[v5.15] WARNING in btrfs_finish_ordered_io

3 views
Skip to first unread message

syzbot

unread,
Apr 30, 2025, 8:49:32 AM4/30/25
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: f7347f400572 Linux 5.15.180
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=10263774580000
kernel config: https://syzkaller.appspot.com/x/.config?x=9a44713381e9503a
dashboard link: https://syzkaller.appspot.com/bug?extid=75afdb8e125baa22ab9e
compiler: Debian clang version 20.1.2 (++20250402124445+58df0ef89dd6-1~exp1~20250402004600.97), Debian LLD 20.1.2
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/e4a01c5e7b2e/disk-f7347f40.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/0b5c497dafe2/vmlinux-f7347f40.xz
kernel image: https://storage.googleapis.com/syzbot-assets/e8d128cf59a3/Image-f7347f40.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+75afdb...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 336 at fs/btrfs/inode.c:3151 btrfs_finish_ordered_io+0x1254/0x1504 fs/btrfs/inode.c:3151
Modules linked in:
CPU: 1 PID: 336 Comm: kworker/u4:4 Not tainted 5.15.180-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/19/2025
Workqueue: btrfs-endio-write btrfs_work_helper
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : btrfs_finish_ordered_io+0x1254/0x1504 fs/btrfs/inode.c:3151
lr : btrfs_finish_ordered_io+0x1254/0x1504 fs/btrfs/inode.c:3151
sp : ffff80001f507880
x29: ffff80001f507a20 x28: ffff0000dc3f4898 x27: 1fffe0001b87e913
x26: 0000000000000000 x25: 00000000ffffffe4 x24: dfff800000000000
x23: ffff0000ea2fc5d0 x22: ffff0000ea2fc608 x21: ffff0000e88813a0
x20: 1fffe0001d45f8c1 x19: ffff0000dc3f4840 x18: 0000000000000001
x17: 0000000000000000 x16: ffff80001119ef40 x15: 00000000ffffffff
x14: 0000000000ff0100 x13: 0000000000000001 x12: 0000000000ff0100
x11: 0000000000000000 x10: 0000000000000000 x9 : 7deb1682f5290400
x8 : 7deb1682f5290400 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff80001f507178 x4 : ffff80001422f280 x3 : ffff800008503f9c
x2 : 0000000000000001 x1 : 0000000100000000 x0 : 0000000000000026
Call trace:
btrfs_finish_ordered_io+0x1254/0x1504 fs/btrfs/inode.c:3151
finish_ordered_fn+0x20/0x30 fs/btrfs/inode.c:3257
btrfs_work_helper+0x328/0x13a0 fs/btrfs/async-thread.c:325
process_one_work+0x79c/0x1140 kernel/workqueue.c:2310
worker_thread+0x8f4/0x101c kernel/workqueue.c:2457
kthread+0x374/0x454 kernel/kthread.c:334
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:870
irq event stamp: 318352
hardirqs last enabled at (318351): [<ffff8000082f7dc0>] __up_console_sem+0xb4/0x100 kernel/printk/printk.c:257
hardirqs last disabled at (318352): [<ffff80001119a800>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:396
softirqs last enabled at (318266): [<ffff800008031a74>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:31
softirqs last disabled at (318264): [<ffff800008031a40>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:18
---[ end trace a237c2cc0833af99 ]---
BTRFS: error (device loop3) in btrfs_finish_ordered_io:3151: errno=-28 No space left
BTRFS info (device loop3): forced readonly


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Apr 30, 2025, 2:01:29 PM4/30/25
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: f7347f400572 Linux 5.15.180
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=17d0b1b3980000
kernel config: https://syzkaller.appspot.com/x/.config?x=9a44713381e9503a
dashboard link: https://syzkaller.appspot.com/bug?extid=75afdb8e125baa22ab9e
compiler: Debian clang version 20.1.2 (++20250402124445+58df0ef89dd6-1~exp1~20250402004600.97), Debian LLD 20.1.2
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1473639b980000
mounted in repro #1: https://storage.googleapis.com/syzbot-assets/b2624c3d8a5c/mount_1.gz
fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=15c25f74580000)
mounted in repro #2: https://storage.googleapis.com/syzbot-assets/996b32839881/mount_8.gz
fsck result: failed (log: https://syzkaller.appspot.com/x/fsck.log?x=1536502f980000)
mounted in repro #3: https://storage.googleapis.com/syzbot-assets/7a6fcb7feb73/mount_9.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+75afdb...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 4905 at fs/btrfs/inode.c:3151 btrfs_finish_ordered_io+0x1254/0x1504 fs/btrfs/inode.c:3151
Modules linked in:
CPU: 0 PID: 4905 Comm: kworker/u4:9 Not tainted 5.15.180-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/19/2025
Workqueue: btrfs-endio-write btrfs_work_helper
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : btrfs_finish_ordered_io+0x1254/0x1504 fs/btrfs/inode.c:3151
lr : btrfs_finish_ordered_io+0x1254/0x1504 fs/btrfs/inode.c:3151
sp : ffff800021517880
x29: ffff800021517a20 x28: ffff0000dd59f478 x27: 1fffe0001bab3e8f
x26: 0000000000000000 x25: 00000000ffffffe4 x24: dfff800000000000
x23: ffff0000da283168 x22: ffff0000da2831a0 x21: ffff0000e5ae93a0
x20: 1fffe0001b450634 x19: ffff0000dd59f420 x18: 0000000000000001
x17: 0000000000000000 x16: ffff80001119ef40 x15: 00000000ffffffff
x14: 0000000000ff0100 x13: fffffffffffeadf0 x12: 0000000000ff0100
x11: 0000000000000000 x10: 0000000000000000 x9 : efd94a752b595200
x8 : efd94a752b595200 x7 : fffffffffffeadf0 x6 : fffffffffffeadb0
x5 : ffff800021517178 x4 : ffff80001420da40 x3 : ffff800008503f9c
x2 : 0000000000000001 x1 : 0000000100000000 x0 : 0000000000000026
Call trace:
btrfs_finish_ordered_io+0x1254/0x1504 fs/btrfs/inode.c:3151
finish_ordered_fn+0x20/0x30 fs/btrfs/inode.c:3257
btrfs_work_helper+0x328/0x13a0 fs/btrfs/async-thread.c:325
process_one_work+0x79c/0x1140 kernel/workqueue.c:2310
worker_thread+0x8f4/0x101c kernel/workqueue.c:2457
kthread+0x374/0x454 kernel/kthread.c:334
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:870
irq event stamp: 6087852
hardirqs last enabled at (6087851): [<ffff8000082f7dc0>] __up_console_sem+0xb4/0x100 kernel/printk/printk.c:257
hardirqs last disabled at (6087852): [<ffff80001119a800>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:396
softirqs last enabled at (6087644): [<ffff80000819d8d8>] softirq_handle_end kernel/softirq.c:401 [inline]
softirqs last enabled at (6087644): [<ffff80000819d8d8>] handle_softirqs+0xa4c/0xbf0 kernel/softirq.c:586
softirqs last disabled at (6087591): [<ffff80000819dedc>] __do_softirq kernel/softirq.c:592 [inline]
softirqs last disabled at (6087591): [<ffff80000819dedc>] do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
softirqs last disabled at (6087591): [<ffff80000819dedc>] invoke_softirq kernel/softirq.c:439 [inline]
softirqs last disabled at (6087591): [<ffff80000819dedc>] __irq_exit_rcu+0x240/0x440 kernel/softirq.c:641
---[ end trace df6382f8b492703d ]---
BTRFS: error (device loop0) in btrfs_finish_ordered_io:3151: errno=-28 No space left
BTRFS info (device loop0): forced readonly


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Aug 8, 2025, 2:01:20 PM8/8/25
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
No recent activity, existing reproducers are no longer triggering the issue.
Reply all
Reply to author
Forward
0 new messages