All of lore.kernel.org
 help / color / mirror / Atom feed
* [syzbot] [v9fs?] WARNING in v9fs_init_request (2)
@ 2026-07-24  5:26 syzbot
  2026-07-24 11:53 ` Forwarded: [PATCH] 9p: add DIAG WARN_ONCE sites to disambiguate v9fs_init_request no_fid failures syzbot
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: syzbot @ 2026-07-24  5:26 UTC (permalink / raw)
  To: asmadeus, ericvh, linux-kernel, linux_oss, lucho, syzkaller-bugs,
	v9fs

Hello,

syzbot found the following issue on:

HEAD commit:    1590cf032971 Linux 7.2-rc4
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=1446a746580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=48ef5c5c0f192153
dashboard link: https://syzkaller.appspot.com/bug?extid=344c09c64fcd8d3d2782
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=1632bc32580000
C reproducer:   https://syzkaller.appspot.com/x/repro.c?x=13e0b789580000

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-1590cf03.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/3ad7477f3064/vmlinux-1590cf03.xz
kernel image: https://storage.googleapis.com/syzbot-assets/8e7a9174d4d6/bzImage-1590cf03.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+344c09c64fcd8d3d2782@syzkaller.appspotmail.com

------------[ cut here ]------------
folio expected an open fid inode->i_ino=4580113
WARNING: fs/9p/vfs_addr.c:168 at v9fs_init_request+0x451/0x540 fs/9p/vfs_addr.c:168, CPU#2: syz.0.21/5945
Modules linked in:
CPU: 2 UID: 0 PID: 5945 Comm: syz.0.21 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:v9fs_init_request+0x455/0x540 fs/9p/vfs_addr.c:168
Code: 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 40 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 db 00 00 00 48 8d 3d bf b1 20 0d 48 8b 73 40 <67> 48 0f b9 3a bb ea ff ff ff e9 41 fe ff ff e8 f7 98 ff fd be 02
RSP: 0018:ffffc90003c5f778 EFLAGS: 00010246
RAX: dffffc0000000000 RBX: ffff888056c2d240 RCX: ffffffff840a4337
RDX: 1ffff1100ad85a50 RSI: 0000000004580113 RDI: ffffffff912af550
RBP: fffffffffffffffe R08: 0000000000000007 R09: fffffffffffff000
R10: fffffffffffffffe R11: 0000000000000000 R12: ffff888038e04178
R13: ffff888050c78e41 R14: ffff888050c78bd0 R15: ffff888056c2d240
FS:  00007ff5dd1fe6c0(0000) GS:ffff8880d5fe6000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ff5dd1bbff8 CR3: 000000003d81d000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 netfs_alloc_request+0x71c/0xcb0 fs/netfs/objects.c:72
 netfs_read_folio+0x20c/0x13f0 fs/netfs/buffered_read.c:513
 filemap_read_folio+0xfc/0x3b0 mm/filemap.c:2510
 do_read_cache_folio+0x2d7/0x6b0 mm/filemap.c:4140
 read_mapping_folio include/linux/pagemap.h:1015 [inline]
 __page_get_link.isra.0+0x30/0x350 fs/namei.c:6336
 page_get_link+0x44/0xf0 fs/namei.c:6366
 v9fs_vfs_get_link_dotl+0x27b/0x310 fs/9p/vfs_inode_dotl.c:930
 pick_link+0xd17/0x13c0 fs/namei.c:2068
 step_into_slowpath+0x9ba/0xf90 fs/namei.c:2127
 step_into fs/namei.c:2152 [inline]
 walk_component fs/namei.c:2288 [inline]
 lookup_last fs/namei.c:2789 [inline]
 path_lookupat+0x58b/0xc40 fs/namei.c:2813
 filename_lookup+0x202/0x590 fs/namei.c:2842
 user_path_at+0x3c/0x60 fs/namei.c:3641
 do_mount fs/namespace.c:4171 [inline]
 __do_sys_mount fs/namespace.c:4390 [inline]
 __se_sys_mount fs/namespace.c:4367 [inline]
 __x64_sys_mount+0x1fb/0x310 fs/namespace.c:4367
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x115/0x870 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7ff5ddb9de99
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ff5dd1fe028 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007ff5dde25fa0 RCX: 00007ff5ddb9de99
RDX: 00002000000004c0 RSI: 0000200000000480 RDI: 0000000000000000
RBP: 00007ff5ddc33eaf R08: 0000200000000c00 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007ff5dde26038 R14: 00007ff5dde25fa0 R15: 00007ffc18202cd8
 </TASK>
----------------
Code disassembly (best guess):
   0:	48 b8 00 00 00 00 00 	movabs $0xdffffc0000000000,%rax
   7:	fc ff df
   a:	48 8d 7b 40          	lea    0x40(%rbx),%rdi
   e:	48 89 fa             	mov    %rdi,%rdx
  11:	48 c1 ea 03          	shr    $0x3,%rdx
  15:	80 3c 02 00          	cmpb   $0x0,(%rdx,%rax,1)
  19:	0f 85 db 00 00 00    	jne    0xfa
  1f:	48 8d 3d bf b1 20 0d 	lea    0xd20b1bf(%rip),%rdi        # 0xd20b1e5
  26:	48 8b 73 40          	mov    0x40(%rbx),%rsi
* 2a:	67 48 0f b9 3a       	ud1    (%edx),%rdi <-- trapping instruction
  2f:	bb ea ff ff ff       	mov    $0xffffffea,%ebx
  34:	e9 41 fe ff ff       	jmp    0xfffffe7a
  39:	e8 f7 98 ff fd       	call   0xfdff9935
  3e:	be                   	.byte 0xbe
  3f:	02                   	.byte 0x2


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-07-25  1:41 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-24  5:26 [syzbot] [v9fs?] WARNING in v9fs_init_request (2) syzbot
2026-07-24 11:53 ` Forwarded: [PATCH] 9p: add DIAG WARN_ONCE sites to disambiguate v9fs_init_request no_fid failures syzbot
2026-07-24 23:41 ` Forwarded: [PATCH] 9p: add printk diagnostics to identify -ENOENT source in v9fs_fid_lookup syzbot
2026-07-25  1:41 ` Forwarded: [PATCH] 9p: don't WARN_ONCE on racy symlink fid lookup failure syzbot

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.