[syzbot] [bcachefs?] kernel BUG in bch2_bio_compress (3)

syzbot <[email protected]>
Newsgroups org.kernel.vger.linux-bcachefs,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hello,

syzbot found the following issue on:

HEAD commit:    5f33ebd2018c Merge tag 'drm-fixes-2025-07-26' of https://g..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=15fa4034580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=8adfe52da0de2761
dashboard link: https://syzkaller.appspot.com/bug?extid=1733f08e3b98628b164a
compiler:       Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-5f33ebd2.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/a554f67105dc/vmlinux-5f33ebd2.xz
kernel image: https://storage.googleapis.com/syzbot-assets/b3d52a10bce9/bzImage-5f33ebd2.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

------------[ cut here ]------------
kernel BUG at fs/bcachefs/compress.c:525!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 5346 Comm: bch-copygc/loop Not tainted 6.16.0-rc7-syzkaller-00120-g5f33ebd2018c #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:__bio_compress fs/bcachefs/compress.c:525 [inline]
RIP: 0010:bch2_bio_compress+0x14b1/0x14c0 fs/bcachefs/compress.c:555
Code: fd 90 0f 0b e8 20 30 90 fd 90 0f 0b e8 18 30 90 fd 90 0f 0b e8 10 30 90 fd 90 0f 0b e8 08 30 90 fd 90 0f 0b e8 00 30 90 fd 90 <0f> 0b 66 66 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90 90 90
RSP: 0018:ffffc9000f51e600 EFLAGS: 00010293
RAX: ffffffff84300110 RBX: 0000000000000003 RCX: ffff88803d990000
RDX: 0000000000000000 RSI: 0000000000000800 RDI: 0000000000000000
RBP: ffffc9000f51e850 R08: 0000000000000005 R09: 0000000000000003
R10: ffffc90001a23033 R11: fffff52000344800 R12: 0000000000000800
R13: 0000000100000001 R14: 0000000000000000 R15: 0000000000002800
FS:  0000000000000000(0000) GS:ffff88808d218000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00005555e44a5168 CR3: 0000000011b80000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 bch2_write_extent fs/bcachefs/io_write.c:1060 [inline]
 __bch2_write+0xfb5/0x3900 fs/bcachefs/io_write.c:1554
 move_write fs/bcachefs/move.c:217 [inline]
 bch2_moving_ctxt_do_pending_writes+0x5a7/0xe60 fs/bcachefs/move.c:248
 bch2_move_ratelimit+0x8e8/0x1330 fs/bcachefs/move.c:585
 __bch2_move_data_phys+0x110f/0x1c50 fs/bcachefs/move.c:904
 bch2_evacuate_bucket+0x228/0x3a0 fs/bcachefs/move.c:1082
 bch2_copygc+0x3be3/0x4510 fs/bcachefs/movinggc.c:234
 bch2_copygc_thread+0x97a/0xe00 fs/bcachefs/movinggc.c:409
 kthread+0x711/0x8a0 kernel/kthread.c:464
 ret_from_fork+0x3fc/0x770 arch/x86/kernel/process.c:148
 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
 </TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:__bio_compress fs/bcachefs/compress.c:525 [inline]
RIP: 0010:bch2_bio_compress+0x14b1/0x14c0 fs/bcachefs/compress.c:555
Code: fd 90 0f 0b e8 20 30 90 fd 90 0f 0b e8 18 30 90 fd 90 0f 0b e8 10 30 90 fd 90 0f 0b e8 08 30 90 fd 90 0f 0b e8 00 30 90 fd 90 <0f> 0b 66 66 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90 90 90
RSP: 0018:ffffc9000f51e600 EFLAGS: 00010293
RAX: ffffffff84300110 RBX: 0000000000000003 RCX: ffff88803d990000
RDX: 0000000000000000 RSI: 0000000000000800 RDI: 0000000000000000
RBP: ffffc9000f51e850 R08: 0000000000000005 R09: 0000000000000003
R10: ffffc90001a23033 R11: fffff52000344800 R12: 0000000000000800
R13: 0000000100000001 R14: 0000000000000000 R15: 0000000000002800


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.