[syzbot] [gfs2?] kernel BUG in gfs2_unpin

syzbot <[email protected]>
Newsgroups dev.linux.lists.gfs2,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hello,

syzbot found the following issue on:

HEAD commit:    b927546677c8 Merge tag 'dma-mapping-6.19-2025-12-22' of gi..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1681cd84580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=513255d80ab78f2b
dashboard link: https://syzkaller.appspot.com/bug?extid=0c5024a57ccf4017c187
compiler:       Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-b9275466.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/16f89c42bab9/vmlinux-b9275466.xz
kernel image: https://storage.googleapis.com/syzbot-assets/54c5ab9b0ef0/bzImage-b9275466.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

syz.0.0: attempt to access beyond end of device
loop0: rw=8390657, sector=68719479344, nr_sectors = 8 limit=32768
Buffer I/O error on dev loop0, logical block 8589934918, lost async page write
------------[ cut here ]------------
kernel BUG at fs/gfs2/lops.c:107!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 5355 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:gfs2_unpin+0x9ac/0x9c0 fs/gfs2/lops.c:107
Code: fe e9 24 fb ff ff 44 89 e1 80 e1 07 80 c1 03 38 c1 0f 8c 52 fb ff ff 4c 89 e7 e8 cf a6 25 fe e9 45 fb ff ff e8 25 fb bd fd 90 <0f> 0b e8 1d fb bd fd 90 0f 0b e8 15 fb bd fd 90 0f 0b 66 90 90 90
RSP: 0018:ffffc9000ae771b0 EFLAGS: 00010293
RAX: ffffffff840309fb RBX: ffff8880458af000 RCX: ffff88801f9e8000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000002
RBP: 1ffff11008b15e09 R08: ffff8880548e3917 R09: 1ffff1100a91c722
R10: dffffc0000000000 R11: ffffed100a91c723 R12: dffffc0000000000
R13: ffff8880458ae230 R14: ffff8880548e3910 R15: ffff888000e30000
FS:  00007fc9591536c0(0000) GS:ffff88808d416000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000010f15000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 databuf_lo_after_commit+0x15e/0x1b0 fs/gfs2/lops.c:1077
 lops_after_commit fs/gfs2/lops.h:51 [inline]
 gfs2_log_flush+0xf60/0x24c0 fs/gfs2/log.c:1110
 gfs2_jdata_writepages+0xf9/0x150 fs/gfs2/aops.c:370
 do_writepages+0x32e/0x550 mm/page-writeback.c:2598
 filemap_writeback mm/filemap.c:387 [inline]
 filemap_fdatawrite_range mm/filemap.c:412 [inline]
 filemap_write_and_wait_range+0x21f/0x320 mm/filemap.c:684
 filemap_write_and_wait include/linux/pagemap.h:65 [inline]
 iomap_bmap+0x1a6/0x3c0 fs/iomap/fiemap.c:106
 gfs2_bmap+0x171/0x200 fs/gfs2/aops.c:573
 bmap+0xac/0xe0 fs/inode.c:2040
 ioctl_fibmap fs/ioctl.c:76 [inline]
 file_ioctl+0x41d/0x780 fs/ioctl.c:326
 do_vfs_ioctl+0xb33/0x1430 fs/ioctl.c:576
 __do_sys_ioctl fs/ioctl.c:595 [inline]
 __se_sys_ioctl+0x82/0x170 fs/ioctl.c:583
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0xec/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fc95838f7c9
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fc959153038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007fc9585e6180 RCX: 00007fc95838f7c9
RDX: 0000200000000280 RSI: 0000000000000001 RDI: 0000000000000008
RBP: 00007fc958413f91 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fc9585e6218 R14: 00007fc9585e6180 R15: 00007ffede3a3fa8
 </TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:gfs2_unpin+0x9ac/0x9c0 fs/gfs2/lops.c:107
Code: fe e9 24 fb ff ff 44 89 e1 80 e1 07 80 c1 03 38 c1 0f 8c 52 fb ff ff 4c 89 e7 e8 cf a6 25 fe e9 45 fb ff ff e8 25 fb bd fd 90 <0f> 0b e8 1d fb bd fd 90 0f 0b e8 15 fb bd fd 90 0f 0b 66 90 90 90
RSP: 0018:ffffc9000ae771b0 EFLAGS: 00010293
RAX: ffffffff840309fb RBX: ffff8880458af000 RCX: ffff88801f9e8000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000002
RBP: 1ffff11008b15e09 R08: ffff8880548e3917 R09: 1ffff1100a91c722
R10: dffffc0000000000 R11: ffffed100a91c723 R12: dffffc0000000000
R13: ffff8880458ae230 R14: ffff8880548e3910 R15: ffff888000e30000
FS:  00007fc9591536c0(0000) GS:ffff88808d416000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000010f15000 CR4: 0000000000352ef0


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.