From: syzbot <syzbot+344c09c64fcd8d3d2782@syzkaller.appspotmail.com>
To: asmadeus@codewreck.org, ericvh@kernel.org,
linux-kernel@vger.kernel.org, linux_oss@crudebyte.com,
lucho@ionkov.net, syzkaller-bugs@googlegroups.com,
v9fs@lists.linux.dev
Subject: [syzbot] [v9fs?] WARNING in v9fs_init_request (2)
Date: Thu, 23 Jul 2026 22:26:32 -0700 [thread overview]
Message-ID: <6a62f788.dde6c935.cf6c8.000e.GAE@google.com> (raw)
Hello,
syzbot found the following issue on:
HEAD commit: 1590cf032971 Linux 7.2-rc4
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1446a746580000
kernel config: https://syzkaller.appspot.com/x/.config?x=48ef5c5c0f192153
dashboard link: https://syzkaller.appspot.com/bug?extid=344c09c64fcd8d3d2782
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=1632bc32580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=13e0b789580000
Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-1590cf03.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/3ad7477f3064/vmlinux-1590cf03.xz
kernel image: https://storage.googleapis.com/syzbot-assets/8e7a9174d4d6/bzImage-1590cf03.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+344c09c64fcd8d3d2782@syzkaller.appspotmail.com
------------[ cut here ]------------
folio expected an open fid inode->i_ino=4580113
WARNING: fs/9p/vfs_addr.c:168 at v9fs_init_request+0x451/0x540 fs/9p/vfs_addr.c:168, CPU#2: syz.0.21/5945
Modules linked in:
CPU: 2 UID: 0 PID: 5945 Comm: syz.0.21 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:v9fs_init_request+0x455/0x540 fs/9p/vfs_addr.c:168
Code: 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 40 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 db 00 00 00 48 8d 3d bf b1 20 0d 48 8b 73 40 <67> 48 0f b9 3a bb ea ff ff ff e9 41 fe ff ff e8 f7 98 ff fd be 02
RSP: 0018:ffffc90003c5f778 EFLAGS: 00010246
RAX: dffffc0000000000 RBX: ffff888056c2d240 RCX: ffffffff840a4337
RDX: 1ffff1100ad85a50 RSI: 0000000004580113 RDI: ffffffff912af550
RBP: fffffffffffffffe R08: 0000000000000007 R09: fffffffffffff000
R10: fffffffffffffffe R11: 0000000000000000 R12: ffff888038e04178
R13: ffff888050c78e41 R14: ffff888050c78bd0 R15: ffff888056c2d240
FS: 00007ff5dd1fe6c0(0000) GS:ffff8880d5fe6000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff5dd1bbff8 CR3: 000000003d81d000 CR4: 0000000000352ef0
Call Trace:
<TASK>
netfs_alloc_request+0x71c/0xcb0 fs/netfs/objects.c:72
netfs_read_folio+0x20c/0x13f0 fs/netfs/buffered_read.c:513
filemap_read_folio+0xfc/0x3b0 mm/filemap.c:2510
do_read_cache_folio+0x2d7/0x6b0 mm/filemap.c:4140
read_mapping_folio include/linux/pagemap.h:1015 [inline]
__page_get_link.isra.0+0x30/0x350 fs/namei.c:6336
page_get_link+0x44/0xf0 fs/namei.c:6366
v9fs_vfs_get_link_dotl+0x27b/0x310 fs/9p/vfs_inode_dotl.c:930
pick_link+0xd17/0x13c0 fs/namei.c:2068
step_into_slowpath+0x9ba/0xf90 fs/namei.c:2127
step_into fs/namei.c:2152 [inline]
walk_component fs/namei.c:2288 [inline]
lookup_last fs/namei.c:2789 [inline]
path_lookupat+0x58b/0xc40 fs/namei.c:2813
filename_lookup+0x202/0x590 fs/namei.c:2842
user_path_at+0x3c/0x60 fs/namei.c:3641
do_mount fs/namespace.c:4171 [inline]
__do_sys_mount fs/namespace.c:4390 [inline]
__se_sys_mount fs/namespace.c:4367 [inline]
__x64_sys_mount+0x1fb/0x310 fs/namespace.c:4367
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7ff5ddb9de99
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ff5dd1fe028 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007ff5dde25fa0 RCX: 00007ff5ddb9de99
RDX: 00002000000004c0 RSI: 0000200000000480 RDI: 0000000000000000
RBP: 00007ff5ddc33eaf R08: 0000200000000c00 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ff5dde26038 R14: 00007ff5dde25fa0 R15: 00007ffc18202cd8
</TASK>
----------------
Code disassembly (best guess):
0: 48 b8 00 00 00 00 00 movabs $0xdffffc0000000000,%rax
7: fc ff df
a: 48 8d 7b 40 lea 0x40(%rbx),%rdi
e: 48 89 fa mov %rdi,%rdx
11: 48 c1 ea 03 shr $0x3,%rdx
15: 80 3c 02 00 cmpb $0x0,(%rdx,%rax,1)
19: 0f 85 db 00 00 00 jne 0xfa
1f: 48 8d 3d bf b1 20 0d lea 0xd20b1bf(%rip),%rdi # 0xd20b1e5
26: 48 8b 73 40 mov 0x40(%rbx),%rsi
* 2a: 67 48 0f b9 3a ud1 (%edx),%rdi <-- trapping instruction
2f: bb ea ff ff ff mov $0xffffffea,%ebx
34: e9 41 fe ff ff jmp 0xfffffe7a
39: e8 f7 98 ff fd call 0xfdff9935
3e: be .byte 0xbe
3f: 02 .byte 0x2
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
next reply other threads:[~2026-07-24 5:26 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-24 5:26 syzbot [this message]
2026-07-24 11:53 ` Forwarded: [PATCH] 9p: add DIAG WARN_ONCE sites to disambiguate v9fs_init_request no_fid failures syzbot
2026-07-24 23:41 ` Forwarded: [PATCH] 9p: add printk diagnostics to identify -ENOENT source in v9fs_fid_lookup syzbot
[not found] <20260724115342.6983-1-kartikey406@gmail.com>
2026-07-24 18:20 ` [syzbot] [v9fs?] WARNING in v9fs_init_request (2) syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a62f788.dde6c935.cf6c8.000e.GAE@google.com \
--to=syzbot+344c09c64fcd8d3d2782@syzkaller.appspotmail.com \
--cc=asmadeus@codewreck.org \
--cc=ericvh@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux_oss@crudebyte.com \
--cc=lucho@ionkov.net \
--cc=syzkaller-bugs@googlegroups.com \
--cc=v9fs@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.