[syzbot] [jffs2?] WARNING: bad unlock balance in jffs2_do_create

1 view
Skip to first unread message

syzbot

unread,
12:40 PM (3 hours ago) 12:40 PM
to dw...@infradead.org, linux-...@vger.kernel.org, linu...@lists.infradead.org, ric...@nod.at, syzkall...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 2f1baf1fc892 Merge tag 'trace-v7.2-rc7' of git://git.kerne..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=13d46279580000
kernel config: https://syzkaller.appspot.com/x/.config?x=ead6a6de2292ff28
dashboard link: https://syzkaller.appspot.com/bug?extid=250fde257a3eebba4426
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-2f1baf1f.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/3cf4d3de19da/vmlinux-2f1baf1f.xz
kernel image: https://storage.googleapis.com/syzbot-assets/2c309c87fcb0/bzImage-2f1baf1f.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+250fde...@syzkaller.appspotmail.com

Zero length message leads to an empty skb
jffs2: notice: (5313) jffs2_build_xattr_subsystem: complete building xattr subsystem, 0 of xdatum (0 unchecked, 0 orphan) and 0 of xref (0 dead, 0 orphan) found.
overlayfs: upper fs does not support tmpfile.
FAULT_INJECTION: forcing a failure.
name failslab, interval 1, probability 0, space 0, times 1
CPU: 0 UID: 0 PID: 5313 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
fail_dump lib/fault-inject.c:73 [inline]
should_fail_ex+0x40c/0x560 lib/fault-inject.c:174
should_failslab+0xa8/0x100 mm/failslab.c:46
slab_pre_alloc_hook mm/slub.c:4539 [inline]
slab_alloc_node mm/slub.c:4897 [inline]
__kmalloc_cache_noprof+0xa8/0x660 mm/slub.c:5485
_kmalloc_noprof include/linux/slab.h:988 [inline]
jffs2_sum_add_kvec+0x858/0x1870 fs/jffs2/summary.c:266
jffs2_flash_direct_writev+0xaa/0xe0 fs/jffs2/writev.c:22
jffs2_flash_writev+0x156/0x1550 fs/jffs2/wbuf.c:805
jffs2_write_dnode+0x485/0xe20 fs/jffs2/write.c:109
jffs2_do_create+0x18e/0xe00 fs/jffs2/write.c:465
jffs2_create+0x1c8/0x320 fs/jffs2/dir.c:205
vfs_create+0x2c4/0x450 fs/namei.c:4202
ovl_do_create+0x81/0xf0 fs/overlayfs/overlayfs.h:244
ovl_create_real+0x1a8/0x740 fs/overlayfs/dir.c:180
ovl_create_temp+0x169/0x240 fs/overlayfs/dir.c:267
ovl_check_rename_whiteout fs/overlayfs/super.c:575 [inline]
ovl_make_workdir fs/overlayfs/super.c:713 [inline]
ovl_get_workdir fs/overlayfs/super.c:836 [inline]
ovl_fill_super_creds fs/overlayfs/super.c:1449 [inline]
ovl_fill_super+0x3c9b/0x5d40 fs/overlayfs/super.c:1560
vfs_get_super fs/super.c:1273 [inline]
get_tree_nodev+0xbb/0x150 fs/super.c:1292
vfs_get_tree+0x92/0x2a0 fs/super.c:1700
fc_mount fs/namespace.c:1198 [inline]
do_new_mount_fc fs/namespace.c:3765 [inline]
do_new_mount+0x319/0xdc0 fs/namespace.c:3841
do_mount fs/namespace.c:4174 [inline]
__do_sys_mount fs/namespace.c:4390 [inline]
__se_sys_mount+0x31d/0x420 fs/namespace.c:4367
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fe775d9e0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fe776d50fe8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007fe776025fa0 RCX: 00007fe775d9e0d9
RDX: 0000200000000b80 RSI: 0000200000000100 RDI: 0000000000000000
RBP: 00007fe776d51050 R08: 0000200000000240 R09: 0000000000000000
R10: 0000000000000008 R11: 0000000000000246 R12: 0000000000000002
R13: 00007fe776026038 R14: 00007fe776025fa0 R15: 00007ffdf4560bd8
</TASK>
jffs2: warning: (5313) jffs2_sum_add_kvec: MEMORY ALLOCATION ERROR!
jffs2: Write of 68 bytes at 0x0001e218 failed. returned -12, retlen 0
jffs2: Not marking the space at 0x0001e218 as dirty because the flash driver returned retlen zero

