[v6.1] possible deadlock in ocfs2_extend_allocation

6 views
Skip to first unread message

syzbot

unread,
Jul 16, 2025, 1:32:41 PM7/16/25
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: f2198ea7eb3e Linux 6.1.145
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=145df58c580000
kernel config: https://syzkaller.appspot.com/x/.config?x=e64d77413184340b
dashboard link: https://syzkaller.appspot.com/bug?extid=dfa4f987ad5d214d451e
compiler: Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/b56a4aeab209/disk-f2198ea7.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/6e8781bcd6b5/vmlinux-f2198ea7.xz
kernel image: https://storage.googleapis.com/syzbot-assets/54e6b0704c35/Image-f2198ea7.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+dfa4f9...@syzkaller.appspotmail.com

ocfs2: Mounting device (7,5) on (node local, slot 0) with ordered data mode.
(syz.5.326,5629,0):ocfs2_block_check_validate:402 ERROR: CRC32 failed: stored: 0x98842a5e, computed 0xe74db1cd. Applying ECC.
======================================================
WARNING: possible circular locking dependency detected
6.1.145-syzkaller #0 Not tainted
------------------------------------------------------
syz.5.326/5629 is trying to acquire lock:
ffff0000f5648650 (sb_internal#3){.+.+}-{0:0}, at: ocfs2_extend_allocation+0x5d4/0x15ec fs/ocfs2/file.c:593

but task is already holding lock:
ffff0000f5aa5108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
ffff0000f5aa5108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: ocfs2_reserve_suballoc_bits+0x12c/0x3cd4 fs/ocfs2/suballoc.c:782

which lock already depends on the new lock.


the existing dependency chain (in reverse order) is:

-> #7 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}:
down_write+0x5c/0x88 kernel/locking/rwsem.c:1573
inode_lock include/linux/fs.h:758 [inline]
ocfs2_reserve_suballoc_bits+0x12c/0x3cd4 fs/ocfs2/suballoc.c:782
ocfs2_reserve_cluster_bitmap_bits fs/ocfs2/suballoc.c:1128 [inline]
ocfs2_reserve_clusters_with_limit+0x290/0x9e0 fs/ocfs2/suballoc.c:1173
ocfs2_reserve_clusters fs/ocfs2/suballoc.c:1223 [inline]
ocfs2_lock_allocators+0x27c/0x518 fs/ocfs2/suballoc.c:2669
ocfs2_extend_allocation+0x328/0x15ec fs/ocfs2/file.c:585
ocfs2_extend_no_holes+0x1a8/0x424 fs/ocfs2/file.c:1027
ocfs2_acquire_dquot+0x550/0xac4 fs/ocfs2/quota_global.c:841
dqget+0x654/0xccc fs/quota/dquot.c:988
ocfs2_setattr+0xc20/0x18d4 fs/ocfs2/file.c:1233
notify_change+0xb0c/0xdcc fs/attr.c:499
chown_common+0x414/0x574 fs/open.c:736
vfs_fchown fs/open.c:804 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:815
__do_sys_fchown fs/open.c:823 [inline]
__se_sys_fchown fs/open.c:821 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:821
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

-> #6 (&ocfs2_quota_ip_alloc_sem_key){++++}-{3:3}:
down_write+0x5c/0x88 kernel/locking/rwsem.c:1573
ocfs2_lock_global_qf+0x1a8/0x22c fs/ocfs2/quota_global.c:314
ocfs2_acquire_dquot+0x268/0xac4 fs/ocfs2/quota_global.c:816
dqget+0x654/0xccc fs/quota/dquot.c:988
ocfs2_setattr+0xc20/0x18d4 fs/ocfs2/file.c:1233
notify_change+0xb0c/0xdcc fs/attr.c:499
chown_common+0x414/0x574 fs/open.c:736
vfs_fchown fs/open.c:804 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:815
__do_sys_fchown fs/open.c:823 [inline]
__se_sys_fchown fs/open.c:821 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:821
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

-> #5 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}:
down_write+0x5c/0x88 kernel/locking/rwsem.c:1573
inode_lock include/linux/fs.h:758 [inline]
ocfs2_lock_global_qf+0x18c/0x22c fs/ocfs2/quota_global.c:313
ocfs2_acquire_dquot+0x268/0xac4 fs/ocfs2/quota_global.c:816
dqget+0x654/0xccc fs/quota/dquot.c:988
ocfs2_setattr+0xc20/0x18d4 fs/ocfs2/file.c:1233
notify_change+0xb0c/0xdcc fs/attr.c:499
chown_common+0x414/0x574 fs/open.c:736
vfs_fchown fs/open.c:804 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:815
__do_sys_fchown fs/open.c:823 [inline]
__se_sys_fchown fs/open.c:821 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:821
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

-> #4 (&dquot->dq_lock){+.+.}-{3:3}:
__mutex_lock_common+0x190/0x1f38 kernel/locking/mutex.c:603
__mutex_lock kernel/locking/mutex.c:747 [inline]
mutex_lock_nested+0x38/0x44 kernel/locking/mutex.c:799
dquot_commit+0x50/0x1c4 fs/quota/dquot.c:507
ext4_write_dquot+0x1b4/0x31c fs/ext4/super.c:6790
ext4_mark_dquot_dirty+0xe8/0x140 fs/ext4/super.c:6867
mark_dquot_dirty fs/quota/dquot.c:372 [inline]
mark_all_dquot_dirty+0x108/0x424 fs/quota/dquot.c:412
__dquot_alloc_space+0x560/0xce8 fs/quota/dquot.c:1752
dquot_alloc_space_nodirty include/linux/quotaops.h:300 [inline]
dquot_alloc_space include/linux/quotaops.h:313 [inline]
dquot_alloc_block include/linux/quotaops.h:337 [inline]
ext4_mb_new_blocks+0xd30/0x435c fs/ext4/mballoc.c:5727
ext4_ext_map_blocks+0x1018/0x559c fs/ext4/extents.c:4340
ext4_map_blocks+0x860/0x1770 fs/ext4/inode.c:679
_ext4_get_block+0x194/0x4c8 fs/ext4/inode.c:822
ext4_get_block+0x4c/0x60 fs/ext4/inode.c:839
ext4_block_write_begin+0x508/0x10f8 fs/ext4/inode.c:1124
ext4_write_begin+0x5ec/0x133c fs/ext4/ext4_jbd2.h:-1
ext4_da_write_begin+0x360/0x9d8 fs/ext4/inode.c:3000
generic_perform_write+0x230/0x4b0 mm/filemap.c:3846
ext4_buffered_write_iter+0x2c4/0x530 fs/ext4/file.c:285
ext4_file_write_iter+0x188/0x152c fs/ext4/file.c:-1
call_write_iter include/linux/fs.h:2265 [inline]
new_sync_write fs/read_write.c:491 [inline]
vfs_write+0x5ac/0x7c4 fs/read_write.c:584
ksys_write+0x120/0x210 fs/read_write.c:637
__do_sys_write fs/read_write.c:649 [inline]
__se_sys_write fs/read_write.c:646 [inline]
__arm64_sys_write+0x7c/0x90 fs/read_write.c:646
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

-> #3 (&ei->i_data_sem){++++}-{3:3}:
down_write+0x5c/0x88 kernel/locking/rwsem.c:1573
ext4_map_blocks+0x7c4/0x1770 fs/ext4/inode.c:672
mpage_map_one_extent fs/ext4/inode.c:2434 [inline]
mpage_map_and_submit_extent fs/ext4/inode.c:2487 [inline]
ext4_writepages+0xd8c/0x284c fs/ext4/inode.c:2855
do_writepages+0x2c0/0x4fc mm/page-writeback.c:2491
__writeback_single_inode+0x164/0x157c fs/fs-writeback.c:1612
writeback_sb_inodes+0x824/0x1404 fs/fs-writeback.c:1903
__writeback_inodes_wb+0x110/0x394 fs/fs-writeback.c:1974
wb_writeback+0x414/0xfb0 fs/fs-writeback.c:2079
wb_check_background_flush fs/fs-writeback.c:2145 [inline]
wb_do_writeback fs/fs-writeback.c:2233 [inline]
wb_workfn+0xac0/0xd98 fs/fs-writeback.c:2260
process_one_work+0x7f4/0x13a8 kernel/workqueue.c:2292
worker_thread+0x8c8/0xfbc kernel/workqueue.c:2439
kthread+0x250/0x2d8 kernel/kthread.c:376
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:849

-> #2 (jbd2_handle){++++}-{0:0}:
start_this_handle+0xfe0/0x122c fs/jbd2/transaction.c:463
jbd2__journal_start+0x288/0x51c fs/jbd2/transaction.c:520
jbd2_journal_start+0x3c/0x4c fs/jbd2/transaction.c:559
ocfs2_start_trans+0x380/0x6c4 fs/ocfs2/journal.c:376
ocfs2_modify_bh+0xe4/0x43c fs/ocfs2/quota_local.c:101
ocfs2_local_read_info+0x102c/0x131c fs/ocfs2/quota_local.c:764
dquot_load_quota_sb+0x6c4/0xa24 fs/quota/dquot.c:2470
dquot_load_quota_inode+0x274/0x4e4 fs/quota/dquot.c:2507
ocfs2_enable_quotas+0x17c/0x3b4 fs/ocfs2/super.c:926
ocfs2_fill_super+0x3060/0x3e98 fs/ocfs2/super.c:1139
mount_bdev+0x264/0x358 fs/super.c:1443
ocfs2_mount+0x44/0x58 fs/ocfs2/super.c:1186
legacy_get_tree+0xd4/0x16c fs/fs_context.c:632
vfs_get_tree+0x90/0x274 fs/super.c:1573
do_new_mount+0x228/0x810 fs/namespace.c:3058
path_mount+0x5b4/0xe78 fs/namespace.c:3388
do_mount fs/namespace.c:3401 [inline]
__do_sys_mount fs/namespace.c:3609 [inline]
__se_sys_mount fs/namespace.c:3586 [inline]
__arm64_sys_mount+0x49c/0x584 fs/namespace.c:3586
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

-> #1 (&journal->j_trans_barrier){.+.+}-{3:3}:
down_read+0x64/0x304 kernel/locking/rwsem.c:1520
ocfs2_start_trans+0x374/0x6c4 fs/ocfs2/journal.c:374
ocfs2_modify_bh+0xe4/0x43c fs/ocfs2/quota_local.c:101
ocfs2_local_read_info+0x102c/0x131c fs/ocfs2/quota_local.c:764
dquot_load_quota_sb+0x6c4/0xa24 fs/quota/dquot.c:2470
dquot_load_quota_inode+0x274/0x4e4 fs/quota/dquot.c:2507
ocfs2_enable_quotas+0x17c/0x3b4 fs/ocfs2/super.c:926
ocfs2_fill_super+0x3060/0x3e98 fs/ocfs2/super.c:1139
mount_bdev+0x264/0x358 fs/super.c:1443
ocfs2_mount+0x44/0x58 fs/ocfs2/super.c:1186
legacy_get_tree+0xd4/0x16c fs/fs_context.c:632
vfs_get_tree+0x90/0x274 fs/super.c:1573
do_new_mount+0x228/0x810 fs/namespace.c:3058
path_mount+0x5b4/0xe78 fs/namespace.c:3388
do_mount fs/namespace.c:3401 [inline]
__do_sys_mount fs/namespace.c:3609 [inline]
__se_sys_mount fs/namespace.c:3586 [inline]
__arm64_sys_mount+0x49c/0x584 fs/namespace.c:3586
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

-> #0 (sb_internal#3){.+.+}-{0:0}:
check_prev_add kernel/locking/lockdep.c:3090 [inline]
check_prevs_add kernel/locking/lockdep.c:3209 [inline]
validate_chain kernel/locking/lockdep.c:3825 [inline]
__lock_acquire+0x293c/0x6544 kernel/locking/lockdep.c:5049
lock_acquire+0x20c/0x644 kernel/locking/lockdep.c:5662
percpu_down_read include/linux/percpu-rwsem.h:51 [inline]
__sb_start_write include/linux/fs.h:1891 [inline]
sb_start_intwrite include/linux/fs.h:2013 [inline]
ocfs2_start_trans+0x20c/0x6c4 fs/ocfs2/journal.c:372
ocfs2_extend_allocation+0x5d4/0x15ec fs/ocfs2/file.c:593
ocfs2_extend_no_holes+0x1a8/0x424 fs/ocfs2/file.c:1027
ocfs2_acquire_dquot+0x550/0xac4 fs/ocfs2/quota_global.c:841
dqget+0x654/0xccc fs/quota/dquot.c:988
ocfs2_setattr+0xc20/0x18d4 fs/ocfs2/file.c:1233
notify_change+0xb0c/0xdcc fs/attr.c:499
chown_common+0x414/0x574 fs/open.c:736
vfs_fchown fs/open.c:804 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:815
__do_sys_fchown fs/open.c:823 [inline]
__se_sys_fchown fs/open.c:821 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:821
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

other info that might help us debug this:

Chain exists of:
sb_internal#3 --> &ocfs2_quota_ip_alloc_sem_key --> &ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3

Possible unsafe locking scenario:

CPU0 CPU1
---- ----
lock(&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3);
lock(&ocfs2_quota_ip_alloc_sem_key);
lock(&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3);
lock(sb_internal#3);

*** DEADLOCK ***

6 locks held by syz.5.326/5629:
#0: ffff0000f5648460 (sb_writers#26){.+.+}-{0:0}, at: mnt_want_write_file+0x64/0x1e8 fs/namespace.c:437
#1: ffff0000f5aa09c8 (&type->i_mutex_dir_key#16){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
#1: ffff0000f5aa09c8 (&type->i_mutex_dir_key#16){+.+.}-{3:3}, at: chown_common+0x2ac/0x574 fs/open.c:726
#2: ffff0000f5ab00a8 (&dquot->dq_lock){+.+.}-{3:3}, at: ocfs2_acquire_dquot+0x25c/0xac4 fs/ocfs2/quota_global.c:811
#3: ffff0000f5aa5f48 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
#3: ffff0000f5aa5f48 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}, at: ocfs2_lock_global_qf+0x18c/0x22c fs/ocfs2/quota_global.c:313
#4: ffff0000f5aa5be0 (&ocfs2_quota_ip_alloc_sem_key){++++}-{3:3}, at: ocfs2_lock_global_qf+0x1a8/0x22c fs/ocfs2/quota_global.c:314
#5: ffff0000f5aa5108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
#5: ffff0000f5aa5108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: ocfs2_reserve_suballoc_bits+0x12c/0x3cd4 fs/ocfs2/suballoc.c:782

stack backtrace:
CPU: 0 PID: 5629 Comm: syz.5.326 Not tainted 6.1.145-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Call trace:
dump_backtrace+0x1c8/0x1f4 arch/arm64/kernel/stacktrace.c:158
show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:165
__dump_stack+0x30/0x40 lib/dump_stack.c:88
dump_stack_lvl+0xf8/0x160 lib/dump_stack.c:106
dump_stack+0x1c/0x5c lib/dump_stack.c:113
print_circular_bug+0x148/0x1b0 kernel/locking/lockdep.c:2048
check_noncircular+0x240/0x2d4 kernel/locking/lockdep.c:2170
check_prev_add kernel/locking/lockdep.c:3090 [inline]
check_prevs_add kernel/locking/lockdep.c:3209 [inline]
validate_chain kernel/locking/lockdep.c:3825 [inline]
__lock_acquire+0x293c/0x6544 kernel/locking/lockdep.c:5049
lock_acquire+0x20c/0x644 kernel/locking/lockdep.c:5662
percpu_down_read include/linux/percpu-rwsem.h:51 [inline]
__sb_start_write include/linux/fs.h:1891 [inline]
sb_start_intwrite include/linux/fs.h:2013 [inline]
ocfs2_start_trans+0x20c/0x6c4 fs/ocfs2/journal.c:372
ocfs2_extend_allocation+0x5d4/0x15ec fs/ocfs2/file.c:593
ocfs2_extend_no_holes+0x1a8/0x424 fs/ocfs2/file.c:1027
ocfs2_acquire_dquot+0x550/0xac4 fs/ocfs2/quota_global.c:841
dqget+0x654/0xccc fs/quota/dquot.c:988
ocfs2_setattr+0xc20/0x18d4 fs/ocfs2/file.c:1233
notify_change+0xb0c/0xdcc fs/attr.c:499
chown_common+0x414/0x574 fs/open.c:736
vfs_fchown fs/open.c:804 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:815
__do_sys_fchown fs/open.c:823 [inline]
__se_sys_fchown fs/open.c:821 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:821
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
(syz.5.326,5629,0):ocfs2_block_check_validate:402 ERROR: CRC32 failed: stored: 0xdf8356d3, computed 0xb8c23ae4. Applying ECC.
(syz.5.326,5629,0):ocfs2_block_check_validate:416 ERROR: Fixed CRC32 failed: stored: 0xdf8356d3, computed 0x2acb7e3c
(syz.5.326,5629,0):ocfs2_read_quota_phys_block:160 ERROR: status = -5
(syz.5.326,5629,0):ocfs2_quota_read:201 ERROR: status = -5
Quota error (device loop5): qtree_write_dquot: Error -5 occurred while creating quota
(syz.5.326,5629,0):ocfs2_acquire_dquot:878 ERROR: status = -5


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Jul 16, 2025, 8:00:41 PM7/16/25
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 89950c454265 Linux 5.15.188
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=134d6382580000
kernel config: https://syzkaller.appspot.com/x/.config?x=2b66ee871ee5d301
dashboard link: https://syzkaller.appspot.com/bug?extid=85970ea43f222f9d33e4
compiler: Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/0ead69d25899/disk-89950c45.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/ddd0acb3cb5f/vmlinux-89950c45.xz
kernel image: https://storage.googleapis.com/syzbot-assets/4f764188587c/Image-89950c45.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+85970e...@syzkaller.appspotmail.com

======================================================
WARNING: possible circular locking dependency detected
5.15.188-syzkaller #0 Not tainted
------------------------------------------------------
syz.5.575/6257 is trying to acquire lock:
ffff0000cfefa650 (sb_internal#7){.+.+}-{0:0}, at: ocfs2_extend_allocation+0x5d4/0x1504 fs/ocfs2/file.c:596

but task is already holding lock:
ffff0000f7513488 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
ffff0000f7513488 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: ocfs2_reserve_suballoc_bits+0x12c/0x3a68 fs/ocfs2/suballoc.c:782

which lock already depends on the new lock.


the existing dependency chain (in reverse order) is:

-> #7 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}:
down_write+0xbc/0x12c kernel/locking/rwsem.c:1551
inode_lock include/linux/fs.h:787 [inline]
ocfs2_reserve_suballoc_bits+0x12c/0x3a68 fs/ocfs2/suballoc.c:782
ocfs2_reserve_cluster_bitmap_bits fs/ocfs2/suballoc.c:1128 [inline]
ocfs2_reserve_clusters_with_limit+0x290/0x9e0 fs/ocfs2/suballoc.c:1173
ocfs2_reserve_clusters fs/ocfs2/suballoc.c:1223 [inline]
ocfs2_lock_allocators+0x27c/0x518 fs/ocfs2/suballoc.c:2669
ocfs2_extend_allocation+0x328/0x1504 fs/ocfs2/file.c:588
ocfs2_extend_no_holes+0x1a8/0x424 fs/ocfs2/file.c:1030
ocfs2_acquire_dquot+0x530/0xa2c fs/ocfs2/quota_global.c:841
dqget+0x658/0xcf4 fs/quota/dquot.c:988
ocfs2_setattr+0xa7c/0x16c4 fs/ocfs2/file.c:1236
notify_change+0xa08/0xcd8 fs/attr.c:505
chown_common+0x42c/0x5a0 fs/open.c:680
vfs_fchown fs/open.c:748 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:759
__do_sys_fchown fs/open.c:767 [inline]
__se_sys_fchown fs/open.c:765 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:765
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x78/0x1e0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0xcc/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584

-> #6 (&ocfs2_quota_ip_alloc_sem_key){++++}-{3:3}:
down_write+0xbc/0x12c kernel/locking/rwsem.c:1551
ocfs2_lock_global_qf+0x1a8/0x22c fs/ocfs2/quota_global.c:314
ocfs2_acquire_dquot+0x244/0xa2c fs/ocfs2/quota_global.c:816
dqget+0x658/0xcf4 fs/quota/dquot.c:988
ocfs2_setattr+0xa7c/0x16c4 fs/ocfs2/file.c:1236
notify_change+0xa08/0xcd8 fs/attr.c:505
chown_common+0x42c/0x5a0 fs/open.c:680
vfs_fchown fs/open.c:748 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:759
__do_sys_fchown fs/open.c:767 [inline]
__se_sys_fchown fs/open.c:765 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:765
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x78/0x1e0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0xcc/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584

-> #5 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}:
down_write+0xbc/0x12c kernel/locking/rwsem.c:1551
inode_lock include/linux/fs.h:787 [inline]
ocfs2_lock_global_qf+0x18c/0x22c fs/ocfs2/quota_global.c:313
ocfs2_acquire_dquot+0x244/0xa2c fs/ocfs2/quota_global.c:816
dqget+0x658/0xcf4 fs/quota/dquot.c:988
ocfs2_setattr+0xa7c/0x16c4 fs/ocfs2/file.c:1236
notify_change+0xa08/0xcd8 fs/attr.c:505
chown_common+0x42c/0x5a0 fs/open.c:680
vfs_fchown fs/open.c:748 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:759
__do_sys_fchown fs/open.c:767 [inline]
__se_sys_fchown fs/open.c:765 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:765
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x78/0x1e0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0xcc/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584

-> #4 (&dquot->dq_lock){+.+.}-{3:3}:
__mutex_lock_common+0x194/0x1edc kernel/locking/mutex.c:596
__mutex_lock kernel/locking/mutex.c:729 [inline]
mutex_lock_nested+0xac/0x11c kernel/locking/mutex.c:743
dquot_commit+0x50/0x1c4 fs/quota/dquot.c:507
ext4_write_dquot+0x1b4/0x31c fs/ext4/super.c:6183
ext4_mark_dquot_dirty+0xe8/0x140 fs/ext4/super.c:6260
mark_dquot_dirty fs/quota/dquot.c:372 [inline]
mark_all_dquot_dirty+0x108/0x424 fs/quota/dquot.c:412
__dquot_alloc_space+0x560/0xd0c fs/quota/dquot.c:1752
dquot_alloc_space_nodirty include/linux/quotaops.h:297 [inline]
dquot_alloc_space include/linux/quotaops.h:310 [inline]
dquot_alloc_block include/linux/quotaops.h:334 [inline]
ext4_mb_new_blocks+0xd30/0x4024 fs/ext4/mballoc.c:5739
ext4_new_meta_blocks+0x134/0x32c fs/ext4/balloc.c:738
ext4_ext_grow_indepth fs/ext4/extents.c:1325 [inline]
ext4_ext_create_new_leaf fs/ext4/extents.c:1431 [inline]
ext4_ext_insert_extent+0xafc/0x4328 fs/ext4/extents.c:2103
ext4_ext_map_blocks+0x105c/0x562c fs/ext4/extents.c:4362
ext4_map_blocks+0x7b8/0x167c fs/ext4/inode.c:673
_ext4_get_block+0x190/0x4ec fs/ext4/inode.c:816
ext4_get_block_unwritten+0x38/0x4c fs/ext4/inode.c:847
ext4_block_write_begin+0x528/0x1110 fs/ext4/inode.c:1101
ext4_write_begin+0x5d0/0xdbc fs/ext4/ext4_jbd2.h:-1
ext4_da_write_begin+0x380/0x83c fs/ext4/inode.c:2975
generic_perform_write+0x204/0x480 mm/filemap.c:3785
ext4_buffered_write_iter+0x408/0x538 fs/ext4/file.c:268
ext4_file_write_iter+0x698/0x14cc include/linux/fs.h:-1
call_write_iter include/linux/fs.h:2172 [inline]
new_sync_write fs/read_write.c:507 [inline]
vfs_write+0x7c8/0xa2c fs/read_write.c:594
ksys_pwrite64 fs/read_write.c:701 [inline]
__do_sys_pwrite64 fs/read_write.c:711 [inline]
__se_sys_pwrite64 fs/read_write.c:708 [inline]
__arm64_sys_pwrite64+0x170/0x200 fs/read_write.c:708
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x78/0x1e0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0xcc/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584

-> #3 (&ei->i_data_sem){++++}-{3:3}:
down_write+0xbc/0x12c kernel/locking/rwsem.c:1551
ext4_map_blocks+0x71c/0x167c fs/ext4/inode.c:666
mpage_map_one_extent fs/ext4/inode.c:2408 [inline]
mpage_map_and_submit_extent fs/ext4/inode.c:2461 [inline]
ext4_writepages+0xf00/0x2c14 fs/ext4/inode.c:2829
do_writepages+0x36c/0x578 mm/page-writeback.c:2386
__writeback_single_inode+0x148/0x11f0 fs/fs-writeback.c:1647
writeback_sb_inodes+0x7fc/0x1378 fs/fs-writeback.c:1930
__writeback_inodes_wb+0x110/0x394 fs/fs-writeback.c:2001
wb_writeback+0x3ec/0xe44 fs/fs-writeback.c:2106
wb_check_background_flush fs/fs-writeback.c:2172 [inline]
wb_do_writeback fs/fs-writeback.c:2260 [inline]
wb_workfn+0xa7c/0xdd8 fs/fs-writeback.c:2288
process_one_work+0x79c/0x1140 kernel/workqueue.c:2310
worker_thread+0x8f4/0x101c kernel/workqueue.c:2457
kthread+0x374/0x454 kernel/kthread.c:334
ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:855

-> #2 (jbd2_handle){++++}-{0:0}:
start_this_handle+0xef4/0x11a4 fs/jbd2/transaction.c:464
jbd2__journal_start+0x28c/0x744 fs/jbd2/transaction.c:521
jbd2_journal_start+0x3c/0x4c fs/jbd2/transaction.c:560
ocfs2_start_trans+0x43c/0x794 fs/ocfs2/journal.c:376
ocfs2_modify_bh+0xe4/0x450 fs/ocfs2/quota_local.c:101
ocfs2_local_read_info+0x102c/0x131c fs/ocfs2/quota_local.c:764
dquot_load_quota_sb+0x6c4/0xa24 fs/quota/dquot.c:2463
dquot_load_quota_inode+0x274/0x4e4 fs/quota/dquot.c:2500
ocfs2_enable_quotas+0x17c/0x3b4 fs/ocfs2/super.c:927
ocfs2_fill_super+0x2e74/0x4074 fs/ocfs2/super.c:1140
mount_bdev+0x264/0x358 fs/super.c:1400
ocfs2_mount+0x44/0x58 fs/ocfs2/super.c:1187
legacy_get_tree+0xd4/0x16c fs/fs_context.c:611
vfs_get_tree+0x90/0x274 fs/super.c:1530
do_new_mount+0x228/0x810 fs/namespace.c:3014
path_mount+0x5b4/0x1000 fs/namespace.c:3344
do_mount fs/namespace.c:3357 [inline]
__do_sys_mount fs/namespace.c:3565 [inline]
__se_sys_mount fs/namespace.c:3542 [inline]
__arm64_sys_mount+0x514/0x5e4 fs/namespace.c:3542
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x78/0x1e0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0xcc/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584

-> #1 (&journal->j_trans_barrier){.+.+}-{3:3}:
down_read+0xc0/0x390 kernel/locking/rwsem.c:1498
ocfs2_start_trans+0x430/0x794 fs/ocfs2/journal.c:374
ocfs2_modify_bh+0xe4/0x450 fs/ocfs2/quota_local.c:101
ocfs2_local_read_info+0x102c/0x131c fs/ocfs2/quota_local.c:764
dquot_load_quota_sb+0x6c4/0xa24 fs/quota/dquot.c:2463
dquot_load_quota_inode+0x274/0x4e4 fs/quota/dquot.c:2500
ocfs2_enable_quotas+0x17c/0x3b4 fs/ocfs2/super.c:927
ocfs2_fill_super+0x2e74/0x4074 fs/ocfs2/super.c:1140
mount_bdev+0x264/0x358 fs/super.c:1400
ocfs2_mount+0x44/0x58 fs/ocfs2/super.c:1187
legacy_get_tree+0xd4/0x16c fs/fs_context.c:611
vfs_get_tree+0x90/0x274 fs/super.c:1530
do_new_mount+0x228/0x810 fs/namespace.c:3014
path_mount+0x5b4/0x1000 fs/namespace.c:3344
do_mount fs/namespace.c:3357 [inline]
__do_sys_mount fs/namespace.c:3565 [inline]
__se_sys_mount fs/namespace.c:3542 [inline]
__arm64_sys_mount+0x514/0x5e4 fs/namespace.c:3542
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x78/0x1e0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0xcc/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584

-> #0 (sb_internal#7){.+.+}-{0:0}:
check_prev_add kernel/locking/lockdep.c:3053 [inline]
check_prevs_add kernel/locking/lockdep.c:3172 [inline]
validate_chain kernel/locking/lockdep.c:3788 [inline]
__lock_acquire+0x2928/0x651c kernel/locking/lockdep.c:5012
lock_acquire+0x1f4/0x620 kernel/locking/lockdep.c:5623
percpu_down_read include/linux/percpu-rwsem.h:51 [inline]
__sb_start_write include/linux/fs.h:1811 [inline]
sb_start_intwrite include/linux/fs.h:1928 [inline]
ocfs2_start_trans+0x2c4/0x794 fs/ocfs2/journal.c:372
ocfs2_extend_allocation+0x5d4/0x1504 fs/ocfs2/file.c:596
ocfs2_extend_no_holes+0x1a8/0x424 fs/ocfs2/file.c:1030
ocfs2_acquire_dquot+0x530/0xa2c fs/ocfs2/quota_global.c:841
dqget+0x658/0xcf4 fs/quota/dquot.c:988
ocfs2_setattr+0xa7c/0x16c4 fs/ocfs2/file.c:1236
notify_change+0xa08/0xcd8 fs/attr.c:505
chown_common+0x42c/0x5a0 fs/open.c:680
vfs_fchown fs/open.c:748 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:759
__do_sys_fchown fs/open.c:767 [inline]
__se_sys_fchown fs/open.c:765 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:765
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x78/0x1e0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0xcc/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584

other info that might help us debug this:

Chain exists of:
sb_internal#7 --> &ocfs2_quota_ip_alloc_sem_key --> &ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3

Possible unsafe locking scenario:

CPU0 CPU1
---- ----
lock(&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3);
lock(&ocfs2_quota_ip_alloc_sem_key);
lock(&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3);
lock(sb_internal#7);

*** DEADLOCK ***

6 locks held by syz.5.575/6257:
#0: ffff0000cfefa460 (sb_writers#33){.+.+}-{0:0}, at: mnt_want_write_file+0x64/0x1e8 fs/namespace.c:421
#1: ffff0000f74d89c8 (&type->i_mutex_dir_key#22){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#1: ffff0000f74d89c8 (&type->i_mutex_dir_key#22){+.+.}-{3:3}, at: chown_common+0x380/0x5a0 fs/open.c:674
#2: ffff0000ea3860a8 (&dquot->dq_lock){+.+.}-{3:3}, at: ocfs2_acquire_dquot+0x238/0xa2c fs/ocfs2/quota_global.c:811
#3: ffff0000f75142c8 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#3: ffff0000f75142c8 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}, at: ocfs2_lock_global_qf+0x18c/0x22c fs/ocfs2/quota_global.c:313
#4: ffff0000f7513f60 (&ocfs2_quota_ip_alloc_sem_key){++++}-{3:3}, at: ocfs2_lock_global_qf+0x1a8/0x22c fs/ocfs2/quota_global.c:314
#5: ffff0000f7513488 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#5: ffff0000f7513488 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: ocfs2_reserve_suballoc_bits+0x12c/0x3a68 fs/ocfs2/suballoc.c:782

stack backtrace:
CPU: 1 PID: 6257 Comm: syz.5.575 Not tainted 5.15.188-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
Call trace:
dump_backtrace+0x0/0x43c arch/arm64/kernel/stacktrace.c:152
show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:216
__dump_stack+0x30/0x40 lib/dump_stack.c:88
dump_stack_lvl+0xf8/0x160 lib/dump_stack.c:106
dump_stack+0x1c/0x5c lib/dump_stack.c:113
print_circular_bug+0x148/0x1b0 kernel/locking/lockdep.c:2011
check_noncircular+0x240/0x2d4 kernel/locking/lockdep.c:2133
check_prev_add kernel/locking/lockdep.c:3053 [inline]
check_prevs_add kernel/locking/lockdep.c:3172 [inline]
validate_chain kernel/locking/lockdep.c:3788 [inline]
__lock_acquire+0x2928/0x651c kernel/locking/lockdep.c:5012
lock_acquire+0x1f4/0x620 kernel/locking/lockdep.c:5623
percpu_down_read include/linux/percpu-rwsem.h:51 [inline]
__sb_start_write include/linux/fs.h:1811 [inline]
sb_start_intwrite include/linux/fs.h:1928 [inline]
ocfs2_start_trans+0x2c4/0x794 fs/ocfs2/journal.c:372
ocfs2_extend_allocation+0x5d4/0x1504 fs/ocfs2/file.c:596
ocfs2_extend_no_holes+0x1a8/0x424 fs/ocfs2/file.c:1030
ocfs2_acquire_dquot+0x530/0xa2c fs/ocfs2/quota_global.c:841
dqget+0x658/0xcf4 fs/quota/dquot.c:988
ocfs2_setattr+0xa7c/0x16c4 fs/ocfs2/file.c:1236
notify_change+0xa08/0xcd8 fs/attr.c:505
chown_common+0x42c/0x5a0 fs/open.c:680
vfs_fchown fs/open.c:748 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:759
__do_sys_fchown fs/open.c:767 [inline]
__se_sys_fchown fs/open.c:765 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:765
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x78/0x1e0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0xcc/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584
(syz.5.575,6257,1):ocfs2_block_check_validate:402 ERROR: CRC32 failed: stored: 0xdf8356d3, computed 0xb8c23ae4. Applying ECC.
(syz.5.575,6257,1):ocfs2_block_check_validate:416 ERROR: Fixed CRC32 failed: stored: 0xdf8356d3, computed 0x2acb7e3c
(syz.5.575,6257,0):ocfs2_read_quota_phys_block:160 ERROR: status = -5
(syz.5.575,6257,0):ocfs2_quota_read:201 ERROR: status = -5
Quota error (device loop5): qtree_write_dquot: Error -5 occurred while creating quota
(syz.5.575,6257,0):ocfs2_acquire_dquot:878 ERROR: status = -5

syzbot

unread,
Jul 17, 2025, 5:50:35 AM7/17/25
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 89950c454265 Linux 5.15.188
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=11101382580000
kernel config: https://syzkaller.appspot.com/x/.config?x=2b66ee871ee5d301
dashboard link: https://syzkaller.appspot.com/bug?extid=85970ea43f222f9d33e4
compiler: Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1763158c580000
mounted in repro #1: https://storage.googleapis.com/syzbot-assets/966c651e14e8/mount_0.gz
fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=11d2e7d4580000)
mounted in repro #2: https://storage.googleapis.com/syzbot-assets/b5fb8f9632fb/mount_1.gz
fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=11f52d8c580000)

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+85970e...@syzkaller.appspotmail.com

======================================================
WARNING: possible circular locking dependency detected
5.15.188-syzkaller #0 Not tainted
------------------------------------------------------
syz.0.22/4249 is trying to acquire lock:
ffff0000d46d8650 (sb_internal#2){.+.+}-{0:0}, at: ocfs2_extend_allocation+0x5d4/0x1504 fs/ocfs2/file.c:596

but task is already holding lock:
ffff0000ef345108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
ffff0000ef345108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: ocfs2_reserve_suballoc_bits+0x12c/0x3a68 fs/ocfs2/suballoc.c:782
wait_on_dquot fs/quota/dquot.c:356 [inline]
dqget+0x5e8/0xcf4 fs/quota/dquot.c:983
dquot_transfer+0x19c/0x3cc fs/quota/dquot.c:2146
ext4_setattr+0x588/0x142c fs/ext4/inode.c:5452
notify_change+0xa08/0xcd8 fs/attr.c:505
chown_common+0x42c/0x5a0 fs/open.c:680
vfs_fchown fs/open.c:748 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:759
__do_sys_fchown fs/open.c:767 [inline]
__se_sys_fchown fs/open.c:765 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:765
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x78/0x1e0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0xcc/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584

-> #3 (&ei->xattr_sem){.+.+}-{3:3}:
down_read+0xc0/0x390 kernel/locking/rwsem.c:1498
ext4_setattr+0x57c/0x142c fs/ext4/inode.c:5451
notify_change+0xa08/0xcd8 fs/attr.c:505
chown_common+0x42c/0x5a0 fs/open.c:680
do_fchownat+0x158/0x268 fs/open.c:711
__do_sys_fchownat fs/open.c:726 [inline]
__se_sys_fchownat fs/open.c:723 [inline]
__arm64_sys_fchownat+0xb8/0xd4 fs/open.c:723
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x78/0x1e0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0xcc/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584

-> #0 (sb_internal#2){.+.+}-{0:0}:
sb_internal#2 --> &ocfs2_quota_ip_alloc_sem_key --> &ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3

Possible unsafe locking scenario:

CPU0 CPU1
---- ----
lock(&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3);
lock(&ocfs2_quota_ip_alloc_sem_key);
lock(&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3);
lock(sb_internal#2);

*** DEADLOCK ***

6 locks held by syz.0.22/4249:
#0: ffff0000d46d8460 (sb_writers#12){.+.+}-{0:0}, at: mnt_want_write_file+0x64/0x1e8 fs/namespace.c:421
#1: ffff0000ef3409c8 (&type->i_mutex_dir_key#8){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#1: ffff0000ef3409c8 (&type->i_mutex_dir_key#8){+.+.}-{3:3}, at: chown_common+0x380/0x5a0 fs/open.c:674
#2: ffff0000dce060a8 (&dquot->dq_lock){+.+.}-{3:3}, at: ocfs2_acquire_dquot+0x238/0xa2c fs/ocfs2/quota_global.c:811
#3: ffff0000ef345f48 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#3: ffff0000ef345f48 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}, at: ocfs2_lock_global_qf+0x18c/0x22c fs/ocfs2/quota_global.c:313
#4: ffff0000ef345be0 (&ocfs2_quota_ip_alloc_sem_key){++++}-{3:3}, at: ocfs2_lock_global_qf+0x1a8/0x22c fs/ocfs2/quota_global.c:314
#5: ffff0000ef345108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:787 [inline]
#5: ffff0000ef345108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: ocfs2_reserve_suballoc_bits+0x12c/0x3a68 fs/ocfs2/suballoc.c:782

stack backtrace:
CPU: 0 PID: 4249 Comm: syz.0.22 Not tainted 5.15.188-syzkaller #0
(syz.0.22,4249,1):ocfs2_block_check_validate:402 ERROR: CRC32 failed: stored: 0xdf8356d3, computed 0xb8c23ae4. Applying ECC.
(syz.0.22,4249,1):ocfs2_block_check_validate:416 ERROR: Fixed CRC32 failed: stored: 0xdf8356d3, computed 0x2acb7e3c
(syz.0.22,4249,1):ocfs2_read_quota_phys_block:160 ERROR: status = -5
(syz.0.22,4249,1):ocfs2_quota_read:201 ERROR: status = -5
Quota error (device loop0): qtree_write_dquot: Error -5 occurred while creating quota
(syz.0.22,4249,1):ocfs2_acquire_dquot:878 ERROR: status = -5


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Aug 18, 2025, 5:58:32 AM8/18/25
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 0bc96de781b4 Linux 6.1.148
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=15f1eba2580000
kernel config: https://syzkaller.appspot.com/x/.config?x=483f799cd9933afc
dashboard link: https://syzkaller.appspot.com/bug?extid=dfa4f987ad5d214d451e
compiler: Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14ba86f0580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/cd15350f801a/disk-0bc96de7.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/789a5d74139d/vmlinux-0bc96de7.xz
kernel image: https://storage.googleapis.com/syzbot-assets/a1ef0a7e815a/Image-0bc96de7.gz.xz
mounted in repro #1: https://storage.googleapis.com/syzbot-assets/811d12c1ac8d/mount_0.gz
fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=10ba86f0580000)
mounted in repro #2: https://storage.googleapis.com/syzbot-assets/c57761e4435a/mount_1.gz
fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=1181bba2580000)

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+dfa4f9...@syzkaller.appspotmail.com

