All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+b93b65ee321c97861072@syzkaller.appspotmail.com>
To: jlbec@evilplan.org, joseph.qi@linux.alibaba.com,
	 linux-kernel@vger.kernel.org, mark@fasheh.com,
	ocfs2-devel@lists.linux.dev,  syzkaller-bugs@googlegroups.com
Subject: Re: [syzbot] [ocfs2?] kernel BUG in ocfs2_truncate_file
Date: Tue, 25 Feb 2025 09:17:21 -0800	[thread overview]
Message-ID: <67bdfb21.050a0220.bbfd1.00ac.GAE@google.com> (raw)
In-Reply-To: <66f0a364.050a0220.a27de.0009.GAE@google.com>

syzbot has found a reproducer for the following issue on:

HEAD commit:    d082ecbc71e9 Linux 6.14-rc4
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=14b126e4580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=5b4c41bdaeea1964
dashboard link: https://syzkaller.appspot.com/bug?extid=b93b65ee321c97861072
compiler:       Debian clang version 15.0.6, GNU ld (GNU Binutils for Debian) 2.40
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=166f77f8580000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=12b126e4580000

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/7feb34a89c2a/non_bootable_disk-d082ecbc.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/c5299c562b1f/vmlinux-d082ecbc.xz
kernel image: https://storage.googleapis.com/syzbot-assets/c0bed38fa342/bzImage-d082ecbc.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/30f6f2b1247c/mount_0.gz
  fsck result: OK (log: https://syzkaller.appspot.com/x/fsck.log?x=10b126e4580000)

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b93b65ee321c97861072@syzkaller.appspotmail.com

(syz-executor151,5310,0):ocfs2_truncate_file:460 ERROR: bug expression: le64_to_cpu(fe->i_size) != i_size_read(inode)
(syz-executor151,5310,0):ocfs2_truncate_file:460 ERROR: Inode 17058, inode i_size = 0 != di i_size = 281481419161600, i_flags = 0x67bd
------------[ cut here ]------------
kernel BUG at fs/ocfs2/file.c:460!
Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 5310 Comm: syz-executor151 Not tainted 6.14.0-rc4-syzkaller #0
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:ocfs2_truncate_file+0x139f/0x1560 fs/ocfs2/file.c:454
Code: 40 01 00 00 48 c7 c6 46 0d 35 8e ba cc 01 00 00 48 c7 c1 c0 69 69 8c 4d 89 e8 4d 89 f9 50 41 56 e8 d6 96 19 00 48 83 c4 10 90 <0f> 0b e8 4a f1 4b 08 f3 0f 1e fa 65 44 8b 35 aa 7a 47 7c bf 07 00
RSP: 0018:ffffc9000d257280 EFLAGS: 00010282
RAX: 5796f80f25df1300 RBX: ffff888048ec542c RCX: 5796f80f25df1300
RDX: 0000000000000000 RSI: 0000000080000000 RDI: 0000000000000000
RBP: ffffc9000d2574b0 R08: ffffffff81a113fc R09: 1ffff92001a4adbc
R10: dffffc0000000000 R11: fffff52001a4adbd R12: 1ffff110091d8a84
R13: 00000000000042a2 R14: 0001000180000000 R15: 0000000000000000
FS:  000055558b494380(0000) GS:ffff88801fc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000056519020e6c0 CR3: 0000000043316000 CR4: 0000000000352ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 ocfs2_setattr+0x1890/0x1ef0 fs/ocfs2/file.c:1212
 notify_change+0xbca/0xe90 fs/attr.c:552
 do_truncate+0x220/0x310 fs/open.c:65
 handle_truncate fs/namei.c:3451 [inline]
 do_open fs/namei.c:3834 [inline]
 path_openat+0x2e1b/0x3590 fs/namei.c:3989
 do_filp_open+0x27f/0x4e0 fs/namei.c:4016
 do_sys_openat2+0x13e/0x1d0 fs/open.c:1428
 do_sys_open fs/open.c:1443 [inline]
 __do_sys_openat fs/open.c:1459 [inline]
 __se_sys_openat fs/open.c:1454 [inline]
 __x64_sys_openat+0x247/0x2a0 fs/open.c:1454
 do_syscall_x64 arch/x86/entry/common.c:52 [inline]
 do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7ff7d0f62e59
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffce7922bd8 EFLAGS: 00000246 ORIG_RAX: 0000000000000101
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007ff7d0f62e59
RDX: 000000000000275a RSI: 0000400000000040 RDI: 00000000ffffff9c
RBP: 0000400000000040 R08: 000055558b4954c0 R09: 000055558b4954c0
R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffce7922c00
R13: 0000400000004500 R14: 00007ffce7922c00 R15: 00007ff7d0fac03b
 </TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:ocfs2_truncate_file+0x139f/0x1560 fs/ocfs2/file.c:454
Code: 40 01 00 00 48 c7 c6 46 0d 35 8e ba cc 01 00 00 48 c7 c1 c0 69 69 8c 4d 89 e8 4d 89 f9 50 41 56 e8 d6 96 19 00 48 83 c4 10 90 <0f> 0b e8 4a f1 4b 08 f3 0f 1e fa 65 44 8b 35 aa 7a 47 7c bf 07 00
RSP: 0018:ffffc9000d257280 EFLAGS: 00010282
RAX: 5796f80f25df1300 RBX: ffff888048ec542c RCX: 5796f80f25df1300
RDX: 0000000000000000 RSI: 0000000080000000 RDI: 0000000000000000
RBP: ffffc9000d2574b0 R08: ffffffff81a113fc R09: 1ffff92001a4adbc
R10: dffffc0000000000 R11: fffff52001a4adbd R12: 1ffff110091d8a84
R13: 00000000000042a2 R14: 0001000180000000 R15: 0000000000000000
FS:  000055558b494380(0000) GS:ffff88801fc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000056519020e6c0 CR3: 0000000043316000 CR4: 0000000000352ef0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

  reply	other threads:[~2025-02-25 17:17 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-09-22 23:08 [syzbot] [ocfs2?] kernel BUG in ocfs2_truncate_file syzbot
2025-02-25 17:17 ` syzbot [this message]
2025-10-28 23:30 ` Forwarded: " syzbot
2025-10-29  0:07 ` syzbot
2025-10-29  6:59 ` syzbot
     [not found] <CAHxJ8O-DsKCj085k8N97bGqgWnHUpa++2HE4Au+axkvMkAPRcw@mail.gmail.com>
2025-10-28 23:52 ` [syzbot] [ocfs2?] " syzbot
     [not found] <CAHxJ8O-JKA=eMjKGOYg3a5nhxxdHsx8rMXLrsdJGHEk34vrm2Q@mail.gmail.com>
2025-10-29  0:29 ` syzbot
     [not found] <CADfthj20y6KMBwQg-kT=be30X7hMOE7rPaS6OiDVLXDPgBub5g@mail.gmail.com>
2025-10-29 10:39 ` syzbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=67bdfb21.050a0220.bbfd1.00ac.GAE@google.com \
    --to=syzbot+b93b65ee321c97861072@syzkaller.appspotmail.com \
    --cc=jlbec@evilplan.org \
    --cc=joseph.qi@linux.alibaba.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mark@fasheh.com \
    --cc=ocfs2-devel@lists.linux.dev \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.