Re: [PATCH] nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch

Ryusuke Konishi <[email protected]> Tue, 28 Jul 2026 13:32:13 +0900
Newsgroups org.kernel.vger.linux-nilfs,org.kernel.vger.linux-kernel
Message-ID <CAKFNMonu620z87=b=+9Xwn44Zr9-CssQkn=mes5EqEc=iJUm0g@mail.gmail.com>
On Mon, Jul 20, 2026 at 11:17=E2=80=AFPM Ryusuke Konishi wrote:
>
> Syzbot reported a kernel BUG triggered within nilfs_copy_dirty_pages(),
> which copies dirty DAT file folios/pages to its shadow page cache.  The
> BUG occurs when a retrieved dirty folio/page unexpectedly loses its
> 'dirty' status.
>
> This issue arises because, since the commit referenced below, the 'dirty'
> flag of a folio/page can be cleared asynchronously after the filesystem
> detects metadata corruption and transitions to read-only mode.
>
> Resolve the issue by returning an -EROFS error if the filesystem has
> transitioned to read-only mode.  Also change the behavior to issue a
> kernel warning only once instead of triggering a kernel BUG when this
> unexpected 'dirty' state is detected while the filesystem is not in
> read-only mode.
>
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=3D8baf9a79a3ffc6271cb6
> Fixes: 8c26c4e2694a ("nilfs2: fix issue with flush kernel thread after re=
mount in RO mode because of driver's internal error or metadata corruption"=
)
> Signed-off-by: Ryusuke Konishi <[email protected]>
> ---
> Viacheslav, please apply this for the next cycle.
>
> This fixes an issue reported by syzbot where a kernel BUG could be
> triggered depending on timing after filesystem corruption is detected.
>
> Thanks,
> Ryusuke Konishi
>
>  fs/nilfs2/page.c | 17 +++++++++++++++--
>  1 file changed, 15 insertions(+), 2 deletions(-)
>
> diff --git a/fs/nilfs2/page.c b/fs/nilfs2/page.c
> index a9d8aa65416f..1d00bce21c37 100644
> --- a/fs/nilfs2/page.c
> +++ b/fs/nilfs2/page.c
> @@ -243,6 +243,7 @@ static void nilfs_copy_folio(struct folio *dst, struc=
t folio *src,
>  int nilfs_copy_dirty_pages(struct address_space *dmap,
>                            struct address_space *smap)
>  {
> +       struct inode *smap_inode =3D smap->host;
>         struct folio_batch fbatch;
>         unsigned int i;
>         pgoff_t index =3D 0;
> @@ -258,8 +259,19 @@ int nilfs_copy_dirty_pages(struct address_space *dma=
p,
>                 struct folio *folio =3D fbatch.folios[i], *dfolio;
>
>                 folio_lock(folio);
> -               if (unlikely(!folio_test_dirty(folio)))
> -                       NILFS_FOLIO_BUG(folio, "inconsistent dirty state"=
);
> +               if (unlikely(!folio_test_dirty(folio))) {
> +                       if (WARN_ONCE(!sb_rdonly(smap_inode->i_sb),
> +                                       "inconsistent dirty state\n"))
> +                               goto unlock_folio;
> +
> +                       /*
> +                        * If the filesystem has been forced to read-only
> +                        * due to metadata corruption.
> +                        */
> +                       folio_unlock(folio);
> +                       err =3D -EROFS;
> +                       break;
> +               }
>
>                 dfolio =3D filemap_grab_folio(dmap, folio->index);
>                 if (IS_ERR(dfolio)) {
> @@ -277,6 +289,7 @@ int nilfs_copy_dirty_pages(struct address_space *dmap=
,
>
>                 folio_unlock(dfolio);
>                 folio_put(dfolio);
> +unlock_folio:
>                 folio_unlock(folio);
>         }
>         folio_batch_release(&fbatch);
> --
> 2.43.0
>

Hi Viacheslav,

Sorry for the disturbance while you are busy.

Could you please pick up the following four pending patches -
including this one - for the next cycle at your convenience?
Excluding those already applied, these are the ones submitted by me or
requested for direct pick-up since the weekend before last:

- [PATCH] nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate
after truncation
- [PATCH v2] nilfs2: fix infinite loop in nilfs_clean_segments()
- [PATCH] nilfs2: prevent out-of-bounds read in super root block parsing
- [PATCH] nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismat=
ch

Thanks,
Ryusuke Konishi