WARNING in __btrfs_unlink_inode

13 views
Skip to first unread message

syzbot

unread,
Mar 7, 2023, 1:13:40 AM3/7/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3f8a27f9e27b Linux 4.19.211
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=110b0fc4c80000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b9277b418617afe
dashboard link: https://syzkaller.appspot.com/bug?extid=c81af59d5b78cf13563b
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/98c0bdb4abb3/disk-3f8a27f9.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/ea228ff02669/vmlinux-3f8a27f9.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c81af5...@syzkaller.appspotmail.com

RBP: 00007f8afefb01d0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001
R13: 00007ffddf9b456f R14: 00007f8afefb0300 R15: 0000000000022000
------------[ cut here ]------------
WARNING: CPU: 0 PID: 20674 at fs/btrfs/inode.c:4058 __btrfs_unlink_inode+0xaef/0xc60 fs/btrfs/inode.c:4058
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 20674 Comm: syz-executor.3 Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2ef lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
__warn.cold+0x20/0x5a kernel/panic.c:541
report_bug+0x262/0x2b0 lib/bug.c:183
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1d7/0x310 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1038
RIP: 0010:__btrfs_unlink_inode+0xaef/0xc60 fs/btrfs/inode.c:4058
Code: 79 fe 8b 85 28 ff ff ff 83 f8 fb 0f 84 6a ad 11 05 e8 b5 bf 79 fe 8b 85 28 ff ff ff 48 c7 c7 40 c3 a4 88 89 c6 e8 86 f7 09 05 <0f> 0b 8b 85 28 ff ff ff 89 85 28 ff ff ff e8 8e bf 79 fe 8b 85 28
RSP: 0018:ffff88803e58fc60 EFLAGS: 00010282
RAX: 0000000000000000 RBX: ffff8880a1fc6400 RCX: 0000000000000000
RDX: 0000000000040000 RSI: ffffffff814dff01 RDI: ffffed1007cb1f7e
RBP: ffff88803e58fd78 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000005 R11: 0000000000000000 R12: ffff8880b488e630
R13: ffff88803ac8e398 R14: 0000000000000007 R15: 0000000000000100
btrfs_unlink_inode fs/btrfs/inode.c:4096 [inline]
btrfs_unlink+0x157/0x2d0 fs/btrfs/inode.c:4140
vfs_unlink+0x27d/0x4e0 fs/namei.c:4002
do_unlinkat+0x3b8/0x660 fs/namei.c:4065
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7f8b00a3e0f9
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 19 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f8afefb0168 EFLAGS: 00000246 ORIG_RAX: 0000000000000057
RAX: ffffffffffffffda RBX: 00007f8b00b5df80 RCX: 00007f8b00a3e0f9
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000020000380
RBP: 00007f8afefb01d0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001
R13: 00007ffddf9b456f R14: 00007f8afefb0300 R15: 0000000000022000
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Mar 7, 2023, 1:55:40 AM3/7/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 3f8a27f9e27b Linux 4.19.211
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=105e1798c80000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b9277b418617afe
dashboard link: https://syzkaller.appspot.com/bug?extid=c81af59d5b78cf13563b
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=147521f4c80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=14641670c80000
mounted in repro: https://storage.googleapis.com/syzbot-assets/45aafcb1804a/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+c81af5...@syzkaller.appspotmail.com

RDX: 00000000000009a0 RSI: 000000000000ffc2 RDI: 0000000020000380
RBP: 00007ffe602f39a0 R08: 0000000000000001 R09: 00007ffe602f39b0
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000005
R13: 00007ffe602f39e0 R14: 00007ffe602f39c0 R15: 0000000000000000
------------[ cut here ]------------
WARNING: CPU: 0 PID: 8086 at fs/btrfs/inode.c:4058 __btrfs_unlink_inode+0xaef/0xc60 fs/btrfs/inode.c:4058
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 8086 Comm: syz-executor136 Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2ef lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
__warn.cold+0x20/0x5a kernel/panic.c:541
report_bug+0x262/0x2b0 lib/bug.c:183
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1d7/0x310 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1038
RIP: 0010:__btrfs_unlink_inode+0xaef/0xc60 fs/btrfs/inode.c:4058
Code: 79 fe 8b 85 28 ff ff ff 83 f8 fb 0f 84 6a ad 11 05 e8 b5 bf 79 fe 8b 85 28 ff ff ff 48 c7 c7 40 c3 a4 88 89 c6 e8 86 f7 09 05 <0f> 0b 8b 85 28 ff ff ff 89 85 28 ff ff ff e8 8e bf 79 fe 8b 85 28
RSP: 0018:ffff888094c4fc60 EFLAGS: 00010282
RAX: 0000000000000000 RBX: ffff88808cbfe000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffffffff814dff01 RDI: ffffed1012989f7e
RBP: ffff888094c4fd78 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000005 R11: 0000000000000000 R12: ffff8880ade91e70
R13: ffff88808cbccec0 R14: 0000000000000007 R15: 0000000000000100
btrfs_unlink_inode fs/btrfs/inode.c:4096 [inline]
btrfs_unlink+0x157/0x2d0 fs/btrfs/inode.c:4140
vfs_unlink+0x27d/0x4e0 fs/namei.c:4002
do_unlinkat+0x3b8/0x660 fs/namei.c:4065
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7ff70f650a09
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 11 15 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffe602f3978 EFLAGS: 00000246 ORIG_RAX: 0000000000000057
RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 00007ff70f650a09
RDX: 00000000000009a0 RSI: 000000000000ffc2 RDI: 0000000020000380
RBP: 00007ffe602f39a0 R08: 0000000000000001 R09: 00007ffe602f39b0
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000005
R13: 00007ffe602f39e0 R14: 00007ffe602f39c0 R15: 0000000000000000

syzbot

unread,
Mar 7, 2023, 2:22:57 AM3/7/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 7878a41b6cc1 Linux 4.14.307
git tree: linux-4.14.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1316c19cc80000
kernel config: https://syzkaller.appspot.com/x/.config?x=77c994a24403ce1c
dashboard link: https://syzkaller.appspot.com/bug?extid=2112d28c84a15a531798
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1224526cc80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16a1fbb0c80000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/1fdebf709d79/disk-7878a41b.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/88229e373f4d/vmlinux-7878a41b.xz
kernel image: https://storage.googleapis.com/syzbot-assets/bf3c4c287a8b/bzImage-7878a41b.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/c64acdbf7f69/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+2112d2...@syzkaller.appspotmail.com

RDX: 00000000000004c0 RSI: 000000000000ffc2 RDI: 0000000020000380
RBP: 00007ffccdfb34c0 R08: 0000000000000001 R09: 00007ffccdfb34d0
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000005
R13: 00007ffccdfb3500 R14: 00007ffccdfb34e0 R15: 0000000000000000
------------[ cut here ]------------
WARNING: CPU: 1 PID: 7962 at fs/btrfs/inode.c:4215 __btrfs_unlink_inode.cold+0x159/0x19c fs/btrfs/inode.c:4215
Kernel panic - not syncing: kernel: panic_on_warn set ...

CPU: 1 PID: 7962 Comm: syz-executor386 Not tainted 4.14.307-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
Call Trace:
__dump_stack lib/dump_stack.c:17 [inline]
dump_stack+0x1b2/0x281 lib/dump_stack.c:58
panic+0x21d/0x451 kernel/panic.c:247
check_panic_on_warn.cold+0x19/0x35 kernel/panic.c:171
__warn+0xdf/0x1e0 kernel/panic.c:603
report_bug+0x208/0x250 lib/bug.c:183
fixup_bug arch/x86/kernel/traps.c:177 [inline]
fixup_bug arch/x86/kernel/traps.c:172 [inline]
do_error_trap+0x195/0x2d0 arch/x86/kernel/traps.c:295
invalid_op+0x1b/0x40 arch/x86/entry/entry_64.S:967
RIP: 0010:__btrfs_unlink_inode.cold+0x159/0x19c fs/btrfs/inode.c:4215
RSP: 0018:ffff888095867c78 EFLAGS: 00010282
RAX: 0000000000000026 RBX: ffff88808cb79080 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffffffff878bd360 RDI: ffffed1012b0cf85
RBP: ffff888095867d68 R08: 0000000000000026 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: ffff88808cb7be08
R13: ffff8880a14809a0 R14: ffff888095908200 R15: 0000000000000007
btrfs_unlink_inode fs/btrfs/inode.c:4253 [inline]
btrfs_unlink+0x147/0x2a0 fs/btrfs/inode.c:4297
vfs_unlink+0x230/0x470 fs/namei.c:4029
do_unlinkat+0x30c/0x5c0 fs/namei.c:4094
do_syscall_64+0x1d5/0x640 arch/x86/entry/common.c:292
entry_SYSCALL_64_after_hwframe+0x5e/0xd3
RIP: 0033:0x7f3cd4703a09
RSP: 002b:00007ffccdfb3498 EFLAGS: 00000246 ORIG_RAX: 0000000000000057
RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 00007f3cd4703a09
RDX: 00000000000004c0 RSI: 000000000000ffc2 RDI: 0000000020000380
RBP: 00007ffccdfb34c0 R08: 0000000000000001 R09: 00007ffccdfb34d0
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000005
R13: 00007ffccdfb3500 R14: 00007ffccdfb34e0 R15: 0000000000000000
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages