From: "Мартыненко Артём" <amartynenko140@gmail.com>
To: slava@dubeyko.com, glaubitz@physik.fu-berlin.de, frank.li@vivo.com
Cc: linux-fsdevel@vger.kernel.org
Subject: [BUG] hfsplus: nls_utf8 refcount underflow after failed mount (6.18.53)
Date: Tue, 29 Sep 2026 15:01:49 +0300 [thread overview]
Message-ID: <9AD67E49-86E9-4508-BBC0-26919C72FB6A@gmail.com> (raw)
Hi,
After a single failed "mount -t hfsplus", the refcount of the nls_utf8
module becomes -1. Afterwards, filesystems that need nls_utf8 fail to
mount because the NLS table cannot be loaded (seen with hfsplus and
vfat).
System:
Kernel 6.18.53-0-lts (Alpine linux-lts), Alpine Linux 3.25.0_alpha20260805 (edge)
Steps to reproduce (right after boot):
modprobe nls_utf8
cat /sys/module/nls_utf8/refcnt # 0
fallocate -l 128M dummy.img
mount -t hfsplus dummy.img /mnt # fails, as expected (no valid HFS+ volume)
cat /sys/module/nls_utf8/refcnt # -1
On a clean boot, a failed mount of the same dummy.img with vfat or
exfat leaves refcnt at 0; only hfsplus changes it (to -1).
dmesg after the failed hfsplus mount:
[ 75.017663] loop0: detected capacity change from 0 to 262144
[ 75.068872] hfsplus: unable to find HFS+ superblock
Consequences:
- The next mount of hfsplus fails with
"hfsplus: unable to load nls for utf8".
- vfat, which uses nls_utf8, also fails to mount:
FAT-fs (loop0): utf8 is not a recommended IO charset for FAT filesystems, filesystem will be case sensitive!
FAT-fs (loop0): IO charset utf8 not found
- exfat and ext4 still mount fine (they don't seem to use nls_utf8),
refcnt stays at -1.
- "rmmod -f nls_utf8" triggers "kernel BUG at kernel/module/main.c:736",
after which lsmod hangs.
Full oops:
[ 1480.472851] kernel BUG at kernel/module/main.c:736!
[ 1480.472860] Oops: invalid opcode: 0000 [#1] SMP NOPTI
[ 1480.473648] CPU: 1 UID: 0 PID: 2459 Comm: rmmod Tainted: G S 6.18.53-0-lts #1-Alpine PREEMPT(voluntary)
[ 1480.474438] Tainted: [S]=CPU_OUT_OF_SPEC
[ 1480.475221] Hardware name: System manufacturer System Product Name/P8H61-M LE/USB3, BIOS 3605 03/08/2012
[ 1480.476019] RIP: 0010:__do_sys_delete_module.isra.0+0x2c2/0x2e0
[ 1480.476825] Code: a8 48 c7 c7 80 e9 dd a8 e8 eb df 58 00 e9 e8 fe ff ff 48 c7 c3 ff ff ff ff e9 41 fe ff ff 48 c7 c3 fc ff ff ff e9 35 fe ff ff <0f> 0b 48 c7 c3 fe ff ff ff e9 27 fe ff ff e8 bb 06 bf 00 66 66 2e
[ 1480.478556] RSP: 0018:ffffd0c58007bdc0 EFLAGS: 00010297
[ 1480.479443] RAX: 00000000ffffffff RBX: ffffffffc153b080 RCX: 0000000000000000
[ 1480.480340] RDX: ffffffffc153b548 RSI: 0000000000000000 RDI: 0000000000000000
[ 1480.481234] RBP: 0000559707f5bc70 R08: 0000000000000000 R09: 0000000000000000
[ 1480.482124] R10: 0000000000000000 R11: 0000000000000000 R12: ffffd0c58007bf48
[ 1480.483020] R13: 00000000000000b0 R14: 0000000000000000 R15: 0000000000000000
[ 1480.483921] FS: 00007f9e8a289b28(0000) GS:ffff88c0afc72000(0000) knlGS:0000000000000000
[ 1480.484835] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 1480.485750] CR2: 00007f9e8a0d5058 CR3: 0000000102578004 CR4: 00000000000626f0
[ 1480.486679] Call Trace:
[ 1480.487601] <TASK>
[ 1480.488518] do_syscall_64+0x88/0xd80
[ 1480.489445] ? count_memcg_events+0xf9/0x1c0
[ 1480.490372] ? handle_mm_fault+0x1e2/0x2e0
[ 1480.491300] ? do_user_addr_fault+0x223/0x670
[ 1480.492225] ? exc_page_fault+0x7e/0x1b0
[ 1480.493146] entry_SYSCALL_64_after_hwframe+0x76/0x7e
[ 1480.494065] RIP: 0033:0x7f9e8a22752a
[ 1480.494981] Code: e9 e6 32 01 00 48 83 ec 08 b8 af 00 00 00 0f 05 48 89 c7 e8 49 eb ff ff 48 83 c4 08 c3 48 83 ec 08 89 f6 b8 b0 00 00 00 0f 05 <48> 89 c7 e8 2f eb ff ff 48 83 c4 08 c3 48 83 ec 08 49 89 ca b8 a5
[ 1480.496975] RSP: 002b:00007ffdce7a6f90 EFLAGS: 00000206 ORIG_RAX: 00000000000000b0
[ 1480.498007] RAX: ffffffffffffffda RBX: 0000559707f5bc10 RCX: 00007f9e8a22752a
[ 1480.499044] RDX: 0000000000000000 RSI: 0000000000000a00 RDI: 0000559707f5bc70
[ 1480.500078] RBP: 00000000fffffffe R08: 0000000000000000 R09: 00007ffdce7a6ff0
[ 1480.501105] R10: 00000000fffffffe R11: 0000000000000206 R12: 0000000000000200
[ 1480.502134] R13: 0000000000000003 R14: 0000000000000002 R15: 0000000000000200
[ 1480.503171] </TASK>
[ 1480.504199] Modules linked in: hfsplus cdrom exfat vfat fat nls_utf8 radeon drm_ttm_helper drm_exec drm_suballoc_helper af_packet tun fuse snd_hda_codec_alc882 snd_hda_codec_realtek_lib snd_hda_codec_generic coretemp intel_rapl_msr intel_rapl_common mousedev snd_hda_intel snd_hda_codec x86_pkg_temp_thermal intel_powerclamp snd_hda_core kvm_intel iTCO_wdt r8169 intel_pmc_bxt snd_intel_dspcfg eeepc_wmi ppdev iTCO_vendor_support kvm asus_wmi snd_intel_sdw_acpi realtek snd_hwdep sparse_keymap snd_pcm battery irqbypass mdio_devres rfkill psmouse snd_timer ghash_clmulni_intel libphy snd mdio_bus rapl intel_cstate serio_raw parport_pc joydev soundcore wmi_bmof at24 input_leds pcspkr parport thermal lpc_ich fan evdev uas hid_generic usbhid hid i915 drm_buddy ttm hwmon i2c_algo_bit drm_display_helper cec intel_gtt video xhci_pci xhci_hcd ehci_pci ehci_hcd i2c_i801 i2c_mux i2c_smbus ata_generic pata_acpi ata_piix libata button wmi loop ext4 crc16 mbcache jbd2 usb_storage usbcore usb_common sd_mod scsi_mod scsi_common
[ 1480.511897] ---[ end trace 0000000000000000 ]---
Kernel config: https://gist.github.com/Artem-coderh/1a88659aad75595b9cadd2f40afee913
Hardware: ASUS P8H61-M LE, BIOS 3605.
I have not tested other kernel versions. I can test patches or bisect
if needed.
Thanks,
Artem Martynenko
next reply other threads:[~2026-09-29 12:01 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 12:01 Мартыненко Артём [this message]
2026-09-29 18:47 ` [BUG] hfsplus: nls_utf8 refcount underflow after failed mount (6.18.53) Viacheslav Dubeyko
2026-09-29 19:43 ` Мартыненко Артём
2026-09-29 23:29 ` Viacheslav Dubeyko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=9AD67E49-86E9-4508-BBC0-26919C72FB6A@gmail.com \
--to=amartynenko140@gmail.com \
--cc=frank.li@vivo.com \
--cc=glaubitz@physik.fu-berlin.de \
--cc=linux-fsdevel@vger.kernel.org \
--cc=slava@dubeyko.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox