[v6.1] WARNING in f2fs_delete_entry

7 views
Skip to first unread message

syzbot

unread,
Nov 21, 2024, 4:29:31 PM11/21/24
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: b67dc5c9ade9 Linux 6.1.118
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=11fb8ec0580000
kernel config: https://syzkaller.appspot.com/x/.config?x=574f3f177f1573fa
dashboard link: https://syzkaller.appspot.com/bug?extid=4ecfc6dcd5172a23fc28
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/7bb54d7e4cde/disk-b67dc5c9.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/884b8b3180c7/vmlinux-b67dc5c9.xz
kernel image: https://storage.googleapis.com/syzbot-assets/476257459caa/Image-b67dc5c9.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+4ecfc6...@syzkaller.appspotmail.com

F2FS-fs (loop3): invalid crc value
F2FS-fs (loop3): Found nat_bits in checkpoint
F2FS-fs (loop3): Mounted with checkpoint version = 48b305e4
------------[ cut here ]------------
WARNING: CPU: 1 PID: 4402 at fs/inode.c:332 drop_nlink+0xe4/0x138 fs/inode.c:332
Modules linked in:
CPU: 1 PID: 4402 Comm: syz.3.8 Not tainted 6.1.118-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : drop_nlink+0xe4/0x138 fs/inode.c:332
lr : drop_nlink+0xe4/0x138 fs/inode.c:332
sp : ffff800021607920
x29: ffff800021607920 x28: dfff800000000000 x27: dfff800000000000
x26: ffff0000f575c000 x25: 1fffe0001e933470 x24: ffff0000f499a3f8
x23: 1fffe0001e933479 x22: dfff800000000000 x21: 0000000000000000
x20: ffff0000f499a3c8 x19: ffff0000f499a380 x18: ffff800021607560
x17: ffff800018aab000 x16: ffff800008300db8 x15: ffff80001858bf80
x14: ffff0000d79741f8 x13: dfff800000000000 x12: 0000000000080000
x11: 000000000000e61e x10: ffff80002396c000 x9 : ffff800008aaad30
x8 : 000000000000e61f x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000020 x4 : 0000000000000000 x3 : 0000000000000000
x2 : 0000000000000006 x1 : 0000000000000000 x0 : 0000000000000000
Call trace:
drop_nlink+0xe4/0x138 fs/inode.c:332
f2fs_i_links_write fs/f2fs/f2fs.h:3044 [inline]
f2fs_drop_nlink+0x110/0x34c fs/f2fs/dir.c:899
f2fs_delete_entry+0xae4/0xefc fs/f2fs/dir.c:966
f2fs_unlink+0x4b8/0xbdc fs/f2fs/namei.c:562
vfs_unlink+0x2f0/0x508 fs/namei.c:4322
do_unlinkat+0x4cc/0x70c fs/namei.c:4390
__do_sys_unlinkat fs/namei.c:4433 [inline]
__se_sys_unlinkat fs/namei.c:4426 [inline]
__arm64_sys_unlinkat+0xcc/0xfc fs/namei.c:4426
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x168 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
irq event stamp: 279280
hardirqs last enabled at (279279): [<ffff800008403650>] seqcount_lockdep_reader_access include/linux/seqlock.h:104 [inline]
hardirqs last enabled at (279279): [<ffff800008403650>] ktime_get_coarse_real_ts64+0x114/0x244 kernel/time/timekeeping.c:2261
hardirqs last disabled at (279280): [<ffff8000122919a4>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (279146): [<ffff800008030310>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (279144): [<ffff8000080302dc>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:19
---[ end trace 0000000000000000 ]---


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Nov 21, 2024, 4:29:32 PM11/21/24
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 0a51d2d4527b Linux 5.15.173
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=137dfae8580000
kernel config: https://syzkaller.appspot.com/x/.config?x=a6b3013b6f1a102b
dashboard link: https://syzkaller.appspot.com/bug?extid=42665772e58deba33ed6
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/731bd13b5412/disk-0a51d2d4.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/a53b07f54a18/vmlinux-0a51d2d4.xz
kernel image: https://storage.googleapis.com/syzbot-assets/5f1392034bb8/Image-0a51d2d4.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+426657...@syzkaller.appspotmail.com

F2FS-fs (loop3): invalid crc value
F2FS-fs (loop3): Found nat_bits in checkpoint
F2FS-fs (loop3): Mounted with checkpoint version = 48b305e4
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4465 at fs/inode.c:307 drop_nlink+0xe8/0x148 fs/inode.c:307
Modules linked in:
CPU: 0 PID: 4465 Comm: syz.3.81 Not tainted 5.15.173-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : drop_nlink+0xe8/0x148 fs/inode.c:307
lr : drop_nlink+0xe8/0x148 fs/inode.c:307
sp : ffff800020497910
x29: ffff800020497910 x28: fffffc0003af3c88 x27: dfff800000000000
x26: dfff800000000000 x25: 1fffe0001d3ce000 x24: ffff0000e9e70078
x23: 1fffe0001d3ce009 x22: dfff800000000000 x21: 0000000000000000
x20: ffff0000e9e70048 x19: ffff0000e9e70000 x18: ffff800020497520
x17: 0000000000000002 x16: ffff8000082ec8b8 x15: 0000000000020e82
x14: ffff800017140500 x13: dfff800000000000 x12: 0000000000080000
x11: 0000000000013b1d x10: ffff8000233ea000 x9 : 0000000000013b1e
x8 : ffff8000089ea188 x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000020 x4 : 0000000000000000 x3 : ffff80000804605c
x2 : 0000000000000006 x1 : 0000000000000000 x0 : 0000000000000000
Call trace:
drop_nlink+0xe8/0x148 fs/inode.c:307
f2fs_i_links_write fs/f2fs/f2fs.h:2884 [inline]
f2fs_drop_nlink+0x10c/0x314 fs/f2fs/dir.c:888
f2fs_delete_entry+0x9e4/0xd6c fs/f2fs/dir.c:955
f2fs_unlink+0x2fc/0x93c fs/f2fs/namei.c:567
vfs_unlink+0x2f0/0x508 fs/namei.c:4280
do_unlinkat+0x4cc/0x830 fs/namei.c:4348
__do_sys_unlinkat fs/namei.c:4391 [inline]
__se_sys_unlinkat fs/namei.c:4384 [inline]
__arm64_sys_unlinkat+0xcc/0xfc fs/namei.c:4384
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x7c/0x1f0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0x84/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584
irq event stamp: 317712
hardirqs last enabled at (317711): [<ffff8000083c6d0c>] seqcount_lockdep_reader_access+0x208/0x2cc include/linux/seqlock.h:105
hardirqs last disabled at (317712): [<ffff800011ab40c0>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:396
softirqs last enabled at (317580): [<ffff8000080308b0>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:31
softirqs last disabled at (317578): [<ffff80000803087c>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:18
---[ end trace a6aa7ac4372ac05a ]---

syzbot

unread,
Nov 21, 2024, 4:44:24 PM11/21/24
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 0a51d2d4527b Linux 5.15.173
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1653a75f980000
kernel config: https://syzkaller.appspot.com/x/.config?x=a6b3013b6f1a102b
dashboard link: https://syzkaller.appspot.com/bug?extid=42665772e58deba33ed6
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16a3fae8580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=10578ec0580000
mounted in repro: https://storage.googleapis.com/syzbot-assets/a9f6e8147854/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+426657...@syzkaller.appspotmail.com

F2FS-fs (loop0): invalid crc value
F2FS-fs (loop0): Found nat_bits in checkpoint
F2FS-fs (loop0): Mounted with checkpoint version = 48b305e4
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4019 at fs/inode.c:307 drop_nlink+0xe8/0x148 fs/inode.c:307
Modules linked in:
CPU: 0 PID: 4019 Comm: syz-executor405 Not tainted 5.15.173-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : drop_nlink+0xe8/0x148 fs/inode.c:307
lr : drop_nlink+0xe8/0x148 fs/inode.c:307
sp : ffff80001d0d7910
x29: ffff80001d0d7910 x28: fffffc000349c5c8 x27: dfff800000000000
x26: dfff800000000000 x25: 1fffe0001ba7d390 x24: ffff0000dd3e9cf8
x23: 1fffe0001ba7d399 x22: dfff800000000000 x21: 0000000000000000
x20: ffff0000dd3e9cc8 x19: ffff0000dd3e9c80 x18: ffff80001d0d7520
x17: 0000000000000000 x16: ffff8000082ec8b8 x15: 000000000000bce9
x14: 00000000b730e04d x13: dfff800000000000 x12: 0000000000000003
x11: 0000000000000000 x10: 0000000000000000 x9 : ffff0000d85151c0
x8 : ffff8000089ea188 x7 : 0000000000000000 x6 : 0000000000000000
x5 : ffff800017797d10 x4 : 0000000000000000 x3 : ffff80000804605c
x2 : 0000000000000006 x1 : 0000000000000000 x0 : 0000000000000000
Call trace:
drop_nlink+0xe8/0x148 fs/inode.c:307
f2fs_i_links_write fs/f2fs/f2fs.h:2884 [inline]
f2fs_drop_nlink+0x10c/0x314 fs/f2fs/dir.c:888
f2fs_delete_entry+0x9e4/0xd6c fs/f2fs/dir.c:955
f2fs_unlink+0x2fc/0x93c fs/f2fs/namei.c:567
vfs_unlink+0x2f0/0x508 fs/namei.c:4280
do_unlinkat+0x4cc/0x830 fs/namei.c:4348
__do_sys_unlinkat fs/namei.c:4391 [inline]
__se_sys_unlinkat fs/namei.c:4384 [inline]
__arm64_sys_unlinkat+0xcc/0xfc fs/namei.c:4384
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x7c/0x1f0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0x84/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584
irq event stamp: 284432
hardirqs last enabled at (284431): [<ffff8000083c6d0c>] seqcount_lockdep_reader_access+0x208/0x2cc include/linux/seqlock.h:105
hardirqs last disabled at (284432): [<ffff800011ab40c0>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:396
softirqs last enabled at (284330): [<ffff8000081b691c>] softirq_handle_end kernel/softirq.c:401 [inline]
softirqs last enabled at (284330): [<ffff8000081b691c>] handle_softirqs+0xb88/0xdbc kernel/softirq.c:586
softirqs last disabled at (284321): [<ffff8000081b6fb4>] __do_softirq kernel/softirq.c:592 [inline]
softirqs last disabled at (284321): [<ffff8000081b6fb4>] do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
softirqs last disabled at (284321): [<ffff8000081b6fb4>] invoke_softirq kernel/softirq.c:439 [inline]
softirqs last disabled at (284321): [<ffff8000081b6fb4>] __irq_exit_rcu+0x268/0x4d8 kernel/softirq.c:641
---[ end trace b42974414c01a154 ]---


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Nov 21, 2024, 4:57:28 PM11/21/24
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: b67dc5c9ade9 Linux 6.1.118
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=140f8ec0580000
kernel config: https://syzkaller.appspot.com/x/.config?x=574f3f177f1573fa
dashboard link: https://syzkaller.appspot.com/bug?extid=4ecfc6dcd5172a23fc28
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1193fae8580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=120f8ec0580000
mounted in repro: https://storage.googleapis.com/syzbot-assets/00f4e37320f3/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+4ecfc6...@syzkaller.appspotmail.com

F2FS-fs (loop0): invalid crc value
F2FS-fs (loop0): Found nat_bits in checkpoint
F2FS-fs (loop0): Mounted with checkpoint version = 48b305e4
------------[ cut here ]------------
WARNING: CPU: 1 PID: 4297 at fs/inode.c:332 drop_nlink+0xe4/0x138 fs/inode.c:332
Modules linked in:
CPU: 1 PID: 4297 Comm: syz-executor347 Not tainted 6.1.118-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : drop_nlink+0xe4/0x138 fs/inode.c:332
lr : drop_nlink+0xe4/0x138 fs/inode.c:332
sp : ffff8000213c7920
x29: ffff8000213c7920 x28: dfff800000000000 x27: dfff800000000000
x26: ffff0000d0652000 x25: 1fffe0001c372354 x24: ffff0000e1b91b18
x23: 1fffe0001c37235d x22: dfff800000000000 x21: 0000000000000000
x20: ffff0000e1b91ae8 x19: ffff0000e1b91aa0 x18: ffff8000213c7560
x17: ffff800018aab000 x16: ffff800008300db8 x15: ffff80001858bf80
x14: 00000000b0d4b4f1 x13: dfff800000000000 x12: 0000000000000003
x11: 0000000000ff0100 x10: 0000000000000000 x9 : ffff800008aaad30
x8 : ffff0000c9f00000 x7 : 0000000000000000 x6 : 0000000000000000
x5 : ffff800018be83d8 x4 : 0000000000000004 x3 : 0000000000000000
x2 : 0000000000000006 x1 : 0000000000000000 x0 : 0000000000000000
Call trace:
drop_nlink+0xe4/0x138 fs/inode.c:332
f2fs_i_links_write fs/f2fs/f2fs.h:3044 [inline]
f2fs_drop_nlink+0x110/0x34c fs/f2fs/dir.c:899
f2fs_delete_entry+0xae4/0xefc fs/f2fs/dir.c:966
f2fs_unlink+0x4b8/0xbdc fs/f2fs/namei.c:562
vfs_unlink+0x2f0/0x508 fs/namei.c:4322
do_unlinkat+0x4cc/0x70c fs/namei.c:4390
__do_sys_unlinkat fs/namei.c:4433 [inline]
__se_sys_unlinkat fs/namei.c:4426 [inline]
__arm64_sys_unlinkat+0xcc/0xfc fs/namei.c:4426
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x168 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
irq event stamp: 251174
hardirqs last enabled at (251173): [<ffff800008403650>] seqcount_lockdep_reader_access include/linux/seqlock.h:104 [inline]
hardirqs last enabled at (251173): [<ffff800008403650>] ktime_get_coarse_real_ts64+0x114/0x244 kernel/time/timekeeping.c:2261
hardirqs last disabled at (251174): [<ffff8000122919a4>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (250886): [<ffff800008030310>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (250884): [<ffff8000080302dc>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:19
---[ end trace 0000000000000000 ]---


---

syzbot

unread,
Sep 18, 2025, 2:39:16 AM9/18/25
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
No recent activity, existing reproducers are no longer triggering the issue.
Reply all
Reply to author
Forward
0 new messages