Re: [PATCH] nilfs2: fix infinite loop in nilfs_clean_segments()

Joshua Crofts <[email protected]> Fri, 17 Jul 2026 12:40:10 +0200
Newsgroups org.kernel.vger.linux-nilfs,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Fri, 17 Jul 2026 19:34:21 +0900
Ryusuke Konishi <[email protected]> wrote:

> On Fri, Jul 17, 2026 at 4:49=E2=80=AFPM Joshua Crofts wrote:
> >
> > syzbot reported a hung task in nilfs_transaction_begin(). This occurs
> > because the cleaner ioctl falls into an infinite loop if
> > nilfs_segctor_construct() repeatedly returns -EROFS (e.g. the device
> > is remounted as read-only after an I/O error).
> >
> > Currently in nilfs_clean_segments(), if err is non-zero, it logs the
> > error and sleeps but doesn't abort when it encounters a terminal error
> > like -EROFS. This causes the thread to loop forever.
> >
> > Fix this by breaking out of the loop if nilfs_segctor_construct()
> > returns -EROFS. This matches the behaviour in
> > nilfs_segctor_write_out(), which also handles -EROFS.
> >
> > Reported-by: [email protected]
> > Closes: https://syzkaller.appspot.com/bug?extid=3Dcae54346a70bbceeff2c
> > Fixes: 9ff05123e3bf ("nilfs2: segment constructor")
> > Assisted-by: gemini:gemini-3.1-pro
> > Signed-off-by: Joshua Crofts <[email protected]>
> > ---
> > As much as I've tried, syzbot is unable to test this and always fails
> > with "FATAL: Kernel too old". Nevertheless, I've tested the patch with
> > the same reproducer in QEMU and the system didn't hang. =20
>=20
> Thanks for the patch, Joshua!
> This fix correctly addresses the issue reported by syzbot.
>=20
> I have one request regarding the loop exit:
> Could you modify the patch to jump to the out_unlock label instead of
> using break?
> This is to prevent discard commands from being sent to the underlying
> block device when the operation has failed and the filesystem state
> has degraded to read-only.

Yes, no problem, that makes more sense. Will send a new version in a bit.

--=20
Kind regards,
Joshua Crofts