Subject: Re: dm-integrity resume vs remove / notifier UAF

Hi Mikulas,

Thanks for the suggested fix. We verified it on Linux 6.6.144 with KASAN
against our minimized PoC (resume racing remove / reboot-notifier UAF).

  if (!dm_suspended_md(md) || test_bit(DMF_FREEING, &md->flags))
          goto out;

Results:
  - unpatched: KASAN slab-use-after-free in notifier_chain_register via
    dm_integrity_resume within ~20s
  - with your change: no KASAN UAF for a 5-minute PoC window

Self-contained test package (patch + poc.c + A/B scripts + captured logs):

  dm-integrity-dm-resume-fix-test.tar.gz

Re-run with Docker (see README.md inside the tarball):

  docker build -t dm-integrity-patch-test -f Dockerfile .
  mkdir -p artifacts
  docker run --rm --privileged --device=/dev/kvm --network=host \
    -v "$PWD/artifacts:/artifacts" -e OUTPUT_DIR=/artifacts \
    dm-integrity-patch-test

Happy to test follow-ups if you prefer a different form of the check.

Thanks,
