From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.sourceforge.net (lists.sourceforge.net [216.105.38.7]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 2BC8FF3C269 for ; Mon, 9 Mar 2026 14:25:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=5JK735EV3qc6up6mDCrX7Dq48spnc6jGmYZWXC3exmg=; b=WPsSfIoIE2lbbwLrG4KFRVbUoO eMEci1hDzo6ST8IKfe31I+959Gw5AHUanfKdpmmi4KhAn1fxxSCNUQFjGGu1FCqdtRb8lT6zNQiuf OE/QHR24pVutCo3NUBQ+cfeZNUnxbJbjnG0jUC7Qjw8fIMY3G/9ZdEk2AIU4ADUhFCxo=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1vzbXy-0006Bp-DK; Mon, 09 Mar 2026 14:25:27 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1vzbXw-0006Bb-Qs for linux-f2fs-devel@lists.sourceforge.net; Mon, 09 Mar 2026 14:25:25 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:Content-Type:MIME-Version :References:In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=c7aG9u42wmFmQg8NexFKsDrO72+eXJWZ5zwfM9O0k3U=; b=IiD0F9HVpESGNgCqsI4mmBEj9N MEPzpoQ/HqI4DzG1gt/b4/9NhJ+5JI3jwkaK3KuHzZFYdVAezWZjv0jh5qunSJTjhMv0M6gU1940/ hc+Y54qNPCn5d10UQkd9avuRiqo8zwoIHh09VS08YXIv4Ll3xj4hlnZjqJ7YATjayToI=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:Content-Type:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=c7aG9u42wmFmQg8NexFKsDrO72+eXJWZ5zwfM9O0k3U=; b=Tp61XFq2jqG+YNKe/XKmyPzm1p wxpS7E3hqc1x8uZsYX/eWeN2Q0riXiqk0vqmHpqV/KkGnpRww62Gf7PquvVH97WUtZ+Er1cVuqCWG am0mOMo1BYg9NOLy7jJGM8cdIQblj91tdQ0NIV5s3ggHJtekcXb+XQoPX/gfSW2ZI0nA=; Received: from mail-pf1-f170.google.com ([209.85.210.170]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95) id 1vzbXx-00030v-5j for linux-f2fs-devel@lists.sourceforge.net; Mon, 09 Mar 2026 14:25:25 +0000 Received: by mail-pf1-f170.google.com with SMTP id d2e1a72fcca58-826dab01bbdso593258b3a.0 for ; Mon, 09 Mar 2026 07:25:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1773066314; x=1773671114; darn=lists.sourceforge.net; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=c7aG9u42wmFmQg8NexFKsDrO72+eXJWZ5zwfM9O0k3U=; b=fDKgS3UGCMlJJsGN52xROYgvX2N2WcnuspshKr7PwIONvhX+HEKqkJJPQhQ82mhwCQ nJJ4xO9UOH0o46XMtFvydsFIa4Qt8977Kxo2jp9OVy22Pmbw63trUMG/F27pJv09YX/j Y6N1UIpDW5ePO36D3F3UjE94T6tqjn3V2G9+bFJiRATpnJuFON2+98UHxkOrbWVi1Kz/ 4eXtv56JbHfUWu/APRoRUdgrzQhmExcjD55Iv6t/F0Au3t3o1lf1QFs8OTVZ3IN0fz0v N4XqlJFWzPd4GgmjVzCTt8phBqDQDc69XlcnQwVPUihVQUgbwr9UII99dS2glciYpMHj 6N2Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1773066314; x=1773671114; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=c7aG9u42wmFmQg8NexFKsDrO72+eXJWZ5zwfM9O0k3U=; b=tefhbli1mU//DgryEmEii6w+j+XSsRjhZMfKBR/ep1Wc/XBQzSXuKm5DvlYA9E0uRE emrry1fntczGxP4SEitUcFw/mz5ptgwkXxDDbKpIYQNRv5p1hGdJBgpQY/VWo6JX36JN crrIQung7Cyzov7kAd2Ki/w7w6r2fAA0NzNAZJmpYzigpmrRM4bALm0Fs219K8XJAG4x uXX1Vb6Gx6U/5vMoVwo++t6TXfyliHVpb4PVbOk6q5XH27aYxL/6MBHMm4oyO7ywlzZy fJ1OzebM2udtqRcpoepaVAZGywj7C1bp7jkxo5M1OZIA90oO78MD7q00N1cCFbJUTfnw 7TOA== X-Forwarded-Encrypted: i=1; AJvYcCXRtbZFdOqg+o6VSHLuYzIm3nSKa2DogMDo7r7PyB8YlUq4f3zSNTdnbuqdk4Wx5D7rRflTR0TdLLukNLp5Sdiw@lists.sourceforge.net X-Gm-Message-State: AOJu0YxsV+ALXmo8QdbOVxwpAC1O8UPTsKSO45EZnpVUUIxjEzTVEz8K BOV2BZ+r06xwWQl9tfrbUQJ1Uplfg9Itsg/TMGqM2zlyDEllIIKmw9bt X-Gm-Gg: ATEYQzwURb65M+tRk4Bup7tZW2m0ZtVywaZ1k1yYUfo6bcEK3PRZqHxiz6OvfDc0qxn 2wsjtHUJlqlDBhdtK7HkdpUc1ttImyTwz4KwVeishredaTaNI8mnTA0YLtW6kJamA02wC6u0m3B JHcUUV4adZMtNug5RdZ1h7Kmn+TNPGGRnWXNZ08BbZIJbhGr9P9y+s/PYY8MBvvb0J9FZVr0O83 