Bug 1523275

Summary: After install Fedora 27 failed to open crypted partition
Product: [Fedora] Fedora Reporter: Danilo Marcucci <danilo>
Component: cryptsetupAssignee: Milan Broz <gmazyland>
Status: CLOSED EOL QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: urgent Docs Contact:
Priority: unspecified    
Version: 27CC: agk, gmazyland, okozina
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-11-30 18:38:23 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Danilo Marcucci 2017-12-07 15:12:06 UTC
Description of problem:
I have installed Fedora 27. During installation i have open a cypted partition and mount point to /home. After install Fedora 27 i have reboot the system but Fedora failed to open crypted partition.

Version-Release number of selected component (if applicable):
# cryptsetup --version
cryptsetup 1.7.5

How reproducible:


Steps to Reproduce:
1. cryptsetup luksOpen /dev/sda5 sda5
Enter passphrase for /dev/sda5: 
device-mapper: reload ioctl on sda5  failed: Invalid argument
2. If digit  wrong password
cryptsetup luksOpen /dev/sda5 sda5
Enter passphrase for /dev/sda5: 
No key available with this pass

Actual results:
Enter passphrase for /dev/sda5: 
device-mapper: reload ioctl on sda5  failed: Invalid argument
from dmsg comamnd
[   51.219859] device-mapper: table: 253:0: crypt: unknown target type
[   51.219893] device-mapper: ioctl: error adding target to table
[  106.927667] device-mapper: table: 253:0: crypt: unknown target type
[  106.927702] device-mapper: ioctl: error adding target to table

from journalctl command
Dec 07 15:55:04 localhost.localdomain audit[2386]: CRYPTO_KEY_USER pid=2386 uid=0 auid=0 ses=4 subj=system_u:system_r:ssh
Dec 07 15:55:51 localhost.localdomain kernel: device-mapper: table: 253:0: crypt: unknown target type
Dec 07 15:55:51 localhost.localdomain kernel: device-mapper: ioctl: error adding target to table
Dec 07 15:57:36 localhost.localdomain kernel: device-mapper: table: 253:0: crypt: unknown target type
Dec 07 15:57:36 localhost.localdomain kernel: device-mapper: ioctl: error adding target to table

Expected results:
Open crypted partition

Additional info:
It's partition worked perfectly on Fedora 26

This is the output from fedora 27:
#cryptsetup luksDump /dev/sda5     
LUKS header information for /dev/sda5

Version:        1
Cipher name:    aes
Cipher mode:    xts-plain64
Hash spec:      sha256
Payload offset: 4096
MK bits:        512
MK digest:      b6 be 79 83 e2 fd bc 4d 64 5b df e2 6d 0d 00 ac ea 4d d6 f6 
MK salt:        11 d5 94 bb 4f b2 94 38 06 07 4f 20 17 2d 58 48 
                db a4 40 df 2b 71 a5 9e da 1e eb f6 0b 71 f2 7b 
MK iterations:  47000
UUID:           dc89361b-263f-4ba5-8f80-444e33b001fe

Key Slot 0: ENABLED
        Iterations:             395671
        Salt:                   3e 11 d7 b5 22 5d f5 0e b6 39 9b 37 b6 2b 20 c8 
                                7d fd 44 91 10 90 ea 2d 0a 46 2e 0a 5b eb c1 1a 
        Key material offset:    8
        AF stripes:             4000
Key Slot 1: DISABLED
Key Slot 2: ENABLED
        Iterations:             1494888
        Salt:                   f3 e4 ff b0 6b 09 2d 0b 40 e0 53 b5 34 94 09 ff 
                                6a 4e 2e 60 14 88 f5 13 bf 52 38 63 b7 eb b6 7a 
        Key material offset:    1016
        AF stripes:             4000
Key Slot 3: DISABLED
Key Slot 4: DISABLED
Key Slot 5: DISABLED
Key Slot 6: DISABLED
Key Slot 7: DISABLED

Comment 1 Ondrej Kozina 2017-12-07 15:41:04 UTC
According to dmesg output there's something wrong with kernel modules. What happens when you enter following as root:

modprobe dm-crypt

?

Comment 2 Danilo Marcucci 2017-12-07 16:23:55 UTC
I have found the problem. Anaconda generate grub.cfg with kernel FC26 and label Fedora 27 and used Fedora 27 system.

