[v5.15] WARNING in btrfs_space_info_update_bytes_may_use

0 views
Skip to first unread message

syzbot

unread,
Apr 7, 2023, 4:54:48 PM4/7/23
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: d86dfc4d95cd Linux 5.15.106
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=17a6ab1bc80000
kernel config: https://syzkaller.appspot.com/x/.config?x=639d55ab480652c5
dashboard link: https://syzkaller.appspot.com/bug?extid=49f99b4e95c9e4a5516d
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/b2a94107dd69/disk-d86dfc4d.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/398f8d288cb9/vmlinux-d86dfc4d.xz
kernel image: https://storage.googleapis.com/syzbot-assets/9b790c7e7c8c/Image-d86dfc4d.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+49f99b...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 4106 at fs/btrfs/space-info.h:110 btrfs_space_info_update_bytes_may_use+0x2c0/0x704
Modules linked in:
CPU: 1 PID: 4106 Comm: syz-executor.1 Not tainted 5.15.106-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : btrfs_space_info_update_bytes_may_use+0x2c0/0x704
lr : btrfs_space_info_update_bytes_may_use+0x2bc/0x704
sp : ffff80001cdc7660
x29: ffff80001cdc7670 x28: ffff0001302d8280 x27: 1fffe0001b0e280c
x26: dfff800000000000 x25: ffff8000148cd310 x24: 0000000000000002
x23: 0000000000000005 x22: 00000000000cf000 x21: 00000000000d0000
x20: ffff0000d8714060 x19: 0000000000000000 x18: 0000000000000000
x17: ff8080000a202b28 x16: ffff800011940934 x15: ffff80000a202b28
x14: 1ffff0000291a06a x13: ffffffffffffffff x12: 0000000000000000
x11: ff8080000a1ea0e0 x10: 0000000000000000 x9 : ffff80000a1ea0e0
x8 : ffff0000cd051ac0 x7 : ffff80000a1e92c4 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff8000083021e0
x2 : fffffffffff30000 x1 : 00000000000d0000 x0 : 00000000000cf000
Call trace:
btrfs_space_info_update_bytes_may_use+0x2c0/0x704
btrfs_space_info_free_bytes_may_use fs/btrfs/space-info.h:142 [inline]
block_rsv_release_bytes fs/btrfs/block-rsv.c:150 [inline]
btrfs_block_rsv_release+0x2e4/0x478 fs/btrfs/block-rsv.c:294
btrfs_release_global_block_rsv+0x38/0x22c fs/btrfs/block-rsv.c:450
btrfs_free_block_groups+0x7e0/0xb54 fs/btrfs/block-group.c:3922
close_ctree+0x61c/0x860 fs/btrfs/disk-io.c:4481
btrfs_put_super+0x40/0x50 fs/btrfs/super.c:340
generic_shutdown_super+0x130/0x29c fs/super.c:475
kill_anon_super+0x4c/0x74 fs/super.c:1067
btrfs_kill_super+0x40/0x58 fs/btrfs/super.c:2393
deactivate_locked_super+0xb8/0x13c fs/super.c:335
deactivate_super+0x108/0x128 fs/super.c:366
cleanup_mnt+0x3c0/0x474 fs/namespace.c:1143
__cleanup_mnt+0x20/0x30 fs/namespace.c:1150
task_work_run+0x130/0x1e4 kernel/task_work.c:164
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
do_notify_resume+0x262c/0x32b8 arch/arm64/kernel/signal.c:946
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:133 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:138 [inline]
el0_svc+0xfc/0x1f0 arch/arm64/kernel/entry-common.c:597
el0t_64_sync_handler+0x84/0xe4 arch/arm64/kernel/entry-common.c:614
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584
irq event stamp: 5362424
hardirqs last enabled at (5362423): [<ffff8000088c48d4>] kasan_quarantine_put+0xdc/0x204 mm/kasan/quarantine.c:231
hardirqs last disabled at (5362424): [<ffff80001193bfc8>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:387
softirqs last enabled at (5360830): [<ffff800008030068>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:31
