[v6.1] WARNING in dbJoin

0 views
Skip to first unread message

syzbot

unread,
Jun 20, 2026, 10:28:31 AM (yesterday) Jun 20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: fdb6fcb41cc7 Linux 6.1.176
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1267bdee580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f312e19619d04f50
dashboard link: https://syzkaller.appspot.com/bug?extid=5a9c5fc22f22f9be4f30
compiler: Debian clang version 22.1.6 (++20260514074242+fc4aad7b5db3-1~exp1~20260514074407.73), Debian LLD 22.1.6
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/be13f594160c/disk-fdb6fcb4.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/861f249f1e1c/vmlinux-fdb6fcb4.xz
kernel image: https://storage.googleapis.com/syzbot-assets/59bb274672f8/Image-fdb6fcb4.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+5a9c5f...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 93 at fs/jfs/jfs_dmap.c:2875 dbAdjTree fs/jfs/jfs_dmap.c:-1 [inline]
WARNING: CPU: 1 PID: 93 at fs/jfs/jfs_dmap.c:2875 dbJoin+0xa08/0xb0c fs/jfs/jfs_dmap.c:2843
Modules linked in:
CPU: 1 PID: 93 Comm: jfsCommit Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/02/2026
pstate: 82400005 (Nzcv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : dbAdjTree fs/jfs/jfs_dmap.c:-1 [inline]
pc : dbJoin+0xa08/0xb0c fs/jfs/jfs_dmap.c:2843
lr : dbAdjTree fs/jfs/jfs_dmap.c:2875 [inline]
lr : dbJoin+0xa04/0xb0c fs/jfs/jfs_dmap.c:2843
sp : ffff80001ff67480
x29: ffff80001ff674e0 x28: 0000000000000000 x27: ffff0000e8b16010
x26: ffff0000e8b16804 x25: 0000000000000001 x24: 0000000000000001
x23: 1fffe0001d162c04 x22: 0000000000000155 x21: 0000000000020056
x20: 0000000000000004 x19: dfff800000000000 x18: 1fffe00033e8417e
x17: ffff8000098e0f0c x16: ffff8000082dba2c x15: 0000000000000000
x14: 0000000000000001 x13: 1fffff80007458b0 x12: 0000000000000000
x11: ff008000098c3e98 x10: 0000000000000000 x9 : ffff8000098c3e98
x8 : ffff0000c78b9c00 x7 : ffff8000086fd3fc x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000
x2 : 0000000000000004 x1 : 0000000000000155 x0 : 0000000000000000
Call trace:
dbAdjTree fs/jfs/jfs_dmap.c:-1 [inline]
dbJoin+0xa08/0xb0c fs/jfs/jfs_dmap.c:2843
dbFreeBits+0x40c/0xbf4 fs/jfs/jfs_dmap.c:2340
dbFreeDmap fs/jfs/jfs_dmap.c:2089 [inline]
dbFree+0x2dc/0x5d4 fs/jfs/jfs_dmap.c:398
txFreeMap+0x800/0xb94 fs/jfs/jfs_txnmgr.c:2516
xtTruncate+0xa1c/0x266c fs/jfs/jfs_xtree.c:2467
jfs_free_zero_link+0x2c0/0x424 fs/jfs/namei.c:758
jfs_evict_inode+0x2f4/0x3e4 fs/jfs/inode.c:159
evict+0x3d8/0x824 fs/inode.c:705
iput_final fs/inode.c:1834 [inline]
iput+0x728/0x7e8 fs/inode.c:1860
txUpdateMap+0x68c/0x7b0 fs/jfs/jfs_txnmgr.c:2368
txLazyCommit fs/jfs/jfs_txnmgr.c:2665 [inline]
jfs_lazycommit+0x360/0x930 fs/jfs/jfs_txnmgr.c:2733
kthread+0x254/0x2e0 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:850
irq event stamp: 70
hardirqs last enabled at (69): [<ffff800011c25a1c>] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:151 [inline]
hardirqs last enabled at (69): [<ffff800011c25a1c>] _raw_spin_unlock_irqrestore+0x48/0xac kernel/locking/spinlock.c:194
hardirqs last disabled at (70): [<ffff800011b3a55c>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (0): [<ffff80000818be70>] copy_process+0x1370/0x38f4 kernel/fork.c:2302
softirqs last disabled at (0): [<0000000000000000>] 0x0
---[ end trace 0000000000000000 ]---


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Jun 20, 2026, 11:19:27 AM (yesterday) Jun 20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: fdb6fcb41cc7 Linux 6.1.176
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13876bd2580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f312e19619d04f50
dashboard link: https://syzkaller.appspot.com/bug?extid=5a9c5fc22f22f9be4f30
compiler: Debian clang version 22.1.6 (++20260514074242+fc4aad7b5db3-1~exp1~20260514074407.73), Debian LLD 22.1.6
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1642d7b6580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1220caae580000
mounted in repro: https://storage.googleapis.com/syzbot-assets/70daf0c449de/mount_0.gz
fsck result: failed (log: https://syzkaller.appspot.com/x/fsck.log?x=15fa7986580000)

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+5a9c5f...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 93 at fs/jfs/jfs_dmap.c:2875 dbAdjTree fs/jfs/jfs_dmap.c:-1 [inline]
WARNING: CPU: 0 PID: 93 at fs/jfs/jfs_dmap.c:2875 dbJoin+0xa08/0xb0c fs/jfs/jfs_dmap.c:2843
Modules linked in:
CPU: 0 PID: 93 Comm: jfsCommit Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/02/2026
pstate: 82400005 (Nzcv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : dbAdjTree fs/jfs/jfs_dmap.c:-1 [inline]
pc : dbJoin+0xa08/0xb0c fs/jfs/jfs_dmap.c:2843
lr : dbAdjTree fs/jfs/jfs_dmap.c:2875 [inline]
lr : dbJoin+0xa04/0xb0c fs/jfs/jfs_dmap.c:2843
sp : ffff800020647480
x29: ffff8000206474e0 x28: 0000000000000000 x27: ffff0000d1fa0010
x26: ffff0000d1fa0804 x25: 0000000000000001 x24: 0000000000000001
x23: 1fffe0001a3f4004 x22: 0000000000000155 x21: 0000000000020056
x20: 0000000000000004 x19: dfff800000000000 x18: 1fffe00033e7ff7e
x17: ffff8000098e0f0c x16: ffff8000082dba2c x15: 0000000000000000
x14: 0000000000000001 x13: 1fffff800068fd00 x12: 0000000000000000
x11: ff008000098c3e98 x10: 0000000000000000 x9 : ffff8000098c3e98
x8 : ffff0000c7c79c00 x7 : ffff8000086fd3fc x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000
x2 : 0000000000000004 x1 : 0000000000000155 x0 : 0000000000000000
Call trace:
dbAdjTree fs/jfs/jfs_dmap.c:-1 [inline]
dbJoin+0xa08/0xb0c fs/jfs/jfs_dmap.c:2843
dbFreeBits+0x40c/0xbf4 fs/jfs/jfs_dmap.c:2340
dbFreeDmap fs/jfs/jfs_dmap.c:2089 [inline]
dbFree+0x2dc/0x5d4 fs/jfs/jfs_dmap.c:398
txFreeMap+0x800/0xb94 fs/jfs/jfs_txnmgr.c:2516
xtTruncate+0xa1c/0x266c fs/jfs/jfs_xtree.c:2467
jfs_free_zero_link+0x2c0/0x424 fs/jfs/namei.c:758
jfs_evict_inode+0x2f4/0x3e4 fs/jfs/inode.c:159
evict+0x3d8/0x824 fs/inode.c:705
iput_final fs/inode.c:1834 [inline]
iput+0x728/0x7e8 fs/inode.c:1860
txUpdateMap+0x68c/0x7b0 fs/jfs/jfs_txnmgr.c:2368
txLazyCommit fs/jfs/jfs_txnmgr.c:2665 [inline]
jfs_lazycommit+0x360/0x930 fs/jfs/jfs_txnmgr.c:2733
kthread+0x254/0x2e0 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:850
irq event stamp: 76
hardirqs last enabled at (75): [<ffff800011c25a1c>] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:151 [inline]
hardirqs last enabled at (75): [<ffff800011c25a1c>] _raw_spin_unlock_irqrestore+0x48/0xac kernel/locking/spinlock.c:194
hardirqs last disabled at (76): [<ffff800011b3a55c>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (0): [<ffff80000818be70>] copy_process+0x1370/0x38f4 kernel/fork.c:2302
softirqs last disabled at (0): [<0000000000000000>] 0x0
---[ end trace 0000000000000000 ]---


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
10:20 AM (10 hours ago) 10:20 AM
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: eceeec79dbc6 Linux 5.15.210
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=11d03566580000
kernel config: https://syzkaller.appspot.com/x/.config?x=6a0cae3abafc69
dashboard link: https://syzkaller.appspot.com/bug?extid=6ca45cc69eba4e310924
compiler: Debian clang version 22.1.6 (++20260514074242+fc4aad7b5db3-1~exp1~20260514074407.73), Debian LLD 22.1.6

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/a8f82a67235a/disk-eceeec79.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/f10abb6026a6/vmlinux-eceeec79.xz
kernel image: https://storage.googleapis.com/syzbot-assets/ade6c70761ba/bzImage-eceeec79.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6ca45c...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 276 at fs/jfs/jfs_dmap.c:2943 dbAdjTree fs/jfs/jfs_dmap.c:2943 [inline]
WARNING: CPU: 0 PID: 276 at fs/jfs/jfs_dmap.c:2943 dbJoin+0xc17/0xd40 fs/jfs/jfs_dmap.c:2911
Modules linked in:
CPU: 1 PID: 276 Comm: jfsCommit Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/09/2026
RIP: 0010:dbAdjTree fs/jfs/jfs_dmap.c:2943 [inline]
RIP: 0010:dbJoin+0xc17/0xd40 fs/jfs/jfs_dmap.c:2911
Code: ff e8 8d 21 aa fe eb 0c e8 86 21 aa fe eb 05 e8 7f 21 aa fe 31 c0 48 83 c4 68 5b 41 5c 41 5d 41 5e 41 5f 5d c3 e8 69 21 aa fe <0f> 0b eb e6 44 89 e9 80 e1 07 38 c1 0f 8c 1d f4 ff ff 4c 89 ef e8
RSP: 0018:ffffc900030cf6b0 EFLAGS: 00010293
RAX: ffffffff82ced137 RBX: 0000000000000155 RCX: ffff88801e10d940
RDX: 0000000000000000 RSI: 0000000000000155 RDI: 0000000000020056
RBP: 0000000000000004 R08: ffffea0001c94687 R09: 1ffffd40003928d0
R10: dffffc0000000000 R11: fffff940003928d1 R12: dffffc0000000000
R13: ffff88807251a020 R14: 0000000000020056 R15: 0000000000000004
FS: 0000000000000000(0000) GS:ffff8880b9100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff26b1352f8 CR3: 0000000063702000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
dbFreeBits+0x49f/0xd40 fs/jfs/jfs_dmap.c:2408
dbFreeDmap fs/jfs/jfs_dmap.c:2157 [inline]
dbFree+0x31c/0x640 fs/jfs/jfs_dmap.c:398
txFreeMap+0x9e2/0xde0 fs/jfs/jfs_txnmgr.c:2550
xtTruncate+0xccf/0x2d10 fs/jfs/jfs_xtree.c:3428
jfs_free_zero_link+0x358/0x4b0 fs/jfs/namei.c:758
jfs_evict_inode+0x34c/0x430 fs/jfs/inode.c:159
evict+0x4b6/0x8b0 fs/inode.c:647
txLazyCommit fs/jfs/jfs_txnmgr.c:2699 [inline]
jfs_lazycommit+0x445/0xb60 fs/jfs/jfs_txnmgr.c:2767
kthread+0x42e/0x520 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>

