[syzbot] [ocfs2?] kernel BUG in ocfs2_truncate_file (2)

syzbot <[email protected]>
Newsgroups dev.linux.lists.ocfs2-devel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hello,

syzbot found the following issue on:

HEAD commit:    2e6803928193 Merge tag 'tracefs-v7.1-2' of git://git.kerne..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=152aecce580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=893fe4d237c86ed2
dashboard link: https://syzkaller.appspot.com/bug?extid=83b3e2bb16ee8eaf0e68
compiler:       Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-2e680392.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/c172e9d12fe6/vmlinux-2e680392.xz
kernel image: https://storage.googleapis.com/syzbot-assets/27e7e7afc115/bzImage-2e680392.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

Buffer I/O error on dev loop0, logical block 19904, async page read
Buffer I/O error on dev loop0, logical block 19905, async page read
Buffer I/O error on dev loop0, logical block 19906, async page read
Buffer I/O error on dev loop0, logical block 19907, async page read
Buffer I/O error on dev loop0, logical block 19908, async page read
Buffer I/O error on dev loop0, logical block 19909, async page read
Buffer I/O error on dev loop0, logical block 19910, async page read
Buffer I/O error on dev loop0, logical block 19911, async page read
(syz.0.0,5344,0):ocfs2_truncate_file:461 ERROR: bug expression: le64_to_cpu(fe->i_size) != i_size_read(inode)
(syz.0.0,5344,0):ocfs2_truncate_file:461 ERROR: Inode 17058, inode i_size = 1048576 != di i_size = 983040, i_flags = 0x2001
------------[ cut here ]------------
kernel BUG at fs/ocfs2/file.c:461!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 5344 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:ocfs2_truncate_file+0x1313/0x14e0 fs/ocfs2/file.c:455
Code: d8 12 8c 49 89 d8 4d 89 f9 50 41 54 e8 c6 cb 17 00 48 83 c4 10 48 b8 00 00 00 00 00 fc ff df 48 8b 4c 24 20 c6 44 01 18 f8 90 <0f> 0b 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c 5c f8 ff ff 48 89 df e8
RSP: 0018:ffffc9000df872e0 EFLAGS: 00010282
RAX: dffffc0000000000 RBX: 00000000000042a2 RCX: 1ffff92001bf0e6c
RDX: ffffc90020011000 RSI: 0000000000018631 RDI: 0000000000018632
RBP: ffffc9000df87510 R08: ffff88801fc247d3 R09: 1ffff11003f848fa
R10: dffffc0000000000 R11: ffffed1003f848fb R12: 00000000000f0000
R13: ffff8880004c842c R14: ffffc9000df87420 R15: 0000000000100000
FS:  00007fc100fc96c0(0000) GS:ffff88808c809000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fc10040d6b8 CR3: 0000000041e52000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 ocfs2_setattr+0x15e5/0x1ca0 fs/ocfs2/file.c:1219
 notify_change+0xc1a/0xf40 fs/attr.c:556
 do_truncate+0x1c2/0x250 fs/open.c:68
 handle_truncate fs/namei.c:4307 [inline]
 do_open fs/namei.c:4703 [inline]
 path_openat+0x2f89/0x3860 fs/namei.c:4858
 do_file_open+0x23e/0x4a0 fs/namei.c:4887
 do_sys_openat2+0x113/0x200 fs/open.c:1364
 do_sys_open fs/open.c:1370 [inline]
 __do_sys_open fs/open.c:1378 [inline]
 __se_sys_open fs/open.c:1374 [inline]
 __x64_sys_open+0x11e/0x150 fs/open.c:1374
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fc10019c819
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fc100fc8fe8 EFLAGS: 00000246 ORIG_RAX: 0000000000000002
RAX: ffffffffffffffda RBX: 00007fc100416090 RCX: 00007fc10019c819
RDX: 0000000000000111 RSI: 000000000014937e RDI: 0000200000000180
RBP: 00007fc100232c91 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fc100416128 R14: 00007fc100416090 R15: 00007fff135c7a78
 </TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:ocfs2_truncate_file+0x1313/0x14e0 fs/ocfs2/file.c:455
Code: d8 12 8c 49 89 d8 4d 89 f9 50 41 54 e8 c6 cb 17 00 48 83 c4 10 48 b8 00 00 00 00 00 fc ff df 48 8b 4c 24 20 c6 44 01 18 f8 90 <0f> 0b 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c 5c f8 ff ff 48 89 df e8
RSP: 0018:ffffc9000df872e0 EFLAGS: 00010282
RAX: dffffc0000000000 RBX: 00000000000042a2 RCX: 1ffff92001bf0e6c
RDX: ffffc90020011000 RSI: 0000000000018631 RDI: 0000000000018632
RBP: ffffc9000df87510 R08: ffff88801fc247d3 R09: 1ffff11003f848fa
R10: dffffc0000000000 R11: ffffed1003f848fb R12: 00000000000f0000
R13: ffff8880004c842c R14: ffffc9000df87420 R15: 0000000000100000
FS:  00007fc100fc96c0(0000) GS:ffff88808c809000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f11c872aa30 CR3: 0000000041e52000 CR4: 0000000000352ef0


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.