All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+e8cf1c2a389352f54126@syzkaller.appspotmail.com>
To: jack@suse.com, linux-kernel@vger.kernel.org,
	 syzkaller-bugs@googlegroups.com
Subject: [syzbot] [udf?] WARNING in udf_new_block (2)
Date: Mon, 13 Apr 2026 20:55:32 -0700	[thread overview]
Message-ID: <69ddbab4.a00a0220.475f0.0034.GAE@google.com> (raw)

Hello,

syzbot found the following issue on:

HEAD commit:    7c6c4ed80b87 Merge tag 'vfs-7.0-rc8.fixes' of git://git.ke..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1679fbd6580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=d46eab0cfd31c214
dashboard link: https://syzkaller.appspot.com/bug?extid=e8cf1c2a389352f54126
compiler:       Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-7c6c4ed8.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/c8457f50ff92/vmlinux-7c6c4ed8.xz
kernel image: https://storage.googleapis.com/syzbot-assets/e5a1d8ae449e/bzImage-7c6c4ed8.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+e8cf1c2a389352f54126@syzkaller.appspotmail.com

loop0: detected capacity change from 0 to 1024
UDF-fs: INFO Mounting volume 'LinuxUDF', timestamp 2022/11/22 14:59 (1000)
UDF-fs: warning (device loop0): udf_update_inode: IO error syncing udf inode [00000347]
------------[ cut here ]------------
!buffer_uptodate(bh)
WARNING: fs/buffer.c:1180 at mark_buffer_dirty+0x299/0x440 fs/buffer.c:1180, CPU#0: syz.0.0/5318
Modules linked in:
CPU: 0 UID: 0 PID: 5318 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:mark_buffer_dirty+0x299/0x440 fs/buffer.c:1180
Code: 4c 89 f7 e8 e9 fc d9 ff 49 8b 3e be 40 00 00 00 5b 41 5c 41 5e 41 5f 5d e9 c4 60 fb ff e8 7f 1c 6e ff eb 8c e8 78 1c 6e ff 90 <0f> 0b 90 e9 a5 fd ff ff e8 6a 1c 6e ff 90 0f 0b 90 e9 cf fd ff ff
RSP: 0018:ffffc9000e32f5d0 EFLAGS: 00010283
RAX: ffffffff8257b318 RBX: ffff888047e2ebc8 RCX: 0000000000100000
RDX: ffffc9000eb62000 RSI: 0000000000000a57 RDI: 0000000000000a58
RBP: ffffc9000e32f801 R08: ffff888047e2ebcf R09: 1ffff11008fc5d79
R10: dffffc0000000000 R11: ffffed1008fc5d7a R12: ffff8880126e8000
R13: 00000000000000bf R14: 000000000000017f R15: ffffc9000e32f950
FS:  00007f14e25e06c0(0000) GS:ffff88808ca49000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f14d560fe00 CR3: 0000000041faa000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 udf_bitmap_new_block fs/udf/balloc.c:347 [inline]
 udf_new_block+0x183b/0x1c70 fs/udf/balloc.c:721
 udf_add_aext fs/udf/inode.c:2131 [inline]
 udf_do_extend_file+0x878/0x11e0 fs/udf/inode.c:588
 udf_extend_file fs/udf/inode.c:709 [inline]
 udf_setsize+0xbf3/0x10b0 fs/udf/inode.c:1297
 udf_setattr+0x3a1/0x5a0 fs/udf/file.c:238
 notify_change+0xc1a/0xf40 fs/attr.c:556
 do_truncate+0x1c2/0x250 fs/open.c:68
 vfs_truncate+0x4b4/0x540 fs/open.c:118
 do_sys_truncate+0xf3/0x1c0 fs/open.c:142
 __do_sys_truncate fs/open.c:154 [inline]
 __se_sys_truncate fs/open.c:152 [inline]
 __x64_sys_truncate+0x5b/0x70 fs/open.c:152
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x14d/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f14e179c819
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f14e25dffe8 EFLAGS: 00000246 ORIG_RAX: 000000000000004c
RAX: ffffffffffffffda RBX: 00007f14e1a15fa0 RCX: 00007f14e179c819
RDX: 0000000000000000 RSI: 00000020fdfffffe RDI: 0000200000000100
RBP: 00007f14e1832c91 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f14e1a16038 R14: 00007f14e1a15fa0 R15: 00007ffe7a99f7e8
 </TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

                 reply	other threads:[~2026-04-14  3:55 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=69ddbab4.a00a0220.475f0.0034.GAE@google.com \
    --to=syzbot+e8cf1c2a389352f54126@syzkaller.appspotmail.com \
    --cc=jack@suse.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.