Hello,
syzbot found the following issue on:
HEAD commit: fa74641fb6b9 Linux 6.1.29
git tree: linux-6.1.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=152f9509280000
kernel config:
https://syzkaller.appspot.com/x/.config?x=7454aa89ac475d7b
dashboard link:
https://syzkaller.appspot.com/bug?extid=03a3f365d3150f0355cc
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
userspace arch: arm64
syz repro:
https://syzkaller.appspot.com/x/repro.syz?x=17874141280000
C reproducer:
https://syzkaller.appspot.com/x/repro.c?x=144e865a280000
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/53e4da6b145c/disk-fa74641f.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/adeb1a2cfa86/vmlinux-fa74641f.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/c976f1155d08/Image-fa74641f.gz.xz
mounted in repro:
https://storage.googleapis.com/syzbot-assets/7198d3be548d/mount_0.gz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+03a3f3...@syzkaller.appspotmail.com
------------[ cut here ]------------
WARNING: CPU: 1 PID: 9 at fs/xfs/libxfs/xfs_bmap.c:4592 xfs_bmapi_convert_delalloc+0xd50/0x10b0 fs/xfs/libxfs/xfs_bmap.c:4592
Modules linked in:
CPU: 1 PID: 9 Comm: kworker/u4:0 Not tainted 6.1.29-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023
Workqueue: writeback wb_workfn (flush-7:0)
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : xfs_bmapi_convert_delalloc+0xd50/0x10b0 fs/xfs/libxfs/xfs_bmap.c:4592
lr : xfs_bmapi_convert_delalloc+0xd50/0x10b0 fs/xfs/libxfs/xfs_bmap.c:4592
sp : ffff800019b667c0
x29: ffff800019b669c0 x28: ffff0000ceff4000 x27: dfff800000000000
x26: 0000000000000000 x25: ffff800019b66900 x24: dfff800000000000
x23: ffff70000336cd0c x22: ffffffffffffffff x21: ffff800019b66980
x20: 0000000000000000 x19: ffff0000e00026c0 x18: ffff800019b66460
x17: ffff80019f0e0000 x16: ffff8000120ec854 x15: 0000000000000000
x14: 1ffff00002ab40b0 x13: dfff800000000000 x12: 0000000000000001
x11: ff80800009a8d938 x10: 0000000000000000 x9 : ffff800009a8d938
x8 : ffff0000c0998000 x7 : 0000000000000000 x6 : 000000000000003f
x5 : 0000000000000040 x4 : 0000000000000000 x3 : ffff800009a348a8
x2 : 0000000000000001 x1 : ffffffffffffffff x0 : ffffffffffffffff
Call trace:
xfs_bmapi_convert_delalloc+0xd50/0x10b0 fs/xfs/libxfs/xfs_bmap.c:4592
xfs_convert_blocks fs/xfs/xfs_aops.c:259 [inline]
xfs_map_blocks+0x85c/0x1464 fs/xfs/xfs_aops.c:380
iomap_writepage_map fs/iomap/buffered-io.c:1360 [inline]
iomap_do_writepage+0x7f4/0x2364 fs/iomap/buffered-io.c:1523
write_cache_pages+0x7fc/0xf60 mm/page-writeback.c:2360
iomap_writepages+0x6c/0x1f4 fs/iomap/buffered-io.c:1540
xfs_vm_writepages+0x124/0x180 fs/xfs/xfs_aops.c:500
do_writepages+0x2e8/0x56c mm/page-writeback.c:2469
__writeback_single_inode+0x16c/0x1770 fs/fs-writeback.c:1590
writeback_sb_inodes+0x978/0x16c0 fs/fs-writeback.c:1881
wb_writeback+0x414/0x1130 fs/fs-writeback.c:2055
wb_do_writeback fs/fs-writeback.c:2198 [inline]
wb_workfn+0x3a8/0x1034 fs/fs-writeback.c:2238
process_one_work+0x7ac/0x1404 kernel/workqueue.c:2289
worker_thread+0x8e4/0xfec kernel/workqueue.c:2436
kthread+0x250/0x2d8 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860
irq event stamp: 299400
hardirqs last enabled at (299399): [<ffff80000b70de64>] get_random_u32+0x34c/0x658 drivers/char/random.c:513
hardirqs last disabled at (299400): [<ffff8000120e850c>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (299336): [<ffff800010427990>] neigh_managed_work+0x1e0/0x21c net/core/neighbour.c:1638
softirqs last disabled at (299332): [<ffff8000104277f0>] neigh_managed_work+0x40/0x21c net/core/neighbour.c:1633
---[ end trace 0000000000000000 ]---
XFS (loop0): page discard on page 00000000e900277c, inode 0x2b, pos 0.
XFS (loop0): page discard on page 000000002ff9fc8b, inode 0x2b, pos 4096.
XFS (loop0): page discard on page 00000000af0efda5, inode 0x2b, pos 8192.
XFS (loop0): page discard on page 00000000e3661837, inode 0x2b, pos 12288.
XFS (loop0): page discard on page 0000000038e7a3e4, inode 0x2b, pos 16384.
XFS (loop0): page discard on page 000000003d02f8b6, inode 0x2b, pos 20480.
XFS (loop0): page discard on page 00000000dea82b9c, inode 0x2b, pos 24576.
XFS (loop0): page discard on page 00000000749686c4, inode 0x2b, pos 28672.
XFS (loop0): page discard on page 0000000060856c2c, inode 0x2b, pos 32768.
XFS (loop0): page discard on page 000000009935e000, inode 0x2b, pos 36864.
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the bug is already fixed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to change bug's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the bug is a duplicate of another bug, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup