lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <68fb440f.050a0220.346f24.00b6.GAE@google.com>
Date: Fri, 24 Oct 2025 02:17:03 -0700
From: syzbot <syzbot+f2107d999290b8166267@...kaller.appspotmail.com>
To: dmantipov@...dex.ru, linux-kernel@...r.kernel.org, 
	syzkaller-bugs@...glegroups.com
Subject: Re: [syzbot] [ocfs2?] kernel BUG in __ocfs2_move_extents_range

Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
kernel BUG in __ocfs2_move_extents_range

ocfs2: Mounting device (7,0) on (node local, slot 0) with writeback data mode.
------------[ cut here ]------------
kernel BUG at fs/ocfs2/suballoc.c:1365!
Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP
Modules linked in:
CPU: 1 PID: 7289 Comm: syz.0.17 Tainted: G        W         syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/30/2025
pstate: 82400005 (Nzcv daif +PAN -UAO +TCO BTYPE=--)
pc : ocfs2_block_group_set_bits+0x44c/0x70c fs/ocfs2/suballoc.c:1365
lr : ocfs2_block_group_set_bits+0x444/0x70c fs/ocfs2/suballoc.c:1365
sp : ffffff80cb35f950
x29: ffffff80cb35f980 x28: dfffffd000000000 
x27: 1ffffff019f28001 x26: 0000000000000002 
x25: ffffff80e95b4d38 x24: ffffff80cf94000c 
x23: ffffff80cf940000 x22: 0000000000000168 
x21: 0000000000000001 x20: ffffff80da545e80 
x19: dfffffd000000000 x18: ffffffd01197d7ac 
x17: 00000000fffffffc x16: 0000000000ff0100 
x15: ffffffffffffffff x14: ffffff80ca764f80 
x13: ffffffd01dd9b000 x12: 0000000000000000 
x11: 0000000000ff0100 x10: 0000000000000000 
x9 : ffffff80ca764f80 x8 : ffffffd01198f8a8 
x7 : 0000000000000000 x6 : ffffffd010c7ba54 
x5 : 0000000000000168 x4 : 0000000000000001 
x3 : ffffff80da545e80 x2 : ffffff80cf940000 
x1 : 0000000000000002 x0 : ffffffd01bc8af10 
Call trace:
 ocfs2_block_group_set_bits+0x44c/0x70c fs/ocfs2/suballoc.c:1365
 ocfs2_move_extent fs/ocfs2/move_extents.c:695 [inline]
 __ocfs2_move_extents_range+0x1e74/0x27ec fs/ocfs2/move_extents.c:868
 ocfs2_move_extents+0x2b0/0x750 fs/ocfs2/move_extents.c:935
 ocfs2_ioctl_move_extents+0x3b0/0x55c fs/ocfs2/move_extents.c:1067
 ocfs2_ioctl+0x2ac/0x10c8 fs/ocfs2/ioctl.c:946
 vfs_ioctl fs/ioctl.c:48 [inline]
 __do_sys_ioctl fs/ioctl.c:753 [inline]
 __se_sys_ioctl fs/ioctl.c:739 [inline]
 __arm64_sys_ioctl+0x148/0x1c0 fs/ioctl.c:739
 __invoke_syscall arch/arm64/kernel/syscall.c:36 [inline]
 invoke_syscall arch/arm64/kernel/syscall.c:48 [inline]
 el0_svc_common+0x1b8/0x480 arch/arm64/kernel/syscall.c:155
 do_el0_svc+0x54/0x134 arch/arm64/kernel/syscall.c:194
 el0_svc+0x1c/0x28 arch/arm64/kernel/entry-common.c:365
 el0_sync_handler+0xc4/0xd8 arch/arm64/kernel/entry-common.c:381
 el0_sync+0x168/0x180 arch/arm64/kernel/entry.S:689
Code: 95bd6322 97aad992 f00517c0 913c4000 (d4210000) 
---[ end trace f4492e09a8a518f9 ]---


Tested on:

commit:         d3d0b4e2 Linux 5.10.245
git tree:       https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git linux-5.10.y
console output: https://syzkaller.appspot.com/x/log.txt?x=141c2d2f980000
kernel config:  https://syzkaller.appspot.com/x/.config?x=37e065cc9b6362d
dashboard link: https://syzkaller.appspot.com/bug?extid=f2107d999290b8166267
compiler:       Debian clang version 20.1.8 (++20250708063551+0c9f909b7976-1~exp1~20250708183702.136), Debian LLD 20.1.8
userspace arch: arm64
patch:          https://syzkaller.appspot.com/x/patch.diff?x=11982d2f980000


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