Hello,
syzbot found the following issue on:
HEAD commit: d86dfc4d95cd Linux 5.15.106
git tree: linux-5.15.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=17a6ab1bc80000
kernel config:
https://syzkaller.appspot.com/x/.config?x=639d55ab480652c5
dashboard link:
https://syzkaller.appspot.com/bug?extid=49f99b4e95c9e4a5516d
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/b2a94107dd69/disk-d86dfc4d.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/398f8d288cb9/vmlinux-d86dfc4d.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/9b790c7e7c8c/Image-d86dfc4d.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+49f99b...@syzkaller.appspotmail.com
------------[ cut here ]------------
WARNING: CPU: 1 PID: 4106 at fs/btrfs/space-info.h:110 btrfs_space_info_update_bytes_may_use+0x2c0/0x704
Modules linked in:
CPU: 1 PID: 4106 Comm: syz-executor.1 Not tainted 5.15.106-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : btrfs_space_info_update_bytes_may_use+0x2c0/0x704
lr : btrfs_space_info_update_bytes_may_use+0x2bc/0x704
sp : ffff80001cdc7660
x29: ffff80001cdc7670 x28: ffff0001302d8280 x27: 1fffe0001b0e280c
x26: dfff800000000000 x25: ffff8000148cd310 x24: 0000000000000002
x23: 0000000000000005 x22: 00000000000cf000 x21: 00000000000d0000
x20: ffff0000d8714060 x19: 0000000000000000 x18: 0000000000000000
x17: ff8080000a202b28 x16: ffff800011940934 x15: ffff80000a202b28
x14: 1ffff0000291a06a x13: ffffffffffffffff x12: 0000000000000000
x11: ff8080000a1ea0e0 x10: 0000000000000000 x9 : ffff80000a1ea0e0
x8 : ffff0000cd051ac0 x7 : ffff80000a1e92c4 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff8000083021e0
x2 : fffffffffff30000 x1 : 00000000000d0000 x0 : 00000000000cf000
Call trace:
btrfs_space_info_update_bytes_may_use+0x2c0/0x704
btrfs_space_info_free_bytes_may_use fs/btrfs/space-info.h:142 [inline]
block_rsv_release_bytes fs/btrfs/block-rsv.c:150 [inline]
btrfs_block_rsv_release+0x2e4/0x478 fs/btrfs/block-rsv.c:294
btrfs_release_global_block_rsv+0x38/0x22c fs/btrfs/block-rsv.c:450
btrfs_free_block_groups+0x7e0/0xb54 fs/btrfs/block-group.c:3922
close_ctree+0x61c/0x860 fs/btrfs/disk-io.c:4481
btrfs_put_super+0x40/0x50 fs/btrfs/super.c:340
generic_shutdown_super+0x130/0x29c fs/super.c:475
kill_anon_super+0x4c/0x74 fs/super.c:1067
btrfs_kill_super+0x40/0x58 fs/btrfs/super.c:2393
deactivate_locked_super+0xb8/0x13c fs/super.c:335
deactivate_super+0x108/0x128 fs/super.c:366
cleanup_mnt+0x3c0/0x474 fs/namespace.c:1143
__cleanup_mnt+0x20/0x30 fs/namespace.c:1150
task_work_run+0x130/0x1e4 kernel/task_work.c:164
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
do_notify_resume+0x262c/0x32b8 arch/arm64/kernel/signal.c:946
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:133 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:138 [inline]
el0_svc+0xfc/0x1f0 arch/arm64/kernel/entry-common.c:597
el0t_64_sync_handler+0x84/0xe4 arch/arm64/kernel/entry-common.c:614
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584
irq event stamp: 5362424
hardirqs last enabled at (5362423): [<ffff8000088c48d4>] kasan_quarantine_put+0xdc/0x204 mm/kasan/quarantine.c:231
hardirqs last disabled at (5362424): [<ffff80001193bfc8>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:387
softirqs last enabled at (5360830): [<ffff800008030068>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:31
softirqs last disabled at (5360828): [<ffff800008030034>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:18
---[ end trace 5c84f2ee2e22623e ]---
------------[ cut here ]------------
WARNING: CPU: 1 PID: 4106 at fs/btrfs/space-info.h:110 btrfs_space_info_update_bytes_may_use+0x2c0/0x704
Modules linked in:
CPU: 1 PID: 4106 Comm: syz-executor.1 Tainted: G W 5.15.106-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : btrfs_space_info_update_bytes_may_use+0x2c0/0x704
lr : btrfs_space_info_update_bytes_may_use+0x2bc/0x704
sp : ffff80001cdc7660
x29: ffff80001cdc7670 x28: ffff00012f700280 x27: 1fffe000193bfb0c
x26: dfff800000000000 x25: ffff8000148cd310 x24: 0000000000000002
x23: 0000000000000005 x22: 00000000000cf000 x21: 00000000000d0000
x20: ffff0000c9dfd860 x19: 0000000000000000 x18: 0000000000000000
x17: ff8080000a202b28 x16: ffff800011940934 x15: ffff80000a202b28
x14: 1ffff0000291a06a x13: ffffffffffffffff x12: 0000000000000000
x11: ff8080000a1ea0e0 x10: 0000000000000000 x9 : ffff80000a1ea0e0
x8 : ffff0000cd051ac0 x7 : ffff80000a1e92c4 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff8000083021e0
x2 : fffffffffff30000 x1 : 00000000000d0000 x0 : 00000000000cf000
Call trace:
btrfs_space_info_update_bytes_may_use+0x2c0/0x704
btrfs_space_info_free_bytes_may_use fs/btrfs/space-info.h:142 [inline]
block_rsv_release_bytes fs/btrfs/block-rsv.c:150 [inline]
btrfs_block_rsv_release+0x2e4/0x478 fs/btrfs/block-rsv.c:294
btrfs_release_global_block_rsv+0x38/0x22c fs/btrfs/block-rsv.c:450
btrfs_free_block_groups+0x7e0/0xb54 fs/btrfs/block-group.c:3922
close_ctree+0x61c/0x860 fs/btrfs/disk-io.c:4481
btrfs_put_super+0x40/0x50 fs/btrfs/super.c:340
generic_shutdown_super+0x130/0x29c fs/super.c:475
kill_anon_super+0x4c/0x74 fs/super.c:1067
btrfs_kill_super+0x40/0x58 fs/btrfs/super.c:2393
deactivate_locked_super+0xb8/0x13c fs/super.c:335
deactivate_super+0x108/0x128 fs/super.c:366
cleanup_mnt+0x3c0/0x474 fs/namespace.c:1143
__cleanup_mnt+0x20/0x30 fs/namespace.c:1150
task_work_run+0x130/0x1e4 kernel/task_work.c:164
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
do_notify_resume+0x262c/0x32b8 arch/arm64/kernel/signal.c:946
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:133 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:138 [inline]
el0_svc+0xfc/0x1f0 arch/arm64/kernel/entry-common.c:597
el0t_64_sync_handler+0x84/0xe4 arch/arm64/kernel/entry-common.c:614
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584
irq event stamp: 5403246
hardirqs last enabled at (5403245): [<ffff8000088c48d4>] kasan_quarantine_put+0xdc/0x204 mm/kasan/quarantine.c:231
hardirqs last disabled at (5403246): [<ffff80001193bfc8>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:387
softirqs last enabled at (5403068): [<ffff800008020ccc>] softirq_handle_end kernel/softirq.c:401 [inline]
softirqs last enabled at (5403068): [<ffff800008020ccc>] __do_softirq+0xb5c/0xe20 kernel/softirq.c:587
softirqs last disabled at (5403055): [<ffff8000081b56e0>] do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
softirqs last disabled at (5403055): [<ffff8000081b56e0>] invoke_softirq kernel/softirq.c:439 [inline]
softirqs last disabled at (5403055): [<ffff8000081b56e0>] __irq_exit_rcu+0x28c/0x534 kernel/softirq.c:636
---[ end trace 5c84f2ee2e22623f ]---
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4106 at fs/btrfs/space-info.h:110 btrfs_space_info_update_bytes_may_use+0x2c0/0x704
Modules linked in:
CPU: 0 PID: 4106 Comm: syz-executor.1 Tainted: G W 5.15.106-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/02/2023
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : btrfs_space_info_update_bytes_may_use+0x2c0/0x704
lr : btrfs_space_info_update_bytes_may_use+0x2bc/0x704
sp : ffff80001cdc7660
x29: ffff80001cdc7670 x28: ffff000126758280 x27: 1fffe00019a07f0c
x26: dfff800000000000 x25: ffff8000148cd310 x24: 0000000000000001
x23: 0000000000000005 x22: 00000000000cf000 x21: 00000000000d0000
x20: ffff0000cd03f860 x19: 0000000000000000 x18: 0000000000000000
x17: ff8080000a202b28 x16: ffff800011940934 x15: ffff80000a202b28
x14: 1ffff0000291a06a x13: ffffffffffffffff x12: 0000000000000000
x11: ff8080000a1ea0e0 x10: 0000000000000000 x9 : ffff80000a1ea0e0
x8 : ffff0000cd051ac0 x7 : ffff80000a1e92c4 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000001 x3 : ffff8000083021e0
x2 : fffffffffff30000 x1 : 00000000000d0000 x0 : 00000000000cf000
Call trace:
btrfs_space_info_update_bytes_may_use+0x2c0/0x704
btrfs_space_info_free_bytes_may_use fs/btrfs/space-info.h:142 [inline]
block_rsv_release_bytes fs/btrfs/block-rsv.c:150 [inline]
btrfs_block_rsv_release+0x2e4/0x478 fs/btrfs/block-rsv.c:294
btrfs_release_global_block_rsv+0x38/0x22c fs/btrfs/block-rsv.c:450
btrfs_free_block_groups+0x7e0/0xb54 fs/btrfs/block-group.c:3922
close_ctree+0x61c/0x860 fs/btrfs/disk-io.c:4481
btrfs_put_super+0x40/0x50 fs/btrfs/super.c:340
generic_shutdown_super+0x130/0x29c fs/super.c:475
kill_anon_super+0x4c/0x74 fs/super.c:1067
btrfs_kill_super+0x40/0x58 fs/btrfs/super.c:2393
deactivate_locked_super+0xb8/0x13c fs/super.c:335
deactivate_super+0x108/0x128 fs/super.c:366
cleanup_mnt+0x3c0/0x474 fs/namespace.c:1143
__cleanup_mnt+0x20/0x30 fs/namespace.c:1150
task_work_run+0x130/0x1e4 kernel/task_work.c:164
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
do_notify_resume+0x262c/0x32b8 arch/arm64/kernel/signal.c:946
prepare_exit_to_user_mode arch/arm64/kernel/entry-common.c:133 [inline]
exit_to_user_mode arch/arm64/kernel/entry-common.c:138 [inline]
el0_svc+0xfc/0x1f0 arch/arm64/kernel/entry-common.c:597
el0t_64_sync_handler+0x84/0xe4 arch/arm64/kernel/entry-common.c:614
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584
irq event stamp: 5440528
hardirqs last enabled at (5440527): [<ffff8000088c48d4>] kasan_quarantine_put+0xdc/0x204 mm/kasan/quarantine.c:231
hardirqs last disabled at (5440528): [<ffff80001193bfc8>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:387
softirqs last enabled at (5439740): [<ffff800008020ccc>] softirq_handle_end kernel/softirq.c:401 [inline]
softirqs last enabled at (5439740): [<ffff800008020ccc>] __do_softirq+0xb5c/0xe20 kernel/softirq.c:587
softirqs last disabled at (5439727): [<ffff8000081b56e0>] do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
softirqs last disabled at (5439727): [<ffff8000081b56e0>] invoke_softirq kernel/softirq.c:439 [inline]
softirqs last disabled at (5439727): [<ffff8000081b56e0>] __irq_exit_rcu+0x28c/0x534 kernel/softirq.c:636
---[ end trace 5c84f2ee2e226240 ]---
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.