[PATCH v2 00/22] coredump: allow to create sparse coredumps on the coredump socket

From: Christian Brauner

Date: Wed Aug 19 2026 - 19:10:18 EST


A coredump generated via the coredump socket ends up transferring
zeroed data when a mapping contains holes. For a large process that
maps a bunch of data that's wasting a ton of work.

Jacob ran into this and Josef has bitched^wcomplained about this to me
before. I dislike the coredump_filter bit solution in [1] which stops
each PT_LOAD at the last populated page.

The problem is real though. I don't think coredump_filter is where we
need to solve this. That mask says which kinds of memory to include and
it propagates across fork and exec, whereas what is being selected here
is an encoding mechanism.

I also think that the usermodehelper - may it swiftly die - isn't really
salvagable for this and it's not the future anyway. The coredump socket
already has a handshake for stuff like this.

I always had an idea how this would look like but punted on it back
then. So here it is.

A server that raises COREDUMP_RECORDS in coredump_ack->mask doesn't get
the coredump as a plain byte stream but as a sequence of records. Each
one a struct coredump_record_header followed by what it describes. A
data record carries its bytes. If a server also raises COREDUMP_SPARSE,
zero records are sent for unpopulated mappings. They only indicate how
many zero bytes need to be written and do not include data. Reassembling
the records gives back the same coredump. A debugger and everything else
still see an ordinary core file and nothing outside the coredump server
has to learn anything.

Numbers from the selftests, on a kernel built from this series:

- a process with 128 threads: 1424153 bytes on the socket for a
coredump of 1075150848 bytes
- a 256MB mapping with the first and last page touched: 188793 bytes on
the socket for a coredump of 268890112 bytes
- the same 256MB mapping with COREDUMP_RECORDS alone: 271009312 bytes on
the socket, so the record overhead itself is under one percent

The first one is the interesting case. Almost all of it is thread stacks.
All stacks are 8MB reservations that are nearly all holes. And they are
holes in the middle of the dump rather than at the end.

Link: https://lore.kernel.org/all/20260731171336.2255844-1-jalalonde@xxxxxxxx [1]

Signed-off-by: Christian Brauner (Amutable) <brauner@xxxxxxxxxx>
---
Changes in v2:
- Use standard naming aligning with other subsystems.
- Add a termination record to make this really clean.
- Link to v1: https://patch.msgid.link/20260811-work-coredump-sparse-v1-0-cd3e8b1e356d@xxxxxxxxxx

---
Christian Brauner (22):
powerpc/spufs: don't dump more than the note supports
coredump: refuse negative skips
coredump: set the minimum send buffer size
selftests/coredump: discard the right amount after the coredump request
selftests/coredump: collapse the expected request check into the helper
selftests/coredump: add a separate helper header
coredump: pin the protocol struct sizes
coredump: move the negotiated mask into struct coredump_params
coredump: deduplicate the to_skip flush
coredump: make the dump helper return bool
coredump: always chunk writes
coredump: clean up coredump state handling
coredump: add COREDUMP_RECORDS to the coredump socket protocol
coredump: add COREDUMP_SPARSE to the coredump socket protocol
tools: sync coredump.h header
coredump: send the coredump in records if requested
coredump: describe the holes when COREDUMP_SPARSE is negotiated
selftests/coredump: test COREDUMP_RECORDS and COREDUMP_SPARSE
selftests/coredump: hand the record stream to a sink
selftests/coredump: put a hole in the middle of a sparse mapping
selftests/coredump: simulate a blob store
selftests/coredump: show how to inspect the task to decide how the coredump should be sent

arch/powerpc/platforms/cell/spufs/file.c | 18 +-
fs/binfmt_elf.c | 12 +-
fs/binfmt_elf_fdpic.c | 12 +-
fs/coredump.c | 325 ++++--
include/linux/binfmts.h | 3 +-
include/linux/coredump.h | 33 +-
include/uapi/linux/coredump.h | 79 +-
tools/include/uapi/linux/coredump.h | 79 +-
.../coredump/coredump_socket_protocol_test.c | 783 ++++++++++++-
tools/testing/selftests/coredump/coredump_test.h | 31 +-
.../selftests/coredump/coredump_test_helpers.c | 1171 +++++++++++++++++++-
.../selftests/coredump/coredump_test_helpers.h | 53 +
12 files changed, 2399 insertions(+), 200 deletions(-)
---
base-commit: 8d3ae59288f1e7d58d76558a6ee96d533bc5019f
change-id: 20260811-work-coredump-sparse-18177d77b014