[v6.1] WARNING in btrfs_fileattr_set

7 views
Skip to first unread message

syzbot

unread,
Jan 9, 2025, 8:19:30 PM1/9/25
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: c63962be84ef Linux 6.1.124
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1303aef8580000
kernel config: https://syzkaller.appspot.com/x/.config?x=2f99ac2134f3ff64
dashboard link: https://syzkaller.appspot.com/bug?extid=beaf04e4ca3250ffbde2
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/7ce6b92b931c/disk-c63962be.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/edbb3cdca2c4/vmlinux-c63962be.xz
kernel image: https://storage.googleapis.com/syzbot-assets/728732ee05ab/Image-c63962be.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+beaf04...@syzkaller.appspotmail.com

BTRFS info (device loop1): 1 blocks of free space at or bigger than bytes is
------------[ cut here ]------------
WARNING: CPU: 0 PID: 8131 at fs/btrfs/ioctl.c:360 btrfs_fileattr_set+0x910/0xa28 fs/btrfs/ioctl.c:360
Modules linked in:
CPU: 0 PID: 8131 Comm: syz.1.747 Not tainted 6.1.124-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : btrfs_fileattr_set+0x910/0xa28 fs/btrfs/ioctl.c:360
lr : btrfs_fileattr_set+0x910/0xa28 fs/btrfs/ioctl.c:360
sp : ffff800023467870
x29: ffff8000234678a0 x28: 0000000000000001 x27: dfff800000000000
x26: 0000000000000000 x25: 0000000000000800 x24: 00000000ffffffe4
x23: ffff0000df194498 x22: 0000000000000000 x21: 1fffe0001be3289d
x20: 0000000000000000 x19: ffff0000df1944e8 x18: 1fffe0003679bf76
x17: ffff800015a8d000 x16: ffff800008301594 x15: ffff0001b3cdfbbc
x14: 1ffff00002b520b2 x13: dfff800000000000 x12: 0000000000000001
x11: 1fffe0001b21ed90 x10: 0000000000000000 x9 : 6e2964479ce71300
x8 : 6e2964479ce71300 x7 : ffff800008278b14 x6 : 0000000000000000
x5 : 0000000000000080 x4 : 0000000000000001 x3 : ffff800008266814
x2 : 0000000000000001 x1 : 0000000000000004 x0 : 0000000000000001
Call trace:
btrfs_fileattr_set+0x910/0xa28 fs/btrfs/ioctl.c:360
vfs_fileattr_set+0x70c/0xad4 fs/ioctl.c:696
do_vfs_ioctl+0x14cc/0x26f8
__do_sys_ioctl fs/ioctl.c:868 [inline]
__se_sys_ioctl fs/ioctl.c:856 [inline]
__arm64_sys_ioctl+0xe4/0x1c8 fs/ioctl.c:856
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2bc arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x58/0x13c arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x168 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
irq event stamp: 818
hardirqs last enabled at (817): [<ffff800008278bb4>] raw_spin_rq_unlock_irq kernel/sched/sched.h:1367 [inline]
hardirqs last enabled at (817): [<ffff800008278bb4>] finish_lock_switch+0xbc/0x1e8 kernel/sched/core.c:5000
hardirqs last disabled at (818): [<ffff80001232af44>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (804): [<ffff8000081c3414>] softirq_handle_end kernel/softirq.c:414 [inline]
softirqs last enabled at (804): [<ffff8000081c3414>] handle_softirqs+0xb84/0xd58 kernel/softirq.c:599
softirqs last disabled at (799): [<ffff800008020174>] __do_softirq+0x14/0x20 kernel/softirq.c:605
---[ end trace 0000000000000000 ]---
BTRFS info (device loop1: state A): dumping space info:
BTRFS info (device loop1: state A): space_info DATA+METADATA has 2043904 free, is full
BTRFS info (device loop1: state A): space_info total=3276800, used=49152, pinned=0, reserved=0, may_use=1183744, readonly=0 zone_unusable=0
BTRFS info (device loop1: state A): space_info SYSTEM has 8155136 free, is not full
BTRFS info (device loop1: state A): space_info total=12451840, used=4096, pinned=0, reserved=4096, may_use=98304, readonly=4190208 zone_unusable=0
BTRFS info (device loop1: state A): global_block_rsv: size 983040 reserved 983040
BTRFS info (device loop1: state A): trans_block_rsv: size 196608 reserved 196608
BTRFS info (device loop1: state A): chunk_block_rsv: size 98304 reserved 98304
BTRFS info (device loop1: state A): delayed_block_rsv: size 0 reserved 0
BTRFS info (device loop1: state A): delayed_refs_rsv: size 196608 reserved 4096
BTRFS: error (device loop1: state A) in btrfs_fileattr_set:360: errno=-28 No space left
BTRFS info (device loop1: state EA): forced readonly


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Jan 12, 2025, 5:39:25 PM1/12/25
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 4735586da88e Linux 5.15.176
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=130a8a18580000
kernel config: https://syzkaller.appspot.com/x/.config?x=caf0c22a63c5c861
dashboard link: https://syzkaller.appspot.com/bug?extid=8f8c6cbae94823e3e2f6
compiler: Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/3e7a2d136136/disk-4735586d.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/7597375cf469/vmlinux-4735586d.xz
kernel image: https://storage.googleapis.com/syzbot-assets/132474c9ad82/Image-4735586d.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+8f8c6c...@syzkaller.appspotmail.com

BTRFS info (device loop4): 1 blocks of free space at or bigger than bytes is
------------[ cut here ]------------
WARNING: CPU: 0 PID: 4151 at fs/btrfs/ioctl.c:339 btrfs_fileattr_set+0x7a8/0x9b8 fs/btrfs/ioctl.c:339
Modules linked in:
CPU: 0 PID: 4151 Comm: syz.4.6 Not tainted 5.15.176-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : btrfs_fileattr_set+0x7a8/0x9b8 fs/btrfs/ioctl.c:339
lr : btrfs_fileattr_set+0x7a8/0x9b8 fs/btrfs/ioctl.c:339
sp : ffff800020ba7850
x29: ffff800020ba7880 x28: 0000000000000001 x27: dfff800000000000
x26: 0000000000000800 x25: 0000000000000000 x24: 00000000ffffffe4
x23: ffff0000dcbe6210 x22: ffff0000e91e0d48 x21: 0000000000000000
x20: 1fffe0001b97cc4d x19: ffff0000dcbe6268 x18: 0000000000000001
x17: 0000000000000002 x16: ffff800011b4c240 x15: 00000000ffffffff
x14: ffff0000d6c01b40 x13: 0000000000000001 x12: 0000000000080000
x11: 000000000001c754 x10: ffff8000281df000 x9 : bbf645542a737e00
x8 : bbf645542a737e00 x7 : 0000000000000001 x6 : 0000000000000001
x5 : ffff800020ba6fb8 x4 : ffff800014c40660 x3 : ffff8000085567f8
x2 : 0000000000000001 x1 : 0000000100000000 x0 : 0000000000000026
Call trace:
btrfs_fileattr_set+0x7a8/0x9b8 fs/btrfs/ioctl.c:339
vfs_fileattr_set+0x70c/0xad4 fs/ioctl.c:700
do_vfs_ioctl+0x1634/0x2a38
__do_sys_ioctl fs/ioctl.c:872 [inline]
__se_sys_ioctl fs/ioctl.c:860 [inline]
__arm64_sys_ioctl+0xe4/0x1c8 fs/ioctl.c:860
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x138/0x258 arch/arm64/kernel/syscall.c:142
do_el0_svc+0x58/0x14c arch/arm64/kernel/syscall.c:181
el0_svc+0x7c/0x1f0 arch/arm64/kernel/entry-common.c:608
el0t_64_sync_handler+0x84/0xe4 arch/arm64/kernel/entry-common.c:626
el0t_64_sync+0x1a0/0x1a4 arch/arm64/kernel/entry.S:584
irq event stamp: 612
hardirqs last enabled at (611): [<ffff80000832c1a4>] __up_console_sem+0xb4/0x100 kernel/printk/printk.c:257
hardirqs last disabled at (612): [<ffff800011b478f4>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:396
softirqs last enabled at (572): [<ffff8000081b691c>] softirq_handle_end kernel/softirq.c:401 [inline]
softirqs last enabled at (572): [<ffff8000081b691c>] handle_softirqs+0xb88/0xdbc kernel/softirq.c:586
softirqs last disabled at (547): [<ffff8000081b6fb4>] __do_softirq kernel/softirq.c:592 [inline]
softirqs last disabled at (547): [<ffff8000081b6fb4>] do_softirq_own_stack include/asm-generic/softirq_stack.h:10 [inline]
softirqs last disabled at (547): [<ffff8000081b6fb4>] invoke_softirq kernel/softirq.c:439 [inline]
softirqs last disabled at (547): [<ffff8000081b6fb4>] __irq_exit_rcu+0x268/0x4d8 kernel/softirq.c:641
---[ end trace b4abf9c573c7fe79 ]---
BTRFS: error (device loop4) in btrfs_fileattr_set:339: errno=-28 No space left

syzbot

unread,
Apr 22, 2025, 6:39:16 PM4/22/25
to syzkaller...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.

syzbot

unread,
Apr 22, 2025, 6:51:17 PM4/22/25
to syzkaller...@googlegroups.com
Reply all
Reply to author
Forward
0 new messages