Qxqnq81VaHIkChfmZMujlIGlRU3digZut+iUZaeQtHTKSaDfQbNV1I3ON9/6Por9PEU/KX2h+Bz 3rHAF4vGEZXMScwopXzVSdSC21eUk9Jxz0i72AIDoplf8W+/9s5RtvxT2/FhLsJ53//bgkg0zAP UyStH4xN+cf8lNvabpyJxvGjix6RKND7eJkQ1dHfcBc3W8EKjeAP3B/A+rYA4Q6TCr4465H6VPE SmRAyFsWbS9htrHgQfP1ZC03wwVAT1vA== X-Received: by 2002:a05:6a00:7087:b0:81f:e791:ea3d with SMTP id d2e1a72fcca58-829a2bc7669mr5220002b3a.0.1773066314438; Mon, 09 Mar 2026 07:25:14 -0700 (PDT) Received: from kt5965-NUC8i3BEH.. ([182.217.14.201]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-829a4636a9dsm10482027b3a.4.2026.03.09.07.25.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 09 Mar 2026 07:25:13 -0700 (PDT) From: kth5965@gmail.com To: Chao Yu , jaegeuk@kernel.org, linux-f2fs-devel@lists.sourceforge.net Date: Mon, 9 Mar 2026 23:25:09 +0900 Message-ID: <20260309142509.75703-1-kth5965@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <9df7bc57-f0e1-4c7b-9ce1-0017eab62c2a@kernel.org> References: <20260224160654.448538-1-kth5965@gmail.com> <20260224165408.450957-1-kth5965@gmail.com> <9df7bc57-f0e1-4c7b-9ce1-0017eab62c2a@kernel.org> MIME-Version: 1.0 X-Headers-End: 1vzbXx-00030v-5j Subject: Re: [f2fs-dev] [PATCH v2] f2fs: evict: truncate page cache before clear_inode X-BeenThere: linux-f2fs-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: kth5965@gmail.com, linux-kernel@vger.kernel.org, syzbot+fc026e87558558f75c00@syzkaller.appspotmail.com Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: linux-f2fs-devel-bounces@lists.sourceforge.net Hi Chao, Thanks for the comment. I took another look at the path, and I think you are right that my current fix is too broad and may hide the real problem. It looks like this happens in a more specific case, where an inode still has FI_INLINE_DATA set, but FI_DATA_EXIST is not set. In that case, f2fs_truncate() goes into the inline conversion path, and f2fs_convert_inline_inode() grabs folio 0 before it checks whether there is real inline data to move. Then f2fs_convert_inline_folio() does this: if (!f2fs_exist_data(dn->inode)) goto clear_out; So for the empty-inline case, it returns success, but folio 0 seems to have already been added to the page cache by then. >From what I can see, f2fs_grab_cache_folio() may create folio 0 and add it to inode->i_mapping when there is no folio at that index, so inode->i_data.nrpages becomes 1 there. After that, f2fs_folio_put() only drops the ref, and the folio stays there. Because of that, clear_inode() later sees nrpages != 0 and hits the BUG. This is the flow I am seeing: f2fs_evict_inode() -> truncate_inode_pages_final(&inode->i_data) // nrpages = 0 -> i_size_write(inode, 0) -> f2fs_truncate(inode) -> !f2fs_may_inline_data(inode) -> f2fs_convert_inline_inode(inode) -> f2fs_grab_cache_folio(inode->i_mapping, 0, false) // folio 0 is inserted into page cache // nrpages = 1 -> f2fs_convert_inline_folio(&dn, folio) -> !f2fs_exist_data(inode) -> clear_out -> f2fs_folio_put(folio, true) // only drops the ref // folio stays in page cache -> clear_inode() -> BUG_ON(inode->i_data.nrpages) So it seems better to fix this in the inline conversion path, instead of truncating all page cache again at the end of eviction. If you agree, I can send a new patch in that direction. Thanks, _______________________________________________ Linux-f2fs-devel mailing list Linux-f2fs-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/linux-f2fs-devel