Re: [moderation/CI] Re: Add EXT4_STATE_MAY_INLINE_DATA check in ext4_readdir

Aleksandr Nogikh <[email protected]>
Newsgroups dev.linux.lists.syzbot
Message-ID <CANp29Y5BbMUkOno5NEbWGYc8i-oksi-5g_E6geDhVMaymX-YFA@mail.gmail.com>
#syz upstream

On Sun, Aug 16, 2026 at 9:48 PM syzbot ci
<[email protected]> wrote:
>
> syzbot ci has tested the following series
>
> [v2] Add EXT4_STATE_MAY_INLINE_DATA check in ext4_readdir
> https://lore.kernel.org/all/[email protected]
> * [PATCH v2] Add EXT4_STATE_MAY_INLINE_DATA check in ext4_readdir
>
> and found the following issue:
> WARNING in invalidate_bh_lru
>
> Full report is available here:
> https://ci.syzbot.org/series/74cf3860-255d-49bb-b3df-51f8ee44a69f
>
> ***
>
> WARNING in invalidate_bh_lru
>
> tree:      linux-next
> URL:       https://kernel.googlesource.com/pub/scm/linux/kernel/git/next/linux-next
> base:      1351c159c59b04195647917c5a5f0e5467f44bb0
> arch:      amd64
> compiler:  Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
> config:    https://ci.syzbot.org/builds/500e2ced-dbe6-480e-affe-813e984ba307/config
> syz repro: https://ci.syzbot.org/findings/875c08a7-1950-4014-851b-0d660dfa2413/syz_repro
>
> ------------[ cut here ]------------
> VFS: brelse: Trying to free free buffer
> WARNING: fs/buffer.c:1147 at __brelse fs/buffer.c:1147 [inline], CPU#0: udevd/5048
> WARNING: fs/buffer.c:1147 at brelse include/linux/buffer_head.h:326 [inline], CPU#0: udevd/5048
> WARNING: fs/buffer.c:1147 at __invalidate_bh_lrus fs/buffer.c:1506 [inline], CPU#0: udevd/5048
> WARNING: fs/buffer.c:1147 at invalidate_bh_lru+0xfa/0x1b0 fs/buffer.c:1519, CPU#0: udevd/5048
> Modules linked in:
> CPU: 0 UID: 0 PID: 5048 Comm: udevd Not tainted syzkaller #0 PREEMPT(full)
> Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
> RIP: 0010:__brelse fs/buffer.c:1147 [inline]
> RIP: 0010:brelse include/linux/buffer_head.h:326 [inline]
> RIP: 0010:__invalidate_bh_lrus fs/buffer.c:1506 [inline]
> RIP: 0010:invalidate_bh_lru+0xfa/0x1b0 fs/buffer.c:1519
> Code: f7 be 04 00 00 00 e8 85 c0 d8 ff f0 41 ff 0e eb 1e e8 8a 21 6b ff 80 3c 2b 00 75 20 eb 26 e8 7d 21 6b ff 48 8d 3d e6 bf 01 0e <67> 48 0f b9 3a 4c 89 fd 4f 8d 3c 2c 80 3c 2b 00 74 08 4c 89 ff e8
> RSP: 0018:ffffc90000007f38 EFLAGS: 00010006
> RAX: ffffffff825be013 RBX: 1ffff11024206b2d RCX: ffff888172139dc0
> RDX: 0000000000010000 RSI: 0000000000000000 RDI: ffffffff905da000
> RBP: 0000000000000000 R08: ffff8881078c875b R09: 1ffff11020f190eb
> R10: dffffc0000000000 R11: ffffed1020f190ec R12: ffff888121035960
> R13: 0000000000000008 R14: ffff8881078c8758 R15: dffffc0000000000
> FS:  00007f6c32242c80(0000) GS:ffff88818d952000(0000) knlGS:0000000000000000
> CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> CR2: 00007fc1515eb7c0 CR3: 000000016c5ac000 CR4: 00000000000006f0
> Call Trace:
>  <IRQ>
>  csd_do_func kernel/smp.c:136 [inline]
>  __flush_smp_call_function_queue+0x32c/0xa20 kernel/smp.c:580
>  __sysvec_call_function_single+0x9a/0x3d0 arch/x86/kernel/smp.c:272
>  instr_sysvec_call_function_single arch/x86/kernel/smp.c:267 [inline]
>  sysvec_call_function_single+0x9e/0xc0 arch/x86/kernel/smp.c:267
>  </IRQ>
>  <TASK>
>  asm_sysvec_call_function_single+0x1a/0x20 arch/x86/include/asm/idtentry.h:681
> RIP: 0010:lock_is_held_type+0x106/0x150 kernel/locking/lockdep.c:5945
> Code: 1a 00 00 b8 ff ff ff ff 65 0f c1 05 54 4c 9c 07 83 f8 01 75 25 9c 58 a9 00 02 00 00 75 39 41 f7 c4 00 02 00 00 74 01 fb 89 d8 <5b> 41 5c 41 5d 41 5e 41 5f 5d e9 1b 00 03 00 cc 90 0f 0b 90 48 c7
> RSP: 0018:ffffc9000624f818 EFLAGS: 00000206
> RAX: 0000000000000001 RBX: 0000000000000001 RCX: 0000000000000046
> RDX: 0000000000000000 RSI: ffffffff8e4ae37e RDI: ffffffff8c4bbd80
> RBP: 00000000ffffffff R08: ffffc9000020daa7 R09: 1ffff92000041b54
> R10: dffffc0000000000 R11: fffff52000041b55 R12: 0000000000000246
> R13: ffff888172139dc0 R14: ffffffff8eb59c60 R15: 0000000000000000
>  __d_lookup+0x170/0x790 fs/dcache.c:2612
>  lookup_fast+0x82/0x5d0 fs/namei.c:1878
>  walk_component fs/namei.c:2278 [inline]
>  link_path_walk+0x71f/0x1910 fs/namei.c:2656
>  path_openat+0x236/0x3830 fs/namei.c:4859
>  do_file_open+0x23e/0x4a0 fs/namei.c:4892
>  do_sys_openat2+0x115/0x200 fs/open.c:1368
>  do_sys_open fs/open.c:1374 [inline]
>  __do_sys_openat fs/open.c:1390 [inline]
>  __se_sys_openat fs/open.c:1385 [inline]
>  __x64_sys_openat+0x138/0x170 fs/open.c:1385
>  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
>  do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
>  entry_SYSCALL_64_after_hwframe+0x77/0x7f
> RIP: 0033:0x7f6c3231a477
> Code: 10 00 00 00 44 8b 54 24 e0 48 89 44 24 c0 48 8d 44 24 d0 48 89 44 24 c8 44 89 c2 4c 89 ce bf 9c ff ff ff b8 01 01 00 00 0f 05 <48> 3d 00 f0 ff ff 76 10 48 8b 15 82 69 0d 00 f7 d8 64 89 02 48 83
> RSP: 002b:00007ffe8da39558 EFLAGS: 00000287 ORIG_RAX: 0000000000000101
> RAX: ffffffffffffffda RBX: 000055a56911c8f0 RCX: 00007f6c3231a477
> RDX: 0000000000090800 RSI: 000055a569100840 RDI: 00000000ffffff9c
> RBP: 000055a569196980 R08: 0000000000090800 R09: 000055a569100840
> R10: 0000000000000000 R11: 0000000000000287 R12: 000055a569100840
> R13: 00000000000000ff R14: 000055a53ac761c4 R15: 0000000000000000
>  </TASK>
> ----------------
> Code disassembly (best guess):
>    0:   f7 be 04 00 00 00       idivl  0x4(%rsi)
>    6:   e8 85 c0 d8 ff          call   0xffd8c090
>    b:   f0 41 ff 0e             lock decl (%r14)
>    f:   eb 1e                   jmp    0x2f
>   11:   e8 8a 21 6b ff          call   0xff6b21a0
>   16:   80 3c 2b 00             cmpb   $0x0,(%rbx,%rbp,1)
>   1a:   75 20                   jne    0x3c
>   1c:   eb 26                   jmp    0x44
>   1e:   e8 7d 21 6b ff          call   0xff6b21a0
>   23:   48 8d 3d e6 bf 01 0e    lea    0xe01bfe6(%rip),%rdi        # 0xe01c010
> * 2a:   67 48 0f b9 3a          ud1    (%edx),%rdi <-- trapping instruction
>   2f:   4c 89 fd                mov    %r15,%rbp
>   32:   4f 8d 3c 2c             lea    (%r12,%r13,1),%r15
>   36:   80 3c 2b 00             cmpb   $0x0,(%rbx,%rbp,1)
>   3a:   74 08                   je     0x44
>   3c:   4c 89 ff                mov    %r15,%rdi
>   3f:   e8                      .byte 0xe8
>
>
> ***
>
> If these findings have caused you to resend the series or submit a
> separate fix, please add the following tag to your commit message:
>   Tested-by: [email protected]
>
> ---
> This report is generated by a bot. It may contain errors.
> syzbot ci engineers can be reached at [email protected].
>
> To test a fix for this bug, please reply with `#syz test`
> (on a separate line) and attach the patch to the email.
>
> Notes:
> - The patch will be applied on top of the tested series (as an
>   incremental fix).
> - To test a new version of the whole series, please send it directly
>   to [email protected].
> - Arguments like custom git repos and branches are not supported.
>
> The email will later be sent to:
> [[email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]]
>
> If the report looks fine to you, reply with:
> #syz upstream
>
> If the report is a false positive, reply with
> #syz invalid
>
> --
> You received this message because you are subscribed to the Google Groups "syzkaller-upstream-moderation" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
> To view this discussion visit https://groups.google.com/d/msgid/syzkaller-upstream-moderation/6a821412.dbb3a75c.20434b.0039.GAE%40google.com.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.