Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1130720 > unrolled thread
| Started by | Łukasz Stelmach <steelman@post.pl> |
|---|---|
| First post | 2022-12-30 00:50 +0100 |
| Last post | 2022-12-30 17:00 +0100 |
| Articles | 4 — 2 participants |
Back to article view | Back to linux.debian.bugs.dist
Bug#1027299: cryptsetup: on buster with linux-image-5.10-686-pae aes-xts-plain is not available Łukasz Stelmach <steelman@post.pl> - 2022-12-30 00:50 +0100
Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org> Łukasz Stelmach <steelman@post.pl> - 2022-12-30 14:00 +0100
Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org> Guilhem Moulin <guilhem@debian.org> - 2022-12-30 14:50 +0100
Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org> Łukasz Stelmach <steelman@post.pl> - 2022-12-30 17:00 +0100
| From | Łukasz Stelmach <steelman@post.pl> |
|---|---|
| Date | 2022-12-30 00:50 +0100 |
| Subject | Bug#1027299: cryptsetup: on buster with linux-image-5.10-686-pae aes-xts-plain is not available |
| Message-ID | <FIaOR-ecMU-7@gated-at.bofh.it> |
Package: cryptsetup-initramfs Version: 2:2.1.0-5+deb10u2 Severity: important X-Debbugs-Cc: none, Łukasz Stelmach <steelman@post.pl> Dear Maintainer, The version of cryptsetup-initramfs in buster is affected by #959423[1]. Although it works with the default 4.19 kernel[2] it fails with 5.10 which is available from the main suite and NOT from buster-backports. Installing cryptsetup-initramfs from buster-backports helps. IMHO the version of cryptsetup-initramfs in buster or buster-updates should support 5.10 kernels. I am upgrading from jessie to bullseye and need 5.10 kernel before the last upgrade. [1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=959423 [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=959423#10 -- Miłego dnia, Łukasz Stelmach
[toc] | [next] | [standalone]
| From | Łukasz Stelmach <steelman@post.pl> |
|---|---|
| Date | 2022-12-30 14:00 +0100 |
| Subject | Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org> |
| Message-ID | <FIn9n-eknY-21@gated-at.bofh.it> |
| In reply to | #1130720 |
[Multipart message — attachments visible in raw view] — view raw
Guilhem Moulin <guilhem@debian.org> writes:
> On Fri, 30 Dec 2022 at 00:30:32 +0100, Łukasz Stelmach wrote:
>> The version of cryptsetup-initramfs in buster is affected by
>> #959423[1]. Although it works with the default 4.19 kernel[2] it fails with
>> 5.10 which is available from the main suite and NOT from
>> buster-backports.
>
> No, buster, buster-security, buster-backports respectively have linux
> 4.19.249-2, 4.19.269-1, and 5.10.127-2~bpo10+1. Debian doesn't support
> a mix and match between oldstable and stable, so if you install the
> kernel from stable you need to install cryptsetup-initramfs from
> stable as well.
>
The 5.10 kernel is from oldstable.
--8<---------------cut here---------------start------------->8---
$ lsb_release -a
Distributor ID: Debian
Description: Debian GNU/Linux 10 (buster)
Release: 10
Codename: buster
$ apt policy linux-image-5.10-686-pae
linux-image-5.10-686-pae:
Installed: 5.10.158-2~deb10u1
Candidate: 5.10.158-2~deb10u1
Version table:
*** 5.10.158-2~deb10u1 500
500 tor://security.debian.org buster/updates/main i386 Packages
100 /var/lib/dpkg/status
$ apt-cache show linux-image-5.10-686-pae | grep Depends:
Depends: linux-image-5.10.0-0.deb10.20-686-pae (= 5.10.158-2~deb10u1)
$ apt policy linux-image-5.10.0-0.deb10.20-686-pae
linux-image-5.10.0-0.deb10.20-686-pae:
Installed: 5.10.158-2~deb10u1
Candidate: 5.10.158-2~deb10u1
Version table:
*** 5.10.158-2~deb10u1 500
500 tor://security.debian.org buster/updates/main i386 Packages
100 /var/lib/dpkg/status
--8<---------------cut here---------------end--------------->8---
> OTOH mixing buster and buster-backports *is* supported (that's the
> reason why backport exist in the first place), so this bug is valid.
> But unfortunately buster had its final point release last summer and
> IMHO the fix #959423 doesn't qualify for an upload to buster-security,
> so I'm closing this.
I am not familiar with Debian policies but I belive this is a regression
(see below) that deserves a fix. Do reconsider. Or at least a note in
the Release Notes, which I followed.
>> IMHO the version of cryptsetup-initramfs in buster or buster-updates
>> should support 5.10 kernels.
>
> It does with the default MODULES=dep, and arguably does too in most
> situations (these days most systems do support AES-NI,
Bad luck, I am upgrading an old Eee PC 901.
> and this has been the case since the default LUKS cipher mode was
> changed to XTS during the jessie release cycle). In other situations,
> workarounds include rebuilding the initramfs with MODULES=most, or
> after adding ‘ecb’ to /etc/initramfs-tools/modules, or installing
> cryptsetup-initramfs from buster-backports.
Yes there are workarounds and I've found them, and I won't stay with
buster longer than necessary, but I am reporting a serious IMHO
regression.
1. I upgraded to from stretch to buster with
linux-image-4.19.0-23-686-pae.
2. I rebooted — successfully.
2. I installed linux-image-5.10-686-pae from buster/updates (see above).
3. 5.10 didn't boot.
>> I am upgrading from jessie to bullseye and need 5.10 kernel before the
>> last upgrade.
>
> Upgrades are only supported from n to n+1. A supported upgrade path
> would be to dist-upgrade to stretch first and reboot (into the stretch
> kernel 4.9), then to buster and reboot (into the buster kernel 4.19)
> before finally dist-upgrading to bullseye. Following that upgrade path
> you shouldn't stumble onto #959423.
I didn't write it explicitly, but I am actually doing n+1. And I #959423
hit me when I tried to boot buster with 5.10 from updates (see above).
--
Kind regards,
Łukasz Stelmach
[toc] | [prev] | [next] | [standalone]
| From | Guilhem Moulin <guilhem@debian.org> |
|---|---|
| Date | 2022-12-30 14:50 +0100 |
| Subject | Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org> |
| Message-ID | <FInVL-ekUk-7@gated-at.bofh.it> |
| In reply to | #1130776 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, 30 Dec 2022 at 13:19:10 +0100, Łukasz Stelmach wrote: > The 5.10 kernel is from oldstable. Oh, didn't realize Buster had both 4.19 and 5.10. I stand corrected. But still the buster kernel is what linux-image-686-pae pulls, namely 4.19 not 5.10. >> OTOH mixing buster and buster-backports *is* supported (that's the >> reason why backport exist in the first place), so this bug is valid. >> But unfortunately buster had its final point release last summer and >> IMHO the fix #959423 doesn't qualify for an upload to buster-security, >> so I'm closing this. > > I am not familiar with Debian policies but I belive this is a regression > (see below) that deserves a fix. Do reconsider. Or at least a note in > the Release Notes, which I followed. Buster was released in July 2019 and the final point release 10.13 was released last summer. buster-proposed-updates is now sealed, and so are the release notes. > Yes there are workarounds and I've found them, and I won't stay with > buster longer than necessary, but I am reporting a serious IMHO > regression. While of course not being able to boot is an unfortunate regression, its scope is very limited (and I guess this is why no one has reported this during the entire 3y release cycle) so “serious” is debatable: affected systems are those with 1/ MODULES=dep (not default), 2/ modern cipher mode on ancient hardware (AES-NI support was already widespread when the default mode switched to XTS, so very old machines that were upgraded aren't affected if they were using the pre-2013 defaults), 3/ non-default kernel version. I'm not arguing it's not a bug, just that there is not much we can do in oldstable right now. Should one report a security vulnerability in Buster's src:cryptsetup I'll remember to cherry-pick that change though. > 1. I upgraded to from stretch to buster with linux-image-4.19.0-23-686-pae. > 2. I rebooted — successfully. > 2. I installed linux-image-5.10-686-pae from buster/updates (see above). > 3. 5.10 didn't boot. Is there any reason why you don't let the dependency resolver chose the kernel for you? (`apt install linux-image-686-pae` instead of specific ABIs.) You would have ended up with 4.9 after dist-upgrading to stretch, 4.19 after dist-upgrading to buster, and with 5.10 after dist-upgrading to bullseye. -- Guilhem.
[toc] | [prev] | [next] | [standalone]
| From | Łukasz Stelmach <steelman@post.pl> |
|---|---|
| Date | 2022-12-30 17:00 +0100 |
| Subject | Bug#1027299: closed by Guilhem Moulin <guilhem@debian.org> |
| Message-ID | <FIpXz-emd6-1@gated-at.bofh.it> |
| In reply to | #1130790 |
[Multipart message — attachments visible in raw view] — view raw
Guilhem Moulin <guilhem@debian.org> writes: > On Fri, 30 Dec 2022 at 13:19:10 +0100, Łukasz Stelmach wrote: >> Yes there are workarounds and I've found them, and I won't stay with >> buster longer than necessary, but I am reporting a serious IMHO >> regression. > > While of course not being able to boot is an unfortunate regression, > its scope is very limited True (see my story below). > I'm not arguing it's not a bug, just that there is not much we can do in > oldstable right now. Should one report a security vulnerability in > Buster's src:cryptsetup I'll remember to cherry-pick that change though. BTW. Do you think it may make sense to raise an issue of inadequate policy regarding "premature" sealing of Release Notes? How could I do it? I mean, I think there should be a section for Known Issuse And How To Work Around Them, that stays open for situations like this. Or a wiki page, what's important, is that it exists for every release and is linked from the RN. >> 1. I upgraded to from stretch to buster with linux-image-4.19.0-23-686-pae. >> 2. I rebooted — successfully. >> 2. I installed linux-image-5.10-686-pae from buster/updates (see above). >> 3. 5.10 didn't boot. > > Is there any reason why you don't let the dependency resolver chose > the kernel for you? (`apt install linux-image-686-pae` instead of > specific ABIs.) You would have ended up with 4.9 after dist-upgrading > to stretch, 4.19 after dist-upgrading to buster, and with 5.10 after > dist-upgrading to bullseye. Yes, dist-upgrade to bsuter has left me with 4.19 and it was fine. At this point (before upgrading to bullseye), however, I wanted to upgrade my SSD, because: a) 4 GB (root) + 16 GB (/home) is somewhat little for doing upgrades (yes, I've bind-mounted /home/apt as /var/cache/apt), b) I'd like to encrypt the new SSD with xchacha12,aes-adiantum[1] (27 MB/s vs aes-xts 17 MB/s) which is available since Linux 5.0. Hence, I chose to install 5.10 ASAP. I know, it's a complicated and exceptional story. Let's hope this report will help those few unfortunate who may follow my path. [1] https://lore.kernel.org/linux-crypto/20181117012631.23528-1-ebiggers@kernel.org/ -- Miłego dnia, Łukasz Stelmach
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web