All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+344c09c64fcd8d3d2782@syzkaller.appspotmail.com>
To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com
Subject: Forwarded: [PATCH] 9p: add DIAG WARN_ONCE sites to disambiguate v9fs_init_request no_fid failures
Date: Fri, 24 Jul 2026 04:53:50 -0700	[thread overview]
Message-ID: <6a63524e.dde6c935.cf6c8.001e.GAE@google.com> (raw)
In-Reply-To: <6a62f788.dde6c935.cf6c8.000e.GAE@google.com>

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: [PATCH] 9p: add DIAG WARN_ONCE sites to disambiguate v9fs_init_request no_fid failures
Author: kartikey406@gmail.com

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master


v9fs_init_request() funnels four different failure modes into a
single shared WARN_ONCE("folio expected an open fid ...") message,
making it impossible to tell from a crash report which one actually
fired. Split each site out with its own message (and the errno for
the v9fs_fid_lookup() case) to identify the exact cause of the
syzbot-reported "WARNING in v9fs_init_request (2)".

Diagnostic only, not a functional fix.

Reported-by: syzbot+344c09c64fcd8d3d2782@syzkaller.appspotmail.com
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
---
 fs/9p/vfs_addr.c | 37 ++++++++++++++++++++++++-------------
 1 file changed, 24 insertions(+), 13 deletions(-)

diff --git a/fs/9p/vfs_addr.c b/fs/9p/vfs_addr.c
index 1ac0b3dcc077..fc05bd963506 100644
--- a/fs/9p/vfs_addr.c
+++ b/fs/9p/vfs_addr.c
@@ -136,21 +136,37 @@ static int v9fs_init_request(struct netfs_io_request *rreq, struct file *file)
 
 	if (file) {
 		fid = file->private_data;
-		if (!fid)
-			goto no_fid;
+		if (!fid) {
+			WARN_ONCE(1, "DIAG: v9fs_init_request: file has no fid, "
+			           "inode->i_ino=%llx\n", rreq->inode->i_ino);
+			return -EINVAL;
+		}
 		p9_fid_get(fid);
 	} else if (S_ISLNK(rreq->inode->i_mode)) {
 		dentry = d_find_any_alias(rreq->inode);
-		if (!dentry)
-			goto no_fid;
+		if (!dentry) {
+			WARN_ONCE(1, "DIAG: v9fs_init_request: symlink inode has no "
+				  "dentry alias, inode->i_ino=%llx\n",
+				   rreq->inode->i_ino);
+			return -EINVAL;
+		}
 		fid = v9fs_fid_lookup(dentry);
+		if (IS_ERR(fid)) {
+			WARN_ONCE(1, "DIAG: v9fs_init_request: v9fs_fid_lookup failed "
+				"for symlink, err=%ld dentry=%pd4 inode->i_ino=%llx\n",
+			 	PTR_ERR(fid), dentry, rreq->inode->i_ino);
+			dput(dentry);
+			return PTR_ERR(fid);
+		}
 		dput(dentry);
-		if (IS_ERR(fid))
-			goto no_fid;
 	} else {
 		fid = v9fs_fid_find_inode(rreq->inode, writing, INVALID_UID, true);
-		if (!fid)
-			goto no_fid;
+		if (!fid) {
+			WARN_ONCE(1, "DIAG: v9fs_init_request: non-symlink inode has "
+				   "no open/writeback fid, inode->i_ino=%llx\n",
+				   rreq->inode->i_ino);
+			return -EINVAL;
+		}
 	}
 
 	rreq->wsize = fid->clnt->msize - P9_IOHDRSZ;
@@ -163,11 +179,6 @@ static int v9fs_init_request(struct netfs_io_request *rreq, struct file *file)
 	WARN_ON(rreq->origin == NETFS_READ_FOR_WRITE && !(fid->mode & P9_ORDWR));
 	rreq->netfs_priv = fid;
 	return 0;
-
-no_fid:
-	WARN_ONCE(1, "folio expected an open fid inode->i_ino=%llx\n",
-		  rreq->inode->i_ino);
-	return -EINVAL;
 }
 
 /**
-- 
2.43.0


      reply	other threads:[~2026-07-24 11:53 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-24  5:26 [syzbot] [v9fs?] WARNING in v9fs_init_request (2) syzbot
2026-07-24 11:53 ` syzbot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6a63524e.dde6c935.cf6c8.001e.GAE@google.com \
    --to=syzbot+344c09c64fcd8d3d2782@syzkaller.appspotmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.