From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f53.google.com (mail-pj1-f53.google.com [209.85.216.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2847E3F2113 for ; Wed, 19 Aug 2026 10:12:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.53 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787134333; cv=none; b=BXl8GTl/yh87WxPLQM8l2Lj1590KqenOyzmPC7bT8GepkW6j670lU5o0YY5tTYouDbBWeNLynA8hqQa7iY3p1USzjQi8ofhKJ3WOxkvVR8tkhyhf/0eDCokTTe+uoJ1ca0bfvNoUCTMP2zMFse33mgk5LwlEScmUD+K5XxHwC04= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787134333; c=relaxed/simple; bh=TXeYnw1JGM5Q878ZHkPHl/nj6OpI24DUCP7Yg+rMnyE=; h=From:Date:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=Gs5fqJZFEotFutS0wiQQBEBZpaf5khT3a/v63KGJBq4AipVJW/ykznKEXyg2CQMzn8j/NiZLo0e2tQT7RfNio7uonGEDMh9hX+L9PPeila1iY4Adm1GyZNPY3T+MQNx7vJoUxJ6Uvg0XWUjcs9RSJHdTTvDXnjL0Fci0UmIuLaE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Cs2VVDLk; arc=none smtp.client-ip=209.85.216.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Cs2VVDLk" Received: by mail-pj1-f53.google.com with SMTP id 98e67ed59e1d1-3900e39d935so912172a91.0 for ; Wed, 19 Aug 2026 03:12:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787134331; x=1787739131; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:date :from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=ftunS58cBiMcbygydM2prujXSBPcF6lUAvIxlRiSWpU=; b=Cs2VVDLkg40xL6SLAaAs4hUCqtI4NVb1RTj/3IFMjEGKrXjsxkj/9pDaZD9iBc1FEQ ZZS1b3FQSrA2oWc/YBPSZTu2QZ//anAWPGMcoLXtDF+yYgKBBqxJRL4QGkH1EwTYtoeb e4YMQfoFQqRbLyUcJbW7qtPvCT9zYgcTW2CZ1xE752yBM6tXIvI0UnKcPwtW0R3om0Mx GlsdH3TbCJDLJaaiwW+doIMU0LZAuzVjCwSY7GV5AzXuiQuhQp3XNthLa1ua+E7QKjCm 7q93LbLVn80gpMdZ28O8BN3PybWKS752UjNS39Gj2yC5Zw0twZiWoj+IB9XjFm49g268 RPVA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787134331; x=1787739131; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:date :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ftunS58cBiMcbygydM2prujXSBPcF6lUAvIxlRiSWpU=; b=KYFJrEKYh8XLUhE2HChD0h3H6uDVEdrPxS2qykP8E4b4oUI/g8GXCN0++gIqG+oEY5 ZsNy58OAneDTwpZrFBWibRNWiCJ7YyOHkyBnDVEdvI5laGbjUS2c9i0wAbetmRLwVQEi EgnoG9Yp09pAUusVS4yjInlB7RNhG4eBCS7z6GTTxXg7/63rOrdaoheqAwMzkiE0fXCE 0HJ3ZOWDP5fw8cVRFg18cy3X1K5Uoiad7WvsYEB+DmGlOSeLpSgiBZoRgPQAt0cuNJDr lMW1/mIWuFeVzwecbkl+KoqAdpSDktjwGljK/fKzcnqwzPouk+eUjMMuq6e9S0mCQmRn 6OUQ== X-Forwarded-Encrypted: i=1; AHgh+RoRrFxZntsQ45s+8xLSKKNuYwzbvltl0u5FAwNDI3wW+PPb1gX8fnSJXgCuJK2896qGlh82LuaCO6LyE5E=@vger.kernel.org X-Gm-Message-State: AFuF++kMuZiVfQE2WNGRq/o0wA77r4g4Rg7khVcrJ2ygEwTuZm6VuJ3/ kNIIUSQzcyysjIr/CruEZpTLeJTHuHOiDT9EkLJxXFo0LAnkfSAqyKIG X-Gm-Gg: AR+sD113NpoU9/GYWOCwwJoHj2rLod4kEK9YECX0zwzIj3U/JqH4UxsglcrWaEQ1KVZ UBoIbzu90lhyjRwnY3Z8MJTwlCCsOOmjs8trf1r4DFt8mq8qwlJCQP+lTu76NWW2hFDV68SJhME vDx4Wg0F0x+wue4xO3+FAGKZ/vhFHpcHHOeFABAAxhmsfXhPZKJFuNVOW0M1zYyNdSh62phkcL6 nTizYa7KE665jEKHm8qlCM2UFriliOthIrOKDQy/tyO6k+CSS5BtxT6fkcujZBGwJuKO4lA9gud MPYXJBi6VRsCZj1wR6CIy/B4qp5uCfgAeTngRFMXzb0eGxteGbniidh8JUp4ocjGvhuhWlFNyXn 63NDzuWu2Jhd7iCRAbAAqG/LXJfZB6BzCQy1jXE8etqww4LEryTpM4eau3Ah1KwbLUyrAE8uuoQ tlmUFEWHzld0qdH/ygSLTMBiMTeDdACwhQZ3wQ3qqEF4WtOGaJT3DsD6fwlse7lnabQzALzjc= X-Received: by 2002:a17:90a:ec88:b0:38e:5964:97a8 with SMTP id 98e67ed59e1d1-3958128686dmr6708038a91.16.1787134331282; Wed, 19 Aug 2026 03:12:11 -0700 (PDT) Received: from localhost ([2400:ac40:62f:3ae5:75e6:e4f4:4401:4289]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3957fc00b22sm742530a91.3.2026.08.19.03.12.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 19 Aug 2026 03:12:10 -0700 (PDT) From: Coiby Xu X-Google-Original-From: Coiby Xu Date: Wed, 19 Aug 2026 18:08:21 +0800 To: Sourabh Jain Cc: kexec@lists.infradead.org, Andrew Morton , Baoquan He , Dave Young , Pratyush Yadav , Mike Rapoport , Pasha Tatashin , Coiby Xu , open list Subject: Re: [PATCH v3 03/10] crash_dump: Disallow writing to dm-crypt configfs during kexec_file_load syscall Message-ID: References: <20260729033654.311541-1-coiby.xu@gmail.com> <20260729033654.311541-4-coiby.xu@gmail.com> <3010bbe1-844f-4513-9941-f4e92e581769@linux.ibm.com> <91f569f4-c370-49f1-8656-245f35793199@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1; format=flowed Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <91f569f4-c370-49f1-8656-245f35793199@linux.ibm.com> On Sun, Aug 09, 2026 at 05:26:54PM +0530, Sourabh Jain wrote: >Hello Coiby, > >On 06/08/26 10:50, Coiby Xu wrote: >>On Wed, Aug 05, 2026 at 04:00:51PM +0530, Sourabh Jain wrote: >>> >>> >>>On 29/07/26 09:06, Coiby Xu wrote: >>>>If writing to the configfs group happens concurrently during >>>>kexec_file_load syscall, it may lead to the following issues, >>>>  - buffer overflow if dm-crypt keys are added after allocation >>>>  - stale total_keys if dm-crypt keys are removed during iteration >>>>  - keys_header will not be freed if config/crash_dm_crypt_key/reuse is >>>>    set true >>>> >>>>So hold config_keys_subsys.su_mutex for the entire sequence during the >>>>kexec_file_load syscall to ensure a consistent snapshot. >>>> >>>>Fixes: 479e58549b0f ("crash_dump: store dm crypt keys in kdump >>>>reserved memory") >>>>Suggested-by: Sourabh Jain >>>>Signed-off-by: Coiby Xu >>>>--- >>>> kernel/crash_dump_dm_crypt.c | 23 +++++++++++++++++++++-- >>>> 1 file changed, 21 insertions(+), 2 deletions(-) >>>> >>>>diff --git a/kernel/crash_dump_dm_crypt.c >>>>b/kernel/crash_dump_dm_crypt.c >>>>index 4335b6cb1fc4..d2e66c6fe6f3 100644 >>>>--- a/kernel/crash_dump_dm_crypt.c >>>>+++ b/kernel/crash_dump_dm_crypt.c >>>>@@ -293,6 +293,7 @@ static ssize_t config_keys_reuse_show(struct >>>>config_item *item, char *page) >>>> static ssize_t config_keys_reuse_store(struct config_item *item, >>>>                        const char *page, size_t count) >>>> { >>>>+    struct mutex *lock; >>>>     bool val; >>>>     int r; >>>>@@ -302,8 +303,12 @@ static ssize_t >>>>config_keys_reuse_store(struct config_item *item, >>>>         return -EINVAL; >>>>     } >>>>+    lock = &to_config_group(item)->cg_subsys->su_mutex; >>>>+    mutex_lock(lock); >>> >>>Is this lock only protecting against races between key reuse and >>>kexec_file_load(), >> >>The lock here is to protect against races between key reuse and >>kexec_file_load. >> >>>or does it also handle the case where a new key is added during >>>key reuse or >>>kexec_file_load() is running? >> >>For the cases where a key is added/deleted, configfs will automatically >>take care of them because it will acquire mutex lock automatically. >> >>> >>>If it is only intended to protect key reuse versus >>>kexec_file_load(), why can't we use >>>the kexec lock instead? >>> >>>The reason I'm asking is that, in upcoming patches, the key reuse >>>path accesses >>>kexec_crash_image properties and the crash reserved region >>>directly. Doing so >>>without taking the kexec lock (using kexec_trylock()) could lead >>>to race conditions. >> >>After comparing the kexec lock approach with the configfs mutex lock >>approach, I think the latter is a simpler solution because >>1. the kexec lock is non-blocking and we have to repeatedly try until the >>   lock get acquired. So it means user space has to make changes as >>   well. >> >>2. configfs already acquires the mutex lock automatically for >>   creating/deleting configfs items. So if we use configfs mutex lock, >>   it means one less place to use the lock. >> >>In config_keys_reuse_store, kexec_crash_image will be checked before >>accessing its properties and the crash reserved region. Can you >>elaborate on what the race conditions are? Will acquiring the lock >>before accessing kexec_crash_image properties and the crash reserved >>region help protect against these races? >> >>In theory, the kexec lock can be a more robust approach. But considering >>only root can write to the crash dm-crypt keys configfs and load kdump >>image, I'm not sure it's necessary to adopt a bit more complex solution. > >The reuse function accesses the kexec crash image properties and crashkernel >memory without taking the kexec lock. This could lead to race conditions or >other problems. > >Since we need to take the kexec lock anyway, my suggestion is: can we >use the >kexec lock instead of cg_subsys->su_mutex if the purpose of the mutex >is only >to synchronize reuse with kexec_file_load? > >As we know, kexec_file_load already runs under the kexec lock. So using the >same lock should provide the required synchronization. > >- Sourabh Jain After 1) digging into the git history to learn more about what problems may happen without ensuring serial access to the kexec crash image properties and 2) noticing kexec-tools won't retry when kexec_file_load syscall failed with -EBUSY due to kexec lock acquisition failure which implies it's very unlikely to fail to get the kexec lock, I'm convinced it's better to switch to kexec lock for the reuse function. Thanks for the suggestion! -- Best regards, Coiby