(syz.3.30,4553,0):ocfs2_block_check_validate:402 ERROR: CRC32 failed: stored: 0x98842a5e, computed 0xe74db1cd. Applying ECC.
======================================================
WARNING: possible circular locking dependency detected
6.1.148-syzkaller #0 Not tainted
------------------------------------------------------
syz.3.30/4553 is trying to acquire lock:
ffff0000c4a90650 (sb_internal#2){.+.+}-{0:0}, at: ocfs2_extend_allocation+0x5d4/0x15ec fs/ocfs2/file.c:593

but task is already holding lock:
ffff0000e9cad108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
ffff0000e9cad108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: ocfs2_reserve_suballoc_bits+0x12c/0x3cd4 fs/ocfs2/suballoc.c:782
wait_on_dquot fs/quota/dquot.c:356 [inline]
dqget+0x5e4/0xccc fs/quota/dquot.c:983
dquot_transfer+0x30c/0x6f0 fs/quota/dquot.c:2150
ext4_setattr+0x7d4/0x150c fs/ext4/inode.c:5502
notify_change+0xb0c/0xdcc fs/attr.c:499
chown_common+0x414/0x574 fs/open.c:736
vfs_fchown fs/open.c:804 [inline]
ksys_fchown+0xe0/0x158 fs/open.c:815
__do_sys_fchown fs/open.c:823 [inline]
__se_sys_fchown fs/open.c:821 [inline]
__arm64_sys_fchown+0x7c/0x94 fs/open.c:821
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

-> #3 (&ei->xattr_sem){.+.+}-{3:3}:
down_read+0x64/0x304 kernel/locking/rwsem.c:1520
ext4_setattr+0x7c4/0x150c fs/ext4/inode.c:5501
notify_change+0xb0c/0xdcc fs/attr.c:499
chown_common+0x414/0x574 fs/open.c:736
do_fchownat+0x158/0x268 fs/open.c:767
__do_sys_fchownat fs/open.c:782 [inline]
__se_sys_fchownat fs/open.c:779 [inline]
__arm64_sys_fchownat+0xb8/0xd4 fs/open.c:779
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

-> #2 (jbd2_handle){++++}-{0:0}:
start_this_handle+0xfe0/0x122c fs/jbd2/transaction.c:463
jbd2__journal_start+0x288/0x51c fs/jbd2/transaction.c:520
jbd2_journal_start+0x3c/0x4c fs/jbd2/transaction.c:559
ocfs2_start_trans+0x380/0x6c4 fs/ocfs2/journal.c:376
ocfs2_modify_bh+0xe4/0x43c fs/ocfs2/quota_local.c:101
ocfs2_local_read_info+0x102c/0x131c fs/ocfs2/quota_local.c:764
dquot_load_quota_sb+0x6c4/0xa24 fs/quota/dquot.c:2470
dquot_load_quota_inode+0x274/0x4e4 fs/quota/dquot.c:2507
ocfs2_enable_quotas+0x17c/0x3b4 fs/ocfs2/super.c:926
ocfs2_fill_super+0x3060/0x3e98 fs/ocfs2/super.c:1139
mount_bdev+0x264/0x358 fs/super.c:1443
ocfs2_mount+0x44/0x58 fs/ocfs2/super.c:1186
legacy_get_tree+0xd4/0x16c fs/fs_context.c:632
vfs_get_tree+0x90/0x274 fs/super.c:1573
do_new_mount+0x228/0x810 fs/namespace.c:3063
path_mount+0x5b4/0xe78 fs/namespace.c:3393
do_mount fs/namespace.c:3406 [inline]
__do_sys_mount fs/namespace.c:3614 [inline]
__se_sys_mount fs/namespace.c:3591 [inline]
__arm64_sys_mount+0x49c/0x584 fs/namespace.c:3591
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

-> #1 (&journal->j_trans_barrier){.+.+}-{3:3}:
down_read+0x64/0x304 kernel/locking/rwsem.c:1520
ocfs2_start_trans+0x374/0x6c4 fs/ocfs2/journal.c:374
ocfs2_modify_bh+0xe4/0x43c fs/ocfs2/quota_local.c:101
ocfs2_local_read_info+0x102c/0x131c fs/ocfs2/quota_local.c:764
dquot_load_quota_sb+0x6c4/0xa24 fs/quota/dquot.c:2470
dquot_load_quota_inode+0x274/0x4e4 fs/quota/dquot.c:2507
ocfs2_enable_quotas+0x17c/0x3b4 fs/ocfs2/super.c:926
ocfs2_fill_super+0x3060/0x3e98 fs/ocfs2/super.c:1139
mount_bdev+0x264/0x358 fs/super.c:1443
ocfs2_mount+0x44/0x58 fs/ocfs2/super.c:1186
legacy_get_tree+0xd4/0x16c fs/fs_context.c:632
vfs_get_tree+0x90/0x274 fs/super.c:1573
do_new_mount+0x228/0x810 fs/namespace.c:3063
path_mount+0x5b4/0xe78 fs/namespace.c:3393
do_mount fs/namespace.c:3406 [inline]
__do_sys_mount fs/namespace.c:3614 [inline]
__se_sys_mount fs/namespace.c:3591 [inline]
__arm64_sys_mount+0x49c/0x584 fs/namespace.c:3591
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x138 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585

-> #0 (sb_internal#2){.+.+}-{0:0}:
sb_internal#2 --> &ocfs2_quota_ip_alloc_sem_key --> &ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3

Possible unsafe locking scenario:

CPU0 CPU1
---- ----
lock(&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3);
lock(&ocfs2_quota_ip_alloc_sem_key);
lock(&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3);
lock(sb_internal#2);

*** DEADLOCK ***

6 locks held by syz.3.30/4553:
#0: ffff0000c4a90460 (sb_writers#12){.+.+}-{0:0}, at: mnt_want_write_file+0x64/0x1e8 fs/namespace.c:437
#1: ffff0000e9ca89c8 (&type->i_mutex_dir_key#8){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
#1: ffff0000e9ca89c8 (&type->i_mutex_dir_key#8){+.+.}-{3:3}, at: chown_common+0x2ac/0x574 fs/open.c:726
#2: ffff0000e2fd60a8 (&dquot->dq_lock){+.+.}-{3:3}, at: ocfs2_acquire_dquot+0x25c/0xac4 fs/ocfs2/quota_global.c:811
#3: ffff0000e9cadf48 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
#3: ffff0000e9cadf48 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}, at: ocfs2_lock_global_qf+0x18c/0x22c fs/ocfs2/quota_global.c:313
#4: ffff0000e9cadbe0 (&ocfs2_quota_ip_alloc_sem_key){++++}-{3:3}, at: ocfs2_lock_global_qf+0x1a8/0x22c fs/ocfs2/quota_global.c:314
#5: ffff0000e9cad108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
#5: ffff0000e9cad108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: ocfs2_reserve_suballoc_bits+0x12c/0x3cd4 fs/ocfs2/suballoc.c:782

stack backtrace:
CPU: 0 PID: 4553 Comm: syz.3.30 Not tainted 6.1.148-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/30/2025
(syz.3.30,4553,0):ocfs2_block_check_validate:402 ERROR: CRC32 failed: stored: 0xdf8356d3, computed 0xb8c23ae4. Applying ECC.
(syz.3.30,4553,0):ocfs2_block_check_validate:416 ERROR: Fixed CRC32 failed: stored: 0xdf8356d3, computed 0x2acb7e3c
(syz.3.30,4553,0):ocfs2_read_quota_phys_block:160 ERROR: status = -5
(syz.3.30,4553,0):ocfs2_quota_read:201 ERROR: status = -5
Quota error (device loop3): qtree_write_dquot: Error -5 occurred while creating quota
(syz.3.30,4553,0):ocfs2_acquire_dquot:878 ERROR: status = -5


---

syzbot

unread,
Aug 28, 2025, 12:55:36 AM8/28/25
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 0bc96de781b4 Linux 6.1.148
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=128fdef0580000
kernel config: https://syzkaller.appspot.com/x/.config?x=5c8a5866886424a8
dashboard link: https://syzkaller.appspot.com/bug?extid=dfa4f987ad5d214d451e
compiler: Debian clang version 20.1.7 (++20250616065708+6146a88f6049-1~exp1~20250616065826.132), Debian LLD 20.1.7
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16080262580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=168bbc42580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/04c58ffc4a8a/disk-0bc96de7.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/01cad248945e/vmlinux-0bc96de7.xz
kernel image: https://storage.googleapis.com/syzbot-assets/fc5395191c77/bzImage-0bc96de7.xz
mounted in repro #1: https://storage.googleapis.com/syzbot-assets/15c6b55ee011/mount_0.gz
fsck result: failed (log: https://syzkaller.appspot.com/x/fsck.log?x=12021fbc580000)
mounted in repro #2: https://storage.googleapis.com/syzbot-assets/178fe83f3af9/mount_2.gz
fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=13e02262580000)

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+dfa4f9...@syzkaller.appspotmail.com

(syz.3.162,4967,0):ocfs2_block_check_validate:402 ERROR: CRC32 failed: stored: 0x98842a5e, computed 0xe74db1cd. Applying ECC.
======================================================
WARNING: possible circular locking dependency detected
6.1.148-syzkaller #0 Not tainted
------------------------------------------------------
syz.3.162/4967 is trying to acquire lock:
ffff8880788d6650 (sb_internal#2){.+.+}-{0:0}, at: ocfs2_extend_allocation+0x6c8/0x1840 fs/ocfs2/file.c:593

but task is already holding lock:
ffff88805c49d108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
ffff88805c49d108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: ocfs2_reserve_suballoc_bits+0x162/0x4630 fs/ocfs2/suballoc.c:782

which lock already depends on the new lock.


the existing dependency chain (in reverse order) is:

-> #7 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}:
down_write+0x36/0x60 kernel/locking/rwsem.c:1573
inode_lock include/linux/fs.h:758 [inline]
ocfs2_reserve_suballoc_bits+0x162/0x4630 fs/ocfs2/suballoc.c:782
ocfs2_reserve_cluster_bitmap_bits fs/ocfs2/suballoc.c:1128 [inline]
ocfs2_reserve_clusters_with_limit+0x2f8/0xba0 fs/ocfs2/suballoc.c:1173
ocfs2_reserve_clusters fs/ocfs2/suballoc.c:1223 [inline]
ocfs2_lock_allocators+0x2f7/0x5b0 fs/ocfs2/suballoc.c:2669
ocfs2_extend_allocation+0x394/0x1840 fs/ocfs2/file.c:585
ocfs2_extend_no_holes+0x20b/0x490 fs/ocfs2/file.c:1027
ocfs2_acquire_dquot+0x5e8/0xb10 fs/ocfs2/quota_global.c:841
dqget+0x778/0xeb0 fs/quota/dquot.c:988
ocfs2_setattr+0xf16/0x1cf0 fs/ocfs2/file.c:1233
notify_change+0xc74/0xf40 fs/attr.c:499
chown_common+0x486/0x620 fs/open.c:736
vfs_fchown fs/open.c:804 [inline]
ksys_fchown+0xe2/0x150 fs/open.c:815
__do_sys_fchown fs/open.c:823 [inline]
__se_sys_fchown fs/open.c:821 [inline]
__x64_sys_fchown+0x76/0x80 fs/open.c:821
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2

-> #6 (&ocfs2_quota_ip_alloc_sem_key){++++}-{3:3}:
down_write+0x36/0x60 kernel/locking/rwsem.c:1573
ocfs2_lock_global_qf+0x1e5/0x270 fs/ocfs2/quota_global.c:314
ocfs2_acquire_dquot+0x2a0/0xb10 fs/ocfs2/quota_global.c:816
dqget+0x778/0xeb0 fs/quota/dquot.c:988
ocfs2_setattr+0xf16/0x1cf0 fs/ocfs2/file.c:1233
notify_change+0xc74/0xf40 fs/attr.c:499
chown_common+0x486/0x620 fs/open.c:736
vfs_fchown fs/open.c:804 [inline]
ksys_fchown+0xe2/0x150 fs/open.c:815
__do_sys_fchown fs/open.c:823 [inline]
__se_sys_fchown fs/open.c:821 [inline]
__x64_sys_fchown+0x76/0x80 fs/open.c:821
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2

-> #5 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}:
down_write+0x36/0x60 kernel/locking/rwsem.c:1573
inode_lock include/linux/fs.h:758 [inline]
ocfs2_lock_global_qf+0x1c7/0x270 fs/ocfs2/quota_global.c:313
ocfs2_acquire_dquot+0x2a0/0xb10 fs/ocfs2/quota_global.c:816
dqget+0x778/0xeb0 fs/quota/dquot.c:988
ocfs2_setattr+0xf16/0x1cf0 fs/ocfs2/file.c:1233
notify_change+0xc74/0xf40 fs/attr.c:499
chown_common+0x486/0x620 fs/open.c:736
vfs_fchown fs/open.c:804 [inline]
ksys_fchown+0xe2/0x150 fs/open.c:815
__do_sys_fchown fs/open.c:823 [inline]
__se_sys_fchown fs/open.c:821 [inline]
__x64_sys_fchown+0x76/0x80 fs/open.c:821
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2

-> #4 (&dquot->dq_lock){+.+.}-{3:3}:
__mutex_lock_common kernel/locking/mutex.c:603 [inline]
__mutex_lock+0x120/0xaf0 kernel/locking/mutex.c:747
dquot_commit+0x5a/0x410 fs/quota/dquot.c:507
ext4_write_dquot+0x1f0/0x360 fs/ext4/super.c:6790
mark_dquot_dirty fs/quota/dquot.c:372 [inline]
mark_all_dquot_dirty+0xf9/0x400 fs/quota/dquot.c:412
__dquot_free_space+0x7ec/0xbc0 fs/quota/dquot.c:1942
dquot_free_space_nodirty include/linux/quotaops.h:379 [inline]
dquot_free_space include/linux/quotaops.h:384 [inline]
dquot_free_block include/linux/quotaops.h:395 [inline]
ext4_mb_clear_bb fs/ext4/mballoc.c:6143 [inline]
ext4_free_blocks+0x1bab/0x2640 fs/ext4/mballoc.c:6273
ext4_remove_blocks fs/ext4/extents.c:2526 [inline]
ext4_ext_rm_leaf fs/ext4/extents.c:2692 [inline]
ext4_ext_remove_space+0x1f0d/0x4490 fs/ext4/extents.c:2940
ext4_ext_truncate+0x211/0x370 fs/ext4/extents.c:4470
ext4_truncate+0xa0b/0x1230 fs/ext4/inode.c:4289
ext4_setattr+0x10cb/0x19f0 fs/ext4/inode.c:5631
notify_change+0xc74/0xf40 fs/attr.c:499
do_truncate+0x197/0x220 fs/open.c:65
handle_truncate fs/namei.c:3285 [inline]
do_open fs/namei.c:3630 [inline]
path_openat+0x27f2/0x2e70 fs/namei.c:3783
do_filp_open+0x1c1/0x3c0 fs/namei.c:3810
do_sys_openat2+0x142/0x490 fs/open.c:1318
do_sys_open fs/open.c:1334 [inline]
__do_sys_open fs/open.c:1342 [inline]
__se_sys_open fs/open.c:1338 [inline]
__x64_sys_open+0x11b/0x140 fs/open.c:1338
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2

-> #3 (&ei->i_data_sem){++++}-{3:3}:
down_write+0x36/0x60 kernel/locking/rwsem.c:1573
ext4_truncate+0x987/0x1230 fs/ext4/inode.c:4284
ext4_setattr+0x10cb/0x19f0 fs/ext4/inode.c:5631
notify_change+0xc74/0xf40 fs/attr.c:499
do_truncate+0x197/0x220 fs/open.c:65
do_sys_ftruncate+0x312/0x3c0 fs/open.c:193
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2

-> #2 (jbd2_handle){++++}-{0:0}:
start_this_handle+0x1f49/0x2150 fs/jbd2/transaction.c:463
jbd2__journal_start+0x2b7/0x5a0 fs/jbd2/transaction.c:520
jbd2_journal_start+0x26/0x30 fs/jbd2/transaction.c:559
ocfs2_start_trans+0x372/0x6c0 fs/ocfs2/journal.c:376
ocfs2_modify_bh+0xe5/0x460 fs/ocfs2/quota_local.c:101
ocfs2_local_read_info+0x13b1/0x16e0 fs/ocfs2/quota_local.c:764
dquot_load_quota_sb+0x756/0xac0 fs/quota/dquot.c:2470
dquot_load_quota_inode+0x2d8/0x5d0 fs/quota/dquot.c:2507
ocfs2_enable_quotas+0x1c3/0x440 fs/ocfs2/super.c:926
ocfs2_fill_super+0x409f/0x4d00 fs/ocfs2/super.c:1139
mount_bdev+0x287/0x3c0 fs/super.c:1443
legacy_get_tree+0xe6/0x180 fs/fs_context.c:632
vfs_get_tree+0x88/0x270 fs/super.c:1573
do_new_mount+0x24a/0xa40 fs/namespace.c:3063
do_mount fs/namespace.c:3406 [inline]
__do_sys_mount fs/namespace.c:3614 [inline]
__se_sys_mount+0x2d6/0x3c0 fs/namespace.c:3591
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2

-> #1 (&journal->j_trans_barrier){.+.+}-{3:3}:
down_read+0x42/0x2d0 kernel/locking/rwsem.c:1520
ocfs2_start_trans+0x366/0x6c0 fs/ocfs2/journal.c:374
ocfs2_modify_bh+0xe5/0x460 fs/ocfs2/quota_local.c:101
ocfs2_local_read_info+0x13b1/0x16e0 fs/ocfs2/quota_local.c:764
dquot_load_quota_sb+0x756/0xac0 fs/quota/dquot.c:2470
dquot_load_quota_inode+0x2d8/0x5d0 fs/quota/dquot.c:2507
ocfs2_enable_quotas+0x1c3/0x440 fs/ocfs2/super.c:926
ocfs2_fill_super+0x409f/0x4d00 fs/ocfs2/super.c:1139
mount_bdev+0x287/0x3c0 fs/super.c:1443
legacy_get_tree+0xe6/0x180 fs/fs_context.c:632
vfs_get_tree+0x88/0x270 fs/super.c:1573
do_new_mount+0x24a/0xa40 fs/namespace.c:3063
do_mount fs/namespace.c:3406 [inline]
__do_sys_mount fs/namespace.c:3614 [inline]
__se_sys_mount+0x2d6/0x3c0 fs/namespace.c:3591
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2

-> #0 (sb_internal#2){.+.+}-{0:0}:
check_prev_add kernel/locking/lockdep.c:3090 [inline]
check_prevs_add kernel/locking/lockdep.c:3209 [inline]
validate_chain kernel/locking/lockdep.c:3825 [inline]
__lock_acquire+0x2cf8/0x7c50 kernel/locking/lockdep.c:5049
lock_acquire+0x1b4/0x490 kernel/locking/lockdep.c:5662
percpu_down_read include/linux/percpu-rwsem.h:51 [inline]
__sb_start_write include/linux/fs.h:1891 [inline]
sb_start_intwrite include/linux/fs.h:2013 [inline]
ocfs2_start_trans+0x267/0x6c0 fs/ocfs2/journal.c:372
ocfs2_extend_allocation+0x6c8/0x1840 fs/ocfs2/file.c:593
ocfs2_extend_no_holes+0x20b/0x490 fs/ocfs2/file.c:1027
ocfs2_acquire_dquot+0x5e8/0xb10 fs/ocfs2/quota_global.c:841
dqget+0x778/0xeb0 fs/quota/dquot.c:988
ocfs2_setattr+0xf16/0x1cf0 fs/ocfs2/file.c:1233
notify_change+0xc74/0xf40 fs/attr.c:499
chown_common+0x486/0x620 fs/open.c:736
vfs_fchown fs/open.c:804 [inline]
ksys_fchown+0xe2/0x150 fs/open.c:815
__do_sys_fchown fs/open.c:823 [inline]
__se_sys_fchown fs/open.c:821 [inline]
__x64_sys_fchown+0x76/0x80 fs/open.c:821
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2

other info that might help us debug this:

Chain exists of:
sb_internal#2 --> &ocfs2_quota_ip_alloc_sem_key --> &ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3

Possible unsafe locking scenario:

CPU0 CPU1
---- ----
lock(&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3);
lock(&ocfs2_quota_ip_alloc_sem_key);
lock(&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3);
lock(sb_internal#2);

*** DEADLOCK ***

6 locks held by syz.3.162/4967:
#0: ffff8880788d6460 (sb_writers#13){.+.+}-{0:0}, at: mnt_want_write_file+0x5c/0x200 fs/namespace.c:437
#1: ffff88805c4989c8 (&type->i_mutex_dir_key#8){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
#1: ffff88805c4989c8 (&type->i_mutex_dir_key#8){+.+.}-{3:3}, at: chown_common+0x320/0x620 fs/open.c:726
#2: ffff888070b100a8 (&dquot->dq_lock){+.+.}-{3:3}, at: ocfs2_acquire_dquot+0x293/0xb10 fs/ocfs2/quota_global.c:811
#3: ffff88805c49df48 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
#3: ffff88805c49df48 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#2){+.+.}-{3:3}, at: ocfs2_lock_global_qf+0x1c7/0x270 fs/ocfs2/quota_global.c:313
#4: ffff88805c49dbe0 (&ocfs2_quota_ip_alloc_sem_key){++++}-{3:3}, at: ocfs2_lock_global_qf+0x1e5/0x270 fs/ocfs2/quota_global.c:314
#5: ffff88805c49d108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: inode_lock include/linux/fs.h:758 [inline]
#5: ffff88805c49d108 (&ocfs2_sysfile_lock_key[args->fi_sysfile_type]#3){+.+.}-{3:3}, at: ocfs2_reserve_suballoc_bits+0x162/0x4630 fs/ocfs2/suballoc.c:782

stack backtrace:
CPU: 0 PID: 4967 Comm: syz.3.162 Not tainted 6.1.148-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
Call Trace:
<TASK>
dump_stack_lvl+0x168/0x22e lib/dump_stack.c:106
check_noncircular+0x274/0x310 kernel/locking/lockdep.c:2170
check_prev_add kernel/locking/lockdep.c:3090 [inline]
check_prevs_add kernel/locking/lockdep.c:3209 [inline]
validate_chain kernel/locking/lockdep.c:3825 [inline]
__lock_acquire+0x2cf8/0x7c50 kernel/locking/lockdep.c:5049
lock_acquire+0x1b4/0x490 kernel/locking/lockdep.c:5662
percpu_down_read include/linux/percpu-rwsem.h:51 [inline]
__sb_start_write include/linux/fs.h:1891 [inline]
sb_start_intwrite include/linux/fs.h:2013 [inline]
ocfs2_start_trans+0x267/0x6c0 fs/ocfs2/journal.c:372
ocfs2_extend_allocation+0x6c8/0x1840 fs/ocfs2/file.c:593
ocfs2_extend_no_holes+0x20b/0x490 fs/ocfs2/file.c:1027
ocfs2_acquire_dquot+0x5e8/0xb10 fs/ocfs2/quota_global.c:841
dqget+0x778/0xeb0 fs/quota/dquot.c:988
ocfs2_setattr+0xf16/0x1cf0 fs/ocfs2/file.c:1233
notify_change+0xc74/0xf40 fs/attr.c:499
chown_common+0x486/0x620 fs/open.c:736
vfs_fchown fs/open.c:804 [inline]
ksys_fchown+0xe2/0x150 fs/open.c:815
__do_sys_fchown fs/open.c:823 [inline]
__se_sys_fchown fs/open.c:821 [inline]
__x64_sys_fchown+0x76/0x80 fs/open.c:821
do_syscall_x64 arch/x86/entry/common.c:51 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:81
entry_SYSCALL_64_after_hwframe+0x68/0xd2
RIP: 0033:0x7f9d3638ebe9
Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffd393e0258 EFLAGS: 00000246 ORIG_RAX: 000000000000005d
RAX: ffffffffffffffda RBX: 00007f9d365b5fa0 RCX: 00007f9d3638ebe9
RDX: 000000000000000a RSI: 000000003a736e6f RDI: 0000000000000005
RBP: 00007f9d36411e19 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f9d365b5fa0 R14: 00007f9d365b5fa0 R15: 0000000000000003
</TASK>
(syz.3.162,4967,1):ocfs2_block_check_validate:402 ERROR: CRC32 failed: stored: 0xdf8356d3, computed 0xb8c23ae4. Applying ECC.
(syz.3.162,4967,1):ocfs2_block_check_validate:416 ERROR: Fixed CRC32 failed: stored: 0xdf8356d3, computed 0x2acb7e3c
(syz.3.162,4967,1):ocfs2_read_quota_phys_block:160 ERROR: status = -5
(syz.3.162,4967,1):ocfs2_quota_read:201 ERROR: status = -5
Quota error (device loop3): qtree_write_dquot: Error -5 occurred while creating quota
(syz.3.162,4967,1):ocfs2_acquire_dquot:878 ERROR: status = -5


---
Reply all
Reply to author
Forward
0 new messages