Skip to content

[syzbot] [nilfs?] WARNING in nilfs_btree_mark #167

@konis

Description

@konis

Link: https://syzkaller.appspot.com/bug?extid=98a040252119df0506f8
Link: https://lore.kernel.org/all/69bba3ff.050a0220.227207.0031.GAE@google.com

Hello,

syzbot found the following issue on:

HEAD commit:    f0caa1d49cc0 Merge tag 'hid-for-linus-2026031701' of git:/..
git tree:       upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=12d868da580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=d46eab0cfd31c214
dashboard link: https://syzkaller.appspot.com/bug?extid=98a040252119df0506f8
compiler:       Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8
syz repro:      https://syzkaller.appspot.com/x/repro.syz?x=1452974a580000

Downloadable assets:
disk image (non-bootable): https://storage.googleapis.com/syzbot-assets/d900f083ada3/non_bootable_disk-f0caa1d4.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/790e2ce16030/vmlinux-f0caa1d4.xz
kernel image: https://storage.googleapis.com/syzbot-assets/dcb6a5644f0c/bzImage-f0caa1d4.xz
mounted in repro: https://storage.googleapis.com/syzbot-assets/93d9925377df/mount_1.gz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+98a040252119df0506f8@syzkaller.appspotmail.com

------------[ cut here ]------------
ret == -ENOENT
WARNING: fs/nilfs2/btree.c:2356 at nilfs_btree_mark+0x1c9/0x210 fs/nilfs2/btree.c:2356, CPU#0: syz.0.17/5469
Modules linked in:
CPU: 0 UID: 0 PID: 5469 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full) 
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:nilfs_btree_mark+0x1c9/0x210 fs/nilfs2/btree.c:2356
Code: 48 8b 05 4a f8 6e 0f 48 3b 44 24 10 75 26 89 e8 48 83 c4 18 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc cc e8 88 f8 17 fe 90 <0f> 0b 90 bd fe ff ff ff eb c3 e8 58 99 02 08 44 89 f1 80 e1 07 80
RSP: 0018:ffffc90003d375b0 EFLAGS: 00010293
RAX: ffffffff83adb7f8 RBX: ffff888042014000 RCX: ffff888040904980
RDX: 0000000000000000 RSI: 00000000fffffffe RDI: 00000000fffffffe
RBP: 00000000fffffffe R08: 000000000000000e R09: 0000000000000000
R10: ffff888042014678 R11: ffffed10084028d3 R12: ffff8880464286a0
R13: dffffc0000000000 R14: ffff888046428668 R15: 0000000000000009
FS:  00007f5bd0f206c0(0000) GS:ffff88808ca55000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fab839e8000 CR3: 0000000033512000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 nilfs_bmap_mark+0xba/0x180 fs/nilfs2/bmap.c:402
 nilfs_ioctl_mark_blocks_dirty fs/nilfs2/ioctl.c:764 [inline]
 nilfs_ioctl_prepare_clean_segments+0x49a/0x800 fs/nilfs2/ioctl.c:799
 nilfs_clean_segments+0x18c/0xa50 fs/nilfs2/segment.c:2525
 nilfs_ioctl_clean_segments fs/nilfs2/ioctl.c:916 [inline]
 nilfs_ioctl+0x261f/0x2780 fs/nilfs2/ioctl.c:1346
 vfs_ioctl fs/ioctl.c:51 [inline]
 __do_sys_ioctl fs/ioctl.c:597 [inline]
 __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:583
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x14d/0xf80 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f5bcff9c799
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f5bd0f20028 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007f5bd0215fa0 RCX: 00007f5bcff9c799
RDX: 0000200000000640 RSI: 0000000040786e88 RDI: 0000000000000004
RBP: 00007f5bd0032c99 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f5bd0216038 R14: 00007f5bd0215fa0 R15: 00007ffdf65e5358
 </TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

Metadata

Metadata

Assignees

No one assigned

    Labels

    patch proposedA patch has been proposed and is in on the way to the main line.syzbot

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions