From: sashiko-bot@kernel.org
To: "Petr Mladek" <pmladek@suse.com>,
"Baoquan He" <baoquan.he@linux.dev>,
"Mike Rapoport" <rppt@kernel.org>,
"Andrew Morton" <akpm@linux-foundation.org>,
"Pratyush Yadav" <pratyush@kernel.org>,
"Dave Young" <ruirui.yang@linux.dev>,
"Zack Rusin" <zack.rusin@broadcom.com>,
"Pasha Tatashin" <pasha.tatashin@soleen.com>
Cc: "Kees Cook" <kees@kernel.org>,
linux-doc@vger.kernel.org,
"Shuah Khan" <skhan@linuxfoundation.org>,
"H. Peter Anvin" <hpa@zytor.com>,
"Dave Hansen" <dave.hansen@linux.intel.com>,
linux-kernel@vger.kernel.org,
"Ian Forbes" <ian.forbes@broadcom.com>,
"Borislav Petkov" <bp@alien8.de>,
"Joel Granados" <joel.granados@kernel.org>,
"Brennan Lamoreaux" <brennan.lamoreaux@broadcom.com>,
"Guilherme G. Piccoli" <gpiccoli@igalia.com>,
"Ajay Kaher" <ajay.kaher@broadcom.com>,
"Bo Gan" <bo.gan@broadcom.com>,
virtualization@lists.linux.dev,
"Sergey Senozhatsky" <senozhatsky@chromium.org>,
"Ingo Molnar" <mingo@redhat.com>,
x86@kernel.org, "Michael S. Tsirkin" <mst@redhat.com>,
"Maaz Mombasawala" <maaz.mombasawala@broadcom.com>,
"Alexey Makhalov" <alexey.makhalov@broadcom.com>,
"Thomas Gleixner" <tglx@kernel.org>,
"John Ogness" <john.ogness@linutronix.de>,
"Stephen Brennan" <stephen.s.brennan@oracle.com>,
"Steven Rostedt" <rostedt@goodmis.org>,
"Jonathan Corbet" <corbet@lwn.net>,
"Randy Dunlap" <rdunlap@infradead.org>,
"Michael Kelley" <mhklinux@outlook.com>,
"Eugenio Perez" <eperezma@redhat.com>,
kexec@lists.infradead.org, bcm-kernel-feedback-list@broadcom.com
Subject: Re: [PATCH v2 2/6] crash: Notify pre-kdump callbacks before switching kernels
Date: Mon, 28 Sep 2026 18:08:28 +0000 [thread overview]
Message-ID: <20260928180829.3A3461F000FF@smtp.kernel.org> (raw)
In-Reply-To: <9ef573cdbbf5e659eea16fa23afeaf2488049198.1790014793.git.zack.rusin@broadcom.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] panic: Pre-kdump callbacks always receive NULL message in default config
--
commit 8884313d127ae4b9734baebea7b4ba8dd25b38a5
Author: Zack Rusin <zack.rusin@broadcom.com>
crash: Notify pre-kdump callbacks before switching kernels
Fatal x86 oopses can call crash_kexec() without reaching panic(). Run the
pre-kdump chain from __crash_kexec() as well, after finding a loaded image
under the kexec lock and capturing the original registers.
Link: https://lore.kernel.org/r/aquttpMVKX8e6zGB@pathway.suse.cz
> the shared guard skips callbacks already invoked by panic().
[Severity: Medium]
Is this statement accurate?
During a standard panic-triggered kdump with crash_kexec_post_notifiers=0
(the default configuration), vpanic() calls __crash_kexec(NULL) before it
formats the panic message and calls its own explicit
panic_notify_pre_kdump(buf).
Because __crash_kexec(NULL) runs first, won't the new
panic_notify_pre_kdump(NULL) call consume the once-per-boot atomic guard,
rather than being skipped by it?
> diff --git a/kernel/crash_core.c b/kernel/crash_core.c
> index 2b36aa9fade06..5d9fe9e00f39f 100644
> --- a/kernel/crash_core.c
> +++ b/kernel/crash_core.c
[ ... ]
> @@ -139,6 +140,7 @@ void __noclone __crash_kexec(struct pt_regs *regs)
> struct pt_regs fixed_regs;
>
> crash_setup_regs(&fixed_regs, regs);
> + panic_notify_pre_kdump(NULL);
[Severity: Medium]
Will this cause pre-kdump notifiers to receive a NULL message pointer instead
of the expected panic message?
If a system panic occurs and kexec is configured with the default setting of
crash_kexec_post_notifiers=0, vpanic() triggers __crash_kexec(NULL) before
reaching its own explicit panic_notify_pre_kdump(buf):
kernel/panic.c:vpanic() {
...
if (!_crash_kexec_post_notifiers)
__crash_kexec(NULL);
...
panic_notify_pre_kdump(buf);
}
When this happens, __crash_kexec() will invoke panic_notify_pre_kdump() with
a NULL message pointer. This permanently consumes the once-per-boot guard,
and any callback relying on the documented msg parameter will experience
data loss or potential NULL dereferences, violating the API contract that
promises the panic message during a panic.
> crash_save_vmcoreinfo();
> machine_crash_shutdown(&fixed_regs);
> crash_cma_clear_pending_dma();
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1790014793.git.zack.rusin@broadcom.com?part=2
WARNING: multiple messages have this Message-ID (diff)
From: sashiko-bot@kernel.org
To: "Petr Mladek" <pmladek@suse.com>,
"Baoquan He" <baoquan.he@linux.dev>,
"Mike Rapoport" <rppt@kernel.org>,
"Andrew Morton" <akpm@linux-foundation.org>,
"Pratyush Yadav" <pratyush@kernel.org>,
"Dave Young" <ruirui.yang@linux.dev>,
"Zack Rusin" <zack.rusin@broadcom.com>,
"Pasha Tatashin" <pasha.tatashin@soleen.com>
Cc: Randy Dunlap <rdunlap@infradead.org>,
"Michael S. Tsirkin" <mst@redhat.com>,
Kees Cook <kees@kernel.org>,
kexec@lists.infradead.org,
Dave Hansen <dave.hansen@linux.intel.com>,
Stephen Brennan <stephen.s.brennan@oracle.com>,
Bo Gan <bo.gan@broadcom.com>, "H. Peter Anvin" <hpa@zytor.com>,
Sergey Senozhatsky <senozhatsky@chromium.org>,
Brennan Lamoreaux <brennan.lamoreaux@broadcom.com>,
x86@kernel.org, Joel Granados <joel.granados@kernel.org>,
Alexey Makhalov <alexey.makhalov@broadcom.com>,
Eugenio Perez <eperezma@redhat.com>,
Ingo Molnar <mingo@redhat.com>,
bcm-kernel-feedback-list@broadcom.com,
Ajay Kaher <ajay.kaher@broadcom.com>,
John Ogness <john.ogness@linutronix.de>,
virtualization@lists.linux.dev,
Steven Rostedt <rostedt@goodmis.org>,
Maaz Mombasawala <maaz.mombasawala@broadcom.com>,
Borislav Petkov <bp@alien8.de>,
Shuah Khan <skhan@linuxfoundation.org>,
Michael Kelley <mhklinux@outlook.com>,
Jonathan Corbet <corbet@lwn.net>,
linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org,
Ian Forbes <ian.forbes@broadcom.com>,
Thomas Gleixner <tglx@kernel.org>
Subject: Re: [PATCH v2 2/6] crash: Notify pre-kdump callbacks before switching kernels
Date: Mon, 28 Sep 2026 18:08:28 +0000 [thread overview]
Message-ID: <20260928180829.3A3461F000FF@smtp.kernel.org> (raw)
In-Reply-To: <9ef573cdbbf5e659eea16fa23afeaf2488049198.1790014793.git.zack.rusin@broadcom.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] panic: Pre-kdump callbacks always receive NULL message in default config
--
commit 8884313d127ae4b9734baebea7b4ba8dd25b38a5
Author: Zack Rusin <zack.rusin@broadcom.com>
crash: Notify pre-kdump callbacks before switching kernels
Fatal x86 oopses can call crash_kexec() without reaching panic(). Run the
pre-kdump chain from __crash_kexec() as well, after finding a loaded image
under the kexec lock and capturing the original registers.
Link: https://lore.kernel.org/r/aquttpMVKX8e6zGB@pathway.suse.cz
> the shared guard skips callbacks already invoked by panic().
[Severity: Medium]
Is this statement accurate?
During a standard panic-triggered kdump with crash_kexec_post_notifiers=0
(the default configuration), vpanic() calls __crash_kexec(NULL) before it
formats the panic message and calls its own explicit
panic_notify_pre_kdump(buf).
Because __crash_kexec(NULL) runs first, won't the new
panic_notify_pre_kdump(NULL) call consume the once-per-boot atomic guard,
rather than being skipped by it?
> diff --git a/kernel/crash_core.c b/kernel/crash_core.c
> index 2b36aa9fade06..5d9fe9e00f39f 100644
> --- a/kernel/crash_core.c
> +++ b/kernel/crash_core.c
[ ... ]
> @@ -139,6 +140,7 @@ void __noclone __crash_kexec(struct pt_regs *regs)
> struct pt_regs fixed_regs;
>
> crash_setup_regs(&fixed_regs, regs);
> + panic_notify_pre_kdump(NULL);
[Severity: Medium]
Will this cause pre-kdump notifiers to receive a NULL message pointer instead
of the expected panic message?
If a system panic occurs and kexec is configured with the default setting of
crash_kexec_post_notifiers=0, vpanic() triggers __crash_kexec(NULL) before
reaching its own explicit panic_notify_pre_kdump(buf):
kernel/panic.c:vpanic() {
...
if (!_crash_kexec_post_notifiers)
__crash_kexec(NULL);
...
panic_notify_pre_kdump(buf);
}
When this happens, __crash_kexec() will invoke panic_notify_pre_kdump() with
a NULL message pointer. This permanently consumes the once-per-boot guard,
and any callback relying on the documented msg parameter will experience
data loss or potential NULL dereferences, violating the API contract that
promises the panic message during a panic.
> crash_save_vmcoreinfo();
> machine_crash_shutdown(&fixed_regs);
> crash_cma_clear_pending_dma();
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1790014793.git.zack.rusin@broadcom.com?part=2
next prev parent reply other threads:[~2026-09-28 18:08 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 17:55 [PATCH v2 0/6] panic, x86/vmware: Preserve crash logs before kdump Zack Rusin
2026-09-28 17:55 ` Zack Rusin
2026-09-28 17:55 ` [PATCH v2 1/6] panic: Add a notifier chain for pre-kdump callbacks Zack Rusin
2026-09-28 17:55 ` Zack Rusin
2026-09-28 18:04 ` sashiko-bot
2026-09-28 18:04 ` sashiko-bot
2026-09-28 17:55 ` [PATCH v2 2/6] crash: Notify pre-kdump callbacks before switching kernels Zack Rusin
2026-09-28 17:55 ` Zack Rusin
2026-09-28 18:08 ` sashiko-bot [this message]
2026-09-28 18:08 ` sashiko-bot
2026-09-28 18:40 ` Zack Rusin
2026-09-28 18:40 ` Zack Rusin
2026-09-28 18:40 ` Zack Rusin
2026-09-28 17:55 ` [PATCH v2 3/6] panic: Allow postponing pre-kdump notifiers Zack Rusin
2026-09-28 17:55 ` Zack Rusin
2026-09-28 18:04 ` sashiko-bot
2026-09-28 18:04 ` sashiko-bot
2026-09-28 17:55 ` [PATCH v2 4/6] x86/vmware: Add a bounded pre-kdump log sender Zack Rusin
2026-09-28 17:55 ` Zack Rusin
2026-09-28 18:07 ` sashiko-bot
2026-09-28 18:07 ` sashiko-bot
2026-09-28 17:55 ` [PATCH v2 5/6] x86/vmware: Add the vmware_record_panic_msg sysctl Zack Rusin
2026-09-28 17:55 ` Zack Rusin
2026-09-28 18:06 ` sashiko-bot
2026-09-28 18:06 ` sashiko-bot
2026-09-28 17:55 ` [PATCH v2 6/6] x86/vmware: Report guest crashes after kmsg dumpers Zack Rusin
2026-09-28 17:55 ` Zack Rusin
2026-09-28 18:03 ` sashiko-bot
2026-09-28 18:03 ` sashiko-bot
2026-09-28 20:39 ` [PATCH v2 0/6] panic, x86/vmware: Preserve crash logs before kdump Bradley Morgan
2026-09-28 20:39 ` Bradley Morgan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928180829.3A3461F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=ajay.kaher@broadcom.com \
--cc=akpm@linux-foundation.org \
--cc=alexey.makhalov@broadcom.com \
--cc=baoquan.he@linux.dev \
--cc=bcm-kernel-feedback-list@broadcom.com \
--cc=bo.gan@broadcom.com \
--cc=bp@alien8.de \
--cc=brennan.lamoreaux@broadcom.com \
--cc=corbet@lwn.net \
--cc=dave.hansen@linux.intel.com \
--cc=eperezma@redhat.com \
--cc=gpiccoli@igalia.com \
--cc=hpa@zytor.com \
--cc=ian.forbes@broadcom.com \
--cc=joel.granados@kernel.org \
--cc=john.ogness@linutronix.de \
--cc=kees@kernel.org \
--cc=kexec@lists.infradead.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=maaz.mombasawala@broadcom.com \
--cc=mhklinux@outlook.com \
--cc=mingo@redhat.com \
--cc=mst@redhat.com \
--cc=pasha.tatashin@soleen.com \
--cc=pmladek@suse.com \
--cc=pratyush@kernel.org \
--cc=rdunlap@infradead.org \
--cc=rostedt@goodmis.org \
--cc=rppt@kernel.org \
--cc=ruirui.yang@linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
--cc=senozhatsky@chromium.org \
--cc=skhan@linuxfoundation.org \
--cc=stephen.s.brennan@oracle.com \
--cc=tglx@kernel.org \
--cc=virtualization@lists.linux.dev \
--cc=x86@kernel.org \
--cc=zack.rusin@broadcom.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.