[syzbot] [jffs2?] WARNING: bad unlock balance in jffs2_do_create
syzbot <[email protected]>
| Newsgroups | gmane.linux.kernel,gmane.linux.drivers.mtd |
|---|---|
| Message-ID | <[email protected]> |
Hello, syzbot found the following issue on: HEAD commit: 2f1baf1fc892 Merge tag 'trace-v7.2-rc7' of git://git.kerne.. git tree: upstream console output: https://syzkaller.appspot.com/x/log.txt?x=13d46279580000 kernel config: https://syzkaller.appspot.com/x/.config?x=ead6a6de2292ff28 dashboard link: https://syzkaller.appspot.com/bug?extid=250fde257a3eebba4426 compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8 Unfortunately, I don't have any reproducer for this issue yet. Downloadable assets: disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-2f1baf1f.raw.xz vmlinux: https://storage.googleapis.com/syzbot-assets/3cf4d3de19da/vmlinux-2f1baf1f.xz kernel image: https://storage.googleapis.com/syzbot-assets/2c309c87fcb0/bzImage-2f1baf1f.xz IMPORTANT: if you fix the issue, please add the following tag to the commit: Reported-by: [email protected] Zero length message leads to an empty skb jffs2: notice: (5313) jffs2_build_xattr_subsystem: complete building xattr subsystem, 0 of xdatum (0 unchecked, 0 orphan) and 0 of xref (0 dead, 0 orphan) found. overlayfs: upper fs does not support tmpfile. FAULT_INJECTION: forcing a failure. name failslab, interval 1, probability 0, space 0, times 1 CPU: 0 UID: 0 PID: 5313 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120 fail_dump lib/fault-inject.c:73 [inline] should_fail_ex+0x40c/0x560 lib/fault-inject.c:174 should_failslab+0xa8/0x100 mm/failslab.c:46 slab_pre_alloc_hook mm/slub.c:4539 [inline] slab_alloc_node mm/slub.c:4897 [inline] __kmalloc_cache_noprof+0xa8/0x660 mm/slub.c:5485 _kmalloc_noprof include/linux/slab.h:988 [inline] jffs2_sum_add_kvec+0x858/0x1870 fs/jffs2/summary.c:266 jffs2_flash_direct_writev+0xaa/0xe0 fs/jffs2/writev.c:22 jffs2_flash_writev+0x156/0x1550 fs/jffs2/wbuf.c:805 jffs2_write_dnode+0x485/0xe20 fs/jffs2/write.c:109 jffs2_do_create+0x18e/0xe00 fs/jffs2/write.c:465 jffs2_create+0x1c8/0x320 fs/jffs2/dir.c:205 vfs_create+0x2c4/0x450 fs/namei.c:4202 ovl_do_create+0x81/0xf0 fs/overlayfs/overlayfs.h:244 ovl_create_real+0x1a8/0x740 fs/overlayfs/dir.c:180 ovl_create_temp+0x169/0x240 fs/overlayfs/dir.c:267 ovl_check_rename_whiteout fs/overlayfs/super.c:575 [inline] ovl_make_workdir fs/overlayfs/super.c:713 [inline] ovl_get_workdir fs/overlayfs/super.c:836 [inline] ovl_fill_super_creds fs/overlayfs/super.c:1449 [inline] ovl_fill_super+0x3c9b/0x5d40 fs/overlayfs/super.c:1560 vfs_get_super fs/super.c:1273 [inline] get_tree_nodev+0xbb/0x150 fs/super.c:1292 vfs_get_tree+0x92/0x2a0 fs/super.c:1700 fc_mount fs/namespace.c:1198 [inline] do_new_mount_fc fs/namespace.c:3765 [inline] do_new_mount+0x319/0xdc0 fs/namespace.c:3841 do_mount fs/namespace.c:4174 [inline] __do_sys_mount fs/namespace.c:4390 [inline] __se_sys_mount+0x31d/0x420 fs/namespace.c:4367 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fe775d9e0d9 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007fe776d50fe8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5 RAX: ffffffffffffffda RBX: 00007fe776025fa0 RCX: 00007fe775d9e0d9 RDX: 0000200000000b80 RSI: 0000200000000100 RDI: 0000000000000000 RBP: 00007fe776d51050 R08: 0000200000000240 R09: 0000000000000000 R10: 0000000000000008 R11: 0000000000000246 R12: 0000000000000002 R13: 00007fe776026038 R14: 00007fe776025fa0 R15: 00007ffdf4560bd8 </TASK> jffs2: warning: (5313) jffs2_sum_add_kvec: MEMORY ALLOCATION ERROR! jffs2: Write of 68 bytes at 0x0001e218 failed. returned -12, retlen 0 jffs2: Not marking the space at 0x0001e218 as dirty because the flash driver returned retlen zero ===================================== WARNING: bad unlock balance detected! syzkaller #0 Not tainted ------------------------------------- syz.0.0/5313 is trying to release lock (&c->alloc_sem) at: [<ffffffff833a6ebe>] jffs2_do_create+0x1ae/0xe00 fs/jffs2/write.c:474 but there are no more locks to release! other info that might help us debug this: 3 locks held by syz.0.0/5313: #0: ffff8880424140d8 (&type->s_umount_key#52/1){+.