* [syzbot] [f2fs?] kernel BUG in f2fs_write_end_io (2)
@ 2026-05-14 20:19 syzbot
0 siblings, 0 replies; 4+ messages in thread
From: syzbot @ 2026-05-14 20:19 UTC (permalink / raw)
To: chao, jaegeuk, linux-f2fs-devel, linux-kernel, syzkaller-bugs
Hello,
syzbot found the following issue on:
HEAD commit: aa54b1d27fe0 rxrpc: Also unshare DATA/RESPONSE packets whe..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=14adabce580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f2e8ebfec4636d32
dashboard link: https://syzkaller.appspot.com/bug?extid=4af46ee83100e99bce09
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1643c3ce580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=12adabce580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/418e3ed628cf/disk-aa54b1d2.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/a35b53d0ab2f/vmlinux-aa54b1d2.xz
kernel image: https://storage.googleapis.com/syzbot-assets/03c3fa0081b4/bzImage-aa54b1d2.xz
mounted in repro #1: https://storage.googleapis.com/syzbot-assets/13e397c7f935/mount_0.gz
fsck result: failed (log: https://syzkaller.appspot.com/x/fsck.log?x=158fad06580000)
mounted in repro #2: https://storage.googleapis.com/syzbot-assets/2f91edde40dc/mount_8.gz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+4af46ee83100e99bce09@syzkaller.appspotmail.com
------------[ cut here ]------------
kernel BUG at fs/f2fs/data.c:388!
Oops: invalid opcode: 0000 [#1] SMP KASAN PTI
CPU: 1 UID: 0 PID: 31 Comm: ksoftirqd/1 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026
RIP: 0010:f2fs_write_end_io+0x16df/0x1740 fs/f2fs/data.c:388
Code: 20 3c 9b 8b e8 12 0a f7 fc 90 0f 0b e8 0a cc 93 fd 48 8b 3c 24 48 c7 c6 20 3c 9b 8b e8 fa 09 f7 fc 90 0f 0b e8 f2 cb 93 fd 90 <0f> 0b e8 ea cb 93 fd 48 8b 3c 24 48 c7 c6 20 3c 9b 8b e8 da 09 f7
RSP: 0018:ffffc90000a5fb18 EFLAGS: 00010246
RAX: ffffffff8430aade RBX: ffffea0000d91c40 RCX: ffff88801d6b0000
RDX: 0000000000000100 RSI: 0000000000000000 RDI: 0000000000000100
RBP: dffffc0000000000 R08: 0000000000000000 R09: 0000000000000100
R10: dffffc0000000000 R11: fffffbfff1f11dff R12: 0000000036471000
R13: ffffea0000d91c80 R14: 000000000000000b R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888126276000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007eff6352cff8 CR3: 000000002caa2000 CR4: 00000000003526f0
Call Trace:
<TASK>
blk_update_request+0x57e/0xe60 block/blk-mq.c:1016
blk_mq_end_request+0x3e/0x70 block/blk-mq.c:1178
blk_complete_reqs block/blk-mq.c:1253 [inline]
blk_done_softirq+0x10a/0x160 block/blk-mq.c:1258
handle_softirqs+0x1de/0x6d0 kernel/softirq.c:622
run_ksoftirqd+0x52/0x180 kernel/softirq.c:1076
smpboot_thread_fn+0x541/0xa50 kernel/smpboot.c:160
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:f2fs_write_end_io+0x16df/0x1740 fs/f2fs/data.c:388
Code: 20 3c 9b 8b e8 12 0a f7 fc 90 0f 0b e8 0a cc 93 fd 48 8b 3c 24 48 c7 c6 20 3c 9b 8b e8 fa 09 f7 fc 90 0f 0b e8 f2 cb 93 fd 90 <0f> 0b e8 ea cb 93 fd 48 8b 3c 24 48 c7 c6 20 3c 9b 8b e8 da 09 f7
RSP: 0018:ffffc90000a5fb18 EFLAGS: 00010246
RAX: ffffffff8430aade RBX: ffffea0000d91c40 RCX: ffff88801d6b0000
RDX: 0000000000000100 RSI: 0000000000000000 RDI: 0000000000000100
RBP: dffffc0000000000 R08: 0000000000000000 R09: 0000000000000100
R10: dffffc0000000000 R11: fffffbfff1f11dff R12: 0000000036471000
R13: ffffea0000d91c80 R14: 000000000000000b R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888126276000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007eff6352cff8 CR3: 000000002caa2000 CR4: 00000000003526f0
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [syzbot] [f2fs?] kernel BUG in f2fs_write_end_io (2)
[not found] <20260514233543.9626-1-kartikey406@gmail.com>
@ 2026-05-15 0:07 ` syzbot
0 siblings, 0 replies; 4+ messages in thread
From: syzbot @ 2026-05-15 0:07 UTC (permalink / raw)
To: kartikey406, linux-kernel, syzkaller-bugs
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
kernel BUG in f2fs_write_end_io
f2fs-dbg: WRITE end_io: index=11 footer_nid=0 ino=0 rc=-117
------------[ cut here ]------------
kernel BUG at fs/f2fs/data.c:397!
Oops: invalid opcode: 0000 [#1] SMP KASAN PTI
CPU: 0 UID: 0 PID: 15 Comm: ksoftirqd/0 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026
RIP: 0010:f2fs_write_end_io+0x193e/0x1970 fs/f2fs/data.c:397
Code: c6 e0 3c 9b 8b e8 02 e5 f6 fc 90 0f 0b e8 8a c9 93 fd 4c 89 e7 48 c7 c6 00 3e 9b 8b e8 eb e4 f6 fc 90 0f 0b e8 73 c9 93 fd 90 <0f> 0b e8 6b c9 93 fd 48 8b 3c 24 48 c7 c6 e0 3c 9b 8b e8 cb e4 f6
RSP: 0018:ffffc90000147b08 EFLAGS: 00010246
RAX: ffffffff8430cfed RBX: 0000000000001000 RCX: ffff88801cee9ec0
RDX: 0000000000000100 RSI: 0000000000000000 RDI: 0000000000000100
RBP: dffffc0000000000 R08: 0000000000000000 R09: 0000000000000100
R10: dffffc0000000000 R11: fffff52000028f11 R12: ffffea0000a312c0
R13: 0000000000001000 R14: 000000000000000b R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888126174000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fa3d3ae7dac CR3: 0000000037e5c000 CR4: 00000000003526f0
Call Trace:
<TASK>
blk_update_request+0x57e/0xe60 block/blk-mq.c:1016
blk_mq_end_request+0x3e/0x70 block/blk-mq.c:1178
blk_complete_reqs block/blk-mq.c:1253 [inline]
blk_done_softirq+0x10a/0x160 block/blk-mq.c:1258
handle_softirqs+0x1de/0x6d0 kernel/softirq.c:622
run_ksoftirqd+0x52/0x180 kernel/softirq.c:1076
smpboot_thread_fn+0x541/0xa50 kernel/smpboot.c:160
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:f2fs_write_end_io+0x193e/0x1970 fs/f2fs/data.c:397
Code: c6 e0 3c 9b 8b e8 02 e5 f6 fc 90 0f 0b e8 8a c9 93 fd 4c 89 e7 48 c7 c6 00 3e 9b 8b e8 eb e4 f6 fc 90 0f 0b e8 73 c9 93 fd 90 <0f> 0b e8 6b c9 93 fd 48 8b 3c 24 48 c7 c6 e0 3c 9b 8b e8 cb e4 f6
RSP: 0018:ffffc90000147b08 EFLAGS: 00010246
RAX: ffffffff8430cfed RBX: 0000000000001000 RCX: ffff88801cee9ec0
RDX: 0000000000000100 RSI: 0000000000000000 RDI: 0000000000000100
RBP: dffffc0000000000 R08: 0000000000000000 R09: 0000000000000100
R10: dffffc0000000000 R11: fffff52000028f11 R12: ffffea0000a312c0
R13: 0000000000001000 R14: 000000000000000b R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888126174000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fa3d3ae7dac CR3: 0000000037e5c000 CR4: 00000000003526f0
Tested on:
commit: 66182ca8 Merge tag 'net-7.1-rc4' of git://git.kernel.o..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=10c5e996580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f2e8ebfec4636d32
dashboard link: https://syzkaller.appspot.com/bug?extid=4af46ee83100e99bce09
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=1105e996580000
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [syzbot] [f2fs?] kernel BUG in f2fs_write_end_io (2)
[not found] <20260515005957.13243-1-kartikey406@gmail.com>
@ 2026-05-15 1:37 ` syzbot
0 siblings, 0 replies; 4+ messages in thread
From: syzbot @ 2026-05-15 1:37 UTC (permalink / raw)
To: kartikey406, linux-kernel, syzkaller-bugs
Hello,
syzbot has tested the proposed patch but the reproducer is still triggering an issue:
kernel BUG in f2fs_write_end_io
f2fs-dbg: READ end_io: index=3 footer_nid=0 ino=0 uptodate=0 dirty=0 rc=-117
f2fs-dbg: READ end_io: index=3 footer_nid=0 ino=0 uptodate=0 dirty=0 rc=-117
f2fs-dbg: WRITE end_io: index=3 footer_nid=0 ino=0 uptodate=0 dirty=0 rc=-117
------------[ cut here ]------------
kernel BUG at fs/f2fs/data.c:394!
Oops: invalid opcode: 0000 [#1] SMP KASAN PTI
CPU: 1 UID: 0 PID: 42 Comm: kworker/u8:2 Not tainted syzkaller #0 PREEMPT_{RT,(full)}
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026
Workqueue: bat_events batadv_bla_periodic_work
RIP: 0010:f2fs_write_end_io+0x1a74/0x1ab0 fs/f2fs/data.c:394
Code: c6 20 3d 9b 8b e8 cc d3 f6 fc 90 0f 0b e8 54 c8 93 fd 4c 89 e7 48 c7 c6 20 3d 9b 8b e8 b5 d3 f6 fc 90 0f 0b e8 3d c8 93 fd 90 <0f> 0b e8 35 c8 93 fd 48 8b 7c 24 08 48 c7 c6 20 3d 9b 8b e8 94 d3
RSP: 0018:ffffc90000b47590 EFLAGS: 00010246
RAX: ffffffff8430e123 RBX: 0000000000001000 RCX: ffff88801f2b0000
RDX: 0000000000000100 RSI: 0000000000000000 RDI: 0000000000000100
RBP: dffffc0000000000 R08: 0000000000000000 R09: 0000000000000100
R10: dffffc0000000000 R11: fffff52000168e61 R12: ffffea0000951140
R13: 0000000000001000 R14: 0000000000000003 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888126274000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000002b72c000 CR4: 00000000003526f0
Call Trace:
<TASK>
blk_update_request+0x57e/0xe60 block/blk-mq.c:1016
blk_mq_end_request+0x3e/0x70 block/blk-mq.c:1178
blk_complete_reqs block/blk-mq.c:1253 [inline]
blk_done_softirq+0x10a/0x160 block/blk-mq.c:1258
handle_softirqs+0x1de/0x6d0 kernel/softirq.c:622
__do_softirq kernel/softirq.c:656 [inline]
__local_bh_enable_ip+0x170/0x2b0 kernel/softirq.c:302
local_bh_enable include/linux/bottom_half.h:33 [inline]
netif_rx+0xb9/0xf0 net/core/dev.c:5775
batadv_bla_send_claim+0xa12/0xeb0 net/batman-adv/bridge_loop_avoidance.c:447
batadv_bla_send_announce net/batman-adv/bridge_loop_avoidance.c:675 [inline]
batadv_bla_periodic_work+0x629/0xae0 net/batman-adv/bridge_loop_avoidance.c:1490
process_one_work kernel/workqueue.c:3314 [inline]
process_scheduled_works+0xb5d/0x1860 kernel/workqueue.c:3397
worker_thread+0xa53/0xfc0 kernel/workqueue.c:3478
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
RIP: 0010:f2fs_write_end_io+0x1a74/0x1ab0 fs/f2fs/data.c:394
Code: c6 20 3d 9b 8b e8 cc d3 f6 fc 90 0f 0b e8 54 c8 93 fd 4c 89 e7 48 c7 c6 20 3d 9b 8b e8 b5 d3 f6 fc 90 0f 0b e8 3d c8 93 fd 90 <0f> 0b e8 35 c8 93 fd 48 8b 7c 24 08 48 c7 c6 20 3d 9b 8b e8 94 d3
RSP: 0018:ffffc90000b47590 EFLAGS: 00010246
RAX: ffffffff8430e123 RBX: 0000000000001000 RCX: ffff88801f2b0000
RDX: 0000000000000100 RSI: 0000000000000000 RDI: 0000000000000100
RBP: dffffc0000000000 R08: 0000000000000000 R09: 0000000000000100
R10: dffffc0000000000 R11: fffff52000168e61 R12: ffffea0000951140
R13: 0000000000001000 R14: 0000000000000003 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff888126274000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000002b72c000 CR4: 00000000003526f0
Tested on:
commit: 66182ca8 Merge tag 'net-7.1-rc4' of git://git.kernel.o..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=142d20ec580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f2e8ebfec4636d32
dashboard link: https://syzkaller.appspot.com/bug?extid=4af46ee83100e99bce09
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=1400d636580000
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [syzbot] [f2fs?] kernel BUG in f2fs_write_end_io (2)
[not found] <20260515015523.14962-1-kartikey406@gmail.com>
@ 2026-05-15 2:37 ` syzbot
0 siblings, 0 replies; 4+ messages in thread
From: syzbot @ 2026-05-15 2:37 UTC (permalink / raw)
To: kartikey406, linux-kernel, syzkaller-bugs
Hello,
syzbot has tested the proposed patch and the reproducer did not trigger any issue:
Reported-by: syzbot+4af46ee83100e99bce09@syzkaller.appspotmail.com
Tested-by: syzbot+4af46ee83100e99bce09@syzkaller.appspotmail.com
Tested on:
commit: 66182ca8 Merge tag 'net-7.1-rc4' of git://git.kernel.o..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=16a0f0c8580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f2e8ebfec4636d32
dashboard link: https://syzkaller.appspot.com/bug?extid=4af46ee83100e99bce09
compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
patch: https://syzkaller.appspot.com/x/patch.diff?x=16d3df6c580000
Note: testing is done by a robot and is best-effort only.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-05-15 2:37 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <20260515015523.14962-1-kartikey406@gmail.com>
2026-05-15 2:37 ` [syzbot] [f2fs?] kernel BUG in f2fs_write_end_io (2) syzbot
[not found] <20260515005957.13243-1-kartikey406@gmail.com>
2026-05-15 1:37 ` syzbot
[not found] <20260514233543.9626-1-kartikey406@gmail.com>
2026-05-15 0:07 ` syzbot
2026-05-14 20:19 syzbot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.