Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1130720 > unrolled thread

Bug#1027299: cryptsetup: on buster with linux-image-5.10-686-pae aes-xts-plain is not available

Started byŁukasz Stelmach <steelman@post.pl>
First post2022-12-30 00:50 +0100
Last post2022-12-30 17:00 +0100
Articles 4 — 2 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1027299: cryptsetup: on buster with linux-image-5.10-686-pae aes-xts-plain is not available Łukasz Stelmach <steelman@post.pl> - 2022-12-30 00:50 +0100
    Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org> Łukasz Stelmach <steelman@post.pl> - 2022-12-30 14:00 +0100
      Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org> Guilhem Moulin <guilhem@debian.org> - 2022-12-30 14:50 +0100
        Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org> Łukasz Stelmach <steelman@post.pl> - 2022-12-30 17:00 +0100

#1130720 — Bug#1027299: cryptsetup: on buster with linux-image-5.10-686-pae aes-xts-plain is not available

FromŁukasz Stelmach <steelman@post.pl>
Date2022-12-30 00:50 +0100
SubjectBug#1027299: cryptsetup: on buster with linux-image-5.10-686-pae aes-xts-plain is not available
Message-ID<FIaOR-ecMU-7@gated-at.bofh.it>
Package: cryptsetup-initramfs
Version: 2:2.1.0-5+deb10u2
Severity: important
X-Debbugs-Cc: none, Łukasz Stelmach <steelman@post.pl>

Dear Maintainer,

The version of cryptsetup-initramfs in buster is affected by
#959423[1]. Although it works with the default 4.19 kernel[2] it fails with
5.10 which is available from the main suite and NOT from
buster-backports. Installing cryptsetup-initramfs from buster-backports
helps.

IMHO the version of cryptsetup-initramfs in buster or buster-updates
should support 5.10 kernels.

I am upgrading from jessie to bullseye and need 5.10 kernel before the
last upgrade.

[1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=959423
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=959423#10
-- 
Miłego dnia,
Łukasz Stelmach

[toc] | [next] | [standalone]


#1130776 — Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org>

FromŁukasz Stelmach <steelman@post.pl>
Date2022-12-30 14:00 +0100
SubjectBug#1027299: closed by Guilhem Moulin <guilhem@debian.org>
Message-ID<FIn9n-eknY-21@gated-at.bofh.it>
In reply to#1130720

[Multipart message — attachments visible in raw view] — view raw

Guilhem Moulin <guilhem@debian.org> writes:
> On Fri, 30 Dec 2022 at 00:30:32 +0100, Łukasz Stelmach wrote:
>> The version of cryptsetup-initramfs in buster is affected by
>> #959423[1]. Although it works with the default 4.19 kernel[2] it fails with
>> 5.10 which is available from the main suite and NOT from
>> buster-backports.
>
> No, buster, buster-security, buster-backports respectively have linux
> 4.19.249-2, 4.19.269-1, and 5.10.127-2~bpo10+1. Debian doesn't support
> a mix and match between oldstable and stable, so if you install the
> kernel from stable you need to install cryptsetup-initramfs from
> stable as well.
>

The 5.10 kernel is from oldstable.

--8<---------------cut here---------------start------------->8---
$ lsb_release  -a
Distributor ID: Debian
Description:    Debian GNU/Linux 10 (buster)
Release:        10
Codename:       buster
$ apt policy linux-image-5.10-686-pae
linux-image-5.10-686-pae:
  Installed: 5.10.158-2~deb10u1
  Candidate: 5.10.158-2~deb10u1
  Version table:
 *** 5.10.158-2~deb10u1 500
        500 tor://security.debian.org buster/updates/main i386 Packages
        100 /var/lib/dpkg/status
$ apt-cache show linux-image-5.10-686-pae | grep Depends:
Depends: linux-image-5.10.0-0.deb10.20-686-pae (= 5.10.158-2~deb10u1)
$ apt policy linux-image-5.10.0-0.deb10.20-686-pae
linux-image-5.10.0-0.deb10.20-686-pae:
  Installed: 5.10.158-2~deb10u1
  Candidate: 5.10.158-2~deb10u1
  Version table:
 *** 5.10.158-2~deb10u1 500
        500 tor://security.debian.org buster/updates/main i386 Packages
        100 /var/lib/dpkg/status
--8<---------------cut here---------------end--------------->8---

> OTOH mixing buster and buster-backports *is* supported (that's the
> reason why backport exist in the first place), so this bug is valid.
> But unfortunately buster had its final point release last summer and
> IMHO the fix #959423 doesn't qualify for an upload to buster-security,
> so I'm closing this.

I am not familiar with Debian policies but I belive this is a regression
(see below) that deserves a fix. Do reconsider. Or at least a note in
the Release Notes, which I followed.

>> IMHO the version of cryptsetup-initramfs in buster or buster-updates
>> should support 5.10 kernels.
>
> It does with the default MODULES=dep, and arguably does too in most
> situations (these days most systems do support AES-NI,

Bad luck, I am upgrading an old Eee PC 901.

> and this has been the case since the default LUKS cipher mode was
> changed to XTS during the jessie release cycle).  In other situations,
> workarounds include rebuilding the initramfs with MODULES=most, or
> after adding ‘ecb’ to /etc/initramfs-tools/modules, or installing
> cryptsetup-initramfs from buster-backports.

Yes there are workarounds and I've found them, and I won't stay with
buster longer than necessary, but I am reporting a serious IMHO
regression.

1. I upgraded to from stretch to buster with
   linux-image-4.19.0-23-686-pae.
2. I rebooted — successfully. 
2. I installed linux-image-5.10-686-pae from buster/updates (see above).
3. 5.10 didn't boot.

>> I am upgrading from jessie to bullseye and need 5.10 kernel before the
>> last upgrade.
>
> Upgrades are only supported from n to n+1.  A supported upgrade path
> would be to dist-upgrade to stretch first and reboot (into the stretch
> kernel 4.9), then to buster and reboot (into the buster kernel 4.19)
> before finally dist-upgrading to bullseye.  Following that upgrade path
> you shouldn't stumble onto #959423.

I didn't write it explicitly, but I am actually doing n+1. And I #959423
hit me when I tried to boot buster with 5.10 from updates (see above).

-- 
Kind regards,
Łukasz Stelmach

[toc] | [prev] | [next] | [standalone]


#1130790 — Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org>

FromGuilhem Moulin <guilhem@debian.org>
Date2022-12-30 14:50 +0100
SubjectBug#1027299: closed by Guilhem Moulin <guilhem@debian.org>
Message-ID<FInVL-ekUk-7@gated-at.bofh.it>
In reply to#1130776

[Multipart message — attachments visible in raw view] — view raw

On Fri, 30 Dec 2022 at 13:19:10 +0100, Łukasz Stelmach wrote:
> The 5.10 kernel is from oldstable.

Oh, didn't realize Buster had both 4.19 and 5.10.  I stand corrected.
But still the buster kernel is what linux-image-686-pae pulls, namely
4.19 not 5.10.

>> OTOH mixing buster and buster-backports *is* supported (that's the
>> reason why backport exist in the first place), so this bug is valid.
>> But unfortunately buster had its final point release last summer and
>> IMHO the fix #959423 doesn't qualify for an upload to buster-security,
>> so I'm closing this.
>
> I am not familiar with Debian policies but I belive this is a regression
> (see below) that deserves a fix. Do reconsider. Or at least a note in
> the Release Notes, which I followed.

Buster was released in July 2019 and the final point release 10.13 was
released last summer.  buster-proposed-updates is now sealed, and so are
the release notes.

> Yes there are workarounds and I've found them, and I won't stay with
> buster longer than necessary, but I am reporting a serious IMHO
> regression.

While of course not being able to boot is an unfortunate regression, its
scope is very limited (and I guess this is why no one has reported this
during the entire 3y release cycle) so “serious” is debatable: affected
systems are those with 1/ MODULES=dep (not default), 2/ modern cipher
mode on ancient hardware (AES-NI support was already widespread when the
default mode switched to XTS, so very old machines that were upgraded
aren't affected if they were using the pre-2013 defaults), 3/
non-default kernel version.

I'm not arguing it's not a bug, just that there is not much we can do in
oldstable right now.  Should one report a security vulnerability in
Buster's src:cryptsetup I'll remember to cherry-pick that change though.

> 1. I upgraded to from stretch to buster with linux-image-4.19.0-23-686-pae.
> 2. I rebooted — successfully.
> 2. I installed linux-image-5.10-686-pae from buster/updates (see above).
> 3. 5.10 didn't boot.

Is there any reason why you don't let the dependency resolver chose the
kernel for you?  (`apt install linux-image-686-pae` instead of specific
ABIs.)  You would have ended up with 4.9 after dist-upgrading to
stretch, 4.19 after dist-upgrading to buster, and with 5.10 after
dist-upgrading to bullseye.

-- 
Guilhem.

[toc] | [prev] | [next] | [standalone]


#1130809 — Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org>

FromŁukasz Stelmach <steelman@post.pl>
Date2022-12-30 17:00 +0100
SubjectBug#1027299: closed by Guilhem Moulin <guilhem@debian.org>
Message-ID<FIpXz-emd6-1@gated-at.bofh.it>
In reply to#1130790

[Multipart message — attachments visible in raw view] — view raw

Guilhem Moulin <guilhem@debian.org> writes:

> On Fri, 30 Dec 2022 at 13:19:10 +0100, Łukasz Stelmach wrote:
>> Yes there are workarounds and I've found them, and I won't stay with
>> buster longer than necessary, but I am reporting a serious IMHO
>> regression.
>
> While of course not being able to boot is an unfortunate regression,
> its scope is very limited

True (see my story below).

> I'm not arguing it's not a bug, just that there is not much we can do in
> oldstable right now.  Should one report a security vulnerability in
> Buster's src:cryptsetup I'll remember to cherry-pick that change though.

BTW. Do you think it may make sense to raise an issue of inadequate
policy regarding "premature" sealing of Release Notes? How could I do
it?  I mean, I think there should be a section for Known Issuse And How
To Work Around Them, that stays open for situations like this. Or a wiki
page, what's important, is that it exists for every release and is
linked from the RN.

>> 1. I upgraded to from stretch to buster with linux-image-4.19.0-23-686-pae.
>> 2. I rebooted — successfully.
>> 2. I installed linux-image-5.10-686-pae from buster/updates (see above).
>> 3. 5.10 didn't boot.
>
> Is there any reason why you don't let the dependency resolver chose
> the kernel for you?  (`apt install linux-image-686-pae` instead of
> specific ABIs.)  You would have ended up with 4.9 after dist-upgrading
> to stretch, 4.19 after dist-upgrading to buster, and with 5.10 after
> dist-upgrading to bullseye.

Yes, dist-upgrade to bsuter has left me with 4.19 and it was fine. At
this point (before upgrading to bullseye), however, I wanted to upgrade
my SSD, because:

a) 4 GB (root) + 16 GB (/home) is somewhat little for doing upgrades
   (yes, I've bind-mounted /home/apt as /var/cache/apt),

b) I'd like to encrypt the new SSD with xchacha12,aes-adiantum[1]
   (27 MB/s vs aes-xts 17 MB/s) which is available since Linux 5.0.

Hence, I chose to install 5.10 ASAP.

I know, it's a complicated and exceptional story. Let's hope this report
will help those few unfortunate who may follow my path.

[1] https://lore.kernel.org/linux-crypto/20181117012631.23528-1-ebiggers@kernel.org/
-- 
Miłego dnia,
Łukasz Stelmach

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web