From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-2.1 required=3.0 tests=BAYES_00,DKIM_ADSP_CUSTOM_MED, DKIM_INVALID,DKIM_SIGNED,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,NICE_REPLY_A,SPF_HELO_NONE, SPF_PASS,USER_AGENT_SANE_1 autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id D11CDC433E0 for ; Sun, 31 Jan 2021 17:37:26 +0000 (UTC) Received: from mail.server123.net (mail.server123.net [78.46.64.186]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 30E1064E40 for ; Sun, 31 Jan 2021 17:37:26 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 30E1064E40 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=dm-crypt-bounces@saout.de X-Virus-Scanned: amavisd-new at saout.de Authentication-Results: mail.server123.net (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received-SPF: Pass (mailfrom) identity=mailfrom; client-ip=2a00:1450:4864:20::330; helo=mail-wm1-x330.google.com; envelope-from=gmazyland@gmail.com; receiver= Received: from mail-wm1-x330.google.com (mail-wm1-x330.google.com [IPv6:2a00:1450:4864:20::330]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mail.server123.net (Postfix) with ESMTPS for ; Sun, 31 Jan 2021 18:36:31 +0100 (CET) Received: by mail-wm1-x330.google.com with SMTP id o10so10036050wmc.1 for ; Sun, 31 Jan 2021 09:36:31 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:references:cc:from:message-id:date:user-agent :mime-version:in-reply-to:content-language:content-transfer-encoding; bh=PdfPwTVfptOl+bM6Duv1zzuOtwaSjuu1++9DRTNZtd8=; b=vY3JhlmfA3AHm+jl0cshNxEewBe/YnCE6mrp5/yhbSLPXv3V3t/AnqCY8VW7ze6M2R +Y6srgtkO7toipNjk5OEoeJt12dG0ZoNw+CQtMmedIIiGnF0QSgdzihvbSBL47l5U66m gAuwIZHHnqLJVKVGH3RLfuGEO1MBvTC6qMKk1bpK22kf/nlZZz6XGaQO34A8C7JjDg/o nQLxK9OKWkH3LV12KfQHyfgdgZJ6HNVNEd2XgrhC2V/vahq0fqsRDJny4CLJlie91Kzo jLOCQ5YdDYVoE4qsrU+SURt3NOKMibTRjJtNY67AhOqHJ9gvltwBkdWierOnECd+1yT5 n0Ww== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:cc:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=PdfPwTVfptOl+bM6Duv1zzuOtwaSjuu1++9DRTNZtd8=; b=Kn8givAd/cZuRM03eAajoHHxS0yHOJg6f8m9aldhIT0ulhCzT1iCFPq1kprJfonnzv PBVy4epI5VHfV1KK7o46lxR9A+rjaJ+eTDjXfO0AMPvJO4c/JdmXGlAUx6ALiBZpc/Az kIl447Rc7VK4PxgCQxYNMe8eF1DWiI7aAXXwuTM8p8h5VPOtMw4+/CzUqzXongd9E0ui je7MZprl1cfHye+1Kjcr7XOktLgYpYuqgiIK6Bizdbqq67U1xbzxAUwTUYkcwPxxNuCC yXWE8eT2x+CAcHj9TqfKT/zzsWv2CsAAQV5SeE+V5xcCh61BcgzoG2PM8Erspny4basq wv2w== X-Gm-Message-State: AOAM533CoUmwrCDyRNOI0tqYjIV6L2+G1lrcZZ51tlarySsogJtC3ncj D+Ywa7C8ZFe2H9dpshCHSy1thhF7oOc= X-Google-Smtp-Source: ABdhPJwgHzuKkPiSIRMLvFsRnfyjdIEGHEPEqbSdno/Li+kR//ZTyD9cB/VefiPs3LzlzkFey6uVsw== X-Received: by 2002:a1c:3c0b:: with SMTP id j11mr11783688wma.90.1612114590921; Sun, 31 Jan 2021 09:36:30 -0800 (PST) Received: from [192.168.2.27] (39.35.broadband4.iol.cz. [85.71.35.39]) by smtp.gmail.com with ESMTPSA id g9sm27761305wmh.3.2021.01.31.09.36.30 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 31 Jan 2021 09:36:30 -0800 (PST) To: Maxime Alves References: <20210131164818.GK10286@bung> From: Milan Broz Message-ID: <48d9a462-2531-eb28-3cb2-8f3a515c3e93@gmail.com> Date: Sun, 31 Jan 2021 18:36:29 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.7.0 MIME-Version: 1.0 In-Reply-To: <20210131164818.GK10286@bung> Content-Language: en-US Subject: Re: [dm-crypt] LUKS device failure after Cryptsetup upgrade X-BeenThere: dm-crypt@saout.de X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: dm-crypt@saout.de Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: dm-crypt-bounces@saout.de Sender: "dm-crypt" Hi, We maintain strict backward compatibility, so there should be no problem during any upgrade. But you have apparently corrupted LUKS header here, reading from the debug log: # Invalid stripes count 1 in keyslot 4. LUKS keyslot 4 is invalid. LUKS keyslot 4 is invalid. Non standard keyslots alignment, manual repair required. it seems there is some corruption in metadata area, but because there is some non-standard data alignment, cryptsetup code will *not* repair this automatically. If the corruption is *only* in the unused keyslot metadata, this should be easily recoverable, just automatic repair is not possible. (But if the corruption is in the used keyslot area also, your data is lost!) If you can send me (privately, not to the list) first 4096 bytes from your LUKS device LV (this should contain only metadata, no private keyslot material), I can try to fix it. Use dd (and send me luks.img file): dd if= of=luks.img bs=4096 count=1 iflag=direct In any case, be sure to backup existing LUKS header though! (If not possible through cryptsetup because of invalid header, just dd first 4MB of disk area). Milan On 31/01/2021 17:48, Maxime Alves wrote: > Hi, > > I just upgraded my Gentoo distribution, and now I can't open my Luks-encrypted > LMV volume. I spent almost a year without rebooting/upgrading and don't really > know what could have caused this error. > > Cryptsetup was upgraded from 2.2.1 to 2.3.2, but I did not reboot since it was > version 1.7.5, so maybe I was still using the 1.7.5 through libvirt. > > > Sadly, I did NOT backup before upgrading my Gentoo distro, thinking that there > would be no big problem upgrading my system. The volume was unmounted, and is > used only in a virtual machine ran by libvirt/kvm. I realized the device was > not unlockable when I restarted my hypervisor and my VM. > > I tried to use a SystemRescue iso to open the device, with cryptsetup 1.7.x . I > could repair the volume, but after that impossible to open it with my old > passphrase. > > Thanks for reading, > Maxime > > > Here are some informations I gathered after the advices of some people of > #gentoo. > > > _______________________________________________ > dm-crypt mailing list > dm-crypt@saout.de > https://www.saout.de/mailman/listinfo/dm-crypt > _______________________________________________ dm-crypt mailing list dm-crypt@saout.de https://www.saout.de/mailman/listinfo/dm-crypt