[syzbot] [btrfs?] WARNING in __cow_file_range_inline (2)

syzbot <[email protected]>
Newsgroups org.kernel.vger.linux-btrfs,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hello,

syzbot found the following issue on:

HEAD commit:    a59f57e2aa12 Merge tag 'watchdog-for-v7.2-rc7' of git://gi..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=11370079580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=a59830cba91a1981
dashboard link: https://syzkaller.appspot.com/bug?extid=90ab2ca74c4ca62b395f
compiler:       Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-a59f57e2.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/3b0b58b842b2/vmlinux-a59f57e2.xz
kernel image: https://storage.googleapis.com/syzbot-assets/48759b65e153/bzImage-a59f57e2.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

x_tables: ip_tables: owner match: used from hooks PREROUTING, but only valid from OUTPUT/POSTROUTING
------------[ cut here ]------------
btrfs_abort_should_print_stack(__error)
WARNING: fs/btrfs/inode.c:641 at __cow_file_range_inline+0xef0/0x1000 fs/btrfs/inode.c:641, CPU#0: syz.0.0/5319
Modules linked in:
CPU: 0 UID: 0 PID: 5319 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:__cow_file_range_inline+0xef0/0x1000 fs/btrfs/inode.c:641
Code: e2 74 39 41 83 fd fb 74 3a 41 83 fd f4 75 3b e8 86 04 b3 fd eb 3d e8 7f 04 b3 fd eb 10 e8 78 04 b3 fd eb 09 e8 71 04 b3 fd 90 <0f> 0b 90 44 89 e9 f7 d9 4c 8b 7c 24 18 e9 d4 fd ff ff e8 59 04 b3
RSP: 0018:ffffc9000eb5ec80 EFLAGS: 00010283
RAX: ffffffff84140e6f RBX: 1ffff92001d6bda0 RCX: 0000000000100000
RDX: ffffc90020001000 RSI: 00000000000010b8 RDI: 00000000000010b9
RBP: ffffc9000eb5ee70 R08: ffff888000ef4a80 R09: 0000000000000003
R10: 00000000fffffffb R11: 0000000000000002 R12: dffffc0000000000
R13: 00000000ffffffe4 R14: ffff888052a24001 R15: ffff888013211d10
FS:  00007fed310f66c0(0000) GS:ffff88808c549000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000020000000c2c0 CR3: 0000000012e06000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 run_delalloc_inline fs/btrfs/inode.c:2351 [inline]
 btrfs_run_delalloc_range+0x1a84/0x1fd0 fs/btrfs/inode.c:2407
 writepage_delalloc+0x10a4/0x1c60 fs/btrfs/extent_io.c:1671
 extent_writepage fs/btrfs/extent_io.c:2043 [inline]
 extent_write_cache_pages fs/btrfs/extent_io.c:2706 [inline]
 btrfs_writepages+0x1667/0x28b0 fs/btrfs/extent_io.c:2838
 do_writepages+0x338/0x560 mm/page-writeback.c:2571
 filemap_writeback mm/filemap.c:387 [inline]
 filemap_fdatawrite_range+0x1ef/0x2f0 mm/filemap.c:412
 btrfs_fdatawrite_range+0x54/0xf0 fs/btrfs/file.c:3884
 btrfs_direct_write+0x69d/0xc20 fs/btrfs/direct-io.c:1038
 btrfs_do_write_iter+0x325/0x790 fs/btrfs/file.c:1449
 do_iter_readv_writev+0x612/0x8c0 fs/read_write.c:-1
 vfs_writev+0x343/0x990 fs/read_write.c:1058
 do_writev+0x154/0x2e0 fs/read_write.c:1104
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fed3019e0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fed310f5fe8 EFLAGS: 00000246 ORIG_RAX: 0000000000000014
RAX: ffffffffffffffda RBX: 00007fed30426090 RCX: 00007fed3019e0d9
RDX: 0000000000000001 RSI: 0000200000000040 RDI: 0000000000000005
RBP: 00007fed30235024 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fed30426128 R14: 00007fed30426090 R15: 00007ffcf827f4e8
 </TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.