=====================================
WARNING: bad unlock balance detected!
syzkaller #0 Not tainted
-------------------------------------
syz.0.0/5313 is trying to release lock (&c->alloc_sem) at:
[<ffffffff833a6ebe>] jffs2_do_create+0x1ae/0xe00 fs/jffs2/write.c:474
but there are no more locks to release!

other info that might help us debug this:
3 locks held by syz.0.0/5313:
#0: ffff8880424140d8 (&type->s_umount_key#52/1){+.+.}-{4:4}, at: alloc_super fs/super.c:345 [inline]
#0: ffff8880424140d8 (&type->s_umount_key#52/1){+.+.}-{4:4}, at: sget_fc+0x938/0x1900 fs/super.c:766
#1: ffff888012c72450 (sb_writers#12){.+.+}-{0:0}, at: mnt_want_write+0x41/0x90 fs/namespace.c:494
#2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: inode_lock_nested include/linux/fs.h:1069 [inline]
#2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: __start_dirop fs/namei.c:2918 [inline]
#2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: start_dirop fs/namei.c:2942 [inline]
#2: ffff88801229a880 (&type->i_mutex_dir_key#8/1){+.+.}-{4:4}, at: start_creating+0xbe/0x100 fs/namei.c:3406

stack backtrace:
CPU: 0 UID: 0 PID: 5313 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
print_unlock_imbalance_bug+0xdc/0xf0 kernel/locking/lockdep.c:5298
__lock_release kernel/locking/lockdep.c:5537 [inline]
lock_release+0x248/0x3c0 kernel/locking/lockdep.c:5889
__mutex_unlock_slowpath+0x88/0x900 kernel/locking/mutex.c:989
jffs2_do_create+0x1ae/0xe00 fs/jffs2/write.c:474
jffs2_create+0x1c8/0x320 fs/jffs2/dir.c:205
vfs_create+0x2c4/0x450 fs/namei.c:4202
ovl_do_create+0x81/0xf0 fs/overlayfs/overlayfs.h:244
ovl_create_real+0x1a8/0x740 fs/overlayfs/dir.c:180
ovl_create_temp+0x169/0x240 fs/overlayfs/dir.c:267
ovl_check_rename_whiteout fs/overlayfs/super.c:575 [inline]
ovl_make_workdir fs/overlayfs/super.c:713 [inline]
ovl_get_workdir fs/overlayfs/super.c:836 [inline]
ovl_fill_super_creds fs/overlayfs/super.c:1449 [inline]
ovl_fill_super+0x3c9b/0x5d40 fs/overlayfs/super.c:1560
vfs_get_super fs/super.c:1273 [inline]
get_tree_nodev+0xbb/0x150 fs/super.c:1292
vfs_get_tree+0x92/0x2a0 fs/super.c:1700
fc_mount fs/namespace.c:1198 [inline]
do_new_mount_fc fs/namespace.c:3765 [inline]
do_new_mount+0x319/0xdc0 fs/namespace.c:3841
do_mount fs/namespace.c:4174 [inline]
__do_sys_mount fs/namespace.c:4390 [inline]
__se_sys_mount+0x31d/0x420 fs/namespace.c:4367
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fe775d9e0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fe776d50fe8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007fe776025fa0 RCX: 00007fe775d9e0d9
RDX: 0000200000000b80 RSI: 0000200000000100 RDI: 0000000000000000
RBP: 00007fe776d51050 R08: 0000200000000240 R09: 0000000000000000
R10: 0000000000000008 R11: 0000000000000246 R12: 0000000000000002
R13: 00007fe776026038 R14: 00007fe776025fa0 R15: 00007ffdf4560bd8
</TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages