Re: [moderation/CI] Re: ext4: move inline data cleanup to ext4_writepages to fix deadlock

Aleksandr Nogikh <[email protected]>
Newsgroups dev.linux.lists.syzbot
Message-ID <CANp29Y6tj_j-Q8aeLGXYC9axTm4-18wiThzotc5vktoHnckhRQ@mail.gmail.com>
#syz upstream

On Wed, Jun 10, 2026 at 9:33 AM syzbot ci
<[email protected]> wrote:
>
> syzbot ci has tested the following series
>
> [v1] ext4: move inline data cleanup to ext4_writepages to fix deadlock
> https://lore.kernel.org/all/[email protected]
> * [PATCH] ext4: move inline data cleanup to ext4_writepages to fix deadlock
>
> and found the following issue:
> kernel BUG in ext4_writepages
>
> Full report is available here:
> https://ci.syzbot.org/series/1ede6029-df2a-4e08-bffc-05540c1f4934
>
> ***
>
> kernel BUG in ext4_writepages
>
> tree:      torvalds
> URL:       https://kernel.googlesource.com/pub/scm/linux/kernel/git/torvalds/linux
> base:      2d3090a8aeb596a26935db0955d46c9a5db5c6ce
> arch:      amd64
> compiler:  Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
> config:    https://ci.syzbot.org/builds/63ee0324-2d17-4b32-aca2-c6230ff64be6/config
> syz repro: https://ci.syzbot.org/findings/676a447c-ea73-43ea-9949-054dac1961e5/syz_repro
>
> EXT4-fs warning (device loop2): ext4_expand_extra_isize_ea:2860: Unable to expand inode 15. Delete some EAs or run e2fsck.
> ------------[ cut here ]------------
> kernel BUG at fs/ext4/inode.c:3047!
> Oops: invalid opcode: 0000 [#1] SMP KASAN PTI
> CPU: 1 UID: 0 PID: 5875 Comm: syz.2.19 Not tainted syzkaller #0 PREEMPT(full)
> Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
> RIP: 0010:ext4_writepages+0x622/0x630 fs/ext4/inode.c:3046
> Code: ff e9 61 fc ff ff 44 89 f1 80 e1 07 80 c1 03 38 c1 0f 8c de fc ff ff 4c 89 f7 e8 f9 2f a8 ff e9 d1 fc ff ff e8 ef d7 3c ff 90 <0f> 0b 66 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90 90 90 90
> RSP: 0018:ffffc900034df2e0 EFLAGS: 00010293
> RAX: ffffffff8288dfb1 RBX: 1ffff9200069be60 RCX: ffff888110555940
> RDX: 0000000000000000 RSI: 0000004000000000 RDI: 0000000000000000
> RBP: ffffc900034df410 R08: ffff8881b48c2f0f R09: 1ffff110369185e1
> R10: dffffc0000000000 R11: ffffed10369185e2 R12: dffffc0000000000
> R13: 0000004000000000 R14: 0000004610000000 R15: 1ffff11020c6fcc5
> FS:  00007f033e9346c0(0000) GS:ffff8882a92a0000(0000) knlGS:0000000000000000
> CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> CR2: 00005556842f3058 CR3: 000000016d5c0000 CR4: 00000000000006f0
> Call Trace:
>  <TASK>
>  do_writepages+0x32e/0x550 mm/page-writeback.c:2571
>  __writeback_single_inode+0x133/0x10e0 fs/fs-writeback.c:1764
>  writeback_single_inode+0x4ac/0xdc0 fs/fs-writeback.c:1883
>  write_inode_now+0x1c2/0x290 fs/fs-writeback.c:2974
>  iput_final fs/inode.c:1950 [inline]
>  iput+0x8c1/0xe80 fs/inode.c:2009
>  ext4_orphan_cleanup+0xc38/0x1470 fs/ext4/orphan.c:472
>  __ext4_fill_super fs/ext4/super.c:5701 [inline]
>  ext4_fill_super+0x5a19/0x6330 fs/ext4/super.c:5824
>  get_tree_bdev_flags+0x431/0x4f0 fs/super.c:1694
>  vfs_get_tree+0x92/0x2a0 fs/super.c:1754
>  fc_mount fs/namespace.c:1193 [inline]
>  do_new_mount_fc fs/namespace.c:3758 [inline]
>  do_new_mount+0x341/0xd30 fs/namespace.c:3834
>  do_mount fs/namespace.c:4167 [inline]
>  __do_sys_mount fs/namespace.c:4383 [inline]
>  __se_sys_mount+0x31d/0x420 fs/namespace.c:4360
>  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
>  do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
>  entry_SYSCALL_64_after_hwframe+0x77/0x7f
> RIP: 0033:0x7f033d99e0ca
> Code: 48 c7 c2 e8 ff ff ff f7 d8 64 89 02 b8 ff ff ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
> RSP: 002b:00007f033e933e58 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
> RAX: ffffffffffffffda RBX: 00007f033e933ee0 RCX: 00007f033d99e0ca
> RDX: 0000200000000040 RSI: 00002000000016c0 RDI: 00007f033e933ea0
> RBP: 0000200000000040 R08: 00007f033e933ee0 R09: 000000000000840e
> R10: 000000000000840e R11: 0000000000000246 R12: 00002000000016c0
> R13: 00007f033e933ea0 R14: 000000000000042f R15: 0000200000000080
>  </TASK>
> Modules linked in:
> ---[ end trace 0000000000000000 ]---
> RIP: 0010:ext4_writepages+0x622/0x630 fs/ext4/inode.c:3046
> Code: ff e9 61 fc ff ff 44 89 f1 80 e1 07 80 c1 03 38 c1 0f 8c de fc ff ff 4c 89 f7 e8 f9 2f a8 ff e9 d1 fc ff ff e8 ef d7 3c ff 90 <0f> 0b 66 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90 90 90 90
> RSP: 0018:ffffc900034df2e0 EFLAGS: 00010293
> RAX: ffffffff8288dfb1 RBX: 1ffff9200069be60 RCX: ffff888110555940
> RDX: 0000000000000000 RSI: 0000004000000000 RDI: 0000000000000000
> RBP: ffffc900034df410 R08: ffff8881b48c2f0f R09: 1ffff110369185e1
> R10: dffffc0000000000 R11: ffffed10369185e2 R12: dffffc0000000000
> R13: 0000004000000000 R14: 0000004610000000 R15: 1ffff11020c6fcc5
> FS:  00007f033e9346c0(0000) GS:ffff8882a92a0000(0000) knlGS:0000000000000000
> CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> CR2: 00005556842f3058 CR3: 000000016d5c0000 CR4: 00000000000006f0
>
>
> ***
>
> If these findings have caused you to resend the series or submit a
> separate fix, please add the following tag to your commit message:
>   Tested-by: [email protected]
>
> ---
> This report is generated by a bot. It may contain errors.
> syzbot ci engineers can be reached at [email protected].
>
> To test a patch for this bug, please reply with `#syz test`
> (should be on a separate line).
>
> The patch should be attached to the email.
> Note: arguments like custom git repos and branches are not supported.
>
> The email will later be sent to:
> [[email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]]
>
> If the report looks fine to you, reply with:
> #syz upstream
>
> If the report is a false positive, reply with
> #syz invalid
>
> --
> You received this message because you are subscribed to the Google Groups "syzkaller-upstream-moderation" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
> To view this discussion visit https://groups.google.com/d/msgid/syzkaller-upstream-moderation/6a291329.39669fcc.33b062.00b7.GAE%40google.com.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.