[syzbot ci] Re: Add EXT4_STATE_MAY_INLINE_DATA check in ext4_readdir
syzbot ci <[email protected]>
| Newsgroups | dev.linux.lists.syzbot,org.kernel.vger.linux-ext4 |
|---|---|
| Message-ID | <[email protected]> |
syzbot ci has tested the following series [v2] Add EXT4_STATE_MAY_INLINE_DATA check in ext4_readdir https://lore.kernel.org/all/[email protected] * [PATCH v2] Add EXT4_STATE_MAY_INLINE_DATA check in ext4_readdir and found the following issue: WARNING in invalidate_bh_lru Full report is available here: https://ci.syzbot.org/series/74cf3860-255d-49bb-b3df-51f8ee44a69f *** WARNING in invalidate_bh_lru tree: linux-next URL: https://kernel.googlesource.com/pub/scm/linux/kernel/git/next/linux-next base: 1351c159c59b04195647917c5a5f0e5467f44bb0 arch: amd64 compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8 config: https://ci.syzbot.org/builds/500e2ced-dbe6-480e-affe-813e984ba307/config syz repro: https://ci.syzbot.org/findings/875c08a7-1950-4014-851b-0d660dfa2413/syz_repro ------------[ cut here ]------------ VFS: brelse: Trying to free free buffer WARNING: fs/buffer.c:1147 at __brelse fs/buffer.c:1147 [inline], CPU#0: udevd/5048 WARNING: fs/buffer.c:1147 at brelse include/linux/buffer_head.h:326 [inline], CPU#0: udevd/5048 WARNING: fs/buffer.c:1147 at __invalidate_bh_lrus fs/buffer.c:1506 [inline], CPU#0: udevd/5048 WARNING: fs/buffer.c:1147 at invalidate_bh_lru+0xfa/0x1b0 fs/buffer.c:1519, CPU#0: udevd/5048 Modules linked in: CPU: 0 UID: 0 PID: 5048 Comm: udevd Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 RIP: 0010:__brelse fs/buffer.c:1147 [inline] RIP: 0010:brelse include/linux/buffer_head.h:326 [inline] RIP: 0010:__invalidate_bh_lrus fs/buffer.c:1506 [inline] RIP: 0010:invalidate_bh_lru+0xfa/0x1b0 fs/buffer.c:1519 Code: f7 be 04 00 00 00 e8 85 c0 d8 ff f0 41 ff 0e eb 1e e8 8a 21 6b ff 80 3c 2b 00 75 20 eb 26 e8 7d 21 6b ff 48 8d 3d e6 bf 01 0e <67> 48 0f b9 3a 4c 89 fd 4f 8d 3c 2c 80 3c 2b 00 74 08 4c 89 ff e8 RSP: 0018:ffffc90000007f38 EFLAGS: 00010006 RAX: ffffffff825be013 RBX: 1ffff11024206b2d RCX: ffff888172139dc0 RDX: 0000000000010000 RSI: 0000000000000000 RDI: ffffffff905da000 RBP: 0000000000000000 R08: ffff8881078c875b R09: 1ffff11020f190eb R10: dffffc0000000000 R11: ffffed1020f190ec R12: ffff888121035960 R13: 0000000000000008 R14: ffff8881078c8758 R15: dffffc0000000000 FS: 00007f6c32242c80(0000) GS:ffff88818d952000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fc1515eb7c0 CR3: 000000016c5ac000 CR4: 00000000000006f0 Call Trace: <IRQ> csd_do_func kernel/smp.c:136 [inline] __flush_smp_call_function_queue+0x32c/0xa20 kernel/smp.c:580 __sysvec_call_function_single+0x9a/0x3d0 arch/x86/kernel/smp.c:272 instr_sysvec_call_function_single arch/x86/kernel/smp.c:267 [inline] sysvec_call_function_single+0x9e/0xc0 arch/x86/kernel/smp.c:267 </IRQ> <TASK> asm_sysvec_call_function_single+0x1a/0x20 arch/x86/include/asm/idtentry.h:681 RIP: 0010:lock_is_held_type+0x106/0x150 kernel/locking/lockdep.c:5945 Code: 1a 00 00 b8 ff ff ff ff 65 0f c1 05 54 4c 9c 07 83 f8 01 75 25 9c 58 a9 00 02 00 00 75 39 41 f7 c4 00 02 00 00 74 01 fb 89 d8 <5b> 41 5c 41 5d 41 5e 41 5f 5d e9 1b 00 03 00 cc 90 0f 0b 90 48 c7 RSP: 0018:ffffc9000624f818 EFLAGS: 00000206 RAX: 0000000000000001 RBX: 0000000000000001 RCX: 0000000000000046 RDX: 0000000000000000 RSI: ffffffff8e4ae37e RDI: ffffffff8c4bbd80 RBP: 00000000ffffffff R08: ffffc9000020daa7 R09: 1ffff92000041b54 R10: dffffc0000000000 R11: fffff52000041b55 R12: 0000000000000246 R13: ffff888172139dc0 R14: ffffffff8eb59c60 R15: 0000000000000000 __d_lookup+0x170/0x790 fs/dcache.c:2612 lookup_fast+0x82/0x5d0 fs/namei.c:1878 walk_component fs/namei.c:2278 [inline] link_path_walk+0x71f/0x1910 fs/namei.c:2656 path_openat+0x236/0x3830 fs/namei.c:4859 do_file_open+0x23e/0x4a0 fs/namei.c:4892 do_sys_openat2+0x115/0x200 fs/open.c:1368 do_sys_open fs/open.c:1374 [inline] __do_sys_openat fs/open.c:1390 [inline] __se_sys_openat fs/open.c:1385 [inline] __x64_sys_openat+0x138/0x170 fs/open.c:1385 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f6c3231a477 Code: 10 00 00 00 44 8b 54 24 e0 48 89 44 24 c0 48 8d 44 24 d0 48 89 44 24 c8 44 89 c2 4c 89 ce bf 9c ff ff ff b8 01 01 00 00 0f 05 <48> 3d 00 f0 ff ff 76 10 48 8b 15 82 69 0d 00 f7 d8 64 89 02 48 83 RSP: 002b:00007ffe8da39558 EFLAGS: 00000287 ORIG_RAX: 0000000000000101 RAX: ffffffffffffffda RBX: 000055a56911c8f0 RCX: 00007f6c3231a477 RDX: 0000000000090800 RSI: 000055a569100840 RDI: 00000000ffffff9c RBP: 000055a569196980 R08: 0000000000090800 R09: 000055a569100840 R10: 0000000000000000 R11: 0000000000000287 R12: 000055a569100840 R13: 00000000000000ff R14: 000055a53ac761c4 R15: 0000000000000000 </TASK> ---------------- Code disassembly (best guess): 0: f7 be 04 00 00 00 idivl 0x4(%rsi) 6: e8 85 c0 d8 ff call 0xffd8c090 b: f0 41 ff 0e lock decl (%r14) f: eb 1e jmp 0x2f 11: e8 8a 21 6b ff call 0xff6b21a0 16: 80 3c 2b 00 cmpb $0x0,(%rbx,%rbp,1) 1a: 75 20 jne 0x3c 1c: eb 26 jmp 0x44 1e: e8 7d 21 6b ff call 0xff6b21a0 23: 48 8d 3d e6 bf 01 0e lea 0xe01bfe6(%rip),%rdi # 0xe01c010 * 2a: 67 48 0f b9 3a ud1 (%edx),%rdi <-- trapping instruction 2f: 4c 89 fd mov %r15,%rbp 32: 4f 8d 3c 2c lea (%r12,%r13,1),%r15 36: 80 3c 2b 00 cmpb $0x0,(%rbx,%rbp,1) 3a: 74 08 je 0x44 3c: 4c 89 ff mov %r15,%rdi 3f: e8 .byte 0xe8 *** If these findings have caused you to resend the series or submit a separate fix, please add the following tag to your commit message: Tested-by: [email protected] --- This report is generated by a bot. It may contain errors. syzbot ci engineers can be reached at [email protected]. To test a fix for this bug, please reply with `#syz test` (on a separate line) and attach the patch to the email. Notes: - The patch will be applied on top of the tested series (as an incremental fix). - To test a new version of the whole series, please send it directly to [email protected]. - Arguments like custom git repos and branches are not supported.