[v5.15] kernel BUG in ocfs2_journal_toggle_dirty

0 views
Skip to first unread message

syzbot

unread,
12:10 PM (4 hours ago) 12:10 PM
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 91d48252ad4b Linux 5.15.202
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=176098d2580000
kernel config: https://syzkaller.appspot.com/x/.config?x=353ae28c40b35af5
dashboard link: https://syzkaller.appspot.com/bug?extid=3aba35f80970c6e536b2
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/74e75dfcb812/disk-91d48252.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/bfa72aab00f2/vmlinux-91d48252.xz
kernel image: https://storage.googleapis.com/syzbot-assets/47ea72d1c7dc/bzImage-91d48252.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3aba35...@syzkaller.appspotmail.com

------------[ cut here ]------------
kernel BUG at fs/ocfs2/journal.c:973!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 1 PID: 4188 Comm: syz-executor Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/18/2026
RIP: 0010:ocfs2_journal_toggle_dirty+0x34a/0x350 fs/ocfs2/journal.c:973
Code: fe ff ff e8 08 c9 9a 06 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c 3f fe ff ff 48 89 df e8 90 8c 9c fe e9 32 fe ff ff e8 36 81 57 fe <0f> 0b 0f 1f 40 00 55 48 89 e5 41 57 41 56 41 55 41 54 53 48 83 e4
RSP: 0018:ffffc90002f0fae0 EFLAGS: 00010293
RAX: ffffffff83219fda RBX: 00000000ffffffff RCX: ffff88807ad95940
RDX: 0000000000000000 RSI: 00000000ffffffff RDI: 0000000000000000
RBP: ffffc90002f0fb90 R08: ffffffff901d4257 R09: 1ffffffff203a84a
R10: dffffc0000000000 R11: fffffbfff203a84b R12: 1ffff1100c074527
R13: ffff88805b61aa00 R14: ffff88805d94a800 R15: ffff8880603a2938
FS: 000055558380b500(0000) GS:ffff8880b9100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ffefe26efe8 CR3: 0000000063a6a000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
ocfs2_journal_shutdown+0x561/0xb10 fs/ocfs2/journal.c:1055
ocfs2_dismount_volume+0x1f9/0x8a0 fs/ocfs2/super.c:1892
generic_shutdown_super+0x130/0x300 fs/super.c:475
kill_block_super+0x7c/0xe0 fs/super.c:1427
deactivate_locked_super+0x93/0xf0 fs/super.c:335
cleanup_mnt+0x42d/0x4e0 fs/namespace.c:1148
task_work_run+0x125/0x1a0 kernel/task_work.c:188
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
exit_to_user_mode_loop+0x10f/0x130 kernel/entry/common.c:181
exit_to_user_mode_prepare+0xee/0x180 kernel/entry/common.c:214
__syscall_exit_to_user_mode_work kernel/entry/common.c:296 [inline]
syscall_exit_to_user_mode+0x16/0x40 kernel/entry/common.c:307
do_syscall_64+0x58/0xa0 arch/x86/entry/common.c:86
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7f921d878a57
Code: a2 c7 05 9c fc 24 00 00 00 00 00 eb 96 e8 e1 12 00 00 90 31 f6 e9 09 00 00 00 66 0f 1f 84 00 00 00 00 00 b8 a6 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 01 c3 48 c7 c2 e8 ff ff ff f7 d8 64 89 02 b8
RSP: 002b:00007ffea04c2898 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 00007f921d90d048 RCX: 00007f921d878a57
RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007ffea04c2950
RBP: 00007ffea04c2950 R08: 00007ffea04c3950 R09: 00000000ffffffff
R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffea04c39e0
R13: 00007f921d90d048 R14: 0000000000030c6d R15: 00007ffea04c3a20
</TASK>
Modules linked in:
---[ end trace 15b152a36f30bff6 ]---
RIP: 0010:ocfs2_journal_toggle_dirty+0x34a/0x350 fs/ocfs2/journal.c:973
Code: fe ff ff e8 08 c9 9a 06 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c 3f fe ff ff 48 89 df e8 90 8c 9c fe e9 32 fe ff ff e8 36 81 57 fe <0f> 0b 0f 1f 40 00 55 48 89 e5 41 57 41 56 41 55 41 54 53 48 83 e4
RSP: 0018:ffffc90002f0fae0 EFLAGS: 00010293
RAX: ffffffff83219fda RBX: 00000000ffffffff RCX: ffff88807ad95940
RDX: 0000000000000000 RSI: 00000000ffffffff RDI: 0000000000000000
RBP: ffffc90002f0fb90 R08: ffffffff901d4257 R09: 1ffffffff203a84a
R10: dffffc0000000000 R11: fffffbfff203a84b R12: 1ffff1100c074527
R13: ffff88805b61aa00 R14: ffff88805d94a800 R15: ffff8880603a2938
FS: 000055558380b500(0000) GS:ffff8880b9000000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000110c3ca0cb CR3: 0000000063a6a000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
1:27 PM (2 hours ago) 1:27 PM
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 91d48252ad4b Linux 5.15.202
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13e686ba580000
kernel config: https://syzkaller.appspot.com/x/.config?x=353ae28c40b35af5
dashboard link: https://syzkaller.appspot.com/bug?extid=3aba35f80970c6e536b2
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1596546a580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=177a95da580000
mounted in repro #1: https://storage.googleapis.com/syzbot-assets/468515dbf9ac/mount_0.gz
fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=1581cdda580000)
mounted in repro #2: https://storage.googleapis.com/syzbot-assets/45512d3e60ac/mount_5.gz
fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=11134e06580000)

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3aba35...@syzkaller.appspotmail.com

------------[ cut here ]------------
kernel BUG at fs/ocfs2/journal.c:973!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 0 PID: 4286 Comm: syz-executor Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/18/2026
RIP: 0010:ocfs2_journal_toggle_dirty+0x34a/0x350 fs/ocfs2/journal.c:973
Code: fe ff ff e8 08 c9 9a 06 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c 3f fe ff ff 48 89 df e8 90 8c 9c fe e9 32 fe ff ff e8 36 81 57 fe <0f> 0b 0f 1f 40 00 55 48 89 e5 41 57 41 56 41 55 41 54 53 48 83 e4
RSP: 0018:ffffc9000318fae0 EFLAGS: 00010293
RAX: ffffffff83219fda RBX: 00000000ffffffff RCX: ffff88801ef9bb80
RDX: 0000000000000000 RSI: 00000000ffffffff RDI: 0000000000000000
RBP: ffffc9000318fb90 R08: ffffffff901d4207 R09: 1ffffffff203a840
R10: dffffc0000000000 R11: fffffbfff203a841 R12: 1ffff1100e96ea22
R13: ffff88805ed40a00 R14: ffff88807d5e2400 R15: ffff888074b75110
FS: 00005555813bb500(0000) GS:ffff8880b9000000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ffe46bb8ff8 CR3: 000000001f927000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
ocfs2_journal_shutdown+0x561/0xb10 fs/ocfs2/journal.c:1055
ocfs2_dismount_volume+0x1f9/0x8a0 fs/ocfs2/super.c:1892
generic_shutdown_super+0x130/0x300 fs/super.c:475
kill_block_super+0x7c/0xe0 fs/super.c:1427
deactivate_locked_super+0x93/0xf0 fs/super.c:335
cleanup_mnt+0x42d/0x4e0 fs/namespace.c:1148
task_work_run+0x125/0x1a0 kernel/task_work.c:188
tracehook_notify_resume include/linux/tracehook.h:189 [inline]
exit_to_user_mode_loop+0x10f/0x130 kernel/entry/common.c:181
exit_to_user_mode_prepare+0xee/0x180 kernel/entry/common.c:214
__syscall_exit_to_user_mode_work kernel/entry/common.c:296 [inline]
syscall_exit_to_user_mode+0x16/0x40 kernel/entry/common.c:307
do_syscall_64+0x58/0xa0 arch/x86/entry/common.c:86
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7f7ee27e1a57
Code: a2 c7 05 9c fc 24 00 00 00 00 00 eb 96 e8 e1 12 00 00 90 31 f6 e9 09 00 00 00 66 0f 1f 84 00 00 00 00 00 b8 a6 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 01 c3 48 c7 c2 e8 ff ff ff f7 d8 64 89 02 b8
RSP: 002b:00007ffe46bb96d8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 00007f7ee2876048 RCX: 00007f7ee27e1a57
RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007ffe46bb9790
RBP: 00007ffe46bb9790 R08: 00007ffe46bba790 R09: 00000000ffffffff
R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffe46bba820
R13: 00007f7ee2876048 R14: 0000000000012ce4 R15: 00007ffe46bba860
</TASK>
Modules linked in:
---[ end trace da1daf3b1997fb09 ]---
RIP: 0010:ocfs2_journal_toggle_dirty+0x34a/0x350 fs/ocfs2/journal.c:973
Code: fe ff ff e8 08 c9 9a 06 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c 3f fe ff ff 48 89 df e8 90 8c 9c fe e9 32 fe ff ff e8 36 81 57 fe <0f> 0b 0f 1f 40 00 55 48 89 e5 41 57 41 56 41 55 41 54 53 48 83 e4
RSP: 0018:ffffc9000318fae0 EFLAGS: 00010293
RAX: ffffffff83219fda RBX: 00000000ffffffff RCX: ffff88801ef9bb80
RDX: 0000000000000000 RSI: 00000000ffffffff RDI: 0000000000000000
RBP: ffffc9000318fb90 R08: ffffffff901d4207 R09: 1ffffffff203a840
R10: dffffc0000000000 R11: fffffbfff203a841 R12: 1ffff1100e96ea22
R13: ffff88805ed40a00 R14: ffff88807d5e2400 R15: ffff888074b75110
FS: 00005555813bb500(0000) GS:ffff8880b9100000(0000) knlGS:0000000000000000
CS:


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
Reply all
Reply to author
Forward
0 new messages