WARNING in btrfs_quota_enable

5 views
Skip to first unread message

syzbot

unread,
Dec 15, 2022, 5:06:46 AM12/15/22
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 3f8a27f9e27b Linux 4.19.211
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=14c2053f880000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b9277b418617afe
dashboard link: https://syzkaller.appspot.com/bug?extid=760589ed572a2a629d01
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/98c0bdb4abb3/disk-3f8a27f9.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/ea228ff02669/vmlinux-3f8a27f9.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+760589...@syzkaller.appspotmail.com

RDX: 0000000020000000 RSI: 00000000c0109428 RDI: 0000000000000006
RBP: 00007f2ee36cf1d0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001
R13: 00007ffde72239ef R14: 00007f2ee36cf300 R15: 0000000000022000
------------[ cut here ]------------
WARNING: CPU: 0 PID: 27786 at fs/btrfs/qgroup.c:926 btrfs_quota_enable+0xa1c/0x10b0 fs/btrfs/qgroup.c:926
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 27786 Comm: syz-executor.3 Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2ef lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
__warn.cold+0x20/0x5a kernel/panic.c:541
report_bug+0x262/0x2b0 lib/bug.c:183
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1d7/0x310 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1038
RIP: 0010:btrfs_quota_enable+0xa1c/0x10b0 fs/btrfs/qgroup.c:926
Code: fb ff ff ff 44 89 f6 e8 82 13 65 fe 41 83 fe fb 0f 84 49 a7 fd 04 e8 03 12 65 fe 44 89 f6 48 c7 c7 80 be a5 88 e8 d9 49 f5 04 <0f> 0b e8 ed 11 65 fe 4c 8b 74 24 28 ba 9e 03 00 00 48 c7 c6 40 c4
RSP: 0018:ffff88809333f910 EFLAGS: 00010286
RAX: 0000000000000000 RBX: ffff888093e298c0 RCX: 0000000000000000
RDX: 0000000000040000 RSI: ffffffff814dff01 RDI: ffffed1012667f14
RBP: ffff8880a1c12980 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000005 R11: 0000000000000000 R12: 00000000fffffff4
R13: ffff8880960d6c00 R14: fffffffffffffff4 R15: ffff888048c1c9c0
btrfs_ioctl_quota_ctl fs/btrfs/ioctl.c:5233 [inline]
btrfs_ioctl+0x622c/0x76d0 fs/btrfs/ioctl.c:6021
vfs_ioctl fs/ioctl.c:46 [inline]
file_ioctl fs/ioctl.c:501 [inline]
do_vfs_ioctl+0xcdb/0x12e0 fs/ioctl.c:688
ksys_ioctl+0x9b/0xc0 fs/ioctl.c:705
__do_sys_ioctl fs/ioctl.c:712 [inline]
__se_sys_ioctl fs/ioctl.c:710 [inline]
__x64_sys_ioctl+0x6f/0xb0 fs/ioctl.c:710
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7f2ee515d0d9
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 19 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f2ee36cf168 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007f2ee527cf80 RCX: 00007f2ee515d0d9
RDX: 0000000020000000 RSI: 00000000c0109428 RDI: 0000000000000006
RBP: 00007f2ee36cf1d0 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001
R13: 00007ffde72239ef R14: 00007f2ee36cf300 R15: 0000000000022000
Kernel Offset: disabled
Rebooting in 86400 seconds..


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Dec 20, 2022, 4:52:34 AM12/20/22
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: 3f8a27f9e27b Linux 4.19.211
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=12562ab7880000
kernel config: https://syzkaller.appspot.com/x/.config?x=9b9277b418617afe
dashboard link: https://syzkaller.appspot.com/bug?extid=760589ed572a2a629d01
compiler: gcc version 10.2.1 20210110 (Debian 10.2.1-6)
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=175433af880000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=152205af880000
mounted in repro: https://storage.googleapis.com/syzbot-assets/16828caa8a78/mount_0.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+760589...@syzkaller.appspotmail.com

RBP: 00007ffc339da100 R08: 0000000000000001 R09: 00007ffc339da080
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000005
R13: 00007ffc339da210 R14: 431bde82d7b634db R15: 00007ffc339da110
------------[ cut here ]------------
WARNING: CPU: 0 PID: 8117 at fs/btrfs/qgroup.c:915 btrfs_quota_enable+0xf17/0x10b0 fs/btrfs/qgroup.c:915
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 8117 Comm: syz-executor343 Not tainted 4.19.211-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x1fc/0x2ef lib/dump_stack.c:118
panic+0x26a/0x50e kernel/panic.c:186
__warn.cold+0x20/0x5a kernel/panic.c:541
report_bug+0x262/0x2b0 lib/bug.c:183
fixup_bug arch/x86/kernel/traps.c:178 [inline]
fixup_bug arch/x86/kernel/traps.c:173 [inline]
do_error_trap+0x1d7/0x310 arch/x86/kernel/traps.c:296
invalid_op+0x14/0x20 arch/x86/entry/entry_64.S:1038
RIP: 0010:btrfs_quota_enable+0xf17/0x10b0 fs/btrfs/qgroup.c:915
Code: 92 c5 31 ff 89 ee e8 48 0e 65 fe 40 84 ed 0f 85 ad a0 fd 04 e8 0a 0d 65 fe be f4 ff ff ff 48 c7 c7 80 be a5 88 e8 de 44 f5 04 <0f> 0b e9 90 a0 fd 04 4c 89 f7 e8 da e9 9a fe e9 5f fb ff ff e8 e0
RSP: 0018:ffff8880b14b7910 EFLAGS: 00010286
RAX: 0000000000000000 RBX: ffff88809232c180 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffffffff814dff01 RDI: ffffed1016296f14
RBP: dffffc0000000000 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000005 R11: 0000000000000000 R12: ffff8880b292d200
R13: ffff8880b3ce1080 R14: ffff8880ae167738 R15: ffff8880952f6000
btrfs_ioctl_quota_ctl fs/btrfs/ioctl.c:5233 [inline]
btrfs_ioctl+0x622c/0x76d0 fs/btrfs/ioctl.c:6021
vfs_ioctl fs/ioctl.c:46 [inline]
file_ioctl fs/ioctl.c:501 [inline]
do_vfs_ioctl+0xcdb/0x12e0 fs/ioctl.c:688
ksys_ioctl+0x9b/0xc0 fs/ioctl.c:705
__do_sys_ioctl fs/ioctl.c:712 [inline]
__se_sys_ioctl fs/ioctl.c:710 [inline]
__x64_sys_ioctl+0x6f/0xb0 fs/ioctl.c:710
do_syscall_64+0xf9/0x620 arch/x86/entry/common.c:293
entry_SYSCALL_64_after_hwframe+0x49/0xbe
RIP: 0033:0x7f989984e209
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 d1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffc339da0e8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 00007f989984e209
RDX: 0000000020000000 RSI: 00000000c0109428 RDI: 0000000000000004
RBP: 00007ffc339da100 R08: 0000000000000001 R09: 00007ffc339da080
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000005
R13: 00007ffc339da210 R14: 431bde82d7b634db R15: 00007ffc339da110
Reply all
Reply to author
Forward
0 new messages