Hello,
syzbot found the following issue on:
HEAD commit: 258cf62a6dfd Linux 6.6.137
git tree: linux-6.6.y
console output:
https://syzkaller.appspot.com/x/log.txt?x=1424d5ba580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=c5b35c4db8465904
dashboard link:
https://syzkaller.appspot.com/bug?extid=8cbe100e78641dc50b4c
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/8abd93876bdd/disk-258cf62a.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/721d0cc7467a/vmlinux-258cf62a.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/7f2dfd911e3d/bzImage-258cf62a.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+8cbe10...@syzkaller.appspotmail.com
kworker/u4:15: attempt to access beyond end of device
loop5: rw=1, sector=320, nr_sectors = 8 limit=0
gfs2: fsid=syz:syz.0: Error 10 writing to journal, jid=0
gfs2: fsid=syz:syz.0: fatal: I/O error(s)
gfs2: fsid=syz:syz.0: about to withdraw this file system
BUG: sleeping function called from invalid context at fs/gfs2/util.c:159
in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 10226, name: kworker/u4:15
preempt_count: 1, expected: 0
RCU nest depth: 0, expected: 0
5 locks held by kworker/u4:15/10226:
#0: ffff88801de4c938 ((wq_completion)writeback){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:2628 [inline]
#0: ffff88801de4c938 ((wq_completion)writeback){+.+.}-{0:0}, at: process_scheduled_works+0x96f/0x15d0 kernel/workqueue.c:2730
#1: ffffc90003187d00 ((work_completion)(&(&wb->dwork)->work)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:2628 [inline]
#1: ffffc90003187d00 ((work_completion)(&(&wb->dwork)->work)){+.+.}-{0:0}, at: process_scheduled_works+0x96f/0x15d0 kernel/workqueue.c:2730
#2: ffff888050471060 (&sdp->sd_log_flush_lock){++++}-{3:3}, at: gfs2_log_flush+0x104/0x2500 fs/gfs2/log.c:1042
#3: ffff888050470e88 (&sdp->sd_log_lock){+.+.}-{2:2}, at: spin_lock include/linux/spinlock.h:351 [inline]
#3: ffff888050470e88 (&sdp->sd_log_lock){+.+.}-{2:2}, at: gfs2_log_lock fs/gfs2/log.h:32 [inline]
#3: ffff888050470e88 (&sdp->sd_log_lock){+.+.}-{2:2}, at: gfs2_flush_revokes+0x52/0x80 fs/gfs2/log.c:814
#4: ffff888050471248 (&sdp->sd_freeze_mutex){+.+.}-{3:3}, at: signal_our_withdraw fs/gfs2/util.c:152 [inline]
#4: ffff888050471248 (&sdp->sd_freeze_mutex){+.+.}-{3:3}, at: gfs2_withdraw+0x43a/0x13d0 fs/gfs2/util.c:333
Preemption disabled at:
[<0000000000000000>] 0x0
CPU: 1 PID: 10226 Comm: kworker/u4:15 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026
Workqueue: writeback wb_workfn (flush-7:5)
Call Trace:
<TASK>
dump_stack_lvl+0x18c/0x250 lib/dump_stack.c:106
__might_resched+0x4ad/0x630 kernel/sched/core.c:10211
signal_our_withdraw fs/gfs2/util.c:157 [inline]
gfs2_withdraw+0x488/0x13d0 fs/gfs2/util.c:333
gfs2_ail1_empty+0x7be/0x850 fs/gfs2/log.c:377
gfs2_flush_revokes+0x5c/0x80 fs/gfs2/log.c:815
revoke_lo_before_commit+0x2c/0x5f0 fs/gfs2/lops.c:867
lops_before_commit fs/gfs2/lops.h:42 [inline]
gfs2_log_flush+0xbd6/0x2500 fs/gfs2/log.c:1102
gfs2_write_inode+0x23f/0x3d0 fs/gfs2/super.c:457
write_inode fs/fs-writeback.c:1483 [inline]
__writeback_single_inode+0x705/0xec0 fs/fs-writeback.c:1700
writeback_sb_inodes+0x7cd/0xf50 fs/fs-writeback.c:1926
wb_writeback+0x46a/0xbf0 fs/fs-writeback.c:2105
wb_do_writeback fs/fs-writeback.c:2252 [inline]
wb_workfn+0x400/0xe60 fs/fs-writeback.c:2292
process_one_work kernel/workqueue.c:2653 [inline]
process_scheduled_works+0xa5d/0x15d0 kernel/workqueue.c:2730
worker_thread+0xa55/0xfc0 kernel/workqueue.c:2811
kthread+0x2fa/0x390 kernel/kthread.c:388
ret_from_fork+0x48/0x80 arch/x86/kernel/process.c:152
ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:293
</TASK>
BUG: scheduling while atomic: kworker/u4:15/10226/0x00000002
5 locks held by kworker/u4:15/10226:
#0: ffff88801de4c938 ((wq_completion)writeback){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:2628 [inline]
#0: ffff88801de4c938 ((wq_completion)writeback){+.+.}-{0:0}, at: process_scheduled_works+0x96f/0x15d0 kernel/workqueue.c:2730
#1: ffffc90003187d00 ((work_completion)(&(&wb->dwork)->work)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:2628 [inline]
#1: ffffc90003187d00 ((work_completion)(&(&wb->dwork)->work)){+.+.}-{0:0}, at: process_scheduled_works+0x96f/0x15d0 kernel/workqueue.c:2730
#2: ffff888050471060 (&sdp->sd_log_flush_lock){++++}-{3:3}, at: gfs2_log_flush+0x104/0x2500 fs/gfs2/log.c:1042
#3: ffff888050470e88 (&sdp->sd_log_lock){+.+.}-{2:2}, at: spin_lock include/linux/spinlock.h:351 [inline]
#3: ffff888050470e88 (&sdp->sd_log_lock){+.+.}-{2:2}, at: gfs2_log_lock fs/gfs2/log.h:32 [inline]
#3: ffff888050470e88 (&sdp->sd_log_lock){+.+.}-{2:2}, at: gfs2_flush_revokes+0x52/0x80 fs/gfs2/log.c:814
#4: ffff888050471248 (&sdp->sd_freeze_mutex){+.+.}-{3:3}, at: signal_our_withdraw fs/gfs2/util.c:152 [inline]
#4: ffff888050471248 (&sdp->sd_freeze_mutex){+.+.}-{3:3}, at: gfs2_withdraw+0x43a/0x13d0 fs/gfs2/util.c:333
Modules linked in:
Preemption disabled at:
[<0000000000000000>] 0x0
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup