Re: [PATCH v2 2/6] crash: Notify pre-kdump callbacks before switching kernels

From: sashiko-bot

Date: Mon Sep 28 2026 - 14:08:40 EST


Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] panic: Pre-kdump callbacks always receive NULL message in default config
--

commit 8884313d127ae4b9734baebea7b4ba8dd25b38a5
Author: Zack Rusin <zack.rusin@xxxxxxxxxxxx>

crash: Notify pre-kdump callbacks before switching kernels

Fatal x86 oopses can call crash_kexec() without reaching panic(). Run the
pre-kdump chain from __crash_kexec() as well, after finding a loaded image
under the kexec lock and capturing the original registers.

Link: https://lore.kernel.org/r/aquttpMVKX8e6zGB@xxxxxxxxxxxxxxx

> the shared guard skips callbacks already invoked by panic().

[Severity: Medium]
Is this statement accurate?

During a standard panic-triggered kdump with crash_kexec_post_notifiers=0
(the default configuration), vpanic() calls __crash_kexec(NULL) before it
formats the panic message and calls its own explicit
panic_notify_pre_kdump(buf).

Because __crash_kexec(NULL) runs first, won't the new
panic_notify_pre_kdump(NULL) call consume the once-per-boot atomic guard,
rather than being skipped by it?

> diff --git a/kernel/crash_core.c b/kernel/crash_core.c
> index 2b36aa9fade06..5d9fe9e00f39f 100644
> --- a/kernel/crash_core.c
> +++ b/kernel/crash_core.c
[ ... ]
> @@ -139,6 +140,7 @@ void __noclone __crash_kexec(struct pt_regs *regs)
> struct pt_regs fixed_regs;
>
> crash_setup_regs(&fixed_regs, regs);
> + panic_notify_pre_kdump(NULL);

[Severity: Medium]
Will this cause pre-kdump notifiers to receive a NULL message pointer instead
of the expected panic message?

If a system panic occurs and kexec is configured with the default setting of
crash_kexec_post_notifiers=0, vpanic() triggers __crash_kexec(NULL) before
reaching its own explicit panic_notify_pre_kdump(buf):

kernel/panic.c:vpanic() {
...
if (!_crash_kexec_post_notifiers)
__crash_kexec(NULL);
...
panic_notify_pre_kdump(buf);
}

When this happens, __crash_kexec() will invoke panic_notify_pre_kdump() with
a NULL message pointer. This permanently consumes the once-per-boot guard,
and any callback relying on the documented msg parameter will experience
data loss or potential NULL dereferences, violating the API contract that
promises the panic message during a panic.

> crash_save_vmcoreinfo();
> machine_crash_shutdown(&fixed_regs);
> crash_cma_clear_pending_dma();

--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1790014793.git.zack.rusin@xxxxxxxxxxxx?part=2