Hello,
syzbot found the following issue on:
HEAD commit: d86dfc4d95cd Linux 5.15.106
git tree: linux-5.15.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=1119f6d9c80000
kernel config:
https://syzkaller.appspot.com/x/.config?x=dca379fe384dda80
dashboard link:
https://syzkaller.appspot.com/bug?extid=3613ace77ebf88fb2c83
compiler: Debian clang version 15.0.7, GNU ld (GNU Binutils for Debian) 2.35.2
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/2c159eb4fcae/disk-d86dfc4d.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/5f50187f87c7/vmlinux-d86dfc4d.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/f787f3f09c09/bzImage-d86dfc4d.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+3613ac...@syzkaller.appspotmail.com
REISERFS panic (device loop1): journal-003 check_journal_end: j_start (260) is too high
------------[ cut here ]------------
kernel BUG at fs/reiserfs/prints.c:390!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 0 PID: 18264 Comm: syz-executor.1 Not tainted 5.15.106-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/30/2023
RIP: 0010:__reiserfs_panic+0x13a/0x140 fs/reiserfs/prints.c:390
Code: c7 c1 80 17 9b 8a 48 0f 44 c8 48 0f 44 d8 48 c7 c7 40 18 9b 8a 4c 89 fe 48 89 da 4d 89 f0 49 c7 c1 a0 43 4d 91 e8 af 1f 09 08 <0f> 0b 0f 1f 40 00 55 48 89 e5 41 57 41 56 41 55 41 54 53 48 83 e4
RSP: 0018:ffffc9000590f540 EFLAGS: 00010246
RAX: 0000000000000057 RBX: ffffffff8a9b6520 RCX: cbe440508a177100
RDX: 0000000000000000 RSI: 0000000080000000 RDI: 0000000000000000
RBP: ffffc9000590f640 R08: ffffffff816612ec R09: ffffed10173467a0
R10: 0000000000000000 R11: dffffc0000000001 R12: ffffffff8a9b6540
R13: ffffc9000590f560 R14: ffffffff8c15a269 R15: ffff888077ba86a8
FS: 0000000000000000(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2dc803d058 CR3: 00000000227ea000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
check_journal_end fs/reiserfs/journal.c:3713 [inline]
do_journal_end+0x45b2/0x4650 fs/reiserfs/journal.c:4038
reiserfs_sync_fs+0xca/0x140 fs/reiserfs/super.c:78
sync_filesystem+0xe8/0x220 fs/sync.c:56
generic_shutdown_super+0x6e/0x2c0 fs/super.c:448
kill_block_super+0x7a/0xe0 fs/super.c:1405
deactivate_locked_super+0xa0/0x110 fs/super.c:335
cleanup_mnt+0x44e/0x500 fs/namespace.c:1143
task_work_run+0x129/0x1a0 kernel/task_work.c:164
exit_task_work include/linux/task_work.h:32 [inline]
do_exit+0x6a3/0x2480 kernel/exit.c:872
do_group_exit+0x144/0x310 kernel/exit.c:994
get_signal+0xc66/0x14e0 kernel/signal.c:2889
arch_do_signal_or_restart+0xc3/0x1890 arch/x86/kernel/signal.c:865
handle_signal_work kernel/entry/common.c:148 [inline]
exit_to_user_mode_loop+0x97/0x130 kernel/entry/common.c:172
exit_to_user_mode_prepare+0xb1/0x140 kernel/entry/common.c:208
__syscall_exit_to_user_mode_work kernel/entry/common.c:290 [inline]
syscall_exit_to_user_mode+0x5d/0x250 kernel/entry/common.c:301
ret_from_fork+0x15/0x30 arch/x86/entry/entry_64.S:291
RIP: 0033:0x7efd79648169
Code: Unable to access opcode bytes at RIP 0x7efd7964813f.
RSP: 002b:00007efd77bba118 EFLAGS: 00000246 ORIG_RAX: 0000000000000038
RAX: 0000000000000000 RBX: 00007efd79767f80 RCX: 00007efd79648169
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 00007efd796a3ca1 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ffdbb332cef R14: 00007efd77bba300 R15: 0000000000022000
</TASK>
Modules linked in:
---[ end trace 80ce0ed61deb582f ]---
RIP: 0010:__reiserfs_panic+0x13a/0x140 fs/reiserfs/prints.c:390
Code: c7 c1 80 17 9b 8a 48 0f 44 c8 48 0f 44 d8 48 c7 c7 40 18 9b 8a 4c 89 fe 48 89 da 4d 89 f0 49 c7 c1 a0 43 4d 91 e8 af 1f 09 08 <0f> 0b 0f 1f 40 00 55 48 89 e5 41 57 41 56 41 55 41 54 53 48 83 e4
RSP: 0018:ffffc9000590f540 EFLAGS: 00010246
RAX: 0000000000000057 RBX: ffffffff8a9b6520 RCX: cbe440508a177100
RDX: 0000000000000000 RSI: 0000000080000000 RDI: 0000000000000000
RBP: ffffc9000590f640 R08: ffffffff816612ec R09: ffffed10173467a0
R10: 0000000000000000 R11: dffffc0000000001 R12: ffffffff8a9b6540
R13: ffffc9000590f560 R14: ffffffff8c15a269 R15: ffff888077ba86a8
FS: 0000000000000000(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2dc803d058 CR3: 00000000227ea000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400