[v6.1] WARNING in xfs_bmapi_convert_delalloc

1 view
Skip to first unread message

syzbot

unread,
May 18, 2023, 10:29:50 AM5/18/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: fa74641fb6b9 Linux 6.1.29
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=152f9509280000
kernel config: https://syzkaller.appspot.com/x/.config?x=7454aa89ac475d7b
dashboard link: https://syzkaller.appspot.com/bug?extid=03a3f365d3150f0355cc
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=17874141280000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=144e865a280000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/53e4da6b145c/disk-fa74641f.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/adeb1a2cfa86/vmlinux-fa74641f.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c976f1155d08/Image-fa74641f.gz.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/7198d3be548d/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+03a3f3...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 9 at fs/xfs/libxfs/xfs_bmap.c:4592 xfs_bmapi_convert_delalloc+0xd50/0x10b0 fs/xfs/libxfs/xfs_bmap.c:4592
Modules linked in:
CPU: 1 PID: 9 Comm: kworker/u4:0 Not tainted 6.1.29-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023
Workqueue: writeback wb_workfn (flush-7:0)
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : xfs_bmapi_convert_delalloc+0xd50/0x10b0 fs/xfs/libxfs/xfs_bmap.c:4592
lr : xfs_bmapi_convert_delalloc+0xd50/0x10b0 fs/xfs/libxfs/xfs_bmap.c:4592
sp : ffff800019b667c0
x29: ffff800019b669c0 x28: ffff0000ceff4000 x27: dfff800000000000
x26: 0000000000000000 x25: ffff800019b66900 x24: dfff800000000000
x23: ffff70000336cd0c x22: ffffffffffffffff x21: ffff800019b66980
x20: 0000000000000000 x19: ffff0000e00026c0 x18: ffff800019b66460
x17: ffff80019f0e0000 x16: ffff8000120ec854 x15: 0000000000000000
x14: 1ffff00002ab40b0 x13: dfff800000000000 x12: 0000000000000001
x11: ff80800009a8d938 x10: 0000000000000000 x9 : ffff800009a8d938
x8 : ffff0000c0998000 x7 : 0000000000000000 x6 : 000000000000003f
x5 : 0000000000000040 x4 : 0000000000000000 x3 : ffff800009a348a8
x2 : 0000000000000001 x1 : ffffffffffffffff x0 : ffffffffffffffff
Call trace:
xfs_bmapi_convert_delalloc+0xd50/0x10b0 fs/xfs/libxfs/xfs_bmap.c:4592
xfs_convert_blocks fs/xfs/xfs_aops.c:259 [inline]
xfs_map_blocks+0x85c/0x1464 fs/xfs/xfs_aops.c:380
iomap_writepage_map fs/iomap/buffered-io.c:1360 [inline]
iomap_do_writepage+0x7f4/0x2364 fs/iomap/buffered-io.c:1523
write_cache_pages+0x7fc/0xf60 mm/page-writeback.c:2360
iomap_writepages+0x6c/0x1f4 fs/iomap/buffered-io.c:1540
xfs_vm_writepages+0x124/0x180 fs/xfs/xfs_aops.c:500
do_writepages+0x2e8/0x56c mm/page-writeback.c:2469
__writeback_single_inode+0x16c/0x1770 fs/fs-writeback.c:1590
writeback_sb_inodes+0x978/0x16c0 fs/fs-writeback.c:1881
wb_writeback+0x414/0x1130 fs/fs-writeback.c:2055
wb_do_writeback fs/fs-writeback.c:2198 [inline]
wb_workfn+0x3a8/0x1034 fs/fs-writeback.c:2238
process_one_work+0x7ac/0x1404 kernel/workqueue.c:2289
worker_thread+0x8e4/0xfec kernel/workqueue.c:2436
kthread+0x250/0x2d8 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860
irq event stamp: 299400
hardirqs last enabled at (299399): [<ffff80000b70de64>] get_random_u32+0x34c/0x658 drivers/char/random.c:513
hardirqs last disabled at (299400): [<ffff8000120e850c>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (299336): [<ffff800010427990>] neigh_managed_work+0x1e0/0x21c net/core/neighbour.c:1638
softirqs last disabled at (299332): [<ffff8000104277f0>] neigh_managed_work+0x40/0x21c net/core/neighbour.c:1633
---[ end trace 0000000000000000 ]---
XFS (loop0): page discard on page 00000000e900277c, inode 0x2b, pos 0.
XFS (loop0): page discard on page 000000002ff9fc8b, inode 0x2b, pos 4096.
XFS (loop0): page discard on page 00000000af0efda5, inode 0x2b, pos 8192.
XFS (loop0): page discard on page 00000000e3661837, inode 0x2b, pos 12288.
XFS (loop0): page discard on page 0000000038e7a3e4, inode 0x2b, pos 16384.
XFS (loop0): page discard on page 000000003d02f8b6, inode 0x2b, pos 20480.
XFS (loop0): page discard on page 00000000dea82b9c, inode 0x2b, pos 24576.
XFS (loop0): page discard on page 00000000749686c4, inode 0x2b, pos 28672.
XFS (loop0): page discard on page 0000000060856c2c, inode 0x2b, pos 32768.
XFS (loop0): page discard on page 000000009935e000, inode 0x2b, pos 36864.


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to change bug's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the bug is a duplicate of another bug, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
May 19, 2023, 2:30:49 AM5/19/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 9d6bde853685 Linux 5.15.112
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1469482e280000
kernel config: https://syzkaller.appspot.com/x/.config?x=508f7a387ef8f82b
dashboard link: https://syzkaller.appspot.com/bug?extid=84aa637d463d7fdfc2b4
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11e4090e280000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1310a90e280000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/a8ab2bd416bb/disk-9d6bde85.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/c358e3d58bb2/vmlinux-9d6bde85.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c82319bbaeb8/Image-9d6bde85.gz.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/b7502cc365f1/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+84aa63...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 153 at fs/xfs/libxfs/xfs_bmap.c:4641 xfs_bmapi_convert_delalloc+0xcec/0x1018
Modules linked in:
CPU: 0 PID: 153 Comm: kworker/u4:3 Not tainted 5.15.112-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023
Workqueue: writeback wb_workfn (flush-7:0)
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : xfs_bmapi_convert_delalloc+0xcec/0x1018
lr : xfs_bmapi_convert_delalloc+0xce8/0x1018 fs/xfs/libxfs/xfs_bmap.c:4641
sp : ffff80001a8867c0
x29: ffff80001a8869c0 x28: ffff0000d77d8000 x27: dfff800000000000
x26: ffff80001a886860 x25: 1ffff00003510d1b x24: 00000000ffffffe4
x23: ffff700003510d0c x22: ffffffffffffffff x21: ffff80001a886980
x20: 0000000000000000 x19: ffff80001a8868a0 x18: 0000000000000000
x17: ff80800009960bcc x16: ffff80001194786c x15: ffff800009960bcc
x14: 1ffff0000291a06a x13: ffffffffffffffff x12: 0000000000000000
x11: ff808000099a6084 x10: 0000000000000000 x9 : ffff8000099a6084
x8 : ffff0000c5f60000 x7 : 0000000000000000 x6 : 000000000000003f
x5 : 0000000000000040 x4 : ffffffffffffffe0 x3 : ffff80000994fce4
x2 : 0000000000000001 x1 : ffffffffffffffff x0 : ffffffffffffffff
Call trace:
xfs_bmapi_convert_delalloc+0xcec/0x1018
xfs_convert_blocks fs/xfs/xfs_aops.c:245 [inline]
xfs_map_blocks+0x858/0x1318 fs/xfs/xfs_aops.c:366
iomap_writepage_map fs/iomap/buffered-io.c:1320 [inline]
iomap_do_writepage+0x538/0x1db8 fs/iomap/buffered-io.c:1485
write_cache_pages+0x878/0xf58 mm/page-writeback.c:2255
iomap_writepages+0x6c/0x1f4 fs/iomap/buffered-io.c:1516
xfs_vm_writepages+0x124/0x180 fs/xfs/xfs_aops.c:488
do_writepages+0x39c/0x5ec mm/page-writeback.c:2364
__writeback_single_inode+0x148/0x13a4 fs/fs-writeback.c:1625
writeback_sb_inodes+0x94c/0x1620 fs/fs-writeback.c:1908
wb_writeback+0x3fc/0xfc8 fs/fs-writeback.c:2082
wb_do_writeback fs/fs-writeback.c:2225 [inline]
wb_workfn+0x3a4/0x1070 fs/fs-writeback.c:2266
process_one_work+0x790/0x11b8 kernel/workqueue.c:2307
worker_thread+0x910/0x1034 kernel/workqueue.c:2454
kthread+0x37c/0x45c kernel/kthread.c:319
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:870
irq event stamp: 672658
hardirqs last enabled at (672657): [<ffff800011a1bba0>] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:160 [inline]
hardirqs last enabled at (672657): [<ffff800011a1bba0>] _raw_spin_unlock_irqrestore+0xac/0x158 kernel/locking/spinlock.c:194
hardirqs last disabled at (672658): [<ffff800011942f00>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:387
softirqs last enabled at (672538): [<ffff800009ab97c0>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:31
softirqs last disabled at (672536): [<ffff800009ab978c>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:18
---[ end trace 03d93e4566892b4d ]---
XFS (loop0): page discard on page 0000000048f9ec32, inode 0x2b, offset 0.
XFS (loop0): page discard on page 0000000047f4e6c3, inode 0x2b, offset 4096.
XFS (loop0): page discard on page 00000000c4303a7f, inode 0x2b, offset 8192.
XFS (loop0): page discard on page 000000009807846a, inode 0x2b, offset 12288.
XFS (loop0): page discard on page 00000000afb91032, inode 0x2b, offset 16384.
XFS (loop0): page discard on page 00000000e0622c16, inode 0x2b, offset 20480.
XFS (loop0): page discard on page 00000000a00f1fd6, inode 0x2b, offset 24576.
XFS (loop0): page discard on page 000000002d8ab8c0, inode 0x2b, offset 28672.
XFS (loop0): page discard on page 0000000025b1aba0, inode 0x2b, offset 32768.
XFS (loop0): page discard on page 000000001a6903b6, inode 0x2b, offset 36864.
Reply all
Reply to author
Forward
0 new messages