+.}-{4:4}, at: alloc_super fs/super.c:345 [inline] #0: ffff8880424140d8 (&type->s_umount_key#52/1){+.+.}-{4:4}, at: sget_fc+0x938/0x1900 fs/super.c:766 #1: ffff888012c72450 (sb_writers#12){.+.+}-{0:0}, at: mnt_want_write+0x41/0x90 fs/namespace.c:494 #2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: inode_lock_nested include/linux/fs.h:1069 [inline] #2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: __start_dirop fs/namei.c:2918 [inline] #2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: start_dirop fs/namei.c:2942 [inline] #2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: start_creating+0xbe/0x100 fs/namei.c:3406 stack backtrace: CPU: 0 UID: 0 PID: 5313 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120 print_unlock_imbalance_bug+0xdc/0xf0 kernel/locking/lockdep.c:5298 __lock_release kernel/locking/lockdep.c:5537 [inline] lock_release+0x248/0x3c0 kernel/locking/lockdep.c:5889 __mutex_unlock_slowpath+0x88/0x900 kernel/locking/mutex.c:989 jffs2_do_create+0x1ae/0xe00 fs/jffs2/write.c:474 jffs2_create+0x1c8/0x320 fs/jffs2/dir.c:205 vfs_create+0x2c4/0x450 fs/namei.c:4202 ovl_do_create+0x81/0xf0 fs/overlayfs/overlayfs.h:244 ovl_create_real+0x1a8/0x740 fs/overlayfs/dir.c:180 ovl_create_temp+0x169/0x240 fs/overlayfs/dir.c:267 ovl_check_rename_whiteout fs/overlayfs/super.c:575 [inline] ovl_make_workdir fs/overlayfs/super.c:713 [inline] ovl_get_workdir fs/overlayfs/super.c:836 [inline] ovl_fill_super_creds fs/overlayfs/super.c:1449 [inline] ovl_fill_super+0x3c9b/0x5d40 fs/overlayfs/super.c:1560 vfs_get_super fs/super.c:1273 [inline] get_tree_nodev+0xbb/0x150 fs/super.c:1292 vfs_get_tree+0x92/0x2a0 fs/super.c:1700 fc_mount fs/namespace.c:1198 [inline] do_new_mount_fc fs/namespace.c:3765 [inline] do_new_mount+0x319/0xdc0 fs/namespace.c:3841 do_mount fs/namespace.c:4174 [inline] __do_sys_mount fs/namespace.c:4390 [inline] __se_sys_mount+0x31d/0x420 fs/namespace.c:4367 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fe775d9e0d9 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007fe776d50fe8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5 RAX: ffffffffffffffda RBX: 00007fe776025fa0 RCX: 00007fe775d9e0d9 RDX: 0000200000000b80 RSI: 0000200000000100 RDI: 0000000000000000 RBP: 00007fe776d51050 R08: 0000200000000240 R09: 0000000000000000 R10: 0000000000000008 R11: 0000000000000246 R12: 0000000000000002 R13: 00007fe776026038 R14: 00007fe776025fa0 R15: 00007ffdf4560bd8 </TASK> --- This report is generated by a bot. It may contain errors. See https://goo.gl/tpsmEJ for more information about syzbot. syzbot engineers can be reached at [email protected]. syzbot will keep track of this issue. See: https://goo.gl/tpsmEJ#status for how to communicate with syzbot. If the report is already addressed, let syzbot know by replying with: #syz fix: exact-commit-title If you want to overwrite report's subsystems, reply with: #syz set subsystems: new-subsystem (See the list of subsystem names on the web dashboard) If the report is a duplicate of another one, reply with: #syz dup: exact-subject-of-another-report If you want to undo deduplication, reply with: #syz undup