Hello,
syzbot found the following issue on:
HEAD commit: 4477a78374a5 Add linux-next specific files for 20260814
git tree: linux-next
console output:
https://syzkaller.appspot.com/x/log.txt?x=14e5ea25580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=9b32a36dd637b06f
dashboard link:
https://syzkaller.appspot.com/bug?extid=e1fcebe01f24c6309792
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro:
https://syzkaller.appspot.com/x/repro.syz?x=1320d949580000
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/994c1c8c560e/disk-4477a783.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/cd54543d69ae/vmlinux-4477a783.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/407cdf8f3fc2/bzImage-4477a783.xz
mounted in repro:
https://storage.googleapis.com/syzbot-assets/8c65ba7adddd/mount_0.gz
fsck result: failed (log:
https://syzkaller.appspot.com/x/fsck.log?x=16b9fa79580000)
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+e1fceb...@syzkaller.appspotmail.com
=============================
WARNING: suspicious RCU usage
syzkaller #0 Not tainted
-----------------------------
./include/linux/radix-tree.h:179 suspicious rcu_dereference_check() usage!
other info that might help us debug this:
rcu_scheduler_active = 2, debug_locks = 1
locks held by syz-executor/5756: 2, last CPU#0:
#0: ffff888079faa0e8 (&type->s_umount_key#56){+.+.}-{4:4}, at: __super_lock fs/super.c:60 [inline]
#0: ffff888079faa0e8 (&type->s_umount_key#56){+.+.}-{4:4}, at: __super_lock_excl fs/super.c:75 [inline]
#0: ffff888079faa0e8 (&type->s_umount_key#56){+.+.}-{4:4}, at: deactivate_super+0xac/0xe0 fs/super.c:631
#1: ffff88801cf908c8 (&im->ino_lock){+.+.}-{3:3}, at: spin_lock include/linux/spinlock.h:347 [inline]
#1: ffff88801cf908c8 (&im->ino_lock){+.+.}-{3:3}, at: __clear_ino_bitmap fs/f2fs/checkpoint.c:809 [inline]
#1: ffff88801cf908c8 (&im->ino_lock){+.+.}-{3:3}, at: f2fs_remove_ino_entry+0x18d/0x3f0 fs/f2fs/checkpoint.c:855
stack backtrace:
CPU: 0 UID: 0 PID: 5756 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
lockdep_rcu_suspicious+0x140/0x1d0 kernel/locking/lockdep.c:6938
radix_tree_deref_slot include/linux/radix-tree.h:179 [inline]
__clear_ino_bitmap fs/f2fs/checkpoint.c:812 [inline]
f2fs_remove_ino_entry+0x3ae/0x3f0 fs/f2fs/checkpoint.c:855
f2fs_delete_inode fs/f2fs/inode.c:946 [inline]
f2fs_evict_inode+0x83d/0x21f0 fs/f2fs/inode.c:1100
evict+0x624/0xb50 fs/inode.c:822
f2fs_pre_evict_inode fs/f2fs/inode.c:911 [inline]
f2fs_evict_inode+0x20f/0x21f0 fs/f2fs/inode.c:1096
evict+0x624/0xb50 fs/inode.c:822
dispose_list fs/inode.c:864 [inline]
evict_inodes+0x7e3/0x870 fs/inode.c:918
generic_shutdown_super+0xaa/0x2d0 fs/super.c:755
kill_block_super+0x44/0xa0 fs/super.c:1918
kill_f2fs_super+0x3b3/0x700 fs/f2fs/super.c:5635
deactivate_locked_super+0xbc/0x110 fs/super.c:603
cleanup_mnt+0x3d3/0x460 fs/namespace.c:1317
task_work_run+0x1d9/0x270 kernel/task_work.c:233
resume_user_mode_work include/linux/resume_user_mode.h:50 [inline]
__exit_to_user_mode_loop kernel/entry/common.c:70 [inline]
exit_to_user_mode_loop+0x204/0x770 kernel/entry/common.c:101
__exit_to_user_mode_prepare include/linux/irq-entry-common.h:207 [inline]
syscall_exit_to_user_mode_prepare include/linux/irq-entry-common.h:230 [inline]
syscall_exit_to_user_mode include/linux/entry-common.h:336 [inline]
do_syscall_64+0x328/0x520 arch/x86/entry/syscall_64.c:89
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f896299f317
Code: a2 c7 05 dc 43 25 00 00 00 00 00 eb 96 e8 e1 12 00 00 90 31 f6 e9 09 00 00 00 66 0f 1f 84 00 00 00 00 00 b8 a6 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 01 c3 48 c7 c2 e8 ff ff ff f7 d8 64 89 02 b8
RSP: 002b:00007ffc3257e798 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6
RAX: 0000000000000000 RBX: 00007f8962a34474 RCX: 00007f896299f317
RDX: 0000000000000000 RSI: 0000000000000009 RDI: 00007ffc3257e850
RBP: 00007ffc3257e850 R08: 00007ffc3257f850 R09: 00000000ffffffff
R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffc3257f8e0
R13: 00007f8962a34474 R14: 0000000000016591 R15: 00007ffc3257f920
</TASK>
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup