[syzbot] [udf?] WARNING in udf_new_block (3)

syzbot <[email protected]>
Newsgroups gmane.linux.kernel
Message-ID <[email protected]>
Hello,

syzbot found the following issue on:

HEAD commit:    b126f6f5940f Merge tag 'x86_mm_for_7.3-rc1' of git://git.k..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=124f8e79580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=fc79d903e3f45b4b
dashboard link: https://syzkaller.appspot.com/bug?extid=118631ef5b63f166c204
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-b126f6f5.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/c87ba89d4d75/vmlinux-b126f6f5.xz
kernel image: https://storage.googleapis.com/syzbot-assets/401019d8b5df/bzImage-b126f6f5.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

------------[ cut here ]------------
!buffer_uptodate(bh)
WARNING: fs/buffer.c:991 at mark_buffer_dirty+0x299/0x410 fs/buffer.c:991, CPU#0: syz.0.0/5327
Modules linked in:
CPU: 0 UID: 0 PID: 5327 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:mark_buffer_dirty+0x299/0x410 fs/buffer.c:991
Code: 4c 89 f7 e8 79 89 d8 ff 49 8b 3e be 40 00 00 00 5b 41 5c 41 5e 41 5f 5d e9 74 52 fb ff e8 7f 37 69 ff eb 8c e8 78 37 69 ff 90 <0f> 0b 90 e9 a5 fd ff ff e8 6a 37 69 ff 90 0f 0b 90 e9 cf fd ff ff
RSP: 0018:ffffc9000de8f270 EFLAGS: 00010283
RAX: ffffffff825def18 RBX: ffff88804386d9a0 RCX: 0000000000100000
RDX: ffffc9000f4b1000 RSI: 0000000000054649 RDI: 000000000005464a
RBP: ffffc9000de8f401 R08: ffff88804386d9a7 R09: 1ffff1100870db34
R10: dffffc0000000000 R11: ffffed100870db35 R12: ffff8880129f6000
R13: dffffc0000000000 R14: 00000000000000e6 R15: 0000000000000026
FS:  00007f8be61816c0(0000) GS:ffff88808c533000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000000136cb000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 udf_bitmap_new_block fs/udf/balloc.c:348 [inline]
 udf_new_block+0x17d9/0x1c00 fs/udf/balloc.c:722
 inode_getblk fs/udf/inode.c:898 [inline]
 udf_map_block+0x138e/0x4270 fs/udf/inode.c:451
 __udf_get_block+0x52/0x250 fs/udf/inode.c:465
 __block_write_begin_int+0x6c2/0x1900 fs/buffer.c:2027
 block_write_begin+0x8d/0x120 fs/buffer.c:2138
 udf_write_begin+0x118/0x270 fs/udf/inode.c:259
 generic_perform_write+0x2d5/0x8f0 mm/filemap.c:4364
 udf_file_write_iter+0x2e8/0x6c0 fs/udf/file.c:112
 new_sync_write fs/read_write.c:595 [inline]
 vfs_write+0x612/0xba0 fs/read_write.c:687
 ksys_write+0x150/0x270 fs/read_write.c:739
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f8be539e0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f8be6180fe8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f8be5626090 RCX: 00007f8be539e0d9
RDX: 000000000000ffc9 RSI: 0000200000000140 RDI: 000000000000000d
RBP: 00007f8be5435024 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f8be5626128 R14: 00007f8be5626090 R15: 00007ffef6d34418
 </TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.