and enhancements for kdump LUKS support
Coiby Xu
coiby.xu at gmail.com
Tue Sep 8 17:36:42 PDT 2026
Hi all,
This patch set brings some stability fixes and improvements to the
recently introduced CONFIG_CRASH_DM_CRYPT feature [1][2] (which is to
support LUKS-encrypted device dump target),
1. address several memory management issues
2. fix race conditions like configfs writing happens concurrently with
kexec_file_load syscall
3. improve configfs handling
4. update documentation
v5
- Changes suggested/inspired by Sourabh
- Fix mistake of unlocking a not-acquired kexec lock
- Only acquire mutex lock when is_dm_key_reused=False
- Patch "crash_dump: Read the number of dm-crypt keys from reserved memory"
is now a prerequisite patch for
"crash_dump: Disallow writing to dm-crypt configfs during kexec_file_load syscall"
- Release the configfs mutex lock early in crash_load_dm_crypt_keys
(previous released at the end of kexec_file_load syscall)
- Address the memory leak issue reported by Jinjie when ARM64 repeatedly
calls crash_load_dm_crypt_keys and also rename
kexec_file_post_load_cleanup_dm_crypt to crash_dm_crypt_cleanup for
readability
v4
- Changes suggested by Sourabh
- Add missing newlines and show the return code in logs
- Return return code instead of count in config_keys_reuse_store
- use kexec_lock instead of mutex lock to ensure serial access to is_dm_key_reused
- drop helper function crash_hotplug_support
- Add Reviewed-by tags from Sourabh
v3
- Changes suggested by Sourabh
- more robust check on crash hotplug support
- use configfs mutex when writing to crash_dm_crypt_keys/restore
- warn the user when keys have been restored
- Drop patch "crash_dump: Release reference to a keyring at correct
time" since Guangshuo's version [3] is a more complete fix
- Adjust layout of documentation for crash hotplug support
- Check return codes of the function that
restore_dm_crypt_keys_to_thread_keyring calls
v2
- A different way to address potential double and UAF issues
- Address several issues [5] scrutinized by Sourabh based on
Sashiko's review feedback [6] on v1 patch
- Other improvements like logging fix and doc updates
[1] http://lists.infradead.org/pipermail/kexec/2025-February/031850.html
[2] https://lore.kernel.org/all/20260225060347.718905-1-coxu@redhat.com/
[3] https://lore.kernel.org/all/20260704112509.3717884-1-lgs201920130244@gmail.com
[4] https://git.kernel.org/pub/scm/linux/kernel/git/liveupdate/linux.git/log/?h=kexec-fixes
[5] https://lore.kernel.org/all/972b9a73-d066-4a38-8a4b-fe7d1ba2944b@linux.ibm.com/
[6] https://sashiko.dev/#/patchset/20260403100126.1468200-1-coxu%40redhat.com
Coiby Xu (9):
crash_dump: Fix potential double free and UAF of keys_header
crash_dump: Read the number of dm-crypt keys from reserved memory
crash_dump: Disallow writing to dm-crypt configfs during
kexec_file_load syscall
crash_dump: Free temporary dm-crypt keys_header buffer in kdump kernel
crash_dump: Only use kexec_dprintk during the kexec_file_load syscall
crash_dump: Improve readability of config_keys_restore_store
crash_dump: Check the function return codes in
restore_dm_crypt_keys_to_thread_keyring
crash_dump: Disallow configfs/crash_dm_crypt_key/reuse if crash
hotplug supported
Documentation: kdump: Add arm64 and ppc64le to encrypted dump target
support list
Documentation/admin-guide/kdump/kdump.rst | 20 ++-
arch/arm64/kernel/kexec_image.c | 1 +
include/linux/kexec.h | 6 +
kernel/crash_dump_dm_crypt.c | 171 ++++++++++++++++------
kernel/kexec_file.c | 2 +
5 files changed, 148 insertions(+), 52 deletions(-)
base-commit: 28924df2a08f440c73991b83028032c901de2ae4
--
2.55.0
More information about the linux-arm-kernel
mailing list