Hello,
syzbot found the following issue on:
HEAD commit: e4f7d8be268e Linux 6.1.182
git tree: linux-6.1.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=1365669e580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link:
https://syzkaller.appspot.com/bug?extid=48f2d47f83a4c223ad14
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/7cd9b1875376/disk-e4f7d8be.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/4b5d35d18c31/vmlinux-e4f7d8be.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/d5ee64c2af77/Image-e4f7d8be.gz.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+48f2d4...@syzkaller.appspotmail.com
jffs2: warning: (10702) jffs2_sum_write_sumnode: Empty summary info!!!
------------[ cut here ]------------
kernel BUG at fs/jffs2/summary.c:868!
Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP
Modules linked in:
CPU: 0 PID: 10702 Comm: jffs2_gcd_mtd0 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
pstate: 62400005 (nZCv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : jffs2_sum_write_sumnode+0x1bcc/0x1bd8 fs/jffs2/summary.c:867
lr : jffs2_sum_write_sumnode+0x1bcc/0x1bd8 fs/jffs2/summary.c:867
sp : ffff800025117480
x29: ffff8000251175c0 x28: ffff0000d357a000 x27: 0000000000001008
x26: 0000000000000ff4 x25: ffff0000d357e120 x24: ffff0000f5f97e00
x23: ffff0000d357a5a8 x22: ffff8000251174e0 x21: 0000000000000000
x20: ffff0000d756d970 x19: dfff800000000000 x18: 1fffe00033e7277e
x17: ffff80001537d000 x16: ffff800011b90080 x15: 0000000040000000
x14: 0000000000000001 x13: 1ffff00004a22df8 x12: 0000000000000000
x11: ff00800008315484 x10: 0000000000000000 x9 : 66a07d2119729d00
x8 : 66a07d2119729d00 x7 : ffff80000825ab50 x6 : 0000000000000000
x5 : 0000000000000080 x4 : 0000000000000001 x3 : ffff80000a927f5c
x2 : ffff00019f393d10 x1 : 0000000100000000 x0 : 0000000000000046
Call trace:
jffs2_sum_write_sumnode+0x1bcc/0x1bd8 fs/jffs2/summary.c:867
jffs2_do_reserve_space+0x150/0xd5c fs/jffs2/nodemgmt.c:388
jffs2_reserve_space_gc+0x60/0xfc fs/jffs2/nodemgmt.c:222
jffs2_garbage_collect_pristine+0xf4/0xb9c fs/jffs2/gc.c:613
jffs2_garbage_collect_live+0x570/0x2950 fs/jffs2/gc.c:546
jffs2_garbage_collect_pass+0x1440/0x1a68 fs/jffs2/gc.c:464
jffs2_garbage_collect_thread+0x3dc/0x44c fs/jffs2/background.c:155
kthread+0x254/0x2e0 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:850
Code: 913e8000 d005b522 9127bc42 97a562c9 (d4210000)
---[ end trace 0000000000000000 ]---
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup