[syzbot] [jffs2?] WARNING: bad unlock balance in jffs2_do_create

syzbot <[email protected]>
Newsgroups gmane.linux.kernel,gmane.linux.drivers.mtd
Message-ID <[email protected]>
Hello,

syzbot found the following issue on:

HEAD commit:    2f1baf1fc892 Merge tag 'trace-v7.2-rc7' of git://git.kerne..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=13d46279580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=ead6a6de2292ff28
dashboard link: https://syzkaller.appspot.com/bug?extid=250fde257a3eebba4426
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-2f1baf1f.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/3cf4d3de19da/vmlinux-2f1baf1f.xz
kernel image: https://storage.googleapis.com/syzbot-assets/2c309c87fcb0/bzImage-2f1baf1f.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

Zero length message leads to an empty skb
jffs2: notice: (5313) jffs2_build_xattr_subsystem: complete building xattr subsystem, 0 of xdatum (0 unchecked, 0 orphan) and 0 of xref (0 dead, 0 orphan) found.
overlayfs: upper fs does not support tmpfile.
FAULT_INJECTION: forcing a failure.
name failslab, interval 1, probability 0, space 0, times 1
CPU: 0 UID: 0 PID: 5313 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
 <TASK>
 dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
 fail_dump lib/fault-inject.c:73 [inline]
 should_fail_ex+0x40c/0x560 lib/fault-inject.c:174
 should_failslab+0xa8/0x100 mm/failslab.c:46
 slab_pre_alloc_hook mm/slub.c:4539 [inline]
 slab_alloc_node mm/slub.c:4897 [inline]
 __kmalloc_cache_noprof+0xa8/0x660 mm/slub.c:5485
 _kmalloc_noprof include/linux/slab.h:988 [inline]
 jffs2_sum_add_kvec+0x858/0x1870 fs/jffs2/summary.c:266
 jffs2_flash_direct_writev+0xaa/0xe0 fs/jffs2/writev.c:22
 jffs2_flash_writev+0x156/0x1550 fs/jffs2/wbuf.c:805
 jffs2_write_dnode+0x485/0xe20 fs/jffs2/write.c:109
 jffs2_do_create+0x18e/0xe00 fs/jffs2/write.c:465
 jffs2_create+0x1c8/0x320 fs/jffs2/dir.c:205
 vfs_create+0x2c4/0x450 fs/namei.c:4202
 ovl_do_create+0x81/0xf0 fs/overlayfs/overlayfs.h:244
 ovl_create_real+0x1a8/0x740 fs/overlayfs/dir.c:180
 ovl_create_temp+0x169/0x240 fs/overlayfs/dir.c:267
 ovl_check_rename_whiteout fs/overlayfs/super.c:575 [inline]
 ovl_make_workdir fs/overlayfs/super.c:713 [inline]
 ovl_get_workdir fs/overlayfs/super.c:836 [inline]
 ovl_fill_super_creds fs/overlayfs/super.c:1449 [inline]
 ovl_fill_super+0x3c9b/0x5d40 fs/overlayfs/super.c:1560
 vfs_get_super fs/super.c:1273 [inline]
 get_tree_nodev+0xbb/0x150 fs/super.c:1292
 vfs_get_tree+0x92/0x2a0 fs/super.c:1700
 fc_mount fs/namespace.c:1198 [inline]
 do_new_mount_fc fs/namespace.c:3765 [inline]
 do_new_mount+0x319/0xdc0 fs/namespace.c:3841
 do_mount fs/namespace.c:4174 [inline]
 __do_sys_mount fs/namespace.c:4390 [inline]
 __se_sys_mount+0x31d/0x420 fs/namespace.c:4367
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fe775d9e0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fe776d50fe8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007fe776025fa0 RCX: 00007fe775d9e0d9
RDX: 0000200000000b80 RSI: 0000200000000100 RDI: 0000000000000000
RBP: 00007fe776d51050 R08: 0000200000000240 R09: 0000000000000000
R10: 0000000000000008 R11: 0000000000000246 R12: 0000000000000002
R13: 00007fe776026038 R14: 00007fe776025fa0 R15: 00007ffdf4560bd8
 </TASK>
jffs2: warning: (5313) jffs2_sum_add_kvec: MEMORY ALLOCATION ERROR!
jffs2: Write of 68 bytes at 0x0001e218 failed. returned -12, retlen 0
jffs2: Not marking the space at 0x0001e218 as dirty because the flash driver returned retlen zero

=====================================
WARNING: bad unlock balance detected!
syzkaller #0 Not tainted
-------------------------------------
syz.0.0/5313 is trying to release lock (&c->alloc_sem) at:
[<ffffffff833a6ebe>] jffs2_do_create+0x1ae/0xe00 fs/jffs2/write.c:474
but there are no more locks to release!

other info that might help us debug this:
3 locks held by syz.0.0/5313:
 #0: ffff8880424140d8 (&type->s_umount_key#52/1){+.+.}-{4:4}, at: alloc_super fs/super.c:345 [inline]
 #0: ffff8880424140d8 (&type->s_umount_key#52/1){+.+.}-{4:4}, at: sget_fc+0x938/0x1900 fs/super.c:766
 #1: ffff888012c72450 (sb_writers#12){.+.+}-{0:0}, at: mnt_want_write+0x41/0x90 fs/namespace.c:494
 #2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: inode_lock_nested include/linux/fs.h:1069 [inline]
 #2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: __start_dirop fs/namei.c:2918 [inline]
 #2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: start_dirop fs/namei.c:2942 [inline]
 #2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: start_creating+0xbe/0x100 fs/namei.c:3406

stack backtrace:
CPU: 0 UID: 0 PID: 5313 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
 <TASK>
 dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
 print_unlock_imbalance_bug+0xdc/0xf0 kernel/locking/lockdep.c:5298
 __lock_release kernel/locking/lockdep.c:5537 [inline]
 lock_release+0x248/0x3c0 kernel/locking/lockdep.c:5889
 __mutex_unlock_slowpath+0x88/0x900 kernel/locking/mutex.c:989
 jffs2_do_create+0x1ae/0xe00 fs/jffs2/write.c:474
 jffs2_create+0x1c8/0x320 fs/jffs2/dir.c:205
 vfs_create+0x2c4/0x450 fs/namei.c:4202
 ovl_do_create+0x81/0xf0 fs/overlayfs/overlayfs.h:244
 ovl_create_real+0x1a8/0x740 fs/overlayfs/dir.c:180
 ovl_create_temp+0x169/0x240 fs/overlayfs/dir.c:267
 ovl_check_rename_whiteout fs/overlayfs/super.c:575 [inline]
 ovl_make_workdir fs/overlayfs/super.c:713 [inline]
 ovl_get_workdir fs/overlayfs/super.c:836 [inline]
 ovl_fill_super_creds fs/overlayfs/super.c:1449 [inline]
 ovl_fill_super+0x3c9b/0x5d40 fs/overlayfs/super.c:1560
 vfs_get_super fs/super.c:1273 [inline]
 get_tree_nodev+0xbb/0x150 fs/super.c:1292
 vfs_get_tree+0x92/0x2a0 fs/super.c:1700
 fc_mount fs/namespace.c:1198 [inline]
 do_new_mount_fc fs/namespace.c:3765 [inline]
 do_new_mount+0x319/0xdc0 fs/namespace.c:3841
 do_mount fs/namespace.c:4174 [inline]
 __do_sys_mount fs/namespace.c:4390 [inline]
 __se_sys_mount+0x31d/0x420 fs/namespace.c:4367
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fe775d9e0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fe776d50fe8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007fe776025fa0 RCX: 00007fe775d9e0d9
RDX: 0000200000000b80 RSI: 0000200000000100 RDI: 0000000000000000
RBP: 00007fe776d51050 R08: 0000200000000240 R09: 0000000000000000
R10: 0000000000000008 R11: 0000000000000246 R12: 0000000000000002
R13: 00007fe776026038 R14: 00007fe776025fa0 R15: 00007ffdf4560bd8
 </TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.