[v6.1] kernel BUG in _ocfs2_free_suballoc_bits

5 views
Skip to first unread message

syzbot

unread,
Oct 27, 2024, 10:52:30 PM10/27/24
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 7ec6f9fa3d97 Linux 6.1.114
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13ef1a87980000
kernel config: https://syzkaller.appspot.com/x/.config?x=344cdb747ab79921
dashboard link: https://syzkaller.appspot.com/bug?extid=3b664d98a77a329be77e
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=129ba940580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12667e5f980000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/e7551ab2b38b/disk-7ec6f9fa.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/99ca69a69b01/vmlinux-7ec6f9fa.xz
kernel image: https://storage.googleapis.com/syzbot-assets/0d62742f11c2/Image-7ec6f9fa.gz.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/a43058f313f3/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+3b664d...@syzkaller.appspotmail.com

------------[ cut here ]------------
kernel BUG at fs/ocfs2/suballoc.c:2469!
Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP
Modules linked in:
CPU: 0 PID: 39 Comm: kworker/u4:2 Not tainted 6.1.114-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
Workqueue: ocfs2_wq ocfs2_truncate_log_worker
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : _ocfs2_free_suballoc_bits+0xdb8/0x11f8 fs/ocfs2/suballoc.c:2469
lr : _ocfs2_free_suballoc_bits+0xdb8/0x11f8 fs/ocfs2/suballoc.c:2469
sp : ffff80001d637540
x29: ffff80001d6376a0 x28: ffff0000e4c63338 x27: ffff0000e1bfb9f8
x26: 000000007f710456 x25: ffff800009f62184 x24: dfff800000000000
x23: 000000007f710d99 x22: ffff0000e3cc0e00 x21: 0000000000000e00
x20: 0000000000000e00 x19: 000000038d6d0000 x18: ffff80001d6373c0
x17: ffff800018aab000 x16: ffff8000122463ac x15: 0000000000000000
x14: 00000000fffffffc x13: ffff0000c0a5d340 x12: ffff80001d6375c0
x11: 0000000000ff0100 x10: 0000000000000000 x9 : ffff800009f6810c
x8 : ffff0000c0a5d340 x7 : 0000000000000000 x6 : ffff800009f62184
x5 : 000000007f710456 x4 : 000000038d6d0000 x3 : 0000000000000943
x2 : ffff0000e1bfb9f8 x1 : 0000000000000e00 x0 : 000000007f710d99
Call trace:
_ocfs2_free_suballoc_bits+0xdb8/0x11f8 fs/ocfs2/suballoc.c:2469
_ocfs2_free_clusters+0x530/0xa90 fs/ocfs2/suballoc.c:2569
ocfs2_free_clusters+0x50/0x68 fs/ocfs2/suballoc.c:2590
ocfs2_replay_truncate_records fs/ocfs2/alloc.c:5964 [inline]
__ocfs2_flush_truncate_log+0x648/0x1260 fs/ocfs2/alloc.c:6047
ocfs2_flush_truncate_log fs/ocfs2/alloc.c:6069 [inline]
ocfs2_truncate_log_worker+0xa8/0x1b4 fs/ocfs2/alloc.c:6082
process_one_work+0x7ac/0x1404 kernel/workqueue.c:2292
worker_thread+0x8e4/0xfec kernel/workqueue.c:2439
kthread+0x250/0x2d8 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:864
Code: 957e46d1 97963dd6 d4210000 97963dd4 (d4210000)
---[ end trace 0000000000000000 ]---


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages