Re: [PATCH] nilfs2: fix infinite loop in nilfs_clean_segments()
Joshua Crofts <[email protected]> Fri, 17 Jul 2026 12:40:10 +0200
| Newsgroups | org.kernel.vger.linux-nilfs,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 17 Jul 2026 19:34:21 +0900 Ryusuke Konishi <[email protected]> wrote: > On Fri, Jul 17, 2026 at 4:49=E2=80=AFPM Joshua Crofts wrote: > > > > syzbot reported a hung task in nilfs_transaction_begin(). This occurs > > because the cleaner ioctl falls into an infinite loop if > > nilfs_segctor_construct() repeatedly returns -EROFS (e.g. the device > > is remounted as read-only after an I/O error). > > > > Currently in nilfs_clean_segments(), if err is non-zero, it logs the > > error and sleeps but doesn't abort when it encounters a terminal error > > like -EROFS. This causes the thread to loop forever. > > > > Fix this by breaking out of the loop if nilfs_segctor_construct() > > returns -EROFS. This matches the behaviour in > > nilfs_segctor_write_out(), which also handles -EROFS. > > > > Reported-by: [email protected] > > Closes: https://syzkaller.appspot.com/bug?extid=3Dcae54346a70bbceeff2c > > Fixes: 9ff05123e3bf ("nilfs2: segment constructor") > > Assisted-by: gemini:gemini-3.1-pro > > Signed-off-by: Joshua Crofts <[email protected]> > > --- > > As much as I've tried, syzbot is unable to test this and always fails > > with "FATAL: Kernel too old". Nevertheless, I've tested the patch with > > the same reproducer in QEMU and the system didn't hang. =20 >=20 > Thanks for the patch, Joshua! > This fix correctly addresses the issue reported by syzbot. >=20 > I have one request regarding the loop exit: > Could you modify the patch to jump to the out_unlock label instead of > using break? > This is to prevent discard commands from being sent to the underlying > block device when the operation has failed and the filesystem state > has degraded to read-only. Yes, no problem, that makes more sense. Will send a new version in a bit. --=20 Kind regards, Joshua Crofts