Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
kernel BUG in ocfs2_commit_truncate
------------[ cut here ]------------
kernel BUG at fs/ocfs2/alloc.c:686!
Oops: invalid opcode: 0000 [#1] SMP KASAN PTI
CPU: 1 UID: 0 PID: 6423 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/02/2025
RIP: 0010:ocfs2_new_path fs/ocfs2/alloc.c:686 [inline]
RIP: 0010:ocfs2_commit_truncate+0x223f/0x2250 fs/ocfs2/alloc.c:7254
Code: 10 e8 35 f5 8b fe e9 3a fc ff ff e8 fb fc 26 fe 44 89 fe 48 c7 c7 00 ab 24 8e e8 7c 61 1f 01 e9 45 fc ff ff e8 e2 fc 26 fe 90 <0f> 0b 66 66 66 66 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90
RSP: 0018:ffffc90003e2f1a0 EFLAGS: 00010293
RAX: ffffffff8397c64e RBX: ffff8880769bce80 RCX: ffff88802e9a9e40
RDX: 0000000000000000 RSI: 0000000000000138 RDI: 0000000000000004
RBP: ffffc90003e2f4d0 R08: ffffc90003e2f38f R09: 0000000000000000
R10: ffffc90003e2f380 R11: fffff520007c5e72 R12: dffffc0000000000
R13: 1ffff920007c5e54 R14: 0000000000000138 R15: 1ffff1100cc73e58
FS: 0000555560f90500(0000) GS:ffff888126504000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000555560fbb648 CR3: 0000000076f74000 CR4: 00000000003526f0
Call Trace:
<TASK>
ocfs2_truncate_for_delete fs/ocfs2/inode.c:699 [inline]
ocfs2_wipe_inode fs/ocfs2/inode.c:866 [inline]
ocfs2_delete_inode fs/ocfs2/inode.c:1155 [inline]
ocfs2_evict_inode+0x1138/0x4100 fs/ocfs2/inode.c:1295
evict+0x504/0x9c0 fs/inode.c:810
d_delete_notify include/linux/fsnotify.h:377 [inline]
vfs_rmdir+0x3ec/0x520 fs/namei.c:4561
do_rmdir+0x25f/0x550 fs/namei.c:4603
__do_sys_unlinkat fs/namei.c:4777 [inline]
__se_sys_unlinkat fs/namei.c:4771 [inline]
__x64_sys_unlinkat+0xc2/0xf0 fs/namei.c:4771
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xfa/0xfa0 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fcf61f852f7
Code: 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 b8 07 01 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffed1eb5598 EFLAGS: 00000207 ORIG_RAX: 0000000000000107
RAX: ffffffffffffffda RBX: 0000000000000065 RCX: 00007fcf61f852f7
RDX: 0000000000000200 RSI: 00007ffed1eb6740 RDI: 00000000ffffff9c
RBP: 00007fcf6200180c R08: 0000555560fb366b R09: 0000000000000000
R10: 0000000000001000 R11: 0000000000000207 R12: 00007ffed1eb6740
R13: 00007fcf6200180c R14: 00007ffed1eb88f0 R15: 0000000000000001
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:ocfs2_new_path fs/ocfs2/alloc.c:686 [inline]
RIP: 0010:ocfs2_commit_truncate+0x223f/0x2250 fs/ocfs2/alloc.c:7254
Code: 10 e8 35 f5 8b fe e9 3a fc ff ff e8 fb fc 26 fe 44 89 fe 48 c7 c7 00 ab 24 8e e8 7c 61 1f 01 e9 45 fc ff ff e8 e2 fc 26 fe 90 <0f> 0b 66 66 66 66 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90
RSP: 0018:ffffc90003e2f1a0 EFLAGS: 00010293
RAX: ffffffff8397c64e RBX: ffff8880769bce80 RCX: ffff88802e9a9e40
RDX: 0000000000000000 RSI: 0000000000000138 RDI: 0000000000000004
RBP: ffffc90003e2f4d0 R08: ffffc90003e2f38f R09: 0000000000000000
R10: ffffc90003e2f380 R11: fffff520007c5e72 R12: dffffc0000000000
R13: 1ffff920007c5e54 R14: 0000000000000138 R15: 1ffff1100cc73e58
FS: 0000555560f90500(0000) GS:ffff888126404000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000c0070ed000 CR3: 0000000076f74000 CR4: 00000000003526f0
Tested on:
commit: 552c5071 Merge tag 'vfio-v6.18-rc3' of
https://github...
git tree:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
console output:
https://syzkaller.appspot.com/x/log.txt?x=146b2d42580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=a1215729170d20fc
dashboard link:
https://syzkaller.appspot.com/bug?extid=c16daba279a1161acfb0
compiler: Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
patch:
https://syzkaller.appspot.com/x/patch.diff?x=126afc58580000