syzbot

unread,
11:51 AM (8 hours ago) 11:51 AM
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: eceeec79dbc6 Linux 5.15.210
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=11c5e8ea580000
kernel config: https://syzkaller.appspot.com/x/.config?x=6a0cae3abafc69
dashboard link: https://syzkaller.appspot.com/bug?extid=6ca45cc69eba4e310924
compiler: Debian clang version 22.1.6 (++20260514074242+fc4aad7b5db3-1~exp1~20260514074407.73), Debian LLD 22.1.6
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11b0cd56580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=1045001c580000
mounted in repro: https://storage.googleapis.com/syzbot-assets/2fa3186cea6e/mount_0.gz
fsck result: failed (log: https://syzkaller.appspot.com/x/fsck.log?x=1544f4fe580000)

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+6ca45c...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 277 at fs/jfs/jfs_dmap.c:2943 dbAdjTree fs/jfs/jfs_dmap.c:2943 [inline]
WARNING: CPU: 0 PID: 277 at fs/jfs/jfs_dmap.c:2943 dbJoin+0xc17/0xd40 fs/jfs/jfs_dmap.c:2911
Modules linked in:
CPU: 0 PID: 277 Comm: jfsCommit Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/09/2026
RIP: 0010:dbAdjTree fs/jfs/jfs_dmap.c:2943 [inline]
RIP: 0010:dbJoin+0xc17/0xd40 fs/jfs/jfs_dmap.c:2911
Code: ff e8 8d 21 aa fe eb 0c e8 86 21 aa fe eb 05 e8 7f 21 aa fe 31 c0 48 83 c4 68 5b 41 5c 41 5d 41 5e 41 5f 5d c3 e8 69 21 aa fe <0f> 0b eb e6 44 89 e9 80 e1 07 38 c1 0f 8c 1d f4 ff ff 4c 89 ef e8
RSP: 0018:ffffc90002a7f6b0 EFLAGS: 00010293
RAX: ffffffff82ced137 RBX: 0000000000000155 RCX: ffff88801e091dc0
RDX: 0000000000000000 RSI: 0000000000000155 RDI: 0000000000020056
RBP: 0000000000000004 R08: ffffea0001c8d287 R09: 1ffffd4000391a50
R10: dffffc0000000000 R11: fffff94000391a51 R12: dffffc0000000000
R13: ffff88807234a020 R14: 0000000000020056 R15: 0000000000000004
FS: 0000000000000000(0000) GS:ffff8880b9100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000561712c7c0c8 CR3: 0000000029e26000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
dbFreeBits+0x49f/0xd40 fs/jfs/jfs_dmap.c:2408
dbFreeDmap fs/jfs/jfs_dmap.c:2157 [inline]
dbFree+0x31c/0x640 fs/jfs/jfs_dmap.c:398
txFreeMap+0x9e2/0xde0 fs/jfs/jfs_txnmgr.c:2550
xtTruncate+0xccf/0x2d10 fs/jfs/jfs_xtree.c:3428
jfs_free_zero_link+0x358/0x4b0 fs/jfs/namei.c:758
jfs_evict_inode+0x34c/0x430 fs/jfs/inode.c:159
evict+0x4b6/0x8b0 fs/inode.c:647
txLazyCommit fs/jfs/jfs_txnmgr.c:2699 [inline]
jfs_lazycommit+0x445/0xb60 fs/jfs/jfs_txnmgr.c:2767
kthread+0x42e/0x520 kernel/kthread.c:334
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:287
</TASK>


---
Reply all
Reply to author
Forward
0 new messages