From: Coiby Xu <coiby.xu@gmail.com>
To: Sourabh Jain <sourabhjain@linux.ibm.com>
Cc: kexec@lists.infradead.org,
Andrew Morton <akpm@linux-foundation.org>,
Baoquan He <baoquan.he@linux.dev>,
Dave Young <ruirui.yang@linux.dev>,
Pratyush Yadav <pratyush@kernel.org>,
Mike Rapoport <rppt@kernel.org>,
Pasha Tatashin <pasha.tatashin@soleen.com>,
Coiby Xu <coxu@redhat.com>,
open list <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH v3 03/10] crash_dump: Disallow writing to dm-crypt configfs during kexec_file_load syscall
Date: Thu, 6 Aug 2026 13:20:58 +0800 [thread overview]
Message-ID: <anQVIaMHXEx8hvep@Rk> (raw)
In-Reply-To: <3010bbe1-844f-4513-9941-f4e92e581769@linux.ibm.com>
On Wed, Aug 05, 2026 at 04:00:51PM +0530, Sourabh Jain wrote:
>
>
>On 29/07/26 09:06, Coiby Xu wrote:
>>If writing to the configfs group happens concurrently during
>>kexec_file_load syscall, it may lead to the following issues,
>> - buffer overflow if dm-crypt keys are added after allocation
>> - stale total_keys if dm-crypt keys are removed during iteration
>> - keys_header will not be freed if config/crash_dm_crypt_key/reuse is
>> set true
>>
>>So hold config_keys_subsys.su_mutex for the entire sequence during the
>>kexec_file_load syscall to ensure a consistent snapshot.
>>
>>Fixes: 479e58549b0f ("crash_dump: store dm crypt keys in kdump reserved memory")
>>Suggested-by: Sourabh Jain <sourabhjain@linux.ibm.com>
>>Signed-off-by: Coiby Xu <coiby.xu@gmail.com>
>>---
>> kernel/crash_dump_dm_crypt.c | 23 +++++++++++++++++++++--
>> 1 file changed, 21 insertions(+), 2 deletions(-)
>>
>>diff --git a/kernel/crash_dump_dm_crypt.c b/kernel/crash_dump_dm_crypt.c
>>index 4335b6cb1fc4..d2e66c6fe6f3 100644
>>--- a/kernel/crash_dump_dm_crypt.c
>>+++ b/kernel/crash_dump_dm_crypt.c
>>@@ -293,6 +293,7 @@ static ssize_t config_keys_reuse_show(struct config_item *item, char *page)
>> static ssize_t config_keys_reuse_store(struct config_item *item,
>> const char *page, size_t count)
>> {
>>+ struct mutex *lock;
>> bool val;
>> int r;
>>@@ -302,8 +303,12 @@ static ssize_t config_keys_reuse_store(struct config_item *item,
>> return -EINVAL;
>> }
>>+ lock = &to_config_group(item)->cg_subsys->su_mutex;
>>+ mutex_lock(lock);
>
>Is this lock only protecting against races between key reuse and
>kexec_file_load(),
The lock here is to protect against races between key reuse and
kexec_file_load.
>or does it also handle the case where a new key is added during key reuse or
>kexec_file_load() is running?
For the cases where a key is added/deleted, configfs will automatically
take care of them because it will acquire mutex lock automatically.
>
>If it is only intended to protect key reuse versus kexec_file_load(),
>why can't we use
>the kexec lock instead?
>
>The reason I'm asking is that, in upcoming patches, the key reuse path
>accesses
>kexec_crash_image properties and the crash reserved region directly.
>Doing so
>without taking the kexec lock (using kexec_trylock()) could lead to
>race conditions.
After comparing the kexec lock approach with the configfs mutex lock
approach, I think the latter is a simpler solution because
1. the kexec lock is non-blocking and we have to repeatedly try until the
lock get acquired. So it means user space has to make changes as
well.
2. configfs already acquires the mutex lock automatically for
creating/deleting configfs items. So if we use configfs mutex lock,
it means one less place to use the lock.
In config_keys_reuse_store, kexec_crash_image will be checked before
accessing its properties and the crash reserved region. Can you
elaborate on what the race conditions are? Will acquiring the lock
before accessing kexec_crash_image properties and the crash reserved
region help protect against these races?
In theory, the kexec lock can be a more robust approach. But considering
only root can write to the crash dm-crypt keys configfs and load kdump
image, I'm not sure it's necessary to adopt a bit more complex solution.
>
>- Sourabh Jain
>>+
>>+ r = -EINVAL;
>> if (kstrtobool(page, &val) || !val)
>>- return -EINVAL;
>>+ goto unlock;
>
>The jump above skips setting count, causing the function to return
>count instead of -EINVAL.
>Is this really intended?
Thanks for catching this issue! In the end of the function, r instead of
count should be returned.
>
>> if (is_dm_key_reused) {
>> pr_info("Already got dm-crypt keys, please continue with kexec_file_load syscall\n");
>>@@ -311,11 +316,15 @@ static ssize_t config_keys_reuse_store(struct config_item *item,
>> r = get_keys_from_kdump_reserved_memory();
>> if (r) {
>> pr_warn("Failed to get dm-crypt keys from reserved memory\n");
>>- return r;
>>+ goto unlock;
>> }
>> is_dm_key_reused = true;
>> }
>>+ r = count;
>>+
>>+unlock:
>>+ mutex_unlock(lock);
>> return count;
>> }
>>@@ -421,6 +430,8 @@ static int build_keys_header(void)
>> return 0;
>> }
>>+static bool mutex_acquired;
>>+
>> int crash_load_dm_crypt_keys(struct kimage *image)
>> {
>> struct kexec_buf kbuf = {
>>@@ -432,6 +443,9 @@ int crash_load_dm_crypt_keys(struct kimage *image)
>> };
>> int r = 0;
>>+ mutex_lock(&config_keys_subsys.su_mutex);
>>+ mutex_acquired = true;
>>+
>> if (key_count <= 0) {
>> kexec_dprintk("No dm-crypt keys\n");
>> return 0;
>>@@ -481,6 +495,11 @@ void kexec_file_post_load_cleanup_dm_crypt(struct kimage *image)
>> kfree_sensitive(keys_header);
>> keys_header = NULL;
>> }
>>+
>>+ if (mutex_acquired) {
>>+ mutex_unlock(&config_keys_subsys.su_mutex);
>>+ mutex_acquired = false;
>>+ }
>> }
>> static int __init configfs_dmcrypt_keys_init(void)
>
--
Best regards,
Coiby
next prev parent reply other threads:[~2026-08-06 5:25 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 3:36 [PATCH v3 00/10] Bug fixes and enhancements for kdump LUKS support Coiby Xu
2026-07-29 3:36 ` [PATCH v3 01/10] crash_dump: release keyring reference at the correct time Coiby Xu
2026-07-29 3:36 ` [PATCH v3 02/10] crash_dump: Fix potential double free and UAF of keys_header Coiby Xu
2026-07-29 3:36 ` [PATCH v3 03/10] crash_dump: Disallow writing to dm-crypt configfs during kexec_file_load syscall Coiby Xu
2026-08-05 10:30 ` Sourabh Jain
2026-08-06 5:20 ` Coiby Xu [this message]
2026-07-29 3:36 ` [PATCH v3 04/10] crash_dump: Read the number of dm-crypt keys from reserved memory Coiby Xu
2026-08-05 11:05 ` Sourabh Jain
2026-08-06 6:20 ` Coiby Xu
2026-07-29 3:36 ` [PATCH v3 05/10] crash_dump: Free temporary dm-crypt keys_header buffer in kdump kernel Coiby Xu
2026-08-05 11:20 ` Sourabh Jain
2026-07-29 3:36 ` [PATCH v3 06/10] crash_dump: Only use kexec_dprintk during the kexec_file_load syscall Coiby Xu
2026-08-05 11:36 ` Sourabh Jain
2026-08-06 5:27 ` Coiby Xu
2026-07-29 3:36 ` [PATCH v3 07/10] crash_dump: Improve readability of config_keys_restore_store Coiby Xu
2026-08-05 11:52 ` Sourabh Jain
2026-08-06 6:26 ` Coiby Xu
2026-07-29 3:36 ` [PATCH v3 08/10] crash_dump: Check the function return codes in restore_dm_crypt_keys_to_thread_keyring Coiby Xu
2026-08-05 12:03 ` Sourabh Jain
2026-07-29 3:36 ` [PATCH v3 09/10] crash_dump: Disallow configfs/crash_dm_crypt_key/reuse if crash hotplug supported Coiby Xu
2026-08-05 12:09 ` Sourabh Jain
2026-08-06 5:33 ` Coiby Xu
2026-07-29 3:36 ` [PATCH v3 10/10] Documentation: kdump: Add arm64 and ppc64le to encrypted dump target support list Coiby Xu
2026-08-05 12:10 ` Sourabh Jain
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=anQVIaMHXEx8hvep@Rk \
--to=coiby.xu@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=baoquan.he@linux.dev \
--cc=coxu@redhat.com \
--cc=kexec@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=pasha.tatashin@soleen.com \
--cc=pratyush@kernel.org \
--cc=rppt@kernel.org \
--cc=ruirui.yang@linux.dev \
--cc=sourabhjain@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox