Hello,
syzbot found the following issue on:
HEAD commit: c596736dadab Linux 6.6.120
git tree: linux-6.6.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=1484ff92580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=691a6769a86ac817
dashboard link:
https://syzkaller.appspot.com/bug?extid=6932c6833ad7f040732b
compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/855c94eb3eef/disk-c596736d.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/b7510b30b774/vmlinux-c596736d.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/3ce7fe4f6991/bzImage-c596736d.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+6932c6...@syzkaller.appspotmail.com
gfs2: fsid=syz:syz: Now mounting FS (format 1801)...
gfs2: fsid=syz:syz.s: journal 0 mapped with 3 extents in 0ms
------------[ cut here ]------------
kernel BUG at block/bio.c:340!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 0 PID: 7835 Comm: syz.0.895 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
RIP: 0010:bio_chain+0xe4/0xf0 block/bio.c:340
Code: d2 df dc fd f0 ff 43 1c 5b 41 5c 41 5d 41 5e 41 5f 5d c3 89 f9 80 e1 07 fe c1 38 c1 7c d4 e8 93 dd dc fd eb cd e8 bc 6d 85 fd <0f> 0b e8 b5 6d 85 fd 0f 0b 0f 1f 00 f3 0f 1e fa 55 41 57 41 56 41
RSP: 0018:ffffc90004dbf5b0 EFLAGS: 00010287
RAX: ffffffff84003d44 RBX: ffff88805f742dc0 RCX: 0000000000080000
RDX: ffffc90005021000 RSI: 000000000004e0b0 RDI: 000000000004e0b1
RBP: 0000000000000004 R08: ffffffff8e4a39ef R09: 1ffffffff1c9473d
R10: dffffc0000000000 R11: fffffbfff1c9473e R12: dffffc0000000000
R13: 1ffff1100bee8598 R14: ffff88805f742c80 R15: ffff88805f742cc0
FS: 00007f4f8bca36c0(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f1da15ad000 CR3: 000000002d2dd000 CR4: 00000000003506f0
Call Trace:
<TASK>
gfs2_chain_bio fs/gfs2/lops.c:495 [inline]
gfs2_find_jhead+0x5fa/0xd20 fs/gfs2/lops.c:559
check_journal_clean+0x191/0x300 fs/gfs2/util.c:76
init_journal+0x17f1/0x2260 fs/gfs2/ops_fstype.c:828
init_inodes+0xdb/0x320 fs/gfs2/ops_fstype.c:886
gfs2_fill_super+0x1815/0x1f80 fs/gfs2/ops_fstype.c:1266
get_tree_bdev+0x3e4/0x510 fs/super.c:1591
gfs2_get_tree+0x51/0x1e0 fs/gfs2/ops_fstype.c:1344
vfs_get_tree+0x8c/0x280 fs/super.c:1764
do_new_mount+0x24b/0xa40 fs/namespace.c:3386
do_mount fs/namespace.c:3726 [inline]
__do_sys_mount fs/namespace.c:3935 [inline]
__se_sys_mount+0x2da/0x3c0 fs/namespace.c:3912
do_syscall_x64 arch/x86/entry/common.c:46 [inline]
do_syscall_64+0x55/0xb0 arch/x86/entry/common.c:76
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f4f8ad90eea
Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb a6 e8 de 1a 00 00 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f4f8bca2e68 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007f4f8bca2ef0 RCX: 00007f4f8ad90eea
RDX: 000020000001f680 RSI: 000020000001f6c0 RDI: 00007f4f8bca2eb0
RBP: 000020000001f680 R08: 00007f4f8bca2ef0 R09: 0000000000000084
R10: 0000000000000084 R11: 0000000000000246 R12: 000020000001f6c0
R13: 00007f4f8bca2eb0 R14: 000000000001f707 R15: 00002000000000c0
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:bio_chain+0xe4/0xf0 block/bio.c:340
Code: d2 df dc fd f0 ff 43 1c 5b 41 5c 41 5d 41 5e 41 5f 5d c3 89 f9 80 e1 07 fe c1 38 c1 7c d4 e8 93 dd dc fd eb cd e8 bc 6d 85 fd <0f> 0b e8 b5 6d 85 fd 0f 0b 0f 1f 00 f3 0f 1e fa 55 41 57 41 56 41
RSP: 0018:ffffc90004dbf5b0 EFLAGS: 00010287
RAX: ffffffff84003d44 RBX: ffff88805f742dc0 RCX: 0000000000080000
RDX: ffffc90005021000 RSI: 000000000004e0b0 RDI: 000000000004e0b1
RBP: 0000000000000004 R08: ffffffff8e4a39ef R09: 1ffffffff1c9473d
R10: dffffc0000000000 R11: fffffbfff1c9473e R12: dffffc0000000000
R13: 1ffff1100bee8598 R14: ffff88805f742c80 R15: ffff88805f742cc0
FS: 00007f4f8bca36c0(0000) GS:ffff8880b8e00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fff7c9c2fa8 CR3: 000000002d2dd000 CR4: 00000000003506f0