#tune2fs -l /dev/sda7 | grep -e UUID -e name
Filesystem volume name:   FEDORA27
Filesystem UUID:          975f0abb-5a7a-4a55-baec-7aa92956c81e

# tune2fs -l /dev/sda6 | grep -e UUID -e name
Filesystem volume name:   FEDORA26
Filesystem UUID:          1b8c6b3b-3ca9-474f-8364-49f4d21cd981

menuentry 'Fedora (4.13.13-200.fc26.x86_64) 27 (Workstation Edition)' --class fedora --class gnu-linux --class gnu --class os --unrestricted $menuentry_id_option 'gnulinux-4.13.13-200.fc26.x86_64-advanced-975f0abb-5a7a-4a55-baec-7aa92956c81e' {
	load_video
	set gfxpayload=keep
	insmod gzio
	insmod part_msdos
	insmod ext2
	set root='hd0,msdos3'
	if [ x$feature_platform_search_hint = xy ]; then
	  search --no-floppy --fs-uuid --set=root --hint-bios=hd0,msdos3 --hint-efi=hd0,msdos3 --hint-baremetal=ahci0,msdos3 --hint='hd0,msdos3'  3d2fbccd-1c3d-4731-a95b-4c1585ffa79f
	else
	  search --no-floppy --fs-uuid --set=root 3d2fbccd-1c3d-4731-a95b-4c1585ffa79f
	fi
	linux16 /vmlinuz-4.13.13-200.fc26.x86_64 root=UUID=975f0abb-5a7a-4a55-baec-7aa92956c81e ro rhgb quiet
	initrd16 /initramfs-4.13.13-200.fc26.x86_64.img
}

The correct parameter to start with Fedora 27 are in the 3th rules 
menuentry 'Fedora (4.13.9-300.fc27.x86_64) 27 (Workstation Edition)' --class fedora --class gnu-linux --class gnu --class os --unrestricted $menuentry_id_option 'gnulinux-4.13.9-300.fc27.x86_64-advanced-975f0abb-5a7a-4a55-baec-7aa92956c81e' {
	load_video
	set gfxpayload=keep
	insmod gzio
	insmod part_msdos
	insmod ext2
	set root='hd0,msdos3'
	if [ x$feature_platform_search_hint = xy ]; then
	  search --no-floppy --fs-uuid --set=root --hint-bios=hd0,msdos3 --hint-efi=hd0,msdos3 --hint-baremetal=ahci0,msdos3 --hint='hd0,msdos3'  3d2fbccd-1c3d-4731-a95b-4c1585ffa79f
	else
	  search --no-floppy --fs-uuid --set=root 3d2fbccd-1c3d-4731-a95b-4c1585ffa79f
	fi
	linux16 /vmlinuz-4.13.9-300.fc27.x86_64 root=UUID=975f0abb-5a7a-4a55-baec-7aa92956c81e ro rhgb quiet LANG=it_IT.UTF-8
	initrd16 /initramfs-4.13.9-300.fc27.x86_64.img
}

I have change the UUID in Fedora 26 rules from =975f0abb-5a7a-4a55-baec-7aa92956c81e to 1b8c6b3b-3ca9-474f-8364-49f4d21cd981
Now works perfectly.

Comment 3 Ben Cotton 2018-11-27 17:54:47 UTC
This message is a reminder that Fedora 27 is nearing its end of life.
On 2018-Nov-30  Fedora will stop maintaining and issuing updates for
Fedora 27. It is Fedora's policy to close all bug reports from releases
that are no longer maintained. At that time this bug will be closed as
EOL if it remains open with a Fedora  'version' of '27'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version.

Thank you for reporting this issue and we are sorry that we were not 
able to fix it before Fedora 27 is end of life. If you would still like 
to see this bug fixed and are able to reproduce it against a later version 
of Fedora, you are encouraged  change the 'version' to a later Fedora 
version prior this bug is closed as described in the policy above.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events. Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

Comment 4 Ben Cotton 2018-11-30 18:38:23 UTC
Fedora 27 changed to end-of-life (EOL) status on 2018-11-30. Fedora 27 is
no longer maintained, which means that it will not receive any further
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version. If you
are unable to reopen this bug, please file a new report against the
current release. If you experience problems, please add a comment to this
bug.

Thank you for reporting this bug and we are sorry it could not be fixed.