From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id C6462C7EE37 for ; Tue, 6 Jun 2023 22:45:49 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S240041AbjFFWpq (ORCPT ); Tue, 6 Jun 2023 18:45:46 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:37446 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S239991AbjFFWpn (ORCPT ); Tue, 6 Jun 2023 18:45:43 -0400 Received: from mail-oi1-x235.google.com (mail-oi1-x235.google.com [IPv6:2607:f8b0:4864:20::235]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id C0303171B for ; Tue, 6 Jun 2023 15:45:36 -0700 (PDT) Received: by mail-oi1-x235.google.com with SMTP id 5614622812f47-3980f2df1e7so5668404b6e.1 for ; Tue, 06 Jun 2023 15:45:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fromorbit-com.20221208.gappssmtp.com; s=20221208; t=1686091536; x=1688683536; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=bcp3ffy5XwTKce5q56EsqOA6PVGSPjy/lGc3gn6qOmU=; b=Wj9iARWqwKYgu1upHY1HlgemGOrhjZzWv7NuN6Ahgl/AsNZfjnfA7Auy9tv7nZm4PR cDlu/GYxb3Sm/ROvjGgow1ZtN87VDyaCjxTir2f4Z1aJht/Jj8YS0TOdKMy3xdewK/z7 ruYyjQhptjT9jyitvst2phsnk0OK2HvFuhXTq2OiB4AC42AL7ByRYrnQvAI3kqwk3bXo gKXtEZaFURDN6igizQDGKO8HhDy8VbSz7VvVbop2CFqMhcQ9lVdJSgXCTM6St/ymWfdO HnryHCajNg/IWpTBRklu65AOYO9egNLWiNS7pYFfEqD0YawgsPxScZXDAu6T02vzZkKc N6Rg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1686091536; x=1688683536; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=bcp3ffy5XwTKce5q56EsqOA6PVGSPjy/lGc3gn6qOmU=; b=kvEzoM9Mnj28xr/cP0+6h6tQBXnlm4MBsfZAZYOXVB+HCfHIxrBXkeeBL+WOQIjTZj 1rF/tT71gFYPnpsjLtf4i7ACP4h2CpcznxhkJnVhUjXWJOTcHtnGci3hpvjqDbTNzKLL lk+Jfr4y4tUXuH+/3QceNhzkB1uX2BWAoMGjgzU1WXcr08aCUBgFg7eoiaQ532TERuXf wwQhF0g1vZ96ONWJgSettTkCf5LH78G2NsqnJnA7PnTcB01ywLqqnzvlAeqKgPQrHolV OsZaodOvGyq6Re2pza1osUpTC5bfjHy0SOWNLrKeT66DOCYyfwAQqUEbmz8NS/3EJVSB oosg== X-Gm-Message-State: AC+VfDzzH8yha+BbquDTMuk1GhfiRuFvqqOJfh00TEUltB6vsVtCNukF hiAsZTiLT/rAcPcwX2HrJNVBTg== X-Google-Smtp-Source: ACHHUZ5fi0BA0A0q3DfsBlhTUutkY29CteYXLvsSh9kIVopCpR1sLQ1E5i8v1OAycYH7pgKENB/E3Q== X-Received: by 2002:aca:130c:0:b0:396:3b9b:d217 with SMTP id e12-20020aca130c000000b003963b9bd217mr3496151oii.18.1686091536046; Tue, 06 Jun 2023 15:45:36 -0700 (PDT) Received: from dread.disaster.area (pa49-179-79-151.pa.nsw.optusnet.com.au. [49.179.79.151]) by smtp.gmail.com with ESMTPSA id b10-20020a63cf4a000000b0050a0227a4bcsm7927471pgj.57.2023.06.06.15.45.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 06 Jun 2023 15:45:35 -0700 (PDT) Received: from dave by dread.disaster.area with local (Exim 4.96) (envelope-from ) id 1q6fQi-008f6H-2S; Wed, 07 Jun 2023 08:45:32 +1000 Date: Wed, 7 Jun 2023 08:45:32 +1000 From: Dave Chinner To: David Sterba Cc: syzbot , clm@fb.com, dsterba@suse.com, josef@toxicpanda.com, linux-btrfs@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Subject: Re: [syzbot] [btrfs?] INFO: task hung in btrfs_sync_file (2) Message-ID: References: <00000000000086021605fd1b484c@google.com> <20230606142405.GI25292@twin.jikos.cz> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20230606142405.GI25292@twin.jikos.cz> Precedence: bulk List-ID: X-Mailing-List: linux-btrfs@vger.kernel.org On Tue, Jun 06, 2023 at 04:24:05PM +0200, David Sterba wrote: > On Thu, Jun 01, 2023 at 06:15:06PM -0700, syzbot wrote: > > RIP: 0010:rep_movs_alternative+0x33/0xb0 arch/x86/lib/copy_user_64.S:56 > > Code: 46 83 f9 08 73 21 85 c9 74 0f 8a 06 88 07 48 ff c7 48 ff c6 48 ff c9 75 f1 c3 66 66 2e 0f 1f 84 00 00 00 00 00 66 90 48 8b 06 <48> 89 07 48 83 c6 08 48 83 c7 08 83 e9 08 74 df 83 f9 08 73 e8 eb > > RSP: 0018:ffffc9000becf728 EFLAGS: 00050206 > > RAX: 0000000000000000 RBX: 0000000000000038 RCX: 0000000000000038 > > RDX: fffff520017d9efb RSI: ffffc9000becf7a0 RDI: 0000000020000120 > > RBP: 0000000020000120 R08: 0000000000000000 R09: fffff520017d9efa > > R10: ffffc9000becf7d7 R11: 0000000000000001 R12: ffffc9000becf7a0 > > R13: 0000000020000158 R14: 0000000000000000 R15: ffffc9000becf7a0 > > copy_user_generic arch/x86/include/asm/uaccess_64.h:112 [inline] > > raw_copy_to_user arch/x86/include/asm/uaccess_64.h:133 [inline] > > _copy_to_user lib/usercopy.c:41 [inline] > > _copy_to_user+0xab/0xc0 lib/usercopy.c:34 > > copy_to_user include/linux/uaccess.h:191 [inline] > > fiemap_fill_next_extent+0x217/0x370 fs/ioctl.c:144 > > emit_fiemap_extent+0x18e/0x380 fs/btrfs/extent_io.c:2616 > > fiemap_process_hole+0x516/0x610 fs/btrfs/extent_io.c:2874 > > and extent enumeration from FIEMAP, this would qualify as a stress on > the inode FWIW, when I've seen this sort of hang on XFS in past times, it's been caused by a corrupt extent list or a circular reference in a btree that the fuzzing introduced. Hence FIEMAP just keeps going around in circles and never gets out of the loop to drop the inode lock.... Cheers, Dave. -- Dave Chinner david@fromorbit.com