[PATCH v2 5/6] x86/vmware: Add the vmware_record_panic_msg sysctl
From: Zack Rusin
Date: Mon Sep 28 2026 - 14:27:54 EST
Allow administrators to disable host log transfer on ordinary guests or
opt in on encrypted guests. Expose the boolean recording policy through
kernel.vmware_record_panic_msg using proc_dobool(), as Joel suggested.
Zero disables recording, nonzero integers enable it, and reads return
0 or 1.
Register the sysctl only after the logger is ready. A registration failure
leaves the internal default in force. Document that disabling the old
post-notifier ordering does not disable this independent logger.
Link: https://lore.kernel.org/r/4e73yd2ofpdzl6rptzvd74no3hnyfblknoq7wzxlw7f3zjbz7c@srfabx6lsusj
Signed-off-by: Zack Rusin <zack.rusin@xxxxxxxxxxxx>
---
v2: use bool/proc_dobool as Joel requested; document direct crash entry.
Maaz's v1 Reviewed-by is omitted for renewed review of the changed sysctl.
Documentation/admin-guide/sysctl/kernel.rst | 20 ++++++++++++++++++++
arch/x86/kernel/cpu/vmware.c | 15 +++++++++++++++
2 files changed, 35 insertions(+)
diff --git a/Documentation/admin-guide/sysctl/kernel.rst b/Documentation/admin-guide/sysctl/kernel.rst
index ffea61d448eb..be13c143b8bb 100644
--- a/Documentation/admin-guide/sysctl/kernel.rst
+++ b/Documentation/admin-guide/sysctl/kernel.rst
@@ -1690,6 +1690,26 @@ entry will default to 2 instead of 0.
= =============================================================
+vmware_record_panic_msg
+======================
+
+Controls whether panic or fatal-oops kmsg data is written to the host's
+``vmware.log`` before kdump. This setting does not control the separate
+VMware guest-crash event. Writing zero disables recording; writing a
+nonzero integer enables it. Reads return 0 or 1.
+
+= ==============================================================
+0 Do not write kmsg data to ``vmware.log``. This is the default
+ for encrypted guests.
+1 Write kmsg data to ``vmware.log``. This is the default for
+ ordinary guests.
+= ==============================================================
+
+``crash_kexec_post_notifiers=0`` alone does not disable this logger.
+``panic_pre_kdump_postpone=1`` skips early logging but leaves late panic
+logging eligible; set this sysctl to 0 to disable both.
+
+
warn_limit
==========
diff --git a/arch/x86/kernel/cpu/vmware.c b/arch/x86/kernel/cpu/vmware.c
index ccf8dc84b30e..4b0e5b084c2c 100644
--- a/arch/x86/kernel/cpu/vmware.c
+++ b/arch/x86/kernel/cpu/vmware.c
@@ -33,6 +33,7 @@
#include <linux/reboot.h>
#include <linux/sizes.h>
#include <linux/static_call.h>
+#include <linux/sysctl.h>
#include <linux/wordpart.h>
#include <linux/sched/cputime.h>
#include <asm/div64.h>
@@ -260,6 +261,16 @@ static int vmware_log_rpc(const char *buffer, size_t length)
static struct page *vmware_panic_page;
static bool vmware_record_panic_msg;
+static const struct ctl_table vmware_panic_sysctls[] = {
+ {
+ .procname = "vmware_record_panic_msg",
+ .data = &vmware_record_panic_msg,
+ .maxlen = sizeof(vmware_record_panic_msg),
+ .mode = 0644,
+ .proc_handler = proc_dobool,
+ },
+};
+
static int vmware_panic_log_notify(struct notifier_block *nb,
unsigned long action, void *data)
{
@@ -311,6 +322,10 @@ static int __init vmware_panic_log_init(void)
vmware_panic_page = NULL;
}
+ if (vmware_panic_page && IS_ENABLED(CONFIG_SYSCTL) &&
+ !register_sysctl("kernel", vmware_panic_sysctls))
+ pr_err("failed to register panic log sysctl\n");
+
return 0;
}
early_initcall(vmware_panic_log_init);