[v6.1] BUG: Dentry still in use in unmount

4 views
Skip to first unread message

syzbot

unread,
Jan 6, 2025, 9:20:24 AM1/6/25
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 7dc732d24ff7 Linux 6.1.123
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12d8b418580000
kernel config: https://syzkaller.appspot.com/x/.config?x=da1827eaa51b65c3
dashboard link: https://syzkaller.appspot.com/bug?extid=d7dfbc1b53951d7719af
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/b77a36eba7b4/disk-7dc732d2.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/f5334562da28/vmlinux-7dc732d2.xz
kernel image: https://storage.googleapis.com/syzbot-assets/f0a16f9a500c/Image-7dc732d2.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d7dfbc...@syzkaller.appspotmail.com

gfs2: fsid=syz:syz.0: first mount done, others may mount
BUG: Dentry 00000000dd03cd3d{i=925,n=/} still in use (5) [unmount of gfs2 loop2]
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4963 at fs/dcache.c:1681 umount_check+0x180/0x1bc fs/dcache.c:1672
Modules linked in:
CPU: 0 PID: 4963 Comm: syz.2.137 Not tainted 6.1.123-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : umount_check+0x180/0x1bc fs/dcache.c:1672
lr : umount_check+0x180/0x1bc fs/dcache.c:1672
sp : ffff8000236d7760
x29: ffff8000236d7760 x28: ffff7000046daf48 x27: ffff0000e1f42468
x26: ffff8000236d7a40 x25: dfff800000000000 x24: ffff0000d70d0000
x23: dfff800000000000 x22: ffff8000161c2440 x21: 0000000000000005
x20: 0000000000000925 x19: ffff0000e1f42468 x18: ffff8000236d6cc0
x17: 756f6d6e755b2029 x16: ffff80001232d384 x15: 0000000000000002
x14: 00000000ffffffff x13: 0000000000000001 x12: 0000000000080000
x11: 000000000000766c x10: ffff800026569000 x9 : be7d6c040e6cbe00
x8 : be7d6c040e6cbe00 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff8000236d7078 x4 : ffff800015b731c0 x3 : ffff80000ab3646c
x2 : ffff0001b3cdfcd0 x1 : 0000000000000001 x0 : 0000000000000051
Call trace:
umount_check+0x180/0x1bc fs/dcache.c:1672
d_walk+0x6c/0x660 fs/dcache.c:1367
do_one_tree+0x44/0xfc fs/dcache.c:1688
shrink_dcache_for_umount+0x80/0x12c fs/dcache.c:1704
generic_shutdown_super+0x68/0x328 fs/super.c:473
kill_block_super+0x70/0xdc fs/super.c:1470
gfs2_kill_sb+0xc0/0xd4
deactivate_locked_super+0xac/0x124 fs/super.c:332
deactivate_super+0xf0/0x110 fs/super.c:363
gfs2_thaw_super+0x18c/0x25c fs/gfs2/super.c:828
do_vfs_ioctl+0x1024/0x26f8
__do_sys_ioctl fs/ioctl.c:868 [inline]
__se_sys_ioctl fs/ioctl.c:856 [inline]
__arm64_sys_ioctl+0xe4/0x1c8 fs/ioctl.c:856
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x168 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
irq event stamp: 101512
hardirqs last enabled at (101511): [<ffff80000833f25c>] __up_console_sem+0xb4/0x100 kernel/printk/printk.c:261
hardirqs last disabled at (101512): [<ffff800012329064>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (101470): [<ffff800008030408>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (101468): [<ffff8000080303d4>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:19
---[ end trace 0000000000000000 ]---
BUG: Dentry 00000000dd03cd3d{i=925,n=/} still in use (4) [unmount of gfs2 loop2]
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4963 at fs/dcache.c:1681 umount_check+0x180/0x1bc fs/dcache.c:1672
Modules linked in:
CPU: 0 PID: 4963 Comm: syz.2.137 Tainted: G W 6.1.123-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : umount_check+0x180/0x1bc fs/dcache.c:1672
lr : umount_check+0x180/0x1bc fs/dcache.c:1672
sp : ffff8000236d7760
x29: ffff8000236d7760 x28: ffff0000e1f42580 x27: ffff0000e1f42468
x26: ffff0000e1f42468 x25: dfff800000000000 x24: ffff0000d70d0000
x23: dfff800000000000 x22: ffff8000161c2440 x21: 0000000000000004
x20: 0000000000000925 x19: ffff0000e1f42468 x18: ffff8000236d6cc0
x17: 756f6d6e755b2029 x16: ffff80001232d384 x15: 0000000000000002
x14: 00000000ffffffff x13: 0000000000000001 x12: 0000000000080000
x11: 0000000000026a6d x10: ffff800026569000 x9 : be7d6c040e6cbe00
x8 : be7d6c040e6cbe00 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff8000236d7078 x4 : ffff800015b731c0 x3 : ffff80000ab3646c
x2 : ffff0001b3cdfcd0 x1 : 0000000000000002 x0 : 0000000000000051
Call trace:
umount_check+0x180/0x1bc fs/dcache.c:1672
d_walk+0x6c/0x660 fs/dcache.c:1367
do_one_tree+0x44/0xfc fs/dcache.c:1688
shrink_dcache_for_umount+0x80/0x12c fs/dcache.c:1704
generic_shutdown_super+0x68/0x328 fs/super.c:473
kill_block_super+0x70/0xdc fs/super.c:1470
gfs2_kill_sb+0xc0/0xd4
deactivate_locked_super+0xac/0x124 fs/super.c:332
deactivate_super+0xf0/0x110 fs/super.c:363
gfs2_thaw_super+0x18c/0x25c fs/gfs2/super.c:828
do_vfs_ioctl+0x1024/0x26f8
__do_sys_ioctl fs/ioctl.c:868 [inline]
__se_sys_ioctl fs/ioctl.c:856 [inline]
__arm64_sys_ioctl+0xe4/0x1c8 fs/ioctl.c:856
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x168 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
irq event stamp: 101632
hardirqs last enabled at (101631): [<ffff80000833f25c>] __up_console_sem+0xb4/0x100 kernel/printk/printk.c:261
hardirqs last disabled at (101632): [<ffff800012329064>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (101610): [<ffff8000081c3414>] softirq_handle_end kernel/softirq.c:414 [inline]
softirqs last enabled at (101610): [<ffff8000081c3414>] handle_softirqs+0xb84/0xd58 kernel/softirq.c:599
softirqs last disabled at (101565): [<ffff800008020174>] __do_softirq+0x14/0x20 kernel/softirq.c:605
---[ end trace 0000000000000000 ]---