softirqs last disabled at (5360828): [<ffff800008030034>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:18
---[ end trace 5c84f2ee2e22623e ]---
------------[ cut here ]------------
WARNING: CPU: 1 PID: 4106 at fs/btrfs/space-info.h:110 btrfs_space_info_update_bytes_may_use+0x2c0/0x704
Modules linked in:
CPU: 1 PID: 4106 Comm: syz-executor.1 Tainted: G W 5.15.106-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : btrfs_space_info_update_bytes_may_use+0x2c0/0x704
lr : btrfs_space_info_update_bytes_may_use+0x2bc/0x704
sp : ffff80001cdc7660
x29: ffff80001cdc7670 x28: ffff00012f700280 x27: 1fffe000193bfb0c
x26: dfff800000000000 x25: ffff8000148cd310 x24: 0000000000000002
x23: 0000000000000005 x22: 00000000000cf000 x21: 00000000000d0000
x20: ffff0000c9dfd860 x19: 0000000000000000 x18: 0000000000000000
x17: ff8080000a202b28 x16: ffff800011940934 x15: ffff80000a202b28
x14: 1ffff0000291a06a x13: ffffffffffffffff x12: 0000000000000000
x11: ff8080000a1ea0e0 x10: 0000000000000000 x9 : ffff80000a1ea0e0
x8 : ffff0000cd051ac0 x7 : ffff80000a1e92c4 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff8000083021e0
x2 : fffffffffff30000 x1 : 00000000000d0000 x0 : 00000000000cf000
Call trace:
btrfs_space_info_update_bytes_may_use+0x2c0/0x704
btrfs_space_info_free_bytes_may_use fs/btrfs/space-info.h:142 [inline]
block_rsv_release_bytes fs/btrfs/block-rsv.c:150 [inline]
btrfs_block_rsv_release+0x2e4/0x478 fs/btrfs/block-rsv.c:294
btrfs_release_global_block_rsv+0x38/0x22c fs/btrfs/block-rsv.c:450
btrfs_free_block_groups+0x7e0/0xb54 fs/btrfs/block-group.c:3922
close_ctree+0x61c/0x860 fs/btrfs/disk-io.c:4481
btrfs_put_super+0x40/0x50 fs/btrfs/super.c:340
generic_shutdown_super+0x130/0x29c fs/super.c:475
kill_anon_super+0x4c/0x74 fs/super.c:1067
btrfs_kill_super+0x40/0x58 fs/btrfs/super.c:2393
deactivate_locked_super+0xb8/0x13c fs/super.c:335
deactivate_super+0x108/0x128 fs/super.c:366
cleanup_mnt+0x3c0/0x474 fs/namespace.c:1143
__cleanup_mnt+0x20/0x30 fs/namespace.c:1150
task_work_run+0x130/0x1e4 kernel/task_work.c:164
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
do_notify_resume+0x262c/0x32b8 arch/arm64/kernel/signal.c:946
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:133 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:138 [inline]
el0_svc+0xfc/0x1f0 arch/arm64/kernel/entry-common.c:597
el0t_64_sync_handler+0x84/0xe4 arch/arm64/kernel/entry-common.c:614
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584
irq event stamp: 5403246
hardirqs last enabled at (5403245): [<ffff8000088c48d4>] kasan_quarantine_put+0xdc/0x204 mm/kasan/quarantine.c:231
hardirqs last disabled at (5403246): [<ffff80001193bfc8>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:387
softirqs last enabled at (5403068): [<ffff800008020ccc>] softirq_handle_end kernel/softirq.c:401 [inline]
softirqs last enabled at (5403068): [<ffff800008020ccc>] __do_softirq+0xb5c/0xe20 kernel/softirq.c:587
softirqs last disabled at (5403055): [<ffff8000081b56e0>] do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
softirqs last disabled at (5403055): [<ffff8000081b56e0>] invoke_softirq kernel/softirq.c:439 [inline]
softirqs last disabled at (5403055): [<ffff8000081b56e0>] __irq_exit_rcu+0x28c/0x534 kernel/softirq.c:636
---[ end trace 5c84f2ee2e22623f ]---
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4106 at fs/btrfs/space-info.h:110 btrfs_space_info_update_bytes_may_use+0x2c0/0x704
Modules linked in:
CPU: 0 PID: 4106 Comm: syz-executor.1 Tainted: G W 5.15.106-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : btrfs_space_info_update_bytes_may_use+0x2c0/0x704
lr : btrfs_space_info_update_bytes_may_use+0x2bc/0x704
sp : ffff80001cdc7660
x29: ffff80001cdc7670 x28: ffff000126758280 x27: 1fffe00019a07f0c
x26: dfff800000000000 x25: ffff8000148cd310 x24: 0000000000000001
x23: 0000000000000005 x22: 00000000000cf000 x21: 00000000000d0000
x20: ffff0000cd03f860 x19: 0000000000000000 x18: 0000000000000000
x17: ff8080000a202b28 x16: ffff800011940934 x15: ffff80000a202b28
x14: 1ffff0000291a06a x13: ffffffffffffffff x12: 0000000000000000
x11: ff8080000a1ea0e0 x10: 0000000000000000 x9 : ffff80000a1ea0e0
x8 : ffff0000cd051ac0 x7 : ffff80000a1e92c4 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff8000083021e0
x2 : fffffffffff30000 x1 : 00000000000d0000 x0 : 00000000000cf000
Call trace:
btrfs_space_info_update_bytes_may_use+0x2c0/0x704
btrfs_space_info_free_bytes_may_use fs/btrfs/space-info.h:142 [inline]
block_rsv_release_bytes fs/btrfs/block-rsv.c:150 [inline]
btrfs_block_rsv_release+0x2e4/0x478 fs/btrfs/block-rsv.c:294
btrfs_release_global_block_rsv+0x38/0x22c fs/btrfs/block-rsv.c:450
btrfs_free_block_groups+0x7e0/0xb54 fs/btrfs/block-group.c:3922
close_ctree+0x61c/0x860 fs/btrfs/disk-io.c:4481
btrfs_put_super+0x40/0x50 fs/btrfs/super.c:340
generic_shutdown_super+0x130/0x29c fs/super.c:475
kill_anon_super+0x4c/0x74 fs/super.c:1067
btrfs_kill_super+0x40/0x58 fs/btrfs/super.c:2393
deactivate_locked_super+0xb8/0x13c fs/super.c:335
deactivate_super+0x108/0x128 fs/super.c:366
cleanup_mnt+0x3c0/0x474 fs/namespace.c:1143
__cleanup_mnt+0x20/0x30 fs/namespace.c:1150
task_work_run+0x130/0x1e4 kernel/task_work.c:164
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
do_notify_resume+0x262c/0x32b8 arch/arm64/kernel/signal.c:946
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:133 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:138 [inline]
el0_svc+0xfc/0x1f0 arch/arm64/kernel/entry-common.c:597
el0t_64_sync_handler+0x84/0xe4 arch/arm64/kernel/entry-common.c:614
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584
irq event stamp: 5440528
hardirqs last enabled at (5440527): [<ffff8000088c48d4>] kasan_quarantine_put+0xdc/0x204 mm/kasan/quarantine.c:231
hardirqs last disabled at (5440528): [<ffff80001193bfc8>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:387
softirqs last enabled at (5439740): [<ffff800008020ccc>] softirq_handle_end kernel/softirq.c:401 [inline]
softirqs last enabled at (5439740): [<ffff800008020ccc>] __do_softirq+0xb5c/0xe20 kernel/softirq.c:587
softirqs last disabled at (5439727): [<ffff8000081b56e0>] do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
softirqs last disabled at (5439727): [<ffff8000081b56e0>] invoke_softirq kernel/softirq.c:439 [inline]
softirqs last disabled at (5439727): [<ffff8000081b56e0>] __irq_exit_rcu+0x28c/0x534 kernel/softirq.c:636
---[ end trace 5c84f2ee2e226240 ]---


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Apr 30, 2023, 6:30:55 PM4/30/23
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: f48aeeaaa64c Linux 5.15.109
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=10c8b5dbc80000
kernel config: https://syzkaller.appspot.com/x/.config?x=f0ea19992afd55ad
dashboard link: https://syzkaller.appspot.com/bug?extid=49f99b4e95c9e4a5516d
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1553ea44280000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16d8df84280000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/fd82b060cee7/disk-f48aeeaa.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/b216234bd1a0/vmlinux-f48aeeaa.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c0609f7a6703/bzImage-f48aeeaa.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/e1f84d004fd5/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+49f99b...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 3535 at fs/btrfs/space-info.h:110 btrfs_space_info_update_bytes_may_use+0x294/0x5c0
Modules linked in:
CPU: 0 PID: 3535 Comm: syz-executor303 Not tainted 5.15.109-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023
RIP: 0010:btrfs_space_info_update_bytes_may_use+0x294/0x5c0 fs/btrfs/space-info.h:110
Code: 25 00 00 74 08 4c 89 ff e8 59 84 49 fe 49 8b 1f 48 89 df 48 8b 6c 24 18 48 89 ee e8 f6 2b 00 fe 48 39 eb 73 14 e8 0c 2a 00 fe <0f> 0b 45 31 f6 43 80 7c 25 00 00 75 ac eb b2 e8 f8 29 00 fe 43 80
RSP: 0018:ffffc90002d1fb40 EFLAGS: 00010293
RAX: ffffffff837fb474 RBX: 00000000000cf000 RCX: ffff88801ea2d700
RDX: 0000000000000000 RSI: 00000000000d0000 RDI: 00000000000cf000
RBP: 00000000000d0000 R08: ffffffff837fb46a R09: fffffbfff1bc7466
R10: 0000000000000000 R11: dffffc0000000001 R12: dffffc0000000000
R13: 1ffff11028ee820c R14: fffffffffff30000 R15: ffff888147741060
FS: 0000555556daa300(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ffea4528f88 CR3: 00000000190bd000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
btrfs_space_info_free_bytes_may_use fs/btrfs/space-info.h:142 [inline]
block_rsv_release_bytes fs/btrfs/block-rsv.c:150 [inline]
btrfs_block_rsv_release+0x444/0x530 fs/btrfs/block-rsv.c:294
btrfs_release_global_block_rsv+0x2f/0x250 fs/btrfs/block-rsv.c:450
btrfs_free_block_groups+0x8ab/0xc90 fs/btrfs/block-group.c:3922
close_ctree+0x6d6/0x886 fs/btrfs/disk-io.c:4498
generic_shutdown_super+0x136/0x2c0 fs/super.c:475
kill_anon_super+0x37/0x60 fs/super.c:1067
btrfs_kill_super+0x3d/0x50 fs/btrfs/super.c:2391
deactivate_locked_super+0xa0/0x110 fs/super.c:335
cleanup_mnt+0x44e/0x500 fs/namespace.c:1143
task_work_run+0x129/0x1a0 kernel/task_work.c:164
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
exit_to_user_mode_loop+0x106/0x130 kernel/entry/common.c:175
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:208
__syscall_exit_to_user_mode_work kernel/entry/common.c:290 [inline]
syscall_exit_to_user_mode+0x5d/0x250 kernel/entry/common.c:301
do_syscall_64+0x49/0xb0 arch/x86/entry/common.c:86
entry_SYSCALL_64_after_hwframe+0x61/0xcb
RIP: 0033:0x7f707f71fe67
Code: 07 00 48 83 c4 08 5b 5d c3 66 2e 0f 1f 84 00 00 00 00 00 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 b8 a6 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffea4529758 EFLAGS: 00000202 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00007f707f71fe67
RDX: 00007ffea4529819 RSI: 000000000000000a RDI: 00007ffea4529810
RBP: 00007ffea4529810 R08: 00000000ffffffff R09: 00007ffea45295f0
R10: 0000555556dab653 R11: 0000000000000202 R12: 00007ffea452a890
R13: 0000555556dab5f0 R14: 00007ffea4529780 R15: 0000000000000002
</TASK>


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
Reply all
Reply to author
Forward
0 new messages