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Jan 6, 2025, 9:38:25 AM1/6/25
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 7dc732d24ff7 Linux 6.1.123
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13c4b418580000
kernel config: https://syzkaller.appspot.com/x/.config?x=da1827eaa51b65c3
dashboard link: https://syzkaller.appspot.com/bug?extid=d7dfbc1b53951d7719af
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=173736f8580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=130079c4580000
mounted in repro: https://storage.googleapis.com/syzbot-assets/49614d3cb7b9/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+d7dfbc...@syzkaller.appspotmail.com

gfs2: fsid=syz:syz.0: first mount done, others may mount
BUG: Dentry 00000000868f9618{i=925,n=/} still in use (5) [unmount of gfs2 loop0]
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4291 at fs/dcache.c:1681 umount_check+0x180/0x1bc fs/dcache.c:1672
Modules linked in:
CPU: 0 PID: 4291 Comm: syz-executor371 Not tainted 6.1.123-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : umount_check+0x180/0x1bc fs/dcache.c:1672
lr : umount_check+0x180/0x1bc fs/dcache.c:1672
sp : ffff800021587760
x29: ffff800021587760 x28: ffff7000042b0f48 x27: ffff0000df4c6a48
x26: ffff800021587a40 x25: dfff800000000000 x24: ffff0000da2fe000
x23: dfff800000000000 x22: ffff8000161c2440 x21: 0000000000000005
x20: 0000000000000925 x19: ffff0000df4c6a48 x18: ffff800021586cc0
x17: 756f6d6e755b2029 x16: ffff80001232d384 x15: 0000000000000000
x14: 00000000ffffffff x13: 0000000000000001 x12: 0000000000000001
x11: 0000000000ff0100 x10: 0000000000000000 x9 : 9e0395660b568c00
x8 : 9e0395660b568c00 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff800021587078 x4 : ffff800015b731c0 x3 : ffff8000085869b0
x2 : 0000000000000001 x1 : 0000000100000001 x0 : 0000000000000051
Call trace:
umount_check+0x180/0x1bc fs/dcache.c:1672
d_walk+0x6c/0x660 fs/dcache.c:1367
do_one_tree+0x44/0xfc fs/dcache.c:1688
shrink_dcache_for_umount+0x80/0x12c fs/dcache.c:1704
generic_shutdown_super+0x68/0x328 fs/super.c:473
kill_block_super+0x70/0xdc fs/super.c:1470
gfs2_kill_sb+0xc0/0xd4
deactivate_locked_super+0xac/0x124 fs/super.c:332
deactivate_super+0xf0/0x110 fs/super.c:363
gfs2_thaw_super+0x18c/0x25c fs/gfs2/super.c:828
do_vfs_ioctl+0x1024/0x26f8
__do_sys_ioctl fs/ioctl.c:868 [inline]
__se_sys_ioctl fs/ioctl.c:856 [inline]
__arm64_sys_ioctl+0xe4/0x1c8 fs/ioctl.c:856
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x168 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
irq event stamp: 96078
hardirqs last enabled at (96077): [<ffff80000833f25c>] __up_console_sem+0xb4/0x100 kernel/printk/printk.c:261
hardirqs last disabled at (96078): [<ffff800012329064>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (95770): [<ffff800008030408>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (95768): [<ffff8000080303d4>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:19
---[ end trace 0000000000000000 ]---
BUG: Dentry 00000000868f9618{i=925,n=/} still in use (5) [unmount of gfs2 loop0]
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4291 at fs/dcache.c:1681 umount_check+0x180/0x1bc fs/dcache.c:1672
Modules linked in:
CPU: 0 PID: 4291 Comm: syz-executor371 Tainted: G W 6.1.123-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : umount_check+0x180/0x1bc fs/dcache.c:1672
lr : umount_check+0x180/0x1bc fs/dcache.c:1672
sp : ffff800021587760
x29: ffff800021587760 x28: ffff0000df4c6b60 x27: ffff0000df4c6a48
x26: ffff0000df4c6a48 x25: dfff800000000000 x24: ffff0000da2fe000
x23: dfff800000000000 x22: ffff8000161c2440 x21: 0000000000000005
x20: 0000000000000925 x19: ffff0000df4c6a48 x18: ffff800021586cc0
x17: 756f6d6e755b2029 x16: ffff80001227ac80 x15: 0000000000000000
x14: 00000000ffffffff x13: 0000000000000001 x12: 0000000000000001
x11: 0000000000ff0100 x10: 0000000000000000 x9 : 9e0395660b568c00
x8 : 9e0395660b568c00 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff800021587078 x4 : ffff800015b731c0 x3 : ffff800008349ebc
x2 : 0000000000000001 x1 : 0000000100000002 x0 : 0000000000000051
Call trace:
umount_check+0x180/0x1bc fs/dcache.c:1672
d_walk+0x6c/0x660 fs/dcache.c:1367
do_one_tree+0x44/0xfc fs/dcache.c:1688
shrink_dcache_for_umount+0x80/0x12c fs/dcache.c:1704
generic_shutdown_super+0x68/0x328 fs/super.c:473
kill_block_super+0x70/0xdc fs/super.c:1470
gfs2_kill_sb+0xc0/0xd4
deactivate_locked_super+0xac/0x124 fs/super.c:332
deactivate_super+0xf0/0x110 fs/super.c:363
gfs2_thaw_super+0x18c/0x25c fs/gfs2/super.c:828
do_vfs_ioctl+0x1024/0x26f8
__do_sys_ioctl fs/ioctl.c:868 [inline]
__se_sys_ioctl fs/ioctl.c:856 [inline]
__arm64_sys_ioctl+0xe4/0x1c8 fs/ioctl.c:856
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x168 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
irq event stamp: 96220
hardirqs last enabled at (96219): [<ffff80000833f25c>] __up_console_sem+0xb4/0x100 kernel/printk/printk.c:261
hardirqs last disabled at (96220): [<ffff800012329064>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (96200): [<ffff8000081c3414>] softirq_handle_end kernel/softirq.c:414 [inline]
softirqs last enabled at (96200): [<ffff8000081c3414>] handle_softirqs+0xb84/0xd58 kernel/softirq.c:599
softirqs last disabled at (96081): [<ffff800008020174>] __do_softirq+0x14/0x20 kernel/softirq.c:605
---[ end trace 0000000000000000 ]---


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
Reply all
Reply to author
Forward